{"cves":[{"cve_id":"CVE-2026-103587","summary":"QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into template variables without validation. Attackers can craft a malicious link containing JavaScript payload in these parameters that executes in an authenticated administrator's session when the victim follows the link.","cvss":5.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":5.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Qloapps/QloApps","https://github.com/Qloapps/QloApps/blob/v1.7.0/modules/hotelreservationsystem/controllers/admin/AdminHotelRoomsBookingController.php","https://github.com/Qloapps/QloApps/blob/v1.7.0/modules/hotelreservationsystem/views/templates/admin/hotel_rooms_booking/helpers/view/_partials/booking-rooms.tpl","https://github.com/Qloapps/QloApps/commit/1d06fd302a935d68203dbdb341d89482621769d7","https://github.com/Qloapps/QloApps/pull/1884","https://hackmd.io/@leediay/four-reflected-xss-qloapps","https://hackmd.io/@leediay/reflected-xss-qloapps-via-booking-now","https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-book-now-search-parameters"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T23:16:58","euvd":{"id":"EUVD-2026-90435","description":"QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into template variables without validation. Attackers can craft a malicious link containing JavaScript payload in these parameters that executes in an authenticated administrator's session when the victim follows the link.","published_time":"2026-09-30T23:02:32","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/Qloapps/QloApps/pull/1884","https://github.com/Qloapps/QloApps/commit/1d06fd302a935d68203dbdb341d89482621769d7","https://github.com/Qloapps/QloApps/blob/v1.7.0/modules/hotelreservationsystem/controllers/admin/AdminHotelRoomsBookingController.php","https://github.com/Qloapps/QloApps/blob/v1.7.0/modules/hotelreservationsystem/views/templates/admin/hotel_rooms_booking/helpers/view/_partials/booking-rooms.tpl","https://hackmd.io/@leediay/reflected-xss-qloapps-via-booking-now","https://hackmd.io/@leediay/four-reflected-xss-qloapps","https://github.com/Qloapps/QloApps","https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-book-now-search-parameters"],"products":["QloApps"],"vendors":["Webkul"]}},{"cve_id":"CVE-2026-103588","summary":"QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious link containing JavaScript payload in the exceptions parameter that executes in an authenticated administrator's session when the victim follows the link.","cvss":5.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":5.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Qloapps/QloApps","https://github.com/Qloapps/QloApps/blob/v1.7.0/controllers/admin/AdminModulesPositionsController.php","https://github.com/Qloapps/QloApps/commit/7ed467d911086b190180d7f297e3b15ba31e82d5","https://github.com/Qloapps/QloApps/pull/1899","https://hackmd.io/@leediay/four-reflected-xss-qloapps","https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-exceptions-field"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T23:16:58","euvd":{"id":"EUVD-2026-90436","description":"QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious link containing JavaScript payload in the exceptions parameter that executes in an authenticated administrator's session when the victim follows the link.","published_time":"2026-09-30T23:02:33","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/Qloapps/QloApps/pull/1899","https://github.com/Qloapps/QloApps/commit/7ed467d911086b190180d7f297e3b15ba31e82d5","https://github.com/Qloapps/QloApps/blob/v1.7.0/controllers/admin/AdminModulesPositionsController.php","https://hackmd.io/@leediay/four-reflected-xss-qloapps","https://github.com/Qloapps/QloApps","https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-exceptions-field"],"products":["QloApps"],"vendors":["Webkul"]}},{"cve_id":"CVE-2026-103589","summary":"QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values in input attributes. Attackers can induce authenticated back-office users to submit crafted POST requests with malicious payloads to execute arbitrary JavaScript in the victim's administrative session.","cvss":5.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":5.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Qloapps/QloApps","https://github.com/Qloapps/QloApps/blob/v1.7.0/admin/themes/default/template/controllers/products/configuration.tpl","https://github.com/Qloapps/QloApps/commit/7ed467d911086b190180d7f297e3b15ba31e82d5","https://github.com/Qloapps/QloApps/pull/1899","https://hackmd.io/@leediay/four-reflected-xss-qloapps","https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-room-type-editor"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T23:16:58","euvd":{"id":"EUVD-2026-90437","description":"QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values in input attributes. Attackers can induce authenticated back-office users to submit crafted POST requests with malicious payloads to execute arbitrary JavaScript in the victim's administrative session.","published_time":"2026-09-30T23:02:34","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/Qloapps/QloApps/pull/1899","https://github.com/Qloapps/QloApps/commit/7ed467d911086b190180d7f297e3b15ba31e82d5","https://github.com/Qloapps/QloApps/blob/v1.7.0/admin/themes/default/template/controllers/products/configuration.tpl","https://hackmd.io/@leediay/four-reflected-xss-qloapps","https://github.com/Qloapps/QloApps","https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-room-type-editor"],"products":["QloApps"],"vendors":["Webkul"]}},{"cve_id":"CVE-2026-103590","summary":"QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of stay fields. Attackers can induce authenticated administrators to submit crafted POST requests with malicious payloads in restriction_min_los and restriction_max_los parameters, executing arbitrary JavaScript in the victim's administrative session.","cvss":5.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":5.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Qloapps/QloApps","https://github.com/Qloapps/QloApps/blob/v1.7.0/admin/themes/default/template/controllers/products/lengthofstay.tpl","https://github.com/Qloapps/QloApps/commit/7ed467d911086b190180d7f297e3b15ba31e82d5","https://github.com/Qloapps/QloApps/pull/1899","https://hackmd.io/@leediay/four-reflected-xss-qloapps","https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-length-of-stay-fields"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T23:16:58","euvd":{"id":"EUVD-2026-90438","description":"QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of stay fields. Attackers can induce authenticated administrators to submit crafted POST requests with malicious payloads in restriction_min_los and restriction_max_los parameters, executing arbitrary JavaScript in the victim's administrative session.","published_time":"2026-09-30T23:02:35","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/Qloapps/QloApps/pull/1899","https://github.com/Qloapps/QloApps/commit/7ed467d911086b190180d7f297e3b15ba31e82d5","https://github.com/Qloapps/QloApps/blob/v1.7.0/admin/themes/default/template/controllers/products/lengthofstay.tpl","https://hackmd.io/@leediay/four-reflected-xss-qloapps","https://github.com/Qloapps/QloApps","https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-length-of-stay-fields"],"products":["QloApps"],"vendors":["Webkul"]}},{"cve_id":"CVE-2026-103591","summary":"DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL repo_url value to bypass path containment checks and read any file accessible to the API process by specifying absolute file paths.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/AsyncFuncAI/deepwiki-open","https://github.com/AsyncFuncAI/deepwiki-open/blob/d92819a9c9f3b99416e3580ff235fc9d3adf8b89/api/repository.py","https://github.com/AsyncFuncAI/deepwiki-open/blob/d92819a9c9f3b99416e3580ff235fc9d3adf8b89/api/routers/codemap.py","https://github.com/AsyncFuncAI/deepwiki-open/blob/d92819a9c9f3b99416e3580ff235fc9d3adf8b89/api/services/codemap.py","https://github.com/AsyncFuncAI/deepwiki-open/issues/590","https://www.vulncheck.com/advisories/deepwiki-open-through-commit-d92819a-unauthenticated-arbitrary-file-read-via-codemap-file"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T23:16:58","euvd":{"id":"EUVD-2026-90439","description":"DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL repo_url value to bypass path containment checks and read any file accessible to the API process by specifying absolute file paths.","published_time":"2026-09-30T23:02:35","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/AsyncFuncAI/deepwiki-open/issues/590","https://github.com/AsyncFuncAI/deepwiki-open/blob/d92819a9c9f3b99416e3580ff235fc9d3adf8b89/api/services/codemap.py","https://github.com/AsyncFuncAI/deepwiki-open/blob/d92819a9c9f3b99416e3580ff235fc9d3adf8b89/api/routers/codemap.py","https://github.com/AsyncFuncAI/deepwiki-open/blob/d92819a9c9f3b99416e3580ff235fc9d3adf8b89/api/repository.py","https://github.com/AsyncFuncAI/deepwiki-open","https://www.vulncheck.com/advisories/deepwiki-open-through-commit-d92819a-unauthenticated-arbitrary-file-read-via-codemap-file"],"products":["deepwiki-open"],"vendors":["AsyncFuncAI"]}},{"cve_id":"CVE-2026-103592","summary":"simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwarded-For, CF-Connecting-IP, or Client-IP headers to impersonate whitelisted addresses or evade blacklists, gaining access to IP-restricted routes.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":6.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/skipperbent/simple-php-router","https://github.com/skipperbent/simple-php-router/blob/5.4.1.7/src/Pecee/Http/Middleware/IpRestrictAccess.php","https://github.com/skipperbent/simple-php-router/blob/5.4.1.7/src/Pecee/Http/Request.php","https://github.com/skipperbent/simple-php-router/issues/727","https://www.vulncheck.com/advisories/simple-php-router-through-5.4.1.7-ip-restriction-bypass-via-forwarding-headers"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T23:16:58","euvd":{"id":"EUVD-2026-90440","description":"simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwarded-For, CF-Connecting-IP, or Client-IP headers to impersonate whitelisted addresses or evade blacklists, gaining access to IP-restricted routes.","published_time":"2026-09-30T23:02:36","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/skipperbent/simple-php-router/issues/727","https://github.com/skipperbent/simple-php-router/blob/5.4.1.7/src/Pecee/Http/Middleware/IpRestrictAccess.php","https://github.com/skipperbent/simple-php-router/blob/5.4.1.7/src/Pecee/Http/Request.php","https://github.com/skipperbent/simple-php-router","https://www.vulncheck.com/advisories/simple-php-router-through-5.4.1.7-ip-restriction-bypass-via-forwarding-headers"],"products":["simple-router"],"vendors":["pecee"]}},{"cve_id":"CVE-2026-103584","summary":"Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki CommonsMetadata extension allows Cross-Site Scripting (XSS).\n\nThis issue affects MediaWiki CommonsMetadata extension: 1.46, 1.45, and 1.43.","cvss":1.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":1.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gerrit.wikimedia.org/r/q/I66c102cae36a9d499c95c37db7458371c7c87258","https://phabricator.wikimedia.org/T435999"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T23:16:57","euvd":{"id":"EUVD-2026-90430","description":"Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki CommonsMetadata extension allows Cross-Site Scripting (XSS).\n\nThis issue affects MediaWiki CommonsMetadata extension: 1.46, 1.45, and 1.43.","published_time":"2026-09-30T22:14:27","cvss":1.1,"cvss_version":"4.0","epss":0.0,"assigner":"wikimedia-foundation","references":["https://phabricator.wikimedia.org/T435999","https://gerrit.wikimedia.org/r/q/I66c102cae36a9d499c95c37db7458371c7c87258"],"products":["MediaWiki CommonsMetadata extension","MediaWiki CommonsMetadata extension","MediaWiki CommonsMetadata extension"],"vendors":["The Wikimedia Foundation"]}},{"cve_id":"CVE-2026-103585","summary":"Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki MediaSearch extension allows Cross-Site Scripting (XSS).\n\nThis issue affects MediaWiki MediaSearch extension: 1.46, 1.45, and 1.43.","cvss":1.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":1.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gerrit.wikimedia.org/r/q/I79e8200289bd120c3c971ba830776eaae779bb99","https://phabricator.wikimedia.org/T435999"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T23:16:57","euvd":{"id":"EUVD-2026-90431","description":"Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki MediaSearch extension allows Cross-Site Scripting (XSS).\n\nThis issue affects MediaWiki MediaSearch extension: 1.46, 1.45, and 1.43.","published_time":"2026-09-30T22:17:37","cvss":1.2,"cvss_version":"4.0","epss":0.0,"assigner":"wikimedia-foundation","references":["https://phabricator.wikimedia.org/T435999","https://gerrit.wikimedia.org/r/q/I79e8200289bd120c3c971ba830776eaae779bb99"],"products":["MediaWiki MediaSearch extension","MediaWiki MediaSearch extension","MediaWiki MediaSearch extension"],"vendors":["The Wikimedia Foundation"]}},{"cve_id":"CVE-2026-101283","summary":"iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22","cvss":9.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://newreleases.io/project/github/esnet/iperf/release/3.22"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T22:16:33","euvd":{"id":"EUVD-2026-90389","description":"iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22","published_time":"2026-09-30T21:32:14","cvss":9.2,"cvss_version":"4.0","epss":0.0,"assigner":"Anthropic","references":["https://newreleases.io/project/github/esnet/iperf/release/3.22"],"products":["iperf3","iperf3"],"vendors":["esnet"]}},{"cve_id":"CVE-2026-103001","summary":"PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same mapping for a later decode() or decode_complete() call and changes verify_signature to true, the mapping can retain false values for expiration, not-before, issued-at, audience, issuer, subject, and JWT ID checks. A signed token with invalid registered claims can then be accepted without disabling signature verification, but applications that create a fresh options mapping for each call are not affected.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/jpadilla/pyjwt/commit/0c87c8c8b1a74cac99ad8115f3050efcb7fbed35","https://github.com/jpadilla/pyjwt/issues/679","https://github.com/jpadilla/pyjwt/security/advisories/GHSA-gvp8-978c-rx2q"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T22:16:33","euvd":{"id":"EUVD-2026-90388","description":"PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same mapping for a later decode() or decode_complete() call and changes verify_signature to true, the mapping can retain false values for expiration, not-before, issued-at, audience, issuer, subject, and JWT ID checks. A signed token with invalid registered claims can then be accepted without disabling signature verification, but applications that create a fresh options mapping for each call are not affected.","published_time":"2026-09-30T21:15:12","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/jpadilla/pyjwt/security/advisories/GHSA-gvp8-978c-rx2q","https://github.com/jpadilla/pyjwt/issues/679","https://github.com/jpadilla/pyjwt/commit/0c87c8c8b1a74cac99ad8115f3050efcb7fbed35"],"products":["pyjwt"],"vendors":["jpadilla"]}},{"cve_id":"CVE-2026-47096","summary":"AJA HELO Plus firmware before 2.1.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers with network access to inject malicious JavaScript by setting an unsanitized eParamID_SystemName value through the /config?action=set web configuration API. Attackers can exploit this flaw when device authentication is disabled to persistently execute arbitrary script in the browser of any administrator who opens the web management interface, enabling theft of stored secrets such as web UI credentials, RTMP stream keys, publish URLs, and NFS/SMB share credentials, as well as hijacking of the authenticated session.","cvss":5.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":5.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://d26ddnfpy9hzf8.cloudfront.net/aja-web/public/pdf/2026/AJA_HELO_PLUS_ReleaseNotes_v2.1.7.pdf","https://www.aja.com/security-advisories/aja-sa-2026-003","https://www.aja.com/support/item/10457","https://www.vulncheck.com/advisories/aja-helo-plus-stored-xss-via-system-name-parameter"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T22:16:33","euvd":{"id":"EUVD-2026-90429","description":"AJA HELO Plus firmware before 2.1.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers with network access to inject malicious JavaScript by setting an unsanitized eParamID_SystemName value through the /config?action=set web configuration API. Attackers can exploit this flaw when device authentication is disabled to persistently execute arbitrary script in the browser of any administrator who opens the web management interface, enabling theft of stored secrets such as web UI credentials, RTMP stream keys, publish URLs, and NFS/SMB share credentials, as well as hijacking of the authenticated session.","published_time":"2026-09-30T22:02:09","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://www.aja.com/security-advisories/aja-sa-2026-003","https://d26ddnfpy9hzf8.cloudfront.net/aja-web/public/pdf/2026/AJA_HELO_PLUS_ReleaseNotes_v2.1.7.pdf","https://www.aja.com/support/item/10457","https://www.vulncheck.com/advisories/aja-helo-plus-stored-xss-via-system-name-parameter"],"products":["HELO Plus"],"vendors":["AJA Video Systems"]}},{"cve_id":"CVE-2026-92172","summary":"Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity to an arbitrary application registering for com.oculus.systemactivities.SCREENSHOT via a broadcast receiver. That would allow the application to impersonate the com.oculus.horizon package towards any endpoint within the OS that uses CallerIdentity authentication.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.facebook.com/security/advisories/cve-2026-92172"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:17","euvd":{"id":"EUVD-2026-90316","description":"Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity to an arbitrary application registering for com.oculus.systemactivities.SCREENSHOT via a broadcast receiver. That would allow the application to impersonate the com.oculus.horizon package towards any endpoint within the OS that uses CallerIdentity authentication.","published_time":"2026-09-30T20:26:49","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Meta","references":["https://www.facebook.com/security/advisories/cve-2026-92172"],"products":["Meta Horizon OS"],"vendors":["Meta Platforms, Inc"]}},{"cve_id":"CVE-2026-92173","summary":"Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listening via NotificationListenerService. That would allow the application to impersonate the com.oculus.vrshell package, as well as packages signed with the same key, towards any endpoint within the OS that uses CallerIdentity authentication.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.facebook.com/security/advisories/cve-2026-92173"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:17","euvd":{"id":"EUVD-2026-90315","description":"Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listening via NotificationListenerService. That would allow the application to impersonate the com.oculus.vrshell package, as well as packages signed with the same key, towards any endpoint within the OS that uses CallerIdentity authentication.","published_time":"2026-09-30T20:26:33","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Meta","references":["https://www.facebook.com/security/advisories/cve-2026-92173"],"products":["Meta Horizon OS"],"vendors":["Meta Platforms, Inc"]}},{"cve_id":"CVE-2026-51872","summary":"Devika v1.0 is vulnerable to Code Injection via the Runner.run_code function in src/agents/runner/runner.py.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/Ro1ME/e65de4e8107334a75dcc241c73ffdfb1","https://github.com/stitionai/devika/issues/715"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:13","euvd":{"id":"EUVD-2026-90411","description":"Devika v1.0 is vulnerable to Code Injection via the Runner.run_code function in src/agents/runner/runner.py.","published_time":"2026-09-30T00:00:00","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"mitre","references":["https://github.com/stitionai/devika/issues/715","https://gist.github.com/Ro1ME/e65de4e8107334a75dcc241c73ffdfb1"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-51860","summary":"bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Directory Traversal in src/backend/bisheng/linsight/domain/task_exec.py.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/Ro1ME/e4129afdd9af2ff1bdcecf27ec5098cf","https://github.com/dataelement/bisheng/issues/1994"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:12","euvd":{"id":"EUVD-2026-90420","description":"bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Directory Traversal in src/backend/bisheng/linsight/domain/task_exec.py.","published_time":"2026-09-30T00:00:00","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"mitre","references":["https://github.com/dataelement/bisheng/issues/1994","https://gist.github.com/Ro1ME/e4129afdd9af2ff1bdcecf27ec5098cf"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-51861","summary":"bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Code Injection in src/backend/bisheng/api/v1/validate.py.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/Ro1ME/a03814bf661b36823c3ef5e32af93298","https://github.com/dataelement/bisheng/issues/1995"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:12","euvd":{"id":"EUVD-2026-90419","description":"bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Code Injection in src/backend/bisheng/api/v1/validate.py.","published_time":"2026-09-30T00:00:00","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"mitre","references":["https://github.com/dataelement/bisheng/issues/1995","https://gist.github.com/Ro1ME/a03814bf661b36823c3ef5e32af93298"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-51862","summary":"DB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:40). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/Ro1ME/c09e6aca2e9c7280ca4fabb1f44dcd2a","https://github.com/eosphoros-ai/DB-GPT/issues/3026"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:12","euvd":{"id":"EUVD-2026-90418","description":"DB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:40). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.","published_time":"2026-09-30T00:00:00","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"mitre","references":["https://github.com/eosphoros-ai/DB-GPT/issues/3026","https://gist.github.com/Ro1ME/c09e6aca2e9c7280ca4fabb1f44dcd2a"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-51864","summary":"DB-GPT v0.7.5 and v0.8.0 contains directory traversal in python_file_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py:42). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/Ro1ME/164a2aff1229df650a5bcc2a039900c5","https://github.com/eosphoros-ai/DB-GPT/issues/3027"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:12","euvd":{"id":"EUVD-2026-90417","description":"DB-GPT v0.7.5 and v0.8.0 contains directory traversal in python_file_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py:42). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.","published_time":"2026-09-30T00:00:00","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"mitre","references":["https://github.com/eosphoros-ai/DB-GPT/issues/3027","https://gist.github.com/Ro1ME/164a2aff1229df650a5bcc2a039900c5"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-51866","summary":"In DB-GPT 0.7.5 and 0.8.0, a skill uploaded through the real /api/v1/skills/upload route can later be executed through the real /api/v1/chat/react-agent flow.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/Ro1ME/f8f5b730a4000684d3a92a67f82ee03c","https://github.com/eosphoros-ai/DB-GPT/issues/3047"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:12","euvd":{"id":"EUVD-2026-90416","description":"In DB-GPT 0.7.5 and 0.8.0, a skill uploaded through the real /api/v1/skills/upload route can later be executed through the real /api/v1/chat/react-agent flow.","published_time":"2026-09-30T00:00:00","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"mitre","references":["https://github.com/eosphoros-ai/DB-GPT/issues/3047","https://gist.github.com/Ro1ME/f8f5b730a4000684d3a92a67f82ee03c"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-51867","summary":"agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in next/src/server/api/routers/agentRouter.ts. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/Ro1ME/62547f81c244f273b66755dad63a8673"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:12","euvd":{"id":"EUVD-2026-90415","description":"agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in next/src/server/api/routers/agentRouter.ts. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object.","published_time":"2026-09-30T00:00:00","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"mitre","references":["https://gist.github.com/Ro1ME/62547f81c244f273b66755dad63a8673"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-51869","summary":"DB-GPT v0.8.0 sandbox API silently falls back to LocalRuntime and executes code on host.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/Ro1ME/884fbbd589998b81fa05c20ac205569f","https://github.com/eosphoros-ai/DB-GPT/issues/3082"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:12","euvd":{"id":"EUVD-2026-90414","description":"DB-GPT v0.8.0 sandbox API silently falls back to LocalRuntime and executes code on host.","published_time":"2026-09-30T00:00:00","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"mitre","references":["https://github.com/eosphoros-ai/DB-GPT/issues/3082","https://gist.github.com/Ro1ME/884fbbd589998b81fa05c20ac205569f"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-51870","summary":"DeepTutor v1.4.0 is vulnerable to command execution in /tutorbot/agent/tools/shell.py:ExecTool.execute.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/Ro1ME/58b7e7523f517bc1241183ff988b6707","https://github.com/HKUDS/DeepTutor/issues/506"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:12","euvd":{"id":"EUVD-2026-90413","description":"DeepTutor v1.4.0 is vulnerable to command execution in /tutorbot/agent/tools/shell.py:ExecTool.execute.","published_time":"2026-09-30T00:00:00","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"mitre","references":["https://github.com/HKUDS/DeepTutor/issues/506","https://gist.github.com/Ro1ME/58b7e7523f517bc1241183ff988b6707"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-51871","summary":"Devika v1.0 is vulnerable to Code Injection in the Runner.execute function in src/agents/runner/runner.py which allows an attacker to achieve arbitrary code execution by exploiting the direct execution of LLM-generated content.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/Ro1ME/3067a5bd69dcd35ffc98dc41ca611242","https://github.com/stitionai/devika/issues/714"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:12","euvd":{"id":"EUVD-2026-90412","description":"Devika v1.0 is vulnerable to Code Injection in the Runner.execute function in src/agents/runner/runner.py which allows an attacker to achieve arbitrary code execution by exploiting the direct execution of LLM-generated content.","published_time":"2026-09-30T00:00:00","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"mitre","references":["https://github.com/stitionai/devika/issues/714","https://gist.github.com/Ro1ME/3067a5bd69dcd35ffc98dc41ca611242"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-51570","summary":"modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/Ro1ME/c6a6857348472db85895b346ba818195"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:11","euvd":{"id":"EUVD-2026-90427","description":"modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file.","published_time":"2026-09-30T00:00:00","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://gist.github.com/Ro1ME/c6a6857348472db85895b346ba818195"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-51852","summary":"agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64 method accepts user-controlled file paths without normalization or validation, allowing path traversal attacks.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/Ro1ME/13af0869833757245685d2d390458664","https://github.com/agent0ai/agent-zero/issues/1540"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:11","euvd":{"id":"EUVD-2026-90426","description":"agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64 method accepts user-controlled file paths without normalization or validation, allowing path traversal attacks.","published_time":"2026-09-30T00:00:00","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"mitre","references":["https://github.com/agent0ai/agent-zero/issues/1540","https://gist.github.com/Ro1ME/13af0869833757245685d2d390458664"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-51853","summary":"agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.__init__. The FileBrowser class initializes with the host root directory as the workspace, allowing the agent to access any file on the system without restriction.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/Ro1ME/4fe09fc7f94c9c0b10c8b6198a70e920","https://github.com/agent0ai/agent-zero/issues/1539"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:11","euvd":{"id":"EUVD-2026-90425","description":"agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.__init__. The FileBrowser class initializes with the host root directory as the workspace, allowing the agent to access any file on the system without restriction.","published_time":"2026-09-30T00:00:00","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"mitre","references":["https://github.com/agent0ai/agent-zero/issues/1539","https://gist.github.com/Ro1ME/4fe09fc7f94c9c0b10c8b6198a70e920"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-51856","summary":"In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting forwards the model-produced tool call to Toolkit.call_tool_function, which invokes execute_python_code without an additional approval or isolation boundary on that path.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/Ro1ME/c383f66d1fd6de40b6693f9b6cc181e7","https://github.com/agentscope-ai/agentscope/issues/1563"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:11","euvd":{"id":"EUVD-2026-90424","description":"In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting forwards the model-produced tool call to Toolkit.call_tool_function, which invokes execute_python_code without an additional approval or isolation boundary on that path.","published_time":"2026-09-30T00:00:00","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"mitre","references":["https://github.com/agentscope-ai/agentscope/issues/1563","https://gist.github.com/Ro1ME/c383f66d1fd6de40b6693f9b6cc181e7"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-51857","summary":"In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/Ro1ME/78606e0763520d6519897e90b305d3cd","https://github.com/camel-ai/camel/issues/4037"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:11","euvd":{"id":"EUVD-2026-90423","description":"In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary.","published_time":"2026-09-30T00:00:00","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"mitre","references":["https://github.com/camel-ai/camel/issues/4037","https://gist.github.com/Ro1ME/78606e0763520d6519897e90b305d3cd"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-51858","summary":"In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, TerminalToolkit.shell_exec allows prompt-driven shell command execution without an approval boundary.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/Ro1ME/1efc7b63bded3e4d39c54ff7b0caedf4","https://github.com/camel-ai/camel/issues/4038"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:11","euvd":{"id":"EUVD-2026-90422","description":"In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, TerminalToolkit.shell_exec allows prompt-driven shell command execution without an approval boundary.","published_time":"2026-09-30T00:00:00","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"mitre","references":["https://github.com/camel-ai/camel/issues/4038","https://gist.github.com/Ro1ME/1efc7b63bded3e4d39c54ff7b0caedf4"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-51859","summary":"bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to directory traversal in save_download_file (src/backend/bisheng/core/cache/utils.py:290).","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/Ro1ME/df160925a60dd917550f7c87bfe62519","https://github.com/dataelement/bisheng/issues/1994"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:11","euvd":{"id":"EUVD-2026-90421","description":"bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to directory traversal in save_download_file (src/backend/bisheng/core/cache/utils.py:290).","published_time":"2026-09-30T00:00:00","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"mitre","references":["https://github.com/dataelement/bisheng/issues/1994","https://gist.github.com/Ro1ME/df160925a60dd917550f7c87bfe62519"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-51568","summary":"modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/Ro1ME/6f26878766be5712ed504857c54492d7","https://github.com/agentscope-ai/agentscope/issues/1508"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:10","euvd":{"id":"EUVD-2026-90428","description":"modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file.","published_time":"2026-09-30T00:00:00","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/agentscope-ai/agentscope/issues/1508","https://gist.github.com/Ro1ME/6f26878766be5712ed504857c54492d7"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-102997","summary":"pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can force pypdf/filters.py to use inefficient byte-by-byte decompression while the earlier recovery counter fails to advance for bytes that successfully decode, causing long runtimes and application unavailability. This is a residual issue after the malformed FlateDecode recovery fix. This issue is fixed in version 6.18.1.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/py-pdf/pypdf/commit/d9d38cf99b115deb562d3b68f36c33027bc04f79","https://github.com/py-pdf/pypdf/pull/4073","https://github.com/py-pdf/pypdf/releases/tag/6.18.1","https://github.com/py-pdf/pypdf/security/advisories/GHSA-jw7q-gvrg-4vj3"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:07","euvd":{"id":"EUVD-2026-90373","description":"pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can force pypdf/filters.py to use inefficient byte-by-byte decompression while the earlier recovery counter fails to advance for bytes that successfully decode, causing long runtimes and application unavailability. This is a residual issue after the malformed FlateDecode recovery fix. This issue is fixed in version 6.18.1.","published_time":"2026-09-30T20:05:51","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/py-pdf/pypdf/security/advisories/GHSA-jw7q-gvrg-4vj3","https://github.com/py-pdf/pypdf/pull/4073","https://github.com/py-pdf/pypdf/commit/d9d38cf99b115deb562d3b68f36c33027bc04f79","https://github.com/py-pdf/pypdf/releases/tag/6.18.1"],"products":["pypdf"],"vendors":["py-pdf"]}},{"cve_id":"CVE-2026-102998","summary":"pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF with form field values can cause pypdf/generic/_appearance_stream.py appearance-stream generation to repeat invariant selection-data work inside a loop when an application updates fields with flattening enabled, resulting in excessive runtimes and application unavailability. This issue is fixed in version 6.19.0.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/py-pdf/pypdf/commit/959467a9b95be83e2dc5ae873ece5f371263ede7","https://github.com/py-pdf/pypdf/pull/4087","https://github.com/py-pdf/pypdf/releases/tag/6.19.0","https://github.com/py-pdf/pypdf/security/advisories/GHSA-php9-fj8v-98fj"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:07","euvd":{"id":"EUVD-2026-90384","description":"pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF with form field values can cause pypdf/generic/_appearance_stream.py appearance-stream generation to repeat invariant selection-data work inside a loop when an application updates fields with flattening enabled, resulting in excessive runtimes and application unavailability. This issue is fixed in version 6.19.0.","published_time":"2026-09-30T20:09:13","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/py-pdf/pypdf/security/advisories/GHSA-php9-fj8v-98fj","https://github.com/py-pdf/pypdf/pull/4087","https://github.com/py-pdf/pypdf/commit/959467a9b95be83e2dc5ae873ece5f371263ede7","https://github.com/py-pdf/pypdf/releases/tag/6.19.0"],"products":["pypdf"],"vendors":["py-pdf"]}},{"cve_id":"CVE-2026-102999","summary":"pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API in pypdf/_doc_common.py to reparse the full attachment list for each content lookup, producing repeated work and long runtimes when an application accesses the embedded-file mapping. This issue is fixed in version 6.19.0.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/py-pdf/pypdf/commit/6b10556d13609a68f9ed18bb29fdd8bba88eb2c3","https://github.com/py-pdf/pypdf/pull/4081","https://github.com/py-pdf/pypdf/releases/tag/6.19.0","https://github.com/py-pdf/pypdf/security/advisories/GHSA-v247-6f48-mgcj"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:07","euvd":{"id":"EUVD-2026-90272","description":"pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API in pypdf/_doc_common.py to reparse the full attachment list for each content lookup, producing repeated work and long runtimes when an application accesses the embedded-file mapping. This issue is fixed in version 6.19.0.","published_time":"2026-09-30T20:10:38","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/py-pdf/pypdf/security/advisories/GHSA-v247-6f48-mgcj","https://github.com/py-pdf/pypdf/pull/4081","https://github.com/py-pdf/pypdf/commit/6b10556d13609a68f9ed18bb29fdd8bba88eb2c3","https://github.com/py-pdf/pypdf/releases/tag/6.19.0"],"products":["pypdf"],"vendors":["py-pdf"]}},{"cve_id":"CVE-2026-103000","summary":"pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings beyond a reasonable page-label length when an application retrieves document page labels, consuming excessive memory and potentially making the application unavailable. This issue is fixed in version 6.19.0.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/py-pdf/pypdf/commit/0d8b5a8832cde1ba308b5c27567b879b7b7eed4a","https://github.com/py-pdf/pypdf/pull/4096","https://github.com/py-pdf/pypdf/releases/tag/6.19.0","https://github.com/py-pdf/pypdf/security/advisories/GHSA-w23x-9jrw-r45c"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:07","euvd":{"id":"EUVD-2026-90283","description":"pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings beyond a reasonable page-label length when an application retrieves document page labels, consuming excessive memory and potentially making the application unavailable. This issue is fixed in version 6.19.0.","published_time":"2026-09-30T20:13:00","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/py-pdf/pypdf/security/advisories/GHSA-w23x-9jrw-r45c","https://github.com/py-pdf/pypdf/pull/4096","https://github.com/py-pdf/pypdf/commit/0d8b5a8832cde1ba308b5c27567b879b7b7eed4a","https://github.com/py-pdf/pypdf/releases/tag/6.19.0"],"products":["pypdf"],"vendors":["py-pdf"]}},{"cve_id":"CVE-2026-102995","summary":"pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can place unusually large source-code or destination-string tokens in a font /ToUnicode mapping, causing pypdf/_cmap.py parse_bfchar to decode and retain oversized values during operations such as text extraction and consume excessive memory. This is a second follow-up to earlier /ToUnicode resource-consumption fixes and is limited to the remaining token-length path. This issue is fixed in version 6.18.1.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/py-pdf/pypdf/commit/319d0b823ce2c311a2435e9fd93c13994d32bb51","https://github.com/py-pdf/pypdf/pull/4071","https://github.com/py-pdf/pypdf/releases/tag/6.18.1","https://github.com/py-pdf/pypdf/security/advisories/GHSA-fp3h-c4fm-7vvf"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:06","euvd":{"id":"EUVD-2026-90367","description":"pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can place unusually large source-code or destination-string tokens in a font /ToUnicode mapping, causing pypdf/_cmap.py parse_bfchar to decode and retain oversized values during operations such as text extraction and consume excessive memory. This is a second follow-up to earlier /ToUnicode resource-consumption fixes and is limited to the remaining token-length path. This issue is fixed in version 6.18.1.","published_time":"2026-09-30T20:01:43","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/py-pdf/pypdf/security/advisories/GHSA-fp3h-c4fm-7vvf","https://github.com/py-pdf/pypdf/pull/4071","https://github.com/py-pdf/pypdf/commit/319d0b823ce2c311a2435e9fd93c13994d32bb51","https://github.com/py-pdf/pypdf/releases/tag/6.18.1"],"products":["pypdf"],"vendors":["py-pdf"]}},{"cve_id":"CVE-2026-102996","summary":"pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths to process entries beyond the 256 character codes meaningful for a simple font and consume excessive memory during operations such as text extraction. This issue is fixed in version 6.18.1.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/py-pdf/pypdf/commit/0fb26eb8cdd01c44b3b2c9fe8329751be2f7cfd5","https://github.com/py-pdf/pypdf/pull/4072","https://github.com/py-pdf/pypdf/releases/tag/6.18.1","https://github.com/py-pdf/pypdf/security/advisories/GHSA-g9cg-prrw-2r8q"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:06","euvd":{"id":"EUVD-2026-90368","description":"pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths to process entries beyond the 256 character codes meaningful for a simple font and consume excessive memory during operations such as text extraction. This issue is fixed in version 6.18.1.","published_time":"2026-09-30T20:03:55","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/py-pdf/pypdf/security/advisories/GHSA-g9cg-prrw-2r8q","https://github.com/py-pdf/pypdf/pull/4072","https://github.com/py-pdf/pypdf/commit/0fb26eb8cdd01c44b3b2c9fe8329751be2f7cfd5","https://github.com/py-pdf/pypdf/releases/tag/6.18.1"],"products":["pypdf"],"vendors":["py-pdf"]}},{"cve_id":"CVE-2026-102142","summary":"A system notification template on the Kiteworks appliance was rendered by a template engine that evaluated expressions contained in the stored template body. An authenticated System Administrator could potentially store a crafted template that executed operating-system commands on the appliance when the notification was next sent.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-gmgg-7xhc-75f9","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:03","euvd":{"id":"EUVD-2026-90271","description":"A system notification template on the Kiteworks appliance was rendered by a template engine that evaluated expressions contained in the stored template body. An authenticated System Administrator could potentially store a crafted template that executed operating-system commands on the appliance when the notification was next sent.","published_time":"2026-09-30T20:10:30","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-gmgg-7xhc-75f9","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102143","summary":"An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload handler that did not properly authenticate the request. This did not by itself result in code execution, which would require a separate vulnerability to place the file in an executable location.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-3p9g-jh62-8f89","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:03","euvd":{"id":"EUVD-2026-90270","description":"An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload handler that did not properly authenticate the request. This did not by itself result in code execution, which would require a separate vulnerability to place the file in an executable location.","published_time":"2026-09-30T20:10:09","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-3p9g-jh62-8f89","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Email Protection Gateway"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102144","summary":"A resource exhaustion vulnerability in Kiteworks Email Protection Gateway allowed an unauthenticated remote attacker to repeatedly trigger a comparatively expensive server-side operation, causing a partial denial of service.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-wwhf-5862-rjxq","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:03","euvd":{"id":"EUVD-2026-90268","description":"A resource exhaustion vulnerability in Kiteworks Email Protection Gateway allowed an unauthenticated remote attacker to repeatedly trigger a comparatively expensive server-side operation, causing a partial denial of service.","published_time":"2026-09-30T20:09:53","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-wwhf-5862-rjxq","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Email Protection Gateway"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102145","summary":"An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through this interface. On its own this did not result in code execution.","cvss":6.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-h97r-j99c-q8xc","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:03","euvd":{"id":"EUVD-2026-90381","description":"An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through this interface. On its own this did not result in code execution.","published_time":"2026-09-30T20:08:34","cvss":6.6,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-h97r-j99c-q8xc","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102146","summary":"An authenticated Email Protection Gateway administrator holding only limited, delegated permissions could write files with attacker-controlled content to arbitrary locations accessible to the Email Protection Gateway service account. This exceeds the administrator's intended privileges and could be used to alter application files and configuration or to disrupt the availability of the service.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-5pgq-v8g2-rg2f","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:03","euvd":{"id":"EUVD-2026-90382","description":"An authenticated Email Protection Gateway administrator holding only limited, delegated permissions could write files with attacker-controlled content to arbitrary locations accessible to the Email Protection Gateway service account. This exceeds the administrator's intended privileges and could be used to alter application files and configuration or to disrupt the availability of the service.","published_time":"2026-09-30T20:08:51","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-5pgq-v8g2-rg2f","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Email Protection Gateway"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102147","summary":"A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator who views the affected page. This could have permitted the attacker to gain full administrative control, including the creation of a new administrative account.","cvss":9.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-xgh2-fgj6-w93r","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:03","euvd":{"id":"EUVD-2026-90383","description":"A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator who views the affected page. This could have permitted the attacker to gain full administrative control, including the creation of a new administrative account.","published_time":"2026-09-30T20:09:08","cvss":9.3,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-xgh2-fgj6-w93r","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102149","summary":"Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the confidentiality and integrity of that account's encrypted mail and, where certificate-based login is enabled, potentially permitting unauthorized access to the account.","cvss":9.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-c9w5-4frw-7wqq","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:03","euvd":{"id":"EUVD-2026-90385","description":"Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the confidentiality and integrity of that account's encrypted mail and, where certificate-based login is enabled, potentially permitting unauthorized access to the account.","published_time":"2026-09-30T20:09:21","cvss":9.4,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-c9w5-4frw-7wqq","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Email Protection Gateway"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102150","summary":"A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operations on the Kiteworks platform; it did not permit access to user accounts, stored files, or form submissions.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-vwvw-rp3m-rm37","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:03","euvd":{"id":"EUVD-2026-90386","description":"A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operations on the Kiteworks platform; it did not permit access to user accounts, stored files, or form submissions.","published_time":"2026-09-30T20:09:36","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-vwvw-rp3m-rm37","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Secure Data Forms"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102134","summary":"Kiteworks Core did not apply its gateway-level API security controls to every request authenticated through the platform's central authentication service. An authenticated user could reach REST API functionality over a request path on which those controls, including enforcement of signed-out and revoked sessions, were not applied.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-8q58-vrwm-jxhq","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:02","euvd":{"id":"EUVD-2026-90281","description":"Kiteworks Core did not apply its gateway-level API security controls to every request authenticated through the platform's central authentication service. An authenticated user could reach REST API functionality over a request path on which those controls, including enforcement of signed-out and revoked sessions, were not applied.","published_time":"2026-09-30T20:12:39","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-8q58-vrwm-jxhq","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102135","summary":"On a Kiteworks Email Protection Gateway cluster with database replication enabled, a party trusted by the cluster could submit a crafted serialized object that was deserialized without sufficient validation, potentially allowing code execution as the gateway service account. Replication is disabled by default, and exploitation requires control of a trusted cluster peer or administrative access to the appliance.","cvss":6.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-vmwr-r5xq-hp49","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:02","euvd":{"id":"EUVD-2026-90280","description":"On a Kiteworks Email Protection Gateway cluster with database replication enabled, a party trusted by the cluster could submit a crafted serialized object that was deserialized without sufficient validation, potentially allowing code execution as the gateway service account. Replication is disabled by default, and exploitation requires control of a trusted cluster peer or administrative access to the appliance.","published_time":"2026-09-30T20:12:22","cvss":6.6,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-vmwr-r5xq-hp49","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Email Protection Gateway"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102136","summary":"In multi-node deployments, an attacker who had already obtained code execution on one appliance node could submit a value through an internal cluster interface that was written into monitoring configuration on another node without sufficient validation, potentially allowing OS commands to be executed there. Execution was limited to an unprivileged service account on that node.","cvss":6.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-rpxx-jm93-w5j7","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:02","euvd":{"id":"EUVD-2026-90279","description":"In multi-node deployments, an attacker who had already obtained code execution on one appliance node could submit a value through an internal cluster interface that was written into monitoring configuration on another node without sufficient validation, potentially allowing OS commands to be executed there. Execution was limited to an unprivileged service account on that node.","published_time":"2026-09-30T20:12:07","cvss":6.3,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-rpxx-jm93-w5j7","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102137","summary":"An authenticated administrator could bypass the content validation applied to an administrative file upload and store a file containing dangerous content on the appliance. This did not by itself result in code execution, which would require a separate vulnerability to run the stored file.","cvss":4.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-m6cv-4pjv-7435","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:02","euvd":{"id":"EUVD-2026-90278","description":"An authenticated administrator could bypass the content validation applied to an administrative file upload and store a file containing dangerous content on the appliance. This did not by itself result in code execution, which would require a separate vulnerability to run the stored file.","published_time":"2026-09-30T20:11:52","cvss":4.1,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-m6cv-4pjv-7435","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102138","summary":"An authenticated administrator on a node with an optional, separately licensed gateway role enabled could supply a connector URL that the server retrieved without sufficient validation of its scheme or destination, causing the server to issue requests to internal network services. Exploitation requires the licensed gateway role to be active.","cvss":3.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-q9w9-c5hj-87jm","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:02","euvd":{"id":"EUVD-2026-90277","description":"An authenticated administrator on a node with an optional, separately licensed gateway role enabled could supply a connector URL that the server retrieved without sufficient validation of its scheme or destination, causing the server to issue requests to internal network services. Exploitation requires the licensed gateway role to be active.","published_time":"2026-09-30T20:11:32","cvss":3.3,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-q9w9-c5hj-87jm","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102139","summary":"An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party to the package being requested. An authenticated user of that optional feature could read the subject, message body, and attachments of packages they neither sent nor received.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-fp46-xhg8-vpgm","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:02","euvd":{"id":"EUVD-2026-90275","description":"An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party to the package being requested. An authenticated user of that optional feature could read the subject, message body, and attachments of packages they neither sent nor received.","published_time":"2026-09-30T20:11:17","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-fp46-xhg8-vpgm","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Email Protection Gateway"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102140","summary":"An authenticated administrator could initiate an administrative import using a file whose contents were not fully verified, because the import validated only the file's header rather than the complete file. This could allow unverified or forged content to be accepted and processed, affecting the integrity of the imported data.","cvss":4.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-wfxj-p5jc-jqjw","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:02","euvd":{"id":"EUVD-2026-90274","description":"An authenticated administrator could initiate an administrative import using a file whose contents were not fully verified, because the import validated only the file's header rather than the complete file. This could allow unverified or forged content to be accepted and processed, affecting the integrity of the imported data.","published_time":"2026-09-30T20:11:07","cvss":4.9,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-wfxj-p5jc-jqjw","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102141","summary":"Two Kiteworks Core cluster-management operations did not validate file paths supplied to them, so an attacker holding root on one node of a cluster could write files as root onto another node and cause them to be executed there. Exploitation requires backend root access on a cluster node and a pending software patch present on the target node.","cvss":6.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-m39v-w8fv-gf3m","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:02","euvd":{"id":"EUVD-2026-90273","description":"Two Kiteworks Core cluster-management operations did not validate file paths supplied to them, so an attacker holding root on one node of a cluster could write files as root onto another node and cause them to be executed there. Exploitation requires backend root access on a cluster node and a pending software patch present on the target node.","published_time":"2026-09-30T20:10:55","cvss":6.7,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-m39v-w8fv-gf3m","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102127","summary":"An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote and unauthenticated sender could potentially use a crafted message to read files accessible to the gateway service account, including cryptographic key material and credentials, and have them sent to a destination they control.","cvss":7.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.0,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-9jwc-h943-6f84","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:01","euvd":{"id":"EUVD-2026-90290","description":"An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote and unauthenticated sender could potentially use a crafted message to read files accessible to the gateway service account, including cryptographic key material and credentials, and have them sent to a destination they control.","published_time":"2026-09-30T20:14:56","cvss":7.0,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-9jwc-h943-6f84","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Email Protection Gateway"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102128","summary":"An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to obtain control of a platform account.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-qjvp-25r3-rgx6","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:01","euvd":{"id":"EUVD-2026-90289","description":"An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to obtain control of a platform account.","published_time":"2026-09-30T20:14:40","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-qjvp-25r3-rgx6","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Email Protection Gateway"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102129","summary":"A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated permissions covered role changes alone could therefore raise an account to full system-administrator privileges.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-4gcf-w86v-34rp","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:01","euvd":{"id":"EUVD-2026-90288","description":"A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated permissions covered role changes alone could therefore raise an account to full system-administrator privileges.","published_time":"2026-09-30T20:14:13","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-4gcf-w86v-34rp","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102130","summary":"Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. An authenticated administrator could potentially use this to execute arbitrary code on the gateway as the underlying service account.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-m92m-q8cf-rcch","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:01","euvd":{"id":"EUVD-2026-90287","description":"Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. An authenticated administrator could potentially use this to execute arbitrary code on the gateway as the underlying service account.","published_time":"2026-09-30T20:13:58","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-m92m-q8cf-rcch","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Email Protection Gateway"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102131","summary":"Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code execution as the gateway service account.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-62f6-c955-4fhq","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:01","euvd":{"id":"EUVD-2026-90286","description":"Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code execution as the gateway service account.","published_time":"2026-09-30T20:13:43","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-62f6-c955-4fhq","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Email Protection Gateway"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102132","summary":"An administrative import function in Kiteworks Core did not verify that the requesting administrator was entitled to create the privileged integration credential being imported. A delegated administrator holding a single narrowly scoped administrative permission could therefore obtain full system administrator privileges, without any action by an existing system administrator.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-qx8c-x3hv-c25g","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:01","euvd":{"id":"EUVD-2026-90285","description":"An administrative import function in Kiteworks Core did not verify that the requesting administrator was entitled to create the privileged integration credential being imported. A delegated administrator holding a single narrowly scoped administrative permission could therefore obtain full system administrator privileges, without any action by an existing system administrator.","published_time":"2026-09-30T20:13:28","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-qx8c-x3hv-c25g","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102133","summary":"An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. An authenticated system administrator could inject additional commands and write arbitrary content to files owned by the service account running the connector, enabling code execution in that account's context; exploitation additionally requires network egress from the appliance to a system under the attacker's control.","cvss":6.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-53qp-jmrc-2g5j","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:01","euvd":{"id":"EUVD-2026-90284","description":"An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. An authenticated system administrator could inject additional commands and write arbitrary content to files owned by the service account running the connector, enabling code execution in that account's context; exploitation additionally requires network egress from the appliance to a system under the attacker's control.","published_time":"2026-09-30T20:13:09","cvss":6.6,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-53qp-jmrc-2g5j","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102120","summary":"A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obtained code execution on one node of a clustered Kiteworks deployment to run operating system commands with elevated privileges on another node of the same cluster. Insufficient input validation in an internal cluster management function let attacker-supplied values reach a privileged execution context; exploitation requires existing access to a node in the cluster, and the affected function is not reachable from outside the cluster.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-m968-434m-rgwp","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:00","euvd":{"id":"EUVD-2026-90299","description":"A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obtained code execution on one node of a clustered Kiteworks deployment to run operating system commands with elevated privileges on another node of the same cluster. Insufficient input validation in an internal cluster management function let attacker-supplied values reach a privileged execution context; exploitation requires existing access to a node in the cluster, and the affected function is not reachable from outside the cluster.","published_time":"2026-09-30T20:17:48","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-m968-434m-rgwp","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102121","summary":"A form-rendering interface in the Advanced Forms component is reachable without authentication so that published forms can be displayed to anonymous visitors, but it returned more data than the form itself required. Anyone who knew the web address of a published form could potentially retrieve the form owner's Kiteworks account profile, including personal details, along with parts of the deployment's configuration settings; no passwords, authentication tokens, or multi-factor secrets were exposed.","cvss":8.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-hf68-855j-745c","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:00","euvd":{"id":"EUVD-2026-90298","description":"A form-rendering interface in the Advanced Forms component is reachable without authentication so that published forms can be displayed to anonymous visitors, but it returned more data than the form itself required. Anyone who knew the web address of a published form could potentially retrieve the form owner's Kiteworks account profile, including personal details, along with parts of the deployment's configuration settings; no passwords, authentication tokens, or multi-factor secrets were exposed.","published_time":"2026-09-30T20:17:31","cvss":8.6,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-hf68-855j-745c","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Secure Data Forms"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102122","summary":"Kiteworks did not correctly enforce which roles a shared folder's manager was permitted to assign. In a default configuration, an authenticated user holding the Manager role on a folder could grant the Owner role to themselves or to other members of that folder.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-7436-q3x6-cqxq","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:00","euvd":{"id":"EUVD-2026-90296","description":"Kiteworks did not correctly enforce which roles a shared folder's manager was permitted to assign. In a default configuration, an authenticated user holding the Manager role on a folder could grant the Owner role to themselves or to other members of that folder.","published_time":"2026-09-30T20:16:24","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-7436-q3x6-cqxq","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102123","summary":"A Kiteworks appliance setup interface did not confine a user-supplied file path to its intended directory, which could allow an unauthenticated attacker to write a file to any location writable by the affected service account, potentially compromising the integrity of the appliance or rendering it unavailable until an operator intervenes. Exploitation requires network access to the affected interface, which is not reachable on a fully configured appliance in its default configuration; reaching it depends on either the transient window while an appliance is first being provisioned or a non-default appliance configuration.","cvss":7.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-vcx7-3759-27xm","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:00","euvd":{"id":"EUVD-2026-90295","description":"A Kiteworks appliance setup interface did not confine a user-supplied file path to its intended directory, which could allow an unauthenticated attacker to write a file to any location writable by the affected service account, potentially compromising the integrity of the appliance or rendering it unavailable until an operator intervenes. Exploitation requires network access to the affected interface, which is not reachable on a fully configured appliance in its default configuration; reaching it depends on either the transient window while an appliance is first being provisioned or a non-default appliance configuration.","published_time":"2026-09-30T20:16:01","cvss":7.4,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-vcx7-3759-27xm","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102124","summary":"A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration. An unauthenticated attacker with network access to the appliance could read and modify a limited set of setup records, including a contact name and email address captured during initial configuration.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-q85p-q4v6-7w6f","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:00","euvd":{"id":"EUVD-2026-90293","description":"A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration. An unauthenticated attacker with network access to the appliance could read and modify a limited set of setup records, including a contact name and email address captured during initial configuration.","published_time":"2026-09-30T20:15:38","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-q85p-q4v6-7w6f","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102125","summary":"The sandbox that isolates document conversion on a Kiteworks appliance did not fully confine the code running inside it. Code already executing within that sandbox could potentially escape its confinement and act with the privileges of the service account that runs the application, which could allow an attacker in that position to read or modify application data and configuration, or to disrupt the service on the affected appliance.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-58j2-hj9r-c258","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:00","euvd":{"id":"EUVD-2026-90292","description":"The sandbox that isolates document conversion on a Kiteworks appliance did not fully confine the code running inside it. Code already executing within that sandbox could potentially escape its confinement and act with the privileges of the service account that runs the application, which could allow an attacker in that position to read or modify application data and configuration, or to disrupt the service on the affected appliance.","published_time":"2026-09-30T20:15:25","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-58j2-hj9r-c258","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102126","summary":"A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding only a single, narrowly scoped delegated permission to store crafted content that later executes arbitrary JavaScript in the authenticated session of a System Administrator who views the affected page. This could have permitted the lower-privileged administrator to escalate to full administrative control of the tenant, including the creation of a new administrative account.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-ccfx-6hq4-fx4g","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:17:00","euvd":{"id":"EUVD-2026-90291","description":"A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding only a single, narrowly scoped delegated permission to store crafted content that later executes arbitrary JavaScript in the authenticated session of a System Administrator who views the affected page. This could have permitted the lower-privileged administrator to escalate to full administrative control of the tenant, including the creation of a new administrative account.","published_time":"2026-09-30T20:15:09","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-ccfx-6hq4-fx4g","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102115","summary":"Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user, including where the account holds administrative privileges.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-q76w-qv9j-q639","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:59","euvd":{"id":"EUVD-2026-90304","description":"Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user, including where the account holds administrative privileges.","published_time":"2026-09-30T20:19:55","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-q76w-qv9j-q639","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102116","summary":"-A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the underlying service account.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-pf8p-p269-4mjv","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:59","euvd":{"id":"EUVD-2026-90303","description":"-A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the underlying service account.","published_time":"2026-09-30T20:19:20","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-pf8p-p269-4mjv","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Email Protection Gateway"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102117","summary":"On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect the underlying system's outbound support connection to a destination of their choosing. That destination could then have operating-system commands executed on the node and receive their output, potentially resulting in remote code execution with the privileges of a local service account.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-5rhv-f48q-gq5v","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:59","euvd":{"id":"EUVD-2026-90302","description":"On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect the underlying system's outbound support connection to a destination of their choosing. That destination could then have operating-system commands executed on the node and receive their output, potentially resulting in remote code execution with the privileges of a local service account.","published_time":"2026-09-30T20:19:02","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-5rhv-f48q-gq5v","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102118","summary":"A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-8pmh-222g-6j48","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:59","euvd":{"id":"EUVD-2026-90301","description":"A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance.","published_time":"2026-09-30T20:18:21","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-8pmh-222g-6j48","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102119","summary":"A path traversal weakness in an optional, non-default administrative feature allowed an authenticated administrator to move files to unintended locations outside the feature's designated directory. This could potentially be leveraged to execute arbitrary code on the underlying system.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-3r3r-hp4c-pxmh","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:59","euvd":{"id":"EUVD-2026-90300","description":"A path traversal weakness in an optional, non-default administrative feature allowed an authenticated administrator to move files to unintended locations outside the feature's designated directory. This could potentially be leveraged to execute arbitrary code on the underlying system.","published_time":"2026-09-30T20:18:01","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-3r3r-hp4c-pxmh","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Email Protection Gateway"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102111","summary":"Kiteworks did not enforce the maximum permitted value for a configurable security-policy setting. An authenticated administrator could set this value outside its intended range so that the associated control never activated, while the control continued to appear enabled in the administrative interface and audit log, allowing it to be silently rendered ineffective.","cvss":4.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-4r97-hch3-g2f9","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:58","euvd":{"id":"EUVD-2026-90308","description":"Kiteworks did not enforce the maximum permitted value for a configurable security-policy setting. An authenticated administrator could set this value outside its intended range so that the associated control never activated, while the control continued to appear enabled in the administrative interface and audit log, allowing it to be silently rendered ineffective.","published_time":"2026-09-30T20:21:15","cvss":4.9,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-4r97-hch3-g2f9","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102112","summary":"A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root and run arbitrary commands with the highest privileges. Exploitation requires existing local access to that service account.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-658c-86vw-g9hf","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:58","euvd":{"id":"EUVD-2026-90307","description":"A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root and run arbitrary commands with the highest privileges. Exploitation requires existing local access to that service account.","published_time":"2026-09-30T20:20:59","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-658c-86vw-g9hf","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102113","summary":"A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root. A privileged routine did not safely handle a filesystem path that the lower-privileged account could influence, allowing the attacker to cause a root-owned operation to run arbitrary commands with the highest privileges. Exploitation requires existing local access to that service account.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-gwj7-wxrr-28v5","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:58","euvd":{"id":"EUVD-2026-90306","description":"A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root. A privileged routine did not safely handle a filesystem path that the lower-privileged account could influence, allowing the attacker to cause a root-owned operation to run arbitrary commands with the highest privileges. Exploitation requires existing local access to that service account.","published_time":"2026-09-30T20:20:35","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-gwj7-wxrr-28v5","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102114","summary":"A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administrator to execute arbitrary operating-system commands as root on the affected appliance node. Successful exploitation requires an administrative account with elevated privileges.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-p5q5-49j9-hx8w","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:58","euvd":{"id":"EUVD-2026-90305","description":"A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administrator to execute arbitrary operating-system commands as root on the affected appliance node. Successful exploitation requires an administrative account with elevated privileges.","published_time":"2026-09-30T20:20:18","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-p5q5-49j9-hx8w","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102102","summary":"Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway retrieves an issuer certificate in an inbound message. Depending on the services reachable from the gateway, this could disclose sensitive internal information or disrupt gateway operation.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-jxv9-v53f-c79m","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:57","euvd":{"id":"EUVD-2026-90282","description":"Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway retrieves an issuer certificate in an inbound message. Depending on the services reachable from the gateway, this could disclose sensitive internal information or disrupt gateway operation.","published_time":"2026-09-30T20:12:42","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-jxv9-v53f-c79m","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Email Protection Gateway"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102103","summary":"Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway retrieves a certificate revocation list in an inbound message. Depending on the services reachable from the gateway, this could disclose sensitive internal information or disrupt gateway operation.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-p435-6c3j-4gh5","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:57","euvd":{"id":"EUVD-2026-90294","description":"Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway retrieves a certificate revocation list in an inbound message. Depending on the services reachable from the gateway, this could disclose sensitive internal information or disrupt gateway operation.","published_time":"2026-09-30T20:16:00","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-p435-6c3j-4gh5","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Email Protection Gateway"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102104","summary":"Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway performs an online certificate status check for an inbound message. Depending on the services reachable from the gateway, this could disclose sensitive internal information or disrupt gateway operation.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-mqw3-m87w-4fx4","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:57","euvd":{"id":"EUVD-2026-90297","description":"Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway performs an online certificate status check for an inbound message. Depending on the services reachable from the gateway, this could disclose sensitive internal information or disrupt gateway operation.","published_time":"2026-09-30T20:17:17","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-mqw3-m87w-4fx4","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Email Protection Gateway"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102105","summary":"Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway renders message content that references external resources. Depending on the services reachable from the gateway, this could disclose sensitive internal information or trigger unintended actions on internal systems.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-hq47-4whq-9hgv","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:57","euvd":{"id":"EUVD-2026-90314","description":"Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway renders message content that references external resources. Depending on the services reachable from the gateway, this could disclose sensitive internal information or trigger unintended actions on internal systems.","published_time":"2026-09-30T20:25:02","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-hq47-4whq-9hgv","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Email Protection Gateway"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102106","summary":"Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so the required password check could be bypassed. An attacker who referenced a valid administrator account could potentially create, modify, or delete internal users and managed domains and change their security-feature configuration without authenticating; deleting a managed domain also removes its user accounts and could lock administrators out of the gateway.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-wwv8-qhqg-4q76","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:57","euvd":{"id":"EUVD-2026-90313","description":"Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so the required password check could be bypassed. An attacker who referenced a valid administrator account could potentially create, modify, or delete internal users and managed domains and change their security-feature configuration without authenticating; deleting a managed domain also removes its user accounts and could lock administrators out of the gateway.","published_time":"2026-09-30T20:24:46","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-wwv8-qhqg-4q76","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Email Protection Gateway"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102107","summary":"Kiteworks Core contains a business logic flaw in a Kiteworks file-request feature allowed an authenticated user to send a request that appeared to originate from another user, because the server did not verify that the requester was authorized to act as the specified account. This could be used to solicit files or information from a recipient under a trusted identity; exploitation requires the feature to be enabled for the attacker's profile and the targeted recipient to act on the request.","cvss":4.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-wv69-6ghf-h3c4","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:57","euvd":{"id":"EUVD-2026-90312","description":"Kiteworks Core contains a business logic flaw in a Kiteworks file-request feature allowed an authenticated user to send a request that appeared to originate from another user, because the server did not verify that the requester was authorized to act as the specified account. This could be used to solicit files or information from a recipient under a trusted identity; exploitation requires the feature to be enabled for the attacker's profile and the targeted recipient to act on the request.","published_time":"2026-09-30T20:24:29","cvss":4.6,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-wv69-6ghf-h3c4","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102108","summary":"An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, potentially allowing arbitrary code execution in the context of the gateway service account. Exploitation requires an administrator account holding a specific queue-management privilege.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-837h-99j2-hxjr","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:57","euvd":{"id":"EUVD-2026-90311","description":"An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, potentially allowing arbitrary code execution in the context of the gateway service account. Exploitation requires an administrator account holding a specific queue-management privilege.","published_time":"2026-09-30T20:24:07","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-837h-99j2-hxjr","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Email Protection Gateway"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102109","summary":"A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could potentially influence that value to inject SQL. Exploitation requires an authenticated session and applies only to deployments where a specific optional feature is in use.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-vw4g-v5qc-vv58","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:57","euvd":{"id":"EUVD-2026-90310","description":"A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could potentially influence that value to inject SQL. Exploitation requires an authenticated session and applies only to deployments where a specific optional feature is in use.","published_time":"2026-09-30T20:23:36","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-vw4g-v5qc-vv58","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Secure Data Forms"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102110","summary":"An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so during the initial activation window an unauthenticated network attacker could repeatedly re-trigger the privileged activation process. This could disrupt setup and leave the appliance in an incompletely configured state. The issue is only reachable while an appliance is being activated for the first time and not yet fully configured.","cvss":5.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-qfqh-c638-m5pg","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:57","euvd":{"id":"EUVD-2026-90309","description":"An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so during the initial activation window an unauthenticated network attacker could repeatedly re-trigger the privileged activation process. This could disrupt setup and leave the appliance in an incompletely configured state. The issue is only reachable while an appliance is being activated for the first time and not yet fully configured.","published_time":"2026-09-30T20:21:42","cvss":5.9,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-qfqh-c638-m5pg","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102095","summary":"Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery. Kiteworks Email Protection Gateway performed server-side fetches of URLs contained in the message content it processed, without adequately restricting the fetch destination. A remote, unauthenticated sender could craft a message that caused the gateway to issue requests to internal services and cloud instance metadata endpoints and return the responses, potentially disclosing sensitive internal data and, depending on the internal service reached, affecting its state.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-f252-4w8q-g74g","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:56","euvd":{"id":"EUVD-2026-90377","description":"Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery. Kiteworks Email Protection Gateway performed server-side fetches of URLs contained in the message content it processed, without adequately restricting the fetch destination. A remote, unauthenticated sender could craft a message that caused the gateway to issue requests to internal services and cloud instance metadata endpoints and return the responses, potentially disclosing sensitive internal data and, depending on the internal service reached, affecting its state.","published_time":"2026-09-30T20:07:22","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-f252-4w8q-g74g","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Email Protection Gateway"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102096","summary":"Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not sufficiently validated before being processed. A crafted package could cause the underlying system to execute arbitrary operating-system commands, potentially with elevated privileges, on the affected appliance.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-c3wx-5mx6-2qpg","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:56","euvd":{"id":"EUVD-2026-90379","description":"Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not sufficiently validated before being processed. A crafted package could cause the underlying system to execute arbitrary operating-system commands, potentially with elevated privileges, on the affected appliance.","published_time":"2026-09-30T20:07:35","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-c3wx-5mx6-2qpg","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102097","summary":"Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kiteworks Email Protection Gateway allowed an authenticated administrator to import configuration whose contents were not sufficiently validated before being processed. A crafted submission could potentially allow arbitrary commands to be executed on the affected gateway.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-465g-wpvm-8qmr","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:56","euvd":{"id":"EUVD-2026-90380","description":"Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kiteworks Email Protection Gateway allowed an authenticated administrator to import configuration whose contents were not sufficiently validated before being processed. A crafted submission could potentially allow arbitrary commands to be executed on the affected gateway.","published_time":"2026-09-30T20:07:48","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-465g-wpvm-8qmr","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Email Protection Gateway"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102098","summary":"Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data from the underlying database and to affect the availability of the service. Exploitation requires an existing, authenticated administrative account with access to the affected reporting function.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-cqg3-857q-cqj6","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:56","euvd":{"id":"EUVD-2026-90370","description":"Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data from the underlying database and to affect the availability of the service. Exploitation requires an existing, authenticated administrative account with access to the affected reporting function.","published_time":"2026-09-30T20:05:28","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-cqg3-857q-cqj6","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102099","summary":"Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction of a user-supplied file path in a Kiteworks administrative export feature could allow an authenticated administrator to write a file to an arbitrary location on the underlying host, potentially leading to command execution on the appliance. Exploitation requires an existing, authenticated administrative account with access to the affected export function.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-qj2g-2wfr-wg43","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:56","euvd":{"id":"EUVD-2026-90378","description":"Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction of a user-supplied file path in a Kiteworks administrative export feature could allow an authenticated administrator to write a file to an arbitrary location on the underlying host, potentially leading to command execution on the appliance. Exploitation requires an existing, authenticated administrative account with access to the affected export function.","published_time":"2026-09-30T20:07:29","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-qj2g-2wfr-wg43","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102100","summary":"Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an authenticated user to submit content that, when later viewed by another user, executes arbitrary JavaScript in that user's authenticated session. This could be used to perform actions on the victim's behalf and may have permitted account takeover, including of higher-privileged users. Exploitation requires the victim to view the attacker-supplied content.","cvss":8.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-vr65-9jwc-jgjx","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:56","euvd":{"id":"EUVD-2026-90269","description":"Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an authenticated user to submit content that, when later viewed by another user, executes arbitrary JavaScript in that user's authenticated session. This could be used to perform actions on the victim's behalf and may have permitted account takeover, including of higher-privileged users. Exploitation requires the victim to view the attacker-supplied content.","published_time":"2026-09-30T20:10:05","cvss":8.7,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-vr65-9jwc-jgjx","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102101","summary":"Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserialization weakness in Kiteworks Core could, under certain conditions, allow crafted data to be deserialized unsafely, potentially resulting in remote code execution on the appliance. Exploitation depends on an attacker first being able to influence the affected data, so this issue is not exploitable on its own.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-x5hx-fgrp-prvf","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:56","euvd":{"id":"EUVD-2026-90276","description":"Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserialization weakness in Kiteworks Core could, under certain conditions, allow crafted data to be deserialized unsafely, potentially resulting in remote code execution on the appliance. Exploitation depends on an attacker first being able to influence the affected data, so this issue is not exploitable on its own.","published_time":"2026-09-30T20:11:24","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-x5hx-fgrp-prvf","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102089","summary":"Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the server. This could potentially be leveraged to execute arbitrary code on the underlying system.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-p853-p65q-2vc8","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:55","euvd":{"id":"EUVD-2026-90369","description":"Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the server. This could potentially be leveraged to execute arbitrary code on the underlying system.","published_time":"2026-09-30T20:05:02","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-p853-p65q-2vc8","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Email Protection Gateway"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102090","summary":"Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate application domain. This could increase the credibility of phishing attempts relying on malicious links embedded in the displayed content.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-g3hj-598g-338g","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:55","euvd":{"id":"EUVD-2026-90371","description":"Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate application domain. This could increase the credibility of phishing attempts relying on malicious links embedded in the displayed content.","published_time":"2026-09-30T20:05:32","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-g3hj-598g-338g","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102091","summary":"Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network requests and read back the responses. This could potentially be used to reach internal-only services or other network-restricted resources.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-m8mj-m4fv-jmrh","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:55","euvd":{"id":"EUVD-2026-90372","description":"Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network requests and read back the responses. This could potentially be used to reach internal-only services or other network-restricted resources.","published_time":"2026-09-30T20:05:47","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-m8mj-m4fv-jmrh","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Secure Data Forms"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102092","summary":"Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could allow an authenticated user to store crafted content that executes arbitrary JavaScript in another user's authenticated session when they preview shared content. This could potentially lead to session compromise and account takeover.","cvss":8.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-mhw9-vrqq-m434","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:55","euvd":{"id":"EUVD-2026-90374","description":"Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could allow an authenticated user to store crafted content that executes arbitrary JavaScript in another user's authenticated session when they preview shared content. This could potentially lead to session compromise and account takeover.","published_time":"2026-09-30T20:06:03","cvss":8.7,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-mhw9-vrqq-m434","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102093","summary":"Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role assignment, which could allow an authenticated administrative user with limited, non-Sysadmin role-management permissions to elevate another user to full system-administrator privileges beyond those the administrative user was authorized to grant.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-mq6c-p42h-75j5","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:55","euvd":{"id":"EUVD-2026-90375","description":"Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role assignment, which could allow an authenticated administrative user with limited, non-Sysadmin role-management permissions to elevate another user to full system-administrator privileges beyond those the administrative user was authorized to grant.","published_time":"2026-09-30T20:06:49","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-mq6c-p42h-75j5","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["core"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-102094","summary":"Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Unsafe Reflection and does not sufficiently restrict the code that the mail-processing pipeline could load from an imported rule configuration. An authenticated administrator with mail-rule configuration privileges could cause the gateway to load and execute code beyond the approved set of mail-processing components, potentially in the context of the mail-gateway service account.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-9f5q-3c34-cpg8","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:55","euvd":{"id":"EUVD-2026-90376","description":"Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Unsafe Reflection and does not sufficiently restrict the code that the mail-processing pipeline could load from an imported rule configuration. An authenticated administrator with mail-rule configuration privileges could cause the gateway to load and execute code beyond the approved set of mail-processing components, potentially in the context of the mail-gateway service account.","published_time":"2026-09-30T20:07:06","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"cisa-cg","references":["https://github.com/kiteworks/security-advisories/security/advisories/GHSA-9f5q-3c34-cpg8","https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json"],"products":["Email Protection Gateway"],"vendors":["Kiteworks"]}},{"cve_id":"CVE-2026-101276","summary":"iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in 3.22.","cvss":9.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://newreleases.io/project/github/esnet/iperf/release/3.22"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:54","euvd":{"id":"EUVD-2026-90387","description":"iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in 3.22.","published_time":"2026-09-30T21:11:52","cvss":9.2,"cvss_version":"4.0","epss":0.0,"assigner":"Anthropic","references":["https://newreleases.io/project/github/esnet/iperf/release/3.22"],"products":["iperf3"],"vendors":["esnet"]}},{"cve_id":"CVE-2023-54403","summary":"Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 parameter and read arbitrary files via an unvalidated filePath parameter. Attackers can exploit this flaw to read sensitive files outside the web application directory, including configuration files containing database or service credentials. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/PeiQi0/PeiQi-WIKI-Book/blob/main/docs/wiki/oa/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%20U8%20CRM%E5%AE%A2%E6%88%B7%E5%85%B3%E7%B3%BB%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%20getemaildata.php%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md","https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/yonyou/yonyou-u8-crm-lfi.yaml","https://security.yonyou.com/#/noticeInfo?id=624","https://www.vulncheck.com/advisories/yonyou-u8-crm-arbitrary-file-read-via-getemaildata-php","https://www.yonyou.com/Global/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:52","euvd":{"id":"EUVD-2023-60699","description":"Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 parameter and read arbitrary files via an unvalidated filePath parameter. Attackers can exploit this flaw to read sensitive files outside the web application directory, including configuration files containing database or service credentials. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.","published_time":"2026-09-30T20:25:40","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://security.yonyou.com/#/noticeInfo?id=624","https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/yonyou/yonyou-u8-crm-lfi.yaml","https://github.com/PeiQi0/PeiQi-WIKI-Book/blob/main/docs/wiki/oa/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8B%20U8%20CRM%E5%AE%A2%E6%88%B7%E5%85%B3%E7%B3%BB%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F%20getemaildata.php%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md","https://www.yonyou.com/Global/","https://www.vulncheck.com/advisories/yonyou-u8-crm-arbitrary-file-read-via-getemaildata-php"],"products":["U8 CRM","U8 CRM","U8 CRM","U8 CRM"],"vendors":["Yonyou"]}},{"cve_id":"CVE-2024-58387","summary":"Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying unvalidated path parameters index and ext. Attackers can craft requests such as /api/model_report/file/download?index=/&ext=<path> to traverse the filesystem and disclose sensitive files including /etc/passwd, application database files, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-11-04 .","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://cn-sec.com/archives/3372984.html","https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/hcm/hcm-cloud-lfi.yaml","https://www.vulncheck.com/advisories/inspur-hcm-cloud-arbitrary-file-read-via-file-download-endpoint"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:52","euvd":{"id":"EUVD-2024-55778","description":"Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying unvalidated path parameters index and ext. Attackers can craft requests such as /api/model_report/file/download?index=/&ext=<path> to traverse the filesystem and disclose sensitive files including /etc/passwd, application database files, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-11-04 .","published_time":"2026-09-30T20:24:25","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/hcm/hcm-cloud-lfi.yaml","https://cn-sec.com/archives/3372984.html","https://www.vulncheck.com/advisories/inspur-hcm-cloud-arbitrary-file-read-via-file-download-endpoint"],"products":["Haiyue HCM Cloud"],"vendors":["Inspur"]}},{"cve_id":"CVE-2023-54402","summary":"iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote unauthenticated attackers to fetch arbitrary URLs by supplying a hardcoded default token value (testtoken) to bypass authentication. Attackers can exploit the unrestricted URL scheme handling, including file:// URIs, to read arbitrary local files such as operating-system and application configuration files, and to reach internal network hosts and services not otherwise accessible. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-03-26.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://blog.csdn.net/qq_41904294/article/details/134995343","https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/idoc/idocview-lfi.yaml","https://www.vulncheck.com/advisories/idocview-ssrf-via-doc-upload-endpoint-hardcoded-token"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T21:16:51","euvd":{"id":"EUVD-2023-60698","description":"iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote unauthenticated attackers to fetch arbitrary URLs by supplying a hardcoded default token value (testtoken) to bypass authentication. Attackers can exploit the unrestricted URL scheme handling, including file:// URIs, to read arbitrary local files such as operating-system and application configuration files, and to reach internal network hosts and services not otherwise accessible. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-03-26.","published_time":"2026-09-30T20:22:33","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/idoc/idocview-lfi.yaml","https://blog.csdn.net/qq_41904294/article/details/134995343","https://www.vulncheck.com/advisories/idocview-ssrf-via-doc-upload-endpoint-hardcoded-token"],"products":["iDocView"],"vendors":["iDocView"]}},{"cve_id":"CVE-2026-103547","summary":"In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process client file descriptor and LDAP message ID. After a connection closes, a later connection that reuses the same file descriptor and message ID can receive the earlier authentication result. A remote attacker who can reach ldapd can complete a Bind as another identity. A missing connection can also cause a NULL pointer dereference. (ldapd is not enabled by default.)","cvss":9.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://ftp.openbsd.org/pub/OpenBSD/patches/7.9/common/021_ldapd.patch.sig","https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960","https://www.openbsd.org/errata78.html","https://www.openbsd.org/errata79.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T20:17:31","euvd":{"id":"EUVD-2026-90259","description":"In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process client file descriptor and LDAP message ID. After a connection closes, a later connection that reuses the same file descriptor and message ID can receive the earlier authentication result. A remote attacker who can reach ldapd can complete a Bind as another identity. A missing connection can also cause a NULL pointer dereference. (ldapd is not enabled by default.)","published_time":"2026-09-30T19:40:53","cvss":9.2,"cvss_version":"4.0","epss":0.0,"assigner":"mitre","references":["https://www.openbsd.org/errata79.html","https://github.com/openbsd/src/commit/4f3f58e83c2a6d239c544236a9d4d76c74bbf960","https://ftp.openbsd.org/pub/OpenBSD/patches/7.9/common/021_ldapd.patch.sig","https://www.openbsd.org/errata78.html"],"products":["OpenBSD","OpenBSD"],"vendors":["OpenBSD"]}},{"cve_id":"CVE-2026-103548","summary":"Improperly stored passwords in the config file in Itron MV-90 xi 3.0 allows attackers to decode the passwords and password histories to gain access to the MV-90 application as any user.","cvss":5.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/PaloAltoNetworks/u42-vulnerability-disclosures/commits/main/2026/PANW-2026-0002/PANW-2026-0002.md"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T20:17:31","euvd":{"id":"EUVD-2026-90362","description":"Improperly stored passwords in the config file in Itron MV-90 xi 3.0 allows attackers to decode the passwords and password histories to gain access to the MV-90 application as any user.","published_time":"2026-09-30T19:45:14","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"palo_alto","references":["https://github.com/PaloAltoNetworks/u42-vulnerability-disclosures/commits/main/2026/PANW-2026-0002/PANW-2026-0002.md"],"products":["MV-90 xi"],"vendors":["iTRON"]}},{"cve_id":"CVE-2026-103387","summary":"A weakness has been identified in garycourt uri-js up to 4.4.1. This affects the function URI.parse of the file src/schemes/mailto.ts of the component Mailto Header Handler. This manipulation of the argument to causes uncaught exception. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.","cvss":2.1,"cvss_version":4.0,"cvss_v2":5.0,"cvss_v3":4.3,"cvss_v4":2.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/garycourt/uri-js/","https://github.com/garycourt/uri-js/issues/103","https://vuldb.com/cve/CVE-2026-103387","https://vuldb.com/submit/956810","https://vuldb.com/vuln/412124","https://vuldb.com/vuln/412124/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T20:17:30","euvd":{"id":"EUVD-2026-90361","description":"A weakness has been identified in garycourt uri-js up to 4.4.1. This affects the function URI.parse of the file src/schemes/mailto.ts of the component Mailto Header Handler. This manipulation of the argument to causes uncaught exception. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.","published_time":"2026-09-30T19:45:07","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/412124","https://vuldb.com/vuln/412124/cti","https://vuldb.com/cve/CVE-2026-103387","https://vuldb.com/submit/956810","https://github.com/garycourt/uri-js/issues/103","https://github.com/garycourt/uri-js/"],"products":["uri-js","uri-js"],"vendors":["garycourt"]}},{"cve_id":"CVE-2026-102994","summary":"pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-object identifiers or generation-number tokens that continue for a long time without whitespace can cause pypdf/_reader.py and pypdf/generic/_base.py to scan excessive input through read_until_whitespace, resulting in long runtimes and application unavailability. This issue is fixed in version 6.18.0.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/py-pdf/pypdf/commit/82501d2993c6387833c4949d205caeb188f8bb9e","https://github.com/py-pdf/pypdf/pull/4055","https://github.com/py-pdf/pypdf/releases/tag/6.18.0","https://github.com/py-pdf/pypdf/security/advisories/GHSA-5jq2-8x83-x246"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T20:17:28","euvd":{"id":"EUVD-2026-90366","description":"pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-object identifiers or generation-number tokens that continue for a long time without whitespace can cause pypdf/_reader.py and pypdf/generic/_base.py to scan excessive input through read_until_whitespace, resulting in long runtimes and application unavailability. This issue is fixed in version 6.18.0.","published_time":"2026-09-30T19:57:37","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/py-pdf/pypdf/security/advisories/GHSA-5jq2-8x83-x246","https://github.com/py-pdf/pypdf/pull/4055","https://github.com/py-pdf/pypdf/commit/82501d2993c6387833c4949d205caeb188f8bb9e","https://github.com/py-pdf/pypdf/releases/tag/6.18.0"],"products":["pypdf"],"vendors":["py-pdf"]}},{"cve_id":"CVE-2026-102992","summary":"piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadPool.options in src/index.ts as a plain object that inherits from Object.prototype. Applications with a separate prototype-pollution primitive can therefore supply inherited values for security-sensitive options that do not have own defaults. An inherited execArgv value is passed to the Node.js Worker constructor and can preload attacker-controlled code in worker threads, an inherited loadBalancer function can execute during task scheduling, and inherited env values can alter worker environments. This issue is fixed in versions 4.9.4, 5.3.2, and 6.0.0-rc.5.","cvss":9.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/piscinajs/piscina/commit/0cb12fca37f526065b072592afe954574dcc656f","https://github.com/piscinajs/piscina/commit/2f69f67159a0e48b38fd61fa4a91c2fdc19fff72","https://github.com/piscinajs/piscina/commit/5be7bbb19e3787bb698862cd516121a578d690f7","https://github.com/piscinajs/piscina/commit/bebbda255c2981cecddd36b171b94be2fd41c9a6","https://github.com/piscinajs/piscina/releases/tag/v4.9.4","https://github.com/piscinajs/piscina/releases/tag/v5.3.2","https://github.com/piscinajs/piscina/releases/tag/v6.0.0-rc.5","https://github.com/piscinajs/piscina/security/advisories/GHSA-67c8-pqhq-4rmx","https://github.com/piscinajs/piscina/security/advisories/GHSA-67c8-pqhq-4rmx"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T20:17:27","euvd":{"id":"EUVD-2026-90364","description":"piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadPool.options in src/index.ts as a plain object that inherits from Object.prototype. Applications with a separate prototype-pollution primitive can therefore supply inherited values for security-sensitive options that do not have own defaults. An inherited execArgv value is passed to the Node.js Worker constructor and can preload attacker-controlled code in worker threads, an inherited loadBalancer function can execute during task scheduling, and inherited env values can alter worker environments. This issue is fixed in versions 4.9.4, 5.3.2, and 6.0.0-rc.5.","published_time":"2026-09-30T19:50:18","cvss":9.2,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/piscinajs/piscina/security/advisories/GHSA-67c8-pqhq-4rmx","https://github.com/piscinajs/piscina/commit/0cb12fca37f526065b072592afe954574dcc656f","https://github.com/piscinajs/piscina/commit/2f69f67159a0e48b38fd61fa4a91c2fdc19fff72","https://github.com/piscinajs/piscina/commit/5be7bbb19e3787bb698862cd516121a578d690f7","https://github.com/piscinajs/piscina/commit/bebbda255c2981cecddd36b171b94be2fd41c9a6","https://github.com/piscinajs/piscina/releases/tag/v4.9.4","https://github.com/piscinajs/piscina/releases/tag/v5.3.2","https://github.com/piscinajs/piscina/releases/tag/v6.0.0-rc.5"],"products":["piscina","piscina","piscina"],"vendors":["piscinajs"]}},{"cve_id":"CVE-2026-102993","summary":"pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/py-pdf/pypdf/commit/89db7c4fe9315ecc964bfdf05a4e8c4b94175163","https://github.com/py-pdf/pypdf/pull/4047","https://github.com/py-pdf/pypdf/releases/tag/6.17.0","https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T20:17:27","euvd":{"id":"EUVD-2026-90365","description":"pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0.","published_time":"2026-09-30T19:55:52","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285","https://github.com/py-pdf/pypdf/pull/4047","https://github.com/py-pdf/pypdf/commit/89db7c4fe9315ecc964bfdf05a4e8c4b94175163","https://github.com/py-pdf/pypdf/releases/tag/6.17.0"],"products":["pypdf"],"vendors":["py-pdf"]}},{"cve_id":"CVE-2026-102990","summary":"basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU time parsing a directory listing because the RE_LINE expression in src/parseListUnix.ts backtracks across adjacent variable-length owner and group fields when a long Unix-style line has a valid prefix but cannot satisfy the later size and date fields. parseList() selects a parser from the last nonblank line and then applies it to every line, so a normal final line can select the Unix parser while an earlier crafted line blocks the Node.js event loop and freezes the process. This issue is fixed in version 6.2.1.","cvss":8.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/patrickjuchli/basic-ftp/commit/d0d9e07c56e519587bb50532ac6eadbb0cb0cfe9","https://github.com/patrickjuchli/basic-ftp/releases/tag/v6.2.1","https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-c475-qrg2-pj4r","https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-c475-qrg2-pj4r"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T20:17:26","euvd":{"id":"EUVD-2026-90360","description":"basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU time parsing a directory listing because the RE_LINE expression in src/parseListUnix.ts backtracks across adjacent variable-length owner and group fields when a long Unix-style line has a valid prefix but cannot satisfy the later size and date fields. parseList() selects a parser from the last nonblank line and then applies it to every line, so a normal final line can select the Unix parser while an earlier crafted line blocks the Node.js event loop and freezes the process. This issue is fixed in version 6.2.1.","published_time":"2026-09-30T19:44:47","cvss":8.2,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-c475-qrg2-pj4r","https://github.com/patrickjuchli/basic-ftp/commit/d0d9e07c56e519587bb50532ac6eadbb0cb0cfe9","https://github.com/patrickjuchli/basic-ftp/releases/tag/v6.2.1"],"products":["basic-ftp"],"vendors":["patrickjuchli"]}},{"cve_id":"CVE-2026-102991","summary":"Mako is a template library written in Python. Prior to 1.4.2, on Windows, TemplateLookup.get_template() in mako/lookup.py resolves template URIs with posixpath, while Template.__init__() in mako/template.py validates them with os.path, which uses ntpath. A URI beginning with a drive designator causes ntpath to absorb the traversal segments before the leading dot-dot check, while posixpath resolution can escape the configured template directory. An application that passes attacker-controlled template names or include paths can disclose process-readable files on the same volume, and a targeted file containing Mako template syntax may also be parsed and executed as a template. Raw URL paths are generally normalized before reaching this form, but query strings, form or JSON bodies, route parameters, and dynamic include expressions can preserve it. This issue is fixed in version 1.4.2.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/sqlalchemy/mako/commit/000ed85e4e48771eff460bf4fc721fb43de80e08","https://github.com/sqlalchemy/mako/issues/441","https://github.com/sqlalchemy/mako/releases/tag/rel_1_4_2","https://github.com/sqlalchemy/mako/security/advisories/GHSA-5639-2j2p-m4mx","https://github.com/sqlalchemy/mako/security/advisories/GHSA-5639-2j2p-m4mx"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T20:17:26","euvd":{"id":"EUVD-2026-90363","description":"Mako is a template library written in Python. Prior to 1.4.2, on Windows, TemplateLookup.get_template() in mako/lookup.py resolves template URIs with posixpath, while Template.__init__() in mako/template.py validates them with os.path, which uses ntpath. A URI beginning with a drive designator causes ntpath to absorb the traversal segments before the leading dot-dot check, while posixpath resolution can escape the configured template directory. An application that passes attacker-controlled template names or include paths can disclose process-readable files on the same volume, and a targeted file containing Mako template syntax may also be parsed and executed as a template. Raw URL paths are generally normalized before reaching this form, but query strings, form or JSON bodies, route parameters, and dynamic include expressions can preserve it. This issue is fixed in version 1.4.2.","published_time":"2026-09-30T19:47:07","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/sqlalchemy/mako/security/advisories/GHSA-5639-2j2p-m4mx","https://github.com/sqlalchemy/mako/issues/441","https://github.com/sqlalchemy/mako/commit/000ed85e4e48771eff460bf4fc721fb43de80e08","https://github.com/sqlalchemy/mako/releases/tag/rel_1_4_2"],"products":["mako"],"vendors":["sqlalchemy"]}},{"cve_id":"CVE-2026-101885","summary":"ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers can convince users to install crafted plugins that write arbitrary files to paths outside the plugins directory, such as shell startup files, enabling code execution.","cvss":8.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":8.5,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/zeroclaw-labs/zeroclaw/blob/v0.8.4/crates/zeroclaw-plugins/src/host.rs#L238-L273","https://github.com/zeroclaw-labs/zeroclaw/commit/432e034d3cb024610d5916a2f328678d151c1dd5","https://github.com/zeroclaw-labs/zeroclaw/releases/tag/v0.8.5","https://github.com/zeroclaw-labs/zeroclaw/security/advisories/GHSA-93f6-34w8-5g98","https://www.vulncheck.com/advisories/zeroclaw-before-0.8.5-path-traversal-via-plugin-manifest-wasm-path","https://github.com/zeroclaw-labs/zeroclaw/security/advisories/GHSA-93f6-34w8-5g98"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T20:17:21","euvd":{"id":"EUVD-2026-90258","description":"ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers can convince users to install crafted plugins that write arbitrary files to paths outside the plugins directory, such as shell startup files, enabling code execution.","published_time":"2026-09-30T19:16:05","cvss":8.5,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/zeroclaw-labs/zeroclaw/security/advisories/GHSA-93f6-34w8-5g98","https://github.com/zeroclaw-labs/zeroclaw/commit/432e034d3cb024610d5916a2f328678d151c1dd5","https://github.com/zeroclaw-labs/zeroclaw/releases/tag/v0.8.5","https://github.com/zeroclaw-labs/zeroclaw/blob/v0.8.4/crates/zeroclaw-plugins/src/host.rs#L238-L273","https://www.vulncheck.com/advisories/zeroclaw-before-0.8.5-path-traversal-via-plugin-manifest-wasm-path"],"products":["ZeroClaw"],"vendors":["zeroclaw-labs"]}},{"cve_id":"CVE-2026-101883","summary":"OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers with gateway or agent access can issue canvas.present to make the node's WebView send requests to localhost, private networks, or tailnet services from the user's machine.","cvss":5.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":5.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Tray.WinUI/Windows/CanvasWindow.xaml.cs#L77-L109","https://github.com/openclaw/openclaw-windows-node/blob/v2026.9.4/src/OpenClaw.Tray.WinUI/Services/NodeService.cs#L1244-L1270","https://github.com/openclaw/openclaw-windows-node/commit/16528aadaa45d7bc6718b07ccf8b01f3eb033ad1","https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-7vch-pmw9-3g4q","https://www.vulncheck.com/advisories/openclaw-windows-node-through-2026.9.4-ssrf-via-canvas-present"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T20:17:20","euvd":{"id":"EUVD-2026-90256","description":"OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers with gateway or agent access can issue canvas.present to make the node's WebView send requests to localhost, private networks, or tailnet services from the user's machine.","published_time":"2026-09-30T19:16:03","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-7vch-pmw9-3g4q","https://github.com/openclaw/openclaw-windows-node/commit/16528aadaa45d7bc6718b07ccf8b01f3eb033ad1","https://github.com/openclaw/openclaw-windows-node/blob/v2026.9.4/src/OpenClaw.Tray.WinUI/Services/NodeService.cs#L1244-L1270","https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Tray.WinUI/Windows/CanvasWindow.xaml.cs#L77-L109","https://www.vulncheck.com/advisories/openclaw-windows-node-through-2026.9.4-ssrf-via-canvas-present"],"products":["OpenClaw Windows Node"],"vendors":["OpenClaw"]}},{"cve_id":"CVE-2026-101884","summary":"OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution.","cvss":7.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":7.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/ExecEnvSanitizer.cs#L15-L50","https://github.com/openclaw/openclaw-windows-node/commit/261ba11aaad671834ad141bb85101b50cf1a38f6","https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1","https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-39cf-qcfw-g8pg","https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-remote-code-execution-via-environment-override","https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-39cf-qcfw-g8pg"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T20:17:20","euvd":{"id":"EUVD-2026-90257","description":"OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution.","published_time":"2026-09-30T19:16:04","cvss":7.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-39cf-qcfw-g8pg","https://github.com/openclaw/openclaw-windows-node/commit/261ba11aaad671834ad141bb85101b50cf1a38f6","https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1","https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/ExecEnvSanitizer.cs#L15-L50","https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-remote-code-execution-via-environment-override"],"products":["OpenClaw Windows Node"],"vendors":["OpenClaw"]}},{"cve_id":"CVE-2026-101881","summary":"OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth until the node process crashes.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":7.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/WebSocketClientBase.cs#L217-L263","https://github.com/openclaw/openclaw-windows-node/commit/1810e357aa0d0639099b347f31c746ba7d31512a","https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1","https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-xxr2-xm56-9cw5","https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-denial-of-service","https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-xxr2-xm56-9cw5"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T20:17:19","euvd":{"id":"EUVD-2026-90254","description":"OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth until the node process crashes.","published_time":"2026-09-30T19:16:02","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-xxr2-xm56-9cw5","https://github.com/openclaw/openclaw-windows-node/commit/1810e357aa0d0639099b347f31c746ba7d31512a","https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1","https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/WebSocketClientBase.cs#L217-L263","https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-denial-of-service"],"products":["OpenClaw Windows Node"],"vendors":["OpenClaw"]}},{"cve_id":"CVE-2026-101882","summary":"OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundll32, and certutil. Remote callers can add broad allow rules to execute arbitrary commands on the Windows host through system.run without operator checks or user prompts.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/Capabilities/SystemCapability.cs#L791-L853","https://github.com/openclaw/openclaw-windows-node/commit/8f07ad92beb28376bc228c0b07093173a043a656","https://github.com/openclaw/openclaw-windows-node/commit/988df5badc84ab5efd5b4e291766a1fa5e7e268a","https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1","https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-f32j-8759-w2fp","https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-g95v-c9r6-2hmq","https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-remote-code-execution-via-system-execapprovals-set"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T20:17:19","euvd":{"id":"EUVD-2026-90255","description":"OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundll32, and certutil. Remote callers can add broad allow rules to execute arbitrary commands on the Windows host through system.run without operator checks or user prompts.","published_time":"2026-09-30T19:16:03","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-f32j-8759-w2fp","https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-g95v-c9r6-2hmq","https://github.com/openclaw/openclaw-windows-node/commit/8f07ad92beb28376bc228c0b07093173a043a656","https://github.com/openclaw/openclaw-windows-node/commit/988df5badc84ab5efd5b4e291766a1fa5e7e268a","https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1","https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/Capabilities/SystemCapability.cs#L791-L853","https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-remote-code-execution-via-system-execapprovals-set"],"products":["OpenClaw Windows Node"],"vendors":["OpenClaw"]}},{"cve_id":"CVE-2026-101879","summary":"OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that allows connected gateways or agents to perform screen snapshots, camera snaps, and location captures without consent prompts. Attackers can invoke screen.snapshot, camera.snap, and location.get over the node WebSocket to silently capture screenshots, photograph users through webcams, and obtain device geolocation without user interaction.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":7.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/openclaw/openclaw-windows-node/blob/v2026.7.1-2/src/OpenClaw.Tray.WinUI/Services/NodeService.cs#L1891-L1913","https://github.com/openclaw/openclaw-windows-node/commit/16cb6897941fa7832ce2811e9d550caed9a49b4b","https://github.com/openclaw/openclaw-windows-node/commit/31a8c6557df740232898079b21f0eb677a4119cf","https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1-3","https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-fxch-cgcp-4v5h","https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-3-missing-authorization"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T20:17:18","euvd":{"id":"EUVD-2026-90252","description":"OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that allows connected gateways or agents to perform screen snapshots, camera snaps, and location captures without consent prompts. Attackers can invoke screen.snapshot, camera.snap, and location.get over the node WebSocket to silently capture screenshots, photograph users through webcams, and obtain device geolocation without user interaction.","published_time":"2026-09-30T19:16:01","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-fxch-cgcp-4v5h","https://github.com/openclaw/openclaw-windows-node/commit/31a8c6557df740232898079b21f0eb677a4119cf","https://github.com/openclaw/openclaw-windows-node/commit/16cb6897941fa7832ce2811e9d550caed9a49b4b","https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1-3","https://github.com/openclaw/openclaw-windows-node/blob/v2026.7.1-2/src/OpenClaw.Tray.WinUI/Services/NodeService.cs#L1891-L1913","https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-3-missing-authorization"],"products":["OpenClaw Windows Node"],"vendors":["OpenClaw"]}},{"cve_id":"CVE-2026-101880","summary":"OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe operators or command substitution syntax, achieving arbitrary command execution on Windows hosts.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/ExecShellWrapperParser.cs#L253","https://github.com/openclaw/openclaw-windows-node/commit/2077aa3e7159101bddcee2f4efcb9d604a81619e","https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1","https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-r3x2-vf2f-vvj8","https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-vg38-vjq2-vgvh","https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-authorization-bypass","https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-r3x2-vf2f-vvj8"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T20:17:18","euvd":{"id":"EUVD-2026-90253","description":"OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe operators or command substitution syntax, achieving arbitrary command execution on Windows hosts.","published_time":"2026-09-30T19:16:01","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-r3x2-vf2f-vvj8","https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-vg38-vjq2-vgvh","https://github.com/openclaw/openclaw-windows-node/commit/2077aa3e7159101bddcee2f4efcb9d604a81619e","https://github.com/openclaw/openclaw-windows-node/releases/tag/v2026.7.1","https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Shared/ExecShellWrapperParser.cs#L253","https://www.vulncheck.com/advisories/openclaw-windows-node-before-2026.7.1-authorization-bypass"],"products":["OpenClaw Windows Node"],"vendors":["OpenClaw"]}},{"cve_id":"CVE-2026-97256","summary":"Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/siteorigin-panels/vulnerability/wordpress-page-builder-by-siteorigin-plugin-2-36-0-php-object-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:44","euvd":{"id":"EUVD-2026-90215","description":"Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions.","published_time":"2026-09-30T17:39:00","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/siteorigin-panels/vulnerability/wordpress-page-builder-by-siteorigin-plugin-2-36-0-php-object-injection-vulnerability?_s_id=cve"],"products":["Page Builder by SiteOrigin"],"vendors":["Greg – SiteOrigin"]}},{"cve_id":"CVE-2026-97265","summary":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS.\n\nThis issue affects JetEngine: from n/a through 3.8.15.3.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/jet-engine/vulnerability/wordpress-jetengine-plugin-3-8-15-3-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:44","euvd":{"id":"EUVD-2026-90216","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS.\n\nThis issue affects JetEngine: from n/a through 3.8.15.3.","published_time":"2026-09-30T17:39:01","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/jet-engine/vulnerability/wordpress-jetengine-plugin-3-8-15-3-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["JetEngine"],"vendors":["Crocoblock. Jetimpex Inc."]}},{"cve_id":"CVE-2026-97290","summary":"Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/photonic/vulnerability/wordpress-photonic-gallery-lightbox-for-flickr-smugmug-others-plugin-3-36-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:44","euvd":{"id":"EUVD-2026-90217","description":"Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions.","published_time":"2026-09-30T17:39:02","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/photonic/vulnerability/wordpress-photonic-gallery-lightbox-for-flickr-smugmug-others-plugin-3-36-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Photonic Gallery & Lightbox for Flickr, SmugMug & Others"],"vendors":["Sayontan Sinha"]}},{"cve_id":"CVE-2026-97291","summary":"Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/schema-and-structured-data-for-wp/vulnerability/wordpress-schema-structured-data-for-wp-amp-plugin-1-66-php-object-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:44","euvd":{"id":"EUVD-2026-90218","description":"Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions.","published_time":"2026-09-30T17:39:02","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/schema-and-structured-data-for-wp/vulnerability/wordpress-schema-structured-data-for-wp-amp-plugin-1-66-php-object-injection-vulnerability?_s_id=cve"],"products":["Schema & Structured Data for WP & AMP"],"vendors":["Magazine3"]}},{"cve_id":"CVE-2026-94171","summary":"Unauthenticated Cross Site Scripting (XSS) in CURCY <= 2.2.16 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/woo-multi-currency/vulnerability/wordpress-curcy-plugin-2-2-16-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:43","euvd":{"id":"EUVD-2026-90214","description":"Unauthenticated Cross Site Scripting (XSS) in CURCY <= 2.2.16 versions.","published_time":"2026-09-30T17:38:59","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/woo-multi-currency/vulnerability/wordpress-curcy-plugin-2-2-16-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["CURCY"],"vendors":["VillaTheme"]}},{"cve_id":"CVE-2026-87004","summary":"Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token returned by the identity provider's token endpoint using jose.jwt.get_unverified_claims() instead of jwt.decode(). This skips signature verification, audience (aud) validation, issuer (iss) validation, and expiry (exp) checking entirely. The extracted claims (email/sub/preferred_username) are then used directly as the user_id for the resulting Tugtainer session. This issue has been patched in version 1.31.3.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Quenary/tugtainer/commit/b55269b6a3bfd43b0f2f5bd5f137ee0c81b7c2e4","https://github.com/Quenary/tugtainer/releases/tag/v1.31.3","https://github.com/Quenary/tugtainer/security/advisories/GHSA-crjc-6vc7-xrfh","https://github.com/Quenary/tugtainer/security/advisories/GHSA-crjc-6vc7-xrfh"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:41","euvd":{"id":"EUVD-2026-90195","description":"Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token returned by the identity provider's token endpoint using jose.jwt.get_unverified_claims() instead of jwt.decode(). This skips signature verification, audience (aud) validation, issuer (iss) validation, and expiry (exp) checking entirely. The extracted claims (email/sub/preferred_username) are then used directly as the user_id for the resulting Tugtainer session. This issue has been patched in version 1.31.3.","published_time":"2026-09-30T17:01:24","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/Quenary/tugtainer/security/advisories/GHSA-crjc-6vc7-xrfh","https://github.com/Quenary/tugtainer/commit/b55269b6a3bfd43b0f2f5bd5f137ee0c81b7c2e4","https://github.com/Quenary/tugtainer/releases/tag/v1.31.3"],"products":["tugtainer"],"vendors":["Quenary"]}},{"cve_id":"CVE-2026-53605","summary":"Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl with no subcommand or argument restriction. This is a local privilege escalation (LPE). Any process running as pollen can obtain full root (uid 0) on the device in three commands, with no additional vulnerability required and no user interaction. This issue has been patched in version 0.2.4.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/pollen-robotics/reachy-mini-os/commit/cee4076f36bd95a2a6b894a56a48c7e971e75445","https://github.com/pollen-robotics/reachy-mini-os/releases/tag/v0.2.4","https://github.com/pollen-robotics/reachy-mini-os/security/advisories/GHSA-7rhg-9v48-x3h2"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:37","euvd":{"id":"EUVD-2026-90198","description":"Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl with no subcommand or argument restriction. This is a local privilege escalation (LPE). Any process running as pollen can obtain full root (uid 0) on the device in three commands, with no additional vulnerability required and no user interaction. This issue has been patched in version 0.2.4.","published_time":"2026-09-30T17:09:23","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/pollen-robotics/reachy-mini-os/security/advisories/GHSA-7rhg-9v48-x3h2","https://github.com/pollen-robotics/reachy-mini-os/commit/cee4076f36bd95a2a6b894a56a48c7e971e75445","https://github.com/pollen-robotics/reachy-mini-os/releases/tag/v0.2.4"],"products":["reachy-mini-os"],"vendors":["pollen-robotics"]}},{"cve_id":"CVE-2026-55094","summary":"Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes. Prior to version 100.3.0, Taskcluster is vulnerable to unauthenticated RCE on Taskcluster deployments with an anonymous role that exposes the GraphQL endpoint and parses filter arguments using the sift library. This issue has been patched in version 100.3.0.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://bugzilla.mozilla.org/show_bug.cgi?id=2045091","https://github.com/taskcluster/taskcluster/commit/a1b0154b8235937657c2ded127f193b564e2334b","https://github.com/taskcluster/taskcluster/issues/8716","https://github.com/taskcluster/taskcluster/pull/8718","https://github.com/taskcluster/taskcluster/releases/tag/v100.3.0","https://github.com/taskcluster/taskcluster/security/advisories/GHSA-ccv5-c45x-2q38"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:37","euvd":{"id":"EUVD-2026-90208","description":"Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes. Prior to version 100.3.0, Taskcluster is vulnerable to unauthenticated RCE on Taskcluster deployments with an anonymous role that exposes the GraphQL endpoint and parses filter arguments using the sift library. This issue has been patched in version 100.3.0.","published_time":"2026-09-30T17:22:52","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/taskcluster/taskcluster/security/advisories/GHSA-ccv5-c45x-2q38","https://github.com/taskcluster/taskcluster/issues/8716","https://github.com/taskcluster/taskcluster/pull/8718","https://github.com/taskcluster/taskcluster/commit/a1b0154b8235937657c2ded127f193b564e2334b","https://bugzilla.mozilla.org/show_bug.cgi?id=2045091","https://github.com/taskcluster/taskcluster/releases/tag/v100.3.0"],"products":["taskcluster"],"vendors":["taskcluster"]}},{"cve_id":"CVE-2026-55107","summary":"Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-party plugins) in-process without giving them access to host memory, files, network, or credentials. From version 0.1.0 to before version 0.9.1, a guest mruby script running inside the Kobako sandbox can execute arbitrary Ruby in the host process, fully escaping the sandbox. This issue has been patched in version 0.9.1.","cvss":10.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":10.0,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/elct9620/kobako/commit/64f84700c81f44902bed9211318d5362f44987b3","https://github.com/elct9620/kobako/releases/tag/v0.9.1","https://github.com/elct9620/kobako/security/advisories/GHSA-7pwq-q9jf-539h","https://github.com/elct9620/kobako/security/advisories/GHSA-7pwq-q9jf-539h"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:37","euvd":{"id":"EUVD-2026-90197","description":"Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-party plugins) in-process without giving them access to host memory, files, network, or credentials. From version 0.1.0 to before version 0.9.1, a guest mruby script running inside the Kobako sandbox can execute arbitrary Ruby in the host process, fully escaping the sandbox. This issue has been patched in version 0.9.1.","published_time":"2026-09-30T17:06:00","cvss":10.0,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/elct9620/kobako/security/advisories/GHSA-7pwq-q9jf-539h","https://github.com/elct9620/kobako/commit/64f84700c81f44902bed9211318d5362f44987b3","https://github.com/elct9620/kobako/releases/tag/v0.9.1"],"products":["kobako"],"vendors":["elct9620"]}},{"cve_id":"CVE-2026-55224","summary":"MineAdmin is a ready-to-use backend management system suitable for quickly building website backends, operation platforms, permission centers, internal management systems, CMS, CRM, OA, ERP and other business applications. Prior to version 3.2.0-alpha.2, the app-store plugin service concatenates unsanitized user-supplied identifier values directly into file system paths. An attacker can use path traversal sequences (e.g., ../) to read, install, or uninstall plugins from arbitrary directories, and potentially execute arbitrary composer commands. This issue has been patched in version 3.2.0-alpha.2.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/mineadmin/MineAdmin/commit/ca41902a2a5422676227e5088f4cc1dec06044f1","https://github.com/mineadmin/MineAdmin/pull/728","https://github.com/mineadmin/MineAdmin/releases/tag/v3.2.0-alpha.2","https://github.com/mineadmin/MineAdmin/security/advisories/GHSA-59xm-4m8c-g3xj"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:37","euvd":{"id":"EUVD-2026-90209","description":"MineAdmin is a ready-to-use backend management system suitable for quickly building website backends, operation platforms, permission centers, internal management systems, CMS, CRM, OA, ERP and other business applications. Prior to version 3.2.0-alpha.2, the app-store plugin service concatenates unsanitized user-supplied identifier values directly into file system paths. An attacker can use path traversal sequences (e.g., ../) to read, install, or uninstall plugins from arbitrary directories, and potentially execute arbitrary composer commands. This issue has been patched in version 3.2.0-alpha.2.","published_time":"2026-09-30T17:26:11","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/mineadmin/MineAdmin/security/advisories/GHSA-59xm-4m8c-g3xj","https://github.com/mineadmin/MineAdmin/pull/728","https://github.com/mineadmin/MineAdmin/commit/ca41902a2a5422676227e5088f4cc1dec06044f1","https://github.com/mineadmin/MineAdmin/releases/tag/v3.2.0-alpha.2"],"products":["MineAdmin"],"vendors":["mineadmin"]}},{"cve_id":"CVE-2026-103500","summary":"An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size. This vulnerability was fixed in Thunderbird 157, Thunderbird 140.17, and Thunderbird 153.4.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://bugzilla.mozilla.org/show_bug.cgi?id=2070267","https://www.mozilla.org/security/advisories/mfsa2026-101/","https://www.mozilla.org/security/advisories/mfsa2026-102/","https://www.mozilla.org/security/advisories/mfsa2026-103/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:18","euvd":{"id":"EUVD-2026-90200","description":"An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size. This vulnerability was fixed in Thunderbird 157, Thunderbird 140.17, and Thunderbird 153.4.","published_time":"2026-09-30T17:15:06","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"mozilla","references":["https://bugzilla.mozilla.org/show_bug.cgi?id=2070267","https://www.mozilla.org/security/advisories/mfsa2026-101/","https://www.mozilla.org/security/advisories/mfsa2026-102/","https://www.mozilla.org/security/advisories/mfsa2026-103/"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-103446","summary":"Authorization bypass through User-Controlled key vulnerability in The Wikimedia Foundation MediaWiki WikiLambda extension allows Authentication Bypass.\n\nThis issue affects MediaWiki WikiLambda extension: 1.46.","cvss":7.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.4,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gerrit.wikimedia.org/r/q/If2c05b109672fc65f63372f86c768859dc6639fd","https://phabricator.wikimedia.org/T435086"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:17","euvd":{"id":"EUVD-2026-90199","description":"Authorization bypass through User-Controlled key vulnerability in The Wikimedia Foundation MediaWiki WikiLambda extension allows Authentication Bypass.\n\nThis issue affects MediaWiki WikiLambda extension: 1.46.","published_time":"2026-09-30T17:13:02","cvss":7.4,"cvss_version":"4.0","epss":0.0,"assigner":"wikimedia-foundation","references":["https://phabricator.wikimedia.org/T435086","https://gerrit.wikimedia.org/r/q/If2c05b109672fc65f63372f86c768859dc6639fd"],"products":["MediaWiki WikiLambda extension"],"vendors":["The Wikimedia Foundation"]}},{"cve_id":"CVE-2026-103471","summary":"restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated attackers to exhaust server memory. Attackers can open TCP connections and stream bytes indefinitely without sending the header delimiter, forcing the server to allocate unbounded heap memory until the process is killed.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Corvusoft/restbed","https://github.com/Corvusoft/restbed/blob/e1227a297ce6d4e9f78222456507b29bb8ab77e9/src/corvusoft/restbed/detail/service_impl.cpp#L554","https://github.com/Corvusoft/restbed/blob/e1227a297ce6d4e9f78222456507b29bb8ab77e9/src/corvusoft/restbed/session.cpp#L200","https://github.com/Corvusoft/restbed/issues/558","https://www.vulncheck.com/advisories/restbed-through-5.0.0-denial-of-service-via-unbounded-header-buffering","https://github.com/Corvusoft/restbed/issues/558"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:17","euvd":{"id":"EUVD-2026-90202","description":"restbed through 5.0.0 buffers HTTP request headers without enforcing a maximum size limit, allowing remote unauthenticated attackers to exhaust server memory. Attackers can open TCP connections and stream bytes indefinitely without sending the header delimiter, forcing the server to allocate unbounded heap memory until the process is killed.","published_time":"2026-09-30T17:22:38","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/Corvusoft/restbed/issues/558","https://github.com/Corvusoft/restbed","https://github.com/Corvusoft/restbed/blob/e1227a297ce6d4e9f78222456507b29bb8ab77e9/src/corvusoft/restbed/detail/service_impl.cpp#L554","https://github.com/Corvusoft/restbed/blob/e1227a297ce6d4e9f78222456507b29bb8ab77e9/src/corvusoft/restbed/session.cpp#L200","https://www.vulncheck.com/advisories/restbed-through-5.0.0-denial-of-service-via-unbounded-header-buffering"],"products":["restbed"],"vendors":["Corvusoft"]}},{"cve_id":"CVE-2026-103472","summary":"restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream buffer. Remote unauthenticated attackers can declare large frame sizes and stream payload data to exhaust server memory, causing denial of service through process crash.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Corvusoft/restbed","https://github.com/Corvusoft/restbed/blob/e1227a297ce6d4e9f78222456507b29bb8ab77e9/src/corvusoft/restbed/detail/web_socket_impl.cpp#L117","https://github.com/Corvusoft/restbed/issues/558","https://www.vulncheck.com/advisories/restbed-through-5.0.0-websocket-memory-exhaustion-via-unbounded-frame-buffering"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:17","euvd":{"id":"EUVD-2026-90203","description":"restbed through 5.0.0 accepts WebSocket frames with declared payload lengths up to 2^63 bytes and buffers the payload without size limits in an unbounded stream buffer. Remote unauthenticated attackers can declare large frame sizes and stream payload data to exhaust server memory, causing denial of service through process crash.","published_time":"2026-09-30T17:22:39","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/Corvusoft/restbed/issues/558","https://github.com/Corvusoft/restbed","https://github.com/Corvusoft/restbed/blob/e1227a297ce6d4e9f78222456507b29bb8ab77e9/src/corvusoft/restbed/detail/web_socket_impl.cpp#L117","https://www.vulncheck.com/advisories/restbed-through-5.0.0-websocket-memory-exhaustion-via-unbounded-frame-buffering"],"products":["restbed"],"vendors":["Corvusoft"]}},{"cve_id":"CVE-2026-103473","summary":"Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with the shell option, allowing arbitrary command execution with Deno process privileges.","cvss":9.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":9.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/denoland/deno","https://github.com/denoland/deno/blob/0c071246a412575e07423263404a5d13e7ed6aa2/ext/node/polyfills/internal/child_process.ts#L1339","https://github.com/denoland/deno/blob/0c071246a412575e07423263404a5d13e7ed6aa2/ext/node/polyfills/internal/child_process.ts#L1499","https://github.com/denoland/deno/pull/36772","https://www.vulncheck.com/advisories/deno-2.7.0-through-2.9.7-command-injection-via-node-child-process"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:17","euvd":{"id":"EUVD-2026-90204","description":"Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with the shell option, allowing arbitrary command execution with Deno process privileges.","published_time":"2026-09-30T17:22:40","cvss":9.2,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/denoland/deno/pull/36772","https://github.com/denoland/deno","https://github.com/denoland/deno/blob/0c071246a412575e07423263404a5d13e7ed6aa2/ext/node/polyfills/internal/child_process.ts#L1499","https://github.com/denoland/deno/blob/0c071246a412575e07423263404a5d13e7ed6aa2/ext/node/polyfills/internal/child_process.ts#L1339","https://www.vulncheck.com/advisories/deno-2.7.0-through-2.9.7-command-injection-via-node-child-process"],"products":["deno"],"vendors":["denoland"]}},{"cve_id":"CVE-2026-103474","summary":"yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP scripts to the web-accessible storage directory and request them to execute arbitrary code on the server.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/yii-starter-kit/yii2-starter-kit","https://github.com/yii-starter-kit/yii2-starter-kit/blob/cc2c451e8c959c7300b04efea597706a38609f58/backend/modules/file/controllers/StorageController.php#L36","https://github.com/yii-starter-kit/yii2-starter-kit/issues/797","https://www.vulncheck.com/advisories/yii2-starter-kit-through-4.2.0-unrestricted-file-upload-rce"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:17","euvd":{"id":"EUVD-2026-90205","description":"yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP scripts to the web-accessible storage directory and request them to execute arbitrary code on the server.","published_time":"2026-09-30T17:22:41","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/yii-starter-kit/yii2-starter-kit/issues/797","https://github.com/yii-starter-kit/yii2-starter-kit","https://github.com/yii-starter-kit/yii2-starter-kit/blob/cc2c451e8c959c7300b04efea597706a38609f58/backend/modules/file/controllers/StorageController.php#L36","https://www.vulncheck.com/advisories/yii2-starter-kit-through-4.2.0-unrestricted-file-upload-rce"],"products":["yii2-starter-kit"],"vendors":["yii2-starter-kit"]}},{"cve_id":"CVE-2026-103475","summary":"yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii endpoint to generate and write PHP files into the application directory.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":9.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/yii-starter-kit/yii2-starter-kit","https://github.com/yii-starter-kit/yii2-starter-kit/blob/cc2c451e8c959c7300b04efea597706a38609f58/common/config/web.php#L21","https://github.com/yii-starter-kit/yii2-starter-kit/issues/797","https://www.vulncheck.com/advisories/yii2-starter-kit-through-4.2.0-debug-and-gii-module-exposure"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:17","euvd":{"id":"EUVD-2026-90206","description":"yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii endpoint to generate and write PHP files into the application directory.","published_time":"2026-09-30T17:22:41","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/yii-starter-kit/yii2-starter-kit/issues/797","https://github.com/yii-starter-kit/yii2-starter-kit","https://github.com/yii-starter-kit/yii2-starter-kit/blob/cc2c451e8c959c7300b04efea597706a38609f58/common/config/web.php#L21","https://www.vulncheck.com/advisories/yii2-starter-kit-through-4.2.0-debug-and-gii-module-exposure"],"products":["yii2-starter-kit"],"vendors":["yii2-starter-kit"]}},{"cve_id":"CVE-2026-103476","summary":"yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers can enumerate sequential attachment identifiers to retrieve files from unpublished articles without authentication or authorization checks.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":6.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/yii-starter-kit/yii2-starter-kit","https://github.com/yii-starter-kit/yii2-starter-kit/blob/cc2c451e8c959c7300b04efea597706a38609f58/frontend/controllers/ArticleController.php#L69","https://github.com/yii-starter-kit/yii2-starter-kit/issues/797","https://www.vulncheck.com/advisories/yii2-starter-kit-through-4.2.0-unauthorized-file-download-via-attachment-download"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:17","euvd":{"id":"EUVD-2026-90207","description":"yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers can enumerate sequential attachment identifiers to retrieve files from unpublished articles without authentication or authorization checks.","published_time":"2026-09-30T17:22:42","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/yii-starter-kit/yii2-starter-kit/issues/797","https://github.com/yii-starter-kit/yii2-starter-kit","https://github.com/yii-starter-kit/yii2-starter-kit/blob/cc2c451e8c959c7300b04efea597706a38609f58/frontend/controllers/ArticleController.php#L69","https://www.vulncheck.com/advisories/yii2-starter-kit-through-4.2.0-unauthorized-file-download-via-attachment-download"],"products":["yii2-starter-kit"],"vendors":["yii2-starter-kit"]}},{"cve_id":"CVE-2026-103399","summary":"A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an early final (non-1xx) response before the body is read, the server neither drains the declared body bytes nor closes the connection. On a keep-alive connection, those leftover bytes are interpreted as a subsequent HTTP request. A remote, unauthenticated attacker can place a complete HTTP request in the body and cause SoupServer to process that smuggled request, leading to unintended request handling.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-103399","https://bugzilla.redhat.com/show_bug.cgi?id=2543949"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:16","euvd":{"id":"EUVD-2026-90226","description":"A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and SoupServer returns an early final (non-1xx) response before the body is read, the server neither drains the declared body bytes nor closes the connection. On a keep-alive connection, those leftover bytes are interpreted as a subsequent HTTP request. A remote, unauthenticated attacker can place a complete HTTP request in the body and cause SoupServer to process that smuggled request, leading to unintended request handling.","published_time":"2026-09-30T17:42:31","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-103399","https://bugzilla.redhat.com/show_bug.cgi?id=2543949"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-103437","summary":"Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki ReadingLists extension allows Reflected XSS.\n\nThis issue affects MediaWiki ReadingLists extension: 1.46 and 1.45.","cvss":1.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":1.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gerrit.wikimedia.org/r/q/I9a724c05b2a55845007512422362e02ed8cf44b0","https://phabricator.wikimedia.org/T435863"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:16","euvd":{"id":"EUVD-2026-90201","description":"Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki ReadingLists extension allows Reflected XSS.\n\nThis issue affects MediaWiki ReadingLists extension: 1.46 and 1.45.","published_time":"2026-09-30T17:17:35","cvss":1.1,"cvss_version":"4.0","epss":0.0,"assigner":"wikimedia-foundation","references":["https://phabricator.wikimedia.org/T435863","https://gerrit.wikimedia.org/r/q/I9a724c05b2a55845007512422362e02ed8cf44b0"],"products":["MediaWiki ReadingLists extension","MediaWiki ReadingLists extension"],"vendors":["The Wikimedia Foundation"]}},{"cve_id":"CVE-2026-103438","summary":"Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikistories extension allows Cross-Site Scripting (XSS).\n\nThis issue affects MediaWiki Wikistories extension: 1.46, 1.45, and 1.43.","cvss":0.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":0.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gerrit.wikimedia.org/r/q/Iad1281879723eba73e4338a00d5ff35c6eed0c3e","https://phabricator.wikimedia.org/T182213"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:16","euvd":{"id":"EUVD-2026-90210","description":"Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikistories extension allows Cross-Site Scripting (XSS).\n\nThis issue affects MediaWiki Wikistories extension: 1.46, 1.45, and 1.43.","published_time":"2026-09-30T17:32:26","cvss":0.3,"cvss_version":"4.0","epss":0.0,"assigner":"wikimedia-foundation","references":["https://phabricator.wikimedia.org/T182213","https://gerrit.wikimedia.org/r/q/Iad1281879723eba73e4338a00d5ff35c6eed0c3e"],"products":["MediaWiki Wikistories extension","MediaWiki Wikistories extension","MediaWiki Wikistories extension"],"vendors":["The Wikimedia Foundation"]}},{"cve_id":"CVE-2026-103439","summary":"Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikbase extension allows Cross-Site Scripting (XSS).\n\nThis issue affects MediaWiki Wikbase extension: 1.46, 1.45, and 1.43.","cvss":0.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":0.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gerrit.wikimedia.org/r/q/Ie7a35b211565148e0cae437a4a8c41633b81f1b3","https://phabricator.wikimedia.org/T182213"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:16","euvd":{"id":"EUVD-2026-90211","description":"Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikbase extension allows Cross-Site Scripting (XSS).\n\nThis issue affects MediaWiki Wikbase extension: 1.46, 1.45, and 1.43.","published_time":"2026-09-30T17:34:10","cvss":0.3,"cvss_version":"4.0","epss":0.0,"assigner":"wikimedia-foundation","references":["https://phabricator.wikimedia.org/T182213","https://gerrit.wikimedia.org/r/q/Ie7a35b211565148e0cae437a4a8c41633b81f1b3"],"products":["MediaWiki Wikbase extension","MediaWiki Wikbase extension","MediaWiki Wikbase extension"],"vendors":["The Wikimedia Foundation"]}},{"cve_id":"CVE-2026-103440","summary":"Exposure of sensitive information through data queries vulnerability in The Wikimedia Foundation MediaWiki PageTriage extension allows Information Elicitation.\n\nThis issue affects MediaWiki PageTriage extension: 1.46, 1.45, and 1.43.","cvss":1.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":1.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gerrit.wikimedia.org/r/q/I4bdd5f5be95ed5d02c504784fb31da4e5de59da6","https://phabricator.wikimedia.org/T435623"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:16","euvd":{"id":"EUVD-2026-90212","description":"Exposure of sensitive information through data queries vulnerability in The Wikimedia Foundation MediaWiki PageTriage extension allows Information Elicitation.\n\nThis issue affects MediaWiki PageTriage extension: 1.46, 1.45, and 1.43.","published_time":"2026-09-30T17:38:27","cvss":1.2,"cvss_version":"4.0","epss":0.0,"assigner":"wikimedia-foundation","references":["https://phabricator.wikimedia.org/T435623","https://gerrit.wikimedia.org/r/q/I4bdd5f5be95ed5d02c504784fb31da4e5de59da6"],"products":["MediaWiki PageTriage extension","MediaWiki PageTriage extension","MediaWiki PageTriage extension"],"vendors":["The Wikimedia Foundation"]}},{"cve_id":"CVE-2026-103445","summary":"Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS.\n\nThis issue affects MediaWiki Page_Forms extension: 1.46, 1.45, and 1.43.","cvss":1.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":1.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gerrit.wikimedia.org/r/q/I4ace525a1c1760ecdd1d770380606d9960d3e644","https://phabricator.wikimedia.org/T435622"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:16","euvd":{"id":"EUVD-2026-90196","description":"Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS.\n\nThis issue affects MediaWiki Page_Forms extension: 1.46, 1.45, and 1.43.","published_time":"2026-09-30T17:04:14","cvss":1.2,"cvss_version":"4.0","epss":0.0,"assigner":"wikimedia-foundation","references":["https://phabricator.wikimedia.org/T435622","https://gerrit.wikimedia.org/r/q/I4ace525a1c1760ecdd1d770380606d9960d3e644"],"products":["MediaWiki Page_Forms extension","MediaWiki Page_Forms extension","MediaWiki Page_Forms extension"],"vendors":["The Wikimedia Foundation"]}},{"cve_id":"CVE-2026-102375","summary":"Subscriber Broken Access Control in Optimole <= 4.2.14 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/optimole-wp/vulnerability/wordpress-optimole-plugin-4-2-14-broken-access-control-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:14","euvd":{"id":"EUVD-2026-90221","description":"Subscriber Broken Access Control in Optimole <= 4.2.14 versions.","published_time":"2026-09-30T17:39:05","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/optimole-wp/vulnerability/wordpress-optimole-plugin-4-2-14-broken-access-control-vulnerability?_s_id=cve"],"products":["Optimole"],"vendors":["Optimole"]}},{"cve_id":"CVE-2026-102376","summary":"Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/branda-white-labeling/vulnerability/wordpress-branda-plugin-3-4-32-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:14","euvd":{"id":"EUVD-2026-90222","description":"Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions.","published_time":"2026-09-30T17:39:05","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/branda-white-labeling/vulnerability/wordpress-branda-plugin-3-4-32-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Branda"],"vendors":["WPMU DEV"]}},{"cve_id":"CVE-2026-102377","summary":"Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/photo-gallery/vulnerability/wordpress-photo-gallery-by-10web-plugin-1-8-46-php-object-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:14","euvd":{"id":"EUVD-2026-90223","description":"Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions.","published_time":"2026-09-30T17:39:06","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/photo-gallery/vulnerability/wordpress-photo-gallery-by-10web-plugin-1-8-46-php-object-injection-vulnerability?_s_id=cve"],"products":["Photo Gallery by 10Web"],"vendors":["10web"]}},{"cve_id":"CVE-2026-102391","summary":"Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/jetformbuilder/vulnerability/wordpress-jetformbuilder-plugin-3-6-5-4-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:14","euvd":{"id":"EUVD-2026-90224","description":"Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions.","published_time":"2026-09-30T17:39:07","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/jetformbuilder/vulnerability/wordpress-jetformbuilder-plugin-3-6-5-4-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["JetFormBuilder"],"vendors":["jetmonsters"]}},{"cve_id":"CVE-2026-102392","summary":"Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/woo-extra-product-options/vulnerability/wordpress-extra-product-options-for-woocommerce-custom-product-addons-and-fields-plugin-3-3-8-php-object-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:14","euvd":{"id":"EUVD-2026-90225","description":"Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions.","published_time":"2026-09-30T17:39:08","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/woo-extra-product-options/vulnerability/wordpress-extra-product-options-for-woocommerce-custom-product-addons-and-fields-plugin-3-3-8-php-object-injection-vulnerability?_s_id=cve"],"products":["Extra Product Options For WooCommerce | Custom Product Addons and Fields"],"vendors":["ThemeHigh"]}},{"cve_id":"CVE-2026-102397","summary":"Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/ultimate-maps-by-supsystic/vulnerability/wordpress-ultimate-maps-by-supsystic-plugin-1-5-5-broken-access-control-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:18:14","euvd":{"id":"EUVD-2026-90213","description":"Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions.","published_time":"2026-09-30T17:38:58","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/ultimate-maps-by-supsystic/vulnerability/wordpress-ultimate-maps-by-supsystic-plugin-1-5-5-broken-access-control-vulnerability?_s_id=cve"],"products":["Ultimate Maps by Supsystic"],"vendors":["Supsystic"]}},{"cve_id":"CVE-2026-100510","summary":"Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/post-and-page-builder/vulnerability/wordpress-post-and-page-builder-by-boldgrid-plugin-1-27-14-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:17:59","euvd":{"id":"EUVD-2026-90219","description":"Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions.","published_time":"2026-09-30T17:39:03","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/post-and-page-builder/vulnerability/wordpress-post-and-page-builder-by-boldgrid-plugin-1-27-14-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Post and Page Builder by BoldGrid"],"vendors":["boldgrid"]}},{"cve_id":"CVE-2026-100512","summary":"Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/wp-nested-pages/vulnerability/wordpress-nested-pages-plugin-3-3-2-php-object-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T18:17:59","euvd":{"id":"EUVD-2026-90220","description":"Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.","published_time":"2026-09-30T17:39:04","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/wp-nested-pages/vulnerability/wordpress-nested-pages-plugin-3-3-2-php-object-injection-vulnerability?_s_id=cve"],"products":["Nested Pages"],"vendors":["Hook & Filter"]}},{"cve_id":"CVE-2026-62308","summary":"Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through the notification test endpoint. The /settings/test_notification endpoint accepts a urls field and passes it directly to Apprise without restricting protocols, hostnames, localhost addresses, private IP ranges, or cloud metadata addresses. This can be abused as an authenticated blind server-side request forgery (SSRF). This issue has been patched in version 1.30.6.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Quenary/tugtainer/commit/c0294d0ab64985b135d0c5b566ac30bf8371f9c3","https://github.com/Quenary/tugtainer/releases/tag/v1.30.6","https://github.com/Quenary/tugtainer/security/advisories/GHSA-c2h5-ppv9-7vrq","https://github.com/Quenary/tugtainer/security/advisories/GHSA-c2h5-ppv9-7vrq"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T17:16:49","euvd":{"id":"EUVD-2026-90194","description":"Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through the notification test endpoint. The /settings/test_notification endpoint accepts a urls field and passes it directly to Apprise without restricting protocols, hostnames, localhost addresses, private IP ranges, or cloud metadata addresses. This can be abused as an authenticated blind server-side request forgery (SSRF). This issue has been patched in version 1.30.6.","published_time":"2026-09-30T16:59:31","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/Quenary/tugtainer/security/advisories/GHSA-c2h5-ppv9-7vrq","https://github.com/Quenary/tugtainer/commit/c0294d0ab64985b135d0c5b566ac30bf8371f9c3","https://github.com/Quenary/tugtainer/releases/tag/v1.30.6"],"products":["tugtainer"],"vendors":["Quenary"]}},{"cve_id":"CVE-2026-75969","summary":"Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device without administrator credentials.\n\n\n\nThis vulnerability allows attackers to upload modified firmware to the device without admin credentials. This issue affects:\n\n\n\n\n\n  *  Move 4K 12X before: 0.0.98\n  *  Move 4K 20X before: 0.1.33\n  *  Move 4K 30X before: 2.1.17\n  *  Link 4K 12X before: 0.0.99\n  *  Link 4K 20X before: 0.1.37\n  *  Link 4K 30X before: 2.1.18\n  *  Move SE 12X before: 9.1.66\n  *  Move SE 20X before: 9.1.44\n  *  Move SE 30X before: 9.1.46\n  *  Studio 4K 12X before: 8.3.32\n  *  Studio 4K 20X before: 8.3.32\n  *  Studio SE 12X before: 8.3.32\n  *  Studio SE 20X before: 8.3.32\n  *  All Generation 2 cameras, including: PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2; PT12X-USB-GY-G2, PT12X-USB-WH-G2; PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2; PT20X-USB-GY-G2, PT20X-USB-WH-G2; PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2; PTVL-ZCAM, PTVL-NDI-ZCAM; PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2; PT12X-ZCAM, PT12X-NDI-ZCAM; PT20X-ZCAM, PT20X-NDI-ZCAM; Studio Pro - All versions\n  *  Upgrade Tool - All versions","cvss":9.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://psirt.havsys.com/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T17:16:49","euvd":{"id":"EUVD-2026-90084","description":"Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device without administrator credentials.\n\n\n\nThis vulnerability allows attackers to upload modified firmware to the device without admin credentials. This issue affects:\n\n\n\n\n\n  *  Move 4K 12X before: 0.0.98\n  *  Move 4K 20X before: 0.1.33\n  *  Move 4K 30X before: 2.1.17\n  *  Link 4K 12X before: 0.0.99\n  *  Link 4K 20X before: 0.1.37\n  *  Link 4K 30X before: 2.1.18\n  *  Move SE 12X before: 9.1.66\n  *  Move SE 20X before: 9.1.44\n  *  Move SE 30X before: 9.1.46\n  *  Studio 4K 12X before: 8.3.32\n  *  Studio 4K 20X before: 8.3.32\n  *  Studio SE 12X before: 8.3.32\n  *  Studio SE 20X before: 8.3.32\n  *  All Generation 2 cameras, including: PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2; PT12X-USB-GY-G2, PT12X-USB-WH-G2; PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2; PT20X-USB-GY-G2, PT20X-USB-WH-G2; PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2; PTVL-ZCAM, PTVL-NDI-ZCAM; PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2; PT12X-ZCAM, PT12X-NDI-ZCAM; PT20X-ZCAM, PT20X-NDI-ZCAM; Studio Pro - All versions\n  *  Upgrade Tool - All versions","published_time":"2026-09-30T16:27:51","cvss":9.1,"cvss_version":"4.0","epss":0.0,"assigner":"hsi","references":["https://psirt.havsys.com/"],"products":["Move SE 30X","PTEPTZ-ZCAM-G2, PTEPTZ-NDI-ZCAM-G2","Studio 4K 20X","Move 4K 20X","PT12X-USB-GY-G2, PT12X-USB-WH-G2","Move SE 20X","PT12X-SDI-GY-G2, PT12X-SDI-WH-G2, PT12X-NDI-GY-G2, PT12X-NDI-WH-G2","Link 4K 30X","Studio 4K 12X","Studio Pro","Move SE 12X","Link 4K 20X","PT12X-ZCAM, PT12X-NDI-ZCAM","PT20X-USB-GY-G2, PT20X-USB-WH-G2","PT30X-SDI-GY-G2, PT30X-SDI-WH-G2, PT30X-NDI-GY-G2, PT30X-NDI-WH-G2","PTVL-ZCAM, PTVL-NDI-ZCAM","Studio SE 12X","Upgrade Tool","Link 4K 12X","Studio SE 20X","PT20X-SDI-GY-G2, PT20X-SDI-WH-G2, PT20X-NDI-GY-G2, PT20X-NDI-WH-G2","Move 4K 12X","Move 4K 30X","PT20X-ZCAM, PT20X-NDI-ZCAM"],"vendors":["PTZOptics"]}},{"cve_id":"CVE-2026-55494","summary":"Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not configured. The Agent uses request signatures to protect its API routes. However, in agent/auth.py, the signature verification function returns successfully if Config.AGENT_SECRET is empty. This causes protected Agent APIs to become accessible without authentication. This issue has been patched in version 1.30.4.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Quenary/tugtainer/commit/0052a5544e187a4d12f771838a8a23ca4afb61cd","https://github.com/Quenary/tugtainer/releases/tag/v1.30.4","https://github.com/Quenary/tugtainer/security/advisories/GHSA-wgw2-c96g-p7h7","https://github.com/Quenary/tugtainer/security/advisories/GHSA-wgw2-c96g-p7h7"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T17:16:47","euvd":{"id":"EUVD-2026-90193","description":"Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not configured. The Agent uses request signatures to protect its API routes. However, in agent/auth.py, the signature verification function returns successfully if Config.AGENT_SECRET is empty. This causes protected Agent APIs to become accessible without authentication. This issue has been patched in version 1.30.4.","published_time":"2026-09-30T16:58:27","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/Quenary/tugtainer/security/advisories/GHSA-wgw2-c96g-p7h7","https://github.com/Quenary/tugtainer/commit/0052a5544e187a4d12f771838a8a23ca4afb61cd","https://github.com/Quenary/tugtainer/releases/tag/v1.30.4"],"products":["tugtainer"],"vendors":["Quenary"]}},{"cve_id":"CVE-2026-46711","summary":"Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 inside each sm-ws-* Fly Machine exposes endpoints (/health, /file/<path>, /archive/<dir>) without any authentication or origin check. Any host that can reach TCP/8080 on a workspace can read arbitrary files under that workspace's /workspace root and download whole project trees as tar archives. Because every workspace shares the same Fly private 6PN and resolves all peer addresses via the unauthenticated _instances.internal TXT record, every other sm-ws-* machine on the same Fly app/org is a reachable, unauthenticated attacker — the trust boundary (workspace owner ↔ everyone-else) is missing. At time of publication, there are no publicly known patches.","cvss":8.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Soft-Machine-io/security/security/advisories/GHSA-h6g6-qr45-qmrr","https://github.com/Soft-Machine-io/security/security/advisories/GHSA-h6g6-qr45-qmrr"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T17:16:46","euvd":{"id":"EUVD-2026-90085","description":"Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 inside each sm-ws-* Fly Machine exposes endpoints (/health, /file/<path>, /archive/<dir>) without any authentication or origin check. Any host that can reach TCP/8080 on a workspace can read arbitrary files under that workspace's /workspace root and download whole project trees as tar archives. Because every workspace shares the same Fly private 6PN and resolves all peer addresses via the unauthenticated _instances.internal TXT record, every other sm-ws-* machine on the same Fly app/org is a reachable, unauthenticated attacker — the trust boundary (workspace owner ↔ everyone-else) is missing. At time of publication, there are no publicly known patches.","published_time":"2026-09-30T16:30:02","cvss":8.3,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/Soft-Machine-io/security/security/advisories/GHSA-h6g6-qr45-qmrr"],"products":["security"],"vendors":["Soft-Machine-io"]}},{"cve_id":"CVE-2026-55176","summary":"Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and authenticateWorkspaceHttp() — accept the global CONTAINER_SHARED_SECRET as a bearer token without verifying which workspace the caller belongs to. Because that secret is set identically on every container in the Fly app and is reachable from the user-facing process environment inside each workspace, any tenant can use it to authenticate to any other tenant's workspace API. The result is cross-workspace read, write, and destructive-restore primitives reachable from any paying customer's shell. The existing per-workspace token check (workspaceTokenMatches) protects the user-facing per-workspace token path, but the shared-secret bearer path bypasses it entirely. At time of publication, there are no publicly known patches.","cvss":9.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.0,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Soft-Machine-io/security/security/advisories/GHSA-63gh-vp9f-vxhj"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T17:16:46","euvd":{"id":"EUVD-2026-90190","description":"Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and authenticateWorkspaceHttp() — accept the global CONTAINER_SHARED_SECRET as a bearer token without verifying which workspace the caller belongs to. Because that secret is set identically on every container in the Fly app and is reachable from the user-facing process environment inside each workspace, any tenant can use it to authenticate to any other tenant's workspace API. The result is cross-workspace read, write, and destructive-restore primitives reachable from any paying customer's shell. The existing per-workspace token check (workspaceTokenMatches) protects the user-facing per-workspace token path, but the shared-secret bearer path bypasses it entirely. At time of publication, there are no publicly known patches.","published_time":"2026-09-30T16:30:42","cvss":9.0,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/Soft-Machine-io/security/security/advisories/GHSA-63gh-vp9f-vxhj"],"products":["security"],"vendors":["Soft-Machine-io"]}},{"cve_id":"CVE-2026-55177","summary":"CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to version 13.10.0, every route in the ESRI helper family (api/routes/esri.ts) takes a fully attacker-controlled URL from the request (POST /api/esri body url, and the portal / server / layer query parameters on the GET /api/esri/* routes) and passes it into EsriBase / EsriProxyPortal / EsriProxyServer / EsriProxyLayer in api/lib/esri.ts, which fetch it with the bare fetch from @tak-ps/etl. No IP / DNS / hostname classification is applied at any point, so the destination is never validated against private, loopback, or link-local ranges. Any authenticated user (the routes only require Auth.is_auth(config, req, { anyResources: true }), i.e. any token, not an admin) can therefore make the CloudTAK server issue arbitrary outbound GET/POST requests to internal addresses such as the cloud instance-metadata service (169.254.169.254), loopback admin ports (127.0.0.1:<port>), and other hosts reachable only from inside the deployment VPC. This is a full-read SSRF, not blind: on success the upstream JSON body is returned to the caller via res.json(...), and on failure the upstream error string is reflected verbatim as ESRI Server Error: <message>. An attacker can read cloud metadata (and the temporary IAM credentials the instance role exposes), enumerate internal services, and exfiltrate their response bodies. The sniff() URL classifier provides no protection: it only pattern-matches the pathname (/rest, /arcgis/rest, /sharing/rest), so a URL like http://169.254.169.254/arcgis/rest or http://127.0.0.1:8500/rest passes sniff() and is fetched. This issue has been patched in version 13.10.0.","cvss":7.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/dfpc-coe/CloudTAK/releases/tag/v13.10.0","https://github.com/dfpc-coe/CloudTAK/security/advisories/GHSA-r95q-fp26-h3hc","https://github.com/dfpc-coe/CloudTAK/security/advisories/GHSA-r95q-fp26-h3hc"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T17:16:46","euvd":{"id":"EUVD-2026-90083","description":"CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to version 13.10.0, every route in the ESRI helper family (api/routes/esri.ts) takes a fully attacker-controlled URL from the request (POST /api/esri body url, and the portal / server / layer query parameters on the GET /api/esri/* routes) and passes it into EsriBase / EsriProxyPortal / EsriProxyServer / EsriProxyLayer in api/lib/esri.ts, which fetch it with the bare fetch from @tak-ps/etl. No IP / DNS / hostname classification is applied at any point, so the destination is never validated against private, loopback, or link-local ranges. Any authenticated user (the routes only require Auth.is_auth(config, req, { anyResources: true }), i.e. any token, not an admin) can therefore make the CloudTAK server issue arbitrary outbound GET/POST requests to internal addresses such as the cloud instance-metadata service (169.254.169.254), loopback admin ports (127.0.0.1:<port>), and other hosts reachable only from inside the deployment VPC. This is a full-read SSRF, not blind: on success the upstream JSON body is returned to the caller via res.json(...), and on failure the upstream error string is reflected verbatim as ESRI Server Error: <message>. An attacker can read cloud metadata (and the temporary IAM credentials the instance role exposes), enumerate internal services, and exfiltrate their response bodies. The sniff() URL classifier provides no protection: it only pattern-matches the pathname (/rest, /arcgis/rest, /sharing/rest), so a URL like http://169.254.169.254/arcgis/rest or http://127.0.0.1:8500/rest passes sniff() and is fetched. This issue has been patched in version 13.10.0.","published_time":"2026-09-30T16:25:02","cvss":7.6,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/dfpc-coe/CloudTAK/security/advisories/GHSA-r95q-fp26-h3hc","https://github.com/dfpc-coe/CloudTAK/releases/tag/v13.10.0"],"products":["CloudTAK"],"vendors":["dfpc-coe"]}},{"cve_id":"CVE-2026-55181","summary":"Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc/enabled endpoint correctly reports that OIDC is disabled. However, a direct request to /auth/oidc/login still starts the OIDC login flow, returns HTTP 302, sets an oidc_state cookie, and redirects the user to the configured OIDC authorization endpoint. This bypasses the intended OIDC disable switch. This issue has been patched in version 1.30.3.","cvss":9.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Quenary/tugtainer/commit/76371db679334b002d4af544b0f3b8587ad86f52","https://github.com/Quenary/tugtainer/releases/tag/v1.30.3","https://github.com/Quenary/tugtainer/security/advisories/GHSA-rg7c-vpfp-2w43","https://github.com/Quenary/tugtainer/security/advisories/GHSA-rg7c-vpfp-2w43"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T17:16:46","euvd":{"id":"EUVD-2026-90192","description":"Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc/enabled endpoint correctly reports that OIDC is disabled. However, a direct request to /auth/oidc/login still starts the OIDC login flow, returns HTTP 302, sets an oidc_state cookie, and redirects the user to the configured OIDC authorization endpoint. This bypasses the intended OIDC disable switch. This issue has been patched in version 1.30.3.","published_time":"2026-09-30T16:57:15","cvss":9.4,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/Quenary/tugtainer/security/advisories/GHSA-rg7c-vpfp-2w43","https://github.com/Quenary/tugtainer/commit/76371db679334b002d4af544b0f3b8587ad86f52","https://github.com/Quenary/tugtainer/releases/tag/v1.30.3"],"products":["tugtainer"],"vendors":["Quenary"]}},{"cve_id":"CVE-2026-19445","summary":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected.","cvss":9.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T17:16:45","euvd":{"id":"EUVD-2026-90077","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected.","published_time":"2026-09-30T16:16:04","cvss":9.2,"cvss_version":"4.0","epss":0.0,"assigner":"PSF","references":["https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c"],"products":["CPython","CPython","CPython","CPython"],"vendors":["Python Software Foundation"]}},{"cve_id":"CVE-2026-19553","summary":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied.","cvss":7.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T17:16:45","euvd":{"id":"EUVD-2026-90078","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied.","published_time":"2026-09-30T16:17:39","cvss":7.6,"cvss_version":"4.0","epss":0.0,"assigner":"PSF","references":["https://github.com/python/cpython/pull/158503","https://github.com/python/cpython/issues/156793","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed"],"products":["CPython","CPython","CPython","CPython"],"vendors":["Python Software Foundation"]}},{"cve_id":"CVE-2026-103443","summary":"Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Collection (Book) extension allows XSS Targeting Non-Script Elements.\n\nThis issue affects MediaWiki Collection (Book) extension: 1.46, 1.45, and 1.43.","cvss":1.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":1.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gerrit.wikimedia.org/r/q/I51d973d4ace99fb6e584296f296efb0ff50339ce","https://phabricator.wikimedia.org/T435822"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T17:16:43","euvd":{"id":"EUVD-2026-90079","description":"Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Collection (Book) extension allows XSS Targeting Non-Script Elements.\n\nThis issue affects MediaWiki Collection (Book) extension: 1.46, 1.45, and 1.43.","published_time":"2026-09-30T16:19:16","cvss":1.1,"cvss_version":"4.0","epss":0.0,"assigner":"wikimedia-foundation","references":["https://phabricator.wikimedia.org/T435822","https://gerrit.wikimedia.org/r/q/I51d973d4ace99fb6e584296f296efb0ff50339ce"],"products":["MediaWiki Collection (Book) extension","MediaWiki Collection (Book) extension","MediaWiki Collection (Book) extension"],"vendors":["The Wikimedia Foundation"]}},{"cve_id":"CVE-2026-103444","summary":"Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki WikiForum extension allows Stored XSS.\n\nThis issue affects MediaWiki WikiForum extension: master.","cvss":1.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":1.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gerrit.wikimedia.org/r/q/I7849ef0f9c3eff48fd63e47e5b8affc3b25bb4dd","https://phabricator.wikimedia.org/T414227"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T17:16:43","euvd":{"id":"EUVD-2026-90082","description":"Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki WikiForum extension allows Stored XSS.\n\nThis issue affects MediaWiki WikiForum extension: master.","published_time":"2026-09-30T16:23:56","cvss":1.1,"cvss_version":"4.0","epss":0.0,"assigner":"wikimedia-foundation","references":["https://phabricator.wikimedia.org/T414227","https://gerrit.wikimedia.org/r/q/I7849ef0f9c3eff48fd63e47e5b8affc3b25bb4dd"],"products":["MediaWiki WikiForum extension"],"vendors":["The Wikimedia Foundation"]}},{"cve_id":"CVE-2026-103232","summary":"A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/table_booking.php. This manipulation of the argument Name causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.","cvss":5.5,"cvss_version":4.0,"cvss_v2":7.5,"cvss_v3":7.3,"cvss_v4":5.5,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/AdithyaYelloju/Restaurant-Management-System/","https://github.com/AdithyaYelloju/Restaurant-Management-System/issues/8","https://vuldb.com/cve/CVE-2026-103232","https://vuldb.com/submit/955081","https://vuldb.com/vuln/411926","https://vuldb.com/vuln/411926/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T17:16:42","euvd":{"id":"EUVD-2026-90076","description":"A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/table_booking.php. This manipulation of the argument Name causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.","published_time":"2026-09-30T16:15:11","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411926","https://vuldb.com/vuln/411926/cti","https://vuldb.com/cve/CVE-2026-103232","https://vuldb.com/submit/955081","https://github.com/AdithyaYelloju/Restaurant-Management-System/issues/8","https://github.com/AdithyaYelloju/Restaurant-Management-System/"],"products":["Restaurant-Management-System"],"vendors":["AdithyaYelloju"]}},{"cve_id":"CVE-2026-103233","summary":"A security vulnerability has been detected in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This impacts an unknown function of the file /admin/ of the component Admin Area. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.","cvss":2.1,"cvss_version":4.0,"cvss_v2":6.5,"cvss_v3":6.3,"cvss_v4":2.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/AdithyaYelloju/Restaurant-Management-System/","https://github.com/AdithyaYelloju/Restaurant-Management-System/issues/9","https://vuldb.com/cve/CVE-2026-103233","https://vuldb.com/submit/955096","https://vuldb.com/vuln/411927","https://vuldb.com/vuln/411927/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T17:16:42","euvd":{"id":"EUVD-2026-90086","description":"A security vulnerability has been detected in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This impacts an unknown function of the file /admin/ of the component Admin Area. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.","published_time":"2026-09-30T16:30:09","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411927","https://vuldb.com/vuln/411927/cti","https://vuldb.com/cve/CVE-2026-103233","https://vuldb.com/submit/955096","https://github.com/AdithyaYelloju/Restaurant-Management-System/issues/9","https://github.com/AdithyaYelloju/Restaurant-Management-System/"],"products":["Restaurant-Management-System"],"vendors":["AdithyaYelloju"]}},{"cve_id":"CVE-2026-103241","summary":"A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file rust/src/parser/src/unified/gemma4.rs of the component Gemma4UnifiedParser. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 0.29.1rc0 is able to resolve this issue. This patch is called 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9. Upgrading the affected component is advised.","cvss":5.5,"cvss_version":4.0,"cvss_v2":5.0,"cvss_v3":5.3,"cvss_v4":5.5,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/Yunzez/8e98d656aa667095b513161eb056d28e","https://github.com/vllm-project/vllm/","https://github.com/vllm-project/vllm/commit/3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9","https://github.com/vllm-project/vllm/issues/50927","https://github.com/vllm-project/vllm/pull/54303","https://github.com/vllm-project/vllm/releases/tag/v0.29.1rc0","https://vuldb.com/cve/CVE-2026-103241","https://vuldb.com/submit/956250","https://vuldb.com/vuln/411965","https://vuldb.com/vuln/411965/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T17:16:42","euvd":{"id":"EUVD-2026-90191","description":"A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file rust/src/parser/src/unified/gemma4.rs of the component Gemma4UnifiedParser. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 0.29.1rc0 is able to resolve this issue. This patch is called 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9. Upgrading the affected component is advised.","published_time":"2026-09-30T16:45:13","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411965","https://vuldb.com/vuln/411965/cti","https://vuldb.com/cve/CVE-2026-103241","https://vuldb.com/submit/956250","https://github.com/vllm-project/vllm/issues/50927","https://github.com/vllm-project/vllm/pull/54303","https://gist.github.com/Yunzez/8e98d656aa667095b513161eb056d28e","https://github.com/vllm-project/vllm/commit/3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9","https://github.com/vllm-project/vllm/releases/tag/v0.29.1rc0","https://github.com/vllm-project/vllm/"],"products":["vllm","vllm","vllm","vllm","vllm","vllm","vllm","vllm","vllm","vllm","vllm","vllm","vllm","vllm","vllm","vllm","vllm","vllm","vllm","vllm","vllm","vllm","vllm","vllm","vllm","vllm"],"vendors":["vllm-project"]}},{"cve_id":"CVE-2026-102489","summary":"Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.","cvss":9.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.4,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://csirt.divd.nl/CVE-2026-102489","https://csirt.divd.nl/DIVD-2026-00015"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T17:16:40","euvd":{"id":"EUVD-2026-90080","description":"Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.","published_time":"2026-09-30T16:21:19","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"DIVD","references":["https://csirt.divd.nl/DIVD-2026-00015","https://csirt.divd.nl/CVE-2026-102489"],"products":["Zammad"],"vendors":["Zammad GmbH"]}},{"cve_id":"CVE-2026-102490","summary":"All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.","cvss":9.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.4,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://csirt.divd.nl/CVE-2026-102490","https://csirt.divd.nl/DIVD-2026-00015"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T17:16:40","euvd":{"id":"EUVD-2026-90081","description":"All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.","published_time":"2026-09-30T16:21:20","cvss":8.5,"cvss_version":"4.0","epss":0.0,"assigner":"DIVD","references":["https://csirt.divd.nl/DIVD-2026-00015","https://csirt.divd.nl/CVE-2026-102490"],"products":["Zammad"],"vendors":["Zammad GmbH"]}},{"cve_id":"CVE-2026-80490","summary":"Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified.\n\nThe matches, first_match and match_details methods use the T_STD_STRING typemap to translate Perl scalars (SVs) into strings via the std::string constructor, using the SvPV macro to stringify the haystack input, and the SvCUR macro to determine the length of the SV.\n\nWhen the input SVs are references, integers (IVs) or floats (NVs), the SvCUR macro will return an invalid length if it is run before the input is stringified, leading to an out-of-bounds read which can abort the process.\n\nNote that the evaluation order of arguments to std::string is unspecified. Depending on the compiler, SvCUR may be run first and lead to an abort that cannot be caught within Perl.\n\nThis can be triggered when the haystack is a numeric value, for example,\n\n    my $ac = Algorithm::AhoCorasick::XS->new( [ \"11\", \"22\" ] );\n    $ac->matches( 211 );\n\nThis can occur when the haystack is the result of reading data from decoded JSON or a numeric database column. It can also be triggered when using a blessed object as a haystack.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/richardjharris/Algorithm-AhoCorasick-XS/pull/1","https://metacpan.org/release/RJH/Algorithm-AhoCorasick-XS-0.04/source/typemap#L14","https://rt.cpan.org/Ticket/Display.html?id=181560","https://security.metacpan.org/patches/A/Algorithm-AhoCorasick-XS/0.04/CVE-2026-80490-r1.patch","http://www.openwall.com/lists/oss-security/2026/09/30/15"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:19:10","euvd":{"id":"EUVD-2026-90025","description":"Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified.\n\nThe matches, first_match and match_details methods use the T_STD_STRING typemap to translate Perl scalars (SVs) into strings via the std::string constructor, using the SvPV macro to stringify the haystack input, and the SvCUR macro to determine the length of the SV.\n\nWhen the input SVs are references, integers (IVs) or floats (NVs), the SvCUR macro will return an invalid length if it is run before the input is stringified, leading to an out-of-bounds read which can abort the process.\n\nNote that the evaluation order of arguments to std::string is unspecified. Depending on the compiler, SvCUR may be run first and lead to an abort that cannot be caught within Perl.\n\nThis can be triggered when the haystack is a numeric value, for example,\n\n    my $ac = Algorithm::AhoCorasick::XS->new( [ \"11\", \"22\" ] );\n    $ac->matches( 211 );\n\nThis can occur when the haystack is the result of reading data from decoded JSON or a numeric database column. It can also be triggered when using a blessed object as a haystack.","published_time":"2026-09-30T15:20:45","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"CPANSec","references":["https://rt.cpan.org/Ticket/Display.html?id=181560","https://metacpan.org/release/RJH/Algorithm-AhoCorasick-XS-0.04/source/typemap#L14","https://github.com/richardjharris/Algorithm-AhoCorasick-XS/pull/1","https://security.metacpan.org/patches/A/Algorithm-AhoCorasick-XS/0.04/CVE-2026-80490-r1.patch"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-47604","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user may access another process's GPU channel state due to missing authorization checks. A successful exploit of this vulnerability might lead to information disclosure.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47604","https://www.cve.org/CVERecord?id=CVE-2026-47604"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:31","euvd":{"id":"EUVD-2026-90181","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user may access another process's GPU channel state due to missing authorization checks. A successful exploit of this vulnerability might lead to information disclosure.","published_time":"2026-09-30T15:54:18","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47604","https://www.cve.org/CVERecord?id=CVE-2026-47604","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Tesla","Guest driver","RTX, Quadro, NVS","Guest driver","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Virtual GPU Manager","GeForce","Tesla","Virtual GPU Manager","RTX, Quadro, NVS","Guest driver","RTX, Quadro, NVS","GeForce","Guest driver","Tesla","GeForce","Tesla","GeForce","Virtual GPU Manager","RTX, Quadro, NVS","GeForce","GeForce","Virtual GPU Manager","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-55174","summary":"UltrafastSecp256k1 is a high-performance, multi-backend secp256k1 engine with reproducible audit evidence, compatibility shims, and profile-based review scopes. Prior to version 4.2.0, UltrafastSecp256k1's ECDSA adaptor pre-signature verification accepts forged adaptor pre-signatures whose \"r\" value is not cryptographically bound to the adaptor point \"T\". This issue has been patched in version 4.2.0.","cvss":5.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/shrec/UltrafastSecp256k1/commit/5478ef566c6af91b48a45c0c61f161f5b1071981","https://github.com/shrec/UltrafastSecp256k1/releases/tag/v4.2.0","https://github.com/shrec/UltrafastSecp256k1/releases/tag/v4.2.1","https://github.com/shrec/UltrafastSecp256k1/security/advisories/GHSA-c7q2-gv3g-rgxm","https://github.com/shrec/UltrafastSecp256k1/security/advisories/GHSA-c7q2-gv3g-rgxm"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:31","euvd":{"id":"EUVD-2026-90188","description":"UltrafastSecp256k1 is a high-performance, multi-backend secp256k1 engine with reproducible audit evidence, compatibility shims, and profile-based review scopes. Prior to version 4.2.0, UltrafastSecp256k1's ECDSA adaptor pre-signature verification accepts forged adaptor pre-signatures whose \"r\" value is not cryptographically bound to the adaptor point \"T\". This issue has been patched in version 4.2.0.","published_time":"2026-09-30T15:49:10","cvss":5.9,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/shrec/UltrafastSecp256k1/security/advisories/GHSA-c7q2-gv3g-rgxm","https://github.com/shrec/UltrafastSecp256k1/commit/5478ef566c6af91b48a45c0c61f161f5b1071981","https://github.com/shrec/UltrafastSecp256k1/releases/tag/v4.2.0","https://github.com/shrec/UltrafastSecp256k1/releases/tag/v4.2.1"],"products":["UltrafastSecp256k1"],"vendors":["shrec"]}},{"cve_id":"CVE-2026-47598","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module event delivery path where an unprivileged local user could cause a use-after-free through a race between asynchronous event delivery and file close. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.","cvss":7.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.0,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47598","https://www.cve.org/CVERecord?id=CVE-2026-47598"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:30","euvd":{"id":"EUVD-2026-90148","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module event delivery path where an unprivileged local user could cause a use-after-free through a race between asynchronous event delivery and file close. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.","published_time":"2026-09-30T15:52:23","cvss":7.0,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47598","https://www.cve.org/CVERecord?id=CVE-2026-47598","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","GeForce","RTX, Quadro, NVS","Guest driver","Tesla","GeForce","RTX, Quadro, NVS","Guest driver","Virtual GPU Manager","Tesla","GeForce","GeForce","RTX, Quadro, NVS","Virtual GPU Manager","Tesla","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47599","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module where an unprivileged local user could cause improper preservation of memory access permissions during DMA mapping. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47599","https://www.cve.org/CVERecord?id=CVE-2026-47599"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:30","euvd":{"id":"EUVD-2026-90139","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module where an unprivileged local user could cause improper preservation of memory access permissions during DMA mapping. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.","published_time":"2026-09-30T15:51:22","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47599","https://www.cve.org/CVERecord?id=CVE-2026-47599","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","Tesla","RTX, Quadro, NVS","GeForce","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","GeForce","Tesla","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47600","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an error-handling path could operate on an improperly initialized resource. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47600","https://www.cve.org/CVERecord?id=CVE-2026-47600"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:30","euvd":{"id":"EUVD-2026-90140","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an error-handling path could operate on an improperly initialized resource. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.","published_time":"2026-09-30T15:51:23","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47600","https://www.cve.org/CVERecord?id=CVE-2026-47600","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","GeForce","Tesla","Tesla","GeForce","GeForce","GeForce","Guest driver","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Tesla","Guest driver","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Tesla","Tesla","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47601","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module DMA-BUF import path where an unprivileged local user could cause improper preservation of memory access permissions when importing a read-only buffer from another device's DMA-BUF exporter. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47601","https://www.cve.org/CVERecord?id=CVE-2026-47601"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:30","euvd":{"id":"EUVD-2026-90141","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module DMA-BUF import path where an unprivileged local user could cause improper preservation of memory access permissions when importing a read-only buffer from another device's DMA-BUF exporter. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.","published_time":"2026-09-30T15:51:24","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47601","https://www.cve.org/CVERecord?id=CVE-2026-47601","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","GeForce","GeForce","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","GeForce","Tesla","GeForce","Tesla","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","Tesla","GeForce","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47602","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user can cause the driver to dereference an untrusted pointer. A successful exploit of this vulnerability might lead to denial of service and information disclosure.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47602","https://www.cve.org/CVERecord?id=CVE-2026-47602"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:30","euvd":{"id":"EUVD-2026-90145","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user can cause the driver to dereference an untrusted pointer. A successful exploit of this vulnerability might lead to denial of service and information disclosure.","published_time":"2026-09-30T15:51:38","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47602","https://www.cve.org/CVERecord?id=CVE-2026-47602","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","GeForce","GeForce","Tesla","Virtual GPU Manager","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","GeForce","Tesla","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","Virtual GPU Manager","RTX, Quadro, NVS","GeForce","Virtual GPU Manager","Virtual GPU Manager","Tesla","RTX, Quadro, NVS","GeForce","Tesla","GeForce","Tesla","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47603","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user may access another process's GPU channel state due to missing authorization checks. A successful exploit of this vulnerability might lead to information disclosure.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47603","https://www.cve.org/CVERecord?id=CVE-2026-47603"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:30","euvd":{"id":"EUVD-2026-90180","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user may access another process's GPU channel state due to missing authorization checks. A successful exploit of this vulnerability might lead to information disclosure.","published_time":"2026-09-30T15:54:16","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47603","https://www.cve.org/CVERecord?id=CVE-2026-47603","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","Guest driver","Guest driver","GeForce","RTX, Quadro, NVS","Tesla","GeForce","Guest driver","RTX, Quadro, NVS","Tesla","GeForce","Virtual GPU Manager","GeForce","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","Tesla","Virtual GPU Manager","RTX, Quadro, NVS","GeForce","Tesla","Tesla","RTX, Quadro, NVS","Virtual GPU Manager","RTX, Quadro, NVS","Guest driver","Virtual GPU Manager","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47591","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could bypass read-only memory protection due to incorrect authorization, enabling write access to memory marked read-only. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47591","https://www.cve.org/CVERecord?id=CVE-2026-47591"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:29","euvd":{"id":"EUVD-2026-90133","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could bypass read-only memory protection due to incorrect authorization, enabling write access to memory marked read-only. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:51:06","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47591","https://www.cve.org/CVERecord?id=CVE-2026-47591","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","RTX, Quadro, NVS","GeForce","Tesla","Virtual GPU Manager","GeForce","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","Tesla","Virtual GPU Manager","Tesla","RTX, Quadro, NVS","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47592","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47592","https://www.cve.org/CVERecord?id=CVE-2026-47592"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:29","euvd":{"id":"EUVD-2026-90134","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:51:08","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47592","https://www.cve.org/CVERecord?id=CVE-2026-47592","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","Tesla","Tesla","GeForce","Guest driver","RTX, Quadro, NVS","Tesla","Virtual GPU Manager","Tesla","RTX, Quadro, NVS","GeForce","GeForce","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","GeForce","Guest driver","Virtual GPU Manager","Tesla","RTX, Quadro, NVS","Tesla","GeForce","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47593","summary":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an unprivileged user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, and denial of service.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47593","https://www.cve.org/CVERecord?id=CVE-2026-47593"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:29","euvd":{"id":"EUVD-2026-90135","description":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an unprivileged user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, and denial of service.","published_time":"2026-09-30T15:51:17","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47593","https://www.cve.org/CVERecord?id=CVE-2026-47593","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","Tesla","GeForce","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Guest driver","GeForce","Guest driver","RTX, Quadro, NVS","GeForce","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47594","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by issuing a sequence of driver commands. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, data tampering, and information disclosure.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47594","https://www.cve.org/CVERecord?id=CVE-2026-47594"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:29","euvd":{"id":"EUVD-2026-90136","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by issuing a sequence of driver commands. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, data tampering, and information disclosure.","published_time":"2026-09-30T15:51:19","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47594","https://www.cve.org/CVERecord?id=CVE-2026-47594","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Guest driver","RTX, Quadro, NVS","Guest driver","Tesla","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Virtual GPU Manager","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","GeForce","GeForce","GeForce","GeForce","GeForce","Virtual GPU Manager","Tesla","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47595","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can write to read-only memory because the memory's permissions are not preserved. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47595","https://www.cve.org/CVERecord?id=CVE-2026-47595"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:29","euvd":{"id":"EUVD-2026-90137","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can write to read-only memory because the memory's permissions are not preserved. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.","published_time":"2026-09-30T15:51:20","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47595","https://www.cve.org/CVERecord?id=CVE-2026-47595","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","Guest driver","Guest driver","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","GeForce","Tesla","Tesla","RTX, Quadro, NVS","Tesla","Tesla","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47596","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can write to read-only memory because the memory's permissions are not preserved. A successful exploit of this vulnerability might lead to code execution and escalation of privileges.","cvss":7.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.0,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47596","https://www.cve.org/CVERecord?id=CVE-2026-47596"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:29","euvd":{"id":"EUVD-2026-90147","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can write to read-only memory because the memory's permissions are not preserved. A successful exploit of this vulnerability might lead to code execution and escalation of privileges.","published_time":"2026-09-30T15:52:21","cvss":7.0,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47596","https://www.cve.org/CVERecord?id=CVE-2026-47596","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","RTX, Quadro, NVS","GeForce","GeForce","RTX, Quadro, NVS","Guest driver","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Guest driver","Tesla","GeForce","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47597","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module Resource Server where an unprivileged local user could cause a use-after-free through a missing self-reference guard in the map cleanup path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47597","https://www.cve.org/CVERecord?id=CVE-2026-47597"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:29","euvd":{"id":"EUVD-2026-90138","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module Resource Server where an unprivileged local user could cause a use-after-free through a missing self-reference guard in the map cleanup path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.","published_time":"2026-09-30T15:51:21","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47597","https://www.cve.org/CVERecord?id=CVE-2026-47597","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","GeForce","Tesla","GeForce","RTX, Quadro, NVS","GeForce","GeForce","Tesla","RTX, Quadro, NVS","Tesla","Tesla","GeForce","Tesla","Tesla","Guest driver","Tesla","GeForce","Guest driver","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47585","summary":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause an integer underflow. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47585","https://www.cve.org/CVERecord?id=CVE-2026-47585"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:28","euvd":{"id":"EUVD-2026-90128","description":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause an integer underflow. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:51:00","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47585","https://www.cve.org/CVERecord?id=CVE-2026-47585","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","Tesla","GeForce","Tesla","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47586","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel module where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":6.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47586","https://www.cve.org/CVERecord?id=CVE-2026-47586"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:28","euvd":{"id":"EUVD-2026-90166","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel module where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:53:05","cvss":6.4,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47586","https://www.cve.org/CVERecord?id=CVE-2026-47586","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","GeForce","Tesla","GeForce","Tesla","Tesla","GeForce","GeForce","RTX, Quadro, NVS","Tesla","GeForce","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47587","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability where an unprivileged user could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47587","https://www.cve.org/CVERecord?id=CVE-2026-47587"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:28","euvd":{"id":"EUVD-2026-90129","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability where an unprivileged user could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.","published_time":"2026-09-30T15:51:01","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47587","https://www.cve.org/CVERecord?id=CVE-2026-47587","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","GeForce","GeForce","Tesla","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47588","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability where an unprivileged user could cause a use-after-free condition by issuing a sequence of driver commands. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service and information disclosure.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47588","https://www.cve.org/CVERecord?id=CVE-2026-47588"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:28","euvd":{"id":"EUVD-2026-90130","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability where an unprivileged user could cause a use-after-free condition by issuing a sequence of driver commands. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service and information disclosure.","published_time":"2026-09-30T15:51:02","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47588","https://www.cve.org/CVERecord?id=CVE-2026-47588","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Guest driver","Guest driver","Tesla","RTX, Quadro, NVS","Guest driver","RTX, Quadro, NVS","Guest driver","GeForce","GeForce","RTX, Quadro, NVS","Tesla","Tesla","GeForce","RTX, Quadro, NVS","Tesla","GeForce","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47589","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by issuing a sequence of driver commands. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, and information disclosure.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47589","https://www.cve.org/CVERecord?id=CVE-2026-47589"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:28","euvd":{"id":"EUVD-2026-90131","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by issuing a sequence of driver commands. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, and information disclosure.","published_time":"2026-09-30T15:51:04","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47589","https://www.cve.org/CVERecord?id=CVE-2026-47589","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Tesla","GeForce","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Tesla","GeForce","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Tesla","GeForce","GeForce","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47590","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by issuing a sequence of driver commands. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, and information disclosure.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47590","https://www.cve.org/CVERecord?id=CVE-2026-47590"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:28","euvd":{"id":"EUVD-2026-90132","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by issuing a sequence of driver commands. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, and information disclosure.","published_time":"2026-09-30T15:51:05","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47590","https://www.cve.org/CVERecord?id=CVE-2026-47590","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","Tesla","Tesla","GeForce","Tesla","GeForce","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","GeForce","GeForce","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47578","summary":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an attacker could cause an incorrect buffer size calculation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47578","https://www.cve.org/CVERecord?id=CVE-2026-47578"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:27","euvd":{"id":"EUVD-2026-90125","description":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an attacker could cause an incorrect buffer size calculation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:50:47","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47578","https://www.cve.org/CVERecord?id=CVE-2026-47578","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","GeForce","Virtual GPU Manager","Tesla","Tesla","GeForce","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Tesla","Virtual GPU Manager"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47579","summary":"The NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode driver through which a user might trigger a use-after-free condition. Successful exploitation of this issue could lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47579","https://www.cve.org/CVERecord?id=CVE-2026-47579"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:27","euvd":{"id":"EUVD-2026-90126","description":"The NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode driver through which a user might trigger a use-after-free condition. Successful exploitation of this issue could lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.","published_time":"2026-09-30T15:50:48","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47579","https://www.cve.org/CVERecord?id=CVE-2026-47579","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","Tesla","Guest driver","Guest driver","GeForce","Tesla","Tesla","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47580","summary":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause a missing authorization issue. A successful exploit of this vulnerability might lead to information disclosure and data tampering.","cvss":7.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47580","https://www.cve.org/CVERecord?id=CVE-2026-47580"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:27","euvd":{"id":"EUVD-2026-90142","description":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause a missing authorization issue. A successful exploit of this vulnerability might lead to information disclosure and data tampering.","published_time":"2026-09-30T15:51:26","cvss":7.3,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47580","https://www.cve.org/CVERecord?id=CVE-2026-47580","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","RTX, Quadro, NVS","Tesla","GeForce","GeForce","GeForce","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47581","summary":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where a user could cause improper locking. A successful exploit of this vulnerability might lead to denial of service.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47581","https://www.cve.org/CVERecord?id=CVE-2026-47581"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:27","euvd":{"id":"EUVD-2026-90178","description":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where a user could cause improper locking. A successful exploit of this vulnerability might lead to denial of service.","published_time":"2026-09-30T15:54:14","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47581","https://www.cve.org/CVERecord?id=CVE-2026-47581","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","Tesla","RTX, Quadro, NVS","GeForce","GeForce","RTX, Quadro, NVS","Virtual GPU Manager","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Virtual GPU Manager","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47582","summary":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.0,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47582","https://www.cve.org/CVERecord?id=CVE-2026-47582"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:27","euvd":{"id":"EUVD-2026-90146","description":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:52:10","cvss":7.0,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47582","https://www.cve.org/CVERecord?id=CVE-2026-47582","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","RTX, Quadro, NVS","Virtual GPU Manager","GeForce","RTX, Quadro, NVS","Tesla","Guest driver","Tesla","RTX, Quadro, NVS","Guest driver","GeForce","GeForce","Virtual GPU Manager","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47583","summary":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause type confusion. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47583","https://www.cve.org/CVERecord?id=CVE-2026-47583"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:27","euvd":{"id":"EUVD-2026-90127","description":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause type confusion. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:50:59","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47583","https://www.cve.org/CVERecord?id=CVE-2026-47583","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","GeForce","Tesla","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47584","summary":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker with local access could cause a NULL pointer dereference. A successful exploit of this vulnerability might lead to denial of service.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47584","https://www.cve.org/CVERecord?id=CVE-2026-47584"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:27","euvd":{"id":"EUVD-2026-90179","description":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker with local access could cause a NULL pointer dereference. A successful exploit of this vulnerability might lead to denial of service.","published_time":"2026-09-30T15:54:15","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47584","https://www.cve.org/CVERecord?id=CVE-2026-47584","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","Tesla","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","GeForce","RTX, Quadro, NVS","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47571","summary":"NVIDIA GPU Display Driver for Windows contains a vulnerability in kernel-mode escape handling where an attacker with local access could bypass an authorization check that is intended to restrict certain operations based on client execution context. A successful exploit of this vulnerability might lead to escalation of privilege, information disclosure, data tampering, denial of service, or code execution.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47571","https://www.cve.org/CVERecord?id=CVE-2026-47571"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:26","euvd":{"id":"EUVD-2026-90120","description":"NVIDIA GPU Display Driver for Windows contains a vulnerability in kernel-mode escape handling where an attacker with local access could bypass an authorization check that is intended to restrict certain operations based on client execution context. A successful exploit of this vulnerability might lead to escalation of privilege, information disclosure, data tampering, denial of service, or code execution.","published_time":"2026-09-30T15:50:41","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47571","https://www.cve.org/CVERecord?id=CVE-2026-47571","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","Virtual GPU Manager","Tesla","GeForce","RTX, Quadro, NVS","Virtual GPU Manager","Tesla","RTX, Quadro, NVS","GeForce","Guest driver","RTX, Quadro, NVS","RTX, Quadro, NVS","Guest driver","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47572","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause type confusion. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47572","https://www.cve.org/CVERecord?id=CVE-2026-47572"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:26","euvd":{"id":"EUVD-2026-90121","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause type confusion. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:50:42","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47572","https://www.cve.org/CVERecord?id=CVE-2026-47572","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","GeForce","Tesla","GeForce","Tesla","GeForce","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47573","summary":"NVIDIA NVAPI for Windows contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47573","https://www.cve.org/CVERecord?id=CVE-2026-47573"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:26","euvd":{"id":"EUVD-2026-90122","description":"NVIDIA NVAPI for Windows contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:50:44","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47573","https://www.cve.org/CVERecord?id=CVE-2026-47573","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","GeForce","RTX, Quadro, NVS","Guest driver","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","Tesla","GeForce","Guest driver"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47574","summary":"NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability where an attacker could cause incorrect resource transfer between spheres. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47574","https://www.cve.org/CVERecord?id=CVE-2026-47574"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:26","euvd":{"id":"EUVD-2026-90070","description":"NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability where an attacker could cause incorrect resource transfer between spheres. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:54:57","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47574","https://www.cve.org/CVERecord?id=CVE-2026-47574","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47575","summary":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the display driver DIAG escape handler where a local unprivileged attacker may cause an integer overflow and out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, and code execution.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47575","https://www.cve.org/CVERecord?id=CVE-2026-47575"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:26","euvd":{"id":"EUVD-2026-90123","description":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the display driver DIAG escape handler where a local unprivileged attacker may cause an integer overflow and out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, and code execution.","published_time":"2026-09-30T15:50:45","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47575","https://www.cve.org/CVERecord?id=CVE-2026-47575","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","Tesla","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47576","summary":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module through which an attacker might initiate an out-of-bounds read. Successful exploitation of this issue could lead to denial of service and information disclosure.","cvss":7.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47576","https://www.cve.org/CVERecord?id=CVE-2026-47576"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:26","euvd":{"id":"EUVD-2026-90144","description":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module through which an attacker might initiate an out-of-bounds read. Successful exploitation of this issue could lead to denial of service and information disclosure.","published_time":"2026-09-30T15:51:37","cvss":7.7,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47576","https://www.cve.org/CVERecord?id=CVE-2026-47576","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","GeForce","Tesla","GeForce","Tesla","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47577","summary":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause an incorrect comparison. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47577","https://www.cve.org/CVERecord?id=CVE-2026-47577"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:26","euvd":{"id":"EUVD-2026-90124","description":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause an incorrect comparison. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:50:46","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47577","https://www.cve.org/CVERecord?id=CVE-2026-47577","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Tesla","RTX, Quadro, NVS","GeForce","Tesla","GeForce","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47563","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause a NULL pointer dereference. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47563","https://www.cve.org/CVERecord?id=CVE-2026-47563"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:25","euvd":{"id":"EUVD-2026-90117","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause a NULL pointer dereference. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:50:28","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47563","https://www.cve.org/CVERecord?id=CVE-2026-47563","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Guest driver","Guest driver","RTX, Quadro, NVS","Tesla","GeForce","Tesla","Virtual GPU Manager","GeForce","GeForce","Virtual GPU Manager","RTX, Quadro, NVS","Tesla","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47565","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a privileged user could trigger a race condition that leads to an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":6.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47565","https://www.cve.org/CVERecord?id=CVE-2026-47565"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:25","euvd":{"id":"EUVD-2026-90165","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a privileged user could trigger a race condition that leads to an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:53:04","cvss":6.4,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47565","https://www.cve.org/CVERecord?id=CVE-2026-47565","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","Guest driver","Tesla","GeForce","GeForce","Tesla","Guest driver","GeForce","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47566","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a memory leak in error paths leading to kernel memory exhaustion. A successful exploit of this vulnerability might lead to denial of service.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47566","https://www.cve.org/CVERecord?id=CVE-2026-47566"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:25","euvd":{"id":"EUVD-2026-90175","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a memory leak in error paths leading to kernel memory exhaustion. A successful exploit of this vulnerability might lead to denial of service.","published_time":"2026-09-30T15:54:02","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47566","https://www.cve.org/CVERecord?id=CVE-2026-47566","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Guest driver","GeForce","Tesla","GeForce","GeForce","Tesla","Virtual GPU Manager","Guest driver","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Virtual GPU Manager"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47567","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where a user could cause uncontrolled resource consumption by exhausting the DRM VMA offset address space. A successful exploit of this vulnerability might lead to denial of service.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47567","https://www.cve.org/CVERecord?id=CVE-2026-47567"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:25","euvd":{"id":"EUVD-2026-90176","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where a user could cause uncontrolled resource consumption by exhausting the DRM VMA offset address space. A successful exploit of this vulnerability might lead to denial of service.","published_time":"2026-09-30T15:54:03","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47567","https://www.cve.org/CVERecord?id=CVE-2026-47567","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","Tesla","Tesla","Virtual GPU Manager","Virtual GPU Manager","Tesla","GeForce","RTX, Quadro, NVS","GeForce","Guest driver","RTX, Quadro, NVS","Guest driver","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47568","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause uncontrolled kernel log generation by repeatedly invoking an interface that emits unrate-limited error messages. A successful exploit of this vulnerability might lead to denial of service.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47568","https://www.cve.org/CVERecord?id=CVE-2026-47568"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:25","euvd":{"id":"EUVD-2026-90177","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause uncontrolled kernel log generation by repeatedly invoking an interface that emits unrate-limited error messages. A successful exploit of this vulnerability might lead to denial of service.","published_time":"2026-09-30T15:54:04","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47568","https://www.cve.org/CVERecord?id=CVE-2026-47568","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Guest driver","RTX, Quadro, NVS","GeForce","Virtual GPU Manager","Tesla","Virtual GPU Manager","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","GeForce","GeForce","Guest driver","Tesla","Tesla","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47569","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause a type confusion via a handle recycle race. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47569","https://www.cve.org/CVERecord?id=CVE-2026-47569"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:25","euvd":{"id":"EUVD-2026-90118","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause a type confusion via a handle recycle race. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:50:39","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47569","https://www.cve.org/CVERecord?id=CVE-2026-47569","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Guest driver","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Guest driver","GeForce","GeForce","Virtual GPU Manager","GeForce","RTX, Quadro, NVS","GeForce","Virtual GPU Manager","RTX, Quadro, NVS","Tesla","Tesla","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47570","summary":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the CUDA driver where an attacker could cause a library to be loaded from an uncontrolled search path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47570","https://www.cve.org/CVERecord?id=CVE-2026-47570"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:25","euvd":{"id":"EUVD-2026-90119","description":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the CUDA driver where an attacker could cause a library to be loaded from an uncontrolled search path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service.","published_time":"2026-09-30T15:50:40","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47570","https://www.cve.org/CVERecord?id=CVE-2026-47570","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","Tesla","GeForce","Guest driver","GeForce","RTX, Quadro, NVS","Tesla","Guest driver","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47557","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a NULL pointer dereference. A successful exploit of this vulnerability might lead to denial of service.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47557","https://www.cve.org/CVERecord?id=CVE-2026-47557"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:24","euvd":{"id":"EUVD-2026-90174","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a NULL pointer dereference. A successful exploit of this vulnerability might lead to denial of service.","published_time":"2026-09-30T15:54:00","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47557","https://www.cve.org/CVERecord?id=CVE-2026-47557","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","Tesla","RTX, Quadro, NVS","GeForce","Virtual GPU Manager","Virtual GPU Manager","RTX, Quadro, NVS","Guest driver","GeForce","RTX, Quadro, NVS","Tesla","GeForce","Tesla","Guest driver","RTX, Quadro, NVS","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47558","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a double-free of imported memory state. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47558","https://www.cve.org/CVERecord?id=CVE-2026-47558"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:24","euvd":{"id":"EUVD-2026-90113","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a double-free of imported memory state. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:50:24","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47558","https://www.cve.org/CVERecord?id=CVE-2026-47558","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Guest driver","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","Tesla","Tesla","RTX, Quadro, NVS","GeForce","Guest driver","GeForce","GeForce","RTX, Quadro, NVS","Tesla","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47559","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could access memory belonging to another user's process. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47559","https://www.cve.org/CVERecord?id=CVE-2026-47559"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:24","euvd":{"id":"EUVD-2026-90114","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could access memory belonging to another user's process. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.","published_time":"2026-09-30T15:50:25","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47559","https://www.cve.org/CVERecord?id=CVE-2026-47559","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","Guest driver","GeForce","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Tesla","Tesla","Tesla","GeForce","RTX, Quadro, NVS","Tesla","Guest driver","GeForce","Guest driver","Tesla","GeForce","Tesla","RTX, Quadro, NVS","GeForce","Guest driver","GeForce","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47560","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47560","https://www.cve.org/CVERecord?id=CVE-2026-47560"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:24","euvd":{"id":"EUVD-2026-90115","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:50:26","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47560","https://www.cve.org/CVERecord?id=CVE-2026-47560","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Guest driver","Guest driver","Guest driver","Tesla","RTX, Quadro, NVS","GeForce","GeForce","Tesla","RTX, Quadro, NVS","Tesla","GeForce","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Guest driver"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47561","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where the size of an ioctl input buffer is not validated, allowing an unprivileged caller to trigger an out-of-bounds write in kernel memory. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47561","https://www.cve.org/CVERecord?id=CVE-2026-47561"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:24","euvd":{"id":"EUVD-2026-90116","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where the size of an ioctl input buffer is not validated, allowing an unprivileged caller to trigger an out-of-bounds write in kernel memory. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:50:27","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47561","https://www.cve.org/CVERecord?id=CVE-2026-47561","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","GeForce","Tesla","Virtual GPU Manager","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Guest driver","Tesla","RTX, Quadro, NVS","GeForce","GeForce","Tesla","Virtual GPU Manager","RTX, Quadro, NVS","Guest driver"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47562","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could inject crafted text into the kernel log because the supplied version string is not properly sanitized. A successful exploit of this vulnerability might lead to denial of service and data tampering.","cvss":4.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47562","https://www.cve.org/CVERecord?id=CVE-2026-47562"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:24","euvd":{"id":"EUVD-2026-90184","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could inject crafted text into the kernel log because the supplied version string is not properly sanitized. A successful exploit of this vulnerability might lead to denial of service and data tampering.","published_time":"2026-09-30T15:54:21","cvss":4.4,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47562","https://www.cve.org/CVERecord?id=CVE-2026-47562","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Virtual GPU Manager","Guest driver","RTX, Quadro, NVS","Guest driver","Virtual GPU Manager","GeForce","GeForce","GeForce","GeForce","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","Tesla","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47551","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where a user could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47551","https://www.cve.org/CVERecord?id=CVE-2026-47551"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:23","euvd":{"id":"EUVD-2026-90109","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where a user could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:50:10","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47551","https://www.cve.org/CVERecord?id=CVE-2026-47551","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","Tesla","RTX, Quadro, NVS","Tesla","GeForce","GeForce","Virtual GPU Manager","GeForce","Virtual GPU Manager","Tesla","GeForce","GeForce","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Guest driver","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","Tesla","Virtual GPU Manager","RTX, Quadro, NVS","Guest driver","Guest driver","Guest driver","Virtual GPU Manager"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47552","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could bypass an authorization check and modify privileged configuration. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47552","https://www.cve.org/CVERecord?id=CVE-2026-47552"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:23","euvd":{"id":"EUVD-2026-90110","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could bypass an authorization check and modify privileged configuration. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:50:20","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47552","https://www.cve.org/CVERecord?id=CVE-2026-47552","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","Guest driver","RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","Tesla","Virtual GPU Manager","GeForce","GeForce","Virtual GPU Manager","Guest driver","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47553","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47553","https://www.cve.org/CVERecord?id=CVE-2026-47553"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:23","euvd":{"id":"EUVD-2026-90111","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:50:21","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47553","https://www.cve.org/CVERecord?id=CVE-2026-47553","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","GeForce","Tesla","Guest driver","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Guest driver","RTX, Quadro, NVS","RTX, Quadro, NVS","Guest driver","Tesla","GeForce","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","Tesla","Tesla","Guest driver","RTX, Quadro, NVS","GeForce","GeForce","Tesla","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47554","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where improper verification of cryptographic signatures may cause signature verification to be bypassed under memory pressure. A successful exploit of this vulnerability might lead to denial of service and data tampering.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47554","https://www.cve.org/CVERecord?id=CVE-2026-47554"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:23","euvd":{"id":"EUVD-2026-90143","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where improper verification of cryptographic signatures may cause signature verification to be bypassed under memory pressure. A successful exploit of this vulnerability might lead to denial of service and data tampering.","published_time":"2026-09-30T15:51:27","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47554","https://www.cve.org/CVERecord?id=CVE-2026-47554","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","Tesla","Tesla","GeForce","Tesla","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47555","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where a user could cause uninitialized kernel memory to be copied back to userspace. A successful exploit of this vulnerability might lead to information disclosure.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47555","https://www.cve.org/CVERecord?id=CVE-2026-47555"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:23","euvd":{"id":"EUVD-2026-90173","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where a user could cause uninitialized kernel memory to be copied back to userspace. A successful exploit of this vulnerability might lead to information disclosure.","published_time":"2026-09-30T15:53:59","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47555","https://www.cve.org/CVERecord?id=CVE-2026-47555","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","Tesla","GeForce","Tesla","Tesla","Tesla","Guest driver","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","Virtual GPU Manager","GeForce","RTX, Quadro, NVS","GeForce","GeForce","GeForce","Virtual GPU Manager","GeForce","Virtual GPU Manager","Guest driver","Guest driver","Guest driver","Tesla","GeForce","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Virtual GPU Manager","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47556","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause an integer overflow that leads to an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47556","https://www.cve.org/CVERecord?id=CVE-2026-47556"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:23","euvd":{"id":"EUVD-2026-90112","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause an integer overflow that leads to an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:50:22","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47556","https://www.cve.org/CVERecord?id=CVE-2026-47556","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","Tesla","Tesla","Tesla","RTX, Quadro, NVS","GeForce","GeForce","Guest driver","GeForce","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","Tesla","GeForce","RTX, Quadro, NVS","GeForce","Guest driver","Tesla","Tesla","RTX, Quadro, NVS","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47545","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47545","https://www.cve.org/CVERecord?id=CVE-2026-47545"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:22","euvd":{"id":"EUVD-2026-90106","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:50:07","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47545","https://www.cve.org/CVERecord?id=CVE-2026-47545","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","Tesla","GeForce","Tesla","RTX, Quadro, NVS","GeForce","GeForce","RTX, Quadro, NVS","Tesla","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","Virtual GPU Manager","Tesla","Tesla","Virtual GPU Manager","RTX, Quadro, NVS","Tesla","GeForce","Virtual GPU Manager","Virtual GPU Manager","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47546","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":6.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47546","https://www.cve.org/CVERecord?id=CVE-2026-47546"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:22","euvd":{"id":"EUVD-2026-90163","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:53:01","cvss":6.7,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47546","https://www.cve.org/CVERecord?id=CVE-2026-47546","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Tesla","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","GeForce","GeForce","GeForce","GeForce","RTX, Quadro, NVS","Tesla","Tesla","RTX, Quadro, NVS","Tesla","GeForce","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47547","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":6.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47547","https://www.cve.org/CVERecord?id=CVE-2026-47547"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:22","euvd":{"id":"EUVD-2026-90164","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:53:02","cvss":6.7,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47547","https://www.cve.org/CVERecord?id=CVE-2026-47547","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","GeForce","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","GeForce","Tesla","GeForce","GeForce","RTX, Quadro, NVS","Tesla","GeForce","GeForce","Tesla","RTX, Quadro, NVS","Tesla","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47548","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47548","https://www.cve.org/CVERecord?id=CVE-2026-47548"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:22","euvd":{"id":"EUVD-2026-90107","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:50:08","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47548","https://www.cve.org/CVERecord?id=CVE-2026-47548","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","GeForce","Tesla","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Virtual GPU Manager","Virtual GPU Manager","Tesla","Virtual GPU Manager","GeForce","GeForce","Virtual GPU Manager","Tesla","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47549","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel module where an unprivileged local user could cause a NULL pointer dereference. A successful exploit of this vulnerability might lead to denial of service.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47549","https://www.cve.org/CVERecord?id=CVE-2026-47549"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:22","euvd":{"id":"EUVD-2026-90172","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel module where an unprivileged local user could cause a NULL pointer dereference. A successful exploit of this vulnerability might lead to denial of service.","published_time":"2026-09-30T15:53:58","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47549","https://www.cve.org/CVERecord?id=CVE-2026-47549","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","Tesla","Guest driver","Virtual GPU Manager","RTX, Quadro, NVS","GeForce","Tesla","GeForce","Virtual GPU Manager","GeForce","Guest driver","RTX, Quadro, NVS","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47550","summary":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an unprivileged local user can supply an untrusted pointer that the driver dereferences without validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47550","https://www.cve.org/CVERecord?id=CVE-2026-47550"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:22","euvd":{"id":"EUVD-2026-90108","description":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an unprivileged local user can supply an untrusted pointer that the driver dereferences without validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:50:09","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47550","https://www.cve.org/CVERecord?id=CVE-2026-47550","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","RTX, Quadro, NVS","Virtual GPU Manager","RTX, Quadro, NVS","GeForce","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","Virtual GPU Manager","Tesla","Tesla","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47539","summary":"NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an incorrect numeric conversion. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":6.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47539","https://www.cve.org/CVERecord?id=CVE-2026-47539"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:21","euvd":{"id":"EUVD-2026-90072","description":"NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an incorrect numeric conversion. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:54:59","cvss":6.7,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47539","https://www.cve.org/CVERecord?id=CVE-2026-47539","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47540","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an integer underflow. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47540","https://www.cve.org/CVERecord?id=CVE-2026-47540"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:21","euvd":{"id":"EUVD-2026-90105","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an integer underflow. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:50:05","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47540","https://www.cve.org/CVERecord?id=CVE-2026-47540","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Virtual GPU Manager","Tesla","Tesla","Tesla","GeForce","RTX, Quadro, NVS","GeForce","Virtual GPU Manager","Tesla","GeForce","RTX, Quadro, NVS","GeForce","GeForce","Virtual GPU Manager","RTX, Quadro, NVS","Virtual GPU Manager","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47541","summary":"NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47541","https://www.cve.org/CVERecord?id=CVE-2026-47541"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:21","euvd":{"id":"EUVD-2026-90068","description":"NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:54:54","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47541","https://www.cve.org/CVERecord?id=CVE-2026-47541","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47542","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":6.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47542","https://www.cve.org/CVERecord?id=CVE-2026-47542"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:21","euvd":{"id":"EUVD-2026-90160","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:52:59","cvss":6.7,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47542","https://www.cve.org/CVERecord?id=CVE-2026-47542","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","GeForce","Tesla","GeForce","RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Tesla","GeForce","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","GeForce","GeForce","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47543","summary":"VIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":6.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47543","https://www.cve.org/CVERecord?id=CVE-2026-47543"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:21","euvd":{"id":"EUVD-2026-90162","description":"VIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:53:00","cvss":6.7,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47543","https://www.cve.org/CVERecord?id=CVE-2026-47543","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","Tesla","Tesla","Tesla","GeForce","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","GeForce","GeForce","Tesla","GeForce","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Tesla","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47544","summary":"NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":6.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47544","https://www.cve.org/CVERecord?id=CVE-2026-47544"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:21","euvd":{"id":"EUVD-2026-90069","description":"NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:54:55","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47544","https://www.cve.org/CVERecord?id=CVE-2026-47544","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47533","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an improper validation of an array index. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":6.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47533","https://www.cve.org/CVERecord?id=CVE-2026-47533"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:20","euvd":{"id":"EUVD-2026-90157","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an improper validation of an array index. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:52:46","cvss":6.7,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47533","https://www.cve.org/CVERecord?id=CVE-2026-47533","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","Tesla","GeForce","RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","GeForce","Tesla","GeForce","Tesla","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","GeForce","GeForce","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47534","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause a divide by zero. A successful exploit of this vulnerability might lead to denial of service.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47534","https://www.cve.org/CVERecord?id=CVE-2026-47534"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:20","euvd":{"id":"EUVD-2026-90171","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause a divide by zero. A successful exploit of this vulnerability might lead to denial of service.","published_time":"2026-09-30T15:53:55","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47534","https://www.cve.org/CVERecord?id=CVE-2026-47534","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","Virtual GPU Manager","GeForce","GeForce","Virtual GPU Manager","Tesla","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","Virtual GPU Manager","GeForce","Tesla","Tesla","RTX, Quadro, NVS","Tesla","Virtual GPU Manager","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","GeForce","GeForce","RTX, Quadro, NVS","GeForce","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47535","summary":"NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47535","https://www.cve.org/CVERecord?id=CVE-2026-47535"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:20","euvd":{"id":"EUVD-2026-90066","description":"NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:54:51","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47535","https://www.cve.org/CVERecord?id=CVE-2026-47535","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47536","summary":"NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47536","https://www.cve.org/CVERecord?id=CVE-2026-47536"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:20","euvd":{"id":"EUVD-2026-90067","description":"NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:54:53","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47536","https://www.cve.org/CVERecord?id=CVE-2026-47536","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47537","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":6.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47537","https://www.cve.org/CVERecord?id=CVE-2026-47537"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:20","euvd":{"id":"EUVD-2026-90158","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:52:47","cvss":6.7,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47537","https://www.cve.org/CVERecord?id=CVE-2026-47537","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","Tesla","Tesla","GeForce","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","GeForce","Tesla","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","Tesla","GeForce","Tesla","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47538","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":6.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47538","https://www.cve.org/CVERecord?id=CVE-2026-47538"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:20","euvd":{"id":"EUVD-2026-90159","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:52:49","cvss":6.7,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47538","https://www.cve.org/CVERecord?id=CVE-2026-47538","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","Tesla","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Tesla","Tesla","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","GeForce","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","GeForce","Tesla","RTX, Quadro, NVS","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47526","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service.","cvss":4.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47526","https://www.cve.org/CVERecord?id=CVE-2026-47526"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:19","euvd":{"id":"EUVD-2026-90182","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service.","published_time":"2026-09-30T15:54:19","cvss":4.4,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47526","https://www.cve.org/CVERecord?id=CVE-2026-47526","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","Tesla","Tesla","GeForce","Tesla","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","GeForce","GeForce","RTX, Quadro, NVS","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47527","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":6.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47527","https://www.cve.org/CVERecord?id=CVE-2026-47527"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:19","euvd":{"id":"EUVD-2026-90154","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:52:42","cvss":6.7,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47527","https://www.cve.org/CVERecord?id=CVE-2026-47527","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","GeForce","GeForce","GeForce","GeForce","RTX, Quadro, NVS","Tesla","Tesla","GeForce","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","Tesla","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47528","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an access of an uninitialized pointer. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47528","https://www.cve.org/CVERecord?id=CVE-2026-47528"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:19","euvd":{"id":"EUVD-2026-90103","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an access of an uninitialized pointer. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:50:03","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47528","https://www.cve.org/CVERecord?id=CVE-2026-47528","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","Virtual GPU Manager","RTX, Quadro, NVS","GeForce","GeForce","GeForce","Tesla","RTX, Quadro, NVS","Tesla","GeForce","Tesla","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","GeForce","Tesla","Virtual GPU Manager","Virtual GPU Manager","RTX, Quadro, NVS","Tesla","Virtual GPU Manager","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47529","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":6.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47529","https://www.cve.org/CVERecord?id=CVE-2026-47529"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:19","euvd":{"id":"EUVD-2026-90155","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:52:43","cvss":6.7,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47529","https://www.cve.org/CVERecord?id=CVE-2026-47529","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","Tesla","Tesla","RTX, Quadro, NVS","Tesla","GeForce","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","GeForce","GeForce","Tesla","GeForce","RTX, Quadro, NVS","Tesla","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47530","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47530","https://www.cve.org/CVERecord?id=CVE-2026-47530"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:19","euvd":{"id":"EUVD-2026-90104","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:50:04","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47530","https://www.cve.org/CVERecord?id=CVE-2026-47530","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","Tesla","Tesla","GeForce","Tesla","Tesla","Tesla","RTX, Quadro, NVS","GeForce","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","GeForce","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47531","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service.","cvss":4.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47531","https://www.cve.org/CVERecord?id=CVE-2026-47531"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:19","euvd":{"id":"EUVD-2026-90183","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service.","published_time":"2026-09-30T15:54:20","cvss":4.4,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47531","https://www.cve.org/CVERecord?id=CVE-2026-47531","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","GeForce","GeForce","Tesla","Tesla","Tesla","GeForce","GeForce","Tesla","RTX, Quadro, NVS","Tesla","Tesla","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47532","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":6.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47532","https://www.cve.org/CVERecord?id=CVE-2026-47532"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:19","euvd":{"id":"EUVD-2026-90156","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:52:44","cvss":6.7,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47532","https://www.cve.org/CVERecord?id=CVE-2026-47532","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","GeForce","GeForce","GeForce","RTX, Quadro, NVS","Tesla","GeForce","Tesla","GeForce","RTX, Quadro, NVS","Tesla","Tesla","GeForce","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47520","summary":"NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47520","https://www.cve.org/CVERecord?id=CVE-2026-47520"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:18","euvd":{"id":"EUVD-2026-90064","description":"NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:54:40","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47520","https://www.cve.org/CVERecord?id=CVE-2026-47520","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Guest driver","Guest driver","Virtual GPU Manager","Virtual GPU Manager","Guest driver","Guest driver","Virtual GPU Manager","Virtual GPU Manager"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47521","summary":"NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47521","https://www.cve.org/CVERecord?id=CVE-2026-47521"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:18","euvd":{"id":"EUVD-2026-90065","description":"NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:54:42","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47521","https://www.cve.org/CVERecord?id=CVE-2026-47521","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Virtual GPU Manager","Virtual GPU Manager"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47522","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":6.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47522","https://www.cve.org/CVERecord?id=CVE-2026-47522"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:18","euvd":{"id":"EUVD-2026-90151","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:52:29","cvss":6.7,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47522","https://www.cve.org/CVERecord?id=CVE-2026-47522","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","GeForce","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","GeForce","GeForce","Tesla","GeForce","Tesla","Tesla","RTX, Quadro, NVS","GeForce","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47523","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47523","https://www.cve.org/CVERecord?id=CVE-2026-47523"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:18","euvd":{"id":"EUVD-2026-90102","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:50:02","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47523","https://www.cve.org/CVERecord?id=CVE-2026-47523","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","GeForce","GeForce","RTX, Quadro, NVS","Virtual GPU Manager","GeForce","Virtual GPU Manager","Virtual GPU Manager","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Virtual GPU Manager","GeForce","Tesla","GeForce","GeForce","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","Tesla","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Tesla","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47524","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":6.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47524","https://www.cve.org/CVERecord?id=CVE-2026-47524"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:18","euvd":{"id":"EUVD-2026-90152","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:52:39","cvss":6.7,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47524","https://www.cve.org/CVERecord?id=CVE-2026-47524","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","GeForce","GeForce","Tesla","GeForce","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Tesla","Tesla","GeForce","RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47525","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an improper validation of an array index. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":6.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47525","https://www.cve.org/CVERecord?id=CVE-2026-47525"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:18","euvd":{"id":"EUVD-2026-90153","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an improper validation of an array index. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:52:41","cvss":6.7,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47525","https://www.cve.org/CVERecord?id=CVE-2026-47525","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Tesla","GeForce","GeForce","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","Tesla","Tesla","Tesla","RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47514","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause exposure of kernel stack contents including return addresses and pointers. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47514","https://www.cve.org/CVERecord?id=CVE-2026-47514"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:17","euvd":{"id":"EUVD-2026-90100","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause exposure of kernel stack contents including return addresses and pointers. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:49:50","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47514","https://www.cve.org/CVERecord?id=CVE-2026-47514","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Guest driver","Tesla","GeForce","RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","GeForce","Guest driver","Tesla","Tesla","GeForce","RTX, Quadro, NVS","Tesla","Guest driver","Tesla","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Guest driver","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47515","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds read via an unbounded string operation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":6.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47515","https://www.cve.org/CVERecord?id=CVE-2026-47515"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:17","euvd":{"id":"EUVD-2026-90150","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds read via an unbounded string operation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:52:27","cvss":6.7,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47515","https://www.cve.org/CVERecord?id=CVE-2026-47515","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","GeForce","RTX, Quadro, NVS","Tesla","Tesla","Tesla","RTX, Quadro, NVS","GeForce","GeForce","RTX, Quadro, NVS","Tesla","Tesla","RTX, Quadro, NVS","Guest driver","Tesla","RTX, Quadro, NVS","Guest driver","GeForce","RTX, Quadro, NVS","Guest driver","Tesla","Guest driver","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47516","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47516","https://www.cve.org/CVERecord?id=CVE-2026-47516"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:17","euvd":{"id":"EUVD-2026-90101","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.","published_time":"2026-09-30T15:49:52","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47516","https://www.cve.org/CVERecord?id=CVE-2026-47516","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Guest driver","GeForce","Tesla","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","Guest driver","Tesla","Tesla","Tesla","GeForce","Tesla","RTX, Quadro, NVS","GeForce","Guest driver","GeForce","RTX, Quadro, NVS","GeForce","GeForce","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","Guest driver","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47517","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode driver where a local user may cause a null pointer dereference by submitting a crafted ioctl. A successful exploit of this vulnerability might lead to denial of service.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47517","https://www.cve.org/CVERecord?id=CVE-2026-47517"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:17","euvd":{"id":"EUVD-2026-90170","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode driver where a local user may cause a null pointer dereference by submitting a crafted ioctl. A successful exploit of this vulnerability might lead to denial of service.","published_time":"2026-09-30T15:53:45","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47517","https://www.cve.org/CVERecord?id=CVE-2026-47517","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","Guest driver","RTX, Quadro, NVS","GeForce","GeForce","Virtual GPU Manager","Guest driver","GeForce","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Virtual GPU Manager","GeForce","RTX, Quadro, NVS","Tesla","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47518","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a secure microcontroller component, where incorrect permission assignment for a critical resource allows an attacker with privileged local access to modify protected memory that should be restricted. A successful exploit of this vulnerability might lead to code execution and escalation of privileges.","cvss":6.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.0,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47518","https://www.cve.org/CVERecord?id=CVE-2026-47518"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:17","euvd":{"id":"EUVD-2026-90167","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a secure microcontroller component, where incorrect permission assignment for a critical resource allows an attacker with privileged local access to modify protected memory that should be restricted. A successful exploit of this vulnerability might lead to code execution and escalation of privileges.","published_time":"2026-09-30T15:53:07","cvss":6.0,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47518","https://www.cve.org/CVERecord?id=CVE-2026-47518","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","Tesla","GeForce","Tesla","Tesla","Tesla","RTX, Quadro, NVS","Tesla","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","GeForce","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47519","summary":"NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47519","https://www.cve.org/CVERecord?id=CVE-2026-47519"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:17","euvd":{"id":"EUVD-2026-90063","description":"NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:54:39","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47519","https://www.cve.org/CVERecord?id=CVE-2026-47519","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Guest driver","Virtual GPU Manager","Guest driver","Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager","Guest driver","Guest driver"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47508","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an incorrect conversion between numeric types. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47508","https://www.cve.org/CVERecord?id=CVE-2026-47508"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:16","euvd":{"id":"EUVD-2026-90095","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an incorrect conversion between numeric types. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:49:44","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47508","https://www.cve.org/CVERecord?id=CVE-2026-47508","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","Virtual GPU Manager","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","Tesla","Tesla","GeForce","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","GeForce","GeForce","GeForce","Tesla","GeForce","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Virtual GPU Manager","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47509","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":6.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47509","https://www.cve.org/CVERecord?id=CVE-2026-47509"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:16","euvd":{"id":"EUVD-2026-90149","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:52:26","cvss":6.7,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47509","https://www.cve.org/CVERecord?id=CVE-2026-47509","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Guest driver","GeForce","RTX, Quadro, NVS","GeForce","Guest driver","Tesla","Tesla","GeForce","Tesla","RTX, Quadro, NVS","Guest driver","Tesla","GeForce","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Guest driver","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47510","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an integer overflow leading to an out-of-bounds write to GPU memory. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47510","https://www.cve.org/CVERecord?id=CVE-2026-47510"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:16","euvd":{"id":"EUVD-2026-90096","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an integer overflow leading to an out-of-bounds write to GPU memory. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:49:45","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47510","https://www.cve.org/CVERecord?id=CVE-2026-47510","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","GeForce","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","Guest driver","Guest driver","RTX, Quadro, NVS","GeForce","Guest driver","Tesla","RTX, Quadro, NVS","Tesla","GeForce","Guest driver","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47511","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47511","https://www.cve.org/CVERecord?id=CVE-2026-47511"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:16","euvd":{"id":"EUVD-2026-90097","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:49:46","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47511","https://www.cve.org/CVERecord?id=CVE-2026-47511","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","Guest driver","Guest driver","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Tesla","GeForce","Guest driver","Tesla","GeForce","GeForce","Guest driver"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47512","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds read leading to kernel information disclosure. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47512","https://www.cve.org/CVERecord?id=CVE-2026-47512"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:16","euvd":{"id":"EUVD-2026-90098","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds read leading to kernel information disclosure. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:49:47","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47512","https://www.cve.org/CVERecord?id=CVE-2026-47512","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","Tesla","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","GeForce","Tesla","GeForce","GeForce","Tesla","Tesla","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47513","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds read from kernel heap memory. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47513","https://www.cve.org/CVERecord?id=CVE-2026-47513"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:16","euvd":{"id":"EUVD-2026-90099","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds read from kernel heap memory. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:49:49","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47513","https://www.cve.org/CVERecord?id=CVE-2026-47513","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","GeForce","Tesla","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","GeForce","GeForce","RTX, Quadro, NVS","Tesla","GeForce","RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","Tesla","Tesla","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47502","summary":"NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer, where a guest user could cause an integer overflow leading to memory corruption. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47502","https://www.cve.org/CVERecord?id=CVE-2026-47502"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:15","euvd":{"id":"EUVD-2026-90091","description":"NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer, where a guest user could cause an integer overflow leading to memory corruption. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:49:30","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47502","https://www.cve.org/CVERecord?id=CVE-2026-47502","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","Tesla","GeForce","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Tesla","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","GeForce","GeForce","GeForce","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47503","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest VM user may cause an out-of-bounds write by sending a crafted RPC message with invalid performance state list size parameters. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47503","https://www.cve.org/CVERecord?id=CVE-2026-47503"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:15","euvd":{"id":"EUVD-2026-90062","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest VM user may cause an out-of-bounds write by sending a crafted RPC message with invalid performance state list size parameters. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.","published_time":"2026-09-30T15:54:38","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47503","https://www.cve.org/CVERecord?id=CVE-2026-47503","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47504","summary":"NVIDIA Linux GPU Display Driver contains a vulnerability in the NGX updater where an outdated embedded cryptographic library is susceptible to type confusion. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, or data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47504","https://www.cve.org/CVERecord?id=CVE-2026-47504"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:15","euvd":{"id":"EUVD-2026-90092","description":"NVIDIA Linux GPU Display Driver contains a vulnerability in the NGX updater where an outdated embedded cryptographic library is susceptible to type confusion. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, or data tampering.","published_time":"2026-09-30T15:49:31","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47504","https://www.cve.org/CVERecord?id=CVE-2026-47504","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","Tesla","GeForce","Tesla","Tesla","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","GeForce"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47505","summary":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, denial of service, or escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47505","https://www.cve.org/CVERecord?id=CVE-2026-47505"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:15","euvd":{"id":"EUVD-2026-90093","description":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, denial of service, or escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:49:33","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47505","https://www.cve.org/CVERecord?id=CVE-2026-47505","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Guest driver","RTX, Quadro, NVS","RTX, Quadro, NVS","Virtual GPU Manager","Virtual GPU Manager","Tesla","RTX, Quadro, NVS","GeForce","GeForce","GeForce","Tesla","Guest driver","Tesla","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47506","summary":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel-mode color transform path where excessive kernel stack use occurs when evaluating YCbCr420 display emulation. A successful exploit of this vulnerability might lead to denial of service.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47506","https://www.cve.org/CVERecord?id=CVE-2026-47506"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:15","euvd":{"id":"EUVD-2026-90169","description":"NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel-mode color transform path where excessive kernel stack use occurs when evaluating YCbCr420 display emulation. A successful exploit of this vulnerability might lead to denial of service.","published_time":"2026-09-30T15:53:19","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47506","https://www.cve.org/CVERecord?id=CVE-2026-47506","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","GeForce","Tesla","GeForce","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47507","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds array access. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47507","https://www.cve.org/CVERecord?id=CVE-2026-47507"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:15","euvd":{"id":"EUVD-2026-90094","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds array access. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:49:43","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47507","https://www.cve.org/CVERecord?id=CVE-2026-47507","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Tesla","Virtual GPU Manager","RTX, Quadro, NVS","Virtual GPU Manager","GeForce","RTX, Quadro, NVS","GeForce","Tesla","GeForce","Tesla","GeForce","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Virtual GPU Manager","Tesla","GeForce","Virtual GPU Manager","RTX, Quadro, NVS","GeForce","GeForce","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47495","summary":"NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer where a user could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47495","https://www.cve.org/CVERecord?id=CVE-2026-47495"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:14","euvd":{"id":"EUVD-2026-90186","description":"NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer where a user could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:54:33","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47495","https://www.cve.org/CVERecord?id=CVE-2026-47495","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47496","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where a guest VM user may cause an out-of-bounds write by sending a specially crafted RPC call to the host. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, and denial of service.","cvss":7.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47496","https://www.cve.org/CVERecord?id=CVE-2026-47496"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:14","euvd":{"id":"EUVD-2026-90071","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where a guest VM user may cause an out-of-bounds write by sending a specially crafted RPC call to the host. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, and denial of service.","published_time":"2026-09-30T15:54:58","cvss":7.3,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47496","https://www.cve.org/CVERecord?id=CVE-2026-47496","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47497","summary":"NVIDIA Virtual GPU Manager contains a vulnerability in the GPU System Processor (GSP) tracing component where a guest VM user may cause improper access by sending crafted data through a shared buffer. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47497","https://www.cve.org/CVERecord?id=CVE-2026-47497"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:14","euvd":{"id":"EUVD-2026-90059","description":"NVIDIA Virtual GPU Manager contains a vulnerability in the GPU System Processor (GSP) tracing component where a guest VM user may cause improper access by sending crafted data through a shared buffer. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.","published_time":"2026-09-30T15:54:34","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47497","https://www.cve.org/CVERecord?id=CVE-2026-47497","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47498","summary":"NVIDIA vGPU Manager contains a vulnerability in the GPU System Processor (GSP) plugin where a guest VM user may cause an out-of-bounds write by sending a specially crafted RPC message. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47498","https://www.cve.org/CVERecord?id=CVE-2026-47498"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:14","euvd":{"id":"EUVD-2026-90060","description":"NVIDIA vGPU Manager contains a vulnerability in the GPU System Processor (GSP) plugin where a guest VM user may cause an out-of-bounds write by sending a specially crafted RPC message. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.","published_time":"2026-09-30T15:54:36","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47498","https://www.cve.org/CVERecord?id=CVE-2026-47498","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47499","summary":"NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer where a guest could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47499","https://www.cve.org/CVERecord?id=CVE-2026-47499"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:14","euvd":{"id":"EUVD-2026-90061","description":"NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer where a guest could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:54:37","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47499","https://www.cve.org/CVERecord?id=CVE-2026-47499","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Virtual GPU Manager","Virtual GPU Manager"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47500","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where improper cleanup of reference counts during error paths could lead to a use-after-free condition. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47500","https://www.cve.org/CVERecord?id=CVE-2026-47500"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:14","euvd":{"id":"EUVD-2026-90089","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where improper cleanup of reference counts during error paths could lead to a use-after-free condition. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:49:27","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47500","https://www.cve.org/CVERecord?id=CVE-2026-47500","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","Virtual GPU Manager","RTX, Quadro, NVS","GeForce","GeForce","Virtual GPU Manager","RTX, Quadro, NVS","Virtual GPU Manager","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","GeForce","Tesla","Virtual GPU Manager","Tesla","Tesla","Guest driver","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Guest driver","RTX, Quadro, NVS","GeForce","Guest driver","Tesla","Tesla","GeForce","RTX, Quadro, NVS","Guest driver","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47501","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause an out-of-bounds write by supplying mismatched memory buffers during event buffer setup. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47501","https://www.cve.org/CVERecord?id=CVE-2026-47501"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:14","euvd":{"id":"EUVD-2026-90090","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause an out-of-bounds write by supplying mismatched memory buffers during event buffer setup. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:49:29","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47501","https://www.cve.org/CVERecord?id=CVE-2026-47501","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Tesla","RTX, Quadro, NVS","Virtual GPU Manager","RTX, Quadro, NVS","Virtual GPU Manager","Tesla","RTX, Quadro, NVS","Tesla","RTX, Quadro, NVS","Guest driver","Guest driver","GeForce","GeForce","GeForce","Tesla","GeForce","Guest driver","Guest driver","Virtual GPU Manager","Virtual GPU Manager"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47489","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where permissions on read-only memory might not be preserved. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47489","https://www.cve.org/CVERecord?id=CVE-2026-47489"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:13","euvd":{"id":"EUVD-2026-90189","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where permissions on read-only memory might not be preserved. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:49:24","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47489","https://www.cve.org/CVERecord?id=CVE-2026-47489","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Guest driver","GeForce","GeForce","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Guest driver","Tesla","Virtual GPU Manager","Tesla","Tesla","GeForce","RTX, Quadro, NVS","Virtual GPU Manager","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47491","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can cause improper release of memory resources, leaving a mapping accessible after the underlying memory is reused. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47491","https://www.cve.org/CVERecord?id=CVE-2026-47491"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:13","euvd":{"id":"EUVD-2026-90087","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can cause improper release of memory resources, leaving a mapping accessible after the underlying memory is reused. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.","published_time":"2026-09-30T15:49:25","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47491","https://www.cve.org/CVERecord?id=CVE-2026-47491","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Guest driver","RTX, Quadro, NVS","GeForce","Tesla","Guest driver","Tesla","Tesla","RTX, Quadro, NVS","Tesla","GeForce","GeForce","GeForce","RTX, Quadro, NVS","RTX, Quadro, NVS"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47492","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an attacker can cause improper access control. A successful exploit of this vulnerability might lead to denial of service.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47492","https://www.cve.org/CVERecord?id=CVE-2026-47492"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:13","euvd":{"id":"EUVD-2026-90168","description":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an attacker can cause improper access control. A successful exploit of this vulnerability might lead to denial of service.","published_time":"2026-09-30T15:53:08","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47492","https://www.cve.org/CVERecord?id=CVE-2026-47492","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["GeForce","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Guest driver","RTX, Quadro, NVS","RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","Tesla","RTX, Quadro, NVS","RTX, Quadro, NVS","Virtual GPU Manager","Tesla","Guest driver","GeForce","Tesla","GeForce","GeForce","Guest driver","Tesla","Tesla","RTX, Quadro, NVS","GeForce","Tesla","Guest driver","Virtual GPU Manager","Tesla","Virtual GPU Manager","Virtual GPU Manager"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47493","summary":"NVIDIA vGPU software for Windows and Linux contains a vulnerability in the GPU kernel driver where a guest may access privileged host GPU resources for which it is not authorized. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47493","https://www.cve.org/CVERecord?id=CVE-2026-47493"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:13","euvd":{"id":"EUVD-2026-90185","description":"NVIDIA vGPU software for Windows and Linux contains a vulnerability in the GPU kernel driver where a guest may access privileged host GPU resources for which it is not authorized. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.","published_time":"2026-09-30T15:54:23","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47493","https://www.cve.org/CVERecord?id=CVE-2026-47493","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager","Virtual GPU Manager"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-47494","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability where a user might be able to cause a format string issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/NVIDIA/product-security/tree/main/2026/5861","https://nvd.nist.gov/vuln/detail/CVE-2026-47494","https://www.cve.org/CVERecord?id=CVE-2026-47494"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:13","euvd":{"id":"EUVD-2026-90088","description":"NVIDIA GPU Display Driver for Linux contains a vulnerability where a user might be able to cause a format string issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.","published_time":"2026-09-30T15:49:26","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"nvidia","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-47494","https://www.cve.org/CVERecord?id=CVE-2026-47494","https://github.com/NVIDIA/product-security/tree/main/2026/5861"],"products":["RTX, Quadro, NVS","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","GeForce","RTX, Quadro, NVS","Tesla","Tesla","GeForce","Tesla","GeForce","Tesla"],"vendors":["NVIDIA"]}},{"cve_id":"CVE-2026-103442","summary":"External control of system or configuration setting vulnerability in The Wikimedia Foundation MediaWiki CentralAuth extension allows Code Injection.\n\nThis issue affects MediaWiki CentralAuth extension: 1.46, 1.45, and 1.43.","cvss":7.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gerrit.wikimedia.org/r/q/I9c59e5c3f217c1eaa02934a076604049bac2b025","https://phabricator.wikimedia.org/T435624"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:10","euvd":{"id":"EUVD-2026-90075","description":"External control of system or configuration setting vulnerability in The Wikimedia Foundation MediaWiki CentralAuth extension allows Code Injection.\n\nThis issue affects MediaWiki CentralAuth extension: 1.46, 1.45, and 1.43.","published_time":"2026-09-30T16:09:40","cvss":7.2,"cvss_version":"4.0","epss":0.0,"assigner":"wikimedia-foundation","references":["https://phabricator.wikimedia.org/T435624","https://gerrit.wikimedia.org/r/q/I9c59e5c3f217c1eaa02934a076604049bac2b025"],"products":["MediaWiki CentralAuth extension","MediaWiki CentralAuth extension","MediaWiki CentralAuth extension"],"vendors":["The Wikimedia Foundation"]}},{"cve_id":"CVE-2026-103470","summary":"In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.grouper.internet2.edu/wiki/spaces/Grouper/pages/240549893/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:10","euvd":{"id":"EUVD-2026-90161","description":"In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges.","published_time":"2026-09-30T15:53:00","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"mitre","references":["https://docs.grouper.internet2.edu/wiki/spaces/Grouper/pages/240549893/"],"products":["Grouper","Grouper","Grouper"],"vendors":["Internet2"]}},{"cve_id":"CVE-2026-103432","summary":"apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi), a related issue to CVE-2026-15544.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://bugzilla.redhat.com/show_bug.cgi?id=2493140","https://github.com/therealbstern/apcupsd/blob/224d19d5faa508d04267f6135fe53d50800550de/src/cgi/upsfetch.c#L240","https://sourceforge.net/projects/apcupsd/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:09","euvd":{"id":"EUVD-2026-90027","description":"apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi), a related issue to CVE-2026-15544.","published_time":"2026-09-30T15:31:08","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://bugzilla.redhat.com/show_bug.cgi?id=2493140","https://github.com/therealbstern/apcupsd/blob/224d19d5faa508d04267f6135fe53d50800550de/src/cgi/upsfetch.c#L240","https://sourceforge.net/projects/apcupsd/"],"products":["apcupsd"],"vendors":["apcupsd"]}},{"cve_id":"CVE-2026-103436","summary":"apcupsd through 3.14.14 discloses uninitialized stack memory in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi. On the single-field path, when the matched STATUS line has fewer than three whitespace-separated tokens, sscanf(\"%*s %*s %s\", answer) performs no assignment but the function returns success, and thus the caller prints the uninitialized destination buffer into the HTTP response.","cvss":3.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://bugzilla.redhat.com/show_bug.cgi?id=2493140","https://github.com/therealbstern/apcupsd/blob/224d19d5faa508d04267f6135fe53d50800550de/src/cgi/upsfetch.c#L240","https://sourceforge.net/projects/apcupsd/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:09","euvd":{"id":"EUVD-2026-90187","description":"apcupsd through 3.14.14 discloses uninitialized stack memory in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi. On the single-field path, when the matched STATUS line has fewer than three whitespace-separated tokens, sscanf(\"%*s %*s %s\", answer) performs no assignment but the function returns success, and thus the caller prints the uninitialized destination buffer into the HTTP response.","published_time":"2026-09-30T15:38:48","cvss":3.7,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://bugzilla.redhat.com/show_bug.cgi?id=2493140","https://github.com/therealbstern/apcupsd/blob/224d19d5faa508d04267f6135fe53d50800550de/src/cgi/upsfetch.c#L240","https://sourceforge.net/projects/apcupsd/"],"products":["apcupsd"],"vendors":["apcupsd"]}},{"cve_id":"CVE-2026-103441","summary":"Deserialization of untrusted data vulnerability in The Wikimedia Foundation MediaWiki Wikibase extension allows Leverage Executable Code in Non-Executable Files.\n\nThis issue affects MediaWiki Wikibase extension: 1.46, 1.45, and 1.43.","cvss":7.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gerrit.wikimedia.org/r/q/Id35bf747e48370e474d9b9444bd7520b24836e8d","https://phabricator.wikimedia.org/T435210"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:09","euvd":{"id":"EUVD-2026-90073","description":"Deserialization of untrusted data vulnerability in The Wikimedia Foundation MediaWiki Wikibase extension allows Leverage Executable Code in Non-Executable Files.\n\nThis issue affects MediaWiki Wikibase extension: 1.46, 1.45, and 1.43.","published_time":"2026-09-30T15:59:42","cvss":7.2,"cvss_version":"4.0","epss":0.0,"assigner":"wikimedia-foundation","references":["https://phabricator.wikimedia.org/T435210","https://gerrit.wikimedia.org/r/q/Id35bf747e48370e474d9b9444bd7520b24836e8d"],"products":["MediaWiki Wikibase extension","MediaWiki Wikibase extension","MediaWiki Wikibase extension"],"vendors":["The Wikimedia Foundation"]}},{"cve_id":"CVE-2026-103229","summary":"A vulnerability was found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This issue affects the function mysqli_query of the file admin/delete1.php of the component Unauthenticated Action Script. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.","cvss":5.5,"cvss_version":4.0,"cvss_v2":7.5,"cvss_v3":7.3,"cvss_v4":5.5,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/AdithyaYelloju/Restaurant-Management-System/","https://github.com/AdithyaYelloju/Restaurant-Management-System/issues/5","https://vuldb.com/cve/CVE-2026-103229","https://vuldb.com/submit/955078","https://vuldb.com/vuln/411922","https://vuldb.com/vuln/411922/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:08","euvd":{"id":"EUVD-2026-89996","description":"A vulnerability was found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This issue affects the function mysqli_query of the file admin/delete1.php of the component Unauthenticated Action Script. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.","published_time":"2026-09-30T15:15:12","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411922","https://vuldb.com/vuln/411922/cti","https://vuldb.com/cve/CVE-2026-103229","https://vuldb.com/submit/955078","https://github.com/AdithyaYelloju/Restaurant-Management-System/issues/5","https://github.com/AdithyaYelloju/Restaurant-Management-System/"],"products":["Restaurant-Management-System"],"vendors":["AdithyaYelloju"]}},{"cve_id":"CVE-2026-103230","summary":"A vulnerability was determined in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Impacted is the function mysqli_query of the file User/ord.php of the component Order Placement. Executing a manipulation of the argument id/name can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.","cvss":5.5,"cvss_version":4.0,"cvss_v2":7.5,"cvss_v3":7.3,"cvss_v4":5.5,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/AdithyaYelloju/Restaurant-Management-System/","https://github.com/AdithyaYelloju/Restaurant-Management-System/issues/6","https://vuldb.com/cve/CVE-2026-103230","https://vuldb.com/submit/955079","https://vuldb.com/vuln/411923","https://vuldb.com/vuln/411923/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:08","euvd":{"id":"EUVD-2026-90026","description":"A vulnerability was determined in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Impacted is the function mysqli_query of the file User/ord.php of the component Order Placement. Executing a manipulation of the argument id/name can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.","published_time":"2026-09-30T15:30:09","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411923","https://vuldb.com/vuln/411923/cti","https://vuldb.com/cve/CVE-2026-103230","https://vuldb.com/submit/955079","https://github.com/AdithyaYelloju/Restaurant-Management-System/issues/6","https://github.com/AdithyaYelloju/Restaurant-Management-System/"],"products":["Restaurant-Management-System"],"vendors":["AdithyaYelloju"]}},{"cve_id":"CVE-2026-103231","summary":"A vulnerability was identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. The affected element is the function mysqli_query of the file User/cancel.php of the component Order Cancellation. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.","cvss":5.5,"cvss_version":4.0,"cvss_v2":7.5,"cvss_v3":7.3,"cvss_v4":5.5,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/AdithyaYelloju/Restaurant-Management-System/","https://github.com/AdithyaYelloju/Restaurant-Management-System/issues/7","https://vuldb.com/cve/CVE-2026-103231","https://vuldb.com/submit/955080","https://vuldb.com/vuln/411924","https://vuldb.com/vuln/411924/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:08","euvd":{"id":"EUVD-2026-90074","description":"A vulnerability was identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. The affected element is the function mysqli_query of the file User/cancel.php of the component Order Cancellation. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.","published_time":"2026-09-30T16:00:11","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411924","https://vuldb.com/vuln/411924/cti","https://vuldb.com/cve/CVE-2026-103231","https://vuldb.com/submit/955080","https://github.com/AdithyaYelloju/Restaurant-Management-System/issues/7","https://github.com/AdithyaYelloju/Restaurant-Management-System/"],"products":["Restaurant-Management-System"],"vendors":["AdithyaYelloju"]}},{"cve_id":"CVE-2026-102427","summary":"Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that would otherwise restrict the saved file’s extension was present in the source and commented out. The saved file’s extension was taken directly from the attacker-supplied filename with no validation, and the file was written to a path directly under the Joomla web root that is executed by the PHP handler. An image/PHP polyglot, a file whose header bytes satisfy the MIME check with PHP source appended after, passed the content check while carrying a .php extension of the attacker’s choosing.","cvss":10.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":10.0,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ordasoft.com/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:17:06","euvd":{"id":"EUVD-2026-89995","description":"Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that would otherwise restrict the saved file’s extension was present in the source and commented out. The saved file’s extension was taken directly from the attacker-supplied filename with no validation, and the file was written to a path directly under the Joomla web root that is executed by the PHP handler. An image/PHP polyglot, a file whose header bytes satisfy the MIME check with PHP source appended after, passed the content check while carrying a .php extension of the attacker’s choosing.","published_time":"2026-09-30T15:14:49","cvss":10.0,"cvss_version":"4.0","epss":0.0,"assigner":"Joomla","references":["https://www.ordasoft.com/"],"products":["OrdaSoft Joomla CCK"],"vendors":["OrdaSoft.com"]}},{"cve_id":"CVE-2026-100275","summary":"In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible","cvss":6.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:59","euvd":{"id":"EUVD-2026-90019","description":"In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible","published_time":"2026-09-30T15:17:54","cvss":6.9,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["YouTrack"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100276","summary":"In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action","cvss":5.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:59","euvd":{"id":"EUVD-2026-90020","description":"In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action","published_time":"2026-09-30T15:17:54","cvss":5.9,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["YouTrack"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100277","summary":"In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature","cvss":8.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:59","euvd":{"id":"EUVD-2026-90021","description":"In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature","published_time":"2026-09-30T15:17:55","cvss":8.9,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["YouTrack"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100278","summary":"In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments","cvss":4.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:59","euvd":{"id":"EUVD-2026-90022","description":"In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments","published_time":"2026-09-30T15:17:55","cvss":4.9,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["YouTrack"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100279","summary":"In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:59","euvd":{"id":"EUVD-2026-90023","description":"In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials","published_time":"2026-09-30T15:17:55","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["YouTrack"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100280","summary":"In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible","cvss":3.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:59","euvd":{"id":"EUVD-2026-90024","description":"In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible","published_time":"2026-09-30T15:17:56","cvss":3.1,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["YouTrack"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100268","summary":"In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates","cvss":7.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:58","euvd":{"id":"EUVD-2026-90012","description":"In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates","published_time":"2026-09-30T15:17:51","cvss":7.7,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["YouTrack"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100269","summary":"In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:58","euvd":{"id":"EUVD-2026-90013","description":"In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed","published_time":"2026-09-30T15:17:51","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["YouTrack"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100270","summary":"In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations","cvss":3.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:58","euvd":{"id":"EUVD-2026-90014","description":"In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations","published_time":"2026-09-30T15:17:52","cvss":3.3,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["YouTrack"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100271","summary":"In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects","cvss":2.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":2.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:58","euvd":{"id":"EUVD-2026-90015","description":"In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects","published_time":"2026-09-30T15:17:52","cvss":2.7,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["YouTrack"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100272","summary":"In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues","cvss":4.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:58","euvd":{"id":"EUVD-2026-90016","description":"In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues","published_time":"2026-09-30T15:17:52","cvss":4.9,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["YouTrack"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100273","summary":"In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution","cvss":8.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:58","euvd":{"id":"EUVD-2026-90017","description":"In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution","published_time":"2026-09-30T15:17:53","cvss":8.2,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["YouTrack"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100274","summary":"In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:58","euvd":{"id":"EUVD-2026-90018","description":"In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template","published_time":"2026-09-30T15:17:53","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["YouTrack"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100262","summary":"In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates","cvss":7.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:57","euvd":{"id":"EUVD-2026-90006","description":"In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates","published_time":"2026-09-30T15:17:49","cvss":7.6,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["YouTrack"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100263","summary":"In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible","cvss":4.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:57","euvd":{"id":"EUVD-2026-90007","description":"In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible","published_time":"2026-09-30T15:17:49","cvss":4.7,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["YouTrack"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100264","summary":"In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host","cvss":2.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":2.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:57","euvd":{"id":"EUVD-2026-90008","description":"In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host","published_time":"2026-09-30T15:17:50","cvss":2.7,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["YouTrack"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100265","summary":"In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation","cvss":4.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:57","euvd":{"id":"EUVD-2026-90009","description":"In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation","published_time":"2026-09-30T15:17:50","cvss":4.8,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["Rider"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100266","summary":"In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address","cvss":7.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:57","euvd":{"id":"EUVD-2026-90010","description":"In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address","published_time":"2026-09-30T15:17:50","cvss":7.7,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["Hub"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100267","summary":"In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters","cvss":5.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:57","euvd":{"id":"EUVD-2026-90011","description":"In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters","published_time":"2026-09-30T15:17:51","cvss":5.9,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["YouTrack"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100255","summary":"In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 administrator account takeover was possible via password reset","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:56","euvd":{"id":"EUVD-2026-89999","description":"In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 administrator account takeover was possible via password reset","published_time":"2026-09-30T15:17:46","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["TeamCity"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100256","summary":"In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:56","euvd":{"id":"EUVD-2026-90000","description":"In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects","published_time":"2026-09-30T15:17:46","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["IntelliJ IDEA"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100257","summary":"In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:56","euvd":{"id":"EUVD-2026-90001","description":"In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export","published_time":"2026-09-30T15:17:46","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["YouTrack"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100258","summary":"In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:56","euvd":{"id":"EUVD-2026-90002","description":"In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings","published_time":"2026-09-30T15:17:47","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["YouTrack"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100259","summary":"In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:56","euvd":{"id":"EUVD-2026-90003","description":"In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access","published_time":"2026-09-30T15:17:48","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["YouTrack"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100260","summary":"In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:56","euvd":{"id":"EUVD-2026-90004","description":"In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset","published_time":"2026-09-30T15:17:48","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["YouTrack"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100261","summary":"In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:56","euvd":{"id":"EUVD-2026-90005","description":"In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission","published_time":"2026-09-30T15:17:48","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["YouTrack"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100253","summary":"In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:55","euvd":{"id":"EUVD-2026-89997","description":"In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL","published_time":"2026-09-30T15:17:44","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["TeamCity"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-100254","summary":"In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T16:16:55","euvd":{"id":"EUVD-2026-89998","description":"In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings","published_time":"2026-09-30T15:17:45","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"JetBrains","references":["https://www.jetbrains.com/privacy-security/issues-fixed/"],"products":["TeamCity"],"vendors":["JetBrains"]}},{"cve_id":"CVE-2026-94545","summary":"Satori is a library to convert HTML and CSS to SVG. Starting in version 0.0.27 and prior to version 0.33.5, Satori does not properly escape certain values before including them in generated SVG output. This can allow crafted values to be interpreted as SVG markup. The impact depends on how the generated SVG is consumed. Version 0.33.5 contains a patch. No complete workaround exists besides upgrading. Applications that cannot immediately upgrade should not render attacker-controlled content with Satori.","cvss":5.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/vercel/next.js/commit/868fad38690d72088868f299fa2bef339b26838e","https://github.com/vercel/next.js/releases/tag/v16.3.6","https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j","https://github.com/vercel/satori/commit/26a52affc031216fee5882b6e965c8dbc7ac1782","https://github.com/vercel/satori/pull/814","https://github.com/vercel/satori/security/advisories/GHSA-wx4j-mvgx-mqwp"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:38","euvd":{"id":"EUVD-2026-89994","description":"Satori is a library to convert HTML and CSS to SVG. Starting in version 0.0.27 and prior to version 0.33.5, Satori does not properly escape certain values before including them in generated SVG output. This can allow crafted values to be interpreted as SVG markup. The impact depends on how the generated SVG is consumed. Version 0.33.5 contains a patch. No complete workaround exists besides upgrading. Applications that cannot immediately upgrade should not render attacker-controlled content with Satori.","published_time":"2026-09-30T14:53:34","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/vercel/satori/security/advisories/GHSA-wx4j-mvgx-mqwp","https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j","https://github.com/vercel/satori/pull/814","https://github.com/vercel/next.js/commit/868fad38690d72088868f299fa2bef339b26838e","https://github.com/vercel/satori/commit/26a52affc031216fee5882b6e965c8dbc7ac1782","https://github.com/vercel/next.js/releases/tag/v16.3.6"],"products":["next","satori"],"vendors":["vercel"]}},{"cve_id":"CVE-2026-97259","summary":"Authorization Bypass Through User-Controlled Key vulnerability in WP Hosting AS Pay with Vipps for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.\n\nThis issue affects Pay with Vipps for WooCommerce: from n/a through 6.2.4.","cvss":5.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/woo-vipps/vulnerability/wordpress-pay-with-vipps-for-woocommerce-plugin-6-2-4-insecure-direct-object-references-idor-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:38","euvd":{"id":"EUVD-2026-89960","description":"Authorization Bypass Through User-Controlled Key vulnerability in WP Hosting AS Pay with Vipps for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.\n\nThis issue affects Pay with Vipps for WooCommerce: from n/a through 6.2.4.","published_time":"2026-09-30T14:10:24","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/woo-vipps/vulnerability/wordpress-pay-with-vipps-for-woocommerce-plugin-6-2-4-insecure-direct-object-references-idor-vulnerability?_s_id=cve"],"products":["Pay with Vipps for WooCommerce"],"vendors":["WP Hosting AS"]}},{"cve_id":"CVE-2026-76570","summary":"Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables  1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request parameters and concatenated into SQL queries, allowing SQLi for reading and writing queries.","cvss":10.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":10.0,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.joomcode.com/","https://www.vulncheck.com/blog/jctables-unauthenticated-sql-rw-to-rce"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:34","euvd":{"id":"EUVD-2026-89987","description":"Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables  1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request parameters and concatenated into SQL queries, allowing SQLi for reading and writing queries.","published_time":"2026-09-30T14:47:48","cvss":10.0,"cvss_version":"4.0","epss":0.0,"assigner":"Joomla","references":["https://www.joomcode.com/","https://www.vulncheck.com/blog/jctables-unauthenticated-sql-rw-to-rce"],"products":["JCTables extension for Joomla"],"vendors":["joomcode.com"]}},{"cve_id":"CVE-2026-62084","summary":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Submitted Posts allows Stored XSS.\n\nThis issue affects User Submitted Posts: from n/a through 20260810.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/user-submitted-posts/vulnerability/wordpress-user-submitted-posts-plugin-20260810-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:32","euvd":{"id":"EUVD-2026-89958","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Submitted Posts allows Stored XSS.\n\nThis issue affects User Submitted Posts: from n/a through 20260810.","published_time":"2026-09-30T14:03:36","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/user-submitted-posts/vulnerability/wordpress-user-submitted-posts-plugin-20260810-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["User Submitted Posts"],"vendors":["Jeff Starr"]}},{"cve_id":"CVE-2026-62097","summary":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPTasty Business Directory business-directory-plugin allows Blind SQL Injection.This issue affects Business Directory: from n/a through 6.4.27.","cvss":7.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/business-directory-plugin/vulnerability/wordpress-business-directory-plugin-6-4-27-sql-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:32","euvd":{"id":"EUVD-2026-89957","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPTasty Business Directory business-directory-plugin allows Blind SQL Injection.This issue affects Business Directory: from n/a through 6.4.27.","published_time":"2026-09-30T14:02:22","cvss":7.6,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/business-directory-plugin/vulnerability/wordpress-business-directory-plugin-6-4-27-sql-injection-vulnerability?_s_id=cve"],"products":["Business Directory"],"vendors":["WPTasty"]}},{"cve_id":"CVE-2026-18782","summary":"Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection.\n\nThis issue affects Trex MES: through 2026-09-29.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1225"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:30","euvd":{"id":"EUVD-2026-89963","description":"Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection.\n\nThis issue affects Trex MES: through 2026-09-29.","published_time":"2026-09-30T14:15:15","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"TR-CERT","references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1225"],"products":["Trex MES"],"vendors":["Trex Digital Smart Manufacturing Systems Inc."]}},{"cve_id":"CVE-2026-18783","summary":"Missing authentication for critical function vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Authentication Bypass.\n\nThis issue affects Trex MES: through 2026-09-29.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1225"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:30","euvd":{"id":"EUVD-2026-89961","description":"Missing authentication for critical function vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Authentication Bypass.\n\nThis issue affects Trex MES: through 2026-09-29.","published_time":"2026-09-30T14:12:02","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"TR-CERT","references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1225"],"products":["Trex MES"],"vendors":["Trex Digital Smart Manufacturing Systems Inc."]}},{"cve_id":"CVE-2026-47097","summary":"AJA HELO Plus firmware before 2.1.7 contains an information disclosure vulnerability that allows unauthenticated attackers to decrypt sensitive diagnostics bundles by exploiting a static AES passphrase embedded in obfuscated form within the firmware. Attackers can reverse engineer the publicly available firmware image to recover the shared passphrase and decrypt diagnostics export bundles retrieved from the unauthenticated diagnostics endpoint on any affected device, exposing highly sensitive server information.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://d26ddnfpy9hzf8.cloudfront.net/aja-web/public/pdf/2026/AJA_HELO_PLUS_ReleaseNotes_v2.1.7.pdf","https://www.aja.com/security-advisories/aja-sa-2026-003","https://www.aja.com/support/item/10457","https://www.vulncheck.com/advisories/aja-helo-plus-hardcoded-aes-passphrase-for-diagnostics-export-bundle"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:30","euvd":{"id":"EUVD-2026-89967","description":"AJA HELO Plus firmware before 2.1.7 contains an information disclosure vulnerability that allows unauthenticated attackers to decrypt sensitive diagnostics bundles by exploiting a static AES passphrase embedded in obfuscated form within the firmware. Attackers can reverse engineer the publicly available firmware image to recover the shared passphrase and decrypt diagnostics export bundles retrieved from the unauthenticated diagnostics endpoint on any affected device, exposing highly sensitive server information.","published_time":"2026-09-30T14:31:11","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://www.aja.com/security-advisories/aja-sa-2026-003","https://d26ddnfpy9hzf8.cloudfront.net/aja-web/public/pdf/2026/AJA_HELO_PLUS_ReleaseNotes_v2.1.7.pdf","https://www.aja.com/support/item/10457","https://www.vulncheck.com/advisories/aja-helo-plus-hardcoded-aes-passphrase-for-diagnostics-export-bundle"],"products":["HELO Plus"],"vendors":["AJA Video Systems"]}},{"cve_id":"CVE-2026-103396","summary":"bbs-go through 4.4.6 contains a permission bypass vulnerability in the AdminMiddleware authorization logic where the read-only dashboard.user.view permission rule matches the /api/admin/user/synccount endpoint before the intended dashboard.user.update rule. Authenticated users with only view permissions can call the synccount endpoint to trigger expensive full-table user recounts and cache invalidations, causing denial of service through repeated concurrent database operations.","cvss":5.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":5.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/mlogclub/bbs-go","https://github.com/mlogclub/bbs-go/blob/v4.4.6/internal/handlers/admin/user_handlers.go#L47-L59","https://github.com/mlogclub/bbs-go/blob/v4.4.6/internal/permissions/admin_permission_registry.go#L59-L60","https://github.com/mlogclub/bbs-go/commit/97d0bb3dcbacd686fd5300295afbf4f4a5da7609","https://github.com/mlogclub/bbs-go/issues/303","https://www.vulncheck.com/advisories/bbs-go-through-4.4.6-incorrect-authorization-via-api-admin-user-synccount"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:28","euvd":{"id":"EUVD-2026-89991","description":"bbs-go through 4.4.6 contains a permission bypass vulnerability in the AdminMiddleware authorization logic where the read-only dashboard.user.view permission rule matches the /api/admin/user/synccount endpoint before the intended dashboard.user.update rule. Authenticated users with only view permissions can call the synccount endpoint to trigger expensive full-table user recounts and cache invalidations, causing denial of service through repeated concurrent database operations.","published_time":"2026-09-30T14:48:56","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/mlogclub/bbs-go/issues/303","https://github.com/mlogclub/bbs-go/commit/97d0bb3dcbacd686fd5300295afbf4f4a5da7609","https://github.com/mlogclub/bbs-go/blob/v4.4.6/internal/permissions/admin_permission_registry.go#L59-L60","https://github.com/mlogclub/bbs-go/blob/v4.4.6/internal/handlers/admin/user_handlers.go#L47-L59","https://github.com/mlogclub/bbs-go","https://www.vulncheck.com/advisories/bbs-go-through-4.4.6-incorrect-authorization-via-api-admin-user-synccount"],"products":["bbs-go"],"vendors":["mlogclub"]}},{"cve_id":"CVE-2026-103397","summary":"OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay requests, allowing unpaired room members to impersonate paired devices by spoofing the RelayMessage From field. Attackers who know the room code can join, read paired peer identifiers from announcements, and send forged requests to access protected sync routes including save data, snapshots, and file operations.","cvss":6.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.6,"cvss_v4":6.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/mansurmavlankulov/2ca66f95965fb9d4aab353bcf2434cdb","https://github.com/Liquid-co/OpenSave","https://github.com/Liquid-co/OpenSave/blob/v2.3.1/internal/p2p/wanclient_handlers.go#L268-L282","https://github.com/Liquid-co/OpenSave/commit/2f2612b13233ac123e01a03cb3008c44bacaeae3","https://www.vulncheck.com/advisories/opensave-before-2.4.0-beta.1-authentication-bypass-via-spoofed-relay-sender"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:28","euvd":{"id":"EUVD-2026-89992","description":"OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay requests, allowing unpaired room members to impersonate paired devices by spoofing the RelayMessage From field. Attackers who know the room code can join, read paired peer identifiers from announcements, and send forged requests to access protected sync routes including save data, snapshots, and file operations.","published_time":"2026-09-30T14:48:57","cvss":6.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://gist.github.com/mansurmavlankulov/2ca66f95965fb9d4aab353bcf2434cdb","https://github.com/Liquid-co/OpenSave/commit/2f2612b13233ac123e01a03cb3008c44bacaeae3","https://github.com/Liquid-co/OpenSave/blob/v2.3.1/internal/p2p/wanclient_handlers.go#L268-L282","https://github.com/Liquid-co/OpenSave","https://www.vulncheck.com/advisories/opensave-before-2.4.0-beta.1-authentication-bypass-via-spoofed-relay-sender"],"products":["OpenSave"],"vendors":["Liquid-co"]}},{"cve_id":"CVE-2026-103398","summary":"OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can specify arbitrary directories outside configured save locations to read and write files through manifest and sync routes.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":8.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/mansurmavlankulov/2ca66f95965fb9d4aab353bcf2434cdb","https://github.com/Liquid-co/OpenSave","https://github.com/Liquid-co/OpenSave/blob/v2.4.0/internal/delta/rootguard.go#L16-L30","https://github.com/Liquid-co/OpenSave/blob/v2.4.0/internal/p2p/routes.go#L555-L566","https://www.vulncheck.com/advisories/opensave-through-2.4.0-arbitrary-file-read-and-write-via-peer-controlled-save-path"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:28","euvd":{"id":"EUVD-2026-89993","description":"OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can specify arbitrary directories outside configured save locations to read and write files through manifest and sync routes.","published_time":"2026-09-30T14:48:57","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://gist.github.com/mansurmavlankulov/2ca66f95965fb9d4aab353bcf2434cdb","https://github.com/Liquid-co/OpenSave/blob/v2.4.0/internal/p2p/routes.go#L555-L566","https://github.com/Liquid-co/OpenSave/blob/v2.4.0/internal/delta/rootguard.go#L16-L30","https://github.com/Liquid-co/OpenSave","https://www.vulncheck.com/advisories/opensave-through-2.4.0-arbitrary-file-read-and-write-via-peer-controlled-save-path"],"products":["OpenSave"],"vendors":["Liquid-co"]}},{"cve_id":"CVE-2026-103388","summary":"MISP renders the source field of a Galaxy Cluster as a clickable hyperlink whenever the stored value passes PHP's FILTER_VALIDATE_URL validation. Because FILTER_VALIDATE_URL accepts the javascript: URI scheme, a user with galaxy editor privileges on the local instance or on a synced instance could store a javascript: URL as the cluster source.\n\nWhen another user views the affected Galaxy Cluster and clicks the rendered link, the embedded script executes in the victim's browser context, enabling session hijacking, data exfiltration, or actions performed on behalf of the victim.\n\nPreconditions:\n\n- Attacker must hold galaxy editor privileges (local or via sync).\n\n- Victim must view the affected cluster and click the malicious link.\n\nImpact:\n\n- Stored cross-site scripting (XSS) in the victim's browser.\n\n- Potential session theft, credential harvesting, or unauthorized actions within the MISP application.\n\nAffected: <2.5.48.","cvss":6.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/MISP/MISP/commit/118528767"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:27","euvd":{"id":"EUVD-2026-89964","description":"MISP renders the source field of a Galaxy Cluster as a clickable hyperlink whenever the stored value passes PHP's FILTER_VALIDATE_URL validation. Because FILTER_VALIDATE_URL accepts the javascript: URI scheme, a user with galaxy editor privileges on the local instance or on a synced instance could store a javascript: URL as the cluster source.\n\nWhen another user views the affected Galaxy Cluster and clicks the rendered link, the embedded script executes in the victim's browser context, enabling session hijacking, data exfiltration, or actions performed on behalf of the victim.\n\nPreconditions:\n\n- Attacker must hold galaxy editor privileges (local or via sync).\n\n- Victim must view the affected cluster and click the malicious link.\n\nImpact:\n\n- Stored cross-site scripting (XSS) in the victim's browser.\n\n- Potential session theft, credential harvesting, or unauthorized actions within the MISP application.\n\nAffected: <2.5.48.","published_time":"2026-09-30T14:22:36","cvss":6.2,"cvss_version":"4.0","epss":0.0,"assigner":"CIRCL","references":["https://github.com/MISP/MISP/commit/118528767"],"products":["MISP"],"vendors":["MISP"]}},{"cve_id":"CVE-2026-103389","summary":"MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was persisted without any server-side validation through the galaxy add, edit, and sync/import capture endpoints. The stored value was subsequently concatenated directly into HTML markup by the D3-based correlation graph rendering scripts (both the default and Overmind themes) using the .html() method.\n\nA user holding the perm_galaxy_editor permission, which is granted to the stock User role, could store arbitrary HTML or JavaScript in the icon field. Any other user who opened the correlation graph of an event containing a cluster belonging to that galaxy would have the injected script executed in their browser session.\n\nImpact:\n\n- Arbitrary script execution in the context of the victim's MISP session\n\n- Potential theft of session credentials, manipulation of displayed data, or initiation of actions on behalf of the victim\n\n- Affects both the default and Overmind UI themes\n\nAffected versions: <2.5.48","cvss":6.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/MISP/MISP/commit/8ea5783dd"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:27","euvd":{"id":"EUVD-2026-89965","description":"MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was persisted without any server-side validation through the galaxy add, edit, and sync/import capture endpoints. The stored value was subsequently concatenated directly into HTML markup by the D3-based correlation graph rendering scripts (both the default and Overmind themes) using the .html() method.\n\nA user holding the perm_galaxy_editor permission, which is granted to the stock User role, could store arbitrary HTML or JavaScript in the icon field. Any other user who opened the correlation graph of an event containing a cluster belonging to that galaxy would have the injected script executed in their browser session.\n\nImpact:\n\n- Arbitrary script execution in the context of the victim's MISP session\n\n- Potential theft of session credentials, manipulation of displayed data, or initiation of actions on behalf of the victim\n\n- Affects both the default and Overmind UI themes\n\nAffected versions: <2.5.48","published_time":"2026-09-30T14:25:59","cvss":6.2,"cvss_version":"4.0","epss":0.0,"assigner":"CIRCL","references":["https://github.com/MISP/MISP/commit/8ea5783dd"],"products":["MISP"],"vendors":["MISP"]}},{"cve_id":"CVE-2026-103395","summary":"LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and pass objects with __reduce__ methods to execute arbitrary code with service account privileges.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":9.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/ModelTC/LightLLM","https://github.com/ModelTC/LightLLM/issues/1610","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/visualserver/objs.py#L6-L11","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/visualserver/visual_only_manager.py#L138-L140","https://www.vulncheck.com/advisories/lightllm-through-1.2.0-unauthenticated-remote-code-execution-via-visual-only-rpyc-service","https://github.com/ModelTC/LightLLM/issues/1610"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:27","euvd":{"id":"EUVD-2026-89990","description":"LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and pass objects with __reduce__ methods to execute arbitrary code with service account privileges.","published_time":"2026-09-30T14:48:55","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/ModelTC/LightLLM/issues/1610","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/visualserver/objs.py#L6-L11","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/visualserver/visual_only_manager.py#L138-L140","https://github.com/ModelTC/LightLLM","https://www.vulncheck.com/advisories/lightllm-through-1.2.0-unauthenticated-remote-code-execution-via-visual-only-rpyc-service"],"products":["LightLLM"],"vendors":["ModelTC"]}},{"cve_id":"CVE-2026-103227","summary":"A weakness has been identified in GPAC up to 26.07.0. Affected by this issue is the function gf_dash_resolve_url of the file src/media_tools/dash_client.c of the component DASH Client. This manipulation causes buffer overflow. The attack is possible to be carried out remotely. Upgrading to version abi-16.26 can resolve this issue. Patch name: 4c8e26f278ff63eec57968f7bc696f604bb0cffd. It is recommended to upgrade the affected component.","cvss":5.3,"cvss_version":4.0,"cvss_v2":7.5,"cvss_v3":6.3,"cvss_v4":5.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/gpac/gpac/","https://github.com/gpac/gpac/commit/4c8e26f278ff63eec57968f7bc696f604bb0cffd","https://github.com/gpac/gpac/issues/3876","https://github.com/gpac/gpac/pull/3879","https://github.com/gpac/gpac/releases/tag/abi-16.26","https://vuldb.com/cve/CVE-2026-103227","https://vuldb.com/submit/955033","https://vuldb.com/vuln/411908","https://vuldb.com/vuln/411908/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:26","euvd":{"id":"EUVD-2026-89966","description":"A weakness has been identified in GPAC up to 26.07.0. Affected by this issue is the function gf_dash_resolve_url of the file src/media_tools/dash_client.c of the component DASH Client. This manipulation causes buffer overflow. The attack is possible to be carried out remotely. Upgrading to version abi-16.26 can resolve this issue. Patch name: 4c8e26f278ff63eec57968f7bc696f604bb0cffd. It is recommended to upgrade the affected component.","published_time":"2026-09-30T14:30:09","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411908","https://vuldb.com/vuln/411908/cti","https://vuldb.com/cve/CVE-2026-103227","https://vuldb.com/submit/955033","https://github.com/gpac/gpac/issues/3876","https://github.com/gpac/gpac/pull/3879","https://github.com/gpac/gpac/commit/4c8e26f278ff63eec57968f7bc696f604bb0cffd","https://github.com/gpac/gpac/releases/tag/abi-16.26","https://github.com/gpac/gpac/"],"products":["GPAC"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-103243","summary":"LightLLM through 1.2.0 fails to validate image_url and audio_url parameters in multimodal endpoints, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply arbitrary URLs to fetch internal resources, with vision model processing disclosing content or error responses revealing internal network topology.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.8,"cvss_v4":6.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/ModelTC/LightLLM","https://github.com/ModelTC/LightLLM/issues/1608","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/multimodal_params.py#L149","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/utils/multimodal_utils.py#L82-L91","https://www.vulncheck.com/advisories/lightllm-through-1.2.0-server-side-request-forgery-via-multimodal-endpoints"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:26","euvd":{"id":"EUVD-2026-89988","description":"LightLLM through 1.2.0 fails to validate image_url and audio_url parameters in multimodal endpoints, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply arbitrary URLs to fetch internal resources, with vision model processing disclosing content or error responses revealing internal network topology.","published_time":"2026-09-30T14:48:54","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/ModelTC/LightLLM/issues/1608","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/utils/multimodal_utils.py#L82-L91","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/multimodal_params.py#L149","https://github.com/ModelTC/LightLLM","https://www.vulncheck.com/advisories/lightllm-through-1.2.0-server-side-request-forgery-via-multimodal-endpoints"],"products":["LightLLM"],"vendors":["ModelTC"]}},{"cve_id":"CVE-2026-103270","summary":"LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated attackers can call endpoints like /pause_generation, /abort_request, /flush_cache, and /init_weights_update_group to disrupt inference operations and wedge workers on deployments started with --enable_rl.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/ModelTC/LightLLM","https://github.com/ModelTC/LightLLM/issues/1609","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/api_http.py#L505-L507","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/api_http_rl.py#L51-L139","https://www.vulncheck.com/advisories/lightllm-through-1.2.0-missing-authentication-on-rl-control-routes","https://github.com/ModelTC/LightLLM/issues/1609"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:26","euvd":{"id":"EUVD-2026-89989","description":"LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated attackers can call endpoints like /pause_generation, /abort_request, /flush_cache, and /init_weights_update_group to disrupt inference operations and wedge workers on deployments started with --enable_rl.","published_time":"2026-09-30T14:48:55","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/ModelTC/LightLLM/issues/1609","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/api_http.py#L505-L507","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/api_http_rl.py#L51-L139","https://github.com/ModelTC/LightLLM","https://www.vulncheck.com/advisories/lightllm-through-1.2.0-missing-authentication-on-rl-control-routes"],"products":["LightLLM"],"vendors":["ModelTC"]}},{"cve_id":"CVE-2026-103222","summary":"A vulnerability was determined in Blosc C-Blosc2 up to 3.3.2. This impacts the function blosclz_decompress of the file blosc/blosclz.c of the component blosclz Decompression. Executing a manipulation can lead to integer overflow. The attack may be launched remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. Upgrading to version 3.3.3 will fix this issue. This patch is called fe2964d114d97847f56570a0ab2be2c57ccbeedc. The affected component should be upgraded.","cvss":6.3,"cvss_version":4.0,"cvss_v2":5.1,"cvss_v3":5.6,"cvss_v4":6.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Blosc/c-blosc2/","https://github.com/Blosc/c-blosc2/commit/fe2964d114d97847f56570a0ab2be2c57ccbeedc","https://github.com/Blosc/c-blosc2/releases/tag/v3.3.3","https://vuldb.com/cve/CVE-2026-103222","https://vuldb.com/submit/954976","https://vuldb.com/vuln/411905","https://vuldb.com/vuln/411905/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:25","euvd":{"id":"EUVD-2026-89956","description":"A vulnerability was determined in Blosc C-Blosc2 up to 3.3.2. This impacts the function blosclz_decompress of the file blosc/blosclz.c of the component blosclz Decompression. Executing a manipulation can lead to integer overflow. The attack may be launched remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. Upgrading to version 3.3.3 will fix this issue. This patch is called fe2964d114d97847f56570a0ab2be2c57ccbeedc. The affected component should be upgraded.","published_time":"2026-09-30T14:00:10","cvss":6.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411905","https://vuldb.com/vuln/411905/cti","https://vuldb.com/cve/CVE-2026-103222","https://vuldb.com/submit/954976","https://github.com/Blosc/c-blosc2/commit/fe2964d114d97847f56570a0ab2be2c57ccbeedc","https://github.com/Blosc/c-blosc2/releases/tag/v3.3.3","https://github.com/Blosc/c-blosc2/"],"products":["c-blosc2","c-blosc2","c-blosc2"],"vendors":["Blosc"]}},{"cve_id":"CVE-2026-103226","summary":"A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. It is suggested to install a patch to address this issue. A solution was implemented: \"I've chosen to fix this slightly differently by using the defined macro in the font parsing loop rather than in the callsubr function, because this better matches the pattern of 'normal' usage.\"","cvss":2.1,"cvss_version":4.0,"cvss_v2":7.5,"cvss_v3":6.3,"cvss_v4":2.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://artifex.com/","https://bugs.ghostscript.com/attachment.cgi?id=28495","https://bugs.ghostscript.com/show_bug.cgi?id=709672","https://bugs.ghostscript.com/show_bug.cgi?id=709672#c3","https://vuldb.com/cve/CVE-2026-103226","https://vuldb.com/submit/955016","https://vuldb.com/vuln/411906","https://vuldb.com/vuln/411906/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:25","euvd":{"id":"EUVD-2026-89962","description":"A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. It is suggested to install a patch to address this issue. A solution was implemented: \"I've chosen to fix this slightly differently by using the defined macro in the font parsing loop rather than in the callsubr function, because this better matches the pattern of 'normal' usage.\"","published_time":"2026-09-30T14:15:06","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411906","https://vuldb.com/vuln/411906/cti","https://vuldb.com/cve/CVE-2026-103226","https://vuldb.com/submit/955016","https://bugs.ghostscript.com/show_bug.cgi?id=709672","https://bugs.ghostscript.com/show_bug.cgi?id=709672#c3","https://bugs.ghostscript.com/attachment.cgi?id=28495","https://artifex.com/"],"products":["ghostscript"],"vendors":["Artifex"]}},{"cve_id":"CVE-2026-102984","summary":"Astro is a web framework for content-driven websites. Prior to 11.1.3, the @astrojs/node adapter builds a request URL from the Host header, and a malformed port can make that URL invalid. The recovery path reuses the same malformed host and throws an uncaught TypeError: Invalid URL before routing begins. In the default standalone configuration, the request returns an HTTP 500 response and the server continues running, but when staticHeaders is enabled the synchronous handler does not catch the exception and the Node process terminates. Proxies and CDNs that reject malformed Host headers prevent this path from reaching the origin. The issue affects availability only and does not expose data or permit code execution. This issue is fixed in version 11.1.3.","cvss":8.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/withastro/astro/commit/2066f39c60707a100531b4ef4bb5dab8feafa7f2","https://github.com/withastro/astro/pull/17572","https://github.com/withastro/astro/releases/tag/@astrojs/node@11.1.3","https://github.com/withastro/astro/security/advisories/GHSA-qh8j-hqjv-7m4x"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:23","euvd":{"id":"EUVD-2026-89970","description":"Astro: Malformed port in the Host header can crash the Node adapter","published_time":"2026-09-30T23:29:40","cvss":8.2,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/withastro/astro/security/advisories/GHSA-qh8j-hqjv-7m4x","https://github.com/withastro/astro/pull/17572","https://github.com/withastro/astro/commit/2066f39c60707a100531b4ef4bb5dab8feafa7f2","https://github.com/withastro/astro/releases/tag/@astrojs/node@11.1.3","https://nvd.nist.gov/vuln/detail/CVE-2026-102984"],"products":["astro"],"vendors":["withastro"]}},{"cve_id":"CVE-2026-102983","summary":"Astro is a web framework for content-driven websites. From 5.2.0 until 8.2.4, the @astrojs/netlify adapter generates regular expressions for Netlify Image CDN remote-image allowlists without anchoring them to the beginning of the URL. Because Netlify evaluates these expressions with RegExp.test(), an allowed origin appearing only in a source URL's path or query can satisfy image.domains or image.remotePatterns while the URL's actual host remains attacker-controlled. An unauthenticated request to the public /.netlify/images endpoint can therefore cause the Image CDN to request attacker-selected URLs and may probe or reach internal services. Netlify egress protections may constrain reachable targets, and image transformation limits direct response exfiltration; no confidentiality or integrity impact has been demonstrated. This issue is fixed in version 8.2.4.","cvss":6.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/withastro/astro/commit/e362d4cf540b27730482455c8fc02efe57d16702","https://github.com/withastro/astro/pull/17752","https://github.com/withastro/astro/releases/tag/@astrojs/netlify@8.2.4","https://github.com/withastro/astro/security/advisories/GHSA-4233-jc72-56c5"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:22","euvd":{"id":"EUVD-2026-89969","description":"Astro: Netlify Image CDN allowlist bypass enables SSRF","published_time":"2026-09-30T23:40:12","cvss":6.3,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/withastro/astro/security/advisories/GHSA-4233-jc72-56c5","https://github.com/withastro/astro/pull/17752","https://github.com/withastro/astro/commit/e362d4cf540b27730482455c8fc02efe57d16702","https://github.com/withastro/astro/releases/tag/@astrojs/netlify@8.2.4","https://nvd.nist.gov/vuln/detail/CVE-2026-102983"],"products":["astro","netlify"],"vendors":["withastro","@astrojs"]}},{"cve_id":"CVE-2026-102717","summary":"MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-hp64-f44f-wjw6"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:21","euvd":{"id":"EUVD-2026-89968","description":"MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash","published_time":"2026-09-30T14:31:22","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-hp64-f44f-wjw6"],"products":["NetX Duo"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-101295","summary":"Path traversal / arbitrary file write in oc-mirror's operator catalog image extraction. When mirroring operator catalogs using either the legacy v1 path (--v1) or the OCI feature path (--use-oci-feature), oc-mirror extracts tar entries from catalog image layers without validating that file paths resolve within the intended destination directory.","cvss":7.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-101295","https://bugzilla.redhat.com/show_bug.cgi?id=2522941","https://github.com/openshift/oc-mirror/blob/22a5722/v1/pkg/cli/mirror/catalog_images.go#L680","https://github.com/openshift/oc-mirror/blob/22a5722/v1/pkg/cli/mirror/fbc_operators.go#L334-L369"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T15:22:19","euvd":{"id":"EUVD-2026-89959","description":"Path traversal / arbitrary file write in oc-mirror's operator catalog image extraction. When mirroring operator catalogs using either the legacy v1 path (--v1) or the OCI feature path (--use-oci-feature), oc-mirror extracts tar entries from catalog image layers without validating that file paths resolve within the intended destination directory.","published_time":"2026-09-30T14:06:16","cvss":7.3,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-101295","https://bugzilla.redhat.com/show_bug.cgi?id=2522941","https://github.com/openshift/oc-mirror/blob/22a5722/v1/pkg/cli/mirror/catalog_images.go#L680","https://github.com/openshift/oc-mirror/blob/22a5722/v1/pkg/cli/mirror/fbc_operators.go#L334-L369"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-93903","summary":"LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain \"corner case.\"","cvss":9.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.4,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.litespeedtech.com/lsws/changelog/#v6-3-7-build-1","https://www.litespeedtech.com/products/litespeed-web-server/release-log"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T14:17:37","euvd":{"id":"EUVD-2026-89955","description":"LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain \"corner case.\"","published_time":"2026-09-30T13:44:11","cvss":9.4,"cvss_version":"4.0","epss":0.0,"assigner":"mitre","references":["https://www.litespeedtech.com/products/litespeed-web-server/release-log","https://docs.litespeedtech.com/lsws/changelog/#v6-3-7-build-1"],"products":["LiteSpeed Web Server"],"vendors":["litespeedtech"]}},{"cve_id":"CVE-2026-91860","summary":"A prototype pollution vulnerability exists in the deep merge helpers of Vaadin Charts and Vaadin Component Base. Merging an object the application does not control into a chart configuration or into a component's i18n property writes onto Object.prototype, making the injected properties visible to every object in the running application.\n\n\nUsers of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:\n\nProduct version\nVaadin 23.0.0 - 23.6.13\nVaadin 24.0.0 - 24.9.20\nVaadin 24.10.0 - 24.10.9\nVaadin 25.0.0 - 25.1.11\nVaadin 25.2.0 - 25.2.6\n\nMitigation\nUpgrade to 23.6.14\nUpgrade to 24.9.21\nUpgrade to 24.10.10\nUpgrade to 25.1.12\nUpgrade to 25.2.7 or newer\n\nPlease note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, 25 version.\n\nArtifacts\nMaven coordinates Vulnerable versions Fixed version\ncom.vaadin:vaadin 23.0.0 - 23.6.13 >=23.6.14\ncom.vaadin:vaadin 24.0.0 - 24.9.20 >=24.9.21\ncom.vaadin:vaadin 24.10.0 - 24.10.9 >=24.10.10\ncom.vaadin:vaadin 25.0.0 - 25.1.11 >=25.1.12\ncom.vaadin:vaadin 25.2.0 - 25.2.6 >=25.2.7\ncom.vaadin:vaadin-core 24.7.0 - 24.9.20 >=24.9.21\ncom.vaadin:vaadin-core 24.10.0 - 24.10.9 >=24.10.10\ncom.vaadin:vaadin-core 25.0.0 - 25.1.11 >=25.1.12\ncom.vaadin:vaadin-core 25.2.0 - 25.2.6 >=25.2.7\ncom.vaadin:vaadin-charts-flow 23.0.0 - 23.6.13 >=23.6.14\ncom.vaadin:vaadin-charts-flow 24.0.0 - 24.9.20 >=24.9.21\ncom.vaadin:vaadin-charts-flow 24.10.0 - 24.10.9 >=24.10.10\ncom.vaadin:vaadin-charts-flow 25.0.0 - 25.1.11 >=25.1.12\ncom.vaadin:vaadin-charts-flow 25.2.0 - 25.2.6 >=25.2.7\n\nnpm packages\nnpm package Vulnerable versions Fixed version\n@vaadin/charts 23.0.0 - 23.6.4 >=23.6.5\n@vaadin/charts 24.0.0 - 24.9.17 >=24.9.18\n@vaadin/charts 24.10.0 - 24.10.4 >=24.10.5\n@vaadin/charts 25.0.0 - 25.1.11 >=25.1.12\n@vaadin/charts 25.2.0 - 25.2.8 >=25.2.9\n@vaadin/component-base 24.7.0 - 24.9.17 >=24.9.18\n@vaadin/component-base 24.10.0 - 24.10.4 >=24.10.5\n@vaadin/component-base 25.0.0 - 25.1.11 >=25.1.12\n@vaadin/component-base 25.2.0 - 25.2.8 >=25.2.9","cvss":6.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/vaadin/web-components/pull/12483","https://github.com/vaadin/web-components/pull/12492","https://github.com/vaadin/web-components/pull/12493","https://github.com/vaadin/web-components/pull/12494","https://github.com/vaadin/web-components/pull/12496","https://github.com/vaadin/web-components/pull/12559","https://vaadin.com/security/cve-2026-91860"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T14:17:34","euvd":{"id":"EUVD-2026-89951","description":"A prototype pollution vulnerability exists in the deep merge helpers of Vaadin Charts and Vaadin Component Base. Merging an object the application does not control into a chart configuration or into a component's i18n property writes onto Object.prototype, making the injected properties visible to every object in the running application.\n\n\nUsers of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:\n\nProduct version\nVaadin 23.0.0 - 23.6.13\nVaadin 24.0.0 - 24.9.20\nVaadin 24.10.0 - 24.10.9\nVaadin 25.0.0 - 25.1.11\nVaadin 25.2.0 - 25.2.6\n\nMitigation\nUpgrade to 23.6.14\nUpgrade to 24.9.21\nUpgrade to 24.10.10\nUpgrade to 25.1.12\nUpgrade to 25.2.7 or newer\n\nPlease note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, 25 version.\n\nArtifacts\nMaven coordinates Vulnerable versions Fixed version\ncom.vaadin:vaadin 23.0.0 - 23.6.13 >=23.6.14\ncom.vaadin:vaadin 24.0.0 - 24.9.20 >=24.9.21\ncom.vaadin:vaadin 24.10.0 - 24.10.9 >=24.10.10\ncom.vaadin:vaadin 25.0.0 - 25.1.11 >=25.1.12\ncom.vaadin:vaadin 25.2.0 - 25.2.6 >=25.2.7\ncom.vaadin:vaadin-core 24.7.0 - 24.9.20 >=24.9.21\ncom.vaadin:vaadin-core 24.10.0 - 24.10.9 >=24.10.10\ncom.vaadin:vaadin-core 25.0.0 - 25.1.11 >=25.1.12\ncom.vaadin:vaadin-core 25.2.0 - 25.2.6 >=25.2.7\ncom.vaadin:vaadin-charts-flow 23.0.0 - 23.6.13 >=23.6.14\ncom.vaadin:vaadin-charts-flow 24.0.0 - 24.9.20 >=24.9.21\ncom.vaadin:vaadin-charts-flow 24.10.0 - 24.10.9 >=24.10.10\ncom.vaadin:vaadin-charts-flow 25.0.0 - 25.1.11 >=25.1.12\ncom.vaadin:vaadin-charts-flow 25.2.0 - 25.2.6 >=25.2.7\n\nnpm packages\nnpm package Vulnerable versions Fixed version\n@vaadin/charts 23.0.0 - 23.6.4 >=23.6.5\n@vaadin/charts 24.0.0 - 24.9.17 >=24.9.18\n@vaadin/charts 24.10.0 - 24.10.4 >=24.10.5\n@vaadin/charts 25.0.0 - 25.1.11 >=25.1.12\n@vaadin/charts 25.2.0 - 25.2.8 >=25.2.9\n@vaadin/component-base 24.7.0 - 24.9.17 >=24.9.18\n@vaadin/component-base 24.10.0 - 24.10.4 >=24.10.5\n@vaadin/component-base 25.0.0 - 25.1.11 >=25.1.12\n@vaadin/component-base 25.2.0 - 25.2.8 >=25.2.9","published_time":"2026-09-30T13:13:05","cvss":6.3,"cvss_version":"4.0","epss":0.0,"assigner":"Vaadin","references":["https://vaadin.com/security/cve-2026-91860","https://github.com/vaadin/web-components/pull/12483","https://github.com/vaadin/web-components/pull/12492","https://github.com/vaadin/web-components/pull/12493","https://github.com/vaadin/web-components/pull/12494","https://github.com/vaadin/web-components/pull/12496","https://github.com/vaadin/web-components/pull/12559"],"products":["Vaadin","@vaadin/component-base","vaadin-core","@vaadin/charts","vaadin-core","@vaadin/component-base","Vaadin","@vaadin/charts","vaadin-charts-flow","vaadin-core","@vaadin/charts","Vaadin","vaadin-charts-flow","vaadin-charts-flow","Vaadin","Vaadin","@vaadin/charts","@vaadin/component-base","@vaadin/charts","@vaadin/component-base","vaadin-core","vaadin-charts-flow","vaadin-charts-flow"],"vendors":["Vaadin"]}},{"cve_id":"CVE-2026-93547","summary":"A missing authorization check in the Vaadin Spreadsheet component allows an authenticated user of an application that renders a spreadsheet to add or replace cell comments on a sheet that has protection enabled, including on cells that are locked. Writing a comment to a cell that does not exist yet also creates the row and the cell.\n\n\nUsers of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:\n\nProduct version\nVaadin 23.1.0 - 23.6.13\nVaadin 24.0.0 - 24.9.21\nVaadin 24.10.0 - 24.10.9\nVaadin 25.0.0 - 25.1.11\nVaadin 25.2.0 - 25.2.6\nVaadin Framework 7 and 8 with the Spreadsheet add-on 2.0.0 - 3.1.0\n\nMitigation\nUpgrade to 23.6.14\nUpgrade to 24.9.22\nUpgrade to 24.10.10\nUpgrade to 25.1.12\nUpgrade to 25.2.7 or newer\nUpgrade the Spreadsheet add-on to 3.1.1\n\nPlease note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, 25 version.\n\nArtifacts\nMaven coordinates Vulnerable versions Fixed version\ncom.vaadin:vaadin 23.1.0 - 23.6.13 >=23.6.14\ncom.vaadin:vaadin 24.0.0 - 24.9.21 >=24.9.22\ncom.vaadin:vaadin 24.10.0 - 24.10.9 >=24.10.10\ncom.vaadin:vaadin 25.0.0 - 25.1.11 >=25.1.12\ncom.vaadin:vaadin 25.2.0 - 25.2.6 >=25.2.7\ncom.vaadin:vaadin-spreadsheet-flow 23.1.0 - 23.6.13 >=23.6.14\ncom.vaadin:vaadin-spreadsheet-flow 24.0.0 - 24.9.21 >=24.9.22\ncom.vaadin:vaadin-spreadsheet-flow 24.10.0 - 24.10.9 >=24.10.10\ncom.vaadin:vaadin-spreadsheet-flow 25.0.0 - 25.1.11 >=25.1.12\ncom.vaadin:vaadin-spreadsheet-flow 25.2.0 - 25.2.6 >=25.2.7\ncom.vaadin:vaadin-spreadsheet 2.0.0 - 3.1.0 >=3.1.1","cvss":5.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/vaadin/flow-components/pull/9905","https://github.com/vaadin/flow-components/pull/9907","https://github.com/vaadin/flow-components/pull/9908","https://github.com/vaadin/flow-components/pull/9909","https://github.com/vaadin/flow-components/pull/9910","https://github.com/vaadin/flow-components/pull/9956","https://github.com/vaadin/spreadsheet/pull/866","https://vaadin.com/security/cve-2026-93547"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T14:17:34","euvd":{"id":"EUVD-2026-89952","description":"A missing authorization check in the Vaadin Spreadsheet component allows an authenticated user of an application that renders a spreadsheet to add or replace cell comments on a sheet that has protection enabled, including on cells that are locked. Writing a comment to a cell that does not exist yet also creates the row and the cell.\n\n\nUsers of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:\n\nProduct version\nVaadin 23.1.0 - 23.6.13\nVaadin 24.0.0 - 24.9.21\nVaadin 24.10.0 - 24.10.9\nVaadin 25.0.0 - 25.1.11\nVaadin 25.2.0 - 25.2.6\nVaadin Framework 7 and 8 with the Spreadsheet add-on 2.0.0 - 3.1.0\n\nMitigation\nUpgrade to 23.6.14\nUpgrade to 24.9.22\nUpgrade to 24.10.10\nUpgrade to 25.1.12\nUpgrade to 25.2.7 or newer\nUpgrade the Spreadsheet add-on to 3.1.1\n\nPlease note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, 25 version.\n\nArtifacts\nMaven coordinates Vulnerable versions Fixed version\ncom.vaadin:vaadin 23.1.0 - 23.6.13 >=23.6.14\ncom.vaadin:vaadin 24.0.0 - 24.9.21 >=24.9.22\ncom.vaadin:vaadin 24.10.0 - 24.10.9 >=24.10.10\ncom.vaadin:vaadin 25.0.0 - 25.1.11 >=25.1.12\ncom.vaadin:vaadin 25.2.0 - 25.2.6 >=25.2.7\ncom.vaadin:vaadin-spreadsheet-flow 23.1.0 - 23.6.13 >=23.6.14\ncom.vaadin:vaadin-spreadsheet-flow 24.0.0 - 24.9.21 >=24.9.22\ncom.vaadin:vaadin-spreadsheet-flow 24.10.0 - 24.10.9 >=24.10.10\ncom.vaadin:vaadin-spreadsheet-flow 25.0.0 - 25.1.11 >=25.1.12\ncom.vaadin:vaadin-spreadsheet-flow 25.2.0 - 25.2.6 >=25.2.7\ncom.vaadin:vaadin-spreadsheet 2.0.0 - 3.1.0 >=3.1.1","published_time":"2026-09-30T13:13:13","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"Vaadin","references":["https://vaadin.com/security/cve-2026-93547","https://github.com/vaadin/flow-components/pull/9905","https://github.com/vaadin/flow-components/pull/9907","https://github.com/vaadin/flow-components/pull/9908","https://github.com/vaadin/flow-components/pull/9909","https://github.com/vaadin/flow-components/pull/9910","https://github.com/vaadin/flow-components/pull/9956","https://github.com/vaadin/spreadsheet/pull/866"],"products":["Vaadin","vaadin-spreadsheet-flow","Vaadin","Vaadin","vaadin-spreadsheet-flow","vaadin-spreadsheet-flow","Vaadin","vaadin-spreadsheet-flow","vaadin-spreadsheet","vaadin-spreadsheet-flow","Vaadin"],"vendors":["Vaadin"]}},{"cve_id":"CVE-2026-82307","summary":"Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection.\n\nThis issue affects SOPLOG: before Soplog 2026.9.4.1.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1224"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T14:17:31","euvd":{"id":"EUVD-2026-89953","description":"Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection.\n\nThis issue affects SOPLOG: before Soplog 2026.9.4.1.","published_time":"2026-09-30T13:20:43","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"TR-CERT","references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1224"],"products":["SOPLOG"],"vendors":["Dolusoft Software Technologies"]}},{"cve_id":"CVE-2026-103118","summary":"A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler. Performing a manipulation results in uncontrolled recursion. The attack may be initiated remotely. The patch is named 627b5b1b2fc2. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.","cvss":5.3,"cvss_version":4.0,"cvss_v2":5.0,"cvss_v3":4.3,"cvss_v4":5.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/627b5b1b2fc2","https://vuldb.com/cve/CVE-2026-103118","https://vuldb.com/submit/954970","https://vuldb.com/vuln/411874","https://vuldb.com/vuln/411874/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T14:17:27","euvd":{"id":"EUVD-2026-89954","description":"A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler. Performing a manipulation results in uncontrolled recursion. The attack may be initiated remotely. The patch is named 627b5b1b2fc2. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.","published_time":"2026-09-30T13:30:05","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411874","https://vuldb.com/vuln/411874/cti","https://vuldb.com/cve/CVE-2026-103118","https://vuldb.com/submit/954970","https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/627b5b1b2fc2"],"products":["GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick","GraphicsMagick"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-97302","summary":"Unauthenticated Sensitive Data Exposure in MPG <= 4.2.3 versions.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/multiple-pages-generator-by-porthas/vulnerability/wordpress-mpg-plugin-4-2-3-sensitive-data-exposure-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:40","euvd":{"id":"EUVD-2026-89936","description":"Unauthenticated Sensitive Data Exposure in MPG <= 4.2.3 versions.","published_time":"2026-09-30T12:28:25","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/multiple-pages-generator-by-porthas/vulnerability/wordpress-mpg-plugin-4-2-3-sensitive-data-exposure-vulnerability?_s_id=cve"],"products":["MPG"],"vendors":["themeisle"]}},{"cve_id":"CVE-2026-97288","summary":"Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/oauth2-provider/vulnerability/wordpress-oauth-server-plugin-4-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:39","euvd":{"id":"EUVD-2026-89929","description":"Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions.","published_time":"2026-09-30T12:28:20","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/oauth2-provider/vulnerability/wordpress-oauth-server-plugin-4-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["OAuth Server"],"vendors":["Jayson T Cote"]}},{"cve_id":"CVE-2026-97289","summary":"Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/quiz-master-next/vulnerability/wordpress-quiz-and-survey-master-plugin-11-2-6-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:39","euvd":{"id":"EUVD-2026-89930","description":"Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions.","published_time":"2026-09-30T12:28:20","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/quiz-master-next/vulnerability/wordpress-quiz-and-survey-master-plugin-11-2-6-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Quiz And Survey Master"],"vendors":["ExpressTech Systems"]}},{"cve_id":"CVE-2026-97292","summary":"Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/yith-woocommerce-tab-manager/vulnerability/wordpress-yith-woocommerce-tab-manager-plugin-2-15-0-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:39","euvd":{"id":"EUVD-2026-89931","description":"Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions.","published_time":"2026-09-30T12:28:21","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/yith-woocommerce-tab-manager/vulnerability/wordpress-yith-woocommerce-tab-manager-plugin-2-15-0-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["YITH WooCommerce Tab Manager"],"vendors":["yithemes"]}},{"cve_id":"CVE-2026-97293","summary":"Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.","cvss":8.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/media-library-assistant/vulnerability/wordpress-media-library-assistant-plugin-3-41-sql-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:39","euvd":{"id":"EUVD-2026-89932","description":"Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.","published_time":"2026-09-30T12:28:22","cvss":8.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/media-library-assistant/vulnerability/wordpress-media-library-assistant-plugin-3-41-sql-injection-vulnerability?_s_id=cve"],"products":["Media Library Assistant"],"vendors":["David Lingren"]}},{"cve_id":"CVE-2026-97298","summary":"Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.86 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/king-addons/vulnerability/wordpress-king-addons-for-elementor-plugin-51-1-86-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:39","euvd":{"id":"EUVD-2026-89933","description":"Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.86 versions.","published_time":"2026-09-30T12:28:23","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/king-addons/vulnerability/wordpress-king-addons-for-elementor-plugin-51-1-86-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["King Addons for Elementor"],"vendors":["kingaddons"]}},{"cve_id":"CVE-2026-97299","summary":"Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/rzp-woocommerce/vulnerability/wordpress-razorpay-payment-links-for-woocommerce-plugin-2-1-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:39","euvd":{"id":"EUVD-2026-89934","description":"Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions.","published_time":"2026-09-30T12:28:23","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/rzp-woocommerce/vulnerability/wordpress-razorpay-payment-links-for-woocommerce-plugin-2-1-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"],"products":["Razorpay Payment Links for WooCommerce"],"vendors":["knitpay"]}},{"cve_id":"CVE-2026-97301","summary":"Contributor Cross Site Scripting (XSS) in Cool Formkit Lite <= 2.7.8 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/extensions-for-elementor-form/vulnerability/wordpress-cool-formkit-lite-plugin-2-7-8-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:39","euvd":{"id":"EUVD-2026-89935","description":"Contributor Cross Site Scripting (XSS) in Cool Formkit Lite <= 2.7.8 versions.","published_time":"2026-09-30T12:28:24","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/extensions-for-elementor-form/vulnerability/wordpress-cool-formkit-lite-plugin-2-7-8-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Cool Formkit Lite"],"vendors":["Cool Plugins"]}},{"cve_id":"CVE-2026-97271","summary":"Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/wpfunnels/vulnerability/wordpress-wpfunnels-plugin-3-13-1-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:38","euvd":{"id":"EUVD-2026-89921","description":"Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.","published_time":"2026-09-30T12:28:14","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/wpfunnels/vulnerability/wordpress-wpfunnels-plugin-3-13-1-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["WPFunnels"],"vendors":["WPFunnels"]}},{"cve_id":"CVE-2026-97272","summary":"Unauthenticated Cross Site Scripting (XSS) in Premmerce Permalink Manager for WooCommerce <= 2.3.13 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/woo-permalink-manager/vulnerability/wordpress-premmerce-permalink-manager-for-woocommerce-plugin-2-3-13-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:38","euvd":{"id":"EUVD-2026-89922","description":"Unauthenticated Cross Site Scripting (XSS) in Premmerce Permalink Manager for WooCommerce <= 2.3.13 versions.","published_time":"2026-09-30T12:28:14","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/woo-permalink-manager/vulnerability/wordpress-premmerce-permalink-manager-for-woocommerce-plugin-2-3-13-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Premmerce Permalink Manager for WooCommerce"],"vendors":["premmerce"]}},{"cve_id":"CVE-2026-97274","summary":"Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/miniorange-login-with-eve-online-google-facebook/vulnerability/wordpress-oauth-single-sign-on-sso-oauth-client-plugin-7-1-2-bypass-vulnerability-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:38","euvd":{"id":"EUVD-2026-89923","description":"Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions.","published_time":"2026-09-30T12:28:15","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/miniorange-login-with-eve-online-google-facebook/vulnerability/wordpress-oauth-single-sign-on-sso-oauth-client-plugin-7-1-2-bypass-vulnerability-vulnerability?_s_id=cve"],"products":["OAuth Single Sign On – SSO (OAuth Client)"],"vendors":["miniorange"]}},{"cve_id":"CVE-2026-97279","summary":"Contributor Cross Site Scripting (XSS) in Polylang <= 3.8.9 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/polylang/vulnerability/wordpress-polylang-plugin-3-8-9-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:38","euvd":{"id":"EUVD-2026-89924","description":"Contributor Cross Site Scripting (XSS) in Polylang <= 3.8.9 versions.","published_time":"2026-09-30T12:28:16","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/polylang/vulnerability/wordpress-polylang-plugin-3-8-9-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Polylang"],"vendors":["Chouby"]}},{"cve_id":"CVE-2026-97282","summary":"Unauthenticated Insecure Direct Object References (IDOR) in Review Schema <= 3.1.0 versions.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/review-schema/vulnerability/wordpress-review-schema-plugin-3-1-0-insecure-direct-object-references-idor-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:38","euvd":{"id":"EUVD-2026-89925","description":"Unauthenticated Insecure Direct Object References (IDOR) in Review Schema <= 3.1.0 versions.","published_time":"2026-09-30T12:28:17","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/review-schema/vulnerability/wordpress-review-schema-plugin-3-1-0-insecure-direct-object-references-idor-vulnerability?_s_id=cve"],"products":["Review Schema"],"vendors":["RadiusTheme"]}},{"cve_id":"CVE-2026-97285","summary":"Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/the-events-calendar/vulnerability/wordpress-the-events-calendar-plugin-6-17-5-broken-access-control-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:38","euvd":{"id":"EUVD-2026-89926","description":"Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions.","published_time":"2026-09-30T12:28:17","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/the-events-calendar/vulnerability/wordpress-the-events-calendar-plugin-6-17-5-broken-access-control-vulnerability?_s_id=cve"],"products":["The Events Calendar"],"vendors":["Nexcess"]}},{"cve_id":"CVE-2026-97286","summary":"Contributor Cross Site Scripting (XSS) in Strong Testimonials <= 3.3.11 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/strong-testimonials/vulnerability/wordpress-strong-testimonials-plugin-3-3-11-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:38","euvd":{"id":"EUVD-2026-89927","description":"Contributor Cross Site Scripting (XSS) in Strong Testimonials <= 3.3.11 versions.","published_time":"2026-09-30T12:28:18","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/strong-testimonials/vulnerability/wordpress-strong-testimonials-plugin-3-3-11-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Strong Testimonials"],"vendors":["WP Chill"]}},{"cve_id":"CVE-2026-97287","summary":"Contributor SQL Injection in Event Tickets <= 5.29.5 versions.","cvss":8.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/event-tickets/vulnerability/wordpress-event-tickets-plugin-5-29-5-sql-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:38","euvd":{"id":"EUVD-2026-89928","description":"Contributor SQL Injection in Event Tickets <= 5.29.5 versions.","published_time":"2026-09-30T12:28:19","cvss":8.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/event-tickets/vulnerability/wordpress-event-tickets-plugin-5-29-5-sql-injection-vulnerability?_s_id=cve"],"products":["Event Tickets"],"vendors":["Nexcess"]}},{"cve_id":"CVE-2026-97250","summary":"Unauthenticated Cross Site Scripting (XSS) in  Geo Mashup <= 1.13.21 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/geo-mashup/vulnerability/wordpress-geo-mashup-plugin-1-13-21-cross-site-scripting-xss-vulnerability-2?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:37","euvd":{"id":"EUVD-2026-89914","description":"Unauthenticated Cross Site Scripting (XSS) in  Geo Mashup <= 1.13.21 versions.","published_time":"2026-09-30T12:28:07","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/geo-mashup/vulnerability/wordpress-geo-mashup-plugin-1-13-21-cross-site-scripting-xss-vulnerability-2?_s_id=cve"],"products":["Geo Mashup"],"vendors":["Dylan Kuhn"]}},{"cve_id":"CVE-2026-97253","summary":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kreatura LayerSlider allows Reflected XSS.\n\nThis issue affects LayerSlider: from n/a through 8.4.0.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/layerslider/vulnerability/wordpress-layerslider-plugin-8-4-0-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:37","euvd":{"id":"EUVD-2026-89915","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kreatura LayerSlider allows Reflected XSS.\n\nThis issue affects LayerSlider: from n/a through 8.4.0.","published_time":"2026-09-30T12:28:08","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/layerslider/vulnerability/wordpress-layerslider-plugin-8-4-0-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["LayerSlider"],"vendors":["Kreatura"]}},{"cve_id":"CVE-2026-97261","summary":"Unauthenticated Sensitive Data Exposure in Notivo <= 1.4.2 versions.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/woo-notification/vulnerability/wordpress-notivo-plugin-1-4-2-sensitive-data-exposure-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:37","euvd":{"id":"EUVD-2026-89916","description":"Unauthenticated Sensitive Data Exposure in Notivo <= 1.4.2 versions.","published_time":"2026-09-30T12:28:10","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/woo-notification/vulnerability/wordpress-notivo-plugin-1-4-2-sensitive-data-exposure-vulnerability?_s_id=cve"],"products":["Notivo"],"vendors":["VillaTheme"]}},{"cve_id":"CVE-2026-97262","summary":"Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.2 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/visualcomposer/vulnerability/wordpress-visual-composer-website-builder-plugin-45-16-2-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:37","euvd":{"id":"EUVD-2026-89917","description":"Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.2 versions.","published_time":"2026-09-30T12:28:11","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/visualcomposer/vulnerability/wordpress-visual-composer-website-builder-plugin-45-16-2-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Visual Composer Website Builder"],"vendors":["Visual Composer"]}},{"cve_id":"CVE-2026-97266","summary":"Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12.1 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/virtue-toolkit/vulnerability/wordpress-virtue-ascend-pinnacle-toolkit-plugin-4-9-12-1-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:37","euvd":{"id":"EUVD-2026-89918","description":"Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12.1 versions.","published_time":"2026-09-30T12:28:11","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/virtue-toolkit/vulnerability/wordpress-virtue-ascend-pinnacle-toolkit-plugin-4-9-12-1-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Virtue/Ascend/Pinnacle Toolkit"],"vendors":["Nexcess"]}},{"cve_id":"CVE-2026-97267","summary":"Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/prevent-file-access/vulnerability/wordpress-prevent-files-folders-access-plugin-2-6-7-broken-access-control-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:37","euvd":{"id":"EUVD-2026-89919","description":"Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions.","published_time":"2026-09-30T12:28:12","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/prevent-file-access/vulnerability/wordpress-prevent-files-folders-access-plugin-2-6-7-broken-access-control-vulnerability?_s_id=cve"],"products":["Prevent files / folders access"],"vendors":["miniorange"]}},{"cve_id":"CVE-2026-97270","summary":"Subscriber Cross Site Scripting (XSS) in CMB2 <= 2.13.0 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/cmb2/vulnerability/wordpress-cmb2-plugin-2-13-0-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:37","euvd":{"id":"EUVD-2026-89920","description":"Subscriber Cross Site Scripting (XSS) in CMB2 <= 2.13.0 versions.","published_time":"2026-09-30T12:28:13","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/cmb2/vulnerability/wordpress-cmb2-plugin-2-13-0-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["CMB2"],"vendors":["Justin Sternberg"]}},{"cve_id":"CVE-2026-97242","summary":"Author Arbitrary File Deletion in WEBO MCP <= 3.0.18 versions.","cvss":6.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/webo-mcp/vulnerability/wordpress-webo-mcp-plugin-3-0-18-arbitrary-file-deletion-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:36","euvd":{"id":"EUVD-2026-89906","description":"Author Arbitrary File Deletion in WEBO MCP <= 3.0.18 versions.","published_time":"2026-09-30T12:28:01","cvss":6.8,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/webo-mcp/vulnerability/wordpress-webo-mcp-plugin-3-0-18-arbitrary-file-deletion-vulnerability?_s_id=cve"],"products":["WEBO MCP"],"vendors":["phuongwebo"]}},{"cve_id":"CVE-2026-97243","summary":"Subscriber Broken Access Control in AllAble Connector <= 0.13.4 versions.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/allable-connector/vulnerability/wordpress-allable-connector-plugin-0-13-4-broken-access-control-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:36","euvd":{"id":"EUVD-2026-89907","description":"Subscriber Broken Access Control in AllAble Connector <= 0.13.4 versions.","published_time":"2026-09-30T12:28:02","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/allable-connector/vulnerability/wordpress-allable-connector-plugin-0-13-4-broken-access-control-vulnerability?_s_id=cve"],"products":["AllAble Connector"],"vendors":["flexyma"]}},{"cve_id":"CVE-2026-97244","summary":"Contributor Path Traversal in Creator LMS <= 1.2.19 versions.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/creatorlms/vulnerability/wordpress-creator-lms-plugin-1-2-19-path-traversal-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:36","euvd":{"id":"EUVD-2026-89908","description":"Contributor Path Traversal in Creator LMS <= 1.2.19 versions.","published_time":"2026-09-30T12:28:03","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/creatorlms/vulnerability/wordpress-creator-lms-plugin-1-2-19-path-traversal-vulnerability?_s_id=cve"],"products":["Creator LMS"],"vendors":["WPFunnels"]}},{"cve_id":"CVE-2026-97245","summary":"Shop Worker Privilege Escalation in SureCart <= 4.7.2 versions.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/surecart/vulnerability/wordpress-surecart-plugin-4-7-2-privilege-escalation-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:36","euvd":{"id":"EUVD-2026-89909","description":"Shop Worker Privilege Escalation in SureCart <= 4.7.2 versions.","published_time":"2026-09-30T12:28:03","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/surecart/vulnerability/wordpress-surecart-plugin-4-7-2-privilege-escalation-vulnerability?_s_id=cve"],"products":["SureCart"],"vendors":["SureCart"]}},{"cve_id":"CVE-2026-97246","summary":"Subscriber PHP Object Injection in ShortPixel Image Optimizer <= 6.5.5 versions.","cvss":4.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/shortpixel-image-optimiser/vulnerability/wordpress-shortpixel-image-optimizer-plugin-6-5-5-php-object-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:36","euvd":{"id":"EUVD-2026-89910","description":"Subscriber PHP Object Injection in ShortPixel Image Optimizer <= 6.5.5 versions.","published_time":"2026-09-30T12:28:04","cvss":4.9,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/shortpixel-image-optimiser/vulnerability/wordpress-shortpixel-image-optimizer-plugin-6-5-5-php-object-injection-vulnerability?_s_id=cve"],"products":["ShortPixel Image Optimizer"],"vendors":["shortpixel"]}},{"cve_id":"CVE-2026-97247","summary":"Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/blocksy-companion/vulnerability/wordpress-blocksy-companion-plugin-2-1-55-broken-access-control-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:36","euvd":{"id":"EUVD-2026-89911","description":"Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions.","published_time":"2026-09-30T12:28:05","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/blocksy-companion/vulnerability/wordpress-blocksy-companion-plugin-2-1-55-broken-access-control-vulnerability?_s_id=cve"],"products":["Blocksy Companion"],"vendors":["Creative Themes"]}},{"cve_id":"CVE-2026-97248","summary":"Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/booking-activities/vulnerability/wordpress-booking-activities-plugin-1-18-7-1-php-object-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:36","euvd":{"id":"EUVD-2026-89912","description":"Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.","published_time":"2026-09-30T12:28:06","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/booking-activities/vulnerability/wordpress-booking-activities-plugin-1-18-7-1-php-object-injection-vulnerability?_s_id=cve"],"products":["Booking Activities"],"vendors":["Booking Activities Team"]}},{"cve_id":"CVE-2026-97249","summary":"Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/paid-member-subscriptions/vulnerability/wordpress-paid-member-subscriptions-plugin-3-0-9-bypass-vulnerability-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:36","euvd":{"id":"EUVD-2026-89913","description":"Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions.","published_time":"2026-09-30T12:28:06","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/paid-member-subscriptions/vulnerability/wordpress-paid-member-subscriptions-plugin-3-0-9-bypass-vulnerability-vulnerability?_s_id=cve"],"products":["Paid Member Subscriptions"],"vendors":["Cozmoslabs"]}},{"cve_id":"CVE-2026-97235","summary":"Unauthenticated Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/trx_addons/vulnerability/wordpress-themerex-addons-plugin-2-45-0-cross-site-scripting-xss-vulnerability-2?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:35","euvd":{"id":"EUVD-2026-89899","description":"Unauthenticated Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions.","published_time":"2026-09-30T12:27:55","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/trx_addons/vulnerability/wordpress-themerex-addons-plugin-2-45-0-cross-site-scripting-xss-vulnerability-2?_s_id=cve"],"products":["ThemeREX Addons"],"vendors":["themerex"]}},{"cve_id":"CVE-2026-97236","summary":"Subscriber Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/trx_addons/vulnerability/wordpress-themerex-addons-plugin-2-45-0-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:35","euvd":{"id":"EUVD-2026-89900","description":"Subscriber Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions.","published_time":"2026-09-30T12:27:56","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/trx_addons/vulnerability/wordpress-themerex-addons-plugin-2-45-0-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["ThemeREX Addons"],"vendors":["themerex"]}},{"cve_id":"CVE-2026-97237","summary":"Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/jet-engine/vulnerability/wordpress-jetengine-plugin-3-8-14-3-cross-site-scripting-xss-vulnerability-2?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:35","euvd":{"id":"EUVD-2026-89901","description":"Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.","published_time":"2026-09-30T12:27:57","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/jet-engine/vulnerability/wordpress-jetengine-plugin-3-8-14-3-cross-site-scripting-xss-vulnerability-2?_s_id=cve"],"products":["JetEngine"],"vendors":["Crocoblock. Jetimpex Inc."]}},{"cve_id":"CVE-2026-97238","summary":"Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/jet-engine/vulnerability/wordpress-jetengine-plugin-3-8-14-3-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:35","euvd":{"id":"EUVD-2026-89902","description":"Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.","published_time":"2026-09-30T12:27:58","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/jet-engine/vulnerability/wordpress-jetengine-plugin-3-8-14-3-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["JetEngine"],"vendors":["Crocoblock. Jetimpex Inc."]}},{"cve_id":"CVE-2026-97239","summary":"Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/mcp-content-manager-lite/vulnerability/wordpress-mcp-content-manager-lite-plugin-1-1-0-broken-access-control-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:35","euvd":{"id":"EUVD-2026-89903","description":"Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions.","published_time":"2026-09-30T12:27:59","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/mcp-content-manager-lite/vulnerability/wordpress-mcp-content-manager-lite-plugin-1-1-0-broken-access-control-vulnerability?_s_id=cve"],"products":["MCP Content Manager Lite"],"vendors":["Jose Conti"]}},{"cve_id":"CVE-2026-97240","summary":"Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/stifli-backup-tools/vulnerability/wordpress-stifli-backup-tools-plugin-2-2-7-sensitive-data-exposure-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:35","euvd":{"id":"EUVD-2026-89904","description":"Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions.","published_time":"2026-09-30T12:28:00","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/stifli-backup-tools/vulnerability/wordpress-stifli-backup-tools-plugin-2-2-7-sensitive-data-exposure-vulnerability?_s_id=cve"],"products":["StifLi Backup Tools"],"vendors":["Esteban"]}},{"cve_id":"CVE-2026-97241","summary":"Unauthenticated Sensitive Data Exposure in BackupEase <= 2.2.2 versions.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/backupease/vulnerability/wordpress-backupease-plugin-2-2-2-sensitive-data-exposure-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:35","euvd":{"id":"EUVD-2026-89905","description":"Unauthenticated Sensitive Data Exposure in BackupEase <= 2.2.2 versions.","published_time":"2026-09-30T12:28:00","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/backupease/vulnerability/wordpress-backupease-plugin-2-2-2-sensitive-data-exposure-vulnerability?_s_id=cve"],"products":["BackupEase"],"vendors":["PrecisionWP"]}},{"cve_id":"CVE-2026-97066","summary":"Unauthenticated Insecure Direct Object References (IDOR) in GiveWP <= 4.16.9 versions.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/give/vulnerability/wordpress-givewp-plugin-4-16-9-insecure-direct-object-references-idor-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:34","euvd":{"id":"EUVD-2026-89892","description":"Unauthenticated Insecure Direct Object References (IDOR) in GiveWP <= 4.16.9 versions.","published_time":"2026-09-30T12:27:49","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/give/vulnerability/wordpress-givewp-plugin-4-16-9-insecure-direct-object-references-idor-vulnerability?_s_id=cve"],"products":["GiveWP"],"vendors":["Nexcess"]}},{"cve_id":"CVE-2026-97067","summary":"Contributor Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.7 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/ewww-image-optimizer/vulnerability/wordpress-ewww-image-optimizer-plugin-8-7-7-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:34","euvd":{"id":"EUVD-2026-89893","description":"Contributor Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.7 versions.","published_time":"2026-09-30T12:27:50","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/ewww-image-optimizer/vulnerability/wordpress-ewww-image-optimizer-plugin-8-7-7-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["EWWW Image Optimizer"],"vendors":["Shane Bishop"]}},{"cve_id":"CVE-2026-97074","summary":"Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/omnisend/vulnerability/wordpress-newsletters-email-marketing-sms-and-popups-by-omnisend-plugin-1-9-0-insecure-direct-object-references-idor-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:34","euvd":{"id":"EUVD-2026-89894","description":"Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions.","published_time":"2026-09-30T12:27:51","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/omnisend/vulnerability/wordpress-newsletters-email-marketing-sms-and-popups-by-omnisend-plugin-1-9-0-insecure-direct-object-references-idor-vulnerability?_s_id=cve"],"products":["Newsletters, Email Marketing, SMS and Popups by Omnisend"],"vendors":["Omnisend"]}},{"cve_id":"CVE-2026-97077","summary":"Unauthenticated Cross Site Scripting (XSS) in Ad Inserter <= 2.8.18 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/ad-inserter/vulnerability/wordpress-ad-inserter-plugin-2-8-18-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:34","euvd":{"id":"EUVD-2026-89895","description":"Unauthenticated Cross Site Scripting (XSS) in Ad Inserter <= 2.8.18 versions.","published_time":"2026-09-30T12:27:52","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/ad-inserter/vulnerability/wordpress-ad-inserter-plugin-2-8-18-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Ad Inserter"],"vendors":["spacetime"]}},{"cve_id":"CVE-2026-97078","summary":"Unauthenticated Insecure Direct Object References (IDOR) in Client Invoicing by Sprout Invoices <= 20.8.17 versions.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/sprout-invoices/vulnerability/wordpress-client-invoicing-by-sprout-invoices-plugin-20-8-17-insecure-direct-object-references-idor-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:34","euvd":{"id":"EUVD-2026-89896","description":"Unauthenticated Insecure Direct Object References (IDOR) in Client Invoicing by Sprout Invoices <= 20.8.17 versions.","published_time":"2026-09-30T12:27:53","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/sprout-invoices/vulnerability/wordpress-client-invoicing-by-sprout-invoices-plugin-20-8-17-insecure-direct-object-references-idor-vulnerability?_s_id=cve"],"products":["Client Invoicing by Sprout Invoices"],"vendors":["boldgrid"]}},{"cve_id":"CVE-2026-97079","summary":"Subscriber Insecure Direct Object References (IDOR) in Webba Booking <= 6.5.0 versions.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/webba-booking-lite/vulnerability/wordpress-webba-booking-plugin-6-5-0-insecure-direct-object-references-idor-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:34","euvd":{"id":"EUVD-2026-89897","description":"Subscriber Insecure Direct Object References (IDOR) in Webba Booking <= 6.5.0 versions.","published_time":"2026-09-30T12:27:54","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/webba-booking-lite/vulnerability/wordpress-webba-booking-plugin-6-5-0-insecure-direct-object-references-idor-vulnerability?_s_id=cve"],"products":["Webba Booking"],"vendors":["Webba Appointment Booking"]}},{"cve_id":"CVE-2026-97197","summary":"Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/wp-migration-duplicator/vulnerability/wordpress-wordpress-backup-migration-plugin-1-6-0-broken-access-control-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:34","euvd":{"id":"EUVD-2026-89898","description":"Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions.","published_time":"2026-09-30T12:27:54","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/wp-migration-duplicator/vulnerability/wordpress-wordpress-backup-migration-plugin-1-6-0-broken-access-control-vulnerability?_s_id=cve"],"products":["WordPress Backup & Migration"],"vendors":["webtoffee"]}},{"cve_id":"CVE-2026-96832","summary":"Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/content-egg/vulnerability/wordpress-content-egg-plugin-6-3-1-php-object-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:33","euvd":{"id":"EUVD-2026-89884","description":"Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions.","published_time":"2026-09-30T12:27:43","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/content-egg/vulnerability/wordpress-content-egg-plugin-6-3-1-php-object-injection-vulnerability?_s_id=cve"],"products":["Content Egg"],"vendors":["Keywordrush"]}},{"cve_id":"CVE-2026-96833","summary":"Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/ultimate-addons-for-contact-form-7/vulnerability/wordpress-ultimate-addons-for-contact-form-7-plugin-3-5-51-php-object-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:33","euvd":{"id":"EUVD-2026-89885","description":"Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions.","published_time":"2026-09-30T12:27:44","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/ultimate-addons-for-contact-form-7/vulnerability/wordpress-ultimate-addons-for-contact-form-7-plugin-3-5-51-php-object-injection-vulnerability?_s_id=cve"],"products":["Ultimate Addons for Contact Form 7"],"vendors":["Themefic"]}},{"cve_id":"CVE-2026-96834","summary":"Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/give/vulnerability/wordpress-givewp-plugin-4-16-9-sensitive-data-exposure-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:33","euvd":{"id":"EUVD-2026-89886","description":"Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions.","published_time":"2026-09-30T12:27:45","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/give/vulnerability/wordpress-givewp-plugin-4-16-9-sensitive-data-exposure-vulnerability?_s_id=cve"],"products":["GiveWP"],"vendors":["Nexcess"]}},{"cve_id":"CVE-2026-96835","summary":"Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.85 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/king-addons/vulnerability/wordpress-king-addons-for-elementor-plugin-51-1-85-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:33","euvd":{"id":"EUVD-2026-89887","description":"Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.85 versions.","published_time":"2026-09-30T12:27:46","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/king-addons/vulnerability/wordpress-king-addons-for-elementor-plugin-51-1-85-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["King Addons for Elementor"],"vendors":["KingAddons.com"]}},{"cve_id":"CVE-2026-96836","summary":"Unauthenticated Cross Site Scripting (XSS) in Parsi Date <= 6.3 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/wp-parsidate/vulnerability/wordpress-parsi-date-plugin-6-3-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:33","euvd":{"id":"EUVD-2026-89888","description":"Unauthenticated Cross Site Scripting (XSS) in Parsi Date <= 6.3 versions.","published_time":"2026-09-30T12:27:47","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/wp-parsidate/vulnerability/wordpress-parsi-date-plugin-6-3-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Parsi Date"],"vendors":["Morteza Geransayeh"]}},{"cve_id":"CVE-2026-96837","summary":"Contributor Remote Code Execution (RCE) in CartFlows <= 3.2.0 versions.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/cartflows/vulnerability/wordpress-cartflows-plugin-3-2-0-remote-code-execution-rce-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:33","euvd":{"id":"EUVD-2026-89889","description":"Contributor Remote Code Execution (RCE) in CartFlows <= 3.2.0 versions.","published_time":"2026-09-30T12:27:47","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/cartflows/vulnerability/wordpress-cartflows-plugin-3-2-0-remote-code-execution-rce-vulnerability?_s_id=cve"],"products":["CartFlows"],"vendors":["Brainstorm Force"]}},{"cve_id":"CVE-2026-96838","summary":"Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager &#8211; WooCommerce Anti-Fraud, Blacklist &amp; Checkout Verification <= 2.3.1 versions.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/wc-blacklist-manager/vulnerability/wordpress-blacklist-manager-8211-woocommerce-anti-fraud-blacklist-amp-checkout-verification-plugin-2-3-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:33","euvd":{"id":"EUVD-2026-89890","description":"Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager &#8211; WooCommerce Anti-Fraud, Blacklist &amp; Checkout Verification <= 2.3.1 versions.","published_time":"2026-09-30T12:27:48","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/wc-blacklist-manager/vulnerability/wordpress-blacklist-manager-8211-woocommerce-anti-fraud-blacklist-amp-checkout-verification-plugin-2-3-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"],"products":["Blacklist Manager &#8211; WooCommerce Anti-Fraud, Blacklist &amp; Checkout Verification"],"vendors":["YoOhw Studio"]}},{"cve_id":"CVE-2026-97065","summary":"Unauthenticated Cross Site Scripting (XSS) in Happyforms <= 1.26.15 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/happyforms/vulnerability/wordpress-happyforms-plugin-1-26-15-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:33","euvd":{"id":"EUVD-2026-89891","description":"Unauthenticated Cross Site Scripting (XSS) in Happyforms <= 1.26.15 versions.","published_time":"2026-09-30T12:27:49","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/happyforms/vulnerability/wordpress-happyforms-plugin-1-26-15-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Happyforms"],"vendors":["Happyforms"]}},{"cve_id":"CVE-2026-96824","summary":"Editor Arbitrary File Deletion in Template Kit – Import <= 1.0.16 versions.","cvss":6.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/template-kit-import/vulnerability/wordpress-template-kit-import-plugin-1-0-16-arbitrary-file-deletion-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:32","euvd":{"id":"EUVD-2026-89877","description":"Editor Arbitrary File Deletion in Template Kit – Import <= 1.0.16 versions.","published_time":"2026-09-30T12:27:37","cvss":6.8,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/template-kit-import/vulnerability/wordpress-template-kit-import-plugin-1-0-16-arbitrary-file-deletion-vulnerability?_s_id=cve"],"products":["Template Kit – Import"],"vendors":["envato"]}},{"cve_id":"CVE-2026-96825","summary":"Subscriber Bypass Vulnerability in All In One WP Security & Firewall <= 5.4.8 versions.","cvss":4.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/all-in-one-wp-security-and-firewall/vulnerability/wordpress-all-in-one-wp-security-firewall-plugin-5-4-8-bypass-vulnerability-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:32","euvd":{"id":"EUVD-2026-89878","description":"Subscriber Bypass Vulnerability in All In One WP Security & Firewall <= 5.4.8 versions.","published_time":"2026-09-30T12:27:38","cvss":4.2,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/all-in-one-wp-security-and-firewall/vulnerability/wordpress-all-in-one-wp-security-firewall-plugin-5-4-8-bypass-vulnerability-vulnerability?_s_id=cve"],"products":["All In One WP Security & Firewall"],"vendors":["David Anderson / Team Updraft"]}},{"cve_id":"CVE-2026-96827","summary":"Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions.","cvss":7.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/admin-notices-manager/vulnerability/wordpress-admin-notices-manager-plugin-1-6-0-sql-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:32","euvd":{"id":"EUVD-2026-89879","description":"Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions.","published_time":"2026-09-30T12:27:38","cvss":7.6,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/admin-notices-manager/vulnerability/wordpress-admin-notices-manager-plugin-1-6-0-sql-injection-vulnerability?_s_id=cve"],"products":["Admin Notices Manager"],"vendors":["Melapress"]}},{"cve_id":"CVE-2026-96828","summary":"Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions.","cvss":7.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/woo-product-category-discount/vulnerability/wordpress-category-discount-woocommerce-plugin-5-18-sql-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:32","euvd":{"id":"EUVD-2026-89880","description":"Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions.","published_time":"2026-09-30T12:27:39","cvss":7.6,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/woo-product-category-discount/vulnerability/wordpress-category-discount-woocommerce-plugin-5-18-sql-injection-vulnerability?_s_id=cve"],"products":["Category Discount Woocommerce"],"vendors":["Vidish"]}},{"cve_id":"CVE-2026-96829","summary":"Contributor Cross Site Scripting (XSS) in The Plus Addons for Elementor Page Builder Lite <= 6.5.1 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/the-plus-addons-for-elementor-page-builder/vulnerability/wordpress-the-plus-addons-for-elementor-page-builder-lite-plugin-6-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:32","euvd":{"id":"EUVD-2026-89881","description":"Contributor Cross Site Scripting (XSS) in The Plus Addons for Elementor Page Builder Lite <= 6.5.1 versions.","published_time":"2026-09-30T12:27:40","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/the-plus-addons-for-elementor-page-builder/vulnerability/wordpress-the-plus-addons-for-elementor-page-builder-lite-plugin-6-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["The Plus Addons for Elementor Page Builder Lite"],"vendors":["POSIMYTH"]}},{"cve_id":"CVE-2026-96830","summary":"Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.9 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/give/vulnerability/wordpress-givewp-plugin-4-16-9-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:32","euvd":{"id":"EUVD-2026-89882","description":"Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.9 versions.","published_time":"2026-09-30T12:27:41","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/give/vulnerability/wordpress-givewp-plugin-4-16-9-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["GiveWP"],"vendors":["Nexcess"]}},{"cve_id":"CVE-2026-96831","summary":"Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/themify-builder/vulnerability/wordpress-themify-builder-plugin-7-8-1-php-object-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:32","euvd":{"id":"EUVD-2026-89883","description":"Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions.","published_time":"2026-09-30T12:27:42","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/themify-builder/vulnerability/wordpress-themify-builder-plugin-7-8-1-php-object-injection-vulnerability?_s_id=cve"],"products":["Themify Builder"],"vendors":["themifyme"]}},{"cve_id":"CVE-2026-96817","summary":"Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions.","cvss":8.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/makecommerce/vulnerability/wordpress-makecommerce-for-woocommerce-plugin-4-1-0-broken-access-control-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:31","euvd":{"id":"EUVD-2026-89870","description":"Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions.","published_time":"2026-09-30T12:27:31","cvss":8.2,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/makecommerce/vulnerability/wordpress-makecommerce-for-woocommerce-plugin-4-1-0-broken-access-control-vulnerability?_s_id=cve"],"products":["MakeCommerce for WooCommerce"],"vendors":["MakeCommerce.net"]}},{"cve_id":"CVE-2026-96818","summary":"Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/wp-express-checkout/vulnerability/wordpress-wp-express-checkout-accept-paypal-payments-plugin-2-4-9-broken-access-control-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:31","euvd":{"id":"EUVD-2026-89871","description":"Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions.","published_time":"2026-09-30T12:27:32","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/wp-express-checkout/vulnerability/wordpress-wp-express-checkout-accept-paypal-payments-plugin-2-4-9-broken-access-control-vulnerability?_s_id=cve"],"products":["WP Express Checkout (Accept PayPal Payments)"],"vendors":["mra13 / Team Tips and Tricks HQ"]}},{"cve_id":"CVE-2026-96819","summary":"Subscriber Cross Site Scripting (XSS) in oik <= 4.15.4 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/oik/vulnerability/wordpress-oik-plugin-4-15-4-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:31","euvd":{"id":"EUVD-2026-89872","description":"Subscriber Cross Site Scripting (XSS) in oik <= 4.15.4 versions.","published_time":"2026-09-30T12:27:33","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/oik/vulnerability/wordpress-oik-plugin-4-15-4-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["oik"],"vendors":["bobbingwide"]}},{"cve_id":"CVE-2026-96820","summary":"Subscriber Cross Site Scripting (XSS) in Awesome Support <= 6.3.9 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/awesome-support/vulnerability/wordpress-awesome-support-plugin-6-3-9-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:31","euvd":{"id":"EUVD-2026-89873","description":"Subscriber Cross Site Scripting (XSS) in Awesome Support <= 6.3.9 versions.","published_time":"2026-09-30T12:27:33","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/awesome-support/vulnerability/wordpress-awesome-support-plugin-6-3-9-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Awesome Support"],"vendors":["awesomesupport"]}},{"cve_id":"CVE-2026-96821","summary":"Subscriber Privilege Escalation in FluentBoards <= 2.0.12 versions.","cvss":6.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/fluent-boards/vulnerability/wordpress-fluentboards-plugin-2-0-12-privilege-escalation-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:31","euvd":{"id":"EUVD-2026-89874","description":"Subscriber Privilege Escalation in FluentBoards <= 2.0.12 versions.","published_time":"2026-09-30T12:27:34","cvss":6.3,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/fluent-boards/vulnerability/wordpress-fluentboards-plugin-2-0-12-privilege-escalation-vulnerability?_s_id=cve"],"products":["FluentBoards"],"vendors":["Mahmudul Hasan Arif"]}},{"cve_id":"CVE-2026-96822","summary":"Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions.","cvss":9.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/wp-books-gallery/vulnerability/wordpress-books-gallery-plugin-4-8-3-sql-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:31","euvd":{"id":"EUVD-2026-89875","description":"Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions.","published_time":"2026-09-30T12:27:35","cvss":9.3,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/wp-books-gallery/vulnerability/wordpress-books-gallery-plugin-4-8-3-sql-injection-vulnerability?_s_id=cve"],"products":["Books Gallery"],"vendors":["Hossni Mubarak"]}},{"cve_id":"CVE-2026-96823","summary":"Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/customer-reviews-woocommerce/vulnerability/wordpress-customer-reviews-for-woocommerce-plugin-5-120-0-arbitrary-content-deletion-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:31","euvd":{"id":"EUVD-2026-89876","description":"Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions.","published_time":"2026-09-30T12:27:36","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/customer-reviews-woocommerce/vulnerability/wordpress-customer-reviews-for-woocommerce-plugin-5-120-0-arbitrary-content-deletion-vulnerability?_s_id=cve"],"products":["Customer Reviews for WooCommerce"],"vendors":["CusRev"]}},{"cve_id":"CVE-2026-96350","summary":"Subscriber Privilege Escalation in Estatik <= 4.3.5 versions.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/estatik/vulnerability/wordpress-estatik-plugin-4-3-5-privilege-escalation-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:30","euvd":{"id":"EUVD-2026-89863","description":"Subscriber Privilege Escalation in Estatik <= 4.3.5 versions.","published_time":"2026-09-30T12:27:25","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/estatik/vulnerability/wordpress-estatik-plugin-4-3-5-privilege-escalation-vulnerability?_s_id=cve"],"products":["Estatik"],"vendors":["Estatik"]}},{"cve_id":"CVE-2026-96351","summary":"Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 6.1.3 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/classified-listing/vulnerability/wordpress-classified-listing-plugin-6-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:30","euvd":{"id":"EUVD-2026-89864","description":"Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 6.1.3 versions.","published_time":"2026-09-30T12:27:26","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/classified-listing/vulnerability/wordpress-classified-listing-plugin-6-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Classified Listing"],"vendors":["RadiusTheme"]}},{"cve_id":"CVE-2026-96352","summary":"Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/yith-woocommerce-ajax-search/vulnerability/wordpress-yith-woocommerce-ajax-search-plugin-2-28-0-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:30","euvd":{"id":"EUVD-2026-89865","description":"Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions.","published_time":"2026-09-30T12:27:27","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/yith-woocommerce-ajax-search/vulnerability/wordpress-yith-woocommerce-ajax-search-plugin-2-28-0-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["YITH WooCommerce Ajax Search"],"vendors":["yithemes"]}},{"cve_id":"CVE-2026-96450","summary":"Contributor Cross Site Scripting (XSS) in pixfort Core < 4.3.3 versions.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/pixfort-core/vulnerability/wordpress-pixfort-core-plugin-4-3-3-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:30","euvd":{"id":"EUVD-2026-89866","description":"Contributor Cross Site Scripting (XSS) in pixfort Core < 4.3.3 versions.","published_time":"2026-09-30T12:27:28","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/pixfort-core/vulnerability/wordpress-pixfort-core-plugin-4-3-3-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["pixfort Core"],"vendors":["PixFort"]}},{"cve_id":"CVE-2026-96814","summary":"Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 5.6.7 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/wc-product-table-lite/vulnerability/wordpress-woocommerce-product-table-lite-plugin-5-6-7-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:30","euvd":{"id":"EUVD-2026-89867","description":"Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 5.6.7 versions.","published_time":"2026-09-30T12:27:28","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/wc-product-table-lite/vulnerability/wordpress-woocommerce-product-table-lite-plugin-5-6-7-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["WooCommerce Product Table Lite"],"vendors":["WP Titan Labs"]}},{"cve_id":"CVE-2026-96815","summary":"Custom role Privilege Escalation in Vitepos <= 3.5.0 versions.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/vitepos-lite/vulnerability/wordpress-vitepos-plugin-3-5-0-privilege-escalation-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:30","euvd":{"id":"EUVD-2026-89868","description":"Custom role Privilege Escalation in Vitepos <= 3.5.0 versions.","published_time":"2026-09-30T12:27:29","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/vitepos-lite/vulnerability/wordpress-vitepos-plugin-3-5-0-privilege-escalation-vulnerability?_s_id=cve"],"products":["Vitepos"],"vendors":["appsbd"]}},{"cve_id":"CVE-2026-96816","summary":"Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce <= 2.0.6 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/trusted-shops-easy-integration-for-woocommerce/vulnerability/wordpress-trusted-shops-easy-integration-for-woocommerce-plugin-2-0-6-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:30","euvd":{"id":"EUVD-2026-89869","description":"Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce <= 2.0.6 versions.","published_time":"2026-09-30T12:27:30","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/trusted-shops-easy-integration-for-woocommerce/vulnerability/wordpress-trusted-shops-easy-integration-for-woocommerce-plugin-2-0-6-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Trusted Shops Easy Integration for WooCommerce"],"vendors":["vendidero"]}},{"cve_id":"CVE-2026-96338","summary":"Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/profile-builder/vulnerability/wordpress-profile-builder-plugin-4-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:29","euvd":{"id":"EUVD-2026-89855","description":"Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions.","published_time":"2026-09-30T12:27:17","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/profile-builder/vulnerability/wordpress-profile-builder-plugin-4-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Profile Builder"],"vendors":["Cozmoslabs"]}},{"cve_id":"CVE-2026-96343","summary":"Custom role PHP Object Injection in WP ERP <= 1.17.9 versions.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/erp/vulnerability/wordpress-wp-erp-plugin-1-17-9-php-object-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:29","euvd":{"id":"EUVD-2026-89856","description":"Custom role PHP Object Injection in WP ERP <= 1.17.9 versions.","published_time":"2026-09-30T12:27:18","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/erp/vulnerability/wordpress-wp-erp-plugin-1-17-9-php-object-injection-vulnerability?_s_id=cve"],"products":["WP ERP"],"vendors":["wedevs"]}},{"cve_id":"CVE-2026-96344","summary":"Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/ecommerce-product-catalog/vulnerability/wordpress-ecommerce-product-catalog-plugin-3-6-0-php-object-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:29","euvd":{"id":"EUVD-2026-89857","description":"Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions.","published_time":"2026-09-30T12:27:19","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/ecommerce-product-catalog/vulnerability/wordpress-ecommerce-product-catalog-plugin-3-6-0-php-object-injection-vulnerability?_s_id=cve"],"products":["eCommerce Product Catalog"],"vendors":["impleCode"]}},{"cve_id":"CVE-2026-96345","summary":"Administrator SQL Injection in Estatik <= 4.3.5 versions.","cvss":7.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/estatik/vulnerability/wordpress-estatik-plugin-4-3-5-sql-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:29","euvd":{"id":"EUVD-2026-89858","description":"Administrator SQL Injection in Estatik <= 4.3.5 versions.","published_time":"2026-09-30T12:27:21","cvss":7.6,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/estatik/vulnerability/wordpress-estatik-plugin-4-3-5-sql-injection-vulnerability?_s_id=cve"],"products":["Estatik"],"vendors":["Estatik"]}},{"cve_id":"CVE-2026-96346","summary":"Author SQL Injection in WP ERP <= 1.17.9 versions.","cvss":7.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/erp/vulnerability/wordpress-wp-erp-plugin-1-17-9-sql-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:29","euvd":{"id":"EUVD-2026-89859","description":"Author SQL Injection in WP ERP <= 1.17.9 versions.","published_time":"2026-09-30T12:27:22","cvss":7.6,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/erp/vulnerability/wordpress-wp-erp-plugin-1-17-9-sql-injection-vulnerability?_s_id=cve"],"products":["WP ERP"],"vendors":["wedevs"]}},{"cve_id":"CVE-2026-96347","summary":"Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/bookly-responsive-appointment-booking-tool/vulnerability/wordpress-bookly-plugin-28-2-insecure-direct-object-references-idor-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:29","euvd":{"id":"EUVD-2026-89860","description":"Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions.","published_time":"2026-09-30T12:27:23","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/bookly-responsive-appointment-booking-tool/vulnerability/wordpress-bookly-plugin-28-2-insecure-direct-object-references-idor-vulnerability?_s_id=cve"],"products":["Bookly"],"vendors":["Bookly"]}},{"cve_id":"CVE-2026-96348","summary":"Unauthenticated Broken Access Control in Bookly <= 28.2 versions.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/bookly-responsive-appointment-booking-tool/vulnerability/wordpress-bookly-plugin-28-2-broken-access-control-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:29","euvd":{"id":"EUVD-2026-89861","description":"Unauthenticated Broken Access Control in Bookly <= 28.2 versions.","published_time":"2026-09-30T12:27:24","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/bookly-responsive-appointment-booking-tool/vulnerability/wordpress-bookly-plugin-28-2-broken-access-control-vulnerability?_s_id=cve"],"products":["Bookly"],"vendors":["Bookly"]}},{"cve_id":"CVE-2026-96349","summary":"Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.","cvss":10.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":10.0,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/siteskite/vulnerability/wordpress-siteskite-plugin-2-1-8-remote-code-execution-rce-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:29","euvd":{"id":"EUVD-2026-89862","description":"Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.","published_time":"2026-09-30T12:27:24","cvss":10.0,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/siteskite/vulnerability/wordpress-siteskite-plugin-2-1-8-remote-code-execution-rce-vulnerability?_s_id=cve"],"products":["SiteSkite"],"vendors":["SiteSkite"]}},{"cve_id":"CVE-2026-95531","summary":"Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/conversational-forms/vulnerability/wordpress-conversational-forms-for-chatbot-plugin-1-5-0-php-object-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:28","euvd":{"id":"EUVD-2026-89853","description":"Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions.","published_time":"2026-09-30T12:27:16","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/conversational-forms/vulnerability/wordpress-conversational-forms-for-chatbot-plugin-1-5-0-php-object-injection-vulnerability?_s_id=cve"],"products":["Conversational Forms for ChatBot"],"vendors":["QuantumCloud"]}},{"cve_id":"CVE-2026-95587","summary":"Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/migrator-plugin/vulnerability/wordpress-hostinger-migrator-plugin-1-0-broken-access-control-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:28","euvd":{"id":"EUVD-2026-89854","description":"Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions.","published_time":"2026-09-30T12:27:17","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/migrator-plugin/vulnerability/wordpress-hostinger-migrator-plugin-1-0-broken-access-control-vulnerability?_s_id=cve"],"products":["Hostinger Migrator"],"vendors":["hostinger"]}},{"cve_id":"CVE-2026-95616","summary":"An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before the message is authenticated, so an eleven-byte extension triggers a 2 GB allocation. Repeated requests exhaust server memory.\nUsers are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread.html/sdf0fsphkg4qbj7nh2brjgwvcmd67hct","http://www.openwall.com/lists/oss-security/2026/09/30/14"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:28","euvd":{"id":"EUVD-2026-89801","description":"An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the signature's key reference, before the message is authenticated, so an eleven-byte extension triggers a 2 GB allocation. Repeated requests exhaust server memory.\nUsers are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.","published_time":"2026-09-30T12:25:28","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread.html/sdf0fsphkg4qbj7nh2brjgwvcmd67hct"],"products":["Apache WSS4J","Apache WSS4J","Apache WSS4J"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-94499","summary":"Subscriber Broken Access Control in FormGent <= 1.12.2 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/formgent/vulnerability/wordpress-formgent-plugin-1-12-2-broken-access-control-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:27","euvd":{"id":"EUVD-2026-89845","description":"Subscriber Broken Access Control in FormGent <= 1.12.2 versions.","published_time":"2026-09-30T12:27:09","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/formgent/vulnerability/wordpress-formgent-plugin-1-12-2-broken-access-control-vulnerability?_s_id=cve"],"products":["FormGent"],"vendors":["wpWax"]}},{"cve_id":"CVE-2026-94672","summary":"Contributor Insecure Direct Object References (IDOR) in Safe SVG <= 2.5.0 versions.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/safe-svg/vulnerability/wordpress-safe-svg-plugin-2-5-0-insecure-direct-object-references-idor-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:27","euvd":{"id":"EUVD-2026-89846","description":"Contributor Insecure Direct Object References (IDOR) in Safe SVG <= 2.5.0 versions.","published_time":"2026-09-30T12:27:10","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/safe-svg/vulnerability/wordpress-safe-svg-plugin-2-5-0-insecure-direct-object-references-idor-vulnerability?_s_id=cve"],"products":["Safe SVG"],"vendors":["10up"]}},{"cve_id":"CVE-2026-94673","summary":"Unauthenticated Insecure Direct Object References (IDOR) in Simply Schedule Appointments <= 1.6.12.31 versions.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/simply-schedule-appointments/vulnerability/wordpress-simply-schedule-appointments-plugin-1-6-12-31-insecure-direct-object-references-idor-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:27","euvd":{"id":"EUVD-2026-89847","description":"Unauthenticated Insecure Direct Object References (IDOR) in Simply Schedule Appointments <= 1.6.12.31 versions.","published_time":"2026-09-30T12:27:11","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/simply-schedule-appointments/vulnerability/wordpress-simply-schedule-appointments-plugin-1-6-12-31-insecure-direct-object-references-idor-vulnerability?_s_id=cve"],"products":["Simply Schedule Appointments"],"vendors":["NSquared"]}},{"cve_id":"CVE-2026-94674","summary":"Contributor Cross Site Scripting (XSS) in Pixel Manager for WooCommerce <= 1.69.0 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/woocommerce-google-adwords-conversion-tracking-tag/vulnerability/wordpress-pixel-manager-for-woocommerce-plugin-1-69-0-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:27","euvd":{"id":"EUVD-2026-89848","description":"Contributor Cross Site Scripting (XSS) in Pixel Manager for WooCommerce <= 1.69.0 versions.","published_time":"2026-09-30T12:27:12","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/woocommerce-google-adwords-conversion-tracking-tag/vulnerability/wordpress-pixel-manager-for-woocommerce-plugin-1-69-0-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Pixel Manager for WooCommerce"],"vendors":["SweetCode"]}},{"cve_id":"CVE-2026-94677","summary":"Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/kadence-woocommerce-email-designer/vulnerability/wordpress-kadence-woocommerce-email-designer-plugin-1-5-19-1-php-object-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:27","euvd":{"id":"EUVD-2026-89849","description":"Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions.","published_time":"2026-09-30T12:27:13","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/kadence-woocommerce-email-designer/vulnerability/wordpress-kadence-woocommerce-email-designer-plugin-1-5-19-1-php-object-injection-vulnerability?_s_id=cve"],"products":["Kadence WooCommerce Email Designer"],"vendors":["Nexcess"]}},{"cve_id":"CVE-2026-94678","summary":"Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/go-live-update-urls/vulnerability/wordpress-go-live-update-urls-plugin-7-0-8-php-object-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:27","euvd":{"id":"EUVD-2026-89850","description":"Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions.","published_time":"2026-09-30T12:27:13","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/go-live-update-urls/vulnerability/wordpress-go-live-update-urls-plugin-7-0-8-php-object-injection-vulnerability?_s_id=cve"],"products":["Go Live Update Urls"],"vendors":["Mat Lipe"]}},{"cve_id":"CVE-2026-94681","summary":"Unauthenticated Denial of Service Attack in WP Store Locator < 3.0.0 versions.","cvss":5.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/wp-store-locator/vulnerability/wordpress-wp-store-locator-plugin-3-0-0-denial-of-service-attack-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:27","euvd":{"id":"EUVD-2026-89851","description":"Unauthenticated Denial of Service Attack in WP Store Locator < 3.0.0 versions.","published_time":"2026-09-30T12:27:14","cvss":5.9,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/wp-store-locator/vulnerability/wordpress-wp-store-locator-plugin-3-0-0-denial-of-service-attack-vulnerability?_s_id=cve"],"products":["WP Store Locator"],"vendors":["Tijmen Smit"]}},{"cve_id":"CVE-2026-94683","summary":"Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/designsetgo/vulnerability/wordpress-designsetgo-plugin-2-8-0-php-object-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:27","euvd":{"id":"EUVD-2026-89852","description":"Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions.","published_time":"2026-09-30T12:27:15","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/designsetgo/vulnerability/wordpress-designsetgo-plugin-2-8-0-php-object-injection-vulnerability?_s_id=cve"],"products":["DesignSetGo"],"vendors":["Justin Nealey"]}},{"cve_id":"CVE-2026-94389","summary":"Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions.","cvss":9.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.0,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/acymailing/vulnerability/wordpress-acymailing-smtp-newsletter-plugin-11-0-5-remote-code-execution-rce-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:26","euvd":{"id":"EUVD-2026-89844","description":"Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions.","published_time":"2026-09-30T12:27:08","cvss":9.0,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/acymailing/vulnerability/wordpress-acymailing-smtp-newsletter-plugin-11-0-5-remote-code-execution-rce-vulnerability?_s_id=cve"],"products":["AcyMailing SMTP Newsletter"],"vendors":["AcyMailing Newsletter Team"]}},{"cve_id":"CVE-2026-94123","summary":"Unauthenticated Arbitrary File Download in NextGEN Gallery <= 4.5.0 versions.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/nextgen-gallery/vulnerability/wordpress-nextgen-gallery-plugin-4-5-0-arbitrary-file-download-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:25","euvd":{"id":"EUVD-2026-89840","description":"Unauthenticated Arbitrary File Download in NextGEN Gallery <= 4.5.0 versions.","published_time":"2026-09-30T12:27:05","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/nextgen-gallery/vulnerability/wordpress-nextgen-gallery-plugin-4-5-0-arbitrary-file-download-vulnerability?_s_id=cve"],"products":["NextGEN Gallery "],"vendors":["Syed Balkhi"]}},{"cve_id":"CVE-2026-94173","summary":"Contributor Insecure Direct Object References (IDOR) in Business Directory <= 6.4.27 versions.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/business-directory-plugin/vulnerability/wordpress-business-directory-plugin-6-4-27-insecure-direct-object-references-idor-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:25","euvd":{"id":"EUVD-2026-89841","description":"Contributor Insecure Direct Object References (IDOR) in Business Directory <= 6.4.27 versions.","published_time":"2026-09-30T12:27:06","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/business-directory-plugin/vulnerability/wordpress-business-directory-plugin-6-4-27-insecure-direct-object-references-idor-vulnerability?_s_id=cve"],"products":["Business Directory"],"vendors":["Strategy11 Team"]}},{"cve_id":"CVE-2026-94177","summary":"Unauthenticated SQL Injection in GamiPress <= 8.0.2 versions.","cvss":8.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/gamipress/vulnerability/wordpress-gamipress-plugin-8-0-2-sql-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:25","euvd":{"id":"EUVD-2026-89842","description":"Unauthenticated SQL Injection in GamiPress <= 8.0.2 versions.","published_time":"2026-09-30T12:27:07","cvss":8.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/gamipress/vulnerability/wordpress-gamipress-plugin-8-0-2-sql-injection-vulnerability?_s_id=cve"],"products":["GamiPress"],"vendors":["Ruben Garcia"]}},{"cve_id":"CVE-2026-94178","summary":"Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/import-users-from-csv-with-meta/vulnerability/wordpress-import-and-export-users-and-customers-plugin-2-5-2-privilege-escalation-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:25","euvd":{"id":"EUVD-2026-89843","description":"Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions.","published_time":"2026-09-30T12:27:08","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/import-users-from-csv-with-meta/vulnerability/wordpress-import-and-export-users-and-customers-plugin-2-5-2-privilege-escalation-vulnerability?_s_id=cve"],"products":["Import and export users and customers"],"vendors":["Javier Carazo"]}},{"cve_id":"CVE-2026-94082","summary":"Author SQL Injection in Quiz Cat <= 3.1.1 versions.","cvss":7.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/quiz-cat/vulnerability/wordpress-quiz-cat-plugin-3-1-1-sql-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:24","euvd":{"id":"EUVD-2026-89835","description":"Author SQL Injection in Quiz Cat <= 3.1.1 versions.","published_time":"2026-09-30T12:27:01","cvss":7.6,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/quiz-cat/vulnerability/wordpress-quiz-cat-plugin-3-1-1-sql-injection-vulnerability?_s_id=cve"],"products":["Quiz Cat"],"vendors":["fatcatapps"]}},{"cve_id":"CVE-2026-94115","summary":"Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions.","cvss":8.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/easy-pricing-tables/vulnerability/wordpress-easy-pricing-tables-plugin-4-1-2-sql-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:24","euvd":{"id":"EUVD-2026-89836","description":"Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions.","published_time":"2026-09-30T12:27:02","cvss":8.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/easy-pricing-tables/vulnerability/wordpress-easy-pricing-tables-plugin-4-1-2-sql-injection-vulnerability?_s_id=cve"],"products":["Easy Pricing Tables"],"vendors":["fatcatapps"]}},{"cve_id":"CVE-2026-94120","summary":"Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/gf-entries-in-excel/vulnerability/wordpress-gravityexport-lite-for-gravity-forms-plugin-2-7-2-broken-access-control-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:24","euvd":{"id":"EUVD-2026-89837","description":"Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions.","published_time":"2026-09-30T12:27:02","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/gf-entries-in-excel/vulnerability/wordpress-gravityexport-lite-for-gravity-forms-plugin-2-7-2-broken-access-control-vulnerability?_s_id=cve"],"products":["GravityExport Lite for Gravity Forms"],"vendors":["GravityKit"]}},{"cve_id":"CVE-2026-94121","summary":"Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/tenweb-speed-optimizer/vulnerability/wordpress-10web-booster-website-speed-optimization-cache-page-speed-optimizer-plugin-2-33-6-php-object-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:24","euvd":{"id":"EUVD-2026-89838","description":"Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions.","published_time":"2026-09-30T12:27:03","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/tenweb-speed-optimizer/vulnerability/wordpress-10web-booster-website-speed-optimization-cache-page-speed-optimizer-plugin-2-33-6-php-object-injection-vulnerability?_s_id=cve"],"products":["10Web Booster – Website speed optimization, Cache & Page Speed optimizer"],"vendors":["10web"]}},{"cve_id":"CVE-2026-94122","summary":"Editor PHP Object Injection in Responsive Slider Gallery  <= 1.5.5 versions.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/responsive-slider-gallery/vulnerability/wordpress-responsive-slider-gallery-plugin-1-5-5-php-object-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:24","euvd":{"id":"EUVD-2026-89839","description":"Editor PHP Object Injection in Responsive Slider Gallery  <= 1.5.5 versions.","published_time":"2026-09-30T12:27:04","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/responsive-slider-gallery/vulnerability/wordpress-responsive-slider-gallery-plugin-1-5-5-php-object-injection-vulnerability?_s_id=cve"],"products":["Responsive Slider Gallery"],"vendors":["A WP Life"]}},{"cve_id":"CVE-2026-94076","summary":"Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/squirrly-seo/vulnerability/wordpress-seo-plugin-by-squirrly-seo-plugin-14-2-5-php-object-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:23","euvd":{"id":"EUVD-2026-89831","description":"Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions.","published_time":"2026-09-30T12:26:57","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/squirrly-seo/vulnerability/wordpress-seo-plugin-by-squirrly-seo-plugin-14-2-5-php-object-injection-vulnerability?_s_id=cve"],"products":["SEO Plugin by Squirrly SEO"],"vendors":["SEO Squirrly"]}},{"cve_id":"CVE-2026-94077","summary":"Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/safe-svg/vulnerability/wordpress-safe-svg-plugin-2-5-0-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:23","euvd":{"id":"EUVD-2026-89832","description":"Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions.","published_time":"2026-09-30T12:26:58","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/safe-svg/vulnerability/wordpress-safe-svg-plugin-2-5-0-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Safe SVG"],"vendors":["10up"]}},{"cve_id":"CVE-2026-94078","summary":"Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/site-reviews/vulnerability/wordpress-site-reviews-plugin-8-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:23","euvd":{"id":"EUVD-2026-89833","description":"Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions.","published_time":"2026-09-30T12:26:59","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/site-reviews/vulnerability/wordpress-site-reviews-plugin-8-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Site Reviews"],"vendors":["Gemini Labs"]}},{"cve_id":"CVE-2026-94081","summary":"Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/wp-persistent-login/vulnerability/wordpress-wordpress-persistent-login-plugin-3-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:23","euvd":{"id":"EUVD-2026-89834","description":"Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions.","published_time":"2026-09-30T12:27:00","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/wp-persistent-login/vulnerability/wordpress-wordpress-persistent-login-plugin-3-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["WordPress Persistent Login"],"vendors":["lukeseager"]}},{"cve_id":"CVE-2026-93514","summary":"Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/notification-for-telegram/vulnerability/wordpress-notification-for-telegram-plugin-3-5-2-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:22","euvd":{"id":"EUVD-2026-89824","description":"Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions.","published_time":"2026-09-30T12:26:52","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/notification-for-telegram/vulnerability/wordpress-notification-for-telegram-plugin-3-5-2-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Notification for Telegram"],"vendors":["rainafarai"]}},{"cve_id":"CVE-2026-93621","summary":"Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions.","cvss":8.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/wp-data-access/vulnerability/wordpress-wp-data-access-plugin-5-5-84-sql-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:22","euvd":{"id":"EUVD-2026-89825","description":"Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions.","published_time":"2026-09-30T12:26:52","cvss":8.2,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/wp-data-access/vulnerability/wordpress-wp-data-access-plugin-5-5-84-sql-injection-vulnerability?_s_id=cve"],"products":["WP Data Access"],"vendors":["Passionate Programmer Peter"]}},{"cve_id":"CVE-2026-93624","summary":"Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/music-player-for-woocommerce/vulnerability/wordpress-music-player-for-woocommerce-plugin-1-9-1-php-object-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:22","euvd":{"id":"EUVD-2026-89826","description":"Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions.","published_time":"2026-09-30T12:26:53","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/music-player-for-woocommerce/vulnerability/wordpress-music-player-for-woocommerce-plugin-1-9-1-php-object-injection-vulnerability?_s_id=cve"],"products":["Music Player for WooCommerce"],"vendors":["CodePeople"]}},{"cve_id":"CVE-2026-93651","summary":"Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/min-and-max-quantity-for-woocommerce/vulnerability/wordpress-minimum-and-maximum-quantity-for-woocommerce-plugin-2-1-2-php-object-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:22","euvd":{"id":"EUVD-2026-89827","description":"Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions.","published_time":"2026-09-30T12:26:54","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/min-and-max-quantity-for-woocommerce/vulnerability/wordpress-minimum-and-maximum-quantity-for-woocommerce-plugin-2-1-2-php-object-injection-vulnerability?_s_id=cve"],"products":["Minimum and Maximum Quantity for WooCommerce"],"vendors":["Dotstore"]}},{"cve_id":"CVE-2026-93770","summary":"Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/wp-statistics/vulnerability/wordpress-wp-statistics-plugin-14-16-13-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:22","euvd":{"id":"EUVD-2026-89828","description":"Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions.","published_time":"2026-09-30T12:26:55","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/wp-statistics/vulnerability/wordpress-wp-statistics-plugin-14-16-13-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["WP Statistics"],"vendors":["VeronaLabs"]}},{"cve_id":"CVE-2026-93771","summary":"Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/cost-of-goods-for-woocommerce/vulnerability/wordpress-cost-of-goods-for-woocommerce-plugin-3-5-2-php-object-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:22","euvd":{"id":"EUVD-2026-89829","description":"Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.","published_time":"2026-09-30T12:26:56","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/cost-of-goods-for-woocommerce/vulnerability/wordpress-cost-of-goods-for-woocommerce-plugin-3-5-2-php-object-injection-vulnerability?_s_id=cve"],"products":["Cost of Goods for WooCommerce"],"vendors":["WPFactory"]}},{"cve_id":"CVE-2026-94074","summary":"Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/simply-schedule-appointments/vulnerability/wordpress-simply-schedule-appointments-plugin-1-6-12-29-broken-access-control-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:22","euvd":{"id":"EUVD-2026-89830","description":"Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions.","published_time":"2026-09-30T12:26:57","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/simply-schedule-appointments/vulnerability/wordpress-simply-schedule-appointments-plugin-1-6-12-29-broken-access-control-vulnerability?_s_id=cve"],"products":["Simply Schedule Appointments"],"vendors":["NSquared"]}},{"cve_id":"CVE-2026-86778","summary":"Observable response discrepancy vulnerability in Maksisoft Technology, IT, and Software Industry and Trade Inc. Maksisoft Gym allows Account Footprinting.\n\nThis issue affects Maksisoft Gym: from 0.5.10 before 0.5.11.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1223"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:21","euvd":{"id":"EUVD-2026-89948","description":"Observable response discrepancy vulnerability in Maksisoft Technology, IT, and Software Industry and Trade Inc. Maksisoft Gym allows Account Footprinting.\n\nThis issue affects Maksisoft Gym: from 0.5.10 before 0.5.11.","published_time":"2026-09-30T12:59:32","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"TR-CERT","references":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1223"],"products":["Maksisoft Gym"],"vendors":["Maksisoft Technology, IT, and Software Industry and Trade Inc."]}},{"cve_id":"CVE-2026-89238","summary":"WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass.\nUsers are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread.html/1lv4hpl8kon1ns5txjnhn2m2sh9rl22w","http://www.openwall.com/lists/oss-security/2026/09/30/11"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:21","euvd":{"id":"EUVD-2026-89794","description":"WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass.\nUsers are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.","published_time":"2026-09-30T11:59:09","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread.html/1lv4hpl8kon1ns5txjnhn2m2sh9rl22w"],"products":["Apache WSS4J","Apache WSS4J","Apache WSS4J"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-92121","summary":"In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal \"inside signed content\" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an element needs checking, so it stops evaluating SignedParts and SignedElements for the rest of the message. A policy requiring the SOAP Body to be signed is then satisfied even when the Body carries no signature, removing the protection against XML Signature Wrapping. Signature verification itself is unaffected. The DOM code is not affected. \nUsers are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4 which fix this issue.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread.html/oop9p4hpl5o9byosb1qg3z7q1sgnn4pc","http://www.openwall.com/lists/oss-security/2026/09/30/12"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:21","euvd":{"id":"EUVD-2026-89795","description":"In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal \"inside signed content\" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an element needs checking, so it stops evaluating SignedParts and SignedElements for the rest of the message. A policy requiring the SOAP Body to be signed is then satisfied even when the Body carries no signature, removing the protection against XML Signature Wrapping. Signature verification itself is unaffected. The DOM code is not affected. \nUsers are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4 which fix this issue.","published_time":"2026-09-30T12:01:55","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread.html/oop9p4hpl5o9byosb1qg3z7q1sgnn4pc"],"products":["Apache WSS4J","Apache WSS4J","Apache WSS4J"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-92899","summary":"Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could re-send it with a space added to the Nonce: the password digest still verified, but the token no longer matched the remembered one, so the replay was accepted. Since a UsernameToken does not cover the message body, the captured token could then be reused on requests of the attacker's choosing until it expired. Affects deployments with a nonce replay cache configured, as Apache CXF has by default, and only tokens using a password digest. The cache is now keyed on the decoded Nonce. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.","cvss":4.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread.html/nrzngsz1xm2lztq3t873663xx9wnrwm7","http://www.openwall.com/lists/oss-security/2026/09/30/13"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:21","euvd":{"id":"EUVD-2026-89798","description":"Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, but authentication decodes that text and uses the bytes.The same bytes can be written as base64 in several ways. An attacker who captured an authenticated request could re-send it with a space added to the Nonce: the password digest still verified, but the token no longer matched the remembered one, so the replay was accepted. Since a UsernameToken does not cover the message body, the captured token could then be reused on requests of the attacker's choosing until it expired. Affects deployments with a nonce replay cache configured, as Apache CXF has by default, and only tokens using a password digest. The cache is now keyed on the decoded Nonce. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.","published_time":"2026-09-30T12:02:41","cvss":4.8,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread.html/nrzngsz1xm2lztq3t873663xx9wnrwm7"],"products":["Apache WSS4J","Apache WSS4J","Apache WSS4J"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-93512","summary":"Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/jw-player-7-for-wp/vulnerability/wordpress-jw-player-for-wordpress-plugin-2-3-11-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:21","euvd":{"id":"EUVD-2026-89823","description":"Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions.","published_time":"2026-09-30T12:26:51","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/jw-player-7-for-wp/vulnerability/wordpress-jw-player-for-wordpress-plugin-2-3-11-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["JW Player for WordPress"],"vendors":["ilGhera"]}},{"cve_id":"CVE-2026-74865","summary":"sogo_yhn configures SOGo with a parameter \"SOGoTrustProxyAuthentication=YES\". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account.\n\n\nThis issue was fixed in version 5.8.0~ynh9.","cvss":9.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://cert.pl/en/posts/2026/09/CVE-2026-74864","https://forum.yunohost.org/t/sogo-critical-vulnerability-fixed-in-5-8-0-ynh9/42699"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:20","euvd":{"id":"EUVD-2026-89797","description":"sogo_yhn configures SOGo with a parameter \"SOGoTrustProxyAuthentication=YES\". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account.\n\n\nThis issue was fixed in version 5.8.0~ynh9.","published_time":"2026-09-30T12:02:40","cvss":9.2,"cvss_version":"4.0","epss":0.0,"assigner":"CERT-PL","references":["https://cert.pl/en/posts/2026/09/CVE-2026-74864","https://forum.yunohost.org/t/sogo-critical-vulnerability-fixed-in-5-8-0-ynh9/42699"],"products":["sogo_yhn"],"vendors":["YunoHost-Apps"]}},{"cve_id":"CVE-2026-76504","summary":"A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.\r\n\r\nThis vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":true,"propose_action":"Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.","ransomware_campaign":"Unknown","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76504"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:20","euvd":{"id":"EUVD-2026-89950","description":"A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.\r\n\r\nThis vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.","published_time":"2026-09-30T13:04:32","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU"],"products":["Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-76504","summary":"A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.\r\n\r\nThis vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":true,"propose_action":"Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.","ransomware_campaign":"Unknown","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76504"],"vendor":"cisco","product":"catalyst_sd-wan_manager","version":null,"published_time":"2026-09-30T13:17:20","euvd":{"id":"EUVD-2026-89950","description":"A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.\r\n\r\nThis vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.","published_time":"2026-09-30T13:04:32","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"cisco","references":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU"],"products":["Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager","Cisco Catalyst SD-WAN Manager"],"vendors":["Cisco"]}},{"cve_id":"CVE-2026-62078","summary":"Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/premium-addons-for-elementor/vulnerability/wordpress-premium-addons-for-elementor-plugin-4-11-105-cross-site-scripting-xss-vulnerability-2?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:19","euvd":{"id":"EUVD-2026-89817","description":"Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions.","published_time":"2026-09-30T12:26:46","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/premium-addons-for-elementor/vulnerability/wordpress-premium-addons-for-elementor-plugin-4-11-105-cross-site-scripting-xss-vulnerability-2?_s_id=cve"],"products":["Premium Addons for Elementor"],"vendors":["leap13"]}},{"cve_id":"CVE-2026-62079","summary":"Contributor Cross Site Scripting (XSS) in Qi Addons For Elementor <= 1.11 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/qi-addons-for-elementor/vulnerability/wordpress-qi-addons-for-elementor-plugin-1-11-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:19","euvd":{"id":"EUVD-2026-89818","description":"Contributor Cross Site Scripting (XSS) in Qi Addons For Elementor <= 1.11 versions.","published_time":"2026-09-30T12:26:47","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/qi-addons-for-elementor/vulnerability/wordpress-qi-addons-for-elementor-plugin-1-11-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Qi Addons For Elementor"],"vendors":["QODE"]}},{"cve_id":"CVE-2026-62080","summary":"Contributor Cross Site Scripting (XSS) in Happy Addons for Elementor <= 3.23.1 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/happy-elementor-addons/vulnerability/wordpress-happy-addons-for-elementor-plugin-3-23-1-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:19","euvd":{"id":"EUVD-2026-89819","description":"Contributor Cross Site Scripting (XSS) in Happy Addons for Elementor <= 3.23.1 versions.","published_time":"2026-09-30T12:26:48","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/happy-elementor-addons/vulnerability/wordpress-happy-addons-for-elementor-plugin-3-23-1-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Happy Addons for Elementor"],"vendors":["Leevio"]}},{"cve_id":"CVE-2026-62081","summary":"Contributor Insecure Direct Object References (IDOR) in Flexible PDF Coupons <= 1.14.11 versions.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/flexible-coupons/vulnerability/wordpress-flexible-pdf-coupons-plugin-1-14-11-insecure-direct-object-references-idor-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:19","euvd":{"id":"EUVD-2026-89820","description":"Contributor Insecure Direct Object References (IDOR) in Flexible PDF Coupons <= 1.14.11 versions.","published_time":"2026-09-30T12:26:49","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/flexible-coupons/vulnerability/wordpress-flexible-pdf-coupons-plugin-1-14-11-insecure-direct-object-references-idor-vulnerability?_s_id=cve"],"products":["Flexible PDF Coupons"],"vendors":["wpdesk"]}},{"cve_id":"CVE-2026-62083","summary":"Subscriber Other Vulnerability Type in Creator LMS <= 1.2.19 versions.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/creatorlms/vulnerability/wordpress-creator-lms-plugin-1-2-19-other-vulnerability-type-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:19","euvd":{"id":"EUVD-2026-89821","description":"Subscriber Other Vulnerability Type in Creator LMS <= 1.2.19 versions.","published_time":"2026-09-30T12:26:49","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/creatorlms/vulnerability/wordpress-creator-lms-plugin-1-2-19-other-vulnerability-type-vulnerability?_s_id=cve"],"products":["Creator LMS"],"vendors":["WPFunnels"]}},{"cve_id":"CVE-2026-62085","summary":"Administrator SQL Injection in WP Activity Log <= 5.6.6 versions.","cvss":7.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/wp-security-audit-log/vulnerability/wordpress-wp-activity-log-plugin-5-6-6-sql-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:19","euvd":{"id":"EUVD-2026-89822","description":"Administrator SQL Injection in WP Activity Log <= 5.6.6 versions.","published_time":"2026-09-30T12:26:50","cvss":7.6,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/wp-security-audit-log/vulnerability/wordpress-wp-activity-log-plugin-5-6-6-sql-injection-vulnerability?_s_id=cve"],"products":["WP Activity Log"],"vendors":["Melapress"]}},{"cve_id":"CVE-2026-74864","summary":"sogo_yhn configures SOGo with a parameter that forces the request with HTTP header \"x-webobjects-remote-user\" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any client can supply it arbitrarily and gain access as any user, including a privileged user, without providing a password.\n\n\n\n\nThis issue was fixed in version 5.8.0~ynh9.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://cert.pl/en/posts/2026/09/CVE-2026-74864","https://forum.yunohost.org/t/sogo-critical-vulnerability-fixed-in-5-8-0-ynh9/42699"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:19","euvd":{"id":"EUVD-2026-89796","description":"sogo_yhn configures SOGo with a parameter that forces the request with HTTP header \"x-webobjects-remote-user\" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any client can supply it arbitrarily and gain access as any user, including a privileged user, without providing a password.\n\n\n\n\nThis issue was fixed in version 5.8.0~ynh9.","published_time":"2026-09-30T12:02:29","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"CERT-PL","references":["https://cert.pl/en/posts/2026/09/CVE-2026-74864","https://forum.yunohost.org/t/sogo-critical-vulnerability-fixed-in-5-8-0-ynh9/42699"],"products":["sogo_yhn"],"vendors":["YunoHost-Apps"]}},{"cve_id":"CVE-2026-103116","summary":"A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List Search Endpoint. This manipulation of the argument LO_sort causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.","cvss":2.1,"cvss_version":4.0,"cvss_v2":6.5,"cvss_v3":6.3,"cvss_v4":2.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/OS4ED/openSIS-Classic/","https://github.com/OS4ED/openSIS-Classic/issues/476","https://vuldb.com/cve/CVE-2026-103116","https://vuldb.com/submit/954962","https://vuldb.com/vuln/411872","https://vuldb.com/vuln/411872/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:18","euvd":{"id":"EUVD-2026-89947","description":"A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List Search Endpoint. This manipulation of the argument LO_sort causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.","published_time":"2026-09-30T12:45:11","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411872","https://vuldb.com/vuln/411872/cti","https://vuldb.com/cve/CVE-2026-103116","https://vuldb.com/submit/954962","https://github.com/OS4ED/openSIS-Classic/issues/476","https://github.com/OS4ED/openSIS-Classic/"],"products":["openSIS-Classic","openSIS-Classic","openSIS-Classic","openSIS-Classic"],"vendors":["OS4ED"]}},{"cve_id":"CVE-2026-103117","summary":"A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save Data Handler. Such manipulation of the argument values leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.","cvss":2.0,"cvss_version":4.0,"cvss_v2":5.8,"cvss_v3":4.7,"cvss_v4":2.0,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/OS4ED/openSIS-Classic/","https://github.com/OS4ED/openSIS-Classic/issues/477","https://vuldb.com/cve/CVE-2026-103117","https://vuldb.com/submit/954963","https://vuldb.com/vuln/411873","https://vuldb.com/vuln/411873/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:18","euvd":{"id":"EUVD-2026-89949","description":"A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save Data Handler. Such manipulation of the argument values leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.","published_time":"2026-09-30T13:00:15","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411873","https://vuldb.com/vuln/411873/cti","https://vuldb.com/cve/CVE-2026-103117","https://vuldb.com/submit/954963","https://github.com/OS4ED/openSIS-Classic/issues/477","https://github.com/OS4ED/openSIS-Classic/"],"products":["openSIS-Classic","openSIS-Classic","openSIS-Classic","openSIS-Classic"],"vendors":["OS4ED"]}},{"cve_id":"CVE-2026-103321","summary":"MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature.\n\nThe event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element's src attribute via string concatenation, allowing a crafted value to break out of the attribute context and inject arbitrary script.\n\nPreconditions:\n\n- An authenticated MISP user with the ability to create or modify an event graph entry.\n\n- A second user (the victim) who views the event graph and triggers the preview popover.\n\nImpact:\n\n- Execution of arbitrary JavaScript in the victim's browser within the MISP application context.\n\n- Potential theft of session tokens, cookies, or sensitive data accessible to the victim's browser.\n\n- Potential for performing actions on behalf of the victim within the MISP application.\n\nAffected: MISP versions prior to the fix (commit applied after v2.5.48).","cvss":8.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/MISP/MISP/commit/92c7ccc43"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:18","euvd":{"id":"EUVD-2026-89800","description":"MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature.\n\nThe event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element's src attribute via string concatenation, allowing a crafted value to break out of the attribute context and inject arbitrary script.\n\nPreconditions:\n\n- An authenticated MISP user with the ability to create or modify an event graph entry.\n\n- A second user (the victim) who views the event graph and triggers the preview popover.\n\nImpact:\n\n- Execution of arbitrary JavaScript in the victim's browser within the MISP application context.\n\n- Potential theft of session tokens, cookies, or sensitive data accessible to the victim's browser.\n\n- Potential for performing actions on behalf of the victim within the MISP application.\n\nAffected: MISP versions prior to the fix (commit applied after v2.5.48).","published_time":"2026-09-30T12:19:01","cvss":8.3,"cvss_version":"4.0","epss":0.0,"assigner":"CIRCL","references":["https://github.com/MISP/MISP/commit/92c7ccc43"],"products":["MISP"],"vendors":["MISP"]}},{"cve_id":"CVE-2026-27085","summary":"Shop manager Content Injection in Astra WordPress Theme <= 4.13.12 versions.","cvss":2.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":2.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/theme/astra/vulnerability/wordpress-astra-wordpress-theme-theme-4-13-12-content-injection-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:18","euvd":{"id":"EUVD-2026-89815","description":"Shop manager Content Injection in Astra WordPress Theme <= 4.13.12 versions.","published_time":"2026-09-30T12:26:45","cvss":2.7,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/theme/astra/vulnerability/wordpress-astra-wordpress-theme-theme-4-13-12-content-injection-vulnerability?_s_id=cve"],"products":["Astra WordPress Theme"],"vendors":["Brainstorm Force"]}},{"cve_id":"CVE-2026-27371","summary":"Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/wpfunnels/vulnerability/wordpress-wpfunnels-plugin-3-13-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:18","euvd":{"id":"EUVD-2026-89816","description":"Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.","published_time":"2026-09-30T12:26:46","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/wpfunnels/vulnerability/wordpress-wpfunnels-plugin-3-13-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["WPFunnels"],"vendors":["WPFunnels"]}},{"cve_id":"CVE-2026-102385","summary":"Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/ninja-forms/vulnerability/wordpress-ninja-forms-plugin-3-15-3-cross-site-scripting-xss-vulnerability-2?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:17","euvd":{"id":"EUVD-2026-89941","description":"Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.","published_time":"2026-09-30T12:28:29","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/ninja-forms/vulnerability/wordpress-ninja-forms-plugin-3-15-3-cross-site-scripting-xss-vulnerability-2?_s_id=cve"],"products":["Ninja Forms"],"vendors":["Kevin Stover"]}},{"cve_id":"CVE-2026-102386","summary":"Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/wp-photo-album-plus/vulnerability/wordpress-wp-photo-album-plus-plugin-9-3-02-003-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:17","euvd":{"id":"EUVD-2026-89942","description":"Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions.","published_time":"2026-09-30T12:28:29","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/wp-photo-album-plus/vulnerability/wordpress-wp-photo-album-plus-plugin-9-3-02-003-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["WP Photo Album Plus"],"vendors":["Jacob N. Breetvelt"]}},{"cve_id":"CVE-2026-102395","summary":"Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/google-maps-easy/vulnerability/wordpress-easy-google-maps-plugin-1-14-6-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:17","euvd":{"id":"EUVD-2026-89943","description":"Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions.","published_time":"2026-09-30T12:28:30","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/google-maps-easy/vulnerability/wordpress-easy-google-maps-plugin-1-14-6-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Easy Google Maps"],"vendors":["Supsystic"]}},{"cve_id":"CVE-2026-102396","summary":"Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/ultimate-maps-by-supsystic/vulnerability/wordpress-ultimate-maps-by-supsystic-plugin-1-5-5-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:17","euvd":{"id":"EUVD-2026-89944","description":"Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions.","published_time":"2026-09-30T12:28:31","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/ultimate-maps-by-supsystic/vulnerability/wordpress-ultimate-maps-by-supsystic-plugin-1-5-5-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Ultimate Maps by Supsystic"],"vendors":["Supsystic"]}},{"cve_id":"CVE-2026-102398","summary":"Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.13.1 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/popup-by-supsystic/vulnerability/wordpress-popup-by-supsystic-plugin-1-13-1-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:17","euvd":{"id":"EUVD-2026-89945","description":"Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.13.1 versions.","published_time":"2026-09-30T12:28:32","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/popup-by-supsystic/vulnerability/wordpress-popup-by-supsystic-plugin-1-13-1-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Popup by Supsystic"],"vendors":["Supsystic"]}},{"cve_id":"CVE-2026-102399","summary":"Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/gallery-by-supsystic/vulnerability/wordpress-photo-gallery-by-supsystic-plugin-1-21-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:17","euvd":{"id":"EUVD-2026-89946","description":"Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions.","published_time":"2026-09-30T12:28:32","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/gallery-by-supsystic/vulnerability/wordpress-photo-gallery-by-supsystic-plugin-1-21-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"],"products":["Photo Gallery by Supsystic"],"vendors":["Supsystic"]}},{"cve_id":"CVE-2026-103115","summary":"A security flaw has been discovered in OS4ED openSIS-Classic up to 9.3. This affects an unknown function of the file functions/CustomFieldsFnc.php of the component Student Search. The manipulation of the argument cust results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.","cvss":2.1,"cvss_version":4.0,"cvss_v2":6.5,"cvss_v3":6.3,"cvss_v4":2.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/OS4ED/openSIS-Classic/","https://github.com/OS4ED/openSIS-Classic/issues/475","https://vuldb.com/cve/CVE-2026-103115","https://vuldb.com/submit/954961","https://vuldb.com/vuln/411871","https://vuldb.com/vuln/411871/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:17","euvd":{"id":"EUVD-2026-89799","description":"A security flaw has been discovered in OS4ED openSIS-Classic up to 9.3. This affects an unknown function of the file functions/CustomFieldsFnc.php of the component Student Search. The manipulation of the argument cust results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.","published_time":"2026-09-30T12:15:12","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411871","https://vuldb.com/vuln/411871/cti","https://vuldb.com/cve/CVE-2026-103115","https://vuldb.com/submit/954961","https://github.com/OS4ED/openSIS-Classic/issues/475","https://github.com/OS4ED/openSIS-Classic/"],"products":["openSIS-Classic","openSIS-Classic","openSIS-Classic","openSIS-Classic"],"vendors":["OS4ED"]}},{"cve_id":"CVE-2026-102384","summary":"Author Cross Site Scripting (XSS) in Supreme Modules Lite <= 2.5.63 versions.","cvss":5.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.9,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/supreme-modules-for-divi/vulnerability/wordpress-supreme-modules-lite-plugin-2-5-63-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:16","euvd":{"id":"EUVD-2026-89940","description":"Author Cross Site Scripting (XSS) in Supreme Modules Lite <= 2.5.63 versions.","published_time":"2026-09-30T12:28:28","cvss":5.9,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/supreme-modules-for-divi/vulnerability/wordpress-supreme-modules-lite-plugin-2-5-63-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["Supreme Modules Lite"],"vendors":["Supreme Modules"]}},{"cve_id":"CVE-2026-100508","summary":"Unauthenticated Denial of Service Attack in Two Factor <= 0.16.0 versions.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/two-factor/vulnerability/wordpress-two-factor-plugin-0-16-0-denial-of-service-attack-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:15","euvd":{"id":"EUVD-2026-89938","description":"Unauthenticated Denial of Service Attack in Two Factor <= 0.16.0 versions.","published_time":"2026-09-30T12:28:26","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/two-factor/vulnerability/wordpress-two-factor-plugin-0-16-0-denial-of-service-attack-vulnerability?_s_id=cve"],"products":["Two Factor"],"vendors":["WordPress.org"]}},{"cve_id":"CVE-2026-100513","summary":"Contributor Cross Site Scripting (XSS) in CF7 Views &#8211; Complete Entry Management for Contact Form 7 <= 3.2.5 versions.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/cf7-views/vulnerability/wordpress-cf7-views-8211-complete-entry-management-for-contact-form-7-plugin-3-2-5-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:15","euvd":{"id":"EUVD-2026-89939","description":"Contributor Cross Site Scripting (XSS) in CF7 Views &#8211; Complete Entry Management for Contact Form 7 <= 3.2.5 versions.","published_time":"2026-09-30T12:28:27","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/cf7-views/vulnerability/wordpress-cf7-views-8211-complete-entry-management-for-contact-form-7-plugin-3-2-5-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["CF7 Views &#8211; Complete Entry Management for Contact Form 7"],"vendors":["Aman"]}},{"cve_id":"CVE-2026-100507","summary":"Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/if-so/vulnerability/wordpress-if-so-dynamic-content-personalization-plugin-1-10-1-cross-site-scripting-xss-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T13:17:14","euvd":{"id":"EUVD-2026-89937","description":"Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions.","published_time":"2026-09-30T12:28:26","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/if-so/vulnerability/wordpress-if-so-dynamic-content-personalization-plugin-1-10-1-cross-site-scripting-xss-vulnerability?_s_id=cve"],"products":["If-So Dynamic Content Personalization"],"vendors":["If-So Dynamic Content"]}},{"cve_id":"CVE-2026-87830","summary":"In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required element without the expected signature or encryption.\nUsers are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread.html/lwlozb1x20d16f9dnyvoygc9rrhzq2vn","http://www.openwall.com/lists/oss-security/2026/09/30/9"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T12:17:14","euvd":{"id":"EUVD-2026-89792","description":"In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required element without the expected signature or encryption.\nUsers are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.","published_time":"2026-09-30T11:57:01","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread.html/lwlozb1x20d16f9dnyvoygc9rrhzq2vn"],"products":["Apache WSS4J","Apache WSS4J","Apache WSS4J"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-88920","summary":"An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key.\n\nUsers are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread.html/grt43m3bgbzz0mk0cnho3rcybb1j01z9","http://www.openwall.com/lists/oss-security/2026/09/30/10"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T12:17:14","euvd":{"id":"EUVD-2026-89793","description":"An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key.\n\nUsers are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.","published_time":"2026-09-30T11:58:00","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread.html/grt43m3bgbzz0mk0cnho3rcybb1j01z9"],"products":["Apache WSS4J","Apache WSS4J","Apache WSS4J"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-62146","summary":"A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container recreate in that sandbox can expose a host-side runtime-management resource inside the container, enabling container escape.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-62146","https://bugzilla.redhat.com/show_bug.cgi?id=2499618","https://github.com/cri-o/cri-o/security/advisories/GHSA-6wmc-5877-hgc9"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T12:17:13","euvd":{"id":"EUVD-2026-89789","description":"A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container recreate in that sandbox can expose a host-side runtime-management resource inside the container, enabling container escape.","published_time":"2026-09-30T11:49:20","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-62146","https://bugzilla.redhat.com/show_bug.cgi?id=2499618","https://github.com/cri-o/cri-o/security/advisories/GHSA-6wmc-5877-hgc9"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-85532","summary":"Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing crafted WS-Security messages. The fixes enforce a minimum key length of 16 bytes, a maximum length of 512 bytes, and a maximum offset of 4096 bytes.\nUsers are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread.html/7jllcpbf4nbzhdp2vchz5yplnl5w6vd6","http://www.openwall.com/lists/oss-security/2026/09/30/8"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T12:17:13","euvd":{"id":"EUVD-2026-89791","description":"Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing crafted WS-Security messages. The fixes enforce a minimum key length of 16 bytes, a maximum length of 512 bytes, and a maximum offset of 4096 bytes.\nUsers are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.","published_time":"2026-09-30T11:55:53","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread.html/7jllcpbf4nbzhdp2vchz5yplnl5w6vd6"],"products":["Apache WSS4J","Apache WSS4J","Apache WSS4J"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-103012","summary":"Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its configuration, ahead of the user's valid Claude Enterprise or Team sign-in when fetching the organization's server-managed settings, even though the session itself authenticated with the Enterprise or Team account. When the settings endpoint rejected that stored key, the session started without the organization's server-managed policy (such as permission deny rules, model restrictions and managed-only locks) or, if a previously cached copy existed on the machine, kept applying that stale copy without receiving later policy changes — while continuing to operate as the organization's account. Triggering this required local access to a device with such a stored API key; the no-policy case additionally required that no managed settings had previously been cached. Endpoint-managed (MDM or file-based) settings were not affected. Claude for Enterprise organizations were affected from version 2.0.68; Claude for Work (Team) organizations from version 2.1.38, when server-managed settings became available to them.\n\nUsers on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to version 2.1.260 or later.\n\nThank you to Tamas Voros / NVIDIA AI Red Team for reporting this issue.","cvss":2.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":2.0,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/anthropics/claude-code/security/advisories/GHSA-gfvf-j8jh-jxxw"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T12:17:12","euvd":{"id":"EUVD-2026-89778","description":"Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its configuration, ahead of the user's valid Claude Enterprise or Team sign-in when fetching the organization's server-managed settings, even though the session itself authenticated with the Enterprise or Team account. When the settings endpoint rejected that stored key, the session started without the organization's server-managed policy (such as permission deny rules, model restrictions and managed-only locks) or, if a previously cached copy existed on the machine, kept applying that stale copy without receiving later policy changes — while continuing to operate as the organization's account. Triggering this required local access to a device with such a stored API key; the no-policy case additionally required that no managed settings had previously been cached. Endpoint-managed (MDM or file-based) settings were not affected. Claude for Enterprise organizations were affected from version 2.0.68; Claude for Work (Team) organizations from version 2.1.38, when server-managed settings became available to them.\n\nUsers on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to version 2.1.260 or later.\n\nThank you to Tamas Voros / NVIDIA AI Red Team for reporting this issue.","published_time":"2026-09-30T11:30:38","cvss":2.0,"cvss_version":"4.0","epss":0.0,"assigner":"Anthropic","references":["https://github.com/anthropics/claude-code/security/advisories/GHSA-gfvf-j8jh-jxxw"],"products":["@anthropic-ai/claude-code"],"vendors":["Anthropic"]}},{"cve_id":"CVE-2026-103114","summary":"A vulnerability was identified in OS4ED openSIS-Classic up to 9.3. The impacted element is the function DBQuery_assignment of the file modules/grades/Assignments.php of the component Assignment Management Endpoint. The manipulation of the argument Tables leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.","cvss":2.1,"cvss_version":4.0,"cvss_v2":6.5,"cvss_v3":6.3,"cvss_v4":2.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/OS4ED/openSIS-Classic/","https://github.com/OS4ED/openSIS-Classic/issues/474","https://vuldb.com/cve/CVE-2026-103114","https://vuldb.com/submit/954960","https://vuldb.com/vuln/411870","https://vuldb.com/vuln/411870/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T12:17:12","euvd":{"id":"EUVD-2026-89777","description":"A vulnerability was identified in OS4ED openSIS-Classic up to 9.3. The impacted element is the function DBQuery_assignment of the file modules/grades/Assignments.php of the component Assignment Management Endpoint. The manipulation of the argument Tables leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.","published_time":"2026-09-30T11:15:08","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411870","https://vuldb.com/vuln/411870/cti","https://vuldb.com/cve/CVE-2026-103114","https://vuldb.com/submit/954960","https://github.com/OS4ED/openSIS-Classic/issues/474","https://github.com/OS4ED/openSIS-Classic/"],"products":["openSIS-Classic","openSIS-Classic","openSIS-Classic","openSIS-Classic"],"vendors":["OS4ED"]}},{"cve_id":"CVE-2026-103242","summary":"A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the tag's attacker-controlled, hex-decoded content — of attacker-chosen length — past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-103242","https://bugzilla.redhat.com/show_bug.cgi?id=2543866"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T12:17:12","euvd":{"id":"EUVD-2026-89790","description":"A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the tag's attacker-controlled, hex-decoded content — of attacker-chosen length — past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.","published_time":"2026-09-30T11:50:32","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-103242","https://bugzilla.redhat.com/show_bug.cgi?id=2543866"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-10726","summary":"Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privileged local user can cause the Windows service, running as Local System, to read and disclose arbitrary local files due to improper file path validation and missing TLS certificate enforcement.","cvss":6.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.8,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://knowledge.catonetworks.com/docs/cve-2026-10726-cve-2026-10739-impacts-windows-client-versions-lower-than-6126"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T12:17:12","euvd":{"id":"EUVD-2026-89780","description":"Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privileged local user can cause the Windows service, running as Local System, to read and disclose arbitrary local files due to improper file path validation and missing TLS certificate enforcement.","published_time":"2026-09-30T11:38:31","cvss":6.8,"cvss_version":"4.0","epss":0.0,"assigner":"Cato","references":["https://knowledge.catonetworks.com/docs/cve-2026-10726-cve-2026-10739-impacts-windows-client-versions-lower-than-6126"],"products":["SDP Client"],"vendors":["Cato Networks"]}},{"cve_id":"CVE-2026-10739","summary":"Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM privileges via improper validation of a client-supplied SID over a local IPC named pipe.","cvss":8.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.5,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://knowledge.catonetworks.com/docs/cve-2026-10726-cve-2026-10739-impacts-windows-client-versions-lower-than-6126"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T12:17:12","euvd":{"id":"EUVD-2026-89779","description":"Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM privileges via improper validation of a client-supplied SID over a local IPC named pipe.","published_time":"2026-09-30T11:37:50","cvss":8.5,"cvss_version":"4.0","epss":0.0,"assigner":"Cato","references":["https://knowledge.catonetworks.com/docs/cve-2026-10726-cve-2026-10739-impacts-windows-client-versions-lower-than-6126"],"products":["SDP Client"],"vendors":["Cato Networks"]}},{"cve_id":"CVE-2026-96342","summary":"Missing Authorization vulnerability in Amauri.IO WPMobile.App wpappninja allows Retrieve Embedded Sensitive Data.This issue affects WPMobile.App: from n/a through 11.83.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/wpappninja/vulnerability/wordpress-wpmobile-app-plugin-11-83-sensitive-data-exposure-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T11:16:48","euvd":{"id":"EUVD-2026-89773","description":"Missing Authorization vulnerability in Amauri.IO WPMobile.App wpappninja allows Retrieve Embedded Sensitive Data.This issue affects WPMobile.App: from n/a through 11.83.","published_time":"2026-09-30T11:00:18","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/wpappninja/vulnerability/wordpress-wpmobile-app-plugin-11-83-sensitive-data-exposure-vulnerability?_s_id=cve"],"products":["WPMobile.App"],"vendors":["Amauri.IO"]}},{"cve_id":"CVE-2026-76992","summary":"The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.certvde.com/en/advisories/VDE-2026-094/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T11:16:47","euvd":{"id":"EUVD-2026-89776","description":"The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus leading to a total loss of availablity.","published_time":"2026-09-30T11:07:45","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"CERTVDE","references":["https://www.certvde.com/en/advisories/VDE-2026-094/"],"products":["HMI (SL) ","Runtime Toolkit","Development System 3","Edge Gateway for Linux","PLCHandler","OPC DA Server SL","Edge Gateway for Windows","Gateway"],"vendors":["CODESYS"]}},{"cve_id":"CVE-2026-103113","summary":"A vulnerability was determined in OS4ED openSIS-Classic up to 9.3. The affected element is the function save action of the file modules/students/Student.php of the component General Information Tab. Executing a manipulation of the argument students can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.","cvss":2.0,"cvss_version":4.0,"cvss_v2":5.8,"cvss_v3":4.7,"cvss_v4":2.0,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/OS4ED/openSIS-Classic/","https://github.com/OS4ED/openSIS-Classic/issues/475","https://vuldb.com/cve/CVE-2026-103113","https://vuldb.com/submit/954959","https://vuldb.com/vuln/411869","https://vuldb.com/vuln/411869/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T11:16:43","euvd":{"id":"EUVD-2026-89762","description":"A vulnerability was determined in OS4ED openSIS-Classic up to 9.3. The affected element is the function save action of the file modules/students/Student.php of the component General Information Tab. Executing a manipulation of the argument students can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.","published_time":"2026-09-30T10:30:08","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411869","https://vuldb.com/vuln/411869/cti","https://vuldb.com/cve/CVE-2026-103113","https://vuldb.com/submit/954959","https://github.com/OS4ED/openSIS-Classic/issues/475","https://github.com/OS4ED/openSIS-Classic/"],"products":["openSIS-Classic","openSIS-Classic","openSIS-Classic","openSIS-Classic"],"vendors":["OS4ED"]}},{"cve_id":"CVE-2026-103239","summary":"MISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality. The affected actions accepted the full HTTP request payload and passed it to a bulk-association save operation, which writes not only the intended tag collection record but also any associated model data present in the payload.\n\nA user holding the tag editor permission could craft a request that includes additional model data (such as User or Organisation records) alongside the tag collection fields. Because the save operation processed all associated models indiscriminately, the injected sibling records were written to the database, enabling the attacker to modify or create privileged accounts and escalate to site administrator.\n\nPreconditions:\n\n- An authenticated account with the tag editor permission (perm_tag_editor)\n\n- Network access to the MISP instance\n\nImpact:\n\n- Unauthorized creation or modification of User and Organisation records\n\n- Privilege escalation from tag editor to site administrator\n\nAffected versions: < 2.5.48","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/MISP/MISP/commit/96f735e7b"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T11:16:43","euvd":{"id":"EUVD-2026-89761","description":"MISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality. The affected actions accepted the full HTTP request payload and passed it to a bulk-association save operation, which writes not only the intended tag collection record but also any associated model data present in the payload.\n\nA user holding the tag editor permission could craft a request that includes additional model data (such as User or Organisation records) alongside the tag collection fields. Because the save operation processed all associated models indiscriminately, the injected sibling records were written to the database, enabling the attacker to modify or create privileged accounts and escalate to site administrator.\n\nPreconditions:\n\n- An authenticated account with the tag editor permission (perm_tag_editor)\n\n- Network access to the MISP instance\n\nImpact:\n\n- Unauthorized creation or modification of User and Organisation records\n\n- Privilege escalation from tag editor to site administrator\n\nAffected versions: < 2.5.48","published_time":"2026-09-30T10:16:18","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"CIRCL","references":["https://github.com/MISP/MISP/commit/96f735e7b"],"products":["MISP"],"vendors":["MISP"]}},{"cve_id":"CVE-2026-13719","summary":"An authenticated user can list alert rules stored in folders they are not allowed to read through the alert rules API list endpoint. When the set of folders the user may read was empty, the folder restriction was dropped and every alert rule in the organization was returned. From Grafana 13.1.0, any user can trigger this with a folder filter. The exposed data is rule configuration; data source credentials are not exposed.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://grafana.com/security/security-advisories/cve-2026-13719"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T11:16:43","euvd":{"id":"EUVD-2026-89774","description":"An authenticated user can list alert rules stored in folders they are not allowed to read through the alert rules API list endpoint. When the set of folders the user may read was empty, the folder restriction was dropped and every alert rule in the organization was returned. From Grafana 13.1.0, any user can trigger this with a folder filter. The exposed data is rule configuration; data source credentials are not exposed.","published_time":"2026-09-30T11:06:38","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"GRAFANA","references":["https://grafana.com/security/security-advisories/cve-2026-13719"],"products":["Grafana Enterprise","Grafana Enterprise","Grafana Enterprise","Grafana Enterprise","Grafana OSS","Grafana OSS","Grafana OSS","Grafana OSS","Grafana OSS","Grafana Enterprise"],"vendors":["Grafana"]}},{"cve_id":"CVE-2026-13720","summary":"An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The dashboard then appears file-provisioned, and administrators can no longer update or delete it through Grafana. The impact is limited to the same organization and no data is exposed.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://grafana.com/security/security-advisories/cve-2026-13720"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T11:16:43","euvd":{"id":"EUVD-2026-89775","description":"An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The dashboard then appears file-provisioned, and administrators can no longer update or delete it through Grafana. The impact is limited to the same organization and no data is exposed.","published_time":"2026-09-30T11:06:38","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"GRAFANA","references":["https://grafana.com/security/security-advisories/cve-2026-13720"],"products":["Grafana Enterprise","Grafana Enterprise","Grafana Enterprise","Grafana Enterprise","Grafana OSS","Grafana OSS","Grafana Enterprise","Grafana Enterprise","Grafana OSS","Grafana Enterprise","Grafana OSS","Grafana OSS","Grafana OSS","Grafana OSS","Grafana OSS","Grafana Enterprise"],"vendors":["Grafana"]}},{"cve_id":"CVE-2026-94029","summary":"Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension. Apache MINA SSHD is a Java library for client-side and server-side SSH.\n\n\n\n\nUsing a very small \"block size\" (for instance 256, which is the minimum) on a huge file generates many (file size / block size) hashes. The resulting SFTP reply message was accumulated fully in memory server-side, which could, with a suitably large (possibly sparse) file exhaust the server-side memory, taking down the server.\n\n\n\n\nUsers are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue by imposing a maximum limit on the size of the reply. Many SFTP implementations have a general limit on the size of SFTP messages anyway; typically 256kB as in OpenSSH or also in Apache MINA SSHD.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00344,"ranking_epss":0.2546,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread.html/ytbl4rwby62xl7llm3wp7k975wwdx99t","http://www.openwall.com/lists/oss-security/2026/09/29/37"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T10:17:18","euvd":{"id":"EUVD-2026-89731","description":"Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension. Apache MINA SSHD is a Java library for client-side and server-side SSH.\n\n\n\n\nUsing a very small \"block size\" (for instance 256, which is the minimum) on a huge file generates many (file size / block size) hashes. The resulting SFTP reply message was accumulated fully in memory server-side, which could, with a suitably large (possibly sparse) file exhaust the server-side memory, taking down the server.\n\n\n\n\nUsers are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue by imposing a maximum limit on the size of the reply. Many SFTP implementations have a general limit on the size of SFTP messages anyway; typically 256kB as in OpenSSH or also in Apache MINA SSHD.","published_time":"2026-09-30T09:35:51","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread.html/ytbl4rwby62xl7llm3wp7k975wwdx99t"],"products":["Apache Mina SSHD","Apache Mina SSHD"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-94052","summary":"A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks.\n\n\n\n\nApache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server.\n\n\n\n\nsshd-ldap is an optional component. SSH servers implemented with Apache MINA SSHD are affected only if they use sshd-ldap and do configure an LdapPasswordAuthenticator to be used for password authentication. Normal password authentication via the built-in mechanisms in sshd-core is _not_ affected by this vulnerability, which concerns only LdapPasswordAuthenticator.\n\n\n\n\nUsers are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00529,"ranking_epss":0.42567,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread.html/qch5kdwwms13y6bylb7c6qqzq718wn24","http://www.openwall.com/lists/oss-security/2026/09/29/38"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T10:17:18","euvd":{"id":"EUVD-2026-89730","description":"A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks.\n\n\n\n\nApache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server.\n\n\n\n\nsshd-ldap is an optional component. SSH servers implemented with Apache MINA SSHD are affected only if they use sshd-ldap and do configure an LdapPasswordAuthenticator to be used for password authentication. Normal password authentication via the built-in mechanisms in sshd-core is _not_ affected by this vulnerability, which concerns only LdapPasswordAuthenticator.\n\n\n\n\nUsers are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue.","published_time":"2026-09-30T09:34:43","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread.html/qch5kdwwms13y6bylb7c6qqzq718wn24"],"products":["Apache Mina SSHD","Apache Mina SSHD"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-94053","summary":"Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5.\n\n\n\n\nApache MINA SSHD is a Java library for client-side and server-side SSH. \nThe optional sshd-ldap component provides support for integrating \npassword and publickey authentication on the server side with an LDAP \nserver.\n\n\n\n\nsshd-ldap is an optional component. SSH servers implemented with Apache \nMINA SSHD are affected only if they use sshd-ldap and do configure it to be used for password of public key authentication.\n\nOther Apache MINA SSHD servers are not affected.\n\n\n\n\nLack of escaping LDAP filter metacharacters enabled successful authentication with username \"*\" and password \"*\".\n\n\n\n\nUsers are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue by properly escaping filter parameters according to RFC 4515.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00529,"ranking_epss":0.42568,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread.html/cyrxkdzl3c70rrqs3klqphqz1hwm7p41","http://www.openwall.com/lists/oss-security/2026/09/29/39"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T10:17:18","euvd":{"id":"EUVD-2026-89757","description":"Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5.\n\n\n\n\nApache MINA SSHD is a Java library for client-side and server-side SSH. \nThe optional sshd-ldap component provides support for integrating \npassword and publickey authentication on the server side with an LDAP \nserver.\n\n\n\n\nsshd-ldap is an optional component. SSH servers implemented with Apache \nMINA SSHD are affected only if they use sshd-ldap and do configure it to be used for password of public key authentication.\n\nOther Apache MINA SSHD servers are not affected.\n\n\n\n\nLack of escaping LDAP filter metacharacters enabled successful authentication with username \"*\" and password \"*\".\n\n\n\n\nUsers are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue by properly escaping filter parameters according to RFC 4515.","published_time":"2026-09-30T09:43:47","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread.html/cyrxkdzl3c70rrqs3klqphqz1hwm7p41"],"products":["Apache Mina SSHD","Apache Mina SSHD"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-77185","summary":"Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an SSH server.\n\n\n\n\nApache MINA SSHD is a Java library for client- and server-side SSH. In the server part of the library, a mechanism to perform \"asynchronous authentication\" exists. A server implemented with Apache MINA SSHD must contain explicit code to make use of this feature. The implementation of this feature was flawed and could potentially lead to skipping checking the signature in public-key or hostbased authentication, or returning a wrong result.\n\n\n\n\nUsers are recommended to upgrade to Apache MINA SSHD 2.20.0 or 3.0.0-M6, which fix the logic error and which additionally forbid the use of this \"asynchronous authentication\" mechanism with the public-key or hostbased authentication schemes: if used, the SSH session will be closed and the server will log an entry indicating that asynchronous authentication may be used only with password or keyboard-interactive authentication.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00466,"ranking_epss":0.37936,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread.html/t8pn812yq8ndokxyfxztg8tovov1284n","http://www.openwall.com/lists/oss-security/2026/09/29/32"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T10:17:17","euvd":{"id":"EUVD-2026-89759","description":"Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an SSH server.\n\n\n\n\nApache MINA SSHD is a Java library for client- and server-side SSH. In the server part of the library, a mechanism to perform \"asynchronous authentication\" exists. A server implemented with Apache MINA SSHD must contain explicit code to make use of this feature. The implementation of this feature was flawed and could potentially lead to skipping checking the signature in public-key or hostbased authentication, or returning a wrong result.\n\n\n\n\nUsers are recommended to upgrade to Apache MINA SSHD 2.20.0 or 3.0.0-M6, which fix the logic error and which additionally forbid the use of this \"asynchronous authentication\" mechanism with the public-key or hostbased authentication schemes: if used, the SSH session will be closed and the server will log an entry indicating that asynchronous authentication may be used only with password or keyboard-interactive authentication.","published_time":"2026-09-30T09:47:03","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread.html/t8pn812yq8ndokxyfxztg8tovov1284n"],"products":["Apache Mina SSHD","Apache Mina SSHD"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-79625","summary":"Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition.","cvss":7.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":7.2,"epss":0.004,"ranking_epss":0.31714,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.certvde.com/en/advisories/VDE-2026-097/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T10:17:17","euvd":{"id":"EUVD-2026-89729","description":"Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenticated remote attacker with monitoring access can exploit this issue to cause incorrect data processing or a denial-of-service condition.","published_time":"2026-09-30T09:23:16","cvss":7.2,"cvss_version":"4.0","epss":0.0,"assigner":"CERTVDE","references":["https://www.certvde.com/en/advisories/VDE-2026-097/"],"products":["Development System 3","Control for BeagleBone SL","Control for Raspberry Pi SL","Safety SIL2","Control for Linux SL","Control RTE (for Beckhoff CX) SL","Control for WAGO Touch Panels 600 SL","Control for PFC100 SL","Control for Linux ARM SL","Virtual Control SL","Runtime Toolkit","Control for IOT2000 SL","Control for PLCnext SL","Control for PFC200 SL","HMI (SL) ","Control for emPC-A/iMX6 SL","Control RTE (SL) ","Control Win (SL)"],"vendors":["CODESYS"]}},{"cve_id":"CVE-2026-93994","summary":"Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different public keys, not just one. In OpenSSH, this would be done by setting in sshd_config AuthenticationMethods \"publickey,publickey\". Apache MINA SSHD provides an equivalent configuration mechanism.\n\n\n\n\nIn Apache MINA SSHD versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 the server code in component sshd-core does not enforce that the two public keys presented are different. A user can thus successfully authenticate with only one of the two key pairs required by presenting this single key twice. This is a partial authentication bypass.\n\n\n\n\n\n\nUsers are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":0.00457,"ranking_epss":0.3727,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread.html/9t3vsm8rnvwdv9779mlg1lq2fbwojdwp","http://www.openwall.com/lists/oss-security/2026/09/29/33"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T10:17:17","euvd":{"id":"EUVD-2026-89758","description":"Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different public keys, not just one. In OpenSSH, this would be done by setting in sshd_config AuthenticationMethods \"publickey,publickey\". Apache MINA SSHD provides an equivalent configuration mechanism.\n\n\n\n\nIn Apache MINA SSHD versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 the server code in component sshd-core does not enforce that the two public keys presented are different. A user can thus successfully authenticate with only one of the two key pairs required by presenting this single key twice. This is a partial authentication bypass.\n\n\n\n\n\n\nUsers are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.","published_time":"2026-09-30T09:45:32","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread.html/9t3vsm8rnvwdv9779mlg1lq2fbwojdwp"],"products":["Apache Mina SSHD","Apache Mina SSHD"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-93995","summary":"Improper input validation in sshd-git in Apache MINA SSHD, versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache \nMINA SSHD is a Java library for client-side and server-side SSH.\n\n\n\n\nComponent org.apache.sshd:sshd-git provides though class GitPgmCommandFactory a way to configure an Apache MINA SSHD server such \nthat authenticated SSH clients can remotely execute git commands via the JGit library \non git repositories stored on the server. In CVE-2026-58624 this mechanism was restricted to only a few git commands, including \"git archive\" without \"--output\" or \"-o\" options such that the resulting archive would not be written on the server but instead sent back to the client over the SSH connection.\n\n\n\n\nThe fix done for CVE-2026-58624 was insufficient as it missed removing the single-argument \"-o=file.zip\" version of the command parameter from the \"archive\" command.\n\n\n\n\nUsers are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00271,"ranking_epss":0.17489,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread.html/k13ox2xlry38h9gh6rhmh1d9zs345clk"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T10:17:17","euvd":{"id":"EUVD-2026-89755","description":"Improper input validation in sshd-git in Apache MINA SSHD, versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache \nMINA SSHD is a Java library for client-side and server-side SSH.\n\n\n\n\nComponent org.apache.sshd:sshd-git provides though class GitPgmCommandFactory a way to configure an Apache MINA SSHD server such \nthat authenticated SSH clients can remotely execute git commands via the JGit library \non git repositories stored on the server. In CVE-2026-58624 this mechanism was restricted to only a few git commands, including \"git archive\" without \"--output\" or \"-o\" options such that the resulting archive would not be written on the server but instead sent back to the client over the SSH connection.\n\n\n\n\nThe fix done for CVE-2026-58624 was insufficient as it missed removing the single-argument \"-o=file.zip\" version of the command parameter from the \"archive\" command.\n\n\n\n\nUsers are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.","published_time":"2026-09-30T09:38:47","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread.html/k13ox2xlry38h9gh6rhmh1d9zs345clk"],"products":["Apache Mina SSHD","Apache Mina SSHD"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-93996","summary":"Uncontrolled resource consumption in component ssd-scp in Apache MINA SSHD versions up to 2.19.0 or 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH.\n\n\n\n\nComponent sshd-scp of Apache MINA SSHD provides a Java implementation of SCP. The SCP command protocol is line-oriented with LF-terminated lines. The protocol handler in sshd-scp did not impose any limit on the length of such protocol lines. A malicious peer just sending a junk command containing a never-ending sequence of characters but never a LF would cause the receiver to allocate memory to store this whole junk command, exhausting memory and crashing the application with an OutOfMemoryError.\n\n\n\n\nUsers are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue by enforcing an upper limit on the length of SCP protocol lines.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00411,"ranking_epss":0.32906,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread.html/xwk8vogkpphcpm01hrt9tb6mgnpjzp35","http://www.openwall.com/lists/oss-security/2026/09/29/35"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T10:17:17","euvd":{"id":"EUVD-2026-89754","description":"Uncontrolled resource consumption in component ssd-scp in Apache MINA SSHD versions up to 2.19.0 or 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH.\n\n\n\n\nComponent sshd-scp of Apache MINA SSHD provides a Java implementation of SCP. The SCP command protocol is line-oriented with LF-terminated lines. The protocol handler in sshd-scp did not impose any limit on the length of such protocol lines. A malicious peer just sending a junk command containing a never-ending sequence of characters but never a LF would cause the receiver to allocate memory to store this whole junk command, exhausting memory and crashing the application with an OutOfMemoryError.\n\n\n\n\nUsers are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue by enforcing an upper limit on the length of SCP protocol lines.","published_time":"2026-09-30T09:37:42","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread.html/xwk8vogkpphcpm01hrt9tb6mgnpjzp35"],"products":["Apache Mina SSHD","Apache Mina SSHD"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-94002","summary":"Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5.\n\n\n\n\nApache \nMINA SSHD is a Java library for client-side and server-side SSH. The sshd-sftp component provides support for SFTP.\n\n\n\n\nThe SFTP client implementation, when receiving a reply, did not check that this reply corresponded to a request sent earlier. Unsolicited replies would be stored but never consumed. A malicious server could keep sending unsolicited replies until available memory in the client was exhausted.\n\n\n\n\nUsers are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00385,"ranking_epss":0.30078,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread.html/x2cb00kh4qvsq145tj2w4g3toy8cybld","http://www.openwall.com/lists/oss-security/2026/09/29/36"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T10:17:17","euvd":{"id":"EUVD-2026-89753","description":"Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5.\n\n\n\n\nApache \nMINA SSHD is a Java library for client-side and server-side SSH. The sshd-sftp component provides support for SFTP.\n\n\n\n\nThe SFTP client implementation, when receiving a reply, did not check that this reply corresponded to a request sent earlier. Unsolicited replies would be stored but never consumed. A malicious server could keep sending unsolicited replies until available memory in the client was exhausted.\n\n\n\n\nUsers are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.","published_time":"2026-09-30T09:37:01","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread.html/x2cb00kh4qvsq145tj2w4g3toy8cybld"],"products":["Apache Mina SSHD","Apache Mina SSHD"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-103235","summary":"MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the primary key and event_id.\n\nAn authenticated attacker could inject a primary key or event_id into the delegation payload to retarget an existing delegation record to any event on the instance. Because a delegation row grants the requesting organisation read access to the event it references, this effectively granted read access to arbitrary events belonging to other organisations. If the target organisation subsequently accepted the delegation, ownership of the event was transferred and the original record was deleted.\n\nPreconditions:\n\n- An authenticated user with the delegation permission (perm_delegate)\n\n- The MISP.delegation server setting must be enabled\n\nImpact:\n\n- Confidentiality: read access to any event on the instance\n\n- Integrity: overwriting existing delegation records and transferring event ownership\n\nAffected versions: MISP < 2.5.48","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00363,"ranking_epss":0.27679,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/MISP/MISP/commit/d1f5684f9"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T10:17:16","euvd":{"id":"EUVD-2026-89728","description":"MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the primary key and event_id.\n\nAn authenticated attacker could inject a primary key or event_id into the delegation payload to retarget an existing delegation record to any event on the instance. Because a delegation row grants the requesting organisation read access to the event it references, this effectively granted read access to arbitrary events belonging to other organisations. If the target organisation subsequently accepted the delegation, ownership of the event was transferred and the original record was deleted.\n\nPreconditions:\n\n- An authenticated user with the delegation permission (perm_delegate)\n\n- The MISP.delegation server setting must be enabled\n\nImpact:\n\n- Confidentiality: read access to any event on the instance\n\n- Integrity: overwriting existing delegation records and transferring event ownership\n\nAffected versions: MISP < 2.5.48","published_time":"2026-09-30T09:09:36","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"CIRCL","references":["https://github.com/MISP/MISP/commit/d1f5684f9"],"products":["MISP"],"vendors":["MISP"]}},{"cve_id":"CVE-2026-103237","summary":"MISP contains an improper input validation vulnerability in its ORM save path. When a user submits data through various endpoints (attribute add/edit, event edit, free-text import, sighting capture, shadow attribute proposal, event report creation, object reference add, user admin edit), the application sanitizes the flat record by stripping the primary key and pinning the event_id or object_id to the caller's context. However, the underlying ORM's set() method gives priority to a nested key whose name matches the model alias and discards the outer scalar fields.\n\nAn authenticated user with basic write permissions can exploit this by embedding a nested block under the model alias key inside their request. The sanitization logic (id removal, event_id pinning) is applied to the outer record, but the ORM binds to the inner record instead, which carries an attacker-chosen id and event_id. This allows the attacker to overwrite, re-parent, or soft-delete rows belonging to other organizations or events they have no read access to.\n\nImpact:\n\n- Cross-tenant data integrity compromise (attribute values rewritten, objects re-parented to attacker events, rows soft-deleted)\n\n- Affects multiple entity types: Attribute, Object, EventReport, Sighting, AttributeTag, ShadowAttribute\n\n- Requires only a low-privilege authenticated account with perm_add\n\nAffected versions: <2.5.48","cvss":8.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.3,"epss":0.00389,"ranking_epss":0.30535,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/MISP/MISP/commit/9485ae40d"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T10:17:16","euvd":{"id":"EUVD-2026-89760","description":"MISP contains an improper input validation vulnerability in its ORM save path. When a user submits data through various endpoints (attribute add/edit, event edit, free-text import, sighting capture, shadow attribute proposal, event report creation, object reference add, user admin edit), the application sanitizes the flat record by stripping the primary key and pinning the event_id or object_id to the caller's context. However, the underlying ORM's set() method gives priority to a nested key whose name matches the model alias and discards the outer scalar fields.\n\nAn authenticated user with basic write permissions can exploit this by embedding a nested block under the model alias key inside their request. The sanitization logic (id removal, event_id pinning) is applied to the outer record, but the ORM binds to the inner record instead, which carries an attacker-chosen id and event_id. This allows the attacker to overwrite, re-parent, or soft-delete rows belonging to other organizations or events they have no read access to.\n\nImpact:\n\n- Cross-tenant data integrity compromise (attribute values rewritten, objects re-parented to attacker events, rows soft-deleted)\n\n- Affects multiple entity types: Attribute, Object, EventReport, Sighting, AttributeTag, ShadowAttribute\n\n- Requires only a low-privilege authenticated account with perm_add\n\nAffected versions: <2.5.48","published_time":"2026-09-30T09:56:35","cvss":8.3,"cvss_version":"4.0","epss":0.0,"assigner":"CIRCL","references":["https://github.com/MISP/MISP/commit/9485ae40d"],"products":["MISP"],"vendors":["MISP"]}},{"cve_id":"CVE-2026-10764","summary":"Information disclosure in BVMS 4.5 up to 12.3 including allows man-in-the-middle attackers to gain unauthorized access to sensitive data.","cvss":8.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.7,"cvss_v4":null,"epss":0.00238,"ranking_epss":0.13386,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.iqsight.com/f/292130204896374/x/594fff1c4a/iqsight-sa-261342.pdf"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T10:17:16","euvd":{"id":"EUVD-2026-89756","description":"Information disclosure in BVMS 4.5 up to 12.3 including allows man-in-the-middle attackers to gain unauthorized access to sensitive data.","published_time":"2026-09-30T09:43:45","cvss":8.7,"cvss_version":"3.1","epss":0.0,"assigner":"IQSIGHT","references":["https://www.iqsight.com/f/292130204896374/x/594fff1c4a/iqsight-sa-261342.pdf"],"products":["BVMS"],"vendors":["IQSIGHT"]}},{"cve_id":"CVE-2026-102587","summary":"A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted to view directly, resulting in unauthorized information disclosure by inferring hidden user data.","cvss":2.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":2.7,"cvss_v4":null,"epss":0.00233,"ranking_epss":0.12815,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-87518","https://access.redhat.com/security/cve/CVE-2026-102587","https://bugzilla.redhat.com/show_bug.cgi?id=2543642","https://moodle.org/mod/forum/discuss.php?d=482506"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:16","euvd":{"id":"EUVD-2026-89726","description":"A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted to view directly, resulting in unauthorized information disclosure by inferring hidden user data.","published_time":"2026-09-30T08:36:21","cvss":2.7,"cvss_version":"3.1","epss":0.0,"assigner":"fedora","references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-87518","https://access.redhat.com/security/cve/CVE-2026-102587","https://bugzilla.redhat.com/show_bug.cgi?id=2543642","https://moodle.org/mod/forum/discuss.php?d=482506"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-102588","summary":"A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with grade management permissions into visiting a malicious webpage, an attacker can trigger unauthorized requests on the victim's behalf. This flaw allows a remote attacker to set or overwrite student grades without authorization.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00173,"ranking_epss":0.06034,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84545","https://access.redhat.com/security/cve/CVE-2026-102588","https://bugzilla.redhat.com/show_bug.cgi?id=2543643","https://moodle.org/mod/forum/discuss.php?d=482507"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:16","euvd":{"id":"EUVD-2026-89727","description":"A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with grade management permissions into visiting a malicious webpage, an attacker can trigger unauthorized requests on the victim's behalf. This flaw allows a remote attacker to set or overwrite student grades without authorization.","published_time":"2026-09-30T08:36:23","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"fedora","references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84545","https://access.redhat.com/security/cve/CVE-2026-102588","https://bugzilla.redhat.com/show_bug.cgi?id=2543643","https://moodle.org/mod/forum/discuss.php?d=482507"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-75098","summary":"The Product Designer App plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.3 via the 'svg' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The endpoint's only authentication gate relies on a nonce and token that are both publicly emitted as JavaScript globals on any page rendering the [pdapp-studio-page] shortcode, making them freely obtainable by anonymous visitors.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.009,"ranking_epss":0.58128,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/product-designer-app/trunk/includes/productdesignerapp-front-ajax.php#L625","https://plugins.trac.wordpress.org/browser/product-designer-app/trunk/includes/productdesignerapp-helpers.php#L261","https://plugins.trac.wordpress.org/browser/product-designer-app/trunk/includes/productdesignerapp-helpers.php#L2867","https://plugins.trac.wordpress.org/browser/product-designer-app/trunk/templates/default/script/variants.php#L22","https://www.wordfence.com/threat-intel/vulnerabilities/id/e94db231-e5d4-4b49-ad36-74c0284abfd2?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:16","euvd":{"id":"EUVD-2026-89684","description":"The Product Designer App plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.3 via the 'svg' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The endpoint's only authentication gate relies on a nonce and token that are both publicly emitted as JavaScript globals on any page rendering the [pdapp-studio-page] shortcode, making them freely obtainable by anonymous visitors.","published_time":"2026-09-30T08:28:04","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/e94db231-e5d4-4b49-ad36-74c0284abfd2?source=cve","https://plugins.trac.wordpress.org/browser/product-designer-app/trunk/includes/productdesignerapp-helpers.php#L2867","https://plugins.trac.wordpress.org/browser/product-designer-app/trunk/includes/productdesignerapp-front-ajax.php#L625","https://plugins.trac.wordpress.org/browser/product-designer-app/trunk/includes/productdesignerapp-helpers.php#L261","https://plugins.trac.wordpress.org/browser/product-designer-app/trunk/templates/default/script/variants.php#L22"],"products":["Product Designer App"],"vendors":["productdesignerapp"]}},{"cve_id":"CVE-2026-92712","summary":"The ReactPress – Create React App for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permalink' parameter in all versions up to, and including, 3.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because the permalink parameter is only passed through sanitize_url(), which does not prevent fetching attacker-controlled remote URLs whose response body — including script tags and event-handler attributes — is written verbatim to disk via file_put_contents().","cvss":6.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.4,"cvss_v4":null,"epss":0.00193,"ranking_epss":0.0808,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/reactpress/tags/3.4.0/admin/Admin.php#L220","https://plugins.trac.wordpress.org/browser/reactpress/tags/3.4.0/admin/Controller.php#L201","https://plugins.trac.wordpress.org/browser/reactpress/tags/3.4.0/admin/Controller.php#L339","https://plugins.trac.wordpress.org/browser/reactpress/tags/3.4.0/includes/Core.php#L153","https://www.wordfence.com/threat-intel/vulnerabilities/id/eaea5a3b-6565-4aa0-864d-5a2b764075fd?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:16","euvd":{"id":"EUVD-2026-89685","description":"The ReactPress – Create React App for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permalink' parameter in all versions up to, and including, 3.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because the permalink parameter is only passed through sanitize_url(), which does not prevent fetching attacker-controlled remote URLs whose response body — including script tags and event-handler attributes — is written verbatim to disk via file_put_contents().","published_time":"2026-09-30T08:28:04","cvss":6.4,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/eaea5a3b-6565-4aa0-864d-5a2b764075fd?source=cve","https://plugins.trac.wordpress.org/browser/reactpress/tags/3.4.0/admin/Controller.php#L339","https://plugins.trac.wordpress.org/browser/reactpress/tags/3.4.0/admin/Controller.php#L201","https://plugins.trac.wordpress.org/browser/reactpress/tags/3.4.0/admin/Admin.php#L220","https://plugins.trac.wordpress.org/browser/reactpress/tags/3.4.0/includes/Core.php#L153"],"products":["ReactPress – Create React App for WordPress"],"vendors":["rockiger"]}},{"cve_id":"CVE-2026-93908","summary":"The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_price_text' parameter in all versions up to, and including, 7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability is further enabled by the absence of any capability, nonce, or ownership check on the wp_ajax_rem_create_pro_ajax handler, and because the value is persisted via update_post_meta rather than post_content, the wp_kses filtering tied to the unfiltered_html capability does not apply.","cvss":6.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.4,"cvss_v4":null,"epss":0.00193,"ranking_epss":0.0808,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/real-estate-manager/tags/7.3/classes/shortcodes.class.php#L1705","https://plugins.trac.wordpress.org/browser/real-estate-manager/tags/7.3/classes/shortcodes.class.php#L1776","https://plugins.trac.wordpress.org/browser/real-estate-manager/tags/7.3/core.functions.php#L178","https://www.wordfence.com/threat-intel/vulnerabilities/id/1b05171e-e27f-437b-b9a8-0636da7bee8d?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:16","euvd":{"id":"EUVD-2026-89683","description":"The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_price_text' parameter in all versions up to, and including, 7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability is further enabled by the absence of any capability, nonce, or ownership check on the wp_ajax_rem_create_pro_ajax handler, and because the value is persisted via update_post_meta rather than post_content, the wp_kses filtering tied to the unfiltered_html capability does not apply.","published_time":"2026-09-30T08:28:03","cvss":6.4,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/1b05171e-e27f-437b-b9a8-0636da7bee8d?source=cve","https://plugins.trac.wordpress.org/browser/real-estate-manager/tags/7.3/core.functions.php#L178","https://plugins.trac.wordpress.org/browser/real-estate-manager/tags/7.3/classes/shortcodes.class.php#L1776","https://plugins.trac.wordpress.org/browser/real-estate-manager/tags/7.3/classes/shortcodes.class.php#L1705"],"products":["Real Estate Manager – Property Listing and Agent Management"],"vendors":["rameez_iqbal"]}},{"cve_id":"CVE-2026-97347","summary":"The Post Views Stats Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The plugin's only input filter is a substring blacklist for known bot signatures (e.g. 'bot', 'spider', 'crawler'), which can be trivially bypassed by crafting a User-Agent payload that omits those strings.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":0.00254,"ranking_epss":0.15273,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/post-views-stats-counter/tags/1.1.7/manage/admin.php#L447","https://plugins.trac.wordpress.org/browser/post-views-stats-counter/tags/1.1.7/manage/admin.php#L681","https://plugins.trac.wordpress.org/browser/post-views-stats-counter/tags/1.1.7/wp_pvscounter.php#L269","https://plugins.trac.wordpress.org/browser/post-views-stats-counter/tags/1.1.7/wp_pvscounter.php#L411","https://www.wordfence.com/threat-intel/vulnerabilities/id/086a8577-eb23-4e05-8ff6-7bbfef62d25c?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:16","euvd":{"id":"EUVD-2026-89682","description":"The Post Views Stats Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The plugin's only input filter is a substring blacklist for known bot signatures (e.g. 'bot', 'spider', 'crawler'), which can be trivially bypassed by crafting a User-Agent payload that omits those strings.","published_time":"2026-09-30T08:28:03","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/086a8577-eb23-4e05-8ff6-7bbfef62d25c?source=cve","https://plugins.trac.wordpress.org/browser/post-views-stats-counter/tags/1.1.7/manage/admin.php#L681","https://plugins.trac.wordpress.org/browser/post-views-stats-counter/tags/1.1.7/manage/admin.php#L447","https://plugins.trac.wordpress.org/browser/post-views-stats-counter/tags/1.1.7/wp_pvscounter.php#L411","https://plugins.trac.wordpress.org/browser/post-views-stats-counter/tags/1.1.7/wp_pvscounter.php#L269"],"products":["Post Views Stats Counter"],"vendors":["kazukiyanamoto"]}},{"cve_id":"CVE-2026-102580","summary":"A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized creation of internal program objects, which may result in unexpected application behavior.","cvss":2.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":2.2,"cvss_v4":null,"epss":0.00233,"ranking_epss":0.12827,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-89078","https://access.redhat.com/security/cve/CVE-2026-102580","https://bugzilla.redhat.com/show_bug.cgi?id=2543635","https://moodle.org/mod/forum/discuss.php?d=482498"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:15","euvd":{"id":"EUVD-2026-89719","description":"A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized creation of internal program objects, which may result in unexpected application behavior.","published_time":"2026-09-30T08:36:06","cvss":2.2,"cvss_version":"3.1","epss":0.0,"assigner":"fedora","references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-89078","https://access.redhat.com/security/cve/CVE-2026-102580","https://bugzilla.redhat.com/show_bug.cgi?id=2543635","https://moodle.org/mod/forum/discuss.php?d=482498"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-102581","summary":"A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious content into a forum post, which then executes arbitrary script code in the browser of another user viewing the affected post.","cvss":4.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.6,"cvss_v4":null,"epss":0.00171,"ranking_epss":0.05841,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88981","https://access.redhat.com/security/cve/CVE-2026-102581","https://bugzilla.redhat.com/show_bug.cgi?id=2543634","https://moodle.org/mod/forum/discuss.php?d=482499"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:15","euvd":{"id":"EUVD-2026-89720","description":"A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious content into a forum post, which then executes arbitrary script code in the browser of another user viewing the affected post.","published_time":"2026-09-30T08:36:08","cvss":4.6,"cvss_version":"3.1","epss":0.0,"assigner":"fedora","references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88981","https://access.redhat.com/security/cve/CVE-2026-102581","https://bugzilla.redhat.com/show_bug.cgi?id=2543634","https://moodle.org/mod/forum/discuss.php?d=482499"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-102582","summary":"A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with enrolment permissions to access the page directly by navigating to its URL. Consequently, an authorized user could manage manual enrolments even after an administrator disabled the feature in the user interface.","cvss":2.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":2.2,"cvss_v4":null,"epss":0.00204,"ranking_epss":0.0938,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88593","https://access.redhat.com/security/cve/CVE-2026-102582","https://bugzilla.redhat.com/show_bug.cgi?id=2543636","https://moodle.org/mod/forum/discuss.php?d=482500"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:15","euvd":{"id":"EUVD-2026-89721","description":"A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with enrolment permissions to access the page directly by navigating to its URL. Consequently, an authorized user could manage manual enrolments even after an administrator disabled the feature in the user interface.","published_time":"2026-09-30T08:36:10","cvss":2.2,"cvss_version":"3.1","epss":0.0,"assigner":"fedora","references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88593","https://access.redhat.com/security/cve/CVE-2026-102582","https://bugzilla.redhat.com/show_bug.cgi?id=2543636","https://moodle.org/mod/forum/discuss.php?d=482500"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-102583","summary":"A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user to invoke the feature without holding the required capability. This flaw permits unauthorized users to access and utilize the AI image generation functionality.","cvss":2.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":2.7,"cvss_v4":null,"epss":0.00236,"ranking_epss":0.13173,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88587","https://access.redhat.com/security/cve/CVE-2026-102583","https://bugzilla.redhat.com/show_bug.cgi?id=2543640","https://moodle.org/mod/forum/discuss.php?d=482501"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:15","euvd":{"id":"EUVD-2026-89722","description":"A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user to invoke the feature without holding the required capability. This flaw permits unauthorized users to access and utilize the AI image generation functionality.","published_time":"2026-09-30T08:36:12","cvss":2.7,"cvss_version":"3.1","epss":0.0,"assigner":"fedora","references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88587","https://access.redhat.com/security/cve/CVE-2026-102583","https://bugzilla.redhat.com/show_bug.cgi?id=2543640","https://moodle.org/mod/forum/discuss.php?d=482501"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-102584","summary":"A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding the required permissions. This issue allows unauthorized users to modify grade penalty records, potentially altering student assessment scores.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00196,"ranking_epss":0.08362,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88585","https://access.redhat.com/security/cve/CVE-2026-102584","https://bugzilla.redhat.com/show_bug.cgi?id=2543637","https://moodle.org/mod/forum/discuss.php?d=482502"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:15","euvd":{"id":"EUVD-2026-89723","description":"A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding the required permissions. This issue allows unauthorized users to modify grade penalty records, potentially altering student assessment scores.","published_time":"2026-09-30T08:36:14","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"fedora","references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88585","https://access.redhat.com/security/cve/CVE-2026-102584","https://bugzilla.redhat.com/show_bug.cgi?id=2543637","https://moodle.org/mod/forum/discuss.php?d=482502"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-102585","summary":"A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether the selected group actually belongs to that course. An authenticated user with teacher privileges could exploit this flaw to add users to groups within courses they do not have authorization to access.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00196,"ranking_epss":0.08361,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88538","https://access.redhat.com/security/cve/CVE-2026-102585","https://bugzilla.redhat.com/show_bug.cgi?id=2543639","https://moodle.org/mod/forum/discuss.php?d=482503"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:15","euvd":{"id":"EUVD-2026-89724","description":"A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether the selected group actually belongs to that course. An authenticated user with teacher privileges could exploit this flaw to add users to groups within courses they do not have authorization to access.","published_time":"2026-09-30T08:36:17","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"fedora","references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88538","https://access.redhat.com/security/cve/CVE-2026-102585","https://bugzilla.redhat.com/show_bug.cgi?id=2543639","https://moodle.org/mod/forum/discuss.php?d=482503"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-102586","summary":"A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting (XSS) attack. By convincing an unauthenticated user to access a specially crafted password reset link, an attacker could execute arbitrary script in the victim's browser.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00286,"ranking_epss":0.19035,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88335","https://access.redhat.com/security/cve/CVE-2026-102586","https://bugzilla.redhat.com/show_bug.cgi?id=2543641","https://moodle.org/mod/forum/discuss.php?d=482504"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:15","euvd":{"id":"EUVD-2026-89725","description":"A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting (XSS) attack. By convincing an unauthenticated user to access a specially crafted password reset link, an attacker could execute arbitrary script in the victim's browser.","published_time":"2026-09-30T08:36:19","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"fedora","references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88335","https://access.redhat.com/security/cve/CVE-2026-102586","https://bugzilla.redhat.com/show_bug.cgi?id=2543641","https://moodle.org/mod/forum/discuss.php?d=482504"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-102509","summary":"Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of the client application, causing a denial of service.\n\nIn the OPC UA driver these defects are reachable before authentication: the offending data is parsed while the secure channel and session are being established, before the server's identity has been bound to it. Configuring a trusted server therefore does not prevent exploitation by an attacker who can \nimpersonate it.\n\nThe individual defects are:\n- Length-prefixed byte strings are allocated at the size claimed on the wire before the length is checked against the data actually received (0.10.0 through 0.13.1).\n- Array fields in generated protocol parsers pre-allocate a list with the element count claimed on the wire, allowing a single count field to trigger a multi-gigabyte allocation. This parser is shared by all PLC4J drivers; the OPC UA driver is the verified pre-authentication path (0.10.0 through 0.13.1).\n- The OPC UA driver accumulates message chunks without enforcing the negotiated maximum chunk count and message size (0.12.0 through 0.13.1).\n- The OPC UA driver pre-allocates collections using element counts received from the server (0.10.0 through 0.13.1).\n- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Go implementation is covered by  CVE-2026-102510 https://cveprocess.apache.org/cve5/CVE-2026-102510 .\n\nThis issue affects Apache PLC4X: from 0.10.0 before 1.0.0.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00401,"ranking_epss":0.31856,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread.html/qngc85qhnlj7kpk3z58z0xlxhz2tn6gp"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:14","euvd":{"id":"EUVD-2026-89678","description":"Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of the client application, causing a denial of service.\n\nIn the OPC UA driver these defects are reachable before authentication: the offending data is parsed while the secure channel and session are being established, before the server's identity has been bound to it. Configuring a trusted server therefore does not prevent exploitation by an attacker who can \nimpersonate it.\n\nThe individual defects are:\n- Length-prefixed byte strings are allocated at the size claimed on the wire before the length is checked against the data actually received (0.10.0 through 0.13.1).\n- Array fields in generated protocol parsers pre-allocate a list with the element count claimed on the wire, allowing a single count field to trigger a multi-gigabyte allocation. This parser is shared by all PLC4J drivers; the OPC UA driver is the verified pre-authentication path (0.10.0 through 0.13.1).\n- The OPC UA driver accumulates message chunks without enforcing the negotiated maximum chunk count and message size (0.12.0 through 0.13.1).\n- The OPC UA driver pre-allocates collections using element counts received from the server (0.10.0 through 0.13.1).\n- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Go implementation is covered by  CVE-2026-102510 https://cveprocess.apache.org/cve5/CVE-2026-102510 .\n\nThis issue affects Apache PLC4X: from 0.10.0 before 1.0.0.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue.","published_time":"2026-09-30T08:00:27","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread.html/qngc85qhnlj7kpk3z58z0xlxhz2tn6gp"],"products":["Apache PLC4X"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-102510","summary":"Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network traffic, to crash or exhaust the memory of the client application,\ncausing a denial of service.\n\nThe individual defects are:\n- Generated parsers pre-allocate arrays with the element count claimed on the wire (0.13.0 through 0.13.1).\n- Transport read helpers allocate buffers of the size claimed on the wire without an upper bound.\n- ADS and KNXnet/IP response handling indexes into received data without checking its length, causing a panic.\n- ADS and EIP frame-length handling accepts, or arithmetically wraps to, a length of zero, breaking message framing.\n- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Java implementation is covered by  CVE-2026-102509 https://cveprocess.apache.org/cve5/CVE-2026-102509 .\n\nAdditionally, length and position arithmetic in generated serializers was performed in 16-bit integers. If an application forwards attacker-influenced payloads larger than 8 KB, the length field wraps, and the remainder of the payload may be interpreted by the receiving device (for example, an ADS PLC) as \nadditional, independent protocol messages.\n\nThis issue affects Apache PLC4X: from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00328,"ranking_epss":0.23467,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread.html/lw66k49p1jf7w0p7h6yg6jqvysborxrs"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:14","euvd":{"id":"EUVD-2026-89679","description":"Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow a malicious device, or an attacker able to inject network traffic, to crash or exhaust the memory of the client application,\ncausing a denial of service.\n\nThe individual defects are:\n- Generated parsers pre-allocate arrays with the element count claimed on the wire (0.13.0 through 0.13.1).\n- Transport read helpers allocate buffers of the size claimed on the wire without an upper bound.\n- ADS and KNXnet/IP response handling indexes into received data without checking its length, causing a panic.\n- ADS and EIP frame-length handling accepts, or arithmetically wraps to, a length of zero, breaking message framing.\n- Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Java implementation is covered by  CVE-2026-102509 https://cveprocess.apache.org/cve5/CVE-2026-102509 .\n\nAdditionally, length and position arithmetic in generated serializers was performed in 16-bit integers. If an application forwards attacker-influenced payloads larger than 8 KB, the length field wraps, and the remainder of the payload may be interpreted by the receiving device (for example, an ADS PLC) as \nadditional, independent protocol messages.\n\nThis issue affects Apache PLC4X: from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue.","published_time":"2026-09-30T08:01:43","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread.html/lw66k49p1jf7w0p7h6yg6jqvysborxrs"],"products":["Apache PLC4X"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-102511","summary":"Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address. The discovery result's connection \naddress was derived from the AmsNetId claimed in the response body rather than from the datagram's actual source address. One spoofed discovery response can therefore insert an inventory entry pointing at any host, including hosts outside the local network, and an application that connects to discovered devices\nwill open its ADS session, including any configured route credentials, to that host.\n\nAdditionally, discovery listeners in both implementations can be disabled by a single malformed datagram:\n- In PLC4Go ADS discovery, a short version block causes a panic that ends the listener for the rest of the discovery call, so legitimate devices answering afterwards are not reported.\n- In PLC4J, the ADS and EtherNet/IP discoverers stop on an unhandled exception from a malformed response.\n- The PLC4J Modbus discoverer can be made to spin indefinitely, consuming a CPU core, by a scanned host that sends a partial response.\n\nExploitation requires the application to invoke the discovery API, which is opt-in, and for the connection redirect, to act on the discovered items.\n\nThis issue affects Apache PLC4X: PLC4Go from 0.11.0 before 1.0.0; PLC4J ADS and Modbus drivers from 0.10.0 before 1.0.0; PLC4J EtherNet/IP driver from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 derives the connection address from the datagram's source address and logs a warning when the claimed AmsNetId disagrees with it.","cvss":8.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.5,"epss":0.00164,"ranking_epss":0.05005,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread.html/g692j4fklrbo80stjr5ll8xghrwszthf","http://www.openwall.com/lists/oss-security/2026/09/30/7"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:14","euvd":{"id":"EUVD-2026-89680","description":"Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address. The discovery result's connection \naddress was derived from the AmsNetId claimed in the response body rather than from the datagram's actual source address. One spoofed discovery response can therefore insert an inventory entry pointing at any host, including hosts outside the local network, and an application that connects to discovered devices\nwill open its ADS session, including any configured route credentials, to that host.\n\nAdditionally, discovery listeners in both implementations can be disabled by a single malformed datagram:\n- In PLC4Go ADS discovery, a short version block causes a panic that ends the listener for the rest of the discovery call, so legitimate devices answering afterwards are not reported.\n- In PLC4J, the ADS and EtherNet/IP discoverers stop on an unhandled exception from a malformed response.\n- The PLC4J Modbus discoverer can be made to spin indefinitely, consuming a CPU core, by a scanned host that sends a partial response.\n\nExploitation requires the application to invoke the discovery API, which is opt-in, and for the connection redirect, to act on the discovered items.\n\nThis issue affects Apache PLC4X: PLC4Go from 0.11.0 before 1.0.0; PLC4J ADS and Modbus drivers from 0.10.0 before 1.0.0; PLC4J EtherNet/IP driver from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 derives the connection address from the datagram's source address and logs a warning when the claimed AmsNetId disagrees with it.","published_time":"2026-09-30T08:03:04","cvss":8.5,"cvss_version":"4.0","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread.html/g692j4fklrbo80stjr5ll8xghrwszthf"],"products":["Apache PLC4X","Apache PLC4X"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-102577","summary":"A flaw was found in Moodle. Incorrect handling of IPv4-mapped IPv6 addresses within the URL downloader's host-blocking logic allows an authenticated remote user to bypass blocked-host restrictions. By supplying a crafted URL, an attacker can induce the server to make requests to restricted destinations, leading to Server-Side Request Forgery (SSRF).","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00263,"ranking_epss":0.16433,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88779","https://access.redhat.com/security/cve/CVE-2026-102577","https://bugzilla.redhat.com/show_bug.cgi?id=2543604","https://moodle.org/mod/forum/discuss.php?d=482495"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:14","euvd":{"id":"EUVD-2026-89716","description":"A flaw was found in Moodle. Incorrect handling of IPv4-mapped IPv6 addresses within the URL downloader's host-blocking logic allows an authenticated remote user to bypass blocked-host restrictions. By supplying a crafted URL, an attacker can induce the server to make requests to restricted destinations, leading to Server-Side Request Forgery (SSRF).","published_time":"2026-09-30T08:35:59","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"fedora","references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-88779","https://access.redhat.com/security/cve/CVE-2026-102577","https://bugzilla.redhat.com/show_bug.cgi?id=2543604","https://moodle.org/mod/forum/discuss.php?d=482495"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-102578","summary":"A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language) injection vulnerability. This issue could allow an attacker to view, alter, or delete sensitive data stored in the underlying database.","cvss":5.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.5,"cvss_v4":null,"epss":0.00247,"ranking_epss":0.1446,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-89383","https://access.redhat.com/security/cve/CVE-2026-102578","https://bugzilla.redhat.com/show_bug.cgi?id=2543632","https://moodle.org/mod/forum/discuss.php?d=482496"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:14","euvd":{"id":"EUVD-2026-89717","description":"A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language) injection vulnerability. This issue could allow an attacker to view, alter, or delete sensitive data stored in the underlying database.","published_time":"2026-09-30T08:36:01","cvss":5.5,"cvss_version":"3.1","epss":0.0,"assigner":"fedora","references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-89383","https://access.redhat.com/security/cve/CVE-2026-102578","https://bugzilla.redhat.com/show_bug.cgi?id=2543632","https://moodle.org/mod/forum/discuss.php?d=482496"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-102579","summary":"A flaw was found in Moodle. An incorrect capability check in the grade web service allows an authenticated student to access profile information of other students enrolled in the same course that they should not have permission to view. This issue leads to unauthorized information disclosure.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00217,"ranking_epss":0.10985,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-89381","https://access.redhat.com/security/cve/CVE-2026-102579","https://bugzilla.redhat.com/show_bug.cgi?id=2543633","https://moodle.org/mod/forum/discuss.php?d=482497"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:14","euvd":{"id":"EUVD-2026-89718","description":"A flaw was found in Moodle. An incorrect capability check in the grade web service allows an authenticated student to access profile information of other students enrolled in the same course that they should not have permission to view. This issue leads to unauthorized information disclosure.","published_time":"2026-09-30T08:36:04","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"fedora","references":["http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-89381","https://access.redhat.com/security/cve/CVE-2026-102579","https://bugzilla.redhat.com/show_bug.cgi?id=2543633","https://moodle.org/mod/forum/discuss.php?d=482497"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-102454","summary":"EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":8.6,"epss":0.00562,"ranking_epss":0.4463,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.twcert.org.tw/en/cp-139-11241-b7eef-2.html","https://www.twcert.org.tw/tw/cp-132-11240-0fa1b-1.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:13","euvd":{"id":"EUVD-2026-89681","description":"EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.","published_time":"2026-09-30T08:26:06","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"twcert","references":["https://www.twcert.org.tw/tw/cp-132-11240-0fa1b-1.html","https://www.twcert.org.tw/en/cp-139-11241-b7eef-2.html"],"products":["EasyFlow .NET","EasyFlow .NET","EasyFlow .NET"],"vendors":["DigiWin"]}},{"cve_id":"CVE-2026-102455","summary":"EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":9.3,"epss":0.00508,"ranking_epss":0.41152,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.twcert.org.tw/en/cp-139-11242-13f37-2.html","https://www.twcert.org.tw/tw/cp-132-11237-c9189-1.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:13","euvd":{"id":"EUVD-2026-89711","description":"EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.","published_time":"2026-09-30T08:29:29","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"twcert","references":["https://www.twcert.org.tw/tw/cp-132-11237-c9189-1.html","https://www.twcert.org.tw/en/cp-139-11242-13f37-2.html"],"products":["EasyFlow .NET","EasyFlow .NET","EasyFlow .NET"],"vendors":["DigiWin"]}},{"cve_id":"CVE-2026-102456","summary":"EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read database contents.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":7.1,"epss":0.00272,"ranking_epss":0.17727,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.twcert.org.tw/en/cp-139-11242-13f37-2.html","https://www.twcert.org.tw/tw/cp-132-11237-c9189-1.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:13","euvd":{"id":"EUVD-2026-89712","description":"EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read database contents.","published_time":"2026-09-30T08:30:47","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"twcert","references":["https://www.twcert.org.tw/tw/cp-132-11237-c9189-1.html","https://www.twcert.org.tw/en/cp-139-11242-13f37-2.html"],"products":["EasyFlow .NET","EasyFlow .NET","EasyFlow .NET"],"vendors":["DigiWin"]}},{"cve_id":"CVE-2026-102457","summary":"EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability. Authenticated remote attackers can exploit this vulnerability to download arbitrary system files.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":7.1,"epss":0.0038,"ranking_epss":0.29547,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.twcert.org.tw/en/cp-139-11242-13f37-2.html","https://www.twcert.org.tw/tw/cp-132-11237-c9189-1.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:13","euvd":{"id":"EUVD-2026-89713","description":"EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability. Authenticated remote attackers can exploit this vulnerability to download arbitrary system files.","published_time":"2026-09-30T08:32:38","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"twcert","references":["https://www.twcert.org.tw/tw/cp-132-11237-c9189-1.html","https://www.twcert.org.tw/en/cp-139-11242-13f37-2.html"],"products":["EasyFlow .NET","EasyFlow .NET","EasyFlow .NET"],"vendors":["DigiWin"]}},{"cve_id":"CVE-2026-102458","summary":"EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":9.3,"epss":0.00425,"ranking_epss":0.34449,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.twcert.org.tw/en/cp-139-11242-13f37-2.html","https://www.twcert.org.tw/tw/cp-132-11237-c9189-1.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:13","euvd":{"id":"EUVD-2026-89714","description":"EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API.","published_time":"2026-09-30T08:34:09","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"twcert","references":["https://www.twcert.org.tw/tw/cp-132-11237-c9189-1.html","https://www.twcert.org.tw/en/cp-139-11242-13f37-2.html"],"products":["EasyFlow .NET","EasyFlow .NET","EasyFlow .NET"],"vendors":["DigiWin"]}},{"cve_id":"CVE-2026-102459","summary":"EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability. Unauthenticated remote attackers can execute arbitrary JavaScript codes in user's browser through phishing attacks.","cvss":5.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":5.1,"epss":0.00201,"ranking_epss":0.08938,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.twcert.org.tw/en/cp-139-11242-13f37-2.html","https://www.twcert.org.tw/tw/cp-132-11237-c9189-1.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:13","euvd":{"id":"EUVD-2026-89715","description":"EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability. Unauthenticated remote attackers can execute arbitrary JavaScript codes in user's browser through phishing attacks.","published_time":"2026-09-30T08:35:41","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"twcert","references":["https://www.twcert.org.tw/tw/cp-132-11237-c9189-1.html","https://www.twcert.org.tw/en/cp-139-11242-13f37-2.html"],"products":["EasyFlow .NET","EasyFlow .NET","EasyFlow .NET"],"vendors":["DigiWin"]}},{"cve_id":"CVE-2025-14564","summary":"The Viable URL Media Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.","cvss":6.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.4,"cvss_v4":null,"epss":0.0019,"ranking_epss":0.0777,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/viable-url-media-uploader/trunk/includes/class-vumu-svg-support.php#L42","https://www.wordfence.com/threat-intel/vulnerabilities/id/c600d267-0fed-4682-bc71-5bd0d2f70cae?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T09:17:11","euvd":{"id":"EUVD-2025-211018","description":"The Viable URL Media Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.","published_time":"2026-09-30T08:28:04","cvss":6.4,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/c600d267-0fed-4682-bc71-5bd0d2f70cae?source=cve","https://plugins.trac.wordpress.org/browser/viable-url-media-uploader/trunk/includes/class-vumu-svg-support.php#L42"],"products":["Viable URL Media Uploader"],"vendors":["ahsangadit"]}},{"cve_id":"CVE-2026-93464","summary":"Stored Cross-Site Scripting via custom content descriptions vulnerability exists in baserCMS . If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused.","cvss":5.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":5.1,"epss":0.00139,"ranking_epss":0.02712,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://basercms.net/security/JVN_14353754","https://jvn.jp/en/jp/JVN14353754"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T08:16:36","euvd":{"id":"EUVD-2026-89663","description":"Stored Cross-Site Scripting via custom content descriptions vulnerability exists in baserCMS . If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused.","published_time":"2026-09-30T07:34:33","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"jpcert","references":["https://jvn.jp/en/jp/JVN14353754","https://basercms.net/security/JVN_14353754"],"products":["basercms","basercms"],"vendors":["baserCMS User Community"]}},{"cve_id":"CVE-2026-97150","summary":"When converting baserCMS4-style addons to baserCMS5-style ones,\r\nBcAddonMigrator includes \"config.php\" from the addon, which means the PHP code in the file is executed.\r\nArbitrary files on the system may be read or deleted by an administrative user.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":8.6,"epss":0.00336,"ranking_epss":0.24565,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://basercms.net/security/JVN_21754394","https://github.com/baserproject/BcAddonMigrator/commit/e836bc875e26910e1b5862f96cf280b4f064c104","https://jvn.jp/en/jp/JVN21754394"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T08:16:36","euvd":{"id":"EUVD-2026-89656","description":"When converting baserCMS4-style addons to baserCMS5-style ones,\r\nBcAddonMigrator includes \"config.php\" from the addon, which means the PHP code in the file is executed.\r\nArbitrary files on the system may be read or deleted by an administrative user.","published_time":"2026-09-30T07:12:22","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"jpcert","references":["https://jvn.jp/en/jp/JVN21754394","https://basercms.net/security/JVN_21754394","https://github.com/baserproject/BcAddonMigrator/commit/e836bc875e26910e1b5862f96cf280b4f064c104"],"products":["BcAddonMigrator"],"vendors":["baserCMS Users Community"]}},{"cve_id":"CVE-2026-92870","summary":"A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":0.0032,"ranking_epss":0.22647,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://jvn.jp/en/jp/JVN22475874/","https://pgpool.net/news/2026-09-29/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T08:16:35","euvd":{"id":"EUVD-2026-89660","description":"A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination.","published_time":"2026-09-30T07:21:24","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"jpcert","references":["https://pgpool.net/news/2026-09-29/","https://jvn.jp/en/jp/JVN22475874/"],"products":["Pgpool-II","Pgpool-II","Pgpool-II","Pgpool-II","Pgpool-II","Pgpool-II"],"vendors":["PgPool Global Development Group"]}},{"cve_id":"CVE-2026-92871","summary":"A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":0.0029,"ranking_epss":0.19468,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://jvn.jp/en/jp/JVN22475874/","https://pgpool.net/news/2026-09-29/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T08:16:35","euvd":{"id":"EUVD-2026-89675","description":"A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process.","published_time":"2026-09-30T07:47:32","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"jpcert","references":["https://pgpool.net/news/2026-09-29/","https://jvn.jp/en/jp/JVN22475874/"],"products":["Pgpool-II","Pgpool-II","Pgpool-II","Pgpool-II","Pgpool-II","Pgpool-II"],"vendors":["PgPool Global Development Group"]}},{"cve_id":"CVE-2026-92872","summary":"Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information.","cvss":5.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":5.3,"epss":0.00184,"ranking_epss":0.07201,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://jvn.jp/en/jp/JVN22475874/","https://pgpool.net/news/2026-09-29/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T08:16:35","euvd":{"id":"EUVD-2026-89676","description":"Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information.","published_time":"2026-09-30T07:47:50","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"jpcert","references":["https://pgpool.net/news/2026-09-29/","https://jvn.jp/en/jp/JVN22475874/"],"products":["Pgpool-II","Pgpool-II","Pgpool-II","Pgpool-II","Pgpool-II","Pgpool-II"],"vendors":["PgPool Global Development Group"]}},{"cve_id":"CVE-2026-92873","summary":"Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.3,"cvss_v4":6.9,"epss":0.00314,"ranking_epss":0.21962,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://jvn.jp/en/jp/JVN22475874/","https://pgpool.net/news/2026-09-29/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T08:16:35","euvd":{"id":"EUVD-2026-89677","description":"Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node.","published_time":"2026-09-30T07:51:52","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"jpcert","references":["https://pgpool.net/news/2026-09-29/","https://jvn.jp/en/jp/JVN22475874/"],"products":["Pgpool-II","Pgpool-II","Pgpool-II","Pgpool-II","Pgpool-II","Pgpool-II"],"vendors":["PgPool Global Development Group"]}},{"cve_id":"CVE-2026-93460","summary":"Stored Cross-site scripting via appended strings in email form fields vulnerability exists in baserCMS . If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused.","cvss":5.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":5.1,"epss":0.00139,"ranking_epss":0.02712,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://basercms.net/security/JVN_14353754","https://jvn.jp/en/jp/JVN14353754"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T08:16:35","euvd":{"id":"EUVD-2026-89662","description":"Stored Cross-site scripting via appended strings in email form fields vulnerability exists in baserCMS . If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused.","published_time":"2026-09-30T07:34:09","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"jpcert","references":["https://jvn.jp/en/jp/JVN14353754","https://basercms.net/security/JVN_14353754"],"products":["basercms","basercms"],"vendors":["baserCMS User Community"]}},{"cve_id":"CVE-2026-93462","summary":"Missing authentication for critical function vulnerability exists in baserCMS . If a remote unauthenticated attacker there is a possibility that sensitive information could be obtained.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":6.9,"epss":0.00325,"ranking_epss":0.23169,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://basercms.net/security/JVN_14353754","https://jvn.jp/en/jp/JVN14353754"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T08:16:35","euvd":{"id":"EUVD-2026-89673","description":"Missing authentication for critical function vulnerability exists in baserCMS . If a remote unauthenticated attacker there is a possibility that sensitive information could be obtained.","published_time":"2026-09-30T07:42:31","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"jpcert","references":["https://jvn.jp/en/jp/JVN14353754","https://basercms.net/security/JVN_14353754"],"products":["basercms","basercms"],"vendors":["baserCMS User Community"]}},{"cve_id":"CVE-2026-93463","summary":"Cross-Site Scripting via Script Validation Bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused.","cvss":5.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":5.1,"epss":0.00151,"ranking_epss":0.03604,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://basercms.net/security/JVN_14353754","https://jvn.jp/en/jp/JVN14353754"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T08:16:35","euvd":{"id":"EUVD-2026-89661","description":"Cross-Site Scripting via Script Validation Bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser may be caused.","published_time":"2026-09-30T07:33:53","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"jpcert","references":["https://jvn.jp/en/jp/JVN14353754","https://basercms.net/security/JVN_14353754"],"products":["basercms","basercms"],"vendors":["baserCMS User Community"]}},{"cve_id":"CVE-2026-6806","summary":"The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'stm_lat/stm_lng' parameter in all versions up to, and including, 1.4.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00273,"ranking_epss":0.17753,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/changeset/3552483/motors-car-dealership-classified-listings/tags/1.4.110","https://www.wordfence.com/threat-intel/vulnerabilities/id/88b5842d-7b8b-4ea7-b2c3-6ac6fac6d2a6?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T08:16:34","euvd":{"id":"EUVD-2026-89669","description":"The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'stm_lat/stm_lng' parameter in all versions up to, and including, 1.4.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","published_time":"2026-09-30T07:41:06","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/88b5842d-7b8b-4ea7-b2c3-6ac6fac6d2a6?source=cve","https://plugins.trac.wordpress.org/changeset/3552483/motors-car-dealership-classified-listings/tags/1.4.110"],"products":["Motors – Car Dealership & Classified Listings Plugin"],"vendors":["stylemix"]}},{"cve_id":"CVE-2026-88037","summary":"The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `title` attribute of the `bt_bb_service` shortcode in all versions up to, and including, 5.7.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","cvss":6.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.4,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.04112,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/changeset/3526548/bold-page-builder/trunk/content_elements/bt_bb_service/bt_bb_service.php","https://www.wordfence.com/threat-intel/vulnerabilities/id/402f63fb-c0c6-49b9-b5a9-382435313406?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T08:16:34","euvd":{"id":"EUVD-2026-89665","description":"The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `title` attribute of the `bt_bb_service` shortcode in all versions up to, and including, 5.7.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","published_time":"2026-09-30T07:41:04","cvss":6.4,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/402f63fb-c0c6-49b9-b5a9-382435313406?source=cve","https://plugins.trac.wordpress.org/changeset/3526548/bold-page-builder/trunk/content_elements/bt_bb_service/bt_bb_service.php"],"products":["Bold Page Builder"],"vendors":["boldthemes"]}},{"cve_id":"CVE-2026-92867","summary":"An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":8.7,"epss":0.00344,"ranking_epss":0.2551,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://jvn.jp/en/jp/JVN22475874/","https://pgpool.net/news/2026-09-29/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T08:16:34","euvd":{"id":"EUVD-2026-89657","description":"An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution.","published_time":"2026-09-30T07:20:27","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"jpcert","references":["https://pgpool.net/news/2026-09-29/","https://jvn.jp/en/jp/JVN22475874/"],"products":["Pgpool-II","Pgpool-II","Pgpool-II","Pgpool-II","Pgpool-II","Pgpool-II"],"vendors":["PgPool Global Development Group"]}},{"cve_id":"CVE-2026-92868","summary":"An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":6.9,"epss":0.00151,"ranking_epss":0.03653,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://jvn.jp/en/jp/JVN22475874/","https://pgpool.net/news/2026-09-29/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T08:16:34","euvd":{"id":"EUVD-2026-89658","description":"An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication.","published_time":"2026-09-30T07:20:48","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"jpcert","references":["https://pgpool.net/news/2026-09-29/","https://jvn.jp/en/jp/JVN22475874/"],"products":["Pgpool-II","Pgpool-II","Pgpool-II","Pgpool-II","Pgpool-II","Pgpool-II"],"vendors":["PgPool Global Development Group"]}},{"cve_id":"CVE-2026-92869","summary":"An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":7.1,"epss":0.0025,"ranking_epss":0.14759,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://jvn.jp/en/jp/JVN22475874/","https://pgpool.net/news/2026-09-29/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T08:16:34","euvd":{"id":"EUVD-2026-89659","description":"An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination.","published_time":"2026-09-30T07:21:09","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"jpcert","references":["https://pgpool.net/news/2026-09-29/","https://jvn.jp/en/jp/JVN22475874/"],"products":["Pgpool-II","Pgpool-II","Pgpool-II","Pgpool-II","Pgpool-II","Pgpool-II"],"vendors":["PgPool Global Development Group"]}},{"cve_id":"CVE-2026-6170","summary":"The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'images' parameter of the plugin's bt_bb_css_image_grid shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","cvss":6.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.4,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.04113,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/changeset/3526548/bold-page-builder/trunk/content_elements/bt_bb_css_image_grid/bt_bb_css_image_grid.php","https://www.wordfence.com/threat-intel/vulnerabilities/id/9b359cdd-840f-4a9b-9a2f-a28e64d73819?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T08:16:33","euvd":{"id":"EUVD-2026-89670","description":"The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'images' parameter of the plugin's bt_bb_css_image_grid shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","published_time":"2026-09-30T07:41:06","cvss":6.4,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/9b359cdd-840f-4a9b-9a2f-a28e64d73819?source=cve","https://plugins.trac.wordpress.org/changeset/3526548/bold-page-builder/trunk/content_elements/bt_bb_css_image_grid/bt_bb_css_image_grid.php"],"products":["Bold Page Builder"],"vendors":["boldthemes"]}},{"cve_id":"CVE-2026-6171","summary":"The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' parameter of the plugin's bt_bb_icon shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","cvss":6.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.4,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.04113,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/changeset/3526548/bold-page-builder/trunk/content_elements/bt_bb_icon/bt_bb_icon.php","https://www.wordfence.com/threat-intel/vulnerabilities/id/74315031-8498-4ae5-bcfc-ba22af4b58dc?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T08:16:33","euvd":{"id":"EUVD-2026-89668","description":"The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' parameter of the plugin's bt_bb_icon shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","published_time":"2026-09-30T07:41:06","cvss":6.4,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/74315031-8498-4ae5-bcfc-ba22af4b58dc?source=cve","https://plugins.trac.wordpress.org/changeset/3526548/bold-page-builder/trunk/content_elements/bt_bb_icon/bt_bb_icon.php"],"products":["Bold Page Builder"],"vendors":["boldthemes"]}},{"cve_id":"CVE-2026-6172","summary":"The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' parameter of the plugin's bt_bb_image shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","cvss":6.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.4,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.04112,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/changeset/3526548/bold-page-builder/trunk/content_elements/bt_bb_image/bt_bb_image.php","https://www.wordfence.com/threat-intel/vulnerabilities/id/3d36cad2-53ff-4515-94e3-25bc9f518070?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T08:16:33","euvd":{"id":"EUVD-2026-89664","description":"The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' parameter of the plugin's bt_bb_image shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","published_time":"2026-09-30T07:41:04","cvss":6.4,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/3d36cad2-53ff-4515-94e3-25bc9f518070?source=cve","https://plugins.trac.wordpress.org/changeset/3526548/bold-page-builder/trunk/content_elements/bt_bb_image/bt_bb_image.php"],"products":["Bold Page Builder"],"vendors":["boldthemes"]}},{"cve_id":"CVE-2026-6173","summary":"The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background_image' parameter of the plugin's bt_bb_section shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","cvss":6.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.4,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.04114,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/changeset/3526548/bold-page-builder/trunk/content_elements/bt_bb_section/bt_bb_section.php","https://www.wordfence.com/threat-intel/vulnerabilities/id/bbadef9e-1e2d-4bd2-800a-f9369b795728?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T08:16:33","euvd":{"id":"EUVD-2026-89672","description":"The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background_image' parameter of the plugin's bt_bb_section shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","published_time":"2026-09-30T07:41:07","cvss":6.4,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/bbadef9e-1e2d-4bd2-800a-f9369b795728?source=cve","https://plugins.trac.wordpress.org/changeset/3526548/bold-page-builder/trunk/content_elements/bt_bb_section/bt_bb_section.php"],"products":["Bold Page Builder"],"vendors":["boldthemes"]}},{"cve_id":"CVE-2026-11895","summary":"The HT Mega Addons for Elementor – Elementor Widgets & Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Data Table 'display_options' Setting in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","cvss":6.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.4,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.04114,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/changeset/3583980/","https://www.wordfence.com/threat-intel/vulnerabilities/id/4abba5ab-523c-4b4f-8d3e-bb7ee57cd280?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T08:16:32","euvd":{"id":"EUVD-2026-89666","description":"The HT Mega Addons for Elementor – Elementor Widgets & Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Data Table 'display_options' Setting in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","published_time":"2026-09-30T07:41:05","cvss":6.4,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/4abba5ab-523c-4b4f-8d3e-bb7ee57cd280?source=cve","https://plugins.trac.wordpress.org/changeset/3583980/"],"products":["HT Mega Addons for Elementor – Elementor Widgets & Template Builder"],"vendors":["devitemsllc"]}},{"cve_id":"CVE-2026-14876","summary":"The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-href' parameter in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","cvss":6.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.4,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.04113,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/changeset/3654530/smart-slider-3","https://www.wordfence.com/threat-intel/vulnerabilities/id/5d882db3-b92e-4b3b-a07e-fa30fed85364?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T08:16:32","euvd":{"id":"EUVD-2026-89667","description":"The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-href' parameter in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","published_time":"2026-09-30T07:41:05","cvss":6.4,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/5d882db3-b92e-4b3b-a07e-fa30fed85364?source=cve","https://plugins.trac.wordpress.org/changeset/3654530/smart-slider-3"],"products":["Smart Slider 3"],"vendors":["nextendweb"]}},{"cve_id":"CVE-2026-16596","summary":"The WP Directory Kit plugin for WordPress is vulnerable to generic SQL Injection via the 'data_fields_list' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00224,"ranking_epss":0.1174,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/changeset/3626960","https://www.wordfence.com/threat-intel/vulnerabilities/id/b7b0d55b-00c5-44ee-99a3-9d4d2b400f71?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T08:16:32","euvd":{"id":"EUVD-2026-89671","description":"The WP Directory Kit plugin for WordPress is vulnerable to generic SQL Injection via the 'data_fields_list' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","published_time":"2026-09-30T07:41:07","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/b7b0d55b-00c5-44ee-99a3-9d4d2b400f71?source=cve","https://plugins.trac.wordpress.org/changeset/3626960"],"products":["WP Directory Kit"],"vendors":["WpDirectoryKit"]}},{"cve_id":"CVE-2026-102508","summary":"Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to read, forge or modify secure-channel traffic, including user credential ssent by the client.\n\nThe defect manifests differently depending on the version:\n- In 0.9.0 through 0.11.0 a failed message-signature check is only logged and never enforced, and there is no mechanism to verify the server certificate: it is taken from the unauthenticated GetEndpoints discovery response and used to encrypt the user's password.\n- In 0.12.0 through 0.13.1 the signature check is inverted (valid signatures are rejected, invalid ones accepted), and server certificates are accepted without a trust anchor by default.\n- In all affected versions the default security policy is None. Starting with 0.12.0 the driver additionally continues silently at a weaker security policy than the one configured, and starting with 0.13.0 endpoint selection prefers the weakest matching endpoint.\n\nUsers checking only for one of these mechanisms may wrongly conclude they are unaffected.\n\nThis issue affects Apache PLC4X: from 0.9.0 before 1.0.0.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 verifies message signatures correctly, refuses to connect unless the server certificate can be verified against a configured trust store or pinned certificate, defaults to Basic256Sha256 with SignAndEncrypt, and fails the\nconnection if the negotiated security policy is weaker than the configured one.","cvss":9.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.2,"epss":0.00124,"ranking_epss":0.01827,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://lists.apache.org/thread.html/o076mcnsx6wnqpdy780m7s6hddbbnjfw","http://www.openwall.com/lists/oss-security/2026/09/30/4"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T08:16:31","euvd":{"id":"EUVD-2026-89674","description":"Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to read, forge or modify secure-channel traffic, including user credential ssent by the client.\n\nThe defect manifests differently depending on the version:\n- In 0.9.0 through 0.11.0 a failed message-signature check is only logged and never enforced, and there is no mechanism to verify the server certificate: it is taken from the unauthenticated GetEndpoints discovery response and used to encrypt the user's password.\n- In 0.12.0 through 0.13.1 the signature check is inverted (valid signatures are rejected, invalid ones accepted), and server certificates are accepted without a trust anchor by default.\n- In all affected versions the default security policy is None. Starting with 0.12.0 the driver additionally continues silently at a weaker security policy than the one configured, and starting with 0.13.0 endpoint selection prefers the weakest matching endpoint.\n\nUsers checking only for one of these mechanisms may wrongly conclude they are unaffected.\n\nThis issue affects Apache PLC4X: from 0.9.0 before 1.0.0.\n\nUsers are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 verifies message signatures correctly, refuses to connect unless the server certificate can be verified against a configured trust store or pinned certificate, defaults to Basic256Sha256 with SignAndEncrypt, and fails the\nconnection if the negotiated security policy is weaker than the configured one.","published_time":"2026-09-30T07:42:43","cvss":9.2,"cvss_version":"4.0","epss":0.0,"assigner":"apache","references":["https://lists.apache.org/thread.html/o076mcnsx6wnqpdy780m7s6hddbbnjfw"],"products":["Apache PLC4X"],"vendors":["Apache Software Foundation"]}},{"cve_id":"CVE-2026-97196","summary":"Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass.\n\nThis issue affects GiveWP: from n/a through 4.16.9.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00296,"ranking_epss":0.20138,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://patchstack.com/database/wordpress/plugin/give/vulnerability/wordpress-givewp-plugin-4-16-9-broken-authentication-vulnerability?_s_id=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T07:16:31","euvd":{"id":"EUVD-2026-89655","description":"Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass.\n\nThis issue affects GiveWP: from n/a through 4.16.9.","published_time":"2026-09-30T06:55:06","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"Patchstack","references":["https://patchstack.com/database/wordpress/plugin/give/vulnerability/wordpress-givewp-plugin-4-16-9-broken-authentication-vulnerability?_s_id=cve"],"products":["GiveWP"],"vendors":["Liquid Web / StellarWP"]}},{"cve_id":"CVE-2026-89294","summary":"The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the 'ssa_locale' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. Notably, exploitation does not require authentication in practice, as the locale filter is installed unconditionally on every request during plugins_loaded and the callback performs no nonce or capability check before returning the raw GET parameter value.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00646,"ranking_epss":0.49032,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.27/includes/class-translation.php#L108","https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.27/includes/class-translation.php#L50","https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.27/includes/class-translation.php#L67","https://www.wordfence.com/threat-intel/vulnerabilities/id/aab8f2ae-993b-4893-81cc-1b8a1a4ef84b?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T07:16:30","euvd":{"id":"EUVD-2026-89654","description":"The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the 'ssa_locale' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. Notably, exploitation does not require authentication in practice, as the locale filter is installed unconditionally on every request during plugins_loaded and the callback performs no nonce or capability check before returning the raw GET parameter value.","published_time":"2026-09-30T06:40:23","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/aab8f2ae-993b-4893-81cc-1b8a1a4ef84b?source=cve","https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.27/includes/class-translation.php#L108","https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.27/includes/class-translation.php#L67","https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/tags/1.6.12.27/includes/class-translation.php#L50"],"products":["Simply Schedule Appointments"],"vendors":["croixhaug"]}},{"cve_id":"CVE-2026-97316","summary":"The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attackers to bypass its internal-address filter and make the server send requests to internal services.","cvss":5.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.8,"cvss_v4":null,"epss":0.00145,"ranking_epss":0.03141,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/d9497ddd-c39c-4928-8660-f1c94ef2c3a0/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:11","euvd":{"id":"EUVD-2026-89627","description":"The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attackers to bypass its internal-address filter and make the server send requests to internal services.","published_time":"2026-09-30T06:00:26","cvss":5.8,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/d9497ddd-c39c-4928-8660-f1c94ef2c3a0/"],"products":["Broken Link Notifier"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-93580","summary":"The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity of incoming shipment webhook requests, relying only on a non-secret identifier and an IP check that is not enforced, allowing unauthenticated attackers who know a target order's parcel tracking number to forge its shipment status and prematurely mark the order completed.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":0.00184,"ranking_epss":0.07133,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/083dab74-cffe-4532-8fc3-939a015c83d4/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:10","euvd":{"id":"EUVD-2026-89623","description":"The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity of incoming shipment webhook requests, relying only on a non-secret identifier and an IP check that is not enforced, allowing unauthenticated attackers who know a target order's parcel tracking number to forge its shipment status and prematurely mark the order completed.","published_time":"2026-09-30T06:00:25","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/083dab74-cffe-4532-8fc3-939a015c83d4/"],"products":["InPost PL"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-94274","summary":"The YayReviews  WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, allowing unauthenticated attackers to harvest reviewers' email addresses and other non-public review content.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":0.00145,"ranking_epss":0.03215,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/23965307-678d-4f59-beae-5a8b33af9a75/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:10","euvd":{"id":"EUVD-2026-89624","description":"The YayReviews  WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, allowing unauthenticated attackers to harvest reviewers' email addresses and other non-public review content.","published_time":"2026-09-30T06:00:25","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/23965307-678d-4f59-beae-5a8b33af9a75/"],"products":["YayReviews"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-94297","summary":"The Media Library Organizer  WordPress plugin before 2.1.4 does not verify that the requesting user holds the target taxonomy's management capability before creating a new term, allowing users with contributor-level access and above to create publicly visible terms in any taxonomy registered on the site.","cvss":2.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":2.7,"cvss_v4":null,"epss":0.00132,"ranking_epss":0.02315,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/c9cecfb4-d554-4d64-8d87-9678363d8b8d/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:10","euvd":{"id":"EUVD-2026-89625","description":"The Media Library Organizer  WordPress plugin before 2.1.4 does not verify that the requesting user holds the target taxonomy's management capability before creating a new term, allowing users with contributor-level access and above to create publicly visible terms in any taxonomy registered on the site.","published_time":"2026-09-30T06:00:25","cvss":2.7,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/c9cecfb4-d554-4d64-8d87-9678363d8b8d/"],"products":["Media Library Organizer"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-96886","summary":"The Course Booking System WordPress plugin before 7.0.9 does not restrict access to its booking export, allowing unauthenticated users to download the name, email address and billing address of every customer who has booked a course.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":0.00145,"ranking_epss":0.03215,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/bdf459bb-7835-43d3-8ef8-83b3b099677a/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:10","euvd":{"id":"EUVD-2026-89626","description":"The Course Booking System WordPress plugin before 7.0.9 does not restrict access to its booking export, allowing unauthenticated users to download the name, email address and billing address of every customer who has booked a course.","published_time":"2026-09-30T06:00:26","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/bdf459bb-7835-43d3-8ef8-83b3b099677a/"],"products":["Course Booking System"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-91051","summary":"The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent authenticated users with author-level permissions from storing a serialized value in a post meta field that is deserialized when the post is rendered, allowing them to perform PHP Object Injection, which can lead to remote code execution when a suitable gadget chain is present via another installed EWWW Image Optimizer WordPress plugin before 8.8.0 or .","cvss":6.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.6,"cvss_v4":null,"epss":0.00358,"ranking_epss":0.27189,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/e24a9497-8fb4-4067-8421-194725455d55/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:09","euvd":{"id":"EUVD-2026-89618","description":"The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent authenticated users with author-level permissions from storing a serialized value in a post meta field that is deserialized when the post is rendered, allowing them to perform PHP Object Injection, which can lead to remote code execution when a suitable gadget chain is present via another installed EWWW Image Optimizer WordPress plugin before 8.8.0 or .","published_time":"2026-09-30T06:00:24","cvss":6.6,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/e24a9497-8fb4-4067-8421-194725455d55/"],"products":["EWWW Image Optimizer"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-91072","summary":"The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file migration routine to the current site's own uploads directory, letting an attacker with Administrator-level access rename or delete existing WebP-derivative image files outside that scope, including, on a multisite network, files belonging to a different site they have no access to.","cvss":4.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.4,"cvss_v4":null,"epss":0.00139,"ranking_epss":0.02737,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/c77770c5-d1af-47f6-9aee-a50d4a919732/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:09","euvd":{"id":"EUVD-2026-89619","description":"The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file migration routine to the current site's own uploads directory, letting an attacker with Administrator-level access rename or delete existing WebP-derivative image files outside that scope, including, on a multisite network, files belonging to a different site they have no access to.","published_time":"2026-09-30T06:00:24","cvss":4.4,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/c77770c5-d1af-47f6-9aee-a50d4a919732/"],"products":["EWWW Image Optimizer"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-91832","summary":"The WP Mobile Menu  WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu  WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every visitor, resulting in Stored Cross-Site Scripting.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":0.00106,"ranking_epss":0.01018,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/9f1448d5-6dc9-47dd-8675-2fbf5f36393b/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:09","euvd":{"id":"EUVD-2026-89620","description":"The WP Mobile Menu  WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu  WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every visitor, resulting in Stored Cross-Site Scripting.","published_time":"2026-09-30T06:00:24","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/9f1448d5-6dc9-47dd-8675-2fbf5f36393b/"],"products":["WP Mobile Menu"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-92424","summary":"The Content Egg  WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary web scripts unfiltered under a privileged user's account, executing in the context of anyone who later views that content.","cvss":6.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.8,"cvss_v4":null,"epss":0.00152,"ranking_epss":0.03719,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/917b8042-b38c-4b6a-9237-1dd08ada157d/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:09","euvd":{"id":"EUVD-2026-89621","description":"The Content Egg  WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary web scripts unfiltered under a privileged user's account, executing in the context of anyone who later views that content.","published_time":"2026-09-30T06:00:25","cvss":6.8,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/917b8042-b38c-4b6a-9237-1dd08ada157d/"],"products":["Content Egg"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-92994","summary":"The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00172,"ranking_epss":0.05967,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/48356bf5-634f-4008-8904-10ab35007e21/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:09","euvd":{"id":"EUVD-2026-89622","description":"The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them back with an attacker-controlled content type, allowing unauthenticated attackers to store a file containing malicious JavaScript that executes in the browser of any user who opens it.","published_time":"2026-09-30T06:00:25","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/48356bf5-634f-4008-8904-10ab35007e21/"],"products":["Verge3D Publishing and E-Commerce"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-89190","summary":"The Robin Image Optimizer  WordPress plugin before 2.0.8 does not check the user's capabilities before dispatching one of its bundled admin framework's request handlers, allowing users with a subscriber-level account to render admin-only Robin Image Optimizer  WordPress plugin before 2.0.8 pages and disclose the Robin Image Optimizer  WordPress plugin before 2.0.8's stored settings.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00132,"ranking_epss":0.02316,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/570e6bfb-cfe9-4a6f-8759-c6e99e19e272/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:08","euvd":{"id":"EUVD-2026-89615","description":"The Robin Image Optimizer  WordPress plugin before 2.0.8 does not check the user's capabilities before dispatching one of its bundled admin framework's request handlers, allowing users with a subscriber-level account to render admin-only Robin Image Optimizer  WordPress plugin before 2.0.8 pages and disclose the Robin Image Optimizer  WordPress plugin before 2.0.8's stored settings.","published_time":"2026-09-30T06:00:23","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/570e6bfb-cfe9-4a6f-8759-c6e99e19e272/"],"products":["Robin image optimizer"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-89193","summary":"The Robin Image Optimizer  WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00172,"ranking_epss":0.05968,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/3c90d1c5-fd45-4a82-9357-504d7a0e5adc/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:08","euvd":{"id":"EUVD-2026-89616","description":"The Robin Image Optimizer  WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators.","published_time":"2026-09-30T06:00:23","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/3c90d1c5-fd45-4a82-9357-504d7a0e5adc/"],"products":["Robin image optimizer"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-90953","summary":"The Image Optimizer  WordPress plugin before 1.7.7 does not enforce its intended capability check on several of its read REST routes, allowing any authenticated user to read attachment metadata and site-wide statistics that should be restricted to administrators.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00139,"ranking_epss":0.02737,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/38412622-513f-41ea-9968-192f357d360e/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:08","euvd":{"id":"EUVD-2026-89617","description":"The Image Optimizer  WordPress plugin before 1.7.7 does not enforce its intended capability check on several of its read REST routes, allowing any authenticated user to read attachment metadata and site-wide statistics that should be restricted to administrators.","published_time":"2026-09-30T06:00:23","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/38412622-513f-41ea-9968-192f357d360e/"],"products":["Image Optimizer"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-86789","summary":"The Connections Business Directory WordPress plugin through 10.4.67 does not apply its visibility and moderation-status restrictions on certain REST API read endpoints, allowing unauthenticated attackers to retrieve directory entries that are marked private or unlisted, or that are still pending moderation, including entry names, organizations, biographies, internal notes and street addresses.\nThe Connections Business Directory WordPress plugin through 10.4.67 has been closed on WordPress.org and no fixed version is available, so site owners should remove it or restrict unauthenticated access to its REST API routes.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":0.00145,"ranking_epss":0.03215,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/3514e2f9-4dda-45ae-80c0-c7caafcb7d8a/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:07","euvd":{"id":"EUVD-2026-89629","description":"The Connections Business Directory WordPress plugin through 10.4.67 does not apply its visibility and moderation-status restrictions on certain REST API read endpoints, allowing unauthenticated attackers to retrieve directory entries that are marked private or unlisted, or that are still pending moderation, including entry names, organizations, biographies, internal notes and street addresses.\nThe Connections Business Directory WordPress plugin through 10.4.67 has been closed on WordPress.org and no fixed version is available, so site owners should remove it or restrict unauthenticated access to its REST API routes.","published_time":"2026-09-30T06:00:22","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/3514e2f9-4dda-45ae-80c0-c7caafcb7d8a/"],"products":["Connections Business Directory"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-87777","summary":"The Hostinger Reach  WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with contributor-level access and above to inject arbitrary web scripts that will execute in the session of a higher-privileged user who opens the affected content in the editor.","cvss":6.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.8,"cvss_v4":null,"epss":0.00152,"ranking_epss":0.03718,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/4a1f5c2b-a6e5-4e6f-afa3-79726d0eb1e3/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:07","euvd":{"id":"EUVD-2026-89628","description":"The Hostinger Reach  WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with contributor-level access and above to inject arbitrary web scripts that will execute in the session of a higher-privileged user who opens the affected content in the editor.","published_time":"2026-09-30T06:00:22","cvss":6.8,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/4a1f5c2b-a6e5-4e6f-afa3-79726d0eb1e3/"],"products":["Hostinger Reach"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-88791","summary":"The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path.","cvss":3.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.4,"cvss_v4":null,"epss":0.00148,"ranking_epss":0.03421,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/a8aa5685-e36e-4e1f-a259-fab3910ee550/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:07","euvd":{"id":"EUVD-2026-89613","description":"The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path.","published_time":"2026-09-30T06:00:22","cvss":3.4,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/a8aa5685-e36e-4e1f-a259-fab3910ee550/"],"products":["Safe Redirect Manager"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-88797","summary":"The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it to every logged-in user, allowing any authenticated user, such as a subscriber, to install and activate any  hosted on the WordPress.org repository.","cvss":7.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":null,"epss":0.00132,"ranking_epss":0.02316,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/250a7d7c-9c9b-4619-a6f4-533d29a30e23/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:07","euvd":{"id":"EUVD-2026-89614","description":"The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it to every logged-in user, allowing any authenticated user, such as a subscriber, to install and activate any  hosted on the WordPress.org repository.","published_time":"2026-09-30T06:00:23","cvss":7.1,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/250a7d7c-9c9b-4619-a6f4-533d29a30e23/"],"products":["Vayu X"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-85415","summary":"The Audio Player Block  WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in the session of any user who later triggers the link (such as an administrator or editor reviewing the post).","cvss":6.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.8,"cvss_v4":null,"epss":0.00152,"ranking_epss":0.03719,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/3ca9c087-311b-4c55-8871-fba318f654b3/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:06","euvd":{"id":"EUVD-2026-89632","description":"The Audio Player Block  WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in the session of any user who later triggers the link (such as an administrator or editor reviewing the post).","published_time":"2026-09-30T06:00:21","cvss":6.8,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/3ca9c087-311b-4c55-8871-fba318f654b3/"],"products":["Audio Player Block"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-85573","summary":"The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim opens them.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00172,"ranking_epss":0.05968,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/0f7f1f25-02e2-49b5-9690-31857e9e6bda/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:06","euvd":{"id":"EUVD-2026-89631","description":"The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim opens them.","published_time":"2026-09-30T06:00:22","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/0f7f1f25-02e2-49b5-9690-31857e9e6bda/"],"products":["All in One Files Upload"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-85576","summary":"The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, when saving its settings, allowing any authenticated user, such as a subscriber, to change them.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00132,"ranking_epss":0.02315,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/5c4546f4-fa6f-47a5-9d2b-9493d34dc13d/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:06","euvd":{"id":"EUVD-2026-89630","description":"The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, when saving its settings, allowing any authenticated user, such as a subscriber, to change them.","published_time":"2026-09-30T06:00:22","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/5c4546f4-fa6f-47a5-9d2b-9493d34dc13d/"],"products":["All in One Files Upload"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-80333","summary":"The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read the rendered content of non-published posts and pages of any type that WordPress would otherwise not serve.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":0.00149,"ranking_epss":0.03514,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/2baffcd4-686e-40db-96b3-5abc70a03a5f/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:05","euvd":{"id":"EUVD-2026-89636","description":"The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read the rendered content of non-published posts and pages of any type that WordPress would otherwise not serve.","published_time":"2026-09-30T06:00:21","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/2baffcd4-686e-40db-96b3-5abc70a03a5f/"],"products":["Solace Extra"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-82127","summary":"The Schema & Structured Data for WP & AMP WordPress plugin before 1.67 does not perform a capability check when saving several of its fields, nor escape them when outputting them back, allowing users with the editor role and above to inject arbitrary web scripts that execute when a higher privileged user views the affected screen. This is only exploitable on multisite installs, where editors do not hold the unfiltered_html capability.","cvss":3.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.5,"cvss_v4":null,"epss":0.00152,"ranking_epss":0.03718,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/fa992935-6764-407e-a95f-31c55c33bf38/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:05","euvd":{"id":"EUVD-2026-89635","description":"The Schema & Structured Data for WP & AMP WordPress plugin before 1.67 does not perform a capability check when saving several of its fields, nor escape them when outputting them back, allowing users with the editor role and above to inject arbitrary web scripts that execute when a higher privileged user views the affected screen. This is only exploitable on multisite installs, where editors do not hold the unfiltered_html capability.","published_time":"2026-09-30T06:00:21","cvss":3.5,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/fa992935-6764-407e-a95f-31c55c33bf38/"],"products":["Schema & Structured Data for WP & AMP"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-83560","summary":"The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":0.00175,"ranking_epss":0.0626,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/dc48141c-c7d3-485e-9470-88f5e24a701f/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:05","euvd":{"id":"EUVD-2026-89634","description":"The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users.","published_time":"2026-09-30T06:00:21","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/dc48141c-c7d3-485e-9470-88f5e24a701f/"],"products":["New User Approve"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-85001","summary":"The EmbedPress  WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which could allow users with the Contributor role or above to inject arbitrary web scripts that execute when the affected content is viewed.","cvss":6.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.8,"cvss_v4":null,"epss":0.00152,"ranking_epss":0.03719,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/889be882-342b-4331-89c5-9eebe90d3704/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:05","euvd":{"id":"EUVD-2026-89633","description":"The EmbedPress  WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which could allow users with the Contributor role or above to inject arbitrary web scripts that execute when the affected content is viewed.","published_time":"2026-09-30T06:00:21","cvss":6.8,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/889be882-342b-4331-89c5-9eebe90d3704/"],"products":["EmbedPress"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-75824","summary":"The User Frontend  WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create accounts on sites where registration is disabled.\n\nThe created account receives the site's default role.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":0.00146,"ranking_epss":0.03269,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/61b04ece-5050-465e-aa11-de2ff79c6e8c/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:04","euvd":{"id":"EUVD-2026-89638","description":"The User Frontend  WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create accounts on sites where registration is disabled.\n\nThe created account receives the site's default role.","published_time":"2026-09-30T06:00:20","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/61b04ece-5050-465e-aa11-de2ff79c6e8c/"],"products":["User Frontend"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-75873","summary":"The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font upload actions, which is available to unauthenticated users, allowing them to upload arbitrary files, including PHP ones, and achieve remote code execution.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":0.00218,"ranking_epss":0.11011,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/15b8a6cb-f89c-4d4d-9812-441e822c647f/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:04","euvd":{"id":"EUVD-2026-89637","description":"The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font upload actions, which is available to unauthenticated users, allowing them to upload arbitrary files, including PHP ones, and achieve remote code execution.","published_time":"2026-09-30T06:00:20","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/15b8a6cb-f89c-4d4d-9812-441e822c647f/"],"products":["Zella Theme"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-75823","summary":"The User Frontend  WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor.\n\nThis affects installations running a PHP build where the sodium extension is unavailable, and where a registration page has been configured. The administrator role cannot be obtained this way.","cvss":7.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.4,"cvss_v4":null,"epss":0.00146,"ranking_epss":0.03269,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/4a385690-3471-4604-aa2a-e120bb31ca53/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:17:03","euvd":{"id":"EUVD-2026-89639","description":"The User Frontend  WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor.\n\nThis affects installations running a PHP build where the sodium extension is unavailable, and where a registration page has been configured. The administrator role cannot be obtained this way.","published_time":"2026-09-30T06:00:20","cvss":7.4,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/4a385690-3471-4604-aa2a-e120bb31ca53/"],"products":["User Frontend"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-100143","summary":"The FluentCart A New Era of eCommerce  WordPress plugin before 1.6.5 does not verify that the person placing a guest checkout controls the email address supplied, allowing unauthenticated attackers who know an existing guest customer's email to obtain a logged-in account bearing that address together with the customer's stored record.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00146,"ranking_epss":0.03269,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://wpscan.com/vulnerability/86c69e28-bdd2-4027-a045-f8b2523f8d7f/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T06:16:58","euvd":{"id":"EUVD-2026-89640","description":"The FluentCart A New Era of eCommerce  WordPress plugin before 1.6.5 does not verify that the person placing a guest checkout controls the email address supplied, allowing unauthenticated attackers who know an existing guest customer's email to obtain a logged-in account bearing that address together with the customer's stored record.","published_time":"2026-09-30T06:00:19","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"WPScan","references":["https://wpscan.com/vulnerability/86c69e28-bdd2-4027-a045-f8b2523f8d7f/"],"products":["FluentCart A New Era of eCommerce"],"vendors":["Unknown"]}},{"cve_id":"CVE-2026-103111","summary":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.","cvss":7.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.6,"cvss_v4":null,"epss":0.00206,"ranking_epss":0.09583,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T05:16:45","euvd":{"id":"EUVD-2026-89608","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.","published_time":"2026-09-30T04:13:59","cvss":7.6,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m"],"products":["pcre2"],"vendors":["PCRE"]}},{"cve_id":"CVE-2026-102913","summary":"A security flaw has been discovered in SourceCodester Car Driving School Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_enrollment. The manipulation results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.","cvss":5.5,"cvss_version":4.0,"cvss_v2":7.5,"cvss_v3":7.3,"cvss_v4":5.5,"epss":0.00269,"ranking_epss":0.17175,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/zhongzhicong1998/CVE/issues/2","https://vuldb.com/cve/CVE-2026-102913","https://vuldb.com/submit/954038","https://vuldb.com/vuln/411637","https://vuldb.com/vuln/411637/cti","https://www.sourcecodester.com/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T05:16:44","euvd":{"id":"EUVD-2026-89609","description":"A security flaw has been discovered in SourceCodester Car Driving School Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_enrollment. The manipulation results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.","published_time":"2026-09-30T04:15:08","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411637","https://vuldb.com/vuln/411637/cti","https://vuldb.com/cve/CVE-2026-102913","https://vuldb.com/submit/954038","https://github.com/zhongzhicong1998/CVE/issues/2","https://www.sourcecodester.com/"],"products":["Car Driving School Management System"],"vendors":["SourceCodester"]}},{"cve_id":"CVE-2026-86134","summary":"A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to crash the management daemon by sending a specially request to the login interface, resulting in a denial of service.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00422,"ranking_epss":0.34197,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://psirt.watchguard.com/CVE-2026-86134"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T04:18:33","euvd":{"id":"EUVD-2026-89605","description":"A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to crash the management daemon by sending a specially request to the login interface, resulting in a denial of service.","published_time":"2026-09-30T03:37:57","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"WatchGuard","references":["https://psirt.watchguard.com/CVE-2026-86134"],"products":["Fireware OS","Fireware OS","Fireware OS","Fireware OS"],"vendors":["WatchGuard"]}},{"cve_id":"CVE-2026-103110","summary":"Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":0.00608,"ranking_epss":0.47117,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.pexip.com/admin/security_bulletins.htm"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T04:18:29","euvd":{"id":"EUVD-2026-89587","description":"Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.","published_time":"2026-09-30T03:03:07","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://docs.pexip.com/admin/security_bulletins.htm"],"products":["Infinity","Infinity","Infinity","Infinity"],"vendors":["Pexip"]}},{"cve_id":"CVE-2026-102911","summary":"A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. Upgrading to version 0.11.8 is able to address this issue. This patch is called 360867034e79175b45c8e04a98e4ca712bbaca35. Upgrading the affected component is advised.","cvss":8.6,"cvss_version":4.0,"cvss_v2":9.0,"cvss_v3":9.9,"cvss_v4":8.6,"epss":0.01779,"ranking_epss":0.77405,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/zosmaai/pi-llm-wiki/","https://github.com/zosmaai/pi-llm-wiki/commit/360867034e79175b45c8e04a98e4ca712bbaca35","https://github.com/zosmaai/pi-llm-wiki/issues/185","https://github.com/zosmaai/pi-llm-wiki/pull/186","https://github.com/zosmaai/pi-llm-wiki/releases/tag/v0.11.8","https://vuldb.com/cve/CVE-2026-102911","https://vuldb.com/submit/953898","https://vuldb.com/vuln/411587","https://vuldb.com/vuln/411587/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T04:18:28","euvd":{"id":"EUVD-2026-89606","description":"A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. Upgrading to version 0.11.8 is able to address this issue. This patch is called 360867034e79175b45c8e04a98e4ca712bbaca35. Upgrading the affected component is advised.","published_time":"2026-09-30T03:45:11","cvss":9.4,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411587","https://vuldb.com/vuln/411587/cti","https://vuldb.com/cve/CVE-2026-102911","https://vuldb.com/submit/953898","https://github.com/zosmaai/pi-llm-wiki/issues/185","https://github.com/zosmaai/pi-llm-wiki/pull/186","https://github.com/zosmaai/pi-llm-wiki/commit/360867034e79175b45c8e04a98e4ca712bbaca35","https://github.com/zosmaai/pi-llm-wiki/releases/tag/v0.11.8","https://github.com/zosmaai/pi-llm-wiki/"],"products":["pi-llm-wiki","pi-llm-wiki","pi-llm-wiki","pi-llm-wiki","pi-llm-wiki","pi-llm-wiki","pi-llm-wiki","pi-llm-wiki"],"vendors":["zosmaai"]}},{"cve_id":"CVE-2026-102912","summary":"A vulnerability was identified in SourceCodester Online Leave Management System 1.0. This issue affects some unknown processing of the file /admin/?page=reports. The manipulation of the argument date_start/date_end leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.","cvss":2.0,"cvss_version":4.0,"cvss_v2":5.8,"cvss_v3":4.7,"cvss_v4":2.0,"epss":0.00214,"ranking_epss":0.10603,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/zhongzhicong1998/CVE/issues/1","https://vuldb.com/cve/CVE-2026-102912","https://vuldb.com/submit/954023","https://vuldb.com/vuln/411636","https://vuldb.com/vuln/411636/cti","https://www.sourcecodester.com/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T04:18:28","euvd":{"id":"EUVD-2026-89607","description":"A vulnerability was identified in SourceCodester Online Leave Management System 1.0. This issue affects some unknown processing of the file /admin/?page=reports. The manipulation of the argument date_start/date_end leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.","published_time":"2026-09-30T04:00:08","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411636","https://vuldb.com/vuln/411636/cti","https://vuldb.com/cve/CVE-2026-102912","https://vuldb.com/submit/954023","https://github.com/zhongzhicong1998/CVE/issues/1","https://www.sourcecodester.com/"],"products":["Online Leave Management System"],"vendors":["SourceCodester"]}},{"cve_id":"CVE-2026-102910","summary":"A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/examproper/exam-delete.php. The manipulation of the argument test_id results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.","cvss":5.5,"cvss_version":4.0,"cvss_v2":7.5,"cvss_v3":7.3,"cvss_v4":5.5,"epss":0.00269,"ranking_epss":0.17174,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Aszadom/cve/issues/3","https://vuldb.com/cve/CVE-2026-102910","https://vuldb.com/submit/953899","https://vuldb.com/vuln/411583","https://vuldb.com/vuln/411583/cti","https://www.sourcecodester.com/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T04:18:27","euvd":{"id":"EUVD-2026-89604","description":"A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/examproper/exam-delete.php. The manipulation of the argument test_id results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.","published_time":"2026-09-30T03:30:07","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411583","https://vuldb.com/vuln/411583/cti","https://vuldb.com/cve/CVE-2026-102910","https://vuldb.com/submit/953899","https://github.com/Aszadom/cve/issues/3","https://www.sourcecodester.com/"],"products":["Online Reviewer Management System"],"vendors":["SourceCodester"]}},{"cve_id":"CVE-2026-103109","summary":"Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a controlled abort during processing, and has the potential to achieve memory corruption.","cvss":7.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.7,"cvss_v4":null,"epss":0.00243,"ranking_epss":0.14023,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.pexip.com/admin/security_bulletins.htm"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T03:17:00","euvd":{"id":"EUVD-2026-89585","description":"Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a controlled abort during processing, and has the potential to achieve memory corruption.","published_time":"2026-09-30T02:59:53","cvss":7.7,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://docs.pexip.com/admin/security_bulletins.htm"],"products":["Infinity","Infinity","Infinity","Infinity"],"vendors":["Pexip"]}},{"cve_id":"CVE-2026-86556","summary":"There is an information disclosure vulnerability in ZTE U30 Air. Due to improper permission control, attackers can exploit the vulnerability to obtain relevant information.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":0.00187,"ranking_epss":0.07481,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/3351503523831148854"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T03:17:00","euvd":{"id":"EUVD-2026-89572","description":"There is an information disclosure vulnerability in ZTE U30 Air. Due to improper permission control, attackers can exploit the vulnerability to obtain relevant information.","published_time":"2026-09-30T02:14:19","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"zte","references":["https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/3351503523831148854"],"products":["U30 Air"],"vendors":["ZTE"]}},{"cve_id":"CVE-2026-96649","summary":"The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the site operator to have enabled guest post submission via the [fpsm] shortcode, which registers a publicly accessible AJAX handler gated only by a nonce emitted on every page containing the shortcode.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":0.00247,"ranking_epss":0.14393,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://plugins.trac.wordpress.org/browser/frontend-post-submission-manager-lite/tags/1.3.4/assets/js/fpsml-fileuploader.js#L578","https://plugins.trac.wordpress.org/browser/frontend-post-submission-manager-lite/tags/1.3.4/assets/js/fpsml-fileuploader.js#L583","https://plugins.trac.wordpress.org/browser/frontend-post-submission-manager-lite/tags/1.3.4/assets/js/fpsml-frontend.js#L40","https://plugins.trac.wordpress.org/browser/frontend-post-submission-manager-lite/tags/1.3.4/includes/classes/class-fpsml-library.php#L112","https://plugins.trac.wordpress.org/browser/frontend-post-submission-manager-lite/tags/1.3.4/includes/cores/ajax-process-form.php#L161","https://plugins.trac.wordpress.org/browser/frontend-post-submission-manager-lite/tags/1.3.4/includes/cores/ajax-process-form.php#L5","https://plugins.trac.wordpress.org/browser/frontend-post-submission-manager-lite/tags/1.3.5/","https://www.wordfence.com/threat-intel/vulnerabilities/id/0af8ff06-68e2-4a0c-9de4-d06a6a2e86c9?source=cve"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T03:17:00","euvd":{"id":"EUVD-2026-89577","description":"The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the site operator to have enabled guest post submission via the [fpsm] shortcode, which registers a publicly accessible AJAX handler gated only by a nonce emitted on every page containing the shortcode.","published_time":"2026-09-30T02:27:19","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"Wordfence","references":["https://www.wordfence.com/threat-intel/vulnerabilities/id/0af8ff06-68e2-4a0c-9de4-d06a6a2e86c9?source=cve","https://plugins.trac.wordpress.org/browser/frontend-post-submission-manager-lite/tags/1.3.4/assets/js/fpsml-fileuploader.js#L583","https://plugins.trac.wordpress.org/browser/frontend-post-submission-manager-lite/tags/1.3.4/assets/js/fpsml-fileuploader.js#L578","https://plugins.trac.wordpress.org/browser/frontend-post-submission-manager-lite/tags/1.3.4/assets/js/fpsml-frontend.js#L40","https://plugins.trac.wordpress.org/browser/frontend-post-submission-manager-lite/tags/1.3.4/includes/cores/ajax-process-form.php#L5","https://plugins.trac.wordpress.org/browser/frontend-post-submission-manager-lite/tags/1.3.4/includes/cores/ajax-process-form.php#L161","https://plugins.trac.wordpress.org/browser/frontend-post-submission-manager-lite/tags/1.3.4/includes/classes/class-fpsml-library.php#L112","https://plugins.trac.wordpress.org/browser/frontend-post-submission-manager-lite/tags/1.3.5/"],"products":["Frontend Post Submission Manager Lite – Guest Post and Frontend Submission Forms"],"vendors":["wpshuffle"]}},{"cve_id":"CVE-2026-103101","summary":"Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a Pexip Infinity node inaccessible.","cvss":8.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":null,"epss":0.00268,"ranking_epss":0.17129,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.pexip.com/admin/security_bulletins.htm"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T03:16:59","euvd":{"id":"EUVD-2026-89576","description":"Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a Pexip Infinity node inaccessible.","published_time":"2026-09-30T02:24:28","cvss":8.6,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://docs.pexip.com/admin/security_bulletins.htm"],"products":["Infinity"],"vendors":["Pexip"]}},{"cve_id":"CVE-2026-103102","summary":"Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue requires accessing a gateway call from a WebRTC/API client.","cvss":8.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":null,"epss":0.0032,"ranking_epss":0.22588,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.pexip.com/admin/security_bulletins.htm"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T03:16:59","euvd":{"id":"EUVD-2026-89578","description":"Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue requires accessing a gateway call from a WebRTC/API client.","published_time":"2026-09-30T02:29:04","cvss":8.6,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://docs.pexip.com/admin/security_bulletins.htm"],"products":["Infinity"],"vendors":["Pexip"]}},{"cve_id":"CVE-2026-103104","summary":"Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a remote attacker to trigger a software abort resulting in a denial of service.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00313,"ranking_epss":0.21898,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.pexip.com/admin/security_bulletins.htm"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T03:16:59","euvd":{"id":"EUVD-2026-89580","description":"Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a remote attacker to trigger a software abort resulting in a denial of service.","published_time":"2026-09-30T02:35:07","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://docs.pexip.com/admin/security_bulletins.htm"],"products":["Infinity","Infinity","Infinity","Infinity"],"vendors":["Pexip"]}},{"cve_id":"CVE-2026-103105","summary":"Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another Pexip Infinity node.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00184,"ranking_epss":0.07204,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.pexip.com/admin/security_bulletins.htm"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T03:16:59","euvd":{"id":"EUVD-2026-89581","description":"Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another Pexip Infinity node.","published_time":"2026-09-30T02:39:23","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://docs.pexip.com/admin/security_bulletins.htm"],"products":["Infinity","Infinity","Infinity","Infinity"],"vendors":["Pexip"]}},{"cve_id":"CVE-2026-103106","summary":"Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an attacker to be able to run arbitrary code on a node by either achieving remote code execution via some other vulnerability or having administrative access to the operating system.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":0.00141,"ranking_epss":0.02893,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.pexip.com/admin/security_bulletins.htm"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T03:16:59","euvd":{"id":"EUVD-2026-89583","description":"Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an attacker to be able to run arbitrary code on a node by either achieving remote code execution via some other vulnerability or having administrative access to the operating system.","published_time":"2026-09-30T02:45:39","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://docs.pexip.com/admin/security_bulletins.htm"],"products":["Infinity","Infinity","Infinity","Infinity"],"vendors":["Pexip"]}},{"cve_id":"CVE-2026-103108","summary":"Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00313,"ranking_epss":0.21899,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.pexip.com/admin/security_bulletins.htm"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T03:16:59","euvd":{"id":"EUVD-2026-89584","description":"Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service","published_time":"2026-09-30T02:49:52","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://docs.pexip.com/admin/security_bulletins.htm"],"products":["Infinity","Infinity","Infinity","Infinity"],"vendors":["Pexip"]}},{"cve_id":"CVE-2026-102906","summary":"A vulnerability was identified in 0xshariq github-mcp-server up to 52e764a7d66eac1726fce02ca7bb5a638571801a. This issue affects the function child_process.exec of the file src/github.ts of the component Git Remove MCP Tool. Such manipulation of the argument File leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.","cvss":2.1,"cvss_version":4.0,"cvss_v2":6.5,"cvss_v3":6.3,"cvss_v4":2.1,"epss":0.01067,"ranking_epss":0.6347,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/0xshariq/github-mcp-server/","https://github.com/0xshariq/github-mcp-server/issues/2","https://vuldb.com/cve/CVE-2026-102906","https://vuldb.com/submit/953767","https://vuldb.com/vuln/411537","https://vuldb.com/vuln/411537/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T03:16:58","euvd":{"id":"EUVD-2026-89579","description":"A vulnerability was identified in 0xshariq github-mcp-server up to 52e764a7d66eac1726fce02ca7bb5a638571801a. This issue affects the function child_process.exec of the file src/github.ts of the component Git Remove MCP Tool. Such manipulation of the argument File leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.","published_time":"2026-09-30T02:30:09","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411537","https://vuldb.com/vuln/411537/cti","https://vuldb.com/cve/CVE-2026-102906","https://vuldb.com/submit/953767","https://github.com/0xshariq/github-mcp-server/issues/2","https://github.com/0xshariq/github-mcp-server/"],"products":["github-mcp-server"],"vendors":["0xshariq"]}},{"cve_id":"CVE-2026-102908","summary":"A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/examproper/questions-view.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.","cvss":5.5,"cvss_version":4.0,"cvss_v2":7.5,"cvss_v3":7.3,"cvss_v4":5.5,"epss":0.00263,"ranking_epss":0.1639,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Aszadom/cve/issues/1","https://vuldb.com/cve/CVE-2026-102908","https://vuldb.com/submit/953892","https://vuldb.com/vuln/411581","https://vuldb.com/vuln/411581/cti","https://www.sourcecodester.com/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T03:16:58","euvd":{"id":"EUVD-2026-89582","description":"A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/examproper/questions-view.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.","published_time":"2026-09-30T02:45:11","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411581","https://vuldb.com/vuln/411581/cti","https://vuldb.com/cve/CVE-2026-102908","https://vuldb.com/submit/953892","https://github.com/Aszadom/cve/issues/1","https://www.sourcecodester.com/"],"products":["Online Reviewer Management System"],"vendors":["SourceCodester"]}},{"cve_id":"CVE-2026-102909","summary":"A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/examproper/btn_functions.php. The manipulation of the argument access_code leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.","cvss":5.5,"cvss_version":4.0,"cvss_v2":7.5,"cvss_v3":7.3,"cvss_v4":5.5,"epss":0.00263,"ranking_epss":0.16388,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Aszadom/cve/issues/2","https://vuldb.com/cve/CVE-2026-102909","https://vuldb.com/submit/953896","https://vuldb.com/vuln/411582","https://vuldb.com/vuln/411582/cti","https://www.sourcecodester.com/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T03:16:58","euvd":{"id":"EUVD-2026-89586","description":"A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/examproper/btn_functions.php. The manipulation of the argument access_code leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.","published_time":"2026-09-30T03:00:09","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411582","https://vuldb.com/vuln/411582/cti","https://vuldb.com/cve/CVE-2026-102909","https://vuldb.com/submit/953896","https://github.com/Aszadom/cve/issues/2","https://www.sourcecodester.com/"],"products":["Online Reviewer Management System"],"vendors":["SourceCodester"]}},{"cve_id":"CVE-2026-103099","summary":"Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00313,"ranking_epss":0.21899,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.pexip.com/admin/security_bulletins.htm"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T03:16:58","euvd":{"id":"EUVD-2026-89573","description":"Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that allows a remote attacker to trigger a software abort resulting in a denial of service.","published_time":"2026-09-30T02:14:57","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://docs.pexip.com/admin/security_bulletins.htm"],"products":["Infinity"],"vendors":["Pexip"]}},{"cve_id":"CVE-2026-103100","summary":"Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trigger a software abort resulting in a denial of service.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00263,"ranking_epss":0.16337,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.pexip.com/admin/security_bulletins.htm"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T03:16:58","euvd":{"id":"EUVD-2026-89575","description":"Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trigger a software abort resulting in a denial of service.","published_time":"2026-09-30T02:17:33","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://docs.pexip.com/admin/security_bulletins.htm"],"products":["Infinity"],"vendors":["Pexip"]}},{"cve_id":"CVE-2026-102874","summary":"A vulnerability was identified in HKUDS AnyTool 0.1.0. Affected is the function subprocess.run of the file anytool/local_server/main.py of the component Execute Endpoint. The manipulation of the argument command/shell leads to os command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.","cvss":5.5,"cvss_version":4.0,"cvss_v2":7.5,"cvss_v3":7.3,"cvss_v4":5.5,"epss":0.01324,"ranking_epss":0.69834,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/HKUDS/AnyTool/","https://github.com/HKUDS/AnyTool/issues/6","https://vuldb.com/cve/CVE-2026-102874","https://vuldb.com/submit/949780","https://vuldb.com/vuln/411510","https://vuldb.com/vuln/411510/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T03:16:57","euvd":{"id":"EUVD-2026-89574","description":"A vulnerability was identified in HKUDS AnyTool 0.1.0. Affected is the function subprocess.run of the file anytool/local_server/main.py of the component Execute Endpoint. The manipulation of the argument command/shell leads to os command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.","published_time":"2026-09-30T02:15:11","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411510","https://vuldb.com/vuln/411510/cti","https://vuldb.com/cve/CVE-2026-102874","https://vuldb.com/submit/949780","https://github.com/HKUDS/AnyTool/issues/6","https://github.com/HKUDS/AnyTool/"],"products":["AnyTool"],"vendors":["HKUDS"]}},{"cve_id":"CVE-2026-103087","summary":"Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1.0 and main before commit 46868b3 allows a remote attacker to cause a Denial of Service (stack exhaustion and application crash) via an SVG document containing an excessive number of deeply nested elements. Because the engine does not limit the nesting depth of processed SVG nodes, rendering such a document overflows the thread stack and terminates the application. The malicious SVG can be embedded through the SRC attribute of an IMG element, and thus exploitation only requires the victim to visit an attacker-controlled web page.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.1,"epss":0.0032,"ranking_epss":0.22581,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/gosub-io/gosub-engine/pull/1229","https://github.com/gosub-io/gosub-engine/security/advisories/GHSA-c762-mxfh-vwvp","https://github.com/gosub-io/gosub-engine/security/advisories/GHSA-c762-mxfh-vwvp"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T02:16:57","euvd":{"id":"EUVD-2026-89554","description":"Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1.0 and main before commit 46868b3 allows a remote attacker to cause a Denial of Service (stack exhaustion and application crash) via an SVG document containing an excessive number of deeply nested elements. Because the engine does not limit the nesting depth of processed SVG nodes, rendering such a document overflows the thread stack and terminates the application. The malicious SVG can be embedded through the SRC attribute of an IMG element, and thus exploitation only requires the victim to visit an attacker-controlled web page.","published_time":"2026-09-30T00:35:06","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"mitre","references":["https://github.com/gosub-io/gosub-engine/security/advisories/GHSA-c762-mxfh-vwvp","https://github.com/gosub-io/gosub-engine/pull/1229"],"products":["gosub-engine"],"vendors":["gosub-io"]}},{"cve_id":"CVE-2026-103088","summary":"Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through a URL handler that percent-decodes the path. In a Spring MVC application with a file: template prefix and a request-derived view name, a percent-encoded traversal such as %2e%2e/ bypasses both the view-resolver check and the loader-side containment and reads files outside the configured template base directory.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00689,"ranking_epss":0.50942,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/jknack/handlebars.java/commit/f6ae3979917d05bef07f00befb4013ef00503660","https://github.com/jknack/handlebars.java/releases/tag/v4.5.5","https://github.com/jknack/handlebars.java/security/advisories/GHSA-pvrx-3g7m-fpgv","https://github.com/jknack/handlebars.java/security/advisories/GHSA-pvrx-3g7m-fpgv"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T02:16:57","euvd":{"id":"EUVD-2026-89555","description":"Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix for CVE-2026-63490 validates template locations as raw percent-encoded strings, whereas the template file is opened through a URL handler that percent-decodes the path. In a Spring MVC application with a file: template prefix and a request-derived view name, a percent-encoded traversal such as %2e%2e/ bypasses both the view-resolver check and the loader-side containment and reads files outside the configured template base directory.","published_time":"2026-09-30T00:55:19","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/jknack/handlebars.java/security/advisories/GHSA-pvrx-3g7m-fpgv","https://github.com/jknack/handlebars.java/commit/f6ae3979917d05bef07f00befb4013ef00503660","https://github.com/jknack/handlebars.java/releases/tag/v4.5.5"],"products":["handlebars.java"],"vendors":["jknack"]}},{"cve_id":"CVE-2026-78229","summary":"Image Scanner Driver for Linux contains an OS command injection vulnerability. An attacker who can log in to a Linux system where the affected product is installed may execute an arbitrary OS command by making certain preparations.","cvss":5.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.7,"cvss_v4":5.4,"epss":0.00434,"ranking_epss":0.35328,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://jvn.jp/en/vu/JVNVU96968110/","https://www.pfu.ricoh.com/global/products_security/vul2026000001e.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T02:16:57","euvd":{"id":"EUVD-2026-89569","description":"Image Scanner Driver for Linux contains an OS command injection vulnerability. An attacker who can log in to a Linux system where the affected product is installed may execute an arbitrary OS command by making certain preparations.","published_time":"2026-09-30T01:51:37","cvss":5.4,"cvss_version":"4.0","epss":0.0,"assigner":"jpcert","references":["https://www.pfu.ricoh.com/global/products_security/vul2026000001e.html","https://jvn.jp/en/vu/JVNVU96968110/"],"products":["Image Scanner Driver for Linux (fi Series)","Image Scanner Driver for Linux (SP Series)","Image Scanner Driver for Linux (fi Series)","Image Scanner Driver for Linux (fi Series)","Image Scanner Driver for Linux (SP Series)","Image Scanner Driver for Linux (SP Series)","Image Scanner Driver for Linux (fi Series)","Image Scanner Driver for Linux (fi Series)","Image Scanner Driver for Linux (fi Series)","Image Scanner Driver for Linux (SP Series)"],"vendors":["PFU Limited"]}},{"cve_id":"CVE-2026-81310","summary":"Image Scanner Driver for Linux contains a link following vulnerability. An attacker who can log in to a Linux system where the product is installed may overwrite arbitrary files by using a special method in advance.","cvss":5.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.6,"cvss_v4":5.2,"epss":0.00119,"ranking_epss":0.01596,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://jvn.jp/en/vu/JVNVU96968110/","https://www.pfu.ricoh.com/global/products_security/vul2026000001e.html"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T02:16:57","euvd":{"id":"EUVD-2026-89568","description":"Image Scanner Driver for Linux contains a link following vulnerability. An attacker who can log in to a Linux system where the product is installed may overwrite arbitrary files by using a special method in advance.","published_time":"2026-09-30T01:51:54","cvss":5.2,"cvss_version":"4.0","epss":0.0,"assigner":"jpcert","references":["https://www.pfu.ricoh.com/global/products_security/vul2026000001e.html","https://jvn.jp/en/vu/JVNVU96968110/"],"products":["Image Scanner Driver for Linux (SP Series)","Image Scanner Driver for Linux (SP Series)","Image Scanner Driver for Linux (fi Series)","Image Scanner Driver for Linux (fi Series)","Image Scanner Driver for Linux (fi Series)","Image Scanner Driver for Linux (SP Series)","Image Scanner Driver for Linux (fi Series)","Image Scanner Driver for Linux (fi Series)","Image Scanner Driver for Linux (SP Series)","Image Scanner Driver for Linux (fi Series)"],"vendors":["PFU Limited"]}},{"cve_id":"CVE-2026-102843","summary":"A security flaw has been discovered in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This affects the function hapus of the file application/modules/admin/controllers/data_galeri.php of the component Endpoint. Performing a manipulation of the argument gbr results in path traversal. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.","cvss":2.0,"cvss_version":4.0,"cvss_v2":5.8,"cvss_v3":4.7,"cvss_v4":2.0,"epss":0.0033,"ranking_epss":0.23665,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/gedelumbung/HospitalManagement/","https://github.com/gedelumbung/HospitalManagement/issues/9","https://vuldb.com/cve/CVE-2026-102843","https://vuldb.com/submit/946239","https://vuldb.com/vuln/411502","https://vuldb.com/vuln/411502/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T02:16:56","euvd":{"id":"EUVD-2026-89556","description":"A security flaw has been discovered in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This affects the function hapus of the file application/modules/admin/controllers/data_galeri.php of the component Endpoint. Performing a manipulation of the argument gbr results in path traversal. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.","published_time":"2026-09-30T01:00:11","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411502","https://vuldb.com/vuln/411502/cti","https://vuldb.com/cve/CVE-2026-102843","https://vuldb.com/submit/946239","https://github.com/gedelumbung/HospitalManagement/issues/9","https://github.com/gedelumbung/HospitalManagement/"],"products":["HospitalManagement"],"vendors":["gedelumbung"]}},{"cve_id":"CVE-2026-102844","summary":"A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vulnerability affects the function detail of the file application/modules/admin/controllers/laporan_data_pasien.php. Executing a manipulation of the argument id_param can lead to authorization bypass. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.","cvss":2.0,"cvss_version":4.0,"cvss_v2":3.3,"cvss_v3":2.7,"cvss_v4":2.0,"epss":0.00258,"ranking_epss":0.15802,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/gedelumbung/HospitalManagement/","https://github.com/gedelumbung/HospitalManagement/issues/10","https://vuldb.com/cve/CVE-2026-102844","https://vuldb.com/submit/946240","https://vuldb.com/vuln/411503","https://vuldb.com/vuln/411503/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T02:16:56","euvd":{"id":"EUVD-2026-89557","description":"A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vulnerability affects the function detail of the file application/modules/admin/controllers/laporan_data_pasien.php. Executing a manipulation of the argument id_param can lead to authorization bypass. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.","published_time":"2026-09-30T01:15:07","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411503","https://vuldb.com/vuln/411503/cti","https://vuldb.com/cve/CVE-2026-102844","https://vuldb.com/submit/946240","https://github.com/gedelumbung/HospitalManagement/issues/10","https://github.com/gedelumbung/HospitalManagement/"],"products":["HospitalManagement"],"vendors":["gedelumbung"]}},{"cve_id":"CVE-2026-102845","summary":"A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This issue affects the function error_reporting of the file index.php of the component HTTP Response. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.","cvss":5.5,"cvss_version":4.0,"cvss_v2":5.0,"cvss_v3":5.3,"cvss_v4":5.5,"epss":0.00311,"ranking_epss":0.21679,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/gedelumbung/HospitalManagement/","https://github.com/gedelumbung/HospitalManagement/issues/11","https://vuldb.com/cve/CVE-2026-102845","https://vuldb.com/submit/946241","https://vuldb.com/vuln/411504","https://vuldb.com/vuln/411504/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T02:16:56","euvd":{"id":"EUVD-2026-89571","description":"A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This issue affects the function error_reporting of the file index.php of the component HTTP Response. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.","published_time":"2026-09-30T01:30:12","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411504","https://vuldb.com/vuln/411504/cti","https://vuldb.com/cve/CVE-2026-102845","https://vuldb.com/submit/946241","https://github.com/gedelumbung/HospitalManagement/issues/11","https://github.com/gedelumbung/HospitalManagement/"],"products":["HospitalManagement"],"vendors":["gedelumbung"]}},{"cve_id":"CVE-2026-102846","summary":"A vulnerability was detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Impacted is the function sistem.php::simpan of the file application/modules/admin/controllers/sistem.php of the component Configuration Handler. The manipulation of the argument tipe/title/content_setting results in improper authorization. The attack may be launched remotely. The exploit is now public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.","cvss":2.0,"cvss_version":4.0,"cvss_v2":5.8,"cvss_v3":4.7,"cvss_v4":2.0,"epss":0.00227,"ranking_epss":0.12157,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/gedelumbung/HospitalManagement/","https://github.com/gedelumbung/HospitalManagement/issues/12","https://vuldb.com/cve/CVE-2026-102846","https://vuldb.com/submit/946242","https://vuldb.com/vuln/411505","https://vuldb.com/vuln/411505/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T02:16:56","euvd":{"id":"EUVD-2026-89570","description":"A vulnerability was detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Impacted is the function sistem.php::simpan of the file application/modules/admin/controllers/sistem.php of the component Configuration Handler. The manipulation of the argument tipe/title/content_setting results in improper authorization. The attack may be launched remotely. The exploit is now public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.","published_time":"2026-09-30T01:45:20","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411505","https://vuldb.com/vuln/411505/cti","https://vuldb.com/cve/CVE-2026-102846","https://vuldb.com/submit/946242","https://github.com/gedelumbung/HospitalManagement/issues/12","https://github.com/gedelumbung/HospitalManagement/"],"products":["HospitalManagement"],"vendors":["gedelumbung"]}},{"cve_id":"CVE-2026-102847","summary":"A flaw has been found in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. The affected element is the function kirim of the file application/modules/web/controllers/buku_tamu.php of the component Guest Book. This manipulation of the argument nama/email/pesan causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been published and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.","cvss":2.1,"cvss_version":4.0,"cvss_v2":5.0,"cvss_v3":4.3,"cvss_v4":2.1,"epss":0.00273,"ranking_epss":0.17764,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/gedelumbung/HospitalManagement/","https://github.com/gedelumbung/HospitalManagement/issues/13","https://vuldb.com/cve/CVE-2026-102847","https://vuldb.com/submit/946243","https://vuldb.com/vuln/411506","https://vuldb.com/vuln/411506/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T02:16:56","euvd":{"id":"EUVD-2026-89567","description":"A flaw has been found in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. The affected element is the function kirim of the file application/modules/web/controllers/buku_tamu.php of the component Guest Book. This manipulation of the argument nama/email/pesan causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been published and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.","published_time":"2026-09-30T02:00:14","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411506","https://vuldb.com/vuln/411506/cti","https://vuldb.com/cve/CVE-2026-102847","https://vuldb.com/submit/946243","https://github.com/gedelumbung/HospitalManagement/issues/13","https://github.com/gedelumbung/HospitalManagement/"],"products":["HospitalManagement"],"vendors":["gedelumbung"]}},{"cve_id":"CVE-2026-103056","summary":"AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters in crowdstrike_rtr.py and endpoint.py. Authenticated users can inject single quotes into file_path, path, script_name, or script_args parameters to break out of quoted arguments and execute arbitrary commands on managed endpoints with SYSTEM or root privileges.","cvss":9.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.0,"cvss_v4":9.4,"epss":0.0146,"ranking_epss":0.72586,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/beenuar/AiSOC/blob/v11.2.0/services/actions/app/clients/crowdstrike_rtr.py#L273","https://github.com/beenuar/AiSOC/blob/v11.2.0/services/actions/app/executors/endpoint.py#L442","https://github.com/beenuar/AiSOC/commit/dac39723404130312daba15d42d19114f09f75b2","https://github.com/beenuar/AiSOC/releases/tag/v12.0.0","https://github.com/beenuar/AiSOC/security/advisories/GHSA-7q37-2wfw-xrx7","https://www.vulncheck.com/advisories/aisoc-7.2.0-before-12.0.0-command-injection-via-crowdstrike-rtr","https://github.com/beenuar/AiSOC/security/advisories/GHSA-7q37-2wfw-xrx7"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T01:16:37","euvd":{"id":"EUVD-2026-89540","description":"AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters in crowdstrike_rtr.py and endpoint.py. Authenticated users can inject single quotes into file_path, path, script_name, or script_args parameters to break out of quoted arguments and execute arbitrary commands on managed endpoints with SYSTEM or root privileges.","published_time":"2026-09-30T00:19:11","cvss":9.4,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/beenuar/AiSOC/security/advisories/GHSA-7q37-2wfw-xrx7","https://github.com/beenuar/AiSOC/commit/dac39723404130312daba15d42d19114f09f75b2","https://github.com/beenuar/AiSOC/releases/tag/v12.0.0","https://github.com/beenuar/AiSOC/blob/v11.2.0/services/actions/app/clients/crowdstrike_rtr.py#L273","https://github.com/beenuar/AiSOC/blob/v11.2.0/services/actions/app/executors/endpoint.py#L442","https://www.vulncheck.com/advisories/aisoc-7.2.0-before-12.0.0-command-injection-via-crowdstrike-rtr"],"products":["AiSOC"],"vendors":["beenuar"]}},{"cve_id":"CVE-2026-103057","summary":"AiSOC versions 5.1.0 before 12.0.0 contain an authentication bypass vulnerability in the realtime service internal endpoints POST /internal/agent-event and POST /internal/push. Attackers can post arbitrary events with spoofed tenant identifiers to broadcast malicious content over WebSocket and Redis SSE channels or send unauthorized notifications to registered devices.","cvss":5.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":5.3,"epss":0.00253,"ranking_epss":0.15229,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/beenuar/AiSOC/blob/v11.2.0/services/realtime/src/index.ts#L681-L691","https://github.com/beenuar/AiSOC/commit/2f0e954f2febecb3720e6eadb017546c5d121c43","https://github.com/beenuar/AiSOC/releases/tag/v12.0.0","https://github.com/beenuar/AiSOC/security/advisories/GHSA-mqjp-pcpr-7c37","https://www.vulncheck.com/advisories/aisoc-5.1.0-before-12.0.0-missing-authentication-on-realtime-service-internal-endpoints","https://github.com/beenuar/AiSOC/security/advisories/GHSA-mqjp-pcpr-7c37"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T01:16:37","euvd":{"id":"EUVD-2026-89541","description":"AiSOC versions 5.1.0 before 12.0.0 contain an authentication bypass vulnerability in the realtime service internal endpoints POST /internal/agent-event and POST /internal/push. Attackers can post arbitrary events with spoofed tenant identifiers to broadcast malicious content over WebSocket and Redis SSE channels or send unauthorized notifications to registered devices.","published_time":"2026-09-30T00:19:12","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/beenuar/AiSOC/security/advisories/GHSA-mqjp-pcpr-7c37","https://github.com/beenuar/AiSOC/commit/2f0e954f2febecb3720e6eadb017546c5d121c43","https://github.com/beenuar/AiSOC/releases/tag/v12.0.0","https://github.com/beenuar/AiSOC/blob/v11.2.0/services/realtime/src/index.ts#L681-L691","https://www.vulncheck.com/advisories/aisoc-5.1.0-before-12.0.0-missing-authentication-on-realtime-service-internal-endpoints"],"products":["AiSOC"],"vendors":["beenuar"]}},{"cve_id":"CVE-2026-51936","summary":"Zetetic SQLCipher before 4.15.0 allows SQL injection. The sqlcipher_export convenience function can be used to copy the contents of one attached database into another. It is most often used to convert between plaintext and encrypted databases. It needs to do dynamic schema manipulation, and thus the function temporarily clears defensive restrictions during operation. A vulnerability in the handling of the source database name parameter made it possible for a caller to supply a crafted source name, which could execute statements that defensive mode would otherwise block. This could allow direct modifications to the sqlite_schema table and database corruption. SQLCipher 4.15.0 now strictly validates the source database name and prevents the bypass.","cvss":2.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":2.1,"epss":0.0018,"ranking_epss":0.06776,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/sqlcipher/sqlcipher/commit/30842cda35c88cdfc7a8adba1c9b20821d2c08d1","https://www.zetetic.net/blog/2026/04/28/sqlcipher-4.15.0-release/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T01:16:37","euvd":{"id":"EUVD-2026-89542","description":"Zetetic SQLCipher before 4.15.0 allows SQL injection. The sqlcipher_export convenience function can be used to copy the contents of one attached database into another. It is most often used to convert between plaintext and encrypted databases. It needs to do dynamic schema manipulation, and thus the function temporarily clears defensive restrictions during operation. A vulnerability in the handling of the source database name parameter made it possible for a caller to supply a crafted source name, which could execute statements that defensive mode would otherwise block. This could allow direct modifications to the sqlite_schema table and database corruption. SQLCipher 4.15.0 now strictly validates the source database name and prevents the bypass.","published_time":"2026-09-30T00:19:30","cvss":2.1,"cvss_version":"4.0","epss":0.0,"assigner":"mitre","references":["https://www.zetetic.net/blog/2026/04/28/sqlcipher-4.15.0-release/","https://github.com/sqlcipher/sqlcipher/commit/30842cda35c88cdfc7a8adba1c9b20821d2c08d1"],"products":["SQLCipher"],"vendors":["Zetetic"]}},{"cve_id":"CVE-2026-102805","summary":"A flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. Executing a manipulation can lead to integer overflow. The attack can be executed remotely. The exploit has been published and may be used.","cvss":5.5,"cvss_version":4.0,"cvss_v2":6.4,"cvss_v3":6.5,"cvss_v4":5.5,"epss":0.00347,"ranking_epss":0.25845,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/nothings/stb/","https://github.com/nothings/stb/issues/1964","https://github.com/nothings/stb/issues/1964#issuecomment-5404606996","https://vuldb.com/cve/CVE-2026-102805","https://vuldb.com/submit/944868","https://vuldb.com/vuln/411497","https://vuldb.com/vuln/411497/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T01:16:36","euvd":{"id":"EUVD-2026-89536","description":"A flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. Executing a manipulation can lead to integer overflow. The attack can be executed remotely. The exploit has been published and may be used.","published_time":"2026-09-30T00:15:17","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411497","https://vuldb.com/vuln/411497/cti","https://vuldb.com/cve/CVE-2026-102805","https://vuldb.com/submit/944868","https://github.com/nothings/stb/issues/1964","https://github.com/nothings/stb/issues/1964#issuecomment-5404606996","https://github.com/nothings/stb/"],"products":["stb","stb","stb","stb","stb","stb","stb","stb","stb","stb","stb","stb","stb","stb","stb","stb","stb"],"vendors":["nothings"]}},{"cve_id":"CVE-2026-102842","summary":"A vulnerability was identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this issue is the function app_user_login_model.php::cekUserLogin of the file application/models/app_user_login_model.php of the component KCFinder File Manager. Such manipulation of the argument ADMIN_RS_KCFINDER leads to unrestricted upload. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.","cvss":2.1,"cvss_version":4.0,"cvss_v2":6.5,"cvss_v3":6.3,"cvss_v4":2.1,"epss":0.00276,"ranking_epss":0.18053,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/gedelumbung/HospitalManagement/","https://github.com/gedelumbung/HospitalManagement/issues/8","https://vuldb.com/cve/CVE-2026-102842","https://vuldb.com/submit/946238","https://vuldb.com/vuln/411501","https://vuldb.com/vuln/411501/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T01:16:36","euvd":{"id":"EUVD-2026-89543","description":"A vulnerability was identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this issue is the function app_user_login_model.php::cekUserLogin of the file application/models/app_user_login_model.php of the component KCFinder File Manager. Such manipulation of the argument ADMIN_RS_KCFINDER leads to unrestricted upload. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.","published_time":"2026-09-30T00:30:15","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411501","https://vuldb.com/vuln/411501/cti","https://vuldb.com/cve/CVE-2026-102842","https://vuldb.com/submit/946238","https://github.com/gedelumbung/HospitalManagement/issues/8","https://github.com/gedelumbung/HospitalManagement/"],"products":["HospitalManagement"],"vendors":["gedelumbung"]}},{"cve_id":"CVE-2026-103053","summary":"AiSOC versions 9.0.0 before 12.0.0 fail to enforce authentication on the response-action API endpoints when AISOC_DEV_MODE is enabled and AISOC_ACTIONS_SERVICE_TOKEN is empty in the default Docker Compose deployment. Unauthenticated attackers can list response-action integrations, submit and approve actions on behalf of arbitrary principals, and dispatch containment actions using vendor credentials.","cvss":5.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":5.3,"epss":0.00237,"ranking_epss":0.1331,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/beenuar/AiSOC/blob/v11.2.0/services/actions/app/security/authz.py#L104-L121","https://github.com/beenuar/AiSOC/commit/dac39723404130312daba15d42d19114f09f75b2","https://github.com/beenuar/AiSOC/releases/tag/v12.0.0","https://github.com/beenuar/AiSOC/security/advisories/GHSA-g4h7-p63q-r8r4","https://www.vulncheck.com/advisories/aisoc-9.0.0-before-12.0.0-missing-authentication-on-actions-service-response-action-api","https://github.com/beenuar/AiSOC/security/advisories/GHSA-g4h7-p63q-r8r4"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T01:16:36","euvd":{"id":"EUVD-2026-89537","description":"AiSOC versions 9.0.0 before 12.0.0 fail to enforce authentication on the response-action API endpoints when AISOC_DEV_MODE is enabled and AISOC_ACTIONS_SERVICE_TOKEN is empty in the default Docker Compose deployment. Unauthenticated attackers can list response-action integrations, submit and approve actions on behalf of arbitrary principals, and dispatch containment actions using vendor credentials.","published_time":"2026-09-30T00:19:09","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/beenuar/AiSOC/security/advisories/GHSA-g4h7-p63q-r8r4","https://github.com/beenuar/AiSOC/commit/dac39723404130312daba15d42d19114f09f75b2","https://github.com/beenuar/AiSOC/releases/tag/v12.0.0","https://github.com/beenuar/AiSOC/blob/v11.2.0/services/actions/app/security/authz.py#L104-L121","https://www.vulncheck.com/advisories/aisoc-9.0.0-before-12.0.0-missing-authentication-on-actions-service-response-action-api"],"products":["AiSOC"],"vendors":["beenuar"]}},{"cve_id":"CVE-2026-103054","summary":"AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that allows authenticated users to add arbitrary tenants to portfolios they own. Attackers can submit tenant UUIDs via the add_tenants_to_portfolio endpoint to claim unclaimed tenants and read their security alerts, incidents, and posture metrics without consent.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":7.1,"epss":0.00222,"ranking_epss":0.11606,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/beenuar/AiSOC/blob/v11.2.0/services/api/app/api/v1/endpoints/mssp.py#L1073-L1110","https://github.com/beenuar/AiSOC/commit/151264a8b846db55099e5e0f4d76c388e8df4a92","https://github.com/beenuar/AiSOC/releases/tag/v12.0.0","https://github.com/beenuar/AiSOC/security/advisories/GHSA-mcg9-8pxf-j98v","https://www.vulncheck.com/advisories/aisoc-10.0.0-before-12.0.0-unauthorized-tenant-access-via-mssp","https://github.com/beenuar/AiSOC/security/advisories/GHSA-mcg9-8pxf-j98v"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T01:16:36","euvd":{"id":"EUVD-2026-89538","description":"AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that allows authenticated users to add arbitrary tenants to portfolios they own. Attackers can submit tenant UUIDs via the add_tenants_to_portfolio endpoint to claim unclaimed tenants and read their security alerts, incidents, and posture metrics without consent.","published_time":"2026-09-30T00:19:10","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/beenuar/AiSOC/security/advisories/GHSA-mcg9-8pxf-j98v","https://github.com/beenuar/AiSOC/commit/151264a8b846db55099e5e0f4d76c388e8df4a92","https://github.com/beenuar/AiSOC/releases/tag/v12.0.0","https://github.com/beenuar/AiSOC/blob/v11.2.0/services/api/app/api/v1/endpoints/mssp.py#L1073-L1110","https://www.vulncheck.com/advisories/aisoc-10.0.0-before-12.0.0-unauthorized-tenant-access-via-mssp"],"products":["AiSOC"],"vendors":["beenuar"]}},{"cve_id":"CVE-2026-103055","summary":"AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET environment variable is not set. Unauthenticated attackers can forge subscription tickets with arbitrary tenant identifiers to access cross-tenant live alerts, cases, agent events and graph updates through the realtime endpoints.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":0.00405,"ranking_epss":0.32265,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/beenuar/AiSOC/blob/v11.2.0/services/realtime/src/auth.ts#L51-L59","https://github.com/beenuar/AiSOC/commit/2f0e954f2febecb3720e6eadb017546c5d121c43","https://github.com/beenuar/AiSOC/releases/tag/v12.0.0","https://github.com/beenuar/AiSOC/security/advisories/GHSA-4m55-xhcm-wjcr","https://www.vulncheck.com/advisories/aisoc-7.5.0-before-12.0.0-authentication-bypass-via-hard-coded-jwt-secret"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T01:16:36","euvd":{"id":"EUVD-2026-89539","description":"AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET environment variable is not set. Unauthenticated attackers can forge subscription tickets with arbitrary tenant identifiers to access cross-tenant live alerts, cases, agent events and graph updates through the realtime endpoints.","published_time":"2026-09-30T00:19:11","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/beenuar/AiSOC/security/advisories/GHSA-4m55-xhcm-wjcr","https://github.com/beenuar/AiSOC/commit/2f0e954f2febecb3720e6eadb017546c5d121c43","https://github.com/beenuar/AiSOC/releases/tag/v12.0.0","https://github.com/beenuar/AiSOC/blob/v11.2.0/services/realtime/src/auth.ts#L51-L59","https://www.vulncheck.com/advisories/aisoc-7.5.0-before-12.0.0-authentication-bypass-via-hard-coded-jwt-secret"],"products":["AiSOC"],"vendors":["beenuar"]}},{"cve_id":"CVE-2026-102804","summary":"A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20. The impacted element is the function hexwave_init in the library stb_hexwave.h. Performing a manipulation of the argument width/oversample results in integer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.","cvss":5.5,"cvss_version":4.0,"cvss_v2":6.4,"cvss_v3":6.5,"cvss_v4":5.5,"epss":0.00347,"ranking_epss":0.25845,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/nothings/stb/","https://github.com/nothings/stb/issues/1961","https://github.com/user-attachments/files/31351618/poc_hexwave.c","https://vuldb.com/cve/CVE-2026-102804","https://vuldb.com/submit/944861","https://vuldb.com/vuln/411496","https://vuldb.com/vuln/411496/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T01:16:35","euvd":{"id":"EUVD-2026-89535","description":"A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20. The impacted element is the function hexwave_init in the library stb_hexwave.h. Performing a manipulation of the argument width/oversample results in integer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.","published_time":"2026-09-30T00:00:17","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411496","https://vuldb.com/vuln/411496/cti","https://vuldb.com/cve/CVE-2026-102804","https://vuldb.com/submit/944861","https://github.com/nothings/stb/issues/1961","https://github.com/user-attachments/files/31351618/poc_hexwave.c","https://github.com/nothings/stb/"],"products":["stb"],"vendors":["nothings"]}},{"cve_id":"CVE-2026-86133","summary":"An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote attacker who has completed the initial IKEv2 handshake to crash the iked process by sending a specially crafted encrypted IKEv2 message, resulting in a denial of service.","cvss":8.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.2,"epss":0.0034,"ranking_epss":0.25047,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://psirt.watchguard.com/CVE-2026-86133"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T00:16:37","euvd":{"id":"EUVD-2026-89495","description":"An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote attacker who has completed the initial IKEv2 handshake to crash the iked process by sending a specially crafted encrypted IKEv2 message, resulting in a denial of service.","published_time":"2026-09-29T23:05:47","cvss":8.2,"cvss_version":"4.0","epss":0.0,"assigner":"WatchGuard","references":["https://psirt.watchguard.com/CVE-2026-86133"],"products":["Fireware OS","Fireware OS","Fireware OS","Fireware OS"],"vendors":["WatchGuard"]}},{"cve_id":"CVE-2026-86136","summary":"A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.1,"epss":0.00265,"ranking_epss":0.16638,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://psirt.watchguard.com/CVE-2026-86136"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T00:16:37","euvd":{"id":"EUVD-2026-89491","description":"A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.","published_time":"2026-09-29T23:05:47","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"WatchGuard","references":["https://psirt.watchguard.com/CVE-2026-86136"],"products":["Fireware OS","Fireware OS","Fireware OS","Fireware OS"],"vendors":["WatchGuard"]}},{"cve_id":"CVE-2026-90441","summary":"A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.1,"epss":0.00207,"ranking_epss":0.09721,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://psirt.watchguard.com/CVE-2026-90441"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T00:16:37","euvd":{"id":"EUVD-2026-89494","description":"A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.","published_time":"2026-09-29T23:05:47","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"WatchGuard","references":["https://psirt.watchguard.com/CVE-2026-90441"],"products":["Fireware OS","Fireware OS","Fireware OS","Fireware OS"],"vendors":["WatchGuard"]}},{"cve_id":"CVE-2026-18145","summary":"A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending a specially crafted management request.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.6,"epss":0.00342,"ranking_epss":0.25236,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://psirt.watchguard.com/CVE-2026-18145"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T00:16:36","euvd":{"id":"EUVD-2026-89500","description":"A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending a specially crafted management request.","published_time":"2026-09-29T23:05:47","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"WatchGuard","references":["https://psirt.watchguard.com/CVE-2026-18145"],"products":["Fireware OS","Fireware OS","Fireware OS","Fireware OS"],"vendors":["WatchGuard"]}},{"cve_id":"CVE-2026-81433","summary":"A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon (fingerd) allows an unauthenticated attacker with adjacent network access to execute arbitrary code or crash the process by sending a specially crafted DHCP packet.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00198,"ranking_epss":0.08613,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://psirt.watchguard.com/CVE-2026-81433"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T00:16:36","euvd":{"id":"EUVD-2026-89488","description":"A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon (fingerd) allows an unauthenticated attacker with adjacent network access to execute arbitrary code or crash the process by sending a specially crafted DHCP packet.","published_time":"2026-09-29T23:05:47","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"WatchGuard","references":["https://psirt.watchguard.com/CVE-2026-81433"],"products":["Fireware OS","Fireware OS","Fireware OS"],"vendors":["WatchGuard"]}},{"cve_id":"CVE-2026-86101","summary":"An improper authorization vulnerability in WatchGuard Fireware OS's SAML login process allows a remote, authenticated SAML user with access only to the Access Portal to obtain unauthorized Mobile VPN with SSL access through a specially crafted request.","cvss":7.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.2,"epss":0.00207,"ranking_epss":0.09722,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://psirt.watchguard.com/CVE-2026-86101"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T00:16:36","euvd":{"id":"EUVD-2026-89499","description":"An improper authorization vulnerability in WatchGuard Fireware OS's SAML login process allows a remote, authenticated SAML user with access only to the Access Portal to obtain unauthorized Mobile VPN with SSL access through a specially crafted request.","published_time":"2026-09-29T23:05:47","cvss":7.2,"cvss_version":"4.0","epss":0.0,"assigner":"WatchGuard","references":["https://psirt.watchguard.com/CVE-2026-86101"],"products":["Fireware OS","Fireware OS","Fireware OS","Fireware OS"],"vendors":["WatchGuard"]}},{"cve_id":"CVE-2026-86104","summary":"An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted request.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":0.00355,"ranking_epss":0.26872,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://psirt.watchguard.com/CVE-2026-86104"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T00:16:36","euvd":{"id":"EUVD-2026-89501","description":"An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted request.","published_time":"2026-09-29T23:05:48","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"WatchGuard","references":["https://psirt.watchguard.com/CVE-2026-86104"],"products":["Fireware OS","Fireware OS","Fireware OS","Fireware OS"],"vendors":["WatchGuard"]}},{"cve_id":"CVE-2026-86105","summary":"An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access.","cvss":6.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.0,"epss":0.00357,"ranking_epss":0.27054,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://psirt.watchguard.com/CVE-2026-86105"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T00:16:36","euvd":{"id":"EUVD-2026-89492","description":"An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access.","published_time":"2026-09-29T23:05:47","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"WatchGuard","references":["https://psirt.watchguard.com/CVE-2026-86105"],"products":["Fireware OS","Fireware OS","Fireware OS","Fireware OS"],"vendors":["WatchGuard"]}},{"cve_id":"CVE-2026-86128","summary":"A NULL pointer dereference vulnerability in Fireware OS's NetFlow packet-processing feature allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted IPv6 packet.","cvss":8.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.2,"epss":0.00355,"ranking_epss":0.26871,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://psirt.watchguard.com/CVE-2026-86128"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T00:16:36","euvd":{"id":"EUVD-2026-89489","description":"A NULL pointer dereference vulnerability in Fireware OS's NetFlow packet-processing feature allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted IPv6 packet.","published_time":"2026-09-29T23:05:47","cvss":8.2,"cvss_version":"4.0","epss":0.0,"assigner":"WatchGuard","references":["https://psirt.watchguard.com/CVE-2026-86128"],"products":["Fireware OS","Fireware OS","Fireware OS","Fireware OS"],"vendors":["WatchGuard"]}},{"cve_id":"CVE-2026-86131","summary":"A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.","cvss":9.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.2,"epss":0.00332,"ranking_epss":0.2405,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://psirt.watchguard.com/CVE-2026-86131"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T00:16:36","euvd":{"id":"EUVD-2026-89497","description":"A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.","published_time":"2026-09-29T23:05:47","cvss":9.2,"cvss_version":"4.0","epss":0.0,"assigner":"WatchGuard","references":["https://psirt.watchguard.com/CVE-2026-86131"],"products":["Fireware OS","Fireware OS","Fireware OS","Fireware OS"],"vendors":["WatchGuard"]}},{"cve_id":"CVE-2026-86132","summary":"An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the process by sending a specially crafted encrypted IKEv2 message negotiated with an AES-GCM cipher suite.","cvss":8.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.2,"epss":0.00355,"ranking_epss":0.26872,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://psirt.watchguard.com/CVE-2026-86132"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T00:16:36","euvd":{"id":"EUVD-2026-89490","description":"An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the process by sending a specially crafted encrypted IKEv2 message negotiated with an AES-GCM cipher suite.","published_time":"2026-09-29T23:05:47","cvss":8.2,"cvss_version":"4.0","epss":0.0,"assigner":"WatchGuard","references":["https://psirt.watchguard.com/CVE-2026-86132"],"products":["Fireware OS","Fireware OS","Fireware OS","Fireware OS"],"vendors":["WatchGuard"]}},{"cve_id":"CVE-2026-103048","summary":"URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - Collection extension allows Fake the Source of Data.\n\nThis issue affects Mediawiki - Collection extension: before 1.46.1, 1.45.5, 1.43.10.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00137,"ranking_epss":0.02593,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gerrit.wikimedia.org/r/c/1346083","https://phabricator.wikimedia.org/T321092"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T00:16:35","euvd":null},{"cve_id":"CVE-2026-103049","summary":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo extension allows Reflected XSS.\n\nThis issue affects Mediawiki - Cargo extension: before 1.46.1.","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":0.00155,"ranking_epss":0.04054,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1310132","https://phabricator.wikimedia.org/T431567"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T00:16:35","euvd":{"id":"EUVD-2026-89502","description":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo extension allows Reflected XSS.\n\nThis issue affects Mediawiki - Cargo extension: before 1.46.1.","published_time":"2026-09-29T23:08:30","cvss":6.1,"cvss_version":"3.1","epss":0.0,"assigner":"wikimedia-foundation","references":["https://phabricator.wikimedia.org/T431567","https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Cargo/+/1310132"],"products":["Mediawiki - Cargo Extension"],"vendors":["The Wikimedia Foundation"]}},{"cve_id":"CVE-2026-103050","summary":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - MassMessage extension allows Stored XSS.\n\nThis issue affects Mediawiki - MassMessage extension: before 1.46.1, 1.45.5, 1.43.10.","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":0.00155,"ranking_epss":0.04054,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gerrit.wikimedia.org/r/c/1346089","https://phabricator.wikimedia.org/T432341"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T00:16:35","euvd":{"id":"EUVD-2026-89503","description":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - MassMessage extension allows Stored XSS.\n\nThis issue affects Mediawiki - MassMessage extension: before 1.46.1, 1.45.5, 1.43.10.","published_time":"2026-09-29T23:11:02","cvss":6.1,"cvss_version":"3.1","epss":0.0,"assigner":"wikimedia-foundation","references":["https://phabricator.wikimedia.org/T432341","https://gerrit.wikimedia.org/r/c/1346089"],"products":["Mediawiki - MassMessage extension"],"vendors":["The Wikimedia Foundation"]}},{"cve_id":"CVE-2026-103051","summary":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralNotice extension allows Stored XSS.\n\nThis issue affects Mediawiki - CentralNotice extension: before 1.46.1, 1.45.5, 1.43.10.","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":0.00155,"ranking_epss":0.04055,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gerrit.wikimedia.org/r/c/mediawiki/extensions/CentralNotice/+/1346103","https://phabricator.wikimedia.org/T432419"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T00:16:35","euvd":{"id":"EUVD-2026-89504","description":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralNotice extension allows Stored XSS.\n\nThis issue affects Mediawiki - CentralNotice extension: before 1.46.1, 1.45.5, 1.43.10.","published_time":"2026-09-29T23:13:32","cvss":6.1,"cvss_version":"3.1","epss":0.0,"assigner":"wikimedia-foundation","references":["https://phabricator.wikimedia.org/T432419","https://gerrit.wikimedia.org/r/c/mediawiki/extensions/CentralNotice/+/1346103"],"products":["Mediawiki - CentralNotice extension"],"vendors":["The Wikimedia Foundation"]}},{"cve_id":"CVE-2026-13046","summary":"A deserialization of untrusted data vulnerability in WatchGuard Fireware OS's SAML single sign-on session handling (samld) allows an attacker who has already obtained the ability to write files on the appliance to execute arbitrary code in the context of the samld service by causing samld to load a maliciously crafted session file.","cvss":7.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.5,"epss":0.00324,"ranking_epss":0.23093,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://psirt.watchguard.com/CVE-2026-13046"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T00:16:35","euvd":{"id":"EUVD-2026-89498","description":"A deserialization of untrusted data vulnerability in WatchGuard Fireware OS's SAML single sign-on session handling (samld) allows an attacker who has already obtained the ability to write files on the appliance to execute arbitrary code in the context of the samld service by causing samld to load a maliciously crafted session file.","published_time":"2026-09-29T23:05:47","cvss":7.5,"cvss_version":"4.0","epss":0.0,"assigner":"WatchGuard","references":["https://psirt.watchguard.com/CVE-2026-13046"],"products":["Fireware OS","Fireware OS","Fireware OS","Fireware OS"],"vendors":["WatchGuard"]}},{"cve_id":"CVE-2026-13224","summary":"A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated administrator to read or list arbitrary files on the local filesystem by sending a specially crafted management request.","cvss":8.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.2,"epss":0.0032,"ranking_epss":0.22622,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://psirt.watchguard.com/CVE-2026-13224"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T00:16:35","euvd":{"id":"EUVD-2026-89496","description":"A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated administrator to read or list arbitrary files on the local filesystem by sending a specially crafted management request.","published_time":"2026-09-29T23:05:47","cvss":8.2,"cvss_version":"4.0","epss":0.0,"assigner":"WatchGuard","references":["https://psirt.watchguard.com/CVE-2026-13224"],"products":["Fireware OS","Fireware OS","Fireware OS","Fireware OS"],"vendors":["WatchGuard"]}},{"cve_id":"CVE-2026-18105","summary":"An uncontrolled resource consumption vulnerability in Fireware OS's diagnostic tasks feature allows a low-privileged, authenticated user to cause a denial of service of the system's diagnostic tools by repeatedly starting and aborting a specially crafted diagnostic task through the web UI.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.1,"epss":0.00226,"ranking_epss":0.12013,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://psirt.watchguard.com/CVE-2026-18105"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T00:16:35","euvd":{"id":"EUVD-2026-89493","description":"An uncontrolled resource consumption vulnerability in Fireware OS's diagnostic tasks feature allows a low-privileged, authenticated user to cause a denial of service of the system's diagnostic tools by repeatedly starting and aborting a specially crafted diagnostic task through the web UI.","published_time":"2026-09-29T23:05:47","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"WatchGuard","references":["https://psirt.watchguard.com/CVE-2026-18105"],"products":["Fireware OS","Fireware OS","Fireware OS","Fireware OS"],"vendors":["WatchGuard"]}},{"cve_id":"CVE-2026-102794","summary":"A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRnetwork/ping. Such manipulation of the argument url leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":8.5,"cvss_version":4.0,"cvss_v2":8.3,"cvss_v3":9.1,"cvss_v4":8.5,"epss":0.02362,"ranking_epss":0.83137,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/waltz-sketch/Ziroom/blob/main/zrnetwork_ping_url_command_injection.md","https://vuldb.com/cve/CVE-2026-102794","https://vuldb.com/submit/914651","https://vuldb.com/vuln/411471","https://vuldb.com/vuln/411471/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T00:16:34","euvd":{"id":"EUVD-2026-89534","description":"A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRnetwork/ping. Such manipulation of the argument url leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-09-29T23:30:10","cvss":9.4,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411471","https://vuldb.com/vuln/411471/cti","https://vuldb.com/cve/CVE-2026-102794","https://vuldb.com/submit/914651","https://github.com/waltz-sketch/Ziroom/blob/main/zrnetwork_ping_url_command_injection.md"],"products":["ZHOME A0101"],"vendors":["Ziroom"]}},{"cve_id":"CVE-2026-102793","summary":"A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function set_time_zone of the file /api/ZRFirmware/set_time_zone. This manipulation of the argument hostname/zonename causes command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":8.5,"cvss_version":4.0,"cvss_v2":8.3,"cvss_v3":9.1,"cvss_v4":8.5,"epss":0.0249,"ranking_epss":0.8405,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/waltz-sketch/Ziroom/blob/main/set_time_zone_hostname_command_injection.md","https://vuldb.com/cve/CVE-2026-102793","https://vuldb.com/submit/914649","https://vuldb.com/submit/914650","https://vuldb.com/vuln/411470","https://vuldb.com/vuln/411470/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-30T00:16:33","euvd":null},{"cve_id":"CVE-2026-15278","summary":"Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":[],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T23:17:22","euvd":null},{"cve_id":"CVE-2026-103043","summary":"anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6 host extraction regex due to catastrophic backtracking. Attackers can supply specially crafted input strings with repeated patterns to cause exponential regex engine backtracking, blocking the Node.js event loop and denying service to other requests.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":0.00446,"ranking_epss":0.3644,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/mmadersbacher/46050b4224eb979431986cdef1dd2ad3","https://github.com/alexcorvi/anchorme.js","https://github.com/alexcorvi/anchorme.js/blob/f3ae9850baa344f27b46bb149e9b891831d273b1/src/index.ts#L109","https://www.npmjs.com/package/anchorme","https://www.vulncheck.com/advisories/anchorme-through-3.0.8-regular-expression-denial-of-service","https://gist.github.com/mmadersbacher/46050b4224eb979431986cdef1dd2ad3"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T23:17:22","euvd":{"id":"EUVD-2026-89484","description":"anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6 host extraction regex due to catastrophic backtracking. Attackers can supply specially crafted input strings with repeated patterns to cause exponential regex engine backtracking, blocking the Node.js event loop and denying service to other requests.","published_time":"2026-09-29T22:51:02","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://gist.github.com/mmadersbacher/46050b4224eb979431986cdef1dd2ad3","https://github.com/alexcorvi/anchorme.js/blob/f3ae9850baa344f27b46bb149e9b891831d273b1/src/index.ts#L109","https://www.npmjs.com/package/anchorme","https://github.com/alexcorvi/anchorme.js","https://www.vulncheck.com/advisories/anchorme-through-3.0.8-regular-expression-denial-of-service"],"products":["anchorme"],"vendors":["alexcorvi"]}},{"cve_id":"CVE-2026-103044","summary":"XML injection (aka blind XPath injection) vulnerability in The Wikimedia Foundation Mediawiki - EasyTimeline extension allows XML Injection.\n\nThis issue affects Mediawiki - EasyTimeline extension: before 1.46.1, 1.45.5, 1.43.10.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.0017,"ranking_epss":0.05701,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gerrit.wikimedia.org/r/c/mediawiki/extensions/timeline/+/1346078","https://phabricator.wikimedia.org/T428006"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T23:17:22","euvd":null},{"cve_id":"CVE-2026-103045","summary":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Refreshed skin allows Stored XSS.\n\nThis issue affects Mediawiki - Refreshed skin: before 1.46.1, 1.45.5, 1.43.10.","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":0.00155,"ranking_epss":0.04054,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gerrit.wikimedia.org/r/c/mediawiki/skins/Refreshed/+/1309277","https://phabricator.wikimedia.org/T268377"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T23:17:22","euvd":{"id":"EUVD-2026-89485","description":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Refreshed skin allows Stored XSS.\n\nThis issue affects Mediawiki - Refreshed skin: before 1.46.1, 1.45.5, 1.43.10.","published_time":"2026-09-29T22:51:04","cvss":6.1,"cvss_version":"3.1","epss":0.0,"assigner":"wikimedia-foundation","references":["https://phabricator.wikimedia.org/T268377","https://gerrit.wikimedia.org/r/c/mediawiki/skins/Refreshed/+/1309277"],"products":["Mediawiki - Refreshed skin"],"vendors":["The Wikimedia Foundation"]}},{"cve_id":"CVE-2026-103046","summary":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation MediaWiki - WikiLambda extension allows Stored XSS.\n\nThis issue affects MediaWiki - WikiLambda extension: before 1.46.1.","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.04116,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gerrit.wikimedia.org/r/c/1307827","https://phabricator.wikimedia.org/T428829"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T23:17:22","euvd":{"id":"EUVD-2026-89478","description":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation MediaWiki - WikiLambda extension allows Stored XSS.\n\nThis issue affects MediaWiki - WikiLambda extension: before 1.46.1.","published_time":"2026-09-29T22:41:36","cvss":6.1,"cvss_version":"3.1","epss":0.0,"assigner":"wikimedia-foundation","references":["https://phabricator.wikimedia.org/T428829","https://gerrit.wikimedia.org/r/c/1307827"],"products":["Mediawiki - WikiLambda Extension"],"vendors":["The Wikimedia Foundation"]}},{"cve_id":"CVE-2026-103047","summary":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth extension allows Stored XSS.\n\nThis issue affects Mediawiki - CentralAuth extension: before 1.46.1, 1.45.5, 1.43.10.","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":0.00156,"ranking_epss":0.04116,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gerrit.wikimedia.org/r/c/1309285","https://phabricator.wikimedia.org/T244682"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T23:17:22","euvd":{"id":"EUVD-2026-89486","description":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth extension allows Stored XSS.\n\nThis issue affects Mediawiki - CentralAuth extension: before 1.46.1, 1.45.5, 1.43.10.","published_time":"2026-09-29T22:59:48","cvss":6.1,"cvss_version":"3.1","epss":0.0,"assigner":"wikimedia-foundation","references":["https://phabricator.wikimedia.org/T244682","https://gerrit.wikimedia.org/r/c/1309285"],"products":["Mediawiki - CentralAuth Extension"],"vendors":["The Wikimedia Foundation"]}},{"cve_id":"CVE-2026-103042","summary":"LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker memory. Attackers can call the exposed_set_value method to store unbounded key-value pairs without size limits, causing the worker process to crash and triggering node failure.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/ModelTC/LightLLM","https://github.com/ModelTC/LightLLM/issues/1595","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/base_kv_move_manager.py#L121-L122","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/nccl_kv_transporter.py#L416-L420","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/nccl_kv_transporter.py#L474-L485","https://www.vulncheck.com/advisories/lightllm-through-1.2.0-unauthenticated-memory-exhaustion-via-nccl-control-channel-set-value"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T23:17:21","euvd":{"id":"EUVD-2026-89483","description":"LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with --pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker memory. Attackers can call the exposed_set_value method to store unbounded key-value pairs without size limits, causing the worker process to crash and triggering node failure.","published_time":"2026-09-29T22:51:01","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/ModelTC/LightLLM/issues/1595","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/nccl_kv_transporter.py#L416-L420","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/nccl_kv_transporter.py#L474-L485","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/model_infer/mode_backend/pd/base_kv_move_manager.py#L121-L122","https://github.com/ModelTC/LightLLM","https://www.vulncheck.com/advisories/lightllm-through-1.2.0-unauthenticated-memory-exhaustion-via-nccl-control-channel-set-value"],"products":["LightLLM"],"vendors":["ModelTC"]}},{"cve_id":"CVE-2026-102792","summary":"A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0. This affects the function set_syslog of the file /api/ZRnetwork/set_syslog. The manipulation of the argument conloglevel/log_size results in command injection. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":8.5,"cvss_version":4.0,"cvss_v2":8.3,"cvss_v3":9.1,"cvss_v4":8.5,"epss":0.03044,"ranking_epss":0.87053,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/waltz-sketch/Ziroom/blob/main/set_syslog_conloglevel_command_injection.md","https://vuldb.com/cve/CVE-2026-102792","https://vuldb.com/submit/914647","https://vuldb.com/submit/914648","https://vuldb.com/vuln/411469","https://vuldb.com/vuln/411469/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T23:17:21","euvd":null},{"cve_id":"CVE-2026-103040","summary":"LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to the profiler command queue.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":9.3,"epss":0.00781,"ranking_epss":0.54282,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/ModelTC/LightLLM","https://github.com/ModelTC/LightLLM/issues/1597","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/profiler_service.py#L32-L34","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/profiler_service.py#L46-L50","https://www.vulncheck.com/advisories/lightllm-through-1.2.0-unauthenticated-remote-code-execution-via-router-profiler-rpyc-service","https://github.com/ModelTC/LightLLM/issues/1597"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T23:17:21","euvd":{"id":"EUVD-2026-89481","description":"LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to the profiler command queue.","published_time":"2026-09-29T22:51:00","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/ModelTC/LightLLM/issues/1597","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/profiler_service.py#L32-L34","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/router/profiler_service.py#L46-L50","https://github.com/ModelTC/LightLLM","https://www.vulncheck.com/advisories/lightllm-through-1.2.0-unauthenticated-remote-code-execution-via-router-profiler-rpyc-service"],"products":["LightLLM"],"vendors":["ModelTC"]}},{"cve_id":"CVE-2026-103041","summary":"LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":9.3,"epss":0.00622,"ranking_epss":0.47854,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/ModelTC/LightLLM","https://github.com/ModelTC/LightLLM/issues/1596","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/embed_cache/manager.py#L29-L31","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/embed_cache/manager.py#L66","https://www.vulncheck.com/advisories/lightllm-through-1.2.0-unauthenticated-remote-code-execution-via-embed-cache-rpyc-service","https://github.com/ModelTC/LightLLM/issues/1596"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T23:17:21","euvd":{"id":"EUVD-2026-89482","description":"LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges.","published_time":"2026-09-29T22:51:00","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/ModelTC/LightLLM/issues/1596","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/embed_cache/manager.py#L29-L31","https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/embed_cache/manager.py#L66","https://github.com/ModelTC/LightLLM","https://www.vulncheck.com/advisories/lightllm-through-1.2.0-unauthenticated-remote-code-execution-via-embed-cache-rpyc-service"],"products":["LightLLM"],"vendors":["ModelTC"]}},{"cve_id":"CVE-2026-91191","summary":"The device's update mechanism includes conditions that allow unauthorized software packages to be accepted as authentic. During the boot process, the stock done function disables signature verification in the OPKG configuration before restoring optional packages from a writable, unsigned feed. Separately, the publicly distributed SDK contains the production private key whose corresponding public key is trusted by both stable and beta firmware builds. Either issue undermines package authenticity, and together they allow an attacker to provide packages that appear valid to the system. Even if signature enforcement is restored, the exposed production key enables an attacker to generate signatures that the device will continue to trust. An attacker who can supply a malicious package may be able to execute arbitrary code with root privileges during installation.","cvss":7.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":7.7,"epss":0.00209,"ranking_epss":0.10048,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-01.json","https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1889828865/Latest+firmware+for+the+G520+Series+G526+G526RP+G527+G528","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-01","https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T22:19:03","euvd":{"id":"EUVD-2026-89467","description":"The device's update mechanism includes conditions that allow unauthorized software packages to be accepted as authentic. During the boot process, the stock done function disables signature verification in the OPKG configuration before restoring optional packages from a writable, unsigned feed. Separately, the publicly distributed SDK contains the production private key whose corresponding public key is trusted by both stable and beta firmware builds. Either issue undermines package authenticity, and together they allow an attacker to provide packages that appear valid to the system. Even if signature enforcement is restored, the exposed production key enables an attacker to generate signatures that the device will continue to trust. An attacker who can supply a malicious package may be able to execute arbitrary code with root privileges during installation.","published_time":"2026-09-29T21:04:52","cvss":7.7,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1889828865/Latest+firmware+for+the+G520+Series+G526+G526RP+G527+G528","https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-01","https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-01.json"],"products":["G520 series"],"vendors":["Lantronix"]}},{"cve_id":"CVE-2026-84409","summary":"The device's update mechanism retrieves metadata for software updates over an unencrypted HTTP connection and stores portions of that metadata for later use. A management interface subsequently returns this stored value in a JSON response, and the web interface responsible for displaying update information inserts that value directly into the page as HTML. This behavior allows attacker‑controlled metadata to be interpreted as script content. In addition, the same authenticated origin provides an interface capable of executing system‑level commands with root privileges. An attacker able to influence update metadata could exploit these conditions to execute arbitrary code within the administrative context of the device.","cvss":7.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":7.7,"epss":0.00391,"ranking_epss":0.30748,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-01.json","https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1889828865/Latest+firmware+for+the+G520+Series+G526+G526RP+G527+G528","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-01","https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T22:19:01","euvd":{"id":"EUVD-2026-89466","description":"The device's update mechanism retrieves metadata for software updates over an unencrypted HTTP connection and stores portions of that metadata for later use. A management interface subsequently returns this stored value in a JSON response, and the web interface responsible for displaying update information inserts that value directly into the page as HTML. This behavior allows attacker‑controlled metadata to be interpreted as script content. In addition, the same authenticated origin provides an interface capable of executing system‑level commands with root privileges. An attacker able to influence update metadata could exploit these conditions to execute arbitrary code within the administrative context of the device.","published_time":"2026-09-29T21:02:09","cvss":7.7,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1889828865/Latest+firmware+for+the+G520+Series+G526+G526RP+G527+G528","https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-01","https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-01.json"],"products":["G520 series"],"vendors":["Lantronix"]}},{"cve_id":"CVE-2026-74220","summary":"U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_read_reply() function in net/nfs-common.c that allows attackers to corrupt memory by supplying crafted NFS READ reply lengths. A malicious NFS server can exploit signed integer handling to bypass length validation and write far past the destination buffer, crashing the bootloader or corrupting memory.","cvss":8.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.2,"cvss_v4":8.8,"epss":0.00338,"ranking_epss":0.2482,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/u-boot/u-boot","https://github.com/u-boot/u-boot/blob/v2026.07/net/nfs-common.c#L695","https://github.com/u-boot/u-boot/commit/0bbf09859658b8cc9ac13be41af23b516b8ef69a","https://www.vulncheck.com/advisories/u-boot-before-2026.10-rc5-buffer-overflow-via-nfs-read-reply"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T22:18:33","euvd":{"id":"EUVD-2026-89433","description":"U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_read_reply() function in net/nfs-common.c that allows attackers to corrupt memory by supplying crafted NFS READ reply lengths. A malicious NFS server can exploit signed integer handling to bypass length validation and write far past the destination buffer, crashing the bootloader or corrupting memory.","published_time":"2026-09-29T21:29:22","cvss":8.8,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/u-boot/u-boot/commit/0bbf09859658b8cc9ac13be41af23b516b8ef69a","https://github.com/u-boot/u-boot/blob/v2026.07/net/nfs-common.c#L695","https://github.com/u-boot/u-boot","https://www.vulncheck.com/advisories/u-boot-before-2026.10-rc5-buffer-overflow-via-nfs-read-reply"],"products":["U-Boot"],"vendors":["U-Boot"]}},{"cve_id":"CVE-2026-74221","summary":"U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_readlink_reply() function in net/nfs-common.c when processing NFS server responses. A malicious NFS server can send crafted READLINK replies with negative or oversized symlink length values to corrupt memory and crash the bootloader.","cvss":8.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.2,"cvss_v4":8.8,"epss":0.00344,"ranking_epss":0.2545,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/u-boot/u-boot","https://github.com/u-boot/u-boot/blob/v2026.07/net/nfs-common.c#L643","https://github.com/u-boot/u-boot/commit/1c0aff3a5fbfeee7a8948f624e0b8554e6e0d8fd","https://www.vulncheck.com/advisories/u-boot-before-2026.10-rc5-buffer-overflow-via-nfs-readlink"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T22:18:33","euvd":{"id":"EUVD-2026-89434","description":"U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_readlink_reply() function in net/nfs-common.c when processing NFS server responses. A malicious NFS server can send crafted READLINK replies with negative or oversized symlink length values to corrupt memory and crash the bootloader.","published_time":"2026-09-29T21:29:23","cvss":8.8,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/u-boot/u-boot/commit/1c0aff3a5fbfeee7a8948f624e0b8554e6e0d8fd","https://github.com/u-boot/u-boot/blob/v2026.07/net/nfs-common.c#L643","https://github.com/u-boot/u-boot","https://www.vulncheck.com/advisories/u-boot-before-2026.10-rc5-buffer-overflow-via-nfs-readlink"],"products":["U-Boot"],"vendors":["U-Boot"]}},{"cve_id":"CVE-2026-74222","summary":"U-Boot before 2026.10-rc5 contains a use-after-free vulnerability in the httpc_recv_cb() function within the lwIP wget implementation. When HTTP data storage fails, the callback frees the connection PCB but returns ERR_BUF instead of ERR_ABRT, causing the TCP input path to access released memory and crash the bootloader.","cvss":8.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.2,"cvss_v4":8.8,"epss":0.00303,"ranking_epss":0.20761,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/u-boot/u-boot","https://github.com/u-boot/u-boot/blob/v2026.07/net/lwip/wget.c#L194","https://github.com/u-boot/u-boot/commit/2d94618a58aeb7630f18eee33419ce48d0fd3616","https://www.vulncheck.com/advisories/u-boot-before-2026.10-rc5-use-after-free-in-lwip-wget-receive-callback"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T22:18:33","euvd":null},{"cve_id":"CVE-2026-74225","summary":"U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths from DHCPv6 packets. Attackers on the local network can send crafted DHCPv6 ADVERTISE or REPLY packets during netboot to corrupt memory and crash the bootloader.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":7.1,"epss":0.00232,"ranking_epss":0.12715,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/u-boot/u-boot","https://github.com/u-boot/u-boot/blob/v2026.07/net/dhcpv6.c#L304","https://github.com/u-boot/u-boot/commit/20209a62bc8565fc1e040882bc03c71ff0d73076","https://www.vulncheck.com/advisories/u-boot-before-2026.10-rc5-out-of-bounds-write-via-dhcpv6"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T22:18:33","euvd":{"id":"EUVD-2026-89436","description":"U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths from DHCPv6 packets. Attackers on the local network can send crafted DHCPv6 ADVERTISE or REPLY packets during netboot to corrupt memory and crash the bootloader.","published_time":"2026-09-29T21:29:24","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/u-boot/u-boot/commit/20209a62bc8565fc1e040882bc03c71ff0d73076","https://github.com/u-boot/u-boot/blob/v2026.07/net/dhcpv6.c#L304","https://github.com/u-boot/u-boot","https://www.vulncheck.com/advisories/u-boot-before-2026.10-rc5-out-of-bounds-write-via-dhcpv6"],"products":["U-Boot"],"vendors":["U-Boot"]}},{"cve_id":"CVE-2026-71973","summary":"U-Boot before 2026.10-rc4 contains an integer overflow vulnerability in sqfs_read_directory_table() function when allocating the directory table buffer. Attackers can supply a crafted SquashFS image with an attacker-controlled superblock metablks_count value that causes heap buffer under-allocation and out-of-bounds writes, corrupting heap memory and crashing the bootloader.","cvss":5.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.2,"cvss_v4":5.2,"epss":0.00185,"ranking_epss":0.07302,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/u-boot/u-boot","https://github.com/u-boot/u-boot/blob/v2026.07/fs/squashfs/sqfs.c#L814","https://github.com/u-boot/u-boot/commit/561ae28cb56a082cfa90c1c421c4955bc215470b","https://www.vulncheck.com/advisories/u-boot-before-2026.10-rc4-integer-overflow-in-squashfs-directory-table-allocation"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T22:18:22","euvd":null},{"cve_id":"CVE-2026-71974","summary":"U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in read_slotted_partition() that fails to validate image size against partition bounds. Attackers with physical access can supply crafted boot media with oversized headers to write past the load buffer into bootloader memory on devices without Android Verified Boot protection.","cvss":4.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":4.8,"cvss_v4":4.3,"epss":0.00177,"ranking_epss":0.06509,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/u-boot/u-boot","https://github.com/u-boot/u-boot/blob/v2026.07/boot/bootmeth_android.c#L356","https://github.com/u-boot/u-boot/commit/35432ef6fe2c79ab72709966e64815a45eb55c76","https://patch.msgid.link/20260729-b4-android-bootmeth-oob-v1-1-31c3450ae0be@byteray.co.uk","https://www.vulncheck.com/advisories/u-boot-before-2026.10-rc3-out-of-bounds-write-via-android-bootmeth-partition-read"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T22:18:22","euvd":{"id":"EUVD-2026-89432","description":"U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in read_slotted_partition() that fails to validate image size against partition bounds. Attackers with physical access can supply crafted boot media with oversized headers to write past the load buffer into bootloader memory on devices without Android Verified Boot protection.","published_time":"2026-09-29T21:29:21","cvss":4.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/u-boot/u-boot/commit/35432ef6fe2c79ab72709966e64815a45eb55c76","https://github.com/u-boot/u-boot/blob/v2026.07/boot/bootmeth_android.c#L356","https://patch.msgid.link/20260729-b4-android-bootmeth-oob-v1-1-31c3450ae0be@byteray.co.uk","https://github.com/u-boot/u-boot","https://www.vulncheck.com/advisories/u-boot-before-2026.10-rc3-out-of-bounds-write-via-android-bootmeth-partition-read"],"products":["U-Boot"],"vendors":["U-Boot"]}},{"cve_id":"CVE-2026-72507","summary":"The \"reportType\" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability.","cvss":8.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.0,"cvss_v4":8.5,"epss":0.00289,"ranking_epss":0.19416,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T22:18:22","euvd":{"id":"EUVD-2026-89473","description":"The \"reportType\" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability.","published_time":"2026-09-29T21:36:53","cvss":8.5,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://www.toptech.com/blog/tms7-version-7-8-strengthens-security","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json"],"products":["TMS7","tophat"],"vendors":["Toptech Systems"]}},{"cve_id":"CVE-2026-72510","summary":"The \"supplier_no\" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection.","cvss":8.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.0,"cvss_v4":8.5,"epss":0.00289,"ranking_epss":0.19415,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T22:18:22","euvd":{"id":"EUVD-2026-89428","description":"The \"supplier_no\" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection.","published_time":"2026-09-29T21:28:26","cvss":8.5,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://www.toptech.com/blog/tms7-version-7-8-strengthens-security","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json"],"products":["tophat","TMS7"],"vendors":["Toptech Systems"]}},{"cve_id":"CVE-2026-71379","summary":"The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.","cvss":10.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":10.0,"cvss_v4":10.0,"epss":0.00442,"ranking_epss":0.36021,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T22:18:21","euvd":{"id":"EUVD-2026-89468","description":"The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.","published_time":"2026-09-29T21:23:25","cvss":10.0,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://www.toptech.com/blog/tms7-version-7-8-strengthens-security","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json"],"products":["tophat","TMS7"],"vendors":["Toptech Systems"]}},{"cve_id":"CVE-2026-71971","summary":"U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote attackers can send a crafted IP fragment with non-zero offset and More-Fragments flag set during netboot to corrupt adjacent memory and crash the bootloader.","cvss":8.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.2,"cvss_v4":8.8,"epss":0.00375,"ranking_epss":0.29011,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/u-boot/u-boot","https://github.com/u-boot/u-boot/blob/v2026.07/net/net.c#L975","https://github.com/u-boot/u-boot/commit/04ca915d5bf39dda5d1bce62d04d2b59d293c5b9","https://www.vulncheck.com/advisories/u-boot-before-2026.10-rc3-out-of-bounds-write-in-ip-fragment-reassembly"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T22:18:21","euvd":{"id":"EUVD-2026-89429","description":"U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote attackers can send a crafted IP fragment with non-zero offset and More-Fragments flag set during netboot to corrupt adjacent memory and crash the bootloader.","published_time":"2026-09-29T21:29:20","cvss":8.8,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/u-boot/u-boot/commit/04ca915d5bf39dda5d1bce62d04d2b59d293c5b9","https://github.com/u-boot/u-boot/blob/v2026.07/net/net.c#L975","https://github.com/u-boot/u-boot","https://www.vulncheck.com/advisories/u-boot-before-2026.10-rc3-out-of-bounds-write-in-ip-fragment-reassembly"],"products":["U-Boot"],"vendors":["U-Boot"]}},{"cve_id":"CVE-2026-71972","summary":"U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerability in the video_display_rle8_bitmap function in drivers/video/video_bmp.c. Attackers can supply a crafted RLE8-compressed BMP image to corrupt memory adjacent to the framebuffer and crash the bootloader.","cvss":6.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.9,"cvss_v4":6.0,"epss":0.00221,"ranking_epss":0.11458,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/u-boot/u-boot","https://github.com/u-boot/u-boot/blob/v2026.10-rc5/drivers/video/video_bmp.c#L126","https://github.com/u-boot/u-boot/commit/5201e83342d64c2f438ea35158575f28225e752e","https://www.vulncheck.com/advisories/u-boot-through-2026.10-rc5-out-of-bounds-write-in-bmp-rle8-decoder"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T22:18:21","euvd":{"id":"EUVD-2026-89430","description":"U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerability in the video_display_rle8_bitmap function in drivers/video/video_bmp.c. Attackers can supply a crafted RLE8-compressed BMP image to corrupt memory adjacent to the framebuffer and crash the bootloader.","published_time":"2026-09-29T21:29:20","cvss":6.0,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/u-boot/u-boot/commit/5201e83342d64c2f438ea35158575f28225e752e","https://github.com/u-boot/u-boot/blob/v2026.10-rc5/drivers/video/video_bmp.c#L126","https://github.com/u-boot/u-boot","https://www.vulncheck.com/advisories/u-boot-through-2026.10-rc5-out-of-bounds-write-in-bmp-rle8-decoder"],"products":["U-Boot"],"vendors":["U-Boot"]}},{"cve_id":"CVE-2026-71189","summary":"An attacker can construct a request that, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application.","cvss":4.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":3.5,"cvss_v4":4.8,"epss":0.00186,"ranking_epss":0.07396,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T22:18:18","euvd":{"id":"EUVD-2026-89476","description":"An attacker can construct a request that, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application.","published_time":"2026-09-29T21:46:48","cvss":4.8,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://www.toptech.com/blog/tms7-version-7-8-strengthens-security","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json"],"products":["tophat","TMS7"],"vendors":["Toptech Systems"]}},{"cve_id":"CVE-2026-71302","summary":"The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an attacker to predefine a session ID and reuse it after victim authentication, resulting in session takeover.","cvss":7.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.1,"cvss_v4":7.5,"epss":0.00287,"ranking_epss":0.19145,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T22:18:18","euvd":{"id":"EUVD-2026-89474","description":"The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an attacker to predefine a session ID and reuse it after victim authentication, resulting in session takeover.","published_time":"2026-09-29T21:41:11","cvss":7.5,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://www.toptech.com/blog/tms7-version-7-8-strengthens-security","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json"],"products":["TMS7","tophat"],"vendors":["Toptech Systems"]}},{"cve_id":"CVE-2026-70356","summary":"The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server.","cvss":9.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":9.4,"epss":0.00395,"ranking_epss":0.31188,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T22:18:16","euvd":{"id":"EUVD-2026-89469","description":"The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server.","published_time":"2026-09-29T21:26:22","cvss":9.4,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://www.toptech.com/blog/tms7-version-7-8-strengthens-security","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json"],"products":["TMS7","tophat"],"vendors":["Toptech Systems"]}},{"cve_id":"CVE-2026-69662","summary":"The application uses unsafe functions that allow execution of inline scripts and string evaluation functions.","cvss":2.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":3.7,"cvss_v4":2.1,"epss":0.00187,"ranking_epss":0.07497,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T22:17:58","euvd":{"id":"EUVD-2026-89475","description":"The application uses unsafe functions that allow execution of inline scripts and string evaluation functions.","published_time":"2026-09-29T21:44:07","cvss":2.1,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://www.toptech.com/blog/tms7-version-7-8-strengthens-security","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json"],"products":["TMS7","tophat"],"vendors":["Toptech Systems"]}},{"cve_id":"CVE-2026-68954","summary":"The \"pattern\" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability.","cvss":8.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.0,"cvss_v4":8.5,"epss":0.00289,"ranking_epss":0.19415,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T22:17:21","euvd":{"id":"EUVD-2026-89471","description":"The \"pattern\" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability.","published_time":"2026-09-29T21:32:05","cvss":8.5,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://www.toptech.com/blog/tms7-version-7-8-strengthens-security","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json"],"products":["TMS7","tophat"],"vendors":["Toptech Systems"]}},{"cve_id":"CVE-2026-68068","summary":"The \"screenID\" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability.","cvss":8.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.0,"cvss_v4":8.5,"epss":0.00289,"ranking_epss":0.19416,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T22:17:15","euvd":{"id":"EUVD-2026-89472","description":"The \"screenID\" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability.","published_time":"2026-09-29T21:33:47","cvss":8.5,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://www.toptech.com/blog/tms7-version-7-8-strengthens-security","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json"],"products":["tophat","TMS7"],"vendors":["Toptech Systems"]}},{"cve_id":"CVE-2026-63713","summary":"The \"search\" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulnerability.","cvss":8.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.0,"cvss_v4":8.5,"epss":0.00289,"ranking_epss":0.19415,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","https://www.toptech.com/blog/tms7-version-7-8-strengthens-security"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T22:17:11","euvd":{"id":"EUVD-2026-89438","description":"The \"search\" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulnerability.","published_time":"2026-09-29T21:30:32","cvss":8.5,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://www.toptech.com/blog/tms7-version-7-8-strengthens-security","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json"],"products":["tophat","TMS7"],"vendors":["Toptech Systems"]}},{"cve_id":"CVE-2026-102771","summary":"A security vulnerability has been detected in Naichen ThinkCMF up to 8.0.7. Affected by this issue is the function MailController::templatePut of the file cmf-api/src/admin/controller/MailController.php of the component Email Template. The manipulation leads to improper neutralization of special elements used in a template engine. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":2.0,"cvss_version":4.0,"cvss_v2":5.8,"cvss_v3":4.7,"cvss_v4":2.0,"epss":0.00239,"ranking_epss":0.13478,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/coolcj-stack/ThinkCMF-v8.0.1-SSTI-Vulnerability/blob/main/ThinkCMF_Vulnerability_Report_EN.docx","https://vuldb.com/cve/CVE-2026-102771","https://vuldb.com/submit/943081","https://vuldb.com/vuln/411468","https://vuldb.com/vuln/411468/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T22:17:08","euvd":{"id":"EUVD-2026-89477","description":"A security vulnerability has been detected in Naichen ThinkCMF up to 8.0.7. Affected by this issue is the function MailController::templatePut of the file cmf-api/src/admin/controller/MailController.php of the component Email Template. The manipulation leads to improper neutralization of special elements used in a template engine. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","published_time":"2026-09-29T22:00:14","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411468","https://vuldb.com/vuln/411468/cti","https://vuldb.com/cve/CVE-2026-102771","https://vuldb.com/submit/943081","https://github.com/coolcj-stack/ThinkCMF-v8.0.1-SSTI-Vulnerability/blob/main/ThinkCMF_Vulnerability_Report_EN.docx"],"products":["ThinkCMF","ThinkCMF","ThinkCMF","ThinkCMF","ThinkCMF","ThinkCMF","ThinkCMF","ThinkCMF"],"vendors":["Naichen"]}},{"cve_id":"CVE-2026-102621","summary":"A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The attack can only be performed from a local environment. The exploit is publicly available and might be used. Upgrading to version 26.09.0 is able to address this issue. The name of the patch is 323c91036d99926a8b90dc14329f7b40aece22f8. It is recommended to upgrade the affected component.","cvss":1.9,"cvss_version":4.0,"cvss_v2":1.7,"cvss_v3":3.3,"cvss_v4":1.9,"epss":0.00112,"ranking_epss":0.01279,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/r1ck9-2q/cve_summit/blob/main/Signed-integer-overflow-in-SplashClip-clipToPath-SplashClip.cc-214.md","https://gitlab.freedesktop.org/poppler/poppler/-/commit/323c91036d99926a8b90dc14329f7b40aece22f8","https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2325","https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1763","https://vuldb.com/cve/CVE-2026-102621","https://vuldb.com/submit/942349","https://vuldb.com/vuln/411411","https://vuldb.com/vuln/411411/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T22:17:07","euvd":{"id":"EUVD-2026-89437","description":"A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The attack can only be performed from a local environment. The exploit is publicly available and might be used. Upgrading to version 26.09.0 is able to address this issue. The name of the patch is 323c91036d99926a8b90dc14329f7b40aece22f8. It is recommended to upgrade the affected component.","published_time":"2026-09-29T21:30:11","cvss":4.8,"cvss_version":"4.0","epss":0.0,"assigner":"VulDB","references":["https://vuldb.com/vuln/411411","https://vuldb.com/vuln/411411/cti","https://vuldb.com/cve/CVE-2026-102621","https://vuldb.com/submit/942349","https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1763","https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2325","https://github.com/r1ck9-2q/cve_summit/blob/main/Signed-integer-overflow-in-SplashClip-clipToPath-SplashClip.cc-214.md","https://gitlab.freedesktop.org/poppler/poppler/-/commit/323c91036d99926a8b90dc14329f7b40aece22f8"],"products":["poppler"],"vendors":["Freedesktop"]}},{"cve_id":"CVE-2026-94204","summary":"The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive user records, live dashcam footage, application packages, and firmware files are exposed to anyone on the internet.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-07.json","https://viidure.app/","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-07"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T21:19:39","euvd":{"id":"EUVD-2026-89457","description":"The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive user records, live dashcam footage, application packages, and firmware files are exposed to anyone on the internet.","published_time":"2026-09-29T20:40:52","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://viidure.app/","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-07","https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-07.json"],"products":["Dashcam Android Application"],"vendors":["Viidure"]}},{"cve_id":"CVE-2026-96587","summary":"The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.","cvss":10.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":10.0,"cvss_v4":10.0,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-07.json","https://viidure.app/","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-07"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T21:19:39","euvd":{"id":"EUVD-2026-89458","description":"The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.","published_time":"2026-09-29T20:42:38","cvss":10.0,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://viidure.app/","https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-07","https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-07.json"],"products":["Dashcam Android Application"],"vendors":["Viidure"]}},{"cve_id":"CVE-2026-93853","summary":"Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots. When a snapshot backup is deleted, either explicitly or by retention policy enforcement, Barman reads the snapshot identifiers from the backup.info file and passes them to the cloud provider's delete API using Barman's own credentials, without verifying that the snapshots belong to that backup. An attacker who can overwrite backup.info but lacks snapshot delete permissions can substitute the identifiers of other snapshots, causing Barman to delete any snapshot its cloud identity can reach on AWS, Microsoft Azure, or Google Cloud. Exploitation requires a deployment where the principal that writes the backup catalog is separate from the identity Barman uses to delete snapshots. Barman versions from 3.4.0 (Google Cloud), 3.6.0 (Azure), and 3.7.0 (AWS) up to and including 3.20.0 are affected. The issue is fixed in Barman 3.20.1.","cvss":7.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.2,"epss":0.00207,"ranking_epss":0.09721,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.enterprisedb.com/docs/security/advisories/cve202693853/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T21:19:39","euvd":{"id":"EUVD-2026-89463","description":"Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots. When a snapshot backup is deleted, either explicitly or by retention policy enforcement, Barman reads the snapshot identifiers from the backup.info file and passes them to the cloud provider's delete API using Barman's own credentials, without verifying that the snapshots belong to that backup. An attacker who can overwrite backup.info but lacks snapshot delete permissions can substitute the identifiers of other snapshots, causing Barman to delete any snapshot its cloud identity can reach on AWS, Microsoft Azure, or Google Cloud. Exploitation requires a deployment where the principal that writes the backup catalog is separate from the identity Barman uses to delete snapshots. Barman versions from 3.4.0 (Google Cloud), 3.6.0 (Azure), and 3.7.0 (AWS) up to and including 3.20.0 are affected. The issue is fixed in Barman 3.20.1.","published_time":"2026-09-29T20:55:51","cvss":7.2,"cvss_version":"4.0","epss":0.0,"assigner":"EDB","references":["https://www.enterprisedb.com/docs/security/advisories/cve202693853/"],"products":["Barman"],"vendors":["EnterpriseDB"]}},{"cve_id":"CVE-2026-94952","summary":"A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formPortFw (port-forwarding configuration handler) and is triggered by the ip_subnet and fw_ip request parameters during the rule-addition flow.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":0.00141,"ranking_epss":0.02891,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/H3rmesk1t/0f2e6a120c92a37282779516b7e93e03","https://gist.github.com/H3rmesk1t/0f2e6a120c92a37282779516b7e93e03"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T21:19:39","euvd":{"id":"EUVD-2026-89470","description":"A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formPortFw (port-forwarding configuration handler) and is triggered by the ip_subnet and fw_ip request parameters during the rule-addition flow.","published_time":"2026-09-29T00:00:00","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://gist.github.com/H3rmesk1t/0f2e6a120c92a37282779516b7e93e03"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-81841","summary":"Pausing a shared (public) dashboard did not revoke its access token for the endpoints that serve frontend bootstrap data. Anyone holding the link to a paused shared dashboard could still retrieve, without authenticating, the configuration of the dashboard's data sources, including stored credentials for data sources using browser access (missing authorization). Deleting the shared dashboard does revoke the token.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":0.00372,"ranking_epss":0.28698,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://grafana.com/security/security-advisories/cve-2026-81841"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T21:19:31","euvd":{"id":"EUVD-2026-89456","description":"Pausing a shared (public) dashboard did not revoke its access token for the endpoints that serve frontend bootstrap data. Anyone holding the link to a paused shared dashboard could still retrieve, without authenticating, the configuration of the dashboard's data sources, including stored credentials for data sources using browser access (missing authorization). Deleting the shared dashboard does revoke the token.","published_time":"2026-09-29T20:35:57","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"GRAFANA","references":["https://grafana.com/security/security-advisories/cve-2026-81841"],"products":["Grafana Enterprise","Grafana Enterprise","Grafana OSS","Grafana Enterprise","Grafana OSS","Grafana OSS","Grafana OSS","Grafana Enterprise","Grafana OSS","Grafana Enterprise","Grafana Enterprise","Grafana Enterprise","Grafana Enterprise","Grafana Enterprise","Grafana OSS","Grafana OSS","Grafana OSS","Grafana OSS"],"vendors":["Grafana"]}},{"cve_id":"CVE-2026-81842","summary":"An authenticated user with edit permission on one folder can move a library panel into another folder where they only have view permission, through the library elements API or the equivalent App Platform resource. The update path did not check library panel create permission on the destination folder (incorrect authorization). No data from the destination folder is disclosed, and existing content there cannot be changed.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00198,"ranking_epss":0.08642,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://grafana.com/security/security-advisories/cve-2026-81842"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T21:19:31","euvd":{"id":"EUVD-2026-89460","description":"An authenticated user with edit permission on one folder can move a library panel into another folder where they only have view permission, through the library elements API or the equivalent App Platform resource. The update path did not check library panel create permission on the destination folder (incorrect authorization). No data from the destination folder is disclosed, and existing content there cannot be changed.","published_time":"2026-09-29T20:50:01","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"GRAFANA","references":["https://grafana.com/security/security-advisories/cve-2026-81842"],"products":["Grafana Enterprise","Grafana OSS","Grafana Enterprise","Grafana OSS","Grafana Enterprise","Grafana OSS","Grafana OSS","Grafana Enterprise","Grafana Enterprise","Grafana OSS"],"vendors":["Grafana"]}},{"cve_id":"CVE-2026-102938","summary":"virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.11, PyEnvCfg.write() writes prompt values verbatim to the line-oriented pyvenv.cfg format while PyEnvCfg._read_values() parses the file with str.splitlines() and accepts the last value for duplicate keys. An attacker who influences --prompt, VIRTUALENV_PROMPT, or configuration input can insert a recognized line boundary and additional keys, including home, causing consumers to use an attacker-selected base interpreter or corrupted environment metadata. The security impact requires prompt input from outside the operator's trust boundary; directly supplied prompt content primarily corrupts the operator's own environment. This issue is fixed in version 21.7.11.","cvss":5.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.8,"epss":0.0014,"ranking_epss":0.0279,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/pypa/virtualenv/commit/a30f995461043acb6cacbf3a890951563ccf7140","https://github.com/pypa/virtualenv/pull/3247","https://github.com/pypa/virtualenv/releases/tag/21.7.11","https://github.com/pypa/virtualenv/security/advisories/GHSA-9h9j-4vrj-gf7g"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T21:17:19","euvd":{"id":"EUVD-2026-89465","description":"virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.11, PyEnvCfg.write() writes prompt values verbatim to the line-oriented pyvenv.cfg format while PyEnvCfg._read_values() parses the file with str.splitlines() and accepts the last value for duplicate keys. An attacker who influences --prompt, VIRTUALENV_PROMPT, or configuration input can insert a recognized line boundary and additional keys, including home, causing consumers to use an attacker-selected base interpreter or corrupted environment metadata. The security impact requires prompt input from outside the operator's trust boundary; directly supplied prompt content primarily corrupts the operator's own environment. This issue is fixed in version 21.7.11.","published_time":"2026-09-29T20:58:20","cvss":5.8,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/pypa/virtualenv/security/advisories/GHSA-9h9j-4vrj-gf7g","https://github.com/pypa/virtualenv/pull/3247","https://github.com/pypa/virtualenv/commit/a30f995461043acb6cacbf3a890951563ccf7140","https://github.com/pypa/virtualenv/releases/tag/21.7.11"],"products":["virtualenv"],"vendors":["pypa"]}},{"cve_id":"CVE-2026-102620","summary":"A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation causes integer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 245d3c6823377755f2c1d5fdddd010279c6ed94d. It is suggested to install a patch to address this issue.","cvss":1.9,"cvss_version":4.0,"cvss_v2":1.7,"cvss_v3":3.3,"cvss_v4":1.9,"epss":0.00115,"ranking_epss":0.01415,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/r1ck9-2q/cve_summit/blob/main/Signed-integer-overflow-in-FoFiTrueType-cvtSfnts-FoFiTrueType.cc-1210.md","https://gitlab.freedesktop.org/poppler/poppler/-/commit/245d3c6823377755f2c1d5fdddd010279c6ed94d","https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2326","https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1762","https://vuldb.com/cve/CVE-2026-102620","https://vuldb.com/submit/942348","https://vuldb.com/vuln/411410","https://vuldb.com/vuln/411410/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T21:17:18","euvd":null},{"cve_id":"CVE-2026-102904","summary":"JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.0.0 until 4.5.11 and 4.6.4, the PyPI Extension Manager uninstall request reaches ExtensionHandler.post, which validates extension names for installation but passes uninstall names to PyPIExtensionManager.uninstall and python -m pip uninstall without rejecting option-like values. The security impact requires that the PyPI Extension Manager is enabled, the account can call the extension API, and kernels and terminals are disabled or delegated to remote hosts; otherwise the user can already read files and make outbound requests directly. An authenticated user with extension API access can supply a pip requirements option to make the server read a local file or fetch an internal URL, and reflected parse errors can return the first unparsable line or response content. A pip log option can also create or corrupt a chosen path with pip-generated log text, but the requester cannot select an arbitrary disclosed line or arbitrary file content, and the injection does not add code execution or availability impact beyond ordinary package removal. This issue is fixed in JupyterLab 4.5.11 and 4.6.4.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00206,"ranking_epss":0.09546,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/jupyterlab/jupyterlab/commit/a274a8276b9185d03efd4c3c20713d3137ac49e6","https://github.com/jupyterlab/jupyterlab/commit/e277bc958e737130ac47b6c5078d08b29298828f","https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.11","https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.4","https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-3325-v43h-43rv"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T21:17:18","euvd":{"id":"EUVD-2026-89459","description":"JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.0.0 until 4.5.11 and 4.6.4, the PyPI Extension Manager uninstall request reaches ExtensionHandler.post, which validates extension names for installation but passes uninstall names to PyPIExtensionManager.uninstall and python -m pip uninstall without rejecting option-like values. The security impact requires that the PyPI Extension Manager is enabled, the account can call the extension API, and kernels and terminals are disabled or delegated to remote hosts; otherwise the user can already read files and make outbound requests directly. An authenticated user with extension API access can supply a pip requirements option to make the server read a local file or fetch an internal URL, and reflected parse errors can return the first unparsable line or response content. A pip log option can also create or corrupt a chosen path with pip-generated log text, but the requester cannot select an arbitrary disclosed line or arbitrary file content, and the injection does not add code execution or availability impact beyond ordinary package removal. This issue is fixed in JupyterLab 4.5.11 and 4.6.4.","published_time":"2026-09-29T20:47:43","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-3325-v43h-43rv","https://github.com/jupyterlab/jupyterlab/commit/a274a8276b9185d03efd4c3c20713d3137ac49e6","https://github.com/jupyterlab/jupyterlab/commit/e277bc958e737130ac47b6c5078d08b29298828f","https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.11","https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.4"],"products":["jupyterlab","jupyterlab"],"vendors":["jupyterlab"]}},{"cve_id":"CVE-2026-102925","summary":"virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already escaped by shlex.quote inside an additional quoted context. In the bash and zsh script, a crafted virtual environment path reaches __VIRTUAL_ENV__ when a relocated environment's recorded directory is absent; in the fish script, crafted Tcl or Tk library paths reach __TCL_LIBRARY__ or __TK_LIBRARY__. The surplus quotes can terminate the data-only quoted run and leave shell metacharacters parsed as commands when a user sources the activation script, allowing code execution with that user's privileges. This issue is fixed in version 21.7.13.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":0.00153,"ranking_epss":0.03775,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/pypa/virtualenv/commit/4d5a105ec2a2723b8c7f4571bb68f4f71d01e3f6","https://github.com/pypa/virtualenv/pull/3252","https://github.com/pypa/virtualenv/releases/tag/21.7.13","https://github.com/pypa/virtualenv/security/advisories/GHSA-p58f-9548-mpm2"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T21:17:18","euvd":{"id":"EUVD-2026-89461","description":"virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already escaped by shlex.quote inside an additional quoted context. In the bash and zsh script, a crafted virtual environment path reaches __VIRTUAL_ENV__ when a relocated environment's recorded directory is absent; in the fish script, crafted Tcl or Tk library paths reach __TCL_LIBRARY__ or __TK_LIBRARY__. The surplus quotes can terminate the data-only quoted run and leave shell metacharacters parsed as commands when a user sources the activation script, allowing code execution with that user's privileges. This issue is fixed in version 21.7.13.","published_time":"2026-09-29T20:50:57","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/pypa/virtualenv/security/advisories/GHSA-p58f-9548-mpm2","https://github.com/pypa/virtualenv/pull/3252","https://github.com/pypa/virtualenv/commit/4d5a105ec2a2723b8c7f4571bb68f4f71d01e3f6","https://github.com/pypa/virtualenv/releases/tag/21.7.13"],"products":["virtualenv"],"vendors":["pypa"]}},{"cve_id":"CVE-2026-102930","summary":"virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, download_wheel() accepts pip and setuptools seed wheels fetched for periodic updates or the --download option without checking their bytes against an authoritative digest equivalent to the embedded wheels' BUNDLE_SHA256 verification. A compromised index, stale mirror, or intercepted TLS connection can substitute a different wheel under the requested distribution, version, and filename, after which virtualenv caches and seeds the attacker-controlled wheel into subsequently created environments. The verification applies to the default PyPI path and is intentionally skipped when PIP_INDEX_URL, PIP_EXTRA_INDEX_URL, or PIP_INDEX configures a custom index that may legitimately publish rebuilt wheels. This issue is fixed in version 21.7.12.","cvss":7.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.7,"epss":0.0016,"ranking_epss":0.04471,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/pypa/virtualenv/commit/a01ed3e2f239d6ab1fce62c5c7664ccf268fff6d","https://github.com/pypa/virtualenv/pull/3251","https://github.com/pypa/virtualenv/security/advisories/GHSA-94p9-xgh2-xp45"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T21:17:18","euvd":{"id":"EUVD-2026-89462","description":"virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, download_wheel() accepts pip and setuptools seed wheels fetched for periodic updates or the --download option without checking their bytes against an authoritative digest equivalent to the embedded wheels' BUNDLE_SHA256 verification. A compromised index, stale mirror, or intercepted TLS connection can substitute a different wheel under the requested distribution, version, and filename, after which virtualenv caches and seeds the attacker-controlled wheel into subsequently created environments. The verification applies to the default PyPI path and is intentionally skipped when PIP_INDEX_URL, PIP_EXTRA_INDEX_URL, or PIP_INDEX configures a custom index that may legitimately publish rebuilt wheels. This issue is fixed in version 21.7.12.","published_time":"2026-09-29T20:53:36","cvss":7.7,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/pypa/virtualenv/security/advisories/GHSA-94p9-xgh2-xp45","https://github.com/pypa/virtualenv/pull/3251","https://github.com/pypa/virtualenv/commit/a01ed3e2f239d6ab1fce62c5c7664ccf268fff6d"],"products":["virtualenv"],"vendors":["pypa"]}},{"cve_id":"CVE-2026-102937","summary":"virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, BatchActivator.quote() returns prompt text unchanged before activate.bat inserts it into a cmd.exe set \"VAR=value\" statement. An attacker who influences --prompt, VIRTUALENV_PROMPT, or the corresponding configuration value can include a double quote that closes the assignment and leaves following cmd.exe operators as executable syntax. When a user activates the generated Windows environment, the injected commands run with that user's privileges. This issue is fixed in version 21.7.12.","cvss":7.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.3,"epss":0.0014,"ranking_epss":0.0279,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/pypa/virtualenv/commit/d721ff140ce4afdc2a9b76751e4584e25d9fbea6","https://github.com/pypa/virtualenv/pull/3250","https://github.com/pypa/virtualenv/releases/tag/21.7.12","https://github.com/pypa/virtualenv/security/advisories/GHSA-x78j-v8h9-3j2q"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T21:17:18","euvd":null},{"cve_id":"CVE-2026-102253","summary":"iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an unrecoverable infinite loop by sending a single crafted control-channel parameter message followed by one 16-byte UDP datagram. Attackers can permanently pin the affected per-stream receive thread at approximately 100% CPU usage, rendering the server unusable until forcibly killed with SIGKILL, as the process does not respond to normal control-channel closure.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":0.00431,"ranking_epss":0.34906,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/esnet/iperf/blob/master/RELNOTES.md","https://github.com/esnet/iperf/releases/tag/3.22","https://www.vulncheck.com/advisories/iperf3-udp-receive-worker-infinite-loop-dos"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T21:17:13","euvd":{"id":"EUVD-2026-89415","description":"iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an unrecoverable infinite loop by sending a single crafted control-channel parameter message followed by one 16-byte UDP datagram. Attackers can permanently pin the affected per-stream receive thread at approximately 100% CPU usage, rendering the server unusable until forcibly killed with SIGKILL, as the process does not respond to normal control-channel closure.","published_time":"2026-09-29T20:11:47","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/esnet/iperf/releases/tag/3.22","https://github.com/esnet/iperf/blob/master/RELNOTES.md","https://www.vulncheck.com/advisories/iperf3-udp-receive-worker-infinite-loop-dos"],"products":["iperf3"],"vendors":["esnet"]}},{"cve_id":"CVE-2026-96274","summary":"In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS payload. Because the eNodeB does not properly validate this payload, it forwards the message to the core network, which can trigger a shutdown of the signaling association for the cell. This results in a temporary service disruption until the eNodeB and core network re-establish connectivity.","cvss":8.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.4,"cvss_v4":8.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-04"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:31","euvd":{"id":"EUVD-2026-89358","description":"In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS payload. Because the eNodeB does not properly validate this payload, it forwards the message to the core network, which can trigger a shutdown of the signaling association for the cell. This results in a temporary service disruption until the eNodeB and core network re-establish connectivity.","published_time":"2026-09-29T19:29:13","cvss":8.3,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-04"],"products":["Nova 430H eNodeB  (model pBS3101SH)"],"vendors":["Baicells"]}},{"cve_id":"CVE-2026-94953","summary":"A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formAjaxSet using the topicurl=setting/setWiFiRepeaterConfig branch and the ApCliWEPKey field.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00154,"ranking_epss":0.03934,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/H3rmesk1t/039c2c968fd535cfffecdf9626e963e2"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:28","euvd":{"id":"EUVD-2026-89364","description":"A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formAjaxSet using the topicurl=setting/setWiFiRepeaterConfig branch and the ApCliWEPKey field.","published_time":"2026-09-29T00:00:00","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://gist.github.com/H3rmesk1t/039c2c968fd535cfffecdf9626e963e2"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-79538","summary":"metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio (createTransport, STDIO branch, routers/mcp-proxy/server.ts).","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/metatool-ai/metamcp","https://www.traceforce.ai/security-advisories/cve-2026-79538"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:27","euvd":{"id":"EUVD-2026-89360","description":"metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio (createTransport, STDIO branch, routers/mcp-proxy/server.ts).","published_time":"2026-09-29T00:00:00","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/metatool-ai/metamcp","https://www.traceforce.ai/security-advisories/cve-2026-79538"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-79535","summary":"mbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The update_config MCP tool (and the \"voicemode config set\" CLI) writes a caller-supplied value into ~/.voicemode/voicemode.env without shell-safe escaping.","cvss":6.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.3,"cvss_v4":null,"epss":0.00575,"ranking_epss":0.4537,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/mbailey/voicemode/commit/c1cef85333fca497c46a11950911d10123f61e48","https://github.com/mbailey/voicemode/releases/tag/v8.10.2","https://www.traceforce.ai/security-advisories/cve-2026-79535"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:27","euvd":{"id":"EUVD-2026-89361","description":"mbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The update_config MCP tool (and the \"voicemode config set\" CLI) writes a caller-supplied value into ~/.voicemode/voicemode.env without shell-safe escaping.","published_time":"2026-09-29T00:00:00","cvss":6.3,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/mbailey/voicemode/commit/c1cef85333fca497c46a11950911d10123f61e48","https://github.com/mbailey/voicemode/releases/tag/v8.10.2","https://www.traceforce.ai/security-advisories/cve-2026-79535"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-79536","summary":"bytebase dbhub v1.2.0 was discovered to contain a SQL injection vulnerability in the /utils/sql-parser.ts component. This vulnerability allows attackers to access sensitive databse information via a crafted SQL statement.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00143,"ranking_epss":0.02992,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.traceforce.ai/security-advisories/cve-2026-79536"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:27","euvd":{"id":"EUVD-2026-89363","description":"bytebase dbhub v1.2.0 was discovered to contain a SQL injection vulnerability in the /utils/sql-parser.ts component. This vulnerability allows attackers to access sensitive databse information via a crafted SQL statement.","published_time":"2026-09-29T00:00:00","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://www.traceforce.ai/security-advisories/cve-2026-79536"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-79537","summary":"metatool-ai MetaMCP through 2.4.22 contains an insecure direct object reference (IDOR) in the MCP transport session dispatch. The session store (getSession in session-lifetime-manager.ts) is keyed only by the client-supplied mcp-session-id header with no owner, namespace, or endpoint binding, and the per-endpoint authorization middleware validates only the URL endpoint's owner, never the session. An attacker who supplies another tenant's session id \" obtained without authentication from GET /metamcp/health/sessions, which discloses active session IDs and namespace UUIDs \" can list and execute the victim tenant's private MCP tools and exfiltrate their data using the victim's forwarded credentials.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.0018,"ranking_epss":0.0679,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/metatool-ai/metamcp","https://www.traceforce.ai/security-advisories/cve-2026-79537"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:27","euvd":{"id":"EUVD-2026-89362","description":"metatool-ai MetaMCP through 2.4.22 contains an insecure direct object reference (IDOR) in the MCP transport session dispatch. The session store (getSession in session-lifetime-manager.ts) is keyed only by the client-supplied mcp-session-id header with no owner, namespace, or endpoint binding, and the per-endpoint authorization middleware validates only the URL endpoint's owner, never the session. An attacker who supplies another tenant's session id \" obtained without authentication from GET /metamcp/health/sessions, which discloses active session IDs and namespace UUIDs \" can list and execute the victim tenant's private MCP tools and exfiltrate their data using the victim's forwarded credentials.","published_time":"2026-09-29T00:00:00","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/metatool-ai/metamcp","https://www.traceforce.ai/security-advisories/cve-2026-79537"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-76736","summary":"A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service.","cvss":3.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.3,"cvss_v4":null,"epss":0.00093,"ranking_epss":0.00521,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:26","euvd":{"id":"EUVD-2026-89355","description":"A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service.","published_time":"2026-09-29T19:28:54","cvss":3.3,"cvss_version":"3.1","epss":0.0,"assigner":"hpe","references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"products":["Instant On"],"vendors":["Hewlett Packard Enterprise (HPE)"]}},{"cve_id":"CVE-2026-76737","summary":"An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service.","cvss":3.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.0,"cvss_v4":null,"epss":0.0009,"ranking_epss":0.00428,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:26","euvd":{"id":"EUVD-2026-89356","description":"An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service.","published_time":"2026-09-29T19:28:56","cvss":3.0,"cvss_version":"3.1","epss":0.0,"assigner":"hpe","references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"products":["Instant On"],"vendors":["Hewlett Packard Enterprise (HPE)"]}},{"cve_id":"CVE-2026-76738","summary":"A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which recovers without manual intervention.","cvss":2.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":2.7,"cvss_v4":null,"epss":0.00231,"ranking_epss":0.12585,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:26","euvd":{"id":"EUVD-2026-89357","description":"A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which recovers without manual intervention.","published_time":"2026-09-29T19:28:58","cvss":2.7,"cvss_version":"3.1","epss":0.0,"assigner":"hpe","references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"products":["Instant On"],"vendors":["Hewlett Packard Enterprise (HPE)"]}},{"cve_id":"CVE-2026-79348","summary":"KitchenAsty through 0.3.0 contains a broken object level authorization (IDOR) vulnerability in the reservations API. The endpoint GET /api/reservations/:id in packages/server applies the authenticate middleware but performs no ownership or role check, and the getReservation handler in packages/server/src/controllers/reservation.controller.ts returns the record retrieved by the client-supplied identifier without comparing reservation.customerId to the authenticated principal","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00217,"ranking_epss":0.10985,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/mighty840/kitchenasty","https://github.com/mighty840/kitchenasty/blob/main/packages/server/src/controllers/reservation.controller.ts","https://github.com/mighty840/kitchenasty/blob/main/packages/server/src/routes/reservation.routes.ts","https://github.com/mighty840/kitchenasty/pull/43","https://github.com/mighty840/kitchenasty/security/advisories/GHSA-2w4m-hjg2-2v92"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:26","euvd":{"id":"EUVD-2026-89425","description":"KitchenAsty through 0.3.0 contains a broken object level authorization (IDOR) vulnerability in the reservations API. The endpoint GET /api/reservations/:id in packages/server applies the authenticate middleware but performs no ownership or role check, and the getReservation handler in packages/server/src/controllers/reservation.controller.ts returns the record retrieved by the client-supplied identifier without comparing reservation.customerId to the authenticated principal","published_time":"2026-09-29T00:00:00","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/mighty840/kitchenasty","https://github.com/mighty840/kitchenasty/pull/43","https://github.com/mighty840/kitchenasty/blob/main/packages/server/src/routes/reservation.routes.ts","https://github.com/mighty840/kitchenasty/blob/main/packages/server/src/controllers/reservation.controller.ts","https://github.com/mighty840/kitchenasty/security/advisories/GHSA-2w4m-hjg2-2v92"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-79403","summary":"An issue in Kilo Code before v7.4.1 allows a local attacker to execute arbitrary code via the permission/allow-everything endpoint","cvss":8.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.4,"cvss_v4":null,"epss":0.00159,"ranking_epss":0.04362,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/akinerkisa/e345af9f9992b87247a71fdb5b36ac2c","https://github.com/Kilo-Org/kilocode/commit/51e45d7fb7","https://github.com/Kilo-Org/kilocode/pull/11887"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:26","euvd":{"id":"EUVD-2026-89423","description":"An issue in Kilo Code before v7.4.1 allows a local attacker to execute arbitrary code via the permission/allow-everything endpoint","published_time":"2026-09-29T00:00:00","cvss":8.4,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/Kilo-Org/kilocode/pull/11887","https://github.com/Kilo-Org/kilocode/commit/51e45d7fb7","https://gist.github.com/akinerkisa/e345af9f9992b87247a71fdb5b36ac2c"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-79417","summary":"Improper Access Control in ArgusMonitor.sys in Argotronic eGbR ArgusMonitor 7.4.02 and earlier allows local, low-privileged users to bypass device handle access restrictions via a TOCTOU condition in IRP_MJ_CREATE and send a crafted IOCTL 0x9C4024A8 request, causing denial-of-service.","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":0.00211,"ranking_epss":0.10266,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://connorjaydunn.github.io/blog/posts/argus-monitor-ldos-cve-2026-79417/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:26","euvd":{"id":"EUVD-2026-89424","description":"Improper Access Control in ArgusMonitor.sys in Argotronic eGbR ArgusMonitor 7.4.02 and earlier allows local, low-privileged users to bypass device handle access restrictions via a TOCTOU condition in IRP_MJ_CREATE and send a crafted IOCTL 0x9C4024A8 request, causing denial-of-service.","published_time":"2026-09-29T00:00:00","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://connorjaydunn.github.io/blog/posts/argus-monitor-ldos-cve-2026-79417/"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-79534","summary":"mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal due to an improper link resolution in validatePath (filesystemserver/handler/helper.go). When filepath.EvalSymlinks returns os.IsNotExist for a dangling symlink, the fallback validates only the parent directory and returns the unresolved path, so write_file (and modify_file, copy_file, move_file, create_directory) follows a pre-existing dangling symlink located inside an allowed directory and creates a file outside the configured allowed directories.","cvss":5.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.9,"cvss_v4":null,"epss":0.00213,"ranking_epss":0.10447,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.traceforce.ai/security-advisories/cve-2026-79534"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:26","euvd":{"id":"EUVD-2026-89359","description":"mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal due to an improper link resolution in validatePath (filesystemserver/handler/helper.go). When filepath.EvalSymlinks returns os.IsNotExist for a dangling symlink, the fallback validates only the parent directory and returns the unresolved path, so write_file (and modify_file, copy_file, move_file, create_directory) follows a pre-existing dangling symlink located inside an allowed directory and creates a file outside the configured allowed directories.","published_time":"2026-09-29T00:00:00","cvss":5.9,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://www.traceforce.ai/security-advisories/cve-2026-79534"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-76729","summary":"A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause memory corruption with a modified input. Successful exploitation could allow an attacker to provoke a denial-of-service condition or remote code execution in the affected system function.","cvss":6.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.6,"cvss_v4":null,"epss":0.00423,"ranking_epss":0.34263,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:25","euvd":{"id":"EUVD-2026-89348","description":"A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause memory corruption with a modified input. Successful exploitation could allow an attacker to provoke a denial-of-service condition or remote code execution in the affected system function.","published_time":"2026-09-29T19:28:45","cvss":6.6,"cvss_version":"3.1","epss":0.0,"assigner":"hpe","references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"products":["Instant On"],"vendors":["Hewlett Packard Enterprise (HPE)"]}},{"cve_id":"CVE-2026-76730","summary":"An authentication bypass vulnerability exists in the PAPI protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to circumvent certain existing authentication mechanisms and send unauthorized network traffic to the target device.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00206,"ranking_epss":0.0951,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:25","euvd":{"id":"EUVD-2026-89349","description":"An authentication bypass vulnerability exists in the PAPI protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to circumvent certain existing authentication mechanisms and send unauthorized network traffic to the target device.","published_time":"2026-09-29T19:28:46","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"hpe","references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"products":["Instant On"],"vendors":["Hewlett Packard Enterprise (HPE)"]}},{"cve_id":"CVE-2026-76731","summary":"An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain limited access to some data and to make limited changes within the affected component.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00314,"ranking_epss":0.2195,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:25","euvd":{"id":"EUVD-2026-89350","description":"An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain limited access to some data and to make limited changes within the affected component.","published_time":"2026-09-29T19:28:47","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"hpe","references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"products":["Instant On"],"vendors":["Hewlett Packard Enterprise (HPE)"]}},{"cve_id":"CVE-2026-76732","summary":"A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges if certain preconditions are met outside of the attacker's control.","cvss":6.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.4,"cvss_v4":null,"epss":0.00107,"ranking_epss":0.01063,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:25","euvd":{"id":"EUVD-2026-89351","description":"A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges if certain preconditions are met outside of the attacker's control.","published_time":"2026-09-29T19:28:49","cvss":6.4,"cvss_version":"3.1","epss":0.0,"assigner":"hpe","references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"products":["Instant On"],"vendors":["Hewlett Packard Enterprise (HPE)"]}},{"cve_id":"CVE-2026-76733","summary":"A denial-of-service vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which resumes without manual intervention.","cvss":4.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.9,"cvss_v4":null,"epss":0.0031,"ranking_epss":0.21504,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:25","euvd":{"id":"EUVD-2026-89352","description":"A denial-of-service vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which resumes without manual intervention.","published_time":"2026-09-29T19:28:51","cvss":4.9,"cvss_version":"3.1","epss":0.0,"assigner":"hpe","references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"products":["Instant On"],"vendors":["Hewlett Packard Enterprise (HPE)"]}},{"cve_id":"CVE-2026-76734","summary":"A memory corruption vulnerability in the affected interface of HPE Networking Instant On could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service and to access some limited information within the affected component.","cvss":4.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.8,"cvss_v4":null,"epss":0.00288,"ranking_epss":0.1928,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:25","euvd":{"id":"EUVD-2026-89353","description":"A memory corruption vulnerability in the affected interface of HPE Networking Instant On could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service and to access some limited information within the affected component.","published_time":"2026-09-29T19:28:52","cvss":4.8,"cvss_version":"3.1","epss":0.0,"assigner":"hpe","references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"products":["Instant On"],"vendors":["Hewlett Packard Enterprise (HPE)"]}},{"cve_id":"CVE-2026-76735","summary":"A sensitive information disclosure vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow an authenticated local attacker with high privileges to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Instant On, only if certain preconditions outside of the attacker's control are met.","cvss":4.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.1,"cvss_v4":null,"epss":0.00093,"ranking_epss":0.00544,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:25","euvd":{"id":"EUVD-2026-89354","description":"A sensitive information disclosure vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow an authenticated local attacker with high privileges to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Instant On, only if certain preconditions outside of the attacker's control are met.","published_time":"2026-09-29T19:28:53","cvss":4.1,"cvss_version":"3.1","epss":0.0,"assigner":"hpe","references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"products":["Instant On"],"vendors":["Hewlett Packard Enterprise (HPE)"]}},{"cve_id":"CVE-2026-76728","summary":"A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:24","euvd":{"id":"EUVD-2026-89347","description":"A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.","published_time":"2026-09-29T19:28:43","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"hpe","references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"products":["Instant On"],"vendors":["Hewlett Packard Enterprise (HPE)"]}},{"cve_id":"CVE-2026-76721","summary":"Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":0.00556,"ranking_epss":0.44236,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:24","euvd":{"id":"EUVD-2026-89340","description":"Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system.","published_time":"2026-09-29T19:28:33","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"hpe","references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"products":["Instant On"],"vendors":["Hewlett Packard Enterprise (HPE)"]}},{"cve_id":"CVE-2026-76722","summary":"Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result in a Denial-of-service or potential remote code execution.","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":0.0054,"ranking_epss":0.43258,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:24","euvd":{"id":"EUVD-2026-89341","description":"Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result in a Denial-of-service or potential remote code execution.","published_time":"2026-09-29T19:28:34","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"hpe","references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"products":["Instant On"],"vendors":["Hewlett Packard Enterprise (HPE)"]}},{"cve_id":"CVE-2026-76723","summary":"Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS that could allow an unauthenticated adjacent attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.0031,"ranking_epss":0.21495,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:24","euvd":{"id":"EUVD-2026-89342","description":"Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS that could allow an unauthenticated adjacent attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.","published_time":"2026-09-29T19:28:35","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"hpe","references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"products":["Instant On"],"vendors":["Hewlett Packard Enterprise (HPE)"]}},{"cve_id":"CVE-2026-76724","summary":"A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00811,"ranking_epss":0.55313,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:24","euvd":{"id":"EUVD-2026-89343","description":"A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.","published_time":"2026-09-29T19:28:37","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"hpe","references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"products":["Instant On"],"vendors":["Hewlett Packard Enterprise (HPE)"]}},{"cve_id":"CVE-2026-76725","summary":"A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could result in a complete bypass of security restrictions, potentially leading to remote code execution with elevated privileges.","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.0032,"ranking_epss":0.22656,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:24","euvd":{"id":"EUVD-2026-89344","description":"A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could result in a complete bypass of security restrictions, potentially leading to remote code execution with elevated privileges.","published_time":"2026-09-29T19:28:39","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"hpe","references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"products":["Instant On"],"vendors":["Hewlett Packard Enterprise (HPE)"]}},{"cve_id":"CVE-2026-76726","summary":"An authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow an unauthenticated remote attacker to bypass network access controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to obtain unauthorized access to restricted networks.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":0.00367,"ranking_epss":0.2819,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:24","euvd":{"id":"EUVD-2026-89345","description":"An authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow an unauthenticated remote attacker to bypass network access controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to obtain unauthorized access to restricted networks.","published_time":"2026-09-29T19:28:40","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"hpe","references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"products":["Instant On"],"vendors":["Hewlett Packard Enterprise (HPE)"]}},{"cve_id":"CVE-2026-76727","summary":"Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":0.00907,"ranking_epss":0.5839,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:24","euvd":{"id":"EUVD-2026-89346","description":"Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.","published_time":"2026-09-29T19:28:41","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"hpe","references":["https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"],"products":["Instant On"],"vendors":["Hewlett Packard Enterprise (HPE)"]}},{"cve_id":"CVE-2026-67993","summary":"basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains a login cross-site request forgery issue in the static credentials callback.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00155,"ranking_epss":0.0402,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/basecamp/upright","https://github.com/basecamp/upright/blob/efe4f2e5254ac6e57e45d2261804cca74dbbca3f/app/controllers/upright/sessions_controller.rb#L3"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:23","euvd":{"id":"EUVD-2026-89426","description":"basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains a login cross-site request forgery issue in the static credentials callback.","published_time":"2026-09-29T00:00:00","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://github.com/basecamp/upright","https://github.com/basecamp/upright/blob/efe4f2e5254ac6e57e45d2261804cca74dbbca3f/app/controllers/upright/sessions_controller.rb#L3"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-67987","summary":"crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains polynomial-time regular expression denial-of-service conditions in think-tag response parsing on Ruby 3.1.x. A malicious or anomalous model response containing many unterminated <think> tags can cause excessive CPU consumption in two consecutive regular expressions and delay chat-completion processing","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00166,"ranking_epss":0.05235,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/crmne/ruby_llm","https://github.com/crmne/ruby_llm/blob/fa6f279847d6d7027814539d9c0dfc3bbdfd2a83/lib/ruby_llm/protocols/chat_completions/chat.rb#L355-L356","https://github.com/crmne/ruby_llm/commit/5e88411f171721b381853fa77d254e266dcf6ad8"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:22","euvd":null},{"cve_id":"CVE-2026-61519","summary":"Liberu CRM 0.9.1 before 10.0.0 contains a broken access control vulnerability that allows any user holding a pending team invitation to invite additional attacker-controlled accounts with elevated privileges by exploiting a flawed authorization predicate in TeamPolicy::addTeamMember() that grants invitation rights based solely on the existence of a pending invitation email match. Attackers can send a POST request to the team-invitations route specifying the admin role for a second account, bypassing privilege-level validation in InviteTeamMember, causing the second account upon invitation acceptance to be attached to the team with full admin-level create, read, update, and delete access over all team-scoped data.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":8.7,"epss":0.00379,"ranking_epss":0.29417,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/liberusoftware/crm-laravel/commit/0846d067ae2e9c437e8555e54a4ec6517927b3d4","https://github.com/liberusoftware/crm-laravel/issues/708","https://github.com/liberusoftware/crm-laravel/releases/tag/v10.0.0","https://www.vulncheck.com/advisories/liberu-crm-broken-access-control-via-teampolicy-addteammember"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:21","euvd":{"id":"EUVD-2026-89339","description":"Liberu CRM 0.9.1 before 10.0.0 contains a broken access control vulnerability that allows any user holding a pending team invitation to invite additional attacker-controlled accounts with elevated privileges by exploiting a flawed authorization predicate in TeamPolicy::addTeamMember() that grants invitation rights based solely on the existence of a pending invitation email match. Attackers can send a POST request to the team-invitations route specifying the admin role for a second account, bypassing privilege-level validation in InviteTeamMember, causing the second account upon invitation acceptance to be attached to the team with full admin-level create, read, update, and delete access over all team-scoped data.","published_time":"2026-09-29T19:13:13","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/liberusoftware/crm-laravel/issues/708","https://github.com/liberusoftware/crm-laravel/releases/tag/v10.0.0","https://github.com/liberusoftware/crm-laravel/commit/0846d067ae2e9c437e8555e54a4ec6517927b3d4","https://www.vulncheck.com/advisories/liberu-crm-broken-access-control-via-teampolicy-addteammember"],"products":["Liberu CRM"],"vendors":["Liberu Software"]}},{"cve_id":"CVE-2026-39117","summary":"An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary code via the index.php","cvss":9.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.glimmernet.com/security/gt-2026-001-ssrf-66uptime-ping-servers/","https://www.glimmernet.com/security/gt-2026-001-ssrf-66uptime-ping-servers/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:20","euvd":{"id":"EUVD-2026-89416","description":"An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary code via the index.php","published_time":"2026-09-29T00:00:00","cvss":9.8,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://www.glimmernet.com/security/gt-2026-001-ssrf-66uptime-ping-servers/"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-53988","summary":"Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting a null webhook secret guard condition. Attackers can enumerate sequential stack IDs and send unsigned webhook requests to force git clone and docker compose operations, enabling denial of service or, when combined with write access to the tracked git branch, container escape and full host compromise via attacker-controlled docker-compose.yml with privileged bind mounts.","cvss":9.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":10.0,"cvss_v4":9.2,"epss":0.00454,"ranking_epss":0.37053,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Finsys/dockhand/releases/tag/v1.0.40","https://www.vulncheck.com/advisories/dockhand-unauthenticated-webhook-trigger-via-git-webhook-endpoints"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:20","euvd":null},{"cve_id":"CVE-2026-53989","summary":"Dockhand before 1.0.36 contains an open redirect vulnerability in the OIDC initiation endpoint that allows unauthenticated remote attackers to redirect authenticated users to attacker-controlled sites by injecting an unvalidated redirect query parameter. Attackers can craft a malicious link targeting the OIDC callback flow to capture authorization codes via the Referer header and conduct follow-up credential phishing against any Dockhand account after a legitimate login.","cvss":5.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":4.7,"cvss_v4":5.3,"epss":0.00258,"ranking_epss":0.15776,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Finsys/dockhand/releases/tag/v1.0.36","https://www.vulncheck.com/advisories/dockhand-open-redirect-via-oidc-initiation-endpoint"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:20","euvd":null},{"cve_id":"CVE-2026-102876","summary":"SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials against Surreal-Auth-NS and Surreal-Auth-DB headers but constructs sessions using Surreal-NS and Surreal-DB headers without validating access permissions. Attackers can authenticate as a user from one tenant while selecting another tenant's namespace and database to read, create, and modify records across tenant boundaries.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":8.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/surrealdb/surrealdb","https://github.com/surrealdb/surrealdb/blob/v3.2.4/surrealdb/server/src/ntw/auth.rs","https://github.com/surrealdb/surrealdb/commit/5000e233b4a8b96689c82715c172061dcf711d31","https://github.com/surrealdb/surrealdb/releases/tag/v3.3.0","https://github.com/surrealdb/surrealdb/security/advisories/GHSA-vx2p-7hhm-wv62","https://www.vulncheck.com/advisories/surrealdb-before-3.3.0-cross-tenant-access-via-headers"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:18","euvd":{"id":"EUVD-2026-89411","description":"SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials against Surreal-Auth-NS and Surreal-Auth-DB headers but constructs sessions using Surreal-NS and Surreal-DB headers without validating access permissions. Attackers can authenticate as a user from one tenant while selecting another tenant's namespace and database to read, create, and modify records across tenant boundaries.","published_time":"2026-09-29T20:01:06","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/surrealdb/surrealdb/security/advisories/GHSA-vx2p-7hhm-wv62","https://github.com/surrealdb/surrealdb/commit/5000e233b4a8b96689c82715c172061dcf711d31","https://github.com/surrealdb/surrealdb/blob/v3.2.4/surrealdb/server/src/ntw/auth.rs","https://github.com/surrealdb/surrealdb/releases/tag/v3.3.0","https://github.com/surrealdb/surrealdb","https://www.vulncheck.com/advisories/surrealdb-before-3.3.0-cross-tenant-access-via-headers"],"products":["surrealdb"],"vendors":["surrealdb"]}},{"cve_id":"CVE-2026-11415","summary":"Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":[],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:18","euvd":null},{"cve_id":"CVE-2026-102875","summary":"VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to write arbitrary files with VLC user privileges, enabling code execution through Lua script injection.","cvss":8.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":8.5,"epss":0.00167,"ranking_epss":0.05417,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://code.videolan.org/videolan/vlc","https://code.videolan.org/videolan/vlc/-/blob/3.0.23/modules/gui/skins2/src/theme_loader.cpp","https://code.videolan.org/videolan/vlc/-/commit/59934edbd03c6c1147d75d6c91e96633b710ec31","https://code.videolan.org/videolan/vlc/-/commit/8d43e99c2c01d9aab3ecad00e7a102806262b06b","https://www.vulncheck.com/advisories/vlc-media-player-before-3.0.24-path-traversal-via-skins2"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:18","euvd":{"id":"EUVD-2026-89410","description":"VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to write arbitrary files with VLC user privileges, enabling code execution through Lua script injection.","published_time":"2026-09-29T20:01:05","cvss":8.5,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://code.videolan.org/videolan/vlc/-/commit/59934edbd03c6c1147d75d6c91e96633b710ec31","https://code.videolan.org/videolan/vlc/-/commit/8d43e99c2c01d9aab3ecad00e7a102806262b06b","https://code.videolan.org/videolan/vlc/-/blob/3.0.23/modules/gui/skins2/src/theme_loader.cpp","https://code.videolan.org/videolan/vlc","https://www.vulncheck.com/advisories/vlc-media-player-before-3.0.24-path-traversal-via-skins2"],"products":["VLC"],"vendors":["VideoLAN"]}},{"cve_id":"CVE-2026-102877","summary":"Fider before 0.38.0 contains a server-side request forgery vulnerability due to a time-of-check time-of-use gap in URL validation for webhooks and custom OAuth provider endpoints. Administrators controlling DNS can perform DNS rebinding attacks to make the Fider server send requests to internal services or cloud metadata endpoints.","cvss":2.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":4.4,"cvss_v4":2.1,"epss":0.00209,"ranking_epss":0.10053,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/getfider/fider","https://github.com/getfider/fider/blob/v0.37.0/app/pkg/validate/general.go","https://github.com/getfider/fider/blob/v0.37.0/app/services/httpclient/httpclient.go","https://github.com/getfider/fider/commit/45f5627b9fd15b912fb9092635c863fb4c91dd69","https://github.com/getfider/fider/releases/tag/v0.38.0","https://github.com/getfider/fider/security/advisories/GHSA-whx4-hxwq-qgjh","https://www.vulncheck.com/advisories/fider-before-0.38.0-ssrf-via-dns-rebinding-in-webhook-validation"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:18","euvd":{"id":"EUVD-2026-89412","description":"Fider before 0.38.0 contains a server-side request forgery vulnerability due to a time-of-check time-of-use gap in URL validation for webhooks and custom OAuth provider endpoints. Administrators controlling DNS can perform DNS rebinding attacks to make the Fider server send requests to internal services or cloud metadata endpoints.","published_time":"2026-09-29T20:01:06","cvss":2.1,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/getfider/fider/security/advisories/GHSA-whx4-hxwq-qgjh","https://github.com/getfider/fider/commit/45f5627b9fd15b912fb9092635c863fb4c91dd69","https://github.com/getfider/fider/blob/v0.37.0/app/pkg/validate/general.go","https://github.com/getfider/fider/blob/v0.37.0/app/services/httpclient/httpclient.go","https://github.com/getfider/fider/releases/tag/v0.38.0","https://github.com/getfider/fider","https://www.vulncheck.com/advisories/fider-before-0.38.0-ssrf-via-dns-rebinding-in-webhook-validation"],"products":["fider"],"vendors":["getfider"]}},{"cve_id":"CVE-2026-102878","summary":"mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions. Attackers can craft malicious web pages that make cross-origin requests to the local server and invoke browser automation tools including script execution, page content reading, and screenshot capture.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":8.6,"epss":0.00235,"ranking_epss":0.13054,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/hangwin/mcp-chrome","https://github.com/hangwin/mcp-chrome/blob/v1.0.0/app/native-server/src/server/index.ts","https://github.com/hangwin/mcp-chrome/issues/384","https://www.vulncheck.com/advisories/mcp-chrome-bridge-through-1.0.31-cors-origin-bypass","https://github.com/hangwin/mcp-chrome/issues/384"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:18","euvd":null},{"cve_id":"CVE-2026-102879","summary":"ClaraVerse through 0.3.1 contains server-side request forgery protection bypasses in the download_file and scrape_web agent tools. Authenticated users can bypass hostname validation and IPv6 transition address filtering to make the server request internal services and cloud instance metadata endpoints.","cvss":5.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.0,"cvss_v4":5.3,"epss":0.00233,"ranking_epss":0.1281,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/claraverse-space/ClaraVerse","https://github.com/claraverse-space/ClaraVerse/blob/v0.3.1/backend/internal/security/ssrf.go","https://github.com/claraverse-space/ClaraVerse/blob/v0.3.1/backend/internal/tools/download_file_tool.go","https://github.com/claraverse-space/ClaraVerse/issues/254","https://www.vulncheck.com/advisories/claraverse-through-0.3.1-ssrf-protection-bypass"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:18","euvd":{"id":"EUVD-2026-89414","description":"ClaraVerse through 0.3.1 contains server-side request forgery protection bypasses in the download_file and scrape_web agent tools. Authenticated users can bypass hostname validation and IPv6 transition address filtering to make the server request internal services and cloud instance metadata endpoints.","published_time":"2026-09-29T20:01:09","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/claraverse-space/ClaraVerse/issues/254","https://github.com/claraverse-space/ClaraVerse/blob/v0.3.1/backend/internal/tools/download_file_tool.go","https://github.com/claraverse-space/ClaraVerse/blob/v0.3.1/backend/internal/security/ssrf.go","https://github.com/claraverse-space/ClaraVerse","https://www.vulncheck.com/advisories/claraverse-through-0.3.1-ssrf-protection-bypass"],"products":["ClaraVerse"],"vendors":["claraverse-space"]}},{"cve_id":"CVE-2026-102327","summary":"Incorrect authorization in WebView in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00266,"ranking_epss":0.16691,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/496212975"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:16","euvd":{"id":"EUVD-2026-89401","description":"Incorrect authorization in WebView in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)","published_time":"2026-09-29T19:45:07","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/496212975"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102327","summary":"Incorrect authorization in WebView in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00266,"ranking_epss":0.16691,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/496212975"],"vendor":"google","product":"android","version":null,"published_time":"2026-09-29T20:17:16","euvd":{"id":"EUVD-2026-89401","description":"Incorrect authorization in WebView in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)","published_time":"2026-09-29T19:45:07","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/496212975"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102328","summary":"Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.003,"ranking_epss":0.20465,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/560536732"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:16","euvd":{"id":"EUVD-2026-89387","description":"Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T19:45:04","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/560536732"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102329","summary":"Cross-site scripting in WebUI in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: High)","cvss":6.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.1,"cvss_v4":null,"epss":0.00237,"ranking_epss":0.13339,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/563297615"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:16","euvd":{"id":"EUVD-2026-89395","description":"Cross-site scripting in WebUI in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T19:45:05","cvss":6.1,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/563297615"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102330","summary":"Incorrect authorization in SiteIsolation in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00225,"ranking_epss":0.11953,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/498793976"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:16","euvd":{"id":"EUVD-2026-89402","description":"Incorrect authorization in SiteIsolation in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)","published_time":"2026-09-29T19:45:07","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/498793976"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102331","summary":"Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00396,"ranking_epss":0.31382,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/551673541"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:16","euvd":{"id":"EUVD-2026-89373","description":"Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","published_time":"2026-09-29T19:45:01","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/551673541"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102331","summary":"Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00396,"ranking_epss":0.31382,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/551673541"],"vendor":"google","product":"android","version":null,"published_time":"2026-09-29T20:17:16","euvd":{"id":"EUVD-2026-89373","description":"Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","published_time":"2026-09-29T19:45:01","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/551673541"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102318","summary":"Out of bounds read in WebGL in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":4.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.7,"cvss_v4":null,"epss":0.0019,"ranking_epss":0.07742,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/562279351"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:15","euvd":null},{"cve_id":"CVE-2026-102319","summary":"Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":3.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.4,"cvss_v4":null,"epss":0.00199,"ranking_epss":0.08799,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/562042411"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:15","euvd":null},{"cve_id":"CVE-2026-102320","summary":"Missing authorization in CORS in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00225,"ranking_epss":0.11953,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/554038924"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:15","euvd":{"id":"EUVD-2026-89399","description":"Missing authorization in CORS in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T19:45:06","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/554038924"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102321","summary":"Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.003,"ranking_epss":0.20466,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/565328105"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:15","euvd":{"id":"EUVD-2026-89398","description":"Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T19:45:06","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/565328105"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102323","summary":"Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.0036,"ranking_epss":0.27367,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/559266114"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:15","euvd":{"id":"EUVD-2026-89380","description":"Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T19:45:03","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/559266114"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102324","summary":"Use after free in PictureInPicture in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":8.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.3,"cvss_v4":null,"epss":0.00261,"ranking_epss":0.16195,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/562174487"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:15","euvd":{"id":"EUVD-2026-89393","description":"Use after free in PictureInPicture in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T19:45:05","cvss":8.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/562174487"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102325","summary":"Uninitialized resource in Skia in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00207,"ranking_epss":0.09684,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/561994362"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:15","euvd":null},{"cve_id":"CVE-2026-102326","summary":"Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.003,"ranking_epss":0.20465,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/560233248"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:15","euvd":{"id":"EUVD-2026-89384","description":"Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T19:45:03","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/560233248"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102310","summary":"Missing authorization in Payments in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00225,"ranking_epss":0.11953,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/477726837"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:14","euvd":{"id":"EUVD-2026-89400","description":"Missing authorization in Payments in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)","published_time":"2026-09-29T19:45:06","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/477726837"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102311","summary":"Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":3.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.4,"cvss_v4":null,"epss":0.00236,"ranking_epss":0.13219,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/559737160"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:14","euvd":null},{"cve_id":"CVE-2026-102311","summary":"Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":3.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.4,"cvss_v4":null,"epss":0.00236,"ranking_epss":0.13219,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/559737160"],"vendor":"google","product":"android","version":null,"published_time":"2026-09-29T20:17:14","euvd":null},{"cve_id":"CVE-2026-102312","summary":"UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: High)","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00224,"ranking_epss":0.11742,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/551668264"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:14","euvd":{"id":"EUVD-2026-89375","description":"UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T19:45:02","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/551668264"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102312","summary":"UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: High)","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00224,"ranking_epss":0.11742,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/551668264"],"vendor":"google","product":"android","version":null,"published_time":"2026-09-29T20:17:14","euvd":{"id":"EUVD-2026-89375","description":"UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T19:45:02","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/551668264"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102313","summary":"Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":4.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.7,"cvss_v4":null,"epss":0.00245,"ranking_epss":0.14187,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/556789073"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:14","euvd":null},{"cve_id":"CVE-2026-102313","summary":"Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":4.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.7,"cvss_v4":null,"epss":0.00245,"ranking_epss":0.14187,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/556789073"],"vendor":"microsoft","product":"windows","version":null,"published_time":"2026-09-29T20:17:14","euvd":null},{"cve_id":"CVE-2026-102314","summary":"UI misrepresentation in TabStrip in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00184,"ranking_epss":0.07189,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/514059780"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:14","euvd":null},{"cve_id":"CVE-2026-102315","summary":"Uninitialized resource in Media in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":3.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.4,"cvss_v4":null,"epss":0.00199,"ranking_epss":0.08799,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/563351482"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:14","euvd":null},{"cve_id":"CVE-2026-102315","summary":"Uninitialized resource in Media in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":3.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.4,"cvss_v4":null,"epss":0.00199,"ranking_epss":0.08799,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/563351482"],"vendor":"microsoft","product":"windows","version":null,"published_time":"2026-09-29T20:17:14","euvd":null},{"cve_id":"CVE-2026-102316","summary":"Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00275,"ranking_epss":0.1794,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/560238698"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:14","euvd":{"id":"EUVD-2026-89385","description":"Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T19:45:04","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/560238698"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102317","summary":"Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)","cvss":8.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":null,"epss":0.00088,"ranking_epss":0.0037,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/517312707"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:14","euvd":{"id":"EUVD-2026-89374","description":"Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)","published_time":"2026-09-29T19:45:01","cvss":8.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/517312707"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102317","summary":"Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)","cvss":8.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":null,"epss":0.00088,"ranking_epss":0.0037,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/517312707"],"vendor":"microsoft","product":"windows","version":null,"published_time":"2026-09-29T20:17:14","euvd":{"id":"EUVD-2026-89374","description":"Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)","published_time":"2026-09-29T19:45:01","cvss":8.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/517312707"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102302","summary":"Buffer overflow in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00308,"ranking_epss":0.21262,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/563716534"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:13","euvd":{"id":"EUVD-2026-89397","description":"Buffer overflow in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T19:45:06","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/563716534"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102303","summary":"Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00245,"ranking_epss":0.14187,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/559727039"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:13","euvd":null},{"cve_id":"CVE-2026-102303","summary":"Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00245,"ranking_epss":0.14187,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/559727039"],"vendor":"google","product":"android","version":null,"published_time":"2026-09-29T20:17:13","euvd":null},{"cve_id":"CVE-2026-102304","summary":"Use after free in Passwords in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00275,"ranking_epss":0.17941,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/560251736"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:13","euvd":{"id":"EUVD-2026-89386","description":"Use after free in Passwords in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T19:45:04","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/560251736"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102305","summary":"UI misrepresentation in SignIn in Google Chrome on on iOS prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00184,"ranking_epss":0.07189,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/533021953"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:13","euvd":null},{"cve_id":"CVE-2026-102305","summary":"UI misrepresentation in SignIn in Google Chrome on on iOS prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00184,"ranking_epss":0.07189,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/533021953"],"vendor":"apple","product":"iphone_os","version":null,"published_time":"2026-09-29T20:17:13","euvd":null},{"cve_id":"CVE-2026-102306","summary":"Use after free in Bluetooth in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.0033,"ranking_epss":0.23665,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/556926296"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:13","euvd":{"id":"EUVD-2026-89378","description":"Use after free in Bluetooth in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T19:45:02","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/556926296"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102307","summary":"Uninitialized resource in Dawn in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":4.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.7,"cvss_v4":null,"epss":0.00245,"ranking_epss":0.14188,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/556959073"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:13","euvd":null},{"cve_id":"CVE-2026-102307","summary":"Uninitialized resource in Dawn in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":4.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.7,"cvss_v4":null,"epss":0.00245,"ranking_epss":0.14188,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/556959073"],"vendor":"google","product":"android","version":null,"published_time":"2026-09-29T20:17:13","euvd":null},{"cve_id":"CVE-2026-102308","summary":"Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00275,"ranking_epss":0.1794,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/561997480"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:13","euvd":{"id":"EUVD-2026-89390","description":"Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T19:45:05","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/561997480"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102309","summary":"Use after free in FullScreen in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00275,"ranking_epss":0.17941,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/560867085"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:13","euvd":{"id":"EUVD-2026-89388","description":"Use after free in FullScreen in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T19:45:04","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/560867085"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102300","summary":"Uninitialized resource in WebGPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/560062638"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:12","euvd":{"id":"EUVD-2026-89383","description":"Uninitialized resource in WebGPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T19:45:03","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/560062638"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102299","summary":"Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.0036,"ranking_epss":0.27367,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/556908674"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:12","euvd":{"id":"EUVD-2026-89377","description":"Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T19:45:02","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/556908674"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102301","summary":"Out of bounds write in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":8.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.3,"cvss_v4":null,"epss":0.00261,"ranking_epss":0.16195,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/562004351"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:12","euvd":{"id":"EUVD-2026-89391","description":"Out of bounds write in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T19:45:05","cvss":8.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html","https://issues.chromium.org/issues/562004351"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-102252","summary":"A path traversal vulnerability (CWE-22) in the embedded VMDK filesystem extractor in Google OSV-SCALIBR versions 0.3.6 through 0.5.0 allows an attacker who controls the scan target to write arbitrary files to the host system. When scanning crafted VMDK images, insufficient validation of archive path entries allows file extractions to escape destination directories.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.9,"epss":0.00088,"ranking_epss":0.00376,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/google/osv-scalibr/pull/2030"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:11","euvd":{"id":"EUVD-2026-89370","description":"A path traversal vulnerability (CWE-22) in the embedded VMDK filesystem extractor in Google OSV-SCALIBR versions 0.3.6 through 0.5.0 allows an attacker who controls the scan target to write arbitrary files to the host system. When scanning crafted VMDK images, insufficient validation of archive path entries allows file extractions to escape destination directories.","published_time":"2026-09-29T19:41:42","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"Google","references":["https://github.com/google/osv-scalibr/pull/2030"],"products":["osv-scalibr"],"vendors":["Google"]}},{"cve_id":"CVE-2026-100296","summary":"In Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4, an empty-body POST to /setUserConfig, dispatched through the web server's SOAP-RPC handler, silently downgrades the administrator password to the default value and corrupts the in-memory authentication state until the device reloads. The handler does not verify the session's privilege level, so any authenticated user can trigger it.","cvss":7.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":7.2,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:10","euvd":{"id":"EUVD-2026-89405","description":"In Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4, an empty-body POST to /setUserConfig, dispatched through the web server's SOAP-RPC handler, silently downgrades the administrator password to the default value and corrupts the in-memory authentication state until the device reloads. The handler does not verify the session's privilege level, so any authenticated user can trigger it.","published_time":"2026-09-29T19:46:35","cvss":7.2,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05"],"products":["YSSD-RTMP-H5"],"vendors":["Anjvision"]}},{"cve_id":"CVE-2026-100297","summary":"In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an unauthenticated network check function can be triggered to probe arbitrary hosts from the device’s internal network. This may expose internal information or leak data via DNS queries.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":6.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:10","euvd":{"id":"EUVD-2026-89406","description":"In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an unauthenticated network check function can be triggered to probe arbitrary hosts from the device’s internal network. This may expose internal information or leak data via DNS queries.","published_time":"2026-09-29T19:48:42","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05"],"products":["YSSD-RTMP-H5"],"vendors":["Anjvision"]}},{"cve_id":"CVE-2026-100298","summary":"In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, two user‑information endpoints can reveal sensitive device and account details under conditions that are not intended for normal operation.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:10","euvd":{"id":"EUVD-2026-89407","description":"In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, two user‑information endpoints can reveal sensitive device and account details under conditions that are not intended for normal operation.","published_time":"2026-09-29T19:50:40","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05"],"products":["YSSD-RTMP-H5"],"vendors":["Anjvision"]}},{"cve_id":"CVE-2026-100299","summary":"In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the device includes a legacy password hash on the serial console that relies on a weak DES‑based encryption.","cvss":7.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.8,"cvss_v4":7.0,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:10","euvd":{"id":"EUVD-2026-89408","description":"In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the device includes a legacy password hash on the serial console that relies on a weak DES‑based encryption.","published_time":"2026-09-29T19:52:15","cvss":7.0,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05"],"products":["YSSD-RTMP-H5"],"vendors":["Anjvision"]}},{"cve_id":"CVE-2026-100291","summary":"In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":9.8,"cvss_v4":9.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:09","euvd":{"id":"EUVD-2026-89366","description":"In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations.","published_time":"2026-09-29T19:34:23","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05"],"products":["YSSD-RTMP-H5"],"vendors":["Anjvision"]}},{"cve_id":"CVE-2026-100292","summary":"In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through an authenticated request, allowing additional commands to be sent to a backend service. Once active, this pathway can unintentionally expose system‑level functionality that could be misused if crafted inputs reach the underlying command handler.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:09","euvd":{"id":"EUVD-2026-89367","description":"In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through an authenticated request, allowing additional commands to be sent to a backend service. Once active, this pathway can unintentionally expose system‑level functionality that could be misused if crafted inputs reach the underlying command handler.","published_time":"2026-09-29T19:35:35","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05"],"products":["YSSD-RTMP-H5"],"vendors":["Anjvision"]}},{"cve_id":"CVE-2026-100293","summary":"In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud update mechanisms apply new firmware without any cryptographic verification, relying only on basic hashing. This design allows an attacker who can reach the update routine to introduce untrusted firmware images that the device will accept as valid.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:09","euvd":{"id":"EUVD-2026-89368","description":"In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud update mechanisms apply new firmware without any cryptographic verification, relying only on basic hashing. This design allows an attacker who can reach the update routine to introduce untrusted firmware images that the device will accept as valid.","published_time":"2026-09-29T19:37:13","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05"],"products":["YSSD-RTMP-H5"],"vendors":["Anjvision"]}},{"cve_id":"CVE-2026-100294","summary":"In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed devices. Anyone obtaining the public firmware package can reuse these values to interact with the cloud service in ways not intended for normal operation.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:09","euvd":{"id":"EUVD-2026-89369","description":"In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed devices. Anyone obtaining the public firmware package can reuse these values to interact with the cloud service in ways not intended for normal operation.","published_time":"2026-09-29T19:40:12","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05"],"products":["YSSD-RTMP-H5"],"vendors":["Anjvision"]}},{"cve_id":"CVE-2026-100295","summary":"In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an internal debug interface can be enabled through an undocumented pathway, exposing functions not intended for normal operation. When activated, this interface allows actions that could unintentionally provide elevated system access.","cvss":5.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.3,"cvss_v4":5.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:09","euvd":{"id":"EUVD-2026-89372","description":"In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an internal debug interface can be enabled through an undocumented pathway, exposing functions not intended for normal operation. When activated, this interface allows actions that could unintentionally provide elevated system access.","published_time":"2026-09-29T19:44:20","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"icscert","references":["https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-05"],"products":["YSSD-RTMP-H5"],"vendors":["Anjvision"]}},{"cve_id":"CVE-2024-31027","summary":"Cross Site Scripting vulnerability in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote attacker to execute arbitrary code via the last name, first name, and username parameters in the user registration functionality.","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00208,"ranking_epss":0.09868,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://panagiotiscp.github.io/cve-2024-31027-stored-xss-user-info/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:08","euvd":{"id":"EUVD-2024-55777","description":"Cross Site Scripting vulnerability in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote attacker to execute arbitrary code via the last name, first name, and username parameters in the user registration functionality.","published_time":"2026-09-29T00:00:00","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://panagiotiscp.github.io/cve-2024-31027-stored-xss-user-info/"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2024-31026","summary":"An issue in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote attacker to execute arbitrary code via the chat input field in the course module.","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00208,"ranking_epss":0.09869,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://panagiotiscp.github.io/cve-2024-31026-html-injection/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T20:17:07","euvd":null},{"cve_id":"CVE-2026-102830","summary":"JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 3.0.0 until 4.5.11 and 4.6.4, and in JupyterLite Core 0.8.3 and earlier, the Plural-Forms header in a selected third-party language pack can append JavaScript after a valid plural rule because prefix-only regular-expression validation accepts a matching prefix without requiring the entire header to match. JupyterLab passes the accepted expression to new Function, so loading the catalogue and translating a plural string executes the appended code in the authenticated JupyterLab origin. Where Jupyter Server kernels, terminals, and APIs are exposed, the code can use authenticated server APIs to read or modify files and run code. Impact is much more limited in JupyterLite because it typically lacks most exposed Jupyter Server surfaces. The default English locale is unaffected because it does not load a translation catalogue. This issue is fixed in JupyterLab 4.5.11 and 4.6.4 and JupyterLite Core 0.8.4.","cvss":6.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/jupyterlab/jupyterlab/commit/985a3223cd77fd4f991cd90066342a90711d70f6","https://github.com/jupyterlab/jupyterlab/commit/de324ae91346c713c4f5e5485f97b6e914e0f774","https://github.com/jupyterlab/jupyterlab/commit/f9de43dc565a1118120d466117f877a189a4ce90","https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.11","https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.4","https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-3jqq-pw4j-pqcj"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T19:17:25","euvd":{"id":"EUVD-2026-89337","description":"JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 3.0.0 until 4.5.11 and 4.6.4, and in JupyterLite Core 0.8.3 and earlier, the Plural-Forms header in a selected third-party language pack can append JavaScript after a valid plural rule because prefix-only regular-expression validation accepts a matching prefix without requiring the entire header to match. JupyterLab passes the accepted expression to new Function, so loading the catalogue and translating a plural string executes the appended code in the authenticated JupyterLab origin. Where Jupyter Server kernels, terminals, and APIs are exposed, the code can use authenticated server APIs to read or modify files and run code. Impact is much more limited in JupyterLite because it typically lacks most exposed Jupyter Server surfaces. The default English locale is unaffected because it does not load a translation catalogue. This issue is fixed in JupyterLab 4.5.11 and 4.6.4 and JupyterLite Core 0.8.4.","published_time":"2026-09-29T18:53:19","cvss":6.8,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-3jqq-pw4j-pqcj","https://github.com/jupyterlab/jupyterlab/commit/985a3223cd77fd4f991cd90066342a90711d70f6","https://github.com/jupyterlab/jupyterlab/commit/de324ae91346c713c4f5e5485f97b6e914e0f774","https://github.com/jupyterlab/jupyterlab/commit/f9de43dc565a1118120d466117f877a189a4ce90","https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.11","https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.4"],"products":["jupyterlab","jupyterlite-core","jupyterlab"],"vendors":["jupyterlab"]}},{"cve_id":"CVE-2026-102827","summary":"simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin compares parsed option names with literal dangerous option spellings while Git accepts unambiguous long-option abbreviations. Attacker-influenced push arguments such as abbreviated --receive-pack or --exec forms can therefore bypass detectVulnerableFlags, reach git push against a local or file remote or an attacker-influenced receive-pack target, and cause Git to invoke an attacker-selected command in consumers that expose those arguments. The clone-side abbreviation handling does not protect the push path. This issue is fixed in 4.0.0.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":0.00363,"ranking_epss":0.2772,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/steveukx/git-js/commit/98864c678444d9336357c844efa4fd5a7984c0d7","https://github.com/steveukx/git-js/pull/1193","https://github.com/steveukx/git-js/releases/tag/simple-git@4.0.0","https://github.com/steveukx/git-js/security/advisories/GHSA-858h-whjf-mvg5"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T19:17:25","euvd":null},{"cve_id":"CVE-2026-102828","summary":"simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not classify trailer.<token>.cmd as unsafe configuration. An application that passes attacker-controlled values through SimpleGitOptions.config or inline -c arguments can therefore allow Git to invoke an attacker-selected shell command when git interpret-trailers processes the configured trailer. The command executes with the operating-system identity and permissions of the Node.js process. This issue is fixed in 4.0.1.","cvss":9.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.2,"epss":0.00275,"ranking_epss":0.17951,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/steveukx/git-js/commit/d762810c13b331ff1e5eb24c0b434646d2a8d1b3","https://github.com/steveukx/git-js/pull/1198","https://github.com/steveukx/git-js/releases/tag/simple-git@4.0.1","https://github.com/steveukx/git-js/security/advisories/GHSA-x6jw-m9v5-85vh"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T19:17:25","euvd":{"id":"EUVD-2026-89334","description":"simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not classify trailer.<token>.cmd as unsafe configuration. An application that passes attacker-controlled values through SimpleGitOptions.config or inline -c arguments can therefore allow Git to invoke an attacker-selected shell command when git interpret-trailers processes the configured trailer. The command executes with the operating-system identity and permissions of the Node.js process. This issue is fixed in 4.0.1.","published_time":"2026-09-29T18:43:19","cvss":9.2,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/steveukx/git-js/security/advisories/GHSA-x6jw-m9v5-85vh","https://github.com/steveukx/git-js/pull/1198","https://github.com/steveukx/git-js/commit/d762810c13b331ff1e5eb24c0b434646d2a8d1b3","https://github.com/steveukx/git-js/releases/tag/simple-git@4.0.1"],"products":["git-js"],"vendors":["steveukx"]}},{"cve_id":"CVE-2026-102829","summary":"simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 2.0.1 of the argv-parser package, parseEnv omits VISUAL from GitEnvKeys, so prepareEnv drops the value before vulnerabilityCheck can classify it as allowUnsafeEditor. A consuming application that forwards attacker-influenced environment values can therefore allow Git to invoke an attacker-selected editor during operations such as commit amendment or interactive rebase when no higher-priority editor setting overrides VISUAL and Git's terminal prerequisites are met. The executable runs with the privileges of the Node.js process. This issue is fixed in argv-parser 2.0.1.","cvss":9.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.2,"epss":0.00275,"ranking_epss":0.1795,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/steveukx/git-js/commit/68874c239f0c7a87f4a68c3d2c4a0d7c75bb27f4","https://github.com/steveukx/git-js/pull/1201","https://github.com/steveukx/git-js/releases/tag/@simple-git/argv-parser@2.0.1","https://github.com/steveukx/git-js/security/advisories/GHSA-v5rq-49vh-5v5c"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T19:17:25","euvd":{"id":"EUVD-2026-89336","description":"simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 2.0.1 of the argv-parser package, parseEnv omits VISUAL from GitEnvKeys, so prepareEnv drops the value before vulnerabilityCheck can classify it as allowUnsafeEditor. A consuming application that forwards attacker-influenced environment values can therefore allow Git to invoke an attacker-selected editor during operations such as commit amendment or interactive rebase when no higher-priority editor setting overrides VISUAL and Git's terminal prerequisites are met. The executable runs with the privileges of the Node.js process. This issue is fixed in argv-parser 2.0.1.","published_time":"2026-09-29T18:46:58","cvss":9.2,"cvss_version":"4.0","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/steveukx/git-js/security/advisories/GHSA-v5rq-49vh-5v5c","https://github.com/steveukx/git-js/pull/1201","https://github.com/steveukx/git-js/commit/68874c239f0c7a87f4a68c3d2c4a0d7c75bb27f4","https://github.com/steveukx/git-js/releases/tag/@simple-git/argv-parser@2.0.1"],"products":["git-js"],"vendors":["steveukx"]}},{"cve_id":"CVE-2026-102831","summary":"JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook 7.5.0 until 7.6.3, and from JupyterLite Core 0.7.0 until 0.8.4, the system clipboard cell-paste path accepts attacker-controlled cell JSON without clearing metadata.trusted. When useSystemClipboardForCells is active and pasteCodeCellsWithoutOutput is disabled, a pasted code cell can mark HTML output as trusted, bypass output sanitization, and execute script in the authenticated JupyterLab origin without executing the cell. Markdown and raw cells are not affected because their output is sanitized. This issue is fixed in JupyterLab 4.5.11 and 4.6.4, Notebook 7.6.3, and JupyterLite Core 0.8.4.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":0.00196,"ranking_epss":0.08358,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/jupyterlab/jupyterlab/commit/1a10a7da5ff655849b21581c2633b46483ae0be9","https://github.com/jupyterlab/jupyterlab/commit/7f9f29e29e0c83fb17b0f11da57d06b3c6a40d96","https://github.com/jupyterlab/jupyterlab/commit/cf6e89a8d315c4134cefa50c220bca296da466a7","https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.11","https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.4","https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-6966-vjj6-99xv"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T19:17:25","euvd":null},{"cve_id":"CVE-2026-102822","summary":"Russh is a Rust SSH client and server library. Prior to 0.63.1, a connection configured to permit mac=none can negotiate it with a MAC-requiring CTR or CBC block cipher because the selection logic validates needs_mac() only when MAC selection fails. A remote peer can then send a packet with a decrypted length of zero, causing russh/src/cipher/mod.rs to shrink the previously read block before indexing buffer.buffer[16..], which panics and terminates the connection task. This issue is fixed in version 0.63.1.","cvss":3.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.7,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Eugeny/russh/commit/2885385abfee279092a41d80c6cb6ac367353159","https://github.com/Eugeny/russh/releases/tag/v0.63.1","https://github.com/Eugeny/russh/security/advisories/GHSA-p8qx-h547-fjw9","https://github.com/Eugeny/russh/security/advisories/GHSA-p8qx-h547-fjw9"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T19:17:24","euvd":{"id":"EUVD-2026-89205","description":"russh: negotiating a MAC-requiring block cipher (CTR/CBC) with mac=none causes a slice-index-out-of-range panic","published_time":"2026-09-30T23:27:30","cvss":3.7,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/Eugeny/russh/security/advisories/GHSA-p8qx-h547-fjw9","https://github.com/Eugeny/russh/commit/2885385abfee279092a41d80c6cb6ac367353159","https://github.com/Eugeny/russh/releases/tag/v0.63.1","https://nvd.nist.gov/vuln/detail/CVE-2026-102822"],"products":["russh"],"vendors":["Eugeny"]}},{"cve_id":"CVE-2026-102823","summary":"Russh is a Rust SSH client and server library. Prior to 0.63.1, client_read_authenticated in russh/src/client/encrypted.rs forwards CHANNEL_DATA, CHANNEL_EXTENDED_DATA, CHANNEL_EOF, CHANNEL_CLOSE, CHANNEL_OPEN_FAILURE, CHANNEL_SUCCESS, CHANNEL_FAILURE, and CHANNEL_REQUEST subtypes exit-status, exit-signal, and xon-xoff to public client::Handler callbacks without confirming that the ChannelId belongs to a channel the client opened and established. A malicious SSH server can send lifecycle events for predicted, unopened, unconfirmed, or released channel identifiers, causing application panics or corrupting command completion and exit-code tracking. This issue is fixed in version 0.63.1.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Eugeny/russh/commit/3430fd26ecafc0dc3705210f5f39a9119fa22774","https://github.com/Eugeny/russh/releases/tag/v0.63.1","https://github.com/Eugeny/russh/security/advisories/GHSA-47hw-gvq5-r2gm"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T19:17:24","euvd":{"id":"EUVD-2026-89206","description":"russh: Client-side channel-scoped Handler callbacks fire for channel IDs the client never opened","published_time":"2026-09-30T23:27:17","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/Eugeny/russh/security/advisories/GHSA-47hw-gvq5-r2gm","https://github.com/Eugeny/russh/commit/3430fd26ecafc0dc3705210f5f39a9119fa22774","https://github.com/Eugeny/russh/releases/tag/v0.63.1","https://nvd.nist.gov/vuln/detail/CVE-2026-102823"],"products":["russh"],"vendors":["Eugeny"]}},{"cve_id":"CVE-2026-102824","summary":"Russh is a Rust SSH client and server library. Prior to 0.63.0, the hybrid ML-KEM 768 and X25519 implementation in russh/src/kex/hybrid_mlkem.rs accepts an all-zero 32-byte peer X25519 public key in both server_dh and compute_shared_secret, forcing the X25519 contribution to the combined shared secret to zero. A malicious SSH peer can therefore make the combined secret depend only on ML-KEM, defeating the hybrid exchange's intended fallback protection if ML-KEM is later weakened. This issue is fixed in version 0.63.0.","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00141,"ranking_epss":0.02888,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Eugeny/russh/commit/8da8967f196472576b1565d518a0ed60fce60f0c","https://github.com/Eugeny/russh/releases/tag/v0.63.0","https://github.com/Eugeny/russh/security/advisories/GHSA-w3jg-pjxf-73p4"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T19:17:24","euvd":{"id":"EUVD-2026-89207","description":"Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange","published_time":"2026-09-30T23:26:48","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/Eugeny/russh/security/advisories/GHSA-w3jg-pjxf-73p4","https://github.com/Eugeny/russh/commit/8da8967f196472576b1565d518a0ed60fce60f0c","https://github.com/Eugeny/russh/releases/tag/v0.63.0","https://nvd.nist.gov/vuln/detail/CVE-2026-102824"],"products":["russh"],"vendors":["Eugeny"]}},{"cve_id":"CVE-2026-102825","summary":"Russh is a Rust SSH client and server library. Prior to 0.62.6, the USERAUTH_REQUEST path reached from server::run_stream in russh/src/server/encrypted.rs increments self.common.auth_attempts but never compares it with server::Config.max_auth_attempts. An unauthenticated remote client can continue submitting authentication requests on one connection beyond the configured cap, bypassing the deployment's attempt-limiting policy and increasing online guessing opportunity and backend authentication workload. This issue is fixed in version 0.62.6.","cvss":3.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.7,"cvss_v4":null,"epss":0.00282,"ranking_epss":0.1864,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Eugeny/russh/commit/f8fd0b11a393364dc7f01a182482d86adafdd653","https://github.com/Eugeny/russh/releases/tag/v0.62.6","https://github.com/Eugeny/russh/security/advisories/GHSA-g6xm-f9xp-qq35","https://github.com/Eugeny/russh/security/advisories/GHSA-g6xm-f9xp-qq35"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T19:17:24","euvd":{"id":"EUVD-2026-89365","description":"Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path","published_time":"2026-09-30T23:26:17","cvss":3.7,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/Eugeny/russh/security/advisories/GHSA-g6xm-f9xp-qq35","https://github.com/Eugeny/russh/commit/f8fd0b11a393364dc7f01a182482d86adafdd653","https://github.com/Eugeny/russh/releases/tag/v0.62.6","https://nvd.nist.gov/vuln/detail/CVE-2026-102825"],"products":["russh"],"vendors":["Eugeny"]}},{"cve_id":"CVE-2026-102826","summary":"simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin does not completely reject configuration includes supplied through customArgs to git.clone(). The missing include.path classification permits Git to load an attacker-controlled configuration file, and the initial remediation does not cover includeIf.<condition>.path, allowing the same file-loading primitive through a conditional include. A loaded configuration can set an executable Git option such as core.sshCommand, which Git invokes during the clone operation with the privileges of the Node.js process. Exploitation requires the application to pass attacker-influenced custom arguments and requires an attacker-controlled file that the process can read. This issue is fixed in 4.0.0.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":0.0046,"ranking_epss":0.37475,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/steveukx/git-js/commit/98864c678444d9336357c844efa4fd5a7984c0d7","https://github.com/steveukx/git-js/pull/1193","https://github.com/steveukx/git-js/releases/tag/simple-git@4.0.0","https://github.com/steveukx/git-js/security/advisories/GHSA-g4wm-2vf7-vfgr","https://github.com/steveukx/git-js/security/advisories/GHSA-g4wm-2vf7-vfgr"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T19:17:24","euvd":null},{"cve_id":"CVE-2026-102820","summary":"pageant provides a [PageantStream] type that implements [AsyncRead] and [AsyncWrite] traits and can be used to talk to a running Pageant instance. Prior to pageant 0.2.3, the Windows pageant crate's pageant/src/wmmessage.rs MemoryMap::read function trusts a peer-controlled u32 response length supplied through the 8192-byte Pageant shared-memory mapping reached by AgentClient::connect_pageant. A local process that impersonates the Pageant window can make query_pageant_direct allocate up to approximately 4 GiB and copy beyond the mapped view, reliably crashing a russh client and conditionally exposing adjacent committed memory. This issue is fixed in pageant 0.2.3.","cvss":6.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.2,"cvss_v4":null,"epss":0.00129,"ranking_epss":0.02141,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Eugeny/russh/commit/5d566989ebabfdebfe6b33243d31765a0812260b","https://github.com/Eugeny/russh/releases/tag/v0.63.2","https://github.com/Eugeny/russh/security/advisories/GHSA-g4mp-vgx3-xrvm","https://github.com/Eugeny/russh/security/advisories/GHSA-g4mp-vgx3-xrvm"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T19:17:23","euvd":{"id":"EUVD-2026-89203","description":"pageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::read via a malicious Pageant agent (Windows)","published_time":"2026-09-30T23:41:02","cvss":6.2,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/Eugeny/russh/security/advisories/GHSA-g4mp-vgx3-xrvm","https://github.com/Eugeny/russh/commit/5d566989ebabfdebfe6b33243d31765a0812260b","https://github.com/Eugeny/russh/releases/tag/v0.63.2","https://nvd.nist.gov/vuln/detail/CVE-2026-102820"],"products":["pageant","russh"],"vendors":["Eugeny","rust"]}},{"cve_id":"CVE-2026-102821","summary":"Russh is a Rust SSH client and server library. Prior to 0.63.2, an authenticated remote peer can send SSH_MSG_KEXINIT without the required SSH_MSG_KEX_ECDH_INIT and then flood SSH_MSG_CHANNEL_OPEN messages while SessionKexState::InProgress prevents priority_receiver in russh/src/server/session.rs from being drained. The server continues processing network input and enqueues a ChannelOpenReply for each request on an unbounded channel, allowing one connection to grow memory until the process is terminated. This issue is fixed in version 0.63.2.","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00295,"ranking_epss":0.19991,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/Eugeny/russh/commit/a282af361ac99bc76b80876d1aae128e89dbf66b","https://github.com/Eugeny/russh/releases/tag/v0.63.2","https://github.com/Eugeny/russh/security/advisories/GHSA-35g8-35p8-c8fw","https://github.com/Eugeny/russh/security/advisories/GHSA-35g8-35p8-c8fw"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T19:17:23","euvd":{"id":"EUVD-2026-89204","description":"Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey","published_time":"2026-09-30T23:40:43","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"GitHub_M","references":["https://github.com/Eugeny/russh/security/advisories/GHSA-35g8-35p8-c8fw","https://github.com/Eugeny/russh/commit/a282af361ac99bc76b80876d1aae128e89dbf66b","https://github.com/Eugeny/russh/releases/tag/v0.63.2","https://nvd.nist.gov/vuln/detail/CVE-2026-102821"],"products":["russh"],"vendors":["Eugeny"]}},{"cve_id":"CVE-2026-102616","summary":"A vulnerability was detected in risesoft-y9 WorkFlow-Engine up to 9.6.10. Impacted is the function getByIdAndYear of the file CustomHistoricProcessServiceImpl.java of the component OAuth2 Resource Filter. Performing a manipulation of the argument year/processInstanceId results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The sink is injectable on two independent positions, not just one. The vendor was contacted early about this disclosure but did not respond in any way.","cvss":5.5,"cvss_version":4.0,"cvss_v2":7.5,"cvss_v3":7.3,"cvss_v4":5.5,"epss":0.00254,"ranking_epss":0.15301,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/fangtang7/CVE/blob/main/WorkFlow-Engine/sql.md","https://vuldb.com/cve/CVE-2026-102616","https://vuldb.com/submit/942286","https://vuldb.com/vuln/411406","https://vuldb.com/vuln/411406/cti"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T19:17:19","euvd":null},{"cve_id":"CVE-2026-95382","summary":"Improper input validation in Auth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/497212105"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:32","euvd":{"id":"EUVD-2026-89249","description":"Improper input validation in Auth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:44","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/497212105"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95384","summary":"Race condition in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/526550688"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:32","euvd":{"id":"EUVD-2026-89129","description":"Race condition in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:51","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/526550688"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95385","summary":"Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/517192965"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:32","euvd":{"id":"EUVD-2026-89156","description":"Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)","published_time":"2026-09-29T17:31:58","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/517192965"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95374","summary":"Incorrect authorization in Network in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/543464436"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:31","euvd":{"id":"EUVD-2026-89134","description":"Incorrect authorization in Network in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:52","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/543464436"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95371","summary":"Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00217,"ranking_epss":0.10949,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/520504291"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:31","euvd":null},{"cve_id":"CVE-2026-95371","summary":"Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00217,"ranking_epss":0.10949,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/520504291"],"vendor":"apple","product":"macos","version":null,"published_time":"2026-09-29T18:17:31","euvd":null},{"cve_id":"CVE-2026-95372","summary":"Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":8.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.3,"cvss_v4":null,"epss":0.00378,"ranking_epss":0.29277,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/534997484"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:31","euvd":{"id":"EUVD-2026-89227","description":"Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:39","cvss":8.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/534997484"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95373","summary":"Use after free in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00366,"ranking_epss":0.2805,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553130481"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:31","euvd":{"id":"EUVD-2026-89233","description":"Use after free in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:40","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553130481"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95375","summary":"Incorrect authorization in BrowserTag in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)","cvss":6.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.3,"cvss_v4":null,"epss":0.00235,"ranking_epss":0.12996,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/502179319","https://issues.chromium.org/issues/502179319"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:31","euvd":{"id":"EUVD-2026-89253","description":"Incorrect authorization in BrowserTag in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:45","cvss":6.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/502179319"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95376","summary":"Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)","cvss":8.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.0,"cvss_v4":null,"epss":0.00148,"ranking_epss":0.03364,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/513134076","https://issues.chromium.org/issues/513134076"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:31","euvd":{"id":"EUVD-2026-89257","description":"Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:46","cvss":8.0,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/513134076"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95380","summary":"Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00399,"ranking_epss":0.31681,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/534579660"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:31","euvd":{"id":"EUVD-2026-89163","description":"Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)","published_time":"2026-09-29T17:31:59","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/534579660"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95381","summary":"Improper input validation in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cvss":8.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.3,"cvss_v4":null,"epss":0.00403,"ranking_epss":0.32092,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/497603247"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:31","euvd":{"id":"EUVD-2026-89250","description":"Improper input validation in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:44","cvss":8.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/497603247"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95364","summary":"Improper input validation in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553271219"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:30","euvd":{"id":"EUVD-2026-89169","description":"Improper input validation in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)","published_time":"2026-09-29T17:32:01","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553271219"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95367","summary":"Information leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/514524620"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:30","euvd":{"id":"EUVD-2026-89155","description":"Information leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)","published_time":"2026-09-29T17:31:57","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/514524620"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95368","summary":"Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/522413520"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:30","euvd":{"id":"EUVD-2026-89157","description":"Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)","published_time":"2026-09-29T17:31:58","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/522413520"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95365","summary":"Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00399,"ranking_epss":0.31681,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/558764482"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:30","euvd":{"id":"EUVD-2026-89240","description":"Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:42","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/558764482"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95366","summary":"Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00435,"ranking_epss":0.35465,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/497204165","https://issues.chromium.org/issues/497204165"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:30","euvd":{"id":"EUVD-2026-89248","description":"Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:44","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/497204165"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95369","summary":"Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00366,"ranking_epss":0.2805,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/513049042"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:30","euvd":{"id":"EUVD-2026-89256","description":"Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:46","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/513049042"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95370","summary":"Inappropriate implementation in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.0023,"ranking_epss":0.1255,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/517417437"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:30","euvd":{"id":"EUVD-2026-89118","description":"Inappropriate implementation in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:48","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/517417437"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95360","summary":"Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)","cvss":5.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/517584808"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:29","euvd":{"id":"EUVD-2026-89120","description":"Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:49","cvss":5.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/517584808"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95363","summary":"UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/522344883"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:29","euvd":{"id":"EUVD-2026-89126","description":"UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:50","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/522344883"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95359","summary":"Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cvss":3.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.4,"cvss_v4":null,"epss":0.00234,"ranking_epss":0.12985,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/513162143"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:29","euvd":null},{"cve_id":"CVE-2026-95359","summary":"Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cvss":3.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.4,"cvss_v4":null,"epss":0.00234,"ranking_epss":0.12985,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/513162143"],"vendor":"google","product":"android","version":null,"published_time":"2026-09-29T18:17:29","euvd":null},{"cve_id":"CVE-2026-95361","summary":"Confused deputy in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00235,"ranking_epss":0.12996,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/533095855"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:29","euvd":{"id":"EUVD-2026-89161","description":"Confused deputy in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)","published_time":"2026-09-29T17:31:59","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/533095855"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95362","summary":"Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.0018,"ranking_epss":0.06857,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/511791538","https://issues.chromium.org/issues/511791538"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:29","euvd":{"id":"EUVD-2026-89255","description":"Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:46","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/511791538"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95351","summary":"Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":8.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.3,"cvss_v4":null,"epss":0.00378,"ranking_epss":0.29278,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/562242429"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:28","euvd":{"id":"EUVD-2026-89246","description":"Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:43","cvss":8.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/562242429"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95352","summary":"Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00217,"ranking_epss":0.10901,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/513791872"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:28","euvd":{"id":"EUVD-2026-89153","description":"Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)","published_time":"2026-09-29T17:31:57","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/513791872"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95353","summary":"Use after free in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00366,"ranking_epss":0.2805,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/522061704"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:28","euvd":{"id":"EUVD-2026-89125","description":"Use after free in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:50","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/522061704"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95354","summary":"Use after free in Verifier in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)","cvss":8.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.3,"cvss_v4":null,"epss":0.00349,"ranking_epss":0.26015,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/524582798"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:28","euvd":{"id":"EUVD-2026-89128","description":"Use after free in Verifier in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:51","cvss":8.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/524582798"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95355","summary":"Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":8.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.3,"cvss_v4":null,"epss":0.00364,"ranking_epss":0.27778,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/508462481"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:28","euvd":{"id":"EUVD-2026-89224","description":"Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:38","cvss":8.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/508462481"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95355","summary":"Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":8.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.3,"cvss_v4":null,"epss":0.00364,"ranking_epss":0.27778,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/508462481"],"vendor":"apple","product":"iphone_os","version":null,"published_time":"2026-09-29T18:17:28","euvd":{"id":"EUVD-2026-89224","description":"Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:38","cvss":8.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/508462481"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95356","summary":"Use after free in WindowDialog in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00409,"ranking_epss":0.32667,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/560439699"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:28","euvd":{"id":"EUVD-2026-89220","description":"Use after free in WindowDialog in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","published_time":"2026-09-29T17:31:37","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/560439699"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95357","summary":"Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00439,"ranking_epss":0.35749,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/530045332"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:28","euvd":{"id":"EUVD-2026-89212","description":"Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","published_time":"2026-09-29T17:31:35","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/530045332"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95357","summary":"Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00439,"ranking_epss":0.35749,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/530045332"],"vendor":"google","product":"android","version":null,"published_time":"2026-09-29T18:17:28","euvd":{"id":"EUVD-2026-89212","description":"Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","published_time":"2026-09-29T17:31:35","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/530045332"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95358","summary":"Incorrect authorization in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to bypass system access restrictions into a privileged page via a co-installed app. (Chromium security severity: Medium)","cvss":4.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.4,"cvss_v4":null,"epss":0.00136,"ranking_epss":0.02508,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553141660"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:28","euvd":{"id":"EUVD-2026-89144","description":"Incorrect authorization in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to bypass system access restrictions into a privileged page via a co-installed app. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:55","cvss":4.4,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553141660"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95343","summary":"Use after free in WebAudio in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00463,"ranking_epss":0.37772,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/559815527"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:27","euvd":{"id":"EUVD-2026-89241","description":"Use after free in WebAudio in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:42","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/559815527"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95344","summary":"Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass site isolation via a crafted Chrome extension. (Chromium security severity: Medium)","cvss":8.0,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.0,"cvss_v4":null,"epss":0.00166,"ranking_epss":0.0531,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/548611433"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:27","euvd":{"id":"EUVD-2026-89140","description":"Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass site isolation via a crafted Chrome extension. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:54","cvss":8.0,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/548611433"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95345","summary":"Use after free in Actor in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00366,"ranking_epss":0.28051,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/516404074"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:27","euvd":{"id":"EUVD-2026-89116","description":"Use after free in Actor in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:48","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/516404074"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95346","summary":"UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via crafted network traffic. (Chromium security severity: Medium)","cvss":4.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.8,"cvss_v4":null,"epss":0.00246,"ranking_epss":0.14348,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/514059630"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:27","euvd":null},{"cve_id":"CVE-2026-95347","summary":"Use after free in Updater in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00377,"ranking_epss":0.29246,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/550181232"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:27","euvd":{"id":"EUVD-2026-89142","description":"Use after free in Updater in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:54","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/550181232"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95347","summary":"Use after free in Updater in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00377,"ranking_epss":0.29246,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/550181232"],"vendor":"apple","product":"macos","version":null,"published_time":"2026-09-29T18:17:27","euvd":{"id":"EUVD-2026-89142","description":"Use after free in Updater in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:54","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/550181232"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95348","summary":"Use after free in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":8.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.3,"cvss_v4":null,"epss":0.00378,"ranking_epss":0.29278,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/554558320"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:27","euvd":{"id":"EUVD-2026-89235","description":"Use after free in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:41","cvss":8.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/554558320"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95349","summary":"Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00448,"ranking_epss":0.36601,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553172761"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:27","euvd":{"id":"EUVD-2026-89216","description":"Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","published_time":"2026-09-29T17:31:36","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553172761"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95349","summary":"Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00448,"ranking_epss":0.36601,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553172761"],"vendor":"google","product":"android","version":null,"published_time":"2026-09-29T18:17:27","euvd":{"id":"EUVD-2026-89216","description":"Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","published_time":"2026-09-29T17:31:36","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553172761"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95350","summary":"Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00481,"ranking_epss":0.39152,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/551573368"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:27","euvd":{"id":"EUVD-2026-89211","description":"Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","published_time":"2026-09-29T17:31:34","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/551573368"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95350","summary":"Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00481,"ranking_epss":0.39152,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/551573368"],"vendor":"google","product":"android","version":null,"published_time":"2026-09-29T18:17:27","euvd":{"id":"EUVD-2026-89211","description":"Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","published_time":"2026-09-29T17:31:34","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/551573368"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95335","summary":"Use after free in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":8.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.3,"cvss_v4":null,"epss":0.00378,"ranking_epss":0.29277,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/555299641"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:26","euvd":{"id":"EUVD-2026-89236","description":"Use after free in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:41","cvss":8.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/555299641"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95336","summary":"Information leak in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00282,"ranking_epss":0.18632,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/532962621"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:26","euvd":null},{"cve_id":"CVE-2026-95337","summary":"UI misrepresentation in Messages in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00225,"ranking_epss":0.11992,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/514019137"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:26","euvd":null},{"cve_id":"CVE-2026-95337","summary":"UI misrepresentation in Messages in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00225,"ranking_epss":0.11992,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/514019137"],"vendor":"google","product":"android","version":null,"published_time":"2026-09-29T18:17:26","euvd":null},{"cve_id":"CVE-2026-95338","summary":"Use after free in PDFium in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00338,"ranking_epss":0.24788,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/556535630"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:26","euvd":{"id":"EUVD-2026-89237","description":"Use after free in PDFium in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)","published_time":"2026-09-29T17:31:41","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/556535630"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95339","summary":"Use after free in ServiceWorker in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00439,"ranking_epss":0.35749,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/548585299"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:26","euvd":{"id":"EUVD-2026-89213","description":"Use after free in ServiceWorker in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","published_time":"2026-09-29T17:31:35","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/548585299"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95340","summary":"Incorrect authorization in PictureInPicture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00235,"ranking_epss":0.12995,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553268567"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:26","euvd":{"id":"EUVD-2026-89168","description":"Incorrect authorization in PictureInPicture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)","published_time":"2026-09-29T17:32:01","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553268567"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95341","summary":"Improper input validation in Desktop in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)","cvss":8.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.3,"cvss_v4":null,"epss":0.00372,"ranking_epss":0.28697,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/523719002"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:26","euvd":{"id":"EUVD-2026-89127","description":"Improper input validation in Desktop in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:50","cvss":8.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/523719002"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95342","summary":"Missing authorization in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00235,"ranking_epss":0.12995,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/547027738"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:26","euvd":{"id":"EUVD-2026-89164","description":"Missing authorization in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)","published_time":"2026-09-29T17:32:00","cvss":4.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/547027738"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95327","summary":"Information leak in Networking in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00282,"ranking_epss":0.18631,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/502077689"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:25","euvd":{"id":"EUVD-2026-89149","description":"Information leak in Networking in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)","published_time":"2026-09-29T17:31:56","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/502077689"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95328","summary":"Confused deputy in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Low)","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.002,"ranking_epss":0.08916,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553148673"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:25","euvd":null},{"cve_id":"CVE-2026-95328","summary":"Confused deputy in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Low)","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.002,"ranking_epss":0.08916,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553148673"],"vendor":"google","product":"android","version":null,"published_time":"2026-09-29T18:17:25","euvd":null},{"cve_id":"CVE-2026-95329","summary":"Out of bounds write in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00409,"ranking_epss":0.32666,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/559320837"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:25","euvd":{"id":"EUVD-2026-89219","description":"Out of bounds write in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","published_time":"2026-09-29T17:31:37","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/559320837"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95329","summary":"Out of bounds write in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00409,"ranking_epss":0.32666,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/559320837"],"vendor":"google","product":"android","version":null,"published_time":"2026-09-29T18:17:25","euvd":{"id":"EUVD-2026-89219","description":"Out of bounds write in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","published_time":"2026-09-29T17:31:37","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/559320837"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95330","summary":"Improper state validation in Downloads in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.0023,"ranking_epss":0.1255,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/517163294","https://issues.chromium.org/issues/517163294"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:25","euvd":{"id":"EUVD-2026-89117","description":"Improper state validation in Downloads in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:48","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/517163294"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95331","summary":"Out of bounds write in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00409,"ranking_epss":0.32665,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/500127519"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:25","euvd":{"id":"EUVD-2026-89251","description":"Out of bounds write in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:45","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/500127519"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95332","summary":"Use of uninitialized variable in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cvss":4.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.7,"cvss_v4":null,"epss":0.0025,"ranking_epss":0.14753,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/546639650"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:25","euvd":null},{"cve_id":"CVE-2026-95332","summary":"Use of uninitialized variable in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cvss":4.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.7,"cvss_v4":null,"epss":0.0025,"ranking_epss":0.14753,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/546639650"],"vendor":"google","product":"android","version":null,"published_time":"2026-09-29T18:17:25","euvd":null},{"cve_id":"CVE-2026-95333","summary":"Use after free in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":0.00393,"ranking_epss":0.31041,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/559682346"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:25","euvd":{"id":"EUVD-2026-89145","description":"Use after free in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:55","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/559682346"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95334","summary":"Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)","cvss":8.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.3,"cvss_v4":null,"epss":0.00412,"ranking_epss":0.33003,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/513403696"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:25","euvd":{"id":"EUVD-2026-89150","description":"Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)","published_time":"2026-09-29T17:31:56","cvss":8.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/513403696"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95326","summary":"Incomplete cleanup in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/533041383"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:24","euvd":{"id":"EUVD-2026-89159","description":"Incomplete cleanup in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)","published_time":"2026-09-29T17:31:58","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/533041383"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95318","summary":"Buffer overflow in Video in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00448,"ranking_epss":0.36601,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/556576976"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:24","euvd":{"id":"EUVD-2026-89238","description":"Buffer overflow in Video in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:41","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/556576976"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95319","summary":"Use after free in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)","cvss":8.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.3,"cvss_v4":null,"epss":0.00378,"ranking_epss":0.29277,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/523765972"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:24","euvd":{"id":"EUVD-2026-89158","description":"Use after free in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)","published_time":"2026-09-29T17:31:58","cvss":8.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/523765972"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95320","summary":"Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00217,"ranking_epss":0.10949,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/514072284"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:24","euvd":null},{"cve_id":"CVE-2026-95321","summary":"UI misrepresentation in Payments in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00225,"ranking_epss":0.11991,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/545879261"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:24","euvd":null},{"cve_id":"CVE-2026-95321","summary":"UI misrepresentation in Payments in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00225,"ranking_epss":0.11991,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/545879261"],"vendor":"google","product":"android","version":null,"published_time":"2026-09-29T18:17:24","euvd":null},{"cve_id":"CVE-2026-95322","summary":"Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","cvss":8.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.3,"cvss_v4":null,"epss":0.00378,"ranking_epss":0.29277,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/556576992"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:24","euvd":{"id":"EUVD-2026-89218","description":"Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","published_time":"2026-09-29T17:31:36","cvss":8.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/556576992"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95322","summary":"Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","cvss":8.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.3,"cvss_v4":null,"epss":0.00378,"ranking_epss":0.29277,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/556576992"],"vendor":"google","product":"android","version":null,"published_time":"2026-09-29T18:17:24","euvd":{"id":"EUVD-2026-89218","description":"Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","published_time":"2026-09-29T17:31:36","cvss":8.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/556576992"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95323","summary":"UI misrepresentation in Chromium in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00225,"ranking_epss":0.11992,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/546438368"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:24","euvd":null},{"cve_id":"CVE-2026-95323","summary":"UI misrepresentation in Chromium in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00225,"ranking_epss":0.11992,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/546438368"],"vendor":"apple","product":"iphone_os","version":null,"published_time":"2026-09-29T18:17:24","euvd":null},{"cve_id":"CVE-2026-95324","summary":"Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":3.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.4,"cvss_v4":null,"epss":0.00234,"ranking_epss":0.12985,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/537857253"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:24","euvd":{"id":"EUVD-2026-89228","description":"Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:39","cvss":3.4,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/537857253"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95325","summary":"Use after free in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00409,"ranking_epss":0.32665,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/536648933"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:24","euvd":{"id":"EUVD-2026-89132","description":"Use after free in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:52","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/536648933"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95314","summary":"Incorrect authorization in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/517802696"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:23","euvd":{"id":"EUVD-2026-89123","description":"Incorrect authorization in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:49","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/517802696"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95309","summary":"UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00225,"ranking_epss":0.1199,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/533074595"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:23","euvd":null},{"cve_id":"CVE-2026-95309","summary":"UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00225,"ranking_epss":0.1199,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/533074595"],"vendor":"apple","product":"iphone_os","version":null,"published_time":"2026-09-29T18:17:23","euvd":null},{"cve_id":"CVE-2026-95310","summary":"Use after free in AdFilter in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00409,"ranking_epss":0.32666,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/562151598"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:23","euvd":{"id":"EUVD-2026-89221","description":"Use after free in AdFilter in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","published_time":"2026-09-29T17:31:37","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/562151598"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95311","summary":"Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00409,"ranking_epss":0.32666,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553123003"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:23","euvd":{"id":"EUVD-2026-89143","description":"Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:54","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553123003"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95312","summary":"Information leak in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)","cvss":3.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.1,"cvss_v4":null,"epss":0.00215,"ranking_epss":0.10755,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/547832510"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:23","euvd":null},{"cve_id":"CVE-2026-95313","summary":"Use after free in Fullscreen in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00409,"ranking_epss":0.32665,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/552665794"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:23","euvd":{"id":"EUVD-2026-89215","description":"Use after free in Fullscreen in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","published_time":"2026-09-29T17:31:36","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/552665794"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95315","summary":"Use after free in Aura in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":0.00106,"ranking_epss":0.01023,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/517661385"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:23","euvd":{"id":"EUVD-2026-89225","description":"Use after free in Aura in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)","published_time":"2026-09-29T17:31:38","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/517661385"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95316","summary":"Unchecked return value in Performance in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially read memory via a local program. (Chromium security severity: Low)","cvss":2.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":2.9,"cvss_v4":null,"epss":0.0009,"ranking_epss":0.00422,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/552023752"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:23","euvd":null},{"cve_id":"CVE-2026-95317","summary":"Incorrect authorization in MediaCapture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)","cvss":3.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.1,"cvss_v4":null,"epss":0.00191,"ranking_epss":0.07896,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/514487499"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:23","euvd":null},{"cve_id":"CVE-2026-95303","summary":"Incomplete cleanup in SmartCard in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/517442714"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:22","euvd":{"id":"EUVD-2026-89119","description":"Incomplete cleanup in SmartCard in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:48","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/517442714"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95301","summary":"Missing authorization in Extensions in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":0.00222,"ranking_epss":0.11543,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/540265100","https://issues.chromium.org/issues/540265100"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:22","euvd":{"id":"EUVD-2026-89222","description":"Missing authorization in Extensions in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:37","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/540265100"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95302","summary":"Incorrect authorization in WebAPKs in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)","cvss":2.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":2.9,"cvss_v4":null,"epss":0.00092,"ranking_epss":0.00473,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/502242455"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:22","euvd":null},{"cve_id":"CVE-2026-95302","summary":"Incorrect authorization in WebAPKs in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)","cvss":2.9,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":2.9,"cvss_v4":null,"epss":0.00092,"ranking_epss":0.00473,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/502242455"],"vendor":"google","product":"android","version":null,"published_time":"2026-09-29T18:17:22","euvd":null},{"cve_id":"CVE-2026-95304","summary":"Out of bounds write in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00366,"ranking_epss":0.28049,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/560536731"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:22","euvd":{"id":"EUVD-2026-89243","description":"Out of bounds write in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:43","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/560536731"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95305","summary":"UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)","cvss":4.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.8,"cvss_v4":null,"epss":0.00246,"ranking_epss":0.14348,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553921181"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:22","euvd":null},{"cve_id":"CVE-2026-95306","summary":"Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00399,"ranking_epss":0.31681,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/560536735"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:22","euvd":{"id":"EUVD-2026-89244","description":"Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:43","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/560536735"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95307","summary":"UI misrepresentation in ExtensionsMenu in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00225,"ranking_epss":0.11989,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/423956129"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:22","euvd":null},{"cve_id":"CVE-2026-95308","summary":"Integer overflow in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)","cvss":3.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":3.4,"cvss_v4":null,"epss":0.00215,"ranking_epss":0.10755,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/513714849"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:22","euvd":{"id":"EUVD-2026-89151","description":"Integer overflow in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)","published_time":"2026-09-29T17:31:57","cvss":3.4,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/513714849"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95295","summary":"Information leak in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a local attacker to leak sensitive information via physical access. (Chromium security severity: Medium)","cvss":4.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/517596255"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:21","euvd":{"id":"EUVD-2026-89121","description":"Information leak in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a local attacker to leak sensitive information via physical access. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:49","cvss":4.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/517596255"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95293","summary":"Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":4.7,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.7,"cvss_v4":null,"epss":0.0025,"ranking_epss":0.14753,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/550953039"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:21","euvd":{"id":"EUVD-2026-89230","description":"Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:40","cvss":4.7,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/550953039"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95294","summary":"UI misrepresentation in Browser in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00225,"ranking_epss":0.1199,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/513992281"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:21","euvd":null},{"cve_id":"CVE-2026-95296","summary":"Missing authorization in Core in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00221,"ranking_epss":0.11421,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/551296612"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:21","euvd":null},{"cve_id":"CVE-2026-95296","summary":"Missing authorization in Core in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00221,"ranking_epss":0.11421,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/551296612"],"vendor":"apple","product":"macos","version":null,"published_time":"2026-09-29T18:17:21","euvd":null},{"cve_id":"CVE-2026-95297","summary":"Missing authorization in Contextual Tasks in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)","cvss":6.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":null,"epss":0.00235,"ranking_epss":0.12995,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/501648493"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:21","euvd":{"id":"EUVD-2026-89252","description":"Missing authorization in Contextual Tasks in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:45","cvss":6.5,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/501648493"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95298","summary":"Use after free in Browser in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":0.00134,"ranking_epss":0.02422,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/520516206"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:21","euvd":{"id":"EUVD-2026-89226","description":"Use after free in Browser in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)","published_time":"2026-09-29T17:31:38","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/520516206"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95299","summary":"Use after free in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00409,"ranking_epss":0.32667,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/561997427"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:21","euvd":{"id":"EUVD-2026-89245","description":"Use after free in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:43","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/561997427"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95300","summary":"Missing authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)","cvss":4.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.8,"cvss_v4":null,"epss":0.00205,"ranking_epss":0.09412,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/545449081"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:21","euvd":{"id":"EUVD-2026-89135","description":"Missing authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:52","cvss":4.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/545449081"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95285","summary":"Missing authorization in WebView in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/497094708"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:20","euvd":{"id":"EUVD-2026-89147","description":"Missing authorization in WebView in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)","published_time":"2026-09-29T17:31:55","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/497094708"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95284","summary":"Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":0.00289,"ranking_epss":0.19404,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/556435507"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:20","euvd":{"id":"EUVD-2026-89217","description":"Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","published_time":"2026-09-29T17:31:36","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/556435507"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95286","summary":"Type confusion in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00399,"ranking_epss":0.31681,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/557523002"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:20","euvd":{"id":"EUVD-2026-89239","description":"Type confusion in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:42","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/557523002"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95287","summary":"Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00222,"ranking_epss":0.11543,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/495529018"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:20","euvd":{"id":"EUVD-2026-89247","description":"Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:44","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/495529018"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95288","summary":"UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00225,"ranking_epss":0.1199,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/533102653"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:20","euvd":null},{"cve_id":"CVE-2026-95288","summary":"UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00225,"ranking_epss":0.1199,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/533102653"],"vendor":"apple","product":"iphone_os","version":null,"published_time":"2026-09-29T18:17:20","euvd":null},{"cve_id":"CVE-2026-95289","summary":"Incorrect authorization in Scroll in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)","cvss":4.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.3,"cvss_v4":null,"epss":0.00221,"ranking_epss":0.11422,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/549911100"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:20","euvd":null},{"cve_id":"CVE-2026-95290","summary":"Missing authorization in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00222,"ranking_epss":0.11543,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/536161355"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:20","euvd":{"id":"EUVD-2026-89131","description":"Missing authorization in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:51","cvss":5.4,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/536161355"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95291","summary":"UI misrepresentation in SecurityIndicators in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: High)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00225,"ranking_epss":0.1199,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/543471693"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:20","euvd":null},{"cve_id":"CVE-2026-95291","summary":"UI misrepresentation in SecurityIndicators in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: High)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00225,"ranking_epss":0.1199,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/543471693"],"vendor":"apple","product":"iphone_os","version":null,"published_time":"2026-09-29T18:17:20","euvd":null},{"cve_id":"CVE-2026-95292","summary":"Incorrect authorization in Safebrowsing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)","cvss":4.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":4.8,"cvss_v4":null,"epss":0.00205,"ranking_epss":0.09412,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/513781838"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:20","euvd":{"id":"EUVD-2026-89152","description":"Incorrect authorization in Safebrowsing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)","published_time":"2026-09-29T17:31:57","cvss":4.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/513781838"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95278","summary":"Missing authorization in WakeLock in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/497344014"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:19","euvd":{"id":"EUVD-2026-89148","description":"Missing authorization in WakeLock in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)","published_time":"2026-09-29T17:31:56","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/497344014"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95277","summary":"Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00409,"ranking_epss":0.32665,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553136141"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:19","euvd":{"id":"EUVD-2026-89234","description":"Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:40","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553136141"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95279","summary":"UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00225,"ranking_epss":0.11991,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/514012689"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:19","euvd":null},{"cve_id":"CVE-2026-95279","summary":"UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)","cvss":5.4,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":5.4,"cvss_v4":null,"epss":0.00225,"ranking_epss":0.11991,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/514012689"],"vendor":"google","product":"android","version":null,"published_time":"2026-09-29T18:17:19","euvd":null},{"cve_id":"CVE-2026-95280","summary":"Race condition in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.0027,"ranking_epss":0.17315,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/560406548"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:19","euvd":{"id":"EUVD-2026-89242","description":"Race condition in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:42","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/560406548"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95281","summary":"Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00448,"ranking_epss":0.36602,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/551708184"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:19","euvd":{"id":"EUVD-2026-89214","description":"Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","published_time":"2026-09-29T17:31:35","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/551708184"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95281","summary":"Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00448,"ranking_epss":0.36602,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/551708184"],"vendor":"google","product":"android","version":null,"published_time":"2026-09-29T18:17:19","euvd":{"id":"EUVD-2026-89214","description":"Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","published_time":"2026-09-29T17:31:35","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/551708184"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95282","summary":"Use after free in Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00366,"ranking_epss":0.2805,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553129513"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:19","euvd":{"id":"EUVD-2026-89232","description":"Use after free in Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:40","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553129513"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95283","summary":"Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00448,"ranking_epss":0.36602,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/543141419"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:19","euvd":{"id":"EUVD-2026-89229","description":"Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:39","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/543141419"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95283","summary":"Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":9.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.6,"cvss_v4":null,"epss":0.00448,"ranking_epss":0.36602,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/543141419"],"vendor":"google","product":"android","version":null,"published_time":"2026-09-29T18:17:19","euvd":{"id":"EUVD-2026-89229","description":"Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:39","cvss":9.6,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/543141419"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-84842","summary":"IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity.","cvss":8.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.1,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7288035"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:18","euvd":{"id":"EUVD-2026-89188","description":"IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity.","published_time":"2026-09-29T17:48:01","cvss":8.1,"cvss_version":"3.1","epss":0.0,"assigner":"ibm","references":["https://www.ibm.com/support/pages/node/7288035"],"products":["Guardium Data Protection"],"vendors":["IBM"]}},{"cve_id":"CVE-2026-95275","summary":"Incorrect reference resolution in MediaStream in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)","cvss":null,"cvss_version":null,"cvss_v2":null,"cvss_v3":null,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/542926849"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:18","euvd":{"id":"EUVD-2026-89133","description":"Incorrect reference resolution in MediaStream in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:52","cvss":0.0,"cvss_version":null,"epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/542926849"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-94954","summary":"A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formFilter (access-control / URL filter configuration handler) and is triggered by the url request parameter when the addFilterUrl (or addFilterUrlFlag) action flag is set.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":0.00152,"ranking_epss":0.03689,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://gist.github.com/H3rmesk1t/9e4bc190ee8130a3df5863c1c047766b"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:18","euvd":{"id":"EUVD-2026-89331","description":"A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formFilter (access-control / URL filter configuration handler) and is triggered by the url request parameter when the addFilterUrl (or addFilterUrlFlag) action flag is set.","published_time":"2026-09-29T00:00:00","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"mitre","references":["https://gist.github.com/H3rmesk1t/9e4bc190ee8130a3df5863c1c047766b"],"products":["n/a"],"vendors":["n/a"]}},{"cve_id":"CVE-2026-95274","summary":"Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cvss":8.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.3,"cvss_v4":null,"epss":0.00378,"ranking_epss":0.29278,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553116160"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:18","euvd":{"id":"EUVD-2026-89231","description":"Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","published_time":"2026-09-29T17:31:40","cvss":8.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/553116160"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-95276","summary":"Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code inside the sandbox via crafted network traffic. (Chromium security severity: Medium)","cvss":8.3,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.3,"cvss_v4":null,"epss":0.00372,"ranking_epss":0.28696,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/517730821"],"vendor":"google","product":"chrome","version":null,"published_time":"2026-09-29T18:17:18","euvd":{"id":"EUVD-2026-89122","description":"Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code inside the sandbox via crafted network traffic. (Chromium security severity: Medium)","published_time":"2026-09-29T17:31:49","cvss":8.3,"cvss_version":"3.1","epss":0.0,"assigner":"Chrome","references":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","https://issues.chromium.org/issues/517730821"],"products":["Chrome"],"vendors":["Google"]}},{"cve_id":"CVE-2026-84421","summary":"IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during archive extraction.","cvss":8.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.8,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7288649"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:17","euvd":{"id":"EUVD-2026-89197","description":"IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during archive extraction.","published_time":"2026-09-29T17:57:20","cvss":8.8,"cvss_version":"3.1","epss":0.0,"assigner":"ibm","references":["https://www.ibm.com/support/pages/node/7288649"],"products":["DataStage on Cloud Pak for Data"],"vendors":["IBM"]}},{"cve_id":"CVE-2026-84414","summary":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":0.00093,"ranking_epss":0.00541,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7289443"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:17","euvd":{"id":"EUVD-2026-89202","description":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.","published_time":"2026-09-29T18:00:05","cvss":7.8,"cvss_version":"3.1","epss":0.0,"assigner":"ibm","references":["https://www.ibm.com/support/pages/node/7289443"],"products":["i","i","i","i"],"vendors":["IBM"]}},{"cve_id":"CVE-2026-84422","summary":"IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges.","cvss":7.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.2,"cvss_v4":null,"epss":0.00676,"ranking_epss":0.50412,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7288034"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:17","euvd":{"id":"EUVD-2026-89196","description":"IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges.","published_time":"2026-09-29T17:55:27","cvss":7.2,"cvss_version":"3.1","epss":0.0,"assigner":"ibm","references":["https://www.ibm.com/support/pages/node/7288034"],"products":["Guardium Data Protection"],"vendors":["IBM"]}},{"cve_id":"CVE-2026-84436","summary":"IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges.","cvss":9.1,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":9.1,"cvss_v4":null,"epss":0.00676,"ranking_epss":0.50412,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7288040"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:17","euvd":{"id":"EUVD-2026-89194","description":"IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges.","published_time":"2026-09-29T17:53:14","cvss":9.1,"cvss_version":"3.1","epss":0.0,"assigner":"ibm","references":["https://www.ibm.com/support/pages/node/7288040"],"products":["Guardium Data Protection"],"vendors":["IBM"]}},{"cve_id":"CVE-2026-84440","summary":"IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.0067,"ranking_epss":0.50115,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://www.ibm.com/support/pages/node/7288035"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:17","euvd":{"id":"EUVD-2026-89192","description":"IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.","published_time":"2026-09-29T17:51:03","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"ibm","references":["https://www.ibm.com/support/pages/node/7288035"],"products":["Guardium Data Protection"],"vendors":["IBM"]}},{"cve_id":"CVE-2026-102808","summary":"PX4 Autopilot through 1.17.0 contains a NULL pointer dereference vulnerability in the sd_stress command where the -b byte count parameter is parsed without validation before being passed to malloc() and memset(). Attackers with shell access, including through MAVLink, can supply invalid byte count values to crash the flight controller.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":7.1,"epss":0.00244,"ranking_epss":0.14053,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/PX4/PX4-Autopilot","https://github.com/PX4/PX4-Autopilot/blob/d6f12ad1c4f70ad3230afd7d86e971421e02fef4/src/systemcmds/sd_stress/sd_stress.cpp#L186-L204","https://github.com/PX4/PX4-Autopilot/commit/c865dc9fde14d1391916775153aa271603c3c592","https://github.com/PX4/PX4-Autopilot/pull/28795","https://www.vulncheck.com/advisories/px4-autopilot-through-1.17.0-null-pointer-dereference-via-sd-stress"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:14","euvd":null},{"cve_id":"CVE-2026-102809","summary":"PX4 Autopilot through 1.17.0 contains an uncontrolled stack allocation vulnerability in the file2 test command that fails to validate the write chunk size parameter. Attackers with shell access can supply an excessively large value to the -c option to trigger stack overflow and crash the flight controller.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":7.1,"epss":0.00483,"ranking_epss":0.39296,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/PX4/PX4-Autopilot","https://github.com/PX4/PX4-Autopilot/blob/d6f12ad1c4f70ad3230afd7d86e971421e02fef4/src/systemcmds/tests/test_file2.c#L86-L130","https://github.com/PX4/PX4-Autopilot/commit/46a77d8ad15e7929ef261c41083dffd1bbfa9f85","https://github.com/PX4/PX4-Autopilot/pull/28586","https://www.vulncheck.com/advisories/px4-autopilot-through-1.17.0-stack-exhaustion-via-tests-file2-command","https://github.com/PX4/PX4-Autopilot/pull/28586"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:14","euvd":null},{"cve_id":"CVE-2026-102810","summary":"Marmite through 0.4.2 contains a path traversal vulnerability in the development server started by --serve that allows unauthenticated attackers to read arbitrary files. The handle_request function in src/server.rs fails to reject .. segments after percent-decoding and joining the request path to the output folder, enabling attackers to request encoded traversal sequences to access files readable by the marmite process.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":0.00389,"ranking_epss":0.30552,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/rochacbruno/marmite","https://github.com/rochacbruno/marmite/blob/4b2ddbd7595233b2e1d0086e18490fec49705098/src/server.rs#L180-L315","https://github.com/rochacbruno/marmite/commit/303a0bf2fff4302f4164c0c39932fdffc6683ad4","https://github.com/rochacbruno/marmite/issues/554","https://www.vulncheck.com/advisories/marmite-through-0.4.2-path-traversal-via-development-server"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:14","euvd":null},{"cve_id":"CVE-2026-102811","summary":"Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite__/content, /__marmite__/config, and /__marmite__/file/, allowing unauthenticated attackers to create, modify, and overwrite site content and configuration. Attackers can exploit unsanitized path parameters in handle_create_content and handle_clone_content to write files outside the project directory via directory traversal.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":8.7,"epss":0.00662,"ranking_epss":0.49787,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/rochacbruno/marmite","https://github.com/rochacbruno/marmite/blob/4b2ddbd7595233b2e1d0086e18490fec49705098/src/content.rs#L1064-L1075","https://github.com/rochacbruno/marmite/blob/4b2ddbd7595233b2e1d0086e18490fec49705098/src/content.rs#L1300-L1322","https://github.com/rochacbruno/marmite/blob/4b2ddbd7595233b2e1d0086e18490fec49705098/src/server.rs#L455-L475","https://github.com/rochacbruno/marmite/commit/303a0bf2fff4302f4164c0c39932fdffc6683ad4","https://github.com/rochacbruno/marmite/issues/554","https://www.vulncheck.com/advisories/marmite-through-0.4.2-unauthenticated-api-access-via-development-server"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:14","euvd":null},{"cve_id":"CVE-2026-12345","summary":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms.","cvss":5.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.9,"epss":0.0018,"ranking_epss":0.06801,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:14","euvd":{"id":"EUVD-2026-89183","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms.","published_time":"2026-09-29T17:46:01","cvss":5.9,"cvss_version":"4.0","epss":0.0,"assigner":"PSF","references":["https://github.com/python/cpython/pull/157580","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993"],"products":["CPython","CPython"],"vendors":["Python Software Foundation"]}},{"cve_id":"CVE-2026-102759","summary":"NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In `_nx_secure_verify_mac`, a decrypted application record whose length equals the negotiated MAC size is treated as valid and returns success after advancing the receive sequence number. The received MAC is never generated or compared.\n\n\n\nEmpty TLS application-data records are legal, and are commonly emitted by TLS 1.0 implementations as a BEAST mitigation.","cvss":6.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-m7j3-vh25-xc8p"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:13","euvd":{"id":"EUVD-2026-89208","description":"NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In `_nx_secure_verify_mac`, a decrypted application record whose length equals the negotiated MAC size is treated as valid and returns success after advancing the receive sequence number. The received MAC is never generated or compared.\n\n\n\nEmpty TLS application-data records are legal, and are commonly emitted by TLS 1.0 implementations as a BEAST mitigation.","published_time":"2026-09-29T17:28:04","cvss":6.3,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-m7j3-vh25-xc8p"],"products":["NetX Duo"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102760","summary":"When NetX Secure is built with `NX_SECURE_KEY_CLEAR`, every TLS record sent on an active session is wiped after it has been handed to TCP. By then the TCP layer owns the packet chain and may already have released it to the packet pool. The wipe therefore writes zeros into packets that are free or in use by another thread, and when a reused packet's pointers no longer describe the old data, the length of the wipe underflows and it runs past the end of the packet pool.","cvss":8.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-8w5x-ff58-2fr2"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:13","euvd":{"id":"EUVD-2026-89209","description":"When NetX Secure is built with `NX_SECURE_KEY_CLEAR`, every TLS record sent on an active session is wiped after it has been handed to TCP. By then the TCP layer owns the packet chain and may already have released it to the packet pool. The wipe therefore writes zeros into packets that are free or in use by another thread, and when a reused packet's pointers no longer describe the old data, the length of the wipe underflows and it runs past the end of the packet pool.","published_time":"2026-09-29T17:29:11","cvss":8.3,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-8w5x-ff58-2fr2"],"products":["NetX Duo"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102806","summary":"OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in the Gateway's local media root allowlist that breaks filesystem isolation between sandboxed sessions. Sandboxed sessions or untrusted content can cause the Gateway to read files from sibling session sandboxes or shared workspace directories through media pipeline functions that fail to restrict reads to the active session.","cvss":6.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.3,"cvss_v4":6.0,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.openclaw.ai/releases/2026.9.5","https://github.com/openclaw/openclaw","https://github.com/openclaw/openclaw/blob/3a9d69db306cd7f081e06254cb89c4bcc14a7107/src/media-understanding/runner.attachments.ts#L40-L50","https://github.com/openclaw/openclaw/blob/3a9d69db306cd7f081e06254cb89c4bcc14a7107/src/media/local-roots.ts#L33-L60","https://github.com/openclaw/openclaw/commit/fca04893b5b337d2eb70a6ba41f03fc8e33eff83","https://github.com/openclaw/openclaw/pull/144347","https://www.vulncheck.com/advisories/openclaw-before-2026.9.5-sandbox-isolation-bypass-via-media-pipelines"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:13","euvd":{"id":"EUVD-2026-89106","description":"OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in the Gateway's local media root allowlist that breaks filesystem isolation between sandboxed sessions. Sandboxed sessions or untrusted content can cause the Gateway to read files from sibling session sandboxes or shared workspace directories through media pipeline functions that fail to restrict reads to the active session.","published_time":"2026-09-29T17:22:39","cvss":6.0,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/openclaw/openclaw/pull/144347","https://github.com/openclaw/openclaw/commit/fca04893b5b337d2eb70a6ba41f03fc8e33eff83","https://github.com/openclaw/openclaw/blob/3a9d69db306cd7f081e06254cb89c4bcc14a7107/src/media/local-roots.ts#L33-L60","https://github.com/openclaw/openclaw/blob/3a9d69db306cd7f081e06254cb89c4bcc14a7107/src/media-understanding/runner.attachments.ts#L40-L50","https://docs.openclaw.ai/releases/2026.9.5","https://github.com/openclaw/openclaw","https://www.vulncheck.com/advisories/openclaw-before-2026.9.5-sandbox-isolation-bypass-via-media-pipelines"],"products":["OpenClaw"],"vendors":["OpenClaw"]}},{"cve_id":"CVE-2026-102807","summary":"OpenClaw before 2026.9.4 contains an incorrect authorization vulnerability in the mcp.app.view method that allows read-scoped operators to execute MCP App tools requiring operator.write scope. Attackers with operator.read tokens can obtain a standalone ticket from mcp.app.view and redeem it at the MCP app view endpoint to invoke state-changing tools without proper authorization checks.","cvss":6.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":5.3,"cvss_v4":6.0,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://docs.openclaw.ai/releases/2026.9.4","https://github.com/openclaw/openclaw","https://github.com/openclaw/openclaw/blob/1391f7cd2d40ab5bbcf2f5f831d3a64f520e72d7/src/gateway/mcp-app-standalone.ts#L209-L215","https://github.com/openclaw/openclaw/commit/3bd8ec2b39b5f9e80aef0973f7d17eadc745b8f8","https://github.com/openclaw/openclaw/pull/142661","https://www.vulncheck.com/advisories/openclaw-before-2026.9.4-authorization-bypass-via-mcp-app-standalone-ticket"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:13","euvd":{"id":"EUVD-2026-89107","description":"OpenClaw before 2026.9.4 contains an incorrect authorization vulnerability in the mcp.app.view method that allows read-scoped operators to execute MCP App tools requiring operator.write scope. Attackers with operator.read tokens can obtain a standalone ticket from mcp.app.view and redeem it at the MCP app view endpoint to invoke state-changing tools without proper authorization checks.","published_time":"2026-09-29T17:22:40","cvss":6.0,"cvss_version":"4.0","epss":0.0,"assigner":"VulnCheck","references":["https://github.com/openclaw/openclaw/pull/142661","https://github.com/openclaw/openclaw/commit/3bd8ec2b39b5f9e80aef0973f7d17eadc745b8f8","https://github.com/openclaw/openclaw/blob/1391f7cd2d40ab5bbcf2f5f831d3a64f520e72d7/src/gateway/mcp-app-standalone.ts#L209-L215","https://docs.openclaw.ai/releases/2026.9.4","https://github.com/openclaw/openclaw","https://www.vulncheck.com/advisories/openclaw-before-2026.9.4-authorization-bypass-via-mcp-app-standalone-ticket"],"products":["OpenClaw"],"vendors":["OpenClaw"]}},{"cve_id":"CVE-2026-102758","summary":"The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake.\n\n\n\nThe function reads the one-byte ASN.1 tag from the caller's buffer *before* checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns `NX_SECURE_X509_ASN1_LENGTH_TOO_LONG`, but the read has already happened one byte past the end of the buffer.\n\n\n\ncode:\n\n\n\nnx_secure/src/nx_secure_x509_asn1_tlv_block_parse.c\n\n\n\n```\n\n\n\nUINT _nx_secure_x509_asn1_tlv_block_parse(const UCHAR *buffer, ULONG *buffer_length, USHORT *tlv_type,\n\n                                          USHORT *tlv_tag_class, ULONG *tlv_length,\n                                          const UCHAR **tlv_data, ULONG *header_length)\n\n\n{\n\n\n\nUINT   current_index;\n\n\n\nUSHORT current_tag;\n\n\n\nULONG  length;\n\n\n\nULONG  length_bytes;\n\n    current_index = 0;\n    current_tag = buffer[current_index];      /* <-- read before the bounds check */\n    if (*buffer_length < 1)\n    {\n        return(NX_SECURE_X509_ASN1_LENGTH_TOO_LONG);\n    }\n\n\n```\n\n\n\nThe remainder of the function is correctly ordered. The multi-byte length path is guarded by `length_bytes > 4 || length_bytes > *buffer_length` before its read loop, the decoded value is checked against `length > *buffer_length`, and the second single-byte length read follows its own `*buffer_length < 1` guard. The tag read is the only load placed ahead of its check.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00093,"ranking_epss":0.00512,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-f95g-xc4w-mrcr"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:13","euvd":{"id":"EUVD-2026-89113","description":"The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake.\n\n\n\nThe function reads the one-byte ASN.1 tag from the caller's buffer *before* checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns `NX_SECURE_X509_ASN1_LENGTH_TOO_LONG`, but the read has already happened one byte past the end of the buffer.\n\n\n\ncode:\n\n\n\nnx_secure/src/nx_secure_x509_asn1_tlv_block_parse.c\n\n\n\n```\n\n\n\nUINT _nx_secure_x509_asn1_tlv_block_parse(const UCHAR *buffer, ULONG *buffer_length, USHORT *tlv_type,\n\n                                          USHORT *tlv_tag_class, ULONG *tlv_length,\n                                          const UCHAR **tlv_data, ULONG *header_length)\n\n\n{\n\n\n\nUINT   current_index;\n\n\n\nUSHORT current_tag;\n\n\n\nULONG  length;\n\n\n\nULONG  length_bytes;\n\n    current_index = 0;\n    current_tag = buffer[current_index];      /* <-- read before the bounds check */\n    if (*buffer_length < 1)\n    {\n        return(NX_SECURE_X509_ASN1_LENGTH_TOO_LONG);\n    }\n\n\n```\n\n\n\nThe remainder of the function is correctly ordered. The multi-byte length path is guarded by `length_bytes > 4 || length_bytes > *buffer_length` before its read loop, the decoded value is checked against `length > *buffer_length`, and the second single-byte length read follows its own `*buffer_length < 1` guard. The tag read is the only load placed ahead of its check.","published_time":"2026-09-29T17:26:44","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-f95g-xc4w-mrcr"],"products":["NetX Duo"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102761","summary":"NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the loop's upper bound belongs to the current packet. With the standard contiguous packet-pool layout, a masked server frame split across two packets therefore drives the XOR loop through the first packet's unused payload area and on through the second packet's `NX_PACKET` control block.\n\n\n\nThe four-byte WebSocket masking key controls the bytes written, so the corruption is attacker-chosen rather than incidental.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.3,"epss":0.00253,"ranking_epss":0.15142,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-6xgx-v7gw-qjph"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:13","euvd":{"id":"EUVD-2026-89210","description":"NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the loop's upper bound belongs to the current packet. With the standard contiguous packet-pool layout, a masked server frame split across two packets therefore drives the XOR loop through the first packet's unused payload area and on through the second packet's `NX_PACKET` control block.\n\n\n\nThe four-byte WebSocket masking key controls the bytes written, so the corruption is attacker-chosen rather than incidental.","published_time":"2026-09-29T17:30:45","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-6xgx-v7gw-qjph"],"products":["NetX Duo"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102762","summary":"The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed PUBLISH costs one packet, or one chain of packets, from the network driver's receive pool, and nothing returns it. A peer that can deliver a few dozen such messages exhausts the pool and stops all inbound network traffic on the device until it is rebooted.","cvss":8.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.2,"epss":0.00207,"ranking_epss":0.09757,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-9v23-qwp9-2q3h"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:13","euvd":{"id":"EUVD-2026-89171","description":"The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed PUBLISH costs one packet, or one chain of packets, from the network driver's receive pool, and nothing returns it. A peer that can deliver a few dozen such messages exhausts the pool and stops all inbound network traffic on the device until it is rebooted.","published_time":"2026-09-29T17:32:48","cvss":8.2,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-9v23-qwp9-2q3h"],"products":["NetX Duo"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102725","summary":"Out-of-bounds Read from Unvalidated MSRP Attribute List Length","cvss":6.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.0,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-m9hv-hvwf-5qh7"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:12","euvd":{"id":"EUVD-2026-89191","description":"Out-of-bounds Read from Unvalidated MSRP Attribute List Length","published_time":"2026-09-29T17:51:03","cvss":6.0,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-m9hv-hvwf-5qh7"],"products":["NetX Duo"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102726","summary":"Unbounded PPP IPCP Option Parsing Causes a Worker Stall and Out-of-bounds Read","cvss":6.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.0,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-2wwp-ffgp-6ggj"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:12","euvd":{"id":"EUVD-2026-89193","description":"Unbounded PPP IPCP Option Parsing Causes a Worker Stall and Out-of-bounds Read","published_time":"2026-09-29T17:51:48","cvss":6.0,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-2wwp-ffgp-6ggj"],"products":["NetX Duo"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102727","summary":"FTP Passive Data Connection Not Bound to the Authenticated Control Peer","cvss":6.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.0,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-r2qx-83vg-xqx4"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:12","euvd":{"id":"EUVD-2026-89199","description":"FTP Passive Data Connection Not Bound to the Authenticated Control Peer","published_time":"2026-09-29T17:57:37","cvss":6.0,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-r2qx-83vg-xqx4"],"products":["NetX Duo"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102729","summary":"`gx_binres_theme_load()` sizes its theme buffer for the theme it was asked for, and allocates it even when the resource holds no theme with that id. A theme id at or past the theme count declared by the resource gets a buffer of zero bytes. The load pass then walks past the end of the theme table, takes whatever follows as a theme header, and writes a `GX_THEME` and its tables into that zero-byte buffer.","cvss":5.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/guix/security/advisories/GHSA-372w-c338-xj8p"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:12","euvd":{"id":"EUVD-2026-89200","description":"`gx_binres_theme_load()` sizes its theme buffer for the theme it was asked for, and allocates it even when the resource holds no theme with that id. A theme id at or past the theme count declared by the resource gets a buffer of zero bytes. The load pass then walks past the end of the theme table, takes whatever follows as a theme header, and writes a `GX_THEME` and its tables into that zero-byte buffer.","published_time":"2026-09-29T17:58:45","cvss":5.9,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/guix/security/advisories/GHSA-372w-c338-xj8p"],"products":["Guix"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102730","summary":"Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the control block, giving a demonstrated control-flow hijack — RIP set to a full 8-byte attacker-chosen value (register-verified). Two accompanying OOB reads. All reproduced verbatim under ASan at HEAD `9f1cfdc`. (The affected metadata-parser header states \"Some portions generated by Copilot (Sonnet 4.6)\" — an AI-generated parser with an unchecked on-flash count.)","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/levelx/security/advisories/GHSA-q6ph-7238-777g"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:12","euvd":{"id":"EUVD-2026-89201","description":"Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the control block, giving a demonstrated control-flow hijack — RIP set to a full 8-byte attacker-chosen value (register-verified). Two accompanying OOB reads. All reproduced verbatim under ASan at HEAD `9f1cfdc`. (The affected metadata-parser header states \"Some portions generated by Copilot (Sonnet 4.6)\" — an AI-generated parser with an unchecked on-flash count.)","published_time":"2026-09-29T17:59:30","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/levelx/security/advisories/GHSA-q6ph-7238-777g"],"products":["eclipse-threadx/levelx(NAND driver)"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102757","summary":"An unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its choosing, in privileged mode, and can use that to clear the MPU enable bit and remove its own isolation boundary.\n\n\n\nThe Module Manager decided whether a privileged service could dereference an object address a module named by asking only whether that address fell outside the module. The manager's object pool is outside every module, so the test was satisfied by an address shifted into the interior of one of the module's own privileged allocations, which denotes no object at all. The bytes such an address presents as a control block are bytes the module put there through ordinary create and set services, so the control block ID at the front of them could be made to read as any type the module chose, and the `_txe_` layer's ID test then agreed. The reported chain uses that to reach a privileged `memset` across an attacker-chosen range.","cvss":8.5,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.5,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/threadx/security/advisories/GHSA-rrjj-jwcw-hvf8"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:12","euvd":{"id":"EUVD-2026-89112","description":"An unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its choosing, in privileged mode, and can use that to clear the MPU enable bit and remove its own isolation boundary.\n\n\n\nThe Module Manager decided whether a privileged service could dereference an object address a module named by asking only whether that address fell outside the module. The manager's object pool is outside every module, so the test was satisfied by an address shifted into the interior of one of the module's own privileged allocations, which denotes no object at all. The bytes such an address presents as a control block are bytes the module put there through ordinary create and set services, so the control block ID at the front of them could be made to read as any type the module chose, and the `_txe_` layer's ID test then agreed. The reported chain uses that to reach a privileged `memset` across an attacker-chosen range.","published_time":"2026-09-29T17:24:54","cvss":8.5,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/threadx/security/advisories/GHSA-rrjj-jwcw-hvf8"],"products":["ThreadX"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102728","summary":"Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them. Both are bounded out-of-bounds reads on a remotely reachable path, both are reached from a TLS or DTLS client connecting to a malicious or malformed server, and both have the same shape: the bounds check exists and returns the correct status, but it runs after the read it is meant to guard.","cvss":7.5,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.5,"cvss_v4":null,"epss":0.00139,"ranking_epss":0.02737,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-4q67-8385-j6m5"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:12","euvd":{"id":"EUVD-2026-89195","description":"Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them. Both are bounded out-of-bounds reads on a remotely reachable path, both are reached from a TLS or DTLS client connecting to a malicious or malformed server, and both have the same shape: the bounds check exists and returns the correct status, but it runs after the read it is meant to guard.","published_time":"2026-09-29T17:55:18","cvss":7.5,"cvss_version":"3.1","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-4q67-8385-j6m5"],"products":["NetX Duo"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102718","summary":"hey,\n\n\n\n`_nx_snmp_utility_object_id_get` in the NetX Duo SNMP addon does not validate the claimed OID data length against the actual buffer size when the OID uses BER multibyte length encoding, so a remote attacker can send a crafted SNMP packet with a multibyte OID length larger than the available buffer, causing the parser to read past the packet buffer boundary into adjacent heap memory. the OOB bytes are decoded as OID component values and written into the agents internal OID string buffer, corrupting agent state. on systems with memory protection the OOB read poses the risk of crashing the SNMP agent thread, causing denial of service. on bare metal embedded systems without memory protection the read silently succeeds and corrupts the agents internal state with heap data.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-7qmm-29vg-7hf8"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:11","euvd":{"id":"EUVD-2026-89181","description":"hey,\n\n\n\n`_nx_snmp_utility_object_id_get` in the NetX Duo SNMP addon does not validate the claimed OID data length against the actual buffer size when the OID uses BER multibyte length encoding, so a remote attacker can send a crafted SNMP packet with a multibyte OID length larger than the available buffer, causing the parser to read past the packet buffer boundary into adjacent heap memory. the OOB bytes are decoded as OID component values and written into the agents internal OID string buffer, corrupting agent state. on systems with memory protection the OOB read poses the risk of crashing the SNMP agent thread, causing denial of service. on bare metal embedded systems without memory protection the read silently succeeds and corrupts the agents internal state with heap data.","published_time":"2026-09-29T17:44:43","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-7qmm-29vg-7hf8"],"products":["NetX Duo"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102719","summary":"Predictable DTLS HelloVerifyRequest Cookie in NetX Secure","cvss":6.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-j6gx-3j6v-3hm4"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:11","euvd":{"id":"EUVD-2026-89182","description":"Predictable DTLS HelloVerifyRequest Cookie in NetX Secure","published_time":"2026-09-29T17:45:21","cvss":6.3,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-j6gx-3j6v-3hm4"],"products":["netxduo"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102720","summary":"A DHCP server, or anyone on the LAN who answers a DISCOVER first, can make the client read about a\n\n\n\nkilobyte past the end of the received message.\n\n\n\nThe option walk keeps a pointer and an offset in step, and the only bound check uses the offset:\n\n\n\n```c\n\n\n\n/* addons/dhcp/nxd_dhcp_client.c:7538, 7572 */\n\n\n\nwhile (i < length - 1)\n\n\n\n{\n\n    ...\n    size = *(++data);      /* data moves 1: type -> length byte */\n    data += size + 1;      /* data moves size + 1 more          */\n    i += size + 1;         /* i moves only size + 1             */\n\n\n}\n\n\n\n```\n\n\n\nA TLV option occupies size + 2 bytes. `data` is advanced by size + 2 in total, `i` by size + 1, so\n\n\n\nthe offset falls one byte behind the real read position for every option the walk skips. After\n\n\n\nenough skipped options the check `i < length - 1` still holds while `data` is already past the end\n\n\n\nof the message, and the subsequent read of the type and length bytes comes from whatever follows.\n\n\n\nA single OFFER carrying a long run of skippable options is enough:\n\n\n\n```\n\n\n\nERROR: AddressSanitizer: heap-buffer-overflow\n\n\n\nREAD of size 1 at 0x61b000000794 thread T5\n\n    #0 _nx_dhcp_search_buffer     addons/dhcp/nxd_dhcp_client.c:7541\n    #1 _nx_dhcp_get_option_value  addons/dhcp/nxd_dhcp_client.c:7082\n\n\n0x61b000000794 is located 164 bytes to the right of 1648-byte region\n\n\n\n```\n\n\n\nA well formed OFFER through the same path is handled normally, the client records the offer and\n\n\n\nmoves to REQUESTING, so the difference is the option layout rather than the harness.\n\n\n\nThe read runs in the DHCP client thread while the client is still unconfigured, so it happens on\n\n\n\nevery boot in reach of a hostile DHCP responder. The values read are used to configure the\n\n\n\ninterface, which is how the disclosed bytes become observable.\n\n\n\nAdvance `i` by size + 2, or derive the bound from `data` rather than keeping a second counter.","cvss":5.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.3,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-8hj5-p46x-5h28"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:11","euvd":{"id":"EUVD-2026-89184","description":"A DHCP server, or anyone on the LAN who answers a DISCOVER first, can make the client read about a\n\n\n\nkilobyte past the end of the received message.\n\n\n\nThe option walk keeps a pointer and an offset in step, and the only bound check uses the offset:\n\n\n\n```c\n\n\n\n/* addons/dhcp/nxd_dhcp_client.c:7538, 7572 */\n\n\n\nwhile (i < length - 1)\n\n\n\n{\n\n    ...\n    size = *(++data);      /* data moves 1: type -> length byte */\n    data += size + 1;      /* data moves size + 1 more          */\n    i += size + 1;         /* i moves only size + 1             */\n\n\n}\n\n\n\n```\n\n\n\nA TLV option occupies size + 2 bytes. `data` is advanced by size + 2 in total, `i` by size + 1, so\n\n\n\nthe offset falls one byte behind the real read position for every option the walk skips. After\n\n\n\nenough skipped options the check `i < length - 1` still holds while `data` is already past the end\n\n\n\nof the message, and the subsequent read of the type and length bytes comes from whatever follows.\n\n\n\nA single OFFER carrying a long run of skippable options is enough:\n\n\n\n```\n\n\n\nERROR: AddressSanitizer: heap-buffer-overflow\n\n\n\nREAD of size 1 at 0x61b000000794 thread T5\n\n    #0 _nx_dhcp_search_buffer     addons/dhcp/nxd_dhcp_client.c:7541\n    #1 _nx_dhcp_get_option_value  addons/dhcp/nxd_dhcp_client.c:7082\n\n\n0x61b000000794 is located 164 bytes to the right of 1648-byte region\n\n\n\n```\n\n\n\nA well formed OFFER through the same path is handled normally, the client records the offer and\n\n\n\nmoves to REQUESTING, so the difference is the option layout rather than the harness.\n\n\n\nThe read runs in the DHCP client thread while the client is still unconfigured, so it happens on\n\n\n\nevery boot in reach of a hostile DHCP responder. The values read are used to configure the\n\n\n\ninterface, which is how the disclosed bytes become observable.\n\n\n\nAdvance `i` by size + 2, or derive the bound from `data` rather than keeping a second counter.","published_time":"2026-09-29T17:46:23","cvss":5.3,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-8hj5-p46x-5h28"],"products":["eclipse-threadx/netxduo"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102721","summary":"A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the\n\n\n\nreceived datagram.\n\n\n\nEach receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229,\n\n\n\n1521, 1984). When the opcode is NX_TFTP_CODE_ERROR the message string is copied with a loop whose\n\n\n\nonly limits are the destination buffer and a NUL byte:\n\n\n\n```c\n\n\n\n/* addons/tftp/nxd_tftp_client.c:1769 */\n\n\n\nfor (i = 0; (i < (sizeof(tftp_client_ptr -> nx_tftp_client_error_string) - 1)) && (*buffer_ptr); i++)\n\n\n\n```\n\n\n\nNothing compares `buffer_ptr` against `nx_packet_append_ptr`. An ERROR packet that carries no\n\n\n\nterminating NUL, which a server controls completely, walks the loop off the end of the packet until\n\n\n\nit happens to meet a zero byte or fills the 64 byte destination.\n\n\n\n```\n\n\n\nERROR: AddressSanitizer: heap-buffer-overflow\n\n\n\nREAD of size 1 at 0x60d0000000c8 thread T4\n\n    #0 _nxd_tftp_client_file_read  addons/tftp/nxd_tftp_client.c:1769\n\n\n0x60d0000000c8 is 0 bytes to the right of 136-byte region\n\n\n\n```\n\n\n\nThe open path has the same loop at :1327 and reports the same way. What is read lands in\n\n\n\n`nx_tftp_client_error_string`, which the application is expected to display or log, so adjacent\n\n\n\npacket pool memory ends up in whatever the device does with the error text.\n\n\n\nAdd `(buffer_ptr < packet_ptr -> nx_packet_append_ptr)` to the loop condition in all three paths.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-wvc9-5m9h-rvxc"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:11","euvd":{"id":"EUVD-2026-89185","description":"A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the\n\n\n\nreceived datagram.\n\n\n\nEach receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229,\n\n\n\n1521, 1984). When the opcode is NX_TFTP_CODE_ERROR the message string is copied with a loop whose\n\n\n\nonly limits are the destination buffer and a NUL byte:\n\n\n\n```c\n\n\n\n/* addons/tftp/nxd_tftp_client.c:1769 */\n\n\n\nfor (i = 0; (i < (sizeof(tftp_client_ptr -> nx_tftp_client_error_string) - 1)) && (*buffer_ptr); i++)\n\n\n\n```\n\n\n\nNothing compares `buffer_ptr` against `nx_packet_append_ptr`. An ERROR packet that carries no\n\n\n\nterminating NUL, which a server controls completely, walks the loop off the end of the packet until\n\n\n\nit happens to meet a zero byte or fills the 64 byte destination.\n\n\n\n```\n\n\n\nERROR: AddressSanitizer: heap-buffer-overflow\n\n\n\nREAD of size 1 at 0x60d0000000c8 thread T4\n\n    #0 _nxd_tftp_client_file_read  addons/tftp/nxd_tftp_client.c:1769\n\n\n0x60d0000000c8 is 0 bytes to the right of 136-byte region\n\n\n\n```\n\n\n\nThe open path has the same loop at :1327 and reports the same way. What is read lands in\n\n\n\n`nx_tftp_client_error_string`, which the application is expected to display or log, so adjacent\n\n\n\npacket pool memory ends up in whatever the device does with the error text.\n\n\n\nAdd `(buffer_ptr < packet_ptr -> nx_packet_append_ptr)` to the loop condition in all three paths.","published_time":"2026-09-29T17:47:12","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-wvc9-5m9h-rvxc"],"products":["NetX Duo"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102722","summary":"In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227` reply. Validation only covers the parse and the non-zero values, thus a malicious server can name any address and direct the Client there.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.9,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-j6g2-8fm3-rm8m"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:11","euvd":{"id":"EUVD-2026-89187","description":"In the IPv4 PASV path, the FTP Client accepts whatever address was sent in the server's `227` reply. Validation only covers the parse and the non-zero values, thus a malicious server can name any address and direct the Client there.","published_time":"2026-09-29T17:47:56","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-j6g2-8fm3-rm8m"],"products":["NetX Duo"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102723","summary":"NULL Pointer Dereference on MSRP Attribute Table Exhaustion","cvss":6.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.0,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-jq4g-x753-4cc6"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:11","euvd":{"id":"EUVD-2026-89189","description":"NULL Pointer Dereference on MSRP Attribute Table Exhaustion","published_time":"2026-09-29T17:48:42","cvss":6.0,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-jq4g-x753-4cc6"],"products":["NetX Duo"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102724","summary":"NULL Pointer Dereference When Evicting the Sole MSRP Attribute","cvss":6.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.0,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-8rp9-5755-q75w"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:11","euvd":{"id":"EUVD-2026-89190","description":"NULL Pointer Dereference When Evicting the Sole MSRP Attribute","published_time":"2026-09-29T17:49:52","cvss":6.0,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-8rp9-5755-q75w"],"products":["NetX Duo"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102711","summary":"Two issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module object via `_txm_module_manager_memory_load` / `_txm_module_manager_in_place_load` — APIs that take ONLY a base pointer, no image length, so every size/offset field in `TXM_MODULE_PREAMBLE` is fully attacker-trusted: (1) a heap OOB **read** (`code_size` trusted as the source-image length in the code-copy loop), and (2) a control-flow-integrity / defense-in-depth gap (module entry/start/callback/stop pointers computed as `code_start + preamble_offset` with only a `!= 0` check, and the preamble `checksum` never verified). No controlled OOB write was found (honest — the copy destination is overflow-guarded).","cvss":5.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/threadx/security/advisories/GHSA-f53h-37j4-mqxx"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:10","euvd":{"id":"EUVD-2026-89174","description":"Two issues in the ThreadX loadable-module loader, reached when a device loads an attacker-controlled module object via `_txm_module_manager_memory_load` / `_txm_module_manager_in_place_load` — APIs that take ONLY a base pointer, no image length, so every size/offset field in `TXM_MODULE_PREAMBLE` is fully attacker-trusted: (1) a heap OOB **read** (`code_size` trusted as the source-image length in the code-copy loop), and (2) a control-flow-integrity / defense-in-depth gap (module entry/start/callback/stop pointers computed as `code_start + preamble_offset` with only a `!= 0` check, and the preamble `checksum` never verified). No controlled OOB write was found (honest — the copy destination is overflow-guarded).","published_time":"2026-09-29T17:38:22","cvss":5.6,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/threadx/security/advisories/GHSA-f53h-37j4-mqxx"],"products":["`eclipse-threadx/threadx` (module manager / loadable-module loader)"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102712","summary":"On the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the\n\n\n\nciphersuite-list length against the total record length instead of the remaining bytes. An unauthenticated\n\n\n\npeer drives an OOB source read of up to 255 bytes, and those bytes are echoed verbatim into the outgoing\n\n\n\nServerHello, disclosing adjacent process memory over the network. The crash variant fires on the first\n\n\n\npacket.","cvss":8.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.8,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-5xr3-wpxf-rw5q"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:10","euvd":{"id":"EUVD-2026-89175","description":"On the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the\n\n\n\nciphersuite-list length against the total record length instead of the remaining bytes. An unauthenticated\n\n\n\npeer drives an OOB source read of up to 255 bytes, and those bytes are echoed verbatim into the outgoing\n\n\n\nServerHello, disclosing adjacent process memory over the network. The crash variant fires on the first\n\n\n\npacket.","published_time":"2026-09-29T17:39:31","cvss":8.8,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-5xr3-wpxf-rw5q"],"products":["NetX Duo"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102713","summary":"The TFTP server accepts a DATA datagram of any size. The dispatcher rejects datagrams shorter than\n\n\n\nfour bytes (nxd_tftp_server.c:1037) and nothing anywhere checks an upper bound, in particular not\n\n\n\nagainst the protocol maximum of 4 + NX_TFTP_FILE_TRANSFER_MAX. Two things follow from that one\n\n\n\nmissing check, both reachable before any authentication because TFTP has none.\n\n\n\nThe handler passes `nx_packet_length - 4` straight to FileX:\n\n\n\n```c\n\n\n\n/* addons/tftp/nxd_tftp_server.c:1863, 1889 */\n\n\n\nstatus = nx_packet_copy(packet_ptr, &temp_ptr,\n\n                        server_ptr -> nx_tftp_server_packet_pool_ptr, NX_WAIT_FOREVER);\n\n\n...\n\n\n\nfx_file_write(&(client_request_ptr -> nx_tftp_client_request_file),\n\n              packet_ptr -> nx_packet_prepend_ptr + 4,\n              packet_ptr -> nx_packet_length - 4);\n\n\n```\n\n\n\n`nx_packet_length` is the length of a chain, not of one contiguous buffer, so FileX copies past the\n\n\n\nend of the first packet:\n\n\n\n```\n\n\n\nERROR: AddressSanitizer: heap-buffer-overflow\n\n\n\nREAD of size 1280 at 0x621000001108 thread T5\n\n    #0 __interceptor_memcpy\n    #1 _fx_utility_memory_copy  filex/common/src/fx_utility_memory_copy.c:78\n\n\n0x621000001108 is 0 bytes to the right of 4104-byte region\n\n\n\n```\n\n\n\nThose bytes are written into the file the attacker is uploading, and a TFTP read request hands them\n\n\n\nback, so this is a memory disclosure with a convenient retrieval channel.\n\n\n\nThe same datagram also wedges the server. `nx_packet_copy` at :1863 needs\n\n\n\nceil(nx_packet_length / pool_payload) packets and asks for them with NX_WAIT_FOREVER, so when the\n\n\n\nattacker sizes the datagram beyond what the pool holds, the server thread suspends and never\n\n\n\nreturns. A liveness probe after one such datagram times out with the pool at 0 of 12 packets and\n\n\n\nthe server thread suspended, and no later client is served.\n\n\n\nReject `nx_packet_length > 4 + NX_TFTP_FILE_TRANSFER_MAX` in the DATA branch before either call,\n\n\n\nand use a bounded wait rather than NX_WAIT_FOREVER for the copy.","cvss":8.8,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.8,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-wr79-332c-ff8f"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:10","euvd":{"id":"EUVD-2026-89176","description":"The TFTP server accepts a DATA datagram of any size. The dispatcher rejects datagrams shorter than\n\n\n\nfour bytes (nxd_tftp_server.c:1037) and nothing anywhere checks an upper bound, in particular not\n\n\n\nagainst the protocol maximum of 4 + NX_TFTP_FILE_TRANSFER_MAX. Two things follow from that one\n\n\n\nmissing check, both reachable before any authentication because TFTP has none.\n\n\n\nThe handler passes `nx_packet_length - 4` straight to FileX:\n\n\n\n```c\n\n\n\n/* addons/tftp/nxd_tftp_server.c:1863, 1889 */\n\n\n\nstatus = nx_packet_copy(packet_ptr, &temp_ptr,\n\n                        server_ptr -> nx_tftp_server_packet_pool_ptr, NX_WAIT_FOREVER);\n\n\n...\n\n\n\nfx_file_write(&(client_request_ptr -> nx_tftp_client_request_file),\n\n              packet_ptr -> nx_packet_prepend_ptr + 4,\n              packet_ptr -> nx_packet_length - 4);\n\n\n```\n\n\n\n`nx_packet_length` is the length of a chain, not of one contiguous buffer, so FileX copies past the\n\n\n\nend of the first packet:\n\n\n\n```\n\n\n\nERROR: AddressSanitizer: heap-buffer-overflow\n\n\n\nREAD of size 1280 at 0x621000001108 thread T5\n\n    #0 __interceptor_memcpy\n    #1 _fx_utility_memory_copy  filex/common/src/fx_utility_memory_copy.c:78\n\n\n0x621000001108 is 0 bytes to the right of 4104-byte region\n\n\n\n```\n\n\n\nThose bytes are written into the file the attacker is uploading, and a TFTP read request hands them\n\n\n\nback, so this is a memory disclosure with a convenient retrieval channel.\n\n\n\nThe same datagram also wedges the server. `nx_packet_copy` at :1863 needs\n\n\n\nceil(nx_packet_length / pool_payload) packets and asks for them with NX_WAIT_FOREVER, so when the\n\n\n\nattacker sizes the datagram beyond what the pool holds, the server thread suspends and never\n\n\n\nreturns. A liveness probe after one such datagram times out with the pool at 0 of 12 packets and\n\n\n\nthe server thread suspended, and no later client is served.\n\n\n\nReject `nx_packet_length > 4 + NX_TFTP_FILE_TRANSFER_MAX` in the DATA branch before either call,\n\n\n\nand use a bounded wait rather than NX_WAIT_FOREVER for the copy.","published_time":"2026-09-29T17:40:40","cvss":8.8,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-wr79-332c-ff8f"],"products":["NetX Duo"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102714","summary":"`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with that tail unexamined; the residue is not negative, so the function returns `NX_SUCCESS`. Its zero-length rejection never sees those bytes.\n\n\n\nEvery consumer then re-walks the same area, reading a two-byte option header at the residue and subtracting `nx_icmpv6_option_length << 3` with no zero check and no remaining-length check. Three outcomes follow, selected by bytes the attacker controls.\n\n\n\n**Zero length byte.** The walker subtracts zero and advances zero. All four handlers loop forever — `_nx_icmpv6_process_ra` (`nx_icmpv6_process_ra.c:245, :528`), `_nx_icmpv6_process_ns` (`:251, :329`), `_nx_icmpv6_process_na` (`:147, :156`) and `_nx_icmpv6_process_redirect` (`:247, :350`). The walk runs in the IP thread, which is the highest-priority thread and does not yield inside the loop, so the system stops until a watchdog reset and the frame can be replayed after each one.\n\n\n\n**Non-zero length byte on a short residue.** The three unsigned counters underflow — `2 - 8` becomes `0xFFFFFFFA` — and the walk continues past the packet buffer, reading until it faults or meets a zero length byte and freezes. The Router Advertisement counter is signed and exits cleanly in this case.\n\n\n\n**One-byte residue.** The walker reads a two-byte option header, over-reading one byte.\n\n\n\nDuring a runaway walk, stray bytes parsing as a link-layer address option are copied into the neighbor cache (`nx_icmpv6_process_ns.c:280, :293`) and subsequently used as the destination MAC for frames to that neighbour, placing off-packet memory on the link. Confirmed by inspection, not reproduced.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-39p4-p83c-58hr"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:10","euvd":{"id":"EUVD-2026-89177","description":"`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with that tail unexamined; the residue is not negative, so the function returns `NX_SUCCESS`. Its zero-length rejection never sees those bytes.\n\n\n\nEvery consumer then re-walks the same area, reading a two-byte option header at the residue and subtracting `nx_icmpv6_option_length << 3` with no zero check and no remaining-length check. Three outcomes follow, selected by bytes the attacker controls.\n\n\n\n**Zero length byte.** The walker subtracts zero and advances zero. All four handlers loop forever — `_nx_icmpv6_process_ra` (`nx_icmpv6_process_ra.c:245, :528`), `_nx_icmpv6_process_ns` (`:251, :329`), `_nx_icmpv6_process_na` (`:147, :156`) and `_nx_icmpv6_process_redirect` (`:247, :350`). The walk runs in the IP thread, which is the highest-priority thread and does not yield inside the loop, so the system stops until a watchdog reset and the frame can be replayed after each one.\n\n\n\n**Non-zero length byte on a short residue.** The three unsigned counters underflow — `2 - 8` becomes `0xFFFFFFFA` — and the walk continues past the packet buffer, reading until it faults or meets a zero length byte and freezes. The Router Advertisement counter is signed and exits cleanly in this case.\n\n\n\n**One-byte residue.** The walker reads a two-byte option header, over-reading one byte.\n\n\n\nDuring a runaway walk, stray bytes parsing as a link-layer address option are copied into the neighbor cache (`nx_icmpv6_process_ns.c:280, :293`) and subsequently used as the destination MAC for frames to that neighbour, placing off-packet memory on the link. Confirmed by inspection, not reproduced.","published_time":"2026-09-29T17:41:28","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-39p4-p83c-58hr"],"products":["NetX Duo"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102715","summary":"Any host on the LAN can send two mDNS records and make the responder write past the end of its\n\n\n\ntransmit packet.\n\n\n\nThe string table stores each name in a slot rounded up to a multiple of four:\n\n\n\n```c\n\n\n\n/* addons/mdns/nxd_mdns.c:11436, 11443, 11447 */\n\n\n\nmemory_len = ((memory_len & 0xFFFFFFFC) + 8) & 0xFFFFFFFF;\n\n\n\n...\n\n\n\nlen = *((USHORT*)(p - 2));           /* slot size, not string length */\n\n\n\nif ((len == memory_len) && ... _nx_mdns_name_match(start, memory_ptr, memory_size) ...)\n\n\n\n```\n\n\n\nThe lookup that decides whether an incoming name is already stored compares the rounded slot size,\n\n\n\nso names of 12, 13, 14 and 15 characters share one bucket. A second name in the bucket is answered\n\n\n\nwith the pointer to the first, and the record then carries a string up to three bytes longer than\n\n\n\nthe length the caller accounted for. `_nx_mdns_packet_rr_add` (nxd_mdns.c:8911) sizes its only\n\n\n\nbound check from that stale length, and `_nx_mdns_name_string_encode` writes the real string.\n\n\n\nTwo PTR records are enough, both ordinary mDNS responses to a `_http._tcp` query, with owner names\n\n\n\nwhose lengths fall in the same bucket:\n\n\n\n```\n\n\n\n==87491==ERROR: AddressSanitizer: heap-buffer-overflow\n\n\n\nWRITE of size 1 at 0x611000000124 thread T5\n\n    #0 _nx_mdns_name_string_encode  addons/mdns/nxd_mdns.c:13096\n    #1 _nx_mdns_packet_rr_add       addons/mdns/nxd_mdns.c:8911\n\n\n0x611000000124 is 0 bytes to the right of 228-byte region\n\n\n\n```\n\n\n\nThe overflow is one to three bytes of attacker-influenced name data past `nx_packet_data_end`. In a\n\n\n\nnormal pool that lands in the next packet in the same pool rather than in a redzone, so the visible\n\n\n\neffect is a corrupted neighbouring packet or a corrupted pool free list rather than a clean crash.\n\n\n\nCompare the slot size against the stored string length before declaring a match, or keep the\n\n\n\nstring length in the slot header and return it to the caller so the encoder and the bound check\n\n\n\nagree.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.1,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-2gf7-5224-5vrj"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:10","euvd":{"id":"EUVD-2026-89178","description":"Any host on the LAN can send two mDNS records and make the responder write past the end of its\n\n\n\ntransmit packet.\n\n\n\nThe string table stores each name in a slot rounded up to a multiple of four:\n\n\n\n```c\n\n\n\n/* addons/mdns/nxd_mdns.c:11436, 11443, 11447 */\n\n\n\nmemory_len = ((memory_len & 0xFFFFFFFC) + 8) & 0xFFFFFFFF;\n\n\n\n...\n\n\n\nlen = *((USHORT*)(p - 2));           /* slot size, not string length */\n\n\n\nif ((len == memory_len) && ... _nx_mdns_name_match(start, memory_ptr, memory_size) ...)\n\n\n\n```\n\n\n\nThe lookup that decides whether an incoming name is already stored compares the rounded slot size,\n\n\n\nso names of 12, 13, 14 and 15 characters share one bucket. A second name in the bucket is answered\n\n\n\nwith the pointer to the first, and the record then carries a string up to three bytes longer than\n\n\n\nthe length the caller accounted for. `_nx_mdns_packet_rr_add` (nxd_mdns.c:8911) sizes its only\n\n\n\nbound check from that stale length, and `_nx_mdns_name_string_encode` writes the real string.\n\n\n\nTwo PTR records are enough, both ordinary mDNS responses to a `_http._tcp` query, with owner names\n\n\n\nwhose lengths fall in the same bucket:\n\n\n\n```\n\n\n\n==87491==ERROR: AddressSanitizer: heap-buffer-overflow\n\n\n\nWRITE of size 1 at 0x611000000124 thread T5\n\n    #0 _nx_mdns_name_string_encode  addons/mdns/nxd_mdns.c:13096\n    #1 _nx_mdns_packet_rr_add       addons/mdns/nxd_mdns.c:8911\n\n\n0x611000000124 is 0 bytes to the right of 228-byte region\n\n\n\n```\n\n\n\nThe overflow is one to three bytes of attacker-influenced name data past `nx_packet_data_end`. In a\n\n\n\nnormal pool that lands in the next packet in the same pool rather than in a redzone, so the visible\n\n\n\neffect is a corrupted neighbouring packet or a corrupted pool free list rather than a clean crash.\n\n\n\nCompare the slot size against the stored string length before declaring a match, or keep the\n\n\n\nstring length in the slot header and return it to the caller so the encoder and the bound check\n\n\n\nagree.","published_time":"2026-09-29T17:42:35","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-2gf7-5224-5vrj"],"products":["eclipse-threadx/netxduo"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102716","summary":"An unauthenticated client can drain the RTSP server's packet pool with a couple of dozen requests\n\n\n\nthat carry a Session header the parser cannot convert.\n\n\n\nThe Session branch returns the raw NetX error code instead of an RTSP status code:\n\n\n\n```c\n\n\n\n/* addons/rtsp/nx_rtsp_server.c:2754 */\n\n\n\nstatus = _nx_utility_string_to_uint(field_value_ptr, field_value_length, &session_id);\n\n\n\nif (status)\n\n\n\n{\n\n    return(status);      /* NX_INVALID_PARAMETERS / NX_SIZE_ERROR / NX_OVERFLOW */\n\n\n}\n\n\n\n```\n\n\n\nEvery other branch of the same function maps its failure to an RTSP status first. The CSeq branch\n\n\n\neighteen lines earlier does exactly that (line 2736 returns NX_RTSP_STATUS_CODE_BAD_REQUEST). The\n\n\n\nraw code then reaches `_nx_rtsp_server_error_response_send` (nx_rtsp_server.c:1234), which does not\n\n\n\nrecognise it, takes a path that returns without releasing the response packet it already allocated,\n\n\n\nand the block never goes back to the pool.\n\n\n\nSix requests with an empty Session header against a 22 packet pool:\n\n\n\n```\n\n\n\nvalid requests:      after request 6: pool available = 21,  AFTER = 22 / 22\n\n\n\nmalformed requests:  after request 6: pool available = 16,  AFTER = 17 / 22\n\n\n\n```\n\n\n\nOne block per request, not returned when the client disconnects. Twenty six requests take the pool\n\n\n\nto zero and the server starts failing allocations, after which it serves nobody. If the pool is\n\n\n\nshared with the rest of the application, as it is in the shipped sample, the rest of the stack\n\n\n\nstops with it.\n\n\n\nConvert the `_nx_utility_string_to_uint` failure in the Session branch into\n\n\n\nNX_RTSP_STATUS_CODE_BAD_REQUEST the way the CSeq branch does, and release the response packet on\n\n\n\nevery exit path of `_nx_rtsp_server_error_response_send`.","cvss":8.7,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.7,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-q462-246c-x3jc"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:10","euvd":{"id":"EUVD-2026-89180","description":"An unauthenticated client can drain the RTSP server's packet pool with a couple of dozen requests\n\n\n\nthat carry a Session header the parser cannot convert.\n\n\n\nThe Session branch returns the raw NetX error code instead of an RTSP status code:\n\n\n\n```c\n\n\n\n/* addons/rtsp/nx_rtsp_server.c:2754 */\n\n\n\nstatus = _nx_utility_string_to_uint(field_value_ptr, field_value_length, &session_id);\n\n\n\nif (status)\n\n\n\n{\n\n    return(status);      /* NX_INVALID_PARAMETERS / NX_SIZE_ERROR / NX_OVERFLOW */\n\n\n}\n\n\n\n```\n\n\n\nEvery other branch of the same function maps its failure to an RTSP status first. The CSeq branch\n\n\n\neighteen lines earlier does exactly that (line 2736 returns NX_RTSP_STATUS_CODE_BAD_REQUEST). The\n\n\n\nraw code then reaches `_nx_rtsp_server_error_response_send` (nx_rtsp_server.c:1234), which does not\n\n\n\nrecognise it, takes a path that returns without releasing the response packet it already allocated,\n\n\n\nand the block never goes back to the pool.\n\n\n\nSix requests with an empty Session header against a 22 packet pool:\n\n\n\n```\n\n\n\nvalid requests:      after request 6: pool available = 21,  AFTER = 22 / 22\n\n\n\nmalformed requests:  after request 6: pool available = 16,  AFTER = 17 / 22\n\n\n\n```\n\n\n\nOne block per request, not returned when the client disconnects. Twenty six requests take the pool\n\n\n\nto zero and the server starts failing allocations, after which it serves nobody. If the pool is\n\n\n\nshared with the rest of the application, as it is in the shipped sample, the rest of the stack\n\n\n\nstops with it.\n\n\n\nConvert the `_nx_utility_string_to_uint` failure in the Session branch into\n\n\n\nNX_RTSP_STATUS_CODE_BAD_REQUEST the way the CSeq branch does, and release the response packet on\n\n\n\nevery exit path of `_nx_rtsp_server_error_response_send`.","published_time":"2026-09-29T17:43:55","cvss":8.7,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/netxduo/security/advisories/GHSA-q462-246c-x3jc"],"products":["eclipse-threadx/netxduo"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102710","summary":"Attacker model / Preconditions: a loaded `TXM_MODULE_USER_MODE | TXM_MODULE_MEMORY_PROTECTION` module issuing kernel dispatch calls, on a build with `TX_ENABLE_EVENT_TRACE`.\n\n\n\nA user-mode, memory-protected module can register an arbitrary function pointer as the global trace-full callback. The kernel calls it directly — no validation, no trampoline — from privileged kernel code when the trace buffer wraps.\n\n\n\nAn invalid pointer faults the kernel (DoS). A pointer into the module's own code was observed running with kernel privilege (`CONTROL.nPRIV = 0`), confirmed at runtime with a register capture inside that code.","cvss":9.3,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":9.3,"epss":0.00096,"ranking_epss":0.00638,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/threadx/security/advisories/GHSA-xr9m-8j99-rw4m"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:10","euvd":{"id":"EUVD-2026-89173","description":"Attacker model / Preconditions: a loaded `TXM_MODULE_USER_MODE | TXM_MODULE_MEMORY_PROTECTION` module issuing kernel dispatch calls, on a build with `TX_ENABLE_EVENT_TRACE`.\n\n\n\nA user-mode, memory-protected module can register an arbitrary function pointer as the global trace-full callback. The kernel calls it directly — no validation, no trampoline — from privileged kernel code when the trace buffer wraps.\n\n\n\nAn invalid pointer faults the kernel (DoS). A pointer into the module's own code was observed running with kernel privilege (`CONTROL.nPRIV = 0`), confirmed at runtime with a register capture inside that code.","published_time":"2026-09-29T17:37:04","cvss":9.3,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/threadx/security/advisories/GHSA-xr9m-8j99-rw4m"],"products":["eclipse-threadx/threadx"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102639","summary":"MobilityDB version 1.3.0 and earlier contains an out-of-bounds read vulnerability in the MEOS binary and library WKB deserialization logic that allows unprivileged database users to crash the PostgreSQL backend process by supplying a crafted WKB payload with a negative length field. The negative length value wraps to a large unsigned size_t due to missing signed validation, bypasses an overflow-unsafe pointer arithmetic bounds check in wkb_parse_state_check(), and causes memcpy() in text_from_wkb_state() to operate with a corrupted unbounded length, resulting in a remote denial-of-service condition affecting all sessions on the PostgreSQL instance.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":6.5,"cvss_v4":7.1,"epss":0.00324,"ranking_epss":0.23121,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/MobilityDB/MobilityDB/releases/tag/v1.2.2","https://github.com/MobilityDB/MobilityDB/releases/tag/v1.3.1","https://github.com/MobilityDB/MobilityDB/security/advisories/GHSA-2c92-2w7c-pm3g","https://www.vulncheck.com/advisories/mobilitydb-through-out-of-bounds-read-dos-via-wkb-deserialization"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:09","euvd":null},{"cve_id":"CVE-2026-102677","summary":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code cache did not verify that a cached entry matched the preload it was served for. A compromised renderer could write attacker-controlled cache data and cause Electron to reuse it for a later load, executing the renderer's code in the more privileged preload context. The issue affects applications that load untrusted content. This issue is fixed in versions 42.10.0, 43.5.0, and 44.0.0-beta.6.","cvss":7.8,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":7.8,"cvss_v4":null,"epss":0.0009,"ranking_epss":0.00421,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/electron/electron/commit/000453e399bd1dee5e86376cdd9ece5fc071e601","https://github.com/electron/electron/commit/25ba8be57c65a83d8c14ebb8aa37693df17a04f3","https://github.com/electron/electron/commit/c38d6fd68756f04647ea857bdb6a2abec332e217","https://github.com/electron/electron/pull/52480","https://github.com/electron/electron/releases/tag/v42.10.0","https://github.com/electron/electron/releases/tag/v43.5.0","https://github.com/electron/electron/releases/tag/v44.0.0-beta.6","https://github.com/electron/electron/security/advisories/GHSA-qmv3-fv6v-rmhq"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:09","euvd":null},{"cve_id":"CVE-2026-102709","summary":"Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executing in the non-secure world to supply pointers to secure memory. The secure firmware subsequently dereferences these attacker-controlled pointers without verifying that they reference non-secure memory, resulting in unintended disclosure of secure memory contents. This violates the isolation guarantees provided by Arm TrustZone-M and can be leveraged as a memory disclosure or corruption primitive that may enable recovery of sensitive cryptographic material.","cvss":8.4,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.4,"epss":0.00104,"ranking_epss":0.00955,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/eclipse-threadx/threadx/security/advisories/GHSA-ffg5-m7vh-vwrp"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:09","euvd":{"id":"EUVD-2026-89172","description":"Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executing in the non-secure world to supply pointers to secure memory. The secure firmware subsequently dereferences these attacker-controlled pointers without verifying that they reference non-secure memory, resulting in unintended disclosure of secure memory contents. This violates the isolation guarantees provided by Arm TrustZone-M and can be leveraged as a memory disclosure or corruption primitive that may enable recovery of sensitive cryptographic material.","published_time":"2026-09-29T17:36:17","cvss":8.4,"cvss_version":"4.0","epss":0.0,"assigner":"eclipse","references":["https://github.com/eclipse-threadx/threadx/security/advisories/GHSA-ffg5-m7vh-vwrp"],"products":["ThreadX"],"vendors":["Eclipse Foundation"]}},{"cve_id":"CVE-2026-102560","summary":"A flaw was found in libsoup. When the permessage-deflate WebSocket extension compresses a very large outgoing message, truncated size calculations used for GByteArray growth could wrap, causing zlib to write past the allocated buffer and resulting in a heap buffer overflow.","cvss":8.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-102560","https://bugzilla.redhat.com/show_bug.cgi?id=2543296"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:08","euvd":{"id":"EUVD-2026-89105","description":"A flaw was found in libsoup. When the permessage-deflate WebSocket extension compresses a very large outgoing message, truncated size calculations used for GByteArray growth could wrap, causing zlib to write past the allocated buffer and resulting in a heap buffer overflow.","published_time":"2026-09-29T17:15:36","cvss":8.6,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-102560","https://bugzilla.redhat.com/show_bug.cgi?id=2543296"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-102558","summary":"A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray based on an attacker-controlled frame length until the length wrapped, causing a heap buffer overflow while reading frame data.","cvss":8.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":null,"epss":0.003,"ranking_epss":0.20449,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-102558","https://bugzilla.redhat.com/show_bug.cgi?id=2543274"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:08","euvd":{"id":"EUVD-2026-89103","description":"A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray based on an attacker-controlled frame length until the length wrapped, causing a heap buffer overflow while reading frame data.","published_time":"2026-09-29T17:15:32","cvss":8.6,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-102558","https://bugzilla.redhat.com/show_bug.cgi?id=2543274"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-102559","summary":"A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray allocation APIs could be truncated while the masking routine still used the full length, causing a heap buffer overflow.","cvss":8.6,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.6,"cvss_v4":null,"epss":0.003,"ranking_epss":0.20448,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-102559","https://bugzilla.redhat.com/show_bug.cgi?id=2543285"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:08","euvd":{"id":"EUVD-2026-89104","description":"A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray allocation APIs could be truncated while the masking routine still used the full length, causing a heap buffer overflow.","published_time":"2026-09-29T17:15:34","cvss":8.6,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-102559","https://bugzilla.redhat.com/show_bug.cgi?id=2543285"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-102555","summary":"A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained embedded NUL bytes, the decoded length could remain uninitialized and be used as the size of the returned GBytes. This can lead to an out-of-bounds read or application crash when processing a crafted data URI.","cvss":8.2,"cvss_version":3.0,"cvss_v2":null,"cvss_v3":8.2,"cvss_v4":null,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://access.redhat.com/security/cve/CVE-2026-102555","https://bugzilla.redhat.com/show_bug.cgi?id=2543224"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:07","euvd":{"id":"EUVD-2026-89102","description":"A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained embedded NUL bytes, the decoded length could remain uninitialized and be used as the size of the returned GBytes. This can lead to an out-of-bounds read or application crash when processing a crafted data URI.","published_time":"2026-09-29T17:15:14","cvss":8.2,"cvss_version":"3.1","epss":0.0,"assigner":"redhat","references":["https://access.redhat.com/security/cve/CVE-2026-102555","https://bugzilla.redhat.com/show_bug.cgi?id=2543224"],"products":[],"vendors":[]}},{"cve_id":"CVE-2026-102242","summary":"Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks directories lexically without resolving symbolic links first, an attacker can access or overwrite arbitrary local files located outside the permitted root directories.","cvss":8.6,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.6,"epss":null,"ranking_epss":null,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://github.com/googleapis/mcp-toolbox/pull/3810"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T18:17:06","euvd":{"id":"EUVD-2026-89186","description":"Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks directories lexically without resolving symbolic links first, an attacker can access or overwrite arbitrary local files located outside the permitted root directories.","published_time":"2026-09-29T17:47:16","cvss":8.6,"cvss_version":"4.0","epss":0.0,"assigner":"Google","references":["https://github.com/googleapis/mcp-toolbox/pull/3810"],"products":["MCP Toolbox for Databases"],"vendors":["Google"]}},{"cve_id":"CVE-2026-92232","summary":"Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The cleanAttribute method removes HTML data URIs, however injected whitespaces characters could circumvent that cleanup, causing an XSS vector.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.1,"epss":0.00272,"ranking_epss":0.17682,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://developer.joomla.org/security-centre/1096-20260916-core-xss-filter-bypass-in-inputfilter-via-whitespace-characters-in-html-data-uris.html","https://www.joomla.org/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T17:17:15","euvd":{"id":"EUVD-2026-89073","description":"Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The cleanAttribute method removes HTML data URIs, however injected whitespaces characters could circumvent that cleanup, causing an XSS vector.","published_time":"2026-09-29T16:36:37","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"Joomla","references":["https://www.joomla.org/","https://developer.joomla.org/security-centre/1096-20260916-core-xss-filter-bypass-in-inputfilter-via-whitespace-characters-in-html-data-uris.html"],"products":["Joomla! Framework Filter package","Joomla! CMS","Joomla! Framework Filter package","Joomla! CMS"],"vendors":["Joomla! Project"]}},{"cve_id":"CVE-2026-92222","summary":"Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside requests were improperly validated, leading to SSRF vectors.","cvss":8.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.9,"epss":0.00207,"ranking_epss":0.09743,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://developer.joomla.org/security-centre/1089-20260909-core-ssrf-vectors-in-various-core-extensions.html","https://www.joomla.org/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T17:17:14","euvd":{"id":"EUVD-2026-89079","description":"Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside requests were improperly validated, leading to SSRF vectors.","published_time":"2026-09-29T16:38:49","cvss":8.9,"cvss_version":"4.0","epss":0.0,"assigner":"Joomla","references":["https://www.joomla.org/","https://developer.joomla.org/security-centre/1089-20260909-core-ssrf-vectors-in-various-core-extensions.html"],"products":["Joomla! CMS","Joomla! CMS"],"vendors":["Joomla! Project"]}},{"cve_id":"CVE-2026-92223","summary":"Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Joomla 5.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to update the workflow stage of inaccessible contents.","cvss":5.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.1,"epss":0.0026,"ranking_epss":0.16017,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://developer.joomla.org/security-centre/1090-20260910-core-improper-acl-checks-for-workflow-stage-changes.html","https://www.joomla.org/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T17:17:14","euvd":{"id":"EUVD-2026-89077","description":"Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage changes in Joomla 5.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to update the workflow stage of inaccessible contents.","published_time":"2026-09-29T16:38:34","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"Joomla","references":["https://www.joomla.org/","https://developer.joomla.org/security-centre/1090-20260910-core-improper-acl-checks-for-workflow-stage-changes.html"],"products":["Joomla! CMS","Joomla! CMS"],"vendors":["Joomla! Project"]}},{"cve_id":"CVE-2026-92224","summary":"Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The link toolbar layout did not properly escape inputs, leading to an XSS vector.","cvss":5.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.9,"epss":0.00256,"ranking_epss":0.15613,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://developer.joomla.org/security-centre/1091-20260911-core-xss-in-link-toolbar-layout.html","https://www.joomla.org/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T17:17:14","euvd":{"id":"EUVD-2026-89086","description":"Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The link toolbar layout did not properly escape inputs, leading to an XSS vector.","published_time":"2026-09-29T16:43:40","cvss":5.9,"cvss_version":"4.0","epss":0.0,"assigner":"Joomla","references":["https://www.joomla.org/","https://developer.joomla.org/security-centre/1091-20260911-core-xss-in-link-toolbar-layout.html"],"products":["Joomla! CMS","Joomla! CMS"],"vendors":["Joomla! Project"]}},{"cve_id":"CVE-2026-92225","summary":"Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The module list layout did not properly escape user supplied values, leading to an XSS vector.","cvss":5.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.9,"epss":0.00256,"ranking_epss":0.15613,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://developer.joomla.org/security-centre/1092-20260912-core-xss-in-module-list.html","https://www.joomla.org/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T17:17:14","euvd":{"id":"EUVD-2026-89075","description":"Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The module list layout did not properly escape user supplied values, leading to an XSS vector.","published_time":"2026-09-29T16:37:05","cvss":5.9,"cvss_version":"4.0","epss":0.0,"assigner":"Joomla","references":["https://www.joomla.org/","https://developer.joomla.org/security-centre/1092-20260912-core-xss-in-module-list.html"],"products":["Joomla! CMS","Joomla! CMS"],"vendors":["Joomla! Project"]}},{"cve_id":"CVE-2026-92226","summary":"Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform edit actions on otherwise uneditable items.","cvss":7.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.0,"epss":0.00259,"ranking_epss":0.15898,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://developer.joomla.org/security-centre/1093-20260913-core-improper-acl-checks-for-varous-webservice-edit-tasks.html","https://www.joomla.org/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T17:17:14","euvd":{"id":"EUVD-2026-89087","description":"Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform edit actions on otherwise uneditable items.","published_time":"2026-09-29T16:45:40","cvss":7.0,"cvss_version":"4.0","epss":0.0,"assigner":"Joomla","references":["https://www.joomla.org/","https://developer.joomla.org/security-centre/1093-20260913-core-improper-acl-checks-for-varous-webservice-edit-tasks.html"],"products":["Joomla! CMS","Joomla! CMS"],"vendors":["Joomla! Project"]}},{"cve_id":"CVE-2026-92227","summary":"Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature issuance of an rememberme cookie leads to a MFA bypass vulnerability.","cvss":8.2,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":8.2,"epss":0.00342,"ranking_epss":0.25319,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://developer.joomla.org/security-centre/1094-20260914-core-mfa-authentication-bypass-through-rememberme-cookies.html","https://www.joomla.org/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T17:17:14","euvd":{"id":"EUVD-2026-89074","description":"Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The premature issuance of an rememberme cookie leads to a MFA bypass vulnerability.","published_time":"2026-09-29T16:36:45","cvss":8.2,"cvss_version":"4.0","epss":0.0,"assigner":"Joomla","references":["https://www.joomla.org/","https://developer.joomla.org/security-centre/1094-20260914-core-mfa-authentication-bypass-through-rememberme-cookies.html"],"products":["Joomla! CMS","Joomla! CMS"],"vendors":["Joomla! Project"]}},{"cve_id":"CVE-2026-92231","summary":"Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute method normalized an attribute value before testing it against the \"javascript:\" scheme regex, however without decoding HTML5 entities beforehand, causing an XSS vector.","cvss":7.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.1,"epss":0.00272,"ranking_epss":0.17681,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://developer.joomla.org/security-centre/1095-20260915-core-xss-filter-bypass-in-inputfilter-via-html5-entity-decode-mismatch.html","https://www.joomla.org/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T17:17:14","euvd":{"id":"EUVD-2026-89082","description":"Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute method normalized an attribute value before testing it against the \"javascript:\" scheme regex, however without decoding HTML5 entities beforehand, causing an XSS vector.","published_time":"2026-09-29T16:40:58","cvss":7.1,"cvss_version":"4.0","epss":0.0,"assigner":"Joomla","references":["https://www.joomla.org/","https://developer.joomla.org/security-centre/1095-20260915-core-xss-filter-bypass-in-inputfilter-via-html5-entity-decode-mismatch.html"],"products":["Joomla! Framework Filter package","Joomla! Framework Filter package","Joomla! CMS","Joomla! CMS"],"vendors":["Joomla! Project"]}},{"cve_id":"CVE-2026-90907","summary":"Joomla! Core - [20260902] - Core - Unauthorized user account creation via profile.save controller in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The profile.save controller did not check the login state of a user, allowing the creation of guest-level users on sites without active user registration.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.9,"epss":0.00249,"ranking_epss":0.14616,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://developer.joomla.org/security-centre/1082-20260902-core-unauthorized-user-account-creation-via-profile-save-controller.html","https://www.joomla.org/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T17:17:13","euvd":{"id":"EUVD-2026-89085","description":"Joomla! Core - [20260902] - Core - Unauthorized user account creation via profile.save controller in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The profile.save controller did not check the login state of a user, allowing the creation of guest-level users on sites without active user registration.","published_time":"2026-09-29T16:43:24","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"Joomla","references":["https://www.joomla.org/","https://developer.joomla.org/security-centre/1082-20260902-core-unauthorized-user-account-creation-via-profile-save-controller.html"],"products":["Joomla! CMS","Joomla! CMS"],"vendors":["Joomla! Project"]}},{"cve_id":"CVE-2026-90913","summary":"Joomla! Core - [20260903] - Core - Improper ACL checks for access level webservice endpoints in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform mutation actions in access level endpoints.","cvss":7.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.0,"epss":0.00259,"ranking_epss":0.15898,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://developer.joomla.org/security-centre/1083-20260903-core-improper-acl-checks-for-user-level-webservice-endpoints.html","https://www.joomla.org/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T17:17:13","euvd":{"id":"EUVD-2026-89115","description":"Joomla! Core - [20260903] - Core - Improper ACL checks for access level webservice endpoints in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform mutation actions in access level endpoints.","published_time":"2026-09-29T16:36:15","cvss":7.0,"cvss_version":"4.0","epss":0.0,"assigner":"Joomla","references":["https://www.joomla.org/","https://developer.joomla.org/security-centre/1083-20260903-core-improper-acl-checks-for-user-level-webservice-endpoints.html"],"products":["Joomla! CMS","Joomla! CMS"],"vendors":["Joomla! Project"]}},{"cve_id":"CVE-2026-90914","summary":"Joomla! Core - [20260904] - Core - XSS in the generic media output layouts in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to an XSS vulnerability in the generic audio and video output layouts.","cvss":5.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.9,"epss":0.00256,"ranking_epss":0.15612,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://developer.joomla.org/security-centre/1084-20260904-core-xss-in-the-generic-media-output-layouts.html","https://www.joomla.org/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T17:17:13","euvd":{"id":"EUVD-2026-89083","description":"Joomla! Core - [20260904] - Core - XSS in the generic media output layouts in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to an XSS vulnerability in the generic audio and video output layouts.","published_time":"2026-09-29T16:42:23","cvss":5.9,"cvss_version":"4.0","epss":0.0,"assigner":"Joomla","references":["https://www.joomla.org/","https://developer.joomla.org/security-centre/1084-20260904-core-xss-in-the-generic-media-output-layouts.html"],"products":["Joomla! CMS","Joomla! CMS"],"vendors":["Joomla! Project"]}},{"cve_id":"CVE-2026-90915","summary":"Joomla! Core - [20260905] - Core - Arbitrary directory deletion via cache purge action in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 -An improper validation of the cache group name allowed path traverals in the file storage of the caching layer, resulting in arbitrary directory deletions.","cvss":7.0,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":7.0,"epss":0.00325,"ranking_epss":0.23178,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://developer.joomla.org/security-centre/1085-20260905-core-arbitrary-directory-deletion-via-cache-purge-action.html","https://www.joomla.org/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T17:17:13","euvd":{"id":"EUVD-2026-89088","description":"Joomla! Core - [20260905] - Core - Arbitrary directory deletion via cache purge action in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 -An improper validation of the cache group name allowed path traverals in the file storage of the caching layer, resulting in arbitrary directory deletions.","published_time":"2026-09-29T16:45:45","cvss":7.0,"cvss_version":"4.0","epss":0.0,"assigner":"Joomla","references":["https://www.joomla.org/","https://developer.joomla.org/security-centre/1085-20260905-core-arbitrary-directory-deletion-via-cache-purge-action.html"],"products":["Joomla! CMS","Joomla! CMS"],"vendors":["Joomla! Project"]}},{"cve_id":"CVE-2026-90916","summary":"Joomla! Core - [20260906] - Core - Improper ACL checks in content history comparison view in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view inaccessible contents.","cvss":5.1,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":5.1,"epss":0.00238,"ranking_epss":0.13422,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://developer.joomla.org/security-centre/1086-20260906-core-improper-acl-checks-in-content-history-comparsion-view.html","https://www.joomla.org/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T17:17:13","euvd":{"id":"EUVD-2026-89072","description":"Joomla! Core - [20260906] - Core - Improper ACL checks in content history comparison view in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view inaccessible contents.","published_time":"2026-09-29T16:36:35","cvss":5.1,"cvss_version":"4.0","epss":0.0,"assigner":"Joomla","references":["https://www.joomla.org/","https://developer.joomla.org/security-centre/1086-20260906-core-improper-acl-checks-in-content-history-comparsion-view.html"],"products":["Joomla! CMS","Joomla! CMS"],"vendors":["Joomla! Project"]}},{"cve_id":"CVE-2026-90917","summary":"Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged items in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view content items from inaccessible categories.","cvss":6.9,"cvss_version":4.0,"cvss_v2":null,"cvss_v3":null,"cvss_v4":6.9,"epss":0.00272,"ranking_epss":0.17675,"kev":false,"propose_action":null,"ransomware_campaign":null,"references":["https://developer.joomla.org/security-centre/1087-20260907-core-improper-acl-checks-in-outputs-for-tagged-items.html","https://www.joomla.org/"],"vendor":null,"product":null,"version":null,"published_time":"2026-09-29T17:17:13","euvd":{"id":"EUVD-2026-89076","description":"Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged items in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view content items from inaccessible categories.","published_time":"2026-09-29T16:38:00","cvss":6.9,"cvss_version":"4.0","epss":0.0,"assigner":"Joomla","references":["https://www.joomla.org/","https://developer.joomla.org/security-centre/1087-20260907-core-improper-acl-checks-in-outputs-for-tagged-items.html"],"products":["Joomla! CMS","Joomla! CMS"],"vendors":["Joomla! Project"]}}]}