| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-4130 | Hig | 0.46 | 7.1 | 0.00 | Sep 10, 2026 | There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear. This vulnerability affects NI SystemLink and NI SystemLink… | ||
| CVE-2026-4129 | Hig | 0.53 | 8.1 | 0.00 | Sep 10, 2026 | There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server… | ||
| CVE-2026-88924 | Hig | 0.45 | 7.0 | 0.00 | Sep 10, 2026 | A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a… | ||
| CVE-2026-88898 | Med | 0.35 | 6.5 | 0.00 | Sep 10, 2026 | AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces. Attackers can write published views with attacker-controlled title,… | ||
| CVE-2026-88897 | Med | 0.31 | 5.9 | 0.00 | Sep 10, 2026 | Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant full API access. | ||
| CVE-2026-88008 | Cri | 0.52 | 9.1 | 0.00 | Sep 10, 2026 | Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backend. If the backend accepts h2c and returns… | ||
| CVE-2026-88007 | Cri | 0.52 | 9.1 | 0.00 | Sep 10, 2026 | Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport instead of a transport dedicated to each… | ||
| CVE-2026-88006 | Med | 0.35 | 6.5 | 0.00 | Sep 10, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without running the OAuth role management that the normal OAuth login callback… | ||
| CVE-2026-88005 | Med | 0.35 | 6.5 | 0.00 | Sep 10, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without applying the email domain allowlist that the normal OAuth login callback… | ||
| CVE-2026-88004 | Hig | 0.41 | 7.4 | 0.00 | Sep 10, 2026 | Traefik is an open source HTTP reverse proxy and load balancer. From 3.2.0 until 3.7.13, Traefik entrypoint defenses aliasHeadersStrategy, underscoreHeadersStrategy, and forwardedHeaders inspect req.Header but not req.Trailer, allowing an unauthenticated client to submit an… | ||
| CVE-2026-85310 | Med | 0.42 | 6.5 | 0.00 | Sep 10, 2026 | import_contacts Path Traversal in Groundhogg <= 4.7.1 versions. | ||
| CVE-2026-84821 | Hig | 0.49 | 7.5 | 0.00 | Sep 10, 2026 | Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions. | ||
| CVE-2026-84819 | Hig | 0.39 | 7.1 | 0.00 | Sep 10, 2026 | Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions. | ||
| CVE-2026-84816 | Hig | 0.46 | 7.1 | 0.00 | Sep 10, 2026 | Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions. | ||
| CVE-2026-81805 | Hig | 0.53 | 8.1 | 0.00 | Sep 10, 2026 | Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions. | ||
| CVE-2026-81804 | Hig | 0.49 | 7.5 | 0.00 | Sep 10, 2026 | Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions. | ||
| CVE-2026-81803 | Hig | 0.49 | 7.5 | 0.00 | Sep 10, 2026 | Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions. | ||
| CVE-2026-81801 | Hig | 0.46 | 8.1 | 0.00 | Sep 10, 2026 | Subscriber Settings Change in WP-Stateless <= 4.4.1 versions. | ||
| CVE-2026-81800 | Cri | 0.60 | 9.3 | 0.00 | Sep 10, 2026 | Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions. | ||
| CVE-2026-81799 | Hig | 0.49 | 7.5 | 0.00 | Sep 10, 2026 | Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions. | ||
| CVE-2026-81796 | Hig | 0.47 | 7.3 | 0.00 | Sep 10, 2026 | Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions. | ||
| CVE-2026-81795 | Hig | 0.46 | 7.1 | 0.00 | Sep 10, 2026 | Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter – Lite <= 1.2.3 versions. | ||
| CVE-2026-81794 | Hig | 0.49 | 7.5 | 0.00 | Sep 10, 2026 | Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions. | ||
| CVE-2026-81793 | Med | 0.42 | 6.5 | 0.00 | Sep 10, 2026 | Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions. | ||
| CVE-2026-81791 | Med | 0.42 | 6.5 | 0.00 | Sep 10, 2026 | Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions. | ||
| CVE-2026-81789 | Hig | 0.56 | 8.6 | 0.00 | Sep 10, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended for WooCommerce: from n/a through 3.1.6. | ||
| CVE-2026-81788 | Med | 0.41 | 6.3 | 0.00 | Sep 10, 2026 | Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions. | ||
| CVE-2026-81787 | Med | 0.42 | 6.5 | 0.00 | Sep 10, 2026 | Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions. | ||
| CVE-2026-81786 | Hig | 0.49 | 7.5 | 0.00 | Sep 10, 2026 | Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions. | ||
| CVE-2026-81785 | Med | 0.42 | 6.5 | 0.00 | Sep 10, 2026 | Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions. | ||
| CVE-2026-81784 | Hig | 0.53 | 8.1 | 0.00 | Sep 10, 2026 | Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions. | ||
| CVE-2026-81783 | Hig | 0.46 | 7.1 | 0.00 | Sep 10, 2026 | Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions. | ||
| CVE-2026-81782 | Med | 0.42 | 6.5 | 0.00 | Sep 10, 2026 | Subscriber Cross Site Scripting (XSS) in WP Docs <= 2.3.1 versions. | ||
| CVE-2026-81275 | Med | 0.42 | 6.5 | 0.00 | Sep 10, 2026 | Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions. | ||
| CVE-2026-78536 | Med | 0.42 | 6.5 | 0.00 | Sep 10, 2026 | Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions. | ||
| CVE-2026-66674 | Med | 0.36 | 5.6 | 0.00 | Sep 10, 2026 | Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions. | ||
| CVE-2026-66632 | Med | 0.42 | 6.5 | 0.00 | Sep 10, 2026 | Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1.42.1 versions. | ||
| CVE-2026-46387 | Hig | 0.42 | 7.5 | 0.01 | Sep 10, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's HTTP/2 decompression path could grow the decompressed response-body buffer without an effective upper bound. A… | ||
| CVE-2026-45747 | Hig | 0.42 | 7.5 | 0.00 | Sep 10, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lua script requested certificate information… | ||
| CVE-2026-15461 | Med | 0.27 | 5.3 | 0.00 | Sep 10, 2026 | The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, later drivers/modem/vendor_standalone/hl78xx/) embeds a generic struct gnss_nmea0183_match_data match_data inside struct hl78xx_gnss_data. The generic NMEA0183 match helper (drivers/gnss/gnss_nmea0183_match.c)… | ||
| CVE-2026-88921 | Med | 0.26 | — | 0.00 | Sep 10, 2026 | MISP contains an HTML injection vulnerability in the MISPElementHTMLFormatterTool component, which is responsible for rendering MISP element references (attributes, objects, and tags) into inline HTML during PDF report export via the convert_markdown_to_pdf module. The… | ||
| CVE-2026-88915 | Hig | 0.39 | — | 0.00 | Sep 10, 2026 | Affected versions of MISP do not consistently enforce the acting user's authorization when instantiating event templates. For templates using distribution = 4, the template can specify a sharing_group_id. The instantiation path passed that value into event creation without… | ||
| CVE-2026-88896 | Med | 0.27 | 5.3 | 0.00 | Sep 10, 2026 | EspoCRM before 10.0.4 is vulnerable to server-side request forgery. HostCheck::ipAddressIsNotInternal(), which validates outbound URLs to block requests to internal/private IP addresses, strips ::ffff: (IPv4-mapped IPv6) prefixes but does not recognize IPv6 transition addresses… | ||
| CVE-2026-88895 | Hig | 0.47 | 7.2 | 0.00 | Sep 10, 2026 | CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or… | ||
| CVE-2026-88894 | Med | 0.28 | 5.4 | 0.00 | Sep 10, 2026 | Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkout target. Unlike the single, bulk, API, accessory, license and consumable checkout paths, App\Services\PredefinedKitCheckoutService never calls… | ||
| CVE-2026-88893 | Hig | 0.49 | 7.5 | 0.00 | Sep 10, 2026 | OpenPanel share lookup procedures fail to validate access controls and return password hashes and protected report definitions to unauthenticated callers. Attackers with a share link can retrieve argon2id password hashes and full report configurations including event names,… | ||
| CVE-2026-88892 | Med | 0.33 | 5.0 | 0.00 | Sep 10, 2026 | OpenPanel is an analytics platform. In all versions (no patched release available at time of publication), the data importer fetches a caller-supplied URL with plain fetch instead of the project's existing SSRF guard (apps/api/src/utils/safe-fetch.ts). In… | ||
| CVE-2026-88891 | Hig | 0.54 | 8.3 | 0.00 | Sep 10, 2026 | OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedule entire projects for deletion,… | ||
| CVE-2026-88890 | Hig | 0.55 | 8.5 | 0.00 | Sep 10, 2026 | OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root… | ||
| CVE-2026-88889 | Hig | 0.44 | 7.8 | 0.01 | Sep 10, 2026 | Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inject shell commands through… |
- risk 0.46cvss 7.1epss 0.00
There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear. This vulnerability affects NI SystemLink and NI SystemLink…
- risk 0.53cvss 8.1epss 0.00
There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server…
- risk 0.45cvss 7.0epss 0.00
A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a…
- risk 0.35cvss 6.5epss 0.00
AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces. Attackers can write published views with attacker-controlled title,…
- risk 0.31cvss 5.9epss 0.00
Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant full API access.
- risk 0.52cvss 9.1epss 0.00
Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backend. If the backend accepts h2c and returns…
- risk 0.52cvss 9.1epss 0.00
Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport instead of a transport dedicated to each…
- risk 0.35cvss 6.5epss 0.00
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without running the OAuth role management that the normal OAuth login callback…
- risk 0.35cvss 6.5epss 0.00
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without applying the email domain allowlist that the normal OAuth login callback…
- risk 0.41cvss 7.4epss 0.00
Traefik is an open source HTTP reverse proxy and load balancer. From 3.2.0 until 3.7.13, Traefik entrypoint defenses aliasHeadersStrategy, underscoreHeadersStrategy, and forwardedHeaders inspect req.Header but not req.Trailer, allowing an unauthenticated client to submit an…
- risk 0.42cvss 6.5epss 0.00
import_contacts Path Traversal in Groundhogg <= 4.7.1 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.
- risk 0.39cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions.
- risk 0.49cvss 7.5epss 0.00
Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.
- risk 0.46cvss 8.1epss 0.00
Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.
- risk 0.47cvss 7.3epss 0.00
Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter – Lite <= 1.2.3 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions.
- risk 0.42cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions.
- risk 0.56cvss 8.6epss 0.00
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended for WooCommerce: from n/a through 3.1.6.
- risk 0.41cvss 6.3epss 0.00
Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions.
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions.
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions.
- risk 0.46cvss 7.1epss 0.00
Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.
- risk 0.42cvss 6.5epss 0.00
Subscriber Cross Site Scripting (XSS) in WP Docs <= 2.3.1 versions.
- risk 0.42cvss 6.5epss 0.00
Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions.
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.
- risk 0.36cvss 5.6epss 0.00
Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions.
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1.42.1 versions.
- risk 0.42cvss 7.5epss 0.01
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's HTTP/2 decompression path could grow the decompressed response-body buffer without an effective upper bound. A…
- risk 0.42cvss 7.5epss 0.00
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lua script requested certificate information…
- risk 0.27cvss 5.3epss 0.00
The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, later drivers/modem/vendor_standalone/hl78xx/) embeds a generic struct gnss_nmea0183_match_data match_data inside struct hl78xx_gnss_data. The generic NMEA0183 match helper (drivers/gnss/gnss_nmea0183_match.c)…
- risk 0.26cvss —epss 0.00
MISP contains an HTML injection vulnerability in the MISPElementHTMLFormatterTool component, which is responsible for rendering MISP element references (attributes, objects, and tags) into inline HTML during PDF report export via the convert_markdown_to_pdf module. The…
- risk 0.39cvss —epss 0.00
Affected versions of MISP do not consistently enforce the acting user's authorization when instantiating event templates. For templates using distribution = 4, the template can specify a sharing_group_id. The instantiation path passed that value into event creation without…
- risk 0.27cvss 5.3epss 0.00
EspoCRM before 10.0.4 is vulnerable to server-side request forgery. HostCheck::ipAddressIsNotInternal(), which validates outbound URLs to block requests to internal/private IP addresses, strips ::ffff: (IPv4-mapped IPv6) prefixes but does not recognize IPv6 transition addresses…
- risk 0.47cvss 7.2epss 0.00
CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or…
- risk 0.28cvss 5.4epss 0.00
Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkout target. Unlike the single, bulk, API, accessory, license and consumable checkout paths, App\Services\PredefinedKitCheckoutService never calls…
- risk 0.49cvss 7.5epss 0.00
OpenPanel share lookup procedures fail to validate access controls and return password hashes and protected report definitions to unauthenticated callers. Attackers with a share link can retrieve argon2id password hashes and full report configurations including event names,…
- risk 0.33cvss 5.0epss 0.00
OpenPanel is an analytics platform. In all versions (no patched release available at time of publication), the data importer fetches a caller-supplied URL with plain fetch instead of the project's existing SSRF guard (apps/api/src/utils/safe-fetch.ts). In…
- risk 0.54cvss 8.3epss 0.00
OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedule entire projects for deletion,…
- risk 0.55cvss 8.5epss 0.00
OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root…
- risk 0.44cvss 7.8epss 0.01
Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inject shell commands through…