NIST

CVE intelligence

Cached from NVD. 2026-09-19 PT. Critical.

CVETitleVendorPublishedCVSSKEV listed
CVE-2026-76460Cisco Identity Services Engine Incorrect Use of Privileged APIs VulnerabilityCisco2026-09-162026-09-16
CVE-2026-76461Cisco Secure Email Gateway SQL Injection VulnerabilityCisco2026-09-142026-09-14
CVE-2026-85706GitLab Community Edition and Enterprise Edition Path Traversal VulnerabilityGitlab2026-09-122026-09-11
CVE-2026-84869ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization VulnerabilityConnectwise2026-09-082026-09-11
CVE-2026-75650Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine VulnerabilityAdobe2026-09-072026-09-08
CVE-2026-86218N-able N-central Static Code Injection VulnerabilityN-able2026-09-062026-09-08
CVE-2026-86153A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Red2026-09-06
CVE-2026-86152A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddW2026-09-06
CVE-2026-86151A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the comp2026-09-06
CVE-2026-75816The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and 2026-09-06
CVE-2026-16310The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'i2026-09-06
CVE-2026-86190WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password2026-09-05
CVE-2026-86189WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitr2026-09-05
CVE-2026-86184Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attack2026-09-05
CVE-2026-86149A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This m2026-09-05
CVE-2026-86148A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of2026-09-05
CVE-2026-86124AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attack2026-09-05
CVE-2026-86123SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL qu2026-09-05
CVE-2026-86121Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfa2026-09-05
CVE-2026-86119Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asse2026-09-05
CVE-2026-86117Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts2026-09-05
CVE-2026-86060MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command VulnerabilityMikrotik2026-09-052026-09-10
CVE-2026-83627The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all ver2026-09-05
CVE-2026-78362The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing2026-09-05
CVE-2026-67276RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the ke2026-09-05
CVE-2026-52777YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImport2026-09-05
CVE-2026-52766YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.2026-09-05
CVE-2026-13447The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is 2026-09-05
CVE-2026-10196The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injectio2026-09-05
CVE-2024-11080The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2026-09-05
CVE-2026-83548SonicWall SMA1000 Appliances Server-Side Request Forgery VulnerabilitySonicwall2026-09-012026-09-02
CVE-2026-82329JFrog Artifactory Improper Authentication VulnerabilityJfrog2026-08-282026-09-02
CVE-2026-82078PaperCut NG/MF Unsafe Reflection VulnerabilityPapercut2026-08-282026-08-31
CVE-2026-60004Gitea Code Injection VulnerabilityGitea2026-08-262026-08-25
CVE-2026-72530TrueConf Server Code Injection VulnerabilityTrueconf2026-08-192026-08-20
CVE-2026-72529TrueConf Server Missing Authentication for Critical Function VulnerabilityTrueconf2026-08-192026-08-20
CVE-2026-19490Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel VulnerabilityCitrix2026-08-192026-09-09
CVE-2026-64849MLflow Server-Side Request Forgery VulnerabilityLfprojects2026-08-172026-08-19
CVE-2026-72898Metabase SQL Injection VulnerabilityMetabase2026-08-102026-08-11
CVE-2026-65400Apple macOS Improper Authentication VulnerabilityApple2026-08-062026-08-18

1–40 of 640Next