CVE catalog
Published CVEs with severity, CVSS and CISA KEV status. For Windows we also carry the part most catalogs leave blank: the update that fixes it, and the build revision that carries the fix.
394,950 CVEs · 1,716 known exploited · 2,982 Windows CVEs with a fix we can name
Newest first.
| CVE | Severity | CVSS | Exploited | Fix | Published | Description |
|---|---|---|---|---|---|---|
| CVE-2026-93870 | Medium | 4.3 | - | - | 2026-09-18 | Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge ratings on behalf of authenticated users. Attackers can craft malicious pages that auto-submit POST requests to modify stored rating data when visited by logged-in users. |
| CVE-2026-93869 | Medium | 6.1 | - | - | 2026-09-18 | Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor. Attackers can bypass the redirect guard by supplying hostnames beginning with the site domain to redirect users to attacker-contr... |
| CVE-2026-93868 | High | 8.1 | - | - | 2026-09-18 | Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date header, precompute candidate tokens within a narrow time window, and pro... |
| CVE-2026-93841 | Low | 3.7 | - | - | 2026-09-18 | vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index the penalty prompt-presence bitset without bounds checking against vocabulary size. Attackers can submit multimodal audio requests with tokens equal to vocabulary size, causing out-of-bounds writes... |
| CVE-2026-93840 | Low | 3.7 | - | - | 2026-09-18 | vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in SamplingParams._validate_allowed_token_ids(). Attackers can supply token IDs above the output vocabulary that pass validation, causing LogitBiasState to corrupt GPU logits state and allow concurrent requests... |
| CVE-2026-93839 | Critical | 9.8 | - | - | 2026-09-18 | LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of se... |
| CVE-2026-93838 | Medium | 5.9 | - | - | 2026-09-18 | SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments. Attackers with access to the decode engine's internal ZMQ rank port can send a frame with an extremely la... |
| CVE-2026-93031 | High | 8.8 | - | - | 2026-09-18 | The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads function. This is due to the import action being registered for unauthenticated users via... |
| CVE-2026-92708 | High | 7.5 | - | - | 2026-09-18 | Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, stringify and uneval functions serialize a typed array by emitting its entire backing ArrayBuffer rather than only the view, so serializing a Node Buffer, whose b... |
| CVE-2026-91205 | Medium | 6 | - | - | 2026-09-18 | A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation with owner assignment. By controlling a writable parent directory, the attacker can replace a newly created directory with a symbolic link (symlink) before the ownership change operation (chown) is ap... |
| CVE-2026-91203 | Medium | 6 | - | - | 2026-09-18 | A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged file operations such as changing file ownership or permissions. By manipulating directory entries and winning this race, the attacker can redirect these operation... |
| CVE-2026-91202 | Medium | 6.1 | - | - | 2026-09-18 | A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then using the privileged "Paste as owner" function. This allows for arbitrary file ownership changes outside the intended pasted directory, leading to a comprom... |
| CVE-2026-84241 | High | 8.1 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization. |
| CVE-2026-84239 | High | 7.6 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command. |
| CVE-2026-84108 | High | 8.1 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation. |
| CVE-2026-84106 | High | 8.9 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. |
| CVE-2026-84105 | High | 7.7 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command. |
| CVE-2026-84089 | High | 7.8 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management. |
| CVE-2026-84086 | High | 7.2 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory. |
| CVE-2026-84085 | High | 8.1 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command. |
| CVE-2026-84084 | High | 8.8 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability. |
| CVE-2026-84083 | High | 7.8 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argument validation in the SUID binary to execute arbitrary commands as root, resulting in... |
| CVE-2026-84082 | Critical | 9.8 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command. |
| CVE-2026-84081 | High | 8.1 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation. |
| CVE-2026-84078 | Critical | 9.9 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact to the integrity and availability of the affected system. |
| CVE-2026-84077 | High | 8.1 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability. |
| CVE-2026-84076 | High | 7.6 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization. |
| CVE-2026-84075 | Critical | 9.9 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet. |
| CVE-2026-84074 | High | 8.9 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. |
| CVE-2026-84073 | Critical | 9.1 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command. |
| CVE-2026-84071 | High | 7.2 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell command executed by the application, potentially resulting in arbitrary command execution... |
| CVE-2026-84070 | High | 8.9 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. |
| CVE-2026-84064 | Critical | 9.9 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command. |
| CVE-2026-84036 | High | 7.4 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization. |
| CVE-2026-84034 | High | 8.8 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthorized access to the internal database and compromise of sensitive system inf... |
| CVE-2026-84031 | Critical | 9 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. |
| CVE-2026-82967 | Critical | 9.8 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface. |
| CVE-2026-82896 | High | 7.6 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability. |
| CVE-2026-82893 | High | 7.8 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management. |
| CVE-2026-82892 | High | 8.1 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. |
| CVE-2026-82890 | Medium | 5.9 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary JavaScript code due to improper neutralization of input during web page generation. |
| CVE-2026-82887 | High | 8.8 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. |
| CVE-2026-82885 | High | 8.8 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API. |
| CVE-2026-82832 | Critical | 9.6 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation. |
| CVE-2026-82340 | Critical | 9.8 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit crafted serialized messages and potentially cause unintended code execution... |
| CVE-2026-81937 | High | 7.2 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command. A highly privileged authenticated user can inject shell commands through the filename parameter, potentially resulting in arbitrary command execution with root privileges and impact to t... |
| CVE-2026-81933 | High | 8.8 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in unauthorized access to sensitive data and impact to the confidentiality,... |
| CVE-2026-81669 | High | 7.2 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create csr wildcard CLI command. An authenticated privileged CLI user can inject arbitrary shell commands through the alias input, resulting in command execution with root privileges. |
| CVE-2026-81657 | Critical | 9.8 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data. |
| CVE-2026-81656 | High | 8.8 | - | - | 2026-09-18 | IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integ... |
What the Fix column means
A KB means we hold Microsoft's own remediation data for that CVE: the update that fixes it and, where Microsoft publishes one, the build revision that carries the fix. That is the difference between knowing a CVE exists and knowing whether the machine in front of you is still exposed to it.
If you want that answered for a specific machine rather than a specific CVE, paste your build into the patch checker. It walks the supersedence chain, so it can tell you that the update you actually installed covers a fix that shipped in an earlier one.
Where the data comes from
CVE records, CVSS scores and descriptions come from NVD. The exploited flag comes from CISA's KEV catalog. Windows fix data comes from Microsoft's own security update feed. We are not endorsed by or certified by any of them.