[{"week":"2026-W39","as_of":"2026-09-25","fetched_at":"2026-09-25T00:00:00Z","cve_id":"CVE-2026-94097","cve_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94097","published_at":"2026-09-21T00:16:59Z","last_modified_at":"2026-09-24T13:17:17Z","description_short":"A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about…","ref_count":5,"cvss_version":"3.1","cvss_score":10.0,"cvss_severity":"CRITICAL","attack_vector":"NETWORK","attack_complexity":"LOW","privileges_required":"NONE","user_interaction":"NONE","remote_no_auth":true,"cwe_ids":"CWE-74,CWE-77","exploit_category":"command-injection","epss":0.03616,"epss_percentile":0.89049,"epss_missing":false,"epss_score_date":"2026-09-24T12:00:20Z","priority_score":96.17,"priority_tier":"p1","disclosure_rank":1,"row_hash":"0e36f15e968bc78b"},{"week":"2026-W39","as_of":"2026-09-25","fetched_at":"2026-09-25T00:00:00Z","cve_id":"CVE-2026-74849","cve_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74849","published_at":"2026-09-22T12:17:14Z","last_modified_at":"2026-09-23T04:17:44Z","description_short":"Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.","ref_count":1,"cvss_version":"3.1","cvss_score":9.8,"cvss_severity":"CRITICAL","attack_vector":"NETWORK","attack_complexity":"LOW","privileges_required":"NONE","user_interaction":"NONE","remote_no_auth":true,"cwe_ids":"CWE-78","exploit_category":"command-injection","epss":0.04606,"epss_percentile":0.9132,"epss_missing":false,"epss_score_date":"2026-09-24T12:00:20Z","priority_score":96.06,"priority_tier":"p1","disclosure_rank":2,"row_hash":"b162a3cb93c1a0e6"},{"week":"2026-W39","as_of":"2026-09-25","fetched_at":"2026-09-25T00:00:00Z","cve_id":"CVE-2026-95675","cve_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-95675","published_at":"2026-09-22T14:17:22Z","last_modified_at":"2026-09-22T20:25:55Z","description_short":"D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web management interface without valid credentials. Attackers can fully compromise the device to persistently modify its configuration and use it as a pivot point into the…","ref_count":3,"cvss_version":"3.1","cvss_score":9.8,"cvss_severity":"CRITICAL","attack_vector":"NETWORK","attack_complexity":"LOW","privileges_required":"NONE","user_interaction":"NONE","remote_no_auth":true,"cwe_ids":"CWE-78","exploit_category":"command-injection","epss":0.0391,"epss_percentile":0.8989,"epss_missing":false,"epss_score_date":"2026-09-24T12:00:20Z","priority_score":95.56,"priority_tier":"p1","disclosure_rank":3,"row_hash":"3961cc0bf0ae9ba7"},{"week":"2026-W39","as_of":"2026-09-25","fetched_at":"2026-09-25T00:00:00Z","cve_id":"CVE-2026-84434","cve_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84434","published_at":"2026-09-19T03:17:15Z","last_modified_at":"2026-09-21T13:33:33Z","description_short":"The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipeline, where hidden file upload fields bypass extension validation and a rejected file's intact upload state is later passed to upload_file() without…","ref_count":2,"cvss_version":"3.1","cvss_score":9.8,"cvss_severity":"CRITICAL","attack_vector":"NETWORK","attack_complexity":"LOW","privileges_required":"NONE","user_interaction":"NONE","remote_no_auth":true,"cwe_ids":"CWE-434","exploit_category":"file-upload","epss":0.03484,"epss_percentile":0.88653,"epss_missing":false,"epss_score_date":"2026-09-24T12:00:20Z","priority_score":95.13,"priority_tier":"p1","disclosure_rank":4,"row_hash":"8af8e04359b0fc0a"},{"week":"2026-W39","as_of":"2026-09-25","fetched_at":"2026-09-25T00:00:00Z","cve_id":"CVE-2026-43641","cve_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-43641","published_at":"2026-09-22T18:17:14Z","last_modified_at":"2026-09-23T16:16:43Z","description_short":"Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authentication through specific parameter combinations. Attackers can deserialize a crafted billing_data POST field and inject shell payloads through the uid field,…","ref_count":4,"cvss_version":"3.1","cvss_score":9.8,"cvss_severity":"CRITICAL","attack_vector":"NETWORK","attack_complexity":"LOW","privileges_required":"NONE","user_interaction":"NONE","remote_no_auth":true,"cwe_ids":"CWE-78","exploit_category":"command-injection","epss":0.03026,"epss_percentile":0.86916,"epss_missing":false,"epss_score_date":"2026-09-24T12:00:20Z","priority_score":94.52,"priority_tier":"p1","disclosure_rank":5,"row_hash":"a50c9d358f59d74b"},{"week":"2026-W39","as_of":"2026-09-25","fetched_at":"2026-09-25T00:00:00Z","cve_id":"CVE-2026-93616","cve_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93616","published_at":"2026-09-22T13:17:11Z","last_modified_at":"2026-09-23T16:38:38Z","description_short":"A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.","ref_count":3,"cvss_version":"3.1","cvss_score":9.8,"cvss_severity":"CRITICAL","attack_vector":"NETWORK","attack_complexity":"LOW","privileges_required":"NONE","user_interaction":"NONE","remote_no_auth":true,"cwe_ids":"CWE-22","exploit_category":"path-traversal","epss":0.02421,"epss_percentile":0.8347,"epss_missing":false,"epss_score_date":"2026-09-24T12:00:20Z","priority_score":93.31,"priority_tier":"p1","disclosure_rank":6,"row_hash":"36d1e672d407d12c"},{"week":"2026-W39","as_of":"2026-09-25","fetched_at":"2026-09-25T00:00:00Z","cve_id":"CVE-2026-94089","cve_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94089","published_at":"2026-09-20T21:16:55Z","last_modified_at":"2026-09-22T16:18:16Z","description_short":"A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.","ref_count":6,"cvss_version":"3.1","cvss_score":10.0,"cvss_severity":"CRITICAL","attack_vector":"NETWORK","attack_complexity":"LOW","privileges_required":"NONE","user_interaction":"NONE","remote_no_auth":true,"cwe_ids":"CWE-119,CWE-121","exploit_category":"memory-corruption","epss":0.01917,"epss_percentile":0.78976,"epss_missing":false,"epss_score_date":"2026-09-24T12:00:20Z","priority_score":92.64,"priority_tier":"p1","disclosure_rank":7,"row_hash":"59fccced37c76b70"},{"week":"2026-W39","as_of":"2026-09-25","fetched_at":"2026-09-25T00:00:00Z","cve_id":"CVE-2026-80155","cve_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80155","published_at":"2026-09-22T16:18:01Z","last_modified_at":"2026-09-24T20:17:31Z","description_short":"Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain an authentication bypass vulnerability in the web management portal upload endpoint that allows unauthenticated attackers to read sensitive configuration files and upload files to arbitrary filesystem locations, leading…","ref_count":6,"cvss_version":"3.1","cvss_score":10.0,"cvss_severity":"CRITICAL","attack_vector":"NETWORK","attack_complexity":"LOW","privileges_required":"NONE","user_interaction":"NONE","remote_no_auth":true,"cwe_ids":"CWE-22","exploit_category":"path-traversal","epss":0.01577,"epss_percentile":0.74393,"epss_missing":false,"epss_score_date":"2026-09-24T12:00:20Z","priority_score":91.04,"priority_tier":"p1","disclosure_rank":8,"row_hash":"fa671ba0276aaa36"},{"week":"2026-W39","as_of":"2026-09-25","fetched_at":"2026-09-25T00:00:00Z","cve_id":"CVE-2026-94493","cve_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94493","published_at":"2026-09-22T01:16:56Z","last_modified_at":"2026-09-24T23:19:22Z","description_short":"A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the file /index.html of the component WebSocket Service. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","ref_count":5,"cvss_version":"3.1","cvss_score":10.0,"cvss_severity":"CRITICAL","attack_vector":"NETWORK","attack_complexity":"LOW","privileges_required":"NONE","user_interaction":"NONE","remote_no_auth":true,"cwe_ids":"CWE-287,CWE-306","exploit_category":"access-control","epss":0.0134,"epss_percentile":0.70083,"epss_missing":false,"epss_score_date":"2026-09-24T12:00:20Z","priority_score":89.53,"priority_tier":"p1","disclosure_rank":9,"row_hash":"88854b681d37d938"},{"week":"2026-W39","as_of":"2026-09-25","fetched_at":"2026-09-25T00:00:00Z","cve_id":"CVE-2026-6721","cve_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6721","published_at":"2026-09-23T21:17:01Z","last_modified_at":"2026-09-25T04:17:38Z","description_short":"IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the underlying system. Successful exploitation allows remote code execution with the privileges of the affected application.","ref_count":1,"cvss_version":"3.1","cvss_score":9.8,"cvss_severity":"CRITICAL","attack_vector":"NETWORK","attack_complexity":"LOW","privileges_required":"NONE","user_interaction":"NONE","remote_no_auth":true,"cwe_ids":"CWE-78","exploit_category":"command-injection","epss":0.01449,"epss_percentile":0.72196,"epss_missing":false,"epss_score_date":"2026-09-24T12:00:20Z","priority_score":89.37,"priority_tier":"p1","disclosure_rank":10,"row_hash":"7f24db566d896aaf"},{"week":"2026-W39","as_of":"2026-09-25","fetched_at":"2026-09-25T00:00:00Z","cve_id":"CVE-2026-73369","cve_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73369","published_at":"2026-09-22T18:17:15Z","last_modified_at":"2026-09-24T14:18:41Z","description_short":"Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.","ref_count":1,"cvss_version":"3.1","cvss_score":10.0,"cvss_severity":"CRITICAL","attack_vector":"NETWORK","attack_complexity":"LOW","privileges_required":"NONE","user_interaction":"NONE","remote_no_auth":true,"cwe_ids":"CWE-94","exploit_category":"command-injection","epss":0.01248,"epss_percentile":0.68045,"epss_missing":false,"epss_score_date":"2026-09-24T12:00:20Z","priority_score":88.82,"priority_tier":"p1","disclosure_rank":11,"row_hash":"8b59fdff9274e175"},{"week":"2026-W39","as_of":"2026-09-25","fetched_at":"2026-09-25T00:00:00Z","cve_id":"CVE-2026-75699","cve_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75699","published_at":"2026-09-22T18:17:15Z","last_modified_at":"2026-09-23T20:32:40Z","description_short":"Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.","ref_count":1,"cvss_version":"3.1","cvss_score":10.0,"cvss_severity":"CRITICAL","attack_vector":"NETWORK","attack_complexity":"LOW","privileges_required":"NONE","user_interaction":"NONE","remote_no_auth":true,"cwe_ids":"CWE-94","exploit_category":"command-injection","epss":0.01248,"epss_percentile":0.68045,"epss_missing":false,"epss_score_date":"2026-09-24T12:00:20Z","priority_score":88.82,"priority_tier":"p1","disclosure_rank":12,"row_hash":"29c3dfc39e40b7ef"},{"week":"2026-W39","as_of":"2026-09-25","fetched_at":"2026-09-25T00:00:00Z","cve_id":"CVE-2026-75703","cve_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75703","published_at":"2026-09-22T18:17:15Z","last_modified_at":"2026-09-23T20:33:09Z","description_short":"Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.","ref_count":1,"cvss_version":"3.1","cvss_score":10.0,"cvss_severity":"CRITICAL","attack_vector":"NETWORK","attack_complexity":"LOW","privileges_required":"NONE","user_interaction":"NONE","remote_no_auth":true,"cwe_ids":"CWE-94","exploit_category":"command-injection","epss":0.01248,"epss_percentile":0.68044,"epss_missing":false,"epss_score_date":"2026-09-24T12:00:20Z","priority_score":88.82,"priority_tier":"p1","disclosure_rank":13,"row_hash":"1f5e8cd0a7825846"},{"week":"2026-W39","as_of":"2026-09-25","fetched_at":"2026-09-25T00:00:00Z","cve_id":"CVE-2026-75721","cve_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75721","published_at":"2026-09-22T18:17:16Z","last_modified_at":"2026-09-23T20:36:16Z","description_short":"Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.","ref_count":1,"cvss_version":"3.1","cvss_score":10.0,"cvss_severity":"CRITICAL","attack_vector":"NETWORK","attack_complexity":"LOW","privileges_required":"NONE","user_interaction":"NONE","remote_no_auth":true,"cwe_ids":"CWE-94","exploit_category":"command-injection","epss":0.01248,"epss_percentile":0.68044,"epss_missing":false,"epss_score_date":"2026-09-24T12:00:20Z","priority_score":88.82,"priority_tier":"p1","disclosure_rank":14,"row_hash":"1f3a3c289999b8b5"},{"week":"2026-W39","as_of":"2026-09-25","fetched_at":"2026-09-25T00:00:00Z","cve_id":"CVE-2026-84412","cve_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84412","published_at":"2026-09-22T18:17:22Z","last_modified_at":"2026-09-23T20:42:52Z","description_short":"Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.","ref_count":1,"cvss_version":"3.1","cvss_score":10.0,"cvss_severity":"CRITICAL","attack_vector":"NETWORK","attack_complexity":"LOW","privileges_required":"NONE","user_interaction":"NONE","remote_no_auth":true,"cwe_ids":"CWE-94","exploit_category":"command-injection","epss":0.01248,"epss_percentile":0.68045,"epss_missing":false,"epss_score_date":"2026-09-24T12:00:20Z","priority_score":88.82,"priority_tier":"p1","disclosure_rank":15,"row_hash":"e6cc0402e4a4dfa2"},{"week":"2026-W39","as_of":"2026-09-25","fetched_at":"2026-09-25T00:00:00Z","cve_id":"CVE-2026-89275","cve_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89275","published_at":"2026-09-22T18:17:29Z","last_modified_at":"2026-09-23T20:43:12Z","description_short":"Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.","ref_count":1,"cvss_version":"3.1","cvss_score":10.0,"cvss_severity":"CRITICAL","attack_vector":"NETWORK","attack_complexity":"LOW","privileges_required":"NONE","user_interaction":"NONE","remote_no_auth":true,"cwe_ids":"CWE-94","exploit_category":"command-injection","epss":0.01248,"epss_percentile":0.68045,"epss_missing":false,"epss_score_date":"2026-09-24T12:00:20Z","priority_score":88.82,"priority_tier":"p1","disclosure_rank":16,"row_hash":"6efff4530ebacb78"},{"week":"2026-W39","as_of":"2026-09-25","fetched_at":"2026-09-25T00:00:00Z","cve_id":"CVE-2026-86708","cve_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86708","published_at":"2026-09-23T14:17:09Z","last_modified_at":"2026-09-24T04:18:03Z","description_short":"ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.","ref_count":1,"cvss_version":"3.1","cvss_score":10.0,"cvss_severity":"CRITICAL","attack_vector":"NETWORK","attack_complexity":"LOW","privileges_required":"NONE","user_interaction":"NONE","remote_no_auth":true,"cwe_ids":"CWE-321","exploit_category":"other","epss":0.01244,"epss_percentile":0.67942,"epss_missing":false,"epss_score_date":"2026-09-24T12:00:20Z","priority_score":88.78,"priority_tier":"p1","disclosure_rank":17,"row_hash":"e87b55b8b6cb2501"},{"week":"2026-W39","as_of":"2026-09-25","fetched_at":"2026-09-25T00:00:00Z","cve_id":"CVE-2026-94127","cve_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94127","published_at":"2026-09-22T15:17:24Z","last_modified_at":"2026-09-23T14:32:07Z","description_short":"When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected…","ref_count":2,"cvss_version":"3.1","cvss_score":9.8,"cvss_severity":"CRITICAL","attack_vector":"NETWORK","attack_complexity":"LOW","privileges_required":"NONE","user_interaction":"NONE","remote_no_auth":true,"cwe_ids":"CWE-122","exploit_category":"memory-corruption","epss":0.01293,"epss_percentile":0.69016,"epss_missing":false,"epss_score_date":"2026-09-24T12:00:20Z","priority_score":88.26,"priority_tier":"p1","disclosure_rank":18,"row_hash":"0a46e8659896085b"},{"week":"2026-W39","as_of":"2026-09-25","fetched_at":"2026-09-25T00:00:00Z","cve_id":"CVE-2026-75723","cve_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75723","published_at":"2026-09-22T18:17:16Z","last_modified_at":"2026-09-23T20:36:39Z","description_short":"Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.","ref_count":1,"cvss_version":"3.1","cvss_score":10.0,"cvss_severity":"CRITICAL","attack_vector":"NETWORK","attack_complexity":"LOW","privileges_required":"NONE","user_interaction":"NONE","remote_no_auth":true,"cwe_ids":"CWE-863","exploit_category":"access-control","epss":0.01166,"epss_percentile":0.65906,"epss_missing":false,"epss_score_date":"2026-09-24T12:00:20Z","priority_score":88.07,"priority_tier":"p1","disclosure_rank":19,"row_hash":"2962b99a45a8e6ed"},{"week":"2026-W39","as_of":"2026-09-25","fetched_at":"2026-09-25T00:00:00Z","cve_id":"CVE-2026-75745","cve_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75745","published_at":"2026-09-22T19:16:47Z","last_modified_at":"2026-09-22T19:23:57Z","description_short":"Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.","ref_count":1,"cvss_version":"3.1","cvss_score":10.0,"cvss_severity":"CRITICAL","attack_vector":"NETWORK","attack_complexity":"LOW","privileges_required":"NONE","user_interaction":"NONE","remote_no_auth":true,"cwe_ids":"CWE-863","exploit_category":"access-control","epss":0.01166,"epss_percentile":0.65906,"epss_missing":false,"epss_score_date":"2026-09-24T12:00:20Z","priority_score":88.07,"priority_tier":"p1","disclosure_rank":20,"row_hash":"e94babcfd2aa7cb6"}]