AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.5 .0209 80.1 —
AFFECTED Product Versions Fixed CF-N1-S 2.6.0.1 – —
TIMELINE Aug 17 Reserved by CNA Aug 18 Public exploit reference published Aug 18 Published (CNA: VulDB)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
CISA adds 4 to KEV; 1407 CVEs published, led by Oracle Corporation (889).
1407 CVEs published August 18, 2026: 211 critical, 731 high, 373 medium, 60 low; 0 in the KEV catalog at press time; 1 with a public exploit reference; 32 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 1007 on continuation pages.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 7670 | 29817 | 1446 | 2564 |
| KEV catalog size | 1671 | |||
1637 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 1263 | 3580 | 363 | 1781 | 635 | 1 | 27 | 3 | 0.1 | 7.8 | .0016 | +1222 ▲ |
| microsoft | 444 | 1875 | 130 | 1274 | 448 | 14 | 380 | 35 | 1.9 | 7.8 | .0039 | -202 ▼ |
| 64 | 1824 | 224 | 754 | 786 | 57 | 74 | 6 | 0.3 | 7.5 | .0024 | -30 ▼ | |
| red hat | 161 | 517 | 35 | 210 | 246 | 26 | 4 | 0 | 0.0 | 6.6 | .0024 | +96 ▲ |
| apple | 34 | 300 | 57 | 77 | 154 | 5 | 94 | 8 | 2.7 | 6.5 | .0022 | +34 ▲ |
| canonical | 11 | 38 | 12 | 9 | 12 | 5 | 0 | 0 | 0.0 | 7.8 | .0017 | +7 ▲ |
| suse | 5 | 26 | 5 | 14 | 6 | 1 | 0 | 0 | 0.0 | 8.1 | .0030 | -3 ▼ |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0015 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 31 | 71 | 11 | 35 | 17 | 0 | 96 | 14 | 19.7 | 7.5 | .0034 | +15 ▲ |
| palo alto networks | 12 | 37 | 0 | 2 | 21 | 12 | 14 | 2 | 5.4 | 4.6 | .0018 | -2 ▼ |
| ubiquiti | 0 | 36 | 14 | 21 | 1 | 0 | 4 | 3 | 8.3 | 8.8 | .0036 | -25 ▼ |
| netgear | 9 | 32 | 0 | 0 | 27 | 5 | 8 | 0 | 0.0 | 4.3 | .0023 | +3 ▲ |
| fortinet | 7 | 30 | 4 | 8 | 14 | 1 | 28 | 6 | 20.0 | 6.6 | .0048 | -7 ▼ |
| f5 | 0 | 17 | 5 | 8 | 3 | 0 | 7 | 1 | 5.9 | 8.6 | .0057 | -8 ▼ |
| vmware | 0 | 16 | 4 | 8 | 2 | 2 | 22 | 1 | 6.3 | 8.2 | .0039 | -8 ▼ |
| ivanti | 3 | 14 | 2 | 6 | 2 | 0 | 33 | 5 | 35.7 | 7.9 | .0754 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 102 | 436 | 87 | 189 | 147 | 12 | 40 | 2 | 0.5 | 7.5 | .0048 | +24 ▲ |
| mozilla | 59 | 186 | 58 | 62 | 46 | 0 | 13 | 0 | 0.0 | 8.1 | .0026 | +53 ▲ |
| gitlab | 15 | 68 | 1 | 14 | 43 | 8 | 4 | 2 | 2.9 | 5.1 | .0025 | +8 ▲ |
| drupal | 0 | 51 | 6 | 5 | 35 | 5 | 5 | 1 | 2.0 | 5.9 | .0018 | -46 ▼ |
| github | 5 | 17 | 1 | 7 | 9 | 0 | 0 | 0 | 0.0 | 6.6 | .0037 | 0 |
| docker | 2 | 9 | 0 | 6 | 3 | 0 | 1 | 0 | 0.0 | 7.2 | .0016 | +2 ▲ |
| wordpress | 2 | 5 | 1 | 3 | 1 | 0 | 5 | 2 | 40.0 | 8.8 | .0089 | +2 ▲ |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0024 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 889 | 2268 | 486 | 1172 | 513 | 96 | 40 | 3 | 0.1 | 7.8 | .0032 | +888 ▲ |
| ibm | 192 | 421 | 97 | 182 | 136 | 6 | 7 | 1 | 0.2 | 7.5 | .0029 | +156 ▲ |
| adobe | 60 | 314 | 39 | 144 | 123 | 5 | 75 | 4 | 1.3 | 7.8 | .0021 | -34 ▼ |
| progress | 19 | 61 | 14 | 37 | 10 | 0 | 9 | 1 | 1.6 | 8.1 | .0032 | +9 ▲ |
| solarwinds | 0 | 23 | 16 | 2 | 3 | 0 | 11 | 4 | 17.4 | 9.1 | .0044 | 0 |
| veeam | 10 | 16 | 5 | 9 | 2 | 0 | 4 | 0 | 0.0 | 8.6 | .0028 | +10 ▲ |
| zohocorp | 4 | 10 | 3 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0129 | +4 ▲ |
| atlassian | 3 | 6 | 1 | 5 | 0 | 0 | 13 | 0 | 0.0 | 8.1 | .0034 | +3 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 16 | 37 | 15 | 5 | 9 | 7 | 26 | 1 | 2.7 | 7.4 | .0104 | +15 ▲ |
| siemens | 19 | 35 | 2 | 23 | 8 | 2 | 1 | 0 | 0.0 | 7.3 | .0013 | +12 ▲ |
| synology | 1 | 24 | 2 | 6 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +1 ▲ |
| rockwell automation | 0 | 24 | 4 | 18 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0025 | -17 ▼ |
| schneider electric | 0 | 9 | 1 | 6 | 2 | 0 | 1 | 0 | 0.0 | 8.6 | .0024 | 0 |
| abb | 0 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -1 ▼ |
| hikvision | 0 | 7 | 0 | 4 | 2 | 0 | 2 | 1 | 14.3 | 7.2 | .0025 | 0 |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 27 | 147 | 0 | 0 | 80 | 67 | 0 | 0 | 0.0 | 5.5 | .0026 | -14 ▼ |
| dell | 33 | 132 | 9 | 68 | 49 | 5 | 2 | 1 | 0.8 | 7.2 | .0019 | -4 ▼ |
| openclaw | 0 | 111 | 0 | 58 | 39 | 14 | 0 | 0 | 0.0 | 7.0 | .0022 | -44 ▼ |
| nvidia | 24 | 106 | 14 | 71 | 21 | 0 | 0 | 0 | 0.0 | 7.5 | .0026 | -16 ▼ |
| gitea | 48 | 89 | 19 | 36 | 30 | 4 | 0 | 0 | 0.0 | 7.5 | .0030 | +8 ▲ |
| siyuan-note | 66 | 88 | 39 | 19 | 28 | 1 | 0 | 0 | 0.0 | 8.7 | .0026 | +60 ▲ |
| itsourcecode | 17 | 88 | 0 | 0 | 19 | 69 | 0 | 0 | 0.0 | 2.1 | .0020 | +3 ▲ |
| zephyrproject | 34 | 87 | 2 | 30 | 46 | 9 | 0 | 0 | 0.0 | 6.5 | .0017 | +19 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-8037 | .9931 | 99.9 | 9.8 |
| CVE-2026-63030 | .9560 | 99.9 | 9.8 |
| CVE-2026-34486 | .8293 | 99.6 | 7.5 |
| CVE-2026-16232 | .7330 | 99.4 | 9.3 |
| CVE-2026-60137 | .7310 | 99.4 | 5.9 |
| CVE-2026-0770 | .5688 | 99.0 | 9.8 |
| CVE-2026-62144 | .2062 | 97.3 | 9.1 |
| CVE-2021-27137 | .1649 | 96.7 | 8.1 |
| CVE-2026-15733 | .1354 | 96.1 | 9.8 |
| CVE-2026-63077 | .1072 | 95.5 | 9.8 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-72898 | 10.0 | .1040 | KEV |
| CVE-2026-8985 | 10.0 | .0660 | |
| CVE-2026-6516 | 10.0 | .0473 | |
| CVE-2026-47668 | 10.0 | .0434 | |
| CVE-2026-48362 | 10.0 | .0207 | |
| CVE-2026-19188 | 10.0 | .0189 | |
| CVE-2026-73299 | 10.0 | .0121 | |
| CVE-2026-45618 | 10.0 | .0095 | |
| CVE-2025-71389 | 10.0 | .0093 | |
| CVE-2026-48168 | 10.0 | .0091 |
| Vendor | CVEs |
|---|---|
| oracle | 1997 |
| linux | 1628 |
| 466 | |
| microsoft | 463 |
| ibm | 261 |
| red hat | 260 |
| apache | 205 |
| apple | 201 |
| mozilla | 124 |
| adobe | 74 |
| Vendor | KEV |
|---|---|
| microsoft | 35 |
| cisco | 14 |
| apple | 8 |
| fortinet | 6 |
| 6 | |
| ivanti | 5 |
| adobe | 4 |
| solarwinds | 4 |
| synacor | 4 |
| langflow | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 66 |
| PyPI | 5 |
| npm | 5 |
| Go | 3 |
| Packagist | 2 |
| crates.io | 2 |
| NuGet | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2021-27137 | DD-WRT | 0 |
| CVE-2025-68686 | Fortinet | 0 |
| CVE-2026-0770 | Langflow | 0 |
| CVE-2026-16232 | checkpoint | 0 |
| CVE-2026-16812 | Arista Networks | 0 |
| CVE-2026-18556 | N-able | 0 |
| CVE-2026-18577 | N-able | 0 |
| CVE-2026-20316 | Cisco | 0 |
| CVE-2026-20349 | Cisco | 0 |
| CVE-2026-34486 | Apache Software Foundation | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1735 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1735 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1735 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1735 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1735 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1735 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1735 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1735 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1735 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1735 |
ADDED TO KEV — CVE-2026-33824 (Microsoft Windows 10 Version 1607). Remediation due August 21, 2026.
ADDED TO KEV — CVE-2026-55040 (Microsoft SharePoint Enterprise Server 2016). Remediation due August 21, 2026.
ADDED TO KEV — CVE-2026-59310 (VMware Cloud Foundation). Remediation due August 21, 2026.
ADDED TO KEV — CVE-2026-65400 (Apple macOS). Remediation due August 21, 2026.
EXPLOIT PUBLISHED — itsourcecode Hospital Management System: 6 CVEs (CVE-2026-19894, CVE-2026-19934, CVE-2026-19972, CVE-2026-75086, CVE-2026-75087, CVE-2026-75088). Public exploit references added.
EXPLOIT PUBLISHED — Webkul Bagisto: 6 CVEs (CVE-2026-19834, CVE-2026-19836, CVE-2026-19993, CVE-2026-19996, CVE-2026-75081, CVE-2026-75082). Public exploit references added.
EXPLOIT PUBLISHED — code-projects Online Shopping System: 4 CVEs (CVE-2026-19919, CVE-2026-19921, CVE-2026-19923, CVE-2026-19998). Public exploit references added.
EXPLOIT PUBLISHED — OpenBoxes: 4 CVEs (CVE-2024-14045, CVE-2024-14046, CVE-2026-19928, CVE-2026-19929). Public exploit references added.
EXPLOIT PUBLISHED — SourceCodester Class and Exam Timetabling System: 4 CVEs (CVE-2026-19899, CVE-2026-75077, CVE-2026-75079, CVE-2026-75080). Public exploit references added.
EXPLOIT PUBLISHED — TOTOLINK A800R: 4 CVEs (CVE-2026-19811, CVE-2026-19813, CVE-2026-19844, CVE-2026-19847). Public exploit references added.
EXPLOIT PUBLISHED — Edimax EW-7478APC: 3 CVEs (CVE-2026-19959, CVE-2026-19960, CVE-2026-19962). Public exploit references added.
EXPLOIT PUBLISHED — parallax jsPDF: 3 CVEs (CVE-2026-24737, CVE-2026-25535, CVE-2026-25755). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2024-21626 (opencontainers runc). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-25256 (Fortinet FortiSIEM). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-62593 (ray-project ray). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17106 (moby go-archive). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19751 (EnzoVezzaro mcp-dominican-layer). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19756 (Dromara lamp-cloud). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19758 (dromara lamp-cloud). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19765 (eyaushev swagger-testcase-mcp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19771 (Baicells EG3661M). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19788 (Tenda AC1206). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19790 (Tenda G0). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19821 (Tenda AC12). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19823 (Tenda W20E). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19826 (alldatacenter alldata). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19828 (648540858 wvp-GB28181-pro). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19839 (SourceCodester Simple Doctors Appointment System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19896 (mangroup dtale). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19898 (VictoriaMetrics). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19901 (LB-LINK X-PRO). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19904 (SourceCodester Online Book Store System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19905 (Jinher OA). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19916 (code-projects Online Food Order System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19918 (SpaceX Starlink Router Gen 3). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19924 (Tenda AC10). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19926 (Evergreen). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19932 (DefaultFuction Notice-System-Managent). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19955 (TrailDB). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19957 (graphlit-mcp-server). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19964 (Jij-Inc Jij-MCP-Server). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19967 (Open Asset Import Library Assimp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19969 (Open Asset Import Library Assimp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19974 (treefrogframework treefrog-framework). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19977 (EFM ipTIME A3004T). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19984 (jkawamoto mcp-florence2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19988 (Alaev SEO Tools Extension). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-25896 (NaturalIntelligence fast-xml-parser). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-26278 (NaturalIntelligence fast-xml-parser). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-53365 (Linux). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58049 (FFmpeg). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-60113 (NASA-AMMOS AIT-DSN). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-64600 (Linux). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-67579 (ash-project ash). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-69414 (Microsoft Malware Protection Engine). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-70667 (Netflix lemur). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-7246 (Pallets Click Click). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-72741 (goodrain rainbond). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-73482 (phplist3). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-74842 (Kira-Pgr PromptShopMCP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-74899 (jahlives openssl_encrypt). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75012 (TOTOLINK EX1200L). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75013 (TOTOLINK EX1200L). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75089 (PHPGurukul Complaint Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75090 (EricLBuehler Mistral.rs). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75093 (sonos tract). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75094 (COMFAST CF-N1-S). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75130 (Uptash Context7). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75773 (karakeep-app karakeep). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75774 (karakeep-app karakeep). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75778 (code-projects Task Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75783 (TRENDnet TEW-WLC100P). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75784 (TRENDnet TEW-WLC100). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75876 (xianrendzw EasyReport). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75877 (TRENDnet TV-IP751WIC). Public exploit reference added.
REJECTED — CVE-2026-64158 (Linux). Record withdrawn by the CNA.
REJECTED — CVE-2026-73682 (semaphoreui semaphore). Record withdrawn by the CNA.
REJECTED — CVE-2026-74511 (Linux). Record withdrawn by the CNA.
RESCORED — parallax jsPDF: 3 CVEs (CVE-2026-25755, CVE-2026-31898, CVE-2026-31938). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2024-44004 (Arni Cinco WPCargo Track & Trace). CVSS 9.3 → 9.8 (NVD).
RESCORED — CVE-2026-40478 (thymeleaf). CVSS 9.1 → 9 (NVD).
RESCORED — CVE-2026-41245 (junrar). CVSS 5.9 → 7.5 (NVD).
RESCORED — CVE-2026-75079 (SourceCodester Class and Exam Timetabling System). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-75080 (SourceCodester Class and Exam Timetabling System). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-75081 (Webkul Bagisto). CVSS 5.3 → 2.1 (NVD).
PATCH SHIPPED — rrrene html_sanitize_ex: 6 CVEs (CVE-2026-66370, CVE-2026-66829, CVE-2026-66843, CVE-2026-68747, CVE-2026-68749, CVE-2026-68750). Fix versions published.
PATCH SHIPPED — Red Hat OpenShift Container Platform 4.20: 3 CVEs (CVE-2026-42965, CVE-2026-50236, CVE-2026-50237). Fix versions published.
PATCH SHIPPED — CVE-2026-18739 (rpm-software-management popt). Fixed in Red Hat Hardened Images 1.19-11.1.hum1.
PATCH SHIPPED — CVE-2026-64611 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 1:2.0.0-13.el10_2.
PATCH SHIPPED — CVE-2026-64612 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 1:2.0.0-13.el10_2.
How to read these box scores · glossary
1407 CVEs published. 25 box scores and 375 table rows below; the remaining 1007 continue on page 2 · page 3 — every CVE is listed, nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.5 .0209 80.1 —
AFFECTED Product Versions Fixed CF-N1-S 2.6.0.1 – —
TIMELINE Aug 17 Reserved by CNA Aug 18 Public exploit reference published Aug 18 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0163 74.3 —
AFFECTED Product Versions Fixed Copilot Web - – —
TIMELINE Jan 21 Reserved by CNA Aug 18 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0118 65.1 —
AFFECTED Product Versions Fixed Forminator Forms – Contact Form, Payment Form & Custom Form Builder unspecified —
TIMELINE Jul 14 Reserved by CNA Aug 18 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0117 64.9 —
AFFECTED Product Versions Fixed valkey < 7.2.14 – —
TIMELINE Jul 17 Reserved by CNA Aug 18 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0107 62.2 —
AFFECTED Product Versions Fixed arcadedb unspecified 26.8.1
TIMELINE Aug 18 Reserved by CNA Aug 18 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0102 60.7 —
AFFECTED Product Versions Fixed TEW-WLC100 1v2.07b01 – —
TIMELINE Aug 18 Public exploit reference published Aug 18 Reserved by CNA Aug 18 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U H H H 7.5 .0089 56.5 —
AFFECTED Product Versions Fixed valkey < 7.2.14 – —
TIMELINE Jun 22 Reserved by CNA Aug 18 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0081 54.2 —
AFFECTED Product Versions Fixed seroval < 1.5.3 – —
TIMELINE Jul 7 Reserved by CNA Aug 18 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0080 53.8 —
AFFECTED Product Versions Fixed WP Compress n/a – 7.20.01
TIMELINE Aug 12 Reserved by CNA Aug 18 Published (CNA: Patchstack)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0079 53.5 —
AFFECTED Product Versions Fixed mybb < 1.8.40 – —
TIMELINE May 8 Reserved by CNA Aug 18 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N L N 6.9 .0071 50.7 —
AFFECTED Product Versions Fixed MailerUp unspecified —
TIMELINE Aug 18 Reserved by CNA Aug 18 Published (CNA: Secur0)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0068 49.5 —
AFFECTED Product Versions Fixed libexpat unspecified —
TIMELINE Jul 23 Reserved by CNA Aug 18 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H H H 8.1 .0065 48.5 —
AFFECTED Product Versions Fixed PowerStore 500T unspecified — PowerStore 1000T unspecified — PowerStore 1200T unspecified — PowerStore 3000T unspecified — PowerStore 3200Q unspecified — PowerStore 3200T unspecified — PowerStore 5000T unspecified — PowerStore 5200Q unspecified — PowerStore 5200T unspecified — PowerStore 7000T unspecified — + 2 more
TIMELINE Aug 4 Reserved by CNA Aug 18 Published (CNA: dell)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 9.4 .0063 47.3 —
AFFECTED Product Versions Fixed TEW-823DRU 1.1.02b01 – —
TIMELINE Aug 18 Reserved by CNA Aug 18 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.2 .0062 47.2 —
AFFECTED Product Versions Fixed FUXA < 1.3.3 – —
TIMELINE Jul 29 Reserved by CNA Aug 18 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N L L L 5.1 .0062 47.1 —
AFFECTED Product Versions Fixed blueprint-studio < 2.5.2 – —
TIMELINE Jun 9 Reserved by CNA Aug 18 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0061 46.7 —
AFFECTED Product Versions Fixed TV-IP751WIC 11.03.03 – —
TIMELINE Aug 18 Public exploit reference published Aug 18 Reserved by CNA Aug 18 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0061 46.6 —
AFFECTED Product Versions Fixed froxlor < 2.3.8 – —
TIMELINE Jun 12 Reserved by CNA Aug 18 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0059 45.6 —
AFFECTED Product Versions Fixed grav unspecified 2.0.15
TIMELINE Aug 18 Reserved by CNA Aug 18 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H L 9.0 .0059 45.4 —
AFFECTED Product Versions Fixed froxlor < 2.3.8 – —
TIMELINE Jul 14 Reserved by CNA Aug 18 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0057 44.9 —
AFFECTED Product Versions Fixed Red Hat Advanced Cluster Management for Kubernetes 2 unspecified —
TIMELINE Jul 27 Reserved by CNA Aug 18 Published (CNA: redhat)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0056 44.0 —
AFFECTED Product Versions Fixed Firefox unspecified 115.39 Thunderbird unspecified 140.14
TIMELINE Aug 17 Reserved by CNA Aug 18 Published (CNA: mozilla)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0056 43.9 —
AFFECTED Product Versions Fixed libheif >= 1.19.0, < 1.23.0 – —
TIMELINE Jun 3 Reserved by CNA Aug 18 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0054 43.0 —
AFFECTED Product Versions Fixed libheif >= 1.19.0, < 1.23.1 – —
TIMELINE Jul 13 Reserved by CNA Aug 18 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0053 42.3 —
AFFECTED Product Versions Fixed Easy Google Maps n/a – 1.14.0
TIMELINE Aug 12 Reserved by CNA Aug 18 Published (CNA: Patchstack)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-73380 | 9.8 | 42.3 | supsystic | Popup by Supsystic | CWE-502 | WordPress Popup by Supsystic plugin <= 1.13.0 - PHP Object Injection vulnerab… |
| CVE-2026-75773 | 2.9 | 42.3 | karakeep-app | karakeep | CWE-307 | karakeep-app karakeep Login Endpoint auth.ts authorize excessive authentication |
| CVE-2026-60672 | 9.8 | 42.1 | Oracle Corporation | Oracle WebLogic Server | — | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60696 | 9.8 | 42.1 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60698 | 9.8 | 42.1 | Oracle Corporation | Oracle WebLogic Server | CWE-306 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60858 | 9.8 | 42.1 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-60977 | 9.8 | 42.1 | Oracle Corporation | Oracle WebLogic Server | — | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-61318 | 9.8 | 42.1 | Oracle Corporation | Siebel CRM Cloud Applications | — | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-62626 | 9.8 | 42.1 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62632 | 9.8 | 42.1 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62633 | 9.8 | 42.1 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62635 | 9.8 | 42.1 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-70926 | 9.8 | 42.1 | Oracle Corporation | Oracle Workflow | — | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (comp… |
| CVE-2026-18929 | 6.9 | 42.0 | Carbone | Carbone | CWE-409 | Resource Exhaustion in Carbone |
| CVE-2026-75090 | 2.1 | 41.7 | EricLBuehler | Mistral.rs | CWE-119 | EricLBuehler Mistral.rs GGUF Tokenizer gguf_tokenizer.rs convert_gguf_to_hf_t… |
| CVE-2026-73381 | 9.1 | 41.5 | supsystic | Popup by Supsystic | CWE-288 | WordPress Popup by Supsystic plugin <= 1.13.0 - Broken Authentication vulnera… |
| CVE-2026-17084 | 6.0 | 41.4 | Python Software Foundation | CPython | CWE-436 | stringprep.map_table_b2() deviates from RFC 3454 Table B.2 |
| CVE-2026-60728 | 9.1 | 41.3 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-73502 | 5.3 | 41.2 | getkin | kin-openapi | CWE-476 | kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating… |
| CVE-2026-75897 | 8.7 | 41.0 | OpenSearch | OpenSearch Dashboards | CWE-1284 | Uncontrolled Resource Consumption in Capabilities Route in OpenSearch Dashboards |
| CVE-2026-75915 | 8.7 | 41.0 | Hmbown | CodeWhale | CWE-200 | CodeWhale before 0.8.64 Environment Variable Leak via js_execution |
| CVE-2026-70820 | 7.2 | 40.7 | Oracle Corporation | Oracle Call Center Technology | — | Vulnerability in the Oracle Call Center Technology product of Oracle E-Busine… |
| CVE-2026-50187 | 8.8 | 40.4 | ohmyzsh | ohmyzsh | CWE-94 | Oh My Zsh: Arbitrary Code Execution in oh-my-zsh dotenv plugin via malicious … |
| CVE-2026-67440 | 6.9 | 40.2 | frangoteam | FUXA | CWE-862 | FUXA: Unauthenticated Socket.IO read events |
| CVE-2026-47720 | 5.3 | 40.2 | frangoteam | FUXA | CWE-89 | FUXA: SQL injection in TDengine DAQ connector via backslash bypass of escapeT… |
| CVE-2026-61003 | 9.9 | 40.1 | Oracle Corporation | Oracle Managed File Transfer | — | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Mi… |
| CVE-2026-19500 | 7.5 | 40.0 | SureForms | SureForms | CWE-400 | SureForms contains an uncontrolled resource consumption vulnerability |
| CVE-2026-60721 | 9.8 | 39.9 | Oracle Corporation | Oracle Identity Manager | — | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-60727 | 9.8 | 40.0 | Oracle Corporation | Oracle Identity Manager | CWE-284 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-60782 | 9.8 | 40.0 | Oracle Corporation | Oracle Payments | — | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (comp… |
| CVE-2026-60821 | 9.8 | 39.9 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | — | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-60921 | 9.8 | 39.9 | Oracle Corporation | Oracle WebCenter Enterprise Capture | — | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60946 | 9.8 | 39.9 | Oracle Corporation | Oracle WebCenter Enterprise Capture | — | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60947 | 9.8 | 39.9 | Oracle Corporation | Oracle WebCenter Enterprise Capture | — | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60958 | 9.8 | 39.9 | Oracle Corporation | Oracle WebCenter Enterprise Capture | — | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-60970 | 9.8 | 39.9 | Oracle Corporation | Oracle WebCenter Enterprise Capture | — | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu… |
| CVE-2026-62457 | 9.8 | 39.9 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62544 | 9.8 | 39.9 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62592 | 9.8 | 39.9 | Oracle Corporation | Siebel CRM Integration | CWE-284 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-62609 | 9.8 | 39.9 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62611 | 9.8 | 39.9 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62614 | 9.8 | 39.9 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62617 | 9.8 | 39.9 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62621 | 9.8 | 39.9 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62622 | 9.8 | 40.0 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62624 | 9.8 | 39.9 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62630 | 9.8 | 39.9 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62634 | 9.8 | 39.9 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62639 | 9.8 | 40.0 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-62640 | 9.8 | 40.0 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-70689 | 9.8 | 39.9 | Oracle Corporation | Oracle Essbase | — | Vulnerability in Oracle Essbase (component: Infrastructure). The supported ve… |
| CVE-2026-70739 | 9.8 | 40.0 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70740 | 9.8 | 40.0 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70745 | 9.8 | 40.0 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70817 | 9.8 | 40.0 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70873 | 9.8 | 39.9 | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-70905 | 9.8 | 39.9 | Oracle Corporation | Oracle Access Manager | — | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-70970 | 9.8 | 40.0 | Oracle Corporation | Oracle WebCenter Portal | — | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-71040 | 9.8 | 39.9 | Oracle Corporation | Oracle Agile PLM | CWE-284 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-71074 | 9.8 | 39.9 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-71152 | 9.8 | 40.0 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-71164 | 9.8 | 40.0 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-60754 | 9.1 | 39.9 | Oracle Corporation | Siebel Apps - Marketing | — | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co… |
| CVE-2026-47719 | 8.2 | 39.8 | frangoteam | FUXA | CWE-918 | FUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PRO… |
| CVE-2026-74012 | 8.8 | 39.7 | Steve Burge | TaxoPress | CWE-502 | WordPress TaxoPress plugin <= 3.51.0 - PHP Object Injection vulnerability |
| CVE-2026-73181 | 7.5 | 39.6 | ThemeComplete | Extra Product Options & Add-Ons for WooCommerce | CWE-22 | WordPress Extra Product Options & Add-Ons for WooCommerce plugin < 7.6 - Arbi… |
| CVE-2026-60702 | 9.9 | 39.5 | Oracle Corporation | Oracle WebLogic Server | CWE-284 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-61206 | 9.9 | 39.5 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-61317 | 9.9 | 39.5 | Oracle Corporation | Siebel CRM Cloud Applications | — | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-70920 | 9.9 | 39.5 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-60716 | 8.8 | 39.5 | Oracle Corporation | Oracle Identity Manager | — | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-60722 | 8.8 | 39.5 | Oracle Corporation | Oracle Identity Manager | — | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-60731 | 8.8 | 39.5 | Oracle Corporation | Oracle WebCenter Portal | CWE-306 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-60751 | 8.8 | 39.5 | Oracle Corporation | Siebel Apps - Marketing | — | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co… |
| CVE-2026-60976 | 8.8 | 39.5 | Oracle Corporation | Oracle Scripting | — | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (com… |
| CVE-2026-61276 | 8.8 | 39.5 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-70710 | 8.8 | 39.5 | Oracle Corporation | Oracle Sales Foundation | — | Vulnerability in the Oracle Sales Foundation product of Oracle E-Business Sui… |
| CVE-2026-70729 | 8.8 | 39.5 | Oracle Corporation | Oracle Teleservice | — | Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (c… |
| CVE-2026-70737 | 8.8 | 39.5 | Oracle Corporation | Oracle Enterprise Manager for Systems Infrastructure | — | Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure pro… |
| CVE-2026-70747 | 8.8 | 39.5 | Oracle Corporation | Oracle Customers Online | — | Vulnerability in the Oracle Customers Online product of Oracle E-Business Sui… |
| CVE-2026-70813 | 8.8 | 39.5 | Oracle Corporation | Oracle Call Center Technology | — | Vulnerability in the Oracle Call Center Technology product of Oracle E-Busine… |
| CVE-2026-70918 | 8.8 | 39.5 | Oracle Corporation | Oracle Product Hub | — | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c… |
| CVE-2026-70922 | 8.8 | 39.5 | Oracle Corporation | Oracle Financial Services Enterprise Case Management | — | Vulnerability in the Oracle Financial Services Enterprise Case Management pro… |
| CVE-2026-71878 | 9.2 | 39.4 | GBIF | Integrated Publishing Toolkit | CWE-306 | Authentication bypass in Integrated Publishing Toolkit |
| CVE-2026-71879 | 9.1 | 39.4 | GBIF | Integrated Publishing Toolkit | CWE-288 | Authentication bypass in Integrated Publishing Toolkit |
| CVE-2026-63643 | 6.3 | 39.2 | MagicMirrorOrg | MagicMirror | CWE-441 | MagicMirror: ssrf calendar .js |
| CVE-2026-70854 | 9.1 | 39.1 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-65984 | 7.5 | 38.7 | frangoteam | FUXA | CWE-613 | FUXA: JWT lifecycle flaws allow deleted or demoted users to retain privileged… |
| CVE-2026-70876 | 9.1 | 38.6 | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-60883 | 7.2 | 38.6 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | — | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-70735 | 7.2 | 38.6 | Oracle Corporation | Oracle Hyperion Profitability and Cost Management | — | Vulnerability in the Oracle Hyperion Profitability and Cost Management produc… |
| CVE-2026-70781 | 7.2 | 38.6 | Oracle Corporation | Oracle Proposals | — | Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (com… |
| CVE-2026-70861 | 7.2 | 38.6 | Oracle Corporation | PeopleSoft Enterprise FIN Common Objects Brazil | — | Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product … |
| CVE-2026-70939 | 7.2 | 38.6 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70950 | 7.2 | 38.6 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-71099 | 7.2 | 38.6 | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | CWE-284 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-75774 | 2.9 | 38.6 | karakeep-app | karakeep | CWE-287 | karakeep-app karakeep OAuth Sign-In auth.ts improper authentication |
| CVE-2026-67271 | 9.8 | 38.4 | Dell | PowerStore 500T | CWE-787 | Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the S… |
| CVE-2026-70700 | 7.5 | 38.2 | Oracle Corporation | Oracle Payables | — | Vulnerability in the Oracle Payables product of Oracle E-Business Suite (comp… |
| CVE-2026-59949 | 6.5 | 38.3 | yawkat | lz4-java | CWE-476 | yawkat LZ4 Java: JVM Crash via Null Byte Array in lz4-java Streaming XXHash J… |
| CVE-2026-75852 | 9.3 | 37.7 | ArcadeData | arcadedb | CWE-306 | ArcadeDB MongoDB wire protocol authentication bypass cross-database |
| CVE-2026-32474 | 9.9 | 37.3 | wpWax | Templatiq | CWE-434 | WordPress Templatiq plugin <= 0.2.5 - Arbitrary File Upload vulnerability |
| CVE-2026-60720 | 9.9 | 37.3 | Oracle Corporation | Oracle Identity Manager | — | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-60730 | 9.9 | 37.3 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-62512 | 9.9 | 37.3 | Oracle Corporation | Siebel CRM Cloud Applications | — | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-62588 | 9.9 | 37.3 | Oracle Corporation | Siebel CRM Integration | CWE-284 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-62608 | 9.9 | 37.3 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-66627 | 9.9 | 37.3 | EDGE22 Studios Ltd. | GP Premium | CWE-434 | WordPress GP Premium plugin <= 2.5.5 - Arbitrary File Upload vulnerability |
| CVE-2026-60715 | 8.8 | 37.3 | Oracle Corporation | Oracle Identity Manager | CWE-284 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-60726 | 8.8 | 37.3 | Oracle Corporation | Oracle Access Manager | CWE-284 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-60729 | 8.8 | 37.3 | Oracle Corporation | Oracle WebCenter Portal | CWE-284 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew… |
| CVE-2026-60767 | 8.8 | 37.3 | Oracle Corporation | Siebel Apps - Marketing | — | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co… |
| CVE-2026-60879 | 8.8 | 37.3 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | — | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-61002 | 8.8 | 37.3 | Oracle Corporation | Oracle SOA Suite | — | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co… |
| CVE-2026-61017 | 8.8 | 37.3 | Oracle Corporation | Oracle WebCenter Sites | — | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-61022 | 8.8 | 37.3 | Oracle Corporation | Oracle WebCenter Sites | — | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-61032 | 8.8 | 37.3 | Oracle Corporation | Oracle WebCenter Sites | — | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-61040 | 8.8 | 37.3 | Oracle Corporation | Oracle WebCenter Sites | — | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-61058 | 8.8 | 37.3 | Oracle Corporation | Oracle WebCenter Sites | — | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-61118 | 8.8 | 37.3 | Oracle Corporation | Oracle Identity Manager | — | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-61284 | 8.8 | 37.3 | Oracle Corporation | Oracle Enterprise Manager Base Platform | — | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-61319 | 8.8 | 37.3 | Oracle Corporation | Oracle U.S. Federal Financials | — | Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Busin… |
| CVE-2026-61330 | 8.8 | 37.3 | Oracle Corporation | Siebel CRM Cloud Applications | — | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-61341 | 8.8 | 37.3 | Oracle Corporation | Siebel CRM Cloud Applications | — | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-62450 | 8.8 | 37.3 | Oracle Corporation | Oracle Flow Manufacturing | — | Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business S… |
| CVE-2026-62500 | 8.8 | 37.3 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62612 | 8.8 | 37.3 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-70686 | 8.8 | 37.3 | Oracle Corporation | Oracle General Ledger | — | Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite… |
| CVE-2026-70688 | 8.8 | 37.3 | Oracle Corporation | Oracle Essbase | — | Vulnerability in Oracle Essbase (component: Calculator). The supported versio… |
| CVE-2026-70742 | 8.8 | 37.3 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70761 | 8.8 | 37.3 | Oracle Corporation | Oracle Risk Management | — | Vulnerability in the Oracle Risk Management product of Oracle E-Business Suit… |
| CVE-2026-70818 | 8.8 | 37.3 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70821 | 8.8 | 37.3 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70863 | 8.8 | 37.3 | Oracle Corporation | Oracle Application Testing Suite | — | Vulnerability in Oracle Application Testing Suite. The supported version that… |
| CVE-2026-70877 | 8.8 | 37.3 | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-70886 | 8.8 | 37.3 | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-70928 | 8.8 | 37.3 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70940 | 8.8 | 37.3 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70944 | 8.8 | 37.3 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70948 | 8.8 | 37.3 | Oracle Corporation | Oracle Purchasing | — | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co… |
| CVE-2026-70949 | 8.8 | 37.3 | Oracle Corporation | Siebel CRM Deployment | CWE-284 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-70966 | 8.8 | 37.3 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | CWE-284 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-71039 | 8.8 | 37.3 | Oracle Corporation | Oracle Agile PLM | CWE-284 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-71055 | 8.8 | 37.3 | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | CWE-284 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-71067 | 8.8 | 37.3 | Oracle Corporation | Oracle Agile PLM MCAD Connector | — | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply… |
| CVE-2026-52736 | 8.7 | 37.1 | ZcashFoundation | zebra | CWE-459 | ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cache |
| CVE-2026-61302 | 8.2 | 37.1 | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | CWE-284 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-70743 | 8.2 | 37.1 | Oracle Corporation | Oracle Hyperion Financial Reporting | CWE-284 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-75627 | 9.3 | 37.0 | bastillion-io | Bastillion | CWE-288 | Bastillion Authentication Bypass via Path-Prefix Routing Mismatch |
| CVE-2026-57580 | 9.4 | 36.9 | goauthentik | authentik | CWE-436 | authentik: Account Takeover via SAML NameID Comment Truncation |
| CVE-2026-60591 | 9.1 | 36.9 | Oracle Corporation | Oracle Hospitality Simphony | — | Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and B… |
| CVE-2026-62638 | 9.1 | 36.9 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-70977 | 9.1 | 36.9 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-70981 | 9.1 | 36.9 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-70984 | 9.1 | 36.9 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71102 | 9.1 | 36.9 | Oracle Corporation | Oracle Database Server | CWE-284 | Vulnerability in the Portable Clusterware component of Oracle Database Server… |
| CVE-2026-75935 | 8.7 | 36.9 | Amazon Ion | Amazon Ion Java | CWE-789 | Memory-amplification denial of service via declared-length preallocation in A… |
| CVE-2026-75936 | 8.7 | 36.9 | Amazon Ion | Amazon Ion Java | CWE-409 | Memory-amplification denial of service via GZIP decompression bomb in Amazon … |
| CVE-2026-70906 | 7.5 | 36.9 | Oracle Corporation | Oracle Java SE | — | Vulnerability in Oracle Java SE (component: 2D). Supported versions that are … |
| CVE-2026-70908 | 7.5 | 36.9 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-70927 | 7.5 | 36.9 | Oracle Corporation | Oracle Workflow | — | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (comp… |
| CVE-2026-71113 | 7.5 | 36.9 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-71153 | 7.5 | 36.9 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73927 | 7.5 | 36.9 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73936 | 7.5 | 36.9 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73997 | 7.5 | 36.9 | Nexcess | Starter Templates by Kadence WP | CWE-770 | WordPress Starter Templates by Kadence WP plugin <= 2.3.3 - Denial of Service… |
| CVE-2026-32444 | 9.9 | 36.7 | Cwicly | Cwicly | CWE-94 | WordPress Cwicly plugin <= 1.4.4 - Remote Code Execution (RCE) vulnerability |
| CVE-2026-44472 | 8.1 | 36.7 | saleor | saleor | CWE-287 | Saleor: Account pre-hijacking vulnerability due to unverified anonymous order… |
| CVE-2026-47627 | 9.8 | 36.5 | NVIDIA | Triton Inference Server | CWE-22 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-73400 | 8.1 | 36.4 | jetmonsters | Restaurant Menu by MotoPress | CWE-98 | WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Local File Inclusio… |
| CVE-2026-50186 | 8.8 | 36.1 | RARgames | 4gaBoards | CWE-22 | 4gaBoards: Path Traversal leading to Arbitrary File Read and Deletion in Boar… |
| CVE-2026-52854 | 8.6 | 36.2 | ProfessionalWiki | Maps | CWE-79 | mediawiki/maps: Stored XSS through the overlays parameter in the display_map … |
| CVE-2026-52829 | 7.5 | 36.1 | ZcashFoundation | zebra | CWE-617 | ZEBRA: IPv4-Mapped Mempool Misbehavior Update Aborts Zebra Address Book |
| CVE-2026-76039 | 6.5 | 36.1 | Chrome | CWE-706 | Incorrect reference resolution in Core in Google Chrome on on Android prior t… | |
| CVE-2026-76040 | 8.8 | 36.1 | Chrome | CWE-416 | Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 … | |
| CVE-2026-75874 | 10.0 | 36.0 | Mozilla | Firefox | CWE-693 | Sandbox escape in the Remote Settings Client component |
| CVE-2026-54543 | 5.4 | 35.9 | froxlor | froxlor | CWE-74 | Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields |
| CVE-2026-70921 | 10.0 | 35.8 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-60737 | 9.1 | 35.8 | Oracle Corporation | Oracle Web Services Manager | — | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Mid… |
| CVE-2026-71166 | 9.4 | 35.7 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-60796 | 8.2 | 35.7 | Oracle Corporation | Siebel CRM Integration | CWE-284 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-70909 | 8.2 | 35.7 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70952 | 8.2 | 35.7 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-49224 | 8.3 | 35.6 | givanz | Vvveb | CWE-639 | Vvveb post revision authorization bypass allows Authors to read, restore, or … |
| CVE-2026-49225 | 8.3 | 35.6 | givanz | Vvveb | CWE-639 | Vvveb product revision authorization bypass allows Vendors to read, restore, … |
| CVE-2026-50167 | 5.3 | 35.4 | kurrier-org | kurrier | CWE-639 | Kurrier: Authenticated cross-user authorization bypass in Kurrier API |
| CVE-2026-48798 | 7.1 | 35.3 | sshnet | SSH.NET | CWE-22 | SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-… |
| CVE-2026-70770 | 8.3 | 35.1 | Oracle Corporation | Oracle Warehouse Management | CWE-284 | Vulnerability in the Oracle Warehouse Management product of Oracle E-Business… |
| CVE-2026-68924 | 4.9 | 34.9 | MobSF | Mobile-Security-Framework-MobSF | CWE-400 | MobSF: Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK E… |
| CVE-2026-60699 | 8.6 | 34.8 | Oracle Corporation | Oracle WebLogic Server | CWE-284 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-62586 | 8.6 | 34.8 | Oracle Corporation | Siebel CRM Administration | — | Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (… |
| CVE-2026-62550 | 7.5 | 34.8 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62554 | 7.5 | 34.8 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70752 | 7.5 | 34.8 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70772 | 7.5 | 34.8 | Oracle Corporation | Oracle Warehouse Management | — | Vulnerability in the Oracle Warehouse Management product of Oracle E-Business… |
| CVE-2026-70799 | 7.5 | 34.8 | Oracle Corporation | Oracle SDP Number Portability | — | Vulnerability in the Oracle SDP Number Portability product of Oracle E-Busine… |
| CVE-2026-70822 | 7.5 | 34.8 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70832 | 7.5 | 34.8 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70889 | 7.5 | 34.8 | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-70891 | 7.5 | 34.8 | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-76036 | 9.6 | 34.7 | Chrome | CWE-122 | Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.16… | |
| CVE-2026-76034 | 8.8 | 34.7 | Chrome | CWE-122 | Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a r… | |
| CVE-2026-75859 | 8.7 | 34.7 | Hmbown | CodeWhale | CWE-22 | CodeWhale before 0.8.64 Arbitrary File Read via instructions |
| CVE-2026-75914 | 8.7 | 34.7 | Hmbown | CodeWhale | CWE-22 | CodeWhale before 0.8.64 Path Traversal via image_analyze symlink |
| CVE-2026-70722 | 8.2 | 34.6 | Oracle Corporation | Oracle Advanced Inbound Telephony | CWE-284 | Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Bu… |
| CVE-2026-62455 | 8.3 | 34.4 | Oracle Corporation | Siebel CRM Cloud Applications | — | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-47606 | 6.5 | 34.2 | NVIDIA | Triton Inference Server | CWE-36 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an at… |
| CVE-2026-62629 | 9.4 | 34.2 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-60707 | 8.7 | 34.2 | Oracle Corporation | Oracle Identity Manager | CWE-284 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew… |
| CVE-2026-61332 | 8.7 | 34.2 | Oracle Corporation | Siebel CRM Cloud Applications | — | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-73937 | 8.2 | 34.2 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-62377 | 4.3 | 34.1 | strukturag | libheif | CWE-617 | libheif: Reachable assertion in HeifContext::get_track() aborts on a valid-bu… |
| CVE-2026-60680 | 8.1 | 33.9 | Oracle Corporation | Oracle WebLogic Server | CWE-284 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60779 | 8.1 | 33.9 | Oracle Corporation | Siebel Apps - Marketing | — | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co… |
| CVE-2026-60992 | 8.1 | 33.8 | Oracle Corporation | Oracle Identity Manager Connector | — | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi… |
| CVE-2026-61265 | 8.1 | 33.8 | Oracle Corporation | JD Edwards EnterpriseOne Orchestrator | — | Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle … |
| CVE-2026-70675 | 8.1 | 33.8 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-70684 | 8.1 | 33.8 | Oracle Corporation | Oracle Enterprise Manager Base Platform | — | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-70704 | 8.1 | 33.8 | Oracle Corporation | Oracle Trading Community | — | Vulnerability in the Oracle Trading Community product of Oracle E-Business Su… |
| CVE-2026-70814 | 8.1 | 33.8 | Oracle Corporation | Oracle Call Center Technology | — | Vulnerability in the Oracle Call Center Technology product of Oracle E-Busine… |
| CVE-2026-70924 | 8.1 | 33.8 | Oracle Corporation | Oracle Web Services Manager | — | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Mid… |
| CVE-2026-70931 | 8.1 | 33.9 | Oracle Corporation | Oracle Workflow | — | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (comp… |
| CVE-2026-70959 | 8.1 | 33.9 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-71042 | 8.1 | 33.9 | Oracle Corporation | Oracle Agile PLM | CWE-284 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-45734 | 5.3 | 33.8 | mybb | mybb | CWE-837 | MyBB: Default CAPTCHA missing invalidation |
| CVE-2026-75783 | 8.6 | 33.4 | TRENDnet | TEW-WLC100P | CWE-119 | TRENDnet TEW-WLC100P DHCP blobmsg netifd stack-based overflow |
| CVE-2026-69219 | 8.7 | 33.3 | rabbitmq | rabbitmq-java-client | CWE-789 | RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers … |
| CVE-2026-69220 | 8.7 | 33.3 | rabbitmq | rabbitmq-java-client | CWE-674 | RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting cau… |
| CVE-2026-73399 | 6.5 | 33.3 | flutterwave | Flutterwave WooCommerce | CWE-288 | WordPress Flutterwave WooCommerce plugin <= 3.3.0 - Broken Authentication vul… |
| CVE-2026-61008 | 9.1 | 33.2 | Oracle Corporation | Oracle WebCenter Sites | — | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-70730 | 9.1 | 33.2 | Oracle Corporation | Oracle Hyperion Profitability and Cost Management | — | Vulnerability in the Oracle Hyperion Profitability and Cost Management produc… |
| CVE-2026-70741 | 9.1 | 33.1 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70884 | 9.1 | 33.1 | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-70978 | 9.1 | 33.1 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71015 | 9.1 | 33.2 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71026 | 9.1 | 33.1 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-73866 | 9.1 | 33.1 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73916 | 9.1 | 33.1 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73917 | 9.1 | 33.1 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-62599 | 8.6 | 33.2 | Oracle Corporation | Oracle Trading Community | — | Vulnerability in the Oracle Trading Community product of Oracle E-Business Su… |
| CVE-2026-62628 | 8.6 | 33.2 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-70721 | 8.6 | 33.1 | Oracle Corporation | Oracle Hyperion Profitability and Cost Management | — | Vulnerability in the Oracle Hyperion Profitability and Cost Management produc… |
| CVE-2026-60391 | 7.5 | 33.2 | Oracle Corporation | Oracle Hyperion Financial Reporting | CWE-284 | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-60393 | 7.5 | 33.1 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-60590 | 7.5 | 33.2 | Oracle Corporation | Oracle Hospitality Simphony | — | Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and B… |
| CVE-2026-60850 | 7.5 | 33.2 | Oracle Corporation | Oracle Unified Directory | — | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60889 | 7.5 | 33.2 | Oracle Corporation | Oracle Unified Directory | — | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-60906 | 7.5 | 33.1 | Oracle Corporation | Oracle WebCenter Content | — | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-60914 | 7.5 | 33.1 | Oracle Corporation | Oracle Unified Directory | — | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle… |
| CVE-2026-61007 | 7.5 | 33.2 | Oracle Corporation | Oracle WebCenter Sites | — | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-70810 | 7.5 | 33.2 | Oracle Corporation | Oracle Scripting | — | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (com… |
| CVE-2026-70896 | 7.5 | 33.1 | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-70910 | 7.5 | 33.2 | Oracle Corporation | Siebel CRM Integration | — | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-70986 | 7.5 | 33.1 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-70987 | 7.5 | 33.2 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71034 | 7.5 | 33.1 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71107 | 7.5 | 33.1 | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-71142 | 7.5 | 33.2 | Oracle Corporation | Oracle Communications Unified Inventory Management | CWE-284 | Vulnerability in the Oracle Communications Unified Inventory Management produ… |
| CVE-2026-71158 | 7.5 | 33.2 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73878 | 7.5 | 33.1 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73883 | 7.5 | 33.1 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73884 | 7.5 | 33.1 | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73907 | 7.5 | 33.1 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73938 | 7.5 | 33.1 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-70680 | 7.1 | 33.0 | Oracle Corporation | Oracle Applications DBA | CWE-284 | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Sui… |
| CVE-2026-73350 | 8.2 | 32.9 | PSM Plugins | SupportCandy | CWE-266 | WordPress SupportCandy plugin <= 3.5.1 - Broken Authentication vulnerability |
| CVE-2026-76038 | 8.8 | 32.8 | Chrome | CWE-843 | Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remot… | |
| CVE-2026-52739 | 5.9 | 32.7 | ZcashFoundation | zebra | CWE-248 | ZEBRA: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplic… |
| CVE-2026-62289 | 4.3 | 32.8 | strukturag | libheif | CWE-191 | libheif: Integer underflow in Fraction constructor via double clap transform … |
| CVE-2026-75853 | 8.7 | 32.6 | ArcadeData | arcadedb | CWE-862 | ArcadeDB Gremlin Wire Protocol Authorization Bypass Cross-Database |
| CVE-2026-71079 | 6.5 | 32.7 | Oracle Corporation | MySQL Connectors | CWE-284 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Con… |
| CVE-2026-62684 | 2.7 | 32.6 | filebrowser | filebrowser | CWE-200 | File Browser: Share API exposes the password hash and bypass token |
| CVE-2026-62463 | 9.6 | 32.5 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70958 | 9.6 | 32.5 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62619 | 8.8 | 32.5 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-71106 | 8.8 | 32.5 | Oracle Corporation | Oracle Hospitality OPERA 5 Property Services | — | Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of … |
| CVE-2026-62477 | 8.1 | 32.5 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62491 | 8.1 | 32.5 | Oracle Corporation | Oracle Purchasing | — | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co… |
| CVE-2026-62502 | 8.1 | 32.5 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70701 | 8.1 | 32.5 | Oracle Corporation | Oracle Payables | — | Vulnerability in the Oracle Payables product of Oracle E-Business Suite (comp… |
| CVE-2026-70762 | 8.1 | 32.5 | Oracle Corporation | Oracle Risk Management | — | Vulnerability in the Oracle Risk Management product of Oracle E-Business Suit… |
| CVE-2026-70811 | 8.1 | 32.5 | Oracle Corporation | Oracle Purchasing | — | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co… |
| CVE-2026-70815 | 8.1 | 32.5 | Oracle Corporation | Oracle Internet Procurement Connector | — | Vulnerability in the Oracle Internet Procurement Connector product of Oracle … |
| CVE-2026-70835 | 8.1 | 32.5 | Oracle Corporation | Oracle iRecruitment | — | Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (… |
| CVE-2026-70878 | 8.1 | 32.5 | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-70881 | 8.1 | 32.5 | Oracle Corporation | Oracle Hyperion Data Relationship Management | — | Vulnerability in the Oracle Hyperion Data Relationship Management product of … |
| CVE-2026-70925 | 8.1 | 32.5 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-18963 | 9.1 | 32.4 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-640 | Keycloak-services: keycloak-services: unauthenticated account takeover via re… |
| CVE-2026-75855 | 8.4 | 32.4 | ArcadeData | arcadedb | CWE-22 | ArcadeDB before 26.8.1 Path Traversal via create/drop database |
| CVE-2026-71095 | 8.3 | 32.4 | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | CWE-284 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-21582 | 8.8 | 32.2 | Atlassian | Crowd Data Center | — | This High severity BASM (Broken Authentication & Session Management) vulnerab… |
| CVE-2026-76043 | 8.8 | 32.1 | Chrome | CWE-682 | Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed … | |
| CVE-2026-76047 | 8.8 | 32.1 | Chrome | CWE-843 | Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remot… | |
| CVE-2026-32470 | 9.8 | 32.0 | Roxnor | FundEngine | CWE-502 | WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability |
| CVE-2026-73341 | 9.8 | 32.0 | Metagauss | RegistrationMagic | CWE-502 | WordPress RegistrationMagic plugin <= 6.0.9.7 - PHP Object Injection vulnerab… |
| CVE-2026-73376 | 9.8 | 32.0 | supsystic | Ultimate Maps by Supsystic | CWE-502 | WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - PHP Object Injection vu… |
| CVE-2026-73397 | 9.8 | 32.0 | Youzify | Youzify | CWE-502 | WordPress Youzify plugin <= 1.3.7 - Deserialization of untrusted data vulnera… |
| CVE-2026-70690 | 8.0 | 31.9 | Oracle Corporation | Oracle HRMS (US) | — | Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (com… |
| CVE-2026-70802 | 8.0 | 31.9 | Oracle Corporation | Oracle Public Sector Human Resources | — | Vulnerability in the Oracle Public Sector Human Resources product of Oracle E… |
| CVE-2026-62475 | 6.6 | 31.9 | Oracle Corporation | Oracle Shipping Execution | — | Vulnerability in the Oracle Shipping Execution product of Oracle E-Business S… |
| CVE-2026-61011 | 8.2 | 31.8 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-61016 | 8.2 | 31.8 | Oracle Corporation | Oracle WebCenter Sites | CWE-284 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-73396 | 7.1 | 31.9 | MakeWebBetter | MWB HubSpot for WooCommerce | CWE-288 | WordPress MWB HubSpot for WooCommerce plugin <= 1.6.7 - Broken Authentication… |
| CVE-2026-53533 | 6.9 | 31.8 | cole | aiosmtplib | CWE-77 | aiosmtplib: SMTP command injection via CR/LF in sender/recipient address |
| CVE-2026-71161 | 5.3 | 31.8 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-61241 | 10.0 | 31.7 | Oracle Corporation | Oracle Internet Directory | — | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middl… |
| CVE-2026-61258 | 9.8 | 31.7 | Oracle Corporation | Oracle Internet Directory | — | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middl… |
| CVE-2026-70669 | 9.8 | 31.7 | Oracle Corporation | Oracle Reports Developer | — | Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle… |
| CVE-2026-45118 | 9.3 | 31.7 | mybb | mybb | CWE-83 | MyBB: Contact page reflected XSS |
| CVE-2026-50161 | 9.3 | 31.7 | baresip | re | CWE-190 | libre: Integer overflow in websock_decode() masked frame length check leads t… |
| CVE-2026-62357 | 8.8 | 31.7 | dragonflydb | dragonfly | CWE-190 | DragonflyDB `CMS.INITBYDIM` integer overflow leads to a remote, attacker-cont… |
| CVE-2026-60592 | 8.2 | 31.7 | Oracle Corporation | MySQL Cluster | — | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluste… |
| CVE-2026-73930 | 9.9 | 31.6 | Oracle Corporation | Helidon | CWE-284 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-73187 | 9.3 | 31.6 | gingerplugins | Sticky Chat Widget | CWE-89 | WordPress Sticky Chat Widget plugin <= 1.4.2 - SQL Injection vulnerability |
| CVE-2026-73339 | 9.3 | 31.6 | Webnus Inc. | Modern Events Calendar | CWE-89 | WordPress Modern Events Calendar plugin < 7.35.0 - SQL Injection vulnerability |
| CVE-2026-73355 | 9.3 | 31.6 | wp.insider | Affiliates Manager | CWE-89 | WordPress Affiliates Manager plugin <= 2.9.53 - SQL Injection vulnerability |
| CVE-2026-73365 | 9.3 | 31.6 | Crocoblock. Jetimpex Inc. | JetAppointment | CWE-89 | WordPress JetAppointment plugin <= 2.5.2 - SQL Injection vulnerability |
| CVE-2026-73392 | 9.3 | 31.6 | highwarden | Super Store Finder | CWE-89 | WordPress Super Store Finder plugin <= 7.8 - SQL Injection vulnerability |
| CVE-2026-45532 | 8.7 | 31.5 | dataease | dataease | CWE-22 | DataEase has a Path Traversal Vulnerability |
| CVE-2026-54347 | 8.7 | 31.5 | froxlor | froxlor | CWE-79 | Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Accoun… |
| CVE-2026-62607 | 8.7 | 31.4 | Oracle Corporation | Oracle Customer Care | — | Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite … |
| CVE-2026-71050 | 8.7 | 31.4 | Oracle Corporation | Oracle Product Lifecycle Analytics | — | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Sup… |
| CVE-2026-60865 | 6.8 | 31.4 | Oracle Corporation | Service Delivery Platform | — | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-71007 | 6.8 | 31.4 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71085 | 4.9 | 31.4 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-60905 | 9.6 | 31.3 | Oracle Corporation | Oracle WebCenter Content | CWE-284 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-49221 | 8.8 | 31.3 | givanz | Vvveb | CWE-639 | Vvveb digital asset authorization bypass allows Vendors to list, read, edit, … |
| CVE-2026-49228 | 8.8 | 31.3 | givanz | Vvveb | CWE-639 | Vvveb product authorization bypass allows Vendors to read, duplicate, or dele… |
| CVE-2026-71057 | 8.5 | 31.3 | Oracle Corporation | Oracle BI Publisher | CWE-284 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone… |
| CVE-2026-60752 | 7.1 | 31.3 | Oracle Corporation | Siebel Apps - Marketing | CWE-284 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co… |
| CVE-2026-61259 | 7.1 | 31.3 | Oracle Corporation | Oracle Hyperion Calculation Manager | CWE-284 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-70733 | 7.1 | 31.3 | Oracle Corporation | Oracle Hyperion Profitability and Cost Management | CWE-284 | Vulnerability in the Oracle Hyperion Profitability and Cost Management produc… |
| CVE-2026-70933 | 7.1 | 31.3 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70934 | 7.1 | 31.3 | Oracle Corporation | Oracle Hyperion Financial Management | CWE-284 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-71880 | 7.6 | 31.2 | GBIF | Integrated Publishing Toolkit | CWE-1336 | Server-side template injection in Integrated Publishing Toolkit |
| CVE-2026-70774 | 7.1 | 31.2 | Oracle Corporation | Oracle Warehouse Management | CWE-284 | Vulnerability in the Oracle Warehouse Management product of Oracle E-Business… |
| CVE-2026-62452 | 9.9 | 31.1 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-284 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-74044 | 7.0 | 31.1 | Wazuh | wazuh-manager | CWE-22 | Wazuh 4.0.0 < 4.14.6 Path Traversal Arbitrary Directory Deletion via Cluster … |
| CVE-2026-32472 | 7.5 | 31.0 | wbolt.com | Online Contact Widget | CWE-862 | WordPress Online Contact Widget plugin <= 1.3.0 - Broken Access Control vulne… |
| CVE-2026-32549 | 7.5 | 31.0 | Codexpert, Inc | ThumbPress | CWE-862 | WordPress ThumbPress plugin < 6.5 - Broken Access Control vulnerability |
| CVE-2026-61029 | 9.0 | 30.9 | Oracle Corporation | Oracle WebCenter Sites | — | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa… |
| CVE-2026-70980 | 9.0 | 30.9 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | CWE-284 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-53455 | 8.6 | 30.9 | ha-china | blueprint-studio | CWE-78 | Blueprint Studio Git credential helper command injection |
| CVE-2026-60415 | 8.1 | 30.9 | Oracle Corporation | Oracle WebLogic Server | — | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa… |
| CVE-2026-60742 | 8.1 | 30.9 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | — | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-60831 | 8.1 | 30.9 | Oracle Corporation | PeopleSoft Enterprise PeopleTools | — | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-61307 | 8.1 | 30.9 | Oracle Corporation | PeopleSoft Enterprise CC Common Application Objects | — | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects prod… |
| CVE-2026-62501 | 8.1 | 30.9 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62531 | 8.1 | 30.9 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70744 | 8.1 | 30.9 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70749 | 8.1 | 30.9 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70868 | 8.1 | 30.9 | Oracle Corporation | Oracle Application Testing Suite | — | Vulnerability in Oracle Application Testing Suite. The supported version that… |
| CVE-2026-71035 | 8.1 | 30.9 | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-71053 | 8.1 | 30.9 | Oracle Corporation | Oracle Agile Engineering Data Management | CWE-284 | Vulnerability in the Oracle Agile Engineering Data Management product of Orac… |
| CVE-2026-71068 | 8.1 | 30.9 | Oracle Corporation | Oracle Agile PLM MCAD Connector | — | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply… |
| CVE-2026-71112 | 8.1 | 30.9 | Oracle Corporation | PeopleSoft Enterprise FIN Common Objects | CWE-284 | Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Orac… |
| CVE-2026-52731 | 6.5 | 30.9 | ZcashFoundation | zebra | CWE-248 | ZEBRA: Full node denial of service via non-ASCII LongPollId in getblocktemplate |
| CVE-2026-76042 | 3.1 | 30.8 | Chrome | CWE-908 | Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169… | |
| CVE-2026-54730 | 8.6 | 30.7 | goauthentik | authentik | CWE-284 | authentik: Authentication Flow Bypass via Unguarded challenge_valid() in Auth… |
| CVE-2026-60861 | 9.6 | 30.6 | Oracle Corporation | Service Delivery Platform | — | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl… |
| CVE-2026-61001 | 9.6 | 30.6 | Oracle Corporation | Oracle Web Services Manager | — | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Mid… |
| CVE-2026-15585 | 7.5 | 30.6 | AKIN Software Computer Import Export Industry and Trade Ltd. | AKINSOFT Wolvox9 ERP / KontrolPanel.exe | CWE-22 | Path Traversal in AKIN Software's Wolvox9 ERP |
| CVE-2026-62467 | 7.7 | 30.4 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-62571 | 7.7 | 30.4 | Oracle Corporation | Oracle Hyperion Calculation Manager | — | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy… |
| CVE-2026-62593 | 7.7 | 30.4 | Oracle Corporation | Siebel CRM Integration | CWE-284 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com… |
| CVE-2026-70771 | 7.7 | 30.4 | Oracle Corporation | Oracle Warehouse Management | — | Vulnerability in the Oracle Warehouse Management product of Oracle E-Business… |
| CVE-2026-70827 | 7.7 | 30.4 | Oracle Corporation | Oracle MES for Process Manufacturing | — | Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E… |
| CVE-2026-70828 | 7.7 | 30.4 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-52738 | 6.9 | 30.4 | ZcashFoundation | zebra | CWE-248 | ZEBRA: Finalized address balance credit-first overflow on consensus-valid blocks |
| CVE-2026-62506 | 6.5 | 30.4 | Oracle Corporation | Oracle Hyperion Infrastructure Technology | — | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora… |
| CVE-2026-70720 | 6.5 | 30.4 | Oracle Corporation | Oracle Production Scheduling | — | Vulnerability in the Oracle Production Scheduling product of Oracle E-Busines… |
| CVE-2026-70767 | 6.5 | 30.4 | Oracle Corporation | Oracle Hyperion Financial Reporting | — | Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy… |
| CVE-2026-70826 | 6.5 | 30.4 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-70831 | 6.5 | 30.4 | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-43971 | 6.3 | 30.4 | ninenines | cowlib | CWE-116 | Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in co… |
Results continue: ranks 401–1407.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-08-18 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion.