Security Box Score — July 27, 2026 — page 2
Edition of July 27, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-43770 | 4.7 | 3.3 | Apple | macOS | CWE-362 | A race condition was addressed with additional validation. This issue is fixe… |
| CVE-2026-17514 | 1.9 | 3.3 | ZJONSSON | node-unzipper | CWE-22 | ZJONSSON node-unzipper extract.js Extract path traversal |
| CVE-2026-65557 | 5.9 | 3.2 | Tychesoftwares | Abandoned Cart Lite for WooCommerce | CWE-79 | WordPress Abandoned Cart Lite for WooCommerce plugin <= 6.8.0 - Cross Site Sc… |
| CVE-2026-65563 | 5.9 | 3.2 | Themeisle | Orbit Fox by ThemeIsle | CWE-79 | WordPress Orbit Fox by ThemeIsle plugin <= 3.0.7 - Cross Site Scripting (XSS)… |
| CVE-2026-66475 | 5.9 | 3.2 | acowebs | Checkout Field Editor for WooCommerce – Checkout Manager | CWE-79 | WordPress Checkout Field Editor for WooCommerce – Checkout Manager plug… |
| CVE-2026-64533 | 7.8 | 3.2 | Linux | Linux | — | fs/ntfs3: validate lcns_follow in log_replay conversion |
| CVE-2026-57917 | 4.8 | 3.2 | Asseco | proCertum SmartSign | CWE-611 | Improper Restriction of XML External Entity Reference in proCertum SmartSign |
| CVE-2026-43665 | 5.5 | 3.1 | Apple | macOS | CWE-862 | This issue was addressed with additional entitlement checks. This issue is fi… |
| CVE-2026-65558 | 5.4 | 3.1 | WPCenter | AffiliateX | CWE-918 | WordPress AffiliateX plugin <= 2.3.5 - Server Side Request Forgery (SSRF) vul… |
| CVE-2026-12990 | 7.7 | 2.9 | Ghost Robotics | Vision 60 | CWE-284 | Multiple vulnerabilities in Ghost Robotics' Vision 60 |
| CVE-2026-43693 | 7.0 | 2.9 | Apple | macOS | CWE-362 | A race condition was addressed with improved state handling. This issue is fi… |
| CVE-2026-64555 | 8.8 | 2.7 | Linux | Linux | — | KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops() |
| CVE-2026-64532 | 7.8 | 2.7 | Linux | Linux | — | fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation} |
| CVE-2026-65448 | 6.5 | 2.6 | AcyMailing Newsletter Team | Anti Spam and list cleaner – AcyChecker | CWE-79 | WordPress Anti Spam and list cleaner – AcyChecker plugin <= 1.8.1 - Cross Sit… |
| CVE-2026-65561 | 6.5 | 2.6 | miniOrange | WordPress Social Login and Register | CWE-79 | WordPress WordPress Social Login and Register plugin <= 7.8.0 - Cross Site Sc… |
| CVE-2026-65562 | 6.5 | 2.6 | WPDeveloper | BetterDocs | CWE-79 | WordPress BetterDocs plugin <= 4.6.2 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-66433 | 6.5 | 2.6 | ShapedPlugin LLC | Location Weather | CWE-79 | WordPress Location Weather plugin <= 3.0.6 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-66434 | 6.5 | 2.6 | Sayontan Sinha | Photonic Gallery & Lightbox for Flickr, SmugMug & Others | CWE-79 | WordPress Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin <= … |
| CVE-2026-66445 | 6.5 | 2.6 | 100plugins | Open User Map | CWE-79 | WordPress Open User Map plugin <= 1.4.46 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-66448 | 6.5 | 2.6 | WP Chill | Gallery PhotoBlocks | CWE-79 | WordPress Gallery PhotoBlocks plugin <= 1.3.3 - Cross Site Scripting (XSS) vu… |
| CVE-2026-64543 | 7.8 | 2.5 | Linux | Linux | — | tipc: fix use-after-free of the discoverer in tipc_disc_rcv() |
| CVE-2026-64550 | 7.3 | 2.5 | Linux | Linux | — | net: qualcomm: rmnet: validate MAP frame length before ingress parsing |
| CVE-2026-64546 | 7.1 | 2.5 | Linux | Linux | — | drm/edid: fix OOB read in drm_parse_tiled_block() |
| CVE-2026-43811 | 4.7 | 2.5 | Apple | iOS and iPadOS | CWE-362 | A race condition was addressed with improved checks. This issue is fixed in i… |
| CVE-2026-17573 | 4.0 | 2.3 | The HDF Group | HDF5 | CWE-415 | Double Free in H5D__chunk_copy() in HDF5 via a Crafted Chunk-Index Size Field |
| CVE-2026-64539 | 7.8 | 2.2 | Linux | Linux | — | Bluetooth: eir: Fix stack OOB write when prepending the Flags AD |
| CVE-2026-17534 | 5.5 | 2.1 | MoonshotAI | Kimi Code | CWE-918 | Kimi Code FetchURL SSRF protection bypass via DNS-resolving hostnames and red… |
| CVE-2026-17523 | 7.8 | 2.0 | Red Hat | Red Hat Enterprise Linux 8 | CWE-825 | Kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges |
| CVE-2026-43755 | 7.0 | 1.8 | Apple | macOS | CWE-362 | A race condition was addressed with improved state management. This issue is … |
| CVE-2026-66437 | 4.9 | 1.8 | Themeisle | Feedzy | CWE-918 | WordPress Feedzy plugin <= 5.2.4 - Server Side Request Forgery (SSRF) vulnera… |
| CVE-2026-17512 | 1.9 | 1.6 | ggml-org | whisper.cpp | CWE-119 | ggml-org whisper.cpp log_mel_spectrogram out-of-bounds |
| CVE-2026-17513 | 1.9 | 1.5 | ggml-org | whisper.cpp | CWE-617 | ggml-org whisper.cpp ggml.c ggml_ftype_to_ggml_type assertion |
| CVE-2025-59180 | 5.1 | 1.4 | Ericsson | Packet Core Controller (PCC) | CWE-798 | Use of Hard-coded Credentials Vulnerability |
| CVE-2026-15003 | 5.6 | 1.2 | Red Hat | Red Hat Hardened Images | CWE-125 | Binutils: gnu binutils: heap-buffer-overflow in linker leads to information d… |
| CVE-2026-17574 | 5.2 | 1.1 | The HDF Group | HDF5 | CWE-476 | NULL Pointer Dereference in HDF5 via Invalid Variable-Length Datatype Type Tag |
| CVE-2026-17572 | 5.5 | 1.0 | The HDF Group | HDF5 | CWE-125 | HDF5 SOHM List Index Heap Buffer Overflow |
| CVE-2026-66428 | 4.3 | 0.8 | jgwhite33 | WP Google Review Slider | CWE-352 | WordPress WP Google Review Slider plugin <= 18.4 - Cross Site Request Forgery… |
| CVE-2026-66474 | 4.3 | 0.8 | HT Plugins | Insert Headers and Footers Code – HT Script | CWE-352 | WordPress Insert Headers and Footers Code – HT Script plugin <= 1.1.8 - Cross… |
| CVE-2026-57916 | 4.6 | 0.4 | Asseco | proCertum SmartSign | CWE-73 | Arbitrary Path Execution via CPS URI in proCertum SmartSign |
| CVE-2026-14837 | 8.5 | 0.3 | Lenze | c430 | CWE-347 | SSH Enablement Signature Verification Bypass |