AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .9862 99.9 YES
AFFECTED Product Versions Fixed Apache Tomcat 11.0.20 – —
TIMELINE Mar 30 Reserved by CNA Aug 4 Added to CISA KEV, due Aug 7 Aug 4 Published (CNA: apache)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
273 CVEs published, led by FlowiseAI (22).
273 CVEs published August 4, 2026: 45 critical, 119 high, 81 medium, 27 low; 2 in the KEV catalog at press time; 3 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 248 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 779 | 22943 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
1166 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 5 | 2320 | 208 | 1234 | 637 | 1 | 11 | 2 | 0.1 | 7.8 | .0016 | -32 ▼ |
| 2 | 1763 | 215 | 713 | 782 | 53 | 77 | 6 | 0.3 | 7.5 | .0025 | -50 ▼ | |
| microsoft | 16 | 1438 | 107 | 988 | 329 | 14 | 286 | 24 | 1.7 | 7.8 | .0047 | -34 ▼ |
| red hat | 19 | 405 | 16 | 157 | 204 | 28 | 2 | 0 | 0.0 | 6.5 | .0029 | +4 ▲ |
| apple | 0 | 271 | 57 | 78 | 133 | 3 | 88 | 7 | 2.6 | 6.5 | .0027 | 0 |
| canonical | 0 | 27 | 3 | 8 | 11 | 5 | 0 | 0 | 0.0 | 5.6 | .0014 | 0 |
| suse | 0 | 21 | 4 | 12 | 4 | 1 | 0 | 0 | 0.0 | 8.5 | .0039 | -2 ▼ |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 0 | 38 | 8 | 18 | 12 | 0 | 56 | 12 | 31.6 | 7.5 | .0057 | -8 ▼ |
| ubiquiti | 0 | 36 | 14 | 21 | 1 | 0 | 3 | 3 | 8.3 | 8.8 | .0049 | -25 ▼ |
| palo alto networks | 0 | 25 | 1 | 3 | 14 | 7 | 13 | 2 | 8.0 | 4.7 | .0028 | 0 |
| fortinet | 0 | 23 | 6 | 6 | 11 | 0 | 28 | 6 | 26.1 | 7.2 | .0040 | 0 |
| netgear | 0 | 23 | 0 | 0 | 22 | 1 | 0 | 0 | 0.0 | 4.6 | .0024 | 0 |
| vmware | 0 | 17 | 4 | 9 | 2 | 2 | 7 | 1 | 5.9 | 8.3 | .0040 | 0 |
| f5 | 0 | 16 | 5 | 8 | 3 | 0 | 4 | 1 | 6.3 | 8.6 | .0057 | 0 |
| checkpoint | 1 | 13 | 4 | 6 | 3 | 0 | 3 | 2 | 15.4 | 7.8 | .0436 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 6 | 342 | 65 | 147 | 117 | 12 | 33 | 2 | 0.6 | 7.5 | .0053 | +1 ▲ |
| mozilla | 1 | 128 | 51 | 42 | 35 | 0 | 9 | 0 | 0.0 | 8.1 | .0031 | -1 ▼ |
| drupal | 0 | 51 | 6 | 5 | 35 | 5 | 4 | 1 | 2.0 | 5.9 | .0026 | 0 |
| gitlab | 0 | 51 | 0 | 7 | 37 | 7 | 4 | 2 | 3.9 | 4.9 | .0029 | 0 |
| github | 0 | 12 | 1 | 3 | 8 | 0 | 0 | 0 | 0.0 | 6.0 | .0042 | -1 ▼ |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.2 | .0016 | 0 |
| wordpress | 0 | 3 | 1 | 1 | 1 | 0 | 2 | 2 | 66.7 | 8.6 | .7979 | 0 |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0035 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 1379 | 343 | 653 | 322 | 61 | 27 | 3 | 0.2 | 8.1 | .0036 | 0 |
| adobe | 7 | 259 | 33 | 117 | 105 | 4 | 19 | 3 | 1.2 | 7.8 | .0026 | +7 ▲ |
| ibm | 0 | 229 | 67 | 86 | 76 | 0 | 6 | 1 | 0.4 | 7.5 | .0032 | 0 |
| progress | 0 | 42 | 6 | 29 | 7 | 0 | 6 | 0 | 0.0 | 8.0 | .0038 | -2 ▼ |
| solarwinds | 0 | 23 | 17 | 3 | 3 | 0 | 10 | 4 | 17.4 | 9.1 | .0058 | 0 |
| veeam | 10 | 16 | 5 | 9 | 2 | 0 | 1 | 0 | 0.0 | 8.6 | .0034 | +10 ▲ |
| zohocorp | 0 | 6 | 2 | 2 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0146 | 0 |
| atlassian | 0 | 3 | 0 | 3 | 0 | 0 | 13 | 0 | 0.0 | 8.0 | .0026 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 1 | 24 | 2 | 6 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +1 ▲ |
| rockwell automation | 0 | 24 | 4 | 18 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0029 | 0 |
| d-link | 0 | 20 | 0 | 5 | 9 | 6 | 3 | 0 | 0.0 | 5.5 | .0105 | 0 |
| siemens | 0 | 16 | 1 | 8 | 7 | 0 | 0 | 0 | 0.0 | 7.6 | .0024 | 0 |
| schneider electric | 0 | 9 | 1 | 6 | 2 | 0 | 0 | 0 | 0.0 | 8.6 | .0037 | 0 |
| abb | 0 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | 0 |
| hikvision | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0040 | 0 |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 0 | 120 | 0 | 0 | 62 | 58 | 0 | 0 | 0.0 | 5.5 | .0034 | -7 ▼ |
| openclaw | 0 | 111 | 0 | 58 | 39 | 14 | 0 | 0 | 0.0 | 7.0 | .0026 | 0 |
| dell | 3 | 102 | 5 | 50 | 44 | 3 | 2 | 1 | 1.0 | 7.2 | .0021 | -17 ▼ |
| nvidia | 16 | 98 | 13 | 66 | 19 | 0 | 0 | 0 | 0.0 | 7.7 | .0034 | -1 ▼ |
| capgo | 0 | 83 | 2 | 42 | 38 | 1 | 0 | 0 | 0.0 | 7.1 | .0037 | 0 |
| spring | 0 | 79 | 2 | 34 | 41 | 2 | 0 | 0 | 0.0 | 6.5 | .0022 | 0 |
| imagemagick | 0 | 78 | 1 | 5 | 60 | 12 | 0 | 0 | 0.0 | 5.3 | .0018 | -8 ▼ |
| itsourcecode | 0 | 71 | 0 | 0 | 19 | 52 | 0 | 0 | 0.0 | 2.1 | .0033 | -3 ▼ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-34486 | .9862 | 99.9 | 7.5 |
| CVE-2026-63030 | .9779 | 99.9 | 9.8 |
| CVE-2026-16232 | .8912 | 99.8 | 9.3 |
| CVE-2026-50522 | .8461 | 99.7 | 9.8 |
| CVE-2026-15409 | .8366 | 99.7 | 10.0 |
| CVE-2026-60137 | .7979 | 99.6 | 5.9 |
| CVE-2026-6875 | .7758 | 99.5 | 9.5 |
| CVE-2026-25089 | .7611 | 99.5 | 9.8 |
| CVE-2026-0770 | .6342 | 99.1 | 9.8 |
| CVE-2026-59310 | .4588 | 98.7 | 9.8 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-15409 | 10.0 | .8366 | KEV |
| CVE-2026-48282 | 10.0 | .4239 | KEV |
| CVE-2026-56290 | 10.0 | .3038 | KEV |
| CVE-2026-48939 | 10.0 | .1973 | KEV |
| CVE-2026-48908 | 10.0 | .1482 | KEV |
| CVE-2026-56291 | 10.0 | .1459 | KEV |
| CVE-2026-59726 | 10.0 | .0688 | |
| CVE-2026-8985 | 10.0 | .0660 | |
| CVE-2026-6516 | 10.0 | .0486 | |
| CVE-2026-47668 | 10.0 | .0388 |
| Vendor | CVEs |
|---|---|
| oracle | 1109 |
| linux | 803 |
| microsoft | 631 |
| 446 | |
| apache | 182 |
| apple | 167 |
| red hat | 167 |
| adobe | 115 |
| ibm | 105 |
| mozilla | 70 |
| Vendor | KEV |
|---|---|
| microsoft | 24 |
| cisco | 12 |
| apple | 7 |
| fortinet | 6 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| oracle | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 67 |
| PyPI | 8 |
| Go | 3 |
| npm | 3 |
| Packagist | 2 |
| crates.io | 2 |
| NuGet | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2021-27137 | DD-WRT | 0 |
| CVE-2025-68686 | Fortinet | 0 |
| CVE-2026-0770 | Langflow | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-16232 | checkpoint | 0 |
| CVE-2026-16812 | Arista Networks | 0 |
| CVE-2026-18556 | N-able | 0 |
| CVE-2026-18577 | N-able | 0 |
| CVE-2026-20316 | Cisco | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1721 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1721 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1721 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1721 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1721 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1721 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1721 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1721 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1721 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1721 |
EXPLOIT PUBLISHED — Linux: 8 CVEs (CVE-2021-47102, CVE-2021-47103, CVE-2021-47107, CVE-2022-48629, CVE-2023-52927, CVE-2025-37947, CVE-2026-46331, CVE-2026-53264). Public exploit references added.
EXPLOIT PUBLISHED — dompdf: 4 CVEs (CVE-2026-56722, CVE-2026-59941, CVE-2026-59942, CVE-2026-59943). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2021-44529 (Ivanti EPM). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-27925. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-30333. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-37042. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2023-46805 (Ivanti ICS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2023-4853 (Red Hat Openshift Serverless 1 on RHEL 8). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2024-0012 (Palo Alto Networks Cloud NGFW). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2024-21887 (Ivanti ICS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2024-24919 (checkpoint Check Point Quantum Gateway, Spark Gateway and CloudGuard Network). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2024-51567. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-15672 (Unknown ChamaWP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-15673 (Unknown Import and export users and customers). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-53770 (Microsoft SharePoint Enterprise Server 2016). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-57631. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10050 (Eclipse Foundation Eclipse Jetty - EE8). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10827 (Unknown Spectra Legacy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-11368 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-11872 (Unknown Clever Mega Menu for Visual Composer). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-11882 (Unknown Builderall for WordPress). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-12872 (Unknown Webinfos). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-13157 (Unknown Theme Demo Import). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-13158 (Unknown Everest Toolkit). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-13604 (Unknown Pixelavo). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-13725 (Unknown Dynamic Pricing With Discount Rules for WooCommerce). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-13729 (Unknown Podlove Podcast Publisher). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14195 (Unknown Brizy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14197 (Unknown Fluent Support). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14214 (Unknown Booking for Appointments and Events Calendar). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14309 (Unknown Chat On Desk Order Notifications). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14557 (Unknown SoftMarket — Digital Marketplace). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14596 (Unknown DynamicKit for Elementor). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14822 (Unknown Event Tickets and Registration). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14823 (Unknown Event Tickets and Registration). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14836 (Unknown Login & Register Forms). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14840 (Unknown YOP Poll). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14938 (Unknown FluentBoards). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-15231 (Unknown Tag, Category, and Taxonomy Manager). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-15244 (Unknown HUSKY). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-15248 (Unknown Meta Box). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-15368 (Unknown User Profile Builder). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-15932 (Unknown Support Genix). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-15939 (Unknown Simple Restrict). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16057 (Unknown Contest Gallery). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16060 (Unknown Insert or Embed Articulate Content into WordPress). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16250 (Unknown Personal QR Message). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16256 (Unknown POUCO Import Users). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16274 (Unknown Classified Listing). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16276 (Unknown Classified Listing). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18616 (GL-iNet GL-MT3000). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18631 (jeequan jeepay). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18641 (Sangfor Operation and Maintenance Security Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18645 (danpros HTMLy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18646 (danpros HTMLy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18647 (jina-ai reader). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18648 (Blix Email Blue Mail Calendar App). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18682 (OpenAkita). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18684 (GL.iNet GL-MT3000). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-32141 (WebReflection flatted). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-33228 (WebReflection flatted). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-33870 (netty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-39363 (vitejs vite). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-39364 (vitejs vite). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-67599 (ClearFoundation ClearOS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-67617 (microweber). Public exploit reference added.
RESCORED — Linux: 1377 CVEs (CVE-2019-25160, CVE-2020-36787, CVE-2020-36791, CVE-2021-4454, CVE-2021-46908, CVE-2021-46910, CVE-2021-46911, CVE-2021-46912, CVE-2021-46913, CVE-2021-46921, CVE-2021-46922, CVE-2021-46925, CVE-2021-46929, CVE-2021-46933, CVE-2021-46948, CVE-2021-46955, CVE-2021-46958, CVE-2021-46960, CVE-2021-46963, CVE-2021-46967, CVE-2021-46974, CVE-2021-46977, CVE-2021-46983, CVE-2021-46992, CVE-2021-46993, CVE-2021-46999, CVE-2021-47001, CVE-2021-47011, CVE-2021-47013, CVE-2021-47017, CVE-2021-47028, CVE-2021-47035, CVE-2021-47036, CVE-2021-47041, CVE-2021-47049, CVE-2021-47055, CVE-2021-47066, CVE-2021-47069, CVE-2021-47103, CVE-2021-47107, CVE-2021-47109, CVE-2021-47111, CVE-2021-47112, CVE-2021-47113, CVE-2021-47124, CVE-2021-47131, CVE-2021-47132, CVE-2021-47136, CVE-2021-47142, CVE-2021-47152, and 1327 more — full list in this day's data.json). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2023-6123 (OpenText ALM Octane.). CVSS 7.5 → 6.1 (NVD).
RESCORED — CVE-2024-10234 (wildfly). CVSS 6.1 → 7.3 (NVD).
RESCORED — CVE-2024-21762 (Fortinet FortiProxy). CVSS 9.6 → 9.8 (NVD).
RESCORED — CVE-2024-51567. CVSS 10 → 9.8 (NVD).
RESCORED — CVE-2024-53704 (SonicWall SonicOS). CVSS 8.2 → 9.8 (NVD).
RESCORED — CVE-2024-55550. CVSS 4.4 → 2.7 (NVD).
RESCORED — CVE-2024-57727. CVSS 9.1 → 7.5 (NVD).
RESCORED — CVE-2025-10035 (Fortra GoAnywhere MFT). CVSS 10 → 9.8 (NVD).
RESCORED — CVE-2025-22457 (Ivanti Connect Secure). CVSS 9 → 9.8 (NVD).
RESCORED — CVE-2025-31324 (SAP_SE SAP NetWeaver (Visual Composer development server)). CVSS 10 → 9.8 (NVD).
RESCORED — CVE-2026-18685 (GL.iNet GL-MT3000). CVSS 9.3 → 8.9 (NVD).
RESCORED — CVE-2026-35154 (Dell PowerProtect Data Domain appliances). CVSS 6.3 → 6.7 (NVD).
RESCORED — CVE-2026-40477 (thymeleaf). CVSS 9.1 → 9 (NVD).
RESCORED — CVE-2026-66310 (Microsoft Edge for Android). CVSS 7.7 → 7.1 (NVD).
RESCORED — CVE-2026-66312 (Microsoft Edge (Chromium-based)). CVSS 6.5 → 8.8 (NVD).
RESCORED — CVE-2026-66314 (Microsoft Edge (Chromium-based)). CVSS 6.5 → 5.3 (NVD).
RESCORED — CVE-2026-66321 (Microsoft Edge (Chromium-based)). CVSS 7.4 → 9.6 (NVD).
RESCORED — CVE-2026-66322 (Microsoft Edge (Chromium-based)). CVSS 7.1 → 5.4 (NVD).
RESCORED — CVE-2026-66326 (Microsoft Edge (Chromium-based)). CVSS 6.5 → 8.8 (NVD).
PATCH SHIPPED — CVE-2023-35078 (Ivanti Endpoint Manager Mobile). Fixed in Endpoint Manager Mobile 11.10.
PATCH SHIPPED — CVE-2026-31431 (Linux). Fixed in Linux 5.10.254.
How to read these box scores · glossary
273 CVEs published. 25 box scores, 248 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .9862 99.9 YES
AFFECTED Product Versions Fixed Apache Tomcat 11.0.20 – —
TIMELINE Mar 30 Reserved by CNA Aug 4 Added to CISA KEV, due Aug 7 Aug 4 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N N H N N 8.2 .0393 89.5 YES
AFFECTED Product Versions Fixed N-central unspecified —
TIMELINE Aug 1 Reserved by CNA Aug 4 Added to CISA KEV, due Aug 7 Aug 4 Published (CNA: N-able)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 7.3 .0271 84.8 —
AFFECTED Product Versions Fixed NX15 V100R017 – —
TIMELINE Aug 4 Reserved by CNA Aug 4 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0261 84.2 —
AFFECTED Product Versions Fixed GL-MT3000 4.4.0 – —
TIMELINE Aug 3 Reserved by CNA Aug 4 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 7.3 .0226 81.7 —
AFFECTED Product Versions Fixed NX15 V100R017 – —
TIMELINE Aug 4 Reserved by CNA Aug 4 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 7.3 .0226 81.7 —
AFFECTED Product Versions Fixed NX15 V100R017 – —
TIMELINE Aug 4 Reserved by CNA Aug 4 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 7.3 .0226 81.7 —
AFFECTED Product Versions Fixed NX15 V100R017 – —
TIMELINE Aug 4 Reserved by CNA Aug 4 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0224 81.5 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Mar 11 Reserved by CNA Aug 4 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 7.4 .0165 74.7 —
AFFECTED Product Versions Fixed AX1800 4.8.0 – —
TIMELINE Aug 4 Reserved by CNA Aug 4 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0162 74.2 —
AFFECTED Product Versions Fixed IP Camera 2.x – —
TIMELINE Jul 10 Reserved by CNA Aug 4 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0148 72.0 —
AFFECTED Product Versions Fixed Linux 42e30bf3463cd37d73839376662cb79b4d5c416c – — Linux 2.6.25 – 5.10.265
TIMELINE Jul 19 Reserved by CNA Aug 4 Published (CNA: Linux)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0120 65.9 —
AFFECTED Product Versions Fixed MaxSite CMS 105.2 – 109.6
TIMELINE Aug 4 Reserved by CNA Aug 4 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0117 65.1 —
AFFECTED Product Versions Fixed WAX650S firmware <= 7.10(ABRM.4)C0 – —
TIMELINE Apr 22 Reserved by CNA Aug 4 Published (CNA: Zyxel)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0116 64.6 —
AFFECTED Product Versions Fixed perspective unspecified —
TIMELINE Jul 28 Reserved by CNA Aug 4 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P L N H H H 9.0 .0106 61.9 —
AFFECTED Product Versions Fixed Flowise < 3.1.3 – — flowise-components < 3.1.3 – —
TIMELINE Aug 3 Reserved by CNA Aug 4 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N L 6.9 .0103 61.0 —
AFFECTED Product Versions Fixed Django 6.0 – 6.0.8
TIMELINE Jul 9 Reserved by CNA Aug 4 Published (CNA: DSF)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N L 6.9 .0103 61.0 —
AFFECTED Product Versions Fixed Django 6.0 – 6.0.8
TIMELINE Jul 15 Reserved by CNA Aug 4 Published (CNA: DSF)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0085 55.4 —
AFFECTED Product Versions Fixed MaxSite CMS 0.78 – 109.6
TIMELINE Aug 4 Reserved by CNA Aug 4 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H H N U H N N 4.4 .0085 55.4 —
AFFECTED Product Versions Fixed Red Hat JBoss Enterprise Application Platform 7 unspecified — Red Hat JBoss Enterprise Application Platform 7 unspecified — Red Hat JBoss Enterprise Application Platform 7 unspecified — Red Hat JBoss Enterprise Application Platform 7 unspecified — Red Hat JBoss Enterprise Application Platform 7 unspecified — Red Hat JBoss Enterprise Application Platform 7 unspecified — Red Hat JBoss Enterprise Application Platform 8 unspecified — Red Hat JBoss Enterprise Application Platform Expansion Pack unspecified — Red Hat Single Sign-On 7 unspecified —
TIMELINE Jul 27 Reserved by CNA Aug 4 Published (CNA: redhat)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0077 53.0 —
AFFECTED Product Versions Fixed Hawkeye unspecified 6.0.7 IxChariot unspecified 10.0.254 IxTap unspecified 3.13.0 IxProbe unspecified 3.13.0 IxByPass unspecified 3.13.0.69
TIMELINE May 29 Reserved by CNA Aug 4 Published (CNA: cisa-cg)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0072 51.0 —
AFFECTED Product Versions Fixed IxChariot unspecified 9.5.102
TIMELINE May 29 Reserved by CNA Aug 4 Published (CNA: cisa-cg)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0072 51.0 —
AFFECTED Product Versions Fixed IxChariot unspecified 9.5.102
TIMELINE May 29 Reserved by CNA Aug 4 Published (CNA: cisa-cg)
AV AC PR UI S C I A CVSS EPSS %ile KEV A L N N U H N N 6.5 .0070 50.4 —
AFFECTED Product Versions Fixed WAX650S firmware <= 7.10(ABRM.4)C0 – —
TIMELINE May 14 Reserved by CNA Aug 4 Published (CNA: Zyxel)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0069 50.1 —
AFFECTED Product Versions Fixed kotaemon unspecified —
TIMELINE Aug 3 Reserved by CNA Aug 4 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0068 49.8 —
AFFECTED Product Versions Fixed Django 6.0 – 6.0.8
TIMELINE Jul 9 Reserved by CNA Aug 4 Published (CNA: DSF)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-45100 | 9.1 | 45.1 | OpenSIPS | opensips | CWE-120 | OpenSIPS: Buffer Overflow in Base64 Encode Transformation |
| CVE-2026-69264 | 9.4 | 45.0 | FlowiseAI | Flowise | CWE-94 | Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated int… |
| CVE-2026-67200 | 8.7 | 44.4 | perspective-dev | perspective | CWE-22 | Perspective 5.0.0 Path Traversal via cwd_static_file_handler |
| CVE-2026-70552 | 9.3 | 44.4 | MaxSite | MaxSite CMS | CWE-306 | MaxSite CMS 109.5 Unauthenticated AJAX Dispatcher Bypass via ajax.php |
| CVE-2026-47612 | 7.5 | 43.6 | NVIDIA | Dynamo | CWE-22 | NVIDIA Dynamo for Linux contains a vulnerability in the image loading compone… |
| CVE-2026-69100 | 8.7 | 43.6 | dromara | lamp-cloud | CWE-94 | LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Execution |
| CVE-2026-69110 | 9.3 | 43.5 | Microck | opencode-studio | CWE-22 | OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/music |
| CVE-2026-24254 | 9.8 | 43.1 | NVIDIA | Dynamo | CWE-288 | NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving to… |
| CVE-2026-18830 | 8.6 | 42.4 | AWS | Amazon Bedrock AgentCore harness | CWE-1287 | Insufficient input validation in Amazon Bedrock AgentCore harness InvokeHarne… |
| CVE-2026-70470 | 9.5 | 42.0 | FlowiseAI | Flowise | CWE-184 | Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE |
| CVE-2026-0163 | 9.8 | 41.7 | Android | CWE-416 | In multiple functions of vpu_ioctl.c, there is a possible use after free due … | |
| CVE-2026-56846 | 7.5 | 40.5 | nodejs | node | CWE-400 | A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks eva… |
| CVE-2026-15314 | 7.1 | 40.5 | TP-Link Systems Inc. | P110 v1 | CWE-120 | Authenticated Denial-of-Service Vulnerability in TP-Link Tapo P110 |
| CVE-2026-56848 | 7.5 | 39.9 | nodejs | node | CWE-416 | A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be c… |
| CVE-2026-46334 | 8.7 | 39.8 | OpenSIPS | opensips | CWE-20 | OpenSIPS: Denial of Service in SDP bandwidth parsing via QoS SDP cloning |
| CVE-2026-10050 | 8.7 | 39.4 | Eclipse Foundation | Eclipse Jetty - EE8 | CWE-173 | Digest authentication lossy encoding |
| CVE-2026-45538 | 9.8 | 39.4 | OpenSIPS | opensips | CWE-121 | OpenSIPS: Stack Buffer Overflow in sip_to_json() Header Name Copy |
| CVE-2026-67858 | 7.5 | 39.3 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discov… |
| CVE-2026-58072 | 9.0 | 38.8 | Veeam | Service Provider Console | CWE-22 | A vulnerability in Veeam Service Provider Console allowing arbitrary file wri… |
| CVE-2026-45084 | 8.7 | 38.2 | OpenSIPS | opensips | CWE-476 | OpenSIPS: Denial of service in presence.handle_publish() from unchecked Conte… |
| CVE-2026-16618 | 9.8 | 38.0 | Unknown | Improve SEO | CWE-434 | ImproveSEO <= 2.0.11 - Unauthenticated Arbitrary File Upload Leading to Remot… |
| CVE-2026-61514 | 9.3 | 38.0 | Puwell Technology Inc. | IP Camera | CWE-306 | Puwell IP Camera 2.x - 4.x Unauthenticated Access via TCP Port 23456 |
| CVE-2026-67859 | 7.5 | 37.9 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to… |
| CVE-2026-69703 | 9.3 | 37.7 | maximeAmini | Atals-Livre | CWE-306 | Atlas-Livre Unauthenticated Access via Admin Controllers Missing Exit |
| CVE-2026-63455 | 9.8 | 37.7 | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Orchestrator | CWE-306 | Authentication bypass via spoofed HTTP headers Orchestrator REST API |
| CVE-2026-64633 | 10.0 | 37.5 | Veeam | ONE | CWE-94 | A vulnerability allowing remote unauthenticated code execution on the agent h… |
| CVE-2026-47619 | 8.1 | 36.9 | NVIDIA | Dynamo | CWE-1357 | NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an… |
| CVE-2026-70477 | 9.5 | 36.8 | FlowiseAI | Flowise | CWE-94 | Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability |
| CVE-2026-66902 | 9.8 | 36.5 | CJCOLLIER | Google::Auth | CWE-78 | Google::Auth versions before 0.06 for Perl run a command named in an external… |
| CVE-2026-63456 | 9.8 | 35.5 | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Orchestrator | CWE-287 | Authentication bypass via spoofed HTTP headers Orchestrator REST API |
| CVE-2026-63252 | 8.7 | 34.9 | Eclipse Foundation | Eclipse Milo | CWE-401 | In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers … |
| CVE-2026-67856 | 7.5 | 34.4 | n/a | n/a | CWE-400 | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a … |
| CVE-2026-67861 | 7.5 | 34.0 | n/a | n/a | CWE-400 | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a … |
| CVE-2026-56845 | 7.5 | 33.0 | Rocket.Chat | Rocket.Chat | CWE-22 | An unauthenticated path traversal (LFI) vulnerability exists under /custom-so… |
| CVE-2026-18103 | 4.9 | 32.9 | Red Hat | Red Hat Enterprise Linux 6 | CWE-120 | Dhcp-server: dhcp-server: persistent denial of service due to buffer overflow… |
| CVE-2026-15920 | 5.1 | 32.1 | djangoproject | Django | CWE-83 | Potential cross-site scripting via URLField values in the admin |
| CVE-2026-69256 | 9.4 | 31.8 | FlowiseAI | Flowise | CWE-94 | Flowise: Remote Code Execution Vulnerability in CSVAgent |
| CVE-2026-47623 | 8.2 | 31.7 | NVIDIA | Dynamo | CWE-502 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could caus… |
| CVE-2026-45809 | 8.7 | 31.6 | OpenSIPS | opensips | CWE-121 | OpenSIPS: Denial of Service in watcherinfo XML generation from oversized watc… |
| CVE-2026-58067 | 8.7 | 31.4 | Veeam | Service Provider Console | CWE-789 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated… |
| CVE-2026-24255 | 7.5 | 31.2 | NVIDIA | Dynamo | CWE-1023 | NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding … |
| CVE-2026-60007 | 9.1 | 31.1 | Eclipse Foundation | Eclipse Milo | CWE-204 | In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing retur… |
| CVE-2026-69258 | 8.8 | 31.1 | FlowiseAI | Flowise | CWE-639 | Flowise: Unauthenticated Property Injection into Flow Execution Context via U… |
| CVE-2026-18810 | 6.9 | 31.1 | H3C | NX15 | CWE-287 | H3C NX15 networkSetup missing authentication |
| CVE-2026-70478 | 9.2 | 30.9 | FlowiseAI | Flowise | CWE-200 | Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens … |
| CVE-2026-18788 | 5.5 | 30.2 | Trippo | ResponsiveFilemanager | CWE-284 | Trippo ResponsiveFilemanager dialog.php unrestricted upload |
| CVE-2026-70486 | 8.2 | 30.2 | open-webui | open-webui | CWE-79 | Open WebUI: Same-origin XSS to account takeover via terminal file-preview ifr… |
| CVE-2026-68494 | 8.7 | 30.0 | FasterXML | jackson-core | CWE-770 | jackson-core: Async parser maxNumberLength bypass via chunked digit accumulat… |
| CVE-2026-58042 | 5.9 | 29.6 | nodejs | node | CWE-400 | A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When … |
| CVE-2026-70619 | 8.7 | 29.1 | odysseus-dev | odysseus | CWE-862 | Odysseus Missing Admin Authorization via Embedding Endpoint Routes |
| CVE-2026-16548 | 6.5 | 29.0 | Unknown | Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat | CWE-434 | Bit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response Endpoint |
| CVE-2026-69254 | 9.4 | 28.9 | FlowiseAI | Flowise | CWE-94 | Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptio… |
| CVE-2026-58071 | 8.2 | 28.8 | Veeam | Service Provider Console | CWE-306 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated… |
| CVE-2026-14818 | 7.2 | 28.6 | Zyxel | ATP series firmware | CWE-22 | A path traversal vulnerability in the CLI command used to execute configurati… |
| CVE-2026-16793 | 8.7 | 28.1 | Lenovo | XClarity Orchestrator | CWE-20 | Remote Command Injection via OS Profile Password in Lenovo XClarity Orchestrator |
| CVE-2026-69259 | 9.4 | 28.0 | FlowiseAI | Flowise | CWE-94 | Flowise RCE via SQLite Record Manager Node |
| CVE-2026-45537 | 9.1 | 28.0 | OpenSIPS | opensips | CWE-120 | OpenSIPS: Global Buffer Overflow in construct_uri |
| CVE-2026-58074 | 8.6 | 28.1 | Veeam | ONE | CWE-94 | A vulnerability allowing a high-privileged user to execute arbitrary code on … |
| CVE-2026-24253 | 8.2 | 27.9 | NVIDIA | Dynamo | CWE-787 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could caus… |
| CVE-2026-70368 | 6.5 | 27.9 | Mobi-Com Polska Sp. z o.o. | stunnel | CWE-125 | Stunnel: stack-based out-of-bounds read/write in stunnel s_vlog via oversized… |
| CVE-2026-64561 | 8.8 | 27.3 | Linux | Linux | — | KVM: x86: Check for invalid/obsolete root *after* making MMU pages available |
| CVE-2026-67857 | 7.5 | 27.1 | n/a | n/a | CWE-125 | open62541 1.5.5 contains an out-of-bounds read in the client-side function re… |
| CVE-2026-66901 | 7.5 | 27.1 | CJCOLLIER | Google::Auth | CWE-201 | Google::Auth versions before 0.09 for Perl allow server side request forgery … |
| CVE-2026-61387 | 6.9 | 27.0 | Eclipse Foundation | Eclipse Milo | CWE-400 | In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting… |
| CVE-2026-69250 | 8.5 | 26.7 | FlowiseAI | Flowise | CWE-639 | Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exf… |
| CVE-2026-18816 | 2.3 | 26.4 | n/a | Baserow | CWE-287 | Baserow 2FA Verify Endpoint views.py verify improper authentication |
| CVE-2026-70482 | 8.1 | 26.2 | open-webui | open-webui | CWE-287 | Open WebUI: Account takeover via OAuth token exchange accepting tokens issued… |
| CVE-2026-69263 | 8.7 | 26.0 | FlowiseAI | Flowise | CWE-184 | Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment … |
| CVE-2026-67862 | 7.5 | 25.6 | n/a | n/a | CWE-400 | open62541 1.5.5 contains a buffer-overflow in the high-level attribute readin… |
| CVE-2026-45103 | 7.5 | 25.1 | OpenSIPS | opensips | CWE-190 | OpenSIPS: SIP Message Smuggling via TCP Content-Length Integer Overflow |
| CVE-2026-67243 | 8.6 | 24.1 | refirio | freo2 | CWE-434 | freo2 provided by refirio contains an unrestricted upload of file with danger… |
| CVE-2026-47613 | 7.5 | 24.1 | NVIDIA | Dynamo | CWE-918 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause … |
| CVE-2026-47614 | 7.5 | 24.1 | NVIDIA | Dynamo | CWE-918 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause … |
| CVE-2026-47615 | 7.5 | 24.1 | NVIDIA | Dynamo | CWE-918 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause … |
| CVE-2026-47616 | 7.5 | 24.1 | NVIDIA | Dynamo | CWE-918 | NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetc… |
| CVE-2026-47617 | 7.5 | 24.1 | NVIDIA | Dynamo | CWE-918 | NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetc… |
| CVE-2026-47618 | 7.5 | 24.1 | NVIDIA | Dynamo | CWE-918 | NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media… |
| CVE-2026-58073 | 9.5 | 23.9 | Veeam | Service Provider Console | CWE-288 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated… |
| CVE-2026-69255 | 9.2 | 23.4 | FlowiseAI | Flowise | CWE-94 | Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Sh… |
| CVE-2026-18753 | 9.1 | 23.4 | GeoVision Inc. | GV-AS1620 (AS-Manager) | CWE-321 | Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-ASManager) |
| CVE-2026-18754 | 9.1 | 23.4 | GeoVision Inc. | GV-AS1620 (GV-Cloud) | CWE-321 | Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-Cloud) |
| CVE-2026-69253 | 9.0 | 23.3 | FlowiseAI | Flowise | CWE-95 | Flowise Sandbox Escape to RCE |
| CVE-2026-18401 | 6.9 | 23.1 | FasterXML | jackson-core | CWE-770 | jackson-core: Number length constraint bypass in non-blocking (async) JSON pa… |
| CVE-2026-70369 | 8.8 | 22.7 | Koha Community | Koha | CWE-89 | Koha - SQL Injection in reports/acquisitions_stats.pl |
| CVE-2026-70370 | 8.8 | 22.7 | Koha Community | Koha | CWE-89 | Koha - SQL Injection in reports/catalogue_stats.pl |
| CVE-2026-70371 | 8.8 | 22.7 | Koha Community | Koha | CWE-89 | Koha - SQL Injection in reports/issues_avg_stats.pl |
| CVE-2026-70372 | 8.8 | 22.7 | Koha Community | Koha | CWE-89 | Koha - SQL Injection in reports/bor_issues_top.pl |
| CVE-2026-70373 | 8.8 | 22.7 | Koha Community | Koha | CWE-89 | Koha - SQL Injection in reports/issues_stats.pl |
| CVE-2026-70474 | 7.6 | 22.5 | FlowiseAI | Flowise | CWE-863 | Flowise: Cross-Workspace OAuth2 Credential Metadata Leak |
| CVE-2026-69702 | 7.1 | 22.6 | aizuda | SnailJob (snail-job) | CWE-789 | SnailJob 1.7.0 Denial of Service via FuryUtil.deserialize OOM |
| CVE-2026-70493 | 6.5 | 22.6 | open-webui | open-webui | CWE-1333 | Open WebUI: Any authenticated user can stall a worker via a knowledge-search … |
| CVE-2026-62927 | 8.7 | 22.5 | Eclipse Foundation | Eclipse Milo | CWE-863 | In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the… |
| CVE-2026-18770 | 5.5 | 22.5 | vibesurf-ai | VibeSurf | CWE-74 | vibesurf-ai VibeSurf Python Validation code code injection |
| CVE-2026-47682 | 7.1 | 22.4 | cvat-ai | cvat | CWE-22 | CVAT: Missing path-containment validation in multiple entry points allows arb… |
| CVE-2026-70481 | 5.4 | 21.9 | open-webui | open-webui | CWE-284 | Open WebUI: Any member with write access to a standard channel can edit or de… |
| CVE-2026-70592 | 5.5 | 21.8 | TryGhost | Ghost | CWE-22 | Ghost: Database Backup Path Traversal |
| CVE-2026-70494 | 8.1 | 21.7 | open-webui | open-webui | CWE-862 | Open WebUI: A folder write-collaborator can permanently delete the owner's ch… |
| CVE-2026-67199 | 7.1 | 21.7 | perspective-dev | perspective | CWE-770 | Perspective 5.0.0 DoS via Loop Expression Evaluation |
| CVE-2026-70475 | 7.1 | 21.6 | FlowiseAI | Flowise | CWE-862 | Flowise: Missing Authorization on Execution Update Endpoint |
| CVE-2026-14194 | 6.5 | 21.5 | Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | CWE-22 | Path Traversal Allows Arbitrary File Download in Bilin Software's HUMANIST Di… |
| CVE-2026-70489 | 6.5 | 21.5 | open-webui | open-webui | CWE-400 | Open WebUI: Instance-wide stall via automation recurrence rules that force mu… |
| CVE-2026-45705 | 5.3 | 21.1 | OpenSIPS | opensips | CWE-125 | OpenSIPS: OOB Read in Multipart Body Boundary Parsing |
| CVE-2026-14175 | 9.8 | 20.9 | Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | CWE-434 | Unrestricted File Upload in Bilin Software's HUMANIST Digital Human Resources |
| CVE-2026-70593 | 6.6 | 20.9 | TryGhost | Ghost | CWE-22 | Ghost: Theme Upload Path Traversal |
| CVE-2026-66883 | 6.3 | 21.0 | Erlang Ecosystem Foundation | oidcc_plug | CWE-178 | Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive h… |
| CVE-2026-67979 | 9.1 | 20.5 | n/a | n/a | CWE-284 | Incorrect access control in the Executive Services dynamic application start … |
| CVE-2026-17070 | 8.8 | 20.5 | HAVELSAN Inc. | Liman MYS | CWE-862 | Vault Credential Confusion via Authorization Bypass in HAVELSAN's Liman MYS |
| CVE-2026-70476 | 8.3 | 20.5 | FlowiseAI | Flowise | CWE-284 | Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-… |
| CVE-2026-67855 | 7.5 | 20.6 | n/a | n/a | CWE-400 | open62541 contains a heap use-after-free in the GDS PushManagement certificat… |
| CVE-2026-18720 | 5.5 | 20.5 | kalcaddle | kodbox | CWE-266 | kalcaddle kodbox msgWarning Plugin action improper authorization |
| CVE-2026-11368 | 6.5 | 20.1 | zephyrproject | zephyr | CWE-416 | Use-after-free in Bluetooth host ATT TX completion on disconnect mid-transfer |
| CVE-2026-58075 | 8.7 | 20.1 | Veeam | ONE | CWE-287 | A vulnerability allowing an unauthenticated attacker to read arbitrary files … |
| CVE-2026-70471 | 7.1 | 19.9 | FlowiseAI | Flowise | CWE-863 | Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure |
| CVE-2026-70492 | 8.7 | 19.5 | open-webui | open-webui | CWE-79 | Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered … |
| CVE-2026-69704 | 7.0 | 19.4 | maximeAmini | Atals-Livre | CWE-89 | Atals-Livre SQL Injection via Unsanitized GET Parameter in supp() |
| CVE-2026-58080 | 8.8 | 19.4 | Eclipse Foundation | Eclipse Milo | CWE-862 | In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fail… |
| CVE-2026-18775 | 2.1 | 18.8 | NousResearch | hermes-agent | CWE-918 | NousResearch hermes-agent Browser Tooling browser_tool.py browser_snapshot se… |
| CVE-2026-16547 | 5.9 | 18.5 | Unknown | REST API Log | CWE-284 | REST API Log < 1.7.1 - Unauthenticated Sensitive Log Data Disclosure via Down… |
| CVE-2026-64631 | 8.5 | 18.3 | Veeam | ONE | CWE-89 | A vulnerability allowing a low-privileged user to inject SQL and extract data… |
| CVE-2026-67860 | 7.5 | 18.4 | n/a | n/a | CWE-122 | open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryR… |
| CVE-2026-70484 | 4.3 | 18.4 | open-webui | open-webui | CWE-862 | Open WebUI: Users denied the image-generation permission can still generate i… |
| CVE-2026-70620 | 6.1 | 17.8 | odysseus-dev | odysseus | CWE-918 | Odysseus SSRF via Embedding Endpoint Configuration |
| CVE-2026-47622 | 5.3 | 17.9 | NVIDIA | Dynamo | CWE-209 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could caus… |
| CVE-2026-16881 | 8.7 | 17.6 | LY Corporation | LINE client for Android | — | A code injection vulnerability exists in the LINE Android app prior to versio… |
| CVE-2026-70479 | 7.7 | 17.3 | open-webui | open-webui | CWE-918 | Open WebUI: SSRF into internal services via unvalidated sub-resource requests… |
| CVE-2026-69252 | 7.2 | 17.4 | FlowiseAI | Flowise | CWE-862 | Flowise: Missing authorization on `/api/v1/files` allows low-privileged API k… |
| CVE-2026-70491 | 6.5 | 17.3 | open-webui | open-webui | CWE-200 | Open WebUI: Tool source code disclosed to read-only users via the tool list a… |
| CVE-2026-70588 | 5.0 | 17.1 | TryGhost | Ghost | CWE-79 | Ghost: Cross-Site Scripting in Universal Import |
| CVE-2026-47620 | 6.5 | 16.6 | NVIDIA | Dynamo | CWE-362 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could caus… |
| CVE-2026-47621 | 6.5 | 16.6 | NVIDIA | Dynamo | CWE-367 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could caus… |
| CVE-2026-58041 | 5.3 | 16.5 | nodejs | node | CWE-367 | A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created th… |
| CVE-2026-14816 | 6.5 | 16.1 | Unknown | The GDPR Framework By Data443 | CWE-284 | The GDPR Framework < 2.4.0 - Unauthenticated Consent Record Forgery and Do No… |
| CVE-2026-70487 | 5.3 | 16.1 | open-webui | open-webui | CWE-862 | Open WebUI: Cross-user file content disclosure via request-scoped direct mode… |
| CVE-2026-18721 | 2.1 | 16.0 | kalcaddle | kodbox | CWE-601 | kalcaddle kodbox SSO API Login apiLogin redirect |
| CVE-2026-14337 | 4.6 | 15.7 | Pegasystems | Pega Infinity | CWE-79 | Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-… |
| CVE-2026-70473 | 8.3 | 15.6 | FlowiseAI | Flowise | CWE-200 | Flowise: Information Disclosure in GET /api/v1/upsert-history returns the ent… |
| CVE-2026-69257 | 7.6 | 15.6 | FlowiseAI | Flowise | CWE-918 | Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses |
| CVE-2026-13227 | 7.1 | 15.6 | Frappe | ERPNext | CWE-862 | ERPNext v16.25.0 - Improper authorization in Prospect opportunities API |
| CVE-2026-13229 | 7.1 | 15.6 | Zammad | Zammad | CWE-862 | Zammad 7.0.1 - Improper authorization in ticket article attachment cloning |
| CVE-2026-69262 | 7.1 | 15.6 | FlowiseAI | Flowise | CWE-863 | Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allo… |
| CVE-2026-70472 | 7.1 | 15.6 | FlowiseAI | Flowise | CWE-285 | Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store |
| CVE-2026-70483 | 3.1 | 15.4 | open-webui | open-webui | CWE-862 | Open WebUI: Any authenticated user can cancel another user's chat generation … |
| CVE-2026-48154 | 5.9 | 15.3 | pilinux | gorest | CWE-362 | GoRest: InMemorySecret2FA race condition allows process crash via concurrent … |
| CVE-2026-58044 | 3.7 | 15.0 | nodejs | node | CWE-444 | A flaw in Node.js HTTP client can cause a request desynchronization for Node.… |
| CVE-2026-65986 | 8.5 | 14.7 | cvat-ai | cvat | CWE-79 | CVAT has stored XSS via annotation guide assets |
| CVE-2026-64630 | 5.3 | 14.3 | Veeam | ONE | CWE-863 | A vulnerability allowing a low-privileged user to retrieve report data outsid… |
| CVE-2026-14804 | 9.1 | 13.9 | Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | CWE-321 | Hardcoded Cryptographic Key in Bilin Software's HUMANIST Digital Human Resources |
| CVE-2026-18650 | 8.8 | 13.8 | HAVELSAN Inc. | Liman MYS | CWE-862 | Missing Authorization Leading to Root Code Execution in HAVELSAN's Liman MYS |
| CVE-2026-16623 | 8.0 | 13.7 | Unknown | Create Block Theme | CWE-94 | Create Block Theme < 2.10.0 - Admin+ PHP Code Injection via Pattern Save (Mul… |
| CVE-2026-48121 | 6.7 | 13.5 | langchain-ai | langgraphjs | CWE-943 | @langchain/langgraph-checkpoint-mongodb: NoSQL parameter injection in MongoDB… |
| CVE-2026-16069 | 6.8 | 13.4 | Unknown | Brizy | CWE-79 | Brizy - Page Builder < 2.8.19 - Contributor+ Stored XSS via Featured Image Fo… |
| CVE-2026-16293 | 6.8 | 13.4 | Unknown | PowerPress Podcasting plugin by Blubrry | CWE-79 | Blubrry PowerPress < 11.16.11 - Contributor+ Stored XSS via Podcast Episode C… |
| CVE-2026-18801 | 9.3 | 13.3 | openmeter | openmeter | CWE-20 | Stored Clickhouse SQL Injection Through Customer Usage Attribution |
| CVE-2026-14939 | 6.8 | 13.3 | Unknown | Visualizer | CWE-918 | Visualizer: Tables and Charts Manager < 4.0.6 - Contributor+ Server-Side Requ… |
| CVE-2026-10526 | 5.8 | 13.4 | Unknown | EmbedPress | CWE-918 | EmbedPress < 4.6.1 - Unauthenticated Blind SSRF |
| CVE-2026-70591 | 4.1 | 13.1 | TryGhost | Ghost | CWE-918 | Ghost: Server-Side Request Forgery in Image Fetching |
| CVE-2026-14872 | 6.8 | 12.8 | Unknown | Database for Contact Form 7, WPforms, Elementor forms | CWE-89 | Database for Contact Form 7, WPforms, Elementor forms < 1.5.5 - Authenticated… |
| CVE-2026-70485 | 7.1 | 12.6 | open-webui | open-webui | CWE-918 | Open WebUI: Any authenticated user can reach internal services and cloud meta… |
| CVE-2026-51144 | 6.1 | 11.6 | n/a | n/a | CWE-79 | Cross Site Scripting vulnerability in Soliton Systems MailZen Management Prot… |
| CVE-2026-66884 | 2.1 | 11.5 | Erlang Ecosystem Foundation | oidcc_plug | CWE-352 | Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session … |
| CVE-2026-54020 | 6.3 | 11.5 | open-webui | open-webui | CWE-367 | Open WebUI: DNS Rebinding SSRF Bypass |
| CVE-2026-70488 | 4.3 | 11.5 | open-webui | open-webui | CWE-639 | Open WebUI: Deletion of directories and file embeddings in other knowledge ba… |
| CVE-2026-18809 | 6.5 | 11.1 | Mozilla | Firefox | CWE-200 | Information disclosure in Firefox for Android and Firefox Focus for Android |
| CVE-2026-18818 | 5.3 | 11.3 | Ehco1996 | django-sspanel | CWE-285 | Ehco1996 django-sspanel Support Ticket views.py TicketDetailView authorization |
| CVE-2026-18722 | 2.1 | 11.3 | diaowen | DWSurvey | CWE-285 | diaowen DWSurvey dev-survey.do in DwDeisgnSurveyController.devSurvey. authori… |
| CVE-2026-14838 | 7.4 | 10.8 | Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | CWE-598 | Session Token Exposure in URL Leading to Account Takeover in Bilin Software's… |
| CVE-2026-70490 | 6.3 | 10.7 | open-webui | open-webui | CWE-863 | Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket au… |
| CVE-2026-14465 | 6.5 | 10.4 | Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | CWE-613 | Session Fixation in Bilin Software's HUMANIST Digital Human Resources |
| CVE-2026-15958 | 9.3 | 10.3 | Unknown | Easy Integration for Dropbox | CWE-862 | Easy Dropbox Integration < 2.2.0 - Unauthenticated Arbitrary Connected Dropbo… |
| CVE-2026-18723 | 2.1 | 9.9 | diaowen | DWSurvey | CWE-266 | diaowen DWSurvey Survey Status up-survey-status.do improper authorization |
| CVE-2026-18773 | 2.1 | 9.9 | NousResearch | hermes-agent | CWE-285 | NousResearch hermes-agent Quick run.py _check_slash_access authorization |
| CVE-2026-18774 | 2.1 | 9.9 | NousResearch | hermes-agent | CWE-918 | NousResearch hermes-agent xAI Image Generation Provider image_gen_provider.py… |
| CVE-2026-67198 | 8.7 | 9.8 | perspective-dev | perspective | CWE-616 | Perspective 5.0.0 DoS via VirtualServer Protocol Dispatcher |
| CVE-2026-18772 | 6.5 | 9.7 | Samsung Open Source | rlottie | CWE-1325 | Improperly controlled sequential memory allocation vulnerability in Samsung O… |
| CVE-2026-67618 | 7.1 | 9.6 | marimo-team | marimo | CWE-345 | marimo < 0.23.15 API Key Exfiltration via Malicious Notebook PEP-723 Metadata |
| CVE-2026-10032 | 6.1 | 9.4 | @a2ui/web_core | CWE-79 | Arbitrary JavaScript Execution via openUrl in @a2ui/web_core | |
| CVE-2026-14202 | 5.3 | 9.5 | Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | CWE-204 | Username Enumeration via Differential Login Responses in Bilin Software's HUM… |
| CVE-2026-70590 | 4.8 | 9.1 | TryGhost | Ghost | CWE-200 | Ghost: Blind Password Hash Disclosure in Ghost Admin API |
| CVE-2026-16035 | 4.3 | 9.1 | Unknown | miniOrange 2FA | CWE-862 | miniOrange 2FA < 6.2.7 - Subscriber+ Arbitrary-Recipient OTP Send |
| CVE-2026-16536 | 5.3 | 9.0 | Unknown | Simple Google Calendar Outlook Events Widget | CWE-918 | Simple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF v… |
| CVE-2026-70480 | 4.1 | 8.9 | open-webui | open-webui | CWE-918 | Open WebUI: Client-side SSRF via unrestricted external resource loading in Ve… |
| CVE-2026-11366 | 3.7 | 8.9 | Unknown | MonsterInsights | CWE-287 | MonsterInsights < 11.1.0 - Unauthenticated Measurement Protocol Secret Update… |
| CVE-2026-18719 | 2.1 | 8.9 | cemtan | sar2html | CWE-74 | cemtan sar2html Search sar2html.py sql injection |
| CVE-2026-18766 | 2.1 | 8.9 | chetans9 | core-php-admin-panel | CWE-74 | chetans9 core-php-admin-panel customers.php sql injection |
| CVE-2026-52370 | 6.1 | 8.5 | n/a | n/a | CWE-79 | A reflected cross-site scripting (XSS) vulnerability in the Forum posting fun… |
| CVE-2026-16296 | 4.7 | 8.3 | Unknown | Clearfy Cache | CWE-601 | Clearfy < 2.4.3 - Open Redirect via Cyrlitera 404 Handler |
| CVE-2026-12698 | 4.3 | 8.1 | Unknown | wpForo Forum | CWE-284 | wpForo Forum < 3.1.3 - Subscriber+ Account Status and Reputation Manipulation… |
| CVE-2026-47487 | 7.1 | 7.9 | NVIDIA | Triton Inference Server | CWE-22 | NVIDIA Triton Inference Server for Linux contains a vulnerability where a use… |
| CVE-2026-64565 | await | 8.0 | Linux | Linux | — | Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() |
| CVE-2026-66300 | 2.3 | 7.7 | SNOMED International | Snowstorm | CWE-79 | SNOMED International Snowstorm reflected XSS |
| CVE-2026-15721 | 9.8 | 6.7 | Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | CWE-312 | Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Sof… |
| CVE-2026-70589 | 4.8 | 6.6 | TryGhost | Ghost | CWE-20 | Ghost: Archived Offers can be Redeemed |
| CVE-2026-14848 | 5.4 | 6.4 | Unknown | Paid Membership Subscriptions | CWE-284 | Paid Member Subscriptions < 3.0.8 - Subscriber+ Cross-User Subscription Hijac… |
| CVE-2026-14824 | 4.8 | 6.3 | Unknown | Quiz and Survey Master (QSM) | CWE-79 | Quiz And Survey Master < 11.2.2 - Contributor+ Stored XSS via Polar Question |
| CVE-2026-16070 | 2.7 | 6.3 | Unknown | Brizy | CWE-639 | Brizy - Page Builder < 2.8.19 - Contributor+ Template Type Update via IDOR |
| CVE-2026-18853 | 1.9 | 6.1 | ZomboDroid | Meme Generator App | CWE-22 | ZomboDroid Meme Generator App com.zombodroid.MemeGenerator t5.l.c path traversal |
| CVE-2026-58045 | 6.2 | 6.0 | nodejs | node | CWE-400 | A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a rea… |
| CVE-2026-18656 | 8.5 | 5.7 | Amazon | Kiro IDE | CWE-427 | Executable Resolution from Untrusted Project Directory in Kiro IDE on Windows |
| CVE-2026-18657 | 8.5 | 5.7 | Amazon | Kiro CLI | CWE-427 | Executable Resolution from Untrusted Project Directory in Kiro CLI on Windows |
| CVE-2026-16056 | 4.3 | 5.5 | Unknown | Contest Gallery | CWE-862 | Contest Gallery < 30.0.7 - Subscriber+ OpenAI Prompt History Disclosure via p… |
| CVE-2026-16295 | 4.3 | 5.5 | Unknown | Clearfy Cache | CWE-284 | Clearfy < 2.4.3 - Subscriber+ Sensitive Information Disclosure via Factory Pa… |
| CVE-2026-70594 | 6.7 | 5.3 | TryGhost | Ghost | CWE-384 | Ghost: Session Fixation in Ghost Admin |
| CVE-2026-18569 | 3.7 | 5.4 | Red Hat | Red Hat Build of Keycloak | CWE-347 | Keycloak-services: keycloak-services: oidc backchannel logout accepts unsigne… |
| CVE-2026-18819 | 2.1 | 5.2 | n/a | RackTables | CWE-352 | RackTables cross-site request forgery |
| CVE-2026-63248 | 6.9 | 4.9 | Eclipse Foundation | Eclipse Milo | CWE-862 | In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes… |
| CVE-2026-70367 | 5.4 | 4.9 | Mobi-Com Polska Sp. z o.o. | stunnel | CWE-918 | Stunnel: ssrf bypass in stunnel socks proxy via ipv4-mapped ipv6 loopback and… |
| CVE-2026-16546 | 4.3 | 4.6 | Unknown | Wired Impact Volunteer Management | CWE-862 | Wired Impact Volunteer Management < 2.8.2 - Subscriber+ Arbitrary RSVP Remova… |
| CVE-2026-47763 | 6.8 | 4.5 | pdm-project | pdm | CWE-61 | pdm: Project-Local State and Config Writes Follow Symlinks |
| CVE-2026-67196 | 5.1 | 4.4 | perspective-dev | perspective | CWE-79 | Perspective 5.0.0 XSS via Debug Plugin innerHTML Interpolation |
| CVE-2026-47764 | 8.4 | 4.3 | pdm-project | pdm | CWE-22 | pdm: Path traversal in wheel installation via overridden write_to_fs |
| CVE-2026-24084 | 7.5 | 4.2 | Qualcomm, Inc. | Snapdragon | CWE-1294 | Insecure Security Identifier Mechanism in Multi-Mode Call Processor |
| CVE-2026-10709 | 7.8 | 4.1 | Autodesk | FBX SDK | CWE-121 | FBX BinaryReadSectionHeader Stack-Based Buffer Overflow Vulnerability in Auto… |
| CVE-2026-10710 | 7.8 | 4.1 | Autodesk | FBX SDK | CWE-121 | FBX ExtractDrive Stack-Based Buffer Overflow Vulnerability in Autodesk FBX SDK |
| CVE-2026-15233 | 4.8 | 3.8 | Unknown | Nested Pages | CWE-79 | Nested Pages < 3.2.15 - Editor+ Stored XSS via Post Title |
| CVE-2026-51401 | 7.7 | 3.5 | n/a | n/a | CWE-94 | An issue in Vim Project v9.2.0389 and earlier allows a local attacker to exec… |
| CVE-2026-16068 | 3.5 | 3.4 | Unknown | Brizy | CWE-79 | Brizy - Page Builder < 2.8.19 - Author+ Stored XSS via brizy_set_project Glob… |
| CVE-2026-42169 | 7.3 | 3.1 | Red Hat | Red Hat Enterprise Linux 9 | CWE-131 | Gimp: gimp apng loader heap-buffer-overflow when fctl width exceeds ihdr widt… |
| CVE-2026-14192 | 5.4 | 3.0 | Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | CWE-79 | Stored XSS in Bilin Software's HUMANIST Digital Human Resources |
| CVE-2026-47781 | 8.4 | 2.9 | pdm-project | pdm | CWE-94 | pdm: Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing |
| CVE-2026-18755 | 7.3 | 2.7 | GeoVision Inc. | GV-ASManager | CWE-428 | GV-ASManager DLL hijacking vulnerability |
| CVE-2026-24079 | 8.1 | 2.6 | Qualcomm, Inc. | Snapdragon | CWE-306 | Missing Authentication for Critical Function in Data Modem |
| CVE-2026-64562 | 8.8 | 2.4 | Linux | Linux | — | KVM: nVMX: Hide shadow VMCS right after VMCLEAR |
| CVE-2026-51400 | 8.4 | 2.4 | n/a | n/a | CWE-401 | An issue in Vim Project v9.2.0389 and earlier allows a local attacker to exec… |
| CVE-2026-18784 | 1.9 | 2.4 | o6 | open62541 | CWE-119 | o6 open62541 ua_client_highlevel.c UA_Client_readNodeClassAttribute heap-base… |
| CVE-2026-14219 | 5.4 | 2.2 | Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | CWE-601 | URL Redirection in Bilin Software's HUMANIST Digital Human Resources |
| CVE-2026-18790 | 1.9 | 2.1 | Systerel | S2OPC | CWE-119 | Systerel S2OPC DeleteMonitoredItemsRequest state_machine.c out-of-bounds |
| CVE-2026-64563 | 7.8 | 1.9 | Linux | Linux | — | rhashtable: clear stale iter->p on table restart |
| CVE-2026-25289 | 9.6 | 1.8 | Qualcomm, Inc. | Snapdragon | CWE-121 | Stack-based Buffer Overflow in WLAN Firmware |
| CVE-2026-18759 | 8.5 | 1.7 | ASUSTOR Inc. | ABP | CWE-269 | An improper authentication and path traversal vulnerability exists in ASUSTOR… |
| CVE-2026-64634 | 8.4 | 1.7 | Veeam | ONE | CWE-269 | A vulnerability allowing local privilege escalation to the Reporter service c… |
| CVE-2026-18785 | 1.9 | 1.5 | o6 | open62541 | CWE-119 | o6 open62541 client_types_custom.c UA_Client_getRemoteDataTypes use after free |
| CVE-2026-18852 | 1.9 | 1.5 | epsilla-cloud | vectordb | CWE-754 | epsilla-cloud vectordb Filter expr.cpp ShuntingYard unusual condition |
| CVE-2026-11835 | 5.6 | 1.4 | Caliptra | Core ROM | CWE-20 | Caliptra Update-Reset Secure-Boot Bypass via Attacker-Chosen AXI Staging Addr… |
| CVE-2026-24077 | 6.5 | 1.2 | Qualcomm, Inc. | Snapdragon | CWE-191 | Integer Underflow (Wrap or Wraparound) in WLAN Host |
| CVE-2026-18739 | 2.5 | 1.2 | rpm-software-management | popt | CWE-787 | Popt-devel: popt-static: off-by-one in poptstuffargs |
| CVE-2026-24078 | 6.5 | 1.2 | Qualcomm, Inc. | Snapdragon | CWE-359 | Exposure of Private Personal Information to an Unauthorized Actor in Data Modem |
| CVE-2026-11836 | 1.8 | 1.1 | Caliptra | Core ROM | CWE-345 | Production Debug-Unlock Token Verification Missing Device Binding |
| CVE-2026-25292 | 7.6 | 1.0 | Qualcomm, Inc. | Snapdragon | CWE-1286 | Improper Validation of Syntactic Correctness of Input in Automotive Linux OS |
| CVE-2026-18806 | 7.1 | 1.0 | TÜBİTAK BİLGEM Software Technologies Research Institute | pardus-image-writer | CWE-73 | Arbitrary Block Device Write via Missing Validation in TÜBİTAK BİLGEM's pardu… |
| CVE-2026-25288 | 7.4 | 0.9 | Qualcomm, Inc. | Snapdragon | CWE-126 | Buffer Over-read in WLAN Firmware |
| CVE-2026-68743 | 7.1 | 0.7 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length … |
| CVE-2026-68744 | 3.3 | 0.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-908 | Sssd: sssd: nss responder uninitialized heap disclosure in initgroups reply |
| CVE-2026-16791 | 1.0 | 0.4 | Lenovo | XClarity Essentials OneCLI | CWE-377 | Predictable Temporary File Symlink Vulnerability in Lenovo XClarity Essential… |
| CVE-2026-16792 | 7.0 | 0.1 | Lenovo | XClarity Orchestrator | CWE-295 | Global TLS Certificate Validation Bypass in Lenovo XClarity Orchestrator |
| CVE-2026-24076 | 6.7 | 0.1 | Qualcomm, Inc. | Snapdragon | CWE-120 | Buffer Copy Without Checking Size of Input in Bluetooth HOST |
| CVE-2026-21366 | 7.8 | 0.0 | Qualcomm, Inc. | Snapdragon | CWE-190 | Integer Overflow or Wraparound in Data Network Stack & Connectivity |
| CVE-2026-24080 | 7.8 | 0.0 | Qualcomm, Inc. | Snapdragon | CWE-120 | Buffer Copy Without Checking Size of Input in Biometrics |
| CVE-2026-24083 | 7.8 | 0.0 | Qualcomm, Inc. | Snapdragon | CWE-822 | Untrusted Pointer Dereference in Automotive Security |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-08-04 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.