Security Box Score — August 5, 2026 — page 2
Edition of August 5, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-16613 | 4.3 | 2.8 | Unknown | GDPR Cookie Compliance | CWE-352 | GDPR Cookie Compliance < 5.1.0 - Cookie Deletion and Forced Logout via CSRF |
| CVE-2026-71261 | 7.8 | 2.6 | mackron | dr_libs | CWE-190 | dr_wav.h W64 CUE Chunk Metadata Parsing Integer Overflow Leading to Heap Buff… |
| CVE-2026-71266 | 7.8 | 2.6 | syoyo | tinyobjloader-c | CWE-121 | tinyobjloader-c Stack Buffer Overflow in MTL Material File Line Parsing |
| CVE-2026-19024 | 8.2 | 2.5 | The HDF Group | HDF5 | CWE-476 | HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message |
| CVE-2026-19027 | 6.9 | 2.4 | The HDF Group | HDF5 | CWE-125 | HDF5 out-of-bounds heap read in N-Bit filter decompression |
| CVE-2026-19026 | 6.8 | 2.4 | The HDF Group | HDF5 | CWE-476 | Nbit filter NULL/short parameter-array dereference |
| CVE-2026-19028 | 6.8 | 2.4 | The HDF Group | HDF5 | CWE-125 | HDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds read |
| CVE-2026-64574 | 7.8 | 2.1 | Linux | Linux | — | wifi: mac80211: tear down new links on vif update error path |
| CVE-2026-64575 | 7.8 | 2.1 | Linux | Linux | — | bpf: tcp: fix double sock release on batch realloc |
| CVE-2026-70435 | 4.2 | 2.1 | Jenkins Project | Jenkins SCM-Manager Plugin | CWE-862 | A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier a… |
| CVE-2026-64567 | 7.8 | 2.0 | Linux | Linux | — | btrfs: reject free space cache with more entries than pages |
| CVE-2026-64568 | 7.8 | 2.0 | Linux | Linux | — | wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure |
| CVE-2026-64580 | 7.8 | 2.0 | Linux | Linux | — | xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() |
| CVE-2026-71259 | 8.6 | 1.9 | esphome | esphome | CWE-184 | ESPHome external_components file:// Scheme Validation Bypass Leading to Remot… |
| CVE-2026-64576 | 7.1 | 1.8 | Linux | Linux | — | nexthop: initialize extack in nh_res_bucket_migrate() |
| CVE-2026-19023 | 6.8 | 1.9 | The HDF Group | HDF5 | CWE-822 | HDF5 h5dump Untrusted Pointer Dereference in Binary Output of Variable-Length… |
| CVE-2026-19025 | 6.8 | 1.9 | The HDF Group | HDF5 | CWE-369 | HDF5 divide-by-zero (SIGFPE) via mismatched chunk-layout dimensionality and d… |
| CVE-2026-71273 | 6.5 | 1.8 | openshwprojects | OpenBK7231T_App | CWE-352 | OpenBK7231T CSRF in /cfg_wifi_set Leading to Implicit Web Password Disable an… |
| CVE-2026-66344 | 5.4 | 1.8 | Integrated Systems Technologies, Inc. | NetKids iMark | CWE-427 | NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an… |
| CVE-2026-15656 | 4.3 | 1.8 | IBM | Maximo Application Suite | CWE-614 | IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerab… |
| CVE-2026-18485 | 8.5 | 1.6 | NI | NI-PAL | CWE-1285 | Local Privilege Escalation in NI-PAL |
| CVE-2026-64581 | 7.8 | 1.5 | Linux | Linux | — | xfrm: fix sk_dst_cache double-free in xfrm_user_policy() |
| CVE-2026-17515 | 4.3 | 1.5 | Unknown | MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings | CWE-200 | MLS Import < 7.0.4 - Subscriber+ Sensitive Information Disclosure via mlsimpo… |
| CVE-2026-8470 | 9.1 | 1.4 | IBM | Langflow OSS | CWE-327 | Langflow is affected by weaknesses in secret handling and sensitive configura… |
| CVE-2026-71212 | 4.4 | 1.5 | indravoyager | xidown | CWE-88 | xidown - Argument Injection via Unterminated yt-dlp Command Line Construction |
| CVE-2026-18954 | 5.7 | 1.3 | AWS | documentdb-mcp-server | CWE-863 | Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs D… |
| CVE-2026-70597 | 6.3 | 1.2 | electron | electron | CWE-367 | Electron: Parent process code-sign check is spoofable |
| CVE-2026-12730 | 3.8 | 1.1 | IBM | Business Automation Workflow containers and traditional | CWE-297 | Improper Validation of Certificate with Host Mismatch in IBM Business Automat… |
| CVE-2026-70603 | 6.0 | 0.9 | electron | electron | CWE-20 | Electron: shell.openPath path validation bypass via embedded null byte |
| CVE-2026-70434 | 4.2 | 0.4 | Jenkins Project | Jenkins SCM-Manager Plugin | CWE-352 | A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plug… |
| CVE-2026-18839 | 2.2 | 0.3 | rpm-software-management | popt | CWE-191 | Popt-devel: popt-static: size_t underflow in singleoptionhelp |
| CVE-2026-55997 | 8.8 | 0.2 | rancher | rancher | CWE-312 | Long-lived Rancher registration token exposed in plaintext |