boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Wednesday, August 5, 2026 · all times UTC← 2026-08-04 · archive · 2026-08-06 →

Security Box Score — August 5, 2026 — page 2

Edition of August 5, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–432 of 432
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-166134.32.8UnknownGDPR Cookie ComplianceCWE-352GDPR Cookie Compliance < 5.1.0 - Cookie Deletion and Forced Logout via CSRF
CVE-2026-712617.82.6mackrondr_libsCWE-190dr_wav.h W64 CUE Chunk Metadata Parsing Integer Overflow Leading to Heap Buff…
CVE-2026-712667.82.6syoyotinyobjloader-cCWE-121tinyobjloader-c Stack Buffer Overflow in MTL Material File Line Parsing
CVE-2026-190248.22.5The HDF GroupHDF5CWE-476HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message
CVE-2026-190276.92.4The HDF GroupHDF5CWE-125HDF5 out-of-bounds heap read in N-Bit filter decompression
CVE-2026-190266.82.4The HDF GroupHDF5CWE-476Nbit filter NULL/short parameter-array dereference
CVE-2026-190286.82.4The HDF GroupHDF5CWE-125HDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds read
CVE-2026-645747.82.1LinuxLinux—wifi: mac80211: tear down new links on vif update error path
CVE-2026-645757.82.1LinuxLinux—bpf: tcp: fix double sock release on batch realloc
CVE-2026-704354.22.1Jenkins ProjectJenkins SCM-Manager PluginCWE-862A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier a…
CVE-2026-645677.82.0LinuxLinux—btrfs: reject free space cache with more entries than pages
CVE-2026-645687.82.0LinuxLinux—wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure
CVE-2026-645807.82.0LinuxLinux—xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()
CVE-2026-712598.61.9esphomeesphomeCWE-184ESPHome external_components file:// Scheme Validation Bypass Leading to Remot…
CVE-2026-645767.11.8LinuxLinux—nexthop: initialize extack in nh_res_bucket_migrate()
CVE-2026-190236.81.9The HDF GroupHDF5CWE-822HDF5 h5dump Untrusted Pointer Dereference in Binary Output of Variable-Length…
CVE-2026-190256.81.9The HDF GroupHDF5CWE-369HDF5 divide-by-zero (SIGFPE) via mismatched chunk-layout dimensionality and d…
CVE-2026-712736.51.8openshwprojectsOpenBK7231T_AppCWE-352OpenBK7231T CSRF in /cfg_wifi_set Leading to Implicit Web Password Disable an…
CVE-2026-663445.41.8Integrated Systems Technologies, Inc.NetKids iMarkCWE-427NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an…
CVE-2026-156564.31.8IBMMaximo Application SuiteCWE-614IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerab…
CVE-2026-184858.51.6NINI-PALCWE-1285Local Privilege Escalation in NI-PAL
CVE-2026-645817.81.5LinuxLinux—xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
CVE-2026-175154.31.5UnknownMLSImport: IDX Plugin & MLS Plugin for Real Estate ListingsCWE-200MLS Import < 7.0.4 - Subscriber+ Sensitive Information Disclosure via mlsimpo…
CVE-2026-84709.11.4IBMLangflow OSSCWE-327Langflow is affected by weaknesses in secret handling and sensitive configura…
CVE-2026-712124.41.5indravoyagerxidownCWE-88xidown - Argument Injection via Unterminated yt-dlp Command Line Construction
CVE-2026-189545.71.3AWSdocumentdb-mcp-serverCWE-863Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs D…
CVE-2026-705976.31.2electronelectronCWE-367Electron: Parent process code-sign check is spoofable
CVE-2026-127303.81.1IBMBusiness Automation Workflow containers and traditionalCWE-297Improper Validation of Certificate with Host Mismatch in IBM Business Automat…
CVE-2026-706036.00.9electronelectronCWE-20Electron: shell.openPath path validation bypass via embedded null byte
CVE-2026-704344.20.4Jenkins ProjectJenkins SCM-Manager PluginCWE-352A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plug…
CVE-2026-188392.20.3rpm-software-managementpoptCWE-191Popt-devel: popt-static: size_t underflow in singleoptionhelp
CVE-2026-559978.80.2rancherrancherCWE-312Long-lived Rancher registration token exposed in plaintext