boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Thursday, August 6, 2026 · all times UTC← 2026-08-05 · archive · 2026-08-07 →

Security Box Score — August 6, 2026

482 CVEs published, led by Google (41).

482 CVEs published August 6, 2026: 87 critical, 187 high, 145 medium, 51 low; 1 in the KEV catalog at press time; 5 with a public exploit reference; 12 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 82 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published169323857——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

1264 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux442359210125463711120.17.8.0016+7 ▲
google431804222743783567760.37.5.0025-9 ▼
microsoft33145512199132914286241.67.8.0047-17 ▼
red hat374232016421029200.06.5.0029+18 ▲
apple1272587813338872.66.8.0027+1 ▲
canonical02738115000.05.6.00140
suse52651461000.08.1.00390
freebsd01601240000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco23611329190561219.77.5.0042+15 ▲
ubiquiti036142110338.38.8.0049-25 ▼
palo alto networks025131471328.04.7.00280
fortinet0236611028626.17.2.00400
netgear02300221000.04.6.00240
vmware0174922715.98.3.00400
f50165830416.38.6.00570
checkpoint11346303215.47.8.0436+1 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache5839475175131123320.57.5.0051+14 ▲
mozilla11285142350900.08.1.0031-2 ▼
drupal05165355412.05.9.00260
gitlab05107377423.94.9.00290
github2141490000.06.2.0043+1 ▲
docker070520000.08.2.00160
wordpress0311102266.78.6.79790
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle01379343653322612730.28.1.00360
ibm3226172104841610.47.5.0031+32 ▲
adobe72593311710541931.27.8.0026+5 ▲
progress1052133270600.08.1.0037+8 ▲
solarwinds0231733010417.49.1.00580
veeam10165920100.08.6.0034+10 ▲
zohocorp062220000.07.8.01460
atlassian0303001300.08.0.00260
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology12426133000.05.6.0025+1 ▲
rockwell automation02441820000.08.7.00290
d-link0200596300.05.5.01050
siemens0161870000.07.6.00240
schneider electric091620000.08.6.00370
abb070430000.07.2.00180
hikvision060420000.07.2.00400
moxa050320000.07.0.00290
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester4124006658000.05.4.0033-23 ▼
openclaw01110583914000.07.0.00260
dell6105850443211.07.2.0021-14 ▼
nvidia16981366190000.07.7.0034-1 ▼
capgo083242381000.07.1.00370
spring079234412000.06.5.00220
imagemagick078156012000.05.3.0018-8 ▼
itsourcecode677001958000.02.1.0033-4 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-34486.986299.97.5
CVE-2026-63030.977999.99.8
CVE-2026-16232.891299.89.3
CVE-2026-63077.847399.79.8
CVE-2026-50522.846199.79.8
CVE-2026-15409.836699.710.0
CVE-2026-60137.797999.65.9
CVE-2026-6875.775899.59.5
CVE-2026-25089.761199.59.8
CVE-2026-0770.634299.19.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1540910.0.8366KEV
CVE-2026-4893910.0.1973KEV
CVE-2026-5629110.0.1459KEV
CVE-2026-5972610.0.0688
CVE-2026-898510.0.0660
CVE-2026-651610.0.0486
CVE-2026-4766810.0.0388
CVE-2026-4633910.0.0335
CVE-2026-6144710.0.0249
CVE-2026-5782710.0.0233
Most disclosures (vendor)
VendorCVEs
oracle1109
linux842
microsoft648
google487
apache189
red hat174
apple168
ibm137
adobe112
mozilla69
Most KEV additions (YTD)
VendorKEV
microsoft24
cisco12
apple7
fortinet6
google6
ivanti5
solarwinds4
adobe3
berriai3
oracle3
Most-affected ecosystems
EcosystemAdvisories
Maven67
PyPI5
Go3
npm3
Packagist2
crates.io2
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2021-27137DD-WRT0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20316Cisco0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171723
CVE-2021-27102n/a2021-11-171723
CVE-2021-27101n/a2021-11-171723
CVE-2021-27103n/a2021-11-171723
CVE-2021-21017Adobe2021-11-171723
CVE-2021-28550Adobe2021-11-171723
CVE-2021-42013Apache Software Foundation2021-11-171723
CVE-2021-41773Apache Software Foundation2021-11-171723
CVE-2021-30858Apple2021-11-171723
CVE-2021-30860Apple2021-11-171723

Transactions

EXPLOIT PUBLISHED — patriksimek vm2: 11 CVEs (CVE-2026-43997, CVE-2026-43998, CVE-2026-43999, CVE-2026-44001, CVE-2026-44004, CVE-2026-44005, CVE-2026-44006, CVE-2026-44007, CVE-2026-44008, CVE-2026-44009, CVE-2026-45411). Public exploit references added.

EXPLOIT PUBLISHED — zephyrproject zephyr: 8 CVEs (CVE-2026-7656, CVE-2026-10634, CVE-2026-10639, CVE-2026-10646, CVE-2026-10647, CVE-2026-10652, CVE-2026-10653, CVE-2026-10670). Public exploit references added.

EXPLOIT PUBLISHED — koxudaxi datamodel-code-generator: 4 CVEs (CVE-2026-54656, CVE-2026-54690, CVE-2026-55389, CVE-2026-55415). Public exploit references added.

EXPLOIT PUBLISHED — ueberauth guardian: 4 CVEs (CVE-2026-54894, CVE-2026-55733, CVE-2026-55734, CVE-2026-55735). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2012-4681. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2019-15107. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2021-22205 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2021-43890 (Microsoft App Installer). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2022-30190 (Microsoft Windows 10 Version 1809). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2022-40684 (Fortinet FortiOS, FortiProxy, FortiSwitchManager). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-42753 (Red Hat Enterprise Linux 7). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-12605 (Eclipse Foundation Eclipse GlassFish). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16746 (Unknown MultiVendorX). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16940 (Unknown Custom Fields). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16981 (Unknown DHL Shipping Germany for WooCommerce). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-18958 (imranrisal-dev Student-Management-System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-18959 (yushine InnoShop). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-44210 (kata-containers). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-47429 (vitest-dev vitest). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-64827 (Telenia Software TVox). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-64828 (Froiden TableTrack). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-67623 (mistralai mistral-vibe). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-69111 (milvus-io milvus). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-70615 (boringproxy). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-70616 (boringproxy). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-8037 (Progress Software LoadMaster). Public exploit reference added.

RESCORED — zephyrproject zephyr: 5 CVEs (CVE-2026-7656, CVE-2026-10634, CVE-2026-10643, CVE-2026-10652, CVE-2026-10653). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2023-42753 (Red Hat Enterprise Linux 7). CVSS 7 → 7.8 (NVD).

RESCORED — CVE-2023-5090 (Red Hat Enterprise Linux 8). CVSS 6 → 5.5 (NVD).

RESCORED — CVE-2024-0646 (kernel). CVSS 7 → 7.8 (NVD).

RESCORED — CVE-2024-1488 (unbound). CVSS 8 → 7.3 (NVD).

RESCORED — CVE-2024-21549 (spatie/browsershot). CVSS 7.7 → 6.6 (NVD).

RESCORED — CVE-2026-11714 (IBM WebSphere Application Server - Liberty). CVSS 8.5 → 9.8 (NVD).

RESCORED — CVE-2026-16108 (Red Hat Build of Keycloak). CVSS 4.3 → 6.5 (NVD).

RESCORED — CVE-2026-18968 (ttttonyhe OBlog). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-18969 (Rongzhitong Visual Integrated Command and Dispatch Platform). CVSS 6.9 → 5.5 (NVD).

RESCORED — CVE-2026-18970 (Rongzhitong Visual Integrated Command and Dispatch Platform). CVSS 6.9 → 5.5 (NVD).

RESCORED — CVE-2026-47429 (vitest-dev vitest). CVSS 9.8 → 5.9 (NVD).

Yesterday's Results

How to read these box scores · glossary

482 CVEs published. 25 box scores and 375 table rows below; the remaining 82 continue on page 2 — every CVE is listed, nothing truncated.

Apple macOS — An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .1043   95.4   YES
AFFECTED
  Product  Versions     Fixed
  macOS    unspecified  —
TIMELINE
  Jul 22  Reserved by CNA
  Aug 6   Published (CNA: apple)
  Aug 18  Added to CISA KEV, due Aug 21
CWE-287 · CNA: apple · CVSS v3.1 · 7 references · NVD status: Analyzed · KEV due August 21, 2026
WGDashboard Remote Code Execution vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .1354   96.2     —
AFFECTED
  Product      Versions     Fixed
  WGDashboard  unspecified  —
TIMELINE
  Jul 14  Reserved by CNA
  Aug 6   Published (CNA: certcc)
CWE-78 · CNA: certcc · CVSS v3.1 · 2 references · NVD status: Received
Shibby Tomato qoslimittc_stop.sh new_qoslimit_stop os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    7.3   .0204   79.7     —
AFFECTED
  Product  Versions     Fixed
  Tomato   1.28.0000 –  —
TIMELINE
  Aug 6   Reserved by CNA
  Aug 6   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Shibby Tomato qoslimit new_qoslimit_start os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    7.3   .0204   79.7     —
AFFECTED
  Product  Versions     Fixed
  Tomato   1.28.0000 –  —
TIMELINE
  Aug 6   Reserved by CNA
  Aug 6   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Shibby Tomato wanoptions sub_40F88C os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    7.3   .0204   79.7     —
AFFECTED
  Product  Versions     Fixed
  Tomato   1.28.0000 –  —
TIMELINE
  Aug 6   Reserved by CNA
  Aug 6   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Bohdan Triapitsyn OpenChamber — OpenChamber 1.11.7 Path Traversal File Read via allowOutsideWorkspace Parameter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   N    9.3   .0190   78.1     —
AFFECTED
  Product      Versions     Fixed
  OpenChamber  unspecified  —
TIMELINE
  Jun 11  Reserved by CNA
  Aug 6   Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Co…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0160   73.9     —
AFFECTED
  Product                                               Versions     Fixed
  Virtual Storage Integrator for VMware vSphere Client  unspecified  —
TIMELINE
  Jul 29  Reserved by CNA
  Aug 6   Published (CNA: dell)
CWE-78 · CNA: dell · CVSS v3.1 · 1 reference · NVD status: Analyzed
nearai ironclaw shell.rs classify_command_risk command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0133   68.8     —
AFFECTED
  Product   Versions  Fixed
  ironclaw  0.29.0 –  —
TIMELINE
  Aug 5   Reserved by CNA
  Aug 6   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 13 references · NVD status: Deferred
MissionSquad mcp-api NPM Package Version packages.ts this.packageService.installPackage command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0125   67.0     —
AFFECTED
  Product  Versions  Fixed
  mcp-api  1.11.0 –  1.11.9
TIMELINE
  Aug 6   Reserved by CNA
  Aug 6   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Deferred
Microsoft Azure Service Bus — Azure Service Bus Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0110   63.1     —
AFFECTED
  Product            Versions  Fixed
  Azure Service Bus  - –       —
TIMELINE
  Jun 4   Reserved by CNA
  Aug 6   Published (CNA: microsoft)
CWE-502 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Bohdan Triapitsyn OpenChamber — OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/exec
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0108   62.7     —
AFFECTED
  Product      Versions     Fixed
  OpenChamber  unspecified  —
TIMELINE
  Jun 11  Reserved by CNA
  Aug 6   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
n/a OpenHands — OpenHands send_pull_request.py initialize_repo command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    5.3   .0107   62.2     —
AFFECTED
  Product    Versions  Fixed
  OpenHands  0.1 –     —
TIMELINE
  Aug 5   Reserved by CNA
  Aug 6   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Eukaryot sonic3air — Sonic 3 A.I.R. Unbounded Memory Allocation DoS via ReceivedPacketCache
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0089   56.6     —
AFFECTED
  Product    Versions     Fixed
  sonic3air  unspecified  2492d1882cd2cf1cc1d7415729ce5c4fd686cd4f
TIMELINE
  Jul 27  Reserved by CNA
  Aug 6   Published (CNA: VulnCheck)
CWE-789 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0077   52.7     —
AFFECTED
  Product                               Versions  Fixed
  Microsoft Entra Provisioning Service  - –       —
TIMELINE
  Jul 2   Reserved by CNA
  Aug 6   Published (CNA: microsoft)
CWE-35 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Red Hat Red Hat Enterprise Linux 10 — Gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0076   52.4     —
AFFECTED
  Product                      Versions     Fixed
  Red Hat Enterprise Linux 10  unspecified  0:1.26.7-2.el10_2.3
  Red Hat Enterprise Linux 8   unspecified  0:1.16.1-7.el8_10.3
  Red Hat Enterprise Linux 9   unspecified  0:1.22.12-7.el9_8.2
  Red Hat Enterprise Linux 7   unspecified  —
TIMELINE
  Aug 3   Reserved by CNA
  Aug 6   Published (CNA: redhat)
CWE-770 · CNA: redhat · CVSS v3.1 · 7 references · NVD status: Awaiting Analysis
ankitects anki — Anki's local HTTP server is vulnerable to directory traversal attacks
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   A   H   N   N    5.9   .0076   52.4     —
AFFECTED
  Product  Versions      Fixed
  anki     >= 25.09.3 –  —
TIMELINE
  Jul 20  Reserved by CNA
  Aug 6   Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · CVSS v4.0 · 2 references · NVD status: Received
Microsoft Application Insights Profiler — Application Insights Profiler Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0075   52.2     —
AFFECTED
  Product                        Versions  Fixed
  Application Insights Profiler  - –       —
TIMELINE
  May 27  Reserved by CNA
  Aug 6   Published (CNA: microsoft)
CWE-22 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
cli cli — GitHub CLI: Terminal escape sequence injection in multiple `gh` commands
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   N   N    5.3   .0073   51.4     —
AFFECTED
  Product  Versions    Fixed
  cli      < 2.97.0 –  —
TIMELINE
  Jul 20  Reserved by CNA
  Aug 6   Published (CNA: GitHub_M)
CWE-150 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Received
PHPCSStandards PHP_CodeSniffer — PHP_CodeSniffer gitblame report command injection via crafted filename
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   P   N   P   H   H   H    7.3   .0070   50.5     —
AFFECTED
  Product          Versions    Fixed
  PHP_CodeSniffer  < 3.13.6 –  —
TIMELINE
  Jul 29  Reserved by CNA
  Aug 6   Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v4.0 · 6 references · NVD status: Received
LeeSinLiang godot-mcp create_scene/add_node index.ts executeOperation command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    1.9   .0070   50.2     —
AFFECTED
  Product    Versions  Fixed
  godot-mcp  0.1.0 –   —
TIMELINE
  Aug 6   Reserved by CNA
  Aug 6   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
n/a n/a — In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0069   50.0     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 21  Reserved by CNA
  Aug 6   Published (CNA: mitre)
CWE-79 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Received
n/a n/a — SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `f…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0069   49.8     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jul 30  Reserved by CNA
  Aug 6   Published (CNA: mitre)
CWE-89 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Received
NocteDefensor LudusMCP ludus_cli_execute cliWrapper.ts executeCommand command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    1.9   .0068   49.7     —
AFFECTED
  Product   Versions  Fixed
  LudusMCP  1.0.0 –   —
TIMELINE
  Aug 6   Reserved by CNA
  Aug 6   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
WGDashboard Server-Side Template Injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0068   49.5     —
AFFECTED
  Product      Versions     Fixed
  WGDashboard  unspecified  —
TIMELINE
  Jul 14  Reserved by CNA
  Aug 6   Published (CNA: certcc)
CWE-1336 · CNA: certcc · CVSS v3.1 · 2 references · NVD status: Received
Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0067   49.1     —
AFFECTED
  Product     Versions  Fixed
  Apache CXF  4.2.0 –   —
TIMELINE
  Jul 28  Reserved by CNA
  Aug 6   Published (CNA: apache)
CWE-502 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Modified
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-5616210.049.0MicrosoftAzure SQL DatabaseCWE-287Azure SQL Database Elevation of Privilege Vulnerability
CVE-2026-703329.647.5MicrosoftMicrosoft SharePoint OnlineCWE-79Microsoft Office SharePoint Spoofing Vulnerability
CVE-2026-190451.947.1NocteDefensorLudusMCPCWE-74NocteDefensor LudusMCP get_credential_from_user secretDialog.ts SecretDialog.…
CVE-2026-6566710.047.0MicrosoftMicrosoft TeamsCWE-862Microsoft Teams Elevation of Privilege Vulnerability
CVE-2026-436299.246.9ggml-orgllama.cppCWE-787llama.cpp b4882–b9058 Buffer Overflow in KV Cache State Restore
CVE-2026-501595.346.5mermaid-jsmermaidCWE-94Mermaid allows CSS injection applying to sibling elements of the diagram
CVE-2026-688239.146.2MicrosoftAzure Confidential LedgerCWE-749Azure Confidential Ledger Remote Code Execution Vulnerability
CVE-2026-705589.345.8DataLinkDCDinkyCWE-434Dinky Unauthenticated Arbitrary File Write via /download/uploadFromRsByLocal …
CVE-2026-159918.845.5bitpressadminFile ManagerCWE-862File Manager 6.0 - 6.9 - Missing Authorization to Authenticated (Subscriber+)…
CVE-2026-676889.845.4n/an/aCWE-434ICS-Park Smart Park Management System v2.0 contains an unrestricted file uplo…
CVE-2026-714768.745.2nrwlnxCWE-22Nx: Zip-Slip in the self-hosted remote cache
CVE-2026-674227.545.2facelessuserpymdown-extensionsCWE-1333pymdown-extensions: Exponential-backtracking ReDoS in caret, tilde, betterem,…
CVE-2026-34189.144.7WSO2WSO2 API ManagerCWE-434Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Re…
CVE-2026-1481210.044.5UnknownPremium SEOCWE-912Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content…
CVE-2026-504819.944.2MicrosoftAzure Active DirectoryCWE-471Azure Active Directory Elevation of Privilege Vulnerability
CVE-2026-480859.843.7open-receptionappointment-booking-softwareCWE-862OpenReception has unauthenticated GLOBAL_ADMIN account creation post-bootstrap
CVE-2026-713247.043.6traefiktraefikCWE-444Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's share…
CVE-2026-191508.842.9GoogleChromeCWE-693Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 a…
CVE-2026-191518.842.9GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remot…
CVE-2026-191688.842.9GoogleChromeCWE-693Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 a…
CVE-2026-58579.242.8Contiki-NGContiki-NGCWE-787Contiki-NG MQTT Client Out-of-Bounds Write in PUBLISH Topic Parser via Persis…
CVE-2026-58558.742.8Contiki-NGContiki-NGCWE-125Contiki-NG LwM2M TLV Parser Out-of-Bounds Read via Unchecked Buffer Length in…
CVE-2026-6350810.042.7MicrosoftMicrosoft Planetary Computer Pro (GeoCatalog)CWE-306Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability
CVE-2026-628739.842.3MicrosoftMicrosoft 365 Admin CenterCWE-347Microsoft 365 Admin Center Elevation of Privilege Vulnerability
CVE-2026-539778.741.9Bohdan TriapitsynOpenChamberCWE-306OpenChamber 1.11.7 Unauthenticated DoS via /api/system/shutdown
CVE-2026-628309.941.5MicrosoftAzure SRE AgentCWE-862Azure SRE Agent Elevation of Privilege Vulnerability
CVE-2026-656688.841.5MicrosoftMicrosoft Purview eDiscoveryCWE-284Microsoft Purview eDiscovery Elevation of Privilege Vulnerability
CVE-2026-154598.141.2wpmudevWPMU DEV DashboardCWE-287WPMU DEV Dashboard <= 5.0.0 - Authentication Bypass to Arbitrary Plugin Insta…
CVE-2026-345017.541.1Apache Software FoundationApache Portable Runtime UtilityCWE-122Apache Portable Runtime Utility: Heap buffer overflow in APR redis client
CVE-2026-345027.541.1Apache Software FoundationApache Portable Runtime UtilityCWE-122Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client
CVE-2026-706337.141.0timescaletimescaledbCWE-191TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Gorilla Compression Reverse Ite…
CVE-2026-191767.540.9GoogleChromeCWE-416Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a rem…
CVE-2026-668292.340.5rrrenehtml_sanitize_exCWE-601html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowin…
CVE-2026-646535.140.4clicliCWE-22GitHub CLI: Unescaped variable components in request URLs could allow path tr…
CVE-2026-191499.640.1GoogleChromeCWE-416Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allo…
CVE-2026-189915.540.1nanocoaiNanoClawCWE-22nanocoai NanoClaw send_file core.ts path traversal
CVE-2026-1197610.039.7UnknownMonsterInsights ProCWE-912MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise
CVE-2026-591189.339.3MicrosoftCopilot CoworkCWE-285Copilot Cowork Elevation of Privilege Vulnerability
CVE-2026-628969.638.6MicrosoftMicrosoft TeamsCWE-287Microsoft Teams Elevation of Privilege Vulnerability
CVE-2026-667099.138.5WebAppickCTX FeedCWE-94WordPress CTX Feed plugin <= 6.6.42 - Remote Code Execution (RCE) vulnerability
CVE-2026-542257.538.3Apache Software FoundationApache CXFCWE-770Apache CXF: Denial of Service attack via large attachments
CVE-2026-578197.538.3Apache Software FoundationApache CXFCWE-400Apache CXF: No default restriction on the amount of form parameters per message
CVE-2026-544899.838.3DellVirtual Storage Integrator for VMware vSphere ClientCWE-200Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to …
CVE-2026-687508.238.3rrrenehtml_sanitize_exCWE-407Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allo…
CVE-2026-6555310.038.2wbolt.comSpider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件CWE-94WordPress Spider Analyser – WordPress搜索引擎蜘蛛分析插件 plugin <= 2.1.3 - Remote Code…
CVE-2026-561619.638.0MicrosoftAzure Logic AppsCWE-284Azure Logic Apps Information Disclosure Vulnerability
CVE-2026-323279.137.8Apache Software FoundationApache Portable Runtime UtilityCWE-674Apache Portable Runtime Utility: apr-util XML stack recursion crash
CVE-2026-184277.537.7@fastify/static@fastify/staticCWE-22@fastify/static vulnerable to route guard bypass via non-canonical path segments
CVE-2026-480879.837.7open-receptionappointment-booking-softwareCWE-287OpenReception: WebAuthn passkey injection allows account takeover
CVE-2026-436306.337.5ggml-orgllama.cppCWE-125llama.cpp b5702–b7653 Out-of-Bounds Read Information Disclosure
CVE-2026-629187.537.4MicrosoftMicrosoft TeamsCWE-347Microsoft Teams Spoofing Vulnerability
CVE-2026-676878.837.2n/an/aCWE-284Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker…
CVE-2026-687498.237.2rrrenehtml_sanitize_exCWE-1333Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-…
CVE-2026-480548.837.1OpenZeppelincontracts-wizardCWE-94OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Fou…
CVE-2026-578178.137.1Apache Software FoundationApache CXFCWE-20Apache CXF: The authorization code hash (c_hash) is not enforced for the hybr…
CVE-2026-191378.337.0GoogleChromeCWE-416Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 a…
CVE-2026-191778.336.8GoogleChromeCWE-20Insufficient validation of untrusted input in UI in Google Chrome prior to 15…
CVE-2026-715545.336.7python-hyperh2CWE-444h2: Duplicate Host header could facilitate request smuggling
CVE-2026-162688.236.3UnknownNewslettersCWE-918Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Boun…
CVE-2026-191748.836.1GoogleChromeCWE-190Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a rem…
CVE-2026-6283610.036.0MicrosoftAzure SQL Managed InstanceCWE-923Azure SQL Managed Instance Elevation of Privilege Vulnerability
CVE-2026-191587.536.0GoogleChromeCWE-416Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 a…
CVE-2026-477657.135.7frappefrappeCWE-862Frappe: Lack of Permissions in restore/bulk_restore
CVE-2026-714395.335.6mermaid-jsmermaidCWE-606Mermaid radar diagrams are vulnerable to DoS
CVE-2026-655489.935.3MuffingroupBethemeCWE-94WordPress Betheme theme <= 28.4.2 - Remote Code Execution (RCE) vulnerability
CVE-2026-684817.535.3Apache Software FoundationApache CXFCWE-672Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider
CVE-2026-191669.635.1GoogleChromeCWE-416Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109…
CVE-2026-614669.135.1Apache Software FoundationApache CXFCWE-304Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation
CVE-2026-715025.135.1mispcti-transmuteCWE-79Unauthenticated Stored Vue Template Injection Leads to Cross-Site Scripting i…
CVE-2026-436319.234.8ggml-orgllama.cppCWE-416llama.cpp b7492–b9060 Use-After-Free RCE via llama-server
CVE-2026-191458.834.6GoogleChromeCWE-416Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed …
CVE-2026-191628.834.6GoogleChromeCWE-787Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a …
CVE-2026-191418.334.4GoogleChromeCWE-416Use after free in Resources in Google Chrome on Android prior to 151.0.7922.1…
CVE-2026-191427.534.4GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a re…
CVE-2026-191597.534.4GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a re…
CVE-2026-190115.534.4n/aTinyAGICWE-73TinyAGI agents.ts buildSystemPrompt file inclusion
CVE-2026-655529.834.2qstudioExport User DataCWE-502WordPress Export User Data plugin <= 2.2.6 - PHP Object Injection vulnerability
CVE-2026-706347.234.2timescaletimescaledbCWE-129TimescaleDB 2.29.1 Out-of-Bounds Read Information Disclosure via Dictionary C…
CVE-2026-654327.533.7Apache Software FoundationApache CXFCWE-611Apache CXF: XXE via WSDL/XSD import parsing
CVE-2026-714365.333.6mermaid-jsmermaidCWE-835Mermaid XY Charts are vulnerable to an infinite loop DoS
CVE-2026-649587.533.4Apache Software FoundationApache CXFCWE-400Apache CXF: Denial of service via message header attachments
CVE-2025-150399.433.3WSO2WSO2 Identity ServerCWE-693Account Takeover via Conditional Authentication Script Logic in Multiple WSO2…
CVE-2026-655437.532.6vimeodevVimeoCWE-201WordPress Vimeo plugin <= 1.2.2 - Sensitive Data Exposure vulnerability
CVE-2026-189905.532.5letta-aiLettaBotCWE-287letta-ai LettaBot API Status Route server.ts missing authentication
CVE-2026-680799.832.4Apache Software FoundationApache CXFCWE-294Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization …
CVE-2026-454156.032.5decidimdecidimCWE-862Decidim: CSV census record endpoints improper authorization
CVE-2026-53366.832.3UnknownDataPress (Dataverse Integration)CWE-200Dataverse Integration < 2.91 - Contributor+ Server-Side Template Injection (S…
CVE-2026-471855.132.1frappefrappeCWE-79Frappe Has Broken Access Control in its Workspace Save API
CVE-2026-480756.531.9open-receptionappointment-booking-softwareCWE-862OpenReception's unauthenticated add-to-tunnel endpoint accepts arbitrary appo…
CVE-2026-190095.531.8n/aTinyAGICWE-73TinyAGI Message API Endpoint response.ts collectFiles file inclusion
CVE-2025-145619.031.3WSO2WSO2 API ManagerCWE-284Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allow…
CVE-2026-480797.431.3open-receptionappointment-booking-softwareCWE-613OpenReception's logout page clears local access_token before server-side revo…
CVE-2026-191579.631.1GoogleChromeCWE-787Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.…
CVE-2026-191709.631.1GoogleChromeCWE-416Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 a…
CVE-2026-191603.131.1GoogleChromeCWE-457Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a …
CVE-2026-157329.830.9WGDashboardWGDashboardCWE-918WGDashboard Server-Side Request Forgery Vulnerability
CVE-2026-539848.830.8Efstratios GoudelisGround StationCWE-306Ground Station prior to 0.6.0 Unauthenticated Database Wipe and Arbitrary Dat…
CVE-2026-539858.730.8Efstratios GoudelisGround StationCWE-306Ground Station prior to 0.6.0 Unauthenticated DoS via service_control Socket.IO
CVE-2025-495067.530.7Apache Software FoundationApache Portable Runtime UtilityCWE-208Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing…
CVE-2026-480715.830.7open-receptionappointment-booking-softwareCWE-307OpenReception's client PIN challenge throttle is keyed by emailHash only, all…
CVE-2026-281399.830.2wpdreamsAjax Search LiteCWE-502WordPress Ajax Search Lite plugin <= 4.14.4 - PHP Object Injection vulnerability
CVE-2026-170329.830.1Unknowngoogle-maps-easy-proCWE-912Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server
CVE-2026-706368.730.1FlowiseAIFlowiseCWE-862Flowise 3.1.4 Authentication Bypass via OAuth2 Credential Refresh Endpoint
CVE-2026-191719.630.0GoogleChromeCWE-416Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 a…
CVE-2026-190105.529.9n/aTinyAGICWE-862TinyAGI Message API Endpoint index.ts processMessage authorization
CVE-2026-191118.629.7AWSstrands-agents-toolsCWE-639Insecure direct object reference in Strands Agents Tools memory tool namespac…
CVE-2026-646405.329.7Apache Software FoundationApache PolarisCWE-863Apache Polaris: register endpoint reads attacker-controlled storage location …
CVE-2026-480823.729.7open-receptionappointment-booking-softwareCWE-770OpenReception's bootstrap challenge proof-of-work difficulty hardcoded to 16 …
CVE-2026-191673.129.2GoogleChromeCWE-190Integer overflow in GPU in Google Chrome prior to 151.0.7922.109 allowed a re…
CVE-2026-713277.629.1traefiktraefikCWE-694Traefik: Gateway API route identity collision allows cross-namespace backend …
CVE-2026-714376.529.0mermaid-jsmermaidCWE-1321Mermaid Architecture diagrams are vulnerable to prototype pollution
CVE-2026-480847.428.8open-receptionappointment-booking-softwareCWE-307OpenReception doesn't rate limit passphrase login attempts
CVE-2026-645979.828.6LinuxLinux—smb: client: fix double-free in SMB2_close() replay
CVE-2026-655497.228.6jegthemeJeg Kit for ElementorCWE-502WordPress Jeg Elementor Kit plugin <= 3.2.10 - PHP Object Injection vulnerabi…
CVE-2026-706357.128.6timescaletimescaledbCWE-129TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Bulk Dictionary Decompression N…
CVE-2026-191649.628.4GoogleChromeCWE-20Insufficient validation of untrusted input in Codecs in Google Chrome prior t…
CVE-2026-191759.628.4GoogleChromeCWE-416Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a…
CVE-2026-191448.828.4GoogleChromeCWE-416Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a rem…
CVE-2026-191698.828.4GoogleChromeCWE-20Insufficient validation of untrusted input in Contextual Tasks in Google Chro…
CVE-2026-190645.328.5SourceCodesterOnline Examination & Learning Management SystemCWE-285SourceCodester Online Examination & Learning Management System view.php autho…
CVE-2026-191388.328.4GoogleChromeCWE-122Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.1…
CVE-2026-54238.228.3neo4jgraphqlCWE-302Subscription Authentication Bypass via Unverified connectionParams.jwt
CVE-2026-713262.128.2traefiktraefikCWE-287Traefik: BasicAuth singleflight key collision allows authenticated identity s…
CVE-2026-616325.328.2facelessuserpymdown-extensionsCWE-22PyMdown Extensions: Path traversal in the b64 extension lets <img src> read f…
CVE-2026-191538.127.9GoogleChromeCWE-20Insufficient validation of untrusted input in Workers in Google Chrome prior …
CVE-2026-706467.527.6vovchic17aiosendCWE-400aiosend: Deserialization of request body before signature verification (Pre-a…
CVE-2026-341919.127.5Apache Software FoundationApache Portable Runtime UtilityCWE-89Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
CVE-2026-480836.527.5open-receptionappointment-booking-softwareCWE-117OpenReception: Unauthenticated POST /api/log accepts arbitrary content with C…
CVE-2026-191465.327.5GoogleChromeCWE-457Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 …
CVE-2026-191548.327.3GoogleChromeCWE-416Use after free in Skia in Google Chrome on Android prior to 151.0.7922.109 al…
CVE-2026-191728.327.3GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a re…
CVE-2026-714887.527.1thephpleaguecommonmarkCWE-407league/commonmark: Quadratic-time denial of service when parsing crafted Mark…
CVE-2026-578188.127.0Apache Software FoundationApache CXFCWE-367Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProv…
CVE-2026-493915.126.8frappefrappeCWE-79Frappe: Stored XSS in Column Headers via Data Import
CVE-2026-34158.726.8WSO2WSO2 API ManagerCWE-776XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Pr…
CVE-2026-190082.126.8mf-yangopenclaw-cnCWE-59mf-yang openclaw-cn apply_patch Tool sandbox-paths.ts assertNoSymlinkEscape l…
CVE-2026-705577.126.3dibootdiboot-coreCWE-639diboot-core Authenticated Arbitrary Field Read via loadRelatedData Discloses …
CVE-2026-191528.326.1GoogleChromeCWE-693Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0…
CVE-2026-190382.126.1MonomythDevelopmentla-forge-mcpCWE-22MonomythDevelopment la-forge-mcp screenshot_element Tool index.ts screenshotE…
CVE-2026-480869.925.8open-receptionappointment-booking-softwareCWE-269OpenReception: Tenant admin self-promotes to GLOBAL_ADMIN
CVE-2026-436329.225.3ggml-orgllama.cppCWE-416llama.cpp b7492–b9060 Use-After-Free in Tokenization Endpoints
CVE-2026-705598.725.2DataLinkDCDinkyCWE-306Dinky Unauthenticated System Configuration and Credential Disclosure via GET …
CVE-2026-539839.224.8Efstratios GoudelisGround StationCWE-918Ground Station prior to 0.6.0 Unauthenticated Persistent Blind Server-Side Re…
CVE-2026-454148.524.6decidimdecidimCWE-639Decidim: JWT-backed authentication can be replayed across organizations
CVE-2026-191408.324.6GoogleChromeCWE-416Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remo…
CVE-2026-191478.324.6GoogleChromeCWE-416Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allo…
CVE-2026-191488.324.6GoogleChromeCWE-787Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 …
CVE-2026-191558.324.6GoogleChromeCWE-416Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a…
CVE-2026-191638.324.6GoogleChromeCWE-416Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 a…
CVE-2026-191738.324.6GoogleChromeCWE-787Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed …
CVE-2026-646552.124.7clicliCWE-185GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacter…
CVE-2026-280059.824.4NexcessKadence WooCommerce Email DesignerCWE-862WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19 - Privilege Esc…
CVE-2026-655079.824.4SergeyAIWUCWE-266WordPress AIWU plugin <= 1.5.6 - Privilege Escalation vulnerability
CVE-2026-191613.124.3GoogleChromeCWE-457Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a …
CVE-2026-714458.224.1ail-projectail-frameworkCWE-79Authenticated Reflected Cross-Site Scripting in Tag Error Responses in ail-fr…
CVE-2026-281466.524.1Unlimited ElementsUnlimited Elements For Elementor (Free Widgets, Addons, Templates)CWE-22WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) …
CVE-2026-190692.124.1itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System treatmentrecord.php sql injection
CVE-2026-190702.124.1itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System viewadmin.php sql injection
CVE-2026-190712.124.1itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System viewappointment.php sql injection
CVE-2026-184875.423.6GNOMEEpiphanyCWE-451Epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_ho…
CVE-2026-190625.523.5chiuwingyanhouseCWE-74chiuwingyan house selectall.action sql injection
CVE-2026-646658.123.3statamiccmsCWE-287Statamic: Account takeover via OAuth email matching without email-verificatio…
CVE-2026-189745.523.3heshengtaosuper-agent-partyCWE-200heshengtao super-agent-party execute_tool_manually Endpoint server.py get_fil…
CVE-2026-182588.823.2ScriptaeScriptoriumCWE-639Authorization Bypass Through User-Controlled Key in eScriptorium
CVE-2026-148315.323.2UnknownEasy BookingCWE-602Easy Booking < 3.5.0 - Unauthenticated Minimum Booking Duration Bypass
CVE-2026-455736.423.0decidimdecidimCWE-918Decidim: Push subscriptions can be abused for server-side requests
CVE-2026-655597.222.8tychesoftwaresOrder Delivery Date for WooCommerceCWE-266WordPress Order Delivery Date for WooCommerce plugin <= 4.6.0 - Privilege Esc…
CVE-2026-664707.122.8Shabti KaplanFrontend Admin by DynamiAppsCWE-862WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Broken Access Cont…
CVE-2026-480775.322.8open-receptionappointment-booking-softwareCWE-862OpenReception: GET appointment by ID returns full appointment record without …
CVE-2026-166367.222.6wpmanageninjaFluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, Mailgun, Postmark, Cloudflare, toSend, Gmail and Any SMTPCWE-79FluentSMTP <= 2.2.95 - Unauthenticated Stored Cross-Site Scripting via Recipi…
CVE-2026-655547.122.7lattepressAnsPress – Question and answerCWE-862WordPress AnsPress – Question and answer plugin 4.4.4 - Broken Access Control…
CVE-2026-646626.522.5statamiccmsCWE-639Statamic: Missing authorization on navigation endpoint allows disclosure of r…
CVE-2026-190192.922.5poco-aipoco-agentCWE-459poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_p…
CVE-2026-655569.822.5MihCheWPBruiser {no- Captcha anti-Spam}CWE-502WordPress WPBruiser {no- Captcha anti-Spam} plugin <= 3.1.43 - PHP Object Inj…
CVE-2026-655719.822.5Axiomthemes69 ClothingCWE-502WordPress 69 Clothing theme <= 1.2.11.1 - PHP Object Injection vulnerability
CVE-2026-655729.822.5AxiomthemesA.WilliamsCWE-502WordPress A.Williams theme <= 1.3.1 - PHP Object Injection vulnerability
CVE-2026-655739.822.5ThemeREXAbelleCWE-502WordPress Abelle theme <= 1.22 - PHP Object Injection vulnerability
CVE-2026-655749.822.5AncoraThemesAbogadoCWE-502WordPress Abogado theme <= 1.18 - PHP Object Injection vulnerability
CVE-2026-655759.822.5AncoraThemesAccaliaCWE-502WordPress Accalia theme <= 1.5.3 - PHP Object Injection vulnerability
CVE-2026-655769.822.5AncoraThemesAdrenaCWE-502WordPress Adrena theme <= 1.2.14 - PHP Object Injection vulnerability
CVE-2026-655779.822.5AncoraThemesAdviceCWE-502WordPress Advice theme <= 1.18.0 - PHP Object Injection vulnerability
CVE-2026-655789.822.5AncoraThemesAgoraCWE-502WordPress Agora theme <= 1.9 - PHP Object Injection vulnerability
CVE-2026-655799.822.5axiomthemesAgricolaCWE-502WordPress Agricola theme <= 1.21.0 - PHP Object Injection vulnerability
CVE-2026-655819.822.5AxiomthemesAI ANNCWE-502WordPress AI ANN theme <= 1.29.0 - PHP Object Injection vulnerability
CVE-2026-17289.822.3WSO2WSO2 API ManagerCWE-269Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits A…
CVE-2026-453787.522.3decidimdecidimCWE-200Decidim: Verification documents can be downloaded through reusable links
CVE-2026-189735.521.8heshengtaosuper-agent-partyCWE-918heshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_u…
CVE-2026-646636.521.6statamiccmsCWE-470Statamic: Unsafe method invocation via Antlers template resolution allows dat…
CVE-2026-667108.121.4E2Pdfe2pdfCWE-98WordPress e2pdf plugin <= 1.32.40 - Local File Inclusion vulnerability
CVE-2026-480889.421.3open-receptionappointment-booking-softwareCWE-862OpenReception vulnerable to unauthenticated staff crypto poisoning that break…
CVE-2026-126059.621.2Eclipse FoundationEclipse GlassFishCWE-918In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServ…
CVE-2026-190005.521.0n/aJeecgBootCWE-918JeecgBoot Anonymous Chat Attachment send server-side request forgery
CVE-2026-148425.321.0UnknownEvents Made EasyCWE-639Events Made Easy < 3.1.2 - Unauthenticated Payment Bypass
CVE-2026-668432.320.9rrrenehtml_sanitize_exCWE-829html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, …
CVE-2026-655209.320.8miniOrangeWP OAuth ServerCWE-89WordPress WP OAuth Server plugin <= 6.2.0 - SQL Injection vulnerability
CVE-2026-172645.320.7MedixantRadiAnt DICOMCWE-787Medixant RadiAnt DICOM Out-of-bounds write
CVE-2026-664256.520.6Saad IqbalGutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form BuilderCWE-288WordPress Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Fo…
CVE-2026-191276.520.6GitroomHQpostiz-appCWE-345Insufficient verification of lifetime-deal redemption codes allows forgery of…
CVE-2026-655089.320.2NSquaredSimply Schedule AppointmentsCWE-89WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - SQL Injection vu…
CVE-2026-133997.520.3UnknownPayment Plugins for PayPal WooCommerceCWE-639Payment Plugins for PayPal WooCommerce < 2.0.20 - Unauthenticated Payment Byp…
CVE-2026-6666510.020.1BrandexponentsType HubCWE-434WordPress Type Hub plugin <= 2.0.6 - Arbitrary File Upload vulnerability
CVE-2026-189952.120.1netease-youdaoLobsterAICWE-200netease-youdao LobsterAI MEDIA Path artifactParser.ts parseMediaTokensFromTex…
CVE-2026-480742.719.9open-receptionappointment-booking-softwareCWE-863OpenReception: Staff deletion removes pending invites cross-tenant by email m…
CVE-2026-183257.219.8wpmudevForminator Forms – Contact Form, Payment Form & Custom Form BuilderCWE-79Forminator Forms <= 1.56.1 - Unauthenticated Stored Cross-Site Scripting via …
CVE-2026-281118.819.7WPMU DEVForminatorCWE-266WordPress Forminator plugin <= 1.56.0 - Privilege Escalation vulnerability
CVE-2026-645988.819.7LinuxLinux—smb/client: Fix error code in smb2_aead_req_alloc()
CVE-2026-655047.519.7ivanbebekBOX NOW Delivery CroatiaCWE-862WordPress BOX NOW Delivery Croatia plugin <= 3.3.0 - Broken Access Control vu…
CVE-2026-655237.519.7approvemeFormidable Forms Signature Online Contract AutomationCWE-639WordPress Formidable Forms Signature Online Contract Automation plugin <= 2.0…
CVE-2026-480808.019.5open-receptionappointment-booking-softwareCWE-200OpenReception's tenant detail endpoint discloses live PostgreSQL connection s…
CVE-2026-167318.319.4OMICRON electronics GmbHOMICRON StationScoutCWE-208Authentication and authorization bypass via cryptographic timing side-channel…
CVE-2026-160549.119.3UnknownDrag and Drop Multiple File Upload for WooCommerceCWE-73Drag and Drop Multiple File Upload for WooCommerce < 1.1.8 - Unauthenticated …
CVE-2026-676217.219.2FlowiseAIFlowiseCWE-862Flowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints
CVE-2026-190665.319.2SourceCodesterOnline Examination & Learning Management SystemCWE-285SourceCodester Online Examination & Learning Management System view_students.…
CVE-2026-105247.518.8UnknownCoCartCWE-472CoCart < 4.9.0 - Unauthenticated Arbitrary Price Manipulation
CVE-2026-655478.518.6Constant ContactCreative MailCWE-89WordPress Creative Mail plugin <= 1.6.9 - SQL Injection vulnerability
CVE-2026-655698.518.6wpjobportalWP Job PortalCWE-89WordPress WP Job Portal plugin <= 2.5.6 - SQL Injection vulnerability
CVE-2026-636879.118.0Apache Software FoundationApache CXFCWE-345Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce para…
CVE-2026-51349.817.9Loca Software Informatics Technology Ltd. Co.CMSCWE-89SQLi in Loca Software's CMS
CVE-2026-182764.318.0ScriptaeScriptoriumCWE-862Missing Authorization in eScriptorium
CVE-2026-666956.517.8BoldGridW3 Total CacheCWE-35WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability
CVE-2026-655839.117.6Apache Software FoundationApache CXFCWE-345Apache CXF: Self-issued ID token claims validation skipped
CVE-2026-191657.517.6GoogleChromeCWE-416Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed…
CVE-2026-190215.517.7SourceCodesterComputer Repair Shop Management SystemCWE-74SourceCodester Computer Repair Shop Management System Master.php delete_produ…
CVE-2026-127139.117.6UnknownWPCargo Track & TraceCWE-89WPCargo Track & Trace < 8.0.4 - Unauthenticated SQL Injection via wpcargo_tra…
CVE-2026-666629.817.4Shabti KaplanFrontend Admin by DynamiAppsCWE-266WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Privilege Escalati…
CVE-2026-166207.517.2UnknownWPC Name Your Price for WooCommerceCWE-472WPC Name Your Price for WooCommerce < 2.2.5 - Unauthenticated Price Manipulat…
CVE-2026-163158.117.1OMICRON electronics GmbHOMICRON StationGuardCWE-208Authentication and authorization bypass via cryptographic timing side-channel…
CVE-2026-637258.617.0nuxsminsysPassCWE-78sysPass FileBackupService Authenticated OS Command Injection via Backup Path
CVE-2026-131537.516.9UnknownGutenberg Essential BlocksCWE-200Essential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure …
CVE-2026-131547.516.9UnknownGutenberg Essential BlocksCWE-200Essential Blocks < 6.4.0 - Unauthenticated Non-Public Custom Post Type Conten…
CVE-2026-180507.516.9UnknownEvents ManagerCWE-200Events Manager < 7.4 - Unauthenticated Pending Upload Disclosure via events-m…
CVE-2026-191567.516.9GoogleChromeCWE-122Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed…
CVE-2024-65416.816.9WSO2WSO2 Micro IntegratorCWE-20Information Disclosure and Integrity Violation via Improper Message Context H…
CVE-2026-190655.316.9SourceCodesterOnline Examination & Learning Management SystemCWE-284SourceCodester Online Examination & Learning Management System upload_files.p…
CVE-2026-655428.816.7Rajat VarlaniSuper SocializerCWE-288WordPress Super Socializer plugin <= 7.14.5 - Broken Authentication vulnerabi…
CVE-2026-636378.616.7dgraph-iodgraphCWE-943Dgraph: DQL Injection via unvalidated regexp filter argument in GraphQL query…
CVE-2026-687472.316.6rrrenehtml_sanitize_exCWE-74CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input
CVE-2026-191101.916.6n/aDataGearCWE-79DataGear Chart Name HtmlTplDashboardWidgetHtmlRenderer.java HtmlTplDashboardW…
CVE-2026-58567.116.5Contiki-NGContiki-NGCWE-125Contiki-NG DNS/mDNS Resolver Out-of-Bounds Read via Unchecked skip_name Trave…
CVE-2026-119835.316.2spacetimeAd Inserter – Ad Manager & AdSense AdsCWE-862Ad Inserter <= 2.8.16 - Missing Authorization to Block Visibility Bypass via …
CVE-2026-646644.316.2statamiccmsCWE-200Statamic: Missing authorization on Control Panel endpoint allows disclosure o…
CVE-2026-480785.316.0open-receptionappointment-booking-softwareCWE-200OpenReception's schedule endpoint discloses isPublic=false channels and slot …
CVE-2026-190672.116.1itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System treatment.php sql injection
CVE-2026-190682.116.1itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System treatmentdetail.php sql injection
CVE-2026-628578.816.0fedify-devfedifyCWE-918Fedify: Server-Side Request Forgery in getNodeInfo() Allows Access to Interna…
CVE-2026-645868.816.0LinuxLinux—wifi: brcmfmac: drain bus_reset work on device removal
CVE-2026-169546.516.0UnknownAI EngineCWE-200AI Engine < 3.6.4 - Editor+ Sensitive Information Disclosure of API Key and B…
CVE-2026-676228.515.7FlowiseAIFlowiseCWE-639Flowise 3.1.4 IDOR in OpenAI Assistants Integration
CVE-2026-714466.915.8ail-projectail-frameworkCWE-79Stored Cross-Site Scripting in AIL Framework Domain Screenshot View
CVE-2026-133425.315.5UnknownSecurity OptimizerCWE-693Security Optimizer – The All-In-One Protection Plugin < 1.6.5 - Login Access …
CVE-2026-189962.115.4cosmicstack-labsmercury-agentCWE-266cosmicstack-labs mercury-agent run_command permissions.ts PermissionManager.c…
CVE-2026-190402.115.4MissionSquadmcp-apiCWE-918MissionSquad mcp-api dcrClients.ts server-side request forgery
CVE-2026-185107.215.2cozmoslabsTranslatePress – Translate Multilingual sites with AI TranslationCWE-79TranslatePress <= 3.2.6 - Unauthenticated Stored Cross-Site Scripting via Com…
CVE-2026-184006.415.2metasliderSlider, Gallery, and Carousel by MetaSlider – Image Slider, Video SliderCWE-79Slider, Gallery, and Carousel by MetaSlider <= 3.111.0 - Authenticated (Autho…
CVE-2026-480766.515.1open-receptionappointment-booking-softwareCWE-863OpenReception's bootstrap booking flow allows unauthenticated booking on isPu…
CVE-2026-34308.615.0UnknownCreative MailCWE-89Creative Mail 1.6.5 - 1.6.9 - Unauthenticated SQLi
CVE-2024-68327.514.9WSO2WSO2 Enterprise IntegratorCWE-693Account Lockout Failure via Secondary User Store Inaccessibility in Multiple …
CVE-2026-547175.414.9silverstripesilverstripe-cmsCWE-79Silverstripe: XSS in breadcrumbs in page list view
CVE-2026-714345.314.9statamiccmsCWE-434Statamic: Missing file upload validation on frontend forms allows uploading d…
CVE-2025-123175.014.9WSO2WSO2 Enterprise IntegratorCWE-613Improper Token Revocation via SOAP Services in Multiple WSO2 Products Allows …
CVE-2026-281407.514.6jetmonstersJetFormBuilderCWE-862WordPress JetFormBuilder plugin <= 3.6.4.1 - Broken Access Control vulnerability
CVE-2026-182777.114.5ScriptaeScriptoriumCWE-862Missing Authorization in eScriptorium
CVE-2026-151495.314.4UnknownWP Hotel BookingCWE-20WP Hotel Booking < 2.3.3 - Unauthenticated Payment Bypass via Price Manipulation
CVE-2026-160675.314.4UnknownEvent Booking Manager for WooCommerce (Pro)CWE-472Event Booking Manager for WooCommerce (Pro) < 5.0.3 - Unauthenticated Payment…
CVE-2026-166197.514.2UnknownminiOrange 2FACWE-307miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts
CVE-2026-664526.514.2IT-Recht KanzleiLegal Text Connector of the IT-Recht KanzleiCWE-862WordPress Legal Text Connector of the IT-Recht Kanzlei plugin <= 1.0.13 - Bro…
CVE-2026-143145.314.2UnknownPeproDev WooCommerce Receipt UploaderCWE-200PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Image Attach…
CVE-2026-714476.914.1ail-projectail-frameworkCWE-79Stored Cross-Site Scripting in Chat and Forum Translation Controls in ail-fra…
CVE-2026-68480await14.1LinuxLinux—x86/bugs: Make Safe-RET robust against interrupt injection
CVE-2026-281695.314.0YITHEMESYITH WooCommerce Zoom MagnifierCWE-497WordPress YITH WooCommerce Zoom Magnifier plugin <= 2.52.0 - Sensitive Data E…
CVE-2026-666835.314.0WP ZoneCustom CSS and JavaScriptCWE-201WordPress Custom CSS and JavaScript plugin <= 2.0.16 - Sensitive Data Exposur…
CVE-2026-666845.314.0Akshay MenariyaExport Import MenusCWE-201WordPress Export Import Menus plugin <= 1.9.2 - Sensitive Data Exposure vulne…
CVE-2026-324695.313.9WPKubeCAPTCHA 4WPCWE-290WordPress CAPTCHA 4WP plugin <= 7.6.0 - Captcha Bypass vulnerability
CVE-2026-655025.313.9bdthemesElement Pack Elementor AddonsCWE-290WordPress Element Pack Elementor Addons plugin <= 8.7.13 - Captcha Bypass vul…
CVE-2026-160656.513.7UnknownWelcart e-CommerceCWE-89Welcart e-Commerce < 2.11.32 - Editor+ SQL Injection via CSV Import
CVE-2026-142252.713.6UnknownEasy AppointmentsCWE-20Easy Appointments < 3.12.28 - Contributor+ Shortcode Allowlist Bypass
CVE-2026-655469.313.5QODEQode ToursCWE-89WordPress Qode Tours plugin <= 3.1.3.1 - SQL Injection vulnerability
CVE-2026-664479.313.5nickbossWordPress File UploadCWE-89WordPress WordPress File Upload plugin <= 5.1.7 - SQL Injection vulnerability
CVE-2026-663704.813.4rrrenehtml_sanitize_exCWE-601html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attr…
CVE-2026-706378.213.2hfiref0xLightFTPCWE-820LightFTP 2.4 Data Race Condition via ABOR Command in ftpserv.c
CVE-2026-655708.113.2Hamid AliniaLogin with phone numberCWE-290WordPress Login with phone number plugin <= 1.8.70 - Bypass vulnerability vul…
CVE-2026-182756.513.2ScriptaeScriptoriumCWE-639Authorization Bypass Through User-Controlled Key in eScriptorium
CVE-2026-655517.513.0SoflyyBreakdanceCWE-862WordPress Breakdance plugin < 2.7 - Broken Access Control vulnerability
CVE-2026-664516.513.0ArrayticsWP Event SOlutionCWE-288WordPress WP Event SOlution plugin <= 4.1.9 - Broken Authentication vulnerabi…
CVE-2026-714335.313.0langchain-ailanggraphCWE-200LangGraph: Namespace prefix matching crosses segment boundaries in Postgres a…
CVE-2026-543010.012.7WSO2WSO2 Universal GatewayCWE-347Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Al…
CVE-2026-281805.312.4Mercado PagoMercado Pago payments for WooCommerceCWE-639WordPress Mercado Pago payments for WooCommerce plugin <= 8.9.0 - Insecure Di…
CVE-2026-325485.312.4SureCartSureCartCWE-862WordPress SureCart plugin <= 4.6.2 - Broken Access Control vulnerability
CVE-2026-183598.512.3ScriptaeScriptoriumCWE-918Server-Side Request Forgery (SSRF) in eScriptorium
CVE-2025-156742.712.0UnknownPasssterCWE-863Content Protector (Passster) < 4.3.7 - Contributor+ Protected Content Disclos…
CVE-2026-190372.111.8n/aWonderTraderCWE-840WonderTrader Internal Limit Order Book Cache MatchEngine.cpp update_lob behav…
CVE-2026-667088.211.7BoldGridTotal UpkeepCWE-862WordPress Total Upkeep plugin <= 1.17.2 - Broken Access Control vulnerability
CVE-2026-189932.111.6NousResearchhermes-agentCWE-266NousResearch hermes-agent Memory Toolset model_tools.py access control
CVE-2026-655417.311.4solutionedStaff TrainingCWE-862WordPress Staff Training plugin <= 1.0.7 - Broken Access Control vulnerability
CVE-2026-667127.511.1wp.insiderSimple MembershipCWE-862WordPress Simple Membership plugin <= 4.7.8 - Broken Access Control vulnerabi…
CVE-2026-06735.311.1bdthemesElement Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor AddonsCWE-93Element Pack Addons for Elementor <= 8.3.15 - Unauthenticated SMTP Header Inj…
CVE-2026-162905.311.0UnknownProfileGridCWE-862ProfileGrid < 6.0.0.0 - Unauthenticated Group Member List Disclosure via pm_g…
CVE-2026-706388.510.9ggml-orgllama.cppCWE-190llama.cpp b1886–b7445 Integer Overflow via new_1batch() in llama-android.cpp
CVE-2026-189762.111.0NousResearchhermes-agentCWE-266NousResearch hermes-agent disabled_toolsets agent_init.py get_tool_definition…
CVE-2026-189922.111.0zhayujieCowAgentCWE-285zhayujie CowAgent Self-Evolution Review Agent executor.py _select_tools autho…
CVE-2026-189972.111.0cosmicstack-labsmercury-agentCWE-285cosmicstack-labs mercury-agent bg agent.ts Agent.handleBgCommand authorization
CVE-2026-189982.111.0cosmicstack-labsmercury-agentCWE-266cosmicstack-labs mercury-agent delegate_task Tool sub-agent.ts SubAgent.run i…
CVE-2026-190052.111.0nanocoaiNanoClawCWE-266nanocoai NanoClaw Child-Agent Creation create-agent.ts handleCreateAgent priv…
CVE-2026-190062.111.0mf-yangopenclaw-cnCWE-285mf-yang openclaw-cn Ggateway Exec Approval Flow bash-tools.exec.ts authorization
CVE-2026-190072.111.0mf-yangopenclaw-cnCWE-266mf-yang openclaw-cn reply-elevated.ts isApprovedElevatedSender privileges man…
CVE-2026-706328.510.6FFmpegFFmpegCWE-787FFmpeg 4.4 < 9.0 Heap Out-of-Bounds Write in CFHD Decoder via AVI Demuxing
CVE-2026-142405.310.6UnknowntourmasterCWE-200Tourmaster < 5.4.9 - Unauthenticated Sensitive Data Disclosure via Order Export
CVE-2026-666924.310.6ColissimoColissimo Officiel : Méthodes de livraison pour WooCommerceCWE-639WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin …
CVE-2026-619596.510.4Strategy11 TeamBusiness DirectoryCWE-79WordPress Business Directory plugin <= 6.4.24 - Cross Site Scripting (XSS) vu…
CVE-2025-139094.310.5WSO2WSO2 Identity ServerCWE-20Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity…
CVE-2026-190591.910.1FoundationAgentsMetaGPTCWE-22FoundationAgents MetaGPT editor.py read path traversal
CVE-2026-436288.510.0ggml-orgllama.cppCWE-191llama.cpp b3978–b9058 Integer Underflow via DRY Sampler
CVE-2026-471948.69.9frappefrappeCWE-346Frappe: Host header poisoning can redirect magic login links to an attacker-c…
CVE-2026-714786.19.8thephpleaguecommonmarkCWE-79league/commonmark: AttributesExtension href/src unsafe-link filter bypass via…
CVE-2025-65084.39.8WSO2WSO2 API ManagerCWE-79User Interface Misrepresentation via Swagger UI Try-out Console in WSO2 API M…
CVE-2026-714382.49.7mermaid-jsmermaidCWE-1321Mermaid configuration APIs allow prototype pollution
CVE-2026-190202.19.8itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System servicetype.php sql injection
CVE-2026-667117.19.6Amir HelzerWooCommerce Multilingual & MulticurrencyCWE-79WordPress WooCommerce Multilingual & Multicurrency plugin <= 5.5.6 - Cross Si…
CVE-2026-143064.39.4UnknownTutor LMSCWE-639Tutor LMS < 3.9.14 - Subscriber+ Paid Course Content Disclosure via Enrollmen…
CVE-2026-666784.39.4Justin KruitAdvanced Custom Fields: Font Awesome FieldCWE-862WordPress Advanced Custom Fields: Font Awesome Field plugin <= 6.1.1 - Broken…
CVE-2026-167347.59.3UnknownStripe Payment Forms by WP Full PayCWE-862Stripe Payment Forms by WP Full Pay < 8.5.2 - Unauthenticated Payment Intent …
CVE-2026-148298.29.0UnknownCheckimate — WooCommerce Checkout, Abandoned Cart Recovery & Order BumpsCWE-284Checkimate <= 1.0.13 - Unauthenticated License Deactivation via Hardcoded Secret
CVE-2026-666855.38.8AlexFeatured Video PlusCWE-201WordPress Featured Video Plus plugin <= 2.3.3 - Sensitive Data Exposure vulne…
CVE-2026-714356.18.8statamiccmsCWE-79Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Te…
CVE-2025-150287.28.7wpwaxFormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & MoreCWE-79FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, P…
CVE-2026-714974.78.7jhyjsoupCWE-79jsoup: Cleaner may expose markup with custom raw-text elements
CVE-2026-254036.58.4bdthemesUltimate Store Kit Elementor AddonsCWE-862WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Broken Access…
CVE-2026-152564.88.4UnknownNinja FormsCWE-74Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Que…
CVE-2025-147793.88.4WSO2WSO2 Identity ServerCWE-281Improper Access Control via Secret Type Management API in WSO2 Identity Server
CVE-2026-190581.98.3FoundationAgentsMetaGPTCWE-74FoundationAgents MetaGPT data_interpreter.py DataInterpreter code injection
CVE-2026-190601.98.3FoundationAgentsMetaGPTCWE-74FoundationAgents MetaGPT code injection
CVE-2026-664397.18.1BeRocketAdvanced AJAX Product FiltersCWE-79WordPress Advanced AJAX Product Filters plugin <= 3.2.0.3 - Cross Site Script…
CVE-2026-664407.18.1XplodedThemesWPIDE – File Manager & Code EditorCWE-79WordPress WPIDE – File Manager & Code Editor plugin <= 3.5.7 - Cross Site Scr…
CVE-2026-664577.18.1@msykesEvents ManagerCWE-79WordPress Events Manager plugin <= 7.4.1 - Cross Site Scripting (XSS) vulnera…
CVE-2026-666637.18.1Passionate Programmer PeterWP Data AccessCWE-79WordPress WP Data Access plugin <= 5.5.79 - Cross Site Scripting (XSS) vulner…
CVE-2026-666647.18.1SEO SquirrlySEO Plugin by Squirrly SEOCWE-79WordPress SEO plugin by Squirrly SEO plugin <= 14.2.0 - Cross Site Scripting …
CVE-2026-185978.58.0Foxit Software Inc.Foxit PDF Services APICWE-918Blind SSRF on Foxit PDF Services API
CVE-2026-145475.37.7UnknownEstatik Real Estate PluginCWE-287Estatik Real Estate Plugin < 4.3.3 - Unauthenticated Arbitrary-Recipient Mail…
CVE-2026-190616.37.7InstaInstaKNXServiceAppCWE-345Insta InstaKNXServiceApp Firmware Update CreateWebClientAndDownloadFileList d…
CVE-2026-455724.87.6decidimdecidimCWE-94Decidim: HTML content blocks allow stored script execution
CVE-2026-125847.57.4UnknownPayment Gateway for Redsys & WooCommerce Lite—Payment Gateway for Redsys & WooCommerce Lite < 7.0.2 - Unauthenticated Payme…
CVE-2026-655177.17.4Scott PatersonEasy PayPal Buy Now ButtonCWE-79WordPress Easy PayPal Buy Now Button plugin <= 2.0.4 - Cross Site Scripting (…
CVE-2026-666995.37.4Dokan, Inc.DokanCWE-862WordPress Dokan plugin <= 5.0.10 - Broken Access Control vulnerability
CVE-2026-667015.37.4CozmoslabsProfile BuilderCWE-862WordPress Profile Builder plugin <= 3.16.5 - Broken Access Control vulnerability
CVE-2025-118504.37.3WSO2WSO2 Identity ServerCWE-639Improper Implicit Association via User Store Initialization in WSO2 Identity …
CVE-2026-666964.37.1NexcessGutenberg Blocks by Kadence BlocksCWE-201WordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.7.8 - Sensitive Data…
CVE-2026-78677.87.0Red HatRed Hat Enterprise Linux 10CWE-863Udisks2: udisks2: local privilege escalation via as-user option spoofing
CVE-2026-280827.17.0Crocoblock. Jetimpex Inc.JetEngineCWE-79WordPress JetEngine plugin <= 3.8.13.1 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-281417.17.0Syed BalkhiNextGEN GalleryCWE-79WordPress NextGEN Gallery plugin <= 4.2.3 - Cross Site Scripting (XSS) vulner…
CVE-2026-281437.17.0WPMU DEVForminatorCWE-79WordPress Forminator plugin <= 1.56.0 - Cross Site Scripting (XSS) vulnerability
CVE-2026-281777.17.0Daniel IserPopup MakerCWE-79WordPress Popup Maker plugin <= 1.23.0 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-619617.17.0WPDeveloperEmbedPressCWE-79WordPress EmbedPress plugin <= 4.5.6 - Cross Site Scripting (XSS) vulnerability
CVE-2026-619637.17.0David LingrenMedia LIbrary AssistantCWE-79WordPress Media LIbrary Assistant plugin <= 3.38 - Cross Site Scripting (XSS)…
CVE-2026-619647.17.0WPManageNinjaNinja TablesCWE-79WordPress Ninja Tables plugin <= 5.2.9 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-619827.17.0jp-secureSiteGuard WP PluginCWE-79WordPress SiteGuard WP Plugin plugin <= 1.8.6 - Cross Site Scripting (XSS) vu…
CVE-2026-655097.17.0wpDataTableswpDataTablesCWE-79WordPress wpDataTables plugin <= 7.5.1 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-655137.17.0NSquaredSimply Schedule AppointmentsCWE-79WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - Cross Site Scrip…
CVE-2026-655157.17.0AffiliateWPAffiliateWPCWE-79WordPress AffiliateWP plugin <= 2.35.0 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-655447.17.0Rajat VarlaniSuper SocializerCWE-79WordPress Super Socializer plugin <= 7.14.5 - Cross Site Scripting (XSS) vuln…
CVE-2026-655457.17.0Jordy MeowAI EngineCWE-79WordPress AI Engine plugin <= 3.6.8 - Cross Site Scripting (XSS) vulnerability
CVE-2026-655607.17.0Property HiveHouzez Property FeedCWE-79WordPress Houzez Property Feed plugin <= 2.5.48 - Cross Site Scripting (XSS) …
CVE-2026-655657.17.0Ays ProSurvey MakerCWE-79WordPress Survey Maker plugin <= 5.2.3.3 - Cross Site Scripting (XSS) vulnera…
CVE-2024-103025.86.9WSO2WSO2 API Control PlaneCWE-20Improper Input Validation via Signup Process in Multiple WSO2 Products Enable…
CVE-2026-191438.66.6GoogleChromeCWE-20Insufficient validation of untrusted input in WebAPKs in Google Chrome on And…
CVE-2026-281795.96.7Damian GóraFiboSearchCWE-79WordPress FiboSearch plugin <= 1.33.0 - Cross Site Scripting (XSS) vulnerability
CVE-2025-137363.76.5WSO2WSO2 Identity Server as Key ManagerCWE-203Username Enumeration via Login Interface in Multiple WSO2 Products Allows Use…
CVE-2026-715554.16.2THM-HealthPILOSCWE-1022PILOS: Reverse tabnabbing in room description
CVE-2026-64590await5.8LinuxLinux—dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning
CVE-2026-64593await5.8LinuxLinux—btrfs: do not trim a device which is not writeable
CVE-2026-64594await5.8LinuxLinux—usb: gadget: f_fs: initialize reset_work at allocation time
CVE-2026-64602await5.8LinuxLinux—iio: adc: spear: Initialize completion before requesting IRQ
CVE-2026-64604await5.8LinuxLinux—KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode
CVE-2026-64591await5.8LinuxLinux—iommu/vt-d: Avoid WARNING in sva unbind path
CVE-2026-115886.15.6UnknownEONSR AEO AgentCWE-79EONSR AEO Agent <= 3.7.9 - Unauthenticated Stored XSS via Scheduled Post Crea…
CVE-2026-105997.55.4UnknownIntegrate PhonePe with WooCommerceCWE-345Integrate PhonePe with WooCommerce <= 1.2.1 - Unauthenticated Payment Bypass …

Results continue: ranks 401–482.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-06 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.