AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .1043 95.4 YES
AFFECTED Product Versions Fixed macOS unspecified —
TIMELINE Jul 22 Reserved by CNA Aug 6 Published (CNA: apple) Aug 18 Added to CISA KEV, due Aug 21
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
482 CVEs published, led by Google (41).
482 CVEs published August 6, 2026: 87 critical, 187 high, 145 medium, 51 low; 1 in the KEV catalog at press time; 5 with a public exploit reference; 12 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 82 on continuation pages.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 1693 | 23857 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
1264 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 44 | 2359 | 210 | 1254 | 637 | 1 | 11 | 2 | 0.1 | 7.8 | .0016 | +7 ▲ |
| 43 | 1804 | 222 | 743 | 783 | 56 | 77 | 6 | 0.3 | 7.5 | .0025 | -9 ▼ | |
| microsoft | 33 | 1455 | 121 | 991 | 329 | 14 | 286 | 24 | 1.6 | 7.8 | .0047 | -17 ▼ |
| red hat | 37 | 423 | 20 | 164 | 210 | 29 | 2 | 0 | 0.0 | 6.5 | .0029 | +18 ▲ |
| apple | 1 | 272 | 58 | 78 | 133 | 3 | 88 | 7 | 2.6 | 6.8 | .0027 | +1 ▲ |
| canonical | 0 | 27 | 3 | 8 | 11 | 5 | 0 | 0 | 0.0 | 5.6 | .0014 | 0 |
| suse | 5 | 26 | 5 | 14 | 6 | 1 | 0 | 0 | 0.0 | 8.1 | .0039 | 0 |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 23 | 61 | 13 | 29 | 19 | 0 | 56 | 12 | 19.7 | 7.5 | .0042 | +15 ▲ |
| ubiquiti | 0 | 36 | 14 | 21 | 1 | 0 | 3 | 3 | 8.3 | 8.8 | .0049 | -25 ▼ |
| palo alto networks | 0 | 25 | 1 | 3 | 14 | 7 | 13 | 2 | 8.0 | 4.7 | .0028 | 0 |
| fortinet | 0 | 23 | 6 | 6 | 11 | 0 | 28 | 6 | 26.1 | 7.2 | .0040 | 0 |
| netgear | 0 | 23 | 0 | 0 | 22 | 1 | 0 | 0 | 0.0 | 4.6 | .0024 | 0 |
| vmware | 0 | 17 | 4 | 9 | 2 | 2 | 7 | 1 | 5.9 | 8.3 | .0040 | 0 |
| f5 | 0 | 16 | 5 | 8 | 3 | 0 | 4 | 1 | 6.3 | 8.6 | .0057 | 0 |
| checkpoint | 1 | 13 | 4 | 6 | 3 | 0 | 3 | 2 | 15.4 | 7.8 | .0436 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 58 | 394 | 75 | 175 | 131 | 12 | 33 | 2 | 0.5 | 7.5 | .0051 | +14 ▲ |
| mozilla | 1 | 128 | 51 | 42 | 35 | 0 | 9 | 0 | 0.0 | 8.1 | .0031 | -2 ▼ |
| drupal | 0 | 51 | 6 | 5 | 35 | 5 | 4 | 1 | 2.0 | 5.9 | .0026 | 0 |
| gitlab | 0 | 51 | 0 | 7 | 37 | 7 | 4 | 2 | 3.9 | 4.9 | .0029 | 0 |
| github | 2 | 14 | 1 | 4 | 9 | 0 | 0 | 0 | 0.0 | 6.2 | .0043 | +1 ▲ |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.2 | .0016 | 0 |
| wordpress | 0 | 3 | 1 | 1 | 1 | 0 | 2 | 2 | 66.7 | 8.6 | .7979 | 0 |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0035 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 1379 | 343 | 653 | 322 | 61 | 27 | 3 | 0.2 | 8.1 | .0036 | 0 |
| ibm | 32 | 261 | 72 | 104 | 84 | 1 | 6 | 1 | 0.4 | 7.5 | .0031 | +32 ▲ |
| adobe | 7 | 259 | 33 | 117 | 105 | 4 | 19 | 3 | 1.2 | 7.8 | .0026 | +5 ▲ |
| progress | 10 | 52 | 13 | 32 | 7 | 0 | 6 | 0 | 0.0 | 8.1 | .0037 | +8 ▲ |
| solarwinds | 0 | 23 | 17 | 3 | 3 | 0 | 10 | 4 | 17.4 | 9.1 | .0058 | 0 |
| veeam | 10 | 16 | 5 | 9 | 2 | 0 | 1 | 0 | 0.0 | 8.6 | .0034 | +10 ▲ |
| zohocorp | 0 | 6 | 2 | 2 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0146 | 0 |
| atlassian | 0 | 3 | 0 | 3 | 0 | 0 | 13 | 0 | 0.0 | 8.0 | .0026 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 1 | 24 | 2 | 6 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +1 ▲ |
| rockwell automation | 0 | 24 | 4 | 18 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0029 | 0 |
| d-link | 0 | 20 | 0 | 5 | 9 | 6 | 3 | 0 | 0.0 | 5.5 | .0105 | 0 |
| siemens | 0 | 16 | 1 | 8 | 7 | 0 | 0 | 0 | 0.0 | 7.6 | .0024 | 0 |
| schneider electric | 0 | 9 | 1 | 6 | 2 | 0 | 0 | 0 | 0.0 | 8.6 | .0037 | 0 |
| abb | 0 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | 0 |
| hikvision | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0040 | 0 |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 4 | 124 | 0 | 0 | 66 | 58 | 0 | 0 | 0.0 | 5.4 | .0033 | -23 ▼ |
| openclaw | 0 | 111 | 0 | 58 | 39 | 14 | 0 | 0 | 0.0 | 7.0 | .0026 | 0 |
| dell | 6 | 105 | 8 | 50 | 44 | 3 | 2 | 1 | 1.0 | 7.2 | .0021 | -14 ▼ |
| nvidia | 16 | 98 | 13 | 66 | 19 | 0 | 0 | 0 | 0.0 | 7.7 | .0034 | -1 ▼ |
| capgo | 0 | 83 | 2 | 42 | 38 | 1 | 0 | 0 | 0.0 | 7.1 | .0037 | 0 |
| spring | 0 | 79 | 2 | 34 | 41 | 2 | 0 | 0 | 0.0 | 6.5 | .0022 | 0 |
| imagemagick | 0 | 78 | 1 | 5 | 60 | 12 | 0 | 0 | 0.0 | 5.3 | .0018 | -8 ▼ |
| itsourcecode | 6 | 77 | 0 | 0 | 19 | 58 | 0 | 0 | 0.0 | 2.1 | .0033 | -4 ▼ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-34486 | .9862 | 99.9 | 7.5 |
| CVE-2026-63030 | .9779 | 99.9 | 9.8 |
| CVE-2026-16232 | .8912 | 99.8 | 9.3 |
| CVE-2026-63077 | .8473 | 99.7 | 9.8 |
| CVE-2026-50522 | .8461 | 99.7 | 9.8 |
| CVE-2026-15409 | .8366 | 99.7 | 10.0 |
| CVE-2026-60137 | .7979 | 99.6 | 5.9 |
| CVE-2026-6875 | .7758 | 99.5 | 9.5 |
| CVE-2026-25089 | .7611 | 99.5 | 9.8 |
| CVE-2026-0770 | .6342 | 99.1 | 9.8 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-15409 | 10.0 | .8366 | KEV |
| CVE-2026-48939 | 10.0 | .1973 | KEV |
| CVE-2026-56291 | 10.0 | .1459 | KEV |
| CVE-2026-59726 | 10.0 | .0688 | |
| CVE-2026-8985 | 10.0 | .0660 | |
| CVE-2026-6516 | 10.0 | .0486 | |
| CVE-2026-47668 | 10.0 | .0388 | |
| CVE-2026-46339 | 10.0 | .0335 | |
| CVE-2026-61447 | 10.0 | .0249 | |
| CVE-2026-57827 | 10.0 | .0233 |
| Vendor | CVEs |
|---|---|
| oracle | 1109 |
| linux | 842 |
| microsoft | 648 |
| 487 | |
| apache | 189 |
| red hat | 174 |
| apple | 168 |
| ibm | 137 |
| adobe | 112 |
| mozilla | 69 |
| Vendor | KEV |
|---|---|
| microsoft | 24 |
| cisco | 12 |
| apple | 7 |
| fortinet | 6 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| oracle | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 67 |
| PyPI | 5 |
| Go | 3 |
| npm | 3 |
| Packagist | 2 |
| crates.io | 2 |
| NuGet | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2021-27137 | DD-WRT | 0 |
| CVE-2025-68686 | Fortinet | 0 |
| CVE-2026-0770 | Langflow | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-16232 | checkpoint | 0 |
| CVE-2026-16812 | Arista Networks | 0 |
| CVE-2026-18556 | N-able | 0 |
| CVE-2026-18577 | N-able | 0 |
| CVE-2026-20316 | Cisco | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1723 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1723 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1723 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1723 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1723 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1723 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1723 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1723 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1723 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1723 |
EXPLOIT PUBLISHED — patriksimek vm2: 11 CVEs (CVE-2026-43997, CVE-2026-43998, CVE-2026-43999, CVE-2026-44001, CVE-2026-44004, CVE-2026-44005, CVE-2026-44006, CVE-2026-44007, CVE-2026-44008, CVE-2026-44009, CVE-2026-45411). Public exploit references added.
EXPLOIT PUBLISHED — zephyrproject zephyr: 8 CVEs (CVE-2026-7656, CVE-2026-10634, CVE-2026-10639, CVE-2026-10646, CVE-2026-10647, CVE-2026-10652, CVE-2026-10653, CVE-2026-10670). Public exploit references added.
EXPLOIT PUBLISHED — koxudaxi datamodel-code-generator: 4 CVEs (CVE-2026-54656, CVE-2026-54690, CVE-2026-55389, CVE-2026-55415). Public exploit references added.
EXPLOIT PUBLISHED — ueberauth guardian: 4 CVEs (CVE-2026-54894, CVE-2026-55733, CVE-2026-55734, CVE-2026-55735). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2012-4681. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2019-15107. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2021-22205 (GitLab). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2021-43890 (Microsoft App Installer). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-30190 (Microsoft Windows 10 Version 1809). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-40684 (Fortinet FortiOS, FortiProxy, FortiSwitchManager). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2023-42753 (Red Hat Enterprise Linux 7). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-12605 (Eclipse Foundation Eclipse GlassFish). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16746 (Unknown MultiVendorX). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16940 (Unknown Custom Fields). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16981 (Unknown DHL Shipping Germany for WooCommerce). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18958 (imranrisal-dev Student-Management-System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18959 (yushine InnoShop). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44210 (kata-containers). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47429 (vitest-dev vitest). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-64827 (Telenia Software TVox). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-64828 (Froiden TableTrack). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-67623 (mistralai mistral-vibe). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-69111 (milvus-io milvus). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-70615 (boringproxy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-70616 (boringproxy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-8037 (Progress Software LoadMaster). Public exploit reference added.
RESCORED — zephyrproject zephyr: 5 CVEs (CVE-2026-7656, CVE-2026-10634, CVE-2026-10643, CVE-2026-10652, CVE-2026-10653). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2023-42753 (Red Hat Enterprise Linux 7). CVSS 7 → 7.8 (NVD).
RESCORED — CVE-2023-5090 (Red Hat Enterprise Linux 8). CVSS 6 → 5.5 (NVD).
RESCORED — CVE-2024-0646 (kernel). CVSS 7 → 7.8 (NVD).
RESCORED — CVE-2024-1488 (unbound). CVSS 8 → 7.3 (NVD).
RESCORED — CVE-2024-21549 (spatie/browsershot). CVSS 7.7 → 6.6 (NVD).
RESCORED — CVE-2026-11714 (IBM WebSphere Application Server - Liberty). CVSS 8.5 → 9.8 (NVD).
RESCORED — CVE-2026-16108 (Red Hat Build of Keycloak). CVSS 4.3 → 6.5 (NVD).
RESCORED — CVE-2026-18968 (ttttonyhe OBlog). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-18969 (Rongzhitong Visual Integrated Command and Dispatch Platform). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-18970 (Rongzhitong Visual Integrated Command and Dispatch Platform). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-47429 (vitest-dev vitest). CVSS 9.8 → 5.9 (NVD).
How to read these box scores · glossary
482 CVEs published. 25 box scores and 375 table rows below; the remaining 82 continue on page 2 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .1043 95.4 YES
AFFECTED Product Versions Fixed macOS unspecified —
TIMELINE Jul 22 Reserved by CNA Aug 6 Published (CNA: apple) Aug 18 Added to CISA KEV, due Aug 21
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .1354 96.2 —
AFFECTED Product Versions Fixed WGDashboard unspecified —
TIMELINE Jul 14 Reserved by CNA Aug 6 Published (CNA: certcc)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 7.3 .0204 79.7 —
AFFECTED Product Versions Fixed Tomato 1.28.0000 – —
TIMELINE Aug 6 Reserved by CNA Aug 6 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 7.3 .0204 79.7 —
AFFECTED Product Versions Fixed Tomato 1.28.0000 – —
TIMELINE Aug 6 Reserved by CNA Aug 6 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 7.3 .0204 79.7 —
AFFECTED Product Versions Fixed Tomato 1.28.0000 – —
TIMELINE Aug 6 Reserved by CNA Aug 6 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H N 9.3 .0190 78.1 —
AFFECTED Product Versions Fixed OpenChamber unspecified —
TIMELINE Jun 11 Reserved by CNA Aug 6 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0160 73.9 —
AFFECTED Product Versions Fixed Virtual Storage Integrator for VMware vSphere Client unspecified —
TIMELINE Jul 29 Reserved by CNA Aug 6 Published (CNA: dell)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0133 68.8 —
AFFECTED Product Versions Fixed ironclaw 0.29.0 – —
TIMELINE Aug 5 Reserved by CNA Aug 6 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0125 67.0 —
AFFECTED Product Versions Fixed mcp-api 1.11.0 – 1.11.9
TIMELINE Aug 6 Reserved by CNA Aug 6 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0110 63.1 —
AFFECTED Product Versions Fixed Azure Service Bus - – —
TIMELINE Jun 4 Reserved by CNA Aug 6 Published (CNA: microsoft)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0108 62.7 —
AFFECTED Product Versions Fixed OpenChamber unspecified —
TIMELINE Jun 11 Reserved by CNA Aug 6 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 5.3 .0107 62.2 —
AFFECTED Product Versions Fixed OpenHands 0.1 – —
TIMELINE Aug 5 Reserved by CNA Aug 6 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0089 56.6 —
AFFECTED Product Versions Fixed sonic3air unspecified 2492d1882cd2cf1cc1d7415729ce5c4fd686cd4f
TIMELINE Jul 27 Reserved by CNA Aug 6 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0077 52.7 —
AFFECTED Product Versions Fixed Microsoft Entra Provisioning Service - – —
TIMELINE Jul 2 Reserved by CNA Aug 6 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0076 52.4 —
AFFECTED Product Versions Fixed Red Hat Enterprise Linux 10 unspecified 0:1.26.7-2.el10_2.3 Red Hat Enterprise Linux 8 unspecified 0:1.16.1-7.el8_10.3 Red Hat Enterprise Linux 9 unspecified 0:1.22.12-7.el9_8.2 Red Hat Enterprise Linux 7 unspecified —
TIMELINE Aug 3 Reserved by CNA Aug 6 Published (CNA: redhat)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N A H N N 5.9 .0076 52.4 —
AFFECTED Product Versions Fixed anki >= 25.09.3 – —
TIMELINE Jul 20 Reserved by CNA Aug 6 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0075 52.2 —
AFFECTED Product Versions Fixed Application Insights Profiler - – —
TIMELINE May 27 Reserved by CNA Aug 6 Published (CNA: microsoft)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N P N N N 5.3 .0073 51.4 —
AFFECTED Product Versions Fixed cli < 2.97.0 – —
TIMELINE Jul 20 Reserved by CNA Aug 6 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L P N P H H H 7.3 .0070 50.5 —
AFFECTED Product Versions Fixed PHP_CodeSniffer < 3.13.6 – —
TIMELINE Jul 29 Reserved by CNA Aug 6 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N L N L L L 1.9 .0070 50.2 —
AFFECTED Product Versions Fixed godot-mcp 0.1.0 – —
TIMELINE Aug 6 Reserved by CNA Aug 6 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0069 50.0 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Jun 21 Reserved by CNA Aug 6 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0069 49.8 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Jul 30 Reserved by CNA Aug 6 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N L N L L L 1.9 .0068 49.7 —
AFFECTED Product Versions Fixed LudusMCP 1.0.0 – —
TIMELINE Aug 6 Reserved by CNA Aug 6 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0068 49.5 —
AFFECTED Product Versions Fixed WGDashboard unspecified —
TIMELINE Jul 14 Reserved by CNA Aug 6 Published (CNA: certcc)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0067 49.1 —
AFFECTED Product Versions Fixed Apache CXF 4.2.0 – —
TIMELINE Jul 28 Reserved by CNA Aug 6 Published (CNA: apache)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-56162 | 10.0 | 49.0 | Microsoft | Azure SQL Database | CWE-287 | Azure SQL Database Elevation of Privilege Vulnerability |
| CVE-2026-70332 | 9.6 | 47.5 | Microsoft | Microsoft SharePoint Online | CWE-79 | Microsoft Office SharePoint Spoofing Vulnerability |
| CVE-2026-19045 | 1.9 | 47.1 | NocteDefensor | LudusMCP | CWE-74 | NocteDefensor LudusMCP get_credential_from_user secretDialog.ts SecretDialog.… |
| CVE-2026-65667 | 10.0 | 47.0 | Microsoft | Microsoft Teams | CWE-862 | Microsoft Teams Elevation of Privilege Vulnerability |
| CVE-2026-43629 | 9.2 | 46.9 | ggml-org | llama.cpp | CWE-787 | llama.cpp b4882–b9058 Buffer Overflow in KV Cache State Restore |
| CVE-2026-50159 | 5.3 | 46.5 | mermaid-js | mermaid | CWE-94 | Mermaid allows CSS injection applying to sibling elements of the diagram |
| CVE-2026-68823 | 9.1 | 46.2 | Microsoft | Azure Confidential Ledger | CWE-749 | Azure Confidential Ledger Remote Code Execution Vulnerability |
| CVE-2026-70558 | 9.3 | 45.8 | DataLinkDC | Dinky | CWE-434 | Dinky Unauthenticated Arbitrary File Write via /download/uploadFromRsByLocal … |
| CVE-2026-15991 | 8.8 | 45.5 | bitpressadmin | File Manager | CWE-862 | File Manager 6.0 - 6.9 - Missing Authorization to Authenticated (Subscriber+)… |
| CVE-2026-67688 | 9.8 | 45.4 | n/a | n/a | CWE-434 | ICS-Park Smart Park Management System v2.0 contains an unrestricted file uplo… |
| CVE-2026-71476 | 8.7 | 45.2 | nrwl | nx | CWE-22 | Nx: Zip-Slip in the self-hosted remote cache |
| CVE-2026-67422 | 7.5 | 45.2 | facelessuser | pymdown-extensions | CWE-1333 | pymdown-extensions: Exponential-backtracking ReDoS in caret, tilde, betterem,… |
| CVE-2026-3418 | 9.1 | 44.7 | WSO2 | WSO2 API Manager | CWE-434 | Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Re… |
| CVE-2026-14812 | 10.0 | 44.5 | Unknown | Premium SEO | CWE-912 | Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content… |
| CVE-2026-50481 | 9.9 | 44.2 | Microsoft | Azure Active Directory | CWE-471 | Azure Active Directory Elevation of Privilege Vulnerability |
| CVE-2026-48085 | 9.8 | 43.7 | open-reception | appointment-booking-software | CWE-862 | OpenReception has unauthenticated GLOBAL_ADMIN account creation post-bootstrap |
| CVE-2026-71324 | 7.0 | 43.6 | traefik | traefik | CWE-444 | Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's share… |
| CVE-2026-19150 | 8.8 | 42.9 | Chrome | CWE-693 | Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 a… | |
| CVE-2026-19151 | 8.8 | 42.9 | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remot… | |
| CVE-2026-19168 | 8.8 | 42.9 | Chrome | CWE-693 | Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 a… | |
| CVE-2026-5857 | 9.2 | 42.8 | Contiki-NG | Contiki-NG | CWE-787 | Contiki-NG MQTT Client Out-of-Bounds Write in PUBLISH Topic Parser via Persis… |
| CVE-2026-5855 | 8.7 | 42.8 | Contiki-NG | Contiki-NG | CWE-125 | Contiki-NG LwM2M TLV Parser Out-of-Bounds Read via Unchecked Buffer Length in… |
| CVE-2026-63508 | 10.0 | 42.7 | Microsoft | Microsoft Planetary Computer Pro (GeoCatalog) | CWE-306 | Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability |
| CVE-2026-62873 | 9.8 | 42.3 | Microsoft | Microsoft 365 Admin Center | CWE-347 | Microsoft 365 Admin Center Elevation of Privilege Vulnerability |
| CVE-2026-53977 | 8.7 | 41.9 | Bohdan Triapitsyn | OpenChamber | CWE-306 | OpenChamber 1.11.7 Unauthenticated DoS via /api/system/shutdown |
| CVE-2026-62830 | 9.9 | 41.5 | Microsoft | Azure SRE Agent | CWE-862 | Azure SRE Agent Elevation of Privilege Vulnerability |
| CVE-2026-65668 | 8.8 | 41.5 | Microsoft | Microsoft Purview eDiscovery | CWE-284 | Microsoft Purview eDiscovery Elevation of Privilege Vulnerability |
| CVE-2026-15459 | 8.1 | 41.2 | wpmudev | WPMU DEV Dashboard | CWE-287 | WPMU DEV Dashboard <= 5.0.0 - Authentication Bypass to Arbitrary Plugin Insta… |
| CVE-2026-34501 | 7.5 | 41.1 | Apache Software Foundation | Apache Portable Runtime Utility | CWE-122 | Apache Portable Runtime Utility: Heap buffer overflow in APR redis client |
| CVE-2026-34502 | 7.5 | 41.1 | Apache Software Foundation | Apache Portable Runtime Utility | CWE-122 | Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client |
| CVE-2026-70633 | 7.1 | 41.0 | timescale | timescaledb | CWE-191 | TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Gorilla Compression Reverse Ite… |
| CVE-2026-19176 | 7.5 | 40.9 | Chrome | CWE-416 | Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a rem… | |
| CVE-2026-66829 | 2.3 | 40.5 | rrrene | html_sanitize_ex | CWE-601 | html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowin… |
| CVE-2026-64653 | 5.1 | 40.4 | cli | cli | CWE-22 | GitHub CLI: Unescaped variable components in request URLs could allow path tr… |
| CVE-2026-19149 | 9.6 | 40.1 | Chrome | CWE-416 | Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allo… | |
| CVE-2026-18991 | 5.5 | 40.1 | nanocoai | NanoClaw | CWE-22 | nanocoai NanoClaw send_file core.ts path traversal |
| CVE-2026-11976 | 10.0 | 39.7 | Unknown | MonsterInsights Pro | CWE-912 | MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise |
| CVE-2026-59118 | 9.3 | 39.3 | Microsoft | Copilot Cowork | CWE-285 | Copilot Cowork Elevation of Privilege Vulnerability |
| CVE-2026-62896 | 9.6 | 38.6 | Microsoft | Microsoft Teams | CWE-287 | Microsoft Teams Elevation of Privilege Vulnerability |
| CVE-2026-66709 | 9.1 | 38.5 | WebAppick | CTX Feed | CWE-94 | WordPress CTX Feed plugin <= 6.6.42 - Remote Code Execution (RCE) vulnerability |
| CVE-2026-54225 | 7.5 | 38.3 | Apache Software Foundation | Apache CXF | CWE-770 | Apache CXF: Denial of Service attack via large attachments |
| CVE-2026-57819 | 7.5 | 38.3 | Apache Software Foundation | Apache CXF | CWE-400 | Apache CXF: No default restriction on the amount of form parameters per message |
| CVE-2026-54489 | 9.8 | 38.3 | Dell | Virtual Storage Integrator for VMware vSphere Client | CWE-200 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to … |
| CVE-2026-68750 | 8.2 | 38.3 | rrrene | html_sanitize_ex | CWE-407 | Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allo… |
| CVE-2026-65553 | 10.0 | 38.2 | wbolt.com | Spider Analyser – WordPress搜索引擎蜘蛛分析插件 | CWE-94 | WordPress Spider Analyser – WordPress搜索引擎蜘蛛分析插件 plugin <= 2.1.3 - Remote Code… |
| CVE-2026-56161 | 9.6 | 38.0 | Microsoft | Azure Logic Apps | CWE-284 | Azure Logic Apps Information Disclosure Vulnerability |
| CVE-2026-32327 | 9.1 | 37.8 | Apache Software Foundation | Apache Portable Runtime Utility | CWE-674 | Apache Portable Runtime Utility: apr-util XML stack recursion crash |
| CVE-2026-18427 | 7.5 | 37.7 | @fastify/static | @fastify/static | CWE-22 | @fastify/static vulnerable to route guard bypass via non-canonical path segments |
| CVE-2026-48087 | 9.8 | 37.7 | open-reception | appointment-booking-software | CWE-287 | OpenReception: WebAuthn passkey injection allows account takeover |
| CVE-2026-43630 | 6.3 | 37.5 | ggml-org | llama.cpp | CWE-125 | llama.cpp b5702–b7653 Out-of-Bounds Read Information Disclosure |
| CVE-2026-62918 | 7.5 | 37.4 | Microsoft | Microsoft Teams | CWE-347 | Microsoft Teams Spoofing Vulnerability |
| CVE-2026-67687 | 8.8 | 37.2 | n/a | n/a | CWE-284 | Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker… |
| CVE-2026-68749 | 8.2 | 37.2 | rrrene | html_sanitize_ex | CWE-1333 | Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-… |
| CVE-2026-48054 | 8.8 | 37.1 | OpenZeppelin | contracts-wizard | CWE-94 | OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Fou… |
| CVE-2026-57817 | 8.1 | 37.1 | Apache Software Foundation | Apache CXF | CWE-20 | Apache CXF: The authorization code hash (c_hash) is not enforced for the hybr… |
| CVE-2026-19137 | 8.3 | 37.0 | Chrome | CWE-416 | Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 a… | |
| CVE-2026-19177 | 8.3 | 36.8 | Chrome | CWE-20 | Insufficient validation of untrusted input in UI in Google Chrome prior to 15… | |
| CVE-2026-71554 | 5.3 | 36.7 | python-hyper | h2 | CWE-444 | h2: Duplicate Host header could facilitate request smuggling |
| CVE-2026-16268 | 8.2 | 36.3 | Unknown | Newsletters | CWE-918 | Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Boun… |
| CVE-2026-19174 | 8.8 | 36.1 | Chrome | CWE-190 | Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a rem… | |
| CVE-2026-62836 | 10.0 | 36.0 | Microsoft | Azure SQL Managed Instance | CWE-923 | Azure SQL Managed Instance Elevation of Privilege Vulnerability |
| CVE-2026-19158 | 7.5 | 36.0 | Chrome | CWE-416 | Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 a… | |
| CVE-2026-47765 | 7.1 | 35.7 | frappe | frappe | CWE-862 | Frappe: Lack of Permissions in restore/bulk_restore |
| CVE-2026-71439 | 5.3 | 35.6 | mermaid-js | mermaid | CWE-606 | Mermaid radar diagrams are vulnerable to DoS |
| CVE-2026-65548 | 9.9 | 35.3 | Muffingroup | Betheme | CWE-94 | WordPress Betheme theme <= 28.4.2 - Remote Code Execution (RCE) vulnerability |
| CVE-2026-68481 | 7.5 | 35.3 | Apache Software Foundation | Apache CXF | CWE-672 | Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider |
| CVE-2026-19166 | 9.6 | 35.1 | Chrome | CWE-416 | Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109… | |
| CVE-2026-61466 | 9.1 | 35.1 | Apache Software Foundation | Apache CXF | CWE-304 | Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation |
| CVE-2026-71502 | 5.1 | 35.1 | misp | cti-transmute | CWE-79 | Unauthenticated Stored Vue Template Injection Leads to Cross-Site Scripting i… |
| CVE-2026-43631 | 9.2 | 34.8 | ggml-org | llama.cpp | CWE-416 | llama.cpp b7492–b9060 Use-After-Free RCE via llama-server |
| CVE-2026-19145 | 8.8 | 34.6 | Chrome | CWE-416 | Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed … | |
| CVE-2026-19162 | 8.8 | 34.6 | Chrome | CWE-787 | Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a … | |
| CVE-2026-19141 | 8.3 | 34.4 | Chrome | CWE-416 | Use after free in Resources in Google Chrome on Android prior to 151.0.7922.1… | |
| CVE-2026-19142 | 7.5 | 34.4 | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a re… | |
| CVE-2026-19159 | 7.5 | 34.4 | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a re… | |
| CVE-2026-19011 | 5.5 | 34.4 | n/a | TinyAGI | CWE-73 | TinyAGI agents.ts buildSystemPrompt file inclusion |
| CVE-2026-65552 | 9.8 | 34.2 | qstudio | Export User Data | CWE-502 | WordPress Export User Data plugin <= 2.2.6 - PHP Object Injection vulnerability |
| CVE-2026-70634 | 7.2 | 34.2 | timescale | timescaledb | CWE-129 | TimescaleDB 2.29.1 Out-of-Bounds Read Information Disclosure via Dictionary C… |
| CVE-2026-65432 | 7.5 | 33.7 | Apache Software Foundation | Apache CXF | CWE-611 | Apache CXF: XXE via WSDL/XSD import parsing |
| CVE-2026-71436 | 5.3 | 33.6 | mermaid-js | mermaid | CWE-835 | Mermaid XY Charts are vulnerable to an infinite loop DoS |
| CVE-2026-64958 | 7.5 | 33.4 | Apache Software Foundation | Apache CXF | CWE-400 | Apache CXF: Denial of service via message header attachments |
| CVE-2025-15039 | 9.4 | 33.3 | WSO2 | WSO2 Identity Server | CWE-693 | Account Takeover via Conditional Authentication Script Logic in Multiple WSO2… |
| CVE-2026-65543 | 7.5 | 32.6 | vimeodev | Vimeo | CWE-201 | WordPress Vimeo plugin <= 1.2.2 - Sensitive Data Exposure vulnerability |
| CVE-2026-18990 | 5.5 | 32.5 | letta-ai | LettaBot | CWE-287 | letta-ai LettaBot API Status Route server.ts missing authentication |
| CVE-2026-68079 | 9.8 | 32.4 | Apache Software Foundation | Apache CXF | CWE-294 | Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization … |
| CVE-2026-45415 | 6.0 | 32.5 | decidim | decidim | CWE-862 | Decidim: CSV census record endpoints improper authorization |
| CVE-2026-5336 | 6.8 | 32.3 | Unknown | DataPress (Dataverse Integration) | CWE-200 | Dataverse Integration < 2.91 - Contributor+ Server-Side Template Injection (S… |
| CVE-2026-47185 | 5.1 | 32.1 | frappe | frappe | CWE-79 | Frappe Has Broken Access Control in its Workspace Save API |
| CVE-2026-48075 | 6.5 | 31.9 | open-reception | appointment-booking-software | CWE-862 | OpenReception's unauthenticated add-to-tunnel endpoint accepts arbitrary appo… |
| CVE-2026-19009 | 5.5 | 31.8 | n/a | TinyAGI | CWE-73 | TinyAGI Message API Endpoint response.ts collectFiles file inclusion |
| CVE-2025-14561 | 9.0 | 31.3 | WSO2 | WSO2 API Manager | CWE-284 | Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allow… |
| CVE-2026-48079 | 7.4 | 31.3 | open-reception | appointment-booking-software | CWE-613 | OpenReception's logout page clears local access_token before server-side revo… |
| CVE-2026-19157 | 9.6 | 31.1 | Chrome | CWE-787 | Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.… | |
| CVE-2026-19170 | 9.6 | 31.1 | Chrome | CWE-416 | Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 a… | |
| CVE-2026-19160 | 3.1 | 31.1 | Chrome | CWE-457 | Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a … | |
| CVE-2026-15732 | 9.8 | 30.9 | WGDashboard | WGDashboard | CWE-918 | WGDashboard Server-Side Request Forgery Vulnerability |
| CVE-2026-53984 | 8.8 | 30.8 | Efstratios Goudelis | Ground Station | CWE-306 | Ground Station prior to 0.6.0 Unauthenticated Database Wipe and Arbitrary Dat… |
| CVE-2026-53985 | 8.7 | 30.8 | Efstratios Goudelis | Ground Station | CWE-306 | Ground Station prior to 0.6.0 Unauthenticated DoS via service_control Socket.IO |
| CVE-2025-49506 | 7.5 | 30.7 | Apache Software Foundation | Apache Portable Runtime Utility | CWE-208 | Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing… |
| CVE-2026-48071 | 5.8 | 30.7 | open-reception | appointment-booking-software | CWE-307 | OpenReception's client PIN challenge throttle is keyed by emailHash only, all… |
| CVE-2026-28139 | 9.8 | 30.2 | wpdreams | Ajax Search Lite | CWE-502 | WordPress Ajax Search Lite plugin <= 4.14.4 - PHP Object Injection vulnerability |
| CVE-2026-17032 | 9.8 | 30.1 | Unknown | google-maps-easy-pro | CWE-912 | Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server |
| CVE-2026-70636 | 8.7 | 30.1 | FlowiseAI | Flowise | CWE-862 | Flowise 3.1.4 Authentication Bypass via OAuth2 Credential Refresh Endpoint |
| CVE-2026-19171 | 9.6 | 30.0 | Chrome | CWE-416 | Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 a… | |
| CVE-2026-19010 | 5.5 | 29.9 | n/a | TinyAGI | CWE-862 | TinyAGI Message API Endpoint index.ts processMessage authorization |
| CVE-2026-19111 | 8.6 | 29.7 | AWS | strands-agents-tools | CWE-639 | Insecure direct object reference in Strands Agents Tools memory tool namespac… |
| CVE-2026-64640 | 5.3 | 29.7 | Apache Software Foundation | Apache Polaris | CWE-863 | Apache Polaris: register endpoint reads attacker-controlled storage location … |
| CVE-2026-48082 | 3.7 | 29.7 | open-reception | appointment-booking-software | CWE-770 | OpenReception's bootstrap challenge proof-of-work difficulty hardcoded to 16 … |
| CVE-2026-19167 | 3.1 | 29.2 | Chrome | CWE-190 | Integer overflow in GPU in Google Chrome prior to 151.0.7922.109 allowed a re… | |
| CVE-2026-71327 | 7.6 | 29.1 | traefik | traefik | CWE-694 | Traefik: Gateway API route identity collision allows cross-namespace backend … |
| CVE-2026-71437 | 6.5 | 29.0 | mermaid-js | mermaid | CWE-1321 | Mermaid Architecture diagrams are vulnerable to prototype pollution |
| CVE-2026-48084 | 7.4 | 28.8 | open-reception | appointment-booking-software | CWE-307 | OpenReception doesn't rate limit passphrase login attempts |
| CVE-2026-64597 | 9.8 | 28.6 | Linux | Linux | — | smb: client: fix double-free in SMB2_close() replay |
| CVE-2026-65549 | 7.2 | 28.6 | jegtheme | Jeg Kit for Elementor | CWE-502 | WordPress Jeg Elementor Kit plugin <= 3.2.10 - PHP Object Injection vulnerabi… |
| CVE-2026-70635 | 7.1 | 28.6 | timescale | timescaledb | CWE-129 | TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Bulk Dictionary Decompression N… |
| CVE-2026-19164 | 9.6 | 28.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in Codecs in Google Chrome prior t… | |
| CVE-2026-19175 | 9.6 | 28.4 | Chrome | CWE-416 | Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a… | |
| CVE-2026-19144 | 8.8 | 28.4 | Chrome | CWE-416 | Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a rem… | |
| CVE-2026-19169 | 8.8 | 28.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in Contextual Tasks in Google Chro… | |
| CVE-2026-19064 | 5.3 | 28.5 | SourceCodester | Online Examination & Learning Management System | CWE-285 | SourceCodester Online Examination & Learning Management System view.php autho… |
| CVE-2026-19138 | 8.3 | 28.4 | Chrome | CWE-122 | Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.1… | |
| CVE-2026-5423 | 8.2 | 28.3 | neo4j | graphql | CWE-302 | Subscription Authentication Bypass via Unverified connectionParams.jwt |
| CVE-2026-71326 | 2.1 | 28.2 | traefik | traefik | CWE-287 | Traefik: BasicAuth singleflight key collision allows authenticated identity s… |
| CVE-2026-61632 | 5.3 | 28.2 | facelessuser | pymdown-extensions | CWE-22 | PyMdown Extensions: Path traversal in the b64 extension lets <img src> read f… |
| CVE-2026-19153 | 8.1 | 27.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in Workers in Google Chrome prior … | |
| CVE-2026-70646 | 7.5 | 27.6 | vovchic17 | aiosend | CWE-400 | aiosend: Deserialization of request body before signature verification (Pre-a… |
| CVE-2026-34191 | 9.1 | 27.5 | Apache Software Foundation | Apache Portable Runtime Utility | CWE-89 | Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle |
| CVE-2026-48083 | 6.5 | 27.5 | open-reception | appointment-booking-software | CWE-117 | OpenReception: Unauthenticated POST /api/log accepts arbitrary content with C… |
| CVE-2026-19146 | 5.3 | 27.5 | Chrome | CWE-457 | Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 … | |
| CVE-2026-19154 | 8.3 | 27.3 | Chrome | CWE-416 | Use after free in Skia in Google Chrome on Android prior to 151.0.7922.109 al… | |
| CVE-2026-19172 | 8.3 | 27.3 | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a re… | |
| CVE-2026-71488 | 7.5 | 27.1 | thephpleague | commonmark | CWE-407 | league/commonmark: Quadratic-time denial of service when parsing crafted Mark… |
| CVE-2026-57818 | 8.1 | 27.0 | Apache Software Foundation | Apache CXF | CWE-367 | Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProv… |
| CVE-2026-49391 | 5.1 | 26.8 | frappe | frappe | CWE-79 | Frappe: Stored XSS in Column Headers via Data Import |
| CVE-2026-3415 | 8.7 | 26.8 | WSO2 | WSO2 API Manager | CWE-776 | XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Pr… |
| CVE-2026-19008 | 2.1 | 26.8 | mf-yang | openclaw-cn | CWE-59 | mf-yang openclaw-cn apply_patch Tool sandbox-paths.ts assertNoSymlinkEscape l… |
| CVE-2026-70557 | 7.1 | 26.3 | diboot | diboot-core | CWE-639 | diboot-core Authenticated Arbitrary Field Read via loadRelatedData Discloses … |
| CVE-2026-19152 | 8.3 | 26.1 | Chrome | CWE-693 | Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0… | |
| CVE-2026-19038 | 2.1 | 26.1 | MonomythDevelopment | la-forge-mcp | CWE-22 | MonomythDevelopment la-forge-mcp screenshot_element Tool index.ts screenshotE… |
| CVE-2026-48086 | 9.9 | 25.8 | open-reception | appointment-booking-software | CWE-269 | OpenReception: Tenant admin self-promotes to GLOBAL_ADMIN |
| CVE-2026-43632 | 9.2 | 25.3 | ggml-org | llama.cpp | CWE-416 | llama.cpp b7492–b9060 Use-After-Free in Tokenization Endpoints |
| CVE-2026-70559 | 8.7 | 25.2 | DataLinkDC | Dinky | CWE-306 | Dinky Unauthenticated System Configuration and Credential Disclosure via GET … |
| CVE-2026-53983 | 9.2 | 24.8 | Efstratios Goudelis | Ground Station | CWE-918 | Ground Station prior to 0.6.0 Unauthenticated Persistent Blind Server-Side Re… |
| CVE-2026-45414 | 8.5 | 24.6 | decidim | decidim | CWE-639 | Decidim: JWT-backed authentication can be replayed across organizations |
| CVE-2026-19140 | 8.3 | 24.6 | Chrome | CWE-416 | Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remo… | |
| CVE-2026-19147 | 8.3 | 24.6 | Chrome | CWE-416 | Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allo… | |
| CVE-2026-19148 | 8.3 | 24.6 | Chrome | CWE-787 | Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 … | |
| CVE-2026-19155 | 8.3 | 24.6 | Chrome | CWE-416 | Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a… | |
| CVE-2026-19163 | 8.3 | 24.6 | Chrome | CWE-416 | Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 a… | |
| CVE-2026-19173 | 8.3 | 24.6 | Chrome | CWE-787 | Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed … | |
| CVE-2026-64655 | 2.1 | 24.7 | cli | cli | CWE-185 | GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacter… |
| CVE-2026-28005 | 9.8 | 24.4 | Nexcess | Kadence WooCommerce Email Designer | CWE-862 | WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19 - Privilege Esc… |
| CVE-2026-65507 | 9.8 | 24.4 | Sergey | AIWU | CWE-266 | WordPress AIWU plugin <= 1.5.6 - Privilege Escalation vulnerability |
| CVE-2026-19161 | 3.1 | 24.3 | Chrome | CWE-457 | Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a … | |
| CVE-2026-71445 | 8.2 | 24.1 | ail-project | ail-framework | CWE-79 | Authenticated Reflected Cross-Site Scripting in Tag Error Responses in ail-fr… |
| CVE-2026-28146 | 6.5 | 24.1 | Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | CWE-22 | WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) … |
| CVE-2026-19069 | 2.1 | 24.1 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System treatmentrecord.php sql injection |
| CVE-2026-19070 | 2.1 | 24.1 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System viewadmin.php sql injection |
| CVE-2026-19071 | 2.1 | 24.1 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System viewappointment.php sql injection |
| CVE-2026-18487 | 5.4 | 23.6 | GNOME | Epiphany | CWE-451 | Epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_ho… |
| CVE-2026-19062 | 5.5 | 23.5 | chiuwingyan | house | CWE-74 | chiuwingyan house selectall.action sql injection |
| CVE-2026-64665 | 8.1 | 23.3 | statamic | cms | CWE-287 | Statamic: Account takeover via OAuth email matching without email-verificatio… |
| CVE-2026-18974 | 5.5 | 23.3 | heshengtao | super-agent-party | CWE-200 | heshengtao super-agent-party execute_tool_manually Endpoint server.py get_fil… |
| CVE-2026-18258 | 8.8 | 23.2 | Scripta | eScriptorium | CWE-639 | Authorization Bypass Through User-Controlled Key in eScriptorium |
| CVE-2026-14831 | 5.3 | 23.2 | Unknown | Easy Booking | CWE-602 | Easy Booking < 3.5.0 - Unauthenticated Minimum Booking Duration Bypass |
| CVE-2026-45573 | 6.4 | 23.0 | decidim | decidim | CWE-918 | Decidim: Push subscriptions can be abused for server-side requests |
| CVE-2026-65559 | 7.2 | 22.8 | tychesoftwares | Order Delivery Date for WooCommerce | CWE-266 | WordPress Order Delivery Date for WooCommerce plugin <= 4.6.0 - Privilege Esc… |
| CVE-2026-66470 | 7.1 | 22.8 | Shabti Kaplan | Frontend Admin by DynamiApps | CWE-862 | WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Broken Access Cont… |
| CVE-2026-48077 | 5.3 | 22.8 | open-reception | appointment-booking-software | CWE-862 | OpenReception: GET appointment by ID returns full appointment record without … |
| CVE-2026-16636 | 7.2 | 22.6 | wpmanageninja | FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, Mailgun, Postmark, Cloudflare, toSend, Gmail and Any SMTP | CWE-79 | FluentSMTP <= 2.2.95 - Unauthenticated Stored Cross-Site Scripting via Recipi… |
| CVE-2026-65554 | 7.1 | 22.7 | lattepress | AnsPress – Question and answer | CWE-862 | WordPress AnsPress – Question and answer plugin 4.4.4 - Broken Access Control… |
| CVE-2026-64662 | 6.5 | 22.5 | statamic | cms | CWE-639 | Statamic: Missing authorization on navigation endpoint allows disclosure of r… |
| CVE-2026-19019 | 2.9 | 22.5 | poco-ai | poco-agent | CWE-459 | poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_p… |
| CVE-2026-65556 | 9.8 | 22.5 | MihChe | WPBruiser {no- Captcha anti-Spam} | CWE-502 | WordPress WPBruiser {no- Captcha anti-Spam} plugin <= 3.1.43 - PHP Object Inj… |
| CVE-2026-65571 | 9.8 | 22.5 | Axiomthemes | 69 Clothing | CWE-502 | WordPress 69 Clothing theme <= 1.2.11.1 - PHP Object Injection vulnerability |
| CVE-2026-65572 | 9.8 | 22.5 | Axiomthemes | A.Williams | CWE-502 | WordPress A.Williams theme <= 1.3.1 - PHP Object Injection vulnerability |
| CVE-2026-65573 | 9.8 | 22.5 | ThemeREX | Abelle | CWE-502 | WordPress Abelle theme <= 1.22 - PHP Object Injection vulnerability |
| CVE-2026-65574 | 9.8 | 22.5 | AncoraThemes | Abogado | CWE-502 | WordPress Abogado theme <= 1.18 - PHP Object Injection vulnerability |
| CVE-2026-65575 | 9.8 | 22.5 | AncoraThemes | Accalia | CWE-502 | WordPress Accalia theme <= 1.5.3 - PHP Object Injection vulnerability |
| CVE-2026-65576 | 9.8 | 22.5 | AncoraThemes | Adrena | CWE-502 | WordPress Adrena theme <= 1.2.14 - PHP Object Injection vulnerability |
| CVE-2026-65577 | 9.8 | 22.5 | AncoraThemes | Advice | CWE-502 | WordPress Advice theme <= 1.18.0 - PHP Object Injection vulnerability |
| CVE-2026-65578 | 9.8 | 22.5 | AncoraThemes | Agora | CWE-502 | WordPress Agora theme <= 1.9 - PHP Object Injection vulnerability |
| CVE-2026-65579 | 9.8 | 22.5 | axiomthemes | Agricola | CWE-502 | WordPress Agricola theme <= 1.21.0 - PHP Object Injection vulnerability |
| CVE-2026-65581 | 9.8 | 22.5 | Axiomthemes | AI ANN | CWE-502 | WordPress AI ANN theme <= 1.29.0 - PHP Object Injection vulnerability |
| CVE-2026-1728 | 9.8 | 22.3 | WSO2 | WSO2 API Manager | CWE-269 | Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits A… |
| CVE-2026-45378 | 7.5 | 22.3 | decidim | decidim | CWE-200 | Decidim: Verification documents can be downloaded through reusable links |
| CVE-2026-18973 | 5.5 | 21.8 | heshengtao | super-agent-party | CWE-918 | heshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_u… |
| CVE-2026-64663 | 6.5 | 21.6 | statamic | cms | CWE-470 | Statamic: Unsafe method invocation via Antlers template resolution allows dat… |
| CVE-2026-66710 | 8.1 | 21.4 | E2Pdf | e2pdf | CWE-98 | WordPress e2pdf plugin <= 1.32.40 - Local File Inclusion vulnerability |
| CVE-2026-48088 | 9.4 | 21.3 | open-reception | appointment-booking-software | CWE-862 | OpenReception vulnerable to unauthenticated staff crypto poisoning that break… |
| CVE-2026-12605 | 9.6 | 21.2 | Eclipse Foundation | Eclipse GlassFish | CWE-918 | In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServ… |
| CVE-2026-19000 | 5.5 | 21.0 | n/a | JeecgBoot | CWE-918 | JeecgBoot Anonymous Chat Attachment send server-side request forgery |
| CVE-2026-14842 | 5.3 | 21.0 | Unknown | Events Made Easy | CWE-639 | Events Made Easy < 3.1.2 - Unauthenticated Payment Bypass |
| CVE-2026-66843 | 2.3 | 20.9 | rrrene | html_sanitize_ex | CWE-829 | html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, … |
| CVE-2026-65520 | 9.3 | 20.8 | miniOrange | WP OAuth Server | CWE-89 | WordPress WP OAuth Server plugin <= 6.2.0 - SQL Injection vulnerability |
| CVE-2026-17264 | 5.3 | 20.7 | Medixant | RadiAnt DICOM | CWE-787 | Medixant RadiAnt DICOM Out-of-bounds write |
| CVE-2026-66425 | 6.5 | 20.6 | Saad Iqbal | Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder | CWE-288 | WordPress Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Fo… |
| CVE-2026-19127 | 6.5 | 20.6 | GitroomHQ | postiz-app | CWE-345 | Insufficient verification of lifetime-deal redemption codes allows forgery of… |
| CVE-2026-65508 | 9.3 | 20.2 | NSquared | Simply Schedule Appointments | CWE-89 | WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - SQL Injection vu… |
| CVE-2026-13399 | 7.5 | 20.3 | Unknown | Payment Plugins for PayPal WooCommerce | CWE-639 | Payment Plugins for PayPal WooCommerce < 2.0.20 - Unauthenticated Payment Byp… |
| CVE-2026-66665 | 10.0 | 20.1 | Brandexponents | Type Hub | CWE-434 | WordPress Type Hub plugin <= 2.0.6 - Arbitrary File Upload vulnerability |
| CVE-2026-18995 | 2.1 | 20.1 | netease-youdao | LobsterAI | CWE-200 | netease-youdao LobsterAI MEDIA Path artifactParser.ts parseMediaTokensFromTex… |
| CVE-2026-48074 | 2.7 | 19.9 | open-reception | appointment-booking-software | CWE-863 | OpenReception: Staff deletion removes pending invites cross-tenant by email m… |
| CVE-2026-18325 | 7.2 | 19.8 | wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | CWE-79 | Forminator Forms <= 1.56.1 - Unauthenticated Stored Cross-Site Scripting via … |
| CVE-2026-28111 | 8.8 | 19.7 | WPMU DEV | Forminator | CWE-266 | WordPress Forminator plugin <= 1.56.0 - Privilege Escalation vulnerability |
| CVE-2026-64598 | 8.8 | 19.7 | Linux | Linux | — | smb/client: Fix error code in smb2_aead_req_alloc() |
| CVE-2026-65504 | 7.5 | 19.7 | ivanbebek | BOX NOW Delivery Croatia | CWE-862 | WordPress BOX NOW Delivery Croatia plugin <= 3.3.0 - Broken Access Control vu… |
| CVE-2026-65523 | 7.5 | 19.7 | approveme | Formidable Forms Signature Online Contract Automation | CWE-639 | WordPress Formidable Forms Signature Online Contract Automation plugin <= 2.0… |
| CVE-2026-48080 | 8.0 | 19.5 | open-reception | appointment-booking-software | CWE-200 | OpenReception's tenant detail endpoint discloses live PostgreSQL connection s… |
| CVE-2026-16731 | 8.3 | 19.4 | OMICRON electronics GmbH | OMICRON StationScout | CWE-208 | Authentication and authorization bypass via cryptographic timing side-channel… |
| CVE-2026-16054 | 9.1 | 19.3 | Unknown | Drag and Drop Multiple File Upload for WooCommerce | CWE-73 | Drag and Drop Multiple File Upload for WooCommerce < 1.1.8 - Unauthenticated … |
| CVE-2026-67621 | 7.2 | 19.2 | FlowiseAI | Flowise | CWE-862 | Flowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints |
| CVE-2026-19066 | 5.3 | 19.2 | SourceCodester | Online Examination & Learning Management System | CWE-285 | SourceCodester Online Examination & Learning Management System view_students.… |
| CVE-2026-10524 | 7.5 | 18.8 | Unknown | CoCart | CWE-472 | CoCart < 4.9.0 - Unauthenticated Arbitrary Price Manipulation |
| CVE-2026-65547 | 8.5 | 18.6 | Constant Contact | Creative Mail | CWE-89 | WordPress Creative Mail plugin <= 1.6.9 - SQL Injection vulnerability |
| CVE-2026-65569 | 8.5 | 18.6 | wpjobportal | WP Job Portal | CWE-89 | WordPress WP Job Portal plugin <= 2.5.6 - SQL Injection vulnerability |
| CVE-2026-63687 | 9.1 | 18.0 | Apache Software Foundation | Apache CXF | CWE-345 | Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce para… |
| CVE-2026-5134 | 9.8 | 17.9 | Loca Software Informatics Technology Ltd. Co. | CMS | CWE-89 | SQLi in Loca Software's CMS |
| CVE-2026-18276 | 4.3 | 18.0 | Scripta | eScriptorium | CWE-862 | Missing Authorization in eScriptorium |
| CVE-2026-66695 | 6.5 | 17.8 | BoldGrid | W3 Total Cache | CWE-35 | WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability |
| CVE-2026-65583 | 9.1 | 17.6 | Apache Software Foundation | Apache CXF | CWE-345 | Apache CXF: Self-issued ID token claims validation skipped |
| CVE-2026-19165 | 7.5 | 17.6 | Chrome | CWE-416 | Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed… | |
| CVE-2026-19021 | 5.5 | 17.7 | SourceCodester | Computer Repair Shop Management System | CWE-74 | SourceCodester Computer Repair Shop Management System Master.php delete_produ… |
| CVE-2026-12713 | 9.1 | 17.6 | Unknown | WPCargo Track & Trace | CWE-89 | WPCargo Track & Trace < 8.0.4 - Unauthenticated SQL Injection via wpcargo_tra… |
| CVE-2026-66662 | 9.8 | 17.4 | Shabti Kaplan | Frontend Admin by DynamiApps | CWE-266 | WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Privilege Escalati… |
| CVE-2026-16620 | 7.5 | 17.2 | Unknown | WPC Name Your Price for WooCommerce | CWE-472 | WPC Name Your Price for WooCommerce < 2.2.5 - Unauthenticated Price Manipulat… |
| CVE-2026-16315 | 8.1 | 17.1 | OMICRON electronics GmbH | OMICRON StationGuard | CWE-208 | Authentication and authorization bypass via cryptographic timing side-channel… |
| CVE-2026-63725 | 8.6 | 17.0 | nuxsmin | sysPass | CWE-78 | sysPass FileBackupService Authenticated OS Command Injection via Backup Path |
| CVE-2026-13153 | 7.5 | 16.9 | Unknown | Gutenberg Essential Blocks | CWE-200 | Essential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure … |
| CVE-2026-13154 | 7.5 | 16.9 | Unknown | Gutenberg Essential Blocks | CWE-200 | Essential Blocks < 6.4.0 - Unauthenticated Non-Public Custom Post Type Conten… |
| CVE-2026-18050 | 7.5 | 16.9 | Unknown | Events Manager | CWE-200 | Events Manager < 7.4 - Unauthenticated Pending Upload Disclosure via events-m… |
| CVE-2026-19156 | 7.5 | 16.9 | Chrome | CWE-122 | Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed… | |
| CVE-2024-6541 | 6.8 | 16.9 | WSO2 | WSO2 Micro Integrator | CWE-20 | Information Disclosure and Integrity Violation via Improper Message Context H… |
| CVE-2026-19065 | 5.3 | 16.9 | SourceCodester | Online Examination & Learning Management System | CWE-284 | SourceCodester Online Examination & Learning Management System upload_files.p… |
| CVE-2026-65542 | 8.8 | 16.7 | Rajat Varlani | Super Socializer | CWE-288 | WordPress Super Socializer plugin <= 7.14.5 - Broken Authentication vulnerabi… |
| CVE-2026-63637 | 8.6 | 16.7 | dgraph-io | dgraph | CWE-943 | Dgraph: DQL Injection via unvalidated regexp filter argument in GraphQL query… |
| CVE-2026-68747 | 2.3 | 16.6 | rrrene | html_sanitize_ex | CWE-74 | CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input |
| CVE-2026-19110 | 1.9 | 16.6 | n/a | DataGear | CWE-79 | DataGear Chart Name HtmlTplDashboardWidgetHtmlRenderer.java HtmlTplDashboardW… |
| CVE-2026-5856 | 7.1 | 16.5 | Contiki-NG | Contiki-NG | CWE-125 | Contiki-NG DNS/mDNS Resolver Out-of-Bounds Read via Unchecked skip_name Trave… |
| CVE-2026-11983 | 5.3 | 16.2 | spacetime | Ad Inserter – Ad Manager & AdSense Ads | CWE-862 | Ad Inserter <= 2.8.16 - Missing Authorization to Block Visibility Bypass via … |
| CVE-2026-64664 | 4.3 | 16.2 | statamic | cms | CWE-200 | Statamic: Missing authorization on Control Panel endpoint allows disclosure o… |
| CVE-2026-48078 | 5.3 | 16.0 | open-reception | appointment-booking-software | CWE-200 | OpenReception's schedule endpoint discloses isPublic=false channels and slot … |
| CVE-2026-19067 | 2.1 | 16.1 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System treatment.php sql injection |
| CVE-2026-19068 | 2.1 | 16.1 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System treatmentdetail.php sql injection |
| CVE-2026-62857 | 8.8 | 16.0 | fedify-dev | fedify | CWE-918 | Fedify: Server-Side Request Forgery in getNodeInfo() Allows Access to Interna… |
| CVE-2026-64586 | 8.8 | 16.0 | Linux | Linux | — | wifi: brcmfmac: drain bus_reset work on device removal |
| CVE-2026-16954 | 6.5 | 16.0 | Unknown | AI Engine | CWE-200 | AI Engine < 3.6.4 - Editor+ Sensitive Information Disclosure of API Key and B… |
| CVE-2026-67622 | 8.5 | 15.7 | FlowiseAI | Flowise | CWE-639 | Flowise 3.1.4 IDOR in OpenAI Assistants Integration |
| CVE-2026-71446 | 6.9 | 15.8 | ail-project | ail-framework | CWE-79 | Stored Cross-Site Scripting in AIL Framework Domain Screenshot View |
| CVE-2026-13342 | 5.3 | 15.5 | Unknown | Security Optimizer | CWE-693 | Security Optimizer – The All-In-One Protection Plugin < 1.6.5 - Login Access … |
| CVE-2026-18996 | 2.1 | 15.4 | cosmicstack-labs | mercury-agent | CWE-266 | cosmicstack-labs mercury-agent run_command permissions.ts PermissionManager.c… |
| CVE-2026-19040 | 2.1 | 15.4 | MissionSquad | mcp-api | CWE-918 | MissionSquad mcp-api dcrClients.ts server-side request forgery |
| CVE-2026-18510 | 7.2 | 15.2 | cozmoslabs | TranslatePress – Translate Multilingual sites with AI Translation | CWE-79 | TranslatePress <= 3.2.6 - Unauthenticated Stored Cross-Site Scripting via Com… |
| CVE-2026-18400 | 6.4 | 15.2 | metaslider | Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider | CWE-79 | Slider, Gallery, and Carousel by MetaSlider <= 3.111.0 - Authenticated (Autho… |
| CVE-2026-48076 | 6.5 | 15.1 | open-reception | appointment-booking-software | CWE-863 | OpenReception's bootstrap booking flow allows unauthenticated booking on isPu… |
| CVE-2026-3430 | 8.6 | 15.0 | Unknown | Creative Mail | CWE-89 | Creative Mail 1.6.5 - 1.6.9 - Unauthenticated SQLi |
| CVE-2024-6832 | 7.5 | 14.9 | WSO2 | WSO2 Enterprise Integrator | CWE-693 | Account Lockout Failure via Secondary User Store Inaccessibility in Multiple … |
| CVE-2026-54717 | 5.4 | 14.9 | silverstripe | silverstripe-cms | CWE-79 | Silverstripe: XSS in breadcrumbs in page list view |
| CVE-2026-71434 | 5.3 | 14.9 | statamic | cms | CWE-434 | Statamic: Missing file upload validation on frontend forms allows uploading d… |
| CVE-2025-12317 | 5.0 | 14.9 | WSO2 | WSO2 Enterprise Integrator | CWE-613 | Improper Token Revocation via SOAP Services in Multiple WSO2 Products Allows … |
| CVE-2026-28140 | 7.5 | 14.6 | jetmonsters | JetFormBuilder | CWE-862 | WordPress JetFormBuilder plugin <= 3.6.4.1 - Broken Access Control vulnerability |
| CVE-2026-18277 | 7.1 | 14.5 | Scripta | eScriptorium | CWE-862 | Missing Authorization in eScriptorium |
| CVE-2026-15149 | 5.3 | 14.4 | Unknown | WP Hotel Booking | CWE-20 | WP Hotel Booking < 2.3.3 - Unauthenticated Payment Bypass via Price Manipulation |
| CVE-2026-16067 | 5.3 | 14.4 | Unknown | Event Booking Manager for WooCommerce (Pro) | CWE-472 | Event Booking Manager for WooCommerce (Pro) < 5.0.3 - Unauthenticated Payment… |
| CVE-2026-16619 | 7.5 | 14.2 | Unknown | miniOrange 2FA | CWE-307 | miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts |
| CVE-2026-66452 | 6.5 | 14.2 | IT-Recht Kanzlei | Legal Text Connector of the IT-Recht Kanzlei | CWE-862 | WordPress Legal Text Connector of the IT-Recht Kanzlei plugin <= 1.0.13 - Bro… |
| CVE-2026-14314 | 5.3 | 14.2 | Unknown | PeproDev WooCommerce Receipt Uploader | CWE-200 | PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Image Attach… |
| CVE-2026-71447 | 6.9 | 14.1 | ail-project | ail-framework | CWE-79 | Stored Cross-Site Scripting in Chat and Forum Translation Controls in ail-fra… |
| CVE-2026-68480 | await | 14.1 | Linux | Linux | — | x86/bugs: Make Safe-RET robust against interrupt injection |
| CVE-2026-28169 | 5.3 | 14.0 | YITHEMES | YITH WooCommerce Zoom Magnifier | CWE-497 | WordPress YITH WooCommerce Zoom Magnifier plugin <= 2.52.0 - Sensitive Data E… |
| CVE-2026-66683 | 5.3 | 14.0 | WP Zone | Custom CSS and JavaScript | CWE-201 | WordPress Custom CSS and JavaScript plugin <= 2.0.16 - Sensitive Data Exposur… |
| CVE-2026-66684 | 5.3 | 14.0 | Akshay Menariya | Export Import Menus | CWE-201 | WordPress Export Import Menus plugin <= 1.9.2 - Sensitive Data Exposure vulne… |
| CVE-2026-32469 | 5.3 | 13.9 | WPKube | CAPTCHA 4WP | CWE-290 | WordPress CAPTCHA 4WP plugin <= 7.6.0 - Captcha Bypass vulnerability |
| CVE-2026-65502 | 5.3 | 13.9 | bdthemes | Element Pack Elementor Addons | CWE-290 | WordPress Element Pack Elementor Addons plugin <= 8.7.13 - Captcha Bypass vul… |
| CVE-2026-16065 | 6.5 | 13.7 | Unknown | Welcart e-Commerce | CWE-89 | Welcart e-Commerce < 2.11.32 - Editor+ SQL Injection via CSV Import |
| CVE-2026-14225 | 2.7 | 13.6 | Unknown | Easy Appointments | CWE-20 | Easy Appointments < 3.12.28 - Contributor+ Shortcode Allowlist Bypass |
| CVE-2026-65546 | 9.3 | 13.5 | QODE | Qode Tours | CWE-89 | WordPress Qode Tours plugin <= 3.1.3.1 - SQL Injection vulnerability |
| CVE-2026-66447 | 9.3 | 13.5 | nickboss | WordPress File Upload | CWE-89 | WordPress WordPress File Upload plugin <= 5.1.7 - SQL Injection vulnerability |
| CVE-2026-66370 | 4.8 | 13.4 | rrrene | html_sanitize_ex | CWE-601 | html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attr… |
| CVE-2026-70637 | 8.2 | 13.2 | hfiref0x | LightFTP | CWE-820 | LightFTP 2.4 Data Race Condition via ABOR Command in ftpserv.c |
| CVE-2026-65570 | 8.1 | 13.2 | Hamid Alinia | Login with phone number | CWE-290 | WordPress Login with phone number plugin <= 1.8.70 - Bypass vulnerability vul… |
| CVE-2026-18275 | 6.5 | 13.2 | Scripta | eScriptorium | CWE-639 | Authorization Bypass Through User-Controlled Key in eScriptorium |
| CVE-2026-65551 | 7.5 | 13.0 | Soflyy | Breakdance | CWE-862 | WordPress Breakdance plugin < 2.7 - Broken Access Control vulnerability |
| CVE-2026-66451 | 6.5 | 13.0 | Arraytics | WP Event SOlution | CWE-288 | WordPress WP Event SOlution plugin <= 4.1.9 - Broken Authentication vulnerabi… |
| CVE-2026-71433 | 5.3 | 13.0 | langchain-ai | langgraph | CWE-200 | LangGraph: Namespace prefix matching crosses segment boundaries in Postgres a… |
| CVE-2026-5430 | 10.0 | 12.7 | WSO2 | WSO2 Universal Gateway | CWE-347 | Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Al… |
| CVE-2026-28180 | 5.3 | 12.4 | Mercado Pago | Mercado Pago payments for WooCommerce | CWE-639 | WordPress Mercado Pago payments for WooCommerce plugin <= 8.9.0 - Insecure Di… |
| CVE-2026-32548 | 5.3 | 12.4 | SureCart | SureCart | CWE-862 | WordPress SureCart plugin <= 4.6.2 - Broken Access Control vulnerability |
| CVE-2026-18359 | 8.5 | 12.3 | Scripta | eScriptorium | CWE-918 | Server-Side Request Forgery (SSRF) in eScriptorium |
| CVE-2025-15674 | 2.7 | 12.0 | Unknown | Passster | CWE-863 | Content Protector (Passster) < 4.3.7 - Contributor+ Protected Content Disclos… |
| CVE-2026-19037 | 2.1 | 11.8 | n/a | WonderTrader | CWE-840 | WonderTrader Internal Limit Order Book Cache MatchEngine.cpp update_lob behav… |
| CVE-2026-66708 | 8.2 | 11.7 | BoldGrid | Total Upkeep | CWE-862 | WordPress Total Upkeep plugin <= 1.17.2 - Broken Access Control vulnerability |
| CVE-2026-18993 | 2.1 | 11.6 | NousResearch | hermes-agent | CWE-266 | NousResearch hermes-agent Memory Toolset model_tools.py access control |
| CVE-2026-65541 | 7.3 | 11.4 | solutioned | Staff Training | CWE-862 | WordPress Staff Training plugin <= 1.0.7 - Broken Access Control vulnerability |
| CVE-2026-66712 | 7.5 | 11.1 | wp.insider | Simple Membership | CWE-862 | WordPress Simple Membership plugin <= 4.7.8 - Broken Access Control vulnerabi… |
| CVE-2026-0673 | 5.3 | 11.1 | bdthemes | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons | CWE-93 | Element Pack Addons for Elementor <= 8.3.15 - Unauthenticated SMTP Header Inj… |
| CVE-2026-16290 | 5.3 | 11.0 | Unknown | ProfileGrid | CWE-862 | ProfileGrid < 6.0.0.0 - Unauthenticated Group Member List Disclosure via pm_g… |
| CVE-2026-70638 | 8.5 | 10.9 | ggml-org | llama.cpp | CWE-190 | llama.cpp b1886–b7445 Integer Overflow via new_1batch() in llama-android.cpp |
| CVE-2026-18976 | 2.1 | 11.0 | NousResearch | hermes-agent | CWE-266 | NousResearch hermes-agent disabled_toolsets agent_init.py get_tool_definition… |
| CVE-2026-18992 | 2.1 | 11.0 | zhayujie | CowAgent | CWE-285 | zhayujie CowAgent Self-Evolution Review Agent executor.py _select_tools autho… |
| CVE-2026-18997 | 2.1 | 11.0 | cosmicstack-labs | mercury-agent | CWE-285 | cosmicstack-labs mercury-agent bg agent.ts Agent.handleBgCommand authorization |
| CVE-2026-18998 | 2.1 | 11.0 | cosmicstack-labs | mercury-agent | CWE-266 | cosmicstack-labs mercury-agent delegate_task Tool sub-agent.ts SubAgent.run i… |
| CVE-2026-19005 | 2.1 | 11.0 | nanocoai | NanoClaw | CWE-266 | nanocoai NanoClaw Child-Agent Creation create-agent.ts handleCreateAgent priv… |
| CVE-2026-19006 | 2.1 | 11.0 | mf-yang | openclaw-cn | CWE-285 | mf-yang openclaw-cn Ggateway Exec Approval Flow bash-tools.exec.ts authorization |
| CVE-2026-19007 | 2.1 | 11.0 | mf-yang | openclaw-cn | CWE-266 | mf-yang openclaw-cn reply-elevated.ts isApprovedElevatedSender privileges man… |
| CVE-2026-70632 | 8.5 | 10.6 | FFmpeg | FFmpeg | CWE-787 | FFmpeg 4.4 < 9.0 Heap Out-of-Bounds Write in CFHD Decoder via AVI Demuxing |
| CVE-2026-14240 | 5.3 | 10.6 | Unknown | tourmaster | CWE-200 | Tourmaster < 5.4.9 - Unauthenticated Sensitive Data Disclosure via Order Export |
| CVE-2026-66692 | 4.3 | 10.6 | Colissimo | Colissimo Officiel : Méthodes de livraison pour WooCommerce | CWE-639 | WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin … |
| CVE-2026-61959 | 6.5 | 10.4 | Strategy11 Team | Business Directory | CWE-79 | WordPress Business Directory plugin <= 6.4.24 - Cross Site Scripting (XSS) vu… |
| CVE-2025-13909 | 4.3 | 10.5 | WSO2 | WSO2 Identity Server | CWE-20 | Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity… |
| CVE-2026-19059 | 1.9 | 10.1 | FoundationAgents | MetaGPT | CWE-22 | FoundationAgents MetaGPT editor.py read path traversal |
| CVE-2026-43628 | 8.5 | 10.0 | ggml-org | llama.cpp | CWE-191 | llama.cpp b3978–b9058 Integer Underflow via DRY Sampler |
| CVE-2026-47194 | 8.6 | 9.9 | frappe | frappe | CWE-346 | Frappe: Host header poisoning can redirect magic login links to an attacker-c… |
| CVE-2026-71478 | 6.1 | 9.8 | thephpleague | commonmark | CWE-79 | league/commonmark: AttributesExtension href/src unsafe-link filter bypass via… |
| CVE-2025-6508 | 4.3 | 9.8 | WSO2 | WSO2 API Manager | CWE-79 | User Interface Misrepresentation via Swagger UI Try-out Console in WSO2 API M… |
| CVE-2026-71438 | 2.4 | 9.7 | mermaid-js | mermaid | CWE-1321 | Mermaid configuration APIs allow prototype pollution |
| CVE-2026-19020 | 2.1 | 9.8 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System servicetype.php sql injection |
| CVE-2026-66711 | 7.1 | 9.6 | Amir Helzer | WooCommerce Multilingual & Multicurrency | CWE-79 | WordPress WooCommerce Multilingual & Multicurrency plugin <= 5.5.6 - Cross Si… |
| CVE-2026-14306 | 4.3 | 9.4 | Unknown | Tutor LMS | CWE-639 | Tutor LMS < 3.9.14 - Subscriber+ Paid Course Content Disclosure via Enrollmen… |
| CVE-2026-66678 | 4.3 | 9.4 | Justin Kruit | Advanced Custom Fields: Font Awesome Field | CWE-862 | WordPress Advanced Custom Fields: Font Awesome Field plugin <= 6.1.1 - Broken… |
| CVE-2026-16734 | 7.5 | 9.3 | Unknown | Stripe Payment Forms by WP Full Pay | CWE-862 | Stripe Payment Forms by WP Full Pay < 8.5.2 - Unauthenticated Payment Intent … |
| CVE-2026-14829 | 8.2 | 9.0 | Unknown | Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps | CWE-284 | Checkimate <= 1.0.13 - Unauthenticated License Deactivation via Hardcoded Secret |
| CVE-2026-66685 | 5.3 | 8.8 | Alex | Featured Video Plus | CWE-201 | WordPress Featured Video Plus plugin <= 2.3.3 - Sensitive Data Exposure vulne… |
| CVE-2026-71435 | 6.1 | 8.8 | statamic | cms | CWE-79 | Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Te… |
| CVE-2025-15028 | 7.2 | 8.7 | wpwax | FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More | CWE-79 | FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, P… |
| CVE-2026-71497 | 4.7 | 8.7 | jhy | jsoup | CWE-79 | jsoup: Cleaner may expose markup with custom raw-text elements |
| CVE-2026-25403 | 6.5 | 8.4 | bdthemes | Ultimate Store Kit Elementor Addons | CWE-862 | WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Broken Access… |
| CVE-2026-15256 | 4.8 | 8.4 | Unknown | Ninja Forms | CWE-74 | Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Que… |
| CVE-2025-14779 | 3.8 | 8.4 | WSO2 | WSO2 Identity Server | CWE-281 | Improper Access Control via Secret Type Management API in WSO2 Identity Server |
| CVE-2026-19058 | 1.9 | 8.3 | FoundationAgents | MetaGPT | CWE-74 | FoundationAgents MetaGPT data_interpreter.py DataInterpreter code injection |
| CVE-2026-19060 | 1.9 | 8.3 | FoundationAgents | MetaGPT | CWE-74 | FoundationAgents MetaGPT code injection |
| CVE-2026-66439 | 7.1 | 8.1 | BeRocket | Advanced AJAX Product Filters | CWE-79 | WordPress Advanced AJAX Product Filters plugin <= 3.2.0.3 - Cross Site Script… |
| CVE-2026-66440 | 7.1 | 8.1 | XplodedThemes | WPIDE – File Manager & Code Editor | CWE-79 | WordPress WPIDE – File Manager & Code Editor plugin <= 3.5.7 - Cross Site Scr… |
| CVE-2026-66457 | 7.1 | 8.1 | @msykes | Events Manager | CWE-79 | WordPress Events Manager plugin <= 7.4.1 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-66663 | 7.1 | 8.1 | Passionate Programmer Peter | WP Data Access | CWE-79 | WordPress WP Data Access plugin <= 5.5.79 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-66664 | 7.1 | 8.1 | SEO Squirrly | SEO Plugin by Squirrly SEO | CWE-79 | WordPress SEO plugin by Squirrly SEO plugin <= 14.2.0 - Cross Site Scripting … |
| CVE-2026-18597 | 8.5 | 8.0 | Foxit Software Inc. | Foxit PDF Services API | CWE-918 | Blind SSRF on Foxit PDF Services API |
| CVE-2026-14547 | 5.3 | 7.7 | Unknown | Estatik Real Estate Plugin | CWE-287 | Estatik Real Estate Plugin < 4.3.3 - Unauthenticated Arbitrary-Recipient Mail… |
| CVE-2026-19061 | 6.3 | 7.7 | Insta | InstaKNXServiceApp | CWE-345 | Insta InstaKNXServiceApp Firmware Update CreateWebClientAndDownloadFileList d… |
| CVE-2026-45572 | 4.8 | 7.6 | decidim | decidim | CWE-94 | Decidim: HTML content blocks allow stored script execution |
| CVE-2026-12584 | 7.5 | 7.4 | Unknown | Payment Gateway for Redsys & WooCommerce Lite | — | Payment Gateway for Redsys & WooCommerce Lite < 7.0.2 - Unauthenticated Payme… |
| CVE-2026-65517 | 7.1 | 7.4 | Scott Paterson | Easy PayPal Buy Now Button | CWE-79 | WordPress Easy PayPal Buy Now Button plugin <= 2.0.4 - Cross Site Scripting (… |
| CVE-2026-66699 | 5.3 | 7.4 | Dokan, Inc. | Dokan | CWE-862 | WordPress Dokan plugin <= 5.0.10 - Broken Access Control vulnerability |
| CVE-2026-66701 | 5.3 | 7.4 | Cozmoslabs | Profile Builder | CWE-862 | WordPress Profile Builder plugin <= 3.16.5 - Broken Access Control vulnerability |
| CVE-2025-11850 | 4.3 | 7.3 | WSO2 | WSO2 Identity Server | CWE-639 | Improper Implicit Association via User Store Initialization in WSO2 Identity … |
| CVE-2026-66696 | 4.3 | 7.1 | Nexcess | Gutenberg Blocks by Kadence Blocks | CWE-201 | WordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.7.8 - Sensitive Data… |
| CVE-2026-7867 | 7.8 | 7.0 | Red Hat | Red Hat Enterprise Linux 10 | CWE-863 | Udisks2: udisks2: local privilege escalation via as-user option spoofing |
| CVE-2026-28082 | 7.1 | 7.0 | Crocoblock. Jetimpex Inc. | JetEngine | CWE-79 | WordPress JetEngine plugin <= 3.8.13.1 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-28141 | 7.1 | 7.0 | Syed Balkhi | NextGEN Gallery | CWE-79 | WordPress NextGEN Gallery plugin <= 4.2.3 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-28143 | 7.1 | 7.0 | WPMU DEV | Forminator | CWE-79 | WordPress Forminator plugin <= 1.56.0 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-28177 | 7.1 | 7.0 | Daniel Iser | Popup Maker | CWE-79 | WordPress Popup Maker plugin <= 1.23.0 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-61961 | 7.1 | 7.0 | WPDeveloper | EmbedPress | CWE-79 | WordPress EmbedPress plugin <= 4.5.6 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-61963 | 7.1 | 7.0 | David Lingren | Media LIbrary Assistant | CWE-79 | WordPress Media LIbrary Assistant plugin <= 3.38 - Cross Site Scripting (XSS)… |
| CVE-2026-61964 | 7.1 | 7.0 | WPManageNinja | Ninja Tables | CWE-79 | WordPress Ninja Tables plugin <= 5.2.9 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-61982 | 7.1 | 7.0 | jp-secure | SiteGuard WP Plugin | CWE-79 | WordPress SiteGuard WP Plugin plugin <= 1.8.6 - Cross Site Scripting (XSS) vu… |
| CVE-2026-65509 | 7.1 | 7.0 | wpDataTables | wpDataTables | CWE-79 | WordPress wpDataTables plugin <= 7.5.1 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-65513 | 7.1 | 7.0 | NSquared | Simply Schedule Appointments | CWE-79 | WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - Cross Site Scrip… |
| CVE-2026-65515 | 7.1 | 7.0 | AffiliateWP | AffiliateWP | CWE-79 | WordPress AffiliateWP plugin <= 2.35.0 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-65544 | 7.1 | 7.0 | Rajat Varlani | Super Socializer | CWE-79 | WordPress Super Socializer plugin <= 7.14.5 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-65545 | 7.1 | 7.0 | Jordy Meow | AI Engine | CWE-79 | WordPress AI Engine plugin <= 3.6.8 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-65560 | 7.1 | 7.0 | Property Hive | Houzez Property Feed | CWE-79 | WordPress Houzez Property Feed plugin <= 2.5.48 - Cross Site Scripting (XSS) … |
| CVE-2026-65565 | 7.1 | 7.0 | Ays Pro | Survey Maker | CWE-79 | WordPress Survey Maker plugin <= 5.2.3.3 - Cross Site Scripting (XSS) vulnera… |
| CVE-2024-10302 | 5.8 | 6.9 | WSO2 | WSO2 API Control Plane | CWE-20 | Improper Input Validation via Signup Process in Multiple WSO2 Products Enable… |
| CVE-2026-19143 | 8.6 | 6.6 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebAPKs in Google Chrome on And… | |
| CVE-2026-28179 | 5.9 | 6.7 | Damian Góra | FiboSearch | CWE-79 | WordPress FiboSearch plugin <= 1.33.0 - Cross Site Scripting (XSS) vulnerability |
| CVE-2025-13736 | 3.7 | 6.5 | WSO2 | WSO2 Identity Server as Key Manager | CWE-203 | Username Enumeration via Login Interface in Multiple WSO2 Products Allows Use… |
| CVE-2026-71555 | 4.1 | 6.2 | THM-Health | PILOS | CWE-1022 | PILOS: Reverse tabnabbing in room description |
| CVE-2026-64590 | await | 5.8 | Linux | Linux | — | dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning |
| CVE-2026-64593 | await | 5.8 | Linux | Linux | — | btrfs: do not trim a device which is not writeable |
| CVE-2026-64594 | await | 5.8 | Linux | Linux | — | usb: gadget: f_fs: initialize reset_work at allocation time |
| CVE-2026-64602 | await | 5.8 | Linux | Linux | — | iio: adc: spear: Initialize completion before requesting IRQ |
| CVE-2026-64604 | await | 5.8 | Linux | Linux | — | KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode |
| CVE-2026-64591 | await | 5.8 | Linux | Linux | — | iommu/vt-d: Avoid WARNING in sva unbind path |
| CVE-2026-11588 | 6.1 | 5.6 | Unknown | EONSR AEO Agent | CWE-79 | EONSR AEO Agent <= 3.7.9 - Unauthenticated Stored XSS via Scheduled Post Crea… |
| CVE-2026-10599 | 7.5 | 5.4 | Unknown | Integrate PhonePe with WooCommerce | CWE-345 | Integrate PhonePe with WooCommerce <= 1.2.1 - Unauthenticated Payment Bypass … |
Results continue: ranks 401–482.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-08-06 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.