boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Friday, August 7, 2026 · all times UTC← 2026-08-06 · archive · 2026-08-08 →

Security Box Score — August 7, 2026

215 CVEs published, led by Tobit Laboratories AG (22).

215 CVEs published August 7, 2026: 25 critical, 79 high, 92 medium, 19 low; 1 in the KEV catalog at press time; 3 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 190 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published190824072——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

1290 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux442359210125463711120.17.8.0016+7 ▲
google431804222743783567760.37.5.0025-9 ▼
microsoft33145512199132914286241.67.8.0047-17 ▼
red hat414272016521230200.06.5.0029+14 ▲
apple1272587813338872.66.8.0027+1 ▲
canonical02738115000.05.6.00140
suse52651461000.08.1.0039-1 ▼
freebsd01601240000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco30681336190561217.67.5.0046+22 ▲
ubiquiti036142110338.38.8.0049-25 ▼
palo alto networks025131471328.04.7.00280
fortinet0236611028626.17.2.00400
netgear02300221000.04.6.00240
vmware0174922715.98.3.00400
f50165830416.38.6.00570
checkpoint11346303215.47.8.0436+1 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache6139777176131123320.57.5.0050+11 ▲
mozilla11285142350900.08.1.0031-2 ▼
drupal05165355412.05.9.00260
gitlab05107377423.94.9.00290
github2141490000.06.2.0043+1 ▲
docker070520000.08.2.00160
wordpress1412102250.08.8.5550+1 ▲
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle01379343653322612730.28.1.00360
ibm3226172104841610.47.5.0031+32 ▲
adobe82603311710641931.27.8.0026+5 ▲
progress1153143270611.98.1.0037+9 ▲
solarwinds0231733010417.49.1.00580
veeam10165920100.08.6.0034+10 ▲
zohocorp062220000.07.8.01460
atlassian0303001300.08.0.00260
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology12426133000.05.6.0025+1 ▲
rockwell automation02441820000.08.7.00290
d-link0200596300.05.5.01050
siemens0161870000.07.6.00240
schneider electric091620000.08.6.00370
abb070430000.07.2.00180
hikvision060420000.07.2.00400
moxa050320000.07.0.00290
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester11131007061000.05.5.0033-16 ▼
openclaw01110583914000.07.0.00260
dell8107950453210.97.2.0021-15 ▼
nvidia16981366190000.07.7.0034-1 ▼
capgo083242381000.07.1.00370
spring079234412000.06.5.00220
imagemagick078156012000.05.3.0018-8 ▼
itsourcecode677001958000.02.1.0033-4 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.995799.99.8
CVE-2026-34486.986299.97.5
CVE-2026-63030.977999.99.8
CVE-2026-16232.891299.89.3
CVE-2026-63077.847399.79.8
CVE-2026-50522.846199.79.8
CVE-2026-15409.836699.710.0
CVE-2026-60137.797999.65.9
CVE-2026-6875.775899.59.5
CVE-2026-25089.761199.59.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1540910.0.8366KEV
CVE-2026-4893910.0.1973KEV
CVE-2026-5629110.0.1459KEV
CVE-2026-5972610.0.0688
CVE-2026-898510.0.0660
CVE-2026-651610.0.0486
CVE-2026-4766810.0.0388
CVE-2026-4633910.0.0335
CVE-2026-6144710.0.0249
CVE-2026-5782710.0.0233
Most disclosures (vendor)
VendorCVEs
oracle1109
linux842
microsoft646
google460
apache191
red hat174
apple168
ibm135
adobe113
mozilla69
Most KEV additions (YTD)
VendorKEV
microsoft24
cisco12
apple7
fortinet6
google6
ivanti5
solarwinds4
adobe3
berriai3
oracle3
Most-affected ecosystems
EcosystemAdvisories
Maven67
PyPI5
Go3
npm3
Packagist2
crates.io2
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2021-27137DD-WRT0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20316Cisco0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171724
CVE-2021-27102n/a2021-11-171724
CVE-2021-27101n/a2021-11-171724
CVE-2021-27103n/a2021-11-171724
CVE-2021-21017Adobe2021-11-171724
CVE-2021-28550Adobe2021-11-171724
CVE-2021-42013Apache Software Foundation2021-11-171724
CVE-2021-41773Apache Software Foundation2021-11-171724
CVE-2021-30858Apple2021-11-171724
CVE-2021-30860Apple2021-11-171724

Transactions

EXPLOIT PUBLISHED — itsourcecode Hospital Management System: 5 CVEs (CVE-2026-19067, CVE-2026-19068, CVE-2026-19069, CVE-2026-19070, CVE-2026-19071). Public exploit references added.

EXPLOIT PUBLISHED — fogproject: 4 CVEs (CVE-2026-47685, CVE-2026-47687, CVE-2026-47688, CVE-2026-47689). Public exploit references added.

EXPLOIT PUBLISHED — FlowiseAI Flowise: 3 CVEs (CVE-2026-67621, CVE-2026-67622, CVE-2026-70636). Public exploit references added.

EXPLOIT PUBLISHED — FoundationAgents MetaGPT: 3 CVEs (CVE-2026-19058, CVE-2026-19059, CVE-2026-19060). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2019-18184. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2022-24682. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2024-1086 (Linux Kernel). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-15674 (Unknown Passster). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-56005. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-10524 (Unknown CoCart). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-10599 (Unknown Integrate PhonePe with WooCommerce). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-10773 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-11361 (Unknown Formidable Forms). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-11976 (Unknown MonsterInsights Pro). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-12501 (Unknown WP Travel Engine). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-12584 (Unknown Payment Gateway for Redsys & WooCommerce Lite). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-12901 (Unknown GetPaid). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-13342 (Unknown Security Optimizer). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-13399 (Unknown Payment Plugins for PayPal WooCommerce). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-14225 (Unknown Easy Appointments). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-14306 (Unknown Tutor LMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-14812 (Unknown Premium SEO). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-14831 (Unknown Easy Booking). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-14842 (Unknown Events Made Easy). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-14936 (Unknown Simple Membership). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-15147 (Unknown Five Star Restaurant Reservations). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-15149 (Unknown WP Hotel Booking). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-15152 (Unknown WP Hotel Booking). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-15208 (Unknown RegistrationMagic). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-15256 (Unknown Ninja Forms). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16067 (Unknown Event Booking Manager for WooCommerce (Pro)). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16619 (Unknown miniOrange 2FA). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16620 (Unknown WPC Name Your Price for WooCommerce). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-17032 (Unknown google-maps-easy-pro). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19062 (chiuwingyan house). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19108 (MZ Automation libiec61850). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19110 (DataGear). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-2411 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-24486 (Kludex python-multipart). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-5336 (Unknown DataPress (Dataverse Integration)). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56816 (netty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56821 (netty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-66041 (FFmpeg). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-66758 (GNOME GIMP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-66759 (GNOME GIMP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-66838 (elixir-ecto postgrex). Public exploit reference added.

DUE DATE PASSED — CVE-2026-18577 (N-able N-central). CISA remediation deadline was August 6, 2026; still in catalog.

RESCORED — CVE-2022-2196 (Linux Kernel). CVSS 5.8 → 8.8 (NVD).

RESCORED — CVE-2023-46847 (squid). CVSS 8.6 → 7.5 (NVD).

RESCORED — CVE-2024-9675 (buildah). CVSS 7.8 → 4.4 (NVD).

RESCORED — CVE-2025-23366 (hal-console). CVSS 6.5 → 4.8 (NVD).

RESCORED — CVE-2026-24486 (Kludex python-multipart). CVSS 8.6 → 7.5 (NVD).

RESCORED — CVE-2026-43964 (Postfix). CVSS 3.7 → 7.5 (NVD).

RESCORED — CVE-2026-49875 (Apache Software Foundation Apache CXF). CVSS 6.5 → 9.8 (NVD).

RESCORED — CVE-2026-62836 (Microsoft Azure SQL Managed Instance). CVSS 8.7 → 10 (NVD).

ENRICHED — CVE-2019-18184. Received CVSS 9.8 and CPE data from NVD.

Yesterday's Results

How to read these box scores · glossary

215 CVEs published. 25 box scores, 190 table rows — nothing truncated.

Progress Software LoadMaster — OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .9957   99.9   YES
AFFECTED
  Product                          Versions     Fixed
  LoadMaster                       V7.2.60.0 –  —
  ECS Connections Manager          V7.2.60.0 –  —
  Object Scale Connection Manager  V7.2.60.0 –  —
  MOVEit WAF                       V7.2.60.0 –  —
TIMELINE
  May 6   Reserved by CNA
  Aug 6   Public exploit reference published
  Aug 7   Added to CISA KEV, due Aug 10
  Aug 7   Published (CNA: ProgressSoftware)
CWE-77 · CNA: ProgressSoftware · CVSS v3.1 · 4 references · NVD status: Analyzed · KEV due August 10, 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially craf…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   A   H   H   H    8.9   .3120   98.1     —
AFFECTED
  Product    Versions     Fixed
  WordPress  unspecified  —
TIMELINE
  Jul 20  Reserved by CNA
  Aug 7   Published (CNA: hackerone)
CWE-79 · CNA: hackerone · CVSS v4.0 · 2 references · NVD status: Received
HKUDS nanobot Shell Allowlist shell.py ExecTool._spawn os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0161   74.1     —
AFFECTED
  Product  Versions  Fixed
  nanobot  0.2.0 –   0.3.0
TIMELINE
  Aug 7   Reserved by CNA
  Aug 7   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 13 references · NVD status: Deferred
HKUDS LightRAG — LightRAG: Missing Authentication for Critical API Functions in Default Configuration
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0138   70.0     —
AFFECTED
  Product   Versions      Fixed
  LightRAG  < 1.5.5rc1 –  —
TIMELINE
  Jul 10  Reserved by CNA
  Aug 7   Published (CNA: GitHub_M)
CWE-306 · CNA: GitHub_M · CVSS v3.1 · 2 references · NVD status: Received
gitroomhq postiz-app — Unauthenticated arbitrary file read via /uploads path traversal (URL-encoded separators) leading to instance takeover
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0077   52.9     —
AFFECTED
  Product     Versions     Fixed
  postiz-app  unspecified  —
TIMELINE
  Aug 7   Reserved by CNA
  Aug 7   Published (CNA: postiz)
CWE-22 · CNA: postiz · CVSS v4.0 · 3 references · NVD status: Received
Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0069   49.9     —
AFFECTED
  Product       Versions     Fixed
  E-cology 9.0  unspecified  —
TIMELINE
  Aug 7   Reserved by CNA
  Aug 7   Published (CNA: VulnCheck)
CWE-434 · CNA: VulnCheck · CVSS v4.0 · 6 references · NVD status: Received
Sonatype Nexus Repository 3 — Nexus Repository 3 - Authorization Bypass in Repository Creation
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   N   H   N    8.2   .0061   46.7     —
AFFECTED
  Product             Versions  Fixed
  Nexus Repository 3  3.0.0 –   —
TIMELINE
  Jul 27  Reserved by CNA
  Aug 7   Published (CNA: Sonatype)
CWE-863 · CNA: Sonatype · CVSS v4.0 · 2 references · NVD status: Received
Apache Fory: Heap type confusion in C++ polymorphic smart-pointer deserialization
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0053   42.3     —
AFFECTED
  Product      Versions  Fixed
  Apache Fory  0.14.0 –  —
TIMELINE
  Aug 7   Reserved by CNA
  Aug 7   Published (CNA: apache)
CWE-843, CWE-502 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Analyzed
Cisco Cisco Secure Endpoint — ClamAV ZIP File Format Processing Memory Corruption Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0051   41.0     —
AFFECTED
  Product                Versions  Fixed
  Cisco Secure Endpoint  7.0.5 –   —
TIMELINE
  Oct 8   Reserved by CNA
  Aug 7   Published (CNA: cisco)
CWE-120 · CNA: cisco · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
Trilby Media grav-plugin-scheduler-webhook — Grav CMS Scheduler Webhook Authentication Bypass via Null Short-Circuit
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    6.9   .0051   40.9     —
AFFECTED
  Product                        Versions     Fixed
  grav-plugin-scheduler-webhook  unspecified  —
  getgrav/grav                   unspecified  —
TIMELINE
  Jun 5   Reserved by CNA
  Aug 7   Published (CNA: VulnCheck)
CWE-303 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Received
honojs hono — Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  L    5.3   .0049   39.8     —
AFFECTED
  Product  Versions     Fixed
  hono     < 4.12.34 –  —
TIMELINE
  Aug 3   Reserved by CNA
  Aug 7   Published (CNA: GitHub_M)
CWE-1333 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Received
Unknown Ajax Search Lite — Ajax Search Lite < 4.14.5 - Unauthenticated PHP Object Injection via Search Statistics REST Endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0047   38.7     —
AFFECTED
  Product           Versions     Fixed
  Ajax Search Lite  unspecified  —
TIMELINE
  Jul 20  Reserved by CNA
  Aug 7   Published (CNA: WPScan)
CWE-502 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Cisco Cisco Secure Endpoint — ClamAV ZIP File Format Processing Memory Corruption Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0047   38.6     —
AFFECTED
  Product                Versions  Fixed
  Cisco Secure Endpoint  7.0.5 –   —
TIMELINE
  Oct 8   Reserved by CNA
  Aug 7   Published (CNA: cisco)
CWE-415 · CNA: cisco · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
Tobit Laboratories AG TeamDavid — TeamDavid: Buffer Overflow in file names of file upload functionalities
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   H   H   H    9.5   .0047   38.2     —
AFFECTED
  Product    Versions     Fixed
  TeamDavid  unspecified  —
TIMELINE
  Jun 12  Reserved by CNA
  Aug 7   Published (CNA: NCSC.ch)
CWE-787 · CNA: NCSC.ch · CVSS v4.0 · 2 references · NVD status: Received
Tobit Laboratories AG TeamDavid — TeamDavid: Buffer Overflow in JSON-parsing
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   H   H   H    9.5   .0047   38.2     —
AFFECTED
  Product    Versions     Fixed
  TeamDavid  unspecified  —
TIMELINE
  Jun 12  Reserved by CNA
  Aug 7   Published (CNA: NCSC.ch)
CWE-787 · CNA: NCSC.ch · CVSS v4.0 · 2 references · NVD status: Received
Cisco Cisco Secure Endpoint — ClamAV PESpin File Format Processing Integer Overflow Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0046   38.0     —
AFFECTED
  Product                Versions  Fixed
  Cisco Secure Endpoint  7.0.5 –   —
TIMELINE
  Oct 8   Reserved by CNA
  Aug 7   Published (CNA: cisco)
CWE-190 · CNA: cisco · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
Cisco Cisco Secure Endpoint — ClamAV GPT File Format Processing Memory Corruption Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0046   38.0     —
AFFECTED
  Product                Versions  Fixed
  Cisco Secure Endpoint  1.12.3 –  —
TIMELINE
  Oct 8   Reserved by CNA
  Aug 7   Published (CNA: cisco)
CWE-121 · CNA: cisco · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
Cisco Cisco Secure Endpoint — ClamAV Mach-O File Format Processing Memory Corruption Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0046   38.0     —
AFFECTED
  Product                Versions  Fixed
  Cisco Secure Endpoint  7.0.5 –   —
TIMELINE
  Oct 8   Reserved by CNA
  Aug 7   Published (CNA: cisco)
CWE-125 · CNA: cisco · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
Cisco Cisco Secure Endpoint — ClamAV XAR File Format Processing Memory Corruption Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0046   38.0     —
AFFECTED
  Product                Versions  Fixed
  Cisco Secure Endpoint  7.0.5 –   —
TIMELINE
  Oct 8   Reserved by CNA
  Aug 7   Published (CNA: cisco)
CWE-120 · CNA: cisco · CVSS v3.1 · 1 reference · NVD status: Analyzed
phoca.cz Phoca Commander extension for Joomla — Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   N   N   N    6.1   .0045   37.1     —
AFFECTED
  Product                               Versions       Fixed
  Phoca Commander extension for Joomla  1.0.0-6.1.3 –  —
TIMELINE
  Jul 27  Reserved by CNA
  Aug 7   Published (CNA: Joomla)
CWE-22 · CNA: Joomla · CVSS v4.0 · 1 reference · NVD status: Received
Tobit Laboratories AG TeamDavid — TeamDavid: Denial of Service via endpoint 'internalRestart'
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    9.2   .0045   36.9     —
AFFECTED
  Product    Versions     Fixed
  TeamDavid  unspecified  —
TIMELINE
  Jun 12  Reserved by CNA
  Aug 7   Published (CNA: NCSC.ch)
CWE-284 · CNA: NCSC.ch · CVSS v4.0 · 2 references · NVD status: Received
Cisco Cisco Secure Endpoint — ClamAV PDF File Format Processing Memory Corruption Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0044   36.9     —
AFFECTED
  Product                Versions  Fixed
  Cisco Secure Endpoint  7.0.5 –   —
TIMELINE
  Oct 8   Reserved by CNA
  Aug 7   Published (CNA: cisco)
CWE-125 · CNA: cisco · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
Apache Fory: Uncaught panic (remote DoS) in Go meta-string decoder from untrusted metadata
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0044   36.2     —
AFFECTED
  Product      Versions  Fixed
  Apache Fory  0.16.0 –  —
TIMELINE
  Aug 7   Reserved by CNA
  Aug 7   Published (CNA: apache)
CWE-502 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Analyzed
Apache Fory: Out-of-bounds heap read in C++ struct deserializer tagged-int fast-path
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0042   34.4     —
AFFECTED
  Product      Versions  Fixed
  Apache Fory  0.14.0 –  —
TIMELINE
  Aug 7   Reserved by CNA
  Aug 7   Published (CNA: apache)
CWE-125, CWE-502 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Analyzed
go-git: Malicious reference names may modify files outside the reference storage
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   R  U  N  H  L    6.3   .0041   34.1     —
AFFECTED
  Product  Versions    Fixed
  go-git   < 5.19.2 –  —
TIMELINE
  Aug 6   Reserved by CNA
  Aug 7   Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · CVSS v3.1 · 7 references · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-542119.533.8Tobit Laboratories AGTeamDavidCWE-787TeamDavid: Buffer Overflow in multiple form data parameters
CVE-2026-675858.733.5DivvyPayHQabsinthe_federationCWE-770Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_fede…
CVE-2026-505409.633.1kata-containerskata-containersCWE-20Kata Containers: Config Path Annotation Arbitrary File Loading
CVE-2026-476598.733.2aehrcpathlingCWE-22Pathling has path traversal in $import-pnp manifest that enables read-capable…
CVE-2026-476618.733.2aehrcpathlingCWE-22Pathling has path traversal in $result endpoint that allows arbitrary warehou…
CVE-2026-687728.533.0ZenMLZenMLCWE-502ZenML 0.94.6 Remote Code Execution via CloudpickleMaterializer
CVE-2026-166376.532.5OPeNDAP Inc.hyrax-dockerCWE-201OPeNDAP Hyrax SSRF and Credential Disclosure via Unvalidated Redirects
CVE-2026-664948.731.7joomshaper.comSP Page Builder extension for JoomlaCWE-284Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API …
CVE-2026-176038.731.5SonatypeNexus Repository 3CWE-94Nexus Repository 3 - HikariCP connectionInitSql Injection RCE via DataStore C…
CVE-2026-159727.531.4HashiCorpConsulCWE-770Unauthenticated denial of service via unbounded external gRPC connection acce…
CVE-2026-542088.530.8Tobit Laboratories AGTeamDavidCWE-20TeamDavid: Arbitrary File Write leading to Stored XSS
CVE-2026-669149.230.6seblod.comSEBLOD extension for JoomlaCWE-22Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.…
CVE-2026-664918.230.4phoca.czPhoca Commander extension for JoomlaCWE-22Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3
CVE-2026-664936.430.4phoca.czPhoca Commander extension for JoomlaCWE-22Joomla Extension - phoca.cz - Path traversal vulnerability in Phoca Commander…
CVE-2026-629926.929.1smarty-phpsmartyCWE-22Smarty: Symlink path traversal out of trusted directories
CVE-2026-464055.329.0openbaoopenbaoCWE-770OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens
CVE-2026-464099.628.9openyakopenyakCWE-94OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution
CVE-2026-658197.528.8gopacketgopacketCWE-125gopacket: Multiple layer decoders panic on crafted packets (out-of-bounds/und…
CVE-2026-715567.128.4go-gitgo-gitCWE-59go-git: Worktree operations may follow symlinks
CVE-2026-152158.828.0UnknownSubscriptions for WooCommerceCWE-269Subscriptions for WooCommerce < 2.0.1 - Shop Manager+ Arbitrary Plugin Instal…
CVE-2026-629966.927.4smarty-phpsmartyCWE-22Smarty Security stream restriction bypass through stream: resource
CVE-2026-490077.527.1ZTEF689CWE-798Information leakage vulnerability in ZTE F689 product
CVE-2026-480399.126.9pipeboard-cometa-ads-mcpCWE-287Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Acc…
CVE-2025-583758.126.7frappefrappeCWE-89Frappe has potential SQL Injection due to missing validation
CVE-2026-718519.025.9brixcrypto-jsCWE-331crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulner…
CVE-2026-480475.926.0xwikixwiki-platformCWE-24XWiki Platform vulnerable to potential arbitrary file writing using path trav…
CVE-2026-120715.325.9Tobit Laboratories AGTeamDavidCWE-601TeamDavid: Header Injection leading to Open Redirect via URL-encoded characters
CVE-2026-542145.325.9Tobit Laboratories AGTeamDavidCWE-601TeamDavid: Header Injection through the 'cType' URL parameter
CVE-2026-718478.725.3rubyjsonCWE-416Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buf…
CVE-2026-190176.825.2HashiCorpConsulCWE-862Consul vulnerable to partial arbitrary file read via Vault Connect CA provider
CVE-2026-192295.525.2SourceCodesterOnline Clothing StoreCWE-200SourceCodester Online Clothing Store Dreamweaver Metadata Files _notes file i…
CVE-2026-162638.825.0UnknownWP MapsCWE-22WP Maps < 4.9.7 - Subscriber+ Local File Inclusion
CVE-2026-542047.724.8Tobit Laboratories AGTeamDavidCWE-20TeamDavid: Server-Side Request Forgery (SSRF) via 'pathnameroot' parameter in…
CVE-2026-542016.924.7Tobit Laboratories AGTeamDavidCWE-862TeamDavid: Missing Authorization
CVE-2026-542039.224.2Tobit Laboratories AGTeamDavidCWE-200TeamDavid: Memory Leak leaking sensitive information
CVE-2025-632357.523.9n/an/aCWE-400In sol commit 373d848 (2024-12-12), the broker does not fully release resourc…
CVE-2026-567939.823.4DellOpenManage Server Administrator Managed Node (Patch) for WindowsCWE-287Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an…
CVE-2026-143659.823.3themetechmountTrueBooker – Appointment Booking and Scheduler SystemCWE-862TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Pass…
CVE-2026-476608.723.2aehrcpathlingCWE-522Pathling: Explicit oauthMetadataUrl in bulk-submit allows OAuth client creden…
CVE-2026-175937.222.9SonatypeNexus RepositoryCWE-470Nexus Repository - Arbitrary Class Instantiation via Unsafe Realm Configuration
CVE-2026-458087.122.9openbaoopenbaoCWE-863OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasse…
CVE-2026-480945.322.5dartissshareopenlyCWE-79ShareOpenly has Cross-Site Scripting (XSS) via Missing esc_url() on Shared UR…
CVE-2026-542028.522.4Tobit Laboratories AGTeamDavidCWE-36TeamDavid: Path Traversal in the archive creation functionality
CVE-2026-567946.522.2DellDell OpenManage Server Administrator Managed Node (Patch) for WindowsCWE-23Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a …
CVE-2026-528797.521.4klever-ioklever-goCWE-400Klever-Go: Unbounded goroutine spawn on direct-message ingress enables peer-d…
CVE-2026-528807.521.4klever-ioklever-goCWE-400Klever-Go: REST API slow-header connection exhaustion via Gin Engine.Run
CVE-2026-175996.921.3SonatypeNexus Repository 3CWE-620Nexus Repository 3 - Unverified Onboarding State on change-admin-password End…
CVE-2026-175975.121.3SonatypeNexus Repository 3CWE-918Nexus Repository 3 - Server-Side Request Forgery via Email Configuration Veri…
CVE-2026-190155.321.3HashiCorpConsulCWE-770Uncontrolled resource consumption in the Consul Connect CA roots endpoint
CVE-2026-191135.321.3HashiCorpConsulCWE-400Unauthenticated denial of service via unbounded request body processing
CVE-2026-158167.521.2Red HatRed Hat Enterprise Linux 10CWE-78Dracut: dracut: root code execution via unescaped error message written to so…
CVE-2026-190827.521.2TONYCImagerCWE-125Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap b…
CVE-2026-705617.121.2TestLinkOpenSourceTRMSTestLinkCWE-639TestLink 1.9.20 and prior Authenticated IDOR via attachmentdownload.php
CVE-2026-691276.921.1getkirbykirbyCWE-497Kirby: System path exposure from error messages in the REST API
CVE-2026-660625.321.1sveltejskitCWE-1333SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via th…
CVE-2026-718485.321.1honojshonoCWE-407Hono: Algorithmic Complexity DoS in Language Middleware
CVE-2026-542098.920.6Tobit Laboratories AGTeamDavidCWE-125TeamDavid: Buffer Overflow in 'editini' function
CVE-2026-175955.320.6SonatypeNexus Repository 3CWE-497Nexus Repository 3 - JEXL Content Selector Sandbox Property-Read Bypass
CVE-2026-143649.820.5themetechmountTrueBooker – Appointment Booking and Scheduler SystemCWE-640TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Pass…
CVE-2026-668385.920.4elixir-ectopostgrexCWE-89SQL injection via the :comment option in Postgrex.stream/4
CVE-2026-568186.520.3nettynettyCWE-401Netty: RedisArrayAggregator max-elements failure leaves retained partial aggr…
CVE-2026-542165.320.3Tobit Laboratories AGTeamDavidCWE-79TeamDavid: Reflected Cross Site Scripting (XSS) via the 'EntryInfo' parameter
CVE-2026-543385.320.1jupyterhubjupyterhubCWE-400JupyterHub: Unauthenticated Denial of Service via Unbounded Username Logging …
CVE-2026-192102.120.1SourceCodesterPhoto Share WebsiteCWE-284SourceCodester Photo Share Website ajax.php save_upload unrestricted upload
CVE-2026-542056.320.0Tobit Laboratories AGTeamDavidCWE-20TeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in lin…
CVE-2026-542066.320.0Tobit Laboratories AGTeamDavidCWE-20TeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in sen…
CVE-2026-542076.320.0Tobit Laboratories AGTeamDavidCWE-20TeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in mov…
CVE-2026-528787.519.8klever-ioklever-goCWE-476Klever-Go: Unauthenticated nil-pointer DoS in P2P transaction validation can …
CVE-2026-472497.519.7klever-ioklever-goCWE-400Klever-Go KVM: Hash-array amplification in P2P resolver request handling
CVE-2026-622957.519.7hapifhirorg.hl7.fhir.coreCWE-20HAPI FHIR: JSON utility parser unbounded recursion causes StackOverflow denia…
CVE-2026-622967.519.7hapifhirorg.hl7.fhir.coreCWE-20HAPI FHIR: XHTML narrative parser unbounded recursion causes StackOverflow de…
CVE-2026-660595.319.3frappefrappeCWE-863Frappe: Field-level permission bypass via Document Follow
CVE-2026-480977.819.20x5t4l1nNexTOR_IP_CHANGERCWE-78NexTOR_IP_CHANGER has PATH Injection Leading to Arbitrary Command Execution
CVE-2026-192082.919.1n/aWonderTraderCWE-840WonderTrader TraderDD.cpp queryTrades behavioral workflow
CVE-2026-192442.019.0HKUDSnanobotCWE-266HKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access control
CVE-2026-542188.818.8Tobit Laboratories AGTeamDavidCWE-321TeamDavid: Weak Cryptography and Insecure Password Storage
CVE-2026-542155.318.8Tobit Laboratories AGTeamDavidCWE-601TeamDavid: Open Redirect via the 'replyUrl' parameter
CVE-2026-192122.118.8n/aWonderTraderCWE-453WonderTrader TraderATP Cash Trade Conversion WTSTradeDef.hpp uninitialized va…
CVE-2026-142059.818.5UnknownWP Events ManagerCWE-287WP Events Manager < 2.2.5 - Subscriber+ Payment Bypass via 'qty' Parameter
CVE-2026-493435.917.8klever-ioklever-goCWE-400Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch boo…
CVE-2026-191965.517.7SourceCodesterPhoto Share WebsiteCWE-74SourceCodester Photo Share Website ajax.php login sql injection
CVE-2026-192115.517.7SourceCodesterPhoto Share WebsiteCWE-74SourceCodester Photo Share Website ajax.php signup sql injection
CVE-2026-192315.517.7SourceCodesterSimple Doctors Appointment SystemCWE-74SourceCodester Simple Doctors Appointment System ajax.php delete_appointment …
CVE-2026-541995.317.6Tobit Laboratories AGTeamDavidCWE-20TeamDavid: Header Injection through request body in link storing functionality
CVE-2026-646379.917.6WebProsPleskCWE-269Improper privilege management in the XML-RPC API of Plesk before 18.0.80, all…
CVE-2026-190144.317.5HashiCorpConsulCWE-770Uncontrolled resource consumption in the Consul Connect authorization endpoint
CVE-2026-481698.817.3MervinPraisonpraisonai-platformCWE-639PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API
CVE-2026-149437.517.3UnknownPassword Protected — Lock Entire Site, Pages, Posts, Categories, and Partial ContentCWE-200Password Protected < 2.8.4 - Unauthenticated Sensitive Information Exposure v…
CVE-2026-660002.317.2frappefrappeCWE-863Frappe: Unrestricted access to Document Follow APIs
CVE-2026-542175.317.1Tobit Laboratories AGTeamDavidCWE-20TeamDavid: Stored XSS in web application
CVE-2026-175985.316.5SonatypeNexus Repository 3CWE-915Nexus Repository 3 - Improper Input Validation in Scheduled Task Configuration
CVE-2026-646367.716.4WebProsPleskCWE-89An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and …
CVE-2026-473646.516.3DatadogAndroid AppCWE-200In versions of the Datadog Android application prior to v545-5.9.2, the app t…
CVE-2026-481709.116.1thomaspoignantscim-patchCWE-1321scimPatch vulnerable to prototype pollution via unfiltered keys in patch
CVE-2026-190125.315.5HashiCorpConsulCWE-476Authenticated denial of service in Consul Enterprise-to-Community Edition dow…
CVE-2026-471276.515.3ghostfolioghostfolioCWE-862Ghostfolio has a Stripe subscription bypass
CVE-2026-542008.415.2Tobit Laboratories AGTeamDavidCWE-73TeamDavid: Local File Inclusion via the form field 'scjob'
CVE-2026-160389.114.8UnknownMStore APICWE-862MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gat…
CVE-2026-476628.714.8aehrcpathlingCWE-20Pathling $bulk-submit allows bearer-token exfiltration and persistent warehou…
CVE-2026-476638.714.8aehrcpathlingCWE-285Pathling: Typed CRUD/search/batch providers can lead to server-wide PHI exfil…
CVE-2026-175966.314.7SonatypeNexus Repository 3CWE-79Nexus Repository 3 - Stored Cross-Site Scripting (XSS) via Blob Store Name
CVE-2026-718493.714.3honojshonoCWE-200Hono: Proxy Helper does not remove response headers listed in the `Connection…
CVE-2026-146448.614.1SonatypeNexus Repository 3CWE-843Nexus Repository 3 - Privilege Escalation
CVE-2026-120708.414.1Tobit Laboratories AGTeamDavidCWE-73TeamDavid: Arbitrary File Deletion via form field 'scjob'
CVE-2026-162656.513.3UnknownWP MapsCWE-400WP Maps < 4.9.7 - Subscriber+ Denial of Service
CVE-2026-119076.513.2xwpStream – Activity Log & Audit TrailCWE-862Stream <= 4.2.0 - Missing Authorization to Authenticated (Subscriber+) Sensit…
CVE-2026-160308.113.1UnknownMStore APICWE-287MStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone Aut…
CVE-2026-660585.313.0frappefrappeCWE-639Frappe: Unrestricted access to a Document Follow API
CVE-2026-192462.112.5HKUDSnanobotCWE-918HKUDS nanobot Provider-returned Image URL image_generation.py _download_image…
CVE-2026-480268.712.1treeverselakeFSCWE-79lakeFS vulnerable to stored XSS in rendered markdown previews via raw HTML
CVE-2026-597174.312.0home-assistantcoreCWE-601Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishing
CVE-2026-192132.111.8n/aWonderTraderCWE-840WonderTrader Pending Order TraderAdapter.h _undone_qty behavioral workflow
CVE-2026-176018.911.7SonatypeNexus Repository 3CWE-862Nexus Repository 3 - Wildcard Privilege Update Self-Escalation to Administrator
CVE-2026-176008.711.7SonatypeNexus Repository 3CWE-613Nexus Repository 3 - Session Not Invalidated on User Account Deletion or Deac…
CVE-2026-153618.111.7UnknownContent ViewsCWE-89Content Views < 4.5 - Subscriber+ SQL Injection via preview_request
CVE-2026-190164.211.4HashiCorpConsulCWE-22Authorization bypass for session deletion in the transaction API
CVE-2026-192071.911.1PHPGurukulCompany Visitor Management SystemCWE-79PHPGurukul Company Visitor Management System manage-newvisitors.php cross sit…
CVE-2026-160417.510.8UnknownMStore APICWE-862MStore API < 4.21.0 - Unauthenticated Product Review Creation
CVE-2026-155707.110.7VestelTelefunken TE24553B45V2DZ Smart TVCWE-918Improper URL Scheme and Destination Validation in SmartCenter browserseturl C…
CVE-2026-153596.510.1UnknownTemplatelyCWE-862Templately < 3.7.1 - Unauthenticated Administrator Templately Cloud Connectio…
CVE-2026-160396.59.9UnknownMStore APICWE-639MStore API < 4.21.0 - Subscriber+ Order and Customer PII Disclosure via IDOR
CVE-2025-714097.19.8ATN-B1CPDLCCWE-306No Authentication for Very High Frequency Data Link messages used in CPDLC
CVE-2026-192092.09.6SourceCodesterPhoto Share WebsiteCWE-79SourceCodester Photo Share Website index.php home cross site scripting
CVE-2026-192302.09.6SourceCodesterPhoto Share WebsiteCWE-79SourceCodester Photo Share Website Comment Input Box ajax.php save_upload cro…
CVE-2025-714106.09.6ATN-B1CPDLCCWE-770Malicious Link Control Frames Can Cause Loss of CPDLC Functions
CVE-2025-714116.09.6ATN-B1CPDLCCWE-770In CPDLC, Broadcast Control Frames Can Disconnect Multiple Aircraft Simultane…
CVE-2025-714136.09.6ATN-B1CPDLCCWE-754In CPDLC, Malformed or Out of Sequence Frames Can Cause Resets
CVE-2026-122615.38.8nltknltk/nltkCWE-284Improper Access Control in nltk/nltk
CVE-2026-449646.58.7DatadogAndroid AppCWE-441In versions of the Datadog Android application prior to v545-5.9.2, OnCallNot…
CVE-2025-714127.18.0ATN-B1CPDLCCWE-754In CPDLC, False Emergency or Status Messages Will be Accepted as Legitimate
CVE-2026-160275.47.9Revenue AdministrationE-SignatureCWE-918Unauthenticated WebSocket-to-XAdES SSRF in Revenue Administration's E-Signature
CVE-2026-472439.27.7kata-containerskata-containersCWE-22Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs
CVE-2026-490086.56.9ZTEF689CWE-321Integrity‑check credential leakage vulnerability in an application function o…
CVE-2026-473616.46.9DatadogAndroid AppCWE-926In versions of the Datadog Android application prior to v541-5.9.2, BubbleCha…
CVE-2026-473624.66.6DatadogAndroid AppCWE-922In versions of the Datadog Android application prior to v554-5.9.4, two Room-…
CVE-2026-191937.16.2JiangminAntivirusCWE-266Jiangmin Antivirus Minifilter Port kvcore.sys MessageNotifyCallback access co…
CVE-2026-191957.16.2V-SecureJingyun AntivirusCWE-266V-Secure Jingyun Antivirus Kernel Driver ZyArk.sys access control
CVE-2026-480078.65.9element-hqelement-callCWE-200Element Call reports full URLs of visited pages to analytics server
CVE-2026-718504.85.8honojshonoCWE-488Hono: `memo()` retains SSR output across requests, leading to cross-user data…
CVE-2026-90316.85.7TP-Link Systems Inc.Archer A6 v4CWE-20Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6
CVE-2026-614772.35.7Red HatRed Hat Enterprise Linux 10CWE-93Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows …
CVE-2026-480936.55.6dartisscode-embedCWE-79Code Embed - Contributor Stored Cross-Site Scripting via Remote URL Embed
CVE-2026-150326.15.6UnknownCommentsCWE-79wpDiscuz < 7.6.60 - Unauthenticated Stored XSS via Image URL Conversion
CVE-2026-152144.35.5UnknownSubscriptions for WooCommerceCWE-639Subscriptions for WooCommerce < 2.0.1 - Subscriber+ Subscription Detail Discl…
CVE-2026-371715.95.3n/an/aCWE-863A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v1…
CVE-2026-159704.25.3HashiCorpConsulCWE-647L7 intention authorization bypass via custom public listener
CVE-2026-162627.55.2UnknownEstatik Real Estate PluginCWE-352Estatik < 4.3.3 - Login CSRF
CVE-2026-713814.05.2AdobeAdobe Genuine Software Integrity ServiceCWE-863Adobe Genuine Software Integrity Service | CWE-863 Incorrect Authorization
CVE-2026-114252.04.9DomoticzDomoticzCWE-79Domoticz Mobile Dashboard versions prior to 2026.3 Stored XSS via Text/Alert …
CVE-2026-128016.44.5themeficUltra Addons for Contact Form 7CWE-79Ultra Addons for Contact Form 7 <= 3.5.43 - Authenticated (Contributor+) Stor…
CVE-2026-490065.34.2ZTEF689CWE-321TLS credential leakage vulnerability in ZTE F689 product
CVE-2026-463585.44.1openbaoopenbaoCWE-532OpenBao's Inline Auth Incorrectly Redacted Headers
CVE-2026-476648.64.0aehrcpathlingCWE-20Pathling: $import-pnp operation enables authenticated SSRF, credential leakag…
CVE-2026-91698.83.9LUCID Vision LabsArena SDKCWE-427LUCID Vision Labs: DLL Search Order Hijacking in Arena SDK 1.0.80.49 on Windows
CVE-2026-143316.13.9UnknownSubscribe2CWE-79Subscribe2 < 10.46 - Reflected XSS via email Parameter
CVE-2026-473636.33.7DatadogAndroid AppCWE-926In versions of the Datadog Android application prior to v541-5.9.2, the expor…
CVE-2026-191907.13.4StableBitScannerCWE-266StableBit Scanner ScannerService Scanner.Service.exe permission
CVE-2026-481208.63.3mawwwkakouneCWE-74Kakoune has a Critical RCE via Autorestore Backup Filename Injection
CVE-2026-480987.32.90x5t4l1nNexTOR_IP_CHANGERCWE-78NexTOR IP Changer Unsafely Uses sudo and shell=True
CVE-2026-90306.82.9TP-Link Systems Inc.Archer A6 v4CWE-362Authenticated Denial-of-Service in HTTPD Service in TP-Link Archer A6
CVE-2026-152455.42.8UnknownBNE TestimonialsCWE-79BNE Testimonials < 2.0.8.2 - Contributor+ Stored XSS via Slider Shortcode
CVE-2026-153865.42.8UnknownMeow GalleryCWE-79Meow Gallery < 5.5.2 - Author+ Stored XSS via Attachment Alt-Text
CVE-2026-718524.82.6py-pdfpypdfCWE-834pypdf: Possible long runtimes/large memory usage for large CID font width ranges
CVE-2026-718704.82.6py-pdfpypdfCWE-400pypdf: Possible large memory usage for large /ToUnicode streams
CVE-2026-481225.42.5Shopifyruby-lspCWE-78Workspace settings can override executable and Gemfile paths used by the Ruby…
CVE-2026-184977.12.4Sean Barrett (nothings)nothings stbCWE-122The nothings stb TrueType library contains a heap buffer overflow vulnerability
CVE-2026-192061.92.4MZ Automationlibiec61850CWE-119MZ Automation libiec61850 ASDU Element sv_subscriber.c SVReceiver_stopThreadl…
CVE-2026-646765.72.2kata-containerskata-containersCWE-862Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host t…
CVE-2026-192451.92.1HKUDSnanobotCWE-200HKUDS nanobot Login-shell Environment shell.py ExecTool._prepare_command info…
CVE-2026-451987.82.0Imagination TechnologiesGraphics DDKCWE-822GPU DDK - RGXFWIF_SYSINIT::sCorememDataStore is untrusted
CVE-2026-582627.11.9klever-ioklever-goCWE-345Klever-Go: PubKeysBitmap padding bits bypass the BLS signature quorum
CVE-2026-174352.51.9RRWOFile::Rotate::SimpleCWE-59File::Rotate::Simple versions before 0.4.0 for Perl create the target of dang…
CVE-2026-622935.01.8hapifhirorg.hl7.fhir.coreCWE-20HAPI FHIR: Stored XSS in scan report via unescaped IG and profile titles
CVE-2026-490052.41.7ZTEF689CWE-916Root password hash exposure vulnerability in ZTE F689 product
CVE-2026-151485.31.7UnknownWP Events ManagerCWE-345WP Events Manager < 2.2.5 - Unauthenticated Payment Bypass and Booking Status…
CVE-2026-660607.11.6home-assistantcoreCWE-862Home Assistant: Unconfirmed NFC/QR tag scans allow silent automation executio…
CVE-2026-660617.11.6home-assistantcoreCWE-862Home Assistant: iOS Companion app forwards NFC/QR tag scans without confirmat…
CVE-2026-449655.51.6DatadogAndroid AppCWE-926In versions of the Datadog Android application prior to v545-5.9.2, six App W…
CVE-2026-191897.11.4Power SofwarePowerISOCWE-266Power Sofware PowerISO Kernel Driver scdemu.sys privileges management
CVE-2026-152115.91.5UnknownSubscriptions for WooCommerceCWE-345Subscriptions for WooCommerce < 2.0.1 - Payment Bypass via Attacker-Supplied …
CVE-2026-152395.31.5UnknownSimple CAPTCHA with Cloudflare TurnstileCWE-345Simple CAPTCHA with Cloudflare Turnstile < 1.42.0 - Unauthenticated Turnstile…
CVE-2026-661515.51.4SonicWallGlobal VPN ClientCWE-125SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to …
CVE-2026-191917.11.3StableBitDrivePoolCWE-266StableBit DrivePool DrivePoolService DrivePool.Service.exe permission
CVE-2026-191927.11.3DeepCoolDisplayServiceCWE-266DeepCool DisplayService DeepCoolDisplayService.exe access control
CVE-2026-497467.11.2Imagination TechnologiesGraphics DDKCWE-823GPU DDK - Dimension Mismatch and Integer Truncation in PMRDevPhysAddrOSMem
CVE-2026-189386.21.2Red HatRed Hat Enterprise Linux 10CWE-122P11-kit: integer overflow in rpc attribute-array length calculation can under…
CVE-2026-452045.51.3Imagination TechnologiesGraphics DDKCWE-476GPU DDK - Out of bounds memory access and kernel NULL pointer dereference in …
CVE-2026-117436.61.2zephyrprojectzephyrCWE-125Missing negative-offset/overflow check in SF32LB MPI QSPI NOR flash driver al…
CVE-2026-117423.60.6zephyrprojectzephyrCWE-416Use-after-free race in kernel `k_queue_peek_head/tail` due to missing spinlock
CVE-2026-190794.40.3Red HatRed Hat Hardened ImagesCWE-367Policycoreutils: policycoreutils: toctou race condition in fixfiles allows ar…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-07 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.