boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Saturday, August 8, 2026 · all times UTC← 2026-08-07 · archive · 2026-08-09 →

Security Box Score — August 8, 2026

62 CVEs published, led by D-Link Corporation (15).

62 CVEs published August 8, 2026: 27 critical, 8 high, 16 medium, 10 low; 0 in the KEV catalog at press time; 1 with a public exploit reference; 1 awaiting enrichment. 25 rendered as box scores below; the remaining 37 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published197024134——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

1307 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux462361211125463711120.17.8.0016+9 ▲
google431804222743783567760.37.5.0025-36 ▼
microsoft33145512199132914286241.67.8.0047-19 ▼
red hat424282016621230200.06.5.0029+11 ▲
apple1272587813338872.66.8.0027+1 ▲
canonical02738115000.05.6.0014-1 ▼
suse52651461000.08.1.0039-1 ▼
freebsd01601240000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco30681336190561217.67.5.0046+22 ▲
ubiquiti036142110338.38.8.0049-25 ▼
palo alto networks025131471328.04.7.0028-1 ▼
fortinet0236611028626.17.2.00400
netgear02300221000.04.6.00240
vmware0174922715.98.3.00400
f50165830416.38.6.00570
checkpoint11346303215.47.8.0436+1 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache6139777176131123320.57.5.0050+10 ▲
mozilla11285142350900.08.1.0031-2 ▼
drupal05165355412.05.9.00260
gitlab05107377423.94.9.0029-7 ▼
github2141490000.06.2.0043+1 ▲
docker070520000.08.2.00160
wordpress1412102250.08.8.5550+1 ▲
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle01379343653322612730.28.1.00360
ibm3226172104841610.47.5.0031+30 ▲
adobe82603311710641931.27.8.0026+5 ▲
progress1153143270611.98.1.0037+1 ▲
solarwinds0231733010417.49.1.00580
veeam10165920100.08.6.0034+10 ▲
zohocorp062220000.07.8.01460
atlassian0303001300.08.0.00260
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link153515596300.07.4.0157+15 ▲
synology12426133000.05.6.0025+1 ▲
rockwell automation02441820000.08.7.00290
siemens0161870000.07.6.00240
schneider electric091620000.08.6.00370
abb070430000.07.2.00180
hikvision060420000.07.2.00400
moxa050320000.07.0.00290
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester11131007061000.05.5.0033-16 ▼
openclaw01110583914000.07.0.0026-1 ▼
dell8107950453210.97.2.0021-19 ▼
nvidia16981366190000.07.7.0034-1 ▼
capgo083242381000.07.1.0037-7 ▼
spring079234412000.06.5.00220
imagemagick078156012000.05.3.0018-10 ▼
itsourcecode677001958000.02.1.0033-4 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.995799.99.8
CVE-2026-34486.986299.97.5
CVE-2026-63030.977999.99.8
CVE-2026-16232.891299.89.3
CVE-2026-63077.847399.79.8
CVE-2026-50522.846199.79.8
CVE-2026-15409.836699.710.0
CVE-2026-60137.797999.65.9
CVE-2026-6875.775899.59.5
CVE-2026-25089.761199.59.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1540910.0.8366KEV
CVE-2026-4893910.0.1973KEV
CVE-2026-5629110.0.1459KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0486
CVE-2026-4766810.0.0388
CVE-2026-4633910.0.0335
CVE-2026-6144710.0.0249
CVE-2026-5782710.0.0233
CVE-2026-4435910.0.0180
Most disclosures (vendor)
VendorCVEs
oracle1109
linux844
microsoft646
google460
apache190
red hat173
apple168
ibm135
adobe113
mozilla69
Most KEV additions (YTD)
VendorKEV
microsoft24
cisco12
apple7
fortinet6
google6
ivanti5
solarwinds4
adobe3
berriai3
oracle3
Most-affected ecosystems
EcosystemAdvisories
Maven66
PyPI5
Go3
npm3
Packagist2
crates.io2
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2021-27137DD-WRT0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20316Cisco0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171725
CVE-2021-27102n/a2021-11-171725
CVE-2021-27101n/a2021-11-171725
CVE-2021-27103n/a2021-11-171725
CVE-2021-21017Adobe2021-11-171725
CVE-2021-28550Adobe2021-11-171725
CVE-2021-42013Apache Software Foundation2021-11-171725
CVE-2021-41773Apache Software Foundation2021-11-171725
CVE-2021-30858Apple2021-11-171725
CVE-2021-30860Apple2021-11-171725

Transactions

EXPLOIT PUBLISHED — CVE-2026-19192 (DeepCool DisplayService). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19193 (Jiangmin Antivirus). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19195 (V-Secure Jingyun Antivirus). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19207 (PHPGurukul Company Visitor Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19212 (WonderTrader). Public exploit reference added.

DUE DATE PASSED — CVE-2026-18556 (N-able N-central). CISA remediation deadline was August 7, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-34486 (Apache Software Foundation Apache Tomcat). CISA remediation deadline was August 7, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-9198 (IBM Langflow OSS). CISA remediation deadline was August 7, 2026; still in catalog.

Yesterday's Results

How to read these box scores · glossary

62 CVEs published. 25 box scores, 37 table rows — nothing truncated.

D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeQuectel
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0208   80.1     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeFibocom
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0208   80.1     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRun
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0208   80.1     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRun
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0208   80.1     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRun
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0208   80.1     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetup
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0208   80.1     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via /boafrm/formSmsManage
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0208   80.1     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via /boafrm/formIMEISetup
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0208   80.1     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetup
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0208   80.0     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via /boafrm/formWsc
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0208   80.0     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via /boafrm/formPinManageSetup
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0204   79.6     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via /boafrm/formNtp
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0204   79.6     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via app.cgi
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0169   75.4     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
MSI Radix AXE6600 v781521 Command Injection via wps.cgi
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0162   74.2     —
AFFECTED
  Product        Versions     Fixed
  Radix AXE6600  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
Kirachon context-engine review-git-diff Endpoint gitUtils.ts execGitCommand command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   L   N   L   L   L    5.1   .0152   72.6     —
AFFECTED
  Product         Versions  Fixed
  context-engine  1.0 –     1.9.1
TIMELINE
  Aug 7   Reserved by CNA
  Aug 8   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Deferred
MSI Radix AXE6600 v781521 Command Injection via urlfilter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0135   69.3     —
AFFECTED
  Product        Versions     Fixed
  Radix AXE6600  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
MSI Radix AXE6600 v781521 Command Injection via accesscontrol Function
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0135   69.4     —
AFFECTED
  Product        Versions     Fixed
  Radix AXE6600  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
MSI Radix AXE6600 v781521 Command Injection via dmz Function
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0135   69.4     —
AFFECTED
  Product        Versions     Fixed
  Radix AXE6600  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
MSI Radix AXE6600 v781521 Command Injection via alg function
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0135   69.4     —
AFFECTED
  Product        Versions     Fixed
  Radix AXE6600  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
MSI Radix AXE6600 v781521 Command Injection via portFw function
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0135   69.3     —
AFFECTED
  Product        Versions     Fixed
  Radix AXE6600  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
MSI Radix AXE6600 v781521 Command Injection via porTrigger function
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0135   69.3     —
AFFECTED
  Product        Versions     Fixed
  Radix AXE6600  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
MSI Radix AXE6600 v781521 Command Injection via TelnetSSH Function
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0135   69.4     —
AFFECTED
  Product        Versions     Fixed
  Radix AXE6600  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
MSI Radix AXE6600 v781521 Command Injection via TelnetSSH Function
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0135   69.4     —
AFFECTED
  Product        Versions     Fixed
  Radix AXE6600  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
MSI Radix AXE6600 v781521 Command Injection via macfilter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0135   69.3     —
AFFECTED
  Product        Versions     Fixed
  Radix AXE6600  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
INQUIRELAB mcp-bridge-api Servers Endpoint mcp-bridge.js command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    6.9   .0134   69.0     —
AFFECTED
  Product         Versions                                    Fixed
  mcp-bridge-api  b30a82aa1d1d1139e0de846c41c8aadee6e06114 –  —
TIMELINE
  Aug 7   Reserved by CNA
  Aug 8   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-192682.162.2abdullah1854MCPGatewayCWE-74abdullah1854 MCPGateway Claude Usage Range Endpoint claude-usage.ts getUsageB…
CVE-2026-145269.849.2wupsalesAI Copilot – Content GeneratorCWE-269AI Copilot – Content Generator <= 1.5.6 - Unauthenticated Privilege Escalatio…
CVE-2026-192791.947.2MIMICLabmcp-pdf-visionCWE-74MIMICLab mcp-pdf-vision index.ts load_pdf command injection
CVE-2026-192811.947.2adolfosalasgomez3011slidev-builder-mcpCWE-74adolfosalasgomez3011 slidev-builder-mcp generateAssets Tool generateAssets.ts…
CVE-2026-192841.947.1MauricioMilanocoder-apiCWE-74MauricioMilano coder-api Projects Endpoint projects.ts createProject command …
CVE-2026-192821.946.7andreahakullm_memory_mcpCWE-74andreahaku llm_memory_mcp GitHooksManager.ts auto.capture command injection
CVE-2026-719579.345.8D-Link CorporationDWR-M961CWE-120D-Link DWR-M961 Buffer Overflow via app.cgi
CVE-2026-719589.344.2D-Link CorporationDWR-M961CWE-120D-Link DWR-M961 Buffer Overflow via quicksetup.cgi
CVE-2026-680829.832.7LinuxLinux—libceph: fix two unsafe bare decodes in decode_lockers()
CVE-2026-87988.725.3Legion of the Bouncy Castle Inc.BC-FJACWE-835Native entropy source retries the CPU entropy instructions without limit
CVE-2026-676206.324.4FlowiseAIFlowiseCWE-918Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List
CVE-2026-165787.523.7UnknownAdmin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force ProtectionCWE-200Admin Safety Guard < 1.4.0 - Unauthenticated User Data Disclosure via 2fa/app…
CVE-2026-162678.118.4UnknownNewslettersCWE-502Newsletters < 4.16 - Unauthenticated PHP Object Injection via Date Form Field
CVE-2026-189886.417.1shapedpluginEasy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQCWE-79Easy Accordion <= 3.1.8 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-135058.716.5Legion of the Bouncy Castle Inc.BC-FJACWE-772Zeroisation of sensitive key material on garbage collection relies on finaliz…
CVE-2026-165947.515.5UnknownWP Directory KitCWE-200WP Directory Kit < 1.5.5 - Subscriber+ Plugin Settings and API Key Disclosure
CVE-2026-165596.813.4UnknownYMC FilterCWE-79YMC Filter < 3.12.9 - Author+ Stored XSS via SVG Icon Upload
CVE-2026-162694.813.1UnknownNewslettersCWE-287Newsletters < 4.16 - Unauthenticated API Authentication Bypass via Type Juggling
CVE-2026-169555.012.9UnknownAI EngineCWE-22AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio Transcription
CVE-2026-165626.512.2UnknownWP StatisticsCWE-200WP Statistics < 14.16.10 - Subscriber+ Sensitive Data Disclosure via Metabox …
CVE-2026-165906.512.2UnknownWP Directory KitCWE-200WP Directory Kit < 1.5.5 - Subscriber+ Contact Message and User Data Disclosure
CVE-2026-165956.512.2UnknownWP Directory KitCWE-200WP Directory Kit < 1.5.5 - Subscriber+ User and Unpublished Listing Disclosure
CVE-2026-169488.111.1UnknownSolace ExtraCWE-284Solace Extra < 1.6.1 - Subscriber+ Multiple Missing Authorization via Site-Wi…
CVE-2026-165897.710.9UnknownWP Directory KitCWE-89WP Directory Kit < 1.5.5 - Subscriber+ SQL Injection via data_fields_list Par…
CVE-2026-166085.39.6UnknownDownload MonitorCWE-862Download Monitor < 5.2.6 - Unauthenticated Download Log Injection
CVE-2026-169534.88.2UnknownAI EngineCWE-639AI Engine < 3.6.4 - Unauthenticated Cross-Session Chatbot File Deletion via F…
CVE-2026-162825.37.7UnknownAppointment Hour BookingCWE-287Appointment Hour Booking < 1.5.88 - Unauthenticated Booking Price Manipulatio…
CVE-2026-421707.86.6Red HatRed Hat Enterprise Linux 6CWE-131Gimp: gimp dds plug-in heap-based buffer overflow via bpp mismatch in load_la…
CVE-2026-165356.15.6UnknownLink LibraryCWE-79Link Library < 7.9.4 - Reflected XSS via Thumbs-Rating likelabel
CVE-2026-68081await4.9LinuxLinux—KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state
CVE-2026-165745.43.4UnknownDokan: AI Powered WooCommerce Multivendor Marketplace SolutionCWE-639Dokan < 5.0.11 - Vendor+ Cross-Vendor Downloadable Product Access Grant via O…
CVE-2026-192871.93.4abrinsmeadmindpilot-mcpCWE-22abrinsmead mindpilot-mcp HistoryService path traversal
CVE-2026-192701.93.3Hulupeepmcp-ui-probeCWE-22Hulupeep mcp-ui-probe Journey/Usage JourneyStorage.ts usage_stats path traversal
CVE-2026-192851.93.3aaronsbmemory-graphCWE-22aaronsb memory-graph memoryTools.ts JsonMemoryStorage.saveMemories path trave…
CVE-2026-192881.93.3astralisonerive-mcp-server-coreCWE-22astralisone rive-mcp-server-core importRiveFile Flow importRiveFile.ts path t…
CVE-2026-165585.42.8UnknownYMC FilterCWE-79YMC Filter < 3.12.8 - Contributor+ Stored XSS via Layout Builder Schema
CVE-2026-192591.92.4MZ Automationlibiec61850CWE-119MZ Automation libiec61850 MMS Protocol Workflow iec61850_common.c MmsMapping_…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-08 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.