boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Saturday, August 8, 2026 · all times UTC← 2026-08-07 · archive · 2026-08-09 →

62 CVEs published, led by D-Link Corporation (15).

62 CVEs published August 8, 2026: 27 critical, 8 high, 16 medium, 10 low; 0 in the KEV catalog at press time; 1 with a public exploit reference; 1 awaiting enrichment. 25 rendered as box scores below; the remaining 37 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published19702411714002564
KEV catalog size1671

1303 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux462363211125463512730.17.8.0014+9 ▲
google431803222739783567460.37.5.0023-36 ▼
microsoft33146411999332914380322.27.8.0041-19 ▼
red hat423982015719625400.06.5.0024+11 ▲
apple1267577312739472.66.8.0024+1 ▲
canonical02738115000.05.6.0011-1 ▼
suse52651461000.08.1.0030-1 ▼
freebsd01601240000.07.8.00150
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco30701134170961318.67.5.0033+22 ▲
ubiquiti036142110438.38.8.0036-25 ▼
palo alto networks025021471428.04.7.0021-1 ▼
fortinet0233611028626.16.7.00390
netgear02300221800.04.6.00220
f50175830715.98.6.00570
vmware01648222200.08.2.00390
checkpoint11346303215.47.8.0436+1 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache6139577176129124020.57.5.0048+10 ▲
mozilla112851423501300.08.1.0029-2 ▼
gitlab05307377423.84.9.0025-7 ▼
drupal05165355512.05.9.00180
github2141490000.06.2.0032+1 ▲
docker070520100.08.2.00160
wordpress1412105250.08.8.3700+1 ▲
kubernetes010001000.02.4.00240
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle01379342653322614030.28.1.00320
adobe82623311610647541.57.8.0021+5 ▲
ibm3226172104841710.47.5.0026+30 ▲
progress1153143270911.98.1.0032+1 ▲
solarwinds0231623011417.49.1.00440
veeam10165920400.08.6.0028+10 ▲
zohocorp062220000.07.8.01090
atlassian0303001300.08.0.00260
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link1536155962612.87.4.0105+15 ▲
synology12426133000.05.6.0025+1 ▲
rockwell automation02441820000.08.7.00250
siemens0161870100.07.6.00190
schneider electric091620100.08.6.00240
abb070430000.07.2.00180
hikvision0704202114.37.2.00250
moxa050320000.07.0.00290
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester11131007061000.05.5.0026-16 ▼
openclaw01110583914000.07.0.0022-1 ▼
dell8107850453210.97.2.0020-19 ▼
nvidia16981366190000.07.7.0025-1 ▼
capgo083242381000.07.1.0028-7 ▼
spring079234412000.06.5.00220
imagemagick078156012300.05.3.0017-10 ▼
itsourcecode677001958000.02.1.0020-4 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.993199.99.8
CVE-2026-63030.956099.99.8
CVE-2026-39808.912199.8
CVE-2026-34486.829399.67.5
CVE-2026-48939.825099.610.0
CVE-2026-50522.769899.59.8
CVE-2026-15410.763599.57.2
CVE-2026-56291.760799.510.0
CVE-2026-15409.742299.410.0
CVE-2026-25089.736099.49.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-1540910.0.7422KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0473
CVE-2026-4766810.0.0434
CVE-2026-4633910.0.0239
CVE-2026-6144710.0.0223
CVE-2026-5782710.0.0160
CVE-2026-4435910.0.0100
Most disclosures (vendor)
VendorCVEs
oracle1109
linux844
microsoft646
google460
apache190
red hat173
apple168
ibm135
adobe113
mozilla69
Most KEV additions (YTD)
VendorKEV
microsoft32
cisco13
apple7
fortinet6
google6
ivanti5
adobe4
solarwinds4
synacor4
langflow3
Most-affected ecosystems
EcosystemAdvisories
Maven66
PyPI5
Go3
npm3
Packagist2
crates.io2
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2008-4128Cisco0
CVE-2021-27137DD-WRT0
CVE-2023-4346KNX Association0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-18556N-able0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171725
CVE-2021-27102Accellion2021-11-171725
CVE-2021-27101Accellion2021-11-171725
CVE-2021-27103Accellion2021-11-171725
CVE-2021-21017Adobe2021-11-171725
CVE-2021-28550Adobe2021-11-171725
CVE-2021-42013Apache2021-11-171725
CVE-2021-41773Apache2021-11-171725
CVE-2021-30858Apple2021-11-171725
CVE-2021-30860Apple2021-11-171725

Transactions

EXPLOIT PUBLISHEDCVE-2026-19192 (DeepCool DisplayService). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19193 (Jiangmin Antivirus). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19195 (V-Secure Jingyun Antivirus). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19207 (PHPGurukul Company Visitor Management System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19212 (WonderTrader). Public exploit reference added.

DUE DATE PASSEDCVE-2026-18556 (N-able N-central). CISA remediation deadline was August 7, 2026; still in catalog.

DUE DATE PASSEDCVE-2026-34486 (Apache Software Foundation Apache Tomcat). CISA remediation deadline was August 7, 2026; still in catalog.

DUE DATE PASSEDCVE-2026-9198 (IBM Langflow OSS). CISA remediation deadline was August 7, 2026; still in catalog.

Yesterday's Results

How to read these box scores · glossary

62 CVEs published. 25 box scores, 37 table rows — nothing truncated.

D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetup
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0213   80.5     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via /boafrm/formWsc
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0213   80.5     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeQuectel
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0209   80.1     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeFibocom
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0209   80.1     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via /boafrm/formPingDiagnosticRun
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0209   80.1     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRun
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0209   80.1     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRun
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0209   80.1     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetup
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0209   80.1     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via /boafrm/formSmsManage
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0209   80.1     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via /boafrm/formIMEISetup
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0209   80.1     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via /boafrm/formPinManageSetup
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0209   80.1     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via /boafrm/formNtp
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0209   80.1     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
D-Link DWR-M961 Command Injection via app.cgi
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0174   75.9     —
AFFECTED
  Product   Versions     Fixed
  DWR-M961  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
MSI Radix AXE6600 v781521 Command Injection via wps.cgi
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0162   74.2     —
AFFECTED
  Product        Versions     Fixed
  Radix AXE6600  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
Kirachon context-engine review-git-diff Endpoint gitUtils.ts execGitCommand command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   L   N   L   L   L    5.1   .0152   72.5     —
AFFECTED
  Product         Versions  Fixed
  context-engine  1.0 –     1.9.1
TIMELINE
  Aug 7   Reserved by CNA
  Aug 8   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Deferred
MSI Radix AXE6600 v781521 Command Injection via urlfilter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0135   69.3     —
AFFECTED
  Product        Versions     Fixed
  Radix AXE6600  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
MSI Radix AXE6600 v781521 Command Injection via accesscontrol Function
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0135   69.3     —
AFFECTED
  Product        Versions     Fixed
  Radix AXE6600  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
MSI Radix AXE6600 v781521 Command Injection via dmz Function
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0135   69.3     —
AFFECTED
  Product        Versions     Fixed
  Radix AXE6600  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
MSI Radix AXE6600 v781521 Command Injection via alg function
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0135   69.3     —
AFFECTED
  Product        Versions     Fixed
  Radix AXE6600  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
MSI Radix AXE6600 v781521 Command Injection via portFw function
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0135   69.3     —
AFFECTED
  Product        Versions     Fixed
  Radix AXE6600  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
MSI Radix AXE6600 v781521 Command Injection via porTrigger function
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0135   69.3     —
AFFECTED
  Product        Versions     Fixed
  Radix AXE6600  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
MSI Radix AXE6600 v781521 Command Injection via TelnetSSH Function
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0135   69.3     —
AFFECTED
  Product        Versions     Fixed
  Radix AXE6600  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
MSI Radix AXE6600 v781521 Command Injection via TelnetSSH Function
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0135   69.3     —
AFFECTED
  Product        Versions     Fixed
  Radix AXE6600  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
MSI Radix AXE6600 v781521 Command Injection via macfilter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0135   69.3     —
AFFECTED
  Product        Versions     Fixed
  Radix AXE6600  unspecified  —
TIMELINE
  Aug 8   Reserved by CNA
  Aug 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
INQUIRELAB mcp-bridge-api Servers Endpoint mcp-bridge.js command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    6.9   .0134   68.9     —
AFFECTED
  Product         Versions                                    Fixed
  mcp-bridge-api  b30a82aa1d1d1139e0de846c41c8aadee6e06114 –  —
TIMELINE
  Aug 7   Reserved by CNA
  Aug 8   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-192682.162.1abdullah1854MCPGatewayCWE-74abdullah1854 MCPGateway Claude Usage Range Endpoint claude-usage.ts getUsageB…
CVE-2026-192791.951.5MIMICLabmcp-pdf-visionCWE-74MIMICLab mcp-pdf-vision index.ts load_pdf command injection
CVE-2026-192811.947.2adolfosalasgomez3011slidev-builder-mcpCWE-74adolfosalasgomez3011 slidev-builder-mcp generateAssets Tool generateAssets.ts…
CVE-2026-192841.947.1MauricioMilanocoder-apiCWE-74MauricioMilano coder-api Projects Endpoint projects.ts createProject command …
CVE-2026-192821.946.7andreahakullm_memory_mcpCWE-74andreahaku llm_memory_mcp GitHooksManager.ts auto.capture command injection
CVE-2026-145269.846.6wupsalesAI Copilot – Content GeneratorCWE-269AI Copilot – Content Generator <= 1.5.6 - Unauthenticated Privilege Escalatio…
CVE-2026-719579.345.8D-Link CorporationDWR-M961CWE-120D-Link DWR-M961 Buffer Overflow via app.cgi
CVE-2026-719589.344.3D-Link CorporationDWR-M961CWE-120D-Link DWR-M961 Buffer Overflow via quicksetup.cgi
CVE-2026-676206.335.7FlowiseAIFlowiseCWE-918Flowise 3.1.4 SSRF via fetch-links Endpoint Incomplete Deny-List
CVE-2026-87988.725.9Legion of the Bouncy Castle Inc.BC-FJACWE-835Native entropy source retries the CPU entropy instructions without limit
CVE-2026-680829.823.5LinuxLinuxlibceph: fix two unsafe bare decodes in decode_lockers()
CVE-2026-165787.521.4UnknownAdmin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force ProtectionCWE-200Admin Safety Guard < 1.4.0 - Unauthenticated User Data Disclosure via 2fa/app…
CVE-2026-162678.119.0UnknownNewslettersCWE-502Newsletters < 4.16 - Unauthenticated PHP Object Injection via Date Form Field
CVE-2026-189886.418.6shapedpluginEasy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQCWE-79Easy Accordion <= 3.1.8 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-135058.717.0Legion of the Bouncy Castle Inc.BC-FJACWE-772Zeroisation of sensitive key material on garbage collection relies on finaliz…
CVE-2026-165947.516.0UnknownWP Directory KitCWE-200WP Directory Kit < 1.5.5 - Subscriber+ Plugin Settings and API Key Disclosure
CVE-2026-165596.814.8UnknownYMC FilterCWE-79YMC Filter < 3.12.9 - Author+ Stored XSS via SVG Icon Upload
CVE-2026-169555.014.2UnknownAI EngineCWE-22AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio Transcription
CVE-2026-162694.813.6UnknownNewslettersCWE-287Newsletters < 4.16 - Unauthenticated API Authentication Bypass via Type Juggling
CVE-2026-165626.512.6UnknownWP StatisticsCWE-200WP Statistics < 14.16.10 - Subscriber+ Sensitive Data Disclosure via Metabox …
CVE-2026-165906.512.6UnknownWP Directory KitCWE-200WP Directory Kit < 1.5.5 - Subscriber+ Contact Message and User Data Disclosure
CVE-2026-165956.512.6UnknownWP Directory KitCWE-200WP Directory Kit < 1.5.5 - Subscriber+ User and Unpublished Listing Disclosure
CVE-2026-165897.712.2UnknownWP Directory KitCWE-89WP Directory Kit < 1.5.5 - Subscriber+ SQL Injection via data_fields_list Par…
CVE-2026-169488.111.5UnknownSolace ExtraCWE-284Solace Extra < 1.6.1 - Subscriber+ Multiple Missing Authorization via Site-Wi…
CVE-2026-421707.88.7Red HatRed Hat Enterprise Linux 6CWE-131Gimp: gimp dds plug-in heap-based buffer overflow via bpp mismatch in load_la…
CVE-2026-162825.38.1UnknownAppointment Hour BookingCWE-287Appointment Hour Booking < 1.5.88 - Unauthenticated Booking Price Manipulatio…
CVE-2026-166085.38.1UnknownDownload MonitorCWE-862Download Monitor < 5.2.6 - Unauthenticated Download Log Injection
CVE-2026-169534.86.8UnknownAI EngineCWE-639AI Engine < 3.6.4 - Unauthenticated Cross-Session Chatbot File Deletion via F…
CVE-2026-165356.15.9UnknownLink LibraryCWE-79Link Library < 7.9.4 - Reflected XSS via Thumbs-Rating likelabel
CVE-2026-68081await5.2LinuxLinuxKVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state
CVE-2026-165745.43.6UnknownDokan: AI Powered WooCommerce Multivendor Marketplace SolutionCWE-639Dokan < 5.0.11 - Vendor+ Cross-Vendor Downloadable Product Access Grant via O…
CVE-2026-192871.93.6abrinsmeadmindpilot-mcpCWE-22abrinsmead mindpilot-mcp HistoryService path traversal
CVE-2026-192701.93.6Hulupeepmcp-ui-probeCWE-22Hulupeep mcp-ui-probe Journey/Usage JourneyStorage.ts usage_stats path traversal
CVE-2026-192851.93.6aaronsbmemory-graphCWE-22aaronsb memory-graph memoryTools.ts JsonMemoryStorage.saveMemories path trave…
CVE-2026-192881.93.6astralisonerive-mcp-server-coreCWE-22astralisone rive-mcp-server-core importRiveFile Flow importRiveFile.ts path t…
CVE-2026-165585.43.3UnknownYMC FilterCWE-79YMC Filter < 3.12.8 - Contributor+ Stored XSS via Layout Builder Schema
CVE-2026-192591.92.5MZ Automationlibiec61850CWE-119MZ Automation libiec61850 MMS Protocol Workflow iec61850_common.c MmsMapping_…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-08 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion.