boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Monday, August 10, 2026 · all times UTC← 2026-08-09 · archive · 2026-08-11 →

Security Box Score — August 10, 2026

670 CVEs published, led by Linux (344).

670 CVEs published August 10, 2026: 85 critical, 251 high, 129 medium, 17 low; 0 in the KEV catalog at press time; 9 with a public exploit reference; 188 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 270 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published271824882——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

1373 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux3902705233138963711120.17.8.0016+352 ▲
google431804222743783567760.37.5.0025-36 ▼
microsoft33145512199132914286241.67.8.0047-19 ▼
red hat754612318722031200.06.5.0030+39 ▲
apple1272587813338872.66.8.0027+1 ▲
canonical02738115000.05.6.0014-1 ▼
suse52651461000.08.1.0039-1 ▼
freebsd01601240000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco30681336190561217.67.5.0046+22 ▲
ubiquiti036142110338.38.8.0049-25 ▼
palo alto networks025131471328.04.7.0028-14 ▼
fortinet0236611028626.17.2.00400
netgear02300221000.04.6.00240
vmware0174922715.98.3.0040-1 ▼
f50165830416.38.6.00570
checkpoint11346303215.47.8.0436+1 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache7641283181135123320.57.5.0050+15 ▲
mozilla11285142350900.08.1.0031-2 ▼
drupal05165355412.05.9.0026-46 ▼
gitlab05107377423.94.9.0029-7 ▼
github2141490000.06.2.0043+1 ▲
docker070520000.08.2.00160
wordpress1412102250.08.8.5550+1 ▲
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle01379343653322612730.28.1.00360
ibm3226172104841610.47.5.0031+30 ▲
adobe82603311710641931.27.8.0026+5 ▲
progress1153143270611.98.1.0037+1 ▲
solarwinds0231733010417.49.1.00580
veeam10165920100.08.6.0034+10 ▲
zohocorp062220000.07.8.01460
atlassian0303001300.08.0.00260
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link153515596300.07.4.0157+14 ▲
synology12426133000.05.6.0025+1 ▲
rockwell automation02441820000.08.7.00290
siemens0161870000.07.6.0024-4 ▼
schneider electric091620000.08.6.00370
abb070430000.07.2.00180
hikvision060420000.07.2.00400
moxa050320000.07.0.00290
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester12132007161000.05.5.0033-16 ▼
openclaw01110583914000.07.0.0026-1 ▼
dell8107950453210.97.2.0021-25 ▼
nvidia16981366190000.07.7.0034-1 ▼
capgo083242381000.07.1.0037-13 ▼
itsourcecode879001960000.02.1.0033-2 ▼
spring079234412000.06.5.00220
imagemagick078156012000.05.3.0018-12 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.995799.99.8
CVE-2026-34486.986299.97.5
CVE-2026-63030.977999.99.8
CVE-2026-16232.891299.89.3
CVE-2026-63077.847399.79.8
CVE-2026-50522.846199.79.8
CVE-2026-15409.836699.710.0
CVE-2026-60137.797999.65.9
CVE-2026-6875.775899.59.5
CVE-2026-25089.761199.59.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1540910.0.8366KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0486
CVE-2026-4766810.0.0388
CVE-2026-4633910.0.0335
CVE-2026-4435910.0.0180
CVE-2026-1681210.0.0157KEV
CVE-2025-7138910.0.0120
CVE-2026-4816810.0.0091
CVE-2026-5288710.0.0089
Most disclosures (vendor)
VendorCVEs
linux1187
oracle1109
microsoft645
google460
red hat203
apache196
apple168
ibm135
adobe113
mozilla69
Most KEV additions (YTD)
VendorKEV
microsoft24
cisco12
apple7
fortinet6
google6
ivanti5
solarwinds4
adobe3
berriai3
oracle3
Most-affected ecosystems
EcosystemAdvisories
Maven66
PyPI5
Go3
npm3
Packagist2
crates.io2
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2021-27137DD-WRT0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20316Cisco0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171727
CVE-2021-27102n/a2021-11-171727
CVE-2021-27101n/a2021-11-171727
CVE-2021-27103n/a2021-11-171727
CVE-2021-21017Adobe2021-11-171727
CVE-2021-28550Adobe2021-11-171727
CVE-2021-42013Apache Software Foundation2021-11-171727
CVE-2021-41773Apache Software Foundation2021-11-171727
CVE-2021-30858Apple2021-11-171727
CVE-2021-30860Apple2021-11-171727

Transactions

EXPLOIT PUBLISHED — code-projects Task Management System: 3 CVEs (CVE-2026-19342, CVE-2026-19343, CVE-2026-19344). Public exploit references added.

EXPLOIT PUBLISHED — Microsoft Windows 10 Version 1507: 3 CVEs (CVE-2021-34527, CVE-2021-40444, CVE-2024-38217). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2021-34473 (Microsoft Exchange Server 2013 Cumulative Update 23). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2021-34523 (Microsoft Exchange Server 2013 Cumulative Update 23). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2021-36942 (Microsoft Windows Server 2008 R2 Service Pack 1). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2021-38647 (Microsoft Azure Automation State Configuration, DSC Extension). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2021-38648 (Microsoft Azure Automation State Configuration, DSC Extension). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2024-21338 (Microsoft Windows 10 Version 1809). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2024-21413 (Microsoft 365 Apps for Enterprise). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-10774 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-10848 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-15038 (Unknown InfiniteWP Client). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16032 (Unknown LWS Optimize). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16267 (Unknown Newsletters). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16269 (Unknown Newsletters). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16282 (Unknown Appointment Hour Booking). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16548 (Unknown Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16559 (Unknown YMC Filter). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16574 (Unknown Dokan: AI Powered WooCommerce Multivendor Marketplace Solution). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16589 (Unknown WP Directory Kit). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16608 (Unknown Download Monitor). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16948 (Unknown Solace Extra). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16953 (Unknown AI Engine). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16955 (Unknown AI Engine). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16957 (Unknown Slim SEO). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16965 (Unknown Solace Extra). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16988 (Unknown GeoDirectory). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16992 (Unknown Create). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-17011 (Unknown Nexter Blocks). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-17014 (Unknown WP Photo Album Plus). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-17017 (Unknown CubeWP Framework). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-17044 (Unknown Iptanus File Upload). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-18032 (Unknown WP Data Access). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-18037 (Unknown Create). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-18357 (Unknown WPC Order Tip for WooCommerce). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-18464 (Unknown WP MAPS PRO). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-18465 (Unknown WP MAPS PRO). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-18473 (Unknown WP Directory Kit). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-18603 (Unknown PiWeb Cancel order / Refund request for WooCommerce). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19243 (HKUDS nanobot). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19341 (UTT HiPER 1200GW). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19346 (Tenda CH22). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19347 (itsourcecode Hospital Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19348 (Shenzhen Aitemi M300 Wi-Fi Repeater). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19352 (mifi lossless-cut). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19353 (DedeCMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19364 (itsourcecode Hospital Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19373 (PhialsBasement KoboldCPP-MCP-Server). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-31842 (Tinyproxy Project Tinyproxy). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48710 (Kludex starlette). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-66297 (livebook-dev livebook). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-66757 (GNOME GIMP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-66881 (livebook-dev livebook). Public exploit reference added.

RESCORED — Microsoft Windows 10 Version 1507: 9 CVEs (CVE-2023-35384, CVE-2023-36903, CVE-2023-36905, CVE-2023-36906, CVE-2023-36907, CVE-2023-36913, CVE-2024-21343, CVE-2024-38240, CVE-2024-38254). CVSS rescored — before/after on each CVE page.

RESCORED — Microsoft Windows Server 2008 Service Pack 2: 3 CVEs (CVE-2024-38231, CVE-2024-38258, CVE-2024-43455). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2023-35391 (Microsoft .NET 6.0). CVSS 6.2 → 7.5 (NVD).

RESCORED — CVE-2023-36741 (Microsoft Edge (Chromium-based)). CVSS 8.3 → 7.5 (NVD).

RESCORED — CVE-2023-36769 (Microsoft Office 2019). CVSS 4.6 → 5.4 (NVD).

RESCORED — CVE-2023-36873 (Microsoft .NET Framework 3.5 and 4.6.2). CVSS 7.4 → 5.9 (NVD).

RESCORED — CVE-2023-36897 (Microsoft 365 Apps for Enterprise). CVSS 8.1 → 6.5 (NVD).

RESCORED — CVE-2023-38186 (Microsoft Windows 10 Version 21H2). CVSS 8.8 → 9.8 (NVD).

RESCORED — CVE-2024-0565 (Linux kernel). CVSS 6.8 → 7.4 (NVD).

RESCORED — CVE-2024-0775 (Linux kernel). CVSS 6.7 → 7.1 (NVD).

RESCORED — CVE-2024-21416 (Microsoft Windows 10 Version 1809). CVSS 8.1 → 9.8 (NVD).

RESCORED — CVE-2024-21489 (uplot). CVSS 8.8 → 7.8 (NVD).

RESCORED — CVE-2024-37337 (Microsoft SQL Server 2017 (CU 31)). CVSS 7.1 → 4.3 (NVD).

RESCORED — CVE-2024-37341 (Microsoft SQL Server 2016 Service Pack 3 (GDR)). CVSS 8.8 → 9.8 (NVD).

RESCORED — CVE-2024-37342 (Microsoft SQL Server 2017 (CU 31)). CVSS 7.1 → 4.3 (NVD).

RESCORED — CVE-2024-37980 (Microsoft SQL Server 2016 Service Pack 3 (GDR)). CVSS 8.8 → 9.8 (NVD).

RESCORED — CVE-2024-38194 (Microsoft Azure Web Apps). CVSS 8.4 → 9.9 (NVD).

RESCORED — CVE-2024-38216 (Microsoft Azure Stack Hub). CVSS 8.2 → 9 (NVD).

RESCORED — CVE-2024-38225 (Microsoft Dynamics 365 Business Central 2023 Release Wave 1). CVSS 8.8 → 9.8 (NVD).

RESCORED — CVE-2024-38230 (Microsoft Windows Server 2012 R2). CVSS 6.5 → 7.5 (NVD).

RESCORED — CVE-2024-43460 (Microsoft Dynamics 365 Business Central Online). CVSS 8.1 → 8.8 (NVD).

RESCORED — CVE-2024-43474 (Microsoft SQL Server 2017 (CU 31)). CVSS 7.6 → 7.5 (NVD).

RESCORED — CVE-2024-43476 (Microsoft Dynamics 365 (on-premises) version 9.1). CVSS 7.6 → 5.4 (NVD).

RESCORED — CVE-2024-43489 (Microsoft Edge (Chromium-based)). CVSS 6.5 → 8.8 (NVD).

RESCORED — CVE-2024-43496 (Microsoft Edge (Chromium-based)). CVSS 6.5 → 8.8 (NVD).

RESCORED — CVE-2025-38525 (Linux). CVSS 7.5 → 5.5 (NVD).

RESCORED — CVE-2026-19375 (dmitriiweb article-scraper-mcp). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-19376 (Uasoft Badaso). CVSS 6.9 → 5.5 (NVD).

RESCORED — CVE-2026-19378 (code-projects Task Management System). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-48618 (nodejs node). CVSS 7.7 → 6.5 (NVD).

RESCORED — CVE-2026-8037 (Progress Software LoadMaster). CVSS 9.6 → 9.8 (NVD).

Yesterday's Results

How to read these box scores · glossary

670 CVEs published. 25 box scores and 375 table rows below; the remaining 270 continue on page 2 — every CVE is listed, nothing truncated.

usmannasir cyberpanel — CyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfer
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0208   80.0     —
AFFECTED
  Product     Versions     Fixed
  cyberpanel  unspecified  eca0c3cbeb35af8eaae9fafb094e8ef3cd923643
TIMELINE
  Aug 8   Reserved by CNA
  Aug 10  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0166   74.8     —
AFFECTED
  Product         Versions   Fixed
  ipTIME AX8004M  15.09.0 –  —
TIMELINE
  Aug 9   Reserved by CNA
  Aug 10  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Apache Ranger: OS Command Injection via Username in UnixUserGroupBuilder
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0131   68.5     —
AFFECTED
  Product        Versions  Fixed
  Apache Ranger  0.6 –     —
TIMELINE
  Mar 2   Reserved by CNA
  Aug 10  Published (CNA: apache)
CWE-77 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Analyzed
alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0128   67.8     —
AFFECTED
  Product     Versions     Fixed
  crontab-ui  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 10  Published (CNA: TuranSec)
CWE-93 · CNA: TuranSec · CVSS v3.1 · 2 references · NVD status: Received
Zyxel Networks WAH7601 — Multiple Vulnerabilities in Zyxel's WAH7601 - OS Command Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0127   67.6     —
AFFECTED
  Product  Versions     Fixed
  WAH7601  unspecified  —
TIMELINE
  Jun 24  Reserved by CNA
  Aug 10  Published (CNA: TR-CERT)
CWE-78 · CNA: TR-CERT · CVSS v3.1 · 1 reference · NVD status: Received
alseambusher crontab-ui - Unauthenticated RCE via Shell Injection in Imported Database hook Field
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0122   66.4     —
AFFECTED
  Product     Versions     Fixed
  crontab-ui  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 10  Published (CNA: TuranSec)
CWE-78 · CNA: TuranSec · CVSS v3.1 · 2 references · NVD status: Received
duhow xiaoai-patch - OS Command Injection in /mute and /unmute Endpoints
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0093   57.9     —
AFFECTED
  Product       Versions     Fixed
  xiaoai-patch  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 10  Published (CNA: TuranSec)
CWE-78 · CNA: TuranSec · CVSS v3.1 · 2 references · NVD status: Received
4xmen pm2panel - Authenticated OS Command Injection via id Query Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0091   57.1     —
AFFECTED
  Product   Versions     Fixed
  pm2panel  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 10  Published (CNA: TuranSec)
CWE-78 · CNA: TuranSec · CVSS v3.1 · 2 references · NVD status: Received
NASA fprime-gds - Missing Authentication and Path Traversal Enable Unauthenticated RCE and Spacecraft Command Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0086   55.6     —
AFFECTED
  Product     Versions     Fixed
  fprime-gds  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 10  Published (CNA: TuranSec)
CWE-306 · CNA: TuranSec · CVSS v3.1 · 4 references · NVD status: Received
o1lab xmysql - Unauthenticated Path Traversal via name Query Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0077   52.8     —
AFFECTED
  Product  Versions     Fixed
  xmysql   unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 10  Published (CNA: TuranSec)
CWE-22 · CNA: TuranSec · CVSS v3.1 · 2 references · NVD status: Received
mustafaakin cast-localvideo - Unauthenticated Path Traversal via dir Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0077   52.8     —
AFFECTED
  Product          Versions     Fixed
  cast-localvideo  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 10  Published (CNA: TuranSec)
CWE-22 · CNA: TuranSec · CVSS v3.1 · 2 references · NVD status: Received
Linux Linux — ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0076   52.5     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    a8599bd821d084d04a3290fffae1071624ec00ea –  —
  Linux    2.6.34 –                                    5.10.265
TIMELINE
  Jul 30  Reserved by CNA
  Aug 10  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 8 references · NVD status: Received
Linux Linux — libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0076   52.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    a303bb0e58345fe9f7ab2f82b90266f2b5036058 –  —
  Linux    4.13 –                                      5.10.266
TIMELINE
  Jul 30  Reserved by CNA
  Aug 10  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 8 references · NVD status: Received
Linux Linux — libceph: reject zero bucket types in crush_decode
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0070   50.5     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    f24e9980eb860d8600cbe5ef3d2fd9295320d229 –  —
  Linux    2.6.34 –                                    5.10.265
TIMELINE
  Jul 30  Reserved by CNA
  Aug 10  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 8 references · NVD status: Received
Linux Linux — libceph: Fix multiplication overflow in decode_new_up_state_weight()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0070   50.5     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    930c532869774ebf8af9efe9484c597f896a7d46 –  —
  Linux    4.7 –                                       5.10.265
TIMELINE
  Jul 30  Reserved by CNA
  Aug 10  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 8 references · NVD status: Received
Red Hat Red Hat OpenShift AI 2.25 — Feast: feast: unsafe dill deserialization of registry-stored udfs — rce on feature server and registry server
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0069   50.0     —
AFFECTED
  Product                       Versions     Fixed
  Red Hat OpenShift AI 2.25     unspecified  1786110051
  Red Hat OpenShift AI 3.3      unspecified  1786110033
  Red Hat OpenShift AI 3.4      unspecified  1786107278
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  + 6 more
TIMELINE
  Aug 5   Reserved by CNA
  Aug 10  Published (CNA: redhat)
CWE-502 · CNA: redhat · CVSS v3.1 · 5 references · NVD status: Awaiting Analysis
Apache Ranger: Remote Code Execution via JDBC URL Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0069   49.9     —
AFFECTED
  Product        Versions     Fixed
  Apache Ranger  unspecified  —
TIMELINE
  Apr 28  Reserved by CNA
  Aug 10  Published (CNA: apache)
CWE-94, CWE-20 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Analyzed
Linux Linux — libceph: guard missing CRUSH type name lookup
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0069   49.9     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    117d96a04f007ce8fc2e292369056c3bd09f6f63 –  —
  Linux    5.8 –                                       5.10.265
TIMELINE
  Jul 30  Reserved by CNA
  Aug 10  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 8 references · NVD status: Received
Linux Linux — libceph: refresh auth->authorizer_buf{,_len} after authorizer update
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0068   49.8     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    0bed9b5c523d577378b6f83eab5835fe30c27208 –  —
  Linux    3.10 –                                      5.10.265
TIMELINE
  Jul 30  Reserved by CNA
  Aug 10  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 8 references · NVD status: Received
Linux Linux — libceph: Reject monmaps advertising zero monitors
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0067   49.2     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    ba75bb98cfb93b62c54af25bf67ff90857264bbe –  —
  Linux    2.6.34 –                                    5.15.216
TIMELINE
  Jul 30  Reserved by CNA
  Aug 10  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 7 references · NVD status: Received
Apache Ranger: Remote Code Execution via Arbitrary Class Instantiation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0066   48.9     —
AFFECTED
  Product        Versions     Fixed
  Apache Ranger  unspecified  —
TIMELINE
  May 6   Reserved by CNA
  Aug 10  Published (CNA: apache)
CWE-94, CWE-470 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Analyzed
Apache Ranger: Remote Code Execution Vulnerability in GraalScriptEngineCreator
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0065   48.3     —
AFFECTED
  Product        Versions     Fixed
  Apache Ranger  unspecified  —
TIMELINE
  Jun 17  Reserved by CNA
  Aug 10  Published (CNA: apache)
CWE-94 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Analyzed
NASA HyperCP - OS Command Injection via Malicious HTTP Response from Data Server
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   R  U  H  H  H    7.5   .0065   48.1     —
AFFECTED
  Product  Versions     Fixed
  HyperCP  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 10  Published (CNA: TuranSec)
CWE-78 · CNA: TuranSec · CVSS v3.1 · 2 references · NVD status: Received
Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   N   H   H    7.0   .0064   48.1     —
AFFECTED
  Product                  Versions     Fixed
  sucuri-wordpress-plugin  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 10  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
Dokploy: Remote Code Execution via volume-backup
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0063   47.6     —
AFFECTED
  Product  Versions     Fixed
  dokploy  < 0.29.13 –  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 10  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-681619.847.3LinuxLinux—sctp: close UDP tunnel sockets during netns teardown
CVE-2026-6691510.046.6fabrikar.comFabrik extension for JoomlaCWE-94Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fa…
CVE-2026-683797.546.1LinuxLinux—tcp: fix TIME_WAIT socket reference leak on PSP policy failure
CVE-2026-727359.945.9DokploydokployCWE-77Dokploy: Command injection in writeTraefikConfigRemote via shell interpolatio…
CVE-2026-683009.845.9LinuxLinux—sctp: auth: verify auth requirement when auth_chunk is NULL
CVE-2026-189417.745.5Red HatRed Hat OpenShift AI 2.25CWE-306Feast: feast-operator: feast: default authentication mode is no_auth — shared…
CVE-2026-590909.945.3—gimpCWE-191Gimp: gimp: arbitrary code execution in psd plugin due to unsigned underflow
CVE-2026-728850.044.9DokploydokployCWE-78Dokploy: Authenticated Command Injection in Dokploy Dockerfile Builder
CVE-2026-107548.644.8PegasystemsPega InfinityCWE-347Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper valid…
CVE-2026-189518.844.7Red HatRed Hat OpenShift AI 3.3CWE-284Odh-training-operator-rhel9: [trainer v2 security] trn-02: rhoai overlay aggr…
CVE-2026-683418.844.4LinuxLinux—ovpn: fix use after free in unlock_ovpn()
CVE-2026-7289910.044.0MetabaseMetabaseCWE-89Metabase SQL injection via public card or dashboard
CVE-2026-681239.844.0LinuxLinux—openvswitch: fix GSO userspace truncation underflow
CVE-2026-691188.743.6cachethqcachetCWE-863Cachet 2.4.1 Authenticated Server-Side Template Injection RCE
CVE-2026-725679.843.6AsyncFuncAIdeepwiki-openCWE-22deepwiki-open - Unauthenticated Path Traversal Leading to Arbitrary File Writ…
CVE-2026-681369.843.3LinuxLinux—net: gro: fix double aggregation of flush-marked skbs
CVE-2026-681279.843.2LinuxLinux—ila: reload IPv6 header after pskb_may_pull in checksum adjust
CVE-2026-681379.843.2LinuxLinux—net/x25: fix use-after-free in x25_kill_by_neigh()
CVE-2026-681449.843.2LinuxLinux—phonet: pep: fix use-after-free in pep_get_sb()
CVE-2026-680967.543.0LinuxLinux—audit: fix recursive locking deadlock in audit_dupe_exe()
CVE-2026-729029.942.9DokploydokployCWE-78Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / r…
CVE-2026-728758.842.9DokploydokployCWE-78Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTr…
CVE-2026-186187.543.0Red HatRed Hat OpenShift AI 2.25CWE-770Ml-metdata: bundled grpc 1.46.3 (2022) with published http/2 dos cves — direc…
CVE-2026-725929.842.7dullduskphpfmCWE-434dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP F…
CVE-2026-681179.842.5LinuxLinux—tipc: clear sock->sk on the failed-insert path in tipc_sk_create()
CVE-2026-681317.542.4LinuxLinux—rbd: Reset positive result codes to zero in object map update path
CVE-2026-681417.542.4LinuxLinux—net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()
CVE-2026-725939.842.2dullduskphpfmCWE-306dulldusk phpfm - Missing Authentication by Default Allows Full Filesystem Access
CVE-2025-302418.642.2TP-Link Systems Inc.HB810(US2) V1.0/1.6/2.0/2.6CWE-78OS Command Injection in Web Interface in Multiple TP-Link Aginet Devices
CVE-2026-727389.941.9DokploydokployCWE-78Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles se…
CVE-2026-727409.941.9DokploydokployCWE-78Dokploy: OS Command Injection via SSH-form `customGitUrl` domain in `ssh-keys…
CVE-2026-681297.541.7LinuxLinux—gve: fix Rx queue stall on alloc failure
CVE-2026-683157.541.7LinuxLinux—sctp: validate stream count in sctp_process_strreset_inreq()
CVE-2026-681709.841.6LinuxLinux—mptcp: fix stale skb->sk reference on subflow close
CVE-2026-683889.841.4LinuxLinux—smb/client: handle overlapping allocated ranges in fallocate
CVE-2026-725699.141.4cube-rootdirectory-serveCWE-22cube-root directory-serve - Unauthenticated Path Traversal Arbitrary File Del…
CVE-2026-683439.141.3LinuxLinux—smb: client: validate DFS referral PathConsumed
CVE-2025-156838.841.1TBEATBEA TLogger (TBEA Communication Box 3rd Generation)CWE-121Multiple Unauthenticated Denial-of-Service Conditions
CVE-2026-682997.541.0LinuxLinux—vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
CVE-2026-726887.540.6OpenSignLabsopensignserverCWE-306OpenSignLabs opensignserver - Missing Authentication for Critical Function
CVE-2026-189828.840.2Red HatRed Hat OpenShift AI 2.25CWE-250Odh-training-operator-rhel9: rhoai fork aggregates training job create onto n…
CVE-2026-683859.839.9LinuxLinux—s390/checksum: Fix csum_partial() without vector facility
CVE-2026-728679.939.9DokploydokployCWE-20Dokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated …
CVE-2026-481599.339.8dai-shiuse-reducer-asyncCWE-506use-reducer-async was vulnerable to malicious code execution via compromised …
CVE-2026-682877.539.8LinuxLinux—drop_monitor: fix size calculations for 64-bit attributes
CVE-2026-727339.939.4DokploydokployCWE-78Dokploy: OS Command Injection via `databaseName` / `backupFile` in database r…
CVE-2026-683029.839.4LinuxLinux—amt: re-read skb header pointers after every pull
CVE-2025-156819.239.1TBEATBEA TLogger (TBEA Communication Box 3rd Generation)CWE-306Insufficient Webserver Authentication
CVE-2026-590877.839.1—gimpCWE-787Gimp: heap buffer overflow in `file-seattle-filmworks` load — `fread` writes …
CVE-2026-683768.138.9LinuxLinux—sctp: fix auth_hmacs array size in struct sctp_cookie
CVE-2026-728816.438.9DokploydokployCWE-78Dokploy: Command Injection via database credentials in backup/restore commands
CVE-2026-728769.938.5DokploydokployCWE-78Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server…
CVE-2026-725659.838.5TencentAPIJSONCWE-89Tencent APIJSON - Unauthenticated SQL Injection via @having Operator Map-Form…
CVE-2026-190899.838.0UnknownProduct Input Fields for WooCommerceCWE-434Product Input Fields for WooCommerce < 2.0.2 - Unauthenticated Arbitrary File…
CVE-2026-727244.337.8discoursediscourseCWE-639Discourse: Private Chat Threat Message Disclosure via Chat Onebox Channel/Thr…
CVE-2026-683819.837.7LinuxLinux—ksmbd: pin conn during async oplock break notification
CVE-2026-618997.537.5Apache Software FoundationApache TapestryCWE-200Apache Tapestry: Possible classpath file download through URL manipulation
CVE-2026-729147.537.5mastodonmastodonCWE-405Mastodon: Exhausting data by an unauthenticated request to the admin retentio…
CVE-2026-144509.937.4Red HatRed Hat OpenShift AI 3.4CWE-290Maas-billing: maas api: privilege escalation via forged http headers due to m…
CVE-2026-730307.237.2frostmingunearthCWE-22unearth 0.18.2 Path Traversal via Unnormalized Paths and Symlink Escape
CVE-2026-186178.837.0Red HatRed Hat OpenShift AI 2.25CWE-915Data-science-pipelines-operator: dspo: mysql dsn parameter injection via cust…
CVE-2026-719628.737.1FlowiseAIFlowiseCWE-862Flowise 2.2.4 - 3.1.4 Missing Authorization via openai-assistants-file/download
CVE-2026-680839.136.9LinuxLinux—ksmbd: fix path resolution in ksmbd_vfs_kern_path_create
CVE-2026-727396.536.8DokploydokployCWE-78Dokploy: Command Injection via Compose Shell Execution
CVE-2026-184129.136.5OpenCartOpenCart—The OpenCart v4.2.0.0 extension installer contains a directory traversal vuln…
CVE-2026-681207.536.5LinuxLinux—rtase: Workaround for TX hang caused by hardware packet parsing
CVE-2026-186088.736.1Red HatRed Hat OpenShift AI 2.25CWE-250Data-science-pipelines-operator: dspo: operator clusterrole grants pods/exec:…
CVE-2026-681008.136.0LinuxLinux—ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl
CVE-2026-727369.935.9DokploydokployCWE-77Dokploy: OS Command Injection in registry credential testing and Swarm cluste…
CVE-2026-728629.935.9DokploydokployCWE-78Dokploy: OS Command Injection via dockerImage field in database service deplo…
CVE-2026-189478.535.8Red HatRed Hat OpenShift AI 2.25CWE-862Feast: feast: authorization bypass in /materialize endpoints enables dos via …
CVE-2026-727215.335.5discoursediscourseCWE-178Discourse: Onebox Domain Blocklist Bypass via Case-Sensitive Comparison
CVE-2026-728848.735.3DokploydokployCWE-78Dokploy: Command Injection via Compose Custom Command
CVE-2026-481619.334.6dai-shireact18-useCWE-506react18-use was vulnerable to malicious code execution via compromised commits
CVE-2026-681968.334.6LinuxLinux—wifi: wilc1000: validate assoc response length before subtracting header
CVE-2026-683528.334.6LinuxLinux—wifi: ath6kl: fix OOB read from firmware IE lengths in connect event
CVE-2026-169858.834.4UnknownSqueezeCWE-434Squeeze < 1.7.12 - Author+ Arbitrary File Upload
CVE-2026-446307.534.3Apache Software FoundationApache IoTDBCWE-400Apache IoTDB: RPC service denial of service via unchecked Thrift string length
CVE-2026-189498.834.2Red HatRed Hat OpenShift AI 2.25CWE-250Odh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets…
CVE-2026-680978.834.2LinuxLinux—ksmbd: validate ACE size against SID sub-authorities
CVE-2026-680988.834.2LinuxLinux—ksmbd: bound DACL dedup walk to copied ACEs
CVE-2026-681928.834.0LinuxLinux—wifi: brcmfmac: make release_scratchbuffers idempotent
CVE-2026-681998.834.0LinuxLinux—wifi: ath6kl: fix OOB access from firmware ADDBA window size
CVE-2026-727196.733.8chatwootchatwootCWE-915Chatwoot: Cross-Account Resource Transfer via `account_id` Parameter
CVE-2026-667387.733.7SPIPSPIPCWE-94SPIP < 4.4.18 Code Injection via Navigation Endpoint on SQLite
CVE-2026-728779.633.0DokploydokployCWE-78Dokploy: Command Injection via dockerImage in buildRemoteDocker
CVE-2025-132949.333.0TBEATBEA TLogger (TBEA Communication Box 3rd Generation)CWE-89Unauthenticated SQL Injection
CVE-2026-728838.832.9DokploydokployCWE-862Dokploy: WebSocket Terminal Missing Service-Level Access Control
CVE-2026-681188.232.5LinuxLinux—tcp: challenge ACK for non-exact RST in SYN-RECEIVED
CVE-2026-481589.332.5dai-shiuse-context-selectorCWE-506use-context-selector was vulnerable to malicious code execution via compromis…
CVE-2026-481609.332.5dai-shireact-trackedCWE-506react-tracked was vulnerable to malicious code execution via compromised commits
CVE-2025-156828.732.5TBEATBEA TLogger (TBEA Communication Box 3rd Generation)CWE-770Unauthenticated Resource Exhaustion
CVE-2026-186117.532.4Red HatRed Hat OpenShift AI 2.25CWE-338Data-science-pipelines-operator: dspo: cryptographically weak secret generati…
CVE-2026-726917.532.1OpenSignLabsopensignserverCWE-288OpenSignLabs opensignserver - Authentication Bypass
CVE-2026-713925.331.8GNUEmacsCWE-190Integer Overflow in GNU Emacs for Android
CVE-2026-713935.331.8GNUEmacsCWE-190Heap Buffer Overflow in GNU Emacs for Android
CVE-2026-409209.831.7Apache Software FoundationApache RangerCWE-269Apache Ranger: Privilege Escalation via URL Parameter
CVE-2026-131707.231.5UnknownEventinCWE-22Eventin < 4.1.20 - Editor+ Local File Inclusion via speaker_template Setting
CVE-2026-727235.331.2discoursediscourseCWE-862Discourse: Anonymous sidebar serialization exposes descriptions of category-r…
CVE-2026-729119.931.1frappeerpnextCWE-1336ERPNext: Possibility of server-side template injection due to missing validation
CVE-2026-154678.130.9Red HatRed Hat OpenShift AI 2.25CWE-266Trustyai-service-operator: trustyai-service-operator: lmevaljob sidecar conta…
CVE-2026-725759.130.2daptindaptinCWE-284daptin - Authentication Bypass via Null Owner Permission Check on usergroup O…
CVE-2026-682838.830.1LinuxLinux—tracing: Fix use-after-free freeing trigger private data
CVE-2026-681197.530.0LinuxLinux—tcp: initialize standalone TCP-AO response padding
CVE-2026-728729.929.9DokploydokployCWE-78Dokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone`
CVE-2025-132939.329.8TBEATBEA TLogger (TBEA Communication Box 3rd Generation)CWE-798Backdoor / default root credentials
CVE-2026-725867.529.5frangoteamFUXACWE-306frangoteam FUXA - Missing Authentication on DAQ_QUERY Socket.IO Event Handler
CVE-2026-684269.829.4LinuxLinux—xfrm: fix stale skb->prev after async crypto steals a GSO segment
CVE-2026-558147.529.3Apache Software FoundationApache RangerCWE-306Apache Ranger: Download APIs expose plugin data without authentication
CVE-2026-322279.829.2Apache Software FoundationApache RangerCWE-89Apache Ranger: SQL Injection vulnerability in lookup functionality
CVE-2026-728689.929.0DokploydokployCWE-78Dokploy: Member-role RCE as host root via destination.testConnection rclone s…
CVE-2026-725818.629.0duhowxiaoai-patchCWE-918duhow xiaoai-patch - Server-Side Request Forgery in /auth Endpoint
CVE-2026-727616.928.9vulnerability-lookupvulnerability-lookupCWE-918Webhook SSRF guard bypassed by IPv6 transition addresses (NAT64/6to4/Teredo p…
CVE-2026-728869.928.8DokploydokployCWE-269Dokploy: Non-admin member gains root on the host by bypassing the owner/admin…
CVE-2026-189508.828.8Red HatRed Hat OpenShift AI 2.25CWE-269Odh-dashboard: odh-dashboard: confused-deputy privilege escalation via unchec…
CVE-2026-480487.528.7xwikixwiki-platformCWE-359XWiki Platform's Livetable results still allow reconstructing password hashes…
CVE-2026-659456.528.7Apache Software FoundationApache RangerCWE-532Apache Ranger: Logs contain replayable JWT bearer tokens
CVE-2026-210755.328.6Samsung MobileMy GalaxyCWE-939Improper authorization in handler for custom URL scheme in My Galaxy prior to…
CVE-2026-729166.328.6mastodonmastodonCWE-918Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses
CVE-2026-728829.928.1DokploydokployCWE-78Dokploy: Authenticated blind command injection via file mounts leads to direc…
CVE-2026-137178.828.2Red HatRed Hat OpenShift AI 3.4CWE-284Rhoai maas: llm-d: maas/llm-d inference gateway: default allowedroutes.namesp…
CVE-2026-728748.728.1DokploydokployCWE-78Dokploy: Command Injection via Unescaped Git URL in Clone Commands
CVE-2026-728659.927.8DokploydokployCWE-78Dokploy: OS Command Injection via compose `composePath`
CVE-2026-728699.927.8DokploydokployCWE-77Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (…
CVE-2026-590917.827.7—gimpCWE-787Gimp: gimp: multiple vulnerabilities in file format plugins via crafted image…
CVE-2026-186217.627.6Red HatRed Hat OpenShift AI 2.25CWE-266Data-sciences-pipeline: dsp: v1 argo template path accepts arbitrary workflow…
CVE-2026-659487.327.5Apache Software FoundationApache RangerCWE-307Apache Ranger: UnixAuth lacks brute-force protection
CVE-2026-681249.627.3LinuxLinux—mctp: serial: handle zero-length frames to prevent rx buffer overflow
CVE-2026-725827.527.3fastschemafastschemaCWE-476fastschema - Unauthenticated NULL Pointer Dereference DoS in Account Recovery…
CVE-2026-719658.727.0usmannasircyberpanelCWE-345CyberPanel 2.4.3 Authenticated RCE via Remote Backup Feature
CVE-2026-706227.126.7composefstar-rsCWE-59tar-rs 0.4.11 - 0.4.46 Symlink Escape via append_dir_all()
CVE-2026-162989.826.7UnknownFoodBoxBookerCWE-269FoodBoxBooker < 1.0.7 - Unauthenticated Arbitrary Password Reset
CVE-2026-162999.826.7UnknownSingle Sign On For TNGCWE-287Single Sign On For TNG < 2.2.0 - Unauthenticated Arbitrary Password Reset
CVE-2026-136008.126.6UnknownAutoNetTV RelayCWE-287AutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled…
CVE-2026-649412.126.6phoenixframeworkphoenix_live_viewCWE-601Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR
CVE-2026-477549.326.2NCEASmetacatCWE-22unauthenticated path traversal in Metacat 2.x
CVE-2026-193897.126.2Red HatRed Hat Enterprise Linux 10CWE-190Gstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflo…
CVE-2026-659427.525.7Apache Software FoundationApache RangerCWE-297Apache Ranger: Clients accept TLS certificates issued for other hostnames
CVE-2026-727266.525.5discoursediscourseCWE-200Discourse: Unauthorized eavesdropping on private AI bot conversations.
CVE-2026-728736.525.5DokploydokployCWE-200Dokploy: Cross-tenant Git provider secrets are disclosed to low-privileged se…
CVE-2026-590885.525.5—gimpCWE-190Gimp: gimp: denial of service via signed integer overflow in fli file processing
CVE-2026-166269.325.4JaspersoftJasperReports ServerCWE-611JasperReports Server: XXE Injection Vulnerability (Unauthenticated)
CVE-2026-118107.525.2zephyrprojectzephyrCWE-476NULL-pointer dereference in UpdateHub OTA agent on empty inner metadata array…
CVE-2026-688716.525.1Apache Software FoundationApache Airflow Yandex providerCWE-639Apache Airflow Yandex provider: yandex Lockbox backend: team-scope guard bypa…
CVE-2026-688726.525.1Apache Software FoundationApache Airflow Amazon providerCWE-639Apache Airflow Amazon provider: amazon SSM / Secrets Manager backends: team-s…
CVE-2026-713915.325.0GNUEmacsCWE-193Off-by-One Error in GNU Emacs for Android
CVE-2026-726897.524.6OpenSignLabsopensignserverCWE-639OpenSignLabs opensignserver - Broken Object Level Authorization
CVE-2026-727224.324.7discoursediscourseCWE-862Discourse: Duplicate lookup reveals restricted topic titles through canonical…
CVE-2026-186207.124.3Red HatRed Hat OpenShift AI 2.25CWE-639Data-sciences-pipeline: user-controlled serviceaccount for workflow pods with…
CVE-2026-681258.824.3LinuxLinux—mac802154: llsec: reject frames shorter than the authentication tag
CVE-2026-719647.123.9usmannasircyberpanelCWE-59CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Upload
CVE-2026-142067.523.8UnknownHT Contact FormCWE-200HT Contact Form < 2.9.3 - Unauthenticated Saved Form Draft Data Disclosure
CVE-2026-175417.523.8UnknownFile ManagerCWE-200Bit File Manager < 6.9.1 - Unauthenticated File Activity Log Disclosure
CVE-2026-184707.523.8UnknownLogin & Register FormsCWE-200Login & Register Forms < 4.0.2 - Unauthenticated Registered User Email Addres…
CVE-2026-194046.523.8Red HatRed Hat Directory Server 11CWE-862389-ds-base: 389-ds-base: missing authorization allows anonymous clients to s…
CVE-2026-725649.623.5fosrlPangolinCWE-639fosrl Pangolin - Access Token Scope Bypass Allows Cross-Resource Authentication
CVE-2026-729038.123.2EugenytabbyCWE-22Tabby: Windows SFTP path traversal allows a malicious server to write files o…
CVE-2026-123396.923.2TP-Link Systems Inc.TL-MR6400 v5.3CWE-22Authenticated Arbitrary File Write Vulnerability in multiple devices
CVE-2026-164566.523.0Red HatRed Hat OpenShift AI 2.25CWE-441Odh-model-controller: odh-model-controller: cross-namespace secret read via n…
CVE-2026-728668.822.9DokploydokployCWE-862WebSocket Terminal Auth Bypass
CVE-2026-189425.522.9Red HatRed Hat OpenShift AI 2.25CWE-94Feast-operator: feast: feast apply cronjob runs user python with feature-serv…
CVE-2026-175427.522.3UnknownFile ManagerCWE-200Bit File Manager < 6.9.1 - Subscriber+ Sensitive Data Disclosure via bitapps_…
CVE-2026-729007.122.1MetabaseMetabaseCWE-862Metabase information exposure
CVE-2026-190498.622.1UnknownProSolution WP ClientCWE-89ProSolution WP Client < 2.0.9 - Unauthenticated SQLi and Plugin Data Deletion…
CVE-2026-727206.421.9discoursediscourseCWE-79Discourse: HTML injection in PrettyText.format_for_email from cooked-attribut…
CVE-2026-728639.921.8DokploydokployCWE-269Dokploy: Missing authorization in WebSocket handlers allows a low-privilege m…
CVE-2026-728809.921.8DokploydokployCWE-78Dokploy: Arbitrary File Write + Remote OS Command Injection via `certificateP…
CVE-2026-727348.421.7DokploydokployCWE-639Dokploy: Cross-organization authorization bypass in server.remove allows dele…
CVE-2026-728717.521.4DokploydokployCWE-306Dokploy: Unauthenticated Git Provider Injection via GitHub OAuth Callback
CVE-2026-631069.321.1RazinsoftReady eCommerceCWE-89ReadyEcommerce < 4.5.2 Unauthenticated SQL Injection via ProductController.php
CVE-2026-210616.021.0Samsung MobileSamsung Mobile DevicesCWE-20Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 a…
CVE-2026-683538.120.9LinuxLinux—wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler
CVE-2026-719596.920.9bitwardenserverCWE-862Bitwarden Server < 2026.7.2 Audit Log Injection via POST /collect
CVE-2026-729049.320.7firecrawlfirecrawlCWE-77Firecrawl: Arbitrary file read via JSON Schema $ref expansion
CVE-2026-187868.820.7UnknownCheckViewCWE-287CheckView < 2.3.2 - Administrator Account Creation via REST API Authenticatio…
CVE-2026-729086.520.7frappeerpnextCWE-89ERPNext: Possibility of SQL injection due to missing validation
CVE-2026-683548.820.5LinuxLinux—firewire: net: Fix fragmented datagram reassembly
CVE-2026-444014.620.2TypemillTypemillCWE-79Typemill CMS 2.x Persistent XSS via Markdown javascript URI
CVE-2026-175408.820.2UnknownFile ManagerCWE-284Bit File Manager < 6.9.1 - Subscriber+ Arbitrary File Read and Deletion via C…
CVE-2026-664058.720.2ECOVACS ROBOTICSDEEBOT PRO M1CWE-489DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The teln…
CVE-2026-681387.820.1LinuxLinux—net/sched: serialize qdisc_rtab_list against concurrent get/put
CVE-2026-727596.920.1mispcti-transmuteCWE-862cti-transmute Conversion History Authorization Bypass Leads to Sensitive Data…
CVE-2026-184785.120.0Magnolia DXPMagnolia CMSCWE-79Stored XSS in Magnolia CMS
CVE-2026-180308.119.8UnknownBricksForgeCWE-862Bricksforge < 3.1.8.8 - Unauthenticated Arbitrary Password Reset via Pro Forms
CVE-2026-184688.119.8UnknownLogin & Register FormsCWE-287Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Passwor…
CVE-2026-184698.119.8UnknownLogin & Register FormsCWE-287Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Passwor…
CVE-2026-713945.319.8GNUEmacsCWE-1284Heap Use of Uninitialized Memory in GNU Emacs for Android
CVE-2026-728799.419.7DokploydokployCWE-78Dokploy: Command Injection via Registry Credentials in Swarm Upload
CVE-2026-728708.719.7DokploydokployCWE-78Dokploy: Command Injection via Docker Credentials in buildRemoteDocker
CVE-2026-727292.019.7discoursediscourseCWE-79Discourse: Stored XSS in discourse-local-dates plugin
CVE-2026-681408.819.6LinuxLinux—net/iucv: fix use-after-free of a severed iucv_path
CVE-2026-681988.819.6LinuxLinux—wifi: ath6kl: fix use-after-free in aggr_reset_state()
CVE-2026-683738.119.6LinuxLinux—wifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
CVE-2026-729157.519.6mastodonmastodonCWE-200Mastodon: Personally-identifying information disclosure due to incorrect acce…
CVE-2026-691147.119.6Spacebar ServerSpacebar ServerCWE-639Spacebar Server Cross-Channel Message Deletion via Permission Check Bypass
CVE-2026-142938.819.5UnknownAutopayCWE-79Autopay / Blue Media for WooCommerce < 5.0.1 - Unauthenticated Stored XSS via…
CVE-2026-729107.119.3frappeerpnextCWE-862ERPNext: Unauthorised modification of master data due to missing validation
CVE-2026-728649.919.2DokploydokployCWE-862Dokploy Broken Access Control on docker-container-terminal WebSocket (Member …
CVE-2026-118093.719.1zephyrprojectzephyrCWE-125UpdateHub probe: uninitialized-heap out-of-bounds read of network-supplied me…
CVE-2026-726927.519.0OpenSignLabsopensignserverCWE-862OpenSignLabs opensignserver - Missing Authorization
CVE-2026-725917.718.7gabehfKoitoCWE-918Koito - Authenticated Server-Side Request Forgery via Album Image URL Parameter
CVE-2026-729097.118.5frappeerpnextCWE-284ERPNext: Broken Access Control on certain endpoints
CVE-2026-684027.118.5LinuxLinux—wifi: cfg80211: bound element ID read when checking non-inheritance
CVE-2026-729175.918.4Mintplex-Labsanything-llmCWE-180AnythingLLM: Password recovery accepts one recovery code twice after whitespa…
CVE-2026-727515.118.4mispcti-transmuteCWE-79Stored Cross-Site Scripting in CTI-Transmute Conversion Graph via Malicious S…
CVE-2026-728789.618.4DokploydokployCWE-78Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-c…
CVE-2026-683268.818.0LinuxLinux—wifi: mwifiex: bound uAP association event IEs to the event buffer
CVE-2026-683978.818.0LinuxLinux—net/iucv: take a reference on the socket found in afiucv_hs_rcv()
CVE-2026-684257.117.7LinuxLinux—IB/mad: Drop unmatched RMPP responses before reassembly
CVE-2026-193845.517.7SourceCodesterSimple Doctors Appointment SystemCWE-74SourceCodester Simple Doctors Appointment System ajax.php set_appointment sql…
CVE-2026-680918.817.6LinuxLinux—HID: wacom: stop hardware after post-start probe failures
CVE-2026-725667.717.1automatischautomatischCWE-918automatisch - Server-Side Request Forgery via HTTP Request Custom Action
CVE-2026-170227.516.9UnknownSalon Booking SystemCWE-200Salon Booking System – Free Version < 10.30.34 - Unauthenticated Booking Info…
CVE-2026-189467.516.9UnknownContact Form to Any APICWE-200Contact Form to Any API < 3.0.7 - Unauthenticated Sensitive File Disclosure v…
CVE-2026-664038.716.7ECOVACS ROBOTICSDEEBOT PRO M1CWE-489DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purpose…
CVE-2026-129848.216.7Zyxel NetworksWAH7601CWE-522Exposure of Sensitive Information to an Unauthorized Actor in Zyxel's WAH7601
CVE-2026-162578.216.7UnknownArvow AI SEO WriterCWE-287Arvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Creation via Web…
CVE-2026-683898.816.6LinuxLinux—Bluetooth: hci_qca: Clear memdump state on invalid dump size
CVE-2026-726907.116.6AttendizeAttendizeCWE-639Attendize Attendize - Cross-Tenant Authorization Bypass
CVE-2026-194338.616.4RoskusProspero Flow CRMCWE-639Authorization Bypass Through User-Controlled Key in Prospero Flow CRM contact…
CVE-2026-155818.016.3Red HatRed Hat OpenShift AI 2.25CWE-306Trustyai-service-operator: trustyai-service-operator: tas internal service by…
CVE-2026-118113.716.4zephyrprojectzephyrCWE-772Socket file-descriptor leak in UpdateHub OTA client start_coap_client() leadi…
CVE-2026-680858.016.2LinuxLinux—Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled
CVE-2026-725885.316.2bluewave-labsCheckmateCWE-204bluewave-labs Checkmate - User Enumeration via Differential HTTP Response in …
CVE-2026-727324.316.2discoursediscourseCWE-862Discourse: Templates endpoint exposes hidden tag names
CVE-2026-142377.216.0UnknownviteposCWE-269Vitepos < 3.6.0 - Outlet Manager+ Privilege Escalation
CVE-2026-727379.615.8DokploydokployCWE-639Dokploy: Cross-organization IDOR in Dokploy backup destinations exposes anoth…
CVE-2026-725847.415.6fastschemafastschemaCWE-367fastschema - TOCTOU Race Condition Bypasses OTP Attempt Limit in Account Reco…
CVE-2026-729076.515.7frappeerpnextCWE-285ERPNext: Broken Access Control on certain endpoint
CVE-2026-691165.315.3xpf0000FlyEnvCWE-79FlyEnv < 4.18.0 Cross-Site Scripting via v-html
CVE-2026-683938.815.1LinuxLinux—Bluetooth: hci_sync: extend conn_hash lookup critical sections
CVE-2026-684098.815.1LinuxLinux—wifi: mac80211: defer link RX stats percpu free to RCU
CVE-2026-193877.614.9Red HatRed Hat Enterprise Linux 10CWE-787Gstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write i…
CVE-2026-725746.115.0picocmsPicoCWE-644picocms Pico - Host Header Injection Enables Script Source Hijacking
CVE-2026-148868.214.8HashiCorpVault EnterpriseCWE-862Vault Enterprise vulnerable to cross-namespace entity deletion
CVE-2026-727605.314.7MISPcti-transmuteCWE-200cti-transmute Following List Exposes User Email Addresses to Authenticated Users
CVE-2026-64264.414.7Red HatRed Hat Enterprise Linux 10CWE-681Qemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-o…
CVE-2026-592338.714.6RoskusProspero Flow CRMCWE-639Missing Authorization in Prospero Flow CRM permission save endpoint allows pr…
CVE-2026-729194.314.6RocketChatRocket.ChatCWE-862Rocket.Chat: Broken Access Control in channels.convertToTeam Allows Unauthori…
CVE-2026-68278await14.5LinuxLinux—drm/dp/mst: fix buffer overflows in sideband chunk accumulation
CVE-2026-727308.714.4discoursediscourseCWE-79Discourse: Stored XSS chat-transcript username unescaped in Rich Text Editor
CVE-2026-68360await14.4LinuxLinux—hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
CVE-2026-148605.314.2UnknownPodcast PlayerCWE-918Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery
CVE-2026-190539.114.1UnknownProSolution WP ClientCWE-89ProSolution WP Client < 2.0.6 - Unauthenticated Blind SQLi via 'jobID' Parameter
CVE-2026-727274.814.1discoursediscourseCWE-79Discourse: Stored XSS in the moderation review queue
CVE-2026-684147.513.9LinuxLinux—wifi: cfg80211: cancel sched scan results work on unregister
CVE-2026-190776.513.9UnknownDuplicate PostCWE-639Copy & Delete Posts < 1.5.5 - Authenticated Arbitrary Post Deletion via Missi…
CVE-2026-63747.313.7Zyxel NetworksWAH7601CWE-798Hardcoded Credentials in Zyxel WAH7601 Router
CVE-2026-727317.113.7discoursediscourseCWE-89Discourse: Strip SQL comments and use non-recursive parameter interpolation i…
CVE-2026-68359await13.7LinuxLinux—hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop
CVE-2026-664116.913.6ECOVACS ROBOTICSDEEBOT PRO M1CWE-303DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algor…
CVE-2026-649408.813.4Nishishi FactoryTegalog -Fumy Otegaru Memo Logger-CWE-625Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vu…
CVE-2026-150476.813.4Unknowns2MemberCWE-79s2Member < 260805 - Contributor+ Stored XSS via Shortcode
CVE-2025-302378.713.0TP-Link Systems Inc.HB810(US2) V1.0/1.6/2.0/2.6CWE-862Authentication Bypass via Broken Access Control in Web Server in Multiple TP-…
CVE-2026-688705.312.9Apache Software FoundationApache Airflow Microsoft Azure providerCWE-639Apache Airflow Microsoft Azure provider: microsoft.azure Key Vault backend: t…
CVE-2026-170184.912.6UnknownCubeWP FrameworkCWE-639CubeWP Framework <= 1.1.30 - Contributor+ Arbitrary Post and User Meta Disclo…
CVE-2026-152375.312.4UnknownMotoPress Hotel BookingCWE-862Hotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Chec…
CVE-2026-68187await12.3LinuxLinux—exec: fix unsigned loop counter wrap in transfer_args_to_stack()
CVE-2026-68212await12.2LinuxLinux—media: saa7134: Fix a possible memory leak in saa7134_video_init1
CVE-2026-68214await12.3LinuxLinux—media: rtl2832: fix use-after-free in rtl2832_remove()
CVE-2026-68215await12.2LinuxLinux—media: radio-si476x: Unregister v4l2_device on probe failure
CVE-2026-68217await12.2LinuxLinux—media: pwc: Drain fill_buf on start_streaming() failure
CVE-2026-68218await12.3LinuxLinux—media: pci: dm1105: Free allocated workqueue
CVE-2026-68223await12.3LinuxLinux—media: meson: vdec: Fix memory leak in error path of vdec_open
CVE-2026-68226await12.2LinuxLinux—media: cx23885: add ioremap return check and cleanup
CVE-2026-68227await12.2LinuxLinux—media: cx231xx: fix devres lifetime
CVE-2026-68231await12.2LinuxLinux—media: airspy: Return queued buffers on start_streaming() failure
CVE-2026-68277await12.3LinuxLinux—drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
CVE-2026-68351await12.3LinuxLinux—wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read
CVE-2026-68405await12.3LinuxLinux—wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock
CVE-2026-683908.812.1LinuxLinux—Bluetooth: hci_sync: hold hdev->lock for hci_conn_params lookups
CVE-2026-193832.012.1saithinkSaiAdminCWE-284saithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestric…
CVE-2026-68130await11.8LinuxLinux—ksmbd: defer destroy_previous_session() until after NTLM authentication
CVE-2026-727255.411.7discoursediscourseCWE-79Discourse: Stored XSS in staff action logs injects staff UI
CVE-2026-566204.311.6HCLSoftwareHCL BigFix MobileCWE-209HCL BigFix Mobile is vulnerable to information disclosure
CVE-2026-68164await11.7LinuxLinux—mm/damon/core: disallow overlapping input ranges for damon_set_regions()
CVE-2026-68205await11.7LinuxLinux—media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subde…
CVE-2026-68207await11.7LinuxLinux—media: ti: vpe: unwind v4l2 device registration on probe error
CVE-2026-68251await11.7LinuxLinux—drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()
CVE-2026-68422await11.7LinuxLinux—btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()
CVE-2026-170125.311.6UnknownAccept PayPal & Stripe with Subscriptions for WooCommerceCWE-284Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via Unvalid…
CVE-2026-730355.311.6raineorshinenpm-check-updatesCWE-150npm-check-updates 23.0.2 Terminal Injection via Unsanitized Escape Sequences
CVE-2026-169495.811.3UnknownTerm PagesCWE-89Term Pages < 2.0.0 - Unauthenticated SQL Injection via tp_lookup
CVE-2026-192786.811.1Red HatRed Hat Advanced Cluster Security 4CWE-625Stackrox: stackrox: privilege escalation via unanchored regular expressions i…
CVE-2026-68175await11.1LinuxLinux—tracing: Fix resource leak on mmiotrace trace_pipe close
CVE-2026-68176await11.1LinuxLinux—tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev
CVE-2026-68180await11.1LinuxLinux—intel_th: fix MSC output device reference leak
CVE-2026-68182await11.1LinuxLinux—comedi: comedi_parport: deal with premature interrupt
CVE-2026-68183await11.1LinuxLinux—firmware: stratix10-svc: fix memory leaks and list corruption bugs
CVE-2026-68184await11.1LinuxLinux—cdrom: fix stack out-of-bounds read in CDROMVOLCTRL
CVE-2026-68186await11.1LinuxLinux—binfmt_misc: set have_execfd only once the interpreter is opened
CVE-2026-68188await11.1LinuxLinux—Bluetooth: RFCOMM: Fix session UAF in set_termios
CVE-2026-68195await11.1LinuxLinux—wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses
CVE-2026-68197await11.1LinuxLinux—wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper
CVE-2026-68250await11.1LinuxLinux—drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()
CVE-2026-68304await11.1LinuxLinux—wifi: brcmfmac: fix 802.1X-SHA256 call trace warning
CVE-2026-68313await11.1LinuxLinux—tipc: fix infinite loop in __tipc_nl_compat_dumpit
CVE-2026-68322await11.1LinuxLinux—rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled
CVE-2026-68344await11.1LinuxLinux—usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect
CVE-2026-68368await11.1LinuxLinux—usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
CVE-2026-68369await11.1LinuxLinux—usb: gadget: printer: fix infinite loop in printer_read()
CVE-2026-68395await11.1LinuxLinux—ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered
CVE-2026-68410await11.1LinuxLinux—wifi: libertas: fix memory leak in helper_firmware_cb()
CVE-2026-68203await10.9LinuxLinux—media: vivid: fix cleanup bugs in vivid_init()
CVE-2026-68220await10.9LinuxLinux—media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe
CVE-2026-68221await10.9LinuxLinux—media: nuvoton: npcm-video: fix memory leaks in probe and remove
CVE-2026-68225await10.9LinuxLinux—media: i2c: alvium: fix critical pointer access in alvium_ctrl_init
CVE-2026-68261await10.9LinuxLinux—drm/imagination: fix error checking of pvr_vm_context_lookup()
CVE-2026-68339await10.9LinuxLinux—Bluetooth: btusb: validate Realtek vendor event length
CVE-2026-68346await10.9LinuxLinux—ALSA: hda: cs35l41: validate and free ACPI mute object
CVE-2026-67916.610.7The GNU C LibraryglibcCWE-121Potential stack-based buffer clash during tilde expansion in wordexp
CVE-2026-68268await10.6LinuxLinux—drm/xe: Return error on non-migratable faults requiring devmem
CVE-2026-68270await10.6LinuxLinux—drm/sysfb: Avoid possible truncation with calculating visible size
CVE-2026-68165await10.5LinuxLinux—mm/damon/core: validate ranges in damon_set_regions()
CVE-2026-68169await10.5LinuxLinux—mptcp: pm: userspace: fix use-after-free in get_local_id
CVE-2026-68181await10.5LinuxLinux—mei: bus: access mei_device under device_lock on cleanup
CVE-2026-68190await10.5LinuxLinux—staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()
CVE-2026-68194await10.5LinuxLinux—wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses
CVE-2026-68269await10.5LinuxLinux—drm/i915/gem: Add missing nospec on parallel submit slot
CVE-2026-68386await10.5LinuxLinux—bpf, sockmap: Reject unhashed UDP sockets on sockmap update
CVE-2026-729064.310.2frappeerpnextCWE-862ERPNext: Unauthorised triggering of automated emails due to missing validation
CVE-2026-68349await10.2LinuxLinux—wifi: carl9170: fix buffer overflow in rx_stream failover path
CVE-2026-729185.49.8RocketChatRocket.ChatCWE-862Rocket.Chat: Insecure implementation of websocket notifications
CVE-2026-68166await9.8LinuxLinux—userfaultfd: prevent registration of special VMAs
CVE-2026-68185await9.8LinuxLinux—LoongArch: Move jump_label_init() before parse_early_param()
CVE-2026-68193await9.8LinuxLinux—wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses
CVE-2026-68296await9.8LinuxLinux—net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM
CVE-2026-68321await9.8LinuxLinux—net: txgbe: fix FDIR filter leak on remove
CVE-2026-68378await9.8LinuxLinux—dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync()
CVE-2026-68396await9.8LinuxLinux—scsi: core: wake eh reliably when using scsi_schedule_eh
CVE-2026-68168await9.6LinuxLinux—afs: Fix afs_edit_dir_remove() to get, not find, block 0
CVE-2026-68174await9.6LinuxLinux—tracing: Fix union collision of module and refcnt for dynamic events
CVE-2026-68208await9.5LinuxLinux—media: ti: vpe: Fix the error code of devm_kzalloc() in vip_probe_slice()
CVE-2026-68224await9.5LinuxLinux—media: mali-c55: Fix possible ERR_PTR in enable_streams
CVE-2026-68232await9.5LinuxLinux—drm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict
CVE-2026-68235await9.5LinuxLinux—drm/amd/display: dce100: skip non-DP stream encoders for DP MST
CVE-2026-68241await9.5LinuxLinux—drm/i915/mst: limit DP MST ESI service loop
CVE-2026-68345await9.5LinuxLinux—arm_mpam: guard MBWU state before adding it to garbage
CVE-2026-68412await9.5LinuxLinux—wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan()
CVE-2026-126244.39.4HashiCorpVaultCWE-863Vault vulnerable to LIST authorization bypass via trailing-slash strip
CVE-2026-68413await9.3LinuxLinux—wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
CVE-2026-683987.89.2LinuxLinux—ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF
CVE-2026-664096.99.1ECOVACS ROBOTICSDEEBOT PRO M1CWE-1391DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for the…
CVE-2026-68361await9.1LinuxLinux—hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop
CVE-2026-186664.38.9UnknownLibrary Management SystemCWE-89Library Management System < 3.6.7 - Subscriber+ SQL Injection via Filter Value
CVE-2026-68276await9.0LinuxLinux—drm/amdgpu/gfx: fix cleaner shader IB buffer overflow
CVE-2026-68421await8.9LinuxLinux—sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx()
CVE-2026-715776.38.7Red HatMulticluster Global HubCWE-522Multicluster-global-hub: multicluster-global-hub: spec-topic read acl leaks b…
CVE-2026-682557.78.7LinuxLinux—drm/virtio: bound EDID block reads to the response buffer
CVE-2026-68167await8.6LinuxLinux—btrfs: do not try compression for data reloc inodes
CVE-2026-68191await8.6LinuxLinux—wifi: ath12k: fix NULL pointer dereference in rhash table destroy
CVE-2026-68242await8.5LinuxLinux—drm/i915/gt: Fix NULL deref on sched_engine alloc failure
CVE-2026-68286await8.5LinuxLinux—drop_monitor: perform u64_stats updates under IRQ-disabled section
CVE-2026-68303await8.5LinuxLinux—drm/vc4: hvs/v3d: Fix null dereference in unbind
CVE-2026-68312await8.5LinuxLinux—cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths
CVE-2026-68358await8.5LinuxLinux—hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop
CVE-2026-170163.78.3UnknownAccept PayPal & Stripe with Subscriptions for WooCommerceCWE-284Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via PDT Und…
CVE-2026-142384.18.2UnknownviteposCWE-89Vitepos < 3.6.0 - Admin+ SQL Injection via product-details-report
CVE-2026-68093await8.1LinuxLinux—KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after ho…
CVE-2026-727286.38.0discoursediscourseCWE-20Discourse: Onebox iframe origin allowlist enforces URL authority boundary
CVE-2026-725876.18.1CoreBunchInstaticCWE-444Instatic - Cache Poisoning via Unauthenticated Server Island Endpoint
CVE-2026-729124.38.1gchqCyberChefCWE-400CyberChef’s pretty-recipe parser vulnerable to client-side ReDoS / CPU exhaus…
CVE-2026-664077.78.0ECOVACS ROBOTICSDEEBOT PRO M1CWE-327DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in Web…
CVE-2026-68132await8.0LinuxLinux—super: fix emergency thaw deadlock on frozen block devices
CVE-2026-68135await8.0LinuxLinux—net: hip04: fix RX buffer leak on build_skb failure
CVE-2026-68146await8.0LinuxLinux—ftrace: Add global mutex to serialize trace_parser access
CVE-2026-68151await8.0LinuxLinux—binfmt_elf_fdpic: only honour the first PT_INTERP
CVE-2026-68279await8.0LinuxLinux—drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers
CVE-2026-68325await8.0LinuxLinux—iommu/amd: Bound the early ACPI HID map
CVE-2026-68350await8.0LinuxLinux—wifi: carl9170: fix OOB read from off-by-two in TX status handler
CVE-2026-68355await8.0LinuxLinux—wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()
CVE-2026-68363await8.0LinuxLinux—wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request
CVE-2026-68365await8.0LinuxLinux—USB: serial: io_edgeport: cap received transmit credits
CVE-2026-68366await8.0LinuxLinux—usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer
CVE-2026-68367await8.0LinuxLinux—usb: gadget: f_tcm: synchronize delayed set_alt with teardown

Results continue: ranks 401–670.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-10 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.