AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N C H H L 8.9 .0151 72.4 YES
AFFECTED Product Versions Fixed Collaboration unspecified —
TIMELINE Aug 12 Reserved by CNA Aug 13 Published (CNA: mitre) Aug 21 Added to CISA KEV, due Aug 24
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
606 CVEs published, led by IBM (74).
606 CVEs published August 13, 2026: 83 critical, 261 high, 233 medium, 28 low; 1 in the KEV catalog at press time; 3 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 206 on continuation pages.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 4690 | 26854 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
1551 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 416 | 2731 | 234 | 1400 | 637 | 1 | 11 | 2 | 0.1 | 7.8 | .0016 | +376 ▲ |
| microsoft | 439 | 1861 | 132 | 1268 | 447 | 14 | 286 | 25 | 1.3 | 7.8 | .0044 | +385 ▲ |
| 49 | 1810 | 222 | 749 | 783 | 56 | 77 | 6 | 0.3 | 7.5 | .0025 | -30 ▼ | |
| red hat | 131 | 517 | 30 | 211 | 245 | 31 | 2 | 0 | 0.0 | 6.5 | .0029 | +92 ▲ |
| apple | 2 | 273 | 58 | 79 | 133 | 3 | 88 | 7 | 2.6 | 7.0 | .0027 | +2 ▲ |
| canonical | 11 | 38 | 12 | 9 | 12 | 5 | 0 | 0 | 0.0 | 7.8 | .0020 | +10 ▲ |
| suse | 5 | 26 | 5 | 14 | 6 | 1 | 0 | 0 | 0.0 | 8.1 | .0039 | -1 ▼ |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 31 | 69 | 13 | 37 | 19 | 0 | 56 | 13 | 18.8 | 7.5 | .0046 | +23 ▲ |
| palo alto networks | 12 | 37 | 1 | 3 | 21 | 12 | 13 | 2 | 5.4 | 4.7 | .0020 | -2 ▼ |
| ubiquiti | 0 | 36 | 14 | 21 | 1 | 0 | 3 | 3 | 8.3 | 8.8 | .0049 | -25 ▼ |
| netgear | 9 | 32 | 0 | 0 | 27 | 5 | 0 | 0 | 0.0 | 4.3 | .0025 | +9 ▲ |
| fortinet | 7 | 30 | 7 | 8 | 14 | 1 | 28 | 6 | 20.0 | 7.0 | .0050 | +7 ▲ |
| vmware | 0 | 17 | 4 | 9 | 2 | 2 | 7 | 1 | 5.9 | 8.3 | .0040 | -1 ▼ |
| f5 | 0 | 16 | 5 | 8 | 3 | 0 | 4 | 1 | 6.3 | 8.6 | .0057 | 0 |
| ivanti | 3 | 14 | 4 | 8 | 2 | 0 | 25 | 5 | 35.7 | 8.3 | .0754 | +3 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 96 | 432 | 86 | 186 | 147 | 12 | 33 | 2 | 0.5 | 7.5 | .0049 | +31 ▲ |
| mozilla | 1 | 128 | 51 | 42 | 35 | 0 | 9 | 0 | 0.0 | 8.1 | .0031 | -3 ▼ |
| gitlab | 13 | 64 | 1 | 13 | 42 | 8 | 4 | 2 | 3.1 | 4.9 | .0028 | +6 ▲ |
| drupal | 0 | 51 | 6 | 5 | 35 | 5 | 4 | 1 | 2.0 | 5.9 | .0026 | -46 ▼ |
| github | 5 | 17 | 1 | 7 | 9 | 0 | 0 | 0 | 0.0 | 6.6 | .0043 | +4 ▲ |
| docker | 1 | 8 | 0 | 5 | 3 | 0 | 0 | 0 | 0.0 | 7.7 | .0015 | +1 ▲ |
| wordpress | 1 | 4 | 1 | 2 | 1 | 0 | 2 | 2 | 50.0 | 8.8 | .5550 | +1 ▲ |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0035 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 1379 | 343 | 653 | 322 | 61 | 27 | 3 | 0.2 | 8.1 | .0036 | 0 |
| ibm | 174 | 403 | 96 | 172 | 130 | 5 | 6 | 1 | 0.2 | 7.5 | .0031 | +172 ▲ |
| adobe | 60 | 312 | 39 | 145 | 123 | 5 | 19 | 3 | 1.0 | 7.8 | .0026 | +55 ▲ |
| progress | 16 | 58 | 14 | 34 | 10 | 0 | 6 | 1 | 1.7 | 8.1 | .0036 | +6 ▲ |
| solarwinds | 0 | 23 | 17 | 3 | 3 | 0 | 10 | 4 | 17.4 | 9.1 | .0058 | 0 |
| veeam | 10 | 16 | 5 | 9 | 2 | 0 | 1 | 0 | 0.0 | 8.6 | .0034 | +10 ▲ |
| zohocorp | 4 | 10 | 3 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0140 | +4 ▲ |
| atlassian | 0 | 3 | 0 | 3 | 0 | 0 | 13 | 0 | 0.0 | 8.0 | .0026 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 15 | 35 | 15 | 5 | 9 | 6 | 3 | 0 | 0.0 | 7.4 | .0157 | +14 ▲ |
| siemens | 17 | 33 | 2 | 23 | 8 | 0 | 0 | 0 | 0.0 | 7.3 | .0016 | +13 ▲ |
| synology | 1 | 24 | 2 | 6 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +1 ▲ |
| rockwell automation | 0 | 24 | 4 | 18 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0029 | 0 |
| schneider electric | 0 | 9 | 1 | 6 | 2 | 0 | 0 | 0 | 0.0 | 8.6 | .0037 | 0 |
| abb | 0 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | 0 |
| hikvision | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0040 | 0 |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 13 | 133 | 0 | 0 | 72 | 61 | 0 | 0 | 0.0 | 5.5 | .0033 | -22 ▼ |
| dell | 12 | 111 | 9 | 54 | 45 | 3 | 2 | 1 | 0.9 | 7.2 | .0021 | -21 ▼ |
| openclaw | 0 | 111 | 0 | 58 | 39 | 14 | 0 | 0 | 0.0 | 7.0 | .0026 | -16 ▼ |
| nvidia | 16 | 98 | 13 | 66 | 19 | 0 | 0 | 0 | 0.0 | 7.7 | .0034 | -1 ▼ |
| gitea | 48 | 89 | 19 | 36 | 30 | 4 | 0 | 0 | 0.0 | 7.5 | .0034 | +8 ▲ |
| elastic | 48 | 86 | 0 | 18 | 68 | 0 | 1 | 0 | 0.0 | 6.5 | .0029 | +39 ▲ |
| capgo | 0 | 83 | 2 | 42 | 38 | 1 | 0 | 0 | 0.0 | 7.1 | .0037 | -22 ▼ |
| itsourcecode | 8 | 79 | 0 | 0 | 19 | 60 | 0 | 0 | 0.0 | 2.1 | .0033 | -3 ▼ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-8037 | .9957 | 99.9 | 9.8 |
| CVE-2026-34486 | .9862 | 99.9 | 7.5 |
| CVE-2026-63030 | .9779 | 99.9 | 9.8 |
| CVE-2026-16232 | .8912 | 99.8 | 9.3 |
| CVE-2026-63077 | .8473 | 99.7 | 9.8 |
| CVE-2026-60137 | .7979 | 99.6 | 5.9 |
| CVE-2026-72898 | .7922 | 99.6 | 10.0 |
| CVE-2026-25089 | .7611 | 99.5 | 9.8 |
| CVE-2026-0770 | .6342 | 99.1 | 9.8 |
| CVE-2026-59310 | .4588 | 98.7 | 9.8 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-72898 | 10.0 | .7922 | KEV |
| CVE-2026-8985 | 10.0 | .0660 | |
| CVE-2026-6516 | 10.0 | .0486 | |
| CVE-2026-48362 | 10.0 | .0431 | |
| CVE-2026-47668 | 10.0 | .0388 | |
| CVE-2026-46339 | 10.0 | .0335 | |
| CVE-2026-44359 | 10.0 | .0180 | |
| CVE-2026-58231 | 10.0 | .0171 | |
| CVE-2026-16812 | 10.0 | .0157 | KEV |
| CVE-2026-73299 | 10.0 | .0121 |
| Vendor | CVEs |
|---|---|
| linux | 1211 |
| oracle | 1109 |
| microsoft | 480 |
| 451 | |
| ibm | 277 |
| red hat | 249 |
| apache | 205 |
| apple | 169 |
| adobe | 75 |
| elastic | 67 |
| Vendor | KEV |
|---|---|
| microsoft | 25 |
| cisco | 13 |
| apple | 7 |
| fortinet | 6 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| oracle | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 67 |
| PyPI | 5 |
| Go | 3 |
| npm | 3 |
| Packagist | 2 |
| crates.io | 2 |
| NuGet | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2021-27137 | DD-WRT | 0 |
| CVE-2025-68686 | Fortinet | 0 |
| CVE-2026-0770 | Langflow | 0 |
| CVE-2026-16232 | checkpoint | 0 |
| CVE-2026-16812 | Arista Networks | 0 |
| CVE-2026-18556 | N-able | 0 |
| CVE-2026-18577 | N-able | 0 |
| CVE-2026-20316 | Cisco | 0 |
| CVE-2026-20349 | Cisco | 0 |
| CVE-2026-25089 | Fortinet | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1730 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1730 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1730 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1730 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1730 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1730 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1730 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1730 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1730 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1730 |
EXPLOIT PUBLISHED — GitLab: 12 CVEs (CVE-2023-7028, CVE-2025-9486, CVE-2026-4879, CVE-2026-6821, CVE-2026-7427, CVE-2026-8667, CVE-2026-15216, CVE-2026-15217, CVE-2026-15423, CVE-2026-16494, CVE-2026-16627, CVE-2026-18433). Public exploit references added.
EXPLOIT PUBLISHED — FlowiseAI Flowise: 5 CVEs (CVE-2026-67620, CVE-2026-67621, CVE-2026-67622, CVE-2026-70636, CVE-2026-71962). Public exploit references added.
EXPLOIT PUBLISHED — netty: 5 CVEs (CVE-2026-42578, CVE-2026-42579, CVE-2026-42581, CVE-2026-42584, CVE-2026-42587). Public exploit references added.
EXPLOIT PUBLISHED — openemr: 5 CVEs (CVE-2026-39931, CVE-2026-39932, CVE-2026-67610, CVE-2026-67611, CVE-2026-67612). Public exploit references added.
EXPLOIT PUBLISHED — usmannasir cyberpanel: 3 CVEs (CVE-2026-71964, CVE-2026-71965, CVE-2026-71966). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2015-1701. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2016-20097 (Weaver Network Co., Ltd. E-cology 8.0). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2017-0144 (Microsoft Corporation Windows SMB). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2017-0145 (Microsoft Corporation Windows SMB). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2017-11357. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2017-18362. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2018-19320. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2018-19321. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2018-19322. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2018-19323. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2018-20753. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2018-6882. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2018-8453 (Microsoft Windows 7). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-1055 (Linux Kernel). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-2586 (Linux Kernel). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-4995 (Weaver Network Co., Ltd. E-cology 9.0). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-50997 (Weaver Network Co., Ltd. E-cology 9.0). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-15684 (Open5GS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-13177 (Unknown Eventin). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-13612 (Unknown KiviCare). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14857 (Unknown WP Crowdfunding). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19246 (HKUDS nanobot). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19345 (code-projects Task Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-3087 (Python Software Foundation CPython). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-41453 (krayin laravel-crm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50559 (quarkusio quarkus). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50656 (Microsoft Malware Protection Engine). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-61523 (WebsiteBaker Org e.V. WebsiteBaker CMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-61524 (WebsiteBaker Org e.V. WebsiteBaker CMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63720 (koxudaxi datamodel-code-generator). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66748 (owen2345 camaleon-cms). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66752 (tiny-http). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66753 (tiny-http). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-67617 (microweber). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-69100 (dromara lamp-cloud). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-70637 (hfiref0x LightFTP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-71959 (bitwarden server). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-71969 (OP-TEE optee_os). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-73678 (MindsDB Minds Platform). Public exploit reference added.
RESCORED — netty: 6 CVEs (CVE-2026-42579, CVE-2026-42581, CVE-2026-42584, CVE-2026-45674, CVE-2026-47691, CVE-2026-48043). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2018-19943 (QNAP Systems Inc. QTS). CVSS 8 → 5.4 (NVD).
RESCORED — CVE-2022-48979 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2022-49159 (Linux). CVSS 8.8 → 5.5 (NVD).
RESCORED — CVE-2026-12539 (Docker Sandboxes). CVSS 5.1 → 5.7 (NVD).
RESCORED — CVE-2026-54230 (Red Hat Enterprise Linux 8). CVSS 7 → 7.8 (NVD).
ENRICHED — Linux: 14 CVEs (CVE-2022-48633, CVE-2022-48823, CVE-2022-48825, CVE-2022-49044, CVE-2022-49051, CVE-2022-49069, CVE-2022-49109, CVE-2022-49112, CVE-2022-49118, CVE-2022-49132, CVE-2022-49133, CVE-2022-49169, CVE-2022-49286, CVE-2022-49309). Received CVSS/CPE analysis.
ENRICHED — CVE-2022-2586 (Linux Kernel). Received CVSS 7.8 and CPE data from NVD.
How to read these box scores · glossary
606 CVEs published. 25 box scores and 375 table rows below; the remaining 206 continue on page 2 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N C H H L 8.9 .0151 72.4 YES
AFFECTED Product Versions Fixed Collaboration unspecified —
TIMELINE Aug 12 Reserved by CNA Aug 13 Published (CNA: mitre) Aug 21 Added to CISA KEV, due Aug 24
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0236 82.5 —
AFFECTED Product Versions Fixed CH7 20260625 – — CH7G 20260625 – — CH10 20260625 – — CP3 20260625 – — CP3 Pro 20260625 – — CP7 20260625 – — TC3B14C 20260625 – — TC3B15C 20260625 – — TC3T14C 20260625 – — TC3T15C 20260625 – —
TIMELINE Aug 13 Reserved by CNA Aug 13 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0158 73.6 —
AFFECTED Product Versions Fixed ManageEngine Password Manager Pro unspecified — ManageEngine PAM360 unspecified —
TIMELINE Jun 10 Reserved by CNA Aug 13 Published (CNA: Zohocorp)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0095 58.7 —
AFFECTED Product Versions Fixed missedcall < 16.0.11 – —
TIMELINE Aug 13 Reserved by CNA Aug 13 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0084 55.0 —
AFFECTED Product Versions Fixed AgenticSeek unspecified —
TIMELINE Aug 10 Reserved by CNA Aug 13 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0070 50.2 —
AFFECTED Product Versions Fixed ManageEngine Password Manager Pro unspecified — ManageEngine PAM360 unspecified —
TIMELINE Jun 15 Reserved by CNA Aug 13 Published (CNA: Zohocorp)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P L N H H H 7.7 .0069 50.1 —
AFFECTED Product Versions Fixed GitPython unspecified 3.1.54
TIMELINE Aug 13 Reserved by CNA Aug 13 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0069 50.0 —
AFFECTED Product Versions Fixed Opensearch 2.13 – — Opensearch 2.13 – —
TIMELINE Jul 30 Reserved by CNA Aug 13 Published (CNA: AMZN)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P L N H H N 7.6 .0066 48.8 —
AFFECTED Product Versions Fixed music < 17.0.7 – —
TIMELINE Aug 13 Reserved by CNA Aug 13 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0065 48.5 —
AFFECTED Product Versions Fixed backup >= 17.0.5.34, < 17.0.11 – —
TIMELINE Aug 13 Reserved by CNA Aug 13 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H L 9.4 .0064 48.1 —
AFFECTED Product Versions Fixed vitest < 3.2.7 – —
TIMELINE Aug 13 Reserved by CNA Aug 13 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0062 46.8 —
AFFECTED Product Versions Fixed openchoreo < 1.0.4 – —
TIMELINE Aug 13 Reserved by CNA Aug 13 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0061 46.6 —
AFFECTED Product Versions Fixed OpenSSL 4.0.0 – —
TIMELINE Jul 2 Reserved by CNA Aug 13 Published (CNA: openssl)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0061 46.6 —
AFFECTED Product Versions Fixed Documentation Offline 1.0.0 – —
TIMELINE Jul 25 Reserved by CNA Aug 13 Published (CNA: ibm)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P L N H H H 9.0 .0061 46.3 —
AFFECTED Product Versions Fixed Flowise unspecified 3.1.3 Flowise unspecified 3.1.3
TIMELINE Aug 13 Reserved by CNA Aug 13 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0059 45.5 —
AFFECTED Product Versions Fixed ASP-CMS unspecified —
TIMELINE Aug 13 Reserved by CNA Aug 13 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H H 9.1 .0058 45.0 —
AFFECTED Product Versions Fixed Gitea Open Source Git Server unspecified —
TIMELINE Jun 30 Reserved by CNA Aug 13 Published (CNA: Gitea)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0057 44.7 —
AFFECTED Product Versions Fixed rsync 2.0.0 – 3.5.0
TIMELINE Aug 4 Reserved by CNA Aug 13 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0057 44.7 —
AFFECTED Product Versions Fixed QA Analytics n/a – 5.2.0.1
TIMELINE Feb 20 Reserved by CNA Aug 13 Published (CNA: Patchstack)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0057 44.6 —
AFFECTED Product Versions Fixed Documentation Offline 1.0.0 – —
TIMELINE Jul 25 Reserved by CNA Aug 13 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0057 44.5 —
AFFECTED Product Versions Fixed encoding/asn1 unspecified —
TIMELINE Mar 23 Reserved by CNA Aug 13 Published (CNA: Go)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0057 44.5 —
AFFECTED Product Versions Fixed net/http unspecified —
TIMELINE Jun 23 Reserved by CNA Aug 13 Published (CNA: Go)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0057 44.5 —
AFFECTED Product Versions Fixed encoding/xml unspecified —
TIMELINE Jun 23 Reserved by CNA Aug 13 Published (CNA: Go)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0055 43.7 —
AFFECTED Product Versions Fixed cyberpanel unspecified —
TIMELINE Jul 29 Reserved by CNA Aug 13 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N A H H L 8.6 .0055 43.6 —
AFFECTED Product Versions Fixed jupyterlab >= 3.3.0, < 4.5.10 – —
TIMELINE Aug 12 Reserved by CNA Aug 13 Published (CNA: GitHub_M)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-14669 | 8.8 | 42.6 | n/a | PostgreSQL | CWE-122 | PostgreSQL to_char heap buffer overflow executes arbitrary code |
| CVE-2026-73420 | 9.1 | 42.3 | nextauthjs | next-auth | CWE-180 | NextAuth.js: Email normalizer validates the address before Unicode normalizat… |
| CVE-2026-16975 | 8.8 | 42.2 | IBM | i | CWE-787 | IBM i is Affected By A Remote Code Execution Vulnerability [] |
| CVE-2026-16239 | 8.8 | 42.2 | n/a | PostgreSQL | CWE-843 | PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code |
| CVE-2026-70453 | 8.7 | 42.1 | RsyncProject | rsync | CWE-407 | rsync < 3.5.0 Algorithmic Complexity DoS via hash_search() |
| CVE-2026-66256 | 7.2 | 41.9 | Apache Software Foundation | Apache Shindig Common | CWE-502 | Apache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via X… |
| CVE-2026-53790 | 9.2 | 41.5 | RsyncProject | rsync | CWE-78 | rsync < 3.5.0 Command Injection via Multiple Code Paths |
| CVE-2026-70461 | 8.8 | 41.1 | RsyncProject | rsync | CWE-787 | rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from Entry |
| CVE-2026-73625 | 8.7 | 40.7 | gitpython-developers | GitPython | CWE-78 | GitPython before 3.1.54 Remote Code Execution via kwarg value smuggling |
| CVE-2026-73649 | 9.8 | 40.6 | shepherdwind | velocity.js | CWE-94 | Velocity.js: Remote Code Execution via property-read to Function constructor … |
| CVE-2026-73416 | 6.1 | 39.7 | jupyterlab | jupyterlab | CWE-178 | jupyterlab: PyPI extension blocklist package-name canonicalization bypass |
| CVE-2022-4993 | 9.1 | 39.3 | — | HTML-FormHandler | CWE-470 | HTML::FormHandler versions through 0.40068 for Perl allow attacker selected m… |
| CVE-2026-73666 | 8.2 | 39.3 | openchoreo | backstage-plugins | CWE-306 | OpenChoreo: Unauthenticated Backstage developer-portal API exposes OpenChoreo… |
| CVE-2026-49827 | 9.8 | 39.2 | SMEWebify | WebErpMesv2 | CWE-20 | WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expens… |
| CVE-2026-70455 | 8.7 | 39.2 | RsyncProject | rsync | CWE-770 | rsync 3.4.2 < 3.5.0 DoS via --zt Zstandard Compression Thread Exhaustion |
| CVE-2024-58374 | 8.7 | 38.9 | Hongjing Century | e-HR | CWE-89 | Hongjing e-HR Unauthenticated SQL Injection via getSdutyTree |
| CVE-2026-13048 | 8.2 | 38.9 | — | Data-MuForm | CWE-22 | Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a me… |
| CVE-2026-19750 | 8.2 | 38.8 | Tenda | CH | CWE-255 | Tenda CH/CP/TX3 SSH hard-coded password |
| CVE-2026-53791 | 9.1 | 38.7 | RsyncProject | rsync | CWE-290 | rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header |
| CVE-2026-56862 | 7.5 | 38.2 | Go standard library | crypto/tls | CWE-770 | Limit handshake messages we are willing to accept post-handshake in crypto/tls |
| CVE-2026-61962 | 10.0 | 38.1 | Hakan Ozevin | WP BASE Booking | CWE-94 | WordPress WP BASE Booking plugin <= 6.3.0 - Arbitrary Code Execution vulnerab… |
| CVE-2026-73532 | 9.3 | 38.1 | WPManageNinja | Fluent Forms Pro | CWE-506 | Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build |
| CVE-2026-70452 | 9.1 | 38.0 | RsyncProject | rsync | CWE-636 | rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure |
| CVE-2026-17473 | 7.5 | 38.0 | IBM | Documentation Offline | CWE-22 | IBM Documentation Offline is vulnerable to information disclosure, session fo… |
| CVE-2026-14662 | 8.8 | 37.9 | n/a | PostgreSQL | CWE-190 | PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound |
| CVE-2026-73421 | 9.1 | 37.8 | nextauthjs | next-auth | CWE-285 | NextAuth.js: Configuration errors can cause existence-based auth checks to fa… |
| CVE-2026-73507 | 7.5 | 37.5 | netty | netty | CWE-400 | Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion |
| CVE-2026-13051 | 9.1 | 37.3 | — | Form-Processor | CWE-470 | Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl… |
| CVE-2026-73533 | 9.3 | 37.1 | WPManageNinja | Ninja Tables Pro | CWE-506 | Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build |
| CVE-2026-70460 | 9.2 | 37.1 | RsyncProject | rsync | CWE-22 | rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink |
| CVE-2026-73514 | 8.7 | 36.8 | PostGIS | address_standardizer | CWE-787 | PostGIS address_standardizer Out-of-Bounds Write via standardize_address() |
| CVE-2026-73660 | 7.5 | 36.8 | FreePBX | tts | CWE-78 | FreePBX: Authenticated TTS AGI Command Injection Through TTS Name |
| CVE-2026-73602 | 9.0 | 36.2 | FlowiseAI | Flowise | CWE-95 | Flowise before 3.1.3 Sandbox Escape to RCE |
| CVE-2026-14664 | 8.8 | 36.1 | n/a | PostgreSQL | CWE-122 | PostgreSQL regexp heap buffer overflow executes arbitrary code |
| CVE-2026-14670 | 8.8 | 36.1 | n/a | PostgreSQL | CWE-122 | PostgreSQL plperl tied object heap buffer overflow executes arbitrary code |
| CVE-2026-15742 | 8.8 | 36.1 | n/a | PostgreSQL | CWE-190 | PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer … |
| CVE-2026-17223 | 8.8 | 36.2 | IBM | i | CWE-787 | IBM i is Affected By Multiple Vulnerabilities in Host Servers |
| CVE-2026-73561 | 7.5 | 35.7 | anephenix | hub | CWE-400 | Hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion |
| CVE-2026-14676 | 8.8 | 35.3 | n/a | PostgreSQL | CWE-122 | PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code |
| CVE-2026-19385 | 8.8 | 35.3 | n/a | PostgreSQL | CWE-122 | PostgreSQL pg_dump heap buffer overflow executes arbitrary code |
| CVE-2026-56860 | 5.9 | 35.1 | Go standard library | net/url | CWE-407 | Avoid quadratic complexity in resolvePath in net/url |
| CVE-2026-19757 | 5.5 | 35.1 | Dromara | lamp-cloud | CWE-22 | Dromara lamp-cloud File-Upload Controller FileAnyoneController.java path trav… |
| CVE-2026-19758 | 5.5 | 35.1 | dromara | lamp-cloud | CWE-22 | dromara lamp-cloud chunk-check endpoint FileChunkController.java path traversal |
| CVE-2026-14671 | 8.8 | 35.0 | n/a | PostgreSQL | CWE-843 | PostgreSQL refint plan cache type confusion executes arbitrary code |
| CVE-2026-14677 | 8.8 | 35.0 | n/a | PostgreSQL | CWE-190 | PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparound |
| CVE-2026-14680 | 8.8 | 35.0 | n/a | PostgreSQL | CWE-843 | PostgreSQL type confusion via "internal" arguments |
| CVE-2026-72841 | 9.4 | 35.0 | openwrt | luci | CWE-73 | luci-app-openvpn Path Traversal RCE via instance_name2 |
| CVE-2026-72842 | 9.4 | 35.0 | openwrt | luci | CWE-73 | OpenWrt luci-app-lxc ACL Inconsistency Authentication Bypass |
| CVE-2026-72850 | 9.4 | 35.0 | budibase | server | CWE-22 | Budibase before 3.40.0 Arbitrary File Write via Path Traversal |
| CVE-2026-56654 | 9.8 | 34.5 | Gitea | Gitea Open Source Git Server | CWE-284 | Privilege Escalation via Access Token Scope Escalation in API |
| CVE-2026-19297 | 9.1 | 34.6 | IBM | Langflow OSS | CWE-307 | Insufficient Authentication Brute Force Protection on Login Endpoint |
| CVE-2026-19487 | 5.3 | 34.6 | — | perl | CWE-670 | Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression m… |
| CVE-2026-16674 | 8.8 | 34.3 | IBM | i | CWE-426 | IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server… |
| CVE-2026-53795 | 7.2 | 34.2 | RsyncProject | rsync | CWE-59 | rsync < 3.5.0 Arbitrary File Write via --temp-dir/--link-dest |
| CVE-2026-73515 | 7.2 | 34.3 | PostGIS | PostGIS | CWE-125 | PostGIS < 3.7.0beta2 Out-of-Bounds Read via FlatGeobuf Buffer |
| CVE-2026-16238 | 8.8 | 34.2 | n/a | PostgreSQL | CWE-843 | PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary … |
| CVE-2026-65582 | 7.7 | 34.0 | LiquidThemes | AI Hub | CWE-22 | WordPress AI Hub theme <= 1.3.10 - Arbitrary File Download vulnerability |
| CVE-2026-16867 | 9.8 | 33.9 | IBM | i | CWE-287 | IBM i is Affected By Multiple Vulnerabilities in NetServer |
| CVE-2026-17101 | 9.6 | 33.8 | IBM | i | CWE-287 | IBM i is Affected By Multiple Vulnerabilities in Navigator for i |
| CVE-2026-58420 | 4.4 | 33.7 | Gitea | Gitea Open Source Git Server | CWE-284 | Local File Inclusion via file:// URI in Migration Restore |
| CVE-2026-16908 | 8.8 | 33.4 | IBM | i | CWE-22 | IBM i is Affected By Multiple SQL Vulnerabilities [, ] |
| CVE-2026-28008 | 9.8 | 33.3 | miniOrange | OAuth Single Sign On – SSO (OAuth Client) | CWE-290 | WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.0.0 - Broken … |
| CVE-2026-19749 | 2.9 | 33.1 | Tenda | CH7 | CWE-287 | Tenda CH7 RTSP/ONVIF missing authentication |
| CVE-2026-19761 | 5.1 | 32.8 | DTStack | Taier | CWE-22 | DTStack Taier Upload Controller UploadController.java MultipartFile.getOrigin… |
| CVE-2026-73670 | 8.6 | 32.6 | Saurus | Saurus CMS Community Edition | CWE-89 | CMS Admin SQL Injection via db_data.php table_name Parameter |
| CVE-2026-66432 | 7.5 | 32.6 | denishua | WPJAM Basic | CWE-1258 | WordPress WPJAM Basic plugin <= 7.0.2.1 - Sensitive Data Exposure vulnerability |
| CVE-2026-73487 | 9.0 | 32.5 | FlowiseAI | Flowise | CWE-94 | Flowise before 3.1.3 Prompt Injection RCE via CSV Agent |
| CVE-2026-70456 | 8.8 | 32.4 | RsyncProject | rsync | CWE-787 | rsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args() |
| CVE-2026-70458 | 8.8 | 32.4 | RsyncProject | rsync | CWE-787 | rsync 3.0.0 < 3.5.0 Out-of-Bounds Write via FLAG_HLINKED Handling |
| CVE-2026-73648 | 5.1 | 32.4 | rails | rails-html-sanitizer | CWE-79 | rails-html-sanitizer: Possible XSS vulnerability with certain configurations |
| CVE-2026-72839 | 9.3 | 32.2 | filebrowser | filebrowser | CWE-266 | filebrowser through 2.63.16 Privilege Escalation via Signup |
| CVE-2026-53793 | 9.1 | 32.1 | RsyncProject | rsync | CWE-59 | rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode |
| CVE-2026-66453 | 9.8 | 32.0 | Dimitri Grassi | Salon booking system | CWE-288 | WordPress Salon booking system plugin <= 10.30.26 - Broken Authentication vul… |
| CVE-2026-66465 | 9.8 | 32.0 | AgniHD | Cartify | CWE-288 | WordPress Cartify theme <= 1.3.0.1 - Account Takeover vulnerability |
| CVE-2026-17220 | 8.2 | 32.0 | IBM | i | CWE-120 | IBM i is Affected By Multiple Vulnerabilities in Host Servers |
| CVE-2026-16982 | 7.5 | 32.0 | IBM | i | CWE-787 | IBM i is Affected By Multiple Vulnerabilities in Host Servers |
| CVE-2026-18846 | 7.5 | 32.0 | IBM | i | CWE-787 | IBM i is Affected By Multiple Vulnerabilities in Host Servers |
| CVE-2026-17206 | 9.8 | 31.7 | IBM | i | CWE-787 | IBM i is Affected By Multiple Vulnerabilities in Host Servers |
| CVE-2026-67613 | 6.9 | 31.7 | usmannasir | cyberpanel | CWE-22 | CyberPanel < 3.0.0 Path Traversal File Read via cloudAPI ReadReport |
| CVE-2026-73559 | 6.5 | 31.6 | vllm-project | vllm | CWE-400 | vLLM: Completion prompt lists fan out into unbounded engine requests |
| CVE-2026-73565 | 5.3 | 31.6 | honojs | node-server | CWE-401 | @hono/node-server: Unauthenticated memory-leak DoS via aborted WebSocket hand… |
| CVE-2026-16887 | 7.5 | 31.4 | IBM | i | CWE-787 | IBM i is Affected By A Denial of Service Vulnerability DST/SST [] |
| CVE-2026-17004 | 7.5 | 31.4 | IBM | i | CWE-835 | IBM i is Affected By Multiple Vulnerabilities in Host Servers |
| CVE-2026-17199 | 7.5 | 31.4 | IBM | i | CWE-770 | IBM i is Affected By Multiple Vulnerabilities in Host Servers |
| CVE-2026-17229 | 7.5 | 31.4 | IBM | i | CWE-835 | IBM i is Affected By Multiple Vulnerabilities in Host Servers |
| CVE-2026-66443 | 7.5 | 31.4 | Pete Nelson | REST API Log | CWE-201 | WordPress REST API Log plugin <= 1.7.1 - Sensitive Data Exposure vulnerability |
| CVE-2026-73564 | 8.7 | 31.1 | fatedier | frp | CWE-129 | frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway v… |
| CVE-2026-73645 | 6.6 | 31.1 | OpenZeppelin | openzeppelin-confidential-contracts | CWE-190 | OpenZeppelin Confidential Contracts ERC7984ERC20Wrapper: once a wrapper is fi… |
| CVE-2026-70459 | 6.9 | 31.1 | RsyncProject | rsync | CWE-908 | rsync 3.0.0 < 3.5.0 Daemon Crash via Malformed File List Entry |
| CVE-2026-73566 | 7.5 | 30.7 | isaacs | node-tar | CWE-400 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable sta… |
| CVE-2026-28161 | 8.8 | 30.5 | Aonetheme | Service Finder Booking | CWE-266 | WordPress Service Finder Booking plugin <= 6.2 - Privilege Escalation vulnera… |
| CVE-2026-42931 | 6.5 | 30.3 | Gitea | Gitea Open Source Git Server | CWE-770 | Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint |
| CVE-2026-28149 | 9.8 | 30.2 | miniOrange | Headless Single Sign On | CWE-502 | WordPress Headless Single Sign On plugin <= 1.6 - PHP Object Injection vulner… |
| CVE-2026-73483 | 9.4 | 30.1 | FlowiseAI | Flowise | CWE-78 | Flowise before 3.1.3 Sandbox Escape via Puppeteer |
| CVE-2026-53783 | 8.6 | 30.1 | RsyncProject | rsync | CWE-59 | rsync < 3.5.0 TOCTOU Race Condition Directory Escape via rrsync |
| CVE-2026-61966 | 9.3 | 29.9 | denishua | WPJAM Basic | CWE-89 | WordPress WPJAM Basic plugin <= 7.0.1 - SQL Injection vulnerability |
| CVE-2026-66446 | 9.3 | 29.9 | If-So Dynamic Content | If-So Dynamic Content Personalization | CWE-89 | WordPress If-So Dynamic Content Personalization plugin <= 1.10 - SQL Injectio… |
| CVE-2026-73569 | 8.7 | 29.9 | NaturalIntelligence | fast-xml-parser | CWE-776 | fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits |
| CVE-2026-73509 | 7.6 | 29.9 | OpenListTeam | OpenList | CWE-22 | OpenList: Authenticated users can rename files outside their base path via ba… |
| CVE-2026-53794 | 6.9 | 29.9 | RsyncProject | rsync | CWE-1284 | rsync < 3.5.0 Denial of Service via --max-alloc=0 Logic Error |
| CVE-2026-45819 | 6.6 | 29.9 | web-platform-dx | baseline-browser-mapping | CWE-705 | baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of th… |
| CVE-2026-28157 | 7.5 | 29.7 | Lasso Analytics, Inc. | Do Lasso | CWE-35 | WordPress Do Lasso plugin <= 358 - Path Traversal vulnerability |
| CVE-2026-73562 | 6.5 | 29.5 | Automattic | mongoose | CWE-1321 | Mongoose: Prototype pollution in the update casting via __proto__-prefixed do… |
| CVE-2026-55982 | 9.1 | 29.5 | Gitea | Gitea Open Source Git Server | CWE-200 | OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Sc… |
| CVE-2026-73305 | 8.8 | 29.5 | Budibase | budibase | CWE-269 | Budibase: Privilege escalation via public role assignment API missing app-lev… |
| CVE-2026-73669 | 6.9 | 29.5 | Signify | Philips Hue Bridge Pro | CWE-306 | Signify Philips Hue Bridge Pro MQTT broker missing authentication |
| CVE-2026-17088 | 4.3 | 29.5 | IBM | i | CWE-22 | IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager |
| CVE-2026-66441 | 7.5 | 29.3 | MultiVendorX | MultiVendorX | CWE-862 | WordPress MultiVendorX plugin <= 5.0.10 - Broken Access Control vulnerability |
| CVE-2026-45774 | 6.9 | 29.3 | oscal-compass | compliance-trestle | CWE-22 | compliance-trestle Profile Import has an Arbitrary File Read via trestle:// U… |
| CVE-2026-73615 | 8.7 | 29.0 | Jovancoding | Network-AI | CWE-436 | Network-AI SandboxPolicy before 5.15.1 Blocklist Bypass via Quote Mismatch |
| CVE-2026-73613 | 7.2 | 29.1 | filebrowser | filebrowser | CWE-59 | filebrowser before 2.63.19 Out-of-Scope File Deletion via Symlink |
| CVE-2026-18408 | 8.8 | 28.9 | n/a | PostgreSQL | CWE-829 | PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute a… |
| CVE-2026-56443 | 9.6 | 28.9 | Gitea | Gitea Open Source Git Server | CWE-863 | Token public-only scope bypassed on Limited-visibility owners (Repository + P… |
| CVE-2026-61980 | 7.5 | 28.9 | Daan.dev | OMGF Pro | CWE-22 | WordPress OMGF Pro plugin <= 5.2.7 - Arbitrary File Download vulnerability |
| CVE-2026-73655 | 7.4 | 28.9 | triggerdotdev | trigger.dev | CWE-287 | Trigger.dev: Account Takeover via Cross-Provider OAuth Email Matching in Goog… |
| CVE-2026-70457 | 8.3 | 28.8 | RsyncProject | rsync | CWE-131 | rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg() |
| CVE-2026-67991 | 7.5 | 28.7 | n/a | n/a | CWE-1333 | crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a … |
| CVE-2026-72660 | 6.5 | 28.6 | Elastic | Kibana | CWE-248 | Uncaught Exception in Kibana Leading to Denial of Service |
| CVE-2026-72683 | 6.5 | 28.6 | Elastic | Elasticsearch | CWE-674 | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-72686 | 6.5 | 28.6 | Elastic | Elasticsearch | CWE-674 | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-27380 | 7.2 | 28.6 | magepeopleteam | Car Rental Manager | CWE-502 | WordPress Car Rental Manager plugin <= 1.3.9 - PHP Object Injection vulnerabi… |
| CVE-2026-73614 | 8.7 | 28.4 | Jovancoding | Network-AI | CWE-436 | Network-AI ClaudeHookBridge Deny Pattern Bypass via Truncation |
| CVE-2026-6464 | 8.1 | 28.5 | n/a | PostgreSQL | CWE-829 | PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql co… |
| CVE-2026-19744 | 5.1 | 28.4 | maalfer | Pentestify | CWE-79 | Stored Cross-site Scripting in Pentestify Markdown renderer via unescaped quotes |
| CVE-2026-72676 | 6.5 | 28.3 | Elastic | Fleet Server | CWE-94 | Improper Control of Generation of Code in Fleet Server Leading to Code Injection |
| CVE-2026-16861 | 5.3 | 28.3 | IBM | i | CWE-125 | IBM i is Affected By Multiple Vulnerabilities in NetServer |
| CVE-2026-17076 | 5.3 | 28.3 | IBM | i | CWE-770 | IBM i is Affected By Multiple Vulnerabilities in DRDA / DDM |
| CVE-2026-17077 | 5.3 | 28.3 | IBM | i | CWE-457 | IBM i is Affected By Multiple Vulnerabilities in DRDA / DDM |
| CVE-2026-17078 | 5.3 | 28.3 | IBM | i | CWE-400 | IBM i is Affected By A Denial of Service Vulnerability in DRDA / DDM [] |
| CVE-2026-17212 | 5.3 | 28.3 | IBM | i | CWE-125 | IBM i is Affected By Multiple Vulnerabilities in NetServer |
| CVE-2026-17216 | 5.3 | 28.3 | IBM | i | CWE-190 | IBM i is Affected By Multiple Vulnerabilities in DRDA / DDM |
| CVE-2026-18146 | 7.2 | 28.3 | wpmanageninja | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | CWE-79 | Fluent Forms <= 6.2.11 - Unauthenticated Stored Cross-Site Scripting via Noti… |
| CVE-2026-73304 | 4.9 | 28.2 | Budibase | budibase | CWE-200 | Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role … |
| CVE-2026-66444 | 6.5 | 28.2 | kendysond | Payment Forms for Paystack | CWE-497 | WordPress Payment Forms for Paystack plugin <= 4.0.5 - Sensitive Data Exposur… |
| CVE-2026-73841 | 8.8 | 28.0 | openchoreo | openchoreo | CWE-639 | OpenChoreo: Cross-project command execution and wirelog view access via OpenC… |
| CVE-2026-16868 | 7.5 | 27.9 | IBM | i | CWE-908 | IBM i is Affected By Multiple Vulnerabilities in NetServer |
| CVE-2026-28186 | 8.1 | 27.8 | themefic | Travelfic Toolkit | CWE-862 | WordPress Travelfic Toolkit plugin <= 1.5.1 - Broken Access Control vulnerabi… |
| CVE-2026-28159 | 6.5 | 27.8 | Aonetheme | Service Finder Booking | CWE-862 | WordPress Service Finder Booking plugin <= 6.2 - Broken Access Control vulner… |
| CVE-2026-17043 | 3.8 | 27.8 | IBM | i | CWE-22 | IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager |
| CVE-2026-73568 | 7.5 | 27.7 | libp2p | py-libp2p | CWE-400 | py-libp2p: yamux connection DoS via oversized data frame |
| CVE-2026-15741 | 8.8 | 27.5 | n/a | PostgreSQL | CWE-89 | PostgreSQL expression deparse allows SQL injection via EXTRACT argument |
| CVE-2026-17197 | 9.8 | 27.2 | IBM | i | CWE-287 | IBM i is Affected By Multiple Vulnerabilities in Host Servers |
| CVE-2026-19484 | 7.5 | 27.3 | @fastify/busboy | @fastify/busboy | CWE-835 | @fastify/busboy vulnerable to Denial of Service via oversized multipart boundary |
| CVE-2026-49857 | 7.4 | 27.3 | ymw0407 | auth-fetch-mcp | CWE-918 | auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback |
| CVE-2026-58429 | 4.9 | 27.2 | Gitea | Gitea Open Source Git Server | CWE-284 | Public-Only Personal access tokens scope bypass in Organization and Permissio… |
| CVE-2026-19745 | 2.1 | 27.0 | Calix | GigaSpire | CWE-404 | Calix GigaSpire Web Management utilities_configurationsave.cgi denial of service |
| CVE-2026-19746 | 2.1 | 27.0 | Calix | GigaSpire | CWE-404 | Calix GigaSpire traceroute.cmd denial of service |
| CVE-2026-73643 | 7.5 | 26.9 | nodeca | js-yaml | CWE-407 | js-yaml: Exponential parsing time in the flow collections leads to denial of … |
| CVE-2026-70463 | 8.6 | 26.8 | RsyncProject | rsync | CWE-863 | rsync 3.1.0 < 3.5.0 Authorization Bypass via auth users Directive Parsing |
| CVE-2026-73659 | 8.1 | 26.9 | triggerdotdev | trigger.dev | CWE-22 | Trigger.dev: Cross-tenant object read/write via path traversal in packet pres… |
| CVE-2026-19716 | 5.1 | 26.8 | maalfer | Pentestify | CWE-79 | Stored Cross-site Scripting in Pentestify user account deletion via unescaped… |
| CVE-2026-73656 | 9.9 | 26.7 | triggerdotdev | trigger.dev | CWE-639 | Trigger.dev: Cross-project deployment worker registration can modify another … |
| CVE-2026-56750 | 9.1 | 26.7 | Gitea | Gitea Open Source Git Server | CWE-284 | Gitea Remember-Me Token Theft Not Invalidating Attacker Session |
| CVE-2026-17272 | 7.5 | 26.7 | IBM | i | CWE-787 | IBM i is Affected By a Denial of Service in HTTP Server [] |
| CVE-2026-58417 | 7.5 | 26.7 | Gitea | Gitea Open Source Git Server | CWE-284 | REST API exposes organization membership of private organizations to public |
| CVE-2026-58427 | 7.5 | 26.7 | Gitea | Gitea Open Source Git Server | CWE-200 | Private org member list leaked via /members API endpoint — incomplete fix for… |
| CVE-2026-59714 | 7.1 | 26.6 | open-webui | open-webui | CWE-862 | Open WebUI: Cross-channel message overwrite via chat completion API (single-m… |
| CVE-2026-66450 | 8.1 | 26.2 | Dylan Kuhn | Geo Mashup | CWE-98 | WordPress Geo Mashup plugin <= 1.13.18 - Local File Inclusion vulnerability |
| CVE-2026-66653 | 8.1 | 26.2 | Edge-Themes | Barista | CWE-98 | WordPress Barista theme <= 2.5.1 - Local File Inclusion vulnerability |
| CVE-2026-66656 | 8.1 | 26.2 | Mikado-Themes | Foton Core | CWE-98 | WordPress Foton Core plugin <= 1.1.1 - Local File Inclusion vulnerability |
| CVE-2026-66657 | 8.1 | 26.2 | Mikado-Themes | Biagiotti Core | CWE-98 | WordPress Biagiotti Core plugin <= 2.1.1 - Local File Inclusion vulnerability |
| CVE-2026-55984 | 2.7 | 26.0 | Gitea | Gitea Open Source Git Server | CWE-284 | Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service |
| CVE-2026-73661 | 8.6 | 25.9 | FreePBX | framework | CWE-15 | FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup |
| CVE-2026-72670 | 7.7 | 25.9 | Elastic | Kibana | CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor in Kibana Leading … |
| CVE-2026-58436 | 7.5 | 25.9 | Gitea | Gitea Open Source Git Server | CWE-407 | ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticat… |
| CVE-2026-73654 | 8.5 | 25.8 | triggerdotdev | trigger.dev | CWE-1321 | Trigger.dev: Prototype pollution via run metadata operations → process-wide c… |
| CVE-2026-73508 | 5.3 | 25.7 | netty | netty | CWE-772 | Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names |
| CVE-2026-28156 | 8.5 | 25.6 | Lasso Analytics, Inc. | Do Lasso | CWE-89 | WordPress Do Lasso plugin <= 358 - SQL Injection vulnerability |
| CVE-2026-28168 | 8.5 | 25.6 | Imran Tauqeer | CubeWP | CWE-89 | WordPress CubeWP plugin <= 1.1.30 - SQL Injection vulnerability |
| CVE-2026-66430 | 8.5 | 25.6 | CODEPRESS | Visitor Traffic Real Time Statistics Pro | CWE-89 | WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.10 - SQL Inje… |
| CVE-2026-66658 | 8.5 | 25.6 | MVPThemes | Reviewer | CWE-89 | WordPress Reviewer plugin <= 3.14.2 - SQL Injection vulnerability |
| CVE-2026-73658 | 8.2 | 25.5 | triggerdotdev | trigger.dev | CWE-20 | Trigger.dev: Cross-tenant object store read and write via URL path traversal |
| CVE-2026-73620 | 7.2 | 25.5 | gitpython-developers | GitPython | CWE-22 | GitPython before 3.1.57 Arbitrary File Overwrite and Read |
| CVE-2026-48099 | 7.1 | 25.4 | mar10 | wsgidav | CWE-22 | WsgiDAV encoded dot segments can escape filesystem share roots |
| CVE-2026-58428 | 6.5 | 25.4 | Gitea | Gitea Open Source Git Server | CWE-424 | Release attachment extension allowlist bypass via web release edit form (vari… |
| CVE-2026-49864 | 8.6 | 25.3 | butlerx | wetty | CWE-79 | wetty vulnerable to DOM XSS via file-download filename |
| CVE-2026-73408 | 7.6 | 25.3 | Budibase | budibase | CWE-89 | Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Databas… |
| CVE-2026-16929 | 6.5 | 25.3 | IBM | i | CWE-787 | IBM i is Affected By Multiple Vulnerabilities in Host Servers |
| CVE-2026-72642 | 8.8 | 25.2 | Elastic | Elasticsearch | CWE-823 | Use of Out-of-range Pointer Offset in the Elasticsearch Machine Learning Nati… |
| CVE-2026-18193 | 10.0 | 25.1 | IBM | i | CWE-269 | IBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java Ru… |
| CVE-2026-61967 | 9.8 | 25.1 | miniOrange | miniorange otp verification | CWE-640 | WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation … |
| CVE-2026-8715 | 9.6 | 25.1 | HashiCorp | Tooling | CWE-552 | Vault Secrets Operator vulnerable to arbitrary file read and credential exfil… |
| CVE-2026-73486 | 9.0 | 25.1 | FlowiseAI | Flowise | CWE-94 | Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV |
| CVE-2026-72629 | 7.1 | 25.1 | Elastic | Kibana | CWE-639 | Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-S… |
| CVE-2026-19710 | 5.5 | 25.2 | SourceCodester | Simple Student Information System | CWE-74 | SourceCodester Simple Student Information System view_department.php sql inje… |
| CVE-2026-19734 | 8.6 | 25.1 | Roskus | Prospero Flow CRM | CWE-639 | IDOR in Prospero Flow CRM allows cross-tenant product disclosure and hijacking |
| CVE-2026-72856 | 8.6 | 25.0 | Budibase | budibase | CWE-640 | Budibase before 3.40.0 Authentication Bypass via Tenant Owner Email |
| CVE-2026-14668 | 8.1 | 25.0 | n/a | PostgreSQL | CWE-843 | PostgreSQL ctid type confusion in selectivity estimator discloses derivative … |
| CVE-2026-16853 | 7.5 | 25.0 | IBM | i | CWE-125 | IBM i is Affected By Multiple Vulnerabilities in NetServer |
| CVE-2026-13610 | 7.5 | 24.9 | Unknown | KiviCare | CWE-269 | KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration |
| CVE-2026-17099 | 7.3 | 24.9 | IBM | i | CWE-287 | IBM i is Affected By Multiple Vulnerabilities in Navigator for i |
| CVE-2026-27999 | 6.5 | 24.9 | themefic | Tourfic | CWE-862 | WordPress Tourfic plugin <= 2.23.1 - Broken Access Control vulnerability |
| CVE-2026-28181 | 6.5 | 24.9 | AcyMailing Newsletter Team | AcyMailing SMTP Newsletter | CWE-862 | WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Broken Access Contro… |
| CVE-2026-49089 | 6.5 | 24.8 | Elastic | Kibana | CWE-770 | Allocation of Resources Without Limits or Throttling in Kibana Leading to Den… |
| CVE-2026-17071 | 2.7 | 24.8 | IBM | i | CWE-22 | IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager |
| CVE-2026-48702 | 7.5 | 24.7 | sigstore | rekor | CWE-770 | Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK … |
| CVE-2026-66424 | 9.8 | 24.4 | Cozy Vision Technologies Pvt. Ltd. | SMS Alert Order Notifications | CWE-266 | WordPress SMS Alert Order Notifications plugin <= 3.9.7 - Privilege Escalatio… |
| CVE-2026-66691 | 9.8 | 24.4 | scriptsbundle | Nokri | CWE-640 | WordPress Nokri theme <= 1.6.6 - Broken Access Control vulnerability |
| CVE-2026-73567 | 9.1 | 24.4 | JuneAndGreen | sm-crypto | CWE-338 | sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.r… |
| CVE-2026-18077 | 7.5 | 24.0 | IBM | i | CWE-787 | IBM i is Affected By Multiple Vulnerabilities in Simple Mail Transfer Protocol |
| CVE-2026-72777 | 7.7 | 23.9 | DayuanJiang | next-ai-draw-io | CWE-918 | Next AI Draw.io 0.4.16 SSRF via DNS Rebinding in parse-url |
| CVE-2026-73603 | 6.3 | 23.8 | FlowiseAI | Flowise | CWE-862 | Flowise before 3.1.4 Credential Abuse via Text-to-Speech |
| CVE-2026-73556 | 5.3 | 23.6 | vllm-project | vllm | CWE-400 | vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (n… |
| CVE-2026-73302 | 9.0 | 23.5 | Budibase | budibase | CWE-287 | Budibase: OIDC SSO account takeover: incoming identity linked by email withou… |
| CVE-2026-0301 | 1.7 | 23.5 | Palo Alto Networks | Cloud NGFW | CWE-908 | PAN-OS: Information Disclosure Vulnerability in URL Filtering |
| CVE-2026-55402 | 8.7 | 23.3 | Absolute Security | Secure Access | CWE-125 | CVE-2026-55402 is an out of bounds read vulnerability in Secure Access server… |
| CVE-2026-59109 | 8.7 | 23.4 | Zalktis Programmas (SIA "Zalktis Programmas") | Zalktis | CWE-20 | Zalktis: SQL injection via partner-controlled fields in imported e-invoices |
| CVE-2026-55401 | 6.9 | 23.3 | Absolute Security | Secure Access | CWE-476 | CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-… |
| CVE-2026-73530 | 6.3 | 23.4 | flytohub | flyto-core | CWE-918 | Flyto2 Core < 2.28.0 SSRF Guard Bypass via is_private_ip() |
| CVE-2026-53789 | 7.1 | 23.2 | RsyncProject | rsync | CWE-807 | rsync < 3.5.0 Arbitrary File Deletion via Malicious File List |
| CVE-2026-53792 | 7.1 | 23.2 | RsyncProject | rsync | CWE-129 | rsync < 3.5.0 Out-of-Bounds Read via Zero-Length Checksum Block |
| CVE-2026-16961 | 9.8 | 23.0 | IBM | i | CWE-89 | IBM i is Affected By SQL Injection Vulnerability in Db2 Mirror [] |
| CVE-2026-17075 | 8.2 | 23.0 | IBM | i | CWE-287 | IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager |
| CVE-2026-17045 | 8.1 | 22.9 | IBM | i | CWE-294 | IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager |
| CVE-2026-19748 | 2.9 | 22.9 | Tenda | CH7 | CWE-330 | Tenda CH7 Kylin Web Service CWebSessionManager_ParseSession entropy |
| CVE-2026-27535 | 7.1 | 22.8 | solacewp | Solace Extra | CWE-862 | WordPress Solace Extra plugin <= 1.6.0 - Broken Access Control vulnerability |
| CVE-2026-14525 | 9.4 | 22.7 | IBM | WebSphere Application Server - Liberty | CWE-306 | IBM WebSphere Application Server Liberty is affected by an authenication bypass |
| CVE-2026-73647 | 5.6 | 22.7 | quasarframework | quasar | CWE-1321 | Quasar Framework: Prototype pollution in Quasar extend() utility |
| CVE-2026-24059 | 6.5 | 22.5 | Gitea | Gitea Open Source Git Server | CWE-269 | Gitea runner registration-token GET endpoint performs a write under a read-on… |
| CVE-2026-14182 | 9.8 | 22.3 | Unknown | Customer Email Verification for WooCommerce | CWE-287 | Customer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account… |
| CVE-2026-59503 | 9.1 | 22.3 | Priority | Portal Generator addon to Priority ERP (developed by Soft Solutions) | CWE-200 | Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Acto… |
| CVE-2026-59504 | 9.1 | 22.3 | Priority | Portal Generator addon to Priority ERP (developed by Soft Solutions) | CWE-602 | Priority – CWE-602: Client-Side Enforcement of Server-Side Security |
| CVE-2026-72840 | 8.7 | 22.4 | openwrt | luci | CWE-266 | OpenWrt LuCI luci-mod-system-mounts ACL Root RCE via Crontab Write |
| CVE-2026-66661 | 7.7 | 22.3 | Onokazu | Directories Pro | CWE-266 | WordPress Directories Pro plugin <= 2.0.5 - Privilege Escalation vulnerability |
| CVE-2026-66462 | 7.5 | 22.3 | BookingWP | WooCommerce Appointments | CWE-497 | WordPress WooCommerce Appointments plugin <= 5.3.8 - Sensitive Data Exposure … |
| CVE-2026-28176 | 8.8 | 22.2 | Booking Activities Team | Booking Activities | CWE-502 | WordPress Booking Activities plugin <= 1.18.4 - PHP Object Injection vulnerab… |
| CVE-2026-17226 | 5.4 | 22.2 | IBM | i | CWE-125 | IBM i is Affected By Multiple Vulnerabilities in NetServer |
| CVE-2026-59765 | 7.5 | 22.1 | Gitea | Gitea Open Source Git Server | CWE-918 | SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal File… |
| CVE-2026-17502 | 7.5 | 22.0 | IBM | i | CWE-787 | IBM i is Affected By Multiple Vulnerabilities in NetServer |
| CVE-2026-57897 | 6.5 | 22.0 | Gitea | Gitea Open Source Git Server | CWE-200 | Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs |
| CVE-2026-59500 | 10.0 | 21.8 | Priority | Portal Generator addon to Priority ERP (developed by Soft Solutions) | CWE-287 | Priority - CWE-287: Improper Authentication |
| CVE-2026-56864 | 7.5 | 21.8 | Go toolchain | cmd/go | CWE-347 | Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb |
| CVE-2026-16878 | 6.5 | 21.8 | IBM | i | CWE-125 | IBM i is Affected By Multiple Vulnerabilities in NetServer |
| CVE-2026-73665 | 9.3 | 21.5 | FreePBX | ucp | CWE-862 | FreePBX UCP: Unauthenticated remote code execution via socket.io namespace au… |
| CVE-2026-55987 | 8.1 | 21.4 | Gitea | Gitea Open Source Git Server | CWE-863 | OAuth2 sign-in reactivates an administrator-deactivated account on auth sourc… |
| CVE-2026-58314 | 7.7 | 21.4 | Gitea | Gitea Open Source Git Server | CWE-918 | Two SSRF findings in Gitea 1.26.2 |
| CVE-2026-72666 | 6.8 | 21.5 | Elastic | Kibana | CWE-639 | Authorization Bypass Through User-Controlled Key in Kibana Leading to Unautho… |
| CVE-2026-73644 | 9.6 | 21.4 | OpenIdentityPlatform | OpenDJ | CWE-285 | OpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder t… |
| CVE-2026-54481 | 7.5 | 21.3 | Gitea | Gitea Open Source Git Server | CWE-295 | Internal API HTTP client hardcodes InsecureSkipVerify:true with no config ove… |
| CVE-2026-66463 | 7.5 | 21.3 | Hassan Fakih | iCARRY | CWE-201 | WordPress iCARRY plugin <= 2.9 - Sensitive Data Exposure vulnerability |
| CVE-2026-72636 | 6.5 | 21.4 | Elastic | Elasticsearch | CWE-674 | Uncontrolled Recursion in Elasticsearch Wildcard Matching Leading to Denial o… |
| CVE-2026-16859 | 5.3 | 21.2 | IBM | i | CWE-125 | IBM i is Affected By Multiple Vulnerabilities in NetServer |
| CVE-2026-59506 | 9.3 | 21.2 | Priority | Portal Generator addon to Priority ERP (developed by Soft Solutions) | CWE-306 | Priority – CWE-306: Missing Authentication for Critical Function |
| CVE-2026-28189 | 7.4 | 21.1 | Roland Barker | Participants Database | CWE-22 | WordPress Participants Database plugin <= 2.7.8.4 - Arbitrary File Deletion v… |
| CVE-2026-73843 | 9.6 | 21.1 | openchoreo | openchoreo | CWE-306 | OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cl… |
| CVE-2026-16692 | 6.5 | 21.0 | IBM | i | CWE-787 | IBM i is Affected By Multiple Vulnerabilities in Simple Mail Transfer Protocol |
| CVE-2026-49820 | 4.7 | 21.0 | getprobo | probo | CWE-601 | Probo has an open redirect bypass via path normalization |
| CVE-2026-15413 | 10.0 | 20.9 | Unknown | Link Factory | CWE-912 | Link Factory - Backdoor |
| CVE-2026-73618 | 8.7 | 21.0 | budibase | server | CWE-943 | Budibase Server before 3.40.0 NoSQL Injection via JSON Parameter |
| CVE-2026-72638 | 6.5 | 20.9 | Elastic | Elasticsearch | CWE-674 | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-72639 | 6.5 | 20.9 | Elastic | Elasticsearch | CWE-789 | Memory Allocation with Excessive Size Value in Elasticsearch Highlighting Lea… |
| CVE-2026-72645 | 6.5 | 20.9 | Elastic | Elasticsearch | CWE-789 | Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denia… |
| CVE-2026-72647 | 6.5 | 20.9 | Elastic | Elasticsearch | CWE-674 | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-72651 | 6.5 | 20.9 | Elastic | Kibana | CWE-770 | Allocation of Resources Without Limits or Throttling in Kibana Leading to Den… |
| CVE-2026-72653 | 6.5 | 20.9 | Elastic | Kibana | CWE-770 | Allocation of Resources Without Limits or Throttling in Kibana Leading to Den… |
| CVE-2026-72656 | 6.5 | 20.9 | Elastic | Elasticsearch | CWE-789 | Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denia… |
| CVE-2026-72659 | 6.5 | 20.9 | Elastic | Kibana | CWE-770 | Allocation of Resources Without Limits or Throttling in Kibana Leading to Den… |
| CVE-2026-72663 | 6.5 | 20.9 | Elastic | Kibana | CWE-407 | Inefficient Algorithmic Complexity in Kibana Leading to Denial of Service |
| CVE-2026-72667 | 6.5 | 20.9 | Elastic | Kibana | CWE-770 | Allocation of Resources Without Limits or Throttling in Kibana Leading to Den… |
| CVE-2026-72674 | 6.5 | 20.9 | Elastic | Kibana | CWE-770 | Allocation of Resources Without Limits or Throttling in Kibana Leading to Den… |
| CVE-2026-72678 | 6.5 | 20.9 | Elastic | Elasticsearch | CWE-789 | Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denia… |
| CVE-2026-72679 | 6.5 | 20.9 | Elastic | Elasticsearch | CWE-674 | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-72684 | 6.5 | 20.9 | Elastic | Elasticsearch | CWE-770 | Allocation of Resources Without Limits or Throttling in Elasticsearch Leading… |
| CVE-2026-72687 | 6.5 | 20.9 | Elastic | Elasticsearch | CWE-789 | Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denia… |
| CVE-2026-73484 | 8.6 | 20.9 | FlowiseAI | Flowise | CWE-184 | Flowise before 3.1.3 Sandbox Escape via Pandas Methods |
| CVE-2026-18020 | 5.3 | 20.9 | IBM | i | CWE-125 | IBM i is Affected By Multiple Vulnerabilities in NetServer |
| CVE-2026-19756 | 2.1 | 20.8 | Dromara | lamp-cloud | CWE-22 | Dromara lamp-cloud Code Generator DefGenProjectController.java path traversal |
| CVE-2026-59505 | 8.6 | 20.6 | Priority | Portal Generator addon to Priority ERP (developed by Soft Solutions) | CWE-284 | Priority - CWE-284: Improper Access Control |
| CVE-2026-14679 | 8.2 | 20.7 | n/a | PostgreSQL | CWE-121 | PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to serv… |
| CVE-2026-61984 | 7.5 | 20.6 | Amauri | WPMobile.App | CWE-862 | WordPress WPMobile.App plugin <= 11.77 - Broken Access Control vulnerability |
| CVE-2026-72851 | 9.0 | 20.5 | budibase | server | CWE-89 | Budibase before 3.40.0 SQL Injection via Unauthenticated Webhook |
| CVE-2026-53801 | 8.2 | 20.5 | RsyncProject | rsync | CWE-59 | rsync < 3.5.0 Symlink Race Condition Directory Traversal |
| CVE-2026-6471 | 7.2 | 20.5 | n/a | PostgreSQL | CWE-862 | PostgreSQL logical decoding can dlopen arbitrary file |
| CVE-2026-50105 | 4.3 | 20.5 | Gitea | Gitea Open Source Git Server | CWE-200 | RSS/Atom feed handlers bypass API-token scope & public-only confinement (inco… |
| CVE-2026-58433 | 9.1 | 20.3 | Gitea | Gitea Open Source Git Server | CWE-862 | Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organ… |
| CVE-2026-58439 | 8.1 | 20.4 | Gitea | Gitea Open Source Git Server | CWE-284 | Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approv… |
| CVE-2026-28001 | 9.3 | 20.2 | WPDirectoryKit | WP Directory Kit | CWE-89 | WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability |
| CVE-2026-28142 | 9.3 | 20.2 | Shamalli | Web Directory Free | CWE-89 | WordPress Web Directory Free plugin <= 1.7.13 - SQL Injection vulnerability |
| CVE-2026-61969 | 9.3 | 20.2 | Webilia Inc. | Listdom | CWE-89 | WordPress Listdom plugin <= 5.6.0 - SQL Injection vulnerability |
| CVE-2026-66436 | 9.3 | 20.2 | RealMag777 | Active Products Tables for WooCommerce | CWE-89 | WordPress Active Products Tables for WooCommerce plugin <= 1.1.1 - SQL Inject… |
| CVE-2026-66458 | 9.3 | 20.2 | ThimPress | RealPress | CWE-89 | WordPress RealPress plugin <= 1.1.2 - SQL Injection vulnerability |
| CVE-2026-66472 | 9.3 | 20.2 | everestthemes | Everest Backup | CWE-89 | WordPress Everest Backup plugin <= 2.3.12 - SQL Injection vulnerability |
| CVE-2026-66478 | 9.3 | 20.2 | andy_moyle | Church Admin | CWE-89 | WordPress Church Admin plugin <= 5.1.1 - SQL Injection vulnerability |
| CVE-2026-73485 | 9.0 | 20.2 | FlowiseAI | Flowise | CWE-94 | Flowise before 3.1.3 Remote Code Execution via Airtable Agent |
| CVE-2026-73622 | 8.7 | 20.2 | gitpython-developers | GitPython | CWE-200 | GitPython before 3.1.55 Environment Variable Exfiltration via Remote.add() |
| CVE-2026-58434 | 7.5 | 20.3 | Gitea | Gitea Open Source Git Server | CWE-200 | Private Repository Metadata Remains Accessible After Access Revocation |
| CVE-2026-16722 | 8.8 | 20.2 | IBM | i | CWE-269 | IBM i is Affected By An Unauthorized Privileges Vulnerability in SQL [] |
| CVE-2026-13460 | 7.5 | 20.1 | IBM | Storage Scale | CWE-798 | The following vulnerabilities that can affect IBM Storage Scale and the Manag… |
| CVE-2026-18249 | 9.9 | 20.1 | IBM | i | CWE-269 | IBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java Ru… |
| CVE-2026-73604 | 7.1 | 20.0 | FlowiseAI | Flowise | CWE-200 | Flowise before 3.1.3 Credential Exposure via API |
| CVE-2026-72664 | 6.5 | 20.0 | Elastic | Kibana | CWE-862 | Missing Authorization in Kibana Leading to Unauthorized Execution of Endpoint… |
| CVE-2026-73346 | 7.6 | 19.8 | Mailchimp | MailChimp For WooCommerce | CWE-89 | WordPress MailChimp For WooCommerce plugin < 6.2 - SQL Injection vulnerability |
| CVE-2026-66693 | 6.5 | 19.8 | Stylemix | Motors | CWE-862 | WordPress Motors plugin <= 1.4.113 - Broken Access Control vulnerability |
| CVE-2026-19481 | 7.5 | 19.8 | @fastify/busboy | @fastify/busboy | CWE-754 | @fastify/busboy vulnerable to Denial of Service via prototype-named multipart… |
| CVE-2026-53798 | 6.9 | 19.7 | RsyncProject | rsync | CWE-704 | rsync < 3.5.0 Privilege Confusion via name-converter uid/gid mapping |
| CVE-2026-58440 | 6.8 | 19.7 | Gitea | Gitea Open Source Git Server | CWE-284 | Webhooks created by a collaborator keep firing after their repo access is rev… |
| CVE-2026-72661 | 6.5 | 19.7 | Elastic | Kibana | CWE-862 | Missing Authorization in Kibana Leading to Information Disclosure |
| CVE-2026-19753 | 5.5 | 19.7 | Model Context Protocol | mcp-rdf-explorer | CWE-918 | Model Context Protocol mcp-rdf-explorer MCP Server server.py explore_url serv… |
| CVE-2026-73624 | 7.2 | 19.6 | gitpython-developers | GitPython | CWE-88 | GitPython before 3.1.54 Arbitrary File Overwrite via diff |
| CVE-2026-72648 | 6.5 | 19.3 | Elastic | Eck Operator | CWE-526 | Cleartext Storage of Sensitive Information in an Environment Variable in Elas… |
| CVE-2026-10571 | 5.3 | 19.3 | IBM | WebSphere Application Server - Liberty | CWE-502 | IBM WebSphere Application Server Liberty is affected by a denial of service |
| CVE-2026-17476 | 5.3 | 19.2 | IBM | i | CWE-787 | IBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java Ru… |
| CVE-2026-72855 | 8.4 | 19.1 | budibase | server | CWE-918 | Budibase before 3.40.0 DNS Rebinding SSRF via OpenAPI and REST |
| CVE-2026-3835 | 5.3 | 19.1 | buildwps | Prevent Direct Access – Protect WordPress Files | CWE-285 | Prevent Direct Access – Protect WordPress Files <= 2.8.8.8 - Unauthenticated … |
| CVE-2026-72677 | 7.3 | 19.0 | Elastic | Kibana | CWE-23 | Relative Path Traversal in Kibana Fleet Leading to Unauthorized Deletion of U… |
| CVE-2026-53786 | 6.9 | 19.0 | RsyncProject | rsync | CWE-863 | rsync < 3.5.0 Filter Rule Bypass via --filter Merge Directive |
| CVE-2026-16815 | 9.1 | 18.8 | IBM | i | CWE-787 | IBM i is Affected By Multiple Vulnerabilities in Simple Mail Transfer Protocol |
| CVE-2026-16871 | 4.3 | 18.8 | IBM | i | CWE-787 | IBM i is Affected By Multiple Vulnerabilities in NetServer |
| CVE-2026-72650 | 4.3 | 18.8 | Elastic | Kibana | CWE-639 | Authorization Bypass Through User-Controlled Key in Kibana Leading to Informa… |
| CVE-2026-28174 | 6.5 | 18.7 | Arraytics | WP Event SOlution | CWE-201 | WordPress WP Event SOlution plugin <= 4.1.18 - Sensitive Data Exposure vulner… |
| CVE-2026-19751 | 2.1 | 18.7 | EnzoVezzaro | mcp-dominican-layer | CWE-918 | EnzoVezzaro mcp-dominican-layer parse-csv tool index.ts axios.get server-side… |
| CVE-2026-19752 | 2.1 | 18.7 | EnzoVezzaro | mcp-dominican-layer | CWE-918 | EnzoVezzaro mcp-dominican-layer PDF Parsing index.ts parse-pdf server-side re… |
| CVE-2026-58508 | 9.1 | 18.4 | Gitea | Gitea Open Source Git Server | CWE-284 | Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing r… |
| CVE-2026-72665 | 8.1 | 18.5 | Elastic | Kibana | CWE-862 | Missing Authorization in Kibana Leading to Unauthorized Execution of Host Res… |
| CVE-2026-58438 | 7.5 | 18.4 | Gitea | Gitea Open Source Git Server | CWE-862 | Cross-repository IDOR in issue-dependency removal lets an attacker tamper wit… |
| CVE-2026-45725 | 7.1 | 18.5 | oscal-compass | compliance-trestle | CWE-73 | compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via … |
| CVE-2026-72657 | 6.5 | 18.4 | Elastic | Fleet Server | CWE-639 | Authorization Bypass Through User-Controlled Key in Fleet Server Leading to I… |
| CVE-2026-58432 | 5.9 | 18.5 | Gitea | Gitea Open Source Git Server | CWE-200 | Missing Authorization and Authorization Bypass Through User-Controlled Key an… |
| CVE-2026-57894 | 8.5 | 18.4 | Gitea | Gitea Open Source Git Server | CWE-918 | Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validat… |
| CVE-2026-73612 | 8.6 | 18.1 | filebrowser | filebrowser | CWE-639 | File Browser before v2.63.22 Authorization Bypass via Recursive Operations |
| CVE-2026-73611 | 7.6 | 18.0 | filebrowser | filebrowser | CWE-613 | File Browser 2.50.0 through 2.63.21 JWT Expiration Bypass |
| CVE-2026-73488 | 6.0 | 18.0 | FlowiseAI | Flowise | CWE-639 | Flowise before 3.1.3 IDOR via customer-default-source endpoint |
| CVE-2026-27543 | 8.1 | 17.8 | FluxBuilder | MStore API | CWE-266 | WordPress MStore API plugin <= 4.20.0 - Privilege Escalation vulnerability |
| CVE-2026-61979 | 8.1 | 17.8 | miniOrange | SAML SP Single Sign On | CWE-266 | WordPress SAML SP Single Sign On plugin <= 5.4.3 - Privilege Escalation vulne… |
| CVE-2026-58425 | 4.3 | 17.6 | Gitea | Gitea Open Source Git Server | CWE-200 | OAuth token introspection returns metadata of tokens issued to other clients … |
| CVE-2026-49096 | 4.3 | 17.5 | Elastic | Kibana | CWE-248 | Uncaught Exception in Kibana Cases Leading to Denial of Service |
| CVE-2026-72685 | 4.3 | 17.5 | Elastic | Elasticsearch | CWE-407 | Inefficient Algorithmic Complexity in Elasticsearch Leading to Denial of Service |
| CVE-2026-17468 | 5.3 | 17.4 | IBM | Documentation Offline | CWE-321 | IBM Documentation Offline is vulnerable to information disclosure, session fo… |
| CVE-2026-73558 | 5.3 | 17.4 | vllm-project | vllm | CWE-190 | vLLM: Cross-User Data Leak Vulnerability |
| CVE-2026-70462 | 7.1 | 17.2 | RsyncProject | rsync | CWE-190 | rsync 3.1.0 < 3.5.0 Signed Integer Overflow via MSG_IO_TIMEOUT |
| CVE-2026-73489 | 4.3 | 17.3 | Eugeny | russh | CWE-129 | Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode re… |
| CVE-2026-72857 | 8.3 | 17.1 | Budibase | budibase | CWE-522 | Budibase before 3.40.0 Credential Exposure via STRING Fields |
| CVE-2026-58507 | 5.3 | 16.9 | Gitea | Gitea Open Source Git Server | CWE-284 | Private Repository Existence Disclosure via go-get Meta Endpoint |
| CVE-2026-73555 | 5.3 | 16.7 | vllm-project | vllm | CWE-209 | vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Er… |
| CVE-2026-16967 | 7.5 | 16.6 | IBM | i | CWE-367 | IBM i is Affected By Multiple SQL Vulnerabilities [, ] |
| CVE-2026-28002 | 8.5 | 16.4 | Arraytics | Booktics | CWE-89 | WordPress Booktics plugin 1.0.22 - SQL Injection vulnerability |
| CVE-2026-72643 | 7.1 | 16.5 | Elastic | Kibana | CWE-863 | Incorrect Authorization in Kibana Agent Builder Leading to Disclosure and Tam… |
| CVE-2026-56858 | 6.1 | 16.5 | Go standard library | html/template | CWE-79 | Fix Javascript regexp context tracking in html/template |
| CVE-2026-55986 | 5.4 | 16.5 | Gitea | Gitea Open Source Git Server | CWE-284 | Email Management API Bypasses ManageCredentials Feature Restrictions |
| CVE-2026-73573 | 3.1 | 16.4 | Zimbra | Collaboration | CWE-24 | In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability … |
| CVE-2026-58416 | 7.1 | 16.4 | Gitea | Gitea Open Source Git Server | CWE-280 | Fork-PR Actions task can read a third private repository via the collaborativ… |
| CVE-2026-72681 | 6.5 | 16.4 | Elastic | Kibana | CWE-862 | Missing Authorization in Kibana Leading to Privilege Escalation and Informati… |
| CVE-2026-57886 | 5.9 | 16.4 | Gitea | Gitea Open Source Git Server | CWE-639 | Cross-repository issue/comment attachment re-linking can expose private attac… |
| CVE-2026-14672 | 5.3 | 16.3 | n/a | PostgreSQL | CWE-204 | PostgreSQL observable response discrepancy with non-default scram_iterations … |
| CVE-2026-16713 | 5.3 | 16.3 | IBM | Documentation Offline | CWE-1327 | IBM Documentation Offline is vulnerable to information disclosure, session fo… |
| CVE-2026-24791 | 8.1 | 16.2 | Gitea | Gitea Open Source Git Server | CWE-863 | Public-only tokens bypass private-resource restrictions on `/api/v1/user` sel… |
| CVE-2026-53788 | 6.9 | 16.2 | RsyncProject | rsync | CWE-93 | rsync < 3.5.0 Newline Injection via name-converter uid/gid mapping |
| CVE-2026-73557 | 6.3 | 16.2 | vllm-project | vllm | CWE-362 | vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent pro… |
| CVE-2026-18715 | 6.5 | 15.9 | IBM | i | CWE-611 | IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server… |
| CVE-2026-73627 | 6.0 | 16.0 | jupyterlab | jupyterlab | CWE-602 | JupyterLab 4.6.0 Plugin Manager Lock-Rule Enforcement Bypass |
| CVE-2026-72672 | 7.7 | 15.9 | Elastic | Kibana | CWE-863 | Incorrect Authorization in Kibana Leading to Disclosure of Elastic Defend End… |
| CVE-2026-72640 | 6.5 | 15.8 | Elastic | Eck Operator | CWE-441 | Unintended Proxy or Intermediary in Elastic Cloud on Kubernetes Leading to Cr… |
| CVE-2026-3639 | 6.4 | 15.9 | buildwps | PPWP – Password Protect Pages | CWE-79 | PPWP – Password Protect Pages <= 1.9.21 - Authenticated (Contributor+) Stored… |
| CVE-2026-23603 | 3.1 | 15.8 | Gitea | Gitea Open Source Git Server | CWE-918 | Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim |
| CVE-2026-72632 | 7.1 | 15.8 | Elastic | Kibana | CWE-203 | Observable Discrepancy in Kibana Fleet Leading to Disclosure of Elastic Agent… |
| CVE-2026-72853 | 8.8 | 15.5 | Budibase | budibase | CWE-89 | Budibase before 3.40.0 SQL Injection via Oracle connector |
| CVE-2026-59499 | 8.6 | 15.5 | Priority | Portal Generator addon to Priority ERP (developed by Soft Solutions). | CWE-200 | Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor |
| CVE-2026-58442 | 6.5 | 15.5 | Gitea | Gitea Open Source Git Server | CWE-200 | Repository migration SSRF via multi-answer DNS allow-list bypass |
| CVE-2026-59507 | 9.3 | 15.3 | Priority | Portal Generator addon to Priority ERP (developed by Soft Solutions) | CWE-798 | Priority – CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensit… |
| CVE-2026-59501 | 8.2 | 15.3 | Priority | Portal Generator addon to Priority ERP (developed by Soft Solutions) | CWE-284 | Priority – CWE-284: Improper Access Control |
| CVE-2026-73482 | 7.2 | 15.3 | phplist | phplist3 | CWE-352 | phpList < 3.7.0-RC5 Cross-Site Request Forgery via admins.php |
| CVE-2026-58511 | 2.7 | 15.3 | Gitea | Gitea Open Source Git Server | CWE-200 | Webhook Authorization Header Returned in Plaintext via API |
| CVE-2026-73650 | 8.2 | 15.1 | svg | svgo | CWE-79 | SVGO: removeScripts plugin leaves some executable scripts intact |
| CVE-2026-73608 | 9.2 | 15.0 | siyuan-note | siyuan | CWE-862 | SiYuan before v3.7.4 Authorization Bypass via getAttributeViewSearchTarget |
| CVE-2026-27538 | 7.5 | 14.9 | WPDirectoryKit | WP Directory Kit | CWE-89 | WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability |
| CVE-2026-14298 | 6.5 | 14.8 | Mattermost | Mattermost | CWE-409 | Denial of service via resource exhaustion in Mattermost |
| CVE-2026-17649 | 5.3 | 14.9 | IBM | i | CWE-125 | IBM i is Affected By Multiple Vulnerabilities in NetServer |
| CVE-2026-59502 | 5.3 | 14.9 | Priority | Portal Generator addon to Priority ERP (developed by Soft Solutions) | CWE-203 | Priority - CWE-203: Observable Discrepancy |
| CVE-2026-58444 | 4.3 | 14.8 | Gitea | Gitea Open Source Git Server | CWE-863 | Personal access token scope enforcement bypass on the repository home page (`… |
| CVE-2026-28148 | 9.8 | 14.8 | miniOrange | Headless Single Sign On | CWE-347 | WordPress Headless Single Sign On plugin <= 1.6 - Bypass Vulnerability vulner… |
| CVE-2026-27345 | 7.5 | 14.6 | magepeopleteam | Taxi Booking Manager for WooCommerce | CWE-862 | WordPress Taxi Booking Manager for WooCommerce plugin <= 2.0.3 - Broken Acces… |
| CVE-2026-66431 | 7.5 | 14.6 | WoompaLoompa | Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) | CWE-862 | WordPress Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) plugi… |
| CVE-2026-66461 | 7.5 | 14.6 | smepay | SMEPay: UPI Gateway for WooCommerce | CWE-862 | WordPress SMEPay: UPI Gateway for WooCommerce plugin <= 1.0.5 - Payment Bypas… |
| CVE-2026-66466 | 7.5 | 14.6 | weDevs | StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart | CWE-862 | WordPress StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, D… |
| CVE-2026-66469 | 7.5 | 14.6 | Afonso Matos | Arvow AI SEO Writer | CWE-862 | WordPress Arvow AI SEO Writer plugin <= 1.5.3 - Broken Access Control vulnera… |
Results continue: ranks 401–606.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-08-13 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.