boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Friday, August 14, 2026 · all times UTC← 2026-08-13 · archive · 2026-08-15 →

Security Box Score — August 14, 2026

201 CVEs published, led by IBM (18).

201 CVEs published August 14, 2026: 24 critical, 84 high, 72 medium, 20 low; 0 in the KEV catalog at press time; 2 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 176 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published489127055——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

1556 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux4162731234140063711120.17.8.0016+376 ▲
microsoft4421864132127144714286251.37.8.0044-182 ▼
google491810222749783567760.37.5.0025-45 ▼
red hat1425283021525231200.06.5.0028+96 ▲
apple2273587913338872.67.0.0027+2 ▲
canonical1138129125000.07.8.0020+10 ▲
suse52651461000.08.1.0039-3 ▼
freebsd01601240000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco31691337190561318.87.5.0046+23 ▲
palo alto networks12371321121325.44.7.0020-2 ▼
ubiquiti036142110338.38.8.0049-25 ▼
netgear93200275000.04.3.0025+3 ▲
fortinet7307814128620.07.0.0050-4 ▼
vmware0174922715.98.3.0040-1 ▼
f50165830416.38.6.00570
ivanti314482025535.78.3.0754+1 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache9743386187147123320.57.5.0049+25 ▲
mozilla11285142350900.08.1.0031-5 ▼
gitlab1364113428423.14.9.0028+6 ▲
drupal05165355412.05.9.0026-46 ▼
github5171790000.06.6.0043+4 ▲
docker180530000.07.7.0015+1 ▲
wordpress1412102250.08.8.5550+1 ▲
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle01379343653322612730.28.1.00360
ibm192421991801375610.27.5.0031+190 ▲
adobe603123914512351931.07.8.0026-33 ▼
progress16581434100611.78.1.0036+6 ▲
solarwinds0231733010417.49.1.00580
veeam10165920100.08.6.0034+10 ▲
zohocorp4103520000.08.7.0140+4 ▲
atlassian0303001300.08.0.00260
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
siemens193522382000.07.3.0016+12 ▲
d-link153515596300.07.4.0157+14 ▲
synology12426133000.05.6.0025+1 ▲
rockwell automation02441820000.08.7.0029-17 ▼
schneider electric091620000.08.6.00370
abb070430000.07.2.00180
hikvision060420000.07.2.00400
moxa050320000.07.0.00290
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester16136007363000.05.5.0033-21 ▼
dell18117958473210.97.2.0021-15 ▼
openclaw01110583914000.07.0.0026-16 ▼
nvidia16981366190000.07.7.0034-24 ▼
gitea48891936304000.07.5.0034+8 ▲
elastic4886018680100.06.5.0029+39 ▲
capgo083242381000.07.1.0037-22 ▼
zephyrproject2780229409000.06.5.0023+13 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.995799.99.8
CVE-2026-34486.986299.97.5
CVE-2026-63030.977999.99.8
CVE-2026-16232.891299.89.3
CVE-2026-63077.847399.79.8
CVE-2026-60137.797999.65.9
CVE-2026-72898.792299.610.0
CVE-2026-25089.761199.59.8
CVE-2026-0770.634299.19.8
CVE-2026-59310.458898.79.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.7922KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0486
CVE-2026-4836210.0.0431
CVE-2026-4766810.0.0388
CVE-2026-1918810.0.0193
CVE-2026-4435910.0.0180
CVE-2026-5823110.0.0171
CVE-2026-1681210.0.0157KEV
CVE-2026-7329910.0.0121
Most disclosures (vendor)
VendorCVEs
linux1211
oracle1108
microsoft483
google451
ibm295
red hat256
apache202
apple169
adobe75
elastic67
Most KEV additions (YTD)
VendorKEV
microsoft25
cisco13
apple7
fortinet6
google6
ivanti5
solarwinds4
adobe3
berriai3
oracle3
Most-affected ecosystems
EcosystemAdvisories
Maven67
PyPI5
Go3
npm3
Packagist2
crates.io2
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2021-27137DD-WRT0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20316Cisco0
CVE-2026-20349Cisco0
CVE-2026-25089Fortinet0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171731
CVE-2021-27102n/a2021-11-171731
CVE-2021-27101n/a2021-11-171731
CVE-2021-27103n/a2021-11-171731
CVE-2021-21017Adobe2021-11-171731
CVE-2021-28550Adobe2021-11-171731
CVE-2021-42013Apache Software Foundation2021-11-171731
CVE-2021-41773Apache Software Foundation2021-11-171731
CVE-2021-30858Apple2021-11-171731
CVE-2021-30860Apple2021-11-171731

Transactions

EXPLOIT PUBLISHED — Unknown ECS: 3 CVEs (CVE-2026-14229, CVE-2026-14230, CVE-2026-18807). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2010-0738. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2010-1428. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2010-2861. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2012-0507. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2016-3351. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2019-25765 (ASP-CMS Project ASP-CMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2021-30116. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2021-30119. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-13328 (Unknown Food Menu). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-13610 (Unknown KiviCare). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16007 (AppFlowy-IO AppFlowy-Cloud). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16541 (Unknown Simply Schedule Appointments). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16611 (Unknown Product Feed PRO for WooCommerce by AdTribes). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-18216 (Unknown Backup Migration). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19710 (SourceCodester Simple Student Information System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19750 (Tenda CH). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19752 (EnzoVezzaro mcp-dominican-layer). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19753 (Model Context Protocol mcp-rdf-explorer). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19895 (opensourcepos Open Source Point of Sale). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19897 (mangroup dtale). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19900 (LB-LINK X-PRO). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19903 (SourceCodester Online Clothing Store). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19917 (code-projects Online Food Order System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19920 (code-projects Online Shopping System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-34881 (OpenStack Glance). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-39883 (open-telemetry opentelemetry-go). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-4035 (mlflow/mlflow). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-43001 (OpenStack Keystone). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54297 (lostisland faraday). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-59109 (Zalktis Programmas (SIA "Zalktis Programmas") Zalktis). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-62241 (MohibShaikh clawvet). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-72741 (goodrain rainbond). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-72777 (DayuanJiang next-ai-draw-io). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-73037 (DayuanJiang next-ai-draw-io). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-73481 (phplist3). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-73482 (phplist3). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-73506 (JanDeDobbeleer oh-my-posh). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-73514 (PostGIS address_standardizer). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-73515 (PostGIS). Public exploit reference added.

RESCORED — CVE-2016-1019. CVSS 7.8 → 9.8 (NVD).

RESCORED — CVE-2021-30116. CVSS 10 → 9.8 (NVD).

RESCORED — CVE-2021-30120. CVSS 9.9 → 7.5 (NVD).

RESCORED — CVE-2026-13601 (Red Hat Enterprise Linux 8). CVSS 7.1 → 6.5 (NVD).

RESCORED — CVE-2026-19757 (Dromara lamp-cloud). CVSS 6.9 → 5.5 (NVD).

RESCORED — CVE-2026-19758 (dromara lamp-cloud). CVSS 6.9 → 5.5 (NVD).

RESCORED — CVE-2026-20156 (Cisco RoomOS Software). CVSS 8.1 → 9.8 (NVD).

RESCORED — CVE-2026-20157 (Cisco RoomOS Software). CVSS 7.5 → 9.8 (NVD).

RESCORED — CVE-2026-34993 (aio-libs aiohttp). CVSS 6.4 → 7.3 (NVD).

RESCORED — CVE-2026-4035 (mlflow/mlflow). CVSS 9.1 → 7.7 (NVD).

RESCORED — CVE-2026-43001 (OpenStack Keystone). CVSS 7.9 → 8 (NVD).

Yesterday's Results

How to read these box scores · glossary

201 CVEs published. 25 box scores, 176 table rows — nothing truncated.

Tenable, Inc. Security Center — Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0284   85.6     —
AFFECTED
  Product          Versions     Fixed
  Security Center  unspecified  —
TIMELINE
  Aug 12  Reserved by CNA
  Aug 14  Published (CNA: tenable)
CWE-78 · CNA: tenable · CVSS v4.0 · 1 reference · NVD status: Analyzed
Baicells EG3661M LuCI Web luci os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    7.3   .0279   85.3     —
AFFECTED
  Product  Versions                Fixed
  EG3661M  BaiCE_BQ6_2.0.5.3_NA –  —
TIMELINE
  Aug 13  Reserved by CNA
  Aug 14  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Tenable, Inc. Security Center — Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0278   85.3     —
AFFECTED
  Product          Versions     Fixed
  Security Center  unspecified  —
TIMELINE
  Aug 12  Reserved by CNA
  Aug 14  Published (CNA: tenable)
CWE-78 · CNA: tenable · CVSS v4.0 · 1 reference · NVD status: Analyzed
Tenable, Inc. Security Center — Remote Code Execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0266   84.5     —
AFFECTED
  Product          Versions     Fixed
  Security Center  unspecified  —
TIMELINE
  Aug 12  Reserved by CNA
  Aug 14  Published (CNA: tenable)
CWE-78 · CNA: tenable · CVSS v4.0 · 1 reference · NVD status: Analyzed
Haiwell IoT Cloud HMI Gateway OS Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0193   78.5     —
AFFECTED
  Product                        Versions     Fixed
  Haiwell IoT Cloud HMI Gateway  3.40.1.12 –  3.50.1.19
TIMELINE
  Aug 6   Reserved by CNA
  Aug 14  Published (CNA: icscert)
CWE-78 · CNA: icscert · CVSS v4.0 · 3 references · NVD status: Received
Cockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg Filename
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0148   71.9     —
AFFECTED
  Product      Versions     Fixed
  Cockpit CMS  unspecified  —
TIMELINE
  Aug 13  Reserved by CNA
  Aug 14  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Received
IBM Db2 Mirror for i is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  N  H    6.5   .0118   65.2     —
AFFECTED
  Product           Versions  Fixed
  Db2 Mirror for i  7.4 –     —
TIMELINE
  Jul 24  Reserved by CNA
  Aug 14  Published (CNA: ibm)
CWE-78 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed
MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0114   64.3     —
AFFECTED
  Product         Versions     Fixed
  Minds Platform  unspecified  —
TIMELINE
  Aug 13  Public exploit reference published
  Aug 13  Reserved by CNA
  Aug 14  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Received
Tenable, Inc. Security Center — Improper Input Validation
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0107   62.2     —
AFFECTED
  Product          Versions     Fixed
  Security Center  unspecified  —
TIMELINE
  Aug 12  Reserved by CNA
  Aug 14  Published (CNA: tenable)
CWE-78 · CNA: tenable · CVSS v4.0 · 1 reference · NVD status: Analyzed
ImpressCMS Authenticated RCE via PHP Custom Tag eval()
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0061   46.5     —
AFFECTED
  Product     Versions     Fixed
  ImpressCMS  unspecified  —
TIMELINE
  Aug 13  Reserved by CNA
  Aug 14  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
Apache Struts: Unbounded read of a JSON request body
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0060   46.1     —
AFFECTED
  Product        Versions  Fixed
  Apache Struts  2.1.8 –   —
TIMELINE
  Aug 13  Reserved by CNA
  Aug 14  Published (CNA: apache)
CWE-400 · CNA: apache · CVSS v3.1 · 1 reference · NVD status: Analyzed
TOTOLINK A800R firewall.so cstecgi.cgi setMacFilterRules stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0060   46.1     —
AFFECTED
  Product  Versions                  Fixed
  A800R    4.1.2cu.5137_B20200730 –  —
TIMELINE
  Aug 14  Reserved by CNA
  Aug 14  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Tenda W20E QoS Edit editQos lstAdd stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0060   46.1     —
AFFECTED
  Product  Versions                           Fixed
  W20E     15.11.0.6(1068_1546_841)_CN_TDC –  —
TIMELINE
  Aug 14  Reserved by CNA
  Aug 14  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
TOTOLINK A800R wps.so cstecgi.cgi setWiFiWpsConfig stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0060   46.1     —
AFFECTED
  Product  Versions                  Fixed
  A800R    4.1.2cu.5137_B20200730 –  —
TIMELINE
  Aug 14  Reserved by CNA
  Aug 14  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
IBM Db2 Mirror for i is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0057   44.6     —
AFFECTED
  Product           Versions  Fixed
  Db2 Mirror for i  7.4 –     —
TIMELINE
  Jul 24  Reserved by CNA
  Aug 14  Published (CNA: ibm)
CWE-22 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed
IBM Db2 Mirror for i is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0057   44.6     —
AFFECTED
  Product           Versions  Fixed
  Db2 Mirror for i  7.4 –     —
TIMELINE
  Aug 1   Reserved by CNA
  Aug 14  Published (CNA: ibm)
CWE-22 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Defender Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0056   43.9     —
AFFECTED
  Product                              Versions  Fixed
  Microsoft Malware Protection Engine  - –       —
TIMELINE
  Aug 3   Reserved by CNA
  Aug 14  Published (CNA: microsoft)
CWE-284 · CNA: microsoft · CVSS v3.1 · 2 references · NVD status: Modified
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  L    8.3   .0053   42.6     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 14  Published (CNA: microsoft)
CWE-122 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with D…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0052   41.9     —
AFFECTED
  Product                      Versions     Fixed
  Wyse Management Suite (WMS)  unspecified  —
TIMELINE
  Jul 24  Reserved by CNA
  Aug 14  Published (CNA: dell)
CWE-434 · CNA: dell · CVSS v3.1 · 1 reference · NVD status: Analyzed
IBM Db2 Mirror for i is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0051   41.4     —
AFFECTED
  Product           Versions  Fixed
  Db2 Mirror for i  7.4 –     —
TIMELINE
  Jul 24  Reserved by CNA
  Aug 14  Published (CNA: ibm)
CWE-73 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed
Netis NC63 V3.0.0.3327 Unauthenticated Firmware Update with Missing Cryptographic Firmware Authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   N   N   H   H   H    8.7   .0051   41.2     —
AFFECTED
  Product                            Versions     Fixed
  Netis NC63 Wireless AC1200 Router  unspecified  —
TIMELINE
  Aug 13  Reserved by CNA
  Aug 14  Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Received
doobidoo mcp-memory-service — mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0050   40.7     —
AFFECTED
  Product             Versions     Fixed
  mcp-memory-service  < 10.67.1 –  —
TIMELINE
  Jun 2   Reserved by CNA
  Aug 14  Published (CNA: GitHub_M)
CWE-306 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Received
getgrav grav — Grav CMS before 2.0.13 Remote Code Execution via ZIP Upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0050   40.6     —
AFFECTED
  Product  Versions     Fixed
  grav     unspecified  2.0.13
TIMELINE
  Aug 10  Reserved by CNA
  Aug 14  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
Tenable, Inc. Security Center — Remote Code Execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0050   40.4     —
AFFECTED
  Product          Versions     Fixed
  Security Center  unspecified  —
TIMELINE
  Aug 12  Reserved by CNA
  Aug 14  Published (CNA: tenable)
CWE-95 · CNA: tenable · CVSS v4.0 · 1 reference · NVD status: Analyzed
TOTOLINK A800R product.so cstecgi.cgi UploadCustomModule stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0049   40.1     —
AFFECTED
  Product  Versions                  Fixed
  A800R    4.1.2cu.5137_B20200730 –  —
TIMELINE
  Aug 14  Reserved by CNA
  Aug 14  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-198157.440.1TOTOLINKA800RCWE-119TOTOLINK A800R firewall.so cstecgi.cgi setParentalRules stack-based overflow
CVE-2026-198447.440.1TOTOLINKA800RCWE-119TOTOLINK A800R ipv6.so cstecgi.cgi setRadvdCfg stack-based overflow
CVE-2026-738499.839.5emlogemlogCWE-306emlog allows unauthenticated reinstallation via `install.php?action=reinstall`.
CVE-2026-198275.539.2alldatacenteralldataCWE-22alldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputSt…
CVE-2026-198305.538.9TRENDnetTEW-816DRMCWE-400TRENDnet TEW-816DRM bftpd bftpd.conf allocation of resources
CVE-2026-728278.738.8getgravgravCWE-1336Grav CMS before 2.0.13 Remote Code Execution via Twig
CVE-2026-728249.338.4getgravgravCWE-862Grav before 1.0.13 API Key Scope Bypass via PagesController
CVE-2026-197887.438.3TendaAC1206CWE-119Tenda AC1206 httpd web management interface SetOnlineDevName set_device_name …
CVE-2026-197897.438.3TendaAC1206CWE-119Tenda AC1206 httpd web management interface WifiGuestSet set_wl_guest_iplist …
CVE-2026-197907.438.3TendaG0CWE-119Tenda G0 httpd Web Management module formSetPortMirror stack-based overflow
CVE-2026-197917.438.3TendaG0CWE-119Tenda G0 httpd web management interface module addStaticRoute stack-based ove…
CVE-2026-197927.438.3TendaG0CWE-119Tenda G0 httpd web management interface module setPortMapping buffer overflow
CVE-2026-198117.438.3TOTOLINKA800RCWE-119TOTOLINK A800R firewall.so cstecgi.cgi setIpQosRules stack-based overflow
CVE-2026-198147.438.3TOTOLINKA800RCWE-119TOTOLINK A800R firewall.so cstecgi.cgi setMacQos stack-based overflow
CVE-2026-198217.438.3TendaAC12CWE-119Tenda AC12 httpd web management interface SetSysAutoRebbotCfg formSetRebootTi…
CVE-2026-198237.438.3TendaW20ECWE-119Tenda W20E QoS Rule Deletion delQos formQOSRuleDel stack-based overflow
CVE-2026-198247.438.3TendaW20ECWE-119Tenda W20E addIpMacBind ipMacBindListStore stack-based overflow
CVE-2026-198457.438.3TOTOLINKA800RCWE-119TOTOLINK A800R lan.so cstecgi.cgi setStaticDhcpConfig stack-based overflow
CVE-2026-198467.438.3TOTOLINKA800RCWE-119TOTOLINK A800R firewall.so cstecgi.cgi setUrlFilterRules stack-based overflow
CVE-2026-736839.236.6LaravelSocialiteCWE-294Laravel Socialite Facebook Provider Authentication Bypass via Nonce Replay
CVE-2026-728309.336.5getgravgravCWE-269Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass
CVE-2026-171829.836.4IBMDb2 Mirror for iCWE-287IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-171736.536.2IBMDb2 Mirror for iCWE-22IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-197625.535.1DTStackTaierCWE-22DTStack Taier Chunk-Check Endpoint FileChunkController.java Paths.ge path tra…
CVE-2026-662707.235.1DellWyse Management Suite (WMS)CWE-434Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unre…
CVE-2026-466037.534.5golang.org/x/imagegolang.org/x/image/vp8lCWE-789Excessive memory allocation during VP8L decoding in golang.org/x/image
CVE-2026-485289.833.2NCEASmetacatCWE-89Metacat has an unauthenticated SQL injection vulnerability
CVE-2026-728156.932.5go-chichiCWE-290go-chi chi v5.2.1 IP Spoofing via X-Forwarded-For Header
CVE-2026-728136.932.3actixactix-webCWE-248actix-files before 0.6.10 Denial of Service via empty Range header
CVE-2026-171818.631.7IBMDb2 Mirror for iCWE-22IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-198719.331.4RoskusProspero Flow CRMCWE-798Use of hard-coded credentials in Prospero Flow CRM employee onboarding
CVE-2026-728146.330.9actixactix-webCWE-22actix-web before 0.6.10 Information Disclosure via Files
CVE-2026-197635.130.9DTStackTaierCWE-22DTStack Taier Cluster Creation ClusterController.java FileUtils.deleteDirecto…
CVE-2026-198372.030.0WebkulBagistoCWE-200Webkul Bagisto Customer Search search information disclosure
CVE-2026-198292.129.2648540858wvp-GB28181-proCWE-22648540858 wvp-GB28181-pro Log File Download Endpoint LogController.java path …
CVE-2026-170817.528.8IBMDb2 Mirror for iCWE-22IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-728229.327.1getgravgravCWE-306Grav before 1.0.13 Authentication Bypass via disable2fa
CVE-2026-691018.326.5datavanetisCWE-611Datavane TIS v5.0.0 XXE Injection via doEditWorkflow Endpoint
CVE-2026-129499.826.4Wishlist MemberWishlist MemberCWE-640Wishlist Member X <= 3.34.1 - Unauthenticated Account Takeover via 'mergewith…
CVE-2026-728206.926.4getgravgravCWE-22Grav 2.0.11 Path Traversal via Backup Profile Configuration
CVE-2026-728357.626.2filebrowserfilebrowserCWE-41filebrowser before v2.63.21 Access Rule Bypass via Path Canonicalization
CVE-2026-181788.126.2IBMDb2 Mirror for iCWE-22IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-456997.525.9NetatalknetatalkCWE-191Netatalk has Integer Underflow → Stack Buffer Overflow in copydir()
CVE-2026-730516.325.9actixactix-webCWE-444actix-http before 3.12.1 HTTP Request Smuggling via CL.TE
CVE-2026-199097.525.8PAX TechnologyQ80CWE-59PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vuln…
CVE-2025-76396.125.7AVEVAAVEVA Enterprise SCADACWE-502AVEVA Enterprise SCADA Deserialization of Untrusted Data
CVE-2026-198806.325.5QOS.CH SarlLogback-classicCWE-22Incomplete protection against CVE-2025-11226
CVE-2026-198265.525.2alldatacenteralldataCWE-20alldatacenter alldata xxl-rpc Listener HessianSerializer.java Hessian2Input.r…
CVE-2026-152058.624.7UnknownPaymob for WooCommerceCWE-89Paymob for WooCommerce < 4.1.9 - Unauthenticated SQL Injection via Paymob Cal…
CVE-2026-171869.824.5IBMDb2 Mirror for iCWE-78IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-728369.224.3filebrowserfilebrowserCWE-178FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass
CVE-2026-728109.223.4siyuan-notesiyuanCWE-862SiYuan before v3.7.4 Publish-Boundary Bypass via WebSocket
CVE-2026-171777.523.5IBMDb2 Mirror for iCWE-674IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-198342.022.9WebkulBagistoCWE-285Webkul Bagisto Admin Customer Impersonation Feature login-as-customer authori…
CVE-2025-714055.122.8go-chichiCWE-601go-chi chi before v5.2.2 Open Redirect via RedirectSlashes
CVE-2026-633618.522.5LimeSurveyLimeSurveyCWE-79LimeSurvey Community Edition 7.0.5+260623 - Reflected XSS in HTML editor popup
CVE-2026-742457.522.6Red HatRed Hat OpenShift Update ServiceCWE-306Quay: unauthenticated exported logs download in quay
CVE-2026-171756.522.6IBMDb2 Mirror for iCWE-287IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-728269.322.2getgravgravCWE-266Grav before 1.0.13 Scope Bypass via createApiKey
CVE-2026-728299.322.2getgravgravCWE-269Grav before 1.0.13 API Key Scope Bypass via UsersController
CVE-2026-728318.722.2getgravgravCWE-863Grav through 2.0.11 Authentication Bypass via Flex Objects
CVE-2026-728378.722.0filebrowserfilebrowserCWE-284File Browser before 2.63.20 Privilege Escalation via Proxy Authentication
CVE-2026-498260.021.9concourseconcourseCWE-601Concourse login flow has an open redirect issue
CVE-2026-728387.121.5filebrowserfilebrowserCWE-770FileBrowser before 2.63.19 Disk Exhaustion via TUS Upload
CVE-2026-198362.121.3WebkulBagistoCWE-285Webkul Bagisto Backend Customer Detail Feature view authorization
CVE-2026-198382.121.3WebkulBagistoCWE-285Webkul Bagisto Backend Reporting Endpoint sales authorization
CVE-2026-198282.120.8648540858wvp-GB28181-proCWE-22648540858 wvp-GB28181-pro Snapshot Endpoint PlayController.java path traversal
CVE-2026-16215.320.6Universal Software Inc.E-MunicipalityCWE-305Register Bypass in Universal Sotware's E-Municipality
CVE-2026-168798.820.4IBMDb2 Mirror for iCWE-285IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-198708.620.1RoskusProspero Flow CRMCWE-639IDOR in Prospero Flow CRM allows cross-tenant payroll disclosure and creation
CVE-2026-142906.820.1UnknownEmbed Google Photos albumCWE-79Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link …
CVE-2026-184036.019.9LimeSurveyLimeSurveyCWE-89LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB
CVE-2026-180398.119.8UnknownEssential Addons for ElementorCWE-269Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation…
CVE-2026-197688.119.7DevolutionsPowerShell UniversalCWE-94Improper control of generation of code ('Code Injection') in the settings fea…
CVE-2026-728126.919.3siyuan-notesiyuanCWE-862SiYuan before v3.7.4 Missing Authorization via refreshBacklink
CVE-2026-728288.619.0getgravgravCWE-269Grav before 1.0.13 API Key Scope Bypass via InvitationsController
CVE-2026-738508.618.5emlogemlogCWE-89Emlog: Arbitrary SQL Execution Vulnerability in ai.php within queryDatabase()…
CVE-2026-499897.118.5cratecrateCWE-863CrateDB's Blob HTTP handler bypasses authorization
CVE-2026-197842.118.4francoisjacquetRosarioSISCWE-285francoisjacquet RosarioSIS Referrals.php DBUpdate authorization
CVE-2026-344927.018.4Johnson ControlsAirwallCWE-73Airwall - Arbitrary file read
CVE-2026-169056.518.0IBMDb2 Mirror for iCWE-287IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-127434.918.3cservitaffiliate-toolkit – Multi-Network Affiliate & Amazon Product DisplayCWE-89affiliate-toolkit <= 3.8.8 - Authenticated (Administrator+) SQL Injection via…
CVE-2026-742438.217.9Red HatRed Hat OpenShift Update ServiceCWE-306Quay: unauthenticated secscan notification endpoint in quay when psk is unset
CVE-2026-181097.217.9boldgridW3 Total CacheCWE-79W3 Total Cache <= 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Co…
CVE-2026-582246.517.7Red HatRed Hat Enterprise Linux 10CWE-353Samba: ctdb fails to do integrity checking of received packets
CVE-2026-198255.517.7SourceCodesterSimple Client Management SystemCWE-74SourceCodester Simple Client Management System Master.php save_service sql in…
CVE-2026-198352.017.6WebkulBagistoCWE-266Webkul Bagisto Customer Item Deletion Endpoint access control
CVE-2026-728338.717.4getgravgravCWE-269Grav 1.0.6 through 1.0.11 Privilege Escalation via Scoped API Keys
CVE-2026-168106.517.2bitpressadminBit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form BuilderCWE-89Bit Form <= 3.2.0 - Authenticated (Administrator+) SQL Injection via 'filterT…
CVE-2026-742424.417.2Red HatRed Hat OpenShift Update ServiceCWE-639Quay: repository notification uuid idor in quay api
CVE-2026-742506.316.6OpenStackIronicCWE-226In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail t…
CVE-2026-197645.516.6RaisecomCommunication Command and Dispatch Management PlatformCWE-74Raisecom Communication Command and Dispatch Management Platform getpwd.php sq…
CVE-2026-662725.316.6DellWyse Management Suite (WMS)CWE-200Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missi…
CVE-2026-728119.916.1siyuan-notesiyuanCWE-89SiYuan before v3.7.4 SQL Injection via backlink search
CVE-2026-197672.116.1itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System viewdoctortimings.php sql injection
CVE-2026-534726.315.9—migration-plannerCWE-79Migration-planner: credentialurl validator accepts javascript: urls
CVE-2026-715705.115.2icagenda.comiCagenda extension for JoomlaCWE-284Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumerat…
CVE-2026-167088.314.5IBMDb2 Mirror for iCWE-15IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-198795.314.2Red HatRed Hat build of Apache Camel for Spring Boot 4CWE-681Io.undertow/undertow: undertow: http response header integrity issue due to c…
CVE-2026-636494.114.3OpenVPNOpenVPNCWE-183The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha…
CVE-2026-196807.113.8Tenable, Inc.Security CenterCWE-89SQL Injection
CVE-2026-500295.313.9sunnyadnjs-tomlCWE-697js-toml has silent type confusion via falsy-primitive duplicate-key bypass
CVE-2026-196316.913.7Tenable, Inc.Security CenterCWE-89SQL Injection
CVE-2026-673659.213.3icagenda.comiCagenda extension for JoomlaCWE-89Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda <…
CVE-2026-196298.613.3Tenable, Inc.Security CenterCWE-863Privilege Escalation
CVE-2026-728345.313.4filebrowserfilebrowserCWE-200filebrowser before 2.63.19 Permission Bypass via checksum
CVE-2026-636502.013.4OpenVPNOpenVPNCWE-295OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated us…
CVE-2026-198392.013.2SourceCodesterSimple Doctors Appointment SystemCWE-284SourceCodester Simple Doctors Appointment System save_file.php save_doctor un…
CVE-2026-199087.112.9PAX TechnologyQ80CWE-306PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability
CVE-2026-738455.312.8ondatackan-mcp-serverCWE-20CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMq…
CVE-2026-574695.112.8KUNBUSPiCtoryCWE-352Cross-Site Request Forgery (CSRF) in KUNBUS PiCtory
CVE-2026-738443.712.7ondatackan-mcp-serverCWE-209CKAN MCP Server: Information disclosure via verbose error reflection
CVE-2026-167395.912.4UnknownEpeken All Kurir for WoocommerceCWE-287Epeken All Kurir <= 2.1.2 - Unauthenticated Order Payment Confirmation Forgery
CVE-2026-196395.312.2Tenable, Inc.Security CenterCWE-1284Improper Access Control
CVE-2026-728166.912.2go-chichiCWE-290go-chi chi before 5.3.0 IP Spoofing via RealIP Middleware
CVE-2026-715718.612.1icagenda.comiCagenda extension for JoomlaCWE-89Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped n…
CVE-2026-505237.811.8MicrosoftPowerShell 7.4CWE-77Microsoft PowerShell Remote Code Execution Vulnerability
CVE-2026-197872.011.0SourceCodesterAir Cargo Management SystemCWE-74SourceCodester Air Cargo Management System Master.php save_cargo_type sql inj…
CVE-2026-197652.111.0eyaushevswagger-testcase-mcpCWE-918eyaushev swagger-testcase-mcp fetch_swagger swagger-parser.ts loadSource serv…
CVE-2026-742484.310.8OpenStackOctaviaCWE-863OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy a…
CVE-2026-736306.910.4siyuan-notesiyuanCWE-203SiYuan before v3.7.4 Information Disclosure via authFilePublishAccess
CVE-2026-172095.410.4IBMDb2 Mirror for iCWE-79IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-197855.310.4francoisjacquetRosarioSISCWE-74francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injection
CVE-2026-172276.510.0IBMDb2 Mirror for iCWE-89IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-167728.19.9AkauntingAkauntingCWE-269CVE-2026-16772
CVE-2026-728257.29.7getgravgravCWE-862Grav before 1.0.13 API-key scope cap bypass via ReportsController
CVE-2026-738476.89.4emlogemlogCWE-352Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full dat…
CVE-2026-730486.99.1siyuan-notesiyuanCWE-862SiYuan before v3.7.4 Information Disclosure via getRefIDsByFileAnnotationID
CVE-2026-730496.99.1siyuan-notesiyuanCWE-863SiYuan before v3.7.4 Information Disclosure via getAttributeViewBacklinks
CVE-2026-728235.38.9getgravgravCWE-862Grav before 1.0.13 API-key scope cap bypass via DemoController
CVE-2026-170794.38.9IBMDb2 Mirror for iCWE-693IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-197947.28.7gamerzWP-StatsCWE-79WP-Stats <= 2.56 - Unauthenticated Stored Cross-Site Scripting
CVE-2026-199107.58.2PAX TechnologyQ80CWE-347PAX Technology Q80 Application Installer Signature Verification Bypass Remote…
CVE-2026-198412.38.1TRENDNETTEW-813DRUCWE-266TRENDNET TEW-813DRU vsftpd vsftpd.conf default permission
CVE-2026-742416.57.9Red HatRed Hat OpenShift Update ServiceCWE-90Quay: ldap referral filter injection in quay external ldap authentication
CVE-2026-728598.37.7budibaseserverCWE-863Budibase 3.39.4 before 3.40.0 Authorization Regression via S3 Presigned URL
CVE-2026-728325.17.6getgravgravCWE-79Grav before 2.0.12 Stored XSS via quoted-attribute bypass
CVE-2026-278712.97.3Johnson ControlsTL280CWE-327TL280
CVE-2026-464397.86.9oscal-compasscompliance-trestleCWE-94compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-S…
CVE-2026-742405.46.7Red HatRed Hat OpenShift Update ServiceCWE-287Quay: jwt claim validation bypasses in quay federated robot and sso authentic…
CVE-2026-539707.56.5lucasgelfondZeroBrewCWE-494ZeroBrew version 0.3.1 and prior Missing Checksum Verification RCE via shim.rb
CVE-2026-123634.26.2zephyrprojectzephyrCWE-787Out-of-bounds write in LoRaWAN fragmented transport from a fragment index of 0
CVE-2026-197865.36.0francoisjacquetRosarioSISCWE-352francoisjacquet RosarioSIS Modules.php cross-site request forgery
CVE-2026-471922.15.8siemenskasCWE-347kas's late signature validation may allow unnoticed repository manipulations
CVE-2026-477665.15.5containerscrunCWE-61crun follows rootfs /dev symlink while creating default devices
CVE-2026-471912.15.2siemenskasCWE-347kas checks out SHA-like git branches as valid commits
CVE-2026-196366.05.0Tenable, Inc.Security CenterCWE-1270Insuffucient Protections Lead to Brute Force
CVE-2026-673665.34.5icagenda.comiCagenda extension for JoomlaCWE-352Joomla Extension - icagenda.com - CSRF on frontend registration actions in iC…
CVE-2025-103084.34.5alianAstro Booking EngineCWE-352Astro Booking Engine <= 1.4.0 - Cross-Site Request Forgery to Settings Reset
CVE-2026-728176.94.4go-chichiCWE-345go-chi chi 0.9.0 before 5.3.0 IP Spoofing via X-Forwarded-For
CVE-2026-494579.14.3benoitcerlang_quicCWE-295QUIC has Broken TLS verification
CVE-2026-742477.14.0Red HatRed Hat OpenShift Update ServiceCWE-918Quay: ssrf via build archive_url in quay build api
CVE-2026-742447.53.7Red HatRed Hat OpenShift Update ServiceCWE-347Quay: stripe webhook accepts forged events without signature verification in …
CVE-2026-728215.13.4getgravgravCWE-79Grav Form Plugin before 9.1.15 Stored XSS via Radio Toggle
CVE-2026-738466.53.3ondatackan-mcp-serverCWE-345CKAN MCP Server: Cache-key canonicalization collision enables cache confusion…
CVE-2026-196358.53.0Tenable, Inc.Security CenterCWE-78Local Privilege Escalation
CVE-2026-492825.12.9capstone-enginecapstoneCWE-125Capstone M68K and RISCV `cs_insn_name()` invalid IDs can trigger out-of-bound…
CVE-2026-198848.42.9Eclipse FoundationEclipse TheiaCWE-15In Eclipse Theia versions up to and including 1.69.0, opening a folder starts…
CVE-2026-492632.02.7capstone-enginecapstoneCWE-197Capstone WASM `br_table` instruction-size truncation can cause no-progress di…
CVE-2026-574726.92.3KUNBUSRevPiPyLoadCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'…
CVE-2026-574716.82.3KUNBUSRevPiPyLoadCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'…
CVE-2026-123668.82.0zephyrprojectzephyrCWE-416Use-after-free freeing an armed dynamically-allocated k_timer in Zephyr users…
CVE-2026-123648.42.0zephyrprojectzephyrCWE-822Missing user-space pointer validation in logging syscall z_log_msg_static_cre…
CVE-2026-499867.11.6cdeustCortexCWE-829Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR`
CVE-2026-648877.01.6Johnson ControlsAirwallCWE-321Airwall - Hardcoded Secrets
CVE-2026-196175.51.4Red HatRed Hat Enterprise Linux 10CWE-770Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config pa…
CVE-2026-197701.91.4feedmobfm-mcp-serversCWE-918feedmob fm-mcp-servers Download Endpoint index.ts downloadReport server-side …
CVE-2026-130024.41.3Red HatRed Hat Enterprise Linux 10CWE-835Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing
CVE-2026-463806.71.0oscal-compasscompliance-trestleCWE-918compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem
CVE-2026-123655.80.9zephyrprojectzephyrCWE-416Use-after-free in Zephyr delayable work-queue cancellation under SMP timing race
CVE-2026-131967.30.9KUNBUSpiControlCWE-787Out-of-bounds Write in KUNBUS piControl
CVE-2026-131977.30.8KUNBUSpiControlCWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Ra…
CVE-2026-131985.90.8KUNBUSpiControlCWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Ra…
CVE-2026-637007.80.4DellWyse Management Suite (WMS)CWE-269Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Inco…
CVE-2026-637017.80.2DellWyse Management Suite (WMS)CWE-269Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Impr…
CVE-2026-637025.50.2DellWyse Management Suite (WMS)CWE-798Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use o…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-14 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.