boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, August 18, 2026 · all times UTC← 2026-08-17 · archive

CISA adds 4 to KEV; 1407 CVEs published, led by Oracle Corporation (889).

1407 CVEs published August 18, 2026: 211 critical, 731 high, 373 medium, 60 low; 0 in the KEV catalog at press time; 1 with a public exploit reference; 32 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 1007 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published76702981714462564
KEV catalog size1671

1637 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux12633580363178163512730.17.8.0016+1222 ▲
microsoft4441875130127444814380351.97.8.0039-202 ▼
google641824224754786577460.37.5.0024-30 ▼
red hat1615173521024626400.06.6.0024+96 ▲
apple34300577715459482.76.5.0022+34 ▲
canonical1138129125000.07.8.0017+7 ▲
suse52651461000.08.1.0030-3 ▼
freebsd01601240000.07.8.00150
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco31711135170961419.77.5.0034+15 ▲
palo alto networks12370221121425.44.6.0018-2 ▼
ubiquiti036142110438.38.8.0036-25 ▼
netgear93200275800.04.3.0023+3 ▲
fortinet7304814128620.06.6.0048-7 ▼
f50175830715.98.6.0057-8 ▼
vmware01648222216.38.2.0039-8 ▼
ivanti314262033535.77.9.0754+1 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache10243687189147124020.57.5.0048+24 ▲
mozilla5918658624601300.08.1.0026+53 ▲
gitlab1568114438422.95.1.0025+8 ▲
drupal05165355512.05.9.0018-46 ▼
github5171790000.06.6.00370
docker290630100.07.2.0016+2 ▲
wordpress2513105240.08.8.0089+2 ▲
kubernetes010001000.02.4.00240
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle88922684861172513964030.17.8.0032+888 ▲
ibm192421971821366710.27.5.0029+156 ▲
adobe603143914412357541.37.8.0021-34 ▼
progress19611437100911.68.1.0032+9 ▲
solarwinds0231623011417.49.1.00440
veeam10165920400.08.6.0028+10 ▲
zohocorp4103520000.08.7.0129+4 ▲
atlassian3615001300.08.1.0034+3 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link1637155972612.77.4.0104+15 ▲
siemens193522382100.07.3.0013+12 ▲
synology12426133000.05.6.0025+1 ▲
rockwell automation02441820000.08.7.0025-17 ▼
schneider electric091620100.08.6.00240
abb070430000.07.2.0018-1 ▼
hikvision0704202114.37.2.00250
moxa050320000.07.0.00290
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester27147008067000.05.5.0026-14 ▼
dell33132968495210.87.2.0019-4 ▼
openclaw01110583914000.07.0.0022-44 ▼
nvidia241061471210000.07.5.0026-16 ▼
gitea48891936304000.07.5.0030+8 ▲
siyuan-note66883919281000.08.7.0026+60 ▲
itsourcecode1788001969000.02.1.0020+3 ▲
zephyrproject3487230469000.06.5.0017+19 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.993199.99.8
CVE-2026-63030.956099.99.8
CVE-2026-34486.829399.67.5
CVE-2026-16232.733099.49.3
CVE-2026-60137.731099.45.9
CVE-2026-0770.568899.09.8
CVE-2026-62144.206297.39.1
CVE-2021-27137.164996.78.1
CVE-2026-15733.135496.19.8
CVE-2026-63077.107295.59.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.1040KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0473
CVE-2026-4766810.0.0434
CVE-2026-4836210.0.0207
CVE-2026-1918810.0.0189
CVE-2026-7329910.0.0121
CVE-2026-4561810.0.0095
CVE-2025-7138910.0.0093
CVE-2026-4816810.0.0091
Most disclosures (vendor)
VendorCVEs
oracle1997
linux1628
google466
microsoft463
ibm261
red hat260
apache205
apple201
mozilla124
adobe74
Most KEV additions (YTD)
VendorKEV
microsoft35
cisco14
apple8
fortinet6
google6
ivanti5
adobe4
solarwinds4
synacor4
langflow3
Most-affected ecosystems
EcosystemAdvisories
Maven66
PyPI5
npm5
Go3
Packagist2
crates.io2
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2021-27137DD-WRT0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20316Cisco0
CVE-2026-20349Cisco0
CVE-2026-34486Apache Software Foundation0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171735
CVE-2021-27102Accellion2021-11-171735
CVE-2021-27101Accellion2021-11-171735
CVE-2021-27103Accellion2021-11-171735
CVE-2021-21017Adobe2021-11-171735
CVE-2021-28550Adobe2021-11-171735
CVE-2021-42013Apache2021-11-171735
CVE-2021-41773Apache2021-11-171735
CVE-2021-30858Apple2021-11-171735
CVE-2021-30860Apple2021-11-171735

Transactions

ADDED TO KEVCVE-2026-33824 (Microsoft Windows 10 Version 1607). Remediation due August 21, 2026.

ADDED TO KEVCVE-2026-55040 (Microsoft SharePoint Enterprise Server 2016). Remediation due August 21, 2026.

ADDED TO KEVCVE-2026-59310 (VMware Cloud Foundation). Remediation due August 21, 2026.

ADDED TO KEVCVE-2026-65400 (Apple macOS). Remediation due August 21, 2026.

EXPLOIT PUBLISHED — itsourcecode Hospital Management System: 6 CVEs (CVE-2026-19894, CVE-2026-19934, CVE-2026-19972, CVE-2026-75086, CVE-2026-75087, CVE-2026-75088). Public exploit references added.

EXPLOIT PUBLISHED — Webkul Bagisto: 6 CVEs (CVE-2026-19834, CVE-2026-19836, CVE-2026-19993, CVE-2026-19996, CVE-2026-75081, CVE-2026-75082). Public exploit references added.

EXPLOIT PUBLISHED — code-projects Online Shopping System: 4 CVEs (CVE-2026-19919, CVE-2026-19921, CVE-2026-19923, CVE-2026-19998). Public exploit references added.

EXPLOIT PUBLISHED — OpenBoxes: 4 CVEs (CVE-2024-14045, CVE-2024-14046, CVE-2026-19928, CVE-2026-19929). Public exploit references added.

EXPLOIT PUBLISHED — SourceCodester Class and Exam Timetabling System: 4 CVEs (CVE-2026-19899, CVE-2026-75077, CVE-2026-75079, CVE-2026-75080). Public exploit references added.

EXPLOIT PUBLISHED — TOTOLINK A800R: 4 CVEs (CVE-2026-19811, CVE-2026-19813, CVE-2026-19844, CVE-2026-19847). Public exploit references added.

EXPLOIT PUBLISHED — Edimax EW-7478APC: 3 CVEs (CVE-2026-19959, CVE-2026-19960, CVE-2026-19962). Public exploit references added.

EXPLOIT PUBLISHED — parallax jsPDF: 3 CVEs (CVE-2026-24737, CVE-2026-25535, CVE-2026-25755). Public exploit references added.

EXPLOIT PUBLISHEDCVE-2024-21626 (opencontainers runc). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-25256 (Fortinet FortiSIEM). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-62593 (ray-project ray). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-17106 (moby go-archive). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19751 (EnzoVezzaro mcp-dominican-layer). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19756 (Dromara lamp-cloud). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19758 (dromara lamp-cloud). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19765 (eyaushev swagger-testcase-mcp). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19771 (Baicells EG3661M). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19788 (Tenda AC1206). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19790 (Tenda G0). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19821 (Tenda AC12). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19823 (Tenda W20E). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19826 (alldatacenter alldata). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19828 (648540858 wvp-GB28181-pro). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19839 (SourceCodester Simple Doctors Appointment System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19896 (mangroup dtale). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19898 (VictoriaMetrics). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19901 (LB-LINK X-PRO). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19904 (SourceCodester Online Book Store System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19905 (Jinher OA). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19916 (code-projects Online Food Order System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19918 (SpaceX Starlink Router Gen 3). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19924 (Tenda AC10). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19926 (Evergreen). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19932 (DefaultFuction Notice-System-Managent). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19955 (TrailDB). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19957 (graphlit-mcp-server). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19964 (Jij-Inc Jij-MCP-Server). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19967 (Open Asset Import Library Assimp). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19969 (Open Asset Import Library Assimp). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19974 (treefrogframework treefrog-framework). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19977 (EFM ipTIME A3004T). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19984 (jkawamoto mcp-florence2). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19988 (Alaev SEO Tools Extension). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-25896 (NaturalIntelligence fast-xml-parser). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-26278 (NaturalIntelligence fast-xml-parser). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-53365 (Linux). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-58049 (FFmpeg). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-60113 (NASA-AMMOS AIT-DSN). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-64600 (Linux). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-67579 (ash-project ash). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-69414 (Microsoft Malware Protection Engine). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-70667 (Netflix lemur). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-7246 (Pallets Click Click). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-72741 (goodrain rainbond). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-73482 (phplist3). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-74842 (Kira-Pgr PromptShopMCP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-74899 (jahlives openssl_encrypt). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75012 (TOTOLINK EX1200L). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75013 (TOTOLINK EX1200L). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75089 (PHPGurukul Complaint Management System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75090 (EricLBuehler Mistral.rs). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75093 (sonos tract). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75094 (COMFAST CF-N1-S). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75130 (Uptash Context7). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75773 (karakeep-app karakeep). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75774 (karakeep-app karakeep). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75778 (code-projects Task Management System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75783 (TRENDnet TEW-WLC100P). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75784 (TRENDnet TEW-WLC100). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75876 (xianrendzw EasyReport). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-75877 (TRENDnet TV-IP751WIC). Public exploit reference added.

REJECTEDCVE-2026-64158 (Linux). Record withdrawn by the CNA.

REJECTEDCVE-2026-73682 (semaphoreui semaphore). Record withdrawn by the CNA.

REJECTEDCVE-2026-74511 (Linux). Record withdrawn by the CNA.

RESCORED — parallax jsPDF: 3 CVEs (CVE-2026-25755, CVE-2026-31898, CVE-2026-31938). CVSS rescored — before/after on each CVE page.

RESCOREDCVE-2024-44004 (Arni Cinco WPCargo Track & Trace). CVSS 9.3 → 9.8 (NVD).

RESCOREDCVE-2026-40478 (thymeleaf). CVSS 9.1 → 9 (NVD).

RESCOREDCVE-2026-41245 (junrar). CVSS 5.9 → 7.5 (NVD).

RESCOREDCVE-2026-75079 (SourceCodester Class and Exam Timetabling System). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-75080 (SourceCodester Class and Exam Timetabling System). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-75081 (Webkul Bagisto). CVSS 5.3 → 2.1 (NVD).

PATCH SHIPPED — rrrene html_sanitize_ex: 6 CVEs (CVE-2026-66370, CVE-2026-66829, CVE-2026-66843, CVE-2026-68747, CVE-2026-68749, CVE-2026-68750). Fix versions published.

PATCH SHIPPED — Red Hat OpenShift Container Platform 4.20: 3 CVEs (CVE-2026-42965, CVE-2026-50236, CVE-2026-50237). Fix versions published.

PATCH SHIPPEDCVE-2026-18739 (rpm-software-management popt). Fixed in Red Hat Hardened Images 1.19-11.1.hum1.

PATCH SHIPPEDCVE-2026-64611 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 1:2.0.0-13.el10_2.

PATCH SHIPPEDCVE-2026-64612 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 1:2.0.0-13.el10_2.

Yesterday's Results

How to read these box scores · glossary

1407 CVEs published. 25 box scores and 375 table rows below; the remaining 1007 continue on page 2 · page 3 — every CVE is listed, nothing truncated.

COMFAST CF-N1-S CGI mbox-config sub_44B438 os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.5   .0209   80.1     —
AFFECTED
  Product  Versions   Fixed
  CF-N1-S  2.6.0.1 –  —
TIMELINE
  Aug 17  Reserved by CNA
  Aug 18  Public exploit reference published
  Aug 18  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Received
Microsoft Copilot Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0163   74.3     —
AFFECTED
  Product      Versions  Fixed
  Copilot Web  - –       —
TIMELINE
  Jan 21  Reserved by CNA
  Aug 18  Published (CNA: microsoft)
CWE-77 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Received
wpmudev Forminator Forms – Contact Form, Payment Form & Custom Form Builder — Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0118   65.1     —
AFFECTED
  Product                                                              Versions     Fixed
  Forminator Forms – Contact Form, Payment Form & Custom Form Builder  unspecified  —
TIMELINE
  Jul 14  Reserved by CNA
  Aug 18  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Received
valkey-io valkey — Valkey: UAF in stream deserialization may lead to remote code execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0117   64.9     —
AFFECTED
  Product  Versions    Fixed
  valkey   < 7.2.14 –  —
TIMELINE
  Jul 17  Reserved by CNA
  Aug 18  Published (CNA: GitHub_M)
CWE-416 · CNA: GitHub_M · CVSS v3.1 · 12 references · NVD status: Received
ArcadeData arcadedb — ArcadeDB Redis Wire-Protocol Plugin Missing Authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0107   62.2     —
AFFECTED
  Product   Versions     Fixed
  arcadedb  unspecified  26.8.1
TIMELINE
  Aug 18  Reserved by CNA
  Aug 18  Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
TRENDnet TEW-WLC100 HTTP Header nginx FUN_0040da4c stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0102   60.7     —
AFFECTED
  Product     Versions     Fixed
  TEW-WLC100  1v2.07b01 –  —
TIMELINE
  Aug 18  Public exploit reference published
  Aug 18  Reserved by CNA
  Aug 18  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
valkey-io valkey — Valkey: TLS pending-data processing use-after-free may allow remote code execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0089   56.5     —
AFFECTED
  Product  Versions    Fixed
  valkey   < 7.2.14 –  —
TIMELINE
  Jun 22  Reserved by CNA
  Aug 18  Published (CNA: GitHub_M)
CWE-416 · CNA: GitHub_M · CVSS v3.1 · 8 references · NVD status: Received
lxsmnsyc seroval — Seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0081   54.2     —
AFFECTED
  Product  Versions   Fixed
  seroval  < 1.5.3 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Aug 18  Published (CNA: GitHub_M)
CWE-502, CWE-843 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Received
AresIT WP Compress — WordPress WP Compress plugin < 7.20.01 - Remote Code Execution (RCE) vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0080   53.8     —
AFFECTED
  Product      Versions  Fixed
  WP Compress  n/a –     7.20.01
TIMELINE
  Aug 12  Reserved by CNA
  Aug 18  Published (CNA: Patchstack)
CWE-94 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Received
MyBB: Installer database configuration RCE
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0079   53.5     —
AFFECTED
  Product  Versions    Fixed
  mybb     < 1.8.40 –  —
TIMELINE
  May 8   Reserved by CNA
  Aug 18  Published (CNA: GitHub_M)
CWE-94 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Received
maalfer MailerUp — HTML Injection in MailerUp double opt-in verification email
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   L   N    6.9   .0071   50.7     —
AFFECTED
  Product   Versions     Fixed
  MailerUp  unspecified  —
TIMELINE
  Aug 18  Reserved by CNA
  Aug 18  Published (CNA: Secur0)
CWE-80 · CNA: Secur0 · CVSS v4.0 · 3 references · NVD status: Received
libexpat project libexpat — Expat Denial of Service via storeAtts() Quadratic Complexity
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0068   49.5     —
AFFECTED
  Product   Versions     Fixed
  libexpat  unspecified  —
TIMELINE
  Jul 23  Reserved by CNA
  Aug 18  Published (CNA: VulnCheck)
CWE-407 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in the NFS/RPC. A…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0065   48.5     —
AFFECTED
  Product           Versions     Fixed
  PowerStore 500T   unspecified  —
  PowerStore 1000T  unspecified  —
  PowerStore 1200T  unspecified  —
  PowerStore 3000T  unspecified  —
  PowerStore 3200Q  unspecified  —
  PowerStore 3200T  unspecified  —
  PowerStore 5000T  unspecified  —
  PowerStore 5200Q  unspecified  —
  PowerStore 5200T  unspecified  —
  PowerStore 7000T  unspecified  —
  + 2 more
TIMELINE
  Aug 4   Reserved by CNA
  Aug 18  Published (CNA: dell)
CWE-120 · CNA: dell · CVSS v3.1 · 1 reference · NVD status: Received
TRENDnet TEW-823DRU NVRAM wan.cgi strcpy stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0063   47.3     —
AFFECTED
  Product     Versions     Fixed
  TEW-823DRU  1.1.02b01 –  —
TIMELINE
  Aug 18  Reserved by CNA
  Aug 18  Published (CNA: VulDB)
CWE-121, CWE-119 · CNA: VulDB · CVSS v4.0 · 6 references
frangoteam FUXA — FUXA: Unauthenticated guest JWT bypasses Node-RED secure-mode authorization gate (Remote Script Execution)
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0062   47.2     —
AFFECTED
  Product  Versions   Fixed
  FUXA     < 1.3.3 –  —
TIMELINE
  Jul 29  Reserved by CNA
  Aug 18  Published (CNA: GitHub_M)
CWE-862 · CNA: GitHub_M · CVSS v4.0 · 4 references · NVD status: Received
ha-china blueprint-studio — Blueprint Studio terminal command working directory not bounded to config directory
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   L   L   L    5.1   .0062   47.1     —
AFFECTED
  Product           Versions   Fixed
  blueprint-studio  < 2.5.2 –  —
TIMELINE
  Jun 9   Reserved by CNA
  Aug 18  Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Received
TRENDnet TV-IP751WIC alphapd FUN_0043372C stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0061   46.7     —
AFFECTED
  Product      Versions    Fixed
  TV-IP751WIC  11.03.03 –  —
TIMELINE
  Aug 18  Public exploit reference published
  Aug 18  Reserved by CNA
  Aug 18  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Database Exfiltration
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0061   46.6     —
AFFECTED
  Product  Versions   Fixed
  froxlor  < 2.3.8 –  —
TIMELINE
  Jun 12  Reserved by CNA
  Aug 18  Published (CNA: GitHub_M)
CWE-89 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Received
getgrav grav — Grav before 2.0.15 Arbitrary File Write via error_log
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0059   45.6     —
AFFECTED
  Product  Versions     Fixed
  grav     unspecified  2.0.15
TIMELINE
  Aug 18  Reserved by CNA
  Aug 18  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  L    9.0   .0059   45.4     —
AFFECTED
  Product  Versions   Fixed
  froxlor  < 2.3.8 –  —
TIMELINE
  Jul 14  Reserved by CNA
  Aug 18  Published (CNA: GitHub_M)
CWE-200 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Received
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2 — Governance-policy-addon-controller: governance-policy-addon-controller: arbitrary container image override via managedclusteraddon annotation enables rce on spoke
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0057   44.9     —
AFFECTED
  Product                                               Versions     Fixed
  Red Hat Advanced Cluster Management for Kubernetes 2  unspecified  —
TIMELINE
  Jul 27  Reserved by CNA
  Aug 18  Published (CNA: redhat)
CWE-20 · CNA: redhat · CVSS v3.1 · 2 references · NVD status: Received
Mozilla Firefox — Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0056   44.0     —
AFFECTED
  Product      Versions     Fixed
  Firefox      unspecified  115.39
  Thunderbird  unspecified  140.14
TIMELINE
  Aug 17  Reserved by CNA
  Aug 18  Published (CNA: mozilla)
CWE-119 · CNA: mozilla · CVSS v3.1 · 9 references · NVD status: Analyzed
strukturag libheif — libheif: unbounded heap allocation in HEIF sequence parser (stsz fixed-size mode missing bound check)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0056   43.9     —
AFFECTED
  Product  Versions               Fixed
  libheif  >= 1.19.0, < 1.23.0 –  —
TIMELINE
  Jun 3   Reserved by CNA
  Aug 18  Published (CNA: GitHub_M)
CWE-190, CWE-770 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Received
strukturag libheif — libheif: Out-of-bounds read in uncompressed unci tile range slicing
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0054   43.0     —
AFFECTED
  Product  Versions               Fixed
  libheif  >= 1.19.0, < 1.23.1 –  —
TIMELINE
  Jul 13  Reserved by CNA
  Aug 18  Published (CNA: GitHub_M)
CWE-125 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Received
supsystic Easy Google Maps — WordPress Easy Google Maps plugin <= 1.13.0 - PHP Object Injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0053   42.3     —
AFFECTED
  Product           Versions  Fixed
  Easy Google Maps  n/a –     1.14.0
TIMELINE
  Aug 12  Reserved by CNA
  Aug 18  Published (CNA: Patchstack)
CWE-502 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-733809.842.3supsysticPopup by SupsysticCWE-502WordPress Popup by Supsystic plugin <= 1.13.0 - PHP Object Injection vulnerab…
CVE-2026-757732.942.3karakeep-appkarakeepCWE-307karakeep-app karakeep Login Endpoint auth.ts authorize excessive authentication
CVE-2026-606729.842.1Oracle CorporationOracle WebLogic ServerVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-606969.842.1Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-606989.842.1Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-608589.842.1Oracle CorporationOracle Hyperion Calculation ManagerVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-609779.842.1Oracle CorporationOracle WebLogic ServerVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-613189.842.1Oracle CorporationSiebel CRM Cloud ApplicationsVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-626269.842.1Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626329.842.1Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626339.842.1Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626359.842.1Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-709269.842.1Oracle CorporationOracle WorkflowVulnerability in the Oracle Workflow product of Oracle E-Business Suite (comp…
CVE-2026-189296.942.0CarboneCarboneCWE-409Resource Exhaustion in Carbone
CVE-2026-750902.141.7EricLBuehlerMistral.rsCWE-119EricLBuehler Mistral.rs GGUF Tokenizer gguf_tokenizer.rs convert_gguf_to_hf_t…
CVE-2026-733819.141.5supsysticPopup by SupsysticCWE-288WordPress Popup by Supsystic plugin <= 1.13.0 - Broken Authentication vulnera…
CVE-2026-170846.041.4Python Software FoundationCPythonCWE-436stringprep.map_table_b2() deviates from RFC 3454 Table B.2
CVE-2026-607289.141.3Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-735025.341.2getkinkin-openapiCWE-476kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating…
CVE-2026-758978.741.0OpenSearchOpenSearch DashboardsCWE-1284Uncontrolled Resource Consumption in Capabilities Route in OpenSearch Dashboards
CVE-2026-759158.741.0HmbownCodeWhaleCWE-200CodeWhale before 0.8.64 Environment Variable Leak via js_execution
CVE-2026-708207.240.7Oracle CorporationOracle Call Center TechnologyVulnerability in the Oracle Call Center Technology product of Oracle E-Busine…
CVE-2026-501878.840.4ohmyzshohmyzshCWE-94Oh My Zsh: Arbitrary Code Execution in oh-my-zsh dotenv plugin via malicious …
CVE-2026-674406.940.2frangoteamFUXACWE-862FUXA: Unauthenticated Socket.IO read events
CVE-2026-477205.340.2frangoteamFUXACWE-89FUXA: SQL injection in TDengine DAQ connector via backslash bypass of escapeT…
CVE-2026-610039.940.1Oracle CorporationOracle Managed File TransferVulnerability in the Oracle Managed File Transfer product of Oracle Fusion Mi…
CVE-2026-195007.540.0SureFormsSureFormsCWE-400SureForms contains an uncontrolled resource consumption vulnerability
CVE-2026-607219.839.9Oracle CorporationOracle Identity ManagerVulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-607279.840.0Oracle CorporationOracle Identity ManagerCWE-284Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-607829.840.0Oracle CorporationOracle PaymentsVulnerability in the Oracle Payments product of Oracle E-Business Suite (comp…
CVE-2026-608219.839.9Oracle CorporationPeopleSoft Enterprise PeopleToolsVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop…
CVE-2026-609219.839.9Oracle CorporationOracle WebCenter Enterprise CaptureVulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-609469.839.9Oracle CorporationOracle WebCenter Enterprise CaptureVulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-609479.839.9Oracle CorporationOracle WebCenter Enterprise CaptureVulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-609589.839.9Oracle CorporationOracle WebCenter Enterprise CaptureVulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-609709.839.9Oracle CorporationOracle WebCenter Enterprise CaptureVulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-624579.839.9Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-625449.839.9Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-625929.839.9Oracle CorporationSiebel CRM IntegrationCWE-284Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com…
CVE-2026-626099.839.9Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626119.839.9Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626149.839.9Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626179.839.9Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626219.839.9Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626229.840.0Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626249.839.9Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626309.839.9Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626349.839.9Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626399.840.0Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626409.840.0Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-706899.839.9Oracle CorporationOracle EssbaseVulnerability in Oracle Essbase (component: Infrastructure). The supported ve…
CVE-2026-707399.840.0Oracle CorporationOracle Hyperion Financial ReportingVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-707409.840.0Oracle CorporationOracle Hyperion Financial ReportingVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-707459.840.0Oracle CorporationOracle Hyperion Financial ReportingVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-708179.840.0Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-708739.839.9Oracle CorporationOracle Hyperion Data Relationship ManagementVulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-709059.839.9Oracle CorporationOracle Access ManagerVulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-709709.840.0Oracle CorporationOracle WebCenter PortalVulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-710409.839.9Oracle CorporationOracle Agile PLMCWE-284Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone…
CVE-2026-710749.839.9Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-711529.840.0Oracle CorporationHelidonVulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-711649.840.0Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-607549.139.9Oracle CorporationSiebel Apps - MarketingVulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co…
CVE-2026-477198.239.8frangoteamFUXACWE-918FUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PRO…
CVE-2026-740128.839.7Steve BurgeTaxoPressCWE-502WordPress TaxoPress plugin <= 3.51.0 - PHP Object Injection vulnerability
CVE-2026-731817.539.6ThemeCompleteExtra Product Options & Add-Ons for WooCommerceCWE-22WordPress Extra Product Options & Add-Ons for WooCommerce plugin < 7.6 - Arbi…
CVE-2026-607029.939.5Oracle CorporationOracle WebLogic ServerCWE-284Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-612069.939.5Oracle CorporationOracle Hyperion Calculation ManagerVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-613179.939.5Oracle CorporationSiebel CRM Cloud ApplicationsVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-709209.939.5Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-607168.839.5Oracle CorporationOracle Identity ManagerVulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-607228.839.5Oracle CorporationOracle Identity ManagerVulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-607318.839.5Oracle CorporationOracle WebCenter PortalCWE-306Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-607518.839.5Oracle CorporationSiebel Apps - MarketingVulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co…
CVE-2026-609768.839.5Oracle CorporationOracle ScriptingVulnerability in the Oracle Scripting product of Oracle E-Business Suite (com…
CVE-2026-612768.839.5Oracle CorporationOracle Hyperion Calculation ManagerVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-707108.839.5Oracle CorporationOracle Sales FoundationVulnerability in the Oracle Sales Foundation product of Oracle E-Business Sui…
CVE-2026-707298.839.5Oracle CorporationOracle TeleserviceVulnerability in the Oracle Teleservice product of Oracle E-Business Suite (c…
CVE-2026-707378.839.5Oracle CorporationOracle Enterprise Manager for Systems InfrastructureVulnerability in the Oracle Enterprise Manager for Systems Infrastructure pro…
CVE-2026-707478.839.5Oracle CorporationOracle Customers OnlineVulnerability in the Oracle Customers Online product of Oracle E-Business Sui…
CVE-2026-708138.839.5Oracle CorporationOracle Call Center TechnologyVulnerability in the Oracle Call Center Technology product of Oracle E-Busine…
CVE-2026-709188.839.5Oracle CorporationOracle Product HubVulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c…
CVE-2026-709228.839.5Oracle CorporationOracle Financial Services Enterprise Case ManagementVulnerability in the Oracle Financial Services Enterprise Case Management pro…
CVE-2026-718789.239.4GBIFIntegrated Publishing ToolkitCWE-306Authentication bypass in Integrated Publishing Toolkit
CVE-2026-718799.139.4GBIFIntegrated Publishing ToolkitCWE-288Authentication bypass in Integrated Publishing Toolkit
CVE-2026-636436.339.2MagicMirrorOrgMagicMirrorCWE-441MagicMirror: ssrf calendar .js
CVE-2026-708549.139.1Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-659847.538.7frangoteamFUXACWE-613FUXA: JWT lifecycle flaws allow deleted or demoted users to retain privileged…
CVE-2026-708769.138.6Oracle CorporationOracle Hyperion Data Relationship ManagementVulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-608837.238.6Oracle CorporationPeopleSoft Enterprise PeopleToolsVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop…
CVE-2026-707357.238.6Oracle CorporationOracle Hyperion Profitability and Cost ManagementVulnerability in the Oracle Hyperion Profitability and Cost Management produc…
CVE-2026-707817.238.6Oracle CorporationOracle ProposalsVulnerability in the Oracle Proposals product of Oracle E-Business Suite (com…
CVE-2026-708617.238.6Oracle CorporationPeopleSoft Enterprise FIN Common Objects BrazilVulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product …
CVE-2026-709397.238.6Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-709507.238.6Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-710997.238.6Oracle CorporationOracle Business Intelligence Enterprise EditionCWE-284Vulnerability in the Oracle Business Intelligence Enterprise Edition product …
CVE-2026-757742.938.6karakeep-appkarakeepCWE-287karakeep-app karakeep OAuth Sign-In auth.ts improper authentication
CVE-2026-672719.838.4DellPowerStore 500TCWE-787Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the S…
CVE-2026-707007.538.2Oracle CorporationOracle PayablesVulnerability in the Oracle Payables product of Oracle E-Business Suite (comp…
CVE-2026-599496.538.3yawkatlz4-javaCWE-476yawkat LZ4 Java: JVM Crash via Null Byte Array in lz4-java Streaming XXHash J…
CVE-2026-758529.337.7ArcadeDataarcadedbCWE-306ArcadeDB MongoDB wire protocol authentication bypass cross-database
CVE-2026-324749.937.3wpWaxTemplatiqCWE-434WordPress Templatiq plugin <= 0.2.5 - Arbitrary File Upload vulnerability
CVE-2026-607209.937.3Oracle CorporationOracle Identity ManagerVulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-607309.937.3Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-625129.937.3Oracle CorporationSiebel CRM Cloud ApplicationsVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-625889.937.3Oracle CorporationSiebel CRM IntegrationCWE-284Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com…
CVE-2026-626089.937.3Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-666279.937.3EDGE22 Studios Ltd.GP PremiumCWE-434WordPress GP Premium plugin <= 2.5.5 - Arbitrary File Upload vulnerability
CVE-2026-607158.837.3Oracle CorporationOracle Identity ManagerCWE-284Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-607268.837.3Oracle CorporationOracle Access ManagerCWE-284Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-607298.837.3Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-607678.837.3Oracle CorporationSiebel Apps - MarketingVulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co…
CVE-2026-608798.837.3Oracle CorporationPeopleSoft Enterprise PeopleToolsVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop…
CVE-2026-610028.837.3Oracle CorporationOracle SOA SuiteVulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co…
CVE-2026-610178.837.3Oracle CorporationOracle WebCenter SitesVulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-610228.837.3Oracle CorporationOracle WebCenter SitesVulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-610328.837.3Oracle CorporationOracle WebCenter SitesVulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-610408.837.3Oracle CorporationOracle WebCenter SitesVulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-610588.837.3Oracle CorporationOracle WebCenter SitesVulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-611188.837.3Oracle CorporationOracle Identity ManagerVulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-612848.837.3Oracle CorporationOracle Enterprise Manager Base PlatformVulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-613198.837.3Oracle CorporationOracle U.S. Federal FinancialsVulnerability in the Oracle U.S. Federal Financials product of Oracle E-Busin…
CVE-2026-613308.837.3Oracle CorporationSiebel CRM Cloud ApplicationsVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-613418.837.3Oracle CorporationSiebel CRM Cloud ApplicationsVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-624508.837.3Oracle CorporationOracle Flow ManufacturingVulnerability in the Oracle Flow Manufacturing product of Oracle E-Business S…
CVE-2026-625008.837.3Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-626128.837.3Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-706868.837.3Oracle CorporationOracle General LedgerVulnerability in the Oracle General Ledger product of Oracle E-Business Suite…
CVE-2026-706888.837.3Oracle CorporationOracle EssbaseVulnerability in Oracle Essbase (component: Calculator). The supported versio…
CVE-2026-707428.837.3Oracle CorporationOracle Hyperion Financial ReportingVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-707618.837.3Oracle CorporationOracle Risk ManagementVulnerability in the Oracle Risk Management product of Oracle E-Business Suit…
CVE-2026-708188.837.3Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-708218.837.3Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-708638.837.3Oracle CorporationOracle Application Testing SuiteVulnerability in Oracle Application Testing Suite. The supported version that…
CVE-2026-708778.837.3Oracle CorporationOracle Hyperion Data Relationship ManagementVulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-708868.837.3Oracle CorporationOracle Hyperion Data Relationship ManagementVulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-709288.837.3Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-709408.837.3Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-709448.837.3Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-709488.837.3Oracle CorporationOracle PurchasingVulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co…
CVE-2026-709498.837.3Oracle CorporationSiebel CRM DeploymentCWE-284Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp…
CVE-2026-709668.837.3Oracle CorporationOracle Hyperion Infrastructure TechnologyCWE-284Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-710398.837.3Oracle CorporationOracle Agile PLMCWE-284Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone…
CVE-2026-710558.837.3Oracle CorporationOracle Business Intelligence Enterprise EditionCWE-284Vulnerability in the Oracle Business Intelligence Enterprise Edition product …
CVE-2026-710678.837.3Oracle CorporationOracle Agile PLM MCAD ConnectorVulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply…
CVE-2026-527368.737.1ZcashFoundationzebraCWE-459ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cache
CVE-2026-613028.237.1Oracle CorporationOracle Business Intelligence Enterprise EditionCWE-284Vulnerability in the Oracle Business Intelligence Enterprise Edition product …
CVE-2026-707438.237.1Oracle CorporationOracle Hyperion Financial ReportingCWE-284Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-756279.337.0bastillion-ioBastillionCWE-288Bastillion Authentication Bypass via Path-Prefix Routing Mismatch
CVE-2026-575809.436.9goauthentikauthentikCWE-436authentik: Account Takeover via SAML NameID Comment Truncation
CVE-2026-605919.136.9Oracle CorporationOracle Hospitality SimphonyVulnerability in the Oracle Hospitality Simphony product of Oracle Food and B…
CVE-2026-626389.136.9Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-709779.136.9Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-709819.136.9Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-709849.136.9Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-711029.136.9Oracle CorporationOracle Database ServerCWE-284Vulnerability in the Portable Clusterware component of Oracle Database Server…
CVE-2026-759358.736.9Amazon IonAmazon Ion JavaCWE-789Memory-amplification denial of service via declared-length preallocation in A…
CVE-2026-759368.736.9Amazon IonAmazon Ion JavaCWE-409Memory-amplification denial of service via GZIP decompression bomb in Amazon …
CVE-2026-709067.536.9Oracle CorporationOracle Java SEVulnerability in Oracle Java SE (component: 2D). Supported versions that are …
CVE-2026-709087.536.9Oracle CorporationHelidonVulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-709277.536.9Oracle CorporationOracle WorkflowVulnerability in the Oracle Workflow product of Oracle E-Business Suite (comp…
CVE-2026-711137.536.9Oracle CorporationOracle VM VirtualBoxCWE-284Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-711537.536.9Oracle CorporationHelidonVulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-739277.536.9Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-739367.536.9Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-739977.536.9NexcessStarter Templates by Kadence WPCWE-770WordPress Starter Templates by Kadence WP plugin <= 2.3.3 - Denial of Service…
CVE-2026-324449.936.7CwiclyCwiclyCWE-94WordPress Cwicly plugin <= 1.4.4 - Remote Code Execution (RCE) vulnerability
CVE-2026-444728.136.7saleorsaleorCWE-287Saleor: Account pre-hijacking vulnerability due to unverified anonymous order…
CVE-2026-476279.836.5NVIDIATriton Inference ServerCWE-22NVIDIA Triton Inference Server for Linux contains a vulnerability where an at…
CVE-2026-734008.136.4jetmonstersRestaurant Menu by MotoPressCWE-98WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Local File Inclusio…
CVE-2026-501868.836.1RARgames4gaBoardsCWE-224gaBoards: Path Traversal leading to Arbitrary File Read and Deletion in Boar…
CVE-2026-528548.636.2ProfessionalWikiMapsCWE-79mediawiki/maps: Stored XSS through the overlays parameter in the display_map …
CVE-2026-528297.536.1ZcashFoundationzebraCWE-617ZEBRA: IPv4-Mapped Mempool Misbehavior Update Aborts Zebra Address Book
CVE-2026-760396.536.1GoogleChromeCWE-706Incorrect reference resolution in Core in Google Chrome on on Android prior t…
CVE-2026-760408.836.1GoogleChromeCWE-416Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 …
CVE-2026-7587410.036.0MozillaFirefoxCWE-693Sandbox escape in the Remote Settings Client component
CVE-2026-545435.435.9froxlorfroxlorCWE-74Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields
CVE-2026-7092110.035.8Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-607379.135.8Oracle CorporationOracle Web Services ManagerVulnerability in the Oracle Web Services Manager product of Oracle Fusion Mid…
CVE-2026-711669.435.7Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-607968.235.7Oracle CorporationSiebel CRM IntegrationCWE-284Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com…
CVE-2026-709098.235.7Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-709528.235.7Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-492248.335.6givanzVvvebCWE-639Vvveb post revision authorization bypass allows Authors to read, restore, or …
CVE-2026-492258.335.6givanzVvvebCWE-639Vvveb product revision authorization bypass allows Vendors to read, restore, …
CVE-2026-501675.335.4kurrier-orgkurrierCWE-639Kurrier: Authenticated cross-user authorization bypass in Kurrier API
CVE-2026-487987.135.3sshnetSSH.NETCWE-22SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-…
CVE-2026-707708.335.1Oracle CorporationOracle Warehouse ManagementCWE-284Vulnerability in the Oracle Warehouse Management product of Oracle E-Business…
CVE-2026-689244.934.9MobSFMobile-Security-Framework-MobSFCWE-400MobSF: Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK E…
CVE-2026-606998.634.8Oracle CorporationOracle WebLogic ServerCWE-284Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-625868.634.8Oracle CorporationSiebel CRM AdministrationVulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (…
CVE-2026-625507.534.8Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-625547.534.8Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-707527.534.8Oracle CorporationOracle Hyperion Financial ReportingVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-707727.534.8Oracle CorporationOracle Warehouse ManagementVulnerability in the Oracle Warehouse Management product of Oracle E-Business…
CVE-2026-707997.534.8Oracle CorporationOracle SDP Number PortabilityVulnerability in the Oracle SDP Number Portability product of Oracle E-Busine…
CVE-2026-708227.534.8Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-708327.534.8Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-708897.534.8Oracle CorporationOracle Hyperion Data Relationship ManagementVulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-708917.534.8Oracle CorporationOracle Hyperion Data Relationship ManagementVulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-760369.634.7GoogleChromeCWE-122Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.16…
CVE-2026-760348.834.7GoogleChromeCWE-122Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a r…
CVE-2026-758598.734.7HmbownCodeWhaleCWE-22CodeWhale before 0.8.64 Arbitrary File Read via instructions
CVE-2026-759148.734.7HmbownCodeWhaleCWE-22CodeWhale before 0.8.64 Path Traversal via image_analyze symlink
CVE-2026-707228.234.6Oracle CorporationOracle Advanced Inbound TelephonyCWE-284Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Bu…
CVE-2026-624558.334.4Oracle CorporationSiebel CRM Cloud ApplicationsVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-476066.534.2NVIDIATriton Inference ServerCWE-36NVIDIA Triton Inference Server for Linux contains a vulnerability where an at…
CVE-2026-626299.434.2Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-607078.734.2Oracle CorporationOracle Identity ManagerCWE-284Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-613328.734.2Oracle CorporationSiebel CRM Cloud ApplicationsVulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-739378.234.2Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-623774.334.1strukturaglibheifCWE-617libheif: Reachable assertion in HeifContext::get_track() aborts on a valid-bu…
CVE-2026-606808.133.9Oracle CorporationOracle WebLogic ServerCWE-284Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-607798.133.9Oracle CorporationSiebel Apps - MarketingVulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co…
CVE-2026-609928.133.8Oracle CorporationOracle Identity Manager ConnectorVulnerability in the Oracle Identity Manager Connector product of Oracle Fusi…
CVE-2026-612658.133.8Oracle CorporationJD Edwards EnterpriseOne OrchestratorVulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle …
CVE-2026-706758.133.8Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-706848.133.8Oracle CorporationOracle Enterprise Manager Base PlatformVulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-707048.133.8Oracle CorporationOracle Trading CommunityVulnerability in the Oracle Trading Community product of Oracle E-Business Su…
CVE-2026-708148.133.8Oracle CorporationOracle Call Center TechnologyVulnerability in the Oracle Call Center Technology product of Oracle E-Busine…
CVE-2026-709248.133.8Oracle CorporationOracle Web Services ManagerVulnerability in the Oracle Web Services Manager product of Oracle Fusion Mid…
CVE-2026-709318.133.9Oracle CorporationOracle WorkflowVulnerability in the Oracle Workflow product of Oracle E-Business Suite (comp…
CVE-2026-709598.133.9Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-710428.133.9Oracle CorporationOracle Agile PLMCWE-284Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone…
CVE-2026-457345.333.8mybbmybbCWE-837MyBB: Default CAPTCHA missing invalidation
CVE-2026-757838.633.4TRENDnetTEW-WLC100PCWE-119TRENDnet TEW-WLC100P DHCP blobmsg netifd stack-based overflow
CVE-2026-692198.733.3rabbitmqrabbitmq-java-clientCWE-789RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers …
CVE-2026-692208.733.3rabbitmqrabbitmq-java-clientCWE-674RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting cau…
CVE-2026-733996.533.3flutterwaveFlutterwave WooCommerceCWE-288WordPress Flutterwave WooCommerce plugin <= 3.3.0 - Broken Authentication vul…
CVE-2026-610089.133.2Oracle CorporationOracle WebCenter SitesVulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-707309.133.2Oracle CorporationOracle Hyperion Profitability and Cost ManagementVulnerability in the Oracle Hyperion Profitability and Cost Management produc…
CVE-2026-707419.133.1Oracle CorporationOracle Hyperion Financial ReportingVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-708849.133.1Oracle CorporationOracle Hyperion Data Relationship ManagementVulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-709789.133.1Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-710159.133.2Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-710269.133.1Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-738669.133.1Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-739169.133.1Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-739179.133.1Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-625998.633.2Oracle CorporationOracle Trading CommunityVulnerability in the Oracle Trading Community product of Oracle E-Business Su…
CVE-2026-626288.633.2Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-707218.633.1Oracle CorporationOracle Hyperion Profitability and Cost ManagementVulnerability in the Oracle Hyperion Profitability and Cost Management produc…
CVE-2026-603917.533.2Oracle CorporationOracle Hyperion Financial ReportingCWE-284Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-603937.533.1Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-605907.533.2Oracle CorporationOracle Hospitality SimphonyVulnerability in the Oracle Hospitality Simphony product of Oracle Food and B…
CVE-2026-608507.533.2Oracle CorporationOracle Unified DirectoryVulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-608897.533.2Oracle CorporationOracle Unified DirectoryVulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-609067.533.1Oracle CorporationOracle WebCenter ContentVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-609147.533.1Oracle CorporationOracle Unified DirectoryVulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-610077.533.2Oracle CorporationOracle WebCenter SitesVulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-708107.533.2Oracle CorporationOracle ScriptingVulnerability in the Oracle Scripting product of Oracle E-Business Suite (com…
CVE-2026-708967.533.1Oracle CorporationOracle Hyperion Data Relationship ManagementVulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-709107.533.2Oracle CorporationSiebel CRM IntegrationVulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com…
CVE-2026-709867.533.1Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-709877.533.2Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-710347.533.1Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-711077.533.1Oracle CorporationOracle Business Intelligence Enterprise EditionVulnerability in the Oracle Business Intelligence Enterprise Edition product …
CVE-2026-711427.533.2Oracle CorporationOracle Communications Unified Inventory ManagementCWE-284Vulnerability in the Oracle Communications Unified Inventory Management produ…
CVE-2026-711587.533.2Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-738787.533.1Oracle CorporationHelidonVulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-738837.533.1Oracle CorporationHelidonVulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-738847.533.1Oracle CorporationHelidonVulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-739077.533.1Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-739387.533.1Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-706807.133.0Oracle CorporationOracle Applications DBACWE-284Vulnerability in the Oracle Applications DBA product of Oracle E-Business Sui…
CVE-2026-733508.232.9PSM PluginsSupportCandyCWE-266WordPress SupportCandy plugin <= 3.5.1 - Broken Authentication vulnerability
CVE-2026-760388.832.8GoogleChromeCWE-843Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remot…
CVE-2026-527395.932.7ZcashFoundationzebraCWE-248ZEBRA: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplic…
CVE-2026-622894.332.8strukturaglibheifCWE-191libheif: Integer underflow in Fraction constructor via double clap transform …
CVE-2026-758538.732.6ArcadeDataarcadedbCWE-862ArcadeDB Gremlin Wire Protocol Authorization Bypass Cross-Database
CVE-2026-710796.532.7Oracle CorporationMySQL ConnectorsCWE-284Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Con…
CVE-2026-626842.732.6filebrowserfilebrowserCWE-200File Browser: Share API exposes the password hash and bypass token
CVE-2026-624639.632.5Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-709589.632.5Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-626198.832.5Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-711068.832.5Oracle CorporationOracle Hospitality OPERA 5 Property ServicesVulnerability in the Oracle Hospitality OPERA 5 Property Services product of …
CVE-2026-624778.132.5Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-624918.132.5Oracle CorporationOracle PurchasingVulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co…
CVE-2026-625028.132.5Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-707018.132.5Oracle CorporationOracle PayablesVulnerability in the Oracle Payables product of Oracle E-Business Suite (comp…
CVE-2026-707628.132.5Oracle CorporationOracle Risk ManagementVulnerability in the Oracle Risk Management product of Oracle E-Business Suit…
CVE-2026-708118.132.5Oracle CorporationOracle PurchasingVulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co…
CVE-2026-708158.132.5Oracle CorporationOracle Internet Procurement ConnectorVulnerability in the Oracle Internet Procurement Connector product of Oracle …
CVE-2026-708358.132.5Oracle CorporationOracle iRecruitmentVulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (…
CVE-2026-708788.132.5Oracle CorporationOracle Hyperion Data Relationship ManagementVulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-708818.132.5Oracle CorporationOracle Hyperion Data Relationship ManagementVulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-709258.132.5Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-189639.132.4Red HatRed Hat build of Keycloak 26.4CWE-640Keycloak-services: keycloak-services: unauthenticated account takeover via re…
CVE-2026-758558.432.4ArcadeDataarcadedbCWE-22ArcadeDB before 26.8.1 Path Traversal via create/drop database
CVE-2026-710958.332.4Oracle CorporationOracle Business Intelligence Enterprise EditionCWE-284Vulnerability in the Oracle Business Intelligence Enterprise Edition product …
CVE-2026-215828.832.2AtlassianCrowd Data CenterThis High severity BASM (Broken Authentication & Session Management) vulnerab…
CVE-2026-760438.832.1GoogleChromeCWE-682Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed …
CVE-2026-760478.832.1GoogleChromeCWE-843Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remot…
CVE-2026-324709.832.0RoxnorFundEngineCWE-502WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability
CVE-2026-733419.832.0MetagaussRegistrationMagicCWE-502WordPress RegistrationMagic plugin <= 6.0.9.7 - PHP Object Injection vulnerab…
CVE-2026-733769.832.0supsysticUltimate Maps by SupsysticCWE-502WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - PHP Object Injection vu…
CVE-2026-733979.832.0YouzifyYouzifyCWE-502WordPress Youzify plugin <= 1.3.7 - Deserialization of untrusted data vulnera…
CVE-2026-706908.031.9Oracle CorporationOracle HRMS (US)Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (com…
CVE-2026-708028.031.9Oracle CorporationOracle Public Sector Human ResourcesVulnerability in the Oracle Public Sector Human Resources product of Oracle E…
CVE-2026-624756.631.9Oracle CorporationOracle Shipping ExecutionVulnerability in the Oracle Shipping Execution product of Oracle E-Business S…
CVE-2026-610118.231.8Oracle CorporationOracle WebCenter SitesCWE-284Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-610168.231.8Oracle CorporationOracle WebCenter SitesCWE-284Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-733967.131.9MakeWebBetterMWB HubSpot for WooCommerceCWE-288WordPress MWB HubSpot for WooCommerce plugin <= 1.6.7 - Broken Authentication…
CVE-2026-535336.931.8coleaiosmtplibCWE-77aiosmtplib: SMTP command injection via CR/LF in sender/recipient address
CVE-2026-711615.331.8Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-6124110.031.7Oracle CorporationOracle Internet DirectoryVulnerability in the Oracle Internet Directory product of Oracle Fusion Middl…
CVE-2026-612589.831.7Oracle CorporationOracle Internet DirectoryVulnerability in the Oracle Internet Directory product of Oracle Fusion Middl…
CVE-2026-706699.831.7Oracle CorporationOracle Reports DeveloperVulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-451189.331.7mybbmybbCWE-83MyBB: Contact page reflected XSS
CVE-2026-501619.331.7baresipreCWE-190libre: Integer overflow in websock_decode() masked frame length check leads t…
CVE-2026-623578.831.7dragonflydbdragonflyCWE-190DragonflyDB `CMS.INITBYDIM` integer overflow leads to a remote, attacker-cont…
CVE-2026-605928.231.7Oracle CorporationMySQL ClusterVulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluste…
CVE-2026-739309.931.6Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-731879.331.6gingerpluginsSticky Chat WidgetCWE-89WordPress Sticky Chat Widget plugin <= 1.4.2 - SQL Injection vulnerability
CVE-2026-733399.331.6Webnus Inc.Modern Events CalendarCWE-89WordPress Modern Events Calendar plugin < 7.35.0 - SQL Injection vulnerability
CVE-2026-733559.331.6wp.insiderAffiliates ManagerCWE-89WordPress Affiliates Manager plugin <= 2.9.53 - SQL Injection vulnerability
CVE-2026-733659.331.6Crocoblock. Jetimpex Inc.JetAppointmentCWE-89WordPress JetAppointment plugin <= 2.5.2 - SQL Injection vulnerability
CVE-2026-733929.331.6highwardenSuper Store FinderCWE-89WordPress Super Store Finder plugin <= 7.8 - SQL Injection vulnerability
CVE-2026-455328.731.5dataeasedataeaseCWE-22DataEase has a Path Traversal Vulnerability
CVE-2026-543478.731.5froxlorfroxlorCWE-79Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Accoun…
CVE-2026-626078.731.4Oracle CorporationOracle Customer CareVulnerability in the Oracle Customer Care product of Oracle E-Business Suite …
CVE-2026-710508.731.4Oracle CorporationOracle Product Lifecycle AnalyticsVulnerability in the Oracle Product Lifecycle Analytics product of Oracle Sup…
CVE-2026-608656.831.4Oracle CorporationService Delivery PlatformVulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-710076.831.4Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-710854.931.4Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-609059.631.3Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-492218.831.3givanzVvvebCWE-639Vvveb digital asset authorization bypass allows Vendors to list, read, edit, …
CVE-2026-492288.831.3givanzVvvebCWE-639Vvveb product authorization bypass allows Vendors to read, duplicate, or dele…
CVE-2026-710578.531.3Oracle CorporationOracle BI PublisherCWE-284Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone…
CVE-2026-607527.131.3Oracle CorporationSiebel Apps - MarketingCWE-284Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co…
CVE-2026-612597.131.3Oracle CorporationOracle Hyperion Calculation ManagerCWE-284Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-707337.131.3Oracle CorporationOracle Hyperion Profitability and Cost ManagementCWE-284Vulnerability in the Oracle Hyperion Profitability and Cost Management produc…
CVE-2026-709337.131.3Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-709347.131.3Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-718807.631.2GBIFIntegrated Publishing ToolkitCWE-1336Server-side template injection in Integrated Publishing Toolkit
CVE-2026-707747.131.2Oracle CorporationOracle Warehouse ManagementCWE-284Vulnerability in the Oracle Warehouse Management product of Oracle E-Business…
CVE-2026-624529.931.1Oracle CorporationSiebel CRM Cloud ApplicationsCWE-284Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-740447.031.1Wazuhwazuh-managerCWE-22Wazuh 4.0.0 < 4.14.6 Path Traversal Arbitrary Directory Deletion via Cluster …
CVE-2026-324727.531.0wbolt.comOnline Contact WidgetCWE-862WordPress Online Contact Widget plugin <= 1.3.0 - Broken Access Control vulne…
CVE-2026-325497.531.0Codexpert, IncThumbPressCWE-862WordPress ThumbPress plugin < 6.5 - Broken Access Control vulnerability
CVE-2026-610299.030.9Oracle CorporationOracle WebCenter SitesVulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-709809.030.9Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-534558.630.9ha-chinablueprint-studioCWE-78Blueprint Studio Git credential helper command injection
CVE-2026-604158.130.9Oracle CorporationOracle WebLogic ServerVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-607428.130.9Oracle CorporationPeopleSoft Enterprise PeopleToolsVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop…
CVE-2026-608318.130.9Oracle CorporationPeopleSoft Enterprise PeopleToolsVulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop…
CVE-2026-613078.130.9Oracle CorporationPeopleSoft Enterprise CC Common Application ObjectsVulnerability in the PeopleSoft Enterprise CC Common Application Objects prod…
CVE-2026-625018.130.9Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-625318.130.9Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-707448.130.9Oracle CorporationOracle Hyperion Financial ReportingVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-707498.130.9Oracle CorporationOracle Hyperion Financial ReportingVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-708688.130.9Oracle CorporationOracle Application Testing SuiteVulnerability in Oracle Application Testing Suite. The supported version that…
CVE-2026-710358.130.9Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerVulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-710538.130.9Oracle CorporationOracle Agile Engineering Data ManagementCWE-284Vulnerability in the Oracle Agile Engineering Data Management product of Orac…
CVE-2026-710688.130.9Oracle CorporationOracle Agile PLM MCAD ConnectorVulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply…
CVE-2026-711128.130.9Oracle CorporationPeopleSoft Enterprise FIN Common ObjectsCWE-284Vulnerability in the PeopleSoft Enterprise FIN Common Objects product of Orac…
CVE-2026-527316.530.9ZcashFoundationzebraCWE-248ZEBRA: Full node denial of service via non-ASCII LongPollId in getblocktemplate
CVE-2026-760423.130.8GoogleChromeCWE-908Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169…
CVE-2026-547308.630.7goauthentikauthentikCWE-284authentik: Authentication Flow Bypass via Unguarded challenge_valid() in Auth…
CVE-2026-608619.630.6Oracle CorporationService Delivery PlatformVulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-610019.630.6Oracle CorporationOracle Web Services ManagerVulnerability in the Oracle Web Services Manager product of Oracle Fusion Mid…
CVE-2026-155857.530.6AKIN Software Computer Import Export Industry and Trade Ltd.AKINSOFT Wolvox9 ERP / KontrolPanel.exeCWE-22Path Traversal in AKIN Software's Wolvox9 ERP
CVE-2026-624677.730.4Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-625717.730.4Oracle CorporationOracle Hyperion Calculation ManagerVulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-625937.730.4Oracle CorporationSiebel CRM IntegrationCWE-284Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com…
CVE-2026-707717.730.4Oracle CorporationOracle Warehouse ManagementVulnerability in the Oracle Warehouse Management product of Oracle E-Business…
CVE-2026-708277.730.4Oracle CorporationOracle MES for Process ManufacturingVulnerability in the Oracle MES for Process Manufacturing product of Oracle E…
CVE-2026-708287.730.4Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-527386.930.4ZcashFoundationzebraCWE-248ZEBRA: Finalized address balance credit-first overflow on consensus-valid blocks
CVE-2026-625066.530.4Oracle CorporationOracle Hyperion Infrastructure TechnologyVulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-707206.530.4Oracle CorporationOracle Production SchedulingVulnerability in the Oracle Production Scheduling product of Oracle E-Busines…
CVE-2026-707676.530.4Oracle CorporationOracle Hyperion Financial ReportingVulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-708266.530.4Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-708316.530.4Oracle CorporationOracle Hyperion Financial ManagementVulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-439716.330.4nineninescowlibCWE-116Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in co…

Results continue: ranks 401–1407.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-18 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion.