boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, August 18, 2026 · all times UTC← 2026-08-17 · archive · 2026-08-19 →

Security Box Score — August 18, 2026

CISA adds 4 to KEV; 1407 CVEs published, led by Oracle Corporation (889).

1407 CVEs published August 18, 2026: 225 critical, 741 high, 380 medium, 60 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 1007 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published766929833——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

1641 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux12633578363178163711120.17.8.0017+1222 ▲
microsoft4441866132127244814286271.47.8.0044-202 ▼
google641825224758786577760.37.5.0025-30 ▼
red hat1615473622325731200.06.6.0028+96 ▲
apple34305588216058882.66.5.0029+34 ▲
canonical1138129125000.07.8.0020+7 ▲
suse52651461000.08.1.0039-3 ▼
freebsd01601240000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco31691337190561318.87.5.0046+16 ▲
palo alto networks12371321121325.44.7.0020-2 ▼
ubiquiti036142110338.38.8.0049-25 ▼
netgear93200275000.04.3.0025+3 ▲
fortinet7307814128620.07.0.0050-6 ▼
vmware01749227211.88.3.0040-8 ▼
f50165830416.38.6.0057-8 ▼
ivanti314482025535.78.3.0754+1 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache10243887189149123320.57.5.0049+24 ▲
mozilla591866868500900.08.1.0031+53 ▲
gitlab1566214428423.05.1.0029+8 ▲
drupal05165355412.05.9.0026-46 ▼
github5171790000.06.6.00430
docker290630000.07.2.0016+2 ▲
wordpress2513102240.08.8.3120+2 ▲
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle88922684871172513962730.17.8.0034+888 ▲
ibm192421991801375610.27.5.0031+156 ▲
adobe603123914512351931.07.8.0026-34 ▼
progress19611437100611.68.1.0037+9 ▲
solarwinds0231733010417.49.1.00580
veeam10165920100.08.6.0034+10 ▲
zohocorp4103520000.08.7.0140+4 ▲
atlassian3615001300.08.1.0034+3 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link163615597300.07.4.0157+15 ▲
siemens193522382000.07.3.0016+12 ▲
synology12426133000.05.6.0025+1 ▲
rockwell automation02441820000.08.7.0029-17 ▼
schneider electric091620000.08.6.00370
abb070430000.07.2.0018-1 ▼
hikvision060420000.07.2.00400
moxa050320000.07.0.00290
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester27147008067000.05.5.0031-14 ▼
dell331321068495210.87.2.0020-4 ▼
openclaw01110583914000.07.0.0026-44 ▼
nvidia241061471210000.07.5.0034-16 ▼
gitea48891936304000.07.5.0034+8 ▲
siyuan-note66883919281000.08.7.0028+60 ▲
itsourcecode1788001969000.02.1.0032+3 ▲
zephyrproject3487230469000.06.5.0022+19 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.995799.99.8
CVE-2026-34486.986299.97.5
CVE-2026-63030.977999.99.8
CVE-2026-16232.891299.89.3
CVE-2026-63077.847399.79.8
CVE-2026-60137.797999.65.9
CVE-2026-72898.792299.610.0
CVE-2026-0770.634299.19.8
CVE-2026-59310.458898.79.8
CVE-2026-61511.339998.39.3
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.7922KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0486
CVE-2026-4836210.0.0431
CVE-2026-4766810.0.0388
CVE-2026-1918810.0.0193
CVE-2026-5823110.0.0171
CVE-2026-1681210.0.0157KEV
CVE-2026-7329910.0.0121
CVE-2025-7138910.0.0120
Most disclosures (vendor)
VendorCVEs
oracle1997
linux1628
google466
microsoft463
ibm261
red hat260
apache205
apple201
mozilla124
adobe74
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco13
apple8
fortinet6
google6
ivanti5
solarwinds4
adobe3
berriai3
oracle3
Most-affected ecosystems
EcosystemAdvisories
Maven66
PyPI5
npm5
Go3
Packagist2
crates.io2
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2021-27137DD-WRT0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20316Cisco0
CVE-2026-20349Cisco0
CVE-2026-34486Apache Software Foundation0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171735
CVE-2021-27102n/a2021-11-171735
CVE-2021-27101n/a2021-11-171735
CVE-2021-27103n/a2021-11-171735
CVE-2021-21017Adobe2021-11-171735
CVE-2021-28550Adobe2021-11-171735
CVE-2021-42013Apache Software Foundation2021-11-171735
CVE-2021-41773Apache Software Foundation2021-11-171735
CVE-2021-30858Apple2021-11-171735
CVE-2021-30860Apple2021-11-171735

Transactions

ADDED TO KEV — CVE-2026-33824 (Microsoft Windows 10 Version 1607). Remediation due August 21, 2026.

ADDED TO KEV — CVE-2026-55040 (Microsoft SharePoint Enterprise Server 2016). Remediation due August 21, 2026.

ADDED TO KEV — CVE-2026-59310 (VMware Cloud Foundation). Remediation due August 21, 2026.

ADDED TO KEV — CVE-2026-65400 (Apple macOS). Remediation due August 21, 2026.

EXPLOIT PUBLISHED — itsourcecode Hospital Management System: 6 CVEs (CVE-2026-19894, CVE-2026-19934, CVE-2026-19972, CVE-2026-75086, CVE-2026-75087, CVE-2026-75088). Public exploit references added.

EXPLOIT PUBLISHED — Webkul Bagisto: 6 CVEs (CVE-2026-19834, CVE-2026-19836, CVE-2026-19993, CVE-2026-19996, CVE-2026-75081, CVE-2026-75082). Public exploit references added.

EXPLOIT PUBLISHED — code-projects Online Shopping System: 4 CVEs (CVE-2026-19919, CVE-2026-19921, CVE-2026-19923, CVE-2026-19998). Public exploit references added.

EXPLOIT PUBLISHED — OpenBoxes: 4 CVEs (CVE-2024-14045, CVE-2024-14046, CVE-2026-19928, CVE-2026-19929). Public exploit references added.

EXPLOIT PUBLISHED — SourceCodester Class and Exam Timetabling System: 4 CVEs (CVE-2026-19899, CVE-2026-75077, CVE-2026-75079, CVE-2026-75080). Public exploit references added.

EXPLOIT PUBLISHED — TOTOLINK A800R: 4 CVEs (CVE-2026-19811, CVE-2026-19813, CVE-2026-19844, CVE-2026-19847). Public exploit references added.

EXPLOIT PUBLISHED — Edimax EW-7478APC: 3 CVEs (CVE-2026-19959, CVE-2026-19960, CVE-2026-19962). Public exploit references added.

EXPLOIT PUBLISHED — parallax jsPDF: 3 CVEs (CVE-2026-24737, CVE-2026-25535, CVE-2026-25755). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2024-21626 (opencontainers runc). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-25256 (Fortinet FortiSIEM). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-62593 (ray-project ray). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-17106 (moby go-archive). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19751 (EnzoVezzaro mcp-dominican-layer). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19756 (Dromara lamp-cloud). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19758 (dromara lamp-cloud). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19765 (eyaushev swagger-testcase-mcp). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19771 (Baicells EG3661M). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19788 (Tenda AC1206). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19790 (Tenda G0). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19821 (Tenda AC12). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19823 (Tenda W20E). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19826 (alldatacenter alldata). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19828 (648540858 wvp-GB28181-pro). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19839 (SourceCodester Simple Doctors Appointment System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19896 (mangroup dtale). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19898 (VictoriaMetrics). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19901 (LB-LINK X-PRO). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19904 (SourceCodester Online Book Store System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19905 (Jinher OA). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19916 (code-projects Online Food Order System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19918 (SpaceX Starlink Router Gen 3). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19924 (Tenda AC10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19926 (Evergreen). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19932 (DefaultFuction Notice-System-Managent). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19955 (TrailDB). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19957 (graphlit-mcp-server). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19964 (Jij-Inc Jij-MCP-Server). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19967 (Open Asset Import Library Assimp). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19969 (Open Asset Import Library Assimp). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19974 (treefrogframework treefrog-framework). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19977 (EFM ipTIME A3004T). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19984 (jkawamoto mcp-florence2). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19988 (Alaev SEO Tools Extension). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-25896 (NaturalIntelligence fast-xml-parser). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-26278 (NaturalIntelligence fast-xml-parser). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-53365 (Linux). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-58049 (FFmpeg). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-60113 (NASA-AMMOS AIT-DSN). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-64600 (Linux). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-67579 (ash-project ash). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-69414 (Microsoft Malware Protection Engine). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-70667 (Netflix lemur). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-7246 (Pallets Click Click). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-72741 (goodrain rainbond). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-73482 (phplist3). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-74842 (Kira-Pgr PromptShopMCP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-74899 (jahlives openssl_encrypt). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-75012 (TOTOLINK EX1200L). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-75013 (TOTOLINK EX1200L). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-75089 (PHPGurukul Complaint Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-75090 (EricLBuehler Mistral.rs). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-75093 (sonos tract). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-75094 (COMFAST CF-N1-S). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-75130 (Uptash Context7). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-75773 (karakeep-app karakeep). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-75774 (karakeep-app karakeep). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-75778 (code-projects Task Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-75783 (TRENDnet TEW-WLC100P). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-75784 (TRENDnet TEW-WLC100). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-75876 (xianrendzw EasyReport). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-75877 (TRENDnet TV-IP751WIC). Public exploit reference added.

REJECTED — CVE-2026-64158 (Linux). Record withdrawn by the CNA.

REJECTED — CVE-2026-73682 (semaphoreui semaphore). Record withdrawn by the CNA.

REJECTED — CVE-2026-74511 (Linux). Record withdrawn by the CNA.

RESCORED — parallax jsPDF: 3 CVEs (CVE-2026-25755, CVE-2026-31898, CVE-2026-31938). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2024-44004 (Arni Cinco WPCargo Track & Trace). CVSS 9.3 → 9.8 (NVD).

RESCORED — CVE-2026-40478 (thymeleaf). CVSS 9.1 → 9 (NVD).

RESCORED — CVE-2026-41245 (junrar). CVSS 5.9 → 7.5 (NVD).

RESCORED — CVE-2026-75079 (SourceCodester Class and Exam Timetabling System). CVSS 6.9 → 5.5 (NVD).

RESCORED — CVE-2026-75080 (SourceCodester Class and Exam Timetabling System). CVSS 6.9 → 5.5 (NVD).

RESCORED — CVE-2026-75081 (Webkul Bagisto). CVSS 5.3 → 2.1 (NVD).

PATCH SHIPPED — rrrene html_sanitize_ex: 6 CVEs (CVE-2026-66370, CVE-2026-66829, CVE-2026-66843, CVE-2026-68747, CVE-2026-68749, CVE-2026-68750). Fix versions published.

PATCH SHIPPED — Red Hat OpenShift Container Platform 4.20: 3 CVEs (CVE-2026-42965, CVE-2026-50236, CVE-2026-50237). Fix versions published.

PATCH SHIPPED — CVE-2026-18739 (rpm-software-management popt). Fixed in Red Hat Hardened Images 1.19-11.1.hum1.

PATCH SHIPPED — CVE-2026-64611 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 1:2.0.0-13.el10_2.

PATCH SHIPPED — CVE-2026-64612 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 1:2.0.0-13.el10_2.

Yesterday's Results

How to read these box scores · glossary

1407 CVEs published. 25 box scores and 375 table rows below; the remaining 1007 continue on page 2 · page 3 — every CVE is listed, nothing truncated.

wpmudev Forminator Forms – Contact Form, Payment Form & Custom Form Builder — Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0443   90.6     —
AFFECTED
  Product                                                              Versions     Fixed
  Forminator Forms – Contact Form, Payment Form & Custom Form Builder  unspecified  —
TIMELINE
  Jul 14  Reserved by CNA
  Aug 18  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
Microsoft Copilot Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0222   81.3     —
AFFECTED
  Product      Versions  Fixed
  Copilot Web  - –       —
TIMELINE
  Jan 21  Reserved by CNA
  Aug 18  Published (CNA: microsoft)
CWE-77 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
COMFAST CF-N1-S CGI mbox-config sub_44B438 os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.5   .0211   80.3     —
AFFECTED
  Product  Versions   Fixed
  CF-N1-S  2.6.0.1 –  —
TIMELINE
  Aug 17  Reserved by CNA
  Aug 18  Public exploit reference published
  Aug 18  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
ArcadeData arcadedb — ArcadeDB Redis Wire-Protocol Plugin Missing Authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0107   62.3     —
AFFECTED
  Product   Versions     Fixed
  arcadedb  unspecified  26.8.1
TIMELINE
  Aug 18  Reserved by CNA
  Aug 18  Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
TRENDnet TEW-WLC100 HTTP Header nginx FUN_0040da4c stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0102   60.8     —
AFFECTED
  Product     Versions     Fixed
  TEW-WLC100  1v2.07b01 –  —
TIMELINE
  Aug 18  Public exploit reference published
  Aug 18  Reserved by CNA
  Aug 18  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
valkey-io valkey — Valkey: UAF in stream deserialization may lead to remote code execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0089   56.6     —
AFFECTED
  Product  Versions    Fixed
  valkey   < 7.2.14 –  —
TIMELINE
  Jul 17  Reserved by CNA
  Aug 18  Published (CNA: GitHub_M)
CWE-416 · CNA: GitHub_M · CVSS v3.1 · 12 references · NVD status: Received
n/a n/a — An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0082   54.4     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 8   Reserved by CNA
  Aug 18  Published (CNA: mitre)
CWE-22 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Received
Google Chrome — Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  H  H    9.6   .0081   54.1     —
AFFECTED
  Product  Versions          Fixed
  Chrome   151.0.7922.169 –  —
TIMELINE
  Aug 18  Reserved by CNA
  Aug 18  Published (CNA: Chrome)
CWE-122 · CNA: Chrome · CVSS v3.1 · 2 references · NVD status: Analyzed
AresIT WP Compress — WordPress WP Compress plugin < 7.20.01 - Remote Code Execution (RCE) vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0080   53.8     —
AFFECTED
  Product      Versions  Fixed
  WP Compress  n/a –     7.20.01
TIMELINE
  Aug 12  Reserved by CNA
  Aug 18  Published (CNA: Patchstack)
CWE-94 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
MyBB: Installer database configuration RCE
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0079   53.6     —
AFFECTED
  Product  Versions    Fixed
  mybb     < 1.8.40 –  —
TIMELINE
  May 8   Reserved by CNA
  Aug 18  Published (CNA: GitHub_M)
CWE-94 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Received
maalfer MailerUp — HTML Injection in MailerUp double opt-in verification email
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   L   N    6.9   .0071   50.7     —
AFFECTED
  Product   Versions     Fixed
  MailerUp  unspecified  —
TIMELINE
  Aug 18  Reserved by CNA
  Aug 18  Published (CNA: Secur0)
CWE-80 · CNA: Secur0 · CVSS v4.0 · 3 references · NVD status: Received
Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in the NFS/RPC. A…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0070   50.5     —
AFFECTED
  Product           Versions     Fixed
  PowerStore 500T   unspecified  —
  PowerStore 1000T  unspecified  —
  PowerStore 1200T  unspecified  —
  PowerStore 3000T  unspecified  —
  PowerStore 3200Q  unspecified  —
  PowerStore 3200T  unspecified  —
  PowerStore 5000T  unspecified  —
  PowerStore 5200Q  unspecified  —
  PowerStore 5200T  unspecified  —
  PowerStore 7000T  unspecified  —
  + 2 more
TIMELINE
  Aug 4   Reserved by CNA
  Aug 18  Published (CNA: dell)
CWE-120 · CNA: dell · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
Google Chrome — Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbi…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0070   50.3     —
AFFECTED
  Product  Versions          Fixed
  Chrome   151.0.7922.169 –  —
TIMELINE
  Aug 18  Reserved by CNA
  Aug 18  Published (CNA: Chrome)
CWE-122 · CNA: Chrome · CVSS v3.1 · 2 references · NVD status: Analyzed
n/a n/a — An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.i…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0065   48.4     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jul 30  Reserved by CNA
  Aug 18  Published (CNA: mitre)
CWE-73 · CNA: mitre · CVSS v3.1 · 3 references · NVD status: Received
TRENDnet TEW-823DRU NVRAM wan.cgi strcpy stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0063   47.3     —
AFFECTED
  Product     Versions     Fixed
  TEW-823DRU  1.1.02b01 –  —
TIMELINE
  Aug 18  Reserved by CNA
  Aug 18  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
frangoteam FUXA — FUXA: Unauthenticated guest JWT bypasses Node-RED secure-mode authorization gate (Remote Script Execution)
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0062   47.1     —
AFFECTED
  Product  Versions   Fixed
  FUXA     < 1.3.3 –  —
TIMELINE
  Jul 29  Reserved by CNA
  Aug 18  Published (CNA: GitHub_M)
CWE-862 · CNA: GitHub_M · CVSS v4.0 · 4 references · NVD status: Received
ha-china blueprint-studio — Blueprint Studio terminal command working directory not bounded to config directory
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   L   L   L    5.1   .0062   47.1     —
AFFECTED
  Product           Versions   Fixed
  blueprint-studio  < 2.5.2 –  —
TIMELINE
  Jun 9   Reserved by CNA
  Aug 18  Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Received
lxsmnsyc seroval — Seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0062   46.7     —
AFFECTED
  Product  Versions   Fixed
  seroval  < 1.5.3 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Aug 18  Published (CNA: GitHub_M)
CWE-502, CWE-843 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Received
TRENDnet TV-IP751WIC alphapd FUN_0043372C stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0061   46.7     —
AFFECTED
  Product      Versions    Fixed
  TV-IP751WIC  11.03.03 –  —
TIMELINE
  Aug 18  Public exploit reference published
  Aug 18  Reserved by CNA
  Aug 18  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Database Exfiltration
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0061   46.6     —
AFFECTED
  Product  Versions   Fixed
  froxlor  < 2.3.8 –  —
TIMELINE
  Jun 12  Reserved by CNA
  Aug 18  Published (CNA: GitHub_M)
CWE-89 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Received
n/a n/a — An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to i…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0061   46.5     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 8   Reserved by CNA
  Aug 18  Published (CNA: mitre)
CWE-284 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Received
getgrav grav — Grav before 2.0.15 Arbitrary File Write via error_log
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0059   45.5     —
AFFECTED
  Product  Versions     Fixed
  grav     unspecified  2.0.15
TIMELINE
  Aug 18  Reserved by CNA
  Aug 18  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  L    9.0   .0059   45.3     —
AFFECTED
  Product  Versions   Fixed
  froxlor  < 2.3.8 –  —
TIMELINE
  Jul 14  Reserved by CNA
  Aug 18  Published (CNA: GitHub_M)
CWE-200 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Received
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2 — Governance-policy-addon-controller: governance-policy-addon-controller: arbitrary container image override via managedclusteraddon annotation enables rce on spoke
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0057   44.8     —
AFFECTED
  Product                                               Versions     Fixed
  Red Hat Advanced Cluster Management for Kubernetes 2  unspecified  —
TIMELINE
  Jul 27  Reserved by CNA
  Aug 18  Published (CNA: redhat)
CWE-20 · CNA: redhat · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
Mozilla Firefox — Use-after-free in the Graphics: ImageLib component
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0057   44.5     —
AFFECTED
  Product      Versions     Fixed
  Firefox      unspecified  115.39
  Thunderbird  unspecified  140.14
TIMELINE
  Aug 17  Reserved by CNA
  Aug 18  Published (CNA: mozilla)
CWE-416 · CNA: mozilla · CVSS v3.1 · 8 references · NVD status: Modified
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-501427.543.8strukturaglibheifCWE-190libheif: unbounded heap allocation in HEIF sequence parser (stsz fixed-size m…
CVE-2026-526076.543.8n/an/aCWE-22A directory traversal vulnerability in reportico-web <= 8.1.0 allows remote a…
CVE-2026-6124110.043.3Oracle CorporationOracle Internet DirectoryCWE-284Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middl…
CVE-2026-749909.842.7MozillaFirefoxCWE-119Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefo…
CVE-2026-733669.842.2supsysticEasy Google MapsCWE-502WordPress Easy Google Maps plugin <= 1.13.0 - PHP Object Injection vulnerability
CVE-2026-733809.842.2supsysticPopup by SupsysticCWE-502WordPress Popup by Supsystic plugin <= 1.13.0 - PHP Object Injection vulnerab…
CVE-2026-757732.942.1karakeep-appkarakeepCWE-307karakeep-app karakeep Login Endpoint auth.ts authorize excessive authentication
CVE-2026-749879.842.0MozillaFirefoxCWE-119Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Fire…
CVE-2026-566847.542.0valkey-iovalkeyCWE-416Valkey: TLS pending-data processing use-after-free may allow remote code exec…
CVE-2026-626269.841.9Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626329.841.9Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626339.841.9Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626359.841.9Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-189639.141.8Red HatRed Hat build of Keycloak 26.4CWE-640Keycloak-services: keycloak-services: unauthenticated account takeover via re…
CVE-2026-750902.141.5EricLBuehlerMistral.rsCWE-119EricLBuehler Mistral.rs GGUF Tokenizer gguf_tokenizer.rs convert_gguf_to_hf_t…
CVE-2026-733819.141.3supsysticPopup by SupsysticCWE-288WordPress Popup by Supsystic plugin <= 1.13.0 - Broken Authentication vulnera…
CVE-2026-606729.841.1Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-606969.841.1Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-606989.841.0Oracle CorporationOracle WebLogic ServerCWE-306Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-609779.841.1Oracle CorporationOracle WebLogic ServerCWE-284Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-760408.841.0GoogleChromeCWE-416Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 …
CVE-2026-607289.140.8Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-758978.740.8OpenSearchOpenSearch DashboardsCWE-1284Uncontrolled Resource Consumption in Capabilities Route in OpenSearch Dashboards
CVE-2026-759158.740.8HmbownCodeWhaleCWE-200CodeWhale before 0.8.64 Environment Variable Leak via js_execution
CVE-2026-348849.840.7Apache Software FoundationApache SkyWalking MCPCWE-918Apache SkyWalking MCP: SSRF via set_skywalking_url Tool and GraphQL Expressio…
CVE-2026-706899.840.5Oracle CorporationOracle Essbase—Vulnerability in Oracle Essbase (component: Infrastructure). The supported ve…
CVE-2026-708207.240.5Oracle CorporationOracle Call Center TechnologyCWE-284Vulnerability in the Oracle Call Center Technology product of Oracle E-Busine…
CVE-2026-760396.540.3GoogleChromeCWE-706Incorrect reference resolution in Core in Google Chrome on on Android prior t…
CVE-2026-501878.840.2ohmyzshohmyzshCWE-94Oh My Zsh: Arbitrary Code Execution in oh-my-zsh dotenv plugin via malicious …
CVE-2026-674406.939.9frangoteamFUXACWE-862FUXA: Unauthenticated Socket.IO read events
CVE-2026-477205.339.9frangoteamFUXACWE-89FUXA: SQL injection in TDengine DAQ connector via backslash bypass of escapeT…
CVE-2026-195007.539.8SureFormsSureFormsCWE-400SureForms contains an uncontrolled resource consumption vulnerability
CVE-2026-624579.839.7Oracle CorporationOracle Hyperion Infrastructure TechnologyCWE-284Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-625449.839.7Oracle CorporationOracle Hyperion Infrastructure Technology—Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-626099.839.7Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626119.839.7Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626149.839.7Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626179.839.7Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626219.839.7Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626229.839.7Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626249.839.7Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626309.839.7Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626349.839.7Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626399.839.7Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-626409.839.7Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-707399.839.7Oracle CorporationOracle Hyperion Financial Reporting—Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-707409.839.7Oracle CorporationOracle Hyperion Financial Reporting—Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-707459.839.7Oracle CorporationOracle Hyperion Financial Reporting—Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-708179.839.7Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-708739.839.7Oracle CorporationOracle Hyperion Data Relationship ManagementCWE-284Vulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-477198.239.5frangoteamFUXACWE-918FUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PRO…
CVE-2026-170846.039.5Python Software FoundationCPythonCWE-436stringprep.map_table_b2() deviates from RFC 3454 Table B.2
CVE-2026-608589.839.4Oracle CorporationOracle Hyperion Calculation ManagerCWE-306Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-609589.839.4Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-613189.839.4Oracle CorporationSiebel CRM Cloud ApplicationsCWE-284Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-625929.839.4Oracle CorporationSiebel CRM IntegrationCWE-284Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com…
CVE-2026-709269.839.4Oracle CorporationOracle WorkflowCWE-306Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (comp…
CVE-2026-740128.839.4TaxoPressTaxoPressCWE-502WordPress TaxoPress plugin <= 3.51.0 - PHP Object Injection vulnerability
CVE-2026-707378.839.2Oracle CorporationOracle Enterprise Manager for Systems Infrastructure—Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure pro…
CVE-2026-707108.839.2Oracle CorporationOracle Sales Foundation—Vulnerability in the Oracle Sales Foundation product of Oracle E-Business Sui…
CVE-2026-707298.839.2Oracle CorporationOracle Teleservice—Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (c…
CVE-2026-707478.839.2Oracle CorporationOracle Customers Online—Vulnerability in the Oracle Customers Online product of Oracle E-Business Sui…
CVE-2026-708138.839.2Oracle CorporationOracle Call Center TechnologyCWE-284Vulnerability in the Oracle Call Center Technology product of Oracle E-Busine…
CVE-2026-718789.239.1GBIFIntegrated Publishing ToolkitCWE-306Authentication bypass in Integrated Publishing Toolkit
CVE-2026-718799.139.1GBIFIntegrated Publishing ToolkitCWE-288Authentication bypass in Integrated Publishing Toolkit
CVE-2026-608219.838.8Oracle CorporationPeopleSoft Enterprise PeopleToolsCWE-284Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop…
CVE-2026-636436.338.9MagicMirrorOrgMagicMirrorCWE-441MagicMirror: ssrf calendar .js
CVE-2026-607219.838.8Oracle CorporationOracle Identity ManagerCWE-306Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-607279.838.8Oracle CorporationOracle Identity ManagerCWE-284Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-609219.838.8Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-609469.838.8Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-609479.838.8Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-609709.838.8Oracle CorporationOracle WebCenter Enterprise CaptureCWE-284Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-709059.838.8Oracle CorporationOracle Access ManagerCWE-287Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-708549.138.8Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-611188.838.7Oracle CorporationOracle Identity ManagerCWE-284Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-659847.538.4frangoteamFUXACWE-613FUXA: JWT lifecycle flaws allow deleted or demoted users to retain privileged…
CVE-2026-731817.538.4ThemeCompleteExtra Product Options & Add-Ons for WooCommerceCWE-22WordPress Extra Product Options & Add-Ons for WooCommerce plugin < 7.6 - Arbi…
CVE-2026-749649.838.3MozillaFirefoxCWE-190Integer overflow in the Graphics component
CVE-2026-195018.838.3SureFormsSureFormsCWE-1236CVE-2026-19501
CVE-2026-708769.138.2Oracle CorporationOracle Hyperion Data Relationship ManagementCWE-284Vulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-707357.238.2Oracle CorporationOracle Hyperion Profitability and Cost Management—Vulnerability in the Oracle Hyperion Profitability and Cost Management produc…
CVE-2026-707817.238.2Oracle CorporationOracle Proposals—Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (com…
CVE-2026-757742.938.2karakeep-appkarakeepCWE-287karakeep-app karakeep OAuth Sign-In auth.ts improper authentication
CVE-2026-672719.838.0DellPowerStore 500TCWE-787Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the S…
CVE-2026-707007.537.9Oracle CorporationOracle Payables—Vulnerability in the Oracle Payables product of Oracle E-Business Suite (comp…
CVE-2026-476279.837.8NVIDIATriton Inference ServerCWE-22NVIDIA Triton Inference Server for Linux contains a vulnerability where an at…
CVE-2026-706888.837.8Oracle CorporationOracle Essbase—Vulnerability in Oracle Essbase (component: Calculator). The supported versio…
CVE-2026-709067.537.4Oracle CorporationOracle Java SECWE-400Vulnerability in Oracle Java SE (component: 2D). Supported versions that are …
CVE-2026-608837.237.4Oracle CorporationPeopleSoft Enterprise PeopleToolsCWE-284Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop…
CVE-2026-599496.537.4yawkatlz4-javaCWE-476yawkat LZ4 Java: JVM Crash via Null Byte Array in lz4-java Streaming XXHash J…
CVE-2026-758529.337.3ArcadeDataarcadedbCWE-306ArcadeDB MongoDB wire protocol authentication bypass cross-database
CVE-2026-607829.837.2Oracle CorporationOracle PaymentsCWE-306Vulnerability in the Oracle Payments product of Oracle E-Business Suite (comp…
CVE-2026-709709.837.2Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-710409.837.2Oracle CorporationOracle Agile PLMCWE-284Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone…
CVE-2026-710749.837.2Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-711529.837.2Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-711649.837.2Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-607549.137.2Oracle CorporationSiebel Apps - MarketingCWE-284Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co…
CVE-2026-622928.737.2strukturaglibheifCWE-125libheif: Out-of-bounds read in uncompressed unci tile range slicing
CVE-2026-760438.837.1GoogleChromeCWE-682Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed …
CVE-2026-324749.937.0wpWaxTemplatiqCWE-434WordPress Templatiq plugin <= 0.2.5 - Arbitrary File Upload vulnerability
CVE-2026-626089.937.0Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-666279.937.0EDGE22 Studios Ltd.GP PremiumCWE-434WordPress GP Premium plugin <= 2.5.5 - Arbitrary File Upload vulnerability
CVE-2026-610028.837.0Oracle CorporationOracle SOA SuiteCWE-284Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (co…
CVE-2026-613198.837.0Oracle CorporationOracle U.S. Federal FinancialsCWE-284Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Busin…
CVE-2026-624508.837.0Oracle CorporationOracle Flow ManufacturingCWE-284Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business S…
CVE-2026-625008.837.0Oracle CorporationOracle Hyperion Infrastructure Technology—Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-626128.837.0Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-706868.837.0Oracle CorporationOracle General Ledger—Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite…
CVE-2026-707428.837.0Oracle CorporationOracle Hyperion Financial Reporting—Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-707618.837.0Oracle CorporationOracle Risk Management—Vulnerability in the Oracle Risk Management product of Oracle E-Business Suit…
CVE-2026-708188.837.0Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-708218.837.0Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-708638.837.0Oracle CorporationOracle Application Testing SuiteCWE-284Vulnerability in Oracle Application Testing Suite. The supported version that…
CVE-2026-708778.837.0Oracle CorporationOracle Hyperion Data Relationship ManagementCWE-284Vulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-527368.736.8ZcashFoundationzebraCWE-459ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cache
CVE-2026-756279.336.7bastillion-ioBastillionCWE-288Bastillion Authentication Bypass via Path-Prefix Routing Mismatch
CVE-2026-749456.536.7MozillaFirefoxCWE-200Information disclosure in the Graphics: Text component
CVE-2026-610039.936.5Oracle CorporationOracle Managed File TransferCWE-284Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Mi…
CVE-2026-575809.436.6goauthentikauthentikCWE-436authentik: Account Takeover via SAML NameID Comment Truncation
CVE-2026-626389.136.5Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-607228.836.5Oracle CorporationOracle Identity ManagerCWE-306Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-607318.836.5Oracle CorporationOracle WebCenter PortalCWE-306Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-759358.736.5Amazon IonAmazon Ion JavaCWE-789Memory-amplification denial of service via declared-length preallocation in A…
CVE-2026-759368.736.5Amazon IonAmazon Ion JavaCWE-409Memory-amplification denial of service via GZIP decompression bomb in Amazon …
CVE-2026-709087.536.5Oracle CorporationHelidonCWE-400Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-709277.536.5Oracle CorporationOracle WorkflowCWE-400Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (comp…
CVE-2026-324449.936.3CwiclyCwiclyCWE-94WordPress Cwicly plugin <= 1.4.4 - Remote Code Execution (RCE) vulnerability
CVE-2026-444728.136.4saleorsaleorCWE-287Saleor: Account pre-hijacking vulnerability due to unverified anonymous order…
CVE-2026-734008.136.1jetmonstersRestaurant Menu by MotoPressCWE-98WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Local File Inclusio…
CVE-2026-189296.936.0CarboneCarboneCWE-409Resource Exhaustion in Carbone
CVE-2026-528548.635.8ProfessionalWikiMapsCWE-79mediawiki/maps: Stored XSS through the overlays parameter in the display_map …
CVE-2026-501868.835.7RARgames4gaBoardsCWE-224gaBoards: Path Traversal leading to Arbitrary File Read and Deletion in Boar…
CVE-2026-607168.835.8Oracle CorporationOracle Identity ManagerCWE-306Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-528297.535.7ZcashFoundationzebraCWE-617ZEBRA: IPv4-Mapped Mempool Misbehavior Update Aborts Zebra Address Book
CVE-2026-708617.235.7Oracle CorporationPeopleSoft Enterprise FIN Common Objects BrazilCWE-284Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product …
CVE-2026-710997.235.7Oracle CorporationOracle Business Intelligence Enterprise EditionCWE-284Vulnerability in the Oracle Business Intelligence Enterprise Edition product …
CVE-2026-709397.235.6Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-709507.235.6Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-739977.535.4NexcessStarter Templates by Kadence WPCWE-770WordPress Starter Templates by Kadence WP plugin <= 2.3.3 - Denial of Service…
CVE-2026-545435.435.5froxlorfroxlorCWE-74Froxlor DomainZones.add allows DNS zone-file RR injection via record/type fields
CVE-2026-607379.135.2Oracle CorporationOracle Web Services ManagerCWE-284Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Mid…
CVE-2026-492248.335.1givanzVvvebCWE-639Vvveb post revision authorization bypass allows Authors to read, restore, or …
CVE-2026-492258.335.1givanzVvvebCWE-639Vvveb product revision authorization bypass allows Vendors to read, restore, …
CVE-2026-709098.235.1Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-760359.635.0GoogleChromeCWE-20Inappropriate implementation in Media in Google Chrome on on Mac prior to 151…
CVE-2026-759148.735.0HmbownCodeWhaleCWE-22CodeWhale before 0.8.64 Path Traversal via image_analyze symlink
CVE-2026-760388.835.0GoogleChromeCWE-843Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remot…
CVE-2026-692198.735.0rabbitmqrabbitmq-java-clientCWE-789RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers …
CVE-2026-501675.335.0kurrier-orgkurrierCWE-639Kurrier: Authenticated cross-user authorization bypass in Kurrier API
CVE-2026-613028.234.9Oracle CorporationOracle Business Intelligence Enterprise EditionCWE-284Vulnerability in the Oracle Business Intelligence Enterprise Edition product …
CVE-2026-707438.234.9Oracle CorporationOracle Hyperion Financial ReportingCWE-284Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-609768.834.5Oracle CorporationOracle ScriptingCWE-284Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (com…
CVE-2026-612069.934.5Oracle CorporationOracle Hyperion Calculation ManagerCWE-284Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-613179.934.5Oracle CorporationSiebel CRM Cloud ApplicationsCWE-284Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-709209.934.5Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-711029.134.4Oracle CorporationOracle Database ServerCWE-284Vulnerability in the Portable Clusterware component of Oracle Database Server…
CVE-2026-607518.834.5Oracle CorporationSiebel Apps - MarketingCWE-284Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co…
CVE-2026-612768.834.5Oracle CorporationOracle Hyperion Calculation ManagerCWE-284Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-709188.834.5Oracle CorporationOracle Product HubCWE-306Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c…
CVE-2026-709228.834.5Oracle CorporationOracle Financial Services Enterprise Case ManagementCWE-287Vulnerability in the Oracle Financial Services Enterprise Case Management pro…
CVE-2026-689244.934.4MobSFMobile-Security-Framework-MobSFCWE-400MobSF: Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK E…
CVE-2026-625507.534.3Oracle CorporationOracle Hyperion Infrastructure Technology—Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-625547.534.3Oracle CorporationOracle Hyperion Infrastructure Technology—Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-707527.534.3Oracle CorporationOracle Hyperion Financial Reporting—Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-707727.534.3Oracle CorporationOracle Warehouse ManagementCWE-284Vulnerability in the Oracle Warehouse Management product of Oracle E-Business…
CVE-2026-707997.534.3Oracle CorporationOracle SDP Number Portability—Vulnerability in the Oracle SDP Number Portability product of Oracle E-Busine…
CVE-2026-708227.534.3Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-708327.534.3Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-739277.534.4Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-739367.534.4Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-607078.734.3Oracle CorporationOracle Identity ManagerCWE-284Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-758598.734.2HmbownCodeWhaleCWE-22CodeWhale before 0.8.64 Arbitrary File Read via instructions
CVE-2026-606998.634.2Oracle CorporationOracle WebLogic ServerCWE-284Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-625868.634.2Oracle CorporationSiebel CRM AdministrationCWE-284Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (…
CVE-2026-749409.834.0MozillaFirefoxCWE-416Use-after-free in the Graphics: Text component
CVE-2026-625889.933.9Oracle CorporationSiebel CRM IntegrationCWE-284Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com…
CVE-2026-607158.833.9Oracle CorporationOracle Identity ManagerCWE-284Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-607298.833.9Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-610328.833.9Oracle CorporationOracle WebCenter SitesCWE-284Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-610408.833.9Oracle CorporationOracle WebCenter SitesCWE-284Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-708868.833.9Oracle CorporationOracle Hyperion Data Relationship ManagementCWE-284Vulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-476066.533.7NVIDIATriton Inference ServerCWE-36NVIDIA Triton Inference Server for Linux contains a vulnerability where an at…
CVE-2026-626299.433.7Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-711137.533.6Oracle CorporationOracle VM VirtualBoxCWE-284Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-605919.133.6Oracle CorporationOracle Hospitality SimphonyCWE-306Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and B…
CVE-2026-709779.133.6Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-306Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-709819.133.6Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-709849.133.6Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-711537.533.6Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-539596.533.6RARgames4gaBoardsCWE-2004gaBoards: Mass Information Disclosure (Internal PII Leakage) on /api/users t…
CVE-2026-158066.033.6Python Software FoundationCPythonCWE-319`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorr…
CVE-2026-739169.133.3Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-7092110.033.3Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2021-437179.833.3n/an/aCWE-798An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identi…
CVE-2026-706758.133.2Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-706848.133.2Oracle CorporationOracle Enterprise Manager Base Platform—Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-707048.133.2Oracle CorporationOracle Trading Community—Vulnerability in the Oracle Trading Community product of Oracle E-Business Su…
CVE-2026-708148.133.2Oracle CorporationOracle Call Center TechnologyCWE-284Vulnerability in the Oracle Call Center Technology product of Oracle E-Busine…
CVE-2026-457345.333.3mybbmybbCWE-837MyBB: Default CAPTCHA missing invalidation
CVE-2026-7587410.033.1MozillaFirefoxCWE-693Sandbox escape in the Remote Settings Client component
CVE-2026-607029.933.1Oracle CorporationOracle WebLogic ServerCWE-284Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-607309.933.1Oracle CorporationOracle WebCenter PortalCWE-284Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-749369.833.2MozillaFirefoxCWE-416Use-after-free in the JavaScript: WebAssembly component
CVE-2026-749449.833.2MozillaFirefoxCWE-416Use-after-free in the DOM: Core & HTML component
CVE-2026-711669.433.2Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-608798.833.1Oracle CorporationPeopleSoft Enterprise PeopleToolsCWE-284Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop…
CVE-2026-607968.233.2Oracle CorporationSiebel CRM IntegrationCWE-284Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com…
CVE-2026-709528.233.2Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-607209.933.1Oracle CorporationOracle Identity ManagerCWE-306Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-607268.833.1Oracle CorporationOracle Access ManagerCWE-284Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-610178.833.1Oracle CorporationOracle WebCenter SitesCWE-284Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-610228.833.1Oracle CorporationOracle WebCenter SitesCWE-284Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-610588.833.1Oracle CorporationOracle WebCenter SitesCWE-284Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-757838.632.9TRENDnetTEW-WLC100PCWE-119TRENDnet TEW-WLC100P DHCP blobmsg netifd stack-based overflow
CVE-2026-710558.832.9Oracle CorporationOracle Business Intelligence Enterprise EditionCWE-284Vulnerability in the Oracle Business Intelligence Enterprise Edition product …
CVE-2026-692208.732.8rabbitmqrabbitmq-java-clientCWE-674RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting cau…
CVE-2026-733996.532.8flutterwaveFlutterwave WooCommerceCWE-288WordPress Flutterwave WooCommerce plugin <= 3.3.0 - Broken Authentication vul…
CVE-2026-707309.132.6Oracle CorporationOracle Hyperion Profitability and Cost Management—Vulnerability in the Oracle Hyperion Profitability and Cost Management produc…
CVE-2026-707419.132.6Oracle CorporationOracle Hyperion Financial Reporting—Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-708849.132.6Oracle CorporationOracle Hyperion Data Relationship ManagementCWE-284Vulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-625998.632.6Oracle CorporationOracle Trading Community—Vulnerability in the Oracle Trading Community product of Oracle E-Business Su…
CVE-2026-626288.632.6Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-707218.632.6Oracle CorporationOracle Hyperion Profitability and Cost Management—Vulnerability in the Oracle Hyperion Profitability and Cost Management produc…
CVE-2026-603937.532.6Oracle CorporationOracle Hyperion Infrastructure TechnologyCWE-200Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-708107.532.6Oracle CorporationOracle Scripting—Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (com…
CVE-2026-738787.532.6Oracle CorporationHelidon—Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-738837.532.6Oracle CorporationHelidon—Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-738847.532.6Oracle CorporationHelidon—Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-610089.132.5Oracle CorporationOracle WebCenter SitesCWE-284Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-739179.132.5Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-604158.132.4Oracle CorporationOracle WebLogic ServerCWE-200Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-608507.532.5Oracle CorporationOracle Unified DirectoryCWE-284Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-608897.532.5Oracle CorporationOracle Unified DirectoryCWE-284Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-609147.532.5Oracle CorporationOracle Unified DirectoryCWE-284Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-610077.532.5Oracle CorporationOracle WebCenter SitesCWE-284Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-739077.532.5Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-739387.532.5Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-215809.332.3AtlassianConfluence Data CenterCWE-79This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Securi…
CVE-2026-733508.232.4PSM PluginsSupportCandyCWE-266WordPress SupportCandy plugin <= 3.5.1 - Broken Authentication vulnerability
CVE-2026-610019.632.3Oracle CorporationOracle Web Services ManagerCWE-284Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Mid…
CVE-2026-476287.532.2NVIDIATriton Inference ServerCWE-770NVIDIA Triton Inference Server for Linux contains a vulnerability where an at…
CVE-2026-476297.532.2NVIDIATriton Inference ServerCWE-20NVIDIA Triton Inference Server for Linux contains a vulnerability where an at…
CVE-2026-708897.532.2Oracle CorporationOracle Hyperion Data Relationship ManagementCWE-284Vulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-708917.532.2Oracle CorporationOracle Hyperion Data Relationship ManagementCWE-284Vulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-527395.932.2ZcashFoundationzebraCWE-248ZEBRA: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplic…
CVE-2026-215828.832.1AtlassianCrowd Data CenterCWE-287This High severity BASM (Broken Authentication & Session Management) vulnerab…
CVE-2026-758538.732.1ArcadeDataarcadedbCWE-862ArcadeDB Gremlin Wire Protocol Authorization Bypass Cross-Database
CVE-2026-626842.732.1filebrowserfilebrowserCWE-200File Browser: Share API exposes the password hash and bypass token
CVE-2026-624639.632.0Oracle CorporationOracle Hyperion Infrastructure Technology—Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-626198.831.9Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-608498.532.0Oracle CorporationOracle Unified Directory—Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middle…
CVE-2026-707228.231.9Oracle CorporationOracle Advanced Inbound TelephonyCWE-284Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Bu…
CVE-2026-609928.132.0Oracle CorporationOracle Identity Manager ConnectorCWE-284Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi…
CVE-2026-624778.132.0Oracle CorporationOracle Hyperion Infrastructure TechnologyCWE-284Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-624918.132.0Oracle CorporationOracle Purchasing—Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co…
CVE-2026-625028.132.0Oracle CorporationOracle Hyperion Infrastructure Technology—Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-707018.132.0Oracle CorporationOracle Payables—Vulnerability in the Oracle Payables product of Oracle E-Business Suite (comp…
CVE-2026-707628.132.0Oracle CorporationOracle Risk Management—Vulnerability in the Oracle Risk Management product of Oracle E-Business Suit…
CVE-2026-708118.132.0Oracle CorporationOracle PurchasingCWE-284Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co…
CVE-2026-708158.132.0Oracle CorporationOracle Internet Procurement ConnectorCWE-284Vulnerability in the Oracle Internet Procurement Connector product of Oracle …
CVE-2026-708358.132.0Oracle CorporationOracle iRecruitmentCWE-284Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (…
CVE-2026-708788.132.0Oracle CorporationOracle Hyperion Data Relationship ManagementCWE-284Vulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-708818.132.0Oracle CorporationOracle Hyperion Data Relationship ManagementCWE-284Vulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-709248.132.0Oracle CorporationOracle Web Services ManagerCWE-306Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Mid…
CVE-2026-716767.532.0n/an/aCWE-122Buffer Overflow vulnerability in Open5GS v.2.7.0 allows a remote attacker to …
CVE-2026-660468.731.9libexpat projectlibexpatCWE-407Expat Denial of Service via storeAtts() Quadratic Complexity
CVE-2026-758558.431.8ArcadeDataarcadedbCWE-22ArcadeDB before 26.8.1 Path Traversal via create/drop database
CVE-2026-625129.931.7Oracle CorporationSiebel CRM Cloud ApplicationsCWE-284Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-607678.831.7Oracle CorporationSiebel Apps - MarketingCWE-284Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (co…
CVE-2026-612848.831.7Oracle CorporationOracle Enterprise Manager Base PlatformCWE-284Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-613308.831.7Oracle CorporationSiebel CRM Cloud ApplicationsCWE-284Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-613418.831.7Oracle CorporationSiebel CRM Cloud ApplicationsCWE-284Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-709288.831.7Oracle CorporationOracle Hyperion Financial ManagementCWE-269Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-709408.831.7Oracle CorporationOracle Hyperion Financial ManagementCWE-306Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-709448.831.7Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-709488.831.7Oracle CorporationOracle PurchasingCWE-284Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co…
CVE-2026-709498.831.7Oracle CorporationSiebel CRM DeploymentCWE-284Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp…
CVE-2026-709668.831.7Oracle CorporationOracle Hyperion Infrastructure TechnologyCWE-284Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-710398.831.7Oracle CorporationOracle Agile PLMCWE-284Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone…
CVE-2026-710678.831.7Oracle CorporationOracle Agile PLM MCAD ConnectorCWE-306Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply…
CVE-2026-610669.931.6Oracle CorporationOracle Identity ManagerCWE-284Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-612489.931.6Oracle CorporationOracle Internet Directory—Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middl…
CVE-2026-612318.831.6Oracle CorporationOracle Virtual Directory—Vulnerability in the Oracle Virtual Directory product of Oracle Fusion Middle…
CVE-2026-760478.831.6GoogleChromeCWE-843Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remot…
CVE-2026-613328.731.5Oracle CorporationSiebel CRM Cloud ApplicationsCWE-284Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-760448.331.5GoogleChromeCWE-367Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remo…
CVE-2026-733419.831.4MetagaussRegistrationMagicCWE-502WordPress RegistrationMagic plugin <= 6.0.9.7 - PHP Object Injection vulnerab…
CVE-2026-733769.831.4supsysticUltimate Maps by SupsysticCWE-502WordPress Ultimate Maps by Supsystic plugin < 1.5.0 - PHP Object Injection vu…
CVE-2026-733979.831.4YouzifyYouzifyCWE-502WordPress Youzify plugin <= 1.3.7 - Deserialization of untrusted data vulnera…
CVE-2026-739378.231.4Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-706908.031.4Oracle CorporationOracle HRMS (US)—Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (com…
CVE-2026-708028.031.4Oracle CorporationOracle Public Sector Human Resources—Vulnerability in the Oracle Public Sector Human Resources product of Oracle E…
CVE-2026-716757.531.4n/an/aCWE-401An issue in Open5GS v.2.7.0 allows a remote attacker to cause a denial of ser…
CVE-2026-624756.631.4Oracle CorporationOracle Shipping ExecutionCWE-284Vulnerability in the Oracle Shipping Execution product of Oracle E-Business S…
CVE-2026-733967.131.3MakeWebBetterMWB HubSpot for WooCommerceCWE-288WordPress MWB HubSpot for WooCommerce plugin <= 1.6.7 - Broken Authentication…
CVE-2026-535336.931.3coleaiosmtplibCWE-77aiosmtplib: SMTP command injection via CR/LF in sender/recipient address
CVE-2026-706699.831.1Oracle CorporationOracle Reports Developer—Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middle…
CVE-2026-451189.331.1mybbmybbCWE-83MyBB: Contact page reflected XSS
CVE-2026-501619.331.2baresipreCWE-190libre: Integer overflow in websock_decode() masked frame length check leads t…
CVE-2026-749599.131.1MozillaFirefoxCWE-693Mitigation bypass in the Storage: Cache API component
CVE-2026-623578.831.1dragonflydbdragonflyCWE-190DragonflyDB `CMS.INITBYDIM` integer overflow leads to a remote, attacker-cont…
CVE-2026-731879.331.1gingerpluginsSticky Chat WidgetCWE-89WordPress Sticky Chat Widget plugin <= 1.4.2 - SQL Injection vulnerability
CVE-2026-733399.331.1Webnus Inc.Modern Events CalendarCWE-89WordPress Modern Events Calendar plugin < 7.35.0 - SQL Injection vulnerability
CVE-2026-733559.331.1wp.insiderAffiliates ManagerCWE-89WordPress Affiliates Manager plugin <= 2.9.53 - SQL Injection vulnerability
CVE-2026-733659.331.1Crocoblock. Jetimpex Inc.JetAppointmentCWE-89WordPress JetAppointment plugin <= 2.5.2 - SQL Injection vulnerability
CVE-2026-733929.331.1highwardenSuper Store FinderCWE-89WordPress Super Store Finder plugin <= 7.8 - SQL Injection vulnerability
CVE-2026-455328.730.9dataeasedataeaseCWE-22DataEase has a Path Traversal Vulnerability
CVE-2026-543478.730.9froxlorfroxlorCWE-79Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Accoun…
CVE-2026-626078.730.8Oracle CorporationOracle Customer Care—Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite …
CVE-2026-710854.930.8Oracle CorporationOracle Hyperion Financial ManagementCWE-200Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-612589.830.8Oracle CorporationOracle Internet DirectoryCWE-284Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middl…
CVE-2026-492218.830.7givanzVvvebCWE-639Vvveb digital asset authorization bypass allows Vendors to list, read, edit, …
CVE-2026-492288.830.7givanzVvvebCWE-639Vvveb product authorization bypass allows Vendors to read, duplicate, or dele…
CVE-2026-487987.130.8sshnetSSH.NETCWE-22SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-…
CVE-2026-739309.930.6Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-718807.630.7GBIFIntegrated Publishing ToolkitCWE-1336Server-side template injection in Integrated Publishing Toolkit
CVE-2026-608656.830.7Oracle CorporationService Delivery PlatformCWE-284Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-740447.030.5Wazuhwazuh-managerCWE-22Wazuh 4.0.0 < 4.14.6 Path Traversal Arbitrary Directory Deletion via Cluster …
CVE-2026-709789.130.4Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-710159.130.4Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-306Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-710269.130.4Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-738669.130.4Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-324727.530.4wbolt.comOnline Contact WidgetCWE-862WordPress Online Contact Widget plugin <= 1.3.0 - Broken Access Control vulne…
CVE-2026-325497.530.4Codexpert, IncThumbPressCWE-862WordPress ThumbPress plugin < 6.5 - Broken Access Control vulnerability
CVE-2026-603917.530.4Oracle CorporationOracle Hyperion Financial ReportingCWE-284Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-605907.530.4Oracle CorporationOracle Hospitality SimphonyCWE-284Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and B…
CVE-2026-609067.530.4Oracle CorporationOracle WebCenter ContentCWE-284Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-708967.530.4Oracle CorporationOracle Hyperion Data Relationship ManagementCWE-284Vulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-709107.530.4Oracle CorporationSiebel CRM IntegrationCWE-284Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com…
CVE-2026-709867.530.4Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-709877.530.4Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-710347.530.4Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience ManagerCWE-284Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-711077.530.5Oracle CorporationOracle Business Intelligence Enterprise EditionCWE-284Vulnerability in the Oracle Business Intelligence Enterprise Edition product …
CVE-2026-711427.530.4Oracle CorporationOracle Communications Unified Inventory ManagementCWE-284Vulnerability in the Oracle Communications Unified Inventory Management produ…
CVE-2026-711587.530.4Oracle CorporationHelidonCWE-284Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-534558.630.4ha-chinablueprint-studioCWE-78Blueprint Studio Git credential helper command injection
CVE-2026-625018.130.3Oracle CorporationOracle Hyperion Infrastructure Technology—Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-625318.130.3Oracle CorporationOracle Hyperion Infrastructure Technology—Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-707448.130.3Oracle CorporationOracle Hyperion Financial Reporting—Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-707498.130.3Oracle CorporationOracle Hyperion Financial Reporting—Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-708688.130.3Oracle CorporationOracle Application Testing SuiteCWE-284Vulnerability in Oracle Application Testing Suite. The supported version that…
CVE-2026-710688.130.3Oracle CorporationOracle Agile PLM MCAD ConnectorCWE-306Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply…
CVE-2026-527316.530.3ZcashFoundationzebraCWE-248ZEBRA: Full node denial of service via non-ASCII LongPollId in getblocktemplate
CVE-2026-324709.830.2RoxnorFundEngineCWE-502WordPress FundEngine plugin <= 1.7.9 - PHP Object Injection vulnerability
CVE-2026-524817.530.2n/an/aCWE-200An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote att…
CVE-2026-610299.030.1Oracle CorporationOracle WebCenter SitesCWE-284Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-547308.630.1goauthentikauthentikCWE-284authentik: Authentication Flow Bypass via Unguarded challenge_valid() in Auth…
CVE-2026-707708.330.1Oracle CorporationOracle Warehouse ManagementCWE-284Vulnerability in the Oracle Warehouse Management product of Oracle E-Business…
CVE-2026-625958.130.2Oracle CorporationSiebel CRM IntegrationCWE-284Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (com…
CVE-2026-610118.230.0Oracle CorporationOracle WebCenter SitesCWE-284Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-610168.230.0Oracle CorporationOracle WebCenter SitesCWE-284Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-612658.130.0Oracle CorporationJD Edwards EnterpriseOne OrchestratorCWE-284Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle …
CVE-2026-155857.530.0AKIN Software Computer Import Export Industry and Trade Ltd.AKINSOFT Wolvox9 ERP / KontrolPanel.exeCWE-22Path Traversal in AKIN Software's Wolvox9 ERP
CVE-2026-439716.329.9nineninescowlibCWE-116Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in co…
CVE-2026-735025.329.9getkinkin-openapiCWE-476kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating…
CVE-2026-624677.729.8Oracle CorporationOracle Hyperion Infrastructure Technology—Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-625717.729.8Oracle CorporationOracle Hyperion Calculation Manager—Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hy…
CVE-2026-707717.729.8Oracle CorporationOracle Warehouse ManagementCWE-284Vulnerability in the Oracle Warehouse Management product of Oracle E-Business…
CVE-2026-708277.729.8Oracle CorporationOracle MES for Process Manufacturing—Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E…
CVE-2026-708287.729.8Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-527386.929.8ZcashFoundationzebraCWE-248ZEBRA: Finalized address balance credit-first overflow on consensus-valid blocks
CVE-2026-625066.529.8Oracle CorporationOracle Hyperion Infrastructure Technology—Vulnerability in the Oracle Hyperion Infrastructure Technology product of Ora…
CVE-2026-707206.529.8Oracle CorporationOracle Production Scheduling—Vulnerability in the Oracle Production Scheduling product of Oracle E-Busines…
CVE-2026-707676.529.8Oracle CorporationOracle Hyperion Financial Reporting—Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hy…
CVE-2026-708266.529.8Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-708316.529.8Oracle CorporationOracle Hyperion Financial ManagementCWE-284Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-527325.329.8ZcashFoundationzebraCWE-770ZEBRA: Mempool transaction admission denial via single-peer inbound queue sat…
CVE-2026-527345.329.8ZcashFoundationzebraCWE-401ZEBRA: Unbounded memory leak in mempool download pipeline via timeout path ca…
CVE-2026-758569.229.7HmbownCodeWhaleCWE-918CodeWhale before 0.8.64 SSRF Bypass via DNS Pinning TOCTOU
CVE-2026-609567.529.8Oracle CorporationJD Edwards EnterpriseOne US PayrollCWE-284Vulnerability in the JD Edwards EnterpriseOne US Payroll product of Oracle JD…
CVE-2026-707137.529.8Oracle CorporationOracle iSetup—Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (compon…
CVE-2026-708297.529.8Oracle CorporationOracle Process Manufacturing SystemsCWE-284Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E…
CVE-2026-666207.229.7Derek HermanOptionTreeCWE-502WordPress OptionTree plugin <= 2.7.3 - PHP Object Injection vulnerability

Results continue: ranks 401–1407.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-18 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.