boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Wednesday, August 19, 2026 · all times UTC← 2026-08-18 · archive · 2026-08-20 →

Security Box Score — August 19, 2026 — page 2

Edition of August 19, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–673 of 673
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-763327.115.7SplunkSplunk EnterpriseCWE-20SPL Injection through Splunk Web in Splunk Enterprise
CVE-2026-117519.115.4LY CorporationArmeria—A vulnerability has been identified in armeria-xds versions prior to 1.41.0, …
CVE-2026-763518.815.5SplunkSplunk EnterpriseCWE-918Server-Side Request Forgery (SSRF) through the Report Notification REST API i…
CVE-2026-733847.515.5cmsMindsPay with Contact Form 7CWE-201WordPress Pay with Contact Form 7 plugin <= 1.0.4 - Sensitive Data Exposure v…
CVE-2026-733867.515.5ZealousWebTrack Geolocation Of Users Using Contact Form 7CWE-201WordPress Track Geolocation Of Users Using Contact Form 7 plugin <= 3.0.2 - S…
CVE-2026-759817.215.5cozmoslabsTranslatePress – Translate Multilingual sites with AI TranslationCWE-79TranslatePress – Translate Multilingual sites with AI Translation <= 3.2.5 - …
CVE-2026-762156.915.3thorstenphpMyFAQCWE-862phpMyFAQ before 4.1.7 Missing Authorization via child resources
CVE-2026-626706.315.3getgravgrav-plugin-flex-objectsCWE-862Fail-open authorization in grav-plugin-flex-objects admin-next API: api.acces…
CVE-2026-763265.715.4SplunkSplunk EnterpriseCWE-79Stored Cross-Site Scripting through Dashboard Sparkline Tooltip Options in Sp…
CVE-2026-405075.115.3openemropenemrCWE-79OpenEMR < 8.3.0 Reflected XSS via templateHtml Parameter in Patient Portal
CVE-2026-51367await15.3n/an/a—An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacke…
CVE-2026-733919.315.0KlbThemeTotal DonationsCWE-89WordPress Total Donations plugin <= 2.0.5 - SQL Injection vulnerability
CVE-2026-544917.114.9koelkoelCWE-918Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fe…
CVE-2026-154466.415.0nosilver4uEWWW Image OptimizerCWE-79EWWW Image Optimizer <= 8.7.3 - Authenticated (Contributor+) Stored Cross-Sit…
CVE-2026-763367.114.8SplunkSplunk EnterpriseCWE-862Improper Access Control through the REST API in Splunk Enterprise
CVE-2026-188496.814.9IBMOPENBMCCWE-22IBM OpenBMC Code Execution
CVE-2026-738296.314.9ZenHivemppCWE-367Non-atomic hash-credential dedup in mpp Tempo allows replay of a confirmed pa…
CVE-2026-191988.714.6AkauntingAkauntingCWE-863Akaunting 3.1.21 - Improper authorization in BulkActions handle dispatch
CVE-2026-556947.114.6grokabilitysnipe-itCWE-639Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Tak…
CVE-2026-731839.314.4Get Maps Marker ProMaps Marker ProCWE-89WordPress Maps Marker Pro plugin <= 4.32 - SQL Injection vulnerability
CVE-2026-731859.314.4wpo-HRNGG Smart Image SearchCWE-89WordPress NGG Smart Image Search plugin < 4.0.0 - SQL Injection vulnerability
CVE-2026-733889.314.4TeconceThemeNikstore CoreCWE-89WordPress Nikstore Core plugin <= 1.5 - SQL Injection vulnerability
CVE-2026-115658.514.2UnknownAdvanced File Manager—Advanced File Manager < 5.4.13 - Authenticated Arbitrary File Read and Write …
CVE-2026-763967.514.2SplunkSplunk AI ToolkitCWE-269Improper Access Control through Scheduled Searches in Splunk AI Toolkit
CVE-2026-164405.714.1Eclipse FoundationEclipse OpenJ9CWE-674In Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deeply nest…
CVE-2026-160585.314.2UnknownYayCurrencyCWE-639YayCurrency < 3.3.5 - Unauthenticated Order and Vendor Financial Data Disclos…
CVE-2026-150788.114.1IBMAIXCWE-295Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-763237.313.7SplunkSplunk EnterpriseCWE-20SPL Risky Command Safeguards Bypass through the Job Details Dashboard in Splu…
CVE-2026-763483.813.8SplunkSplunk EnterpriseCWE-862Missing Authorization in Search Head Cluster Member Controls in Splunk Enterp…
CVE-2026-762058.613.6thorstenphpMyFAQCWE-89phpMyFAQ before 4.1.7 SQL Injection via Glossary
CVE-2026-763318.113.6SplunkSplunk EnterpriseCWE-943SPL Injection through the REST API in Splunk Enterprise
CVE-2026-194062.713.6UnknownEasy AppointmentsCWE-200Easy Appointments < 4.0.1 - Contributor+ Sensitive Information Disclosure via…
CVE-2026-762564.313.5SplunkSplunk EnterpriseCWE-200Information Exposure through REST API Endpoints in Splunk Secure Gateway
CVE-2026-168359.613.3IBMPower Systems FirmwareCWE-295Power System Improper Certificate Validation
CVE-2026-768276.813.2Red HatRed Hat Advanced Cluster Management for Kubernetes 2CWE-693Search-indexer: search-indexer: update/delete operations not scoped to caller…
CVE-2026-763415.413.2SplunkSplunk EnterpriseCWE-863Risky Commands Safeguards Bypass through Table Editor Dataset Initial Data in…
CVE-2026-762348.712.8celabshqlibcrux-ecdhCWE-347libcrux before 0.0.6 Cryptographic Implementation Bug Fixes
CVE-2026-181023.512.9IBMiCWE-122IBM i Buffer Overflow
CVE-2026-19507await12.6RDKRDK-B WebUI—RDK WebUI uncontrolled resource consumption
CVE-2026-762557.312.6SplunkSplunk EnterpriseCWE-862Risky Command Safeguards Bypass through Splunk Web in Splunk Enterprise
CVE-2026-187775.312.4UnknownTrueBookerCWE-862TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Arbitrary Appointmen…
CVE-2026-187795.312.4UnknownTrueBookerCWE-862TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Appointment and Paym…
CVE-2026-19506await12.4RDKRDK-B WebUI—RDK-B WebUI race condition vulnerability
CVE-2026-494158.812.3FreeBSDFreeBSDCWE-367Local privilege escalation via execve(2) TOCTOU race
CVE-2026-125228.812.1zephyrprojectzephyrCWE-787Stack buffer overflow in Zephyr hl7800 modem driver parsing network-supplied …
CVE-2026-762635.412.1SplunkSplunk EnterpriseCWE-639Improper Access Control through the REST API in Splunk Enterprise
CVE-2026-148262.712.0UnknownQuiz and Survey Master (QSM)CWE-639Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Email and Results C…
CVE-2026-763612.712.0SplunkSplunk SOARCWE-918Server-Side Request Forgery (SSRF) through the Connectivity Check REST API in…
CVE-2026-763682.712.0SplunkSplunk SOARCWE-862Missing Authorization through Playbooks in Splunk SOAR
CVE-2026-756196.912.0TP-Link Systems Inc.Tapo C100 v5CWE-122RTSP Heap Buffer Overflow Denial-of-Service Vulnerability on TP-Link Tapo C10…
CVE-2026-762449.111.9eidetic-labsstigmemCWE-319stigmem-node Insecure Federation Transport Configuration
CVE-2026-763245.411.8SplunkSplunk EnterpriseCWE-79Stored Cross-Site Scripting (XSS) in Splunk Web Tours in Splunk Enterprise
CVE-2026-763094.311.8SplunkSplunk EnterpriseCWE-89Structured Query Language (SQL) Injection through the REST API in Splunk Ente…
CVE-2026-762095.311.7thorstenphpMyFAQCWE-862phpMyFAQ before v4.1.6 Registration Bypass via API
CVE-2026-763755.011.6SplunkAD LDAP app for Splunk SOARCWE-532Information Disclosure through Environment Data Logging in AD LDAP app for Sp…
CVE-2026-763744.311.6SplunkAD LDAP app for Splunk SOARCWE-532Information Disclosure through Sensitive Data Logging in AD LDAP app for Splu…
CVE-2026-126338.111.6zephyrprojectzephyrCWE-787Out-of-bounds write in IPv6 6LoWPAN Context Option handling via unauthenticat…
CVE-2026-762266.811.6renovatebotrenovateCWE-78Renovate 43.65.0 through 43.102.11 Remote Code Execution via lockFileMaintenance
CVE-2026-763425.411.5SplunkSplunk EnterpriseCWE-863Risky Commands Safeguards Bypass through Splunk Web in Splunk Enterprise
CVE-2026-58081await11.5FreeBSDFreeBSDCWE-122Heap based buffer overflow in iconv(3)
CVE-2026-58082await11.6FreeBSDFreeBSDCWE-121Stack based buffer overflow in iconv(3)
CVE-2026-762616.511.3SplunkSplunk EnterpriseCWE-732Insecure Default Access Control List through the REST API in Splunk Secure Ga…
CVE-2026-555195.411.3grokabilitysnipe-itCWE-285Snipe-IT: Improper Authorization in File Deletion (IDOR)
CVE-2026-762517.111.2SplunkSplunk EnterpriseCWE-862Missing Authorization through REST API Endpoints in the Splunk App for Splunk…
CVE-2026-168466.511.3IBMAIXCWE-476Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-763496.411.3SplunkSplunk EnterpriseCWE-943SPL Injection through Splunk Web Form Tokens in Splunk Enterprise
CVE-2026-184665.410.9UnknownWP MapsCWE-284WP Maps < 4.9.8 - Subscriber+ Unlimited Autoloaded Option Creation
CVE-2026-763475.410.9SplunkSplunk EnterpriseCWE-918Server-Side Request Forgery (SSRF) through the Report Notifications REST API …
CVE-2026-763286.710.9SplunkSplunk EnterpriseCWE-77SPL Injection through Splunk Web in Splunk Enterprise
CVE-2026-616074.610.8getgravgrav-plugin-apiCWE-79Grav API Plugin: Stored XSS via SVG Upload - API Media Pipeline Bypasses Sani…
CVE-2026-166879.610.7IBMPower Systems FirmwareCWE-121Power System Buffer Overflow
CVE-2026-763276.410.7SplunkSplunk EnterpriseCWE-943SPL Injection through Splunk Web in Splunk Secure Gateway
CVE-2026-763206.510.6SplunkSplunk EnterpriseCWE-943SPL Injection through Cross-Site Request Forgery (CSRF) in the Event Type Bui…
CVE-2026-763604.310.5SplunkSplunk SOARCWE-862Information Disclosure through Missing Authorization in the Health REST API i…
CVE-2026-763704.310.5SplunkSplunk SOARCWE-863Information Disclosure through the REST API in Splunk SOAR
CVE-2026-203276.510.4CiscoCisco Unified Intelligence CenterCWE-89Cisco Unified Intelligence Center SQL Injection Vulnerability
CVE-2026-202325.410.4CiscoCisco Industrial Ethernet SwitchesCWE-80Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vu…
CVE-2026-131732.710.4UnknownEventinCWE-862Eventin < 4.1.21 - Contributor+ User Role and Meta Modification via Speaker C…
CVE-2026-148252.710.4UnknownQuiz and Survey Master (QSM)CWE-639Quiz And Survey Master < 11.2.4 - Contributor+ Arbitrary Quiz Text Settings U…
CVE-2026-763712.710.4SplunkFireAMPCWE-732Incorrect Permission Assignment through Safe Mode in FireAMP for Splunk SOAR
CVE-2026-762115.310.3thorstenphpMyFAQCWE-862phpMyFAQ before 4.1.7 Information Disclosure via Admin API
CVE-2026-755832.310.3ridafkihkeeper.shCWE-918keeper.sh Calendar version prior to 2.18.14 SSRF Guard Bypass via DNS Rebinding
CVE-2026-733857.510.0Outanking TeamOutranking Plugin OptionsCWE-862WordPress Outranking plugin Options plugin <= 1.1.3 - Broken Access Control v…
CVE-2026-733947.510.0StitchexpressStitch ExpressCWE-862WordPress Stitch Express plugin <= 1.9.0 - Broken Access Control vulnerability
CVE-2026-168517.410.0IBMAIXCWE-416Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-49430await10.0FreeBSDFreeBSDCWE-122Kernel heap overflow in ZFS_IOC_RECV_NEW ioctl
CVE-2026-186816.89.8IBMServer FirmwareCWE-121This Power System Buffer Overflow
CVE-2026-198428.89.7UnknownSAML Single Sign OnCWE-287SAML Single Sign On 4.8.85 - 5.4.6 - Unauthenticated Administrator Account Ta…
CVE-2026-175657.29.8UnknownAnimation Addons for ElementorCWE-918Animation Addons for Elementor < 2.7.2 - Unauthenticated Server-Side Request …
CVE-2026-547947.29.8DellOpenManage EnterpriseCWE-918Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side R…
CVE-2026-19505await9.8RDKRDK-B WebUI—RDK-B WebUI improper cryptographic signature verification vulnerability
CVE-2026-168229.39.7IBMAIXCWE-295Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-487117.09.7libfusesshfsCWE-88SSHFS: Improper Neutralization of Argument Delimiters in a Command ('Argument…
CVE-2026-168494.39.7IBMAIXCWE-129Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-168864.39.7IBMAIXCWE-787Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-145146.59.4IBMReliable Scalable Cluster Technology (RSCT)CWE-770Reliable Scalable Cluster Technology Denial-of-Service
CVE-2026-169794.39.4UnknownSmartCrawl SEO checker, analyzer & optimizerCWE-639SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Disclosure and Pos…
CVE-2026-763296.49.2SplunkSplunk EnterpriseCWE-943SPL Injection through Monitoring Console Dashboard Inputs in Splunk Enterprise
CVE-2026-764037.48.9SplunkSplunk Connect for KafkaCWE-295Improper Certificate Validation through HTTP Event Collector Kerberos Authent…
CVE-2026-756187.18.9TP-Link Systems Inc.Tapo C100 v5CWE-476RTSP Null Pointer Dereference Denial-of-Service Vulnerability on TP-Link Tapo…
CVE-2026-170286.59.0IBMPowerVM HypervisorCWE-125Power System Out-of-bounds Read
CVE-2026-631236.59.0tinacmstinacmsCWE-352Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files …
CVE-2026-763185.48.9SplunkSplunk EnterpriseCWE-79Stored Cross-Site Scripting (XSS) through Splunk Web in Splunk Enterprise
CVE-2026-557034.39.0grokabilitysnipe-itCWE-862Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GET
CVE-2026-188217.58.7IBMPowerVM HypervisorCWE-787Power System Out-of-bounds Write
CVE-2026-554826.38.8grokabilitysnipe-itCWE-639Snipe-IT: Multi-Tenancy Bypass via Bulk Asset Update
CVE-2026-493925.38.7wazuhwazuhCWE-20Wazuh: Local SQL injection in FIM db due to path lookup interpolation in wazu…
CVE-2026-168328.48.6IBMPower Systems FirmwareCWE-121Power System Buffer Overflow
CVE-2026-194164.38.6UnknownKiviCareCWE-639KiviCare < 4.5.4 - Patient+ Cross-Patient Appointment Modification via IDOR
CVE-2026-763465.48.4SplunkSplunk EnterpriseCWE-79Stored Cross-Site Scripting (XSS) through Splunk Web Dashboard Sparkline Form…
CVE-2026-116173.18.3TaniumFindingsCWE-409Tanium addressed a compression bomb vulnerability in Findings.
CVE-2026-754763.18.3TaniumThreat ResponseCWE-409Tanium addressed a compression bomb vulnerability in Threat Response.
CVE-2026-627277.08.2MicrosoftWindows 10 Version 1607CWE-362Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-174148.18.1IBMPowerVM HypervisorCWE-20Power System Improper Input Validation
CVE-2026-141964.38.1UnknownWCFM MarketplaceCWE-639WCFM Marketplace < 3.8.1 - Store Vendor+ Cross-Vendor Review Deletion and Sta…
CVE-2026-763984.38.1SplunkSplunk AI ToolkitCWE-862Improper Access Control during Experiment History Deletion through the REST A…
CVE-2026-203026.18.0CiscoCisco RoomOS SoftwareCWE-120Cisco RoomOS Stack Overflow Vulnerability
CVE-2026-762526.17.9SplunkSplunk EnterpriseCWE-79Cross-Site Scripting (XSS) through Splunk Web Message Validation in Splunk En…
CVE-2026-75589await8.0—Net-OAuthCWE-208Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLA…
CVE-2026-762457.17.9eidetic-labsstigmemCWE-345stigmem Federation Peer Token Timestamp Validation Bypass
CVE-2025-363985.47.8IBMDS8A00 (R10.0 - R10.1)CWE-73DS8900F and DS8A00 Information Disclosure
CVE-2026-197825.47.8UnknownWPS BidouilleCWE-200WPS Bidouille < 1.33.5 - Subscriber+ User Email Disclosure via wps_get_users
CVE-2026-763735.47.8SplunkAD LDAP app for Splunk SOARCWE-90Filter Injection through Action Parameters in AD LDAP app for Splunk SOAR
CVE-2026-168295.37.7IBMAIXCWE-476Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-165707.17.5UnknownNextScripts: Social Networks Auto-PosterCWE-79NextScripts: Social Networks Auto-Poster < 4.4.8 - Reflected XSS via Facebook…
CVE-2026-190557.17.5UnknownProSolution WP ClientCWE-79ProSolution WP Client < 2.0.11 - Reflected XSS via Multiple Parameters
CVE-2026-190567.17.5UnknownProSolution WP ClientCWE-79ProSolution WP Client < 2.0.11 - Reflected XSS via 'page' Parameter
CVE-2026-763395.47.6SplunkSplunk EnterpriseCWE-77SPL Injection through the geostats Command in Splunk Enterprise
CVE-2026-763627.47.4SplunkSplunk SOARCWE-295Improper Certificate Validation through CyberArk Vault Privileged Access Mana…
CVE-2026-769263.17.4Wireshark FoundationWiresharkCWE-617Reachable Assertion in Wireshark
CVE-2026-49431await7.3FreeBSDFreeBSDCWE-863Incorrect user validation in ZFS_IOC_SET_PROP ioctl
CVE-2026-505505.87.2grokabilitysnipe-itCWE-863Snipe-IT: 2FA reset privilege bypass
CVE-2026-768843.16.9Wireshark FoundationWiresharkCWE-126Buffer Over-read in Wireshark
CVE-2026-768853.16.9Wireshark FoundationWiresharkCWE-126Buffer Over-read in Wireshark
CVE-2026-768873.16.9Wireshark FoundationWiresharkCWE-122Heap-based Buffer Overflow in Wireshark
CVE-2026-768883.16.9Wireshark FoundationWiresharkCWE-122Heap-based Buffer Overflow in Wireshark
CVE-2026-768903.16.9Wireshark FoundationWiresharkCWE-825Expired Pointer Dereference in Wireshark
CVE-2026-768913.16.9Wireshark FoundationWiresharkCWE-825Expired Pointer Dereference in Wireshark
CVE-2026-168287.66.9IBMPower Systems FirmwareCWE-125Power System Out-of-bounds Read
CVE-2026-733636.56.9magepeopleteamTaxi Booking Manager for WooCommerceCWE-862WordPress Taxi Booking Manager for WooCommerce plugin < 2.0.8 - Broken Access…
CVE-2026-405085.16.6openemropenemrCWE-79OpenEMR < 8.3.0 Stored XSS via Patient Portal Template Import Handler
CVE-2026-167244.56.4IBMVirtualization Management InterfaceCWE-190Power System Integer Overflow
CVE-2026-763925.46.2SplunkSplunk AI ToolkitCWE-798Use of Hard-coded Credentials in Container Connections in Splunk AI Toolkit
CVE-2026-663585.16.3Extra Innovation Inc.acmailer CGICWE-79A cross-site scripting vulnerability exists in acmailer, which may allow an a…
CVE-2026-142874.76.0Unknown10Web BoosterCWE-79TenWeb Speed Optimizer < 2.33.5 - Unauthenticated Stored XSS via Critical CSS…
CVE-2026-494297.85.9FreeBSDFreeBSDCWE-122Kernel heap overflow in ZFS_IOC_USERSPACE_MANY ioctl
CVE-2026-547935.45.9DellOpenManage EnterpriseCWE-79Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neu…
CVE-2026-76647await5.9LeantimeJSON-RPC API—Leantime JSON-RPC API contains a missing authorization vulnerability
CVE-2026-168757.85.7IBMAIXCWE-78Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2024-139427.65.7RockchipRK3588sCWE-367Rockchip RK3588s Secure BootROM TOCTOU (time-of-check to time-of-use) vulnera…
CVE-2026-759179.35.6siyuan-notesiyuanCWE-79SiYuan before v3.7.4 XSS-to-RCE via pathName.ts
CVE-2026-19509await5.6RDKRDK-B WebUI—RDK WebUI DOS vulnerability
CVE-2026-759169.35.2siyuan-notesiyuanCWE-79SiYuan XSS-to-RCE via unescaped block metadata in hint popup
CVE-2026-439617.85.2vimvimCWE-94Vim: vimscript injection via unescaped filename in netrw s:netrwmarkfile() fi…
CVE-2026-759524.65.3cmsjunkie.comJ-BusinessDirectory extension for JoomlaCWE-352Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDi…
CVE-2026-2230610.04.8Ozols GrupaOZOLSCWE-319Critical flaw impacting OZOLS ERP's automatic update channel
CVE-2026-763834.34.6SplunkRSA SecurID Authentication Manager app for Splunk SOARCWE-312Information Disclosure through Action Parameters in RSA SecurID Authenticatio…
CVE-2026-751486.94.6jkuhlmanncgltfCWE-190cgltf 1.15 Integer Overflow via cgltf_validate() Accessor Bounds Check
CVE-2026-763674.04.4SplunkSplunk SOARCWE-79Stored Cross-Site Scripting (XSS) through Notes in Splunk SOAR
CVE-2026-49423await4.4FreeBSDFreeBSDCWE-908Remote DOS via uninitialized memory access in KTLS receive
CVE-2026-49424await4.4FreeBSDFreeBSDCWE-908Kernel stack disclosure in Linux compatibility layer
CVE-2026-49425await4.4FreeBSDFreeBSDCWE-908Kernel stack disclosure in 32-bit compatibility support
CVE-2026-49426await4.4FreeBSDFreeBSDCWE-223Incorrect audit records for ptrace(2) syscall requests
CVE-2026-50719await4.4n/an/a—The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and e…
CVE-2026-50720await4.4n/an/a—The Ingenic T31 SoC boot ROM flash-boot verification path compares only a sin…
CVE-2026-75953await4.4cmsjunkie.comJ-BusinessDirectory extension for JoomlaCWE-201Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6…
CVE-2026-501496.54.2projectcontourcontourCWE-295Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts w…
CVE-2026-619867.14.1Wasiliy StreckerContest GalleryCWE-79WordPress Contest Gallery plugin <= 30.0.5 - Cross Site Scripting (XSS) vulne…
CVE-2026-665967.14.1Stefano LissaNewsletterCWE-79WordPress Newsletter plugin <= 9.3.3 - Cross Site Scripting (XSS) vulnerability
CVE-2026-731827.14.1Jeff StarrBBQ ProCWE-79WordPress BBQ Pro plugin <= 3.9 - Cross Site Scripting (XSS) vulnerability
CVE-2026-731847.14.1LCwebGlobal GalleryCWE-79WordPress Global Gallery plugin <= 11.1.2 - Cross Site Scripting (XSS) vulner…
CVE-2026-733547.14.1ReichertBrothersSimplyRETS Real Estate IDXCWE-79WordPress SimplyRETS Real Estate IDX plugin <= 3.2.8 - Cross Site Scripting (…
CVE-2026-763784.34.0SplunkCisco Secure Malware Analytics app for Splunk SOARCWE-312Information Disclosure through Action Parameters in Cisco Secure Malware Anal…
CVE-2026-763794.34.0SplunkCisco Webex app for Splunk SOARCWE-312Information Disclosure through Action Parameters in Cisco Webex app for Splun…
CVE-2026-58084await3.9FreeBSDFreeBSDCWE-908Kernel stack disclosure via timer_settime(2)
CVE-2026-58085await3.7FreeBSDFreeBSDCWE-347Missing MAC validation in wg(4) packet decryption
CVE-2026-58086await3.7FreeBSDFreeBSDCWE-273ktrace(2) privilege incorrectly validated in jails
CVE-2026-763764.33.5SplunkAWS IAM app for Splunk SOARCWE-312Information Disclosure through Action Parameters in AWS IAM app for Splunk SOAR
CVE-2026-763774.33.5SplunkAzure AD Graph app for Splunk SOARCWE-312Information Disclosure through Action Parameters in Azure AD Graph app for Sp…
CVE-2026-763804.33.5SplunkCrowdStrike OAuth API app for Splunk SOARCWE-312Information Disclosure through Action Parameters in CrowdStrike OAuth API app…
CVE-2026-763814.33.5SplunkMS Graph for Active Directory app for Splunk SOARCWE-312Information Disclosure through Action Parameters in MS Graph for Active Direc…
CVE-2026-763824.33.5SplunkPhantom app for Splunk SOARCWE-312Information Disclosure through Action Parameters in Phantom app for Splunk SOAR
CVE-2026-763844.33.5SplunkSplunk Attack Analyzer Connector for Splunk SOARCWE-312Information Disclosure through Action Parameters in Splunk Attack Analyzer Co…
CVE-2026-763864.33.5SplunkZoom app for Splunk SOARCWE-312Information Disclosure through Action Parameters in Zoom app for Splunk SOAR
CVE-2026-764054.33.5SplunkSplunk On-Call (VictorOps)CWE-312Information Disclosure through Cleartext Storage in the App Key Value Store i…
CVE-2026-169386.93.4IBMPower Systems FirmwareCWE-862Power System Missing Authorization
CVE-2026-751418.53.3FFmpegFFmpegCWE-122FFmpeg Heap Buffer Overflow in hvcC Box Writer via HEVC Muxing
CVE-2026-751428.53.3FFmpegFFmpegCWE-121FFmpeg Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c
CVE-2026-751448.53.3FFmpegFFmpegCWE-122FFmpeg Heap Buffer Overflow in VC-2/Dirac RTP Packetizer
CVE-2026-169146.73.3IBMAIXCWE-787Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-72889await3.3—Net-OAuthCWE-347Net::OAuth versions before 0.33 for Perl allow the sender to choose the signa…
CVE-2026-763935.93.3SplunkSplunk AI ToolkitCWE-362Race Condition during Model Upload through the REST API in Splunk AI Toolkit
CVE-2026-626715.43.2getgravgrav-plugin-loginCWE-352CSRF in grav-plugin-login: anonymous attacker rotates a logged-in user's 2FA …
CVE-2026-166618.23.0IBMPowerVM HypervisorCWE-190Power System Integer Overflow
CVE-2026-167078.23.0IBMPowerVM HypervisorCWE-125Power System Out-of-bounds Read
CVE-2026-49421await3.0FreeBSDFreeBSDCWE-273unlinkat(2) ignores AT_RESOLVE_BENEATH flag
CVE-2026-685542.32.9coturncoturnCWE-345Coturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-pat…
CVE-2026-528347.32.9tirr-cjxl-oxideCWE-122jxl-oxide: Out-of-bounds writes due to integer overflow in jxl-grid on 32-bit…
CVE-2026-762597.82.7SplunkSplunk EnterpriseCWE-269Improper Privilege Management on the Management Port in Splunk Enterprise for…
CVE-2026-405095.32.6openemropenemrCWE-352OpenEMR < 8.3.0 CSRF via DICOM Viewer web_path Parameter
CVE-2026-168747.82.6IBMAIXCWE-269Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-494228.42.5FreeBSDFreeBSDCWE-416Use-after-free in TCP RACK stack option handler
CVE-2026-763346.42.5SplunkSplunk EnterpriseCWE-352SPL Injection through Dashboard Studio Workflow Actions in Splunk Enterprise
CVE-2026-168697.82.4IBMAIXCWE-426Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-580838.42.3FreeBSDFreeBSDCWE-416Use-after-free in kqueue copy-on-fork
CVE-2026-169338.22.3IBMPower Systems FirmwareCWE-190Power System Integer Overflow
CVE-2026-192348.22.3IBMPower Systems FirmwareCWE-121Power System Buffer Overflow
CVE-2026-567966.62.3DellDell Command Update (DCU)CWE-59Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link …
CVE-2026-656102.42.3nnnnnnCWE-197Numeric Truncation Error in nnn
CVE-2026-550864.22.2etheretherpadCWE-59Etherpad: Import/export use Math.random() for temp file paths; predictable pa…
CVE-2026-580877.82.1FreeBSDFreeBSDCWE-125Heap out-of-bounds access in semctl(2)
CVE-2026-751476.92.1FFmpegFFmpegCWE-125FFmpeg Out-of-Bounds Read in AV1 RTP Packetizer via rtpenc_av1.c
CVE-2026-149785.52.1HashiCorpgo-slugCWE-176Unicode normalization mismatch in go-slug ignore pattern matching may bypass …
CVE-2026-760141.92.1n/aBusyBoxCWE-404BusyBox FEATURE_WGET_TIMEOUT wget.c null pointer dereference
CVE-2026-168737.82.0IBMAIXCWE-787Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-498177.82.1DellDell Command Update (DCU)CWE-502Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization…
CVE-2026-169308.21.9IBMPower Systems FirmwareCWE-862Power System Missing Authorization
CVE-2026-769215.51.9Wireshark FoundationWiresharkCWE-416Use After Free in Wireshark
CVE-2026-170637.91.8IBMPower Systems FirmwareCWE-863Power System Incorrect Authorization
CVE-2026-751455.81.8FFmpegFFmpegCWE-681FFmpeg Integer Narrowing Conversion OOB Memory Access in AV1 RTP Packetizer
CVE-2026-170918.41.8IBMPowerVM HypervisorCWE-190Power System Integer Overflow
CVE-2026-762276.81.7renovatebotrenovateCWE-526Renovate 42.68.1 before 42.96.3 Environment Variable Exposure
CVE-2026-170938.21.7IBMPower Systems FirmwareCWE-121Power System Buffer Overflow
CVE-2026-171008.21.7IBMPower Systems FirmwareCWE-787Power System Out-of-bounds Write
CVE-2026-174948.21.7IBMPower Systems FirmwareCWE-121Power System Buffer Overflow
CVE-2026-656092.41.7nnnnnnCWE-787Out-of-bounds write in nnn
CVE-2026-168835.51.7IBMAIXCWE-125Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-751126.91.6Rockwell AutomationOTTO® Fleet ManagerCWE-916OTTO® Fleet Manager – Weak Password Hashing Configuration
CVE-2026-498167.81.5DellDell Command Update (DCU)CWE-502Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization…
CVE-2026-168974.41.5IBMAIXCWE-369Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-759006.11.5Red HatRed Hat Enterprise Linux 10CWE-125Swtpm: swtpm: out-of-bounds read in swtpm_nvram_checkheader due to sizeof(poi…
CVE-2026-170977.31.4IBMPowerVM HypervisorCWE-129Power System Improper Validation
CVE-2026-188717.31.4IBMPowerVM HypervisorCWE-121Power System Buffer Overflow
CVE-2026-193216.71.3IBMPower Systems FirmwareCWE-190Power System Integer Overflow
CVE-2026-769245.51.3Wireshark FoundationWiresharkCWE-125Out-of-bounds Read in Wireshark
CVE-2026-580887.41.2FreeBSDFreeBSDCWE-362Race condition in ELF core dump segment counting
CVE-2026-168913.31.2IBMAIXCWE-125Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-170427.31.2IBMPower Systems FirmwareCWE-125Power System Out-of-bounds Read
CVE-2026-769175.51.2Wireshark FoundationWiresharkCWE-122Heap-based Buffer Overflow in Wireshark
CVE-2026-769185.51.2Wireshark FoundationWiresharkCWE-122Heap-based Buffer Overflow in Wireshark
CVE-2026-769225.51.2Wireshark FoundationWiresharkCWE-476NULL Pointer Dereference in Wireshark
CVE-2026-769235.51.2Wireshark FoundationWiresharkCWE-125Out-of-bounds Read in Wireshark
CVE-2026-126345.31.2zephyrprojectzephyrCWE-787Out-of-bounds stack write in the settings NVS backend from over-reported nvs_…
CVE-2026-768814.71.2Wireshark FoundationWiresharkCWE-476NULL Pointer Dereference in Wireshark
CVE-2026-768824.71.2Wireshark FoundationWiresharkCWE-125Out-of-bounds Read in Wireshark
CVE-2026-174298.11.1IBMPower Systems FirmwareCWE-863Power System Incorrect Authorization
CVE-2026-88106.91.1Insyde SoftwareInsydeH2O, InsydeH2O ARMCWE-522HDD Password leakage vulnerability
CVE-2026-672686.51.1DellDell Command Update (DCU)CWE-611Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restr…
CVE-2026-168555.51.0IBMAIXCWE-787Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-672675.51.0DellDell Command Update (DCU)CWE-497Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Se…
CVE-2026-188488.30.9IBMPower Systems FirmwareCWE-352Power System Cross-Site Request Forgery (CSRF)
CVE-2026-196536.50.9IBMAIXCWE-400Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-769274.70.9Wireshark FoundationWiresharkCWE-476NULL Pointer Dereference in Wireshark
CVE-2026-769294.70.9Wireshark FoundationWiresharkCWE-125Out-of-bounds Read in Wireshark
CVE-2026-49375.30.9IBMPowerVM HypervisorCWE-331Power System Insufficient Entropy
CVE-2026-768834.70.8Wireshark FoundationWiresharkCWE-122Heap-based Buffer Overflow in Wireshark
CVE-2026-768894.70.8Wireshark FoundationWiresharkCWE-122Heap-based Buffer Overflow in Wireshark
CVE-2026-769204.70.8Wireshark FoundationWiresharkCWE-787Out-of-bounds Write in Wireshark
CVE-2026-159615.20.7IBMPowerVM HypervisorCWE-134Power System Information Disclosure
CVE-2026-167037.80.7IBMAIXCWE-269Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-585658.80.6DellDell Command Update (DCU)CWE-862Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authori…
CVE-2026-585647.80.6DellDell Command Update (DCU)CWE-276Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Defa…
CVE-2026-585627.30.6DellDell Command Update (DCU)CWE-862Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authori…
CVE-2026-763854.30.6SplunkVenafi app for Splunk SOARCWE-312Information Disclosure through Action Parameters in Venafi app for Splunk SOAR
CVE-2026-168903.60.6IBMAIXCWE-190Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-328025.30.5DellPowerPathCWE-269Dell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privileg…
CVE-2026-762417.30.4eidetic-labsstigmemCWE-494stigmem Plugin Signature Enforcement Bypass via Configuration
CVE-2026-168197.70.4IBMAIXCWE-367Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-534777.80.3DellDell Command Update (DCU)CWE-367Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check T…
CVE-2026-672665.50.3DellDell Command Update (DCU)CWE-863Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Auth…
CVE-2026-567977.30.3DellDell Command Update (DCU)CWE-367Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-u…
CVE-2026-168387.00.2IBMAIXCWE-367Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-49365.10.1IBMPowerVM HypervisorCWE-331Power System Insufficient Entropy