Security Box Score — August 19, 2026 — page 2
Edition of August 19, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-76332 | 7.1 | 15.7 | Splunk | Splunk Enterprise | CWE-20 | SPL Injection through Splunk Web in Splunk Enterprise |
| CVE-2026-11751 | 9.1 | 15.4 | LY Corporation | Armeria | — | A vulnerability has been identified in armeria-xds versions prior to 1.41.0, … |
| CVE-2026-76351 | 8.8 | 15.5 | Splunk | Splunk Enterprise | CWE-918 | Server-Side Request Forgery (SSRF) through the Report Notification REST API i… |
| CVE-2026-73384 | 7.5 | 15.5 | cmsMinds | Pay with Contact Form 7 | CWE-201 | WordPress Pay with Contact Form 7 plugin <= 1.0.4 - Sensitive Data Exposure v… |
| CVE-2026-73386 | 7.5 | 15.5 | ZealousWeb | Track Geolocation Of Users Using Contact Form 7 | CWE-201 | WordPress Track Geolocation Of Users Using Contact Form 7 plugin <= 3.0.2 - S… |
| CVE-2026-75981 | 7.2 | 15.5 | cozmoslabs | TranslatePress – Translate Multilingual sites with AI Translation | CWE-79 | TranslatePress – Translate Multilingual sites with AI Translation <= 3.2.5 - … |
| CVE-2026-76215 | 6.9 | 15.3 | thorsten | phpMyFAQ | CWE-862 | phpMyFAQ before 4.1.7 Missing Authorization via child resources |
| CVE-2026-62670 | 6.3 | 15.3 | getgrav | grav-plugin-flex-objects | CWE-862 | Fail-open authorization in grav-plugin-flex-objects admin-next API: api.acces… |
| CVE-2026-76326 | 5.7 | 15.4 | Splunk | Splunk Enterprise | CWE-79 | Stored Cross-Site Scripting through Dashboard Sparkline Tooltip Options in Sp… |
| CVE-2026-40507 | 5.1 | 15.3 | openemr | openemr | CWE-79 | OpenEMR < 8.3.0 Reflected XSS via templateHtml Parameter in Patient Portal |
| CVE-2026-51367 | await | 15.3 | n/a | n/a | — | An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacke… |
| CVE-2026-73391 | 9.3 | 15.0 | KlbTheme | Total Donations | CWE-89 | WordPress Total Donations plugin <= 2.0.5 - SQL Injection vulnerability |
| CVE-2026-54491 | 7.1 | 14.9 | koel | koel | CWE-918 | Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fe… |
| CVE-2026-15446 | 6.4 | 15.0 | nosilver4u | EWWW Image Optimizer | CWE-79 | EWWW Image Optimizer <= 8.7.3 - Authenticated (Contributor+) Stored Cross-Sit… |
| CVE-2026-76336 | 7.1 | 14.8 | Splunk | Splunk Enterprise | CWE-862 | Improper Access Control through the REST API in Splunk Enterprise |
| CVE-2026-18849 | 6.8 | 14.9 | IBM | OPENBMC | CWE-22 | IBM OpenBMC Code Execution |
| CVE-2026-73829 | 6.3 | 14.9 | ZenHive | mpp | CWE-367 | Non-atomic hash-credential dedup in mpp Tempo allows replay of a confirmed pa… |
| CVE-2026-19198 | 8.7 | 14.6 | Akaunting | Akaunting | CWE-863 | Akaunting 3.1.21 - Improper authorization in BulkActions handle dispatch |
| CVE-2026-55694 | 7.1 | 14.6 | grokability | snipe-it | CWE-639 | Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Tak… |
| CVE-2026-73183 | 9.3 | 14.4 | Get Maps Marker Pro | Maps Marker Pro | CWE-89 | WordPress Maps Marker Pro plugin <= 4.32 - SQL Injection vulnerability |
| CVE-2026-73185 | 9.3 | 14.4 | wpo-HR | NGG Smart Image Search | CWE-89 | WordPress NGG Smart Image Search plugin < 4.0.0 - SQL Injection vulnerability |
| CVE-2026-73388 | 9.3 | 14.4 | TeconceTheme | Nikstore Core | CWE-89 | WordPress Nikstore Core plugin <= 1.5 - SQL Injection vulnerability |
| CVE-2026-11565 | 8.5 | 14.2 | Unknown | Advanced File Manager | — | Advanced File Manager < 5.4.13 - Authenticated Arbitrary File Read and Write … |
| CVE-2026-76396 | 7.5 | 14.2 | Splunk | Splunk AI Toolkit | CWE-269 | Improper Access Control through Scheduled Searches in Splunk AI Toolkit |
| CVE-2026-16440 | 5.7 | 14.1 | Eclipse Foundation | Eclipse OpenJ9 | CWE-674 | In Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deeply nest… |
| CVE-2026-16058 | 5.3 | 14.2 | Unknown | YayCurrency | CWE-639 | YayCurrency < 3.3.5 - Unauthenticated Order and Vendor Financial Data Disclos… |
| CVE-2026-15078 | 8.1 | 14.1 | IBM | AIX | CWE-295 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-76323 | 7.3 | 13.7 | Splunk | Splunk Enterprise | CWE-20 | SPL Risky Command Safeguards Bypass through the Job Details Dashboard in Splu… |
| CVE-2026-76348 | 3.8 | 13.8 | Splunk | Splunk Enterprise | CWE-862 | Missing Authorization in Search Head Cluster Member Controls in Splunk Enterp… |
| CVE-2026-76205 | 8.6 | 13.6 | thorsten | phpMyFAQ | CWE-89 | phpMyFAQ before 4.1.7 SQL Injection via Glossary |
| CVE-2026-76331 | 8.1 | 13.6 | Splunk | Splunk Enterprise | CWE-943 | SPL Injection through the REST API in Splunk Enterprise |
| CVE-2026-19406 | 2.7 | 13.6 | Unknown | Easy Appointments | CWE-200 | Easy Appointments < 4.0.1 - Contributor+ Sensitive Information Disclosure via… |
| CVE-2026-76256 | 4.3 | 13.5 | Splunk | Splunk Enterprise | CWE-200 | Information Exposure through REST API Endpoints in Splunk Secure Gateway |
| CVE-2026-16835 | 9.6 | 13.3 | IBM | Power Systems Firmware | CWE-295 | Power System Improper Certificate Validation |
| CVE-2026-76827 | 6.8 | 13.2 | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | CWE-693 | Search-indexer: search-indexer: update/delete operations not scoped to caller… |
| CVE-2026-76341 | 5.4 | 13.2 | Splunk | Splunk Enterprise | CWE-863 | Risky Commands Safeguards Bypass through Table Editor Dataset Initial Data in… |
| CVE-2026-76234 | 8.7 | 12.8 | celabshq | libcrux-ecdh | CWE-347 | libcrux before 0.0.6 Cryptographic Implementation Bug Fixes |
| CVE-2026-18102 | 3.5 | 12.9 | IBM | i | CWE-122 | IBM i Buffer Overflow |
| CVE-2026-19507 | await | 12.6 | RDK | RDK-B WebUI | — | RDK WebUI uncontrolled resource consumption |
| CVE-2026-76255 | 7.3 | 12.6 | Splunk | Splunk Enterprise | CWE-862 | Risky Command Safeguards Bypass through Splunk Web in Splunk Enterprise |
| CVE-2026-18777 | 5.3 | 12.4 | Unknown | TrueBooker | CWE-862 | TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Arbitrary Appointmen… |
| CVE-2026-18779 | 5.3 | 12.4 | Unknown | TrueBooker | CWE-862 | TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Appointment and Paym… |
| CVE-2026-19506 | await | 12.4 | RDK | RDK-B WebUI | — | RDK-B WebUI race condition vulnerability |
| CVE-2026-49415 | 8.8 | 12.3 | FreeBSD | FreeBSD | CWE-367 | Local privilege escalation via execve(2) TOCTOU race |
| CVE-2026-12522 | 8.8 | 12.1 | zephyrproject | zephyr | CWE-787 | Stack buffer overflow in Zephyr hl7800 modem driver parsing network-supplied … |
| CVE-2026-76263 | 5.4 | 12.1 | Splunk | Splunk Enterprise | CWE-639 | Improper Access Control through the REST API in Splunk Enterprise |
| CVE-2026-14826 | 2.7 | 12.0 | Unknown | Quiz and Survey Master (QSM) | CWE-639 | Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Email and Results C… |
| CVE-2026-76361 | 2.7 | 12.0 | Splunk | Splunk SOAR | CWE-918 | Server-Side Request Forgery (SSRF) through the Connectivity Check REST API in… |
| CVE-2026-76368 | 2.7 | 12.0 | Splunk | Splunk SOAR | CWE-862 | Missing Authorization through Playbooks in Splunk SOAR |
| CVE-2026-75619 | 6.9 | 12.0 | TP-Link Systems Inc. | Tapo C100 v5 | CWE-122 | RTSP Heap Buffer Overflow Denial-of-Service Vulnerability on TP-Link Tapo C10… |
| CVE-2026-76244 | 9.1 | 11.9 | eidetic-labs | stigmem | CWE-319 | stigmem-node Insecure Federation Transport Configuration |
| CVE-2026-76324 | 5.4 | 11.8 | Splunk | Splunk Enterprise | CWE-79 | Stored Cross-Site Scripting (XSS) in Splunk Web Tours in Splunk Enterprise |
| CVE-2026-76309 | 4.3 | 11.8 | Splunk | Splunk Enterprise | CWE-89 | Structured Query Language (SQL) Injection through the REST API in Splunk Ente… |
| CVE-2026-76209 | 5.3 | 11.7 | thorsten | phpMyFAQ | CWE-862 | phpMyFAQ before v4.1.6 Registration Bypass via API |
| CVE-2026-76375 | 5.0 | 11.6 | Splunk | AD LDAP app for Splunk SOAR | CWE-532 | Information Disclosure through Environment Data Logging in AD LDAP app for Sp… |
| CVE-2026-76374 | 4.3 | 11.6 | Splunk | AD LDAP app for Splunk SOAR | CWE-532 | Information Disclosure through Sensitive Data Logging in AD LDAP app for Splu… |
| CVE-2026-12633 | 8.1 | 11.6 | zephyrproject | zephyr | CWE-787 | Out-of-bounds write in IPv6 6LoWPAN Context Option handling via unauthenticat… |
| CVE-2026-76226 | 6.8 | 11.6 | renovatebot | renovate | CWE-78 | Renovate 43.65.0 through 43.102.11 Remote Code Execution via lockFileMaintenance |
| CVE-2026-76342 | 5.4 | 11.5 | Splunk | Splunk Enterprise | CWE-863 | Risky Commands Safeguards Bypass through Splunk Web in Splunk Enterprise |
| CVE-2026-58081 | await | 11.5 | FreeBSD | FreeBSD | CWE-122 | Heap based buffer overflow in iconv(3) |
| CVE-2026-58082 | await | 11.6 | FreeBSD | FreeBSD | CWE-121 | Stack based buffer overflow in iconv(3) |
| CVE-2026-76261 | 6.5 | 11.3 | Splunk | Splunk Enterprise | CWE-732 | Insecure Default Access Control List through the REST API in Splunk Secure Ga… |
| CVE-2026-55519 | 5.4 | 11.3 | grokability | snipe-it | CWE-285 | Snipe-IT: Improper Authorization in File Deletion (IDOR) |
| CVE-2026-76251 | 7.1 | 11.2 | Splunk | Splunk Enterprise | CWE-862 | Missing Authorization through REST API Endpoints in the Splunk App for Splunk… |
| CVE-2026-16846 | 6.5 | 11.3 | IBM | AIX | CWE-476 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-76349 | 6.4 | 11.3 | Splunk | Splunk Enterprise | CWE-943 | SPL Injection through Splunk Web Form Tokens in Splunk Enterprise |
| CVE-2026-18466 | 5.4 | 10.9 | Unknown | WP Maps | CWE-284 | WP Maps < 4.9.8 - Subscriber+ Unlimited Autoloaded Option Creation |
| CVE-2026-76347 | 5.4 | 10.9 | Splunk | Splunk Enterprise | CWE-918 | Server-Side Request Forgery (SSRF) through the Report Notifications REST API … |
| CVE-2026-76328 | 6.7 | 10.9 | Splunk | Splunk Enterprise | CWE-77 | SPL Injection through Splunk Web in Splunk Enterprise |
| CVE-2026-61607 | 4.6 | 10.8 | getgrav | grav-plugin-api | CWE-79 | Grav API Plugin: Stored XSS via SVG Upload - API Media Pipeline Bypasses Sani… |
| CVE-2026-16687 | 9.6 | 10.7 | IBM | Power Systems Firmware | CWE-121 | Power System Buffer Overflow |
| CVE-2026-76327 | 6.4 | 10.7 | Splunk | Splunk Enterprise | CWE-943 | SPL Injection through Splunk Web in Splunk Secure Gateway |
| CVE-2026-76320 | 6.5 | 10.6 | Splunk | Splunk Enterprise | CWE-943 | SPL Injection through Cross-Site Request Forgery (CSRF) in the Event Type Bui… |
| CVE-2026-76360 | 4.3 | 10.5 | Splunk | Splunk SOAR | CWE-862 | Information Disclosure through Missing Authorization in the Health REST API i… |
| CVE-2026-76370 | 4.3 | 10.5 | Splunk | Splunk SOAR | CWE-863 | Information Disclosure through the REST API in Splunk SOAR |
| CVE-2026-20327 | 6.5 | 10.4 | Cisco | Cisco Unified Intelligence Center | CWE-89 | Cisco Unified Intelligence Center SQL Injection Vulnerability |
| CVE-2026-20232 | 5.4 | 10.4 | Cisco | Cisco Industrial Ethernet Switches | CWE-80 | Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vu… |
| CVE-2026-13173 | 2.7 | 10.4 | Unknown | Eventin | CWE-862 | Eventin < 4.1.21 - Contributor+ User Role and Meta Modification via Speaker C… |
| CVE-2026-14825 | 2.7 | 10.4 | Unknown | Quiz and Survey Master (QSM) | CWE-639 | Quiz And Survey Master < 11.2.4 - Contributor+ Arbitrary Quiz Text Settings U… |
| CVE-2026-76371 | 2.7 | 10.4 | Splunk | FireAMP | CWE-732 | Incorrect Permission Assignment through Safe Mode in FireAMP for Splunk SOAR |
| CVE-2026-76211 | 5.3 | 10.3 | thorsten | phpMyFAQ | CWE-862 | phpMyFAQ before 4.1.7 Information Disclosure via Admin API |
| CVE-2026-75583 | 2.3 | 10.3 | ridafkih | keeper.sh | CWE-918 | keeper.sh Calendar version prior to 2.18.14 SSRF Guard Bypass via DNS Rebinding |
| CVE-2026-73385 | 7.5 | 10.0 | Outanking Team | Outranking Plugin Options | CWE-862 | WordPress Outranking plugin Options plugin <= 1.1.3 - Broken Access Control v… |
| CVE-2026-73394 | 7.5 | 10.0 | Stitchexpress | Stitch Express | CWE-862 | WordPress Stitch Express plugin <= 1.9.0 - Broken Access Control vulnerability |
| CVE-2026-16851 | 7.4 | 10.0 | IBM | AIX | CWE-416 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-49430 | await | 10.0 | FreeBSD | FreeBSD | CWE-122 | Kernel heap overflow in ZFS_IOC_RECV_NEW ioctl |
| CVE-2026-18681 | 6.8 | 9.8 | IBM | Server Firmware | CWE-121 | This Power System Buffer Overflow |
| CVE-2026-19842 | 8.8 | 9.7 | Unknown | SAML Single Sign On | CWE-287 | SAML Single Sign On 4.8.85 - 5.4.6 - Unauthenticated Administrator Account Ta… |
| CVE-2026-17565 | 7.2 | 9.8 | Unknown | Animation Addons for Elementor | CWE-918 | Animation Addons for Elementor < 2.7.2 - Unauthenticated Server-Side Request … |
| CVE-2026-54794 | 7.2 | 9.8 | Dell | OpenManage Enterprise | CWE-918 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side R… |
| CVE-2026-19505 | await | 9.8 | RDK | RDK-B WebUI | — | RDK-B WebUI improper cryptographic signature verification vulnerability |
| CVE-2026-16822 | 9.3 | 9.7 | IBM | AIX | CWE-295 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-48711 | 7.0 | 9.7 | libfuse | sshfs | CWE-88 | SSHFS: Improper Neutralization of Argument Delimiters in a Command ('Argument… |
| CVE-2026-16849 | 4.3 | 9.7 | IBM | AIX | CWE-129 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-16886 | 4.3 | 9.7 | IBM | AIX | CWE-787 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-14514 | 6.5 | 9.4 | IBM | Reliable Scalable Cluster Technology (RSCT) | CWE-770 | Reliable Scalable Cluster Technology Denial-of-Service |
| CVE-2026-16979 | 4.3 | 9.4 | Unknown | SmartCrawl SEO checker, analyzer & optimizer | CWE-639 | SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Disclosure and Pos… |
| CVE-2026-76329 | 6.4 | 9.2 | Splunk | Splunk Enterprise | CWE-943 | SPL Injection through Monitoring Console Dashboard Inputs in Splunk Enterprise |
| CVE-2026-76403 | 7.4 | 8.9 | Splunk | Splunk Connect for Kafka | CWE-295 | Improper Certificate Validation through HTTP Event Collector Kerberos Authent… |
| CVE-2026-75618 | 7.1 | 8.9 | TP-Link Systems Inc. | Tapo C100 v5 | CWE-476 | RTSP Null Pointer Dereference Denial-of-Service Vulnerability on TP-Link Tapo… |
| CVE-2026-17028 | 6.5 | 9.0 | IBM | PowerVM Hypervisor | CWE-125 | Power System Out-of-bounds Read |
| CVE-2026-63123 | 6.5 | 9.0 | tinacms | tinacms | CWE-352 | Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files … |
| CVE-2026-76318 | 5.4 | 8.9 | Splunk | Splunk Enterprise | CWE-79 | Stored Cross-Site Scripting (XSS) through Splunk Web in Splunk Enterprise |
| CVE-2026-55703 | 4.3 | 9.0 | grokability | snipe-it | CWE-862 | Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GET |
| CVE-2026-18821 | 7.5 | 8.7 | IBM | PowerVM Hypervisor | CWE-787 | Power System Out-of-bounds Write |
| CVE-2026-55482 | 6.3 | 8.8 | grokability | snipe-it | CWE-639 | Snipe-IT: Multi-Tenancy Bypass via Bulk Asset Update |
| CVE-2026-49392 | 5.3 | 8.7 | wazuh | wazuh | CWE-20 | Wazuh: Local SQL injection in FIM db due to path lookup interpolation in wazu… |
| CVE-2026-16832 | 8.4 | 8.6 | IBM | Power Systems Firmware | CWE-121 | Power System Buffer Overflow |
| CVE-2026-19416 | 4.3 | 8.6 | Unknown | KiviCare | CWE-639 | KiviCare < 4.5.4 - Patient+ Cross-Patient Appointment Modification via IDOR |
| CVE-2026-76346 | 5.4 | 8.4 | Splunk | Splunk Enterprise | CWE-79 | Stored Cross-Site Scripting (XSS) through Splunk Web Dashboard Sparkline Form… |
| CVE-2026-11617 | 3.1 | 8.3 | Tanium | Findings | CWE-409 | Tanium addressed a compression bomb vulnerability in Findings. |
| CVE-2026-75476 | 3.1 | 8.3 | Tanium | Threat Response | CWE-409 | Tanium addressed a compression bomb vulnerability in Threat Response. |
| CVE-2026-62727 | 7.0 | 8.2 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-17414 | 8.1 | 8.1 | IBM | PowerVM Hypervisor | CWE-20 | Power System Improper Input Validation |
| CVE-2026-14196 | 4.3 | 8.1 | Unknown | WCFM Marketplace | CWE-639 | WCFM Marketplace < 3.8.1 - Store Vendor+ Cross-Vendor Review Deletion and Sta… |
| CVE-2026-76398 | 4.3 | 8.1 | Splunk | Splunk AI Toolkit | CWE-862 | Improper Access Control during Experiment History Deletion through the REST A… |
| CVE-2026-20302 | 6.1 | 8.0 | Cisco | Cisco RoomOS Software | CWE-120 | Cisco RoomOS Stack Overflow Vulnerability |
| CVE-2026-76252 | 6.1 | 7.9 | Splunk | Splunk Enterprise | CWE-79 | Cross-Site Scripting (XSS) through Splunk Web Message Validation in Splunk En… |
| CVE-2026-75589 | await | 8.0 | — | Net-OAuth | CWE-208 | Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLA… |
| CVE-2026-76245 | 7.1 | 7.9 | eidetic-labs | stigmem | CWE-345 | stigmem Federation Peer Token Timestamp Validation Bypass |
| CVE-2025-36398 | 5.4 | 7.8 | IBM | DS8A00 (R10.0 - R10.1) | CWE-73 | DS8900F and DS8A00 Information Disclosure |
| CVE-2026-19782 | 5.4 | 7.8 | Unknown | WPS Bidouille | CWE-200 | WPS Bidouille < 1.33.5 - Subscriber+ User Email Disclosure via wps_get_users |
| CVE-2026-76373 | 5.4 | 7.8 | Splunk | AD LDAP app for Splunk SOAR | CWE-90 | Filter Injection through Action Parameters in AD LDAP app for Splunk SOAR |
| CVE-2026-16829 | 5.3 | 7.7 | IBM | AIX | CWE-476 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-16570 | 7.1 | 7.5 | Unknown | NextScripts: Social Networks Auto-Poster | CWE-79 | NextScripts: Social Networks Auto-Poster < 4.4.8 - Reflected XSS via Facebook… |
| CVE-2026-19055 | 7.1 | 7.5 | Unknown | ProSolution WP Client | CWE-79 | ProSolution WP Client < 2.0.11 - Reflected XSS via Multiple Parameters |
| CVE-2026-19056 | 7.1 | 7.5 | Unknown | ProSolution WP Client | CWE-79 | ProSolution WP Client < 2.0.11 - Reflected XSS via 'page' Parameter |
| CVE-2026-76339 | 5.4 | 7.6 | Splunk | Splunk Enterprise | CWE-77 | SPL Injection through the geostats Command in Splunk Enterprise |
| CVE-2026-76362 | 7.4 | 7.4 | Splunk | Splunk SOAR | CWE-295 | Improper Certificate Validation through CyberArk Vault Privileged Access Mana… |
| CVE-2026-76926 | 3.1 | 7.4 | Wireshark Foundation | Wireshark | CWE-617 | Reachable Assertion in Wireshark |
| CVE-2026-49431 | await | 7.3 | FreeBSD | FreeBSD | CWE-863 | Incorrect user validation in ZFS_IOC_SET_PROP ioctl |
| CVE-2026-50550 | 5.8 | 7.2 | grokability | snipe-it | CWE-863 | Snipe-IT: 2FA reset privilege bypass |
| CVE-2026-76884 | 3.1 | 6.9 | Wireshark Foundation | Wireshark | CWE-126 | Buffer Over-read in Wireshark |
| CVE-2026-76885 | 3.1 | 6.9 | Wireshark Foundation | Wireshark | CWE-126 | Buffer Over-read in Wireshark |
| CVE-2026-76887 | 3.1 | 6.9 | Wireshark Foundation | Wireshark | CWE-122 | Heap-based Buffer Overflow in Wireshark |
| CVE-2026-76888 | 3.1 | 6.9 | Wireshark Foundation | Wireshark | CWE-122 | Heap-based Buffer Overflow in Wireshark |
| CVE-2026-76890 | 3.1 | 6.9 | Wireshark Foundation | Wireshark | CWE-825 | Expired Pointer Dereference in Wireshark |
| CVE-2026-76891 | 3.1 | 6.9 | Wireshark Foundation | Wireshark | CWE-825 | Expired Pointer Dereference in Wireshark |
| CVE-2026-16828 | 7.6 | 6.9 | IBM | Power Systems Firmware | CWE-125 | Power System Out-of-bounds Read |
| CVE-2026-73363 | 6.5 | 6.9 | magepeopleteam | Taxi Booking Manager for WooCommerce | CWE-862 | WordPress Taxi Booking Manager for WooCommerce plugin < 2.0.8 - Broken Access… |
| CVE-2026-40508 | 5.1 | 6.6 | openemr | openemr | CWE-79 | OpenEMR < 8.3.0 Stored XSS via Patient Portal Template Import Handler |
| CVE-2026-16724 | 4.5 | 6.4 | IBM | Virtualization Management Interface | CWE-190 | Power System Integer Overflow |
| CVE-2026-76392 | 5.4 | 6.2 | Splunk | Splunk AI Toolkit | CWE-798 | Use of Hard-coded Credentials in Container Connections in Splunk AI Toolkit |
| CVE-2026-66358 | 5.1 | 6.3 | Extra Innovation Inc. | acmailer CGI | CWE-79 | A cross-site scripting vulnerability exists in acmailer, which may allow an a… |
| CVE-2026-14287 | 4.7 | 6.0 | Unknown | 10Web Booster | CWE-79 | TenWeb Speed Optimizer < 2.33.5 - Unauthenticated Stored XSS via Critical CSS… |
| CVE-2026-49429 | 7.8 | 5.9 | FreeBSD | FreeBSD | CWE-122 | Kernel heap overflow in ZFS_IOC_USERSPACE_MANY ioctl |
| CVE-2026-54793 | 5.4 | 5.9 | Dell | OpenManage Enterprise | CWE-79 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neu… |
| CVE-2026-76647 | await | 5.9 | Leantime | JSON-RPC API | — | Leantime JSON-RPC API contains a missing authorization vulnerability |
| CVE-2026-16875 | 7.8 | 5.7 | IBM | AIX | CWE-78 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2024-13942 | 7.6 | 5.7 | Rockchip | RK3588s | CWE-367 | Rockchip RK3588s Secure BootROM TOCTOU (time-of-check to time-of-use) vulnera… |
| CVE-2026-75917 | 9.3 | 5.6 | siyuan-note | siyuan | CWE-79 | SiYuan before v3.7.4 XSS-to-RCE via pathName.ts |
| CVE-2026-19509 | await | 5.6 | RDK | RDK-B WebUI | — | RDK WebUI DOS vulnerability |
| CVE-2026-75916 | 9.3 | 5.2 | siyuan-note | siyuan | CWE-79 | SiYuan XSS-to-RCE via unescaped block metadata in hint popup |
| CVE-2026-43961 | 7.8 | 5.2 | vim | vim | CWE-94 | Vim: vimscript injection via unescaped filename in netrw s:netrwmarkfile() fi… |
| CVE-2026-75952 | 4.6 | 5.3 | cmsjunkie.com | J-BusinessDirectory extension for Joomla | CWE-352 | Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDi… |
| CVE-2026-22306 | 10.0 | 4.8 | Ozols Grupa | OZOLS | CWE-319 | Critical flaw impacting OZOLS ERP's automatic update channel |
| CVE-2026-76383 | 4.3 | 4.6 | Splunk | RSA SecurID Authentication Manager app for Splunk SOAR | CWE-312 | Information Disclosure through Action Parameters in RSA SecurID Authenticatio… |
| CVE-2026-75148 | 6.9 | 4.6 | jkuhlmann | cgltf | CWE-190 | cgltf 1.15 Integer Overflow via cgltf_validate() Accessor Bounds Check |
| CVE-2026-76367 | 4.0 | 4.4 | Splunk | Splunk SOAR | CWE-79 | Stored Cross-Site Scripting (XSS) through Notes in Splunk SOAR |
| CVE-2026-49423 | await | 4.4 | FreeBSD | FreeBSD | CWE-908 | Remote DOS via uninitialized memory access in KTLS receive |
| CVE-2026-49424 | await | 4.4 | FreeBSD | FreeBSD | CWE-908 | Kernel stack disclosure in Linux compatibility layer |
| CVE-2026-49425 | await | 4.4 | FreeBSD | FreeBSD | CWE-908 | Kernel stack disclosure in 32-bit compatibility support |
| CVE-2026-49426 | await | 4.4 | FreeBSD | FreeBSD | CWE-223 | Incorrect audit records for ptrace(2) syscall requests |
| CVE-2026-50719 | await | 4.4 | n/a | n/a | — | The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and e… |
| CVE-2026-50720 | await | 4.4 | n/a | n/a | — | The Ingenic T31 SoC boot ROM flash-boot verification path compares only a sin… |
| CVE-2026-75953 | await | 4.4 | cmsjunkie.com | J-BusinessDirectory extension for Joomla | CWE-201 | Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6… |
| CVE-2026-50149 | 6.5 | 4.2 | projectcontour | contour | CWE-295 | Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts w… |
| CVE-2026-61986 | 7.1 | 4.1 | Wasiliy Strecker | Contest Gallery | CWE-79 | WordPress Contest Gallery plugin <= 30.0.5 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-66596 | 7.1 | 4.1 | Stefano Lissa | Newsletter | CWE-79 | WordPress Newsletter plugin <= 9.3.3 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-73182 | 7.1 | 4.1 | Jeff Starr | BBQ Pro | CWE-79 | WordPress BBQ Pro plugin <= 3.9 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-73184 | 7.1 | 4.1 | LCweb | Global Gallery | CWE-79 | WordPress Global Gallery plugin <= 11.1.2 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-73354 | 7.1 | 4.1 | ReichertBrothers | SimplyRETS Real Estate IDX | CWE-79 | WordPress SimplyRETS Real Estate IDX plugin <= 3.2.8 - Cross Site Scripting (… |
| CVE-2026-76378 | 4.3 | 4.0 | Splunk | Cisco Secure Malware Analytics app for Splunk SOAR | CWE-312 | Information Disclosure through Action Parameters in Cisco Secure Malware Anal… |
| CVE-2026-76379 | 4.3 | 4.0 | Splunk | Cisco Webex app for Splunk SOAR | CWE-312 | Information Disclosure through Action Parameters in Cisco Webex app for Splun… |
| CVE-2026-58084 | await | 3.9 | FreeBSD | FreeBSD | CWE-908 | Kernel stack disclosure via timer_settime(2) |
| CVE-2026-58085 | await | 3.7 | FreeBSD | FreeBSD | CWE-347 | Missing MAC validation in wg(4) packet decryption |
| CVE-2026-58086 | await | 3.7 | FreeBSD | FreeBSD | CWE-273 | ktrace(2) privilege incorrectly validated in jails |
| CVE-2026-76376 | 4.3 | 3.5 | Splunk | AWS IAM app for Splunk SOAR | CWE-312 | Information Disclosure through Action Parameters in AWS IAM app for Splunk SOAR |
| CVE-2026-76377 | 4.3 | 3.5 | Splunk | Azure AD Graph app for Splunk SOAR | CWE-312 | Information Disclosure through Action Parameters in Azure AD Graph app for Sp… |
| CVE-2026-76380 | 4.3 | 3.5 | Splunk | CrowdStrike OAuth API app for Splunk SOAR | CWE-312 | Information Disclosure through Action Parameters in CrowdStrike OAuth API app… |
| CVE-2026-76381 | 4.3 | 3.5 | Splunk | MS Graph for Active Directory app for Splunk SOAR | CWE-312 | Information Disclosure through Action Parameters in MS Graph for Active Direc… |
| CVE-2026-76382 | 4.3 | 3.5 | Splunk | Phantom app for Splunk SOAR | CWE-312 | Information Disclosure through Action Parameters in Phantom app for Splunk SOAR |
| CVE-2026-76384 | 4.3 | 3.5 | Splunk | Splunk Attack Analyzer Connector for Splunk SOAR | CWE-312 | Information Disclosure through Action Parameters in Splunk Attack Analyzer Co… |
| CVE-2026-76386 | 4.3 | 3.5 | Splunk | Zoom app for Splunk SOAR | CWE-312 | Information Disclosure through Action Parameters in Zoom app for Splunk SOAR |
| CVE-2026-76405 | 4.3 | 3.5 | Splunk | Splunk On-Call (VictorOps) | CWE-312 | Information Disclosure through Cleartext Storage in the App Key Value Store i… |
| CVE-2026-16938 | 6.9 | 3.4 | IBM | Power Systems Firmware | CWE-862 | Power System Missing Authorization |
| CVE-2026-75141 | 8.5 | 3.3 | FFmpeg | FFmpeg | CWE-122 | FFmpeg Heap Buffer Overflow in hvcC Box Writer via HEVC Muxing |
| CVE-2026-75142 | 8.5 | 3.3 | FFmpeg | FFmpeg | CWE-121 | FFmpeg Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c |
| CVE-2026-75144 | 8.5 | 3.3 | FFmpeg | FFmpeg | CWE-122 | FFmpeg Heap Buffer Overflow in VC-2/Dirac RTP Packetizer |
| CVE-2026-16914 | 6.7 | 3.3 | IBM | AIX | CWE-787 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-72889 | await | 3.3 | — | Net-OAuth | CWE-347 | Net::OAuth versions before 0.33 for Perl allow the sender to choose the signa… |
| CVE-2026-76393 | 5.9 | 3.3 | Splunk | Splunk AI Toolkit | CWE-362 | Race Condition during Model Upload through the REST API in Splunk AI Toolkit |
| CVE-2026-62671 | 5.4 | 3.2 | getgrav | grav-plugin-login | CWE-352 | CSRF in grav-plugin-login: anonymous attacker rotates a logged-in user's 2FA … |
| CVE-2026-16661 | 8.2 | 3.0 | IBM | PowerVM Hypervisor | CWE-190 | Power System Integer Overflow |
| CVE-2026-16707 | 8.2 | 3.0 | IBM | PowerVM Hypervisor | CWE-125 | Power System Out-of-bounds Read |
| CVE-2026-49421 | await | 3.0 | FreeBSD | FreeBSD | CWE-273 | unlinkat(2) ignores AT_RESOLVE_BENEATH flag |
| CVE-2026-68554 | 2.3 | 2.9 | coturn | coturn | CWE-345 | Coturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-pat… |
| CVE-2026-52834 | 7.3 | 2.9 | tirr-c | jxl-oxide | CWE-122 | jxl-oxide: Out-of-bounds writes due to integer overflow in jxl-grid on 32-bit… |
| CVE-2026-76259 | 7.8 | 2.7 | Splunk | Splunk Enterprise | CWE-269 | Improper Privilege Management on the Management Port in Splunk Enterprise for… |
| CVE-2026-40509 | 5.3 | 2.6 | openemr | openemr | CWE-352 | OpenEMR < 8.3.0 CSRF via DICOM Viewer web_path Parameter |
| CVE-2026-16874 | 7.8 | 2.6 | IBM | AIX | CWE-269 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-49422 | 8.4 | 2.5 | FreeBSD | FreeBSD | CWE-416 | Use-after-free in TCP RACK stack option handler |
| CVE-2026-76334 | 6.4 | 2.5 | Splunk | Splunk Enterprise | CWE-352 | SPL Injection through Dashboard Studio Workflow Actions in Splunk Enterprise |
| CVE-2026-16869 | 7.8 | 2.4 | IBM | AIX | CWE-426 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-58083 | 8.4 | 2.3 | FreeBSD | FreeBSD | CWE-416 | Use-after-free in kqueue copy-on-fork |
| CVE-2026-16933 | 8.2 | 2.3 | IBM | Power Systems Firmware | CWE-190 | Power System Integer Overflow |
| CVE-2026-19234 | 8.2 | 2.3 | IBM | Power Systems Firmware | CWE-121 | Power System Buffer Overflow |
| CVE-2026-56796 | 6.6 | 2.3 | Dell | Dell Command Update (DCU) | CWE-59 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link … |
| CVE-2026-65610 | 2.4 | 2.3 | nnn | nnn | CWE-197 | Numeric Truncation Error in nnn |
| CVE-2026-55086 | 4.2 | 2.2 | ether | etherpad | CWE-59 | Etherpad: Import/export use Math.random() for temp file paths; predictable pa… |
| CVE-2026-58087 | 7.8 | 2.1 | FreeBSD | FreeBSD | CWE-125 | Heap out-of-bounds access in semctl(2) |
| CVE-2026-75147 | 6.9 | 2.1 | FFmpeg | FFmpeg | CWE-125 | FFmpeg Out-of-Bounds Read in AV1 RTP Packetizer via rtpenc_av1.c |
| CVE-2026-14978 | 5.5 | 2.1 | HashiCorp | go-slug | CWE-176 | Unicode normalization mismatch in go-slug ignore pattern matching may bypass … |
| CVE-2026-76014 | 1.9 | 2.1 | n/a | BusyBox | CWE-404 | BusyBox FEATURE_WGET_TIMEOUT wget.c null pointer dereference |
| CVE-2026-16873 | 7.8 | 2.0 | IBM | AIX | CWE-787 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-49817 | 7.8 | 2.1 | Dell | Dell Command Update (DCU) | CWE-502 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization… |
| CVE-2026-16930 | 8.2 | 1.9 | IBM | Power Systems Firmware | CWE-862 | Power System Missing Authorization |
| CVE-2026-76921 | 5.5 | 1.9 | Wireshark Foundation | Wireshark | CWE-416 | Use After Free in Wireshark |
| CVE-2026-17063 | 7.9 | 1.8 | IBM | Power Systems Firmware | CWE-863 | Power System Incorrect Authorization |
| CVE-2026-75145 | 5.8 | 1.8 | FFmpeg | FFmpeg | CWE-681 | FFmpeg Integer Narrowing Conversion OOB Memory Access in AV1 RTP Packetizer |
| CVE-2026-17091 | 8.4 | 1.8 | IBM | PowerVM Hypervisor | CWE-190 | Power System Integer Overflow |
| CVE-2026-76227 | 6.8 | 1.7 | renovatebot | renovate | CWE-526 | Renovate 42.68.1 before 42.96.3 Environment Variable Exposure |
| CVE-2026-17093 | 8.2 | 1.7 | IBM | Power Systems Firmware | CWE-121 | Power System Buffer Overflow |
| CVE-2026-17100 | 8.2 | 1.7 | IBM | Power Systems Firmware | CWE-787 | Power System Out-of-bounds Write |
| CVE-2026-17494 | 8.2 | 1.7 | IBM | Power Systems Firmware | CWE-121 | Power System Buffer Overflow |
| CVE-2026-65609 | 2.4 | 1.7 | nnn | nnn | CWE-787 | Out-of-bounds write in nnn |
| CVE-2026-16883 | 5.5 | 1.7 | IBM | AIX | CWE-125 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-75112 | 6.9 | 1.6 | Rockwell Automation | OTTO® Fleet Manager | CWE-916 | OTTO® Fleet Manager – Weak Password Hashing Configuration |
| CVE-2026-49816 | 7.8 | 1.5 | Dell | Dell Command Update (DCU) | CWE-502 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization… |
| CVE-2026-16897 | 4.4 | 1.5 | IBM | AIX | CWE-369 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-75900 | 6.1 | 1.5 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Swtpm: swtpm: out-of-bounds read in swtpm_nvram_checkheader due to sizeof(poi… |
| CVE-2026-17097 | 7.3 | 1.4 | IBM | PowerVM Hypervisor | CWE-129 | Power System Improper Validation |
| CVE-2026-18871 | 7.3 | 1.4 | IBM | PowerVM Hypervisor | CWE-121 | Power System Buffer Overflow |
| CVE-2026-19321 | 6.7 | 1.3 | IBM | Power Systems Firmware | CWE-190 | Power System Integer Overflow |
| CVE-2026-76924 | 5.5 | 1.3 | Wireshark Foundation | Wireshark | CWE-125 | Out-of-bounds Read in Wireshark |
| CVE-2026-58088 | 7.4 | 1.2 | FreeBSD | FreeBSD | CWE-362 | Race condition in ELF core dump segment counting |
| CVE-2026-16891 | 3.3 | 1.2 | IBM | AIX | CWE-125 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-17042 | 7.3 | 1.2 | IBM | Power Systems Firmware | CWE-125 | Power System Out-of-bounds Read |
| CVE-2026-76917 | 5.5 | 1.2 | Wireshark Foundation | Wireshark | CWE-122 | Heap-based Buffer Overflow in Wireshark |
| CVE-2026-76918 | 5.5 | 1.2 | Wireshark Foundation | Wireshark | CWE-122 | Heap-based Buffer Overflow in Wireshark |
| CVE-2026-76922 | 5.5 | 1.2 | Wireshark Foundation | Wireshark | CWE-476 | NULL Pointer Dereference in Wireshark |
| CVE-2026-76923 | 5.5 | 1.2 | Wireshark Foundation | Wireshark | CWE-125 | Out-of-bounds Read in Wireshark |
| CVE-2026-12634 | 5.3 | 1.2 | zephyrproject | zephyr | CWE-787 | Out-of-bounds stack write in the settings NVS backend from over-reported nvs_… |
| CVE-2026-76881 | 4.7 | 1.2 | Wireshark Foundation | Wireshark | CWE-476 | NULL Pointer Dereference in Wireshark |
| CVE-2026-76882 | 4.7 | 1.2 | Wireshark Foundation | Wireshark | CWE-125 | Out-of-bounds Read in Wireshark |
| CVE-2026-17429 | 8.1 | 1.1 | IBM | Power Systems Firmware | CWE-863 | Power System Incorrect Authorization |
| CVE-2026-8810 | 6.9 | 1.1 | Insyde Software | InsydeH2O, InsydeH2O ARM | CWE-522 | HDD Password leakage vulnerability |
| CVE-2026-67268 | 6.5 | 1.1 | Dell | Dell Command Update (DCU) | CWE-611 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restr… |
| CVE-2026-16855 | 5.5 | 1.0 | IBM | AIX | CWE-787 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-67267 | 5.5 | 1.0 | Dell | Dell Command Update (DCU) | CWE-497 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Se… |
| CVE-2026-18848 | 8.3 | 0.9 | IBM | Power Systems Firmware | CWE-352 | Power System Cross-Site Request Forgery (CSRF) |
| CVE-2026-19653 | 6.5 | 0.9 | IBM | AIX | CWE-400 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-76927 | 4.7 | 0.9 | Wireshark Foundation | Wireshark | CWE-476 | NULL Pointer Dereference in Wireshark |
| CVE-2026-76929 | 4.7 | 0.9 | Wireshark Foundation | Wireshark | CWE-125 | Out-of-bounds Read in Wireshark |
| CVE-2026-4937 | 5.3 | 0.9 | IBM | PowerVM Hypervisor | CWE-331 | Power System Insufficient Entropy |
| CVE-2026-76883 | 4.7 | 0.8 | Wireshark Foundation | Wireshark | CWE-122 | Heap-based Buffer Overflow in Wireshark |
| CVE-2026-76889 | 4.7 | 0.8 | Wireshark Foundation | Wireshark | CWE-122 | Heap-based Buffer Overflow in Wireshark |
| CVE-2026-76920 | 4.7 | 0.8 | Wireshark Foundation | Wireshark | CWE-787 | Out-of-bounds Write in Wireshark |
| CVE-2026-15961 | 5.2 | 0.7 | IBM | PowerVM Hypervisor | CWE-134 | Power System Information Disclosure |
| CVE-2026-16703 | 7.8 | 0.7 | IBM | AIX | CWE-269 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-58565 | 8.8 | 0.6 | Dell | Dell Command Update (DCU) | CWE-862 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authori… |
| CVE-2026-58564 | 7.8 | 0.6 | Dell | Dell Command Update (DCU) | CWE-276 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Defa… |
| CVE-2026-58562 | 7.3 | 0.6 | Dell | Dell Command Update (DCU) | CWE-862 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authori… |
| CVE-2026-76385 | 4.3 | 0.6 | Splunk | Venafi app for Splunk SOAR | CWE-312 | Information Disclosure through Action Parameters in Venafi app for Splunk SOAR |
| CVE-2026-16890 | 3.6 | 0.6 | IBM | AIX | CWE-190 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-32802 | 5.3 | 0.5 | Dell | PowerPath | CWE-269 | Dell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privileg… |
| CVE-2026-76241 | 7.3 | 0.4 | eidetic-labs | stigmem | CWE-494 | stigmem Plugin Signature Enforcement Bypass via Configuration |
| CVE-2026-16819 | 7.7 | 0.4 | IBM | AIX | CWE-367 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-53477 | 7.8 | 0.3 | Dell | Dell Command Update (DCU) | CWE-367 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check T… |
| CVE-2026-67266 | 5.5 | 0.3 | Dell | Dell Command Update (DCU) | CWE-863 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Auth… |
| CVE-2026-56797 | 7.3 | 0.3 | Dell | Dell Command Update (DCU) | CWE-367 | Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-u… |
| CVE-2026-16838 | 7.0 | 0.2 | IBM | AIX | CWE-367 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-4936 | 5.1 | 0.1 | IBM | PowerVM Hypervisor | CWE-331 | Power System Insufficient Entropy |