Security Box Score — August 20, 2026 — page 2
Edition of August 20, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-70383 | 8.4 | 4.6 | Estonian Information System Authority (RIA) | DigiDoc4 | CWE-22 | Arbitrary file overwrite vulnerability in DigiDoc4 client |
| CVE-2026-76833 | 8.4 | 4.5 | cgauge | @cgauge/yaml | CWE-95 | @cgauge/yaml npm Package Arbitrary Code Execution via eval() YAML Tag |
| CVE-2025-62300 | 5.9 | 4.3 | HCL Software | IEM | CWE-362 | HCL IntelliOps Event Management is affected by multiple security vulnerabilit… |
| CVE-2026-54625 | 4.8 | 4.2 | django-cms | django-cms | CWE-349 | django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poi… |
| CVE-2026-28164 | 9.6 | 4.1 | HashThemes | Easy Elementor Addons | CWE-352 | WordPress Easy Elementor Addons plugin <= 2.3.7 - Cross Site Request Forgery … |
| CVE-2026-18716 | 7.9 | 4.1 | IBM | AIX | CWE-125 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-67448 | 6.5 | 4.1 | axllent | mailpit | CWE-177 | Mailpit: WebSocket origin check bypass via percent-encoded path (regression o… |
| CVE-2026-43798 | await | 4.0 | Apple | swift-nio-ssh | — | A single crafted SSH message gives an unauthenticated network attacker an out… |
| CVE-2026-64773 | await | 4.0 | Apple | container | — | An attacker that can reach a container's published TCP port may be able to fo… |
| CVE-2026-63388 | 8.4 | 3.7 | libevent | libevent | CWE-617 | Libevent: Heap out-of-bounds write in bufferevent_socket_set_conn_address_ re… |
| CVE-2026-21784 | 4.8 | 3.8 | HCL Software | IEM | CWE-200 | HCL IntelliOps Event Management is affected by multiple security vulnerabilit… |
| CVE-2026-72852 | 8.5 | 3.6 | hank-ai | darknet | CWE-190 | darknet Integer Overflow in Convolutional Layer Buffer Sizing Leads to Heap B… |
| CVE-2026-55893 | 7.3 | 3.6 | capstone-engine | capstone | CWE-122 | Capstone SH disassembler `set_reg_n` heap buffer overflow via crafted SH2A FP… |
| CVE-2026-17422 | 9.3 | 3.2 | IBM | AIX | CWE-787 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-54389 | 6.7 | 3.2 | NationalSecurityAgency | ghidra | CWE-770 | Ghidra < 12.1.3 PDB Parser Uncontrolled Heap Growth DoS via AbstractPdb |
| CVE-2026-55894 | 6.8 | 3.1 | capstone-engine | capstone | CWE-125 | Capstone SH disassembler `sh_disassemble` out-of-bounds read via crafted SH2A… |
| CVE-2026-18263 | 7.8 | 3.0 | Parallels | RAS Client | CWE-749 | Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Pri… |
| CVE-2026-77118 | 8.4 | 2.9 | GraphicsMagick Group | GraphicsMagick | CWE-787 | Out-of-bounds write in GraphicsMagick PCD decoder |
| CVE-2026-13121 | 7.8 | 2.8 | Parallels | RAS Client | CWE-749 | Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Pri… |
| CVE-2026-18262 | 7.8 | 2.8 | Parallels | RAS Client | CWE-749 | Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Pri… |
| CVE-2026-18917 | 7.8 | 2.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-190 | Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buf… |
| CVE-2026-61898 | 7.8 | 2.9 | Canonical | accountsservice | CWE-78 | accountsservice: shell injection via attacker-controlled ~/.pam_environment i… |
| CVE-2026-17171 | 7.8 | 2.8 | IBM | AIX | CWE-59 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-16951 | 6.7 | 2.8 | IBM | AIX | CWE-787 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-18840 | 8.2 | 2.6 | IBM | AIX | CWE-822 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-16989 | 7.1 | 2.6 | IBM | AIX | CWE-59 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-55586 | 6.6 | 2.6 | sumatrapdfreader | sumatrapdf | CWE-119 | SumatraPDF: Heap out-of-bounds write in vendored CHMLib LZX Huffman table con… |
| CVE-2026-19442 | 8.2 | 2.3 | IBM | AIX | CWE-822 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-16997 | 7.8 | 2.3 | IBM | AIX | CWE-269 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-70653 | 4.8 | 2.3 | libvips | libvips | CWE-122 | libvips: Possible heap-based buffer read overflow when decoding a well-crafte… |
| CVE-2026-18842 | 8.4 | 2.2 | IBM | AIX | CWE-787 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-17124 | 7.8 | 2.2 | IBM | AIX | CWE-125 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-70651 | 6.9 | 2.1 | libvips | libvips | CWE-680 | libvips: Possible integer overflow when reading multi-page TIFF images via Im… |
| CVE-2026-63381 | 5.8 | 2.1 | libevent | libevent | CWE-908 | Libevent: Dangling Pointer in `evbuffer_add_buffer_reference` |
| CVE-2026-16943 | 7.8 | 2.0 | IBM | AIX | CWE-787 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-16944 | 7.8 | 2.0 | IBM | AIX | CWE-787 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-19783 | 6.7 | 1.8 | IBM | AIX | CWE-787 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-16936 | 8.8 | 1.7 | IBM | AIX | CWE-787 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-16945 | 7.8 | 1.7 | IBM | AIX | CWE-121 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-18270 | 7.8 | 1.8 | Kenwood | DNR1007XR | CWE-732 | Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Esca… |
| CVE-2026-16996 | 8.8 | 1.6 | IBM | AIX | CWE-787 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-70654 | 5.8 | 1.6 | libvips | libvips | CWE-122 | libvips: A well-crafted PPM image processed via a custom source could lead to… |
| CVE-2026-70652 | 2.0 | 1.6 | libvips | libvips | CWE-126 | libvips: Possible heap-based buffer read overflow when resizing and re-encodi… |
| CVE-2026-72854 | 5.8 | 1.5 | msgpack | msgpack-c | CWE-190 | msgpack-c Integer Overflow in msgpack_unpacker_expand_buffer Causes a False-S… |
| CVE-2026-63380 | 5.7 | 1.6 | libevent | libevent | CWE-416 | Libevent: Null Pointer Dereference in `evws_new_session` |
| CVE-2026-17007 | 6.7 | 1.4 | IBM | AIX | CWE-125 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-73542 | 6.3 | 1.4 | SEIKO EPSON CORPORATION | Multiple SEIKO EPSON printers and scanners | CWE-296 | Multiple SEIKO EPSON printers and scanners contain revoked root certificates.… |
| CVE-2026-16973 | 5.5 | 1.3 | IBM | AIX | CWE-200 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-18822 | 4.4 | 1.3 | IBM | AIX | CWE-400 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-16934 | 8.8 | 1.2 | IBM | AIX | CWE-787 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-16946 | 7.8 | 1.2 | IBM | AIX | CWE-787 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-19755 | 6.9 | 1.1 | NoSleep | NoSleep | CWE-862 | NoSleep 1.5.1 - Unauthorized disclosure of root-owned files through privilege… |
| CVE-2026-72847 | 2.4 | 1.1 | Canop | broot | CWE-150 | broot Terminal Escape Sequence Injection via Unsanitized File and Directory N… |
| CVE-2026-76957 | 4.9 | 1.0 | libexpat project | libexpat | CWE-416 | libexpat before 2.8.4 lacks handler call depth tracking with custom encoding … |
| CVE-2026-19449 | 8.8 | 0.9 | IBM | AIX | CWE-269 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-16991 | 7.8 | 0.9 | IBM | AIX | CWE-269 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-17195 | 6.5 | 0.9 | IBM | AIX | CWE-787 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-16952 | 5.5 | 0.9 | IBM | AIX | CWE-400 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-16980 | 5.5 | 0.9 | IBM | AIX | CWE-59 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-61897 | 7.8 | 0.8 | Canonical | accountsservice | CWE-273 | accountsservice: incomplete privilege drop when running Ubuntu-specific langu… |
| CVE-2026-16937 | 7.8 | 0.6 | IBM | AIX | CWE-269 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-17009 | 4.7 | 0.4 | IBM | AIX | CWE-476 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-64846 | 2.8 | 0.4 | NixOS | nix | CWE-61 | Nix: Arbitrary file truncation outside the sandbox with recursive-nix experim… |
| CVE-2026-16925 | 7.1 | 0.4 | IBM | AIX | CWE-285 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-16935 | 7.0 | 0.3 | IBM | AIX | CWE-367 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-16927 | 7.3 | 0.3 | IBM | AIX | CWE-367 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-16923 | 7.0 | 0.2 | IBM | AIX | CWE-269 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-16922 | 7.0 | 0.1 | IBM | AIX | CWE-367 | Vulnerabilities in IBM AIX and PowerVM VIOS |