boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Friday, August 21, 2026 · all times UTC← 2026-08-20 · archive · 2026-08-22 →

Security Box Score — August 21, 2026

CISA adds 1 to KEV; 260 CVEs published, led by Apache Software Foundation (21).

260 CVEs published August 21, 2026: 38 critical, 93 high, 89 medium, 20 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 20 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 235 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published907031234——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

1723 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux12673582363178163711120.17.8.0017+788 ▲
microsoft4691891145128145114286271.47.8.0044-177 ▼
google711832224765786577760.37.5.0025-44 ▼
red hat1895754323726431200.06.8.0029+96 ▲
apple40311588216368882.66.5.0029+40 ▲
canonical14411211135000.07.8.0020+7 ▲
freebsd233902340000.07.8.0015+23 ▲
suse52651461000.08.1.0039-3 ▼
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco46842139240561315.57.5.0044+31 ▲
palo alto networks12371321121325.44.7.0020-2 ▼
ubiquiti036142110338.38.8.0049-25 ▼
netgear93200275000.04.3.0025+3 ▲
fortinet7307814128620.07.0.0050-6 ▼
vmware21949427210.58.1.0040-6 ▼
f50165830416.38.6.0057-8 ▼
ivanti314482025535.78.3.0754+1 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache13246890198157133320.47.5.0048+40 ▲
mozilla591866868500900.08.1.0031-11 ▼
gitlab1566214428423.05.1.0029+8 ▲
drupal05165355412.05.9.0026-46 ▼
github5171790000.06.6.00430
docker290630000.07.2.0016+2 ▲
wordpress2513102240.08.8.31200
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle88922684871172513962730.17.8.0034-209 ▼
ibm3746031332851769610.27.5.0029+338 ▲
adobe603123914512351931.07.8.0026-35 ▼
progress19611437100611.68.1.0037+8 ▲
solarwinds0231733010417.49.1.0058-15 ▼
veeam10165920100.08.6.0034+10 ▲
zohocorp4103520000.08.7.0140+2 ▲
atlassian3615001300.08.1.00340
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link163615597300.07.4.0157+8 ▲
siemens193522382000.07.3.0016+12 ▲
rockwell automation12541830000.08.7.0029-16 ▼
synology12426133000.05.6.0025+1 ▲
schneider electric091620000.08.6.00370
abb070430000.07.2.0018-1 ▼
hikvision060420000.07.2.00400
moxa050320000.07.0.00290
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester37157008671000.05.5.0029-12 ▼
dell561551083575210.67.2.0019+19 ▲
splunk110128647705110.86.5.0025+107 ▲
openclaw01110583914000.07.0.0026-44 ▼
nvidia241061471210000.07.5.0034-17 ▼
siyuan-note69914219281000.08.7.0028+63 ▲
zephyrproject3790232479000.06.5.0022+16 ▲
itsourcecode1990001971000.02.1.0032+2 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.995799.99.8
CVE-2026-34486.986299.97.5
CVE-2026-63077.847399.79.8
CVE-2026-72898.792299.610.0
CVE-2026-59310.458898.79.8
CVE-2026-61511.339998.39.3
CVE-2026-64638.312098.18.9
CVE-2025-68686.291598.05.9
CVE-2026-71362.251497.89.1
CVE-2026-66066.189597.19.5
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.7922KEV
CVE-2026-651610.0.0486
CVE-2026-4836210.0.0431
CVE-2026-4766810.0.0388
CVE-2026-1918810.0.0193
CVE-2026-5823110.0.0171
CVE-2026-6983610.0.0159
CVE-2026-1681210.0.0157KEV
CVE-2026-7329910.0.0121
CVE-2025-7138910.0.0120
Most disclosures (vendor)
VendorCVEs
linux1623
oracle889
microsoft488
google452
ibm442
red hat251
apache221
apple207
splunk110
siyuan-note76
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco13
apple8
fortinet6
google6
ivanti5
solarwinds4
adobe3
berriai3
oracle3
Most-affected ecosystems
EcosystemAdvisories
Maven56
PyPI10
npm6
Go4
Packagist2
NuGet1
crates.io1
Fastest to KEV
CVEVendorDays
CVE-2025-68686Fortinet0
CVE-2026-16812Arista Networks0
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20316Cisco0
CVE-2026-20349Cisco0
CVE-2026-34486Apache Software Foundation0
CVE-2026-63077JetBrains0
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171738
CVE-2021-27102n/a2021-11-171738
CVE-2021-27101n/a2021-11-171738
CVE-2021-27103n/a2021-11-171738
CVE-2021-21017Adobe2021-11-171738
CVE-2021-28550Adobe2021-11-171738
CVE-2021-42013Apache Software Foundation2021-11-171738
CVE-2021-41773Apache Software Foundation2021-11-171738
CVE-2021-30858Apple2021-11-171738
CVE-2021-30860Apple2021-11-171738

Transactions

ADDED TO KEV — CVE-2026-73570 (Zimbra Collaboration). Remediation due August 24, 2026.

EXPLOIT PUBLISHED — gimp: 4 CVEs (CVE-2026-59088, CVE-2026-59089, CVE-2026-59090, CVE-2026-59091). Public exploit references added.

EXPLOIT PUBLISHED — netty: 3 CVEs (CVE-2026-42579, CVE-2026-42581, CVE-2026-42584). Public exploit references added.

EXPLOIT PUBLISHED — Red Hat Enterprise Linux 10: 3 CVEs (CVE-2026-35091, CVE-2026-35092, CVE-2026-55654). Public exploit references added.

EXPLOIT PUBLISHED — Red Hat Hardened Images: 3 CVEs (CVE-2026-0989, CVE-2026-0990, CVE-2026-0992). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2017-20268 (Zcontent Zap Calendar Lite). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2017-20269 (Terrywcarter KissGallery). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2017-20270 (Raindropsinfotech Twitch Tv). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2017-20271 (Nordmograph StreetGuessr Game). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2017-20273 (Joomlashowroom Event Registration Pro Calendar). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2017-20275 (Henryschorradt Bridge). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2019-25754 (Wdmtech vRestaurant). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2019-25755 (Wdmtech vReview). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2019-25756 (Wdmtech vAccount). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2019-25757 (Wdmtech vWishlist). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2019-25760 (Joomtech Easy Shop). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2019-25761 (Joomboost JoomCRM). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2019-25762 (Joomboost JoomProject). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2022-4996 (mruby). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-54357 (Artio Joomla! com_booking component). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-4598 (systemd-coredump). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19579 (Grokability Snipe-IT). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-3832 (gnutls). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-41523 (vllm-project vllm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-53804 (Centuran Consulting OTRS Community Edition). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-69414 (Microsoft Malware Protection Engine). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-72529 (TrueConf Server). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-72530 (TrueConf Server). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-72844 (leanprover lean4). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76764 (code-projects Employee Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76799 (code-projects Login Registration System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76800 (DeDeCMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76991 (itsourcecode Hospital Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76997 (SourceCodester Simple Online Food Ordering System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76998 (SourceCodester Simple Online Food Ordering System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-77020 (CodeAstro Apartment Visitor Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-77022 (Comfast CF-N1-S). Public exploit reference added.

DUE DATE PASSED — CVE-2025-62593 (ray-project ray). CISA remediation deadline was August 20, 2026; still in catalog.

RESCORED — IBM Db2 Mirror for i: 4 CVEs (CVE-2026-17186, CVE-2026-17209, CVE-2026-17227, CVE-2026-18178). CVSS rescored — before/after on each CVE page.

RESCORED — Red Hat Hardened Images: 4 CVEs (CVE-2025-14821, CVE-2026-3184, CVE-2026-3441, CVE-2026-3442). CVSS rescored — before/after on each CVE page.

RESCORED — libarchive: 3 CVEs (CVE-2025-5916, CVE-2025-5917, CVE-2025-5918). CVSS rescored — before/after on each CVE page.

RESCORED — Red Hat Enterprise Linux 10: 3 CVEs (CVE-2026-0964, CVE-2026-0966, CVE-2026-0967). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2024-12086 (rsync). CVSS 6.1 → 6.8 (NVD).

RESCORED — CVE-2025-32988 (libgnutls). CVSS 6.5 → 8.2 (NVD).

RESCORED — CVE-2025-32990 (libgnutls). CVSS 6.5 → 8.2 (NVD).

RESCORED — CVE-2025-46281 (Apple macOS). CVSS 8.4 → 8.8 (NVD).

RESCORED — CVE-2025-46291 (Apple macOS). CVSS 5.5 → 7.8 (NVD).

RESCORED — CVE-2025-5372 (libssh). CVSS 5 → 8.8 (NVD).

RESCORED — CVE-2026-59090 (gimp). CVSS 8.4 → 9.9 (NVD).

RESCORED — CVE-2026-59091 (gimp). CVSS 7.3 → 7.8 (NVD).

Yesterday's Results

How to read these box scores · glossary

260 CVEs published. 25 box scores, 235 table rows — nothing truncated.

Comfast CF-N1-S mbox-config system command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0151   72.5     —
AFFECTED
  Product  Versions   Fixed
  CF-N1-S  2.6.0.1 –  —
TIMELINE
  Aug 21  Reserved by CNA
  Aug 21  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Apache CloudStack: Get and Run Diagnostics Command Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0122   66.4     —
AFFECTED
  Product            Versions    Fixed
  Apache CloudStack  4.14.0.0 –  —
TIMELINE
  Jul 9   Reserved by CNA
  Aug 21  Published (CNA: apache)
CWE-77 · CNA: apache · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
Cloud Foundry Foundation BOSH CLI — CVE-2026-47827 – BOSH CLI Powershell Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   A   H   N   N  U  H  H  H    7.5   .0116   64.7     —
AFFECTED
  Product   Versions  Fixed
  BOSH CLI  0.0 –     —
TIMELINE
  May 20  Reserved by CNA
  Aug 21  Published (CNA: vmware)
CWE-77 · CNA: vmware · CVSS v3.1 · 1 reference · NVD status: Received
Datiphy Data Management Center - Improper Neutralization of Special Elements used in an OS Command
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    9.4   .0083   54.9     —
AFFECTED
  Product                 Versions  Fixed
  Data Management Center  v8.3.0 –  —
TIMELINE
  Aug 19  Reserved by CNA
  Aug 21  Published (CNA: ZUSO ART)
CWE-78 · CNA: ZUSO ART · CVSS v4.0 · 1 reference · NVD status: Received
lxc incus — Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0081   54.0     —
AFFECTED
  Product  Versions   Fixed
  incus    < 7.2.0 –  —
TIMELINE
  May 22  Reserved by CNA
  Aug 21  Published (CNA: GitHub_M)
CWE-73 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Received
lxc incus — Incus has arbitrary file read+write on host via templates/ symlink in malicious image
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0081   54.0     —
AFFECTED
  Product  Versions   Fixed
  incus    < 7.2.0 –  —
TIMELINE
  May 22  Reserved by CNA
  Aug 21  Published (CNA: GitHub_M)
CWE-73 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Received
lxc incus — Incus has an arbitrary file write on host via `exec-output` symlink in crafted image
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0078   53.3     —
AFFECTED
  Product  Versions   Fixed
  incus    < 7.2.0 –  —
TIMELINE
  May 22  Reserved by CNA
  Aug 21  Published (CNA: GitHub_M)
CWE-73 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Received
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the w…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0078   53.3     —
AFFECTED
  Product  Versions     Fixed
  SPIP     unspecified  —
TIMELINE
  Aug 21  Reserved by CNA
  Aug 21  Published (CNA: mitre)
CWE-94 · CNA: mitre · CVSS v3.1 · 4 references · NVD status: Received
ggml-org llama.cpp — llama.cpp Use-After-Free in RPC GRAPH_RECOMPUTE Handler
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   H   H   H    9.2   .0077   52.8     —
AFFECTED
  Product    Versions     Fixed
  llama.cpp  unspecified  —
TIMELINE
  Apr 7   Reserved by CNA
  Aug 21  Published (CNA: VulnCheck)
CWE-416 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Received
tclahr uac — UAC < 3.3.0 Command Injection via User Substitution in parse_artifact.sh
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   N   P   H   H   H    8.5   .0072   51.1     —
AFFECTED
  Product  Versions     Fixed
  uac      unspecified  —
TIMELINE
  Apr 20  Reserved by CNA
  Aug 21  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
lxc incus — Incus has an arbitrary file write via path traversal in S3 multipart upload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0071   50.7     —
AFFECTED
  Product  Versions   Fixed
  incus    < 7.1.0 –  —
TIMELINE
  May 22  Reserved by CNA
  Aug 21  Published (CNA: GitHub_M)
CWE-73 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Received
lxc incus — Incus has a restricted project bypass leading to arbitrary command execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0070   50.5     —
AFFECTED
  Product  Versions   Fixed
  incus    < 7.2.0 –  —
TIMELINE
  May 22  Reserved by CNA
  Aug 21  Published (CNA: GitHub_M)
CWE-862 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Received
4xmen xshop — xShop: Unrestricted File Upload in File Attachment Module in Admin panel leads to Arbitrary Code Execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0070   50.3     —
AFFECTED
  Product  Versions   Fixed
  xshop    = 3.0.3 –  —
TIMELINE
  Jun 1   Reserved by CNA
  Aug 21  Published (CNA: GitHub_M)
CWE-434 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Received
tclahr uac — UAC < 3.3.0 Command Injection via command_collector.sh
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   N   P   H   H   H    8.5   .0070   50.3     —
AFFECTED
  Product  Versions     Fixed
  uac      unspecified  —
TIMELINE
  Apr 20  Reserved by CNA
  Aug 21  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
xorbitsai inference — Xinference: Remote code execution via unsafe `eval()` in Llama3 tool-call parsing
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0066   48.7     —
AFFECTED
  Product    Versions   Fixed
  inference  < 2.7.0 –  —
TIMELINE
  Jul 10  Reserved by CNA
  Aug 21  Published (CNA: GitHub_M)
CWE-95 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Received
siyuan-note siyuan — SiYuan before v3.7.4 Path Traversal via packageName
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    9.4   .0065   48.2     —
AFFECTED
  Product  Versions     Fixed
  siyuan   unspecified  3.7.4
TIMELINE
  Aug 20  Reserved by CNA
  Aug 21  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
tclahr uac — UAC < 3.3.0 Command Injection via run_command.sh
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   N   P   H   H   H    8.5   .0064   47.9     —
AFFECTED
  Product  Versions     Fixed
  uac      unspecified  —
TIMELINE
  Apr 20  Reserved by CNA
  Aug 21  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
Microsoft Azure SQL Database — Azure SQL Database Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  N   10.0   .0058   45.2     —
AFFECTED
  Product             Versions  Fixed
  Azure SQL Database  - –       —
TIMELINE
  Aug 3   Reserved by CNA
  Aug 21  Published (CNA: microsoft)
CWE-918 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Received
101gen Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code — Automation Web Platform <= 4.8.6 - Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0057   44.5     —
AFFECTED
  Product                                                                                 Versions     Fixed
  Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 21  Published (CNA: Wordfence)
CWE-640 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
Runtipi: Authenticated arbitrary file write via backup restore symlink planting
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  N  H  H    6.5   .0053   42.3     —
AFFECTED
  Product  Versions    Fixed
  runtipi  < 4.10.1 –  —
TIMELINE
  Jun 16  Reserved by CNA
  Aug 21  Published (CNA: GitHub_M)
CWE-59, CWE-61 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Received
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0052   42.1     —
AFFECTED
  Product   Versions  Fixed
  geotools  = 35.0 –  —
TIMELINE
  Aug 19  Reserved by CNA
  Aug 21  Published (CNA: GitHub_M)
CWE-89 · CNA: GitHub_M · CVSS v3.1 · 9 references · NVD status: Received
CVE-2026-47359AWAITING ENRICHMENT
Apache CloudStack: OS Command Injection due to unsanitized mount command
  CVSS   EPSS    %ile   KEV
  —      .0051   41.4   —
AFFECTED
  Product            Versions    Fixed
  Apache CloudStack  4.20.0.0 –  —
TIMELINE
  May 19  Reserved by CNA
  Aug 21  Published (CNA: apache)
CWE-78 · CNA: apache · 1 reference · NVD status: Awaiting Analysis
jsonata-js jsonata — JSONata: Arbitrary Code Execution via crafted JSONata expressions
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0051   41.0     —
AFFECTED
  Product  Versions   Fixed
  jsonata  < 1.8.8 –  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 21  Published (CNA: GitHub_M)
CWE-94 · CNA: GitHub_M · CVSS v4.0 · 11 references · NVD status: Received
misp misp-stix — Path Traversal in MISP Object Template Resolution During STIX Import and Export in misp-stix library
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   L   N    8.8   .0048   39.4     —
AFFECTED
  Product    Versions     Fixed
  misp-stix  unspecified  —
TIMELINE
  Aug 21  Reserved by CNA
  Aug 21  Published (CNA: CIRCL)
CWE-22 · CNA: CIRCL · CVSS v4.0 · 2 references · NVD status: Received
keystonejs keystone — Keystone: `graphql.maxTake` bypass with negative `take`
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0047   38.5     —
AFFECTED
  Product   Versions   Fixed
  keystone  < 6.5.3 –  —
TIMELINE
  Jul 16  Reserved by CNA
  Aug 21  Published (CNA: GitHub_M)
CWE-20, CWE-480 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-493607.837.1DataReccerecceCWE-73Recce server has unauthenticated SQL execution that allows local file read/wr…
CVE-2026-626758.837.1omnigent-aiomnigentCWE-94Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Ca…
CVE-2026-347418.637.0CombodoiTopCWE-306Combodo iTop: Authentication bypass in exec.php allows PHP file execution
CVE-2026-626778.836.9omnigent-aiomnigentCWE-22Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesy…
CVE-2026-487559.936.4lxcincusCWE-20Incus has an argument injection in backup compression algorithm leading to AF…
CVE-2026-487699.936.4lxcincusCWE-20Incus has an arbitrary file write on its client due to trusted image hash
CVE-2026-552417.536.3bluewave-labsCheckmateCWE-400Checkmate: Pre-auth Denial of Service via File Upload on Registration
CVE-2026-776499.836.0droundyinternmentCWE-506The internment crate 0.8.7 for Rust can trigger execution of malicious code w…
CVE-2026-776509.836.0droundyappend-only-vecCWE-506The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious c…
CVE-2026-776519.836.0droundyarrayrefCWE-506The arrayref crate 0.3.10 for Rust can trigger execution of malicious code wh…
CVE-2026-714935.935.2infracostinfracostCWE-22Infracost: Arbitrary file read via config-template readFile symlink traversal
CVE-2026-551855.135.3minifluxv2CWE-601Miniflux 2: Open Redirect Bypass
CVE-2026-450996.935.0gruntwork-ioterragruntCWE-22Terragrunt: Arbitrary File Deletion via Malicious Module Manifest
CVE-2026-631259.934.6lxcincusCWE-59Incus vulnerable to root RCE via image backup.yaml symlink
CVE-2026-761578.834.5Datiphy Inc.Data Management CenterCWE-306Datiphy Data Management Center - Missing Authentication for Critical Function
CVE-2026-742528.634.4j2commerce.comJ2Store extension for JoomlaCWE-79Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1…
CVE-2026-706564.934.4bluewave-labsCheckmateCWE-1333Checkmate: Regular Expression Denial of Service (ReDoS) via User-Controlled R…
CVE-2026-761589.334.2Datiphy Inc.Data Management CenterCWE-73Datiphy Data Management Center - External Control of File Name or Path
CVE-2026-778158.733.8zanllpinfinite-image-browsingCWE-59Infinite Image Browsing Resolves Paths With normpath, Allowing Symlink Escape…
CVE-2026-774139.333.7jsonata-jsjsonataCWE-94JSONata: Arbitrary Code Execution via crafted JSONata expressions
CVE-2026-778148.733.7zanllpinfinite-image-browsingCWE-22Infinite Image Browsing is_path_trusted Prefix Comparison Omits the Trailing …
CVE-2026-759329.232.8Jet AdminJet AdminCWE-862Jet Admin tenant isolation failure
CVE-2026-770879.432.5paperclipaipaperclipCWE-862Paperclip before 0.3.1 Remote Code Execution via DNS Rebinding
CVE-2026-547897.532.2OpenIDCmod_auth_openidcCWE-125mod_auth_openidc has out-of-bounds read and write in state cookie parsing
CVE-2026-759286.931.8BrushfireOnline ExperienceCWE-497Brushfire unauthenticated information disclosure
CVE-2026-592797.531.4SpringSpring AICWE-770Unbounded persistent session allocation via repeated initialize requests
CVE-2026-646798.131.1runatlantisatlantisCWE-22Atlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds …
CVE-2026-634627.530.7UnleashunleashCWE-674Unleash: Unauthenticated single-request DoS via OpenAPI validation error form…
CVE-2026-501128.830.0Apache Software FoundationApache CloudStackCWE-78Apache CloudStack: RCE and SSRF in direct download, metalink and NFS templates
CVE-2026-163237.530.1FuyaWeb Internet and Informatics ServicesArchitectPanel Web Admin PanelCWE-698Authentication Bypass via Execution After Redirect in FuyaSoft's Architect Pa…
CVE-2026-593235.329.9VMwareSpringCWE-770Micrometer Tracing Brave Bridge W3C Baggage propagation DoS vulnerability
CVE-2026-778116.229.8AWSAmazon OpenSearch ServiceCWE-79Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dash…
CVE-2026-777616.329.7mispmisp-stixCWE-459Cross-Document Parser State Contamination in misp-stix
CVE-2026-622839.929.6nezhahqnezhaCWE-639Nezha Monitoring: Cross-tenant terminal/file-manager session hijack via WebSo…
CVE-2026-75501await29.5CalixGS7 XGS (GS5239XG)—CVE-2026-75501
CVE-2026-714945.929.3infracostinfracostCWE-522Infracost: Terraform Cloud and registry token disclosure via unvalidated host…
CVE-2026-777757.729.0Headroom LabsHeadroomCWE-918Headroom Proxy Sends Upstream Requests to a Client-Supplied Base URL Without …
CVE-2026-777678.728.8reconmapreconmapCWE-862Reconmap Report Preview Endpoint Is Marked AllowAnonymous, Exposing Every Pro…
CVE-2026-629607.428.8git-for-windowsgitCWE-200Git for Windows: Server-advertised bundle-uri can trigger outbound SMB callba…
CVE-2026-480508.828.5Basekick-LabsarcCWE-200Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state a…
CVE-2026-502905.328.3asymmetric-effortspecifyjsCWE-79@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in re…
CVE-2026-769057.528.0getkinkin-openapiCWE-476kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed mu…
CVE-2026-718627.527.9bluewave-labsCheckmateCWE-200Checkmate: Sensitive Bearer Token Exposure via Public Status Pages When showU…
CVE-2026-778109.427.3AWSAthena Federated Query Neptune ConnectorCWE-95Code Injection via Gremlin Query Passthrough in Amazon Athena Neptune Connector
CVE-2026-774149.327.3jsonata-jsjsonataCWE-94JSONata: Arbitrary Code Execution via crafted JSONata expressions
CVE-2026-766128.627.3yootheme.comZoo extension for JoomlaCWE-79Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-control…
CVE-2026-535288.827.1perberleafwikiCWE-23FileWiki has path traversal in RenameAsset via unsanitized oldFilename parameter
CVE-2026-777769.327.0Headroom LabsHeadroomCWE-639Headroom Proxy Treats the Client-Supplied x-headroom-user-id Header as an Aut…
CVE-2026-626749.026.8omnigent-aiomnigentCWE-94Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
CVE-2026-692285.326.8EsriPortal for ArcGISCWE-306missing authentication vulnerability in Esri Portal for ArcGIS
CVE-2026-673625.126.4j2commerce.comJ2Store extension for JoomlaCWE-601Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Sto…
CVE-2026-732677.725.8Red HatMulticluster Engine for KubernetesCWE-602Clusterclaims-controller: clusterclaims-controller: managedcluster deletion k…
CVE-2026-766116.925.5yootheme.comZoo extension for JoomlaCWE-22Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing…
CVE-2026-692245.925.4EsriPortal for ArcGISCWE-200information disclosure vulnerability in Esri Portal for ArcGIS
CVE-2026-692255.925.4EsriPortal for ArcGISCWE-200information disclosure vulnerability in Esri Portal for ArcGIS
CVE-2026-777637.124.8juicedatajuicefsCWE-22JuiceFS Local Filestore Backend Joins Object Keys onto the Storage Root Witho…
CVE-2026-505388.824.3LibVNClibvncserverCWE-122libvncclient Tight decoder has an attacker-controlled heap out-of-bounds write
CVE-2026-777598.724.2RoskusProspero Flow CRMCWE-639IDOR and missing authorization in the Prospero Flow CRM transaction API allow…
CVE-2026-187818.124.3UnknownDrag and Drop Multiple File Upload for Contact Form 7CWE-94Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Unauthentic…
CVE-2026-535725.924.1kedacorekedaCWE-74KEDA: PostgreSQL connection string parameter injection via incomplete whitesp…
CVE-2026-623168.823.8microsoftUFOCWE-200Microsoft UFO: DNS Rebinding → Unauthenticated File Read / Command Execution
CVE-2026-558505.323.7element-hqelement-webCWE-79Element Web: A malicious homeserver can inject HTML in Element Web using its …
CVE-2026-274627.523.6CombodoiTopCWE-204Combodo iTop: User enumeration via password reset
CVE-2026-274907.523.6CombodoiTopCWE-330Combodo iTop: Weak secret generation for inline image
CVE-2026-194415.323.6IKAS Technology Inc.RushCWE-306Unauthenticated API Allows Analytics Data Manipulation in IKAS Technology's Rush
CVE-2026-599899.223.4phalconcphalconCWE-94Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI lea…
CVE-2026-751157.023.4yootheme.comYOOtheme Pro extension for JoomlaCWE-22Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file re…
CVE-2026-777558.722.5mispmisp-stixCWE-400Denial of Service in MISP-STIX Import via Malformed or Oversized STIX Documen…
CVE-2026-773548.722.2getkinkin-openapiCWE-400kin-openapi: Uncontrolled resource consumption in openapi3filter deepObject q…
CVE-2026-759338.521.8Jet AdminJet AdminCWE-79Jet Admin Stored XSS
CVE-2026-626767.121.4omnigent-aiomnigentCWE-184Omnigent Guardrail policy bypass: shell-command parser fails open in policies…
CVE-2026-544577.721.4tensorzerotensorzeroCWE-552TensorZero: Arbitrary file read and SSRF in TensorZero Gateway's internal obj…
CVE-2026-477357.121.3Basekick-LabsarcCWE-22Arc has an authenticated arbitrary local-file read via DuckDB I/O functions t…
CVE-2026-766138.621.3yootheme.comYOOtheme Pro extension for JoomlaCWE-89Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in …
CVE-2026-761559.321.1Datiphy Inc.Data Management CenterCWE-1392Datiphy Data Management Center - Use of Default Credentials
CVE-2026-777106.921.1MISPmisp-stixCWE-20STIX2 Parser Confusion and Mass Assignment Allow Unauthorized MISP Attribute …
CVE-2026-628679.920.8lxcincusCWE-88Incus has an argument injection in storage volume block.create_options that l…
CVE-2026-630468.820.7Apache Software FoundationApache InLongCWE-88Apache InLong: Agent Installer — Command Injection to RCE via Default Credent…
CVE-2026-172517.120.8TP-Link Systems Inc.TL-MR6400 v7.0CWE-476Unauthenticated Denial of Service via Null Pointer Dereference in HTTP Reques…
CVE-2026-768768.220.0puemoscraftplanCWE-862Craftplan < 0.5.1 Broken Access Control Information Disclosure via Settings API
CVE-2026-348366.519.9CombodoiTopCWE-862Combodo iTop: Improper access control in ajax.render.php and ajax.document.php
CVE-2026-502888.719.5asymmetric-effortspecifyjsCWE-918@asymmetric-effort/specifyjs: URL parse failure silently allows request
CVE-2026-226818.319.5VolcengineOpenVikingCWE-918OpenViking < 0.3.4 SSRF via /api/v1/resources
CVE-2026-630045.519.4UnleashunleashCWE-918Unleash: Addon webhook URL is dialed server-side with no internal-address fil…
CVE-2026-776862.119.3n/aDolibarrCWE-266Dolibarr Account card.php improper authorization
CVE-2026-308667.518.8CombodoiTopCWE-200Combodo iTop: Insecured access to uploaded images via sniffed url
CVE-2026-776812.118.7CodeAstroOnline Job PortalCWE-284CodeAstro Online Job Portal update-profile.php unrestricted upload
CVE-2026-332408.818.6CombodoiTopCWE-79Combodo iTop: Reflected XSS in foreign key search criteria
CVE-2026-155766.918.6Checkmk GmbHCheckmkCWE-306Agent receiver accepts mTLS requests without a client certificate
CVE-2026-535246.518.4weechatweechatCWE-409WeeChat has a Decompression Bomb in Relay WebSocket (DoS)
CVE-2026-633439.918.3lxcincusCWE-73Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesys…
CVE-2026-319368.818.4CombodoiTopCWE-862Combodo iTop: Unauthorized access to object information via search operation
CVE-2026-673598.717.5j2commerce.comJ2Store extension for JoomlaCWE-639Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.…
CVE-2026-757967.217.6UnknownAI EngineCWE-269AI Engine 2.8.0 - 3.6.0 - Admin+ Multisite Network Administrator Account Take…
CVE-2026-165767.217.0UnknownDokan: AI Powered WooCommerce Multivendor Marketplace SolutionCWE-284Dokan < 5.0.14 - Shop Manager+ Arbitrary Plugin Installation/Activation via R…
CVE-2026-535316.917.0erweixinRaTeXCWE-400ratex-parser has unbounded parser recursion that leads to stack overflow (pro…
CVE-2026-308197.316.8CombodoiTopCWE-79Combodo iTop: Reflected XSS in /pages/ajax.render.php dashboard_id parameter
CVE-2026-175595.316.7UnknownPasssterCWE-863Content Protector (Passster) < 4.3.9 - Unauthenticated Protected Content Disc…
CVE-2026-535257.416.6weechatweechatCWE-208WeeChat has Non-Constant-Time Password Hash Comparison in Relay Authentication
CVE-2026-535308.716.4erweixinRaTeXCWE-248ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundar…
CVE-2026-777805.316.4RoskusProspero Flow CRMCWE-639Unvalidated bank account and card foreign keys in the Prospero Flow CRM trans…
CVE-2026-685087.816.3facebookresearchhydraCWE-94Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
CVE-2026-274635.316.0CombodoiTopCWE-200Combodo iTop: Version disclosure via login page logo
CVE-2026-773922.116.1SourceCodesterDynamic Input Field Generator Using HTML, CSS, and PHPCWE-74SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP submit.…
CVE-2026-692335.515.9EsriPortal for ArcGISCWE-79stored cross site scripting issue in Esri Portal for ArcGIS
CVE-2026-631358.215.8YOURLSYOURLSCWE-79YOURLS: Stored XSS in referrer statistics chart via crafted Referer header
CVE-2026-502786.515.7InternationalColorConsortiumiccDEVCWE-125iccDEV: CIccEmbedIO::Read8() size_t underflow
CVE-2026-629419.915.7lxcincusCWE-863Incus: Cross-project instance copy bypasses target project restrictions via T…
CVE-2026-535278.815.5perberleafwikiCWE-269LeafWiki Vulnerable to Privilege Escalation via User Self-Service Update
CVE-2026-770285.315.4yootheme.comZoo extension for JoomlaCWE-79Joomla Extension - yootheme.com - Reflected XSS and open redirect via the sub…
CVE-2026-777687.115.3Openpanel-devopenpanelCWE-639OpenPanel report.get Returns Any Report by Identifier Without Checking Projec…
CVE-2026-777697.115.3Openpanel-devopenpanelCWE-639OpenPanel report.list Queries Reports by an Unverified dashboardId, Crossing …
CVE-2026-535294.815.2perberleafwikiCWE-79LeafWiki vulnerable to stored XSS via search-result title (highlight() return…
CVE-2026-772207.114.8michaelrsweetpdfioCWE-825PDFio < 1.6.5 Dangling Pointer via Dictionary String-Formatting
CVE-2026-673606.314.8j2commerce.comJ2Store extension for JoomlaCWE-639Joomla Extension - j2commerce.com - Cross-customer order replication in J2Sto…
CVE-2026-692315.514.6EsriPortal for ArcGISCWE-79stored cross site scripting issue in Esri Portal for ArcGIS
CVE-2026-692325.514.6EsriPortal for ArcGISCWE-79stored cross site scripting issue in Esri Portal for ArcGIS
CVE-2026-137365.314.6UnknownNewPath WildApricotPress Add-onCWE-284NewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated…
CVE-2026-77781await14.6—Tie-Hash-RegexCWE-248Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on un…
CVE-2026-131762.714.5UnknownEventinCWE-918Eventin < 4.1.21 - Contributor+ Server-Side Request Forgery
CVE-2026-692346.114.2EsriPortal for ArcGISCWE-79reflected cross site scripting vulnerability in Esri Portal for ArcGIS
CVE-2026-308268.014.0CombodoiTopCWE-79Combodo iTop: Reflected XSS in run_query.php
CVE-2026-308908.014.0CombodoiTopCWE-79Combodo iTop: Reflected XSS in synchro/synchro_import.php
CVE-2026-318038.014.0CombodoiTopCWE-79Combodo iTop: Reflected XSS in tag admin
CVE-2026-318808.014.0CombodoiTopCWE-79Combodo iTop: Reflected XSS in universal search
CVE-2026-534975.314.1cenodudeCrossWatchCWE-200CrossWatch: Unauthenticated /api/app-auth/status endpoint leaks active sessio…
CVE-2026-629409.913.9lxcincusCWE-862Incus has a project restriction bypass via instance migration config override
CVE-2026-184097.213.8WPFormsWPForms ProCWE-79WPForms Pro <= 2.0.0.2 - Unauthenticated Stored Cross-Site Scripting via Sing…
CVE-2026-146016.813.7UnknownLink Whisper FreeCWE-89Link Whisper < 0.9.7 - Editor+ SQL Injection via domain Parameter
CVE-2026-169596.813.7UnknownMedia Library AssistantCWE-89Media Library Assistant < 3.40 - Author+ SQL Injection via mla_search_connector
CVE-2026-618248.213.4kepanodefuddleCWE-79Defuddle: XSS via unescaped attribute interpolation in site extractors
CVE-2026-535414.313.3OliveTinOliveTinCWE-20OliveTin has Unvalidated `ot_`-prefixed Arguments that Bypass Input Filtering
CVE-2026-349487.713.2CombodoiTopCWE-200Combodo iTop: Access control bypass via OQL joins
CVE-2026-596546.813.1Apache Software FoundationApache CloudStackCWE-772Apache CloudStack: DoS caused by database connections leak
CVE-2026-487542.113.1lxcincusCWE-476Incus: Nil-pointer dereference in createDependentVolumesFromBackup on disk.{V…
CVE-2026-487562.113.1lxcincusCWE-476Incus: CreateCustomVolumeFromBackup nil-pointer dereference on volume_snapsho…
CVE-2026-198486.512.7UnknownProfilePressCWE-74ProfilePress < 4.17.1 - Unauthenticated Arbitrary Shortcode Execution via Dis…
CVE-2026-692295.412.6EsriPortal for ArcGISCWE-79HTML injection vulnerability in Esri Portal for ArcGIS
CVE-2026-349496.512.4CombodoiTopCWE-306Combodo iTop: Unauthenticated user can delete .readonly file
CVE-2026-330474.312.3CombodoiTopCWE-862Combodo iTop: Object can be locked by a user without write permissions
CVE-2026-535095.711.9ondatackan-mcp-serverCWE-918@aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networ…
CVE-2026-623134.311.4lxcincusCWE-863Incus: Project restriction `restricted.containers.privilege=isolated` bypassa…
CVE-2026-541347.011.3OctoPrintOctoPrintCWE-73OctoPrint: File exfiltration possible via query parameters on upload endpoints
CVE-2026-206794.311.2ApplemacOSCWE-125The issue was addressed with improved checks. This issue is fixed in macOS Se…
CVE-2026-165755.310.6UnknownDokan: AI Powered WooCommerce Multivendor Marketplace SolutionCWE-200Dokan < 5.0.14 - Unauthenticated Commission Settings Disclosure via Store Cat…
CVE-2026-556217.79.9lxcincusCWE-284Incus has a project restriction bypass for custom volume copy across projects
CVE-2026-556227.79.9lxcincusCWE-284Incus has a project restriction bypass in instance copy across projects
CVE-2026-777955.39.9DromaraRuoYi-Vue-PlusCWE-266Dromara RuoYi-Vue-Plus Workflow Endpoint TestLeaveController improper authori…
CVE-2026-761316.99.6Yamaha CorporationVOCALOID6CWE-798Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an …
CVE-2026-183563.79.5UnknownLimit Login Attempts SecurityCWE-184Limit Login Attempts Reloaded < 3.3.5 - Username Denylist Bypass via Case Var…
CVE-2026-592965.99.4VMwareSpring MicrometerCWE-74Micrometer StatsD and Logging meter registries line-protocol and log injectio…
CVE-2026-333333.59.5CombodoiTopCWE-209Combodo iTop: Information disclosure in ajax.render.php
CVE-2026-692305.59.3EsriPortal for ArcGISCWE-79stored cross site scripting issue in Esri Portal for ArcGIS
CVE-2026-692373.89.3EsriPortal for ArcGISCWE-79HTML injection vulnerability in Esri Portal for ArcGIS
CVE-2026-748665.88.9@fastify/busboy@fastify/busboyCWE-93@fastify/busboy vulnerable to CRLF injection via multipart Content-Dispositio…
CVE-2026-194352.78.9UnknownDuplicate PostCWE-200Copy & Delete Posts < 1.5.6 - Authenticated Arbitrary Post Content and Passwo…
CVE-2026-172508.58.9TP-Link Systems Inc.TL-MR6400 v7.0CWE-121Authenticated Remote Code Execution via Stack-Based Buffer Overflow in Firmwa…
CVE-2026-155806.98.6N-ablePassPortalCWE-1385PassPortal browser extension: vault token disclosure via unvalidated postMessage
CVE-2026-308657.18.3CombodoiTopCWE-79Combodo iTop: Reflected XSS in dashboard save
CVE-2026-735375.18.2Japan Science and Technology Agency (JST)Miraikan Assist App Android versionCWE-79Cross-site scripting vulnerability exists in Miraikan Assist App. If this vul…
CVE-2026-439806.38.0zenitraMmallaCWE-79Malla: Stored XSS via Meshtastic node names in multiple frontend pages
CVE-2026-634664.17.9UnleashunleashCWE-116Unleash: Global Mustache.escape override disables HTML escaping process-wide,…
CVE-2026-190852.77.9UnknownDuplicate PostCWE-639Copy & Delete Posts < 1.5.6 - Author+ Password-Protected Post Content Disclosure
CVE-2026-597998.87.7Apache Software FoundationApache CloudStackCWE-269Apache CloudStack: Missing Privilege Check in Two-Factor Authentication Disab…
CVE-2026-169625.37.7UnknownTamara CheckoutCWE-862Tamara Checkout <= 1.9.9.20 - Unauthenticated Order Status Manipulation
CVE-2026-445176.37.5containersbuildahCWE-22Buildah: Build breakout using malicious Containerfile and Git Smart HTTP serv…
CVE-2026-65644await7.6Rocket.ChatRocket.ChatCWE-79Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.…
CVE-2026-773912.17.5SourceCodesterDynamic Input Field Generator Using HTML, CSS, and PHPCWE-352SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP cross-s…
CVE-2026-692356.17.3EsriPortal for ArcGISCWE-79stored cross site scripting issue in Esri Portal for ArcGIS
CVE-2026-692366.17.3EsriPortal for ArcGISCWE-79stored cross site scripting issue in Esri Portal for ArcGIS
CVE-2025-156715.47.2UnknownWelcart e-CommerceCWE-287Welcart e-Commerce < 2.12.1 - Session Fixation via uscesid Parameter
CVE-2026-172527.16.6TP-Link Systems Inc.TL-MR6400 v7.0CWE-787Unauthenticated Denial of Service via Composed HTTP Parsing and Stack-Based O…
CVE-2026-534874.36.5kite-orgkiteCWE-862Kite has an authenticated cluster RBAC bypass in /api/v1/overview
CVE-2026-59780await6.4Apache Software FoundationApache CloudStackCWE-200Apache CloudStack: LDAP provider configuration disclosure
CVE-2026-481058.36.4Basekick-LabsarcCWE-22Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths wit…
CVE-2026-59655await6.4Apache Software FoundationApache CloudStackCWE-200Apache CloudStack: Unauthenticated OAuth provider client-secret disclosure
CVE-2026-61397await6.4Apache Software FoundationApache CloudStackCWE-200Apache CloudStack: OAuth2 Token Cross-Request Leak
CVE-2026-593186.56.3SpringSpring AICWE-863DefaultToolCallingManager Global Resolver Fallback Allows Unadvertised Tool D…
CVE-2026-534684.66.2typemilltypemillCWE-79Typemill has Stored HTML Attribute Injection in Metadata Fields
CVE-2026-165772.76.3UnknownDokan: AI Powered WooCommerce Multivendor Marketplace SolutionCWE-863Dokan < 5.0.14 - Vendor+ Reverse Withdrawal Ledger Manipulation via Client-Su…
CVE-2026-470802.16.2joshnussxml_builderCWE-91CDATA Section Breakout via Unsanitised ]]> in xml_builder
CVE-2026-485902.16.2joshnussxml_builderCWE-91Element and Attribute Names Injected Verbatim into XML Output in xml_builder
CVE-2026-673616.95.8j2commerce.comJ2Store extension for JoomlaCWE-352Joomla Extension - j2commerce.com - Unauthenticated file upload with missing …
CVE-2026-74580await5.9LinuxLinux—vhost: reset the vring metadata cache on vring reconfiguration
CVE-2026-74581await5.8LinuxLinux—net: ipv6: clear suppressed fib6 rule result
CVE-2026-74583await5.8LinuxLinux—net/sched: cls_route: fix fastmap use-after-free on filter
CVE-2026-673585.35.7j2commerce.comJ2Store extension for JoomlaCWE-352Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.…
CVE-2026-770294.65.3yootheme.comZoo extension for JoomlaCWE-352Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state chan…
CVE-2026-534997.25.2NICMxFORT-validatorCWE-346FORT-validator Vulnerable to RRDP Shared Snapshot Cache Poisoning
CVE-2026-593084.25.2SpringSpring AICWE-668Semantic Cache Cross-Tenant Isolation Bypass via SHA-256 Truncation
CVE-2026-481068.35.1Basekick-LabsarcCWE-306Arc Enterprise cluster replication accepts unauthenticated MsgReplicateSync m…
CVE-2026-74582await5.0LinuxLinux—packet: use consistent hard_header_len in non-ring send paths
CVE-2026-45201await4.4Imagination TechnologiesGraphics DDKCWE-1284GPU DDK - Incorrect page size validation in PhysmemNewRamBackedPMR could lead…
CVE-2026-45199await4.4Imagination TechnologiesGraphics DDKCWE-823GPU DDK - rgxfw_to_ptr() does not reject FW private data pointers
CVE-2026-45202await4.4Imagination TechnologiesGraphics DDKCWE-415GPU DDK - Silent High-Order CMA Memory Leak & Double Free in `_FreeOSPages_Fast`
CVE-2026-65645await4.0Rocket.ChatRocket.Chat—Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.…
CVE-2026-656134.33.9Apache Software FoundationApache CloudStackCWE-200Apache CloudStack: Webhook Deliveries Incorrect Access
CVE-2026-59085await3.9Apache Software FoundationApache CloudStackCWE-918Apache CloudStack: Server-Side Request Forgery (SSRF) vulnerability in webhoo…
CVE-2026-143253.53.8UnknownDrag and Drop Multiple File Upload for Contact Form 7CWE-79Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Admin+ Stor…
CVE-2026-692383.53.8EsriPortal for ArcGISCWE-79HTML injection vulnerability in Esri Portal for ArcGIS
CVE-2026-470792.13.8joshnussxml_builderCWE-838Round-trip Corruption via Improper Entity Escaping in xml_builder
CVE-2026-477534.43.7lxcincusCWE-476Incus has a Nil-Pointer Dereference Panic via Instance Backup Import (volume …
CVE-2026-613994.83.5Apache Software FoundationApache CloudStackCWE-116Apache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Lock User Func…
CVE-2026-351634.63.5OctoPrintOctoPrintCWE-80OctoPrint: XSS in Suppressed Command Notifications
CVE-2026-61398await3.5Apache Software FoundationApache CloudStackCWE-116Apache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Instance Reset…
CVE-2026-667975.43.4Apache Software FoundationApache CloudStackCWE-284Apache CloudStack: Unauthorised comment creation and disclosure
CVE-2026-540717.83.3funstory-aiBabelDOCCWE-502BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldo…
CVE-2026-546828.23.2TyrrrzDiscordChatExporterCWE-79DiscordChatExporter: Stored XSS in HTML export when markdown formatting is di…
CVE-2026-614224.33.0Apache Software FoundationApache CloudStackCWE-918Apache CloudStack: Authenticated pre-validation SSRF in registerTemplate
CVE-2026-667227.23.0Apache Software FoundationApache CloudStackCWE-285Apache CloudStack: ProjectRole & ProjectRolePermission authorization issue
CVE-2026-667212.73.0Apache Software FoundationApache CloudStackCWE-862Apache CloudStack: Authorization issue with listHostTags for domain admins
CVE-2026-50222await3.0Apache Software FoundationApache CloudStackCWE-200Apache CloudStack: Improper access control in Userdata reference APIs
CVE-2026-62440await3.0Apache Software FoundationApache CloudStackCWE-284Apache CloudStack: Improper access control in Kubernetes Service (CKS) cluste…
CVE-2026-772196.92.7GNUEmacsCWE-125GNU Emacs < 31.0.91 Heap Over-Read via PBM/PPM/PGM Image Loader
CVE-2026-151505.32.4UnknownmyCredCWE-345myCred < 3.2.5 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiv…
CVE-2026-166505.32.4UnknownCharitableCWE-345Charitable < 1.8.12 - Unauthenticated Donation Payment-Status Manipulation vi…
CVE-2026-546814.12.5TyrrrzDiscordChatExporterCWE-79DiscordChatExporter: HTML attribute injection via unescaped emoji name in HTM…
CVE-2026-772378.22.1FreeRTOSFreeRTOS-KernelCWE-125Missing type validation in xQueueAddToSet in FreeRTOS-Kernel
CVE-2026-436792.42.1ApplewatchOSCWE-284This issue was addressed with improved permissions checking. This issue is fi…
CVE-2026-772349.31.6FreeRTOSFreeRTOS-KernelCWE-863Improper input validation in FreeRTOS-Kernel timer command handling
CVE-2026-452715.51.6h2opicotlsCWE-835picotls has infinite recursion in the minicrypto ASN.1 decoder
CVE-2026-142087.31.4Remote Utilities Pte. Ltd.Remote Utilities HostCWE-732Local Privilege Escalation via Insecure DLL Permissions in Remote Utilities H…
CVE-2026-761374.81.3Yamaha CorporationVOCALOID6CWE-306Missing authentication for critical function vulnerability exists in VOCALOID…
CVE-2026-772368.31.2FreeRTOSFreeRTOS-KernelCWE-787Missing size validation in SecureContext_AllocateContext in FreeRTOS-Kernel
CVE-2026-491146.81.3ONNXONNXCWE-22ONNX symlink-following and path-traversal arbitrary file write
CVE-2026-772358.31.1FreeRTOSFreeRTOS-KernelCWE-416Missing privilege check in SecureContext_FreeContext in FreeRTOS-Kernel
CVE-2026-59657await0.8Apache Software FoundationApache CloudStackCWE-312Apache CloudStack: Sensitive Information Disclosure via Cleartext Storage in …
CVE-2026-150464.20.7UnknownLitExtensionCWE-352LitExtension: Store to WooCommerce Migration <= 1.2.5 - Connector Token Takeo…
CVE-2026-536566.30.6voxel51fiftyoneCWE-346FiftyOne App server uses wildcard CORS (Access-Control-Allow-Origin: *), enab…
CVE-2026-540734.60.5veracryptVeraCryptCWE-693VeraCrypt: Hidden volume quick format weakens plausible deniability
CVE-2026-687458.10.1Apache Software FoundationApache CloudStackCWE-347Apache CloudStack: SAML2 Signature Validation Silently Skipped for Cert-less IdP
CVE-2026-759468.20.1HP IncOMEN Gaming HubCWE-347OMEN Gaming Hub – Potential Escalation of Privilege & Information Disclosure
CVE-2026-278756.90.0Johnson ControlsSimplex Incident Manager / Autocall Fire AdministratorCWE-316Simplex Incident Manager Clear Test
CVE-2026-778129.40.0DJINeoCWE-311Cleartext Exposure of DJI Drone Wi-Fi Credentials via BLE
CVE-2026-537626.20.0veracryptVeraCryptCWE-916VeraCryp: wolfCrypt backend bypasses VeraCrypt PBKDF2 iteration count (non-de…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-21 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.