AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0151 72.5 —
AFFECTED Product Versions Fixed CF-N1-S 2.6.0.1 – —
TIMELINE Aug 21 Reserved by CNA Aug 21 Published (CNA: VulDB)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
CISA adds 1 to KEV; 260 CVEs published, led by Apache Software Foundation (21).
260 CVEs published August 21, 2026: 38 critical, 93 high, 89 medium, 20 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 20 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 235 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 9070 | 31234 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
1723 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 1267 | 3582 | 363 | 1781 | 637 | 1 | 11 | 2 | 0.1 | 7.8 | .0017 | +788 ▲ |
| microsoft | 469 | 1891 | 145 | 1281 | 451 | 14 | 286 | 27 | 1.4 | 7.8 | .0044 | -177 ▼ |
| 71 | 1832 | 224 | 765 | 786 | 57 | 77 | 6 | 0.3 | 7.5 | .0025 | -44 ▼ | |
| red hat | 189 | 575 | 43 | 237 | 264 | 31 | 2 | 0 | 0.0 | 6.8 | .0029 | +96 ▲ |
| apple | 40 | 311 | 58 | 82 | 163 | 6 | 88 | 8 | 2.6 | 6.5 | .0029 | +40 ▲ |
| canonical | 14 | 41 | 12 | 11 | 13 | 5 | 0 | 0 | 0.0 | 7.8 | .0020 | +7 ▲ |
| freebsd | 23 | 39 | 0 | 23 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0015 | +23 ▲ |
| suse | 5 | 26 | 5 | 14 | 6 | 1 | 0 | 0 | 0.0 | 8.1 | .0039 | -3 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 46 | 84 | 21 | 39 | 24 | 0 | 56 | 13 | 15.5 | 7.5 | .0044 | +31 ▲ |
| palo alto networks | 12 | 37 | 1 | 3 | 21 | 12 | 13 | 2 | 5.4 | 4.7 | .0020 | -2 ▼ |
| ubiquiti | 0 | 36 | 14 | 21 | 1 | 0 | 3 | 3 | 8.3 | 8.8 | .0049 | -25 ▼ |
| netgear | 9 | 32 | 0 | 0 | 27 | 5 | 0 | 0 | 0.0 | 4.3 | .0025 | +3 ▲ |
| fortinet | 7 | 30 | 7 | 8 | 14 | 1 | 28 | 6 | 20.0 | 7.0 | .0050 | -6 ▼ |
| vmware | 2 | 19 | 4 | 9 | 4 | 2 | 7 | 2 | 10.5 | 8.1 | .0040 | -6 ▼ |
| f5 | 0 | 16 | 5 | 8 | 3 | 0 | 4 | 1 | 6.3 | 8.6 | .0057 | -8 ▼ |
| ivanti | 3 | 14 | 4 | 8 | 2 | 0 | 25 | 5 | 35.7 | 8.3 | .0754 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 132 | 468 | 90 | 198 | 157 | 13 | 33 | 2 | 0.4 | 7.5 | .0048 | +40 ▲ |
| mozilla | 59 | 186 | 68 | 68 | 50 | 0 | 9 | 0 | 0.0 | 8.1 | .0031 | -11 ▼ |
| gitlab | 15 | 66 | 2 | 14 | 42 | 8 | 4 | 2 | 3.0 | 5.1 | .0029 | +8 ▲ |
| drupal | 0 | 51 | 6 | 5 | 35 | 5 | 4 | 1 | 2.0 | 5.9 | .0026 | -46 ▼ |
| github | 5 | 17 | 1 | 7 | 9 | 0 | 0 | 0 | 0.0 | 6.6 | .0043 | 0 |
| docker | 2 | 9 | 0 | 6 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0016 | +2 ▲ |
| wordpress | 2 | 5 | 1 | 3 | 1 | 0 | 2 | 2 | 40.0 | 8.8 | .3120 | 0 |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0035 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 889 | 2268 | 487 | 1172 | 513 | 96 | 27 | 3 | 0.1 | 7.8 | .0034 | -209 ▼ |
| ibm | 374 | 603 | 133 | 285 | 176 | 9 | 6 | 1 | 0.2 | 7.5 | .0029 | +338 ▲ |
| adobe | 60 | 312 | 39 | 145 | 123 | 5 | 19 | 3 | 1.0 | 7.8 | .0026 | -35 ▼ |
| progress | 19 | 61 | 14 | 37 | 10 | 0 | 6 | 1 | 1.6 | 8.1 | .0037 | +8 ▲ |
| solarwinds | 0 | 23 | 17 | 3 | 3 | 0 | 10 | 4 | 17.4 | 9.1 | .0058 | -15 ▼ |
| veeam | 10 | 16 | 5 | 9 | 2 | 0 | 1 | 0 | 0.0 | 8.6 | .0034 | +10 ▲ |
| zohocorp | 4 | 10 | 3 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0140 | +2 ▲ |
| atlassian | 3 | 6 | 1 | 5 | 0 | 0 | 13 | 0 | 0.0 | 8.1 | .0034 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 16 | 36 | 15 | 5 | 9 | 7 | 3 | 0 | 0.0 | 7.4 | .0157 | +8 ▲ |
| siemens | 19 | 35 | 2 | 23 | 8 | 2 | 0 | 0 | 0.0 | 7.3 | .0016 | +12 ▲ |
| rockwell automation | 1 | 25 | 4 | 18 | 3 | 0 | 0 | 0 | 0.0 | 8.7 | .0029 | -16 ▼ |
| synology | 1 | 24 | 2 | 6 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +1 ▲ |
| schneider electric | 0 | 9 | 1 | 6 | 2 | 0 | 0 | 0 | 0.0 | 8.6 | .0037 | 0 |
| abb | 0 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -1 ▼ |
| hikvision | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0040 | 0 |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 37 | 157 | 0 | 0 | 86 | 71 | 0 | 0 | 0.0 | 5.5 | .0029 | -12 ▼ |
| dell | 56 | 155 | 10 | 83 | 57 | 5 | 2 | 1 | 0.6 | 7.2 | .0019 | +19 ▲ |
| splunk | 110 | 128 | 6 | 47 | 70 | 5 | 1 | 1 | 0.8 | 6.5 | .0025 | +107 ▲ |
| openclaw | 0 | 111 | 0 | 58 | 39 | 14 | 0 | 0 | 0.0 | 7.0 | .0026 | -44 ▼ |
| nvidia | 24 | 106 | 14 | 71 | 21 | 0 | 0 | 0 | 0.0 | 7.5 | .0034 | -17 ▼ |
| siyuan-note | 69 | 91 | 42 | 19 | 28 | 1 | 0 | 0 | 0.0 | 8.7 | .0028 | +63 ▲ |
| zephyrproject | 37 | 90 | 2 | 32 | 47 | 9 | 0 | 0 | 0.0 | 6.5 | .0022 | +16 ▲ |
| itsourcecode | 19 | 90 | 0 | 0 | 19 | 71 | 0 | 0 | 0.0 | 2.1 | .0032 | +2 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-8037 | .9957 | 99.9 | 9.8 |
| CVE-2026-34486 | .9862 | 99.9 | 7.5 |
| CVE-2026-63077 | .8473 | 99.7 | 9.8 |
| CVE-2026-72898 | .7922 | 99.6 | 10.0 |
| CVE-2026-59310 | .4588 | 98.7 | 9.8 |
| CVE-2026-61511 | .3399 | 98.3 | 9.3 |
| CVE-2026-64638 | .3120 | 98.1 | 8.9 |
| CVE-2025-68686 | .2915 | 98.0 | 5.9 |
| CVE-2026-71362 | .2514 | 97.8 | 9.1 |
| CVE-2026-66066 | .1895 | 97.1 | 9.5 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-72898 | 10.0 | .7922 | KEV |
| CVE-2026-6516 | 10.0 | .0486 | |
| CVE-2026-48362 | 10.0 | .0431 | |
| CVE-2026-47668 | 10.0 | .0388 | |
| CVE-2026-19188 | 10.0 | .0193 | |
| CVE-2026-58231 | 10.0 | .0171 | |
| CVE-2026-69836 | 10.0 | .0159 | |
| CVE-2026-16812 | 10.0 | .0157 | KEV |
| CVE-2026-73299 | 10.0 | .0121 | |
| CVE-2025-71389 | 10.0 | .0120 |
| Vendor | CVEs |
|---|---|
| linux | 1623 |
| oracle | 889 |
| microsoft | 488 |
| 452 | |
| ibm | 442 |
| red hat | 251 |
| apache | 221 |
| apple | 207 |
| splunk | 110 |
| siyuan-note | 76 |
| Vendor | KEV |
|---|---|
| microsoft | 27 |
| cisco | 13 |
| apple | 8 |
| fortinet | 6 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| oracle | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 56 |
| PyPI | 10 |
| npm | 6 |
| Go | 4 |
| Packagist | 2 |
| NuGet | 1 |
| crates.io | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2025-68686 | Fortinet | 0 |
| CVE-2026-16812 | Arista Networks | 0 |
| CVE-2026-18556 | N-able | 0 |
| CVE-2026-18577 | N-able | 0 |
| CVE-2026-20316 | Cisco | 0 |
| CVE-2026-20349 | Cisco | 0 |
| CVE-2026-34486 | Apache Software Foundation | 0 |
| CVE-2026-63077 | JetBrains | 0 |
| CVE-2026-72529 | TrueConf | 0 |
| CVE-2026-72530 | TrueConf | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1738 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1738 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1738 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1738 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1738 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1738 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1738 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1738 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1738 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1738 |
ADDED TO KEV — CVE-2026-73570 (Zimbra Collaboration). Remediation due August 24, 2026.
EXPLOIT PUBLISHED — gimp: 4 CVEs (CVE-2026-59088, CVE-2026-59089, CVE-2026-59090, CVE-2026-59091). Public exploit references added.
EXPLOIT PUBLISHED — netty: 3 CVEs (CVE-2026-42579, CVE-2026-42581, CVE-2026-42584). Public exploit references added.
EXPLOIT PUBLISHED — Red Hat Enterprise Linux 10: 3 CVEs (CVE-2026-35091, CVE-2026-35092, CVE-2026-55654). Public exploit references added.
EXPLOIT PUBLISHED — Red Hat Hardened Images: 3 CVEs (CVE-2026-0989, CVE-2026-0990, CVE-2026-0992). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2017-20268 (Zcontent Zap Calendar Lite). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2017-20269 (Terrywcarter KissGallery). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2017-20270 (Raindropsinfotech Twitch Tv). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2017-20271 (Nordmograph StreetGuessr Game). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2017-20273 (Joomlashowroom Event Registration Pro Calendar). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2017-20275 (Henryschorradt Bridge). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2019-25754 (Wdmtech vRestaurant). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2019-25755 (Wdmtech vReview). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2019-25756 (Wdmtech vAccount). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2019-25757 (Wdmtech vWishlist). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2019-25760 (Joomtech Easy Shop). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2019-25761 (Joomboost JoomCRM). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2019-25762 (Joomboost JoomProject). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-4996 (mruby). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2023-54357 (Artio Joomla! com_booking component). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-4598 (systemd-coredump). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19579 (Grokability Snipe-IT). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-3832 (gnutls). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-41523 (vllm-project vllm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-53804 (Centuran Consulting OTRS Community Edition). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-69414 (Microsoft Malware Protection Engine). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-72529 (TrueConf Server). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-72530 (TrueConf Server). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-72844 (leanprover lean4). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-76764 (code-projects Employee Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-76799 (code-projects Login Registration System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-76800 (DeDeCMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-76991 (itsourcecode Hospital Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-76997 (SourceCodester Simple Online Food Ordering System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-76998 (SourceCodester Simple Online Food Ordering System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-77020 (CodeAstro Apartment Visitor Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-77022 (Comfast CF-N1-S). Public exploit reference added.
DUE DATE PASSED — CVE-2025-62593 (ray-project ray). CISA remediation deadline was August 20, 2026; still in catalog.
RESCORED — IBM Db2 Mirror for i: 4 CVEs (CVE-2026-17186, CVE-2026-17209, CVE-2026-17227, CVE-2026-18178). CVSS rescored — before/after on each CVE page.
RESCORED — Red Hat Hardened Images: 4 CVEs (CVE-2025-14821, CVE-2026-3184, CVE-2026-3441, CVE-2026-3442). CVSS rescored — before/after on each CVE page.
RESCORED — libarchive: 3 CVEs (CVE-2025-5916, CVE-2025-5917, CVE-2025-5918). CVSS rescored — before/after on each CVE page.
RESCORED — Red Hat Enterprise Linux 10: 3 CVEs (CVE-2026-0964, CVE-2026-0966, CVE-2026-0967). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2024-12086 (rsync). CVSS 6.1 → 6.8 (NVD).
RESCORED — CVE-2025-32988 (libgnutls). CVSS 6.5 → 8.2 (NVD).
RESCORED — CVE-2025-32990 (libgnutls). CVSS 6.5 → 8.2 (NVD).
RESCORED — CVE-2025-46281 (Apple macOS). CVSS 8.4 → 8.8 (NVD).
RESCORED — CVE-2025-46291 (Apple macOS). CVSS 5.5 → 7.8 (NVD).
RESCORED — CVE-2025-5372 (libssh). CVSS 5 → 8.8 (NVD).
RESCORED — CVE-2026-59090 (gimp). CVSS 8.4 → 9.9 (NVD).
RESCORED — CVE-2026-59091 (gimp). CVSS 7.3 → 7.8 (NVD).
How to read these box scores · glossary
260 CVEs published. 25 box scores, 235 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0151 72.5 —
AFFECTED Product Versions Fixed CF-N1-S 2.6.0.1 – —
TIMELINE Aug 21 Reserved by CNA Aug 21 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0122 66.4 —
AFFECTED Product Versions Fixed Apache CloudStack 4.14.0.0 – —
TIMELINE Jul 9 Reserved by CNA Aug 21 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV A H N N U H H H 7.5 .0116 64.7 —
AFFECTED Product Versions Fixed BOSH CLI 0.0 – —
TIMELINE May 20 Reserved by CNA Aug 21 Published (CNA: vmware)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 9.4 .0083 54.9 —
AFFECTED Product Versions Fixed Data Management Center v8.3.0 – —
TIMELINE Aug 19 Reserved by CNA Aug 21 Published (CNA: ZUSO ART)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0081 54.0 —
AFFECTED Product Versions Fixed incus < 7.2.0 – —
TIMELINE May 22 Reserved by CNA Aug 21 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0081 54.0 —
AFFECTED Product Versions Fixed incus < 7.2.0 – —
TIMELINE May 22 Reserved by CNA Aug 21 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0078 53.3 —
AFFECTED Product Versions Fixed incus < 7.2.0 – —
TIMELINE May 22 Reserved by CNA Aug 21 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0078 53.3 —
AFFECTED Product Versions Fixed SPIP unspecified —
TIMELINE Aug 21 Reserved by CNA Aug 21 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N N H H H 9.2 .0077 52.8 —
AFFECTED Product Versions Fixed llama.cpp unspecified —
TIMELINE Apr 7 Reserved by CNA Aug 21 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N N P H H H 8.5 .0072 51.1 —
AFFECTED Product Versions Fixed uac unspecified —
TIMELINE Apr 20 Reserved by CNA Aug 21 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0071 50.7 —
AFFECTED Product Versions Fixed incus < 7.1.0 – —
TIMELINE May 22 Reserved by CNA Aug 21 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0070 50.5 —
AFFECTED Product Versions Fixed incus < 7.2.0 – —
TIMELINE May 22 Reserved by CNA Aug 21 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0070 50.3 —
AFFECTED Product Versions Fixed xshop = 3.0.3 – —
TIMELINE Jun 1 Reserved by CNA Aug 21 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N N P H H H 8.5 .0070 50.3 —
AFFECTED Product Versions Fixed uac unspecified —
TIMELINE Apr 20 Reserved by CNA Aug 21 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0066 48.7 —
AFFECTED Product Versions Fixed inference < 2.7.0 – —
TIMELINE Jul 10 Reserved by CNA Aug 21 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 9.4 .0065 48.2 —
AFFECTED Product Versions Fixed siyuan unspecified 3.7.4
TIMELINE Aug 20 Reserved by CNA Aug 21 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N N P H H H 8.5 .0064 47.9 —
AFFECTED Product Versions Fixed uac unspecified —
TIMELINE Apr 20 Reserved by CNA Aug 21 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H N 10.0 .0058 45.2 —
AFFECTED Product Versions Fixed Azure SQL Database - – —
TIMELINE Aug 3 Reserved by CNA Aug 21 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0057 44.5 —
AFFECTED Product Versions Fixed Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code unspecified —
TIMELINE Aug 20 Reserved by CNA Aug 21 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U N H H 6.5 .0053 42.3 —
AFFECTED Product Versions Fixed runtipi < 4.10.1 – —
TIMELINE Jun 16 Reserved by CNA Aug 21 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0052 42.1 —
AFFECTED Product Versions Fixed geotools = 35.0 – —
TIMELINE Aug 19 Reserved by CNA Aug 21 Published (CNA: GitHub_M)
CVSS EPSS %ile KEV — .0051 41.4 —
AFFECTED Product Versions Fixed Apache CloudStack 4.20.0.0 – —
TIMELINE May 19 Reserved by CNA Aug 21 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0051 41.0 —
AFFECTED Product Versions Fixed jsonata < 1.8.8 – —
TIMELINE Aug 20 Reserved by CNA Aug 21 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H L N 8.8 .0048 39.4 —
AFFECTED Product Versions Fixed misp-stix unspecified —
TIMELINE Aug 21 Reserved by CNA Aug 21 Published (CNA: CIRCL)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0047 38.5 —
AFFECTED Product Versions Fixed keystone < 6.5.3 – —
TIMELINE Jul 16 Reserved by CNA Aug 21 Published (CNA: GitHub_M)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-49360 | 7.8 | 37.1 | DataRecce | recce | CWE-73 | Recce server has unauthenticated SQL execution that allows local file read/wr… |
| CVE-2026-62675 | 8.8 | 37.1 | omnigent-ai | omnigent | CWE-94 | Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Ca… |
| CVE-2026-34741 | 8.6 | 37.0 | Combodo | iTop | CWE-306 | Combodo iTop: Authentication bypass in exec.php allows PHP file execution |
| CVE-2026-62677 | 8.8 | 36.9 | omnigent-ai | omnigent | CWE-22 | Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesy… |
| CVE-2026-48755 | 9.9 | 36.4 | lxc | incus | CWE-20 | Incus has an argument injection in backup compression algorithm leading to AF… |
| CVE-2026-48769 | 9.9 | 36.4 | lxc | incus | CWE-20 | Incus has an arbitrary file write on its client due to trusted image hash |
| CVE-2026-55241 | 7.5 | 36.3 | bluewave-labs | Checkmate | CWE-400 | Checkmate: Pre-auth Denial of Service via File Upload on Registration |
| CVE-2026-77649 | 9.8 | 36.0 | droundy | internment | CWE-506 | The internment crate 0.8.7 for Rust can trigger execution of malicious code w… |
| CVE-2026-77650 | 9.8 | 36.0 | droundy | append-only-vec | CWE-506 | The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious c… |
| CVE-2026-77651 | 9.8 | 36.0 | droundy | arrayref | CWE-506 | The arrayref crate 0.3.10 for Rust can trigger execution of malicious code wh… |
| CVE-2026-71493 | 5.9 | 35.2 | infracost | infracost | CWE-22 | Infracost: Arbitrary file read via config-template readFile symlink traversal |
| CVE-2026-55185 | 5.1 | 35.3 | miniflux | v2 | CWE-601 | Miniflux 2: Open Redirect Bypass |
| CVE-2026-45099 | 6.9 | 35.0 | gruntwork-io | terragrunt | CWE-22 | Terragrunt: Arbitrary File Deletion via Malicious Module Manifest |
| CVE-2026-63125 | 9.9 | 34.6 | lxc | incus | CWE-59 | Incus vulnerable to root RCE via image backup.yaml symlink |
| CVE-2026-76157 | 8.8 | 34.5 | Datiphy Inc. | Data Management Center | CWE-306 | Datiphy Data Management Center - Missing Authentication for Critical Function |
| CVE-2026-74252 | 8.6 | 34.4 | j2commerce.com | J2Store extension for Joomla | CWE-79 | Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1… |
| CVE-2026-70656 | 4.9 | 34.4 | bluewave-labs | Checkmate | CWE-1333 | Checkmate: Regular Expression Denial of Service (ReDoS) via User-Controlled R… |
| CVE-2026-76158 | 9.3 | 34.2 | Datiphy Inc. | Data Management Center | CWE-73 | Datiphy Data Management Center - External Control of File Name or Path |
| CVE-2026-77815 | 8.7 | 33.8 | zanllp | infinite-image-browsing | CWE-59 | Infinite Image Browsing Resolves Paths With normpath, Allowing Symlink Escape… |
| CVE-2026-77413 | 9.3 | 33.7 | jsonata-js | jsonata | CWE-94 | JSONata: Arbitrary Code Execution via crafted JSONata expressions |
| CVE-2026-77814 | 8.7 | 33.7 | zanllp | infinite-image-browsing | CWE-22 | Infinite Image Browsing is_path_trusted Prefix Comparison Omits the Trailing … |
| CVE-2026-75932 | 9.2 | 32.8 | Jet Admin | Jet Admin | CWE-862 | Jet Admin tenant isolation failure |
| CVE-2026-77087 | 9.4 | 32.5 | paperclipai | paperclip | CWE-862 | Paperclip before 0.3.1 Remote Code Execution via DNS Rebinding |
| CVE-2026-54789 | 7.5 | 32.2 | OpenIDC | mod_auth_openidc | CWE-125 | mod_auth_openidc has out-of-bounds read and write in state cookie parsing |
| CVE-2026-75928 | 6.9 | 31.8 | Brushfire | Online Experience | CWE-497 | Brushfire unauthenticated information disclosure |
| CVE-2026-59279 | 7.5 | 31.4 | Spring | Spring AI | CWE-770 | Unbounded persistent session allocation via repeated initialize requests |
| CVE-2026-64679 | 8.1 | 31.1 | runatlantis | atlantis | CWE-22 | Atlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds … |
| CVE-2026-63462 | 7.5 | 30.7 | Unleash | unleash | CWE-674 | Unleash: Unauthenticated single-request DoS via OpenAPI validation error form… |
| CVE-2026-50112 | 8.8 | 30.0 | Apache Software Foundation | Apache CloudStack | CWE-78 | Apache CloudStack: RCE and SSRF in direct download, metalink and NFS templates |
| CVE-2026-16323 | 7.5 | 30.1 | FuyaWeb Internet and Informatics Services | ArchitectPanel Web Admin Panel | CWE-698 | Authentication Bypass via Execution After Redirect in FuyaSoft's Architect Pa… |
| CVE-2026-59323 | 5.3 | 29.9 | VMware | Spring | CWE-770 | Micrometer Tracing Brave Bridge W3C Baggage propagation DoS vulnerability |
| CVE-2026-77811 | 6.2 | 29.8 | AWS | Amazon OpenSearch Service | CWE-79 | Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dash… |
| CVE-2026-77761 | 6.3 | 29.7 | misp | misp-stix | CWE-459 | Cross-Document Parser State Contamination in misp-stix |
| CVE-2026-62283 | 9.9 | 29.6 | nezhahq | nezha | CWE-639 | Nezha Monitoring: Cross-tenant terminal/file-manager session hijack via WebSo… |
| CVE-2026-75501 | await | 29.5 | Calix | GS7 XGS (GS5239XG) | — | CVE-2026-75501 |
| CVE-2026-71494 | 5.9 | 29.3 | infracost | infracost | CWE-522 | Infracost: Terraform Cloud and registry token disclosure via unvalidated host… |
| CVE-2026-77775 | 7.7 | 29.0 | Headroom Labs | Headroom | CWE-918 | Headroom Proxy Sends Upstream Requests to a Client-Supplied Base URL Without … |
| CVE-2026-77767 | 8.7 | 28.8 | reconmap | reconmap | CWE-862 | Reconmap Report Preview Endpoint Is Marked AllowAnonymous, Exposing Every Pro… |
| CVE-2026-62960 | 7.4 | 28.8 | git-for-windows | git | CWE-200 | Git for Windows: Server-advertised bundle-uri can trigger outbound SMB callba… |
| CVE-2026-48050 | 8.8 | 28.5 | Basekick-Labs | arc | CWE-200 | Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state a… |
| CVE-2026-50290 | 5.3 | 28.3 | asymmetric-effort | specifyjs | CWE-79 | @asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in re… |
| CVE-2026-76905 | 7.5 | 28.0 | getkin | kin-openapi | CWE-476 | kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed mu… |
| CVE-2026-71862 | 7.5 | 27.9 | bluewave-labs | Checkmate | CWE-200 | Checkmate: Sensitive Bearer Token Exposure via Public Status Pages When showU… |
| CVE-2026-77810 | 9.4 | 27.3 | AWS | Athena Federated Query Neptune Connector | CWE-95 | Code Injection via Gremlin Query Passthrough in Amazon Athena Neptune Connector |
| CVE-2026-77414 | 9.3 | 27.3 | jsonata-js | jsonata | CWE-94 | JSONata: Arbitrary Code Execution via crafted JSONata expressions |
| CVE-2026-76612 | 8.6 | 27.3 | yootheme.com | Zoo extension for Joomla | CWE-79 | Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-control… |
| CVE-2026-53528 | 8.8 | 27.1 | perber | leafwiki | CWE-23 | FileWiki has path traversal in RenameAsset via unsanitized oldFilename parameter |
| CVE-2026-77776 | 9.3 | 27.0 | Headroom Labs | Headroom | CWE-639 | Headroom Proxy Treats the Client-Supplied x-headroom-user-id Header as an Aut… |
| CVE-2026-62674 | 9.0 | 26.8 | omnigent-ai | omnigent | CWE-94 | Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE |
| CVE-2026-69228 | 5.3 | 26.8 | Esri | Portal for ArcGIS | CWE-306 | missing authentication vulnerability in Esri Portal for ArcGIS |
| CVE-2026-67362 | 5.1 | 26.4 | j2commerce.com | J2Store extension for Joomla | CWE-601 | Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Sto… |
| CVE-2026-73267 | 7.7 | 25.8 | Red Hat | Multicluster Engine for Kubernetes | CWE-602 | Clusterclaims-controller: clusterclaims-controller: managedcluster deletion k… |
| CVE-2026-76611 | 6.9 | 25.5 | yootheme.com | Zoo extension for Joomla | CWE-22 | Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing… |
| CVE-2026-69224 | 5.9 | 25.4 | Esri | Portal for ArcGIS | CWE-200 | information disclosure vulnerability in Esri Portal for ArcGIS |
| CVE-2026-69225 | 5.9 | 25.4 | Esri | Portal for ArcGIS | CWE-200 | information disclosure vulnerability in Esri Portal for ArcGIS |
| CVE-2026-77763 | 7.1 | 24.8 | juicedata | juicefs | CWE-22 | JuiceFS Local Filestore Backend Joins Object Keys onto the Storage Root Witho… |
| CVE-2026-50538 | 8.8 | 24.3 | LibVNC | libvncserver | CWE-122 | libvncclient Tight decoder has an attacker-controlled heap out-of-bounds write |
| CVE-2026-77759 | 8.7 | 24.2 | Roskus | Prospero Flow CRM | CWE-639 | IDOR and missing authorization in the Prospero Flow CRM transaction API allow… |
| CVE-2026-18781 | 8.1 | 24.3 | Unknown | Drag and Drop Multiple File Upload for Contact Form 7 | CWE-94 | Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Unauthentic… |
| CVE-2026-53572 | 5.9 | 24.1 | kedacore | keda | CWE-74 | KEDA: PostgreSQL connection string parameter injection via incomplete whitesp… |
| CVE-2026-62316 | 8.8 | 23.8 | microsoft | UFO | CWE-200 | Microsoft UFO: DNS Rebinding → Unauthenticated File Read / Command Execution |
| CVE-2026-55850 | 5.3 | 23.7 | element-hq | element-web | CWE-79 | Element Web: A malicious homeserver can inject HTML in Element Web using its … |
| CVE-2026-27462 | 7.5 | 23.6 | Combodo | iTop | CWE-204 | Combodo iTop: User enumeration via password reset |
| CVE-2026-27490 | 7.5 | 23.6 | Combodo | iTop | CWE-330 | Combodo iTop: Weak secret generation for inline image |
| CVE-2026-19441 | 5.3 | 23.6 | IKAS Technology Inc. | Rush | CWE-306 | Unauthenticated API Allows Analytics Data Manipulation in IKAS Technology's Rush |
| CVE-2026-59989 | 9.2 | 23.4 | phalcon | cphalcon | CWE-94 | Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI lea… |
| CVE-2026-75115 | 7.0 | 23.4 | yootheme.com | YOOtheme Pro extension for Joomla | CWE-22 | Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file re… |
| CVE-2026-77755 | 8.7 | 22.5 | misp | misp-stix | CWE-400 | Denial of Service in MISP-STIX Import via Malformed or Oversized STIX Documen… |
| CVE-2026-77354 | 8.7 | 22.2 | getkin | kin-openapi | CWE-400 | kin-openapi: Uncontrolled resource consumption in openapi3filter deepObject q… |
| CVE-2026-75933 | 8.5 | 21.8 | Jet Admin | Jet Admin | CWE-79 | Jet Admin Stored XSS |
| CVE-2026-62676 | 7.1 | 21.4 | omnigent-ai | omnigent | CWE-184 | Omnigent Guardrail policy bypass: shell-command parser fails open in policies… |
| CVE-2026-54457 | 7.7 | 21.4 | tensorzero | tensorzero | CWE-552 | TensorZero: Arbitrary file read and SSRF in TensorZero Gateway's internal obj… |
| CVE-2026-47735 | 7.1 | 21.3 | Basekick-Labs | arc | CWE-22 | Arc has an authenticated arbitrary local-file read via DuckDB I/O functions t… |
| CVE-2026-76613 | 8.6 | 21.3 | yootheme.com | YOOtheme Pro extension for Joomla | CWE-89 | Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in … |
| CVE-2026-76155 | 9.3 | 21.1 | Datiphy Inc. | Data Management Center | CWE-1392 | Datiphy Data Management Center - Use of Default Credentials |
| CVE-2026-77710 | 6.9 | 21.1 | MISP | misp-stix | CWE-20 | STIX2 Parser Confusion and Mass Assignment Allow Unauthorized MISP Attribute … |
| CVE-2026-62867 | 9.9 | 20.8 | lxc | incus | CWE-88 | Incus has an argument injection in storage volume block.create_options that l… |
| CVE-2026-63046 | 8.8 | 20.7 | Apache Software Foundation | Apache InLong | CWE-88 | Apache InLong: Agent Installer — Command Injection to RCE via Default Credent… |
| CVE-2026-17251 | 7.1 | 20.8 | TP-Link Systems Inc. | TL-MR6400 v7.0 | CWE-476 | Unauthenticated Denial of Service via Null Pointer Dereference in HTTP Reques… |
| CVE-2026-76876 | 8.2 | 20.0 | puemos | craftplan | CWE-862 | Craftplan < 0.5.1 Broken Access Control Information Disclosure via Settings API |
| CVE-2026-34836 | 6.5 | 19.9 | Combodo | iTop | CWE-862 | Combodo iTop: Improper access control in ajax.render.php and ajax.document.php |
| CVE-2026-50288 | 8.7 | 19.5 | asymmetric-effort | specifyjs | CWE-918 | @asymmetric-effort/specifyjs: URL parse failure silently allows request |
| CVE-2026-22681 | 8.3 | 19.5 | Volcengine | OpenViking | CWE-918 | OpenViking < 0.3.4 SSRF via /api/v1/resources |
| CVE-2026-63004 | 5.5 | 19.4 | Unleash | unleash | CWE-918 | Unleash: Addon webhook URL is dialed server-side with no internal-address fil… |
| CVE-2026-77686 | 2.1 | 19.3 | n/a | Dolibarr | CWE-266 | Dolibarr Account card.php improper authorization |
| CVE-2026-30866 | 7.5 | 18.8 | Combodo | iTop | CWE-200 | Combodo iTop: Insecured access to uploaded images via sniffed url |
| CVE-2026-77681 | 2.1 | 18.7 | CodeAstro | Online Job Portal | CWE-284 | CodeAstro Online Job Portal update-profile.php unrestricted upload |
| CVE-2026-33240 | 8.8 | 18.6 | Combodo | iTop | CWE-79 | Combodo iTop: Reflected XSS in foreign key search criteria |
| CVE-2026-15576 | 6.9 | 18.6 | Checkmk GmbH | Checkmk | CWE-306 | Agent receiver accepts mTLS requests without a client certificate |
| CVE-2026-53524 | 6.5 | 18.4 | weechat | weechat | CWE-409 | WeeChat has a Decompression Bomb in Relay WebSocket (DoS) |
| CVE-2026-63343 | 9.9 | 18.3 | lxc | incus | CWE-73 | Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesys… |
| CVE-2026-31936 | 8.8 | 18.4 | Combodo | iTop | CWE-862 | Combodo iTop: Unauthorized access to object information via search operation |
| CVE-2026-67359 | 8.7 | 17.5 | j2commerce.com | J2Store extension for Joomla | CWE-639 | Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.… |
| CVE-2026-75796 | 7.2 | 17.6 | Unknown | AI Engine | CWE-269 | AI Engine 2.8.0 - 3.6.0 - Admin+ Multisite Network Administrator Account Take… |
| CVE-2026-16576 | 7.2 | 17.0 | Unknown | Dokan: AI Powered WooCommerce Multivendor Marketplace Solution | CWE-284 | Dokan < 5.0.14 - Shop Manager+ Arbitrary Plugin Installation/Activation via R… |
| CVE-2026-53531 | 6.9 | 17.0 | erweixin | RaTeX | CWE-400 | ratex-parser has unbounded parser recursion that leads to stack overflow (pro… |
| CVE-2026-30819 | 7.3 | 16.8 | Combodo | iTop | CWE-79 | Combodo iTop: Reflected XSS in /pages/ajax.render.php dashboard_id parameter |
| CVE-2026-17559 | 5.3 | 16.7 | Unknown | Passster | CWE-863 | Content Protector (Passster) < 4.3.9 - Unauthenticated Protected Content Disc… |
| CVE-2026-53525 | 7.4 | 16.6 | weechat | weechat | CWE-208 | WeeChat has Non-Constant-Time Password Hash Comparison in Relay Authentication |
| CVE-2026-53530 | 8.7 | 16.4 | erweixin | RaTeX | CWE-248 | ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundar… |
| CVE-2026-77780 | 5.3 | 16.4 | Roskus | Prospero Flow CRM | CWE-639 | Unvalidated bank account and card foreign keys in the Prospero Flow CRM trans… |
| CVE-2026-68508 | 7.8 | 16.3 | facebookresearch | hydra | CWE-94 | Hydra: hydra.utils.instantiate with untrusted config can lead to code execution |
| CVE-2026-27463 | 5.3 | 16.0 | Combodo | iTop | CWE-200 | Combodo iTop: Version disclosure via login page logo |
| CVE-2026-77392 | 2.1 | 16.1 | SourceCodester | Dynamic Input Field Generator Using HTML, CSS, and PHP | CWE-74 | SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP submit.… |
| CVE-2026-69233 | 5.5 | 15.9 | Esri | Portal for ArcGIS | CWE-79 | stored cross site scripting issue in Esri Portal for ArcGIS |
| CVE-2026-63135 | 8.2 | 15.8 | YOURLS | YOURLS | CWE-79 | YOURLS: Stored XSS in referrer statistics chart via crafted Referer header |
| CVE-2026-50278 | 6.5 | 15.7 | InternationalColorConsortium | iccDEV | CWE-125 | iccDEV: CIccEmbedIO::Read8() size_t underflow |
| CVE-2026-62941 | 9.9 | 15.7 | lxc | incus | CWE-863 | Incus: Cross-project instance copy bypasses target project restrictions via T… |
| CVE-2026-53527 | 8.8 | 15.5 | perber | leafwiki | CWE-269 | LeafWiki Vulnerable to Privilege Escalation via User Self-Service Update |
| CVE-2026-77028 | 5.3 | 15.4 | yootheme.com | Zoo extension for Joomla | CWE-79 | Joomla Extension - yootheme.com - Reflected XSS and open redirect via the sub… |
| CVE-2026-77768 | 7.1 | 15.3 | Openpanel-dev | openpanel | CWE-639 | OpenPanel report.get Returns Any Report by Identifier Without Checking Projec… |
| CVE-2026-77769 | 7.1 | 15.3 | Openpanel-dev | openpanel | CWE-639 | OpenPanel report.list Queries Reports by an Unverified dashboardId, Crossing … |
| CVE-2026-53529 | 4.8 | 15.2 | perber | leafwiki | CWE-79 | LeafWiki vulnerable to stored XSS via search-result title (highlight() return… |
| CVE-2026-77220 | 7.1 | 14.8 | michaelrsweet | pdfio | CWE-825 | PDFio < 1.6.5 Dangling Pointer via Dictionary String-Formatting |
| CVE-2026-67360 | 6.3 | 14.8 | j2commerce.com | J2Store extension for Joomla | CWE-639 | Joomla Extension - j2commerce.com - Cross-customer order replication in J2Sto… |
| CVE-2026-69231 | 5.5 | 14.6 | Esri | Portal for ArcGIS | CWE-79 | stored cross site scripting issue in Esri Portal for ArcGIS |
| CVE-2026-69232 | 5.5 | 14.6 | Esri | Portal for ArcGIS | CWE-79 | stored cross site scripting issue in Esri Portal for ArcGIS |
| CVE-2026-13736 | 5.3 | 14.6 | Unknown | NewPath WildApricotPress Add-on | CWE-284 | NewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated… |
| CVE-2026-77781 | await | 14.6 | — | Tie-Hash-Regex | CWE-248 | Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on un… |
| CVE-2026-13176 | 2.7 | 14.5 | Unknown | Eventin | CWE-918 | Eventin < 4.1.21 - Contributor+ Server-Side Request Forgery |
| CVE-2026-69234 | 6.1 | 14.2 | Esri | Portal for ArcGIS | CWE-79 | reflected cross site scripting vulnerability in Esri Portal for ArcGIS |
| CVE-2026-30826 | 8.0 | 14.0 | Combodo | iTop | CWE-79 | Combodo iTop: Reflected XSS in run_query.php |
| CVE-2026-30890 | 8.0 | 14.0 | Combodo | iTop | CWE-79 | Combodo iTop: Reflected XSS in synchro/synchro_import.php |
| CVE-2026-31803 | 8.0 | 14.0 | Combodo | iTop | CWE-79 | Combodo iTop: Reflected XSS in tag admin |
| CVE-2026-31880 | 8.0 | 14.0 | Combodo | iTop | CWE-79 | Combodo iTop: Reflected XSS in universal search |
| CVE-2026-53497 | 5.3 | 14.1 | cenodude | CrossWatch | CWE-200 | CrossWatch: Unauthenticated /api/app-auth/status endpoint leaks active sessio… |
| CVE-2026-62940 | 9.9 | 13.9 | lxc | incus | CWE-862 | Incus has a project restriction bypass via instance migration config override |
| CVE-2026-18409 | 7.2 | 13.8 | WPForms | WPForms Pro | CWE-79 | WPForms Pro <= 2.0.0.2 - Unauthenticated Stored Cross-Site Scripting via Sing… |
| CVE-2026-14601 | 6.8 | 13.7 | Unknown | Link Whisper Free | CWE-89 | Link Whisper < 0.9.7 - Editor+ SQL Injection via domain Parameter |
| CVE-2026-16959 | 6.8 | 13.7 | Unknown | Media Library Assistant | CWE-89 | Media Library Assistant < 3.40 - Author+ SQL Injection via mla_search_connector |
| CVE-2026-61824 | 8.2 | 13.4 | kepano | defuddle | CWE-79 | Defuddle: XSS via unescaped attribute interpolation in site extractors |
| CVE-2026-53541 | 4.3 | 13.3 | OliveTin | OliveTin | CWE-20 | OliveTin has Unvalidated `ot_`-prefixed Arguments that Bypass Input Filtering |
| CVE-2026-34948 | 7.7 | 13.2 | Combodo | iTop | CWE-200 | Combodo iTop: Access control bypass via OQL joins |
| CVE-2026-59654 | 6.8 | 13.1 | Apache Software Foundation | Apache CloudStack | CWE-772 | Apache CloudStack: DoS caused by database connections leak |
| CVE-2026-48754 | 2.1 | 13.1 | lxc | incus | CWE-476 | Incus: Nil-pointer dereference in createDependentVolumesFromBackup on disk.{V… |
| CVE-2026-48756 | 2.1 | 13.1 | lxc | incus | CWE-476 | Incus: CreateCustomVolumeFromBackup nil-pointer dereference on volume_snapsho… |
| CVE-2026-19848 | 6.5 | 12.7 | Unknown | ProfilePress | CWE-74 | ProfilePress < 4.17.1 - Unauthenticated Arbitrary Shortcode Execution via Dis… |
| CVE-2026-69229 | 5.4 | 12.6 | Esri | Portal for ArcGIS | CWE-79 | HTML injection vulnerability in Esri Portal for ArcGIS |
| CVE-2026-34949 | 6.5 | 12.4 | Combodo | iTop | CWE-306 | Combodo iTop: Unauthenticated user can delete .readonly file |
| CVE-2026-33047 | 4.3 | 12.3 | Combodo | iTop | CWE-862 | Combodo iTop: Object can be locked by a user without write permissions |
| CVE-2026-53509 | 5.7 | 11.9 | ondata | ckan-mcp-server | CWE-918 | @aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networ… |
| CVE-2026-62313 | 4.3 | 11.4 | lxc | incus | CWE-863 | Incus: Project restriction `restricted.containers.privilege=isolated` bypassa… |
| CVE-2026-54134 | 7.0 | 11.3 | OctoPrint | OctoPrint | CWE-73 | OctoPrint: File exfiltration possible via query parameters on upload endpoints |
| CVE-2026-20679 | 4.3 | 11.2 | Apple | macOS | CWE-125 | The issue was addressed with improved checks. This issue is fixed in macOS Se… |
| CVE-2026-16575 | 5.3 | 10.6 | Unknown | Dokan: AI Powered WooCommerce Multivendor Marketplace Solution | CWE-200 | Dokan < 5.0.14 - Unauthenticated Commission Settings Disclosure via Store Cat… |
| CVE-2026-55621 | 7.7 | 9.9 | lxc | incus | CWE-284 | Incus has a project restriction bypass for custom volume copy across projects |
| CVE-2026-55622 | 7.7 | 9.9 | lxc | incus | CWE-284 | Incus has a project restriction bypass in instance copy across projects |
| CVE-2026-77795 | 5.3 | 9.9 | Dromara | RuoYi-Vue-Plus | CWE-266 | Dromara RuoYi-Vue-Plus Workflow Endpoint TestLeaveController improper authori… |
| CVE-2026-76131 | 6.9 | 9.6 | Yamaha Corporation | VOCALOID6 | CWE-798 | Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an … |
| CVE-2026-18356 | 3.7 | 9.5 | Unknown | Limit Login Attempts Security | CWE-184 | Limit Login Attempts Reloaded < 3.3.5 - Username Denylist Bypass via Case Var… |
| CVE-2026-59296 | 5.9 | 9.4 | VMware | Spring Micrometer | CWE-74 | Micrometer StatsD and Logging meter registries line-protocol and log injectio… |
| CVE-2026-33333 | 3.5 | 9.5 | Combodo | iTop | CWE-209 | Combodo iTop: Information disclosure in ajax.render.php |
| CVE-2026-69230 | 5.5 | 9.3 | Esri | Portal for ArcGIS | CWE-79 | stored cross site scripting issue in Esri Portal for ArcGIS |
| CVE-2026-69237 | 3.8 | 9.3 | Esri | Portal for ArcGIS | CWE-79 | HTML injection vulnerability in Esri Portal for ArcGIS |
| CVE-2026-74866 | 5.8 | 8.9 | @fastify/busboy | @fastify/busboy | CWE-93 | @fastify/busboy vulnerable to CRLF injection via multipart Content-Dispositio… |
| CVE-2026-19435 | 2.7 | 8.9 | Unknown | Duplicate Post | CWE-200 | Copy & Delete Posts < 1.5.6 - Authenticated Arbitrary Post Content and Passwo… |
| CVE-2026-17250 | 8.5 | 8.9 | TP-Link Systems Inc. | TL-MR6400 v7.0 | CWE-121 | Authenticated Remote Code Execution via Stack-Based Buffer Overflow in Firmwa… |
| CVE-2026-15580 | 6.9 | 8.6 | N-able | PassPortal | CWE-1385 | PassPortal browser extension: vault token disclosure via unvalidated postMessage |
| CVE-2026-30865 | 7.1 | 8.3 | Combodo | iTop | CWE-79 | Combodo iTop: Reflected XSS in dashboard save |
| CVE-2026-73537 | 5.1 | 8.2 | Japan Science and Technology Agency (JST) | Miraikan Assist App Android version | CWE-79 | Cross-site scripting vulnerability exists in Miraikan Assist App. If this vul… |
| CVE-2026-43980 | 6.3 | 8.0 | zenitraM | malla | CWE-79 | Malla: Stored XSS via Meshtastic node names in multiple frontend pages |
| CVE-2026-63466 | 4.1 | 7.9 | Unleash | unleash | CWE-116 | Unleash: Global Mustache.escape override disables HTML escaping process-wide,… |
| CVE-2026-19085 | 2.7 | 7.9 | Unknown | Duplicate Post | CWE-639 | Copy & Delete Posts < 1.5.6 - Author+ Password-Protected Post Content Disclosure |
| CVE-2026-59799 | 8.8 | 7.7 | Apache Software Foundation | Apache CloudStack | CWE-269 | Apache CloudStack: Missing Privilege Check in Two-Factor Authentication Disab… |
| CVE-2026-16962 | 5.3 | 7.7 | Unknown | Tamara Checkout | CWE-862 | Tamara Checkout <= 1.9.9.20 - Unauthenticated Order Status Manipulation |
| CVE-2026-44517 | 6.3 | 7.5 | containers | buildah | CWE-22 | Buildah: Build breakout using malicious Containerfile and Git Smart HTTP serv… |
| CVE-2026-65644 | await | 7.6 | Rocket.Chat | Rocket.Chat | CWE-79 | Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.… |
| CVE-2026-77391 | 2.1 | 7.5 | SourceCodester | Dynamic Input Field Generator Using HTML, CSS, and PHP | CWE-352 | SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP cross-s… |
| CVE-2026-69235 | 6.1 | 7.3 | Esri | Portal for ArcGIS | CWE-79 | stored cross site scripting issue in Esri Portal for ArcGIS |
| CVE-2026-69236 | 6.1 | 7.3 | Esri | Portal for ArcGIS | CWE-79 | stored cross site scripting issue in Esri Portal for ArcGIS |
| CVE-2025-15671 | 5.4 | 7.2 | Unknown | Welcart e-Commerce | CWE-287 | Welcart e-Commerce < 2.12.1 - Session Fixation via uscesid Parameter |
| CVE-2026-17252 | 7.1 | 6.6 | TP-Link Systems Inc. | TL-MR6400 v7.0 | CWE-787 | Unauthenticated Denial of Service via Composed HTTP Parsing and Stack-Based O… |
| CVE-2026-53487 | 4.3 | 6.5 | kite-org | kite | CWE-862 | Kite has an authenticated cluster RBAC bypass in /api/v1/overview |
| CVE-2026-59780 | await | 6.4 | Apache Software Foundation | Apache CloudStack | CWE-200 | Apache CloudStack: LDAP provider configuration disclosure |
| CVE-2026-48105 | 8.3 | 6.4 | Basekick-Labs | arc | CWE-22 | Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths wit… |
| CVE-2026-59655 | await | 6.4 | Apache Software Foundation | Apache CloudStack | CWE-200 | Apache CloudStack: Unauthenticated OAuth provider client-secret disclosure |
| CVE-2026-61397 | await | 6.4 | Apache Software Foundation | Apache CloudStack | CWE-200 | Apache CloudStack: OAuth2 Token Cross-Request Leak |
| CVE-2026-59318 | 6.5 | 6.3 | Spring | Spring AI | CWE-863 | DefaultToolCallingManager Global Resolver Fallback Allows Unadvertised Tool D… |
| CVE-2026-53468 | 4.6 | 6.2 | typemill | typemill | CWE-79 | Typemill has Stored HTML Attribute Injection in Metadata Fields |
| CVE-2026-16577 | 2.7 | 6.3 | Unknown | Dokan: AI Powered WooCommerce Multivendor Marketplace Solution | CWE-863 | Dokan < 5.0.14 - Vendor+ Reverse Withdrawal Ledger Manipulation via Client-Su… |
| CVE-2026-47080 | 2.1 | 6.2 | joshnuss | xml_builder | CWE-91 | CDATA Section Breakout via Unsanitised ]]> in xml_builder |
| CVE-2026-48590 | 2.1 | 6.2 | joshnuss | xml_builder | CWE-91 | Element and Attribute Names Injected Verbatim into XML Output in xml_builder |
| CVE-2026-67361 | 6.9 | 5.8 | j2commerce.com | J2Store extension for Joomla | CWE-352 | Joomla Extension - j2commerce.com - Unauthenticated file upload with missing … |
| CVE-2026-74580 | await | 5.9 | Linux | Linux | — | vhost: reset the vring metadata cache on vring reconfiguration |
| CVE-2026-74581 | await | 5.8 | Linux | Linux | — | net: ipv6: clear suppressed fib6 rule result |
| CVE-2026-74583 | await | 5.8 | Linux | Linux | — | net/sched: cls_route: fix fastmap use-after-free on filter |
| CVE-2026-67358 | 5.3 | 5.7 | j2commerce.com | J2Store extension for Joomla | CWE-352 | Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.… |
| CVE-2026-77029 | 4.6 | 5.3 | yootheme.com | Zoo extension for Joomla | CWE-352 | Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state chan… |
| CVE-2026-53499 | 7.2 | 5.2 | NICMx | FORT-validator | CWE-346 | FORT-validator Vulnerable to RRDP Shared Snapshot Cache Poisoning |
| CVE-2026-59308 | 4.2 | 5.2 | Spring | Spring AI | CWE-668 | Semantic Cache Cross-Tenant Isolation Bypass via SHA-256 Truncation |
| CVE-2026-48106 | 8.3 | 5.1 | Basekick-Labs | arc | CWE-306 | Arc Enterprise cluster replication accepts unauthenticated MsgReplicateSync m… |
| CVE-2026-74582 | await | 5.0 | Linux | Linux | — | packet: use consistent hard_header_len in non-ring send paths |
| CVE-2026-45201 | await | 4.4 | Imagination Technologies | Graphics DDK | CWE-1284 | GPU DDK - Incorrect page size validation in PhysmemNewRamBackedPMR could lead… |
| CVE-2026-45199 | await | 4.4 | Imagination Technologies | Graphics DDK | CWE-823 | GPU DDK - rgxfw_to_ptr() does not reject FW private data pointers |
| CVE-2026-45202 | await | 4.4 | Imagination Technologies | Graphics DDK | CWE-415 | GPU DDK - Silent High-Order CMA Memory Leak & Double Free in `_FreeOSPages_Fast` |
| CVE-2026-65645 | await | 4.0 | Rocket.Chat | Rocket.Chat | — | Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.… |
| CVE-2026-65613 | 4.3 | 3.9 | Apache Software Foundation | Apache CloudStack | CWE-200 | Apache CloudStack: Webhook Deliveries Incorrect Access |
| CVE-2026-59085 | await | 3.9 | Apache Software Foundation | Apache CloudStack | CWE-918 | Apache CloudStack: Server-Side Request Forgery (SSRF) vulnerability in webhoo… |
| CVE-2026-14325 | 3.5 | 3.8 | Unknown | Drag and Drop Multiple File Upload for Contact Form 7 | CWE-79 | Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Admin+ Stor… |
| CVE-2026-69238 | 3.5 | 3.8 | Esri | Portal for ArcGIS | CWE-79 | HTML injection vulnerability in Esri Portal for ArcGIS |
| CVE-2026-47079 | 2.1 | 3.8 | joshnuss | xml_builder | CWE-838 | Round-trip Corruption via Improper Entity Escaping in xml_builder |
| CVE-2026-47753 | 4.4 | 3.7 | lxc | incus | CWE-476 | Incus has a Nil-Pointer Dereference Panic via Instance Backup Import (volume … |
| CVE-2026-61399 | 4.8 | 3.5 | Apache Software Foundation | Apache CloudStack | CWE-116 | Apache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Lock User Func… |
| CVE-2026-35163 | 4.6 | 3.5 | OctoPrint | OctoPrint | CWE-80 | OctoPrint: XSS in Suppressed Command Notifications |
| CVE-2026-61398 | await | 3.5 | Apache Software Foundation | Apache CloudStack | CWE-116 | Apache CloudStack: Cross-Site Scripting (XSS) Vulnerability in Instance Reset… |
| CVE-2026-66797 | 5.4 | 3.4 | Apache Software Foundation | Apache CloudStack | CWE-284 | Apache CloudStack: Unauthorised comment creation and disclosure |
| CVE-2026-54071 | 7.8 | 3.3 | funstory-ai | BabelDOC | CWE-502 | BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldo… |
| CVE-2026-54682 | 8.2 | 3.2 | Tyrrrz | DiscordChatExporter | CWE-79 | DiscordChatExporter: Stored XSS in HTML export when markdown formatting is di… |
| CVE-2026-61422 | 4.3 | 3.0 | Apache Software Foundation | Apache CloudStack | CWE-918 | Apache CloudStack: Authenticated pre-validation SSRF in registerTemplate |
| CVE-2026-66722 | 7.2 | 3.0 | Apache Software Foundation | Apache CloudStack | CWE-285 | Apache CloudStack: ProjectRole & ProjectRolePermission authorization issue |
| CVE-2026-66721 | 2.7 | 3.0 | Apache Software Foundation | Apache CloudStack | CWE-862 | Apache CloudStack: Authorization issue with listHostTags for domain admins |
| CVE-2026-50222 | await | 3.0 | Apache Software Foundation | Apache CloudStack | CWE-200 | Apache CloudStack: Improper access control in Userdata reference APIs |
| CVE-2026-62440 | await | 3.0 | Apache Software Foundation | Apache CloudStack | CWE-284 | Apache CloudStack: Improper access control in Kubernetes Service (CKS) cluste… |
| CVE-2026-77219 | 6.9 | 2.7 | GNU | Emacs | CWE-125 | GNU Emacs < 31.0.91 Heap Over-Read via PBM/PPM/PGM Image Loader |
| CVE-2026-15150 | 5.3 | 2.4 | Unknown | myCred | CWE-345 | myCred < 3.2.5 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiv… |
| CVE-2026-16650 | 5.3 | 2.4 | Unknown | Charitable | CWE-345 | Charitable < 1.8.12 - Unauthenticated Donation Payment-Status Manipulation vi… |
| CVE-2026-54681 | 4.1 | 2.5 | Tyrrrz | DiscordChatExporter | CWE-79 | DiscordChatExporter: HTML attribute injection via unescaped emoji name in HTM… |
| CVE-2026-77237 | 8.2 | 2.1 | FreeRTOS | FreeRTOS-Kernel | CWE-125 | Missing type validation in xQueueAddToSet in FreeRTOS-Kernel |
| CVE-2026-43679 | 2.4 | 2.1 | Apple | watchOS | CWE-284 | This issue was addressed with improved permissions checking. This issue is fi… |
| CVE-2026-77234 | 9.3 | 1.6 | FreeRTOS | FreeRTOS-Kernel | CWE-863 | Improper input validation in FreeRTOS-Kernel timer command handling |
| CVE-2026-45271 | 5.5 | 1.6 | h2o | picotls | CWE-835 | picotls has infinite recursion in the minicrypto ASN.1 decoder |
| CVE-2026-14208 | 7.3 | 1.4 | Remote Utilities Pte. Ltd. | Remote Utilities Host | CWE-732 | Local Privilege Escalation via Insecure DLL Permissions in Remote Utilities H… |
| CVE-2026-76137 | 4.8 | 1.3 | Yamaha Corporation | VOCALOID6 | CWE-306 | Missing authentication for critical function vulnerability exists in VOCALOID… |
| CVE-2026-77236 | 8.3 | 1.2 | FreeRTOS | FreeRTOS-Kernel | CWE-787 | Missing size validation in SecureContext_AllocateContext in FreeRTOS-Kernel |
| CVE-2026-49114 | 6.8 | 1.3 | ONNX | ONNX | CWE-22 | ONNX symlink-following and path-traversal arbitrary file write |
| CVE-2026-77235 | 8.3 | 1.1 | FreeRTOS | FreeRTOS-Kernel | CWE-416 | Missing privilege check in SecureContext_FreeContext in FreeRTOS-Kernel |
| CVE-2026-59657 | await | 0.8 | Apache Software Foundation | Apache CloudStack | CWE-312 | Apache CloudStack: Sensitive Information Disclosure via Cleartext Storage in … |
| CVE-2026-15046 | 4.2 | 0.7 | Unknown | LitExtension | CWE-352 | LitExtension: Store to WooCommerce Migration <= 1.2.5 - Connector Token Takeo… |
| CVE-2026-53656 | 6.3 | 0.6 | voxel51 | fiftyone | CWE-346 | FiftyOne App server uses wildcard CORS (Access-Control-Allow-Origin: *), enab… |
| CVE-2026-54073 | 4.6 | 0.5 | veracrypt | VeraCrypt | CWE-693 | VeraCrypt: Hidden volume quick format weakens plausible deniability |
| CVE-2026-68745 | 8.1 | 0.1 | Apache Software Foundation | Apache CloudStack | CWE-347 | Apache CloudStack: SAML2 Signature Validation Silently Skipped for Cert-less IdP |
| CVE-2026-75946 | 8.2 | 0.1 | HP Inc | OMEN Gaming Hub | CWE-347 | OMEN Gaming Hub – Potential Escalation of Privilege & Information Disclosure |
| CVE-2026-27875 | 6.9 | 0.0 | Johnson Controls | Simplex Incident Manager / Autocall Fire Administrator | CWE-316 | Simplex Incident Manager Clear Test |
| CVE-2026-77812 | 9.4 | 0.0 | DJI | Neo | CWE-311 | Cleartext Exposure of DJI Drone Wi-Fi Credentials via BLE |
| CVE-2026-53762 | 6.2 | 0.0 | veracrypt | VeraCrypt | CWE-916 | VeraCryp: wolfCrypt backend bypasses VeraCrypt PBKDF2 iteration count (non-de… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-08-21 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.