boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Saturday, August 22, 2026 · all times UTC← 2026-08-21 · archive · 2026-08-23 →

Security Box Score — August 22, 2026

241 CVEs published, led by Linux (150).

241 CVEs published August 22, 2026: 15 critical, 33 high, 36 medium, 5 low; 0 in the KEV catalog at press time; 1 with a public exploit reference; 152 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 216 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published931131475——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

1738 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux14173732363178163711120.17.8.0017+938 ▲
microsoft4691891145128145114286271.47.8.0044-177 ▼
google711832224765786577760.37.5.0025-44 ▼
red hat1895754323726431200.06.8.0029+87 ▲
apple40311588216368882.66.5.0029+40 ▲
canonical14411211135000.07.8.0020+7 ▲
freebsd233902340000.07.8.0015+23 ▲
suse52651461000.08.1.0039-3 ▼
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco46842139240561315.57.5.0044+31 ▲
palo alto networks12371321121325.44.7.0020-2 ▼
ubiquiti036142110338.38.8.0049-25 ▼
netgear93200275000.04.3.0025+3 ▲
fortinet7307814128620.07.0.0050-6 ▼
vmware21949427210.58.1.0040-6 ▼
f50165830416.38.6.0057-8 ▼
ivanti314482025535.78.3.0754+1 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache13246890198157133320.47.5.0048+40 ▲
mozilla591866868500900.08.1.0031-12 ▼
gitlab1566214428423.05.1.0029+8 ▲
drupal05165355412.05.9.0026-46 ▼
github5171790000.06.6.00430
docker290630000.07.2.0016+2 ▲
wordpress2513102240.08.8.31200
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle88922684871172513962730.17.8.0034-220 ▼
ibm3746031332851769610.27.5.0029+337 ▲
adobe603123914512351931.07.8.0026-35 ▼
progress19611437100611.68.1.0037-5 ▼
solarwinds0231733010417.49.1.0058-15 ▼
veeam10165920100.08.6.0034+9 ▲
zohocorp4103520000.08.7.0140+2 ▲
atlassian3615001300.08.1.00340
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link163615597300.07.4.0157+8 ▲
siemens193522382000.07.3.0016+12 ▲
rockwell automation12541830000.08.7.0029-16 ▼
synology12426133000.05.6.0025+1 ▲
schneider electric091620000.08.6.00370
abb070430000.07.2.0018-1 ▼
hikvision060420000.07.2.0040-5 ▼
moxa050320000.07.0.00290
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester37157008671000.05.5.0029-12 ▼
dell561551083575210.67.2.0019+13 ▲
splunk110128647705110.86.5.0025+107 ▲
openclaw01110583914000.07.0.0026-44 ▼
nvidia241061471210000.07.5.0034-17 ▼
siyuan-note73954220311000.08.7.0027+67 ▲
zephyrproject3891232489000.06.5.0022+17 ▲
itsourcecode1990001971000.02.1.0032+1 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.995799.99.8
CVE-2026-34486.986299.97.5
CVE-2026-63077.847399.79.8
CVE-2026-72898.792299.610.0
CVE-2026-59310.458898.79.8
CVE-2026-61511.339998.39.3
CVE-2026-64638.312098.18.9
CVE-2025-68686.291598.05.9
CVE-2026-71362.251497.89.1
CVE-2026-66066.189597.19.5
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.7922KEV
CVE-2026-4836210.0.0431
CVE-2026-1918810.0.0193
CVE-2026-5823110.0.0171
CVE-2026-6983610.0.0159
CVE-2026-1681210.0.0157KEV
CVE-2026-7329910.0.0121
CVE-2026-7367810.0.0114
CVE-2026-4561810.0.0092
CVE-2026-4816810.0.0091
Most disclosures (vendor)
VendorCVEs
linux1772
oracle889
microsoft484
google448
ibm442
red hat246
apache221
apple204
splunk110
siyuan-note77
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco13
apple8
fortinet6
google6
ivanti5
solarwinds4
adobe3
berriai3
oracle3
Most-affected ecosystems
EcosystemAdvisories
Maven56
PyPI10
npm5
Go4
Packagist2
NuGet1
crates.io1
Fastest to KEV
CVEVendorDays
CVE-2025-68686Fortinet0
CVE-2026-16812Arista Networks0
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20316Cisco0
CVE-2026-20349Cisco0
CVE-2026-34486Apache Software Foundation0
CVE-2026-63077JetBrains0
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171739
CVE-2021-27102n/a2021-11-171739
CVE-2021-27101n/a2021-11-171739
CVE-2021-27103n/a2021-11-171739
CVE-2021-21017Adobe2021-11-171739
CVE-2021-28550Adobe2021-11-171739
CVE-2021-42013Apache Software Foundation2021-11-171739
CVE-2021-41773Apache Software Foundation2021-11-171739
CVE-2021-30858Apple2021-11-171739
CVE-2021-30860Apple2021-11-171739

Transactions

EXPLOIT PUBLISHED — CVE-2026-14764 (code-projects Hotel and Tourism Reservation). Public exploit reference added.

DUE DATE PASSED — CVE-2026-33824 (Microsoft Windows 10 Version 1607). CISA remediation deadline was August 21, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-55040 (Microsoft SharePoint Enterprise Server 2016). CISA remediation deadline was August 21, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-59310 (VMware Cloud Foundation). CISA remediation deadline was August 21, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-65400 (Apple macOS). CISA remediation deadline was August 21, 2026; still in catalog.

RESCORED — CVE-2026-8836 (lwIP). CVSS 9.3 → 8.9 (NVD).

Yesterday's Results

How to read these box scores · glossary

241 CVEs published. 25 box scores, 216 table rows — nothing truncated.

TRENDnet TEW-823DRU CLI Configuration Tool nvram_get command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   L   L   L    2.0   .0209   80.2     —
AFFECTED
  Product     Versions     Fixed
  TEW-823DRU  1.1.02b01 –  —
TIMELINE
  Aug 21  Reserved by CNA
  Aug 22  Published (CNA: VulDB)
CWE-77, CWE-74 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
TRENDnet TEW-821DAP ssi upload.cgi command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0128   67.9     —
AFFECTED
  Product     Versions     Fixed
  TEW-821DAP  2.2.01b05 –  —
TIMELINE
  Aug 21  Reserved by CNA
  Aug 22  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
NLTK 3.10.0 through 3.10.2 Remote Code Execution via AllowlistUnpickler Dotted-Name Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    8.7   .0078   53.3     —
AFFECTED
  Product  Versions  Fixed
  nltk     3.10.0 –  3.10.3
TIMELINE
  Aug 6   Reserved by CNA
  Aug 22  Published (CNA: VulnCheck)
CWE-502 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Received
strongSwan strongSwan — In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0067   49.2     —
AFFECTED
  Product     Versions  Fixed
  strongSwan  4.3.3 –   —
TIMELINE
  May 20  Reserved by CNA
  Aug 22  Published (CNA: mitre)
CWE-415 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Received
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels <= 4.9.8 - Authenticated (Subscriber+) Arbitrary File Read via 'customer_note' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0064   48.1     —
AFFECTED
  Product                                                                              Versions     Fixed
  WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels  unspecified  —
TIMELINE
  Jul 28  Reserved by CNA
  Aug 22  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
westguard WS Form LITE – Drag & Drop Contact Form Builder — WS Form LITE <= 1.10.80 - Unauthenticated PHP Object Injection via Form Submission
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0062   47.2     —
AFFECTED
  Product                                          Versions     Fixed
  WS Form LITE – Drag & Drop Contact Form Builder  unspecified  —
TIMELINE
  Mar 23  Reserved by CNA
  Aug 22  Published (CNA: Wordfence)
CWE-502 · CNA: Wordfence · CVSS v3.1 · 4 references · NVD status: Deferred
TRENDnet TEW-821DAP NTP Timezone Configuration apply_time.cgi uci_safe_get stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0062   47.0     —
AFFECTED
  Product     Versions     Fixed
  TEW-821DAP  2.2.01b05 –  —
TIMELINE
  Aug 21  Reserved by CNA
  Aug 22  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Mailgun for WordPress <= 2.2.0 - Unauthenticated Server-Side Request Forgery (SSRF) via 'addresses' Array Keys
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0057   44.7     —
AFFECTED
  Product                Versions     Fixed
  Mailgun for WordPress  unspecified  —
TIMELINE
  Aug 21  Reserved by CNA
  Aug 22  Published (CNA: Wordfence)
CWE-918 · CNA: Wordfence · CVSS v3.1 · 9 references · NVD status: Deferred
Comfast CF-N1-S Web Management mbox-config sub_41AD7C stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0057   44.5     —
AFFECTED
  Product  Versions   Fixed
  CF-N1-S  2.6.0.1 –  —
TIMELINE
  Aug 22  Reserved by CNA
  Aug 22  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
buildwps PPWP – Password Protect Pages — PPWP – Password Protect Pages <= 1.9.18 - Authenticated (Contributor+) PHP Object Injection via post_protection_roles
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0053   42.3     —
AFFECTED
  Product                        Versions     Fixed
  PPWP – Password Protect Pages  unspecified  —
TIMELINE
  Jan 1   Reserved by CNA
  Aug 22  Published (CNA: Wordfence)
CWE-502 · CNA: Wordfence · CVSS v3.1 · 3 references · NVD status: Deferred
joomgalleryfriends.net JoomGallery extension for Joomla — Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    6.9   .0051   41.1     —
AFFECTED
  Product                           Versions       Fixed
  JoomGallery extension for Joomla  4.0.0-4.3.0 –  —
TIMELINE
  Jul 28  Reserved by CNA
  Aug 22  Published (CNA: Joomla)
CWE-284 · CNA: Joomla · CVSS v4.0 · 1 reference · NVD status: Received
maartenbelmans Advanced Product Fields (Product Addons) for WooCommerce — Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.21 - Unauthenticated Improper Input Validation to Price Bypass via Add-to-Cart POST Request
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  N    7.5   .0049   39.9     —
AFFECTED
  Product                                                   Versions     Fixed
  Advanced Product Fields (Product Addons) for WooCommerce  unspecified  —
TIMELINE
  Feb 23  Reserved by CNA
  Aug 22  Published (CNA: Wordfence)
CWE-20 · CNA: Wordfence · CVSS v3.1 · 4 references · NVD status: Deferred
NLTK FramenetCorpusReader Symlink Sandbox Bypass before 3.10.2
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0049   39.7     —
AFFECTED
  Product  Versions  Fixed
  nltk     3.10.0 –  3.10.2
TIMELINE
  Jul 13  Reserved by CNA
  Aug 22  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
NLTK StreamBackedCorpusView Bypasses pathsec.ENFORCE Arbitrary File Read
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0049   39.7     —
AFFECTED
  Product  Versions     Fixed
  nltk     unspecified  3.10.0
TIMELINE
  Jul 16  Reserved by CNA
  Aug 22  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
joomgalleryfriends.net JoomGallery extension for Joomla — Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0047   38.3     —
AFFECTED
  Product                           Versions       Fixed
  JoomGallery extension for Joomla  4.0.0-4.3.0 –  —
TIMELINE
  Jul 28  Reserved by CNA
  Aug 22  Published (CNA: Joomla)
CWE-79 · CNA: Joomla · CVSS v4.0 · 1 reference · NVD status: Received
Unknown Forminator Forms — Forminator Forms < 1.57.0.5 - Admin+ Network-Wide RCE via Hub Connector API Key on Multisite
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0046   37.6     —
AFFECTED
  Product           Versions  Fixed
  Forminator Forms  1.40.0 –  —
TIMELINE
  Aug 7   Reserved by CNA
  Aug 22  Published (CNA: WPScan)
CWE-94 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
marc4 Security Hardener — Security Hardener <= 2.4.4 - Authenticated (Subscriber+) Privilege Escalation via REST API '/wp/v2/users' permission_callback Overwrite
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0043   35.2     —
AFFECTED
  Product            Versions     Fixed
  Security Hardener  unspecified  —
TIMELINE
  Jul 17  Reserved by CNA
  Aug 22  Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
Unknown Social Login & Sharing buttons with Analytics By SoClever — Social Login & Sharing buttons with Analytics By SoClever <= 1.2.0 - Unauthenticated Authentication Bypass
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0042   34.4     —
AFFECTED
  Product                                                    Versions     Fixed
  Social Login & Sharing buttons with Analytics By SoClever  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 22  Published (CNA: WPScan)
CWE-287 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
fabrikar.com Fabrik extension for Joomla — Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0041   33.9     —
AFFECTED
  Product                      Versions       Fixed
  Fabrik extension for Joomla  1.0.0-4.7.1 –  —
TIMELINE
  Aug 19  Reserved by CNA
  Aug 22  Published (CNA: Joomla)
CWE-94 · CNA: Joomla · CVSS v4.0 · 1 reference · NVD status: Received
fabrikar.com Fabrik extension for Joomla — Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0041   33.9     —
AFFECTED
  Product                      Versions       Fixed
  Fabrik extension for Joomla  1.0.0-4.7.1 –  —
TIMELINE
  Aug 19  Reserved by CNA
  Aug 22  Published (CNA: Joomla)
CWE-94 · CNA: Joomla · CVSS v4.0 · 1 reference · NVD status: Received
alexta69 MeTube Cookie File cookies.txt file access
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    5.5   .0040   33.3     —
AFFECTED
  Product  Versions     Fixed
  MeTube   2026.06.0 –  2026.06.20
TIMELINE
  Aug 22  Reserved by CNA
  Aug 22  Published (CNA: VulDB)
CWE-425, CWE-552 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Systerel S2OPC AddNodes Service sopc_node_mgt_helper_internal.c out-of-bounds
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   N   N   L    2.9   .0040   32.5     —
AFFECTED
  Product  Versions  Fixed
  S2OPC    1.7.0 –   —
TIMELINE
  Aug 22  Reserved by CNA
  Aug 22  Published (CNA: VulDB)
CWE-119, CWE-125 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Deferred
properfraction kk Star Ratings – Rate Post & Collect User Feedbacks — kk Star Ratings <= 5.4.10.3 - Unauthenticated Arbitrary Shortcode Execution via 'payload' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0039   31.8     —
AFFECTED
  Product                                               Versions     Fixed
  kk Star Ratings – Rate Post & Collect User Feedbacks  unspecified  —
TIMELINE
  Mar 2   Reserved by CNA
  Aug 22  Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Deferred
etruel WPeMatico RSS Feed Fetcher — WPeMatico RSS Feed Fetcher <= 2.8.24 - Authenticated (Subscriber+) Privilege Escalation via Arbitrary Option Update to wpematico_import_settings admin_action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0037   29.5     —
AFFECTED
  Product                     Versions     Fixed
  WPeMatico RSS Feed Fetcher  unspecified  —
TIMELINE
  Aug 14  Reserved by CNA
  Aug 22  Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
wpsoul Greenshift – animation and page builder blocks — Greenshift <= 12.8.9 - Authenticated (Contributor+) Theme Settings Modification via 'gspb_update_global_wp_settings'
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  N    4.3   .0036   28.1     —
AFFECTED
  Product                                         Versions     Fixed
  Greenshift – animation and page builder blocks  unspecified  —
TIMELINE
  Mar 29  Reserved by CNA
  Aug 22  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-765978.727.9fabrikar.comFabrik extension for JoomlaCWE-284Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to we…
CVE-2026-767938.127.3UnknownFirebase AuthenticationCWE-287Firebase Authentication < 1.7.1 - Unauthenticated Account Takeover via Fireba…
CVE-2026-600848.427.1siyuan-notesiyuanCWE-22SiYuan before v3.7.4 Arbitrary File Deletion via removeTemplate
CVE-2026-663938.726.9nltknltkCWE-674NLTK before 3.9.4 Denial of Service via JSONTaggedDecoder
CVE-2026-750275.326.7themifymeThemify BuilderCWE-862Themify Builder <= 7.8.0 - Missing Authorization to Unauthenticated Arbitrary…
CVE-2026-770009.826.7UnknownWP Social Media LoginCWE-287WP Social Media Login <= 1.0.6 - Unauthenticated Account Takeover via Twitter…
CVE-2026-770029.826.7UnknownSmilePass Selfie LoginCWE-287SmilePass Selfie Login <= 1.0.2 - Unauthenticated Authentication Bypass
CVE-2026-767898.826.5UnknownSlider Hero with Video Background, AnimationCWE-79Slider Hero < 9.1.3 - Unauthenticated Stored XSS via Slider Type Change and A…
CVE-2026-598088.725.9WWBNAVideoCWE-306AVideo Authentication Bypass via Unkeyed Video Hash Disclosure
CVE-2026-623888.725.8nltknltkCWE-1188NLTK before 3.10.0 Insecure Default Configuration pathsec
CVE-2026-7660610.025.5fabrikar.comFabrik extension for JoomlaCWE-22Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik …
CVE-2026-190936.824.8UnknownTutor LMSCWE-552Tutor LMS < 4.0.6 - Instructor+ Arbitrary File Read via Video Path
CVE-2026-127109.324.5Google CloudApplication IntegrationCWE-862Missing Authorization in Application Integration QueryEngineTask
CVE-2026-781228.324.5Tecnativadocker-socket-proxyCWE-1220docker-socket-proxy through 0.5.0 Insufficient Access Control Granularity Exp…
CVE-2026-623806.324.2nettynettyCWE-626Netty before 4.2.16.Final SOCKS Proxy Null Byte Injection
CVE-2026-45596.423.9wpchillImage Photo Gallery Final Tiles GridCWE-79Image Photo Gallery Final Tiles Grid <= 3.6.12 - Authenticated (Contributor+)…
CVE-2026-45616.423.9dvankootenMC4WP: Mailchimp for WordPressCWE-79MC4WP: Mailchimp for WordPress <= 4.12.0 - Authenticated (Author+) Stored Cro…
CVE-2026-765988.723.2fabrikar.comFabrik extension for JoomlaCWE-284Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing…
CVE-2026-765998.721.5fabrikar.comFabrik extension for JoomlaCWE-284Joomla Extension - fabrikar.com - Unauthenticated database table list and tab…
CVE-2026-766016.921.5fabrikar.comFabrik extension for JoomlaCWE-284Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < …
CVE-2026-766086.921.5fabrikar.comFabrik extension for JoomlaCWE-284Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter…
CVE-2026-42454.321.4metaphorcreationsPost DuplicatorCWE-863Post Duplicator <= 3.0.11 - Authorization Bypass to Authenticated (Contributo…
CVE-2026-623858.221.1nltknltkCWE-73NLTK 3.9.4 Path Traversal via FrameNet and NKJP Readers
CVE-2026-162606.821.0UnknownPost Grid, Slider & Carousel UltimateCWE-79Post Grid, Slider & Carousel Ultimate < 1.8.1 - Contributor+ Stored XSS via H…
CVE-2026-659157.120.6nltknltkCWE-284NLTK before 3.10.0 Arbitrary File Read via FileSystemPathPointer
CVE-2026-623826.919.5pglombardoPasswordPusherCWE-863PasswordPusher before v2.9.6 Authentication Bypass via Null Comparison
CVE-2026-765719.318.8fabrikar.comFabrik extension for JoomlaCWE-89Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filte…
CVE-2026-180528.119.0UnknownManageWP WorkerCWE-287ManageWP Worker < 4.9.37 - Unauthenticated Authentication Bypass via Unsigned…
CVE-2026-592568.718.7WWBNAVideoCWE-200WWBN AVideo Unbound Token Authorization Bypass via Gallery
CVE-2026-779929.517.6fabrikar.comFabrik extension for JoomlaCWE-94Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc ele…
CVE-2026-192226.617.3UnknownForminator FormsCWE-269Forminator Forms < 1.57.0.7 - Authenticated Privilege Escalation via Registra…
CVE-2026-770278.617.1fabrikar.comFabrik extension for JoomlaCWE-79Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2
CVE-2026-760574.316.7rubengcAutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPressCWE-862AutomatorWP <= 5.8.4 - Missing Authorization to Authenticated (Subscriber+) S…
CVE-2026-166125.316.2UnknownFiboSearchCWE-200FiboSearch < 1.34.1 - Unauthenticated Password-Protected Product Information …
CVE-2026-766029.315.9fabrikar.comFabrik extension for JoomlaCWE-89Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY i…
CVE-2026-633116.916.0nltknltkCWE-918NLTK before 3.10.0 SSRF via DNS Resolution Failure
CVE-2026-598096.915.3siyuan-notesiyuanCWE-201SiYuan before v3.8.0 Secret Exfiltration via http_request URL
CVE-2026-167385.314.9UnknownConekta Payment GatewayCWE-284Conekta Payment Gateway < 6.2.2 - Unauthenticated Order Payment Completion vi…
CVE-2026-7660710.014.8fabrikar.comFabrik extension for JoomlaCWE-284Joomla Extension - fabrikar.com - Missing ACL check in download element in Fa…
CVE-2026-765968.714.8fabrikar.comFabrik extension for JoomlaCWE-284Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.d…
CVE-2026-766006.914.8fabrikar.comFabrik extension for JoomlaCWE-284Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in …
CVE-2026-766036.914.8fabrikar.comFabrik extension for JoomlaCWE-284Joomla Extension - fabrikar.com - Unauthenticated row disclosure via form.inl…
CVE-2026-766096.914.8fabrikar.comFabrik extension for JoomlaCWE-284Joomla Extension - fabrikar.com - Unauthenticated modification of any comment…
CVE-2026-760744.313.9rubengcAutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPressCWE-862AutomatorWP <= 5.8.4 - Missing Authorization to Authenticated (Subscriber+) S…
CVE-2026-75866await13.8—Punk-OAuth2CWE-862Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outsi…
CVE-2026-600836.913.7siyuan-notesiyuanCWE-863SiYuan before v3.8.0 Incomplete Path Blocklist via MCP file tool
CVE-2026-141872.712.0UnknownTutor LMSCWE-639Tutor LMS < 4.0.6 - Instructor+ Cross-Instructor Private Course Disclosure vi…
CVE-2026-75870await11.9—PunkCWE-1394Punk versions before 0.18 for Perl allow session cookie forgery via an empty …
CVE-2026-563806.911.6WWBNAVideoCWE-200AVideo feed/index.php Exposure of Channel Owner Email Address
CVE-2026-74649await10.7LinuxLinux—staging: rtl8723bs: fix missing shared-key auth challenge length check
CVE-2026-42444.39.3metaphorcreationsPost DuplicatorCWE-862Post Duplicator <= 3.0.11 - Missing Authorization to Authenticated (Contribut…
CVE-2026-74689await9.2LinuxLinux—net/atm: fix slab-out-of-bounds read in vcc_setsockopt()
CVE-2026-74730await9.0LinuxLinux—NFS: Pin the 'struct nfs_server' during a FREE_STATEID call
CVE-2026-74683await8.7LinuxLinux—Input: evdev - sanitize event type index when fetching event masks
CVE-2026-74686await8.6LinuxLinux—rqspinlock: Reset tail when preserving queue on deadlock
CVE-2026-74601await8.1LinuxLinux—ring-buffer: Use current_context for safe per-CPU buffer swap
CVE-2026-74667await8.1LinuxLinux—net/packet: reset the MAC header on the packet-socket transmit path
CVE-2026-74679await8.1LinuxLinux—usb: gadget: f_ncm: Use unsigned int for ndp_index
CVE-2026-74732await7.9LinuxLinux—drm/amd/display: Check for tg ops in dce110_set_avmute
CVE-2026-74585await7.2LinuxLinux—thunderbolt: Bound the DROM dual link port number before indexing sw->ports
CVE-2026-74586await7.2LinuxLinux—sctp: clear new_transport when removing a peer
CVE-2026-74587await7.2LinuxLinux—sctp: fix use-after-free of cached ASCONF chunk
CVE-2026-74588await7.2LinuxLinux—sctp: keep chunk->transport in step with the list it is queued on
CVE-2026-74589await7.2LinuxLinux—bpf, sockmap: Fix sk_redir use-after-free in send verdict
CVE-2026-74594await7.2LinuxLinux—sched/psi: Shut down rtpoll_timer in psi_cgroup_free()
CVE-2026-74597await7.2LinuxLinux—ip6_tunnel: clear skb2->cb[] in ip6ip6_err()
CVE-2026-74598await7.2LinuxLinux—ipv6: fix Route Information option length validation
CVE-2026-74609await7.2LinuxLinux—tipc: read le->link under the node lock in tipc_node_link_down()
CVE-2026-74613await7.2LinuxLinux—vsock/virtio: avoid refilling the RX queue after teardown
CVE-2026-74615await7.2LinuxLinux—vxlan: do not arm the ageing timer on a device that is down
CVE-2026-74620await7.2LinuxLinux—net/sched: act_gact, act_police: range check the fallback control action
CVE-2026-74622await7.2LinuxLinux—net: atlantic: free RX pages of consumed but not refilled buffers
CVE-2026-74623await7.2LinuxLinux—net: atlantic: free stranded TX buffers on ring deinit
CVE-2026-74625await7.2LinuxLinux—netfilter: bridge: release template ct on non-IP path
CVE-2026-74630await7.2LinuxLinux—ipv6: prevent in6_dev_get() from resurrecting inet6_dev
CVE-2026-74631await7.2LinuxLinux—net: smc: fix splice entry lifetime imbalance in smc_rx_splice
CVE-2026-74635await7.2LinuxLinux—fbdev: bitblit: bound-check glyph index in bit_cursor()
CVE-2026-74641await7.2LinuxLinux—ALSA: usx2y: bound the hwdep mmap fault offset
CVE-2026-74648await7.2LinuxLinux—staging: rtl8723bs: validate monitor transmit frame lengths
CVE-2026-74651await7.2LinuxLinux—staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie()
CVE-2026-74654await7.2LinuxLinux—serial: 8250_dma: Clear stale RX state on shutdown
CVE-2026-74656await7.2LinuxLinux—ipv4: fix use-after-free in fib_nhc_update_mtu()
CVE-2026-74658await7.2LinuxLinux—futex: Prevent robust futex exit race some more
CVE-2026-74660await7.2LinuxLinux—netfilter: ebt_nflog: pin the NFLOG backend
CVE-2026-74664await7.2LinuxLinux—net: openvswitch: reallocate update replies for mismatched IDs
CVE-2026-74669await7.2LinuxLinux—ipvs: clear IPv4 options after rebasing tunnel ICMP errors
CVE-2026-74671await7.2LinuxLinux—ima: fix out-of-bounds read in xattr_verify()
CVE-2026-74673await7.2LinuxLinux—Input: evdev - fix information leak in evdev_pass_values()
CVE-2026-74675await7.2LinuxLinux—vt: stabilize tty reference in kbd_keycode with tty_port_tty_get
CVE-2026-74676await7.2LinuxLinux—vt: add permission check for KDSKBMETA ioctl
CVE-2026-74680await7.3LinuxLinux—usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()
CVE-2026-74682await7.2LinuxLinux—ALSA: usb-audio: fix OOB write on Type II inbound URBs
CVE-2026-74688await7.3LinuxLinux—sctp: clear control chunk transport if it is being removed
CVE-2026-74693await7.2LinuxLinux—net: prestera: validate firmware header length
CVE-2026-74694await7.2LinuxLinux—net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length
CVE-2026-74701await7.3LinuxLinux—net/openvswitch: check Ethernet header length in key_extract()
CVE-2026-74704await7.2LinuxLinux—net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter
CVE-2026-74705await7.2LinuxLinux—udp: fix potential use-after-free in tunnel segmentation
CVE-2026-74717await7.2LinuxLinux—net/mlx5: fw_tracer, return NULL on create error
CVE-2026-74719await7.2LinuxLinux—net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_e…
CVE-2026-74720await7.2LinuxLinux—bpf: Preserve pointer state for commuted arithmetic
CVE-2026-74726await7.2LinuxLinux—bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor
CVE-2026-74707await7.1LinuxLinux—xsk: validate metadata when processing requests
CVE-2026-74599await6.7LinuxLinux—mm/ptdump: always stabilise against page table freeing using init_mm
CVE-2026-74603await6.7LinuxLinux—ptp: ocp: Fix board ID over-read
CVE-2026-74604await6.7LinuxLinux—Revert "thermal/drivers/hwmon: Cleanup coding style a bit"
CVE-2026-74607await6.7LinuxLinux—KVM: SVM: Serialize accesses to the owner and mirror list with separate lock
CVE-2026-74608await6.7LinuxLinux—smb: client: Fix use-after-free in cifs_try_adding_channels()
CVE-2026-74612await6.7LinuxLinux—veth: fix skb length accounting after XDP frag adjustment
CVE-2026-74614await6.7LinuxLinux—vsock/virtio: read virtqueues under worker locks
CVE-2026-74616await6.7LinuxLinux—xdp: reject clones that overrun skb_shared_info tailroom
CVE-2026-74621await6.7LinuxLinux—net/sched: act_ct: fix sk_buff leak when the header checks reject a packet
CVE-2026-74624await6.7LinuxLinux—netfilter: nf_conntrack: defer invalid log until after unlock
CVE-2026-74628await6.7LinuxLinux—net/x25: fix use-after-free of the socket by its timers
CVE-2026-74632await6.7LinuxLinux—mm/huge_memory: fix huge_zero_pfn race
CVE-2026-74636await6.7LinuxLinux—tracing: Fix race between update_event_fields and, event_define_fields
CVE-2026-74650await6.7LinuxLinux—staging: rtl8723bs: fix OOB read in WMM_param_handler()
CVE-2026-74657await6.7LinuxLinux—ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops
CVE-2026-74659await6.7LinuxLinux—net: bridge: mrp: fix uninitialised bytes on the wire
CVE-2026-74663await6.7LinuxLinux—net/sched: reject overly deep qdisc hierarchies
CVE-2026-74672await6.7LinuxLinux—mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF
CVE-2026-74678await6.7LinuxLinux—net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup()
CVE-2026-74691await6.7LinuxLinux—net: thunderbolt: Tear down DMA paths before stopping the rings
CVE-2026-74692await6.7LinuxLinux—net/smc: fix TOCTOU race between smc_listen_out() and listener close
CVE-2026-74696await6.7LinuxLinux—tcp: fix TFO max_qlen accounting across reuseport migration
CVE-2026-74697await6.8LinuxLinux—bnxt_en: Disable EOP for TPA on all chips to prevent data corruption
CVE-2026-74714await6.7LinuxLinux—bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()
CVE-2026-74722await6.7LinuxLinux—btrfs: fix memory leak in btrfs_do_encoded_write()
CVE-2026-74728await6.4LinuxLinux—xfs: handle NULL b_addr in xfs_buf_free
CVE-2026-74729await6.4LinuxLinux—soc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read
CVE-2026-74731await6.4LinuxLinux—sched_ext: Skip sub-disable teardown for never-linked sub-schedulers
CVE-2026-74733await6.4LinuxLinux—gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock
CVE-2026-74584await6.3LinuxLinux—RDMA/bnxt_re: zero shared page before exposing to userspace
CVE-2026-74590await6.2LinuxLinux—fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions
CVE-2026-74592await6.2LinuxLinux—ima: Instantiate file_truncate and path_truncate hooks
CVE-2026-74602await6.2LinuxLinux—ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer()
CVE-2026-74606await6.2LinuxLinux—eventfs: Fix use-after-free in eventfs_remove_rec()
CVE-2026-74610await6.2LinuxLinux—tls: don't leave a full plaintext sk_msg ring unpushed
CVE-2026-74618await6.2LinuxLinux—binfmt_misc: don't warn when the mount is completed from another user namespace
CVE-2026-74619await6.2LinuxLinux—ovl: don't warn when the mount is completed from another user namespace
CVE-2026-74634await6.2LinuxLinux—ring-buffer: Prevent subbuf order change when resizing is disabled
CVE-2026-74637await6.2LinuxLinux—perf/core: Fix group leader use-after-free after sibling detach
CVE-2026-74642await6.2LinuxLinux—ALSA: usb: Fix UAF at delayed release of MIDI2 EPs
CVE-2026-74644await6.2LinuxLinux—mm/damon/ops-common: putback folios on invalid migrate nid
CVE-2026-74646await6.2LinuxLinux—misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke
CVE-2026-74647await6.2LinuxLinux—misc: fastrpc: Remove buffer from list prior to unmap operation
CVE-2026-74655await6.2LinuxLinux—serial: qcom-geni: fix TX DMA buffer flush
CVE-2026-74661await6.2LinuxLinux—mac802154: fix netdev use-after-free in beacon worker
CVE-2026-74665await6.2LinuxLinux—net: fix skb length accounting after generic XDP frag adjustment
CVE-2026-74666await6.2LinuxLinux—packet: synchronize pressure clearing with ring reconfiguration
CVE-2026-74668await6.2LinuxLinux—packet: use consistent hard_header_len in TX_RING send path
CVE-2026-74670await6.2LinuxLinux—ipvs: stop estimator after disabled calc phase
CVE-2026-74677await6.2LinuxLinux—net: usb: ipheth: fix carrier_work UAF on disconnect
CVE-2026-74684await6.2LinuxLinux—net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp()
CVE-2026-74685await6.2LinuxLinux—hwmon: (ltc4282) Clamp negative current limits
CVE-2026-74700await6.2LinuxLinux—net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers
CVE-2026-74710await6.2LinuxLinux—xsk: require at least 16 bytes of TX metadata
CVE-2026-74712await6.2LinuxLinux—vdpa/mlx5: Fix buffer length in create_direct_keys()
CVE-2026-74718await6.2LinuxLinux—devlink: fix net namespace reference leak in reload
CVE-2026-74725await6.2LinuxLinux—enic: fix tx_hang_reset use-after-free on device removal
CVE-2026-74703await6.1LinuxLinux—vhost-scsi: Validate T10 PI scatterlist counts
CVE-2026-74709await6.1LinuxLinux—xsk: clear metadata pointer when no timestamp is requested
CVE-2026-74591await6.0LinuxLinux—mm/filemap: __filemap_add_folio() restore index before retrying
CVE-2026-74593await6.0LinuxLinux—sched_ext: Take cgroup_lock() first in scx_cgroup_lock()
CVE-2026-74600await6.0LinuxLinux—mm/page_table_check: skip special zero mappings
CVE-2026-74611await6.0LinuxLinux—tls: rx: restore msg_iter before TLS 1.3 optimistic retry
CVE-2026-74617await6.0LinuxLinux—dibs: initialise dibs->lock in dibs_dev_alloc()
CVE-2026-74626await6.0LinuxLinux—NTB: ntb_netdev: Preserve RX queue depth on allocation failure
CVE-2026-74627await6.0LinuxLinux—net: devmem: prevent net-iov / page mixing
CVE-2026-74629await6.0LinuxLinux—net/dibs: Correct freeing of dmb_clientid_arr
CVE-2026-74633await6.0LinuxLinux—tracing: Fix NULL pointer dereference in module event cache removal
CVE-2026-74638await6.0LinuxLinux—drm/v3d: Serialize the scheduler timeout handlers
CVE-2026-74639await6.0LinuxLinux—ALSA: us144mkii: re-anchor capture URBs on resubmission
CVE-2026-74640await6.0LinuxLinux—ALSA: FCP: fix OOB write in fcp_meter_ctl_get()
CVE-2026-74643await6.0LinuxLinux—samples/damon/mtier: error out for zero quota goal target values
CVE-2026-74652await6.0LinuxLinux—serial: amba-pl011: cancel RS485 hrtimers after freeing IRQ
CVE-2026-74653await6.0LinuxLinux—serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx
CVE-2026-74662await6.0LinuxLinux—inet: frags: publish queues before arming timer
CVE-2026-74681await6.0LinuxLinux—usb: misc: usbio: check ibuf_len against rxbuf_len in bulk msg
CVE-2026-74687await6.0LinuxLinux—watchdog: at91sam9_wdt: prevent timer rearm during teardown
CVE-2026-74690await6.0LinuxLinux—s390/ism: Fix UAF of sba and ieq during ism_dev_exit()
CVE-2026-74695await6.0LinuxLinux—netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref()
CVE-2026-74698await6.0LinuxLinux—net/mlx5e: fix BQL reset on SQ re-activation
CVE-2026-74702await6.0LinuxLinux—vhost-scsi: reject feature changes after endpoint
CVE-2026-74708await6.0LinuxLinux—xsk: validate launch-time metadata size
CVE-2026-74711await6.0LinuxLinux—hwmon: (pmbus) Fix type confusion in notification logic
CVE-2026-74727await6.0LinuxLinux—ovpn: skip rehash for peers already removed from by_id
CVE-2026-74724await5.9LinuxLinux—ipvs: avoid out-of-bounds write in ip_vs_nat_icmp
CVE-2026-687668.55.6hashcathashcatCWE-88hashcat through 7.1.2 Arbitrary File Write via Restore File Option Injection
CVE-2026-129995.35.2zephyrprojectzephyrCWE-401Infineon Airoc Wi-Fi driver leaks TX buffers on send failure, leading to perm…
CVE-2026-74706await5.0LinuxLinux—bnge: Fix NULL pointer dereference in aux device release
CVE-2026-622438.74.8nettynettyCWE-297Netty 4.2.0 through 4.2.16 TLS Hostname Verification Bypass
CVE-2026-74596await4.9LinuxLinux—fs,fsverity: remove check for fsverity being enabled in setattr_prepare()
CVE-2026-74605await4.9LinuxLinux—eventfs: Use children field for rcu head and add memory barriers
CVE-2026-74645await4.9LinuxLinux—mm/damon/lru_sort: error out for >10000 active_mem_bp
CVE-2026-74674await4.9LinuxLinux—mm: fix incorrect flush address in direct page table reclaim
CVE-2026-74699await4.9LinuxLinux—drm/xe: Fix memory leak in exec_queue_set_hang_replay_state()
CVE-2026-74713await4.9LinuxLinux—vhost_iotlb: bound map allocation in add_range
CVE-2026-74715await4.9LinuxLinux—bpf: Fix netns reference imbalance in conntrack kfuncs
CVE-2026-74716await4.9LinuxLinux—accel/amdxdna: Fix locally exploitable BUG_ON in amdxdna_insert_pages()
CVE-2026-74721await4.9LinuxLinux—accel/amxdna: Fix page-insertion errors in amdxdna_insert_pages()
CVE-2026-74723await4.9LinuxLinux—btrfs: lzo: reject inline extents without valid headers
CVE-2026-579988.54.0jeemokbetter-npm-auditCWE-78better-npm-audit OS Command Injection via registry flag
CVE-2026-706268.63.8nltknltkCWE-59NLTK before 3.9.4 Symlink Escape via CorpusReader
CVE-2026-715142.03.9nltknltkCWE-22NLTK 3.9.4 through 3.10.2 Path Traversal via CrubadanCorpusReader pathsec Bypass
CVE-2026-687686.93.7hashcathashcatCWE-120hashcat through 7.1.2 Heap Buffer Overflow in outfile_write() via Oversized U…
CVE-2026-623836.83.6nltknltkCWE-22nltk IPIPANCorpusReader Symlink Arbitrary File Read
CVE-2026-580027.13.6WWBNAVideoCWE-345WWBN AVideo Authorization Bypass via Users_affiliations add.json.php
CVE-2026-687676.92.7hashcathashcatCWE-193hashcat through 7.1.2 Off-by-One Out-of-Bounds Heap Write in fgetl()
CVE-2026-74595await2.1LinuxLinux—fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy()
CVE-2026-580037.11.6WWBNAVideoCWE-352WWBN AVideo Cross-Site Request Forgery via releaseVideoNow.json.php
CVE-2026-580016.91.5WWBNAVideoCWE-352WWBN AVideo Cross-Site Request Forgery via videoEditLight.php
CVE-2026-633109.31.4nltknltkCWE-494NLTK before 3.9.3 Missing Post-Download Integrity Verification
CVE-2026-579445.30.9WWBNAVideoCWE-352AVideo channelToGallery.json.php Cross-Site Request Forgery
CVE-2026-623816.90.1openwrtluciCWE-122luci-lib-px5g 2040-bit Certificate Signing Heap Buffer Overflow
CVE-2026-622045.90.0siyuan-notesiyuanCWE-345SiYuan before v3.7.4 Plugin Overwrite via Bazaar Install

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-22 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.