AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N L L L 2.0 .0209 80.2 —
AFFECTED Product Versions Fixed TEW-823DRU 1.1.02b01 – —
TIMELINE Aug 21 Reserved by CNA Aug 22 Published (CNA: VulDB)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
241 CVEs published, led by Linux (150).
241 CVEs published August 22, 2026: 15 critical, 33 high, 36 medium, 5 low; 0 in the KEV catalog at press time; 1 with a public exploit reference; 152 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 216 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 9311 | 31475 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
1738 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 1417 | 3732 | 363 | 1781 | 637 | 1 | 11 | 2 | 0.1 | 7.8 | .0017 | +938 ▲ |
| microsoft | 469 | 1891 | 145 | 1281 | 451 | 14 | 286 | 27 | 1.4 | 7.8 | .0044 | -177 ▼ |
| 71 | 1832 | 224 | 765 | 786 | 57 | 77 | 6 | 0.3 | 7.5 | .0025 | -44 ▼ | |
| red hat | 189 | 575 | 43 | 237 | 264 | 31 | 2 | 0 | 0.0 | 6.8 | .0029 | +87 ▲ |
| apple | 40 | 311 | 58 | 82 | 163 | 6 | 88 | 8 | 2.6 | 6.5 | .0029 | +40 ▲ |
| canonical | 14 | 41 | 12 | 11 | 13 | 5 | 0 | 0 | 0.0 | 7.8 | .0020 | +7 ▲ |
| freebsd | 23 | 39 | 0 | 23 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0015 | +23 ▲ |
| suse | 5 | 26 | 5 | 14 | 6 | 1 | 0 | 0 | 0.0 | 8.1 | .0039 | -3 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 46 | 84 | 21 | 39 | 24 | 0 | 56 | 13 | 15.5 | 7.5 | .0044 | +31 ▲ |
| palo alto networks | 12 | 37 | 1 | 3 | 21 | 12 | 13 | 2 | 5.4 | 4.7 | .0020 | -2 ▼ |
| ubiquiti | 0 | 36 | 14 | 21 | 1 | 0 | 3 | 3 | 8.3 | 8.8 | .0049 | -25 ▼ |
| netgear | 9 | 32 | 0 | 0 | 27 | 5 | 0 | 0 | 0.0 | 4.3 | .0025 | +3 ▲ |
| fortinet | 7 | 30 | 7 | 8 | 14 | 1 | 28 | 6 | 20.0 | 7.0 | .0050 | -6 ▼ |
| vmware | 2 | 19 | 4 | 9 | 4 | 2 | 7 | 2 | 10.5 | 8.1 | .0040 | -6 ▼ |
| f5 | 0 | 16 | 5 | 8 | 3 | 0 | 4 | 1 | 6.3 | 8.6 | .0057 | -8 ▼ |
| ivanti | 3 | 14 | 4 | 8 | 2 | 0 | 25 | 5 | 35.7 | 8.3 | .0754 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 132 | 468 | 90 | 198 | 157 | 13 | 33 | 2 | 0.4 | 7.5 | .0048 | +40 ▲ |
| mozilla | 59 | 186 | 68 | 68 | 50 | 0 | 9 | 0 | 0.0 | 8.1 | .0031 | -12 ▼ |
| gitlab | 15 | 66 | 2 | 14 | 42 | 8 | 4 | 2 | 3.0 | 5.1 | .0029 | +8 ▲ |
| drupal | 0 | 51 | 6 | 5 | 35 | 5 | 4 | 1 | 2.0 | 5.9 | .0026 | -46 ▼ |
| github | 5 | 17 | 1 | 7 | 9 | 0 | 0 | 0 | 0.0 | 6.6 | .0043 | 0 |
| docker | 2 | 9 | 0 | 6 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0016 | +2 ▲ |
| wordpress | 2 | 5 | 1 | 3 | 1 | 0 | 2 | 2 | 40.0 | 8.8 | .3120 | 0 |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0035 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 889 | 2268 | 487 | 1172 | 513 | 96 | 27 | 3 | 0.1 | 7.8 | .0034 | -220 ▼ |
| ibm | 374 | 603 | 133 | 285 | 176 | 9 | 6 | 1 | 0.2 | 7.5 | .0029 | +337 ▲ |
| adobe | 60 | 312 | 39 | 145 | 123 | 5 | 19 | 3 | 1.0 | 7.8 | .0026 | -35 ▼ |
| progress | 19 | 61 | 14 | 37 | 10 | 0 | 6 | 1 | 1.6 | 8.1 | .0037 | -5 ▼ |
| solarwinds | 0 | 23 | 17 | 3 | 3 | 0 | 10 | 4 | 17.4 | 9.1 | .0058 | -15 ▼ |
| veeam | 10 | 16 | 5 | 9 | 2 | 0 | 1 | 0 | 0.0 | 8.6 | .0034 | +9 ▲ |
| zohocorp | 4 | 10 | 3 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0140 | +2 ▲ |
| atlassian | 3 | 6 | 1 | 5 | 0 | 0 | 13 | 0 | 0.0 | 8.1 | .0034 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 16 | 36 | 15 | 5 | 9 | 7 | 3 | 0 | 0.0 | 7.4 | .0157 | +8 ▲ |
| siemens | 19 | 35 | 2 | 23 | 8 | 2 | 0 | 0 | 0.0 | 7.3 | .0016 | +12 ▲ |
| rockwell automation | 1 | 25 | 4 | 18 | 3 | 0 | 0 | 0 | 0.0 | 8.7 | .0029 | -16 ▼ |
| synology | 1 | 24 | 2 | 6 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +1 ▲ |
| schneider electric | 0 | 9 | 1 | 6 | 2 | 0 | 0 | 0 | 0.0 | 8.6 | .0037 | 0 |
| abb | 0 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -1 ▼ |
| hikvision | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0040 | -5 ▼ |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 37 | 157 | 0 | 0 | 86 | 71 | 0 | 0 | 0.0 | 5.5 | .0029 | -12 ▼ |
| dell | 56 | 155 | 10 | 83 | 57 | 5 | 2 | 1 | 0.6 | 7.2 | .0019 | +13 ▲ |
| splunk | 110 | 128 | 6 | 47 | 70 | 5 | 1 | 1 | 0.8 | 6.5 | .0025 | +107 ▲ |
| openclaw | 0 | 111 | 0 | 58 | 39 | 14 | 0 | 0 | 0.0 | 7.0 | .0026 | -44 ▼ |
| nvidia | 24 | 106 | 14 | 71 | 21 | 0 | 0 | 0 | 0.0 | 7.5 | .0034 | -17 ▼ |
| siyuan-note | 73 | 95 | 42 | 20 | 31 | 1 | 0 | 0 | 0.0 | 8.7 | .0027 | +67 ▲ |
| zephyrproject | 38 | 91 | 2 | 32 | 48 | 9 | 0 | 0 | 0.0 | 6.5 | .0022 | +17 ▲ |
| itsourcecode | 19 | 90 | 0 | 0 | 19 | 71 | 0 | 0 | 0.0 | 2.1 | .0032 | +1 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-8037 | .9957 | 99.9 | 9.8 |
| CVE-2026-34486 | .9862 | 99.9 | 7.5 |
| CVE-2026-63077 | .8473 | 99.7 | 9.8 |
| CVE-2026-72898 | .7922 | 99.6 | 10.0 |
| CVE-2026-59310 | .4588 | 98.7 | 9.8 |
| CVE-2026-61511 | .3399 | 98.3 | 9.3 |
| CVE-2026-64638 | .3120 | 98.1 | 8.9 |
| CVE-2025-68686 | .2915 | 98.0 | 5.9 |
| CVE-2026-71362 | .2514 | 97.8 | 9.1 |
| CVE-2026-66066 | .1895 | 97.1 | 9.5 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-72898 | 10.0 | .7922 | KEV |
| CVE-2026-48362 | 10.0 | .0431 | |
| CVE-2026-19188 | 10.0 | .0193 | |
| CVE-2026-58231 | 10.0 | .0171 | |
| CVE-2026-69836 | 10.0 | .0159 | |
| CVE-2026-16812 | 10.0 | .0157 | KEV |
| CVE-2026-73299 | 10.0 | .0121 | |
| CVE-2026-73678 | 10.0 | .0114 | |
| CVE-2026-45618 | 10.0 | .0092 | |
| CVE-2026-48168 | 10.0 | .0091 |
| Vendor | CVEs |
|---|---|
| linux | 1772 |
| oracle | 889 |
| microsoft | 484 |
| 448 | |
| ibm | 442 |
| red hat | 246 |
| apache | 221 |
| apple | 204 |
| splunk | 110 |
| siyuan-note | 77 |
| Vendor | KEV |
|---|---|
| microsoft | 27 |
| cisco | 13 |
| apple | 8 |
| fortinet | 6 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| oracle | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 56 |
| PyPI | 10 |
| npm | 5 |
| Go | 4 |
| Packagist | 2 |
| NuGet | 1 |
| crates.io | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2025-68686 | Fortinet | 0 |
| CVE-2026-16812 | Arista Networks | 0 |
| CVE-2026-18556 | N-able | 0 |
| CVE-2026-18577 | N-able | 0 |
| CVE-2026-20316 | Cisco | 0 |
| CVE-2026-20349 | Cisco | 0 |
| CVE-2026-34486 | Apache Software Foundation | 0 |
| CVE-2026-63077 | JetBrains | 0 |
| CVE-2026-72529 | TrueConf | 0 |
| CVE-2026-72530 | TrueConf | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1739 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1739 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1739 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1739 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1739 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1739 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1739 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1739 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1739 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1739 |
EXPLOIT PUBLISHED — CVE-2026-14764 (code-projects Hotel and Tourism Reservation). Public exploit reference added.
DUE DATE PASSED — CVE-2026-33824 (Microsoft Windows 10 Version 1607). CISA remediation deadline was August 21, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-55040 (Microsoft SharePoint Enterprise Server 2016). CISA remediation deadline was August 21, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-59310 (VMware Cloud Foundation). CISA remediation deadline was August 21, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-65400 (Apple macOS). CISA remediation deadline was August 21, 2026; still in catalog.
RESCORED — CVE-2026-8836 (lwIP). CVSS 9.3 → 8.9 (NVD).
How to read these box scores · glossary
241 CVEs published. 25 box scores, 216 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N L L L 2.0 .0209 80.2 —
AFFECTED Product Versions Fixed TEW-823DRU 1.1.02b01 – —
TIMELINE Aug 21 Reserved by CNA Aug 22 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0128 67.9 —
AFFECTED Product Versions Fixed TEW-821DAP 2.2.01b05 – —
TIMELINE Aug 21 Reserved by CNA Aug 22 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N P H H H 8.7 .0078 53.3 —
AFFECTED Product Versions Fixed nltk 3.10.0 – 3.10.3
TIMELINE Aug 6 Reserved by CNA Aug 22 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U H H H 7.5 .0067 49.2 —
AFFECTED Product Versions Fixed strongSwan 4.3.3 – —
TIMELINE May 20 Reserved by CNA Aug 22 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0064 48.1 —
AFFECTED Product Versions Fixed WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels unspecified —
TIMELINE Jul 28 Reserved by CNA Aug 22 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0062 47.2 —
AFFECTED Product Versions Fixed WS Form LITE – Drag & Drop Contact Form Builder unspecified —
TIMELINE Mar 23 Reserved by CNA Aug 22 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0062 47.0 —
AFFECTED Product Versions Fixed TEW-821DAP 2.2.01b05 – —
TIMELINE Aug 21 Reserved by CNA Aug 22 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0057 44.7 —
AFFECTED Product Versions Fixed Mailgun for WordPress unspecified —
TIMELINE Aug 21 Reserved by CNA Aug 22 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0057 44.5 —
AFFECTED Product Versions Fixed CF-N1-S 2.6.0.1 – —
TIMELINE Aug 22 Reserved by CNA Aug 22 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0053 42.3 —
AFFECTED Product Versions Fixed PPWP – Password Protect Pages unspecified —
TIMELINE Jan 1 Reserved by CNA Aug 22 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L N N 6.9 .0051 41.1 —
AFFECTED Product Versions Fixed JoomGallery extension for Joomla 4.0.0-4.3.0 – —
TIMELINE Jul 28 Reserved by CNA Aug 22 Published (CNA: Joomla)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H N 7.5 .0049 39.9 —
AFFECTED Product Versions Fixed Advanced Product Fields (Product Addons) for WooCommerce unspecified —
TIMELINE Feb 23 Reserved by CNA Aug 22 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0049 39.7 —
AFFECTED Product Versions Fixed nltk 3.10.0 – 3.10.2
TIMELINE Jul 13 Reserved by CNA Aug 22 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0049 39.7 —
AFFECTED Product Versions Fixed nltk unspecified 3.10.0
TIMELINE Jul 16 Reserved by CNA Aug 22 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0047 38.3 —
AFFECTED Product Versions Fixed JoomGallery extension for Joomla 4.0.0-4.3.0 – —
TIMELINE Jul 28 Reserved by CNA Aug 22 Published (CNA: Joomla)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0046 37.6 —
AFFECTED Product Versions Fixed Forminator Forms 1.40.0 – —
TIMELINE Aug 7 Reserved by CNA Aug 22 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0043 35.2 —
AFFECTED Product Versions Fixed Security Hardener unspecified —
TIMELINE Jul 17 Reserved by CNA Aug 22 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0042 34.4 —
AFFECTED Product Versions Fixed Social Login & Sharing buttons with Analytics By SoClever unspecified —
TIMELINE Aug 20 Reserved by CNA Aug 22 Published (CNA: WPScan)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0041 33.9 —
AFFECTED Product Versions Fixed Fabrik extension for Joomla 1.0.0-4.7.1 – —
TIMELINE Aug 19 Reserved by CNA Aug 22 Published (CNA: Joomla)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0041 33.9 —
AFFECTED Product Versions Fixed Fabrik extension for Joomla 1.0.0-4.7.1 – —
TIMELINE Aug 19 Reserved by CNA Aug 22 Published (CNA: Joomla)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L N N 5.5 .0040 33.3 —
AFFECTED Product Versions Fixed MeTube 2026.06.0 – 2026.06.20
TIMELINE Aug 22 Reserved by CNA Aug 22 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N N N N L 2.9 .0040 32.5 —
AFFECTED Product Versions Fixed S2OPC 1.7.0 – —
TIMELINE Aug 22 Reserved by CNA Aug 22 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N L N 5.3 .0039 31.8 —
AFFECTED Product Versions Fixed kk Star Ratings – Rate Post & Collect User Feedbacks unspecified —
TIMELINE Mar 2 Reserved by CNA Aug 22 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0037 29.5 —
AFFECTED Product Versions Fixed WPeMatico RSS Feed Fetcher unspecified —
TIMELINE Aug 14 Reserved by CNA Aug 22 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N L N 4.3 .0036 28.1 —
AFFECTED Product Versions Fixed Greenshift – animation and page builder blocks unspecified —
TIMELINE Mar 29 Reserved by CNA Aug 22 Published (CNA: Wordfence)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-76597 | 8.7 | 27.9 | fabrikar.com | Fabrik extension for Joomla | CWE-284 | Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to we… |
| CVE-2026-76793 | 8.1 | 27.3 | Unknown | Firebase Authentication | CWE-287 | Firebase Authentication < 1.7.1 - Unauthenticated Account Takeover via Fireba… |
| CVE-2026-60084 | 8.4 | 27.1 | siyuan-note | siyuan | CWE-22 | SiYuan before v3.7.4 Arbitrary File Deletion via removeTemplate |
| CVE-2026-66393 | 8.7 | 26.9 | nltk | nltk | CWE-674 | NLTK before 3.9.4 Denial of Service via JSONTaggedDecoder |
| CVE-2026-75027 | 5.3 | 26.7 | themifyme | Themify Builder | CWE-862 | Themify Builder <= 7.8.0 - Missing Authorization to Unauthenticated Arbitrary… |
| CVE-2026-77000 | 9.8 | 26.7 | Unknown | WP Social Media Login | CWE-287 | WP Social Media Login <= 1.0.6 - Unauthenticated Account Takeover via Twitter… |
| CVE-2026-77002 | 9.8 | 26.7 | Unknown | SmilePass Selfie Login | CWE-287 | SmilePass Selfie Login <= 1.0.2 - Unauthenticated Authentication Bypass |
| CVE-2026-76789 | 8.8 | 26.5 | Unknown | Slider Hero with Video Background, Animation | CWE-79 | Slider Hero < 9.1.3 - Unauthenticated Stored XSS via Slider Type Change and A… |
| CVE-2026-59808 | 8.7 | 25.9 | WWBN | AVideo | CWE-306 | AVideo Authentication Bypass via Unkeyed Video Hash Disclosure |
| CVE-2026-62388 | 8.7 | 25.8 | nltk | nltk | CWE-1188 | NLTK before 3.10.0 Insecure Default Configuration pathsec |
| CVE-2026-76606 | 10.0 | 25.5 | fabrikar.com | Fabrik extension for Joomla | CWE-22 | Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik … |
| CVE-2026-19093 | 6.8 | 24.8 | Unknown | Tutor LMS | CWE-552 | Tutor LMS < 4.0.6 - Instructor+ Arbitrary File Read via Video Path |
| CVE-2026-12710 | 9.3 | 24.5 | Google Cloud | Application Integration | CWE-862 | Missing Authorization in Application Integration QueryEngineTask |
| CVE-2026-78122 | 8.3 | 24.5 | Tecnativa | docker-socket-proxy | CWE-1220 | docker-socket-proxy through 0.5.0 Insufficient Access Control Granularity Exp… |
| CVE-2026-62380 | 6.3 | 24.2 | netty | netty | CWE-626 | Netty before 4.2.16.Final SOCKS Proxy Null Byte Injection |
| CVE-2026-4559 | 6.4 | 23.9 | wpchill | Image Photo Gallery Final Tiles Grid | CWE-79 | Image Photo Gallery Final Tiles Grid <= 3.6.12 - Authenticated (Contributor+)… |
| CVE-2026-4561 | 6.4 | 23.9 | dvankooten | MC4WP: Mailchimp for WordPress | CWE-79 | MC4WP: Mailchimp for WordPress <= 4.12.0 - Authenticated (Author+) Stored Cro… |
| CVE-2026-76598 | 8.7 | 23.2 | fabrikar.com | Fabrik extension for Joomla | CWE-284 | Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing… |
| CVE-2026-76599 | 8.7 | 21.5 | fabrikar.com | Fabrik extension for Joomla | CWE-284 | Joomla Extension - fabrikar.com - Unauthenticated database table list and tab… |
| CVE-2026-76601 | 6.9 | 21.5 | fabrikar.com | Fabrik extension for Joomla | CWE-284 | Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < … |
| CVE-2026-76608 | 6.9 | 21.5 | fabrikar.com | Fabrik extension for Joomla | CWE-284 | Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter… |
| CVE-2026-4245 | 4.3 | 21.4 | metaphorcreations | Post Duplicator | CWE-863 | Post Duplicator <= 3.0.11 - Authorization Bypass to Authenticated (Contributo… |
| CVE-2026-62385 | 8.2 | 21.1 | nltk | nltk | CWE-73 | NLTK 3.9.4 Path Traversal via FrameNet and NKJP Readers |
| CVE-2026-16260 | 6.8 | 21.0 | Unknown | Post Grid, Slider & Carousel Ultimate | CWE-79 | Post Grid, Slider & Carousel Ultimate < 1.8.1 - Contributor+ Stored XSS via H… |
| CVE-2026-65915 | 7.1 | 20.6 | nltk | nltk | CWE-284 | NLTK before 3.10.0 Arbitrary File Read via FileSystemPathPointer |
| CVE-2026-62382 | 6.9 | 19.5 | pglombardo | PasswordPusher | CWE-863 | PasswordPusher before v2.9.6 Authentication Bypass via Null Comparison |
| CVE-2026-76571 | 9.3 | 18.8 | fabrikar.com | Fabrik extension for Joomla | CWE-89 | Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filte… |
| CVE-2026-18052 | 8.1 | 19.0 | Unknown | ManageWP Worker | CWE-287 | ManageWP Worker < 4.9.37 - Unauthenticated Authentication Bypass via Unsigned… |
| CVE-2026-59256 | 8.7 | 18.7 | WWBN | AVideo | CWE-200 | WWBN AVideo Unbound Token Authorization Bypass via Gallery |
| CVE-2026-77992 | 9.5 | 17.6 | fabrikar.com | Fabrik extension for Joomla | CWE-94 | Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc ele… |
| CVE-2026-19222 | 6.6 | 17.3 | Unknown | Forminator Forms | CWE-269 | Forminator Forms < 1.57.0.7 - Authenticated Privilege Escalation via Registra… |
| CVE-2026-77027 | 8.6 | 17.1 | fabrikar.com | Fabrik extension for Joomla | CWE-79 | Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2 |
| CVE-2026-76057 | 4.3 | 16.7 | rubengc | AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress | CWE-862 | AutomatorWP <= 5.8.4 - Missing Authorization to Authenticated (Subscriber+) S… |
| CVE-2026-16612 | 5.3 | 16.2 | Unknown | FiboSearch | CWE-200 | FiboSearch < 1.34.1 - Unauthenticated Password-Protected Product Information … |
| CVE-2026-76602 | 9.3 | 15.9 | fabrikar.com | Fabrik extension for Joomla | CWE-89 | Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY i… |
| CVE-2026-63311 | 6.9 | 16.0 | nltk | nltk | CWE-918 | NLTK before 3.10.0 SSRF via DNS Resolution Failure |
| CVE-2026-59809 | 6.9 | 15.3 | siyuan-note | siyuan | CWE-201 | SiYuan before v3.8.0 Secret Exfiltration via http_request URL |
| CVE-2026-16738 | 5.3 | 14.9 | Unknown | Conekta Payment Gateway | CWE-284 | Conekta Payment Gateway < 6.2.2 - Unauthenticated Order Payment Completion vi… |
| CVE-2026-76607 | 10.0 | 14.8 | fabrikar.com | Fabrik extension for Joomla | CWE-284 | Joomla Extension - fabrikar.com - Missing ACL check in download element in Fa… |
| CVE-2026-76596 | 8.7 | 14.8 | fabrikar.com | Fabrik extension for Joomla | CWE-284 | Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.d… |
| CVE-2026-76600 | 6.9 | 14.8 | fabrikar.com | Fabrik extension for Joomla | CWE-284 | Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in … |
| CVE-2026-76603 | 6.9 | 14.8 | fabrikar.com | Fabrik extension for Joomla | CWE-284 | Joomla Extension - fabrikar.com - Unauthenticated row disclosure via form.inl… |
| CVE-2026-76609 | 6.9 | 14.8 | fabrikar.com | Fabrik extension for Joomla | CWE-284 | Joomla Extension - fabrikar.com - Unauthenticated modification of any comment… |
| CVE-2026-76074 | 4.3 | 13.9 | rubengc | AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress | CWE-862 | AutomatorWP <= 5.8.4 - Missing Authorization to Authenticated (Subscriber+) S… |
| CVE-2026-75866 | await | 13.8 | — | Punk-OAuth2 | CWE-862 | Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outsi… |
| CVE-2026-60083 | 6.9 | 13.7 | siyuan-note | siyuan | CWE-863 | SiYuan before v3.8.0 Incomplete Path Blocklist via MCP file tool |
| CVE-2026-14187 | 2.7 | 12.0 | Unknown | Tutor LMS | CWE-639 | Tutor LMS < 4.0.6 - Instructor+ Cross-Instructor Private Course Disclosure vi… |
| CVE-2026-75870 | await | 11.9 | — | Punk | CWE-1394 | Punk versions before 0.18 for Perl allow session cookie forgery via an empty … |
| CVE-2026-56380 | 6.9 | 11.6 | WWBN | AVideo | CWE-200 | AVideo feed/index.php Exposure of Channel Owner Email Address |
| CVE-2026-74649 | await | 10.7 | Linux | Linux | — | staging: rtl8723bs: fix missing shared-key auth challenge length check |
| CVE-2026-4244 | 4.3 | 9.3 | metaphorcreations | Post Duplicator | CWE-862 | Post Duplicator <= 3.0.11 - Missing Authorization to Authenticated (Contribut… |
| CVE-2026-74689 | await | 9.2 | Linux | Linux | — | net/atm: fix slab-out-of-bounds read in vcc_setsockopt() |
| CVE-2026-74730 | await | 9.0 | Linux | Linux | — | NFS: Pin the 'struct nfs_server' during a FREE_STATEID call |
| CVE-2026-74683 | await | 8.7 | Linux | Linux | — | Input: evdev - sanitize event type index when fetching event masks |
| CVE-2026-74686 | await | 8.6 | Linux | Linux | — | rqspinlock: Reset tail when preserving queue on deadlock |
| CVE-2026-74601 | await | 8.1 | Linux | Linux | — | ring-buffer: Use current_context for safe per-CPU buffer swap |
| CVE-2026-74667 | await | 8.1 | Linux | Linux | — | net/packet: reset the MAC header on the packet-socket transmit path |
| CVE-2026-74679 | await | 8.1 | Linux | Linux | — | usb: gadget: f_ncm: Use unsigned int for ndp_index |
| CVE-2026-74732 | await | 7.9 | Linux | Linux | — | drm/amd/display: Check for tg ops in dce110_set_avmute |
| CVE-2026-74585 | await | 7.2 | Linux | Linux | — | thunderbolt: Bound the DROM dual link port number before indexing sw->ports |
| CVE-2026-74586 | await | 7.2 | Linux | Linux | — | sctp: clear new_transport when removing a peer |
| CVE-2026-74587 | await | 7.2 | Linux | Linux | — | sctp: fix use-after-free of cached ASCONF chunk |
| CVE-2026-74588 | await | 7.2 | Linux | Linux | — | sctp: keep chunk->transport in step with the list it is queued on |
| CVE-2026-74589 | await | 7.2 | Linux | Linux | — | bpf, sockmap: Fix sk_redir use-after-free in send verdict |
| CVE-2026-74594 | await | 7.2 | Linux | Linux | — | sched/psi: Shut down rtpoll_timer in psi_cgroup_free() |
| CVE-2026-74597 | await | 7.2 | Linux | Linux | — | ip6_tunnel: clear skb2->cb[] in ip6ip6_err() |
| CVE-2026-74598 | await | 7.2 | Linux | Linux | — | ipv6: fix Route Information option length validation |
| CVE-2026-74609 | await | 7.2 | Linux | Linux | — | tipc: read le->link under the node lock in tipc_node_link_down() |
| CVE-2026-74613 | await | 7.2 | Linux | Linux | — | vsock/virtio: avoid refilling the RX queue after teardown |
| CVE-2026-74615 | await | 7.2 | Linux | Linux | — | vxlan: do not arm the ageing timer on a device that is down |
| CVE-2026-74620 | await | 7.2 | Linux | Linux | — | net/sched: act_gact, act_police: range check the fallback control action |
| CVE-2026-74622 | await | 7.2 | Linux | Linux | — | net: atlantic: free RX pages of consumed but not refilled buffers |
| CVE-2026-74623 | await | 7.2 | Linux | Linux | — | net: atlantic: free stranded TX buffers on ring deinit |
| CVE-2026-74625 | await | 7.2 | Linux | Linux | — | netfilter: bridge: release template ct on non-IP path |
| CVE-2026-74630 | await | 7.2 | Linux | Linux | — | ipv6: prevent in6_dev_get() from resurrecting inet6_dev |
| CVE-2026-74631 | await | 7.2 | Linux | Linux | — | net: smc: fix splice entry lifetime imbalance in smc_rx_splice |
| CVE-2026-74635 | await | 7.2 | Linux | Linux | — | fbdev: bitblit: bound-check glyph index in bit_cursor() |
| CVE-2026-74641 | await | 7.2 | Linux | Linux | — | ALSA: usx2y: bound the hwdep mmap fault offset |
| CVE-2026-74648 | await | 7.2 | Linux | Linux | — | staging: rtl8723bs: validate monitor transmit frame lengths |
| CVE-2026-74651 | await | 7.2 | Linux | Linux | — | staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() |
| CVE-2026-74654 | await | 7.2 | Linux | Linux | — | serial: 8250_dma: Clear stale RX state on shutdown |
| CVE-2026-74656 | await | 7.2 | Linux | Linux | — | ipv4: fix use-after-free in fib_nhc_update_mtu() |
| CVE-2026-74658 | await | 7.2 | Linux | Linux | — | futex: Prevent robust futex exit race some more |
| CVE-2026-74660 | await | 7.2 | Linux | Linux | — | netfilter: ebt_nflog: pin the NFLOG backend |
| CVE-2026-74664 | await | 7.2 | Linux | Linux | — | net: openvswitch: reallocate update replies for mismatched IDs |
| CVE-2026-74669 | await | 7.2 | Linux | Linux | — | ipvs: clear IPv4 options after rebasing tunnel ICMP errors |
| CVE-2026-74671 | await | 7.2 | Linux | Linux | — | ima: fix out-of-bounds read in xattr_verify() |
| CVE-2026-74673 | await | 7.2 | Linux | Linux | — | Input: evdev - fix information leak in evdev_pass_values() |
| CVE-2026-74675 | await | 7.2 | Linux | Linux | — | vt: stabilize tty reference in kbd_keycode with tty_port_tty_get |
| CVE-2026-74676 | await | 7.2 | Linux | Linux | — | vt: add permission check for KDSKBMETA ioctl |
| CVE-2026-74680 | await | 7.3 | Linux | Linux | — | usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() |
| CVE-2026-74682 | await | 7.2 | Linux | Linux | — | ALSA: usb-audio: fix OOB write on Type II inbound URBs |
| CVE-2026-74688 | await | 7.3 | Linux | Linux | — | sctp: clear control chunk transport if it is being removed |
| CVE-2026-74693 | await | 7.2 | Linux | Linux | — | net: prestera: validate firmware header length |
| CVE-2026-74694 | await | 7.2 | Linux | Linux | — | net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length |
| CVE-2026-74701 | await | 7.3 | Linux | Linux | — | net/openvswitch: check Ethernet header length in key_extract() |
| CVE-2026-74704 | await | 7.2 | Linux | Linux | — | net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter |
| CVE-2026-74705 | await | 7.2 | Linux | Linux | — | udp: fix potential use-after-free in tunnel segmentation |
| CVE-2026-74717 | await | 7.2 | Linux | Linux | — | net/mlx5: fw_tracer, return NULL on create error |
| CVE-2026-74719 | await | 7.2 | Linux | Linux | — | net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_e… |
| CVE-2026-74720 | await | 7.2 | Linux | Linux | — | bpf: Preserve pointer state for commuted arithmetic |
| CVE-2026-74726 | await | 7.2 | Linux | Linux | — | bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor |
| CVE-2026-74707 | await | 7.1 | Linux | Linux | — | xsk: validate metadata when processing requests |
| CVE-2026-74599 | await | 6.7 | Linux | Linux | — | mm/ptdump: always stabilise against page table freeing using init_mm |
| CVE-2026-74603 | await | 6.7 | Linux | Linux | — | ptp: ocp: Fix board ID over-read |
| CVE-2026-74604 | await | 6.7 | Linux | Linux | — | Revert "thermal/drivers/hwmon: Cleanup coding style a bit" |
| CVE-2026-74607 | await | 6.7 | Linux | Linux | — | KVM: SVM: Serialize accesses to the owner and mirror list with separate lock |
| CVE-2026-74608 | await | 6.7 | Linux | Linux | — | smb: client: Fix use-after-free in cifs_try_adding_channels() |
| CVE-2026-74612 | await | 6.7 | Linux | Linux | — | veth: fix skb length accounting after XDP frag adjustment |
| CVE-2026-74614 | await | 6.7 | Linux | Linux | — | vsock/virtio: read virtqueues under worker locks |
| CVE-2026-74616 | await | 6.7 | Linux | Linux | — | xdp: reject clones that overrun skb_shared_info tailroom |
| CVE-2026-74621 | await | 6.7 | Linux | Linux | — | net/sched: act_ct: fix sk_buff leak when the header checks reject a packet |
| CVE-2026-74624 | await | 6.7 | Linux | Linux | — | netfilter: nf_conntrack: defer invalid log until after unlock |
| CVE-2026-74628 | await | 6.7 | Linux | Linux | — | net/x25: fix use-after-free of the socket by its timers |
| CVE-2026-74632 | await | 6.7 | Linux | Linux | — | mm/huge_memory: fix huge_zero_pfn race |
| CVE-2026-74636 | await | 6.7 | Linux | Linux | — | tracing: Fix race between update_event_fields and, event_define_fields |
| CVE-2026-74650 | await | 6.7 | Linux | Linux | — | staging: rtl8723bs: fix OOB read in WMM_param_handler() |
| CVE-2026-74657 | await | 6.7 | Linux | Linux | — | ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops |
| CVE-2026-74659 | await | 6.7 | Linux | Linux | — | net: bridge: mrp: fix uninitialised bytes on the wire |
| CVE-2026-74663 | await | 6.7 | Linux | Linux | — | net/sched: reject overly deep qdisc hierarchies |
| CVE-2026-74672 | await | 6.7 | Linux | Linux | — | mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF |
| CVE-2026-74678 | await | 6.7 | Linux | Linux | — | net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() |
| CVE-2026-74691 | await | 6.7 | Linux | Linux | — | net: thunderbolt: Tear down DMA paths before stopping the rings |
| CVE-2026-74692 | await | 6.7 | Linux | Linux | — | net/smc: fix TOCTOU race between smc_listen_out() and listener close |
| CVE-2026-74696 | await | 6.7 | Linux | Linux | — | tcp: fix TFO max_qlen accounting across reuseport migration |
| CVE-2026-74697 | await | 6.8 | Linux | Linux | — | bnxt_en: Disable EOP for TPA on all chips to prevent data corruption |
| CVE-2026-74714 | await | 6.7 | Linux | Linux | — | bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch() |
| CVE-2026-74722 | await | 6.7 | Linux | Linux | — | btrfs: fix memory leak in btrfs_do_encoded_write() |
| CVE-2026-74728 | await | 6.4 | Linux | Linux | — | xfs: handle NULL b_addr in xfs_buf_free |
| CVE-2026-74729 | await | 6.4 | Linux | Linux | — | soc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read |
| CVE-2026-74731 | await | 6.4 | Linux | Linux | — | sched_ext: Skip sub-disable teardown for never-linked sub-schedulers |
| CVE-2026-74733 | await | 6.4 | Linux | Linux | — | gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock |
| CVE-2026-74584 | await | 6.3 | Linux | Linux | — | RDMA/bnxt_re: zero shared page before exposing to userspace |
| CVE-2026-74590 | await | 6.2 | Linux | Linux | — | fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions |
| CVE-2026-74592 | await | 6.2 | Linux | Linux | — | ima: Instantiate file_truncate and path_truncate hooks |
| CVE-2026-74602 | await | 6.2 | Linux | Linux | — | ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer() |
| CVE-2026-74606 | await | 6.2 | Linux | Linux | — | eventfs: Fix use-after-free in eventfs_remove_rec() |
| CVE-2026-74610 | await | 6.2 | Linux | Linux | — | tls: don't leave a full plaintext sk_msg ring unpushed |
| CVE-2026-74618 | await | 6.2 | Linux | Linux | — | binfmt_misc: don't warn when the mount is completed from another user namespace |
| CVE-2026-74619 | await | 6.2 | Linux | Linux | — | ovl: don't warn when the mount is completed from another user namespace |
| CVE-2026-74634 | await | 6.2 | Linux | Linux | — | ring-buffer: Prevent subbuf order change when resizing is disabled |
| CVE-2026-74637 | await | 6.2 | Linux | Linux | — | perf/core: Fix group leader use-after-free after sibling detach |
| CVE-2026-74642 | await | 6.2 | Linux | Linux | — | ALSA: usb: Fix UAF at delayed release of MIDI2 EPs |
| CVE-2026-74644 | await | 6.2 | Linux | Linux | — | mm/damon/ops-common: putback folios on invalid migrate nid |
| CVE-2026-74646 | await | 6.2 | Linux | Linux | — | misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke |
| CVE-2026-74647 | await | 6.2 | Linux | Linux | — | misc: fastrpc: Remove buffer from list prior to unmap operation |
| CVE-2026-74655 | await | 6.2 | Linux | Linux | — | serial: qcom-geni: fix TX DMA buffer flush |
| CVE-2026-74661 | await | 6.2 | Linux | Linux | — | mac802154: fix netdev use-after-free in beacon worker |
| CVE-2026-74665 | await | 6.2 | Linux | Linux | — | net: fix skb length accounting after generic XDP frag adjustment |
| CVE-2026-74666 | await | 6.2 | Linux | Linux | — | packet: synchronize pressure clearing with ring reconfiguration |
| CVE-2026-74668 | await | 6.2 | Linux | Linux | — | packet: use consistent hard_header_len in TX_RING send path |
| CVE-2026-74670 | await | 6.2 | Linux | Linux | — | ipvs: stop estimator after disabled calc phase |
| CVE-2026-74677 | await | 6.2 | Linux | Linux | — | net: usb: ipheth: fix carrier_work UAF on disconnect |
| CVE-2026-74684 | await | 6.2 | Linux | Linux | — | net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() |
| CVE-2026-74685 | await | 6.2 | Linux | Linux | — | hwmon: (ltc4282) Clamp negative current limits |
| CVE-2026-74700 | await | 6.2 | Linux | Linux | — | net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers |
| CVE-2026-74710 | await | 6.2 | Linux | Linux | — | xsk: require at least 16 bytes of TX metadata |
| CVE-2026-74712 | await | 6.2 | Linux | Linux | — | vdpa/mlx5: Fix buffer length in create_direct_keys() |
| CVE-2026-74718 | await | 6.2 | Linux | Linux | — | devlink: fix net namespace reference leak in reload |
| CVE-2026-74725 | await | 6.2 | Linux | Linux | — | enic: fix tx_hang_reset use-after-free on device removal |
| CVE-2026-74703 | await | 6.1 | Linux | Linux | — | vhost-scsi: Validate T10 PI scatterlist counts |
| CVE-2026-74709 | await | 6.1 | Linux | Linux | — | xsk: clear metadata pointer when no timestamp is requested |
| CVE-2026-74591 | await | 6.0 | Linux | Linux | — | mm/filemap: __filemap_add_folio() restore index before retrying |
| CVE-2026-74593 | await | 6.0 | Linux | Linux | — | sched_ext: Take cgroup_lock() first in scx_cgroup_lock() |
| CVE-2026-74600 | await | 6.0 | Linux | Linux | — | mm/page_table_check: skip special zero mappings |
| CVE-2026-74611 | await | 6.0 | Linux | Linux | — | tls: rx: restore msg_iter before TLS 1.3 optimistic retry |
| CVE-2026-74617 | await | 6.0 | Linux | Linux | — | dibs: initialise dibs->lock in dibs_dev_alloc() |
| CVE-2026-74626 | await | 6.0 | Linux | Linux | — | NTB: ntb_netdev: Preserve RX queue depth on allocation failure |
| CVE-2026-74627 | await | 6.0 | Linux | Linux | — | net: devmem: prevent net-iov / page mixing |
| CVE-2026-74629 | await | 6.0 | Linux | Linux | — | net/dibs: Correct freeing of dmb_clientid_arr |
| CVE-2026-74633 | await | 6.0 | Linux | Linux | — | tracing: Fix NULL pointer dereference in module event cache removal |
| CVE-2026-74638 | await | 6.0 | Linux | Linux | — | drm/v3d: Serialize the scheduler timeout handlers |
| CVE-2026-74639 | await | 6.0 | Linux | Linux | — | ALSA: us144mkii: re-anchor capture URBs on resubmission |
| CVE-2026-74640 | await | 6.0 | Linux | Linux | — | ALSA: FCP: fix OOB write in fcp_meter_ctl_get() |
| CVE-2026-74643 | await | 6.0 | Linux | Linux | — | samples/damon/mtier: error out for zero quota goal target values |
| CVE-2026-74652 | await | 6.0 | Linux | Linux | — | serial: amba-pl011: cancel RS485 hrtimers after freeing IRQ |
| CVE-2026-74653 | await | 6.0 | Linux | Linux | — | serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx |
| CVE-2026-74662 | await | 6.0 | Linux | Linux | — | inet: frags: publish queues before arming timer |
| CVE-2026-74681 | await | 6.0 | Linux | Linux | — | usb: misc: usbio: check ibuf_len against rxbuf_len in bulk msg |
| CVE-2026-74687 | await | 6.0 | Linux | Linux | — | watchdog: at91sam9_wdt: prevent timer rearm during teardown |
| CVE-2026-74690 | await | 6.0 | Linux | Linux | — | s390/ism: Fix UAF of sba and ieq during ism_dev_exit() |
| CVE-2026-74695 | await | 6.0 | Linux | Linux | — | netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() |
| CVE-2026-74698 | await | 6.0 | Linux | Linux | — | net/mlx5e: fix BQL reset on SQ re-activation |
| CVE-2026-74702 | await | 6.0 | Linux | Linux | — | vhost-scsi: reject feature changes after endpoint |
| CVE-2026-74708 | await | 6.0 | Linux | Linux | — | xsk: validate launch-time metadata size |
| CVE-2026-74711 | await | 6.0 | Linux | Linux | — | hwmon: (pmbus) Fix type confusion in notification logic |
| CVE-2026-74727 | await | 6.0 | Linux | Linux | — | ovpn: skip rehash for peers already removed from by_id |
| CVE-2026-74724 | await | 5.9 | Linux | Linux | — | ipvs: avoid out-of-bounds write in ip_vs_nat_icmp |
| CVE-2026-68766 | 8.5 | 5.6 | hashcat | hashcat | CWE-88 | hashcat through 7.1.2 Arbitrary File Write via Restore File Option Injection |
| CVE-2026-12999 | 5.3 | 5.2 | zephyrproject | zephyr | CWE-401 | Infineon Airoc Wi-Fi driver leaks TX buffers on send failure, leading to perm… |
| CVE-2026-74706 | await | 5.0 | Linux | Linux | — | bnge: Fix NULL pointer dereference in aux device release |
| CVE-2026-62243 | 8.7 | 4.8 | netty | netty | CWE-297 | Netty 4.2.0 through 4.2.16 TLS Hostname Verification Bypass |
| CVE-2026-74596 | await | 4.9 | Linux | Linux | — | fs,fsverity: remove check for fsverity being enabled in setattr_prepare() |
| CVE-2026-74605 | await | 4.9 | Linux | Linux | — | eventfs: Use children field for rcu head and add memory barriers |
| CVE-2026-74645 | await | 4.9 | Linux | Linux | — | mm/damon/lru_sort: error out for >10000 active_mem_bp |
| CVE-2026-74674 | await | 4.9 | Linux | Linux | — | mm: fix incorrect flush address in direct page table reclaim |
| CVE-2026-74699 | await | 4.9 | Linux | Linux | — | drm/xe: Fix memory leak in exec_queue_set_hang_replay_state() |
| CVE-2026-74713 | await | 4.9 | Linux | Linux | — | vhost_iotlb: bound map allocation in add_range |
| CVE-2026-74715 | await | 4.9 | Linux | Linux | — | bpf: Fix netns reference imbalance in conntrack kfuncs |
| CVE-2026-74716 | await | 4.9 | Linux | Linux | — | accel/amdxdna: Fix locally exploitable BUG_ON in amdxdna_insert_pages() |
| CVE-2026-74721 | await | 4.9 | Linux | Linux | — | accel/amxdna: Fix page-insertion errors in amdxdna_insert_pages() |
| CVE-2026-74723 | await | 4.9 | Linux | Linux | — | btrfs: lzo: reject inline extents without valid headers |
| CVE-2026-57998 | 8.5 | 4.0 | jeemok | better-npm-audit | CWE-78 | better-npm-audit OS Command Injection via registry flag |
| CVE-2026-70626 | 8.6 | 3.8 | nltk | nltk | CWE-59 | NLTK before 3.9.4 Symlink Escape via CorpusReader |
| CVE-2026-71514 | 2.0 | 3.9 | nltk | nltk | CWE-22 | NLTK 3.9.4 through 3.10.2 Path Traversal via CrubadanCorpusReader pathsec Bypass |
| CVE-2026-68768 | 6.9 | 3.7 | hashcat | hashcat | CWE-120 | hashcat through 7.1.2 Heap Buffer Overflow in outfile_write() via Oversized U… |
| CVE-2026-62383 | 6.8 | 3.6 | nltk | nltk | CWE-22 | nltk IPIPANCorpusReader Symlink Arbitrary File Read |
| CVE-2026-58002 | 7.1 | 3.6 | WWBN | AVideo | CWE-345 | WWBN AVideo Authorization Bypass via Users_affiliations add.json.php |
| CVE-2026-68767 | 6.9 | 2.7 | hashcat | hashcat | CWE-193 | hashcat through 7.1.2 Off-by-One Out-of-Bounds Heap Write in fgetl() |
| CVE-2026-74595 | await | 2.1 | Linux | Linux | — | fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() |
| CVE-2026-58003 | 7.1 | 1.6 | WWBN | AVideo | CWE-352 | WWBN AVideo Cross-Site Request Forgery via releaseVideoNow.json.php |
| CVE-2026-58001 | 6.9 | 1.5 | WWBN | AVideo | CWE-352 | WWBN AVideo Cross-Site Request Forgery via videoEditLight.php |
| CVE-2026-63310 | 9.3 | 1.4 | nltk | nltk | CWE-494 | NLTK before 3.9.3 Missing Post-Download Integrity Verification |
| CVE-2026-57944 | 5.3 | 0.9 | WWBN | AVideo | CWE-352 | AVideo channelToGallery.json.php Cross-Site Request Forgery |
| CVE-2026-62381 | 6.9 | 0.1 | openwrt | luci | CWE-122 | luci-lib-px5g 2040-bit Certificate Signing Heap Buffer Overflow |
| CVE-2026-62204 | 5.9 | 0.0 | siyuan-note | siyuan | CWE-345 | SiYuan before v3.7.4 Plugin Overwrite via Bazaar Install |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-08-22 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.