boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Sunday, August 23, 2026 · all times UTC← 2026-08-22 · archive

Security Box Score — August 23, 2026

43 CVEs published, led by EmilStenstrom (11).

43 CVEs published August 23, 2026: 4 critical, 5 high, 15 medium, 15 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 4 awaiting enrichment. 25 rendered as box scores below; the remaining 18 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published935431518——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

1748 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux14173732363178163711120.17.8.0017+937 ▲
microsoft4691891145128145114286271.47.8.0044-181 ▼
google711832224765786577760.37.5.0025-48 ▼
red hat1895754323726431200.06.8.0029+82 ▲
apple40311588216368882.66.5.0029+37 ▲
canonical14411211135000.07.8.0020+7 ▲
freebsd233902340000.07.8.0015+23 ▲
suse52651461000.08.1.0039-3 ▼
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco46842139240561315.57.5.0044+31 ▲
palo alto networks12371321121325.44.7.0020-2 ▼
ubiquiti036142110338.38.8.0049-25 ▼
netgear93200275000.04.3.0025+3 ▲
fortinet7307814128620.07.0.0050-6 ▼
vmware21949427210.58.1.0040-6 ▼
f50165830416.38.6.0057-8 ▼
ivanti314482025535.78.3.0754+1 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache13246890198157133320.47.5.0048+40 ▲
mozilla591866868500900.08.1.0031-12 ▼
gitlab1667215428423.05.3.0029+9 ▲
drupal05165355412.05.9.0026-46 ▼
github5171790000.06.6.00430
docker290630000.07.2.0016+2 ▲
wordpress2513102240.08.8.31200
kubernetes010001000.02.4.0035-1 ▼
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle88922684871172513962730.17.8.0034-220 ▼
ibm3746031332851769610.27.5.0029+337 ▲
adobe603123914512351931.07.8.0026-35 ▼
progress19611437100611.68.1.0037-9 ▼
solarwinds0231733010417.49.1.0058-15 ▼
veeam10165920100.08.6.0034+9 ▲
zohocorp4103520000.08.7.0140+1 ▲
atlassian3615001300.08.1.00340
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link163615597300.07.4.0157+8 ▲
siemens193522382000.07.3.0016+12 ▲
rockwell automation12541830000.08.7.0029-16 ▼
synology12426133000.05.6.0025+1 ▲
schneider electric091620000.08.6.00370
abb070430000.07.2.0018-1 ▼
hikvision060420000.07.2.0040-5 ▼
moxa050320000.07.0.00290
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester42162008676000.05.3.0030-7 ▼
dell561551083575210.67.2.0019+13 ▲
splunk110128647705110.86.5.0025+107 ▲
openclaw01110583914000.07.0.0026-44 ▼
nvidia241061471210000.07.5.0034-17 ▼
siyuan-note73954220311000.08.7.0027+64 ▲
zephyrproject3891232489000.06.5.0022+17 ▲
itsourcecode2091001972000.02.1.0032+2 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.995799.99.8
CVE-2026-34486.986299.97.5
CVE-2026-63077.847399.79.8
CVE-2026-72898.792299.610.0
CVE-2026-59310.458898.79.8
CVE-2026-61511.339998.39.3
CVE-2026-64638.312098.18.9
CVE-2025-68686.291598.05.9
CVE-2026-71362.251497.89.1
CVE-2026-66066.189597.19.5
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.7922KEV
CVE-2026-4836210.0.0431
CVE-2026-1918810.0.0193
CVE-2026-5823110.0.0171
CVE-2026-6983610.0.0159
CVE-2026-1681210.0.0157KEV
CVE-2026-7329910.0.0121
CVE-2026-7367810.0.0114
CVE-2026-4561810.0.0092
CVE-2026-4816810.0.0091
Most disclosures (vendor)
VendorCVEs
linux1724
oracle889
microsoft474
google448
ibm442
red hat236
apache210
apple204
splunk110
siyuan-note77
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco13
apple8
fortinet6
google6
ivanti5
solarwinds4
adobe3
berriai3
oracle3
Most-affected ecosystems
EcosystemAdvisories
Maven51
PyPI10
npm5
Go4
Packagist2
NuGet1
crates.io1
Fastest to KEV
CVEVendorDays
CVE-2025-68686Fortinet0
CVE-2026-16812Arista Networks0
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20316Cisco0
CVE-2026-20349Cisco0
CVE-2026-34486Apache Software Foundation0
CVE-2026-63077JetBrains0
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171740
CVE-2021-27102n/a2021-11-171740
CVE-2021-27101n/a2021-11-171740
CVE-2021-27103n/a2021-11-171740
CVE-2021-21017Adobe2021-11-171740
CVE-2021-28550Adobe2021-11-171740
CVE-2021-42013Apache Software Foundation2021-11-171740
CVE-2021-41773Apache Software Foundation2021-11-171740
CVE-2021-30858Apple2021-11-171740
CVE-2021-30860Apple2021-11-171740

Transactions

EXPLOIT PUBLISHED — guardian language-system: 6 CVEs (CVE-2026-34100, CVE-2026-34101, CVE-2026-34102, CVE-2026-34103, CVE-2026-34104, CVE-2026-34105). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2025-5914 (libarchive). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-14187 (Unknown Tutor LMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16260 (Unknown Post Grid, Slider & Carousel Ultimate). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16612 (Unknown FiboSearch). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16738 (Unknown Conekta Payment Gateway). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-18052 (Unknown ManageWP Worker). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19093 (Unknown Tutor LMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19221 (Unknown Forminator Forms). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19222 (Unknown Forminator Forms). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-46243 (Linux). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-46331 (Linux). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-50656 (Microsoft Malware Protection Engine). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76789 (Unknown Slider Hero with Video Background, Animation). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76793 (Unknown Firebase Authentication). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-77000 (Unknown WP Social Media Login). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-77001 (Unknown Social Login & Sharing buttons with Analytics By SoClever). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-77002 (Unknown SmilePass Selfie Login). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-77988 (TRENDnet TEW-823DRU). Public exploit reference added.

RESCORED — CVE-2026-78050 (Comfast CF-N1-S). CVSS 9.4 → 8.6 (NVD).

RESCORED — CVE-2026-78051 (alexta69 MeTube). CVSS 6.9 → 5.5 (NVD).

PATCH SHIPPED — CVE-2026-10805 (Red Hat Enterprise Linux 8). Fixed in Red Hat Enterprise Linux 8 1:1.40.16-21.el8_10.

PATCH SHIPPED — CVE-2026-52902 (Red Hat Ansible Automation Platform 2.7 for RHEL 10). Fixed in Red Hat Ansible Automation Platform 2.7 for RHEL 10 0:4.8.6-1.el10ap.

ENRICHED — CVE-2024-40973 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHED — CVE-2025-23160 (Linux). Received CVSS 5.5 and CPE data from NVD.

Yesterday's Results

How to read these box scores · glossary

43 CVEs published. 25 box scores, 18 table rows — nothing truncated.

Tenda CH22 editFileName formeditFileName command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0107   62.2     —
AFFECTED
  Product  Versions   Fixed
  CH22     1.0.0.1 –  —
TIMELINE
  Aug 22  Reserved by CNA
  Aug 23  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Tenda CH22 exeCommand formexeCommand command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0107   62.2     —
AFFECTED
  Product  Versions   Fixed
  CH22     1.0.0.1 –  —
TIMELINE
  Aug 23  Reserved by CNA
  Aug 23  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
GitLab GitLab — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  C  H  H  H    8.5   .0072   51.1     —
AFFECTED
  Product  Versions  Fixed
  GitLab   18.8 –    —
TIMELINE
  May 29  Reserved by CNA
  Aug 23  Published (CNA: GitLab)
CWE-22 · CNA: GitLab · CVSS v3.1 · 2 references · NVD status: Received
ggml-org llama.cpp ggml-RPC Server ggml-rpc.cpp graph_compute null pointer dereference
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    6.9   .0054   43.0     —
AFFECTED
  Product    Versions     Fixed
  llama.cpp  bec4772f6 –  —
TIMELINE
  Aug 23  Reserved by CNA
  Aug 23  Published (CNA: VulDB)
CWE-476, CWE-404 · CNA: VulDB · CVSS v4.0 · 7 references
ggml-org llama.cpp ggml-RPC Server ggml-rpc.cpp deserialize_tensor deserialization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    6.9   .0043   35.8     —
AFFECTED
  Product    Versions     Fixed
  llama.cpp  bec4772f6 –  —
TIMELINE
  Aug 23  Reserved by CNA
  Aug 23  Published (CNA: VulDB)
CWE-20, CWE-502 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
n/a CTFd — CTFd __init__.py _is_safe_url redirect
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   L   N    2.1   .0042   34.7     —
AFFECTED
  Product  Versions  Fixed
  CTFd     3.8.0 –   —
TIMELINE
  Aug 23  Reserved by CNA
  Aug 23  Published (CNA: VulDB)
CWE-601 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Deferred
the-momentum open-wearables Public Invitation-Code Redemption Endpoint user_invitation_code.py redeem_invitation_code missing authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    6.9   .0040   33.4     —
AFFECTED
  Product         Versions  Fixed
  open-wearables  0.6.0 –   —
TIMELINE
  Aug 23  Reserved by CNA
  Aug 23  Published (CNA: VulDB)
CWE-306, CWE-287 · CNA: VulDB · CVSS v4.0 · 6 references
EmilStenstrom justhtml — justhtml before 1.12.0 Sanitizer Bypass via Markdown
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0038   30.8     —
AFFECTED
  Product   Versions     Fixed
  justhtml  unspecified  1.12.0
TIMELINE
  May 12  Reserved by CNA
  Aug 23  Published (CNA: VulnCheck)
CWE-79 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
EmilStenstrom justhtml — justhtml before 1.18.0 Denial of Service via CSS Selector
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0037   29.9     —
AFFECTED
  Product   Versions     Fixed
  justhtml  unspecified  1.18.0
TIMELINE
  Mar 23  Reserved by CNA
  Aug 23  Published (CNA: VulnCheck)
CWE-400 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
SourceCodester Stock Management System printOrder.php cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   L   N    2.1   .0035   28.1     —
AFFECTED
  Product                  Versions  Fixed
  Stock Management System  1.0 –     —
TIMELINE
  Aug 22  Reserved by CNA
  Aug 23  Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
SourceCodester Stock Management System getOrderReport.php cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   L   N    2.1   .0035   28.1     —
AFFECTED
  Product                  Versions  Fixed
  Stock Management System  1.0 –     —
TIMELINE
  Aug 22  Reserved by CNA
  Aug 23  Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
EmilStenstrom justhtml — justhtml before 1.16.0 Multiple Security Issues via Sanitization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0035   27.8     —
AFFECTED
  Product   Versions     Fixed
  justhtml  unspecified  1.16.0
TIMELINE
  May 4   Reserved by CNA
  Aug 23  Published (CNA: VulnCheck)
CWE-20 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
SourceCodester Class and Exam Timetabling System BSIT2.php cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   L   N    2.1   .0035   27.3     —
AFFECTED
  Product                            Versions  Fixed
  Class and Exam Timetabling System  1.0 –     —
TIMELINE
  Aug 22  Reserved by CNA
  Aug 23  Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
EmilStenstrom justhtml — justhtml before 1.15.0 Multiple Security Issues
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0034   27.0     —
AFFECTED
  Product   Versions     Fixed
  justhtml  unspecified  1.15.0
TIMELINE
  Apr 1   Reserved by CNA
  Aug 23  Published (CNA: VulnCheck)
CWE-20 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
n/a Open5GS — Open5GS S6a Authentication-Information-Request hss-s6a-path.c hss_ogs_diam_s6a_air_cb heap-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    5.3   .0033   25.7     —
AFFECTED
  Product  Versions  Fixed
  Open5GS  2.8.0 –   —
TIMELINE
  Aug 23  Reserved by CNA
  Aug 23  Published (CNA: VulDB)
CWE-122, CWE-119 · CNA: VulDB · CVSS v4.0 · 7 references
SourceCodester Class and Exam Timetabling System User Account Update edit_user_account.php improper authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   L   L    2.1   .0030   21.6     —
AFFECTED
  Product                            Versions  Fixed
  Class and Exam Timetabling System  1.0 –     —
TIMELINE
  Aug 22  Reserved by CNA
  Aug 23  Published (CNA: VulDB)
CWE-266, CWE-285 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
code-projects Barangay Resident Profiling Management System Boarder Management boarders.php authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0029   20.9     —
AFFECTED
  Product                                        Versions  Fixed
  Barangay Resident Profiling Management System  1.0 –     —
TIMELINE
  Aug 23  Reserved by CNA
  Aug 23  Published (CNA: VulDB)
CWE-285, CWE-639 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
vas3k TaxHacker JWT Secret config.ts envSchema.parse hard-coded credentials
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0029   20.8     —
AFFECTED
  Product    Versions  Fixed
  TaxHacker  0.8.0 –   —
TIMELINE
  Aug 22  Reserved by CNA
  Aug 23  Published (CNA: VulDB)
CWE-259, CWE-798 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
CVE-2026-19565AWAITING ENRICHMENT
Apache-AppSamurai — Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey
  CVSS   EPSS    %ile   KEV
  —      .0028   20.2   —
AFFECTED
  Product            Versions     Fixed
  Apache-AppSamurai  unspecified  —
TIMELINE
  Aug 11  Reserved by CNA
  Aug 23  Published (CNA: CPANSec)
CWE-341 · CNA: CPANSec · 3 references · NVD status: Received
EmilStenstrom justhtml — justhtml before 1.10.0 Denial of Service via deeply nested HTML
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0028   19.7     —
AFFECTED
  Product   Versions     Fixed
  justhtml  unspecified  1.10.0
TIMELINE
  May 27  Reserved by CNA
  Aug 23  Published (CNA: VulnCheck)
CWE-674 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
vas3k TaxHacker Email Sync imap-client.ts buildImapConfig server-side request forgery
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    5.3   .0028   19.4     —
AFFECTED
  Product    Versions  Fixed
  TaxHacker  0.8.0 –   —
TIMELINE
  Aug 22  Reserved by CNA
  Aug 23  Published (CNA: VulDB)
CWE-918 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
SourceCodester Class and Exam Timetabling System BSIS1.php cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   L   N    2.1   .0027   19.1     —
AFFECTED
  Product                            Versions  Fixed
  Class and Exam Timetabling System  1.0 –     —
TIMELINE
  Aug 22  Reserved by CNA
  Aug 23  Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
OnGres StackGres — Untrusted Search Path in StackGres
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0027   19.0     —
AFFECTED
  Product    Versions     Fixed
  StackGres  unspecified  —
TIMELINE
  Aug 23  Reserved by CNA
  Aug 23  Published (CNA: GitLab)
CWE-426 · CNA: GitLab · CVSS v3.1 · 1 reference · NVD status: Received
code-projects Barangay Resident Profiling Management System Resident Search Functionality residents.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0026   17.7     —
AFFECTED
  Product                                        Versions  Fixed
  Barangay Resident Profiling Management System  1.0 –     —
TIMELINE
  Aug 23  Reserved by CNA
  Aug 23  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
CVE-2026-75922AWAITING ENRICHMENT
Reverse-Proxy — Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request line
  CVSS   EPSS    %ile   KEV
  —      .0026   17.6   —
AFFECTED
  Product        Versions     Fixed
  Reverse-Proxy  unspecified  —
TIMELINE
  Aug 18  Reserved by CNA
  Aug 23  Published (CNA: CPANSec)
CWE-93, CWE-444 · CNA: CPANSec · 5 references · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-780572.116.7sambitrajStudent-Management-SystemCWE-74sambitraj Student-Management-System Management Mutation sql injection
CVE-2026-781122.116.1itsourcecodeHospital Management System Project in PHPCWE-74itsourcecode Hospital Management System Project in PHP viewservicetype.php sq…
CVE-2026-781402.015.3DromaraUJCMSCWE-791Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java updat…
CVE-2026-78183await13.5—DBD-PgCWE-787DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float
CVE-2026-781422.112.3code-projectsBarangay Resident Profiling Management SystemCWE-285code-projects Barangay Resident Profiling Management System Restore/Delete ar…
CVE-2026-747935.110.3EmilStenstromjusthtmlCWE-79justhtml before 3.11.0 XSS via selectedcontent projection
CVE-2026-780562.110.3sambitrajStudent-Management-SystemCWE-74sambitraj Student-Management-System Dashboard sql injection
CVE-2026-781367.88.4chirpmyradioCHIRPCWE-95chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data.…
CVE-2026-770885.38.4EmilStenstromjusthtmlCWE-79justhtml 0.9.0 through 1.21.0 Cross-Site Scripting via code-span
CVE-2026-53895.18.4EmilStenstromjusthtmlCWE-80justhtml before 1.13.0 XSS via code fence breakout
CVE-2026-57515.18.4EmilStenstromjusthtmlCWE-79justhtml before 1.14.0 Mutation XSS via custom sanitization policies
CVE-2026-86305.18.4EmilStenstromjusthtmlCWE-79justhtml before 1.12.0 Mutation XSS via Raw Text Elements
CVE-2026-68275.18.3EmilStenstromjusthtmlCWE-79justhtml before 1.17.0 Multiple Cross-Site Scripting Vulnerabilities
CVE-2026-148534.36.4UnknownWooCommerce BookingsCWE-862WooCommerce Bookings < 3.9.0 - Subscriber+ Draft Bookable Product Creation vi…
CVE-2026-770032.76.3UnknownContent MaskCWE-269Content Mask 1.8.0 - 1.8.5.4 - Contributor Publish Capability Bypass via crea…
CVE-2026-771164.35.9UnknownBraveCWE-639Brave Popup Builder < 0.8.6 - Subscriber+ Unpublished Popup Disclosure via Pr…
CVE-2026-13598await4.6UnknownRestrictMate—RestrictMate < 1.3.0 - Unauthenticated Privilege Escalation to Administrator
CVE-2026-771157.14.1UnknownBraveCWE-79Brave Popup Builder < 0.8.6 - Unauthenticated Reflected XSS via UTM Parameters

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-23 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.