AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0155 73.1 —
AFFECTED Product Versions Fixed 4MOSAn GCB Doctor unspecified —
TIMELINE Aug 24 Reserved by CNA Aug 24 Published (CNA: twcert)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
CISA adds 1 to KEV; 310 CVEs published, led by DrayTek Corporation (40).
310 CVEs published August 24, 2026: 39 critical, 157 high, 77 medium, 14 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 23 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 285 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 9664 | 31829 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
1767 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 1417 | 3732 | 363 | 1781 | 637 | 1 | 11 | 2 | 0.1 | 7.8 | .0017 | +889 ▲ |
| microsoft | 469 | 1891 | 145 | 1281 | 451 | 14 | 286 | 27 | 1.4 | 7.8 | .0044 | -191 ▼ |
| 73 | 1834 | 225 | 766 | 786 | 57 | 77 | 6 | 0.3 | 7.5 | .0025 | -46 ▼ | |
| red hat | 198 | 584 | 43 | 246 | 264 | 31 | 2 | 0 | 0.0 | 6.8 | .0029 | +81 ▲ |
| apple | 40 | 311 | 58 | 82 | 163 | 6 | 88 | 8 | 2.6 | 6.5 | .0029 | +37 ▲ |
| canonical | 15 | 42 | 13 | 11 | 13 | 5 | 0 | 0 | 0.0 | 7.8 | .0020 | +8 ▲ |
| freebsd | 23 | 39 | 0 | 23 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0015 | +23 ▲ |
| suse | 5 | 26 | 5 | 14 | 6 | 1 | 0 | 0 | 0.0 | 8.1 | .0039 | -3 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 46 | 84 | 21 | 39 | 24 | 0 | 56 | 13 | 15.5 | 7.5 | .0044 | +31 ▲ |
| palo alto networks | 12 | 37 | 1 | 3 | 21 | 12 | 13 | 2 | 5.4 | 4.7 | .0020 | -2 ▼ |
| ubiquiti | 0 | 36 | 14 | 21 | 1 | 0 | 3 | 3 | 8.3 | 8.8 | .0049 | -25 ▼ |
| netgear | 9 | 32 | 0 | 0 | 27 | 5 | 0 | 0 | 0.0 | 4.3 | .0025 | +3 ▲ |
| fortinet | 7 | 30 | 7 | 8 | 14 | 1 | 28 | 6 | 20.0 | 7.0 | .0050 | -6 ▼ |
| vmware | 2 | 19 | 4 | 9 | 4 | 2 | 7 | 2 | 10.5 | 8.1 | .0040 | -6 ▼ |
| f5 | 0 | 17 | 5 | 9 | 3 | 0 | 4 | 1 | 5.9 | 8.7 | .0057 | -8 ▼ |
| ivanti | 3 | 14 | 4 | 8 | 2 | 0 | 25 | 5 | 35.7 | 8.3 | .0754 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 141 | 477 | 90 | 198 | 158 | 13 | 33 | 2 | 0.4 | 7.5 | .0048 | +38 ▲ |
| mozilla | 59 | 186 | 68 | 68 | 50 | 0 | 9 | 0 | 0.0 | 8.1 | .0031 | -12 ▼ |
| gitlab | 16 | 67 | 2 | 15 | 42 | 8 | 4 | 2 | 3.0 | 5.3 | .0029 | +9 ▲ |
| drupal | 0 | 51 | 6 | 5 | 35 | 5 | 4 | 1 | 2.0 | 5.9 | .0026 | -46 ▼ |
| github | 5 | 17 | 1 | 7 | 9 | 0 | 0 | 0 | 0.0 | 6.6 | .0043 | 0 |
| docker | 2 | 9 | 0 | 6 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0016 | +2 ▲ |
| wordpress | 2 | 5 | 1 | 3 | 1 | 0 | 2 | 2 | 40.0 | 8.8 | .3120 | 0 |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0035 | -1 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 889 | 2268 | 487 | 1172 | 513 | 96 | 28 | 4 | 0.2 | 7.8 | .0034 | -220 ▼ |
| ibm | 374 | 603 | 133 | 286 | 176 | 8 | 6 | 1 | 0.2 | 7.5 | .0029 | +337 ▲ |
| adobe | 60 | 312 | 39 | 145 | 123 | 5 | 19 | 3 | 1.0 | 7.8 | .0026 | -35 ▼ |
| progress | 19 | 61 | 14 | 37 | 10 | 0 | 6 | 1 | 1.6 | 8.1 | .0037 | -9 ▼ |
| solarwinds | 0 | 23 | 17 | 3 | 3 | 0 | 10 | 4 | 17.4 | 9.1 | .0058 | -15 ▼ |
| veeam | 10 | 16 | 5 | 9 | 2 | 0 | 1 | 0 | 0.0 | 8.6 | .0034 | +9 ▲ |
| zohocorp | 4 | 10 | 3 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0140 | +1 ▲ |
| atlassian | 3 | 6 | 1 | 5 | 0 | 0 | 13 | 0 | 0.0 | 8.1 | .0034 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 16 | 36 | 15 | 5 | 9 | 7 | 3 | 0 | 0.0 | 7.4 | .0157 | +8 ▲ |
| siemens | 19 | 35 | 2 | 23 | 8 | 2 | 0 | 0 | 0.0 | 7.3 | .0016 | +12 ▲ |
| rockwell automation | 1 | 25 | 4 | 18 | 3 | 0 | 0 | 0 | 0.0 | 8.7 | .0029 | -16 ▼ |
| synology | 1 | 24 | 2 | 6 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +1 ▲ |
| schneider electric | 0 | 9 | 1 | 6 | 2 | 0 | 0 | 0 | 0.0 | 8.6 | .0037 | 0 |
| abb | 0 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -1 ▼ |
| hikvision | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0040 | -5 ▼ |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 47 | 167 | 0 | 0 | 91 | 76 | 0 | 0 | 0.0 | 5.5 | .0029 | -2 ▼ |
| dell | 58 | 157 | 10 | 84 | 58 | 5 | 2 | 1 | 0.6 | 7.2 | .0019 | +15 ▲ |
| splunk | 110 | 128 | 6 | 47 | 70 | 5 | 1 | 1 | 0.8 | 6.5 | .0025 | +107 ▲ |
| openclaw | 0 | 111 | 0 | 58 | 39 | 14 | 0 | 0 | 0.0 | 7.0 | .0026 | -44 ▼ |
| nvidia | 24 | 106 | 14 | 71 | 21 | 0 | 0 | 0 | 0.0 | 7.5 | .0034 | -17 ▼ |
| itsourcecode | 28 | 99 | 0 | 0 | 25 | 74 | 0 | 0 | 0.0 | 2.1 | .0028 | +10 ▲ |
| siyuan-note | 73 | 95 | 42 | 20 | 31 | 1 | 0 | 0 | 0.0 | 8.7 | .0027 | +64 ▲ |
| zephyrproject | 42 | 95 | 2 | 33 | 51 | 9 | 0 | 0 | 0.0 | 6.4 | .0022 | +20 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-8037 | .9957 | 99.9 | 9.8 |
| CVE-2026-34486 | .9862 | 99.9 | 7.5 |
| CVE-2026-63077 | .8473 | 99.7 | 9.8 |
| CVE-2026-72898 | .7922 | 99.6 | 10.0 |
| CVE-2026-59310 | .4588 | 98.7 | 9.8 |
| CVE-2026-61511 | .3399 | 98.3 | 9.3 |
| CVE-2026-64638 | .3120 | 98.1 | 8.9 |
| CVE-2025-68686 | .2915 | 98.0 | 5.9 |
| CVE-2026-71362 | .2514 | 97.8 | 9.1 |
| CVE-2026-66066 | .1895 | 97.1 | 9.5 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-72898 | 10.0 | .7922 | KEV |
| CVE-2026-48362 | 10.0 | .0431 | |
| CVE-2026-19188 | 10.0 | .0193 | |
| CVE-2026-58231 | 10.0 | .0171 | |
| CVE-2026-69836 | 10.0 | .0159 | |
| CVE-2026-16812 | 10.0 | .0157 | KEV |
| CVE-2026-73299 | 10.0 | .0121 | |
| CVE-2026-73678 | 10.0 | .0114 | |
| CVE-2026-45618 | 10.0 | .0092 | |
| CVE-2026-48168 | 10.0 | .0091 |
| Vendor | CVEs |
|---|---|
| linux | 1450 |
| oracle | 889 |
| microsoft | 474 |
| 450 | |
| ibm | 442 |
| red hat | 245 |
| apache | 219 |
| apple | 204 |
| splunk | 110 |
| siyuan-note | 76 |
| Vendor | KEV |
|---|---|
| microsoft | 27 |
| cisco | 13 |
| apple | 8 |
| fortinet | 6 |
| 6 | |
| ivanti | 5 |
| oracle | 4 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 59 |
| PyPI | 14 |
| npm | 13 |
| Go | 4 |
| Packagist | 2 |
| NuGet | 1 |
| crates.io | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2025-68686 | Fortinet | 0 |
| CVE-2026-16812 | Arista Networks | 0 |
| CVE-2026-18556 | N-able | 0 |
| CVE-2026-18577 | N-able | 0 |
| CVE-2026-20316 | Cisco | 0 |
| CVE-2026-20349 | Cisco | 0 |
| CVE-2026-34486 | Apache Software Foundation | 0 |
| CVE-2026-63077 | JetBrains | 0 |
| CVE-2026-72529 | TrueConf | 0 |
| CVE-2026-72530 | TrueConf | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1741 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1741 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1741 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1741 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1741 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1741 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1741 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1741 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1741 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1741 |
ADDED TO KEV — CVE-2026-21962 (Oracle Corporation Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in). Remediation due August 27, 2026.
EXPLOIT PUBLISHED — axios: 16 CVEs (CVE-2025-62718, CVE-2026-25639, CVE-2026-40175, CVE-2026-42033, CVE-2026-42039, CVE-2026-42041, CVE-2026-42043, CVE-2026-42044, CVE-2026-42264, CVE-2026-44486, CVE-2026-44487, CVE-2026-44488, CVE-2026-44492, CVE-2026-44494, CVE-2026-44495, CVE-2026-44496). Public exploit references added.
EXPLOIT PUBLISHED — Red Hat Enterprise Linux 10: 7 CVEs (CVE-2026-4878, CVE-2026-12548, CVE-2026-48864, CVE-2026-55653, CVE-2026-66337, CVE-2026-66338, CVE-2026-66339). Public exploit references added.
EXPLOIT PUBLISHED — isaacs node-tar: 3 CVEs (CVE-2026-23745, CVE-2026-23950, CVE-2026-24842). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2024-21626 (opencontainers runc). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2024-22373 (Grassroot DICOM). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2024-31823. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2024-31828. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2024-33775. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-56005. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-61258. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10053 (GitLab). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-2332 (Eclipse Foundation Eclipse Jetty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-24049 (pypa wheel). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-25896 (NaturalIntelligence fast-xml-parser). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-26369 (JUNG eNet SMART HOME server). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-29063 (immutable-js). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-30922 (pyasn1). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-33487 (russellhaering goxmldsig). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-40938 (tektoncd pipeline). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-41035 (Samba rsync). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45736 (websockets ws). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-4740 (Red Hat multicluster engine for Kubernetes 2.1). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48779 (websockets ws). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-59087 (gimp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-59091 (gimp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66759 (GNOME GIMP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-6732 (Red Hat Hardened Images). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-78050 (Comfast CF-N1-S). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-78051 (alexta69 MeTube). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-78055 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-78057 (sambitraj Student-Management-System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-78059 (SourceCodester Stock Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-78063 (Tenda CH22). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-78112 (itsourcecode Hospital Management System Project in PHP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-78140 (Dromara UJCMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-78142 (code-projects Barangay Resident Profiling Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-78143 (code-projects Barangay Resident Profiling Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-78145 (CTFd). Public exploit reference added.
DUE DATE PASSED — CVE-2026-72529 (TrueConf Server). CISA remediation deadline was August 23, 2026; still in catalog.
RESCORED — guardian language-system: 6 CVEs (CVE-2026-34100, CVE-2026-34101, CVE-2026-34102, CVE-2026-34103, CVE-2026-34104, CVE-2026-34105). CVSS rescored — before/after on each CVE page.
RESCORED — getgrav grav: 5 CVEs (CVE-2026-72822, CVE-2026-72824, CVE-2026-72826, CVE-2026-72829, CVE-2026-72830). CVSS rescored — before/after on each CVE page.
RESCORED — IBM AIX: 4 CVEs (CVE-2026-16923, CVE-2026-16925, CVE-2026-16927, CVE-2026-16989). CVSS rescored — before/after on each CVE page.
RESCORED — axios: 3 CVEs (CVE-2026-42043, CVE-2026-42044, CVE-2026-42264). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2023-50176 (Fortinet FortiOS). CVSS 4 → 8.8 (NVD).
RESCORED — CVE-2024-22373 (Grassroot DICOM). CVSS 8.1 → 9.8 (NVD).
RESCORED — CVE-2025-36255 (IBM DS8A00( R10.0 - R10.1 )). CVSS 7.5 → 8.8 (NVD).
RESCORED — CVE-2025-46252 (Kofi Mokome Message Filter for Contact Form 7). CVSS 7.6 → 7.2 (NVD).
RESCORED — CVE-2026-17015 (IBM i). CVSS 5.4 → 8.1 (NVD).
RESCORED — CVE-2026-18102 (IBM i). CVSS 3.5 → 4.3 (NVD).
RESCORED — CVE-2026-18652 (Rapid7 Velociraptor). CVSS 4.9 → 6.5 (NVD).
RESCORED — CVE-2026-22029 (remix-run react-router). CVSS 8 → 6.1 (NVD).
RESCORED — CVE-2026-23950 (isaacs node-tar). CVSS 8.8 → 5.9 (NVD).
RESCORED — CVE-2026-24049 (pypa wheel). CVSS 7.1 → 5.5 (NVD).
RESCORED — CVE-2026-33810 (Go standard library crypto/x509). CVSS 7.5 → 8.2 (NVD).
RESCORED — CVE-2026-39910 (STACKIT IaaS API). CVSS 9.3 → 8.7 (NVD).
RESCORED — CVE-2026-41035 (Samba rsync). CVSS 7.4 → 7.8 (NVD).
RESCORED — CVE-2026-45736 (websockets ws). CVSS 4.4 → 7.5 (NVD).
RESCORED — CVE-2026-4800 (lodash). CVSS 8.1 → 9.8 (NVD).
RESCORED — CVE-2026-66338 (Red Hat Enterprise Linux 10). CVSS 5.4 → 7.2 (NVD).
RESCORED — CVE-2026-6732 (Red Hat Hardened Images). CVSS 6.5 → 7.5 (NVD).
RESCORED — CVE-2026-67340 (ArcadeData arcadedb). CVSS 9.3 → 8.6 (NVD).
RESCORED — CVE-2026-70894 (Oracle Corporation Oracle Hyperion Data Relationship Management). CVSS 7.7 → 7.1 (NVD).
RESCORED — CVE-2026-71474 (Red Hat Advanced Cluster Management for Kubernetes 2). CVSS 6.3 → 6.5 (NVD).
RESCORED — CVE-2026-7163 (Red Hat multicluster engine for Kubernetes 2.1). CVSS 6.1 → 5.5 (NVD).
RESCORED — CVE-2026-71845 (Red Hat Advanced Cluster Management for Kubernetes 2). CVSS 6.3 → 7.7 (NVD).
RESCORED — CVE-2026-78156 (Open5GS). CVSS 5.3 → 2.1 (NVD).
PATCH SHIPPED — Adobe Experience Manager as a Cloud Service: 57 CVEs (CVE-2026-34692, CVE-2026-47935, CVE-2026-47936, CVE-2026-47939, CVE-2026-47941, CVE-2026-47942, CVE-2026-47943, CVE-2026-47944, CVE-2026-47945, CVE-2026-47946, CVE-2026-47947, CVE-2026-47948, CVE-2026-47949, CVE-2026-47950, CVE-2026-47951, CVE-2026-47953, CVE-2026-47954, CVE-2026-47956, CVE-2026-47957, CVE-2026-47958, CVE-2026-47962, CVE-2026-47966, CVE-2026-47970, CVE-2026-47972, CVE-2026-47973, CVE-2026-47974, CVE-2026-47975, CVE-2026-47977, CVE-2026-47978, CVE-2026-47980, CVE-2026-47981, CVE-2026-47982, CVE-2026-47983, CVE-2026-47985, CVE-2026-47986, CVE-2026-47987, CVE-2026-47989, CVE-2026-47990, CVE-2026-47991, CVE-2026-47993, CVE-2026-48250, CVE-2026-48251, CVE-2026-48256, CVE-2026-48258, CVE-2026-48264, CVE-2026-48265, CVE-2026-48266, CVE-2026-48268, CVE-2026-48271, CVE-2026-48280, and 7 more — full list in this day's data.json). Fix versions published.
PATCH SHIPPED — Adobe ColdFusion 2025: 13 CVEs (CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48282, CVE-2026-48283, CVE-2026-48285, CVE-2026-48307, CVE-2026-48313, CVE-2026-48314, CVE-2026-48315, CVE-2026-48316, CVE-2026-48363, CVE-2026-48364). Fix versions published.
PATCH SHIPPED — CVE-2026-48286 (Adobe Campaign Classic). Fixed in Adobe Campaign Classic ACC v7: 7.4.3 build 9397.
How to read these box scores · glossary
310 CVEs published. 25 box scores, 285 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0155 73.1 —
AFFECTED Product Versions Fixed 4MOSAn GCB Doctor unspecified —
TIMELINE Aug 24 Reserved by CNA Aug 24 Published (CNA: twcert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0103 61.1 —
AFFECTED Product Versions Fixed ipTIME T16000M 14.20.2 – —
TIMELINE Aug 23 Reserved by CNA Aug 24 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0093 57.9 —
AFFECTED Product Versions Fixed ipTIME T24000M 14.0 – —
TIMELINE Aug 23 Reserved by CNA Aug 24 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N N A H H H 8.4 .0074 51.9 —
AFFECTED Product Versions Fixed Sakura Editor unspecified —
TIMELINE Jul 6 Reserved by CNA Aug 24 Published (CNA: jpcert)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0066 48.6 —
AFFECTED Product Versions Fixed DIAEnergie unspecified —
TIMELINE Aug 24 Reserved by CNA Aug 24 Published (CNA: Deltaww)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0066 48.6 —
AFFECTED Product Versions Fixed DIAEnergie unspecified —
TIMELINE Aug 24 Reserved by CNA Aug 24 Published (CNA: Deltaww)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0066 48.6 —
AFFECTED Product Versions Fixed DIAEnergie unspecified —
TIMELINE Aug 24 Reserved by CNA Aug 24 Published (CNA: Deltaww)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0066 48.6 —
AFFECTED Product Versions Fixed DIAEnergie unspecified —
TIMELINE Aug 24 Reserved by CNA Aug 24 Published (CNA: Deltaww)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0062 46.9 —
AFFECTED Product Versions Fixed LXD 4.0.0 – —
TIMELINE Jul 28 Reserved by CNA Aug 24 Published (CNA: canonical)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L H N L N L L L 1.1 .0060 46.2 —
AFFECTED Product Versions Fixed devtools-vite 0.7.0 – —
TIMELINE Aug 23 Reserved by CNA Aug 24 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0050 40.6 —
AFFECTED Product Versions Fixed 4MOSAn Management Center unspecified —
TIMELINE Aug 24 Reserved by CNA Aug 24 Published (CNA: twcert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0045 36.9 —
AFFECTED Product Versions Fixed exceljs unspecified —
TIMELINE Aug 24 Reserved by CNA Aug 24 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H L 9.3 .0044 36.4 —
AFFECTED Product Versions Fixed exceljs unspecified —
TIMELINE Aug 24 Reserved by CNA Aug 24 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 6.9 .0044 36.4 —
AFFECTED Product Versions Fixed jQWidgets 24.0.0 – —
TIMELINE Aug 23 Reserved by CNA Aug 24 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 6.9 .0044 36.4 —
AFFECTED Product Versions Fixed next 1.27.0 – —
TIMELINE Aug 23 Reserved by CNA Aug 24 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0044 36.4 —
AFFECTED Product Versions Fixed ractive 1.4.0 – —
TIMELINE Aug 23 Reserved by CNA Aug 24 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0044 36.3 —
AFFECTED Product Versions Fixed HiPER 1250GW 3.2.7-210907-180535 – —
TIMELINE Aug 23 Reserved by CNA Aug 24 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 7.4 .0044 36.3 —
AFFECTED Product Versions Fixed HiPER 1200GW 2.5.3-170306 – —
TIMELINE Aug 23 Reserved by CNA Aug 24 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H N 7.5 .0043 35.2 —
AFFECTED Product Versions Fixed fast-uri 2.4.2 – 2.4.5
TIMELINE Aug 18 Reserved by CNA Aug 24 Published (CNA: openjs)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N P N L N 1.3 .0041 34.1 —
AFFECTED Product Versions Fixed Piwigo 16.3.0 – 16.4.0
TIMELINE Aug 23 Reserved by CNA Aug 24 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0040 33.4 —
AFFECTED Product Versions Fixed libwebsockets 4.5.0 – —
TIMELINE Aug 23 Reserved by CNA Aug 24 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H N 7.5 .0040 33.1 —
AFFECTED Product Versions Fixed fast-uri 2.4.1 – 2.4.5
TIMELINE Aug 18 Reserved by CNA Aug 24 Published (CNA: openjs)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H N 7.5 .0040 33.1 —
AFFECTED Product Versions Fixed fast-uri 2.3.1 – 2.4.5
TIMELINE Aug 18 Reserved by CNA Aug 24 Published (CNA: openjs)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N N N L 2.1 .0039 31.8 —
AFFECTED Product Versions Fixed Open5GS 2.0 – —
TIMELINE Aug 23 Reserved by CNA Aug 24 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0039 31.6 —
AFFECTED Product Versions Fixed Neo unspecified — Neo 2 unspecified — Flip unspecified — Air 3 unspecified — Air 3S unspecified — Avata 2 unspecified — Avata 360 unspecified — Mavic 3 unspecified — Mavic 3 Classic unspecified — Mavic 3 Pro unspecified — + 6 more
TIMELINE Aug 24 Reserved by CNA Aug 24 Published (CNA: CIRCL)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-78208 | 8.7 | 30.0 | exceljs | exceljs | CWE-73 | exceljs through 4.4.0 Path Traversal via Unvalidated addImage filename |
| CVE-2026-19853 | 6.9 | 25.9 | CyberTutor | NewSiteServer (NSS) | CWE-306 | CyberTutor|NewSiteServer (NSS) - Missing Authentication |
| CVE-2026-78179 | 5.3 | 25.3 | rexrainbow | phaser3-rex-notes | CWE-94 | rexrainbow phaser3-rex-notes BehaviorTree Blackboard Data SetValue.js SetValu… |
| CVE-2026-78171 | 5.5 | 25.2 | itsourcecode | Sales and Inventory System | CWE-74 | itsourcecode Sales and Inventory System processlogin.php sql injection |
| CVE-2026-78182 | 5.5 | 23.5 | Shenzhen Gongji Technology | XBROTHER Dynamic Environment Monitoring System | CWE-74 | Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System pla… |
| CVE-2026-78213 | 6.2 | 23.2 | Hepta Platforms | Heptabase | CWE-79 | Hepta Platforms|Heptabase - Stored Cross-Site Scripting |
| CVE-2026-78166 | 2.1 | 22.6 | provectus | kafka-ui | CWE-74 | provectus kafka-ui Groovy Code MessagesController.java executeSmartFilterTest… |
| CVE-2026-78205 | 6.9 | 22.1 | bentoml | BentoML | CWE-918 | BentoML 1.4.19 through 1.4.39 Server-Side Request Forgery via Unfiltered RFC … |
| CVE-2026-78209 | 8.4 | 21.5 | exceljs | exceljs | CWE-1236 | exceljs through 4.4.0 CSV Formula Injection via Unescaped Cell Values |
| CVE-2026-78160 | 2.1 | 20.9 | Dolibarr | ERP | CWE-285 | Dolibarr ERP User Notes note.php authorization |
| CVE-2026-78202 | 5.5 | 20.7 | itsourcecode | Payroll System | CWE-284 | itsourcecode Payroll System admin_class.php save_settings unrestricted upload |
| CVE-2026-78203 | 7.1 | 18.7 | GhostManager | Ghostwriter | CWE-639 | Ghostwriter before 7.1.2 Cross-Client Report Template Disclosure via Unauthor… |
| CVE-2026-78197 | 5.5 | 18.0 | SourceCodester | Simple Online Food Ordering System | CWE-74 | SourceCodester Simple Online Food Ordering System ajax.php save_user sql inje… |
| CVE-2026-78198 | 5.5 | 17.7 | SourceCodester | Simple Online Food Ordering System | CWE-74 | SourceCodester Simple Online Food Ordering System ajax.php add_to_cart sql in… |
| CVE-2026-78199 | 5.5 | 17.7 | SourceCodester | Simple Online Food Ordering System | CWE-74 | SourceCodester Simple Online Food Ordering System view_prod.php sql injection |
| CVE-2026-78201 | 5.5 | 17.7 | itsourcecode | Payroll System | CWE-74 | itsourcecode Payroll System admin_class.php login sql injection |
| CVE-2026-77993 | 5.3 | 17.1 | joomlack.fr | Page Builder CK extension for Joomla | CWE-79 | Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 |
| CVE-2026-78200 | 2.1 | 16.2 | itsourcecode | Library Management System | CWE-74 | itsourcecode Library Management System editbooks.php sql injection |
| CVE-2026-78185 | 2.1 | 16.1 | itsourcecode | Sales and Inventory System | CWE-74 | itsourcecode Sales and Inventory System cust_edit.php sql injection |
| CVE-2026-78255 | 8.7 | 14.8 | DJI | Neo | CWE-306 | DJI Drone HTTP Media Server Allows Unauthenticated Access to Stored Media |
| CVE-2026-19852 | 5.1 | 14.1 | CyberTutor | NewSiteServer (NSS) | CWE-434 | CyberTutor|NewSiteServer (NSS) - Arbitrary File Upload |
| CVE-2026-77994 | 9.3 | 13.3 | joomlack.fr | Page Builder CK extension for Joomla | CWE-89 | Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder C… |
| CVE-2026-19200 | 8.9 | 13.3 | Rapid7 | Velociraptor | CWE-94 | Velociraptor Analyst overwrites live built-in artifacts through verify() |
| CVE-2026-78157 | 2.1 | 13.4 | n/a | Open5GS | CWE-119 | Open5GS Rx AA-Request pcrf-rx-path.c pcrf_rx_aar_cb out-of-bounds |
| CVE-2026-78204 | 5.3 | 12.7 | GhostManager | Ghostwriter | CWE-862 | Ghostwriter through 7.2.6 Missing Authorization on Report Template Lint Endpo… |
| CVE-2026-78158 | 2.1 | 11.0 | n/a | Open5GS | CWE-266 | Open5GS AMF UEContextReleaseRequest Path improper authorization |
| CVE-2026-8173 | 5.3 | 10.6 | Murrelektronik | Xelity 4TX M GE | CWE-209 | Information Disclosure via 'Copy learned MAC Addresses' Function |
| CVE-2026-78321 | 6.0 | 5.8 | DJI | Neo | CWE-770 | DJI Drone HTTP Media Server Denial of Service via Connection Pool Exhaustion |
| CVE-2026-78306 | 8.5 | 4.3 | DJI | Neo | CWE-306 | DJI Drone Bluetooth Interface Unauthenticated DUML Command Execution |
| CVE-2026-78196 | 4.8 | 3.3 | achorein | expo-share-intent | CWE-22 | achorein expo-share-intent Android File Copy Routine ExpoShareIntentModule.kt… |
| CVE-2025-36939 | 10.0 | — | Nest | CWE-121 | Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An au… | |
| CVE-2026-77995 | 10.0 | — | miniorange.com | miniOrange OAuth Client extension for Joomla | CWE-639 | Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange … |
| CVE-2026-32559 | 9.9 | — | tophive | UltimateAI | CWE-434 | WordPress UltimateAI plugin <= 3.1.0 - Arbitrary File Upload vulnerability |
| CVE-2026-28165 | 9.8 | — | UnitedOver, LLC | Digits | CWE-266 | WordPress Digits plugin <= 9.2 - Privilege Escalation vulnerability |
| CVE-2026-32558 | 9.8 | — | RedefiningTheWeb | Affiliate Pro - Affiliate Program for WooCommerce & WordPress | CWE-266 | WordPress Affiliate Pro - Affiliate Program for WooCommerce & WordPress plugi… |
| CVE-2026-32563 | 9.8 | — | A CPT | ACPT (Pro) - Custom Post Types Plugin for WordPress | CWE-502 | WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.6… |
| CVE-2026-66587 | 9.8 | — | WPCafe | WP Cafe Pro | CWE-98 | WordPress WP Cafe Pro plugin < 3.0.15 - Local File Inclusion vulnerability |
| CVE-2026-66648 | 9.8 | — | MVPThemes | Jawn | CWE-266 | WordPress Jawn theme <= 1.4.2 - Privilege Escalation vulnerability |
| CVE-2026-66650 | 9.8 | — | Theme-Rex | FreightCo | CWE-502 | WordPress FreightCo theme <= 1.1.15 - PHP Object Injection vulnerability |
| CVE-2026-78262 | 9.8 | — | weDevs | WP Project Manager | CWE-502 | WordPress WP Project Manager plugin <= 4.0.6 - PHP Object Injection vulnerabi… |
| CVE-2026-78265 | 9.8 | — | Nexcess | The Events Calendar | CWE-502 | WordPress The Events Calendar plugin <= 6.17.2 - PHP Object Injection vulnera… |
| CVE-2026-78267 | 9.8 | — | Cozmoslabs | TranslatePress | CWE-266 | WordPress TranslatePress plugin <= 3.3.2 - Privilege Escalation vulnerability |
| CVE-2026-39975 | 9.4 | — | Combodo | iTop | CWE-94 | Combodo iTop: Remote code execution using external auth variable value |
| CVE-2026-78387 | 9.4 | — | ransomlook | ransomlook | CWE-862 | RansomLook Missing Authorization in Web Configuration Editor Allows Applicati… |
| CVE-2026-78555 | 9.4 | — | ransomlook | ransomlook | CWE-200 | RansomLook API Key Disclosure Through /admin/apikeys HTML Source |
| CVE-2026-32551 | 9.3 | — | DiviNext | Woo Essential | CWE-89 | WordPress Woo Essential plugin <= 4.3.0 - SQL Injection vulnerability |
| CVE-2026-32554 | 9.3 | — | WBW | WooBeWoo Product Filter Pro | CWE-89 | WordPress WooBeWoo Product Filter Pro plugin <= 3.1.8 - SQL Injection vulnera… |
| CVE-2026-32555 | 9.3 | — | PixelYourSite Professional | Boost | CWE-89 | WordPress Boost plugin <= 2.0.4 - SQL Injection vulnerability |
| CVE-2026-67602 | 9.3 | — | phpipam | phpipam | CWE-706 | phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache |
| CVE-2026-71914 | 9.3 | — | DrayTek Corporation | VigorAP 918R | CWE-78 | DrayTek VigorAP Multiple Models Pre-Authentication OS Command Injection via d… |
| CVE-2026-71921 | 9.3 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-78 | DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection v… |
| CVE-2026-76070 | 9.3 | — | Netis Systems | NC63 | CWE-121 | Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password Parameter |
| CVE-2026-76071 | 9.3 | — | Netis Systems | NC63 | CWE-121 | Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter |
| CVE-2026-76835 | 9.3 | — | oauth2-proxy | oauth2-proxy | CWE-290 | OAuth2 Proxy 7.15.2 through 7.15.4 Authentication Bypass via X-Forwarded-Uri … |
| CVE-2026-77915 | 9.3 | — | rconfig | rconfig | CWE-306 | rConfig 8.0.0 < 8.2.10 Unauthorized Admin Registration via web.php |
| CVE-2026-78365 | 9.3 | — | Roskus | Prospero Flow CRM | CWE-639 | IDOR and missing authorization in Prospero Flow CRM supplier API allows cross… |
| CVE-2026-77635 | 9.2 | — | cakephp | cakephp | CWE-89 | CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with Postgr… |
| CVE-2026-78370 | 9.2 | — | ransomlook | ransomlook | CWE-862 | RansomLook Unauthenticated Database Export Exposes Private Data |
| CVE-2026-78372 | 9.2 | — | ransomlook | ransomlook | CWE-862 | RansomLook Missing Authorization Allows Disclosure of Private Group and Ranso… |
| CVE-2026-19874 | 9.1 | — | Konami | Metal Gear Online 3 | CWE-122 | Konami's Metal Gear Online 3 contains a heap-based buffer overflow |
| CVE-2026-59564 | 9.1 | — | Zscaler | Client Connector | CWE-304 | Authentication bypass between ZCC and client connector portal |
| CVE-2026-59568 | 9.1 | — | Zscaler | Client Connector | CWE-20 | Remote Code Execution |
| CVE-2026-77337 | 9.1 | — | cakephp | authentication | CWE-290 | CakePHP: Potential Authentication bypass with CookieAuthenticator |
| CVE-2026-30864 | 8.9 | — | Combodo | iTop | CWE-79 | Combodo iTop: Reflected XSS in dashboard revert |
| CVE-2025-36940 | 8.8 | — | Android | CWE-416 | Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which … | |
| CVE-2026-13212 | 8.8 | — | zephyrproject | zephyr | CWE-129 | Zephyr virtio driver calls an arbitrary function pointer from an out-of-range… |
| CVE-2026-32560 | 8.8 | — | LiquidThemes | MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator | CWE-98 | WordPress MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Gener… |
| CVE-2026-32561 | 8.8 | — | LiquidThemes | Booking Hub | CWE-266 | WordPress Booking Hub plugin <= 1.3.0 - Privilege Escalation vulnerability |
| CVE-2026-59565 | 8.8 | — | Zscaler | Client Connector | CWE-229 | Local and kernel denial-of-service |
| CVE-2026-59567 | 8.8 | — | Zscaler | Client Connector | CWE-280 | Local privilege escalation |
| CVE-2026-71933 | 8.8 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-862 | DrayTek VigorSwitch Multiple Models Missing Authorization in Syslog Functions |
| CVE-2026-76842 | 8.8 | — | mercadopago | mercadopago | CWE-22 | Mercado Pago Node.js SDK through 3.4.0 Path Injection via Unencoded Identifie… |
| CVE-2026-78369 | 8.8 | — | ransomlook | ransomlook | CWE-306 | Missing Authentication Allows Unauthorized Creation of Crypto Groups in Ranso… |
| CVE-2026-78376 | 8.8 | — | Red Hat | Red Hat Enterprise Linux 6 | CWE-416 | Webkitgtk: use-after-free of jscvalue function parameters |
| CVE-2026-78391 | 8.8 | — | ransomlook | ransomlook | CWE-79 | Stored Cross-Site Scripting via Untrusted Cryptocurrency Address Rendering in… |
| CVE-2026-78551 | 8.8 | — | ransomlook | ransomlook | CWE-307 | RansomLook Login Endpoint Allows Timing-Based Username Enumeration and Unthro… |
| CVE-2026-9254 | 8.7 | — | TP-Link Systems Inc. | Archer BE800 V1 | CWE-78 | Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer … |
| CVE-2026-40877 | 8.7 | — | Combodo | iTop | CWE-94 | Combodo iTop: PHP Object Injection Leading to Remote Code Execution on user p… |
| CVE-2026-71922 | 8.7 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-476 | DrayTek VigorSwitch Multiple Models Pre-Authentication NULL Pointer Dereferen… |
| CVE-2026-76073 | 8.7 | — | HumanSignal | label-studio | CWE-639 | Label Studio through 1.23.0 Cross-Organization Annotation Access via Unscoped… |
| CVE-2026-76836 | 8.7 | — | AzuraCast | AzuraCast | CWE-94 | AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Seri… |
| CVE-2026-76841 | 8.7 | — | xorbitsai | inference | CWE-94 | Xinference through 2.11.0 Remote Code Execution via Hardcoded trust_remote_co… |
| CVE-2026-76847 | 8.7 | — | nektos | act | CWE-321 | act 0.2.81 through 0.2.89 Missing Authorization in the Artifacts V4 Backend |
| CVE-2026-76848 | 8.7 | — | typeorm | typeorm | CWE-89 | TypeORM 0.2.21 through 1.1.0 SQL Injection via SelectQueryBuilder.distinctOn |
| CVE-2026-78380 | 8.7 | — | ransomlook | ransomlook | CWE-862 | Private Group and Market Posts Disclosed Through Public Notification Channels… |
| CVE-2026-78386 | 8.7 | — | ransomlook | ransomlook | CWE-200 | Unauthenticated Disclosure of Scraping Credentials and Bypass Configuration v… |
| CVE-2026-78416 | 8.7 | — | craftcms | cms | CWE-915 | Authenticated RCE via `condition.config` JSON cleanse bypass |
| CVE-2026-28171 | 8.6 | — | vanquish | WooCommerce File Approval | CWE-22 | WordPress WooCommerce File Approval plugin <= 10.7 - Arbitrary File Deletion … |
| CVE-2026-32477 | 8.6 | — | RadiusTheme, LLC | ShopBuilder Pro – Elementor WooCommerce Builder Addons | CWE-22 | WordPress ShopBuilder Pro – Elementor WooCommerce Builder Addons plugin <= 2.… |
| CVE-2026-71504 | 8.6 | — | Dolibarr | dolibarr | CWE-862 | Dolibarr < 24.0.0 Members REST API Improper Authorization via Password Reset |
| CVE-2026-71904 | 8.6 | — | DrayTek Corporation | VigorAP 918R | CWE-78 | DrayTek VigorAP Multiple Models OS Command Injection via tr069TestInform |
| CVE-2026-71905 | 8.6 | — | DrayTek Corporation | VigorAP 918R | CWE-78 | DrayTek VigorAP Multiple Models OS Command Injection via ExportSettings |
| CVE-2026-71906 | 8.6 | — | DrayTek Corporation | VigorAP 918R | CWE-78 | DrayTek VigorAP Multiple Models OS Command Injection via setLan |
| CVE-2026-71907 | 8.6 | — | DrayTek Corporation | VigorAP 918R | CWE-78 | DrayTek VigorAP Multiple Models OS Command Injection via setcamset |
| CVE-2026-71908 | 8.6 | — | DrayTek Corporation | VigorAP 918R | CWE-78 | DrayTek VigorAP Multiple Models OS Command Injection via mesh_start_speed_test |
| CVE-2026-71909 | 8.6 | — | DrayTek Corporation | VigorAP 918R | CWE-78 | DrayTek VigorAP Multiple Models OS Command Injection via InquierTime |
| CVE-2026-71910 | 8.6 | — | DrayTek Corporation | VigorAP 918R | CWE-78 | DrayTek VigorAP Multiple Models OS Command Injection via apautotest |
| CVE-2026-71911 | 8.6 | — | DrayTek Corporation | VigorAP 918R | CWE-120 | DrayTek VigorAP Multiple Models Buffer Overflow via setLan |
| CVE-2026-71912 | 8.6 | — | DrayTek Corporation | VigorAP 918R | CWE-120 | DrayTek VigorAP Multiple Models Buffer Overflow via apautotest |
| CVE-2026-71913 | 8.6 | — | DrayTek Corporation | VigorAP 918R | CWE-78 | DrayTek VigorAP Multiple Models OS Command Injection via upload_settings.cgi |
| CVE-2026-71915 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-78 | DrayTek VigorSwitch Multiple Models OS Command Injection via jsonstatus |
| CVE-2026-71916 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-78 | DrayTek VigorSwitch Multiple Models OS Command Injection via commandTable |
| CVE-2026-71917 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-78 | DrayTek VigorSwitch Multiple Models OS Command Injection via pingtrace |
| CVE-2026-71918 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-78 | DrayTek VigorSwitch Multiple Models OS Command Injection via webBackupAction |
| CVE-2026-71919 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-78 | DrayTek VigorSwitch Multiple Models OS Command Injection via sysreboot |
| CVE-2026-71923 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-78 | DrayTek VigorSwitch Multiple Models OS Command Injection via auth_set |
| CVE-2026-71924 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-78 | DrayTek VigorSwitch Multiple Models OS Command Injection via getVid |
| CVE-2026-71925 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-78 | DrayTek VigorSwitch Multiple Models OS Command Injection via getDetail |
| CVE-2026-71926 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-78 | DrayTek VigorSwitch Multiple Models OS Command Injection via setDevice |
| CVE-2026-71927 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-78 | DrayTek VigorSwitch Multiple Models OS Command Injection via rebDevice |
| CVE-2026-71928 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-78 | DrayTek VigorSwitch Multiple Models OS Command Injection via fdftDevice |
| CVE-2026-71929 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-78 | DrayTek VigorSwitch Multiple Models OS Command Injection via setDevProto |
| CVE-2026-71930 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-78 | DrayTek VigorSwitch Multiple Models OS Command Injection via setTime |
| CVE-2026-71931 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-78 | DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgrade |
| CVE-2026-71934 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-120 | DrayTek VigorSwitch Multiple Models Buffer Overflow via pingtrace |
| CVE-2026-71935 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-120 | DrayTek VigorSwitch Multiple Models Buffer Overflow via webBackupAction |
| CVE-2026-71936 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-120 | DrayTek VigorSwitch Multiple Models Buffer Overflow via sysreboot |
| CVE-2026-71937 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-120 | DrayTek VigorSwitch Multiple Models Buffer Overflow via poe_schedule_profile |
| CVE-2026-71938 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-120 | DrayTek VigorSwitch Multiple Models Buffer Overflow via switch_lan_gvrp |
| CVE-2026-71939 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-120 | DrayTek VigorSwitch Multiple Models Buffer Overflow via acl_general_setup Add… |
| CVE-2026-71940 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-120 | DrayTek VigorSwitch Multiple Models Buffer Overflow via acl_general_setup Edi… |
| CVE-2026-71941 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-120 | DrayTek VigorSwitch Multiple Models Buffer Overflow via diag_logmail |
| CVE-2026-71942 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-120 | DrayTek VigorSwitch Multiple Models Buffer Overflow via mail_mailalert |
| CVE-2026-71943 | 8.6 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-78 | DrayTek VigorSwitch Multiple Models OS Command Injection via setDevNet |
| CVE-2026-78284 | 8.6 | — | Stylemix | MasterStudy LMS | CWE-22 | WordPress MasterStudy LMS plugin <= 3.7.42 - Arbitrary File Deletion vulnerab… |
| CVE-2025-63080 | 8.5 | — | KAON | PG5298A | CWE-863 | Authenticated RCE in KAON PG5298 |
| CVE-2026-12554 | 8.5 | — | HP Inc | HP Easy Start for macOS | CWE-1104 | HP Easy Start for macOS - Security Update |
| CVE-2026-16348 | 8.5 | — | TP-Link Systems Inc. | Archer BE800 v1 | CWE-78 | Command Injection Vulnerability in VPN connection of Archer BE800 |
| CVE-2026-32471 | 8.5 | — | ThemeBing | ProLancer Element | CWE-89 | WordPress ProLancer Element plugin <= 1.4.8 - SQL Injection vulnerability |
| CVE-2026-32478 | 8.5 | — | weDevs Pte. Ltd | WP Project Manager Pro | CWE-89 | WordPress WP Project Manager Pro plugin <= 4.0.1 - SQL Injection vulnerability |
| CVE-2026-39915 | 8.5 | — | TIM Solutions | TIM Flow | CWE-113 | TIM Flow < 26.0.6 CRLF Injection via rt Parameter |
| CVE-2026-76840 | 8.5 | — | rustdesk | rustdesk | CWE-20 | RustDesk through 1.4.9 Heap Buffer Overflow via Unvalidated CLIPRDR FileConte… |
| CVE-2026-78541 | 8.5 | — | TP-Link Systems Inc. | Archer BE3600 v1 | CWE-78 | Command Injection in Parent Control of TP-Link Archer BE3600 v1 |
| CVE-2026-59566 | 8.4 | — | Zscaler | Client Connector | CWE-229 | Local denial-of-service |
| CVE-2026-76838 | 8.4 | — | HiEventsDev | Hi.Events | CWE-918 | Hi.Events before 1.11.1-beta Server-Side Request Forgery via Unvalidated Webh… |
| CVE-2026-76843 | 8.4 | — | flairNLP | flair | CWE-502 | Flair 0.15.0 and 0.15.1 Deserialization of Untrusted Data via ClusteringModel… |
| CVE-2026-10582 | 8.3 | — | gohugoio | hugo | CWE-918 | Hugo 0.91.0 through 0.165.0 Server-Side Request Forgery via security.http.url… |
| CVE-2026-75542 | 8.3 | — | hexpm | hexpm | CWE-863 | OAuth token exchange grants repository scopes for organizations the principal… |
| CVE-2026-76072 | 8.3 | — | continuedev | continue | CWE-184 | Continue CLI through 1.5.47 Incomplete Destructive Command Denylist in Headle… |
| CVE-2026-76844 | 8.3 | — | webpack | webpack-dev-middleware | CWE-22 | webpack-dev-middleware Path Traversal via Offset Slice on a Non-Slash-Termina… |
| CVE-2026-77634 | 8.2 | — | cakephp | cakephp | CWE-93 | CakePHP: SmtpTransport vulnerable to CRLF header injection |
| CVE-2026-78381 | 8.2 | — | ransomlook | ransomlook | CWE-22 | RansomLook Arbitrary File Read via Path Traversal in Post screen Field |
| CVE-2026-78385 | 8.2 | — | ransomlook | ransomlook | CWE-918 | RansomLook Analysis PDF Generation Allows Server-Side Request Forgery and Arb… |
| CVE-2026-28151 | 8.1 | — | Select-Themes | Tonda | CWE-98 | WordPress Tonda theme < 2.6 - Local File Inclusion vulnerability |
| CVE-2026-28152 | 8.1 | — | Select-Themes | Tonda Core | CWE-98 | WordPress Tonda Core plugin < 2.6 - Local File Inclusion vulnerability |
| CVE-2026-66670 | 8.1 | — | Elated-Themes | Måne | CWE-98 | WordPress Måne theme <= 1.7 - Local File Inclusion vulnerability |
| CVE-2026-66671 | 8.1 | — | Elated-Themes | Verdure Core | CWE-98 | WordPress Verdure Core plugin <= 1.2 - Local File Inclusion vulnerability |
| CVE-2026-77567 | 8.1 | — | filamentphp | filament | CWE-287 | Filament: App-based MFA can be bypassed when recovery codes are enabled |
| CVE-2026-78414 | 8.0 | — | Network Optix | Nx Witness VMS | CWE-79 | Cross-site scripting in Nx Witness VMS Web Administration allows session toke… |
| CVE-2026-7455 | 7.8 | — | Autodesk | 3ds Max | CWE-787 | FLT File Parsing Out-of-Bounds Write Vulnerability in Autodesk 3ds Max |
| CVE-2026-16783 | 7.8 | — | Autodesk | 3ds Max | CWE-787 | ABC File Parsing Out-of-Bounds Write Vulnerability in Autodesk 3ds Max |
| CVE-2026-19568 | 7.8 | — | Autodesk | 3ds Max | CWE-120 | SVG File Parsing Memory Corruption Vulnerability in Autodesk 3ds Max |
| CVE-2026-61419 | 7.8 | — | Dell | ThinOS 10 | CWE-284 | Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Co… |
| CVE-2026-12555 | 7.7 | — | HP Inc | HP Easy Start for macOS | CWE-379 | HP Easy Start for macOS - Security Update |
| CVE-2026-12556 | 7.7 | — | HP Inc | HP Easy Start for macOS | CWE-319 | HP Easy Start for macOS - Security Update |
| CVE-2026-15469 | 7.7 | — | TP-Link Systems Inc. | Deco XE75 v3 / XE5300 v3.6/ WE10800 v3.6 | CWE-321 | Hard-coded Mesh Group Private Key in TP-Link Deco XE75, XE5300, and WE10800 |
| CVE-2026-71366 | 7.7 | — | Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | CWE-918 | Awx: notification backends allow ssrf and credential leakage |
| CVE-2026-78270 | 7.6 | — | WP ManageNinja LLC | FluentCRM Pro | CWE-89 | WordPress FluentCRM Pro plugin <= 3.1.12 - SQL Injection vulnerability |
| CVE-2025-68825 | 7.5 | — | HCLSoftware | HCL Hive | CWE-276 | HCL Hive is affected by incorrect default permissions |
| CVE-2026-21752 | 7.5 | — | HCLSoftware | HCL Hive | CWE-1104 | HCL Hive is affected by a use of vulnerable third-party components |
| CVE-2026-28153 | 7.5 | — | Notification Master | Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More | CWE-862 | WordPress Notification Master – Real-Time WordPress Notifications With Email,… |
| CVE-2026-28167 | 7.5 | — | Super Forms | Super Forms | CWE-22 | WordPress Super Forms plugin <= 6.3.315 - Arbitrary File Download vulnerability |
| CVE-2026-66585 | 7.5 | — | WPCafe | WP Cafe Pro | CWE-201 | WordPress WP Cafe Pro plugin < 3.0.15 - Sensitive Data Exposure vulnerability |
| CVE-2026-76055 | 7.5 | — | Black Duck | blackduck-c-cpp | CWE-78 | Improper Neutralization of Special Elements used in an OS Command in the pack… |
| CVE-2026-76098 | 7.5 | — | lepture | mistune | CWE-674 | Mistune has Denial of Service — RecursionError via Excessive Emphasis Markers… |
| CVE-2026-76172 | 7.5 | — | fast-uri | fast-uri | CWE-177 | fast-uri vulnerable to host confusion via percent-encoded scheme normalization |
| CVE-2026-77384 | 7.5 | — | libp2p | js-libp2p | CWE-400 | libp2p: Circuit relay v2 server reservation refresh leaks abort listeners and… |
| CVE-2026-78268 | 7.5 | — | Extend Themes | Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads | CWE-497 | WordPress Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Cal… |
| CVE-2026-21751 | 7.4 | — | HCLSoftware | HCL Hive | CWE-1240 | HCL Hive is affected by use of a cryptographic primitive with a risky impleme… |
| CVE-2026-18349 | 7.3 | — | Microchip | SAMA5D4 | CWE-1247 | SAMA5D44 Fault Injection Vulnerability |
| CVE-2026-78259 | 7.3 | — | WP Legal Pages | WPLegalPages | CWE-288 | WordPress WPLegalPages plugin <= 3.7.0 - Broken Authentication vulnerability |
| CVE-2026-21756 | 7.2 | — | HCLSoftware | HCL Hive | CWE-266 | HCL Hive is affected by a broken access control vulnerability |
| CVE-2026-71364 | 7.2 | — | Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | CWE-22 | Awx: project archive extraction allows path traversal file writes |
| CVE-2026-71506 | 7.2 | — | Dolibarr | dolibarr | CWE-863 | Dolibarr < 24.0.0 Payments REST API Improper Authorization via Delete Endpoint |
| CVE-2026-6017 | 7.1 | — | KAON | PG5298A | CWE-306 | Missing Authentication for Critical Function in KAON PG5298 |
| CVE-2026-19685 | 7.1 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-863 | Networkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass priv… |
| CVE-2026-28162 | 7.1 | — | Franky | Events Made Easy | CWE-79 | WordPress Events Made Easy plugin <= 3.2.5 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-28166 | 7.1 | — | GoodLayers | Tourmaster | CWE-79 | WordPress Tourmaster plugin <= 5.4.9 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-28190 | 7.1 | — | ThemeBing | ProLancer Element | CWE-862 | WordPress ProLancer Element plugin <= 1.4.8 - Broken Access Control vulnerabi… |
| CVE-2026-32476 | 7.1 | — | AmpleByte Pvt Limited | Brave Conversion Engine (PRO) | CWE-79 | WordPress Brave Conversion Engine (PRO) plugin <= 0.8.6 - Cross Site Scriptin… |
| CVE-2026-32556 | 7.1 | — | PixelYourSite Professional | Boost | CWE-79 | WordPress Boost plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-39914 | 7.1 | — | TIM Solutions | TIM Flow | CWE-862 | TIM Flow < 26.0.6 Unauthorized SQL Query Execution via Dashboard Export Endpoint |
| CVE-2026-53532 | 7.1 | — | AcademySoftwareFoundation | openexr | CWE-617 | OpenEXR: Unhandled assert abort in HTJ2K decoder via crafted QCD marker (DoS) |
| CVE-2026-66584 | 7.1 | — | Code for Recovery | 12 Step Meeting List | CWE-79 | WordPress 12 Step Meeting List plugin <= 3.19.16 - Cross Site Scripting (XSS)… |
| CVE-2026-66599 | 7.1 | — | Liquid Web / StellarWP | WPComplete | CWE-79 | WordPress WPComplete plugin <= 2.9.5.6 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-66610 | 7.1 | — | thembay | Urna | CWE-79 | WordPress Urna theme <= 2.6.2 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-66623 | 7.1 | — | Inisev | Social Media & Share Icons | CWE-79 | WordPress Social Media & Share Icons plugin <= 2.9.9 - Cross Site Scripting (… |
| CVE-2026-71505 | 7.1 | — | Dolibarr | dolibarr | CWE-639 | Dolibarr < 24.0.0 REST API Broken Object-Level Authorization via Third-Party … |
| CVE-2026-71507 | 7.1 | — | Dolibarr | dolibarr | CWE-639 | Dolibarr < 24.0.0 REST API Broken Object-Level Authorization via Bank Account… |
| CVE-2026-71508 | 7.1 | — | Dolibarr | dolibarr | CWE-862 | Dolibarr < 24.0.0 REST API Improper Authorization via User Update Endpoint |
| CVE-2026-71509 | 7.1 | — | Dolibarr | dolibarr | CWE-862 | Dolibarr < 24.0.0 Expense Report REST API Improper Authorization via Update E… |
| CVE-2026-71510 | 7.1 | — | Dolibarr | dolibarr | CWE-863 | Dolibarr < 24.0.0 Users REST API SQL Injection via filter parameter |
| CVE-2026-71511 | 7.1 | — | Dolibarr | dolibarr | CWE-522 | Dolibarr < 24.0.0 Members REST API Sensitive Data Exposure via Member Endpoints |
| CVE-2026-76054 | 7.1 | — | Black Duck | blackduck-c-cpp | CWE-214 | Invocation of Process Using Visible Sensitive Information in Black Duck black… |
| CVE-2026-77914 | 7.1 | — | rconfig | rconfig | CWE-22 | rConfig < 8.2.13 Core Path Traversal via Export Download Endpoint |
| CVE-2026-78263 | 7.1 | — | Nexcess | Event Tickets | CWE-79 | WordPress Event Tickets plugin <= 5.29.2.1 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-78264 | 7.1 | — | Site Building with Toolset | Toolset Blocks | CWE-79 | WordPress Toolset Blocks plugin <= 1.6.26 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-78282 | 7.1 | — | mra13 | Stripe Payments | CWE-79 | WordPress Stripe Payments plugin <= 2.1.2 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-78367 | 7.0 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-94 | Rpm: rpmbuild gettarspec() crafted tar member name → macro injection |
| CVE-2026-78465 | 7.0 | — | Red Hat | Red Hat Enterprise Linux 6 | CWE-190 | Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit |
| CVE-2026-78553 | 7.0 | — | ransomlook | ransomlook | CWE-276 | Insecure Flask Secret-Key File Permissions Allow Local Administrator Session … |
| CVE-2026-71920 | 6.9 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-476 | DrayTek VigorSwitch Multiple Models NULL Pointer Dereference via formlogout |
| CVE-2026-71932 | 6.9 | — | DrayTek Corporation | VigorSwitch G2540xs | CWE-22 | DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFile |
| CVE-2026-78378 | 6.9 | — | ransomlook | ransomlook | CWE-200 | Redis Glob Pattern Injection Allows Unauthorized Enumeration of Private Ranso… |
| CVE-2020-37268 | 6.8 | — | rocq-prover | rocq | CWE-778 | Coq and Rocq Prover Print Assumptions Omits Unsafe Universe Checking Inlined … |
| CVE-2026-5006 | 6.8 | — | HashiCorp | Vault | CWE-639 | Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Pol… |
| CVE-2026-17033 | 6.8 | — | Grafana | Grafana OSS | CWE-79 | CVE-2026-17033 CVE Record |
| CVE-2026-72703 | 6.8 | — | rocq-prover | rocq | CWE-670 | Rocq Prover 8.20 before 9.2.0 Guard Checker Accepts Non-Terminating Fixpoint … |
| CVE-2026-72704 | 6.8 | — | rocq-prover | rocq | CWE-670 | Rocq Prover through 9.2.0 Guard Checker Trusts Corrupted Recursive Tree After… |
| CVE-2026-72705 | 6.8 | — | rocq-prover | rocq | CWE-670 | Rocq Prover before 9.2.0 Guard Checker Accepts Fixpoint Passed as a Higher-Or… |
| CVE-2026-72711 | 6.8 | — | leanprover | lean4 | CWE-20 | Lean 4 before 4.32.2 Kernel Accepts Opaque Declaration With an Unbound Free V… |
| CVE-2026-72714 | 6.8 | — | rocq-prover | rocq | CWE-459 | Rocq Prover through 9.2.0 Universe Checking State Desynchronised After Module… |
| CVE-2026-76845 | 6.8 | — | cthackers | adm-zip | CWE-59 | adm-zip 0.5.9 through 0.6.0 Arbitrary File Overwrite via Symlink Following on… |
| CVE-2026-63693 | 6.6 | — | Dell | Alienware Area 51m R2 | CWE-379 | Dell Client BIOS contains an Improper Link Resolution Before File Access ('Li… |
| CVE-2026-27364 | 6.5 | — | AnalogWP | Style Kits | CWE-862 | WordPress Style Kits plugin <= 2.6.5 - Broken Access Control vulnerability |
| CVE-2026-68516 | 6.5 | — | AcademySoftwareFoundation | openexr | CWE-121 | OpenEXR: HTJ2K SIZ image-offset gap stack buffer overflow |
| CVE-2026-75509 | 6.5 | — | authlib | joserfc | CWE-290 | joserfc claim-validation bypass via array-typed single-string claims (iss/sub… |
| CVE-2026-78266 | 6.5 | — | Ruben Garcia | AutomatorWP | CWE-862 | WordPress AutomatorWP plugin <= 5.8.3 - Broken Access Control vulnerability |
| CVE-2026-78290 | 6.5 | — | ThemeGrill | Magazine Blocks | CWE-79 | WordPress Magazine Blocks plugin <= 1.8.6 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-78323 | 6.5 | — | Red Hat | Red Hat Certificate System 10 | CWE-295 | Jss: jss: jsstrustmanager does not verify nss trust flags on ca certificates |
| CVE-2026-9728 | 6.4 | — | zephyrproject | zephyr | CWE-367 | TOCTOU race in mbox_send syscall verifier allows userspace to leak kernel memory |
| CVE-2026-78269 | 6.4 | — | Tammersoft | Shared Files | CWE-918 | WordPress Shared Files plugin <= 1.7.69 - Server Side Request Forgery (SSRF) … |
| CVE-2026-34491 | 6.1 | — | Johnson Controls | Metasys 14 | — | Improper neutralization of input during web page generation ('cross-site scri… |
| CVE-2026-78475 | 6.1 | — | Red Hat | Red Hat Enterprise Linux 6 | CWE-125 | Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loader |
| CVE-2026-17113 | 6.0 | — | Red Hat | Red Hat OpenShift Container Platform 4 | CWE-1287 | Cri-o: cri-o: unvalidated image env var causes daemon crash |
| CVE-2026-45404 | 5.9 | — | open-telemetry | opentelemetry-go | CWE-362 | OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access |
| CVE-2026-59295 | 5.9 | — | VMware (Broadcom) | io.micrometer:micrometer-core | CWE-401 | Micrometer Instrumentation of Apache HttpAsyncClient Denial of Service Vulner… |
| CVE-2026-16781 | 5.5 | — | Autodesk | 3ds Max | CWE-674 | SVG File Parsing Stack Exhaustion Vulnerability in Autodesk 3ds Max |
| CVE-2026-78244 | 5.5 | — | itsourcecode | Real Estate Management System | CWE-74 | itsourcecode Real Estate Management System search.php sql injection |
| CVE-2026-78245 | 5.5 | — | itsourcecode | Online Pharmacy System | CWE-284 | itsourcecode Online Pharmacy System User Registration register.php move_uploa… |
| CVE-2026-78246 | 5.5 | — | itsourcecode | Online Clinic Management System | CWE-74 | itsourcecode Online Clinic Management System Admin Login login.php sql injection |
| CVE-2026-78247 | 5.5 | — | SourceCodester | Simple Online Food Ordering System | CWE-74 | SourceCodester Simple Online Food Ordering System ajax.php confirm_order sql … |
| CVE-2026-78248 | 5.5 | — | SourceCodester | Simple Online Food Ordering System | CWE-74 | SourceCodester Simple Online Food Ordering System ajax.php save_settings sql … |
| CVE-2026-78434 | 5.5 | — | Faveo | Helpdesk | CWE-287 | Faveo Helpdesk post-ticket-reply Endpoint FormController.php post_ticket_repl… |
| CVE-2026-78272 | 5.4 | — | WP ManageNinja LLC | Fluent Support Pro | CWE-862 | WordPress Fluent Support Pro plugin <= 2.3.1 - Broken Access Control vulnerab… |
| CVE-2026-78279 | 5.4 | — | WP ManageNinja LLC | Fluent Support Pro | CWE-352 | WordPress Fluent Support Pro plugin <= 2.3.1 - Cross Site Request Forgery (CS… |
| CVE-2025-68833 | 5.3 | — | HCLSoftware | HCL Hive | CWE-1240 | HCL Hive is affected by use of a cryptographic primitive with a risky impleme… |
| CVE-2026-13213 | 5.3 | — | zephyrproject | zephyr | CWE-476 | Bluetooth HAS: NULL-pointer dereference DoS when a bonded peer reconnects bef… |
| CVE-2026-13343 | 5.3 | — | zephyrproject | zephyr | CWE-200 | Uninitialised stack memory disclosure in the MIDI 2.0 UMP Stream responder |
| CVE-2026-16782 | 5.3 | — | Autodesk | 3ds Max | CWE-125 | SVG File Parsing Out-of-Bounds Read Vulnerability in Autodesk 3ds Max |
| CVE-2026-21755 | 5.3 | — | HCLSoftware | HCL Hive | CWE-307 | HCL Hive is affected by a missing rate limit |
| CVE-2026-67204 | 5.3 | — | BookStackApp | BookStack | CWE-863 | BookStack < 26.05.4 Broken Access Control via Image Gallery API |
| CVE-2026-75099 | 5.3 | — | Apache Software Foundation | Apache Allura | CWE-200 | Apache Allura: Unauthenticated REST disclosure |
| CVE-2026-76837 | 5.3 | — | Baserow | Baserow | CWE-79 | Baserow before 2.3.0 Stored Cross-Site Scripting via Rich Text Mention Displa… |
| CVE-2026-77310 | 5.3 | — | FasterXML | com.fasterxml.jackson.core:jackson-databind | CWE-918 | jackson-databind: Eager DNS resolution (SSRF) still present in InetAddress de… |
| CVE-2026-77923 | 5.3 | — | Dolibarr | dolibarr | CWE-863 | Dolibarr 21.0.0 < 24.0.0 Authorization Bypass via clonetasks Mass Action |
| CVE-2026-78258 | 5.3 | — | Magepeople inc. | Booking and Rental Manager | CWE-862 | WordPress Booking and Rental Manager plugin <= 2.7.5 - Broken Access Control … |
| CVE-2026-78278 | 5.3 | — | WP ManageNinja LLC | Fluent Boards Pro | CWE-639 | WordPress Fluent Boards Pro plugin <= 2.0.11 - Insecure Direct Object Referen… |
| CVE-2026-78291 | 5.3 | — | Webful Creations | RepairBuddy | CWE-862 | WordPress RepairBuddy plugin <= 4.1223 - Broken Access Control vulnerability |
| CVE-2026-65053 | 5.1 | — | horde | imp | CWE-79 | Horde IMP before 7.2.0 Stored Cross-Site Scripting via AppleDouble Viewer Par… |
| CVE-2026-71503 | 5.1 | — | Dolibarr | dolibarr | CWE-79 | Dolibarr < 24.0.0 Reflected XSS via Extra Fields Administration Template |
| CVE-2026-78277 | 4.9 | — | WP ManageNinja LLC | FluentCRM Pro | CWE-918 | WordPress FluentCRM Pro plugin <= 3.1.12 - Server Side Request Forgery (SSRF)… |
| CVE-2026-10618 | 4.8 | — | gohugoio | hugo | CWE-79 | Hugo 0.93.0 through 0.165.0 Stored Cross-Site Scripting via Unescaped Code-Fe… |
| CVE-2026-78337 | 4.8 | — | Roskus | Prospero Flow CRM | CWE-434 | Unrestricted upload of file with dangerous type in Prospero Flow CRM allows s… |
| CVE-2026-21759 | 4.3 | — | HCLSoftware | HCL Hive | CWE-215 | HCL Hive is affected by an information exposure vulnerability |
| CVE-2026-55468 | 4.3 | — | wagtail | wagtail | CWE-280 | Wagtail: Improper restriction handling on Pages admin API |
| CVE-2026-78280 | 4.3 | — | HashThemes | Hash Form | CWE-352 | WordPress Hash Form plugin <= 1.4.0 - Cross Site Request Forgery (CSRF) vulne… |
| CVE-2026-76816 | 3.5 | — | netty | netty | CWE-20 | Netty: MQTT Topic Name and Client ID Validation Bypass |
| CVE-2026-75554 | 2.3 | — | hexpm | hexpm | CWE-613 | Explicit organization scopes survive token refresh after membership ends |
| CVE-2026-78250 | 2.1 | — | bytebot-ai | bytebot | CWE-404 | bytebot-ai bytebot Agent Execution Workflow infinite loop |
| CVE-2026-78435 | 2.0 | — | Faveo | Helpdesk | CWE-22 | Faveo Helpdesk Logo SettingsController.php unlink path traversal |
| CVE-2026-78430 | 1.9 | — | sworddut | mcp-ffmpeg-helper | CWE-77 | sworddut mcp-ffmpeg-helper Tool handlers.ts handleToolCall os command injection |
| CVE-2022-30983 | await | — | n/a | n/a | — | A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms… |
| CVE-2025-26237 | await | — | n/a | n/a | — | D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in … |
| CVE-2025-26238 | await | — | n/a | n/a | — | In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploite… |
| CVE-2026-30512 | await | — | n/a | n/a | — | A local privilege escalation vulnerability exists in the Restricted Access (K… |
| CVE-2026-52490 | await | — | n/a | n/a | — | An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attack… |
| CVE-2026-52492 | await | — | n/a | n/a | — | An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function w… |
| CVE-2026-56135 | await | — | n/a | n/a | — | In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the func… |
| CVE-2026-56136 | await | — | n/a | n/a | — | In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() … |
| CVE-2026-59230 | await | — | Apache Software Foundation | Apache Camel | CWE-20 | Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers o… |
| CVE-2026-60093 | await | — | Apache Software Foundation | Apache Camel | CWE-23 | Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation buil… |
| CVE-2026-63621 | await | — | Apache Software Foundation | Apache Camel | CWE-20 | Apache Camel: Camel-Knative: CloudEvent extension fields received in structur… |
| CVE-2026-66906 | await | — | Apache Software Foundation | Apache Camel | CWE-23 | Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation buil… |
| CVE-2026-66907 | await | — | Apache Software Foundation | Apache Camel | CWE-23 | Apache Camel: Camel-Google-Storage: the consumer appended the remote object n… |
| CVE-2026-66908 | await | — | Apache Software Foundation | Apache Camel | CWE-287 | Apache Camel: Camel-platform-http-main: when JWT authentication was configure… |
| CVE-2026-71300 | await | — | Apache Software Foundation | Apache Camel | CWE-20 | Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection |
| CVE-2026-71832 | await | — | n/a | n/a | — | Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/b… |
| CVE-2026-75368 | await | — | n/a | n/a | — | A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC softwar… |
| CVE-2026-75369 | await | — | n/a | n/a | — | An out-of-bounds read vulnerability in the CAN::Application::parsePerformFunc… |
| CVE-2026-75370 | await | — | n/a | n/a | — | An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHe… |
| CVE-2026-75371 | await | — | n/a | n/a | — | An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC… |
| CVE-2026-75464 | await | — | n/a | n/a | — | OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability … |
| CVE-2026-78329 | await | — | Apache Software Foundation | Apache Camel | CWE-20 | Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific he… |
| CVE-2026-78417 | await | — | Devolutions | Remote Desktop Manager | CWE-345 | Insufficient verification of data authenticity in the IronVNC client in Devol… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-08-24 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.