boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Monday, August 24, 2026 · all times UTC← 2026-08-23 · archive

Security Box Score — August 24, 2026

CISA adds 1 to KEV; 310 CVEs published, led by DrayTek Corporation (40).

310 CVEs published August 24, 2026: 39 critical, 157 high, 77 medium, 14 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 23 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 285 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published966431829——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

1767 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux14173732363178163711120.17.8.0017+889 ▲
microsoft4691891145128145114286271.47.8.0044-191 ▼
google731834225766786577760.37.5.0025-46 ▼
red hat1985844324626431200.06.8.0029+81 ▲
apple40311588216368882.66.5.0029+37 ▲
canonical15421311135000.07.8.0020+8 ▲
freebsd233902340000.07.8.0015+23 ▲
suse52651461000.08.1.0039-3 ▼
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco46842139240561315.57.5.0044+31 ▲
palo alto networks12371321121325.44.7.0020-2 ▼
ubiquiti036142110338.38.8.0049-25 ▼
netgear93200275000.04.3.0025+3 ▲
fortinet7307814128620.07.0.0050-6 ▼
vmware21949427210.58.1.0040-6 ▼
f50175930415.98.7.0057-8 ▼
ivanti314482025535.78.3.0754+1 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache14147790198158133320.47.5.0048+38 ▲
mozilla591866868500900.08.1.0031-12 ▼
gitlab1667215428423.05.3.0029+9 ▲
drupal05165355412.05.9.0026-46 ▼
github5171790000.06.6.00430
docker290630000.07.2.0016+2 ▲
wordpress2513102240.08.8.31200
kubernetes010001000.02.4.0035-1 ▼
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle88922684871172513962840.27.8.0034-220 ▼
ibm3746031332861768610.27.5.0029+337 ▲
adobe603123914512351931.07.8.0026-35 ▼
progress19611437100611.68.1.0037-9 ▼
solarwinds0231733010417.49.1.0058-15 ▼
veeam10165920100.08.6.0034+9 ▲
zohocorp4103520000.08.7.0140+1 ▲
atlassian3615001300.08.1.00340
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link163615597300.07.4.0157+8 ▲
siemens193522382000.07.3.0016+12 ▲
rockwell automation12541830000.08.7.0029-16 ▼
synology12426133000.05.6.0025+1 ▲
schneider electric091620000.08.6.00370
abb070430000.07.2.0018-1 ▼
hikvision060420000.07.2.0040-5 ▼
moxa050320000.07.0.00290
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester47167009176000.05.5.0029-2 ▼
dell581571084585210.67.2.0019+15 ▲
splunk110128647705110.86.5.0025+107 ▲
openclaw01110583914000.07.0.0026-44 ▼
nvidia241061471210000.07.5.0034-17 ▼
itsourcecode2899002574000.02.1.0028+10 ▲
siyuan-note73954220311000.08.7.0027+64 ▲
zephyrproject4295233519000.06.4.0022+20 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.995799.99.8
CVE-2026-34486.986299.97.5
CVE-2026-63077.847399.79.8
CVE-2026-72898.792299.610.0
CVE-2026-59310.458898.79.8
CVE-2026-61511.339998.39.3
CVE-2026-64638.312098.18.9
CVE-2025-68686.291598.05.9
CVE-2026-71362.251497.89.1
CVE-2026-66066.189597.19.5
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.7922KEV
CVE-2026-4836210.0.0431
CVE-2026-1918810.0.0193
CVE-2026-5823110.0.0171
CVE-2026-6983610.0.0159
CVE-2026-1681210.0.0157KEV
CVE-2026-7329910.0.0121
CVE-2026-7367810.0.0114
CVE-2026-4561810.0.0092
CVE-2026-4816810.0.0091
Most disclosures (vendor)
VendorCVEs
linux1450
oracle889
microsoft474
google450
ibm442
red hat245
apache219
apple204
splunk110
siyuan-note76
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco13
apple8
fortinet6
google6
ivanti5
oracle4
solarwinds4
adobe3
berriai3
Most-affected ecosystems
EcosystemAdvisories
Maven59
PyPI14
npm13
Go4
Packagist2
NuGet1
crates.io1
Fastest to KEV
CVEVendorDays
CVE-2025-68686Fortinet0
CVE-2026-16812Arista Networks0
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20316Cisco0
CVE-2026-20349Cisco0
CVE-2026-34486Apache Software Foundation0
CVE-2026-63077JetBrains0
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171741
CVE-2021-27102n/a2021-11-171741
CVE-2021-27101n/a2021-11-171741
CVE-2021-27103n/a2021-11-171741
CVE-2021-21017Adobe2021-11-171741
CVE-2021-28550Adobe2021-11-171741
CVE-2021-42013Apache Software Foundation2021-11-171741
CVE-2021-41773Apache Software Foundation2021-11-171741
CVE-2021-30858Apple2021-11-171741
CVE-2021-30860Apple2021-11-171741

Transactions

ADDED TO KEV — CVE-2026-21962 (Oracle Corporation Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in). Remediation due August 27, 2026.

EXPLOIT PUBLISHED — axios: 16 CVEs (CVE-2025-62718, CVE-2026-25639, CVE-2026-40175, CVE-2026-42033, CVE-2026-42039, CVE-2026-42041, CVE-2026-42043, CVE-2026-42044, CVE-2026-42264, CVE-2026-44486, CVE-2026-44487, CVE-2026-44488, CVE-2026-44492, CVE-2026-44494, CVE-2026-44495, CVE-2026-44496). Public exploit references added.

EXPLOIT PUBLISHED — Red Hat Enterprise Linux 10: 7 CVEs (CVE-2026-4878, CVE-2026-12548, CVE-2026-48864, CVE-2026-55653, CVE-2026-66337, CVE-2026-66338, CVE-2026-66339). Public exploit references added.

EXPLOIT PUBLISHED — isaacs node-tar: 3 CVEs (CVE-2026-23745, CVE-2026-23950, CVE-2026-24842). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2024-21626 (opencontainers runc). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2024-22373 (Grassroot DICOM). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2024-31823. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2024-31828. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2024-33775. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-56005. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-61258. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-10053 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-2332 (Eclipse Foundation Eclipse Jetty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-24049 (pypa wheel). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-25896 (NaturalIntelligence fast-xml-parser). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-26369 (JUNG eNet SMART HOME server). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-29063 (immutable-js). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-30922 (pyasn1). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-33487 (russellhaering goxmldsig). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-40938 (tektoncd pipeline). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-41035 (Samba rsync). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-45736 (websockets ws). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-4740 (Red Hat multicluster engine for Kubernetes 2.1). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48779 (websockets ws). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-59087 (gimp). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-59091 (gimp). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-66759 (GNOME GIMP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-6732 (Red Hat Hardened Images). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78050 (Comfast CF-N1-S). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78051 (alexta69 MeTube). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78055 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78057 (sambitraj Student-Management-System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78059 (SourceCodester Stock Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78063 (Tenda CH22). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78112 (itsourcecode Hospital Management System Project in PHP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78140 (Dromara UJCMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78142 (code-projects Barangay Resident Profiling Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78143 (code-projects Barangay Resident Profiling Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78145 (CTFd). Public exploit reference added.

DUE DATE PASSED — CVE-2026-72529 (TrueConf Server). CISA remediation deadline was August 23, 2026; still in catalog.

RESCORED — guardian language-system: 6 CVEs (CVE-2026-34100, CVE-2026-34101, CVE-2026-34102, CVE-2026-34103, CVE-2026-34104, CVE-2026-34105). CVSS rescored — before/after on each CVE page.

RESCORED — getgrav grav: 5 CVEs (CVE-2026-72822, CVE-2026-72824, CVE-2026-72826, CVE-2026-72829, CVE-2026-72830). CVSS rescored — before/after on each CVE page.

RESCORED — IBM AIX: 4 CVEs (CVE-2026-16923, CVE-2026-16925, CVE-2026-16927, CVE-2026-16989). CVSS rescored — before/after on each CVE page.

RESCORED — axios: 3 CVEs (CVE-2026-42043, CVE-2026-42044, CVE-2026-42264). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2023-50176 (Fortinet FortiOS). CVSS 4 → 8.8 (NVD).

RESCORED — CVE-2024-22373 (Grassroot DICOM). CVSS 8.1 → 9.8 (NVD).

RESCORED — CVE-2025-36255 (IBM DS8A00( R10.0 - R10.1 )). CVSS 7.5 → 8.8 (NVD).

RESCORED — CVE-2025-46252 (Kofi Mokome Message Filter for Contact Form 7). CVSS 7.6 → 7.2 (NVD).

RESCORED — CVE-2026-17015 (IBM i). CVSS 5.4 → 8.1 (NVD).

RESCORED — CVE-2026-18102 (IBM i). CVSS 3.5 → 4.3 (NVD).

RESCORED — CVE-2026-18652 (Rapid7 Velociraptor). CVSS 4.9 → 6.5 (NVD).

RESCORED — CVE-2026-22029 (remix-run react-router). CVSS 8 → 6.1 (NVD).

RESCORED — CVE-2026-23950 (isaacs node-tar). CVSS 8.8 → 5.9 (NVD).

RESCORED — CVE-2026-24049 (pypa wheel). CVSS 7.1 → 5.5 (NVD).

RESCORED — CVE-2026-33810 (Go standard library crypto/x509). CVSS 7.5 → 8.2 (NVD).

RESCORED — CVE-2026-39910 (STACKIT IaaS API). CVSS 9.3 → 8.7 (NVD).

RESCORED — CVE-2026-41035 (Samba rsync). CVSS 7.4 → 7.8 (NVD).

RESCORED — CVE-2026-45736 (websockets ws). CVSS 4.4 → 7.5 (NVD).

RESCORED — CVE-2026-4800 (lodash). CVSS 8.1 → 9.8 (NVD).

RESCORED — CVE-2026-66338 (Red Hat Enterprise Linux 10). CVSS 5.4 → 7.2 (NVD).

RESCORED — CVE-2026-6732 (Red Hat Hardened Images). CVSS 6.5 → 7.5 (NVD).

RESCORED — CVE-2026-67340 (ArcadeData arcadedb). CVSS 9.3 → 8.6 (NVD).

RESCORED — CVE-2026-70894 (Oracle Corporation Oracle Hyperion Data Relationship Management). CVSS 7.7 → 7.1 (NVD).

RESCORED — CVE-2026-71474 (Red Hat Advanced Cluster Management for Kubernetes 2). CVSS 6.3 → 6.5 (NVD).

RESCORED — CVE-2026-7163 (Red Hat multicluster engine for Kubernetes 2.1). CVSS 6.1 → 5.5 (NVD).

RESCORED — CVE-2026-71845 (Red Hat Advanced Cluster Management for Kubernetes 2). CVSS 6.3 → 7.7 (NVD).

RESCORED — CVE-2026-78156 (Open5GS). CVSS 5.3 → 2.1 (NVD).

PATCH SHIPPED — Adobe Experience Manager as a Cloud Service: 57 CVEs (CVE-2026-34692, CVE-2026-47935, CVE-2026-47936, CVE-2026-47939, CVE-2026-47941, CVE-2026-47942, CVE-2026-47943, CVE-2026-47944, CVE-2026-47945, CVE-2026-47946, CVE-2026-47947, CVE-2026-47948, CVE-2026-47949, CVE-2026-47950, CVE-2026-47951, CVE-2026-47953, CVE-2026-47954, CVE-2026-47956, CVE-2026-47957, CVE-2026-47958, CVE-2026-47962, CVE-2026-47966, CVE-2026-47970, CVE-2026-47972, CVE-2026-47973, CVE-2026-47974, CVE-2026-47975, CVE-2026-47977, CVE-2026-47978, CVE-2026-47980, CVE-2026-47981, CVE-2026-47982, CVE-2026-47983, CVE-2026-47985, CVE-2026-47986, CVE-2026-47987, CVE-2026-47989, CVE-2026-47990, CVE-2026-47991, CVE-2026-47993, CVE-2026-48250, CVE-2026-48251, CVE-2026-48256, CVE-2026-48258, CVE-2026-48264, CVE-2026-48265, CVE-2026-48266, CVE-2026-48268, CVE-2026-48271, CVE-2026-48280, and 7 more — full list in this day's data.json). Fix versions published.

PATCH SHIPPED — Adobe ColdFusion 2025: 13 CVEs (CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48282, CVE-2026-48283, CVE-2026-48285, CVE-2026-48307, CVE-2026-48313, CVE-2026-48314, CVE-2026-48315, CVE-2026-48316, CVE-2026-48363, CVE-2026-48364). Fix versions published.

PATCH SHIPPED — CVE-2026-48286 (Adobe Campaign Classic). Fixed in Adobe Campaign Classic ACC v7: 7.4.3 build 9397.

Yesterday's Results

How to read these box scores · glossary

310 CVEs published. 25 box scores, 285 table rows — nothing truncated.

4MOSAn Security Technology|4MOSAn GCB Doctor - OS Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0155   73.1     —
AFFECTED
  Product            Versions     Fixed
  4MOSAn GCB Doctor  unspecified  —
TIMELINE
  Aug 24  Reserved by CNA
  Aug 24  Published (CNA: twcert)
CWE-78 · CNA: twcert · CVSS v4.0 · 2 references · NVD status: Received
EFM ipTIME T16000M Session Validation httpcon_check_session_url improper authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0103   61.1     —
AFFECTED
  Product         Versions   Fixed
  ipTIME T16000M  14.20.2 –  —
TIMELINE
  Aug 23  Reserved by CNA
  Aug 24  Published (CNA: VulDB)
CWE-287 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
EFM ipTIME T24000M Session Validation httpcon_check_session_url improper authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0093   57.9     —
AFFECTED
  Product         Versions  Fixed
  ipTIME T24000M  14.0 –    —
TIMELINE
  Aug 23  Reserved by CNA
  Aug 24  Published (CNA: VulDB)
CWE-287 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerabilit…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   N   A   H   H   H    8.4   .0074   51.9     —
AFFECTED
  Product        Versions     Fixed
  Sakura Editor  unspecified  —
TIMELINE
  Jul 6   Reserved by CNA
  Aug 24  Published (CNA: jpcert)
CWE-78 · CNA: jpcert · CVSS v4.0 · 3 references · NVD status: Received
deltaww DIAEnergie — DIAEnergie - SQL Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0066   48.6     —
AFFECTED
  Product     Versions     Fixed
  DIAEnergie  unspecified  —
TIMELINE
  Aug 24  Reserved by CNA
  Aug 24  Published (CNA: Deltaww)
CWE-89 · CNA: Deltaww · CVSS v3.1 · 1 reference · NVD status: Received
deltaww DIAEnergie — DIAEnergie - SQL Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0066   48.6     —
AFFECTED
  Product     Versions     Fixed
  DIAEnergie  unspecified  —
TIMELINE
  Aug 24  Reserved by CNA
  Aug 24  Published (CNA: Deltaww)
CWE-89 · CNA: Deltaww · CVSS v3.1 · 1 reference · NVD status: Received
deltaww DIAEnergie — DIAEnergie - SQL Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0066   48.6     —
AFFECTED
  Product     Versions     Fixed
  DIAEnergie  unspecified  —
TIMELINE
  Aug 24  Reserved by CNA
  Aug 24  Published (CNA: Deltaww)
CWE-89 · CNA: Deltaww · CVSS v3.1 · 1 reference · NVD status: Received
deltaww DIAEnergie — DIAEnergie - SQL Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0066   48.6     —
AFFECTED
  Product     Versions     Fixed
  DIAEnergie  unspecified  —
TIMELINE
  Aug 24  Reserved by CNA
  Aug 24  Published (CNA: Deltaww)
CWE-89 · CNA: Deltaww · CVSS v3.1 · 1 reference · NVD status: Received
Canonical LXD — Instance template path traversal allows arbitrary host file write as root
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0062   46.9     —
AFFECTED
  Product  Versions  Fixed
  LXD      4.0.0 –   —
TIMELINE
  Jul 28  Reserved by CNA
  Aug 24  Published (CNA: canonical)
CWE-22, CWE-23 · CNA: canonical · CVSS v3.1 · 1 reference · NVD status: Received
TanStack devtools-vite Development Devtools Event Bus package-manager.ts installPackage os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   H   N   L   N   L   L   L    1.1   .0060   46.2     —
AFFECTED
  Product        Versions  Fixed
  devtools-vite  0.7.0 –   —
TIMELINE
  Aug 23  Reserved by CNA
  Aug 24  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
4MOSAn Security Technology|4MOSAn Management Center - Arbitrary File Read
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0050   40.6     —
AFFECTED
  Product                   Versions     Fixed
  4MOSAn Management Center  unspecified  —
TIMELINE
  Aug 24  Reserved by CNA
  Aug 24  Published (CNA: twcert)
CWE-23 · CNA: twcert · CVSS v4.0 · 2 references · NVD status: Received
exceljs through 4.4.0 Uncontrolled Resource Consumption via Unbounded xlsx Decompression
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0045   36.9     —
AFFECTED
  Product  Versions     Fixed
  exceljs  unspecified  —
TIMELINE
  Aug 24  Reserved by CNA
  Aug 24  Published (CNA: VulnCheck)
CWE-409 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Received
exceljs through 4.4.0 Prototype Pollution via deepMerge Reached From Note Serialization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   L    9.3   .0044   36.4     —
AFFECTED
  Product  Versions     Fixed
  exceljs  unspecified  —
TIMELINE
  Aug 24  Reserved by CNA
  Aug 24  Published (CNA: VulnCheck)
CWE-1321 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Received
n/a jQWidgets — jQWidgets jqx-all.js jqxBaseFramework.extend prototype pollution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    6.9   .0044   36.4     —
AFFECTED
  Product    Versions  Fixed
  jQWidgets  24.0.0 –  —
TIMELINE
  Aug 23  Reserved by CNA
  Aug 24  Published (CNA: VulDB)
CWE-94, CWE-1321 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
alibaba-fusion next deepMerge index.tsx ConfigProvider.getContextProps prototype pollution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    6.9   .0044   36.4     —
AFFECTED
  Product  Versions  Fixed
  next     1.27.0 –  —
TIMELINE
  Aug 23  Reserved by CNA
  Aug 24  Published (CNA: VulDB)
CWE-94, CWE-1321 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
ractivejs ractive Keypath Ractive#set prototype pollution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0044   36.4     —
AFFECTED
  Product  Versions  Fixed
  ractive  1.4.0 –   —
TIMELINE
  Aug 23  Reserved by CNA
  Aug 24  Published (CNA: VulDB)
CWE-94, CWE-1321 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
UTT HiPER 1250GW HTTP Request aspRemoteApConfTempSend strcpy stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0044   36.3     —
AFFECTED
  Product       Versions               Fixed
  HiPER 1250GW  3.2.7-210907-180535 –  —
TIMELINE
  Aug 23  Reserved by CNA
  Aug 24  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
UTT HiPER 1200GW formConfigFastDirectionW strcpy buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0044   36.3     —
AFFECTED
  Product       Versions        Fixed
  HiPER 1200GW  2.5.3-170306 –  —
TIMELINE
  Aug 23  Reserved by CNA
  Aug 24  Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  N    7.5   .0043   35.2     —
AFFECTED
  Product   Versions  Fixed
  fast-uri  2.4.2 –   2.4.5
TIMELINE
  Aug 18  Reserved by CNA
  Aug 24  Published (CNA: openjs)
CWE-436 · CNA: openjs · CVSS v3.1 · 2 references · NVD status: Received
n/a Piwigo — Piwigo Public Authentication cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   P   N   L   N    1.3   .0041   34.1     —
AFFECTED
  Product  Versions  Fixed
  Piwigo   16.3.0 –  16.4.0
TIMELINE
  Aug 23  Reserved by CNA
  Aug 24  Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Deferred
warmcat libwebsockets LECP CBOR Recording lecp.c report_raw_cbor out-of-bounds write
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0040   33.4     —
AFFECTED
  Product        Versions  Fixed
  libwebsockets  4.5.0 –   —
TIMELINE
  Aug 23  Reserved by CNA
  Aug 24  Published (CNA: VulDB)
CWE-119, CWE-787 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Deferred
fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  N    7.5   .0040   33.1     —
AFFECTED
  Product   Versions  Fixed
  fast-uri  2.4.1 –   2.4.5
TIMELINE
  Aug 18  Reserved by CNA
  Aug 24  Published (CNA: openjs)
CWE-174, CWE-918 · CNA: openjs · CVSS v3.1 · 2 references · NVD status: Received
fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  N    7.5   .0040   33.1     —
AFFECTED
  Product   Versions  Fixed
  fast-uri  2.3.1 –   2.4.5
TIMELINE
  Aug 18  Reserved by CNA
  Aug 24  Published (CNA: openjs)
CWE-20, CWE-918 · CNA: openjs · CVSS v3.1 · 2 references · NVD status: Received
n/a Open5GS — Open5GS HSS hss-cx-path.c assertion
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   N   L    2.1   .0039   31.8     —
AFFECTED
  Product  Versions  Fixed
  Open5GS  2.0 –     —
TIMELINE
  Aug 23  Reserved by CNA
  Aug 24  Published (CNA: VulDB)
CWE-617 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
DJI Drone FTP Service Allows Unrestricted Storage Consumption of the /blackbox Directory
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0039   31.6     —
AFFECTED
  Product          Versions     Fixed
  Neo              unspecified  —
  Neo 2            unspecified  —
  Flip             unspecified  —
  Air 3            unspecified  —
  Air 3S           unspecified  —
  Avata 2          unspecified  —
  Avata 360        unspecified  —
  Mavic 3          unspecified  —
  Mavic 3 Classic  unspecified  —
  Mavic 3 Pro      unspecified  —
  + 6 more
TIMELINE
  Aug 24  Reserved by CNA
  Aug 24  Published (CNA: CIRCL)
CWE-798 · CNA: CIRCL · CVSS v4.0 · 1 reference
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-782088.730.0exceljsexceljsCWE-73exceljs through 4.4.0 Path Traversal via Unvalidated addImage filename
CVE-2026-198536.925.9CyberTutorNewSiteServer (NSS)CWE-306CyberTutor|NewSiteServer (NSS) - Missing Authentication
CVE-2026-781795.325.3rexrainbowphaser3-rex-notesCWE-94rexrainbow phaser3-rex-notes BehaviorTree Blackboard Data SetValue.js SetValu…
CVE-2026-781715.525.2itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System processlogin.php sql injection
CVE-2026-781825.523.5Shenzhen Gongji TechnologyXBROTHER Dynamic Environment Monitoring SystemCWE-74Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System pla…
CVE-2026-782136.223.2Hepta PlatformsHeptabaseCWE-79Hepta Platforms|Heptabase - Stored Cross-Site Scripting
CVE-2026-781662.122.6provectuskafka-uiCWE-74provectus kafka-ui Groovy Code MessagesController.java executeSmartFilterTest…
CVE-2026-782056.922.1bentomlBentoMLCWE-918BentoML 1.4.19 through 1.4.39 Server-Side Request Forgery via Unfiltered RFC …
CVE-2026-782098.421.5exceljsexceljsCWE-1236exceljs through 4.4.0 CSV Formula Injection via Unescaped Cell Values
CVE-2026-781602.120.9DolibarrERPCWE-285Dolibarr ERP User Notes note.php authorization
CVE-2026-782025.520.7itsourcecodePayroll SystemCWE-284itsourcecode Payroll System admin_class.php save_settings unrestricted upload
CVE-2026-782037.118.7GhostManagerGhostwriterCWE-639Ghostwriter before 7.1.2 Cross-Client Report Template Disclosure via Unauthor…
CVE-2026-781975.518.0SourceCodesterSimple Online Food Ordering SystemCWE-74SourceCodester Simple Online Food Ordering System ajax.php save_user sql inje…
CVE-2026-781985.517.7SourceCodesterSimple Online Food Ordering SystemCWE-74SourceCodester Simple Online Food Ordering System ajax.php add_to_cart sql in…
CVE-2026-781995.517.7SourceCodesterSimple Online Food Ordering SystemCWE-74SourceCodester Simple Online Food Ordering System view_prod.php sql injection
CVE-2026-782015.517.7itsourcecodePayroll SystemCWE-74itsourcecode Payroll System admin_class.php login sql injection
CVE-2026-779935.317.1joomlack.frPage Builder CK extension for JoomlaCWE-79Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5
CVE-2026-782002.116.2itsourcecodeLibrary Management SystemCWE-74itsourcecode Library Management System editbooks.php sql injection
CVE-2026-781852.116.1itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System cust_edit.php sql injection
CVE-2026-782558.714.8DJINeoCWE-306DJI Drone HTTP Media Server Allows Unauthenticated Access to Stored Media
CVE-2026-198525.114.1CyberTutorNewSiteServer (NSS)CWE-434CyberTutor|NewSiteServer (NSS) - Arbitrary File Upload
CVE-2026-779949.313.3joomlack.frPage Builder CK extension for JoomlaCWE-89Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder C…
CVE-2026-192008.913.3Rapid7VelociraptorCWE-94Velociraptor Analyst overwrites live built-in artifacts through verify()
CVE-2026-781572.113.4n/aOpen5GSCWE-119Open5GS Rx AA-Request pcrf-rx-path.c pcrf_rx_aar_cb out-of-bounds
CVE-2026-782045.312.7GhostManagerGhostwriterCWE-862Ghostwriter through 7.2.6 Missing Authorization on Report Template Lint Endpo…
CVE-2026-781582.111.0n/aOpen5GSCWE-266Open5GS AMF UEContextReleaseRequest Path improper authorization
CVE-2026-81735.310.6MurrelektronikXelity 4TX M GECWE-209Information Disclosure via 'Copy learned MAC Addresses' Function
CVE-2026-783216.05.8DJINeoCWE-770DJI Drone HTTP Media Server Denial of Service via Connection Pool Exhaustion
CVE-2026-783068.54.3DJINeoCWE-306DJI Drone Bluetooth Interface Unauthenticated DUML Command Execution
CVE-2026-781964.83.3achoreinexpo-share-intentCWE-22achorein expo-share-intent Android File Copy Routine ExpoShareIntentModule.kt…
CVE-2025-3693910.0—GoogleNestCWE-121Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An au…
CVE-2026-7799510.0—miniorange.comminiOrange OAuth Client extension for JoomlaCWE-639Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange …
CVE-2026-325599.9—tophiveUltimateAICWE-434WordPress UltimateAI plugin <= 3.1.0 - Arbitrary File Upload vulnerability
CVE-2026-281659.8—UnitedOver, LLCDigitsCWE-266WordPress Digits plugin <= 9.2 - Privilege Escalation vulnerability
CVE-2026-325589.8—RedefiningTheWebAffiliate Pro - Affiliate Program for WooCommerce & WordPressCWE-266WordPress Affiliate Pro - Affiliate Program for WooCommerce & WordPress plugi…
CVE-2026-325639.8—A CPTACPT (Pro) - Custom Post Types Plugin for WordPressCWE-502WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.6…
CVE-2026-665879.8—WPCafeWP Cafe ProCWE-98WordPress WP Cafe Pro plugin < 3.0.15 - Local File Inclusion vulnerability
CVE-2026-666489.8—MVPThemesJawnCWE-266WordPress Jawn theme <= 1.4.2 - Privilege Escalation vulnerability
CVE-2026-666509.8—Theme-RexFreightCoCWE-502WordPress FreightCo theme <= 1.1.15 - PHP Object Injection vulnerability
CVE-2026-782629.8—weDevsWP Project ManagerCWE-502WordPress WP Project Manager plugin <= 4.0.6 - PHP Object Injection vulnerabi…
CVE-2026-782659.8—NexcessThe Events CalendarCWE-502WordPress The Events Calendar plugin <= 6.17.2 - PHP Object Injection vulnera…
CVE-2026-782679.8—CozmoslabsTranslatePressCWE-266WordPress TranslatePress plugin <= 3.3.2 - Privilege Escalation vulnerability
CVE-2026-399759.4—CombodoiTopCWE-94Combodo iTop: Remote code execution using external auth variable value
CVE-2026-783879.4—ransomlookransomlookCWE-862RansomLook Missing Authorization in Web Configuration Editor Allows Applicati…
CVE-2026-785559.4—ransomlookransomlookCWE-200RansomLook API Key Disclosure Through /admin/apikeys HTML Source
CVE-2026-325519.3—DiviNextWoo EssentialCWE-89WordPress Woo Essential plugin <= 4.3.0 - SQL Injection vulnerability
CVE-2026-325549.3—WBWWooBeWoo Product Filter ProCWE-89WordPress WooBeWoo Product Filter Pro plugin <= 3.1.8 - SQL Injection vulnera…
CVE-2026-325559.3—PixelYourSite ProfessionalBoostCWE-89WordPress Boost plugin <= 2.0.4 - SQL Injection vulnerability
CVE-2026-676029.3—phpipamphpipamCWE-706phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache
CVE-2026-719149.3—DrayTek CorporationVigorAP 918RCWE-78DrayTek VigorAP Multiple Models Pre-Authentication OS Command Injection via d…
CVE-2026-719219.3—DrayTek CorporationVigorSwitch G2540xsCWE-78DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection v…
CVE-2026-760709.3—Netis SystemsNC63CWE-121Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password Parameter
CVE-2026-760719.3—Netis SystemsNC63CWE-121Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter
CVE-2026-768359.3—oauth2-proxyoauth2-proxyCWE-290OAuth2 Proxy 7.15.2 through 7.15.4 Authentication Bypass via X-Forwarded-Uri …
CVE-2026-779159.3—rconfigrconfigCWE-306rConfig 8.0.0 < 8.2.10 Unauthorized Admin Registration via web.php
CVE-2026-783659.3—RoskusProspero Flow CRMCWE-639IDOR and missing authorization in Prospero Flow CRM supplier API allows cross…
CVE-2026-776359.2—cakephpcakephpCWE-89CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with Postgr…
CVE-2026-783709.2—ransomlookransomlookCWE-862RansomLook Unauthenticated Database Export Exposes Private Data
CVE-2026-783729.2—ransomlookransomlookCWE-862RansomLook Missing Authorization Allows Disclosure of Private Group and Ranso…
CVE-2026-198749.1—KonamiMetal Gear Online 3CWE-122Konami's Metal Gear Online 3 contains a heap-based buffer overflow
CVE-2026-595649.1—ZscalerClient ConnectorCWE-304Authentication bypass between ZCC and client connector portal
CVE-2026-595689.1—ZscalerClient ConnectorCWE-20Remote Code Execution
CVE-2026-773379.1—cakephpauthenticationCWE-290CakePHP: Potential Authentication bypass with CookieAuthenticator
CVE-2026-308648.9—CombodoiTopCWE-79Combodo iTop: Reflected XSS in dashboard revert
CVE-2025-369408.8—GoogleAndroidCWE-416Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which …
CVE-2026-132128.8—zephyrprojectzephyrCWE-129Zephyr virtio driver calls an arbitrary function pointer from an out-of-range…
CVE-2026-325608.8—LiquidThemesMagicAI for WordPress - AI Text, Image, Chat, Code, and Voice GeneratorCWE-98WordPress MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Gener…
CVE-2026-325618.8—LiquidThemesBooking HubCWE-266WordPress Booking Hub plugin <= 1.3.0 - Privilege Escalation vulnerability
CVE-2026-595658.8—ZscalerClient ConnectorCWE-229Local and kernel denial-of-service
CVE-2026-595678.8—ZscalerClient ConnectorCWE-280Local privilege escalation
CVE-2026-719338.8—DrayTek CorporationVigorSwitch G2540xsCWE-862DrayTek VigorSwitch Multiple Models Missing Authorization in Syslog Functions
CVE-2026-768428.8—mercadopagomercadopagoCWE-22Mercado Pago Node.js SDK through 3.4.0 Path Injection via Unencoded Identifie…
CVE-2026-783698.8—ransomlookransomlookCWE-306Missing Authentication Allows Unauthorized Creation of Crypto Groups in Ranso…
CVE-2026-783768.8—Red HatRed Hat Enterprise Linux 6CWE-416Webkitgtk: use-after-free of jscvalue function parameters
CVE-2026-783918.8—ransomlookransomlookCWE-79Stored Cross-Site Scripting via Untrusted Cryptocurrency Address Rendering in…
CVE-2026-785518.8—ransomlookransomlookCWE-307RansomLook Login Endpoint Allows Timing-Based Username Enumeration and Unthro…
CVE-2026-92548.7—TP-Link Systems Inc.Archer BE800 V1CWE-78Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer …
CVE-2026-408778.7—CombodoiTopCWE-94Combodo iTop: PHP Object Injection Leading to Remote Code Execution on user p…
CVE-2026-719228.7—DrayTek CorporationVigorSwitch G2540xsCWE-476DrayTek VigorSwitch Multiple Models Pre-Authentication NULL Pointer Dereferen…
CVE-2026-760738.7—HumanSignallabel-studioCWE-639Label Studio through 1.23.0 Cross-Organization Annotation Access via Unscoped…
CVE-2026-768368.7—AzuraCastAzuraCastCWE-94AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Seri…
CVE-2026-768418.7—xorbitsaiinferenceCWE-94Xinference through 2.11.0 Remote Code Execution via Hardcoded trust_remote_co…
CVE-2026-768478.7—nektosactCWE-321act 0.2.81 through 0.2.89 Missing Authorization in the Artifacts V4 Backend
CVE-2026-768488.7—typeormtypeormCWE-89TypeORM 0.2.21 through 1.1.0 SQL Injection via SelectQueryBuilder.distinctOn
CVE-2026-783808.7—ransomlookransomlookCWE-862Private Group and Market Posts Disclosed Through Public Notification Channels…
CVE-2026-783868.7—ransomlookransomlookCWE-200Unauthenticated Disclosure of Scraping Credentials and Bypass Configuration v…
CVE-2026-784168.7—craftcmscmsCWE-915Authenticated RCE via `condition.config` JSON cleanse bypass
CVE-2026-281718.6—vanquishWooCommerce File ApprovalCWE-22WordPress WooCommerce File Approval plugin <= 10.7 - Arbitrary File Deletion …
CVE-2026-324778.6—RadiusTheme, LLCShopBuilder Pro – Elementor WooCommerce Builder AddonsCWE-22WordPress ShopBuilder Pro – Elementor WooCommerce Builder Addons plugin <= 2.…
CVE-2026-715048.6—DolibarrdolibarrCWE-862Dolibarr < 24.0.0 Members REST API Improper Authorization via Password Reset
CVE-2026-719048.6—DrayTek CorporationVigorAP 918RCWE-78DrayTek VigorAP Multiple Models OS Command Injection via tr069TestInform
CVE-2026-719058.6—DrayTek CorporationVigorAP 918RCWE-78DrayTek VigorAP Multiple Models OS Command Injection via ExportSettings
CVE-2026-719068.6—DrayTek CorporationVigorAP 918RCWE-78DrayTek VigorAP Multiple Models OS Command Injection via setLan
CVE-2026-719078.6—DrayTek CorporationVigorAP 918RCWE-78DrayTek VigorAP Multiple Models OS Command Injection via setcamset
CVE-2026-719088.6—DrayTek CorporationVigorAP 918RCWE-78DrayTek VigorAP Multiple Models OS Command Injection via mesh_start_speed_test
CVE-2026-719098.6—DrayTek CorporationVigorAP 918RCWE-78DrayTek VigorAP Multiple Models OS Command Injection via InquierTime
CVE-2026-719108.6—DrayTek CorporationVigorAP 918RCWE-78DrayTek VigorAP Multiple Models OS Command Injection via apautotest
CVE-2026-719118.6—DrayTek CorporationVigorAP 918RCWE-120DrayTek VigorAP Multiple Models Buffer Overflow via setLan
CVE-2026-719128.6—DrayTek CorporationVigorAP 918RCWE-120DrayTek VigorAP Multiple Models Buffer Overflow via apautotest
CVE-2026-719138.6—DrayTek CorporationVigorAP 918RCWE-78DrayTek VigorAP Multiple Models OS Command Injection via upload_settings.cgi
CVE-2026-719158.6—DrayTek CorporationVigorSwitch G2540xsCWE-78DrayTek VigorSwitch Multiple Models OS Command Injection via jsonstatus
CVE-2026-719168.6—DrayTek CorporationVigorSwitch G2540xsCWE-78DrayTek VigorSwitch Multiple Models OS Command Injection via commandTable
CVE-2026-719178.6—DrayTek CorporationVigorSwitch G2540xsCWE-78DrayTek VigorSwitch Multiple Models OS Command Injection via pingtrace
CVE-2026-719188.6—DrayTek CorporationVigorSwitch G2540xsCWE-78DrayTek VigorSwitch Multiple Models OS Command Injection via webBackupAction
CVE-2026-719198.6—DrayTek CorporationVigorSwitch G2540xsCWE-78DrayTek VigorSwitch Multiple Models OS Command Injection via sysreboot
CVE-2026-719238.6—DrayTek CorporationVigorSwitch G2540xsCWE-78DrayTek VigorSwitch Multiple Models OS Command Injection via auth_set
CVE-2026-719248.6—DrayTek CorporationVigorSwitch G2540xsCWE-78DrayTek VigorSwitch Multiple Models OS Command Injection via getVid
CVE-2026-719258.6—DrayTek CorporationVigorSwitch G2540xsCWE-78DrayTek VigorSwitch Multiple Models OS Command Injection via getDetail
CVE-2026-719268.6—DrayTek CorporationVigorSwitch G2540xsCWE-78DrayTek VigorSwitch Multiple Models OS Command Injection via setDevice
CVE-2026-719278.6—DrayTek CorporationVigorSwitch G2540xsCWE-78DrayTek VigorSwitch Multiple Models OS Command Injection via rebDevice
CVE-2026-719288.6—DrayTek CorporationVigorSwitch G2540xsCWE-78DrayTek VigorSwitch Multiple Models OS Command Injection via fdftDevice
CVE-2026-719298.6—DrayTek CorporationVigorSwitch G2540xsCWE-78DrayTek VigorSwitch Multiple Models OS Command Injection via setDevProto
CVE-2026-719308.6—DrayTek CorporationVigorSwitch G2540xsCWE-78DrayTek VigorSwitch Multiple Models OS Command Injection via setTime
CVE-2026-719318.6—DrayTek CorporationVigorSwitch G2540xsCWE-78DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgrade
CVE-2026-719348.6—DrayTek CorporationVigorSwitch G2540xsCWE-120DrayTek VigorSwitch Multiple Models Buffer Overflow via pingtrace
CVE-2026-719358.6—DrayTek CorporationVigorSwitch G2540xsCWE-120DrayTek VigorSwitch Multiple Models Buffer Overflow via webBackupAction
CVE-2026-719368.6—DrayTek CorporationVigorSwitch G2540xsCWE-120DrayTek VigorSwitch Multiple Models Buffer Overflow via sysreboot
CVE-2026-719378.6—DrayTek CorporationVigorSwitch G2540xsCWE-120DrayTek VigorSwitch Multiple Models Buffer Overflow via poe_schedule_profile
CVE-2026-719388.6—DrayTek CorporationVigorSwitch G2540xsCWE-120DrayTek VigorSwitch Multiple Models Buffer Overflow via switch_lan_gvrp
CVE-2026-719398.6—DrayTek CorporationVigorSwitch G2540xsCWE-120DrayTek VigorSwitch Multiple Models Buffer Overflow via acl_general_setup Add…
CVE-2026-719408.6—DrayTek CorporationVigorSwitch G2540xsCWE-120DrayTek VigorSwitch Multiple Models Buffer Overflow via acl_general_setup Edi…
CVE-2026-719418.6—DrayTek CorporationVigorSwitch G2540xsCWE-120DrayTek VigorSwitch Multiple Models Buffer Overflow via diag_logmail
CVE-2026-719428.6—DrayTek CorporationVigorSwitch G2540xsCWE-120DrayTek VigorSwitch Multiple Models Buffer Overflow via mail_mailalert
CVE-2026-719438.6—DrayTek CorporationVigorSwitch G2540xsCWE-78DrayTek VigorSwitch Multiple Models OS Command Injection via setDevNet
CVE-2026-782848.6—StylemixMasterStudy LMSCWE-22WordPress MasterStudy LMS plugin <= 3.7.42 - Arbitrary File Deletion vulnerab…
CVE-2025-630808.5—KAONPG5298ACWE-863Authenticated RCE in KAON PG5298
CVE-2026-125548.5—HP IncHP Easy Start for macOSCWE-1104HP Easy Start for macOS - Security Update
CVE-2026-163488.5—TP-Link Systems Inc.Archer BE800 v1CWE-78Command Injection Vulnerability in VPN connection of Archer BE800
CVE-2026-324718.5—ThemeBingProLancer ElementCWE-89WordPress ProLancer Element plugin <= 1.4.8 - SQL Injection vulnerability
CVE-2026-324788.5—weDevs Pte. LtdWP Project Manager ProCWE-89WordPress WP Project Manager Pro plugin <= 4.0.1 - SQL Injection vulnerability
CVE-2026-399158.5—TIM SolutionsTIM FlowCWE-113TIM Flow < 26.0.6 CRLF Injection via rt Parameter
CVE-2026-768408.5—rustdeskrustdeskCWE-20RustDesk through 1.4.9 Heap Buffer Overflow via Unvalidated CLIPRDR FileConte…
CVE-2026-785418.5—TP-Link Systems Inc.Archer BE3600 v1CWE-78Command Injection in Parent Control of TP-Link Archer BE3600 v1
CVE-2026-595668.4—ZscalerClient ConnectorCWE-229Local denial-of-service
CVE-2026-768388.4—HiEventsDevHi.EventsCWE-918Hi.Events before 1.11.1-beta Server-Side Request Forgery via Unvalidated Webh…
CVE-2026-768438.4—flairNLPflairCWE-502Flair 0.15.0 and 0.15.1 Deserialization of Untrusted Data via ClusteringModel…
CVE-2026-105828.3—gohugoiohugoCWE-918Hugo 0.91.0 through 0.165.0 Server-Side Request Forgery via security.http.url…
CVE-2026-755428.3—hexpmhexpmCWE-863OAuth token exchange grants repository scopes for organizations the principal…
CVE-2026-760728.3—continuedevcontinueCWE-184Continue CLI through 1.5.47 Incomplete Destructive Command Denylist in Headle…
CVE-2026-768448.3—webpackwebpack-dev-middlewareCWE-22webpack-dev-middleware Path Traversal via Offset Slice on a Non-Slash-Termina…
CVE-2026-776348.2—cakephpcakephpCWE-93CakePHP: SmtpTransport vulnerable to CRLF header injection
CVE-2026-783818.2—ransomlookransomlookCWE-22RansomLook Arbitrary File Read via Path Traversal in Post screen Field
CVE-2026-783858.2—ransomlookransomlookCWE-918RansomLook Analysis PDF Generation Allows Server-Side Request Forgery and Arb…
CVE-2026-281518.1—Select-ThemesTondaCWE-98WordPress Tonda theme < 2.6 - Local File Inclusion vulnerability
CVE-2026-281528.1—Select-ThemesTonda CoreCWE-98WordPress Tonda Core plugin < 2.6 - Local File Inclusion vulnerability
CVE-2026-666708.1—Elated-ThemesMåneCWE-98WordPress Måne theme <= 1.7 - Local File Inclusion vulnerability
CVE-2026-666718.1—Elated-ThemesVerdure CoreCWE-98WordPress Verdure Core plugin <= 1.2 - Local File Inclusion vulnerability
CVE-2026-775678.1—filamentphpfilamentCWE-287Filament: App-based MFA can be bypassed when recovery codes are enabled
CVE-2026-784148.0—Network OptixNx Witness VMSCWE-79Cross-site scripting in Nx Witness VMS Web Administration allows session toke…
CVE-2026-74557.8—Autodesk3ds MaxCWE-787FLT File Parsing Out-of-Bounds Write Vulnerability in Autodesk 3ds Max
CVE-2026-167837.8—Autodesk3ds MaxCWE-787ABC File Parsing Out-of-Bounds Write Vulnerability in Autodesk 3ds Max
CVE-2026-195687.8—Autodesk3ds MaxCWE-120SVG File Parsing Memory Corruption Vulnerability in Autodesk 3ds Max
CVE-2026-614197.8—DellThinOS 10CWE-284Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Co…
CVE-2026-125557.7—HP IncHP Easy Start for macOSCWE-379HP Easy Start for macOS - Security Update
CVE-2026-125567.7—HP IncHP Easy Start for macOSCWE-319HP Easy Start for macOS - Security Update
CVE-2026-154697.7—TP-Link Systems Inc.Deco XE75 v3 / XE5300 v3.6/ WE10800 v3.6CWE-321Hard-coded Mesh Group Private Key in TP-Link Deco XE75, XE5300, and WE10800
CVE-2026-713667.7—Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8CWE-918Awx: notification backends allow ssrf and credential leakage
CVE-2026-782707.6—WP ManageNinja LLCFluentCRM ProCWE-89WordPress FluentCRM Pro plugin <= 3.1.12 - SQL Injection vulnerability
CVE-2025-688257.5—HCLSoftwareHCL HiveCWE-276HCL Hive is affected by incorrect default permissions
CVE-2026-217527.5—HCLSoftwareHCL HiveCWE-1104HCL Hive is affected by a use of vulnerable third-party components
CVE-2026-281537.5—Notification MasterNotification Master &#8211; Real-Time WordPress Notifications With Email, SMS, Webhooks &amp; MoreCWE-862WordPress Notification Master – Real-Time WordPress Notifications With Email,…
CVE-2026-281677.5—Super FormsSuper FormsCWE-22WordPress Super Forms plugin <= 6.3.315 - Arbitrary File Download vulnerability
CVE-2026-665857.5—WPCafeWP Cafe ProCWE-201WordPress WP Cafe Pro plugin < 3.0.15 - Sensitive Data Exposure vulnerability
CVE-2026-760557.5—Black Duckblackduck-c-cppCWE-78Improper Neutralization of Special Elements used in an OS Command in the pack…
CVE-2026-760987.5—lepturemistuneCWE-674Mistune has Denial of Service — RecursionError via Excessive Emphasis Markers…
CVE-2026-761727.5—fast-urifast-uriCWE-177fast-uri vulnerable to host confusion via percent-encoded scheme normalization
CVE-2026-773847.5—libp2pjs-libp2pCWE-400libp2p: Circuit relay v2 server reservation refresh leaks abort listeners and…
CVE-2026-782687.5—Extend ThemesLead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeadsCWE-497WordPress Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Cal…
CVE-2026-217517.4—HCLSoftwareHCL HiveCWE-1240HCL Hive is affected by use of a cryptographic primitive with a risky impleme…
CVE-2026-183497.3—MicrochipSAMA5D4CWE-1247SAMA5D44 Fault Injection Vulnerability
CVE-2026-782597.3—WP Legal PagesWPLegalPagesCWE-288WordPress WPLegalPages plugin <= 3.7.0 - Broken Authentication vulnerability
CVE-2026-217567.2—HCLSoftwareHCL HiveCWE-266HCL Hive is affected by a broken access control vulnerability
CVE-2026-713647.2—Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8CWE-22Awx: project archive extraction allows path traversal file writes
CVE-2026-715067.2—DolibarrdolibarrCWE-863Dolibarr < 24.0.0 Payments REST API Improper Authorization via Delete Endpoint
CVE-2026-60177.1—KAONPG5298ACWE-306Missing Authentication for Critical Function in KAON PG5298
CVE-2026-196857.1—Red HatRed Hat Enterprise Linux 10CWE-863Networkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass priv…
CVE-2026-281627.1—FrankyEvents Made EasyCWE-79WordPress Events Made Easy plugin <= 3.2.5 - Cross Site Scripting (XSS) vulne…
CVE-2026-281667.1—GoodLayersTourmasterCWE-79WordPress Tourmaster plugin <= 5.4.9 - Cross Site Scripting (XSS) vulnerability
CVE-2026-281907.1—ThemeBingProLancer ElementCWE-862WordPress ProLancer Element plugin <= 1.4.8 - Broken Access Control vulnerabi…
CVE-2026-324767.1—AmpleByte Pvt LimitedBrave Conversion Engine (PRO)CWE-79WordPress Brave Conversion Engine (PRO) plugin <= 0.8.6 - Cross Site Scriptin…
CVE-2026-325567.1—PixelYourSite ProfessionalBoostCWE-79WordPress Boost plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability
CVE-2026-399147.1—TIM SolutionsTIM FlowCWE-862TIM Flow < 26.0.6 Unauthorized SQL Query Execution via Dashboard Export Endpoint
CVE-2026-535327.1—AcademySoftwareFoundationopenexrCWE-617OpenEXR: Unhandled assert abort in HTJ2K decoder via crafted QCD marker (DoS)
CVE-2026-665847.1—Code for Recovery12 Step Meeting ListCWE-79WordPress 12 Step Meeting List plugin <= 3.19.16 - Cross Site Scripting (XSS)…
CVE-2026-665997.1—Liquid Web / StellarWPWPCompleteCWE-79WordPress WPComplete plugin <= 2.9.5.6 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-666107.1—thembayUrnaCWE-79WordPress Urna theme <= 2.6.2 - Cross Site Scripting (XSS) vulnerability
CVE-2026-666237.1—InisevSocial Media & Share IconsCWE-79WordPress Social Media & Share Icons plugin <= 2.9.9 - Cross Site Scripting (…
CVE-2026-715057.1—DolibarrdolibarrCWE-639Dolibarr < 24.0.0 REST API Broken Object-Level Authorization via Third-Party …
CVE-2026-715077.1—DolibarrdolibarrCWE-639Dolibarr < 24.0.0 REST API Broken Object-Level Authorization via Bank Account…
CVE-2026-715087.1—DolibarrdolibarrCWE-862Dolibarr < 24.0.0 REST API Improper Authorization via User Update Endpoint
CVE-2026-715097.1—DolibarrdolibarrCWE-862Dolibarr < 24.0.0 Expense Report REST API Improper Authorization via Update E…
CVE-2026-715107.1—DolibarrdolibarrCWE-863Dolibarr < 24.0.0 Users REST API SQL Injection via filter parameter
CVE-2026-715117.1—DolibarrdolibarrCWE-522Dolibarr < 24.0.0 Members REST API Sensitive Data Exposure via Member Endpoints
CVE-2026-760547.1—Black Duckblackduck-c-cppCWE-214Invocation of Process Using Visible Sensitive Information in Black Duck black…
CVE-2026-779147.1—rconfigrconfigCWE-22rConfig < 8.2.13 Core Path Traversal via Export Download Endpoint
CVE-2026-782637.1—NexcessEvent TicketsCWE-79WordPress Event Tickets plugin <= 5.29.2.1 - Cross Site Scripting (XSS) vulne…
CVE-2026-782647.1—Site Building with ToolsetToolset BlocksCWE-79WordPress Toolset Blocks plugin <= 1.6.26 - Cross Site Scripting (XSS) vulner…
CVE-2026-782827.1—mra13Stripe PaymentsCWE-79WordPress Stripe Payments plugin <= 2.1.2 - Cross Site Scripting (XSS) vulner…
CVE-2026-783677.0—Red HatRed Hat Enterprise Linux 10CWE-94Rpm: rpmbuild gettarspec() crafted tar member name → macro injection
CVE-2026-784657.0—Red HatRed Hat Enterprise Linux 6CWE-190Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit
CVE-2026-785537.0—ransomlookransomlookCWE-276Insecure Flask Secret-Key File Permissions Allow Local Administrator Session …
CVE-2026-719206.9—DrayTek CorporationVigorSwitch G2540xsCWE-476DrayTek VigorSwitch Multiple Models NULL Pointer Dereference via formlogout
CVE-2026-719326.9—DrayTek CorporationVigorSwitch G2540xsCWE-22DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFile
CVE-2026-783786.9—ransomlookransomlookCWE-200Redis Glob Pattern Injection Allows Unauthorized Enumeration of Private Ranso…
CVE-2020-372686.8—rocq-proverrocqCWE-778Coq and Rocq Prover Print Assumptions Omits Unsafe Universe Checking Inlined …
CVE-2026-50066.8—HashiCorpVaultCWE-639Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Pol…
CVE-2026-170336.8—GrafanaGrafana OSSCWE-79CVE-2026-17033 CVE Record
CVE-2026-727036.8—rocq-proverrocqCWE-670Rocq Prover 8.20 before 9.2.0 Guard Checker Accepts Non-Terminating Fixpoint …
CVE-2026-727046.8—rocq-proverrocqCWE-670Rocq Prover through 9.2.0 Guard Checker Trusts Corrupted Recursive Tree After…
CVE-2026-727056.8—rocq-proverrocqCWE-670Rocq Prover before 9.2.0 Guard Checker Accepts Fixpoint Passed as a Higher-Or…
CVE-2026-727116.8—leanproverlean4CWE-20Lean 4 before 4.32.2 Kernel Accepts Opaque Declaration With an Unbound Free V…
CVE-2026-727146.8—rocq-proverrocqCWE-459Rocq Prover through 9.2.0 Universe Checking State Desynchronised After Module…
CVE-2026-768456.8—cthackersadm-zipCWE-59adm-zip 0.5.9 through 0.6.0 Arbitrary File Overwrite via Symlink Following on…
CVE-2026-636936.6—DellAlienware Area 51m R2CWE-379Dell Client BIOS contains an Improper Link Resolution Before File Access ('Li…
CVE-2026-273646.5—AnalogWPStyle KitsCWE-862WordPress Style Kits plugin <= 2.6.5 - Broken Access Control vulnerability
CVE-2026-685166.5—AcademySoftwareFoundationopenexrCWE-121OpenEXR: HTJ2K SIZ image-offset gap stack buffer overflow
CVE-2026-755096.5—authlibjoserfcCWE-290joserfc claim-validation bypass via array-typed single-string claims (iss/sub…
CVE-2026-782666.5—Ruben GarciaAutomatorWPCWE-862WordPress AutomatorWP plugin <= 5.8.3 - Broken Access Control vulnerability
CVE-2026-782906.5—ThemeGrillMagazine BlocksCWE-79WordPress Magazine Blocks plugin <= 1.8.6 - Cross Site Scripting (XSS) vulner…
CVE-2026-783236.5—Red HatRed Hat Certificate System 10CWE-295Jss: jss: jsstrustmanager does not verify nss trust flags on ca certificates
CVE-2026-97286.4—zephyrprojectzephyrCWE-367TOCTOU race in mbox_send syscall verifier allows userspace to leak kernel memory
CVE-2026-782696.4—TammersoftShared FilesCWE-918WordPress Shared Files plugin <= 1.7.69 - Server Side Request Forgery (SSRF) …
CVE-2026-344916.1—Johnson ControlsMetasys 14—Improper neutralization of input during web page generation ('cross-site scri…
CVE-2026-784756.1—Red HatRed Hat Enterprise Linux 6CWE-125Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loader
CVE-2026-171136.0—Red HatRed Hat OpenShift Container Platform 4CWE-1287Cri-o: cri-o: unvalidated image env var causes daemon crash
CVE-2026-454045.9—open-telemetryopentelemetry-goCWE-362OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access
CVE-2026-592955.9—VMware (Broadcom)io.micrometer:micrometer-coreCWE-401Micrometer Instrumentation of Apache HttpAsyncClient Denial of Service Vulner…
CVE-2026-167815.5—Autodesk3ds MaxCWE-674SVG File Parsing Stack Exhaustion Vulnerability in Autodesk 3ds Max
CVE-2026-782445.5—itsourcecodeReal Estate Management SystemCWE-74itsourcecode Real Estate Management System search.php sql injection
CVE-2026-782455.5—itsourcecodeOnline Pharmacy SystemCWE-284itsourcecode Online Pharmacy System User Registration register.php move_uploa…
CVE-2026-782465.5—itsourcecodeOnline Clinic Management SystemCWE-74itsourcecode Online Clinic Management System Admin Login login.php sql injection
CVE-2026-782475.5—SourceCodesterSimple Online Food Ordering SystemCWE-74SourceCodester Simple Online Food Ordering System ajax.php confirm_order sql …
CVE-2026-782485.5—SourceCodesterSimple Online Food Ordering SystemCWE-74SourceCodester Simple Online Food Ordering System ajax.php save_settings sql …
CVE-2026-784345.5—FaveoHelpdeskCWE-287Faveo Helpdesk post-ticket-reply Endpoint FormController.php post_ticket_repl…
CVE-2026-782725.4—WP ManageNinja LLCFluent Support ProCWE-862WordPress Fluent Support Pro plugin <= 2.3.1 - Broken Access Control vulnerab…
CVE-2026-782795.4—WP ManageNinja LLCFluent Support ProCWE-352WordPress Fluent Support Pro plugin <= 2.3.1 - Cross Site Request Forgery (CS…
CVE-2025-688335.3—HCLSoftwareHCL HiveCWE-1240HCL Hive is affected by use of a cryptographic primitive with a risky impleme…
CVE-2026-132135.3—zephyrprojectzephyrCWE-476Bluetooth HAS: NULL-pointer dereference DoS when a bonded peer reconnects bef…
CVE-2026-133435.3—zephyrprojectzephyrCWE-200Uninitialised stack memory disclosure in the MIDI 2.0 UMP Stream responder
CVE-2026-167825.3—Autodesk3ds MaxCWE-125SVG File Parsing Out-of-Bounds Read Vulnerability in Autodesk 3ds Max
CVE-2026-217555.3—HCLSoftwareHCL HiveCWE-307HCL Hive is affected by a missing rate limit
CVE-2026-672045.3—BookStackAppBookStackCWE-863BookStack < 26.05.4 Broken Access Control via Image Gallery API
CVE-2026-750995.3—Apache Software FoundationApache AlluraCWE-200Apache Allura: Unauthenticated REST disclosure
CVE-2026-768375.3—BaserowBaserowCWE-79Baserow before 2.3.0 Stored Cross-Site Scripting via Rich Text Mention Displa…
CVE-2026-773105.3—FasterXMLcom.fasterxml.jackson.core:jackson-databindCWE-918jackson-databind: Eager DNS resolution (SSRF) still present in InetAddress de…
CVE-2026-779235.3—DolibarrdolibarrCWE-863Dolibarr 21.0.0 < 24.0.0 Authorization Bypass via clonetasks Mass Action
CVE-2026-782585.3—Magepeople inc.Booking and Rental ManagerCWE-862WordPress Booking and Rental Manager plugin <= 2.7.5 - Broken Access Control …
CVE-2026-782785.3—WP ManageNinja LLCFluent Boards ProCWE-639WordPress Fluent Boards Pro plugin <= 2.0.11 - Insecure Direct Object Referen…
CVE-2026-782915.3—Webful CreationsRepairBuddyCWE-862WordPress RepairBuddy plugin <= 4.1223 - Broken Access Control vulnerability
CVE-2026-650535.1—hordeimpCWE-79Horde IMP before 7.2.0 Stored Cross-Site Scripting via AppleDouble Viewer Par…
CVE-2026-715035.1—DolibarrdolibarrCWE-79Dolibarr < 24.0.0 Reflected XSS via Extra Fields Administration Template
CVE-2026-782774.9—WP ManageNinja LLCFluentCRM ProCWE-918WordPress FluentCRM Pro plugin <= 3.1.12 - Server Side Request Forgery (SSRF)…
CVE-2026-106184.8—gohugoiohugoCWE-79Hugo 0.93.0 through 0.165.0 Stored Cross-Site Scripting via Unescaped Code-Fe…
CVE-2026-783374.8—RoskusProspero Flow CRMCWE-434Unrestricted upload of file with dangerous type in Prospero Flow CRM allows s…
CVE-2026-217594.3—HCLSoftwareHCL HiveCWE-215HCL Hive is affected by an information exposure vulnerability
CVE-2026-554684.3—wagtailwagtailCWE-280Wagtail: Improper restriction handling on Pages admin API
CVE-2026-782804.3—HashThemesHash FormCWE-352WordPress Hash Form plugin <= 1.4.0 - Cross Site Request Forgery (CSRF) vulne…
CVE-2026-768163.5—nettynettyCWE-20Netty: MQTT Topic Name and Client ID Validation Bypass
CVE-2026-755542.3—hexpmhexpmCWE-613Explicit organization scopes survive token refresh after membership ends
CVE-2026-782502.1—bytebot-aibytebotCWE-404bytebot-ai bytebot Agent Execution Workflow infinite loop
CVE-2026-784352.0—FaveoHelpdeskCWE-22Faveo Helpdesk Logo SettingsController.php unlink path traversal
CVE-2026-784301.9—sworddutmcp-ffmpeg-helperCWE-77sworddut mcp-ffmpeg-helper Tool handlers.ts handleToolCall os command injection
CVE-2022-30983await—n/an/a—A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms…
CVE-2025-26237await—n/an/a—D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in …
CVE-2025-26238await—n/an/a—In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploite…
CVE-2026-30512await—n/an/a—A local privilege escalation vulnerability exists in the Restricted Access (K…
CVE-2026-52490await—n/an/a—An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attack…
CVE-2026-52492await—n/an/a—An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function w…
CVE-2026-56135await—n/an/a—In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the func…
CVE-2026-56136await—n/an/a—In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() …
CVE-2026-59230await—Apache Software FoundationApache CamelCWE-20Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers o…
CVE-2026-60093await—Apache Software FoundationApache CamelCWE-23Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation buil…
CVE-2026-63621await—Apache Software FoundationApache CamelCWE-20Apache Camel: Camel-Knative: CloudEvent extension fields received in structur…
CVE-2026-66906await—Apache Software FoundationApache CamelCWE-23Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation buil…
CVE-2026-66907await—Apache Software FoundationApache CamelCWE-23Apache Camel: Camel-Google-Storage: the consumer appended the remote object n…
CVE-2026-66908await—Apache Software FoundationApache CamelCWE-287Apache Camel: Camel-platform-http-main: when JWT authentication was configure…
CVE-2026-71300await—Apache Software FoundationApache CamelCWE-20Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection
CVE-2026-71832await—n/an/a—Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/b…
CVE-2026-75368await—n/an/a—A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC softwar…
CVE-2026-75369await—n/an/a—An out-of-bounds read vulnerability in the CAN::Application::parsePerformFunc…
CVE-2026-75370await—n/an/a—An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHe…
CVE-2026-75371await—n/an/a—An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC…
CVE-2026-75464await—n/an/a—OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability …
CVE-2026-78329await—Apache Software FoundationApache CamelCWE-20Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific he…
CVE-2026-78417await—DevolutionsRemote Desktop ManagerCWE-345Insufficient verification of data authenticity in the IronVNC client in Devol…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-24 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.