boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, August 25, 2026 · all times UTC← 2026-08-24 · archive

Security Box Score — August 25, 2026

787 CVEs published, led by Google (327).

787 CVEs published August 25, 2026: 70 critical, 219 high, 142 medium, 14 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 342 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 387 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1044932619——
KEV catalog size1676

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

1786 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux14173732384186463711120.17.8.0017+615 ▲
google4002161252779786577760.37.5.0025+281 ▲
microsoft4691891145128145114286271.47.8.0044-191 ▼
red hat2085964325027231200.06.8.0028+91 ▲
apple44315588216578882.56.5.0029+41 ▲
canonical15421311135000.07.8.0020+8 ▲
freebsd233902340000.07.8.0015+23 ▲
suse52651461000.08.1.0039-3 ▼
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco46842139240561315.57.5.0044+31 ▲
palo alto networks12371321121325.44.7.0020-2 ▼
ubiquiti036142110338.38.8.0049-25 ▼
netgear93200275000.04.3.0025+3 ▲
fortinet7307814128620.07.0.0050-6 ▼
vmware21949427210.58.1.0040-6 ▼
f50175930415.98.7.0057-8 ▼
sonicwall1214354017214.37.8.0024+10 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache15549196206161133320.47.5.0048+52 ▲
mozilla591866868500900.08.1.0030-12 ▼
drupal176865355411.55.9.0026-29 ▼
gitlab1667215428423.05.3.0029+9 ▲
github5171790000.06.6.00430
docker290630000.07.2.0016+2 ▲
wordpress2513102240.08.8.31200
kubernetes010001000.02.4.0035-1 ▼
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle88922684871172513962840.27.8.0034-220 ▼
ibm3746031442791728610.27.6.0030+337 ▲
adobe983504217412951930.97.8.0026+3 ▲
progress19611437100611.68.1.0037-9 ▼
solarwinds0231733010417.49.1.0058-15 ▼
veeam10165920100.08.6.0034+9 ▲
zohocorp4103520000.08.7.0140+1 ▲
atlassian3615001300.08.1.00340
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link163615597300.07.4.0157+8 ▲
siemens193522382000.07.3.0016+12 ▲
rockwell automation12541830000.08.7.0029-16 ▼
synology12426133000.05.6.0025+1 ▲
schneider electric091620000.08.6.00370
abb070430000.07.2.0018-1 ▼
hikvision060420000.07.2.0040-5 ▼
moxa050320000.07.0.00290
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester47167009176000.05.5.0030-2 ▼
dell581571084585210.67.2.0019+15 ▲
nvidia521341688300000.07.8.0034+11 ▲
splunk110128647705110.86.5.0025+107 ▲
openclaw01110583914000.07.0.0026-44 ▼
getgrav641021359282000.08.4.0032+27 ▲
zephyrproject47100333559000.06.4.0022+24 ▲
itsourcecode29100002575000.02.1.0028+11 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.995799.99.8
CVE-2026-34486.986299.97.5
CVE-2026-63077.847399.79.8
CVE-2026-72898.792299.610.0
CVE-2026-61511.707799.39.3
CVE-2026-59310.458898.79.8
CVE-2026-64638.312098.18.9
CVE-2025-68686.291598.05.9
CVE-2026-71362.251497.89.1
CVE-2026-66066.189597.19.5
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.7922KEV
CVE-2026-4836210.0.0431
CVE-2026-1918810.0.0193
CVE-2026-5823110.0.0171
CVE-2026-6983610.0.0159
CVE-2026-1681210.0.0157KEV
CVE-2026-7329910.0.0121
CVE-2026-7367810.0.0114
CVE-2026-4561810.0.0092
CVE-2026-4816810.0.0091
Most disclosures (vendor)
VendorCVEs
linux1448
oracle889
google777
microsoft471
ibm442
red hat255
apache233
apple208
adobe111
splunk110
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco13
apple8
fortinet6
google6
ivanti5
oracle4
solarwinds4
adobe3
berriai3
Most-affected ecosystems
EcosystemAdvisories
Maven63
Packagist26
PyPI14
npm13
Go4
NuGet1
crates.io1
Fastest to KEV
CVEVendorDays
CVE-2025-68686Fortinet0
CVE-2026-16812Arista Networks0
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20316Cisco0
CVE-2026-20349Cisco0
CVE-2026-34486Apache Software Foundation0
CVE-2026-63077JetBrains0
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171742
CVE-2021-27102n/a2021-11-171742
CVE-2021-27101n/a2021-11-171742
CVE-2021-27103n/a2021-11-171742
CVE-2021-21017Adobe2021-11-171742
CVE-2021-28550Adobe2021-11-171742
CVE-2021-42013Apache Software Foundation2021-11-171742
CVE-2021-41773Apache Software Foundation2021-11-171742
CVE-2021-30858Apple2021-11-171742
CVE-2021-30860Apple2021-11-171742

Transactions

EXPLOIT PUBLISHED — axios: 13 CVEs (CVE-2025-62718, CVE-2026-25639, CVE-2026-40175, CVE-2026-42033, CVE-2026-42041, CVE-2026-42043, CVE-2026-44486, CVE-2026-44487, CVE-2026-44488, CVE-2026-44492, CVE-2026-44494, CVE-2026-44495, CVE-2026-44496). Public exploit references added.

EXPLOIT PUBLISHED — GNOME GLib: 6 CVEs (CVE-2026-58010, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015, CVE-2026-58016). Public exploit references added.

EXPLOIT PUBLISHED — Red Hat Enterprise Linux 10: 4 CVEs (CVE-2026-4878, CVE-2026-48864, CVE-2026-55653, CVE-2026-55654). Public exploit references added.

EXPLOIT PUBLISHED — rocq-prover rocq: 3 CVEs (CVE-2020-37268, CVE-2026-72704, CVE-2026-72714). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2020-1938 (Apache Tomcat). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2022-37315. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-6610 (Linux kernel). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-5914 (libarchive). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-29063 (immutable-js). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-29181 (open-telemetry opentelemetry-go). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-33487 (russellhaering goxmldsig). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-34070 (langchain-ai langchain). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-3832 (gnutls). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-39363 (vitejs vite). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-41523 (vllm-project vllm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-42945 (F5 NGINX Plus). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-45186 (libexpat project libexpat). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-45736 (websockets ws). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-4740 (Red Hat multicluster engine for Kubernetes 2.10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-71225 (Stephan Muelle libkcapi). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-71227 (Stephan Muelle libkcapi). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76574 (code-projects Hospital Information System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76589 (TRENDnet TEW-755AP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76762 (code-projects Assessment Management). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76795 (AeternaLabsHQ PullMD). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76989 (liftoff-sr CIPster). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76996 (SourceCodester Simple Online Food Ordering System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-77019 (CodeAstro Apartment Visitor Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-77036 (elunez eladmin). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-77945 (TRENDnet TEW-821DAP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78434 (Faveo Helpdesk). Public exploit reference added.

DUE DATE PASSED — CVE-2026-73570 (Zimbra Collaboration). CISA remediation deadline was August 24, 2026; still in catalog.

REJECTED — CVE-2026-73189 (Themeum WP Crowdfunding). Record withdrawn by the CNA.

REJECTED — CVE-2026-78154 (the-momentum open-wearables). Record withdrawn by the CNA.

RESCORED — IBM AIX: 26 CVEs (CVE-2026-17000, CVE-2026-17003, CVE-2026-17006, CVE-2026-17007, CVE-2026-17009, CVE-2026-17024, CVE-2026-17060, CVE-2026-17120, CVE-2026-17138, CVE-2026-17168, CVE-2026-17422, CVE-2026-17423, CVE-2026-17424, CVE-2026-17436, CVE-2026-18670, CVE-2026-18716, CVE-2026-18822, CVE-2026-18828, CVE-2026-18832, CVE-2026-18840, CVE-2026-18842, CVE-2026-19437, CVE-2026-19442, CVE-2026-19448, CVE-2026-19653, CVE-2026-19783). CVSS rescored — before/after on each CVE page.

RESCORED — IBM PowerVM Hypervisor: 6 CVEs (CVE-2026-4936, CVE-2026-4937, CVE-2026-15961, CVE-2026-17097, CVE-2026-17414, CVE-2026-18821). CVSS rescored — before/after on each CVE page.

RESCORED — nodejs node: 3 CVEs (CVE-2026-56847, CVE-2026-56850, CVE-2026-58043). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2026-1615 (jsonpath). CVSS 9.2 → 8.2 (NVD).

RESCORED — CVE-2026-35385 (OpenBSD OpenSSH). CVSS 7.5 → 8.1 (NVD).

RESCORED — CVE-2026-35535 (Sudo project Sudo). CVSS 7.4 → 7.8 (NVD).

RESCORED — CVE-2026-45186 (libexpat project libexpat). CVSS 2.9 → 7.5 (NVD).

RESCORED — CVE-2026-7141 (vLLM). CVSS 6.3 → 2.9 (NVD).

PATCH SHIPPED — Red Hat multicluster engine for Kubernetes 2.10: 9 CVEs (CVE-2026-10059, CVE-2026-19130, CVE-2026-66794, CVE-2026-66795, CVE-2026-73266, CVE-2026-73267, CVE-2026-73268, CVE-2026-73269, CVE-2026-75569). Fix versions published.

PATCH SHIPPED — CVE-2026-15809 (Red Hat OpenShift Container Platform 4.22). Fixed in Red Hat OpenShift Container Platform 4.22 0:1.35.6-5.rhaos4.22.git41f610b.el9.

PATCH SHIPPED — CVE-2026-17527 (Red Hat Container Native Virtualization 4.19). Fixed in Red Hat Container Native Virtualization 4.19 1787234290.

ENRICHED — CVE-2021-4090 (Linux kernel). Received CVSS 7.1 and CPE data from NVD.

ENRICHED — CVE-2022-37315. Received CVSS 7.5 and CPE data from NVD.

Yesterday's Results

How to read these box scores · glossary

787 CVEs published. 25 box scores and 375 table rows below; the remaining 387 continue on page 2 — every CVE is listed, nothing truncated.

vrana adminer — Adminer before 5.4.3 Remote Code Execution via SQLite VACUUM INTO
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0113   64.0     —
AFFECTED
  Product  Versions     Fixed
  adminer  unspecified  5.4.3
TIMELINE
  Jun 22  Reserved by CNA
  Aug 25  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
netweblogic Events Manager – Calendar, Bookings, Tickets, and more! — Events Manager <= 7.3.7.4 - Authenticated (Administrator+) Local File Inclusion via 'dbem_data[updates]' Array Keys
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  H  H  H    6.6   .0071   50.8     —
AFFECTED
  Product                                                  Versions     Fixed
  Events Manager – Calendar, Bookings, Tickets, and more!  unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Aug 25  Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Received
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is e…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   N   N   N    5.8   .0065   48.6     —
AFFECTED
  Product             Versions            Fixed
  SKYSEA Client View  Ver.19.300.09h –    —
  SKYMEC IT Manager   Ver.2024.005.10a –  —
TIMELINE
  Aug 5   Reserved by CNA
  Aug 25  Published (CNA: jpcert)
CWE-22 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Received
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is e…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   N   N   N    5.8   .0065   48.6     —
AFFECTED
  Product             Versions            Fixed
  SKYSEA Client View  Ver.19.300.09h –    —
  SKYMEC IT Manager   Ver.2024.005.10a –  —
TIMELINE
  Aug 5   Reserved by CNA
  Aug 25  Published (CNA: jpcert)
CWE-25 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Received
creativemindssolutions CM Map Locations – Visualize and share your locations in a few clicks — CM Map Locations <= 2.1.8 - Authenticated (Subscriber+) Arbitrary File Upload via cmloc_route_image_upload AJAX Action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0063   47.4     —
AFFECTED
  Product                                                                Versions     Fixed
  CM Map Locations – Visualize and share your locations in a few clicks  unspecified  —
TIMELINE
  Jul 22  Reserved by CNA
  Aug 25  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 9 references · NVD status: Received
Sky Co., LTD. SKYSEA Client View — A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vul…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   N   N   N    5.8   .0061   46.5     —
AFFECTED
  Product             Versions        Fixed
  SKYSEA Client View  unspecified     —
  SKYMEC IT Manager   2023.225.03a –  —
TIMELINE
  Aug 5   Reserved by CNA
  Aug 25  Published (CNA: jpcert)
CWE-121 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Received
getgrav grav — Grav before 2.0.16 Path Traversal via MediaUploadTrait deleteFile
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   N   N    7.1   .0057   44.5     —
AFFECTED
  Product  Versions     Fixed
  grav     unspecified  2.0.16
TIMELINE
  Aug 10  Reserved by CNA
  Aug 25  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
TYPO3 Extension "powermail" — Server-Side Template Injection in extension "powermail" (powermail)
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.5   .0055   43.8     —
AFFECTED
  Product                Versions  Fixed
  Extension "powermail"  13.0.0 –  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 25  Published (CNA: TYPO3)
CWE-1336 · CNA: TYPO3 · CVSS v4.0 · 1 reference · NVD status: Received
Weidmueller Interface IE-SR-2TX-WL — Unauthenticated Remote Code Execution via Shell Injection in Web Management Interface
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0052   41.8     —
AFFECTED
  Product               Versions  Fixed
  IE-SR-2TX-WL          1.52 –    —
  IE-SR-2TX-WL-4G-EU    1.67 –    —
  IE-SR-2TX-WL-4G-US-V  1.67 –    —
TIMELINE
  Jul 17  Reserved by CNA
  Aug 25  Published (CNA: CERTVDE)
CWE-78 · CNA: CERTVDE · CVSS v4.0 · 1 reference · NVD status: Received
zephyrproject zephyr — Stack buffer overflow in OCPP GetConfiguration key parsing
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0051   41.3     —
AFFECTED
  Product  Versions  Fixed
  zephyr   4.3.0 –   —
TIMELINE
  Jun 24  Reserved by CNA
  Aug 25  Published (CNA: zephyr)
CWE-787 · CNA: zephyr · CVSS v3.1 · 2 references · NVD status: Received
vrana adminer — Adminer before 5.4.3 Remote Code Execution via MSSQL PDO DSN Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0050   40.4     —
AFFECTED
  Product  Versions     Fixed
  adminer  unspecified  5.4.3
TIMELINE
  Jun 22  Reserved by CNA
  Aug 25  Published (CNA: VulnCheck)
CWE-73 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
Elated-Themes Mane — Måne <= 1.7 - Unauthenticated Local File Inclusion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0049   39.7     —
AFFECTED
  Product  Versions     Fixed
  Mane     unspecified  —
TIMELINE
  Aug 24  Reserved by CNA
  Aug 25  Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Received
Mikado-Themes Verdure Core — Verdure Core <= 1.2 - Unauthenticated Local File Inclusion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0048   39.1     —
AFFECTED
  Product       Versions     Fixed
  Verdure Core  unspecified  —
TIMELINE
  Aug 24  Reserved by CNA
  Aug 25  Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Received
Edge-Themes Shuffle — Shuffle <= 1.8 - Unauthenticated Local File Inclusion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0048   39.1     —
AFFECTED
  Product  Versions     Fixed
  Shuffle  unspecified  —
TIMELINE
  Aug 24  Reserved by CNA
  Aug 25  Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Received
netweblogic Events Manager – Calendar, Bookings, Tickets, and more! — Events Manager <= 7.4.0 - Authenticated (Contributor+) SQL Injection via 'meta_key' Parameter in Event/Location Duplicate Action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0043   35.3     —
AFFECTED
  Product                                                  Versions     Fixed
  Events Manager – Calendar, Bookings, Tickets, and more!  unspecified  —
TIMELINE
  Jul 8   Reserved by CNA
  Aug 25  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 14 references · NVD status: Received
TYPO3 Extension "HTML5 Video Player vs. Powermail" — Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail)
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0042   35.0     —
AFFECTED
  Product                                       Versions     Fixed
  Extension "HTML5 Video Player vs. Powermail"  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 25  Published (CNA: TYPO3)
CWE-502 · CNA: TYPO3 · CVSS v4.0 · 1 reference · NVD status: Received
team-alembic ash_authentication — Reflected XSS in AshAuthentication confirmation and magic link interaction forms
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   A   N   N   N    2.1   .0042   34.5     —
AFFECTED
  Product             Versions                                    Fixed
  ash_authentication  4.8.0 –                                     —
  ash_authentication  fe0b4558dbe852fee5d81a460a8355577618a8c8 –  62719710790a150a9eacab9c0a066e0d122d15be
TIMELINE
  Jul 28  Reserved by CNA
  Aug 25  Published (CNA: EEF)
CWE-79 · CNA: EEF · CVSS v4.0 · 5 references · NVD status: Received
gitpython-developers GitPython — GitPython before 3.1.59 Path Traversal via separate-git-dir
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0042   34.4     —
AFFECTED
  Product    Versions     Fixed
  GitPython  unspecified  3.1.59
TIMELINE
  Aug 25  Reserved by CNA
  Aug 25  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
cleverbrush framework/deep deepExtend.ts deepExtend prototype pollution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0042   34.4     —
AFFECTED
  Product    Versions  Fixed
  framework  4.0 –     4.4.1
  deep       4.0 –     4.4.1
TIMELINE
  Aug 24  Reserved by CNA
  Aug 25  Published (CNA: VulDB)
CWE-94, CWE-1321 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Received
gitpython-developers GitPython — GitPython before 3.1.59 Remote Code Execution via Config Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0040   33.3     —
AFFECTED
  Product    Versions     Fixed
  GitPython  unspecified  3.1.59
TIMELINE
  Aug 25  Reserved by CNA
  Aug 25  Published (CNA: VulnCheck)
CWE-88 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
TYPO3 Extension "Event management and registration" — Broken Access Control in extension "Event management and registration" (sf_event_mgt)
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   L   N   N    6.3   .0037   29.9     —
AFFECTED
  Product                                        Versions  Fixed
  Extension "Event management and registration"  9.0.0 –   —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 25  Published (CNA: TYPO3)
CWE-862 · CNA: TYPO3 · CVSS v4.0 · 1 reference · NVD status: Received
getgrav grav — Grav before 4.2.2 Remote Code Execution via Email Twig
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0036   29.1     —
AFFECTED
  Product  Versions     Fixed
  grav     unspecified  4.2.2
TIMELINE
  Aug 17  Reserved by CNA
  Aug 25  Published (CNA: VulnCheck)
CWE-1336 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
team-alembic ash_authentication — Purpose-limited JWT accepted as full bearer authentication in AshAuthentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   P   H   H   N    7.6   .0036   28.6     —
AFFECTED
  Product             Versions                                    Fixed
  ash_authentication  3.10.5 –                                    —
  ash_authentication  eca8cadea0f1595ed2c10a0c177b1da9aa9e5269 –  8cf8b2d4426172be0900a3505e9491800b951750
TIMELINE
  Jul 22  Reserved by CNA
  Aug 25  Published (CNA: EEF)
CWE-287 · CNA: EEF · CVSS v4.0 · 5 references · NVD status: Received
Le-yan|Medical Practice Management System - Remote Code Execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   H   H   H    8.6   .0035   27.3     —
AFFECTED
  Product                             Versions   Fixed
  Medical Practice Management System  2.4.2.8 –  —
TIMELINE
  Aug 25  Reserved by CNA
  Aug 25  Published (CNA: twcert)
CWE-940 · CNA: twcert · CVSS v4.0 · 2 references · NVD status: Received
vrana adminer — Adminer before 5.4.3 Unrestricted File Upload via AdminerFileUpload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   N   N    7.1   .0034   26.8     —
AFFECTED
  Product  Versions     Fixed
  adminer  unspecified  5.4.3
TIMELINE
  Jun 22  Reserved by CNA
  Aug 25  Published (CNA: VulnCheck)
CWE-434 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-787016.526.3Red HatRed Hat Directory Server 11CWE-787389-ds-base: 389-ds-base: cve-2026-11610 incomplete fix may introduce a conne…
CVE-2026-106275.325.7netweblogicEvents Manager – Calendar, Bookings, Tickets, and more!CWE-862Events Manager <= 7.4.0 - Missing Authorization to Unauthenticated Sensitive …
CVE-2026-597698.825.5FURUNO ELECTRIC CO., LTD.FA-50CWE-798FA-50 all versions contain hard-coded credentials. An attacker, who knows the…
CVE-2026-349687.225.4vranaadminerCWE-22Adminer before 5.4.3 Arbitrary File Deletion via SQLite Drop
CVE-2026-560966.325.3TYPO3Extension "Apache Solr for TYPO3 - Enterprise Search"CWE-943Information Disclosure in extension "Apache Solr for TYPO3 - Enterprise Searc…
CVE-2026-786376.924.9Fdawgsnode-popplerCWE-74Fdawgs node-poppler Argument Injection index.js pdfUnite argument injection
CVE-2026-183237.223.2wpmudevForminator Forms – Contact Form, Payment Form & Custom Form BuilderCWE-79Forminator Forms <= 1.57.0.2 - Unauthenticated Stored Cross-Site Scripting vi…
CVE-2026-726977.122.8getgravgravCWE-22Grav CMS before 2.0.16 Path Traversal via media_directory
CVE-2026-349646.922.8vranaadminerCWE-918Adminer before 5.5.0 SSRF via PDO DSN Injection
CVE-2026-675788.722.1FURUNO ELECTRIC CO., LTD.FA-50CWE-306FA-50 all versions miss authentication for some configuration. An attacker wi…
CVE-2026-771447.122.1TYPO3Extension "Events 2"CWE-915Broken Access Control in extension "Events 2" (events2)
CVE-2026-164342.322.1vranaadminerCWE-20Adminer before 5.5.1 X-Forwarded-Prefix Backslash Bypass
CVE-2026-784779.822.0MVPThemesJawnCWE-266Jawn <= 1.4.2 - Unauthenticated Privilege Escalation
CVE-2026-785689.822.1KlbThemeTotal DonationsCWE-89Total Donations <= 2.0.5 - Unauthenticated SQL Injection
CVE-2026-198014.321.6wpdevteamBetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCPCWE-862BetterLinks <= 3.1.0 - Missing Authorization to Authenticated (Subscriber+) A…
CVE-2026-567066.121.4vranaadminerCWE-330Adminer before 5.4.3 CSRF Token Secret Recovery via XOR Masking
CVE-2026-771396.021.2TYPO3Extension "Mask"CWE-22Path Traversal in extension "Mask" (mask)
CVE-2026-667667.521.1SAP_SESAP S/4HANA (Manage Supply Protection)CWE-1333Denial of Service (DoS) in SAP S/4HANA (Manage Supply Protection)
CVE-2026-567109.320.4getgravgravCWE-863Grav Login Plugin before 1.0.16 Privilege Escalation via Unlock
CVE-2026-106304.320.3hookandhookWP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education CoursesCWE-639WP Courses LMS <= 3.2.29 - Insecure Direct Object Reference to Authenticated …
CVE-2026-783226.520.2Red HatRed Hat Enterprise Linux 6CWE-120File-roller: file-roller: stack buffer overflow in parse_progress_line for 7z…
CVE-2026-170896.119.9netweblogicEvents Manager – Calendar, Bookings, Tickets, and more!CWE-79Events Manager <= 7.4.0.1 - Reflected Cross-Site Scripting via 'header_format…
CVE-2026-786818.719.8nltknltkCWE-776NLTK before 3.10.3 Entity Expansion DoS via ElementTree
CVE-2026-786839.419.5nltknltkCWE-502NLTK before 3.10.0 Remote Code Execution via Unsafe Pickle Deserialization
CVE-2026-768398.719.0getgravgravCWE-522Grav before 2.0.16 Information Disclosure via offsetGet
CVE-2026-635878.818.5Weidmueller InterfaceIE-SR-2TX-WL-4G-EUCWE-288SMS Password Authorization Bypass via Failed Attempt Counter
CVE-2026-567098.716.9getgravgravCWE-350Grav before 3.9.2 Host Header Injection via sendInvitationEmail
CVE-2026-560946.316.9TYPO3Extension "Apache Solr for TYPO3 - Enterprise Search"CWE-943Information Disclosure in extension "Apache Solr for TYPO3 - Enterprise Searc…
CVE-2026-727008.716.7getgravgravCWE-208Grav before 3.9.1 Timing Attack via Non-Constant-Time Token Comparison
CVE-2026-771276.016.8TYPO3Extension "Modules"CWE-639Information Disclosure in extension "Modules" (modules)
CVE-2026-771468.315.8TYPO3Extension "femanager"CWE-862Broken Access Control in extension "femanager" (femanager)
CVE-2026-560957.715.7TYPO3Extension "Apache Solr for TYPO3 - Enterprise Search"CWE-502Insecure Deserialization in extension "Apache Solr for TYPO3 - Enterprise Sea…
CVE-2026-198928.815.6Infused AddonsInfusedWoo ProCWE-862InfusedWoo Pro <= 5.1.18 - Authenticated (Subscriber+) Privilege Escalation v…
CVE-2026-786828.715.5nltknltkCWE-918NLTK before 3.10.3 SSRF Protection Bypass via Proxy
CVE-2026-560936.315.1TYPO3Extension "Apache Solr for TYPO3 - Enterprise Search"CWE-639Broken Access Control in extension "Apache Solr for TYPO3 - Enterprise Search…
CVE-2026-768468.715.0getgravgravCWE-522Grav before 2.0.16 Information Disclosure via Twig Sandbox
CVE-2026-183287.215.0wpmudevForminator Forms – Contact Form, Payment Form & Custom Form BuilderCWE-79Forminator Forms <= 1.57.0 - Unauthenticated DOM-Based Cross-Site Scripting v…
CVE-2026-726987.115.0getgravgravCWE-200Grav CMS before 2.0.16 Information Disclosure via Twig Sandbox Bypass
CVE-2026-786797.115.0gitpython-developersGitPythonCWE-73GitPython before 3.1.59 Arbitrary File Read via TagReference.create
CVE-2026-567045.315.0vranaadminerCWE-79Adminer before 5.4.3 Cross-Site Scripting via MySQL Version String
CVE-2026-771418.814.8TYPO3Extension "Club Directory"CWE-639Broken Access Control in extension "Club Directory" (clubdirectory)
CVE-2026-771428.814.8TYPO3Extension "Industry Directory"CWE-639Broken Access Control in extension "Industry Directory" (yellowpages2)
CVE-2026-771438.814.8TYPO3Extension "Forum"CWE-639Broken Access Control in extension "Forum" (pforum)
CVE-2026-771408.714.8TYPO3Extension "Telephone Directory"CWE-639Broken Access Control in extension "Telephone Directory" (telephonedirectory)
CVE-2026-771348.314.8TYPO3Extension "femanager"CWE-863Broken Access Control in extension "femanager" (femanager)
CVE-2026-771358.214.8TYPO3Extension "femanager"CWE-639Information Disclosure in extension "femanager" (femanager)
CVE-2026-349675.314.5vranaadminerCWE-73Adminer sql-log Plugin 5.3.0 through 5.4.2 Arbitrary File Write
CVE-2026-185126.414.2cozmoslabsTranslatePress – Translate Multilingual sites with AI TranslationCWE-79TranslatePress <= 3.2.6 - Authenticated (Subscriber+) Stored Cross-Site Scrip…
CVE-2026-771297.714.1TYPO3Extension "Event management and registration"CWE-1336Server-Side Template Injection in extension "Event management and registratio…
CVE-2026-771377.714.1TYPO3Extension "Forms Export"CWE-89SQL Injection in extension "Forms Export" (frp_form_answers)
CVE-2026-755756.913.8RocketChatRocket.ChatCWE-204Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor Method
CVE-2026-759824.413.6thimpressLearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-862LearnPress <= 4.4.4 - Missing Authorization to Authenticated (Editor+) Limite…
CVE-2026-784706.513.4wedevsWP Project Manager ProCWE-89WP Project Manager Pro <= 4.0.1 - Authenticated (Subscriber+) SQL Injection
CVE-2026-786787.113.2gitpython-developersGitPythonCWE-88GitPython before 3.1.59 Arbitrary File Read via Repo.blame()
CVE-2026-759304.313.0roxnorFundEngine – Donation and Crowdfunding PlatformCWE-862FundEngine <= 1.8.1 - Missing Authorization to Authenticated (Subscriber+) Ar…
CVE-2026-560927.612.6TYPO3Extension "Apache Solr for TYPO3 - Enterprise Search"CWE-862Broken Access Control in extension "Apache Solr for TYPO3 - Enterprise Search…
CVE-2026-567078.312.5getgravgravCWE-862Grav Flex Objects 1.4.0 through 1.4.7 Authorization Bypass via Shortcode
CVE-2026-181006.412.4roxnorMetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for ElementorCWE-79MetForm <= 4.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting v…
CVE-2026-549200.011.5AcademySoftwareFoundationopenexrCWE-190OpenEXR: Integer overflow and uninitialized pointer cause invalid delete in O…
CVE-2026-349595.310.8vranaadminerCWE-20Adminer before 5.5.0 Open Redirect via X-Forwarded-Prefix
CVE-2026-771457.110.7TYPO3Extension "Events 2"CWE-639Broken Access Control in extension "Events 2" (events2)
CVE-2026-771336.010.7TYPO3Extension "femanager"CWE-862Broken Access Control in extension "femanager" (femanager)
CVE-2026-175485.310.7Checkmk GmbHCheckmkCWE-862Missing authorization for viewing background jobs
CVE-2026-771305.310.7TYPO3Extension "SYSSY - TYPO3 Monitoring & Security Checks"CWE-613Insufficient Session Expiration in extension "SYSSY - TYPO3 Monitoring & Secu…
CVE-2026-726999.310.4getgravgravCWE-203Grav Login Plugin before 3.9.1 Email Enumeration via Registration
CVE-2026-198517.710.3Dassault SystèmesTuleap Enterprise EditionCWE-1393Use of Default Password vulnerability affecting Tuleap Enterprise Edition fro…
CVE-2026-199436.49.9jegstudioGutenverse – WordPress Blocks, Page Builder & Site EditorCWE-79Gutenverse <= 4.0.2 - Authenticated (Contributor+) Stored Cross-Site Scriptin…
CVE-2026-750196.49.9cozythemesCozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & TemplatesCWE-79Cozy Blocks <= 2.2.16 - Authenticated (Contributor+) Stored Cross-Site Script…
CVE-2026-760636.49.9roxnorFundEngine – Donation and Crowdfunding PlatformCWE-79FundEngine <= 1.8.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting…
CVE-2026-786562.19.8itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System cust_del.php sql injection
CVE-2025-98786.49.0buildwpsPPWP – Password Protect PagesCWE-79Password Protect WordPress Lite <= 1.9.21 - Authenticated (Contributor+) Stor…
CVE-2026-785637.28.7WPDeveloperNotificationX ProCWE-79NotificationX Pro <= 3.1.4 - Unauthenticated Stored Cross-Site Scripting
CVE-2026-132156.87.8zephyrprojectzephyrCWE-787Zephyr ext2 mount: unvalidated superblock block size causes out-of-bounds wri…
CVE-2026-125616.47.4tagDivtagDiv ComposerCWE-79tagDiv Composer <= 5.4.5 - Authenticated (Contributor+) Stored Cross-Site Scr…
CVE-2026-727016.37.4getgravgravCWE-208Grav CMS before 2.0.16 Timing Attack via verifyNonce
CVE-2026-567086.96.9getgravgravCWE-367Grav API Plugin before 1.0.16 SSRF via DNS Rebinding
CVE-2026-591835.56.2AcademySoftwareFoundationopenexrCWE-190OpenEXR: Signed Integer Overflow Leading to Out-of-Bounds Memory Access in De…
CVE-2026-661098.55.5Sky Co., LTD.SKYSEA Client ViewCWE-862A missing authorization vulnerability exists in SKYSEA Client View and SKYMEC…
CVE-2026-696658.55.5Sky Co., LTD.SKYSEA Client ViewCWE-276SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect defa…
CVE-2026-784664.35.5Fluent BoarsFluent Boards ProCWE-639Fluent Boards Pro <= 2.0.11 - Authenticated (Subscriber+) Insecure Direct Obj…
CVE-2026-784674.35.5Fluent SupportFluent Support ProCWE-862Fluent Support Pro <= 2.3.1 - Missing Authorization
CVE-2026-771315.34.6TYPO3Extension "SYSSY - TYPO3 Monitoring & Security Checks"CWE-319Cleartext Transmission of Sensitive Information in extension "SYSSY - TYPO3 M…
CVE-2026-726968.63.8getgravgravCWE-59Grav CMS before 2.0.16 Symlink Following via createLockFile
CVE-2026-786381.93.3peerigonunzip-crxCWE-22peerigon unzip-crx/unzip-crx-3 Archive Extraction index.js unzip path traversal
CVE-2026-786758.62.2gitpython-developersGitPythonCWE-73GitPython before 3.1.59 Local File Content Disclosure via .gitmodules
CVE-2026-786808.52.1nltknltkCWE-426NLTK before 3.10.3 Arbitrary Code Execution via Graphviz dot Binary
CVE-2026-553716.91.8AcademySoftwareFoundationopenexrCWE-20OpenEXR: OpenEXRCore exr_attr_set_bytes() accepts NULL type_hint with positiv…
CVE-2026-553736.21.4AcademySoftwareFoundationopenexrCWE-190OpenEXR: OpenEXRUtil SampleCountChannel endEdit() can loop forever on UINT_MA…
CVE-2026-727029.31.1getgravgravCWE-346Grav CMS before 2.0.16 Origin Validation Bypass via Referer
CVE-2026-550596.11.1AcademySoftwareFoundationopenexrCWE-787OpenEXR: OpenEXRUtil SampleCountChannel row setter heap has an out-of-bounds …
CVE-2026-7619310.0—AdobeAdobe Campaign ClassicCWE-918Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
CVE-2026-7619510.0—AdobeAdobe Campaign ClassicCWE-78Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements us…
CVE-2026-7619710.0—AdobeAdobe Campaign ClassicCWE-78Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements us…
CVE-2026-7799810.0—miniorange.comSAML SSO for Joomla extension for JoomlaCWE-639Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via…
CVE-2026-650839.9—NVIDIAOpenShellCWE-184NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioni…
CVE-2026-650939.9—NVIDIAOpenShellCWE-427NVIDIA OpenShell for Linux contains a vulnerability where an attacker could c…
CVE-2026-162869.8—TRtek Technological Products Computer Software Hardware Industry and Trade Limited CompanySoftware Repository ManagementCWE-434File Upload in TRTEK Software's Software Repository Management
CVE-2026-450189.8—ChainlitchainlitCWE-78Chainlit: Command injection via MCP stdio transport allows unauthenticated re…
CVE-2026-498459.8—Apache Software FoundationApache HiveCWE-94Apache Hive: SQL Injection vulnerability in HiveMetaStore partition-name dire…
CVE-2026-555469.8—QWED-AIqwed-mcpCWE-94QWED-MCP: Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized M…
CVE-2026-785709.8—KlbThemeTotal DonationsCWE-269Total Donations <= 2.0.5 - Unauthenticated Privilege Escalation
CVE-2026-789099.6—GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a rem…
CVE-2026-789379.6—GoogleChromeCWE-416Use after free in Search in Google Chrome on on Android prior to 152.0.7977.6…
CVE-2026-789399.6—GoogleChromeCWE-416Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed …
CVE-2026-789459.6—GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a rem…
CVE-2026-789519.6—GoogleChromeCWE-416Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allow…
CVE-2026-789649.6—GoogleChromeCWE-416Use after free in Sync in Google Chrome on on iOS prior to 152.0.7977.65 allo…
CVE-2026-789839.6—GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a rem…
CVE-2026-790129.6—GoogleChromeCWE-416Use after free in Safebrowsing in Google Chrome on on Mac prior to 152.0.7977…
CVE-2026-790479.6—GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a rem…
CVE-2026-790529.6—GoogleChromeCWE-416Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remo…
CVE-2026-790549.6—GoogleChromeCWE-416Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed …
CVE-2026-790569.6—GoogleChromeCWE-416Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allow…
CVE-2026-790789.6—GoogleChromeCWE-416Use after free in FedCM in Google Chrome prior to 152.0.7977.65 allowed a rem…
CVE-2026-790919.6—GoogleChromeCWE-416Use after free in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65…
CVE-2026-791289.6—GoogleChromeCWE-416Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 all…
CVE-2026-791409.6—GoogleChromeCWE-416Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 all…
CVE-2026-791499.6—GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a rem…
CVE-2026-791509.6—GoogleChromeCWE-416Use after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 all…
CVE-2026-792009.6—GoogleChromeCWE-416Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remo…
CVE-2026-792109.6—GoogleChromeCWE-416Use after free in Audio in Google Chrome on on Android prior to 152.0.7977.65…
CVE-2026-792249.6—GoogleChromeCWE-416Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed …
CVE-2026-792329.6—GoogleChromeCWE-416Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remo…
CVE-2026-792359.6—GoogleChromeCWE-416Use after free in WebGL in Google Chrome prior to 152.0.7977.65 allowed a rem…
CVE-2026-792579.6—GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a rem…
CVE-2026-792759.6—GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a rem…
CVE-2026-792829.6—GoogleChromeCWE-416Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65…
CVE-2026-792909.6—GoogleChromeCWE-416Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remo…
CVE-2026-579099.4—WatchGuardWatchGuard AgentCWE-94WatchGuard Agent path traversal allows unauthenticated remote code execution
CVE-2022-510009.3—sparklemotionnokogiriCWE-416Nokogiri before 1.13.2 Multiple Vulnerabilities via libxml2 libxslt
CVE-2024-583779.3—sparklemotionnokogiriCWE-427Nokogiri before 1.16.5 libxml2 Dependency Update
CVE-2024-583789.3—sparklemotionnokogiriCWE-416Nokogiri before 1.16.2 Use-After-Free via xmlTextReader
CVE-2025-714079.3—sparklemotionnokogiriCWE-787Nokogiri before 1.18.3 Stack Buffer Overflow and Use-After-Free
CVE-2026-579109.3—WatchGuardWatchGuard AgentCWE-306WatchGuard Agent improper authentication allows unauthenticated remote code e…
CVE-2026-796579.3—nltknltkCWE-502NLTK before 3.10.3 Remote Code Execution via Unsafe Pickle Deserialization
CVE-2026-796759.3—nltknltkCWE-88NLTK before 3.10.3 JVM Argument Injection via Per-Call Options
CVE-2026-797749.3—wintercmswinterCWE-693Winter CMS before 1.2.13 Twig Sandbox Escape via SecurityPolicy
CVE-2026-797829.3—rclonercloneCWE-319rclone before 1.74.4 Security Token Disclosure via HTTPS to HTTP Redirect
CVE-2026-797879.3—AlluxioalluxioCWE-287Alluxio through 2.9.5 S3 REST Proxy Authentication Bypass via Unverified Requ…
CVE-2026-799119.3—TOTOLINKN600RCWE-119TOTOLINK N600R CGI cstecgi.cgi setSystemConfig stack-based overflow
CVE-2026-801049.3—eosphoros-aiDB-GPTCWE-22DB-GPT 0.8.0 Path Traversal Arbitrary File Write via Skill Upload Filename
CVE-2026-802029.3—kimaikimaiCWE-863Kimai before 2.56.0 Authorization Bypass via TimesheetVoter
CVE-2026-783799.2—Amazonstrands-agents-toolsCWE-1427Consent bypass in python_repl tool via batch kwargs forwarding in Amazon Stra…
CVE-2026-801389.2—MacWarriorclipbucket-v5CWE-78ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php…
CVE-2026-555369.1—MervinPraisonPraisonAICWE-284Browser Server WebSocket origin validation bypass via unanchored regex (patch…
CVE-2026-556409.1—cbcoutinhonextcloud-mcp-serverCWE-306Nextcloud MCP Server: Unauthenticated `POST /webhooks/nextcloud` allows arbit…
CVE-2026-628629.1—baptisteArnotypebot.ioCWE-307TypeBot: Account takeover via brute-forceable 6-digit magic-link code
CVE-2026-796649.1—lin-snowEch0CWE-613Ech0 before 4.7.3 Access Token Revocation Bypass
CVE-2022-509998.8—sparklemotionnokogiriCWE-119Nokogiri before 1.13.5 Integer Overflow via libxml2
CVE-2026-199498.8—servmaskAll-in-One WP Migration and BackupCWE-89All-in-One WP Migration and Backup <= 7.109 - Unauthenticated Second-Order SQ…
CVE-2026-241708.8—NVIDIAUnified Fabric Manager Enterprise - GACWE-287NVIDIA UFM Enterprise contains a vulnerability in the web interface authoriza…
CVE-2026-490508.8—Apache Software FoundationApache DolphinSchedulerCWE-863Apache DolphinScheduler: General user can mint admin access tokens via /acces…
CVE-2026-555418.8—MervinPraisonPraisonAICWE-862PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
CVE-2026-555858.8—QWED-AIqwed-verificationCWE-94QWED: Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
CVE-2026-556378.8—GeiserXgenieacs-mcpCWE-346genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport
CVE-2026-650918.8—NVIDIAOpenShellCWE-78NVIDIA OpenShell for all platforms contains a vulnerability where a malicious…
CVE-2026-788998.8—GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote…
CVE-2026-789448.8—GoogleChromeCWE-416Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a …
CVE-2026-789908.8—GoogleChromeCWE-416Use after free in Compositing in Google Chrome prior to 152.0.7977.65 allowed…
CVE-2026-790978.8—GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote…
CVE-2026-791198.8—GoogleChromeCWE-416Use after free in PDF in Google Chrome prior to 152.0.7977.65 allowed a remot…
CVE-2026-791878.8—GoogleChromeCWE-416Use after free in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a re…
CVE-2026-791958.8—GoogleChromeCWE-416Use after free in Script in Google Chrome prior to 152.0.7977.65 allowed a re…
CVE-2026-791978.8—GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote…
CVE-2026-791988.8—GoogleChromeCWE-416Use after free in Platform in Google Chrome prior to 152.0.7977.65 allowed a …
CVE-2026-792028.8—GoogleChromeCWE-416Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed …
CVE-2026-792448.8—GoogleChromeCWE-416Use after free in Animation in Google Chrome prior to 152.0.7977.65 allowed a…
CVE-2026-792668.8—GoogleChromeCWE-416Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a …
CVE-2026-796628.8—lin-snowEch0CWE-601Ech0 before 4.7.3 OAuth Redirect URI Validation Bypass
CVE-2026-796748.8—nltknltkCWE-73NLTK 3.10.2 Path Traversal via corpus-reader constructors
CVE-2021-479968.7—sparklemotionnokogiriCWE-119Nokogiri before 1.11.4 Multiple Vulnerabilities via libxml2
CVE-2022-509988.7—sparklemotionnokogiriCWE-476Nokogiri before 1.13.9 Multiple Vulnerabilities via libxml2
CVE-2023-543548.7—sparklemotionnokogiriCWE-476Nokogiri before 1.14.3 Null Pointer Dereference via libxml2
CVE-2025-713468.7—sparklemotionnokogiriCWE-125Nokogiri before 1.18.8 Heap Buffer Under-read via XML Schema
CVE-2025-714068.7—sparklemotionnokogiriCWE-416Nokogiri before 1.18.4 Use-After-Free via libxslt
CVE-2026-126008.7—PopplerInnodata LabsCWE-400Uncontrolled memory usage in Innodata Labs’ Poppler JPX decoderUncontrolled m…
CVE-2026-578638.7—crater-invoice-inccraterCWE-22Crater Invoice 6.0.6 Path Traversal RCE via update/unzip endpoint
CVE-2026-593358.7—Cloud FoundryUAACWE-178Case-Sensitive Authorization Check Bypass via Identity Zone ID Case Manipulat…
CVE-2026-628658.7—baptisteArnotypebot.ioCWE-73TypeBot: Arbitrary server file read via Send Email block attachment path
CVE-2026-634038.7—contribsysfaktoryCWE-248Faktory: Unrecovered panic in command handlers allows full-server denial of s…
CVE-2026-773578.7—mesop-devmesopCWE-400Mesop: DoS in /hot-reload endpoint allows unauthenticated attacker to exhaust…
CVE-2026-796588.7—lin-snowEch0CWE-400Ech0 before 5.0.1 Denial of Service via Accept-Language
CVE-2026-796658.7—lin-snowEch0CWE-862Ech0 before 4.5.1 Authorization Bypass via Session Tokens
CVE-2026-797698.7—sparklemotionnokogiriCWE-843Nokogiri before 1.19.4 Invalid Memory Read via initialize_copy_with_args
CVE-2026-797708.7—sparklemotionnokogiriCWE-1333Nokogiri before 1.19.3 ReDoS via CSS selector tokenizer
CVE-2026-800498.7—airbytehqairbyte-platformCWE-639Airbyte Platform through 2.0.0 Cross-Workspace Authorization Bypass via Calle…
CVE-2026-801918.7—GROWI, Inc.GROWICWE-862GROWI before 8.0.2 Missing Authorization on Attachment Retrieval for Unauthen…
CVE-2026-801938.7—kimaikimaiCWE-862Kimai before 2.62.0 Authorization Bypass via QuickEntry
CVE-2026-801948.7—kimaikimaiCWE-200Kimai before 2.64.0 Missing Authorization via ProjectViewController export
CVE-2026-801958.7—kimaikimaiCWE-841Kimai before 2.63.0 Team Membership Removal via API
CVE-2026-801968.7—kimaikimaiCWE-640Kimai before 2.58.0 Authentication Bypass via Password Reset Link
CVE-2026-801978.7—kimaikimaiCWE-639Kimai before 2.57.0 Improper Authorization via Favorite Endpoints
CVE-2026-801988.7—kimaikimaiCWE-693Kimai before 2.56.0 Information Disclosure via config() Twig Function
CVE-2026-128788.6—Octopus DeployCodefreshCWE-269In affected versions of the Codefresh platform an authenticated user can util…
CVE-2026-527768.6—oscal-compasscompliance-trestleCWE-184Trestle URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0…
CVE-2026-555348.6—MervinPraisonPraisonAICWE-306PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote …
CVE-2026-555398.6—MervinPraisonPraisonAICWE-306PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no aut…
CVE-2026-555578.6—That1Drifterbrowse-mcpCWE-22browse-mcp: Arbitrary file write via unconfined download and state paths
CVE-2026-555808.6—soniricomcp-shellCWE-78mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell I…
CVE-2026-754968.6—WebkulQloAppsCWE-434Webkul QloApps improper file upload validation
CVE-2026-754978.6—WebkulQloAppsCWE-89Webkul QloApps SQL injection
CVE-2026-754988.6—WebkulQloAppsCWE-89Webkul QloApps SQL injection
CVE-2026-797848.6—gemelo-aivocosCWE-470Vocos through 0.1.0 Arbitrary Code Execution via Unrestricted class_path in M…
CVE-2026-801928.6—better-authssoCWE-287better-auth SSO before 1.6.27 Domain Ownership Authentication Bypass
CVE-2026-162338.5—NILabVIEWCWE-787Out-of-Bounds Write Vulnerability in NI LabVIEW when loading VI
CVE-2026-162348.5—NILabVIEWCWE-125Out-of-Bounds Read Vulnerability in NI LabVIEW when loading VI
CVE-2026-555268.5—MervinPraisonPraisonAICWE-350PraisonAI: SSRF protection bypass in `spider_tools._host_is_blocked()` via DN…
CVE-2026-642018.5—NILabVIEWCWE-125Out-of-Bounds Read Vulnerability in NI LabVIEW when loading VI
CVE-2026-642028.5—NILabVIEWCWE-125Out-of-Bounds Read Vulnerability in NI LabVIEW when loading VI
CVE-2026-642038.5—NILabVIEWCWE-125Out-of-Bounds Read Vulnerability in NI LabVIEW when loading VI
CVE-2026-642048.5—NILabVIEWCWE-787Out-of-Bounds Write Vulnerability in NI LabVIEW when loading VI
CVE-2026-650928.5—NVIDIAOpenShellCWE-22NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker…
CVE-2026-705518.5—jfrogartifactoryCWE-918Server-Side Request Forgery Via VCS remote download in JFrog Artifactory
CVE-2026-796738.5—lin-snowEch0CWE-863Ech0 before 4.4.3 Scope Bypass via profile:read Token
CVE-2026-555818.4—soniricomcp-shellCWE-78mcp-shell: Secure Mode Allowlist Bypass via Default `/bin/bash` Executable
CVE-2026-555828.4—soniricomcp-shellCWE-78mcp-shell: Secure Mode Allowlist Bypass via Git Shell Alias
CVE-2026-796598.3—lin-snowEch0CWE-918Ech0 before 4.7.3 Server-Side Request Forgery via fetchPeerConnectInfo
CVE-2026-242628.2—NVIDIADGX SparkCWE-787NVIDIA DGX Spark contains a vulnerability in the system firmware, where a pri…
CVE-2026-242638.2—NVIDIADGX SparkCWE-476NVIDIA DGX Spark contains a vulnerability in the system firmware, where a pri…
CVE-2026-476268.2—NVIDIADGX SparkCWE-787NVIDIA DGX Spark contains a vulnerability in the system firmware, where a pri…
CVE-2026-555288.2—MervinPraisonPraisonAICWE-306praisonaiagents: AgentServer declares auth_token but never enforces it on any…
CVE-2026-555338.2—MervinPraisonPraisonAICWE-287PraisonAI: Authentication fail-open in Recipe server allows unauthenticated a…
CVE-2026-555718.2—djust-orgdjustCWE-285djust authentication bypass: a login_required / on_mount LiveView mount redir…
CVE-2026-796768.2—nltknltkCWE-22NLTK before 3.10.3 Path Traversal via Symlink Bypass
CVE-2026-797858.2—CVHub520X-AnyLabelingCWE-295X-AnyLabeling before 4.0.0-beta.9 Improper Certificate Validation in Model Do…
CVE-2026-162318.1—hbshbsCWE-79hbs vulnerable to XSS via registerAsyncHelper output-escaping bypass
CVE-2026-650818.1—NVIDIANemoClawCWE-494NVIDIA NemoClaw for Linux contains a vulnerability in its installation proces…
CVE-2026-650848.1—NVIDIANemoClawCWE-295NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process,…
CVE-2026-650988.1—NVIDIANemoClawCWE-1390NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helpe…
CVE-2026-651058.1—NVIDIANemoClawCWE-306NVIDIA NemoClaw for Linux contains a vulnerability in its inference server se…
CVE-2026-785728.1—unknownKalles AddonsCWE-502Kalles Addons <= 1.0.6 - Unauthenticated PHP Object Injection
CVE-2026-790278.1—GoogleChromeCWE-416Use after free in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a re…
CVE-2026-241698.0—NVIDIAUnified Fabric Manager Enterprise - GACWE-77NVIDIA UFM Enterprise contains a vulnerability in the plugin management API, …
CVE-2026-484177.8—AdobeAdobe Substance 3D SamplerCWE-121Substance3D - Sampler | Stack-based Buffer Overflow (CWE-121)
CVE-2026-484187.8—AdobeAdobe Substance 3D SamplerCWE-787Substance3D - Sampler | Out-of-bounds Write (CWE-787)
CVE-2026-484197.8—AdobeAdobe Substance 3D SamplerCWE-787Substance3D - Sampler | Out-of-bounds Write (CWE-787)
CVE-2026-484207.8—AdobeAdobe Substance 3D SamplerCWE-787Substance3D - Sampler | Out-of-bounds Write (CWE-787)
CVE-2026-484217.8—AdobeAdobe Substance 3D SamplerCWE-787Substance3D - Sampler | Out-of-bounds Write (CWE-787)
CVE-2026-484227.8—AdobeAdobe Substance 3D SamplerCWE-122Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122)
CVE-2026-484237.8—AdobeAdobe Substance 3D SamplerCWE-122Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122)
CVE-2026-484247.8—AdobeAdobe Substance 3D SamplerCWE-122Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122)
CVE-2026-484257.8—AdobeAdobe Substance 3D SamplerCWE-122Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122)
CVE-2026-484267.8—AdobeAdobe Substance 3D DesignerCWE-787Substance3D - Designer | Out-of-bounds Write (CWE-787)
CVE-2026-484277.8—AdobeAdobe Substance 3D DesignerCWE-787Substance3D - Designer | Out-of-bounds Write (CWE-787)
CVE-2026-484287.8—AdobeAdobe Substance 3D DesignerCWE-122Substance3D - Designer | Heap-based Buffer Overflow (CWE-122)
CVE-2026-484307.8—AdobeAdobe Substance 3D DesignerCWE-122Substance3D - Designer | Heap-based Buffer Overflow (CWE-122)
CVE-2026-484317.8—AdobeAdobe Substance 3D DesignerCWE-122Substance3D - Designer | Heap-based Buffer Overflow (CWE-122)
CVE-2026-484327.8—AdobeAdobe Substance 3D DesignerCWE-122Substance3D - Designer | Heap-based Buffer Overflow (CWE-122)
CVE-2026-484337.8—AdobeAdobe Substance 3D DesignerCWE-122Substance3D - Designer | Heap-based Buffer Overflow (CWE-122)
CVE-2026-547577.8—oscal-compasscompliance-trestleCWE-94Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-e…
CVE-2026-571707.8—oscal-compasscompliance-trestleCWE-94Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomple…
CVE-2026-650897.8—NVIDIANemoClawCWE-78NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plu…
CVE-2026-650907.8—NVIDIANemoClawCWE-78NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management comp…
CVE-2026-650967.8—NVIDIANemoClawCWE-78NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge com…
CVE-2026-650997.8—NVIDIANemoClawCWE-78NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interf…
CVE-2026-713827.8—AdobeAdobe Substance 3D SamplerCWE-787Substance3D - Sampler | Out-of-bounds Write (CWE-787)
CVE-2026-713997.8—AdobeAdobe XDCWE-120Adobe XD | Buffer Overflow (CWE-120)
CVE-2026-715647.8—AdobeAdobe Substance 3D DesignerCWE-787Substance3D - Designer | Out-of-bounds Write (CWE-787)
CVE-2026-757497.8—AdobeAdobe Substance 3D PainterCWE-787Substance3D - Painter | Out-of-bounds Write (CWE-787)
CVE-2026-757507.8—AdobeAdobe Substance 3D PainterCWE-122Substance3D - Painter | Heap-based Buffer Overflow (CWE-122)
CVE-2026-757667.8—AdobeAdobe Substance 3D PainterCWE-122Substance3D - Painter | Heap-based Buffer Overflow (CWE-122)
CVE-2026-757677.8—AdobeAdobe Substance 3D PainterCWE-122Substance3D - Painter | Heap-based Buffer Overflow (CWE-122)
CVE-2026-757687.8—AdobeAdobe Substance 3D PainterCWE-426Substance3D - Painter | Untrusted Search Path (CWE-426)
CVE-2026-757697.8—AdobeAdobe Substance 3D PainterCWE-122Substance3D - Painter | Heap-based Buffer Overflow (CWE-122)
CVE-2026-757707.8—AdobeAdobe Substance 3D PainterCWE-787Substance3D - Painter | Out-of-bounds Write (CWE-787)
CVE-2026-796557.8—Red HatRed Hat Enterprise Linux 10CWE-59Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/…
CVE-2026-799927.8—Red HatRed Hat Enterprise Linux 10CWE-78Emacs: local shell command injection through the user field in emacs tramp
CVE-2026-571717.7—oscal-compasscompliance-trestleCWE-22Trestle is vulnerable to arbitrary file write via path traversal in author ge…
CVE-2026-555327.6—MervinPraisonPraisonAICWE-346PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthe…
CVE-2026-691047.6—jfrogartifactoryCWE-862Potential unauthorized repository migration in JFrog Artifactory
CVE-2026-801827.6—OpenStackKeystoneCWE-863In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token,…
CVE-2026-801847.6—OpenStackKeystoneCWE-863In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentica…
CVE-2026-801867.6—Red HatRed Hat Enterprise Linux 10CWE-120Bluez: stack overflow in name2utf8 causes dos and potential code execution
CVE-2026-144577.5—OpenSSLOpenSSLCWE-476RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate
CVE-2026-187987.5—OpenSSLOpenSSLCWE-415QUIC Server May Trigger Double Free When Processing INITIAL Packet
CVE-2026-548747.5—OpenSSLOpenSSLCWE-405Excessive Memory Use Buffering DTLS Records for a Future Epoch
CVE-2026-550997.5—collectiveicalendarCWE-400icalendar: Algorithmic Complexity in Equality
CVE-2026-555257.5—MervinPraisonPraisonAICWE-918PraisonAI: SSRF via redirect-following in praisonaiagents web_crawl
CVE-2026-555537.5—node-modulesurllibCWE-200urllib: Cross-origin redirects preserve credential-bearing request headers, l…
CVE-2026-556207.5—GOVCERT-LUeml_parserCWE-770eml_parser: DoS via deeply nested parens in Received headers
CVE-2026-630727.5—OpenSSLOpenSSLCWE-787Heap Buffer Overflow in CMS Key Unwrapping
CVE-2026-630757.5—OpenSSLOpenSSLCWE-770QUIC ACK-only Packet Retention Can Cause Memory Exhaustion
CVE-2026-630767.5—OpenSSLOpenSSLCWE-476Invalid Pointer Dereference in CMP Server via Crafted protectionAlg
CVE-2026-650977.5—NVIDIANemoClawCWE-494NVIDIA NemoClaw for Linux contains a vulnerability in its installation script…
CVE-2026-713607.5—AdobeC2PA ToolCWE-400CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVE-2026-714427.5—AdobeC2PA ToolCWE-191CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)
CVE-2026-714437.5—AdobeC2PA ToolCWE-20CAI Content Credentials | Improper Input Validation (CWE-20)
CVE-2026-749327.5—UnknownWP Fastest Cache—WP Fastest Cache 0.9.0.3 - 1.5.0 - Unauthenticated Stored XSS via Host Header…
CVE-2026-779967.5—yootheme.comYOOtheme Pro extension for JoomlaCWE-79Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOO…
CVE-2026-785767.5—ReadablerReadablerCWE-89Readabler < 2.0.18 - Unauthenticated SQL Injection
CVE-2026-417077.4—SpringSpring SecurityCWE-294Spring Security DPoPProofJwtDecoderFactory vulnerable to DPoP Proof Replay
CVE-2026-555387.3—MervinPraisonPraisonAICWE-306PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignor…
CVE-2026-634047.3—contribsysfaktoryCWE-377Faktory: Insecure predictable /tmp/redis.conf enables local Redis config hija…
CVE-2026-750377.3—ilya-zlobintsevLACTCWE-290Polkit authentication bypass in LACT
CVE-2026-450197.2—ChainlitchainlitCWE-918Chainlit: SSRF via MCP SSE and streamable-http transports allows unauthentica…
CVE-2026-759717.2—roxnorShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo WidgetsCWE-269ShopEngine Elementor WooCommerce Builder Addon <= 4.9.4 - Authenticated (Shop…
CVE-2026-796677.2—lin-snowEch0CWE-285Ech0 before 4.4.3 Authentication Bypass via Scope Enforcement
CVE-2026-555277.1—MervinPraisonPraisonAICWE-22PraisonAI: Arbitrary file write via unsanitized `user_id` in `FileMemory.__in…
CVE-2026-555377.1—MervinPraisonPraisonAICWE-367PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webho…
CVE-2026-555407.1—MervinPraisonPraisonAICWE-22PraisonAI: [Path Traversal] agent tools escape the configured workspace via s…
CVE-2026-556097.1—ruvnetsublinear-time-solverCWE-73sublinear-time-solver: Arbitrary file write in consciousness-explorer / subli…
CVE-2026-591847.1—AcademySoftwareFoundationopenexrCWE-416OpenEXR: OpenEXRUtil FlatImageChannel row nonzero dataWindow heap OOB write
CVE-2026-591867.1—AcademySoftwareFoundationopenexrCWE-122OpenEXR: Heap out-of-bounds write in TiledRgbaInputFile via integer overflow …
CVE-2026-591877.1—AcademySoftwareFoundationopenexrCWE-122OpenEXR: exrmetrics deep pixelmode heap buffer overflow
CVE-2026-591897.1—AcademySoftwareFoundationopenexrCWE-125OpenEXR: Out-of-bounds read in DeepImageChannel::row() for non-zero dataWindo…
CVE-2026-599817.1—AcademySoftwareFoundationopenexrCWE-125OpenEXR: Heap OOB read in SampleCountChannel row when using nonzero dataWindow
CVE-2026-599827.1—AcademySoftwareFoundationopenexrCWE-190OpenEXR: DWAA InputFile AC buffer overflow on ILP32 platforms
CVE-2026-685137.1—AcademySoftwareFoundationopenexrCWE-122OpenEXR: Heap buffer overflow in PyOpenEXR from literal/prefixed RGB channel …
CVE-2026-685157.1—AcademySoftwareFoundationopenexrCWE-122OpenEXR: Heap out-of-bounds write in exrmultiview with subsampled channel union
CVE-2026-796667.1—lin-snowEch0CWE-862Ech0 before 4.4.3 Missing Authorization via dashboard log endpoints
CVE-2026-797757.1—rclonercloneCWE-129rclone Archive Backend SquashFS Parser Denial of Service
CVE-2026-797887.1—dradisdradis-ceCWE-918Dradis Community Edition 5.1.0 through 5.2.0 Server-Side Request Forgery via …
CVE-2026-800507.1—continew-orgcontinew-adminCWE-434ContiNew Admin through 4.1.0 Missing Authorization and File-Type Allowlist on…
CVE-2026-801897.1—perberleafwikiCWE-409LeafWiki 0.10.0 through 0.12.0 Uncontrolled Resource Consumption via Unbounde…
CVE-2026-650827.0—NVIDIANemoClawCWE-94NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, …
CVE-2026-796727.0—lin-snowEch0CWE-862Ech0 before 4.4.3 Authentication Bypass via Comment Panel
CVE-2026-797867.0—corootcorootCWE-601Coroot 1.20.2 through 1.24.5 Unvalidated Redirect URI in MCP OAuth Client Reg…
CVE-2026-184446.9—NILabVIEWCWE-195Integer Conversion Vulnerability Resulting in an Out of Bounds Read in NI Lab…
CVE-2026-184456.9—NILabVIEWCWE-190Integer Overflow Vulnerability Resulting in an Out of Bounds Write in NI LabVIEW
CVE-2026-539656.9—modelcontextprotocolphp-sdkCWE-400MCP PHP SDK: Unbounded SSE buffer in HttpTransport enables client-side denial…
CVE-2026-555296.9—MervinPraisonPraisonAICWE-306PraisonAI: Origin validation bypass in MCP HTTP Stream transport allows brows…
CVE-2026-750386.9—ilya-zlobintsevLACTCWE-61Predictable temporary file in /tmp allows symlink attack in LACT
CVE-2026-786846.9—vllm-projectvllmCWE-400vLLM before 0.27.0 Denial of Service via DeepStream Backend
CVE-2026-796606.9—lin-snowEch0CWE-200Ech0 before 4.7.3 Email Disclosure via Public API
CVE-2026-796616.9—lin-snowEch0CWE-770Ech0 before 4.7.3 Unauthenticated fav_count Modification
CVE-2026-796686.9—lin-snowEch0CWE-306Ech0 before 4.7.3 Unauthenticated Like Endpoint Metric Inflation
CVE-2026-797716.9—sparklemotionnokogiriCWE-401Nokogiri before 1.19.3 Memory Leak via XSLT Transform
CVE-2026-797726.9—sparklemotionnokogiriCWE-252Nokogiri before 1.19.1 Unchecked Return Value canonicalize
CVE-2026-797736.9—wintercmswinterCWE-22Winter CMS before 1.2.13 Local File Inclusion via JavaScript
CVE-2026-797766.9—rclonercloneCWE-200rclone before 1.75.0 Authentication Bypass via pprof
CVE-2026-797816.9—rclonercloneCWE-22rclone serve s3 Path Traversal via dot-dot object keys
CVE-2026-241676.8—NVIDIAUnified Fabric Manager Enterprise - GACWE-77NVIDIA UFM Enterprise contains a vulnerability in the user management compone…
CVE-2026-241686.8—NVIDIAUnified Fabric Manager Enterprise - GACWE-77NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an …
CVE-2026-555356.8—MervinPraisonPraisonAICWE-367PraisonAI: Server-Side Request Forgery via DNS rebinding bypass in webhook_ur…
CVE-2026-650866.8—NVIDIAOpenShellCWE-78NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handl…
CVE-2026-659796.7—AcademySoftwareFoundationopenexrCWE-20OpenEXR: Out-of-bounds read in HTJ2K decoder from unvalidated chunk header le…
CVE-2026-555316.5—MervinPraisonPraisonAICWE-400PraisonAI: Unauthenticated unbounded session accumulation in the PraisonAI MC…
CVE-2026-555886.5—oras-projectorasCWE-400ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Co…
CVE-2026-556186.5—GOVCERT-LUeml_parserCWE-116eml_parser: URL extraction bypass via HTML entities in URLs
CVE-2026-705506.5—jfrogartifactoryCWE-862Potential unauthorized access to private Composer repository metadata in JFro…
CVE-2026-784686.5—FluentCRMFluentCRM Pro – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM SolutionCWE-89FluentCRM Pro <= 3.1.12 - Authenticated (Author+) SQL Injection
CVE-2026-185476.4—ultimatememberUltimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership PluginCWE-79Ultimate Member <= 2.12.1 - Authenticated (Subscriber+) Stored Cross-Site Scr…
CVE-2026-628616.4—baptisteArnotypebot.ioCWE-639TypeBot: Cross-tenant custom-domain removal via unbound `name` in handleDelet…
CVE-2026-761286.4—implecodeeCommerce Product CatalogCWE-79eCommerce Product Catalog <= 3.5.10 - Authenticated (Contributor+) Stored Cro…
CVE-2026-797176.4—Red HatRed Hat Ansible Automation Platform 2CWE-918Galaxy_ng: galaxy_ng: blind ssrf via namespace avatar_url with no private-add…
CVE-2026-444766.3—doorkeeper-gemdoorkeeper-openid_connectCWE-287Doorkeeper OpenID Connect: Dynamic Client Registration feature creates public…
CVE-2026-788856.3—liketrekTREKCWE-287liketrek TREK OIDC Service oidcService.ts findOrCreateUser improper authentic…
CVE-2026-788866.3—liketrekTREKCWE-22liketrek TREK Public Journey Photo Proxy journey-public.controller.ts path tr…
CVE-2026-788876.3—liketrekTREKCWE-285liketrek TREK Journey Photo Proxy validateShareTokenForAsset authorization
CVE-2026-801996.3—kimaikimaiCWE-208Kimai before 2.54.0 Username Enumeration via Timing Oracle
CVE-2026-714446.2—AdobeC2PA ToolCWE-191CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)
CVE-2026-761896.2—AdobeC2PA ToolCWE-191CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)
CVE-2026-132166.1—zephyrprojectzephyrCWE-787Out-of-bounds stack write in Zephyr virtio PCI driver from unvalidated device…
CVE-2026-555306.1—MervinPraisonPraisonAICWE-862PraisonAI: ast_grep_rewrite rewrites arbitrary files without the @require_app…
CVE-2026-242256.0—NVIDIADGX SparkCWE-125NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where…
CVE-2026-476246.0—NVIDIADGX SparkCWE-693NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause …
CVE-2026-797786.0—rclonercloneCWE-248rclone before v1.75.0 Denial of Service via TUS nil-response panic
CVE-2026-797796.0—rclonercloneCWE-319rclone before v1.75.0 WebDAV Credential Exposure via HTTPS-to-HTTP Redirect
CVE-2026-797806.0—rclonercloneCWE-200rclone before v1.75.0 Credential Exposure via S3 Redirect
CVE-2026-132175.9—zephyrprojectzephyrCWE-476NULL-pointer dereference in Zephyr OCPP CALLRESULT parsing via unchecked strt…
CVE-2026-326375.9—velero-ioveleroCWE-22Velero vulnerable to file path traversal when extracting from backup's tarball
CVE-2026-630745.9—OpenSSLOpenSSLCWE-770CMP Indefinite Cache Growth of ExtraCerts
CVE-2026-796525.9—Red HatRed Hat Build of KeycloakCWE-862Keycloak-services: keycloak-services: jwt bearer authorization grant does not…
CVE-2026-800515.9—graphql-go projectgraphql-goCWE-1287github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not validat…
CVE-2026-801855.7—Red HatRed Hat Enterprise Linux 10CWE-843Bluez: sdp-xml: bluez 5.86: unprivileged-local and adjacent-le-peer leads to …
CVE-2026-556635.6—versaticamediasoupCWE-345mediasoup: SCTP state cookie lacks cryptographic authentication, enabling una…
CVE-2026-650875.6—NVIDIANemoClawCWE-522NVIDIA NemoClaw contains a vulnerability where an attacker could cause insuff…
CVE-2026-134785.5—zephyrprojectzephyrCWE-125Out-of-bounds read in Zephyr ext2 block-bitmap validation from a crafted s_bl…
CVE-2026-484295.5—AdobeAdobe Substance 3D DesignerCWE-476Substance3D - Designer | NULL Pointer Dereference (CWE-476)
CVE-2026-599835.5—AcademySoftwareFoundationopenexrCWE-125OpenEXR: Out-of-bounds read in DeepTiledInputFile sample-count table decode o…
CVE-2026-599845.5—AcademySoftwareFoundationopenexrCWE-787OpenEXR: Scratch buffer overflow decoding B44-compressed InputFile on ILP32
CVE-2026-599855.5—AcademySoftwareFoundationopenexrCWE-125OpenEXR: Heap out-of-bounds read in OpenEXRCore RLE decoding on ILP32
CVE-2026-615555.5—AcademySoftwareFoundationopenexrCWE-125OpenEXR: Empty multiView viewFromChannelName file crash
CVE-2026-647055.5—ApplemacOSCWE-120A buffer overflow was addressed with improved bounds checking. This issue is …
CVE-2026-650885.5—NVIDIANemoClawCWE-214NVIDIA NemoClaw contains a vulnerability where an attacker could cause invoca…

Results continue: ranks 401–787.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-25 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.