boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Wednesday, August 26, 2026 · all times UTC← 2026-08-25 · archive

Security Box Score — August 26, 2026

CISA adds 7 to KEV; 394 CVEs published, led by Linux (92).

394 CVEs published August 26, 2026: 68 critical, 149 high, 95 medium, 16 low; 1 in the KEV catalog at press time; 2 with a public exploit reference; 66 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 369 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1084033073——
KEV catalog size1682

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

1861 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux15093824401191463711120.17.8.0016+705 ▲
google4012163274833872617760.37.5.0026+282 ▲
microsoft4691891145128145114287281.57.8.0044-194 ▼
red hat2116044325127732200.06.8.0029+94 ▲
apple44316598416578882.56.5.0029+41 ▲
freebsd324843383000.07.8.0015+32 ▲
canonical15421311135000.07.8.0020+8 ▲
suse52651461000.08.1.0039-3 ▼
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco46842139240561315.57.5.0044+31 ▲
ubiquiti2359362210335.19.1.0049-2 ▼
palo alto networks12371321121325.44.7.0020-2 ▼
netgear93200275000.04.3.0025+3 ▲
fortinet7307814128620.07.0.0050-6 ▼
vmware21949427210.58.1.0040-6 ▼
f50175930415.98.7.0057-8 ▼
sonicwall1214374017214.37.8.0024+10 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache156493102214163133320.47.5.0048+53 ▲
mozilla591866868500900.08.1.0030-12 ▼
gitlab2273216469422.75.3.0029+15 ▲
drupal1768107465411.55.9.0024-29 ▼
github5171790000.06.6.00430
docker290630000.07.2.0016+2 ▲
wordpress2513102240.08.8.31200
kubernetes010001000.02.4.0035-1 ▼
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle89022694841170519962840.27.8.0034-219 ▼
ibm3746031442801718610.27.6.0030+337 ▲
adobe984004420114961930.87.8.0026+3 ▲
progress19611437100611.68.1.0037-9 ▼
solarwinds0231733010417.49.1.0058-15 ▼
veeam131961030100.08.6.0032+12 ▲
zohocorp4103520000.08.7.0140+1 ▲
atlassian3615001300.08.1.00340
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
siemens203622383000.07.3.0016+13 ▲
d-link163615597300.07.4.0157+8 ▲
rockwell automation12541830000.08.7.0029-16 ▼
synology12426133000.05.6.0025+1 ▲
schneider electric091620000.08.6.00370
abb070430000.07.2.0018-1 ▼
hikvision060420000.07.2.0040-5 ▼
mitsubishi electric050410000.07.2.00520
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell711701189655210.67.2.0019+28 ▲
sourcecodester48168009276000.05.5.0029-1 ▼
nvidia521341688300000.07.8.0034+11 ▲
splunk110128647705110.86.5.0025+107 ▲
openclaw01110583914000.07.0.0026-44 ▼
getgrav661041559282000.08.4.0032+29 ▲
zephyrproject501033335611000.06.4.0021+27 ▲
spring24103240583000.06.5.0022+24 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.995799.99.8
CVE-2026-34486.986299.97.5
CVE-2026-63077.847399.79.8
CVE-2026-60004.824099.69.8
CVE-2026-72898.792299.610.0
CVE-2026-18577.540798.98.2
CVE-2026-59310.458898.79.8
CVE-2026-18556.401698.58.2
CVE-2026-64638.312098.18.9
CVE-2026-66066.278697.99.5
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.7922KEV
CVE-2026-4836210.0.0431
CVE-2026-1918810.0.0193
CVE-2026-5823110.0.0171
CVE-2026-6983610.0.0155
CVE-2026-7619510.0.0147
CVE-2026-7619710.0.0147
CVE-2026-7329910.0.0121
CVE-2026-7367810.0.0114
CVE-2026-7755410.0.0099
Most disclosures (vendor)
VendorCVEs
linux1515
oracle890
google777
microsoft471
ibm442
red hat251
apache217
adobe111
splunk110
siyuan-note73
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco13
apple8
fortinet6
google6
ivanti5
oracle4
solarwinds4
adobe3
berriai3
Most-affected ecosystems
EcosystemAdvisories
Maven58
Packagist26
PyPI14
npm12
Go1
Fastest to KEV
CVEVendorDays
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20316Cisco0
CVE-2026-20349Cisco0
CVE-2026-34486Apache Software Foundation0
CVE-2026-63077JetBrains0
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
CVE-2026-72898Metabase0
CVE-2026-8037Progress Software0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171743
CVE-2021-27102n/a2021-11-171743
CVE-2021-27101n/a2021-11-171743
CVE-2021-27103n/a2021-11-171743
CVE-2021-21017Adobe2021-11-171743
CVE-2021-28550Adobe2021-11-171743
CVE-2021-42013Apache Software Foundation2021-11-171743
CVE-2021-41773Apache Software Foundation2021-11-171743
CVE-2021-30858Apple2021-11-171743
CVE-2021-30860Apple2021-11-171743

Transactions

ADDED TO KEV — CVE-2015-3246. Remediation due September 9, 2026.

ADDED TO KEV — CVE-2015-5287. Remediation due September 9, 2026.

ADDED TO KEV — CVE-2019-1068 (Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)). Remediation due August 29, 2026.

ADDED TO KEV — CVE-2021-23758 (AjaxPro.2). Remediation due September 9, 2026.

ADDED TO KEV — CVE-2022-0995 (kernel). Remediation due September 9, 2026.

ADDED TO KEV — CVE-2026-60004 (Gitea). Remediation due August 28, 2026.

ADDED TO KEV — CVE-2026-8452 (NetScaler ADC). Remediation due August 29, 2026.

EXPLOIT PUBLISHED — axios: 14 CVEs (CVE-2026-25639, CVE-2026-40175, CVE-2026-42033, CVE-2026-42039, CVE-2026-42041, CVE-2026-42043, CVE-2026-42044, CVE-2026-44486, CVE-2026-44487, CVE-2026-44488, CVE-2026-44492, CVE-2026-44494, CVE-2026-44495, CVE-2026-44496). Public exploit references added.

EXPLOIT PUBLISHED — dolibarr: 4 CVEs (CVE-2026-71504, CVE-2026-71506, CVE-2026-71509, CVE-2026-71511). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2021-47983 (mra13 Accept Stripe Payments). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2024-14041 (Legion of the Bouncy Castle Inc. BC-JAVA). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-59693. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-59694. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-59695. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-59696. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-59697. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-59698. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-59699. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-59700. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-59701. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-59702. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-59703. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-59704. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-59705. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-21901 (Juniper Networks Junos OS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-22306 (Ozols Grupa OZOLS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-24049 (pypa wheel). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-26278 (NaturalIntelligence fast-xml-parser). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-29063 (immutable-js). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-33487 (russellhaering goxmldsig). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-41242 (protobufjs protobuf.js). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-45137 (solana-foundation anchor). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-45736 (websockets ws). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-46625 (js-cookie). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-50151 (oras-project oras-go). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54344 (ToolJet). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54673 (electron-userland electron-builder). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-58192 (appium). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-58500 (appium-mcp). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-59151 (prowler-cloud prowler). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-59723 (cline). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-59887 (markdown-it linkify-it). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-60004 (Gitea). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-65053 (horde imp). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-6732 (Red Hat Hardened Images). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-72703 (rocq-prover rocq). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-72705 (rocq-prover rocq). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-74932 (Unknown WP Fastest Cache). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76071 (Netis Systems NC63). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-77681 (CodeAstro Online Job Portal). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-77946 (TRENDnet TEW-821DAP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78049 (Systerel S2OPC). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78054 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78056 (sambitraj Student-Management-System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78060 (SourceCodester Stock Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78115 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78122 (Tecnativa docker-socket-proxy). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78141 (Tenda CH22). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78144 (code-projects Barangay Resident Profiling Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78166 (provectus kafka-ui). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78168 (EFM ipTIME T24000M). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78171 (itsourcecode Sales and Inventory System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78181 (ractivejs ractive). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78185 (itsourcecode Sales and Inventory System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78198 (SourceCodester Simple Online Food Ordering System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78201 (itsourcecode Payroll System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78244 (itsourcecode Real Estate Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78247 (SourceCodester Simple Online Food Ordering System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78250 (bytebot-ai bytebot). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78435 (Faveo Helpdesk). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78638 (peerigon unzip-crx). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-79623 (FishCodeTech Muteki). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-79792 (zackees transcribe-anything). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-79793 (code-projects Online Shopping System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-79845 (code-projects Simple Inventory System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-79911 (TOTOLINK N600R). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-79912 (TOTOLINK N600R). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-80182 (OpenStack Keystone). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-80184 (OpenStack Keystone). Public exploit reference added.

DUE DATE PASSED — CVE-2026-68820 (Microsoft Windows 10 Version 1607). CISA remediation deadline was August 25, 2026; still in catalog.

REJECTED — CVE-2026-74234 (Legora). Record withdrawn by the CNA.

REJECTED — CVE-2026-78466 (Fluent Boars Fluent Boards Pro). Record withdrawn by the CNA.

REJECTED — CVE-2026-78467 (Fluent Support Pro). Record withdrawn by the CNA.

REJECTED — CVE-2026-78468 (FluentCRM Pro – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution). Record withdrawn by the CNA.

RESCORED — Oracle Corporation Oracle Reports Developer: 6 CVEs (CVE-2026-62613, CVE-2026-62623, CVE-2026-62631, CVE-2026-62637, CVE-2026-70670, CVE-2026-70674). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2025-59700. CVSS 5.8 → 3.9 (NVD).

RESCORED — CVE-2025-59704. CVSS 7.8 → 4.6 (NVD).

RESCORED — CVE-2026-16708 (IBM Db2 Mirror for i). CVSS 8.3 → 7.5 (NVD).

RESCORED — CVE-2026-19582 (Red Hat Migration Toolkit for Containers). CVSS 7.8 → 0 (NVD).

RESCORED — CVE-2026-4932 (IBM PowerVM Hypervisor). CVSS 4.2 → 4.6 (NVD).

RESCORED — CVE-2026-54344 (ToolJet). CVSS 4.7 → 8.8 (NVD).

RESCORED — CVE-2026-58192 (appium). CVSS 8.6 → 10 (NVD).

RESCORED — CVE-2026-5917 (libgit2). CVSS 9.4 → 8.6 (NVD).

RESCORED — CVE-2026-70715 (Oracle Corporation Oracle Autonomous Health Framework). CVSS 8.8 → 6.8 (NVD).

RESCORED — CVE-2026-70717 (Oracle Corporation Oracle Autonomous Health Framework). CVSS 7.7 → 6.7 (NVD).

RESCORED — CVE-2026-7868 (IBM OPENBMC). CVSS 6.5 → 8.8 (NVD).

RESCORED — CVE-2026-8058 (IBM OPENBMC). CVSS 4.5 → 4.9 (NVD).

PATCH SHIPPED — Red Hat Advanced Cluster Management for Kubernetes 2.11: 29 CVEs (CVE-2026-10090, CVE-2026-18874, CVE-2026-64927, CVE-2026-66780, CVE-2026-66781, CVE-2026-66792, CVE-2026-66793, CVE-2026-66878, CVE-2026-67567, CVE-2026-70398, CVE-2026-70495, CVE-2026-70496, CVE-2026-71468, CVE-2026-71469, CVE-2026-71470, CVE-2026-71471, CVE-2026-71472, CVE-2026-71473, CVE-2026-71474, CVE-2026-71845, CVE-2026-71846, CVE-2026-72508, CVE-2026-72526, CVE-2026-73122, CVE-2026-73137, CVE-2026-73834, CVE-2026-75485, CVE-2026-76139, CVE-2026-76827). Fix versions published.

PATCH SHIPPED — Adobe Acrobat DC: 22 CVEs (CVE-2026-47911, CVE-2026-47912, CVE-2026-47913, CVE-2026-47914, CVE-2026-47915, CVE-2026-47916, CVE-2026-47917, CVE-2026-47918, CVE-2026-47919, CVE-2026-47920, CVE-2026-47921, CVE-2026-47923, CVE-2026-47924, CVE-2026-47925, CVE-2026-47926, CVE-2026-47937, CVE-2026-47952, CVE-2026-47955, CVE-2026-47959, CVE-2026-47961, CVE-2026-47965, CVE-2026-48373). Fix versions published.

PATCH SHIPPED — Adobe InDesign Desktop: 12 CVEs (CVE-2026-34695, CVE-2026-34696, CVE-2026-34697, CVE-2026-34698, CVE-2026-34699, CVE-2026-34700, CVE-2026-34701, CVE-2026-34702, CVE-2026-34703, CVE-2026-34704, CVE-2026-34705, CVE-2026-48293). Fix versions published.

PATCH SHIPPED — Adobe Content Credentials Rust SDK: 8 CVEs (CVE-2026-34657, CVE-2026-34711, CVE-2026-34712, CVE-2026-34713, CVE-2026-47902, CVE-2026-47903, CVE-2026-47904, CVE-2026-47905). Fix versions published.

PATCH SHIPPED — Adobe ColdFusion 2025: 7 CVEs (CVE-2026-47928, CVE-2026-47929, CVE-2026-47930, CVE-2026-47931, CVE-2026-47932, CVE-2026-47933, CVE-2026-47960). Fix versions published.

PATCH SHIPPED — Adobe Dreamweaver Desktop: 5 CVEs (CVE-2026-47906, CVE-2026-47907, CVE-2026-47908, CVE-2026-47909, CVE-2026-47910). Fix versions published.

PATCH SHIPPED — Adobe Substance 3D Sampler: 4 CVEs (CVE-2026-34709, CVE-2026-34710, CVE-2026-48305, CVE-2026-48306). Fix versions published.

PATCH SHIPPED — Adobe Experience Manager 6.5 LTS: 3 CVEs (CVE-2026-34691, CVE-2026-34693, CVE-2026-34694). Fix versions published.

PATCH SHIPPED — Adobe InCopy: 3 CVEs (CVE-2026-34706, CVE-2026-34707, CVE-2026-34708). Fix versions published.

PATCH SHIPPED — CVE-2026-15218 (Red Hat OpenShift AI 3.4). Fixed in Red Hat OpenShift AI 3.4 1787153683.

PATCH SHIPPED — CVE-2026-15378 (Red Hat OpenShift AI 3.4). Fixed in Red Hat OpenShift AI 3.4 1787360218.

PATCH SHIPPED — CVE-2026-47927 (Adobe DNG Software Development Kit (SDK)). Fixed in Adobe DNG Software Development Kit (SDK) 1.7.1.2611.

PATCH SHIPPED — CVE-2026-47934 (Adobe DNG Software Development Kit (SDK)). Fixed in Adobe DNG Software Development Kit (SDK) 1.7.1.2611.

PATCH SHIPPED — CVE-2026-47938 (Adobe Campaign Classic). Fixed in Adobe Campaign Classic ACC v7: 7.4.3 build 9396.

PATCH SHIPPED — CVE-2026-47963 (Adobe DNG Software Development Kit (SDK)). Fixed in Adobe DNG Software Development Kit (SDK) 1.7.1.2611.

PATCH SHIPPED — CVE-2026-47964 (Adobe DNG Software Development Kit (SDK)). Fixed in Adobe DNG Software Development Kit (SDK) 1.7.1.2611.

PATCH SHIPPED — CVE-2026-48267 (Adobe DNG Software Development Kit (SDK)). Fixed in Adobe DNG Software Development Kit (SDK) 1.7.1.2611.

PATCH SHIPPED — CVE-2026-48291 (Adobe Format Plugins). Fixed in Format Plugins 1.1.3.

PATCH SHIPPED — CVE-2026-48292 (Adobe Format Plugins). Fixed in Format Plugins 1.1.3.

PATCH SHIPPED — CVE-2026-48303 (Adobe Campaign Classic). Fixed in Adobe Campaign Classic ACC v7: 7.4.3 build 9396.

PATCH SHIPPED — CVE-2026-48389 (Adobe DNG Software Development Kit (SDK)). Fixed in Adobe DNG Software Development Kit (SDK) 1.7.1.2611.

PATCH SHIPPED — CVE-2026-4897 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:125-4.el10_2.1.

PATCH SHIPPED — CVE-2026-71467 (Red Hat Advanced Cluster Management for Kubernetes 2.17). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.17 1787229541.

PATCH SHIPPED — CVE-2026-71475 (Red Hat Advanced Cluster Management for Kubernetes 2.13). Fixed in Red Hat Advanced Cluster Management for Kubernetes 2.13 1787259125.

Yesterday's Results

How to read these box scores · glossary

394 CVEs published. 25 box scores, 369 table rows — nothing truncated.

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .8240   99.6   YES
AFFECTED
  Product  Versions  Fixed
  Gitea    1.17 –    —
TIMELINE
  Jul 8   Reserved by CNA
  Aug 26  Added to CISA KEV, due Aug 28
  Aug 26  Public exploit reference published
  Aug 26  Published (CNA: mitre)
CWE-94 · CNA: mitre · CVSS v3.1 · 5 references · NVD status: Analyzed · KEV due August 28, 2026
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elemen…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0219   81.1     —
AFFECTED
  Product                  Versions     Fixed
  Cloud Disaster Recovery  unspecified  —
TIMELINE
  Aug 4   Reserved by CNA
  Aug 26  Published (CNA: dell)
CWE-78 · CNA: dell · CVSS v3.1 · 1 reference · NVD status: Received
TeamViewer Full Client — Command Injection in TeamViewer Desktop Client for Linux through Chat Link Handling
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0200   79.3     —
AFFECTED
  Product      Versions  Fixed
  Full Client  15.0 –    —
  Host         15.0 –    —
TIMELINE
  Aug 6   Reserved by CNA
  Aug 26  Published (CNA: TV)
CWE-78 · CNA: TV · CVSS v3.1 · 1 reference · NVD status: Received
LibreNMS: Remote Code Execution by Signal Alert Transportation Module
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0113   64.0     —
AFFECTED
  Product   Versions               Fixed
  librenms  >= 21.6.0, < 26.5.0 –  —
TIMELINE
  Jun 16  Reserved by CNA
  Aug 26  Published (CNA: GitHub_M)
CWE-77 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Received
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0106   62.2     —
AFFECTED
  Product           Versions     Fixed
  PowerProtect One  unspecified  —
TIMELINE
  Aug 16  Reserved by CNA
  Aug 26  Published (CNA: dell)
CWE-78 · CNA: dell · CVSS v3.1 · 1 reference · NVD status: Received
Ubiquiti Inc UniFi Protect Application — A malicious actor with access to the network and low privileges could exploit an Improper Input Validation …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0101   60.8     —
AFFECTED
  Product                    Versions     Fixed
  UniFi Protect Application  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 26  Published (CNA: Ubiquiti)
CWE-20 · CNA: Ubiquiti · CVSS v3.1 · 1 reference · NVD status: Received
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elemen…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0101   60.6     —
AFFECTED
  Product                  Versions     Fixed
  Cloud Disaster Recovery  unspecified  —
TIMELINE
  Aug 4   Reserved by CNA
  Aug 26  Published (CNA: dell)
CWE-78 · CNA: dell · CVSS v3.1 · 1 reference · NVD status: Received
Ubiquiti Inc UniFi Talk Application — A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0099   60.0     —
AFFECTED
  Product                 Versions     Fixed
  UniFi Talk Application  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 26  Published (CNA: Ubiquiti)
CWE-20 · CNA: Ubiquiti · CVSS v3.1 · 1 reference · NVD status: Received
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0098   59.7     —
AFFECTED
  Product           Versions     Fixed
  PowerProtect One  unspecified  —
TIMELINE
  Jul 31  Reserved by CNA
  Aug 26  Published (CNA: dell)
CWE-78 · CNA: dell · CVSS v3.1 · 1 reference · NVD status: Received
Ubiquiti Inc UniFi Protect Application — A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0094   58.5     —
AFFECTED
  Product                    Versions     Fixed
  UniFi Protect Application  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 26  Published (CNA: Ubiquiti)
CWE-20 · CNA: Ubiquiti · CVSS v3.1 · 1 reference · NVD status: Received
Ubiquiti Inc UniFi Enterprise Audio/Video Bridge — A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0089   56.9     —
AFFECTED
  Product                              Versions     Fixed
  UniFi Enterprise Audio/Video Bridge  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 26  Published (CNA: Ubiquiti)
CWE-20 · CNA: Ubiquiti · CVSS v3.1 · 1 reference · NVD status: Received
Ubiquiti Inc UniFi Network Application — A malicious actor with access to the network and high privileges could exploit an Improper Input Validation…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0081   54.3     —
AFFECTED
  Product                    Versions     Fixed
  UniFi Network Application  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 26  Published (CNA: Ubiquiti)
CWE-20 · CNA: Ubiquiti · CVSS v3.1 · 1 reference · NVD status: Received
Ubiquiti Inc UniFi OS Server — A malicious actor with access to the network and high privileges could exploit an Improper Input Validation…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0081   54.3     —
AFFECTED
  Product          Versions     Fixed
  UniFi OS Server  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 26  Published (CNA: Ubiquiti)
CWE-20 · CNA: Ubiquiti · CVSS v3.1 · 1 reference · NVD status: Received
Ubiquiti Inc UniFi OS Server — A malicious actor with access to the network and high privileges could exploit an Improper Input Validation…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0081   54.3     —
AFFECTED
  Product          Versions     Fixed
  UniFi OS Server  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 26  Published (CNA: Ubiquiti)
CWE-20 · CNA: Ubiquiti · CVSS v3.1 · 1 reference · NVD status: Received
Ubiquiti Inc UID Enterprise Agent — A malicious actor with access to the network and high privileges could exploit an Improper Input Validation…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0081   54.3     —
AFFECTED
  Product               Versions     Fixed
  UID Enterprise Agent  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 26  Published (CNA: Ubiquiti)
CWE-20 · CNA: Ubiquiti · CVSS v3.1 · 1 reference · NVD status: Received
Ubiquiti Inc UniFi Access Application — A malicious actor with access to the network and low privileges could exploit an Improper Input Validation …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0080   54.1     —
AFFECTED
  Product                   Versions     Fixed
  UniFi Access Application  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 26  Published (CNA: Ubiquiti)
CWE-20 · CNA: Ubiquiti · CVSS v3.1 · 1 reference · NVD status: Received
Ubiquiti Inc UniFi Access Application — A malicious actor with access to the network and low privileges could exploit an Improper Input Validation …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0080   54.1     —
AFFECTED
  Product                   Versions     Fixed
  UniFi Access Application  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 26  Published (CNA: Ubiquiti)
CWE-20 · CNA: Ubiquiti · CVSS v3.1 · 1 reference · NVD status: Received
Ubiquiti Inc UniFi Access Application — A malicious actor with access to the network and low privileges could exploit an Improper Input Validation …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0080   54.1     —
AFFECTED
  Product                   Versions     Fixed
  UniFi Access Application  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 26  Published (CNA: Ubiquiti)
CWE-20 · CNA: Ubiquiti · CVSS v3.1 · 1 reference · NVD status: Received
Ubiquiti Inc UniFi Protect Application — A malicious actor with access to the network and low privileges could exploit an Improper Input Validation …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0080   54.1     —
AFFECTED
  Product                    Versions     Fixed
  UniFi Protect Application  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 26  Published (CNA: Ubiquiti)
CWE-20 · CNA: Ubiquiti · CVSS v3.1 · 1 reference · NVD status: Received
cozmoslabs TranslatePress – Translate Multilingual sites with AI Translation — TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0079   53.5     —
AFFECTED
  Product                                                            Versions     Fixed
  TranslatePress – Translate Multilingual sites with AI Translation  unspecified  —
TIMELINE
  Aug 12  Reserved by CNA
  Aug 26  Published (CNA: Wordfence)
CWE-640 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
SENAITE.CORE: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') and Missing Authorization in senaite.core
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0078   53.2     —
AFFECTED
  Product       Versions              Fixed
  senaite.core  >= 2.0.0, <= 2.6.0 –  —
TIMELINE
  Jun 15  Reserved by CNA
  Aug 26  Published (CNA: GitHub_M)
CWE-95, CWE-862 · CNA: GitHub_M · CVSS v3.1 · 5 references · NVD status: Received
Strategy11 Formidable Charts — Formidable Charts <= 2.0.1 - Unauthenticated Arbitrary File Read via 'frm_graph' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0069   50.1     —
AFFECTED
  Product            Versions     Fixed
  Formidable Charts  unspecified  —
TIMELINE
  Jul 16  Reserved by CNA
  Aug 26  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
Thinking Software Technology|EFence - Arbitrary File Upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0068   49.6     —
AFFECTED
  Product  Versions     Fixed
  EFence   unspecified  —
TIMELINE
  Aug 26  Reserved by CNA
  Aug 26  Published (CNA: twcert)
CWE-434 · CNA: twcert · CVSS v4.0 · 2 references · NVD status: Deferred
wedevs ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce — ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0067   49.4     —
AFFECTED
  Product                                                         Versions     Fixed
  ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce  unspecified  —
TIMELINE
  Jul 28  Reserved by CNA
  Aug 26  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
themefusion Avada (Fusion) Builder — Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0064   48.0     —
AFFECTED
  Product                                              Versions     Fixed
  Avada (Fusion) Builder                               unspecified  —
  Avada | Website Builder For WordPress & WooCommerce  unspecified  —
TIMELINE
  Jul 30  Reserved by CNA
  Aug 26  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-759778.847.3kitae-parkMang Board WPCWE-269Mang Board WP <= 2.3.7 - Authenticated (Subscriber+) Privilege Escalation to …
CVE-2026-802338.647.1CAYIN TechnologyCAYIN CMS-WSCWE-434CAYIN Technology|CAYIN CMS-WS/CMS-SE/SMP - Arbitrary File Upload
CVE-2026-580959.846.2FreeBSDFreeBSDCWE-122ppp(8): incorrect length calculation in mp_Enddisc()
CVE-2026-580969.846.2FreeBSDFreeBSDCWE-130ppp(8): missing length validation in LcpDecodeConfig()
CVE-2026-802378.745.9Thinking Software TechnologyEfenceCWE-434Thinking Software Technology|Efence - Arbitrary File Upload
CVE-2026-96686.345.2ZTESCPCWE-89SQL injection vulnerability in ZTE SCP product
CVE-2026-596839.345.1CalcProgrammer1OpenRGBCWE-73OpenRGB: local and remote system compromise via arbitrary file write using at…
CVE-2020-15874await44.3n/an/a—An issue was discovered in LibreNMS 1.65. A remote authenticated attacker wit…
CVE-2026-747379.844.2LinuxLinux—net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG
CVE-2026-656419.343.4VeeamOneCWE-288A vulnerability allowing an unauthenticated network attacker to coerce SMB au…
CVE-2026-747469.843.3LinuxLinux—netfilter: flowtable: publish GC-visible tuple last
CVE-2026-731088.742.5rustdeskrustdeskCWE-770RustDesk < 1.4.7 Uncontrolled Memory Allocation DoS via BytesCodec
CVE-2026-805289.842.0LinuxLinux—ceph: avoid fs reclaim while using current->journal_info
CVE-2026-805589.842.0LinuxLinux—libceph: Avoid using invalid osd indices from primary_temp
CVE-2026-805619.842.0LinuxLinux—libceph: fix multiple unsafe decodes in decode_locker()
CVE-2026-747439.841.9LinuxLinux—macvlan: inherit needed_headroom and needed_tailroom from lowerdev
CVE-2026-747449.841.9LinuxLinux—ipvlan: inherit needed_headroom and needed_tailroom from phy_dev
CVE-2026-804289.341.8ILIAS-eLearning e.V.ILIASCWE-502ILIAS before 9.22, 10.10 and 11.3 Unauthenticated PHP Object Injection via Sh…
CVE-2026-803488.741.7TarsCloudTarsWebCWE-862TarsWeb through 3.0.16 Missing Authorization on Patch Deploy, Download and De…
CVE-2026-596828.841.6CalcProgrammer1OpenRGBCWE-73Arbitrary file overwrite and deletion local and remote in OpenRGB
CVE-2026-805277.541.2LinuxLinux—ceph: fix hanging __ceph_get_caps() with stale mds_wanted
CVE-2026-748517.240.9UnknownPodsCWE-94Pods < 3.3.9.1 - Author+ RCE via Shortcode Display Callback
CVE-2026-187948.838.6CalcProgrammer1OpenRGBCWE-1288OpenRGB: insufficient input data checks lead to Denial-of-Service, memory ove…
CVE-2026-747427.538.4LinuxLinux—veth: fix queue index used to wake the peer txq in veth_poll
CVE-2026-630415.338.0Apache Software FoundationApache APISIXCWE-807Apache APISIX: attach-consumer-label does not strip client-supplied consumer-…
CVE-2026-656478.737.9WebProsPlesk MigratorCWE-59Improper symlink resolution before file access in Plesk allows remote authent…
CVE-2026-584748.637.8Andyyyy64whichllmCWE-94whichllm < 0.5.16 Code Injection via run and snippet commands
CVE-2026-803499.337.6TarsCloudTarsWebCWE-290TarsWeb through 3.0.14 Authentication Bypass via Spoofed X-Forwarded-For and …
CVE-2026-127179.437.5Google CloudBigQuery Data Transfer ServiceCWE-74Remote Code Execution in BigQuery Data Transfer Service via JDBC Connection S…
CVE-2026-747417.537.4LinuxLinux—net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling
CVE-2026-805199.837.2LinuxLinux—ovpn: finish crypto callback cleanup before peer release
CVE-2026-747529.836.2LinuxLinux—sctp: validate cookie AUTH state before use
CVE-2026-805207.535.9LinuxLinux—ovpn: fix NULL dereference when killing missing key
CVE-2026-7755010.035.6Ubiquiti IncUniFi OS ServerCWE-93A malicious actor with access to the network could exploit an Improper Neutra…
CVE-2026-656428.635.5WebProsPleskCWE-639Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 th…
CVE-2025-109036.535.1GitLabGitLabCWE-835Loop with Unreachable Exit Condition ('Infinite Loop') in GitLab
CVE-2026-802148.634.8librenmslibrenmsCWE-78LibreNMS Virtualisation Discovery Module RCE
CVE-2026-188847.534.4wpgenieWooCommerce LotteryCWE-89WooCommerce Lottery <= 2.2.9 - Unauthenticated Time-Based SQL Injection via '…
CVE-2026-142166.534.2UnknownBooking for Appointments and Events CalendarCWE-287Amelia < 2.4.7 - Unauthenticated Notification Queue Dispatch
CVE-2026-805869.833.4LinuxLinux—mptcp: options: reset DSS fields in case of unexpected size
CVE-2026-545239.633.1kyvernokyvernoCWE-862Kyverno: NamespacedGeneratingPolicy generator.apply() namespace argument unva…
CVE-2026-197607.233.1emrevonaWP Fastest Cache – WordPress Cache PluginCWE-79WP Fastest Cache <= 1.5.0 - Unauthenticated Stored Cross-Site Scripting via H…
CVE-2026-802346.933.1CAYIN TechnologyCAYIN CMS-WSCWE-306CAYIN Technology|CAYIN CMS-WS/CMS-SE - Missing Authentication
CVE-2026-812025.533.1itsourcecodePayroll SystemCWE-287itsourcecode Payroll System CRUD Operation ajax.php delete missing authentica…
CVE-2026-463697.532.1nimiqcore-rs-albatrossCWE-193Nimiq: Validity store off by one error
CVE-2026-810307.132.0mage-aimage-aiCWE-22Mage AI through 0.9.79 Arbitrary File Read via Unvalidated Path in browser_it…
CVE-2026-802039.331.6getgravgravCWE-863Grav before 1.0.18 Authentication Bypass via Scoped API Key
CVE-2026-803467.131.6StarRocksStarRocksCWE-862StarRocks through 4.0.13 Missing Authorization on DROP MATERIALIZED VIEW for …
CVE-2026-757977.731.0UnknownAI EngineCWE-22AI Engine 3.3.3 - 3.7.1 - Subscriber+ Arbitrary File Read via 'url' Parameter
CVE-2026-805579.830.8LinuxLinux—libceph: fix OOB read in decode_watchers() via missing bounds check
CVE-2026-802058.730.7nltknltkCWE-1333NLTK before 3.10.0 ReDoS via Text.findall() unvalidated regex
CVE-2026-545507.430.5izpackizpackCWE-22IzPack: Path Traversal in UnpackerBase allows writing files outside the insta…
CVE-2026-805899.830.4LinuxLinux—block: stop the timeout timer when releasing a never added disk
CVE-2026-802368.830.0Thinking Software TechnologyEfenceCWE-89Thinking Software Technology|Efence - SQL Injection
CVE-2026-183317.230.0strategy11teamFormidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & MoreCWE-79Formidable Forms <= 6.33.1 - Unauthenticated Stored Cross-Site Scripting via …
CVE-2026-805879.829.2LinuxLinux—mptcp: avoid combining some incoming suboptions
CVE-2026-152039.328.9DanfossiC7-Automation SPCWE-1191Debug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 …
CVE-2026-747457.528.7LinuxLinux—eth: bnxt: avoid deadlock when canceling IRQ affinity notifier
CVE-2026-747507.528.7LinuxLinux—ovpn: defer key slot crypto freeing to workqueue
CVE-2026-6595610.028.61Panel-devKubePiCWE-306KubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover …
CVE-2026-546068.528.1JiHong88suneditorCWE-79SunEditor: DOM XSS in SunEditor Embed Plugin via External Script Element Afte…
CVE-2026-195388.228.2NLnet LabsNSDCWE-290Bypass of BLOCKED ACL items on proxy protocol port over TCP or TLS
CVE-2026-631794.927.8wintercmswinterCWE-22Winter: Local File Inclusion through @import directives in LESS compilation o…
CVE-2026-759608.727.7RentlySmart HomeCWE-522Insufficiently Protected Credentials in Rently Smart Home
CVE-2026-810286.927.8ZLMediaKitZLMediaKitCWE-22ZLMediaKit downloadFile Root-Directory Confinement Bypass via Prefix Collision
CVE-2026-61786.427.6MuffinGroupBethemeCWE-79Betheme <= 28.4 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…
CVE-2026-778016.527.1GitLabGitLabCWE-770Allocation of Resources Without Limits or Throttling in GitLab
CVE-2026-776938.726.8UnknownOrder Tip for WooCommerceCWE-73Order Tip for WooCommerce < 1.6.0 - Shop Manager+ Arbitrary File Deletion via…
CVE-2026-805887.526.5LinuxLinux—mptcp: reclaim forward-allocated memory on RX path errors
CVE-2026-182527.326.4GitLabGitLabCWE-829Inclusion of Functionality from Untrusted Control Sphere in GitLab
CVE-2026-169846.526.4UnknownPrivacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer TemplatesCWE-284WP Legal Pages < 3.7.1 - Unauthenticated API Secret Disclosure
CVE-2026-747519.426.3LinuxLinux—riscv: lib: Fix ZBB strnlen reading past count boundary
CVE-2026-542457.626.3fleetdmfleetCWE-89Fleet: SQL injection in Okta conditional access endpoint allows host-controll…
CVE-2026-545535.426.2jowilfstarlette-adminCWE-200Starlette-Admin: Unvalidated `order_by` parameter allows ordering by hidden c…
CVE-2026-194018.225.7NLnet LabsNSDCWE-400Remote UDP DoS by sending multiple DNS Cookie options
CVE-2026-189166.925.7NLnet LabsNSDCWE-191Remote TCP DoS by throttling the TCP receive window
CVE-2026-775579.825.5Ubiquiti IncUniFi Protect AI KeyCWE-284A malicious actor with access to the network could exploit an Improper Access…
CVE-2026-796544.325.2Red HatRed Hat Satellite 6CWE-639Ketello: katello content view history api cross-organization authorization by…
CVE-2026-159858.124.9RadiusThemeClassified Listing - Mobile Number VerificationCWE-289Classified Listing - Mobile Number Verification <= 1.6.0 - Unauthenticated Au…
CVE-2026-145505.324.9UnknownWPCafeCWE-862WPCafe < 3.0.18 - Unauthenticated Reservation Approval Bypass via Missing Aut…
CVE-2026-192266.824.4UnknownRoyal Addons for ElementorCWE-79Royal Elementor Addons < 1.7.1066 - Contributor+ Stored XSS via Image Accordi…
CVE-2026-805859.424.0LinuxLinux—mptcp: fastopen: only mark MPTFO subflows with SYN data
CVE-2026-799218.923.9rabbitmqamqp091-goCWE-770amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Co…
CVE-2026-617927.723.9WeblateOrgweblateCWE-22Weblate path traversal allows a project administrator to read arbitrary files…
CVE-2026-186648.223.8NLnet LabsNSDCWE-284Wrong interpretation of ACL ranges
CVE-2026-810318.623.6iduraridurar-erp-crmCWE-639IDURAR ERP CRM through 4.1.1 Account Takeover via Unverified Identifier on Pa…
CVE-2026-131725.323.1UnknownEventinCWE-862Eventin < 4.1.22 - Unauthenticated Unpublished Content Disclosure
CVE-2026-134065.323.1UnknownRoyal Addons for ElementorCWE-862Royal Elementor Addons < 1.7.1066 - Unauthenticated Taxonomy Term Disclosure
CVE-2026-546144.323.1cakephpdebug_kitCWE-470DebugKit: MailPreview contains unsafe reflection
CVE-2026-810368.522.9stalwartlabsstalwartCWE-601Stalwart Mail Server through 0.16.19 Authorization Code Disclosure via Unvali…
CVE-2026-660037.122.9frappefrappeCWE-863Frappe: Access control bypass via REST API dot-notation fields on linked doct…
CVE-2026-545118.622.8dahlialogtapeCWE-93@logtape/syslog: syslog log injection via unescaped control characters and un…
CVE-2026-749287.522.8UnknownProject ManagerCWE-862WP Project Manager 2.1.0 - 4.0.6 - Unauthenticated Subscriber Account Creatio…
CVE-2026-39275await22.6n/an/a—Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows …
CVE-2026-478417.422.5SpringSpring Security—WebAuthn User Verification Bypass via Session Serialization
CVE-2026-192717.522.4TÜBİTAK BİLGEM Software Technologies Research InstituteLiderahenkCWE-90Blind LDAP Injection in Sign-In Endpoint in TÜBİTAK BİLGEM's Liderahenk
CVE-2026-545568.222.3http4shttp4sCWE-409Http4s: HTTP/2 Denial of Service with Ember Backend
CVE-2026-775499.022.2Ubiquiti IncUniFi OS ServerCWE-93A malicious actor with access to the network and under certain conditions cou…
CVE-2026-810298.522.1open-metadataOpenMetadataCWE-601OpenMetadata before 2.0.0 JWT Disclosure via Unvalidated SAML and OIDC Redire…
CVE-2026-731026.921.3rustdeskrustdeskCWE-22RustDesk Path Traversal via macOS Clipboard File-Paste
CVE-2026-134045.321.1UnknownRoyal Addons for ElementorCWE-639Royal Elementor Addons < 1.7.1066 - Unauthenticated Like Count and IP Meta Mo…
CVE-2026-169865.321.1UnknownBooking PackageCWE-284Booking Package < 1.7.25 - Unauthenticated Price Manipulation via Service and…
CVE-2026-810329.321.0vesoft-incnebulaCWE-306NebulaGraph through 3.8.0 Unauthenticated Read and Modification of Runtime Co…
CVE-2026-772988.721.0seaweedfsseaweedfsCWE-863SeaweedFS S3 OIDC Bearer authentication bypasses IAM role trust policy
CVE-2026-197188.121.0UnknownBlogVault Backup & StagingCWE-287BlogVault, MalCare and WP Remote 5.16 - 6.62 - Unauthenticated Site Takeover …
CVE-2026-814216.920.8ddfourtwosentry-selfhosted-mcpCWE-918ddfourtwo sentry-selfhosted-mcp raw_sentry_api server-side request forgery
CVE-2026-810278.420.6songquanpengone-apiCWE-862one-api through 0.6.10 Missing Authorization on URL-Parameter Channel Pinning
CVE-2026-656468.720.5WebProsPleskCWE-74Improper neutralization of special elements in Plesk allows remote authentica…
CVE-2026-803507.120.6OneUptimeOneUptimeCWE-918OneUptime before 12.0.7 Server-Side Request Forgery via IPv4-Mapped IPv6 Webh…
CVE-2026-810336.920.5automatischautomatischCWE-204Automatisch through 0.15.0 User Enumeration via Forgot-Password Response Disc…
CVE-2026-478376.820.4SpringSpring Cloud ConfigCWE-306Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Requests
CVE-2026-190945.320.3UnknownTutor LMSCWE-89Tutor LMS < 4.0.6 - Unauthenticated SQLi via 'offset' and 'item_per_page' Par…
CVE-2026-688637.519.9DellPowerProtect OneCWE-121Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buf…
CVE-2026-810357.219.9midday-aimiddayCWE-862Midday Missing Owner Check on Team Deletion
CVE-2026-326396.819.9wintercmswinterCWE-289Winter: Broken access control in `Cms\Controllers\Index` allows cross-templat…
CVE-2026-803478.719.6kazuphmcp-fetchCWE-918mcp-fetch through 1.6.3 Server-Side Request Forgery via Unstripped IPv6 Liter…
CVE-2026-142124.719.5UnknownBooking for Appointments and Events CalendarCWE-639Amelia Pro < 9.8 - Provider+ Arbitrary Provider Password Update via IDOR
CVE-2020-15878await19.5n/an/a—An issue was discovered in LibreNMS 1.65. A remote authenticated attacker wit…
CVE-2025-56798await19.6n/an/a—Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Un…
CVE-2026-633607.419.1LimeSurveyLimeSurveyCWE-79LimeSurvey Community Edition 7.0.5 - Reflected XSS in user activation confirm…
CVE-2026-775329.618.8Ubiquiti IncEdgeMAX EdgeSwitchCWE-122A malicious actor with access to an adjacent network could exploit a Buffer O…
CVE-2026-777545.318.9UnknownKirkiCWE-200Kirki < 6.0.14 - Unauthenticated User and Comment Author Email Disclosure via…
CVE-2026-777585.318.9UnknownStripe Payment Forms by WP Full PayCWE-200Stripe Payment Forms by WP Full Pay < 8.5.1 - Unauthenticated Customer Portal…
CVE-2026-463706.518.8fleetdmfleetCWE-89Fleet has observer-level enrollment secret extraction via ORDER BY oracle on …
CVE-2026-478517.517.7SpringSpring AICWE-674Unbounded recursion over attacker-controlled PDF outline tree in Spring AI PD…
CVE-2026-30026.417.7jegstudioGutenverse – WordPress Blocks, Page Builder & Site EditorCWE-79Gutenverse <= 4.0.2 - Authenticated (Contributor+) Stored Cross-Site Scriptin…
CVE-2026-812035.517.8SourceCodesterSimple Online Food Ordering SystemCWE-74SourceCodester Simple Online Food Ordering System ajax.php login2 sql injection
CVE-2026-159738.417.5LimeSurveyLimeSurveyCWE-79LimeSurvey 7.0.5 - Stored XSS in Survey Menu Entries
CVE-2026-164447.517.1TeamViewerFull Client, Host, QuickSupport & PortableCWE-73Improper Validation of File Paths in TeamViewer Desktop Clients
CVE-2026-775419.117.0Ubiquiti IncUniFi Network ApplicationCWE-284A malicious actor with access to the network and high privileges could exploi…
CVE-2026-777575.416.7UnknownDirectorist: AI-Powered Business Directory, Listings & Classified AdsCWE-22Directorist 8.5 - 8.9.2 - Subscriber+ Arbitrary Image Move via REST v2 Listin…
CVE-2026-617904.416.6WeblateOrgweblateCWE-284Weblate: Team-enforced 2FA is bypassed for global permissions
CVE-2026-354457.116.5wintercmswinterCWE-285Winter: Authenticated backend users can bypass Users controller permission ch…
CVE-2026-476658.716.3penpotpenpotCWE-79Penpot: Stored XSS via comment content, innerHTML renders unsanitized HTML
CVE-2026-487866.516.3fleetdmfleetCWE-200Fleet: Observer-class users can view team enroll secrets and credential-beari…
CVE-2026-478616.316.3SpringSpring IntegrationCWE-918UDP adapter sends ack to attacker-supplied host:port parsed from packet body,…
CVE-2026-802068.216.1nltknltkCWE-1333NLTK 3.10.2 Regular Expression Denial of Service via tgrep
CVE-2026-616177.716.0pterodactylwingsCWE-400Pterodactyl Wings SFTP write path does not enforce disk quota, allowing node-…
CVE-2026-623266.516.0WeblateOrgweblateCWE-400Weblate Has Uncontrolled Resource Consumption via
CVE-2026-478625.416.1SpringSpring IntegrationCWE-22ZipTransformer uses file_name header to build workDirectory path without sani…
CVE-2026-125878.615.3ResamaniaVirtuagymCWE-798Embedded credentials in Virtuagym
CVE-2026-168097.215.3LimeSurveyLimeSurveyCWE-79LimeSurvey Community Edition 7.0.5 - Stored XSS in quota message rendering
CVE-2026-659304.815.3LimeSurveyLimeSurveyCWE-79LimeSurvey Community Edition 7.0.5 - Stored XSS in replacement-fields
CVE-2026-30355.514.8GitLabGitLabCWE-288Authentication Bypass Using an Alternate Path or Channel in GitLab
CVE-2026-757985.314.7UnknownAI EngineCWE-862AI Engine 3.4.0 - 3.7.1 - Unauthenticated Arbitrary AI Query Execution via Ed…
CVE-2026-776945.314.7UnknownEventinCWE-862Eventin < 4.1.19 - Unauthenticated Order Completion Without Payment via order…
CVE-2026-691295.814.61Panel-devKubePiCWE-639KubePi: Insufficient per-cluster authorization checks in cluster management APIs
CVE-2026-478745.314.6SpringReactor NettyCWE-770Reactor Netty HTTP Server Denial of Service With Pipelined Requests
CVE-2026-32355.314.5peterschulznlWP Data Access – App Builder for Tables, Forms, Charts, Maps & DashboardsCWE-639WP Data Access – No-Code App Builder with Tables, Forms, Charts & Maps <= 5.5…
CVE-2026-775075.314.6WeblateOrgweblateCWE-200Weblate: Object-scoped RSS feeds disclose private change history to unauthori…
CVE-2026-478606.514.2SpringSpring AMQP—Unbounded decompression of attacker-supplied compressed message bodies
CVE-2026-23886.414.2designextremeReviews and Rating – Google ReviewsCWE-79Reviews and Rating – Google Reviews <= 5.10 - Authenticated (Contributor+) St…
CVE-2026-478566.314.3SpringSpring IntegrationCWE-502JsonToObjectTransformer resolves the json__TypeId__ message header to an arbi…
CVE-2026-581081.214.0EricssonCodeCheckerCWE-284Personal access token delete filters on Session columns while deleting from P…
CVE-2026-775349.913.9Ubiquiti IncUniFi OS ServerCWE-284A malicious actor with access to the network and low privileges could exploit…
CVE-2026-775369.913.9Ubiquiti IncUniFi OS ServerCWE-284A malicious actor with access to the network and low privileges could exploit…
CVE-2026-775539.913.9Ubiquiti IncUniFi Access ApplicationCWE-284A malicious actor with access to the network and low privileges could exploit…
CVE-2026-758969.113.9TÜBİTAK BİLGEM Software Technologies Research InstituteLiderahenkCWE-798Use of Hard-coded LDAP Credentials in TÜBİTAK BİLGEM's Liderahenk
CVE-2026-750629.213.7GooglelangfunCWE-95Eval Injection in google/langfun via default lf.query protocol
CVE-2026-804267.013.8voxel51fiftyoneCWE-79FiftyOne before 1.21.0 Stored Cross-Site Scripting via Unescaped Field Descri…
CVE-2026-781466.513.7UnknownSimple Newsletter PluginCWE-200Noptin < 4.3.3 - Unauthenticated Subscriber PII and confirm_key Disclosure vi…
CVE-2020-15876await13.8n/an/a—An issue was discovered in LibreNMS 1.65. A remote authenticated attacker wit…
CVE-2026-756014.313.7static-web-serverstatic-web-serverCWE-306Static Web Server: Authentication bypass on /metrics endpoint when --basic-au…
CVE-2026-74873.513.6GitLabGitLabCWE-1280Access Control Check Implemented After Asset is Accessed in GitLab
CVE-2026-552288.113.2WeblateOrgweblateCWE-639Weblate:: WebIDOR in GroupViewSet allows authenticated project manager to gai…
CVE-2026-194859.313.1Google CloudVertex AI Search for CommerceCWE-330Bucket Squatting in Vertex AI Search for Commerce
CVE-2026-801837.113.1OpenStackKeystoneCWE-843In OpenStack Keystone before 29.0.3, any authenticated user holding role:read…
CVE-2026-775388.213.0Ubiquiti IncUniFi Connect ApplicationCWE-284A malicious actor with access to the network could exploit an Improper Access…
CVE-2026-75411await12.9n/an/a—JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode comp…
CVE-2026-478575.912.6SpringReactor CoreCWE-190Reactor Core windowTimeout fair-backpressure stream hang due to 20-bit index …
CVE-2026-478635.912.6SpringReactor CoreCWE-835Reactor Core bufferTimeout fair-backpressure pipeline permanently hangs when …
CVE-2026-776117.112.5seaweedfsseaweedfsCWE-863SeaweedFS: Authenticated S3 object-scope bypass in PutObjectAcl allows overwr…
CVE-2026-775519.012.3Ubiquiti IncUniFi Connect Display Cast ProCWE-284A malicious actor with access to the network and under certain conditions cou…
CVE-2026-773178.112.4seaweedfsseaweedfsCWE-863SeaweedFS: SFTP path ACL literal prefix match permits cross-tenant file read …
CVE-2026-36851await12.4n/an/a—Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitra…
CVE-2026-799387.612.2DellPower Protect Cyber RecoveryCWE-287Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper…
CVE-2026-463716.512.2fleetdmfleetCWE-89Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on App…
CVE-2026-498096.512.2DellPower Protect Cyber RecoveryCWE-89Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Imprope…
CVE-2026-580977.812.1FreeBSDFreeBSDCWE-122ppp(8): missing length validation in mp_SetEnddisc()
CVE-2026-153652.411.9vivoKids ModeCWE-841A pop-up logic flaw in a certain feature of Kids Mode allows users to bypass …
CVE-2026-52103await11.9n/an/a—A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notif…
CVE-2026-710546.511.9Oracle CorporationOracle Java SECWE-770Vulnerability in Oracle Java SE (component: 2D). Supported versions that are …
CVE-2026-776956.511.9UnknownReturn Refund and Exchange For WooCommerceCWE-284Woo Refund And Exchange Lite < 4.6.4 - Unauthenticated Guest Order Message Di…
CVE-2026-322578.111.8wintercmswinterCWE-79Winter: Stored XSS through Brand Settings custom styles
CVE-2026-322588.111.8wintercmswinterCWE-79Winter: Stored XSS through Editor Settings custom styles
CVE-2026-773687.611.8seaweedfsseaweedfsCWE-639SeaweedFS: Authenticated Cross-Prefix IDOR in Filer TUS Handler Enables Arbit…
CVE-2026-775459.011.7Ubiquiti IncUniFi OS ServerCWE-489A malicious actor with access to the network, low privileges and under certai…
CVE-2026-749304.311.4UnknownProject ManagerCWE-639WP Project Manager 2.2.0 - 4.0.6 - Subscriber+ User Activity Feed Disclosure …
CVE-2026-646328.510.7VeeamONECWE-522A vulnerability allowing a low-privileged user to capture the NTLM credential…
CVE-2026-153874.310.8GitLabGitLabCWE-349Acceptance of Extraneous Untrusted Data With Trusted Data in GitLab
CVE-2026-761488.410.6SASAKI NobuyukiCorvusSKKCWE-94CorvusSKK contains a code injection vulnerability, which may lead to arbitrar…
CVE-2026-50926.410.5wpsoulGreenshift – animation and page builder blocksCWE-79Greenshift <= 12.8.9 - Authenticated (Contributor+) Stored Cross-Site Scripti…
CVE-2026-153662.410.3vivoKids ModeCWE-653A control logic defect in a specific built-in webpage of Kids Mode allows use…
CVE-2026-478527.510.1SpringSpring AICWE-377Predictable cache directory location allows local ONNX model substitution in …
CVE-2026-191976.310.1GrafanaGrafana OSSCWE-862Broken access control in dashboard snapshots
CVE-2026-476667.69.9penpotpenpotCWE-79Penpot: Stored XSS via custom font family name injected into a @font-face sty…
CVE-2026-478344.89.8SpringSpring Data JPA—Spring Data JPA Sort expression validation bypass
CVE-2026-777894.39.8UnknownStripe Payment Forms by WP Full PayCWE-639Stripe Payment Forms by WP Full Pay < 8.5.1 - Cross-Customer Subscription Mod…
CVE-2026-747716.59.2DellPowerProtect OneCWE-639Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization …
CVE-2026-478595.49.3SpringSpring IntegrationCWE-770Unbounded memory allocation in RFC6587SyslogDeserializer (octet-counted frami…
CVE-2026-75363await9.1n/an/a—An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute …
CVE-2026-192203.78.7UnknownForminator FormsCWE-269Forminator Forms < 1.57.1 - Unauthenticated Multisite Site Creation and Privi…
CVE-2026-77790await8.7UnknownRegistrationMagic—RegistrationMagic < 6.0.9.4 - Admin+ SQLi via 'rm_sortby' Parameter
CVE-2026-478445.38.6SpringReactor Netty—Reactor Netty HTTP Server Leaks Exception Details
CVE-2026-711724.38.0DellCloud Disaster RecoveryCWE-918Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side …
CVE-2026-412624.37.9fleetdmfleetCWE-863Fleet: Cross-Team Policy Data Exposure via Global Policy Read Endpoint
CVE-2026-552274.37.9WeblateOrgweblateCWE-203Observable object existence disclosure in private Weblate projects via global…
CVE-2026-622494.37.9WeblateOrgweblateCWE-200Weblate: Restricted-component change history leaked to non-member project use…
CVE-2026-436218.67.7SimpleMachinesSMFCWE-863Simple Machines Forum < 2.1.7 Authorization Confusion via Profile::load()
CVE-2026-799405.97.7DelliDRAC9CWE-284Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to …
CVE-2026-749295.47.7UnknownProject ManagerCWE-284WP Project Manager < 4.0.7 - Subscriber+ Cross-Project Task Disclosure and Ta…
CVE-2026-75325await7.5n/an/a—DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsu…
CVE-2026-478504.37.5SpringSpring Data RESTCWE-915Spring Data REST allows mutation of the version property of immutable aggrega…
CVE-2025-70293await7.4n/an/a—An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vu…
CVE-2026-478455.37.2SpringReactor NettyCWE-290Reactor Netty HTTP Server may incorrectly evaluate proxy addresses
CVE-2026-74740await7.1LinuxLinux—net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain
CVE-2026-74734await6.8LinuxLinux—firewire: ohci: fix NULL pointer dereference in ar_context_release
CVE-2026-74738await6.8LinuxLinux—regmap: sdw-mbq: don't call an unset readable_reg callback
CVE-2026-75414await6.8n/an/a—In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expression…
CVE-2026-80529await6.8LinuxLinux—xfs: don't swallow dquot recovery verification errors
CVE-2026-80534await6.8LinuxLinux—xfs: fix ilock leak on error in xfs_dq_get_next_id
CVE-2026-325935.96.7wintercmswinterCWE-89Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersF…
CVE-2026-672755.36.7DellPowerProtect OneCWE-1357Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Ins…
CVE-2025-70290await6.5n/an/a—An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vu…
CVE-2026-753299.86.5n/an/aCWE-306The Netty configuration distribution service (port 8283) of super-diamond-ser…
CVE-2026-753389.86.5n/an/aCWE-284disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable …
CVE-2026-52473await6.4n/an/a—An issue in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via…
CVE-2026-75364await6.4n/an/a—Comfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30 build), the updat…
CVE-2026-75413await6.5n/an/a—DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need…
CVE-2026-485496.96.3Nagios Enterprises, LLC.Nagios CoreCWE-352Nagios Core / XI CSRF via cmd.cgi Double-Submit Cookie
CVE-2026-80525await6.3LinuxLinux—ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup
CVE-2026-80532await6.3LinuxLinux—xfs: fix another iunlink infinite loop bug in online fsck
CVE-2026-80533await6.3LinuxLinux—xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair
CVE-2026-80535await6.3LinuxLinux—xfs: don't double-lock when deleting a self-referential directory
CVE-2026-80539await6.3LinuxLinux—drm/amdgpu: disallow multiple FENCE chunks in one submit
CVE-2026-80563await6.3LinuxLinux—gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind
CVE-2026-478433.76.1SpringReactor Netty—Reactor Netty may incorrectly route traffic due to DNS resolver reuse
CVE-2026-80542await6.1LinuxLinux—drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank()
CVE-2026-80562await6.1LinuxLinux—gpio: ml-ioh: use raw_spinlock_t for the register lock
CVE-2026-80564await6.1LinuxLinux—gve: fix NULL dereference due to missing ptp adjfine
CVE-2026-80567await5.9LinuxLinux—Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue
CVE-2026-80573await5.9LinuxLinux—Input: iforce - validate input packet lengths
CVE-2026-565473.55.8HCLSoftwareTravelerCWE-20An input reflection vulnerability affects HCL Traveler
CVE-2026-74735await5.7LinuxLinux—l2tp: fix tunnel and session refcount leak on seq_file release
CVE-2026-74749await5.7LinuxLinux—rseq: Prevent hard lockup on granted time slice extension
CVE-2026-134815.45.6zephyrprojectzephyrCWE-125Out-of-bounds read in PTP management TLV TIME parsing in Zephyr net PTP
CVE-2026-134803.15.6zephyrprojectzephyrCWE-20Out-of-bounds read in LoRaWAN fragmented data block transport (FUOTA) downlin…
CVE-2026-810348.35.5gravitlnetmakerCWE-295Netmaker through 1.6.0 Improper Certificate Validation in SMTP Client
CVE-2026-80566await5.1LinuxLinux—Input: hynitron_cstxxx - validate touch count and finger IDs
CVE-2026-80577await5.1LinuxLinux—drm/panthor: skip zero-sized firmware sections
CVE-2025-70340await5.0n/an/a—A Broken Access Control vulnerability exists in ThingsBoard Professional Edit…
CVE-2026-26445await5.0n/an/a—stomper 5e2741e is vulnerable to Denial of Service. A malicious client can se…
CVE-2026-26446await5.0n/an/a—Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data …
CVE-2026-26447await5.0n/an/a—Stomper 5e2741e is vulnerable to Use-After-Free. When a single client repeate…
CVE-2026-26448await5.0n/an/a—Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple…
CVE-2026-26449await5.0n/an/a—In Stomper 5e2741e when a client sends a SEND frame missing the destination h…
CVE-2026-74754await5.0LinuxLinux—scsi: core: pair EH runtime PM get and put
CVE-2026-75334await4.9n/an/a—The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitr…
CVE-2026-80524await5.0LinuxLinux—optee: ffa: Add NULL check in optee_ffa_lend_protmem
CVE-2026-80543await5.0LinuxLinux—s390/zcrypt: Pad trailing CCA or EP11 message with zeros
CVE-2025-51679await4.9n/an/a—An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between …
CVE-2025-61165await4.9n/an/a—An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload compo…
CVE-2026-80571await4.9LinuxLinux—powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak
CVE-2026-80581await4.9LinuxLinux—ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout
CVE-2026-802049.34.8getgravgravCWE-863Grav before 1.0.18 Authentication Bypass via Scoped API Key
CVE-2026-804278.64.7nfriedlybestzipCWE-88bestzip before 2.2.6 and 3.0.x before 3.0.2 Argument Injection via Missing Op…
CVE-2026-478486.14.7SpringReactor Netty—Reactor Netty WebSocket Client Leaks Credentials On Redirect
CVE-2026-775083.54.7WeblateOrgweblateCWE-302Weblate: Unverified REST API email changes
CVE-2026-68000await4.6n/an/a—The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to S…
CVE-2026-776527.84.6GNOMEDiaCWE-122Dia: dia: heap buffer overflow in wpg colormap parser via out-of-bounds palet…
CVE-2026-134793.14.6zephyrprojectzephyrCWE-125Out-of-bounds read in LoRaWAN clock-sync AppTimeAns downlink handler
CVE-2026-299888.34.5MilesightAM102/102L V2CWE-319A cleartext transmission of sensitive information vulnerability in the NFC in…
CVE-2026-544677.04.5TrustedFirmwareTrusted Firmware-MCWE-283On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mai…
CVE-2025-29419await4.5n/an/a—CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.
CVE-2026-478426.54.4SpringSpring Security—Deterministic AES/CBC Encryption in Spring Security AesBytesEncryptor Allows …
CVE-2026-767848.74.2TP-Link Systems Inc.HS103P3 / HS103P4 v5CWE-325Insufficient Cryptographic Protections in Local Device Communication Protocol…
CVE-2026-456945.44.2librenmslibrenmsCWE-79LibreNMS: Reflected XSS in the Proxmox app view via unsanitized instance/vmid…
CVE-2026-580925.44.2FreeBSDFreeBSDCWE-288Unauthorized credential switching
CVE-2023-42179await4.1n/an/a—Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access C…
CVE-2025-61162await4.1n/an/a—Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitr…
CVE-2025-61163await4.1n/an/a—Cohere North AI v1.1.5 was discovered to contain excessively permissive cross…
CVE-2025-61164await4.1n/an/a—Cohere North AI v1.1.5 was discovered to contain an information leak via the …
CVE-2026-805519.34.0LinuxLinux—s390/vfio_ccw: Ensure first IDAW remains constant
CVE-2026-805549.34.0LinuxLinux—s390/vfio_ccw: Limit the number of channel program segments
CVE-2026-776587.84.0GNOMEDiaCWE-121Dia: dia: stack buffer overflow in bus object via unvalidated handle count in…
CVE-2026-753309.83.9n/an/aCWE-89The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} o…
CVE-2026-753369.83.9n/an/aCWE-89Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces …
CVE-2026-542565.43.9wintercmswinterCWE-284Winter: Authenticated IDOR in backend FileUpload widget allows cross-user acc…
CVE-2026-805368.43.8LinuxLinux—xfs: bounds-check buffer log item's dirty bitmap
CVE-2026-805447.83.8LinuxLinux—s390/zcrypt: Improve EP11 CPRB domain handling with ASN.1 parsing
CVE-2026-775733.53.8WeblateOrgweblateCWE-367Weblate: DNS rebinding in VCS operations allows server-side request forgery
CVE-2026-805557.13.7LinuxLinux—s390/vfio_ccw: Free all memory if cp_init() fails
CVE-2026-753329.13.6n/an/aCWE-918Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via …
CVE-2026-753409.13.6n/an/aCWE-918The device metadata import interface /device/instance/{productId}/property-me…
CVE-2026-753337.53.6n/an/aCWE-22yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as…
CVE-2026-485486.93.6Nagios Enterprises, LLC.Nagios CoreCWE-352Nagios Core CSRF via cmd.cgi
CVE-2026-747745.93.5DellPowerProtect OneCWE-295Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certi…
CVE-2025-51675await3.6n/an/a—An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate updat…
CVE-2025-61478await3.6n/an/a—An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.1…
CVE-2025-61479await3.6n/an/a—An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.1…
CVE-2025-61480await3.6n/an/a—An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.1…
CVE-2026-75327await3.6n/an/a—In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSyst…
CVE-2026-75328await3.6n/an/a—In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/c…
CVE-2026-75415await3.6n/an/a—AntFlow V2.0.0 is vulnerable to Incorrect Access Control. JiMuMDCCommonsReque…
CVE-2026-75466await3.6n/an/a—libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the…
CVE-2026-747367.83.5LinuxLinux—net/sched: cls_bpf: reject dev-bound programs bound to a different device
CVE-2026-747397.83.5LinuxLinux—net/sched: cls_u32: skip hash tables in u32_bind_class()
CVE-2026-747487.83.5LinuxLinux—netfilter: ipset: fix refcount race between list:set GC and swap
CVE-2026-796197.33.5OpenZFSOpenZFSCWE-863OpenZFS: user-namespace capability check allows unprivileged local authorizat…
CVE-2026-805507.93.4LinuxLinux—s390/vfio_ccw: Fix out of bounds check on CCW array
CVE-2026-753314.63.4n/an/aCWE-434tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS.…
CVE-2026-805457.83.3LinuxLinux—s390/zcrypt: Improve EP11 CPRB length and overflow checks
CVE-2026-805467.83.3LinuxLinux—s390/zcrypt: Improve CCA CPRB length and overflow checks
CVE-2026-805748.43.2LinuxLinux—Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet
CVE-2026-805848.43.2LinuxLinux—s390/qeth: validate user buffer length in SNMP and ARP query ioctls
CVE-2026-805498.23.2LinuxLinux—s390/vfio_ccw: Move cp cleanup out of not operational
CVE-2026-580907.83.2FreeBSDFreeBSDCWE-416Use-after-free in unix SOCK_STREAM message handling
CVE-2026-580917.83.2FreeBSDFreeBSDCWE-416Kernel use-after-free via the SNDCTL_DSP_SYNCSTART ioctl
CVE-2026-782377.83.2Admin By Request (ABR)Admin By Request (ABR)CWE-20Insufficient input validation in Admin By Request (ABR)
CVE-2026-805707.83.2LinuxLinux—Input: synaptics-rmi4 - zero report size on F54 work error
CVE-2026-761494.63.2SASAKI NobuyukiCorvusSKKCWE-190CorvusSKK contains an integer overflow vulnerability, which may allow malicio…
CVE-2026-805687.83.1LinuxLinux—Input: synaptics-rmi4 - block s_input when F54 queue is busy
CVE-2026-51106await3.1n/an/a—An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of …
CVE-2026-805528.82.8LinuxLinux—s390/vfio_ccw: Ensure index for read/write regions are within range
CVE-2026-747477.82.9LinuxLinux—ipvs: revalidate ihl to prevent out-of-bounds access
CVE-2026-805407.82.8LinuxLinux—drm/amdgpu: Fix UVD decode image min size calculation
CVE-2026-805417.82.8LinuxLinux—drm/amdgpu: validate GEM_CREATE domain combinations
CVE-2026-805597.82.8LinuxLinux—Input: sur40 - fix input device registration ordering
CVE-2026-805607.82.8LinuxLinux—openrisc: signal: do not restore privileged SR bits on sigreturn
CVE-2026-805478.82.8LinuxLinux—s390/vfio_ccw: Implement a crw lock
CVE-2026-805488.82.8LinuxLinux—s390/vfio_ccw: Selectively expand io_mutex
CVE-2026-805538.82.8LinuxLinux—s390/vfio_ccw: Cancel existing workqueues
CVE-2026-805227.82.8LinuxLinux—crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req()
CVE-2026-805267.82.8LinuxLinux—ASoC: tas2562: Validate values for volume writes
CVE-2026-805317.82.8LinuxLinux—xfs: avoid UAF on sc->tempip in xrep_tempfile_create
CVE-2026-799025.52.8GNOMEGIMPCWE-190Gimp: stack vla size underflow denial of service in seattle
CVE-2026-733354.62.8Digital AgencyAndroid App "Myna Point"CWE-939Android application "Myna Point" is vulnerable to Improper Authorization in H…
CVE-2026-747537.82.6LinuxLinux—perf: Reject exited events as group leaders
CVE-2026-805377.82.6LinuxLinux—xfs: fix off-by-one in rtrefcount btree root level validation
CVE-2026-805307.12.6LinuxLinux—xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN
CVE-2026-805567.82.5LinuxLinux—mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition
CVE-2026-805237.12.5LinuxLinux—clk: spacemit: k3: set hdma clock as critical
CVE-2026-805387.12.4LinuxLinux—xfs: propagate errors from xfs_rtginode_load
CVE-2026-805768.82.0LinuxLinux—drm/amdgpu: reject oversized IBs with per-ring packet limits
CVE-2026-805217.82.1LinuxLinux—af_unix: Unlink scc_entry in unix_del_edge().
CVE-2026-805657.82.1LinuxLinux—crypto: qce - fix error path in devm_qce_register_algs
CVE-2026-805697.82.1LinuxLinux—Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer
CVE-2026-805757.82.0LinuxLinux—Input: cs40l50-vibra - validate custom data from user space
CVE-2026-580897.82.0FreeBSDFreeBSDCWE-273hwpmc fails to detach PMCs during exec credential transitions
CVE-2026-805727.81.9LinuxLinux—Input: byd - synchronize timer deletion before freeing private data
CVE-2026-98052.71.8Insyde SoftwareInsydeH2OCWE-787FMTSWriteUseIntelLib: FMTS SMM IHISI Buffer Overflow
CVE-2026-805787.31.8LinuxLinux—fbdev: core: Fix pointer desynchronization in fb_io_read()
CVE-2026-580706.81.8VeeamBackup and ReplicationCWE-532A vulnerability that records guest OS processing credentials in cleartext in …
CVE-2025-623413.71.8HCLSoftwareConnectionsCWE-918HCL Connections is vulnerable to server-side request forgery (SSRF)
CVE-2026-805797.81.5LinuxLinux—fbdev: clear fb_info->mode before deleting a videomode
CVE-2026-805807.81.5LinuxLinux—fbdev: bound mode sysfs output to the sysfs buffer
CVE-2026-805827.81.5LinuxLinux—drm/shmem_helper: Check VMA boundaries for PMD mappings
CVE-2026-805837.81.5LinuxLinux—ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses
CVE-2026-799395.81.5DellPower Protect Cyber RecoveryCWE-61Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Sym…
CVE-2026-580947.81.4FreeBSDFreeBSDCWE-367TOCTOU race in POSIX shared memory large page configuration
CVE-2026-801585.51.0Red HatRed Hat Ceph Storage 5CWE-214Ansible-collection-community-general: community.general: ipa_getkeytab does n…
CVE-2026-218084.11.0HCLSoftwareBigFix Quantum Risk AnalyzerCWE-532HCL BigFix Quantum Risk Analyzer is affected by logging sensitive information
CVE-2026-782368.80.7Admin By Request (ABR)Admin By Request (ABR)CWE-284Insecure PIN derivation mechanism in Admin By Request (ABR)
CVE-2026-218073.90.6HCLSoftwareBigFix Quantum Risk AnalyzerCWE-121HCL BigFix Quantum Risk Analyzer is affected by a stack-based buffer overflow
CVE-2026-218093.90.5HCLSoftwareBigFix Quantum Risk AnalyzerCWE-209HCL BigFix Quantum Risk Analyzer is affected by generating error messages wit…
CVE-2026-545483.30.5siemenskasCWE-295kas: Persistent SSH Host Key Checking Disablement
CVE-2026-580937.00.5FreeBSDFreeBSDCWE-362Kernel use-after-free via tty ioctls
CVE-2026-478367.20.2SpringSpring Cloud Config—Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN
CVE-2026-218104.40.1HCLSoftwareBigFix Quantum Risk AnalyzerCWE-494HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-26 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.