boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Thursday, August 27, 2026 · all times UTC← 2026-08-26 · archive

Security Box Score — August 27, 2026

CISA adds 3 to KEV; 437 CVEs published, led by Spring (64).

437 CVEs published August 27, 2026: 65 critical, 153 high, 131 medium, 22 low; 0 in the KEV catalog at press time; 6 with a public exploit reference; 66 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 37 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1127733716——
KEV catalog size1685

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

1943 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux15093824401191463711230.17.8.0016+680 ▲
google4022164270838927737760.37.5.0026+282 ▲
microsoft4691891145128245014287281.57.8.0044-194 ▼
red hat2176104225428132200.06.8.0029+93 ▲
apple44316598516578882.56.5.0029-123 ▼
freebsd324823673000.07.8.0016+32 ▲
canonical15421311135000.07.8.0020+8 ▲
suse72851481000.07.7.0038-1 ▼
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco46842139240561315.57.5.0044+31 ▲
ubiquiti2359362210335.19.1.0049-2 ▼
palo alto networks12371321121325.44.7.0020-2 ▼
netgear93200275000.04.3.0025+3 ▲
fortinet7307814128620.07.0.0050-7 ▼
vmware21959327210.58.3.0040-6 ▼
f50175930415.98.7.0057-8 ▼
sonicwall1214374017214.37.8.0024+10 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache159496102216164133320.47.5.0049+39 ▲
mozilla591866868500900.08.1.0030-12 ▼
gitlab2576218479422.65.3.0028+18 ▲
drupal1768107465411.55.9.0024-29 ▼
github5171790000.06.6.00430
docker290630000.07.2.0016+2 ▲
wordpress2513102240.08.8.31200
kubernetes010001000.02.4.0035-1 ▼
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle89022694841170519962840.27.8.0034-219 ▼
adobe1016065030024791930.57.8.0021+6 ▲
ibm3746031442801718610.27.6.0030+337 ▲
progress19611437100611.68.1.0037-14 ▼
solarwinds0231733010417.49.1.0058-15 ▼
veeam131961030100.08.6.0032+12 ▲
zohocorp4103520000.08.7.0140+1 ▲
atlassian3615001300.08.1.00340
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
siemens213722483000.07.3.0016+14 ▲
d-link163615597300.07.4.0157+8 ▲
rockwell automation12541740000.08.4.0024-16 ▼
synology12426133000.05.6.0025+1 ▲
schneider electric091620000.08.6.00370
abb070430000.07.2.0018-1 ▼
hikvision060420000.07.2.0040-5 ▼
mitsubishi electric050410000.07.2.00520
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring911706518516000.06.3.0022+91 ▲
dell711701189655210.67.2.0019+28 ▲
sourcecodester48168009276000.05.5.0029-1 ▼
nvidia521341688300000.07.8.0034+10 ▲
splunk110128647705110.86.5.0025+107 ▲
openclaw01110583914000.07.0.0026-44 ▼
getgrav661041559282000.08.4.0032+29 ▲
zephyrproject501033335611000.06.4.0021+25 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.995799.99.8
CVE-2026-34486.986299.97.5
CVE-2026-63077.877199.89.8
CVE-2026-60004.845599.79.8
CVE-2026-72898.792299.610.0
CVE-2026-18577.540799.08.2
CVE-2026-59310.458898.89.8
CVE-2026-18556.401698.68.2
CVE-2026-64638.312098.28.9
CVE-2026-66066.278698.09.5
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.7922KEV
CVE-2026-4836210.0.0431
CVE-2026-1918810.0.0193
CVE-2026-5823110.0.0171
CVE-2026-6983610.0.0155
CVE-2026-7619510.0.0147
CVE-2026-7619710.0.0147
CVE-2026-7329910.0.0121
CVE-2026-7367810.0.0114
CVE-2026-7755410.0.0099
Most disclosures (vendor)
VendorCVEs
linux1515
oracle890
google778
microsoft470
ibm411
red hat252
apache216
splunk110
adobe104
spring97
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco13
apple8
fortinet6
google6
ivanti5
oracle4
solarwinds4
adobe3
berriai3
Most-affected ecosystems
EcosystemAdvisories
Maven58
Packagist27
PyPI14
npm12
Go1
Fastest to KEV
CVEVendorDays
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20316Cisco0
CVE-2026-20349Cisco0
CVE-2026-34486Apache Software Foundation0
CVE-2026-63077JetBrains0
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
CVE-2026-72898Metabase0
CVE-2026-8037Progress Software0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171744
CVE-2021-27102n/a2021-11-171744
CVE-2021-27101n/a2021-11-171744
CVE-2021-27103n/a2021-11-171744
CVE-2021-21017Adobe2021-11-171744
CVE-2021-28550Adobe2021-11-171744
CVE-2021-42013Apache Software Foundation2021-11-171744
CVE-2021-41773Apache Software Foundation2021-11-171744
CVE-2021-30858Apple2021-11-171744
CVE-2021-30860Apple2021-11-171744

Transactions

ADDED TO KEV — CVE-2023-49105. Remediation due August 30, 2026.

ADDED TO KEV — CVE-2026-53362 (Linux). Remediation due August 30, 2026.

ADDED TO KEV — CVE-2026-66384 (jfrog artifactory). Remediation due September 10, 2026.

EXPLOIT PUBLISHED — nltk: 4 CVEs (CVE-2026-62383, CVE-2026-62388, CVE-2026-63311, CVE-2026-66393). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2021-23758 (AjaxPro.2). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2022-0995 (kernel). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-13598 (Unknown RestrictMate). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-18252 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-2332 (Eclipse Foundation Eclipse Jetty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-29181 (open-telemetry opentelemetry-go). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-41035 (Samba rsync). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-44902 (open-telemetry opentelemetry-js). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56121 (feast-dev feast). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78435 (Faveo Helpdesk). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78638 (peerigon unzip-crx). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-79623 (FishCodeTech Muteki). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-79911 (TOTOLINK N600R). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-81202 (itsourcecode Payroll System). Public exploit reference added.

RESCORED — Google Chrome: 4 CVEs (CVE-2026-78983, CVE-2026-79054, CVE-2026-79210, CVE-2026-79224). CVSS rescored — before/after on each CVE page.

RESCORED — FreeBSD: 3 CVEs (CVE-2026-58092, CVE-2026-58095, CVE-2026-58096). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2021-23758 (AjaxPro.2). CVSS 8.1 → 9.8 (NVD).

RESCORED — CVE-2026-10573 (Rockwell Automation 1734 POINT I/O). CVSS 8.7 → 6.3 (NVD).

RESCORED — CVE-2026-13097 (Red Hat Enterprise Linux 10). CVSS 9.1 → 8.7 (NVD).

RESCORED — CVE-2026-65660 (Microsoft SharePoint Enterprise Server 2016). CVSS 6.5 → 8.8 (NVD).

RESCORED — CVE-2026-66299 (Apache Software Foundation Apache Tomcat). CVSS 7.5 → 5.3 (NVD).

RESCORED — CVE-2026-81421 (ddfourtwo sentry-selfhosted-mcp). CVSS 6.9 → 5.5 (NVD).

PATCH SHIPPED — CVE-2026-15538 (primefaces primereact). Fixed in primereact 10.9.9.

PATCH SHIPPED — CVE-2026-34621 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21411.

Yesterday's Results

How to read these box scores · glossary

437 CVEs published. 25 box scores and 375 table rows below; the remaining 37 continue on page 2 — every CVE is listed, nothing truncated.

Spring Spring Integration — Unsafe Java deserialization in SerializingHttpMessageConverter — remote code execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  L  L    6.4   .0344   88.1     —
AFFECTED
  Product             Versions  Fixed
  Spring Integration  7.1.0 –   —
TIMELINE
  May 20  Reserved by CNA
  Aug 27  Published (CNA: vmware)
CWE-502 · CNA: vmware · CVSS v3.1 · 1 reference · NVD status: Received
Zbtlink MQWrt infosrvd Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0263   84.4     —
AFFECTED
  Product       Versions   Fixed
  WE1326        19.1101 –  —
  WE2426-C      19.1112 –  —
  WE357         19.1101 –  —
  WE5926        19.1101 –  —
  WE5926-EC_QP  20.0516 –  —
  WE5926-WD     19.1101 –  —
  WE826-Q       19.1101 –  —
  WE826-T2      19.1101 –  —
  WE826-WD      19.1101 –  —
  WF3526-P      19.051 –   —
  + 6 more
TIMELINE
  Aug 14  Reserved by CNA
  Aug 27  Published (CNA: VulnCheck)
CWE-78, CWE-321 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
Zoneminder Zoneminder — OS Command Injection in PayRange API
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0232   82.0     —
AFFECTED
  Product     Versions   Fixed
  Zoneminder  1.37.48 –  1.38.3
TIMELINE
  Aug 18  Reserved by CNA
  Aug 27  Published (CNA: icscert)
CWE-78 · CNA: icscert · CVSS v4.0 · 5 references
Xiiaozet LK100W OS Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0122   66.1     —
AFFECTED
  Product          Versions     Fixed
  Xiiaozet LK100W  unspecified  2.1.240
TIMELINE
  Aug 25  Reserved by CNA
  Aug 27  Published (CNA: icscert)
CWE-78 · CNA: icscert · CVSS v4.0 · 2 references
limanmys core — Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0096   58.4     —
AFFECTED
  Product  Versions          Fixed
  core     < 2.2.2 - 1103 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Aug 27  Published (CNA: GitHub_M)
CWE-20, CWE-78 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Received
Silverstripe Advanced Workflow: Remote code execution via advanced workflow email template
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0072   51.0     —
AFFECTED
  Product                        Versions   Fixed
  silverstripe-advancedworkflow  < 6.4.5 –  —
TIMELINE
  Jun 15  Reserved by CNA
  Aug 27  Published (CNA: GitHub_M)
CWE-1336 · CNA: GitHub_M · CVSS v3.1 · 9 references · NVD status: Received
Unitree G1 EDU 1.5.2 Unauthenticated RCE via DDS Bridge and Path Traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   N   N   H   H   H    8.7   .0071   50.7     —
AFFECTED
  Product  Versions     Fixed
  G1 EDU   unspecified  —
TIMELINE
  Aug 19  Reserved by CNA
  Aug 27  Published (CNA: VulnCheck)
CWE-22, CWE-306 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
WatchGuard Dimension — Dimension SQL Injection in Scheduled Report
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0070   50.1     —
AFFECTED
  Product    Versions  Fixed
  Dimension  2.0 –     —
TIMELINE
  Aug 24  Reserved by CNA
  Aug 27  Published (CNA: WatchGuard)
CWE-502, CWE-89 · CNA: WatchGuard · CVSS v4.0 · 1 reference
WatchGuard Dimension — Dimension SQL Injection in Audit Report
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0070   50.1     —
AFFECTED
  Product    Versions  Fixed
  Dimension  2.0 –     —
TIMELINE
  Aug 24  Reserved by CNA
  Aug 27  Published (CNA: WatchGuard)
CWE-502, CWE-89 · CNA: WatchGuard · CVSS v4.0 · 1 reference
Xiiaozet LK100W Authentication Bypass Using an Alternate Path or Channel
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0067   49.2     —
AFFECTED
  Product          Versions     Fixed
  Xiiaozet LK100W  unspecified  2.1.240
TIMELINE
  Aug 25  Reserved by CNA
  Aug 27  Published (CNA: icscert)
CWE-288 · CNA: icscert · CVSS v4.0 · 2 references
AlexGladkov claude-in-mobile client.ts execSync os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    1.9   .0063   47.6     —
AFFECTED
  Product           Versions  Fixed
  claude-in-mobile  3.10.2 –  3.10.3
TIMELINE
  Aug 27  Reserved by CNA
  Aug 27  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Deferred
Volmarg Personal Management System Path Traversal via get-file Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   N   N    7.1   .0062   47.1     —
AFFECTED
  Product                     Versions     Fixed
  personal-management-system  unspecified  a0443570e105ed4835ce57f3c0a3e33d5b77418c
TIMELINE
  Apr 13  Reserved by CNA
  Aug 27  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Received
WatchGuard Dimension — Dimension SQL Injection in Log Viewer
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0061   46.3     —
AFFECTED
  Product    Versions  Fixed
  Dimension  2.0 –     —
TIMELINE
  Aug 24  Reserved by CNA
  Aug 27  Published (CNA: WatchGuard)
CWE-89 · CNA: WatchGuard · CVSS v4.0 · 1 reference
Red Hat Red Hat Enterprise Linux 10 — Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() function
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0061   46.3     —
AFFECTED
  Product                      Versions     Fixed
  Red Hat Enterprise Linux 10  unspecified  —
  Red Hat Enterprise Linux 6   unspecified  —
  Red Hat Enterprise Linux 6   unspecified  —
  Red Hat Enterprise Linux 7   unspecified  —
  Red Hat Enterprise Linux 8   unspecified  —
  Red Hat Enterprise Linux 9   unspecified  —
TIMELINE
  Aug 21  Reserved by CNA
  Aug 27  Published (CNA: redhat)
CWE-131 · CNA: redhat · CVSS v3.1 · 3 references · NVD status: Received
CVE-2026-37003AWAITING ENRICHMENT
n/a n/a — Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The Pytho…
  CVSS   EPSS    %ile   KEV
  —      .0060   46.1   —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Aug 27  Published (CNA: mitre)
CNA: mitre · 2 references · NVD status: Received
Wazuh cluster worker file sync allows arbitrary file write under /var/ossec (incomplete fix for CVE-2026-30893)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0059   45.5     —
AFFECTED
  Product  Versions              Fixed
  wazuh    >= 4.4.0, < 4.14.7 –  —
TIMELINE
  Jul 10  Reserved by CNA
  Aug 27  Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · CVSS v3.1 · 2 references
Redis TLS pending-data list use-after-free
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0059   45.3     —
AFFECTED
  Product  Versions  Fixed
  Redis    8.8.0 –   8.2.9
TIMELINE
  Aug 27  Reserved by CNA
  Aug 27  Published (CNA: cisa-cg)
CWE-416 · CNA: cisa-cg · CVSS v4.0 · 7 references · NVD status: Awaiting Analysis
mims-harvard ToolUniverse — ToolUniverse through 1.2.6 Unauthenticated Remote Code Execution via python_code_executor Sandbox Escape
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0057   44.8     —
AFFECTED
  Product       Versions     Fixed
  ToolUniverse  unspecified  —
TIMELINE
  Aug 26  Reserved by CNA
  Aug 27  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Received
Xiiaozet LK100W Missing Authentication for Critical Function
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0055   43.7     —
AFFECTED
  Product          Versions     Fixed
  Xiiaozet LK100W  unspecified  2.1.240
TIMELINE
  Aug 25  Reserved by CNA
  Aug 27  Published (CNA: icscert)
CWE-306 · CNA: icscert · CVSS v4.0 · 2 references
CVE-2026-35868AWAITING ENRICHMENT
n/a n/a — A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library…
  CVSS   EPSS    %ile   KEV
  —      .0054   43.0   —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Aug 27  Published (CNA: mitre)
CNA: mitre · 1 reference · NVD status: Received
bytedance UI-TARS-desktop — UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authentication, Exposing Arbitrary Command Execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0053   42.7     —
AFFECTED
  Product          Versions     Fixed
  UI-TARS-desktop  unspecified  c2ad42e3eb9b27830db41a3e6f51ca7179d9b168
TIMELINE
  Aug 27  Reserved by CNA
  Aug 27  Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Received
Ebyte NE2-D11 Missing Authentication for Critical Function
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0053   42.5     —
AFFECTED
  Product                 Versions        Fixed
  Ebyte NE2-D11 Firmware  FW-9167-0-11 –  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 27  Published (CNA: icscert)
CWE-306 · CNA: icscert · CVSS v4.0 · 2 references
Greenbone Greenbone OS — Stack buffer overflow in Greenbone OS and openvas-scanner
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0053   42.5     —
AFFECTED
  Product          Versions  Fixed
  Greenbone OS     5.0 –     —
  openvas-scanner  3.0 –     —
TIMELINE
  Aug 27  Reserved by CNA
  Aug 27  Published (CNA: CERTVDE)
CWE-787 · CNA: CERTVDE · CVSS v4.0 · 1 reference · NVD status: Received
CVE-2026-35869AWAITING ENRICHMENT
n/a n/a — A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library…
  CVSS   EPSS    %ile   KEV
  —      .0053   42.4   —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Aug 27  Published (CNA: mitre)
CNA: mitre · 1 reference · NVD status: Received
INFINITUM FORM Geo Controller — WordPress Geo Controller plugin <= 8.9.8 - PHP Object Injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0053   42.2     —
AFFECTED
  Product         Versions  Fixed
  Geo Controller  n/a –     8.9.9
TIMELINE
  Aug 24  Reserved by CNA
  Aug 27  Published (CNA: Patchstack)
CWE-502 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-782929.842.2hashthemesHash FormCWE-502WordPress Hash Form plugin <= 1.4.1 - PHP Object Injection vulnerability
CVE-2026-711879.341.9EbyteEbyte NE2-D11 FirmwareCWE-603Ebyte NE2-D11 Use of Client-Side Authentication
CVE-2026-810989.340.9team-telnyxtelnyx-mcpCWE-306Telnyx MCP Server through 6.83.0 Missing Authentication on Streamable HTTP Tr…
CVE-2026-782767.240.8WP Manage NinjaFluent Boards ProCWE-502WordPress Fluent Boards Pro plugin <= 2.0.11 - PHP Object Injection vulnerabi…
CVE-2026-750207.040.8Apache Software FoundationApache APISIXCWE-90Apache APISIX: ldap-auth plugin cross-subtree identity impersonation
CVE-2026-782756.840.8WP Manage NinjaFluent Boards ProCWE-22WordPress Fluent Boards Pro plugin <= 2.0.11 - Arbitrary File Deletion vulner…
CVE-2026-802127.539.9RubyresolvCWE-770An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS:…
CVE-2026-816908.739.8jahlivesopenssl_encryptCWE-59verify-usb before 1.4.9 Symlink Directory Traversal Code Execution
CVE-2026-750058.739.7Apache Software FoundationApache APISIXCWE-407Apache APISIX: Unauthenticated CPU-exhaustion DoS
CVE-2026-748487.039.7Apache Software FoundationApache APISIXCWE-444Apache APISIX: Cross-user response poisoning in serverless plugins
CVE-2026-782578.839.5magepeopleteamBooking and Rental ManagerCWE-502WordPress Booking and Rental Manager plugin <= 2.7.5 - PHP Object Injection v…
CVE-2026-814855.539.3danielpopamdlinkedin-ads-mcpCWE-22danielpopamd linkedin-ads-mcp Media Upload campaign-management.ts fs.readFile…
CVE-2026-814865.539.3bsmi021mcp-file-context-serverCWE-22bsmi021 mcp-file-context-server Path Resolution index.ts read_context path tr…
CVE-2026-815605.539.3blackmsaistackCWE-22blackms aistack Static File server.ts path traversal
CVE-2026-810938.739.1apifyactors-mcp-serverCWE-918Apify Actors MCP Server before 0.9.12 Server-Side Request Forgery via get-htm…
CVE-2026-742329.339.0ZbtlinkL3_V2_8CWE-300Zbtlink MQWrt yunmgrd Cloud C2 Implant
CVE-2026-193139.338.8WatchGuardFireware OSCWE-122Fireware OS Pre-Authentication Heap Buffer Overflow in iked Allows Remote Cod…
CVE-2026-193189.338.8WatchGuardFireware OSCWE-121Fireware OS Pre-Authentication Stack Buffer Overflow in iked Allows Remote Co…
CVE-2026-782749.138.3WP Manage NinjaFluent Boards ProCWE-434WordPress Fluent Boards Pro plugin <= 2.0.11 - Arbitrary File Upload vulnerab…
CVE-2026-546876.137.9DangerBlackn8n-node-sqlite3CWE-22n8n-nodes-sqlite3: Path traversal via user-controlled database file path (db_…
CVE-2026-193159.337.8WatchGuardFireware OSCWE-125Fireware OS Pre-Authentication Type Confusion in iked Allows Remote Code Exec…
CVE-2026-815738.637.7wibu-systems-agcodemeter-runtimeCWE-284Improper Access Control in Local-Only Configuration Commands
CVE-2026-325669.837.3ACPTACPT (Pro) - Custom Post Types Plugin for WordPressCWE-266WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.6…
CVE-2026-189658.736.7PayRangePayRange APICWE-862Missing Authorization in PayRange API
CVE-2026-130869.336.7WatchGuardFireware OSCWE-121Fireware OS Stack-Based Buffer Overflow in Mobile Security epm Endpoint
CVE-2026-815757.536.6wibu-systems-agcodemeter-runtimeCWE-130Missing Sanity Checks for Buffer Lengths
CVE-2026-59285await36.3SpringSpring for GraphQL—Spring for GraphQL Unsafe Deserialization in pagination support
CVE-2026-761799.336.1EbyteEbyte NE2-D11 FirmwareCWE-598Ebyte NE2-D11 Use of GET Request Method With Sensitive Query Strings
CVE-2026-477278.636.1TriliumNextTriliumCWE-94Trilium: RCE via `shareTemplate` relation missing `isDangerous` flag — Safe i…
CVE-2026-782717.235.7WP Manage NinjaFluentCRM ProCWE-266WordPress FluentCRM Pro plugin <= 3.1.12 - Privilege Escalation vulnerability
CVE-2026-557586.935.4cc-tweakedCC-TweakedCWE-918CC: Tweaked: Incomplete fix for GHSA-5jh9-2h63-pw4q: RFC 8215 NAT64 prefix (6…
CVE-2026-810949.335.1mcp-routermcp-routerCWE-306mcp-router CLI before 0.6.3 Binds the MCP Aggregator to All Interfaces Withou…
CVE-2026-478849.835.1SpringSpring FrameworkCWE-22Spring Framework Improper Path Limitation in XsltView
CVE-2026-813358.735.0BaserowBaserowCWE-862Baserow before 2.3.1 Unauthenticated Data Disclosure via Discarded Permission…
CVE-2026-547218.834.4silverstripesilverstripe-userformsCWE-94Silverstripe UserForms: Remote code execution via userforms email subject
CVE-2026-779919.434.3joomlaeventmanager.netJEM - Joomla Event Manager extension for JoomlaCWE-434Joomla Extension - joomlaeventmanager.net - Privileged remote code execution …
CVE-2026-817079.334.0jahlivesopenssl_encryptCWE-20openssl_encrypt before 1.4.9 ANSI Escape Injection via Identity Email
CVE-2026-814915.533.9boxpositronwith-context-mcpCWE-22boxpositron with-context-mcp index.ts project_folder path traversal
CVE-2026-815748.233.8wibu-systems-agcodemeter-runtimeCWE-134Format String Vulnerability in Logger
CVE-2026-770188.833.6UnknownWorkeeraCWE-434Workeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Upload vi…
CVE-2026-56807.533.4Red HatRed Hat build of Apache Camel for Spring Boot 4CWE-770Undertow-core: undertow: denial of service via websocket permessage-deflate p…
CVE-2026-618026.533.0wazuhwazuhCWE-200Wazuh discloses cleartext cluster key to low-privilege API users via GET /clu…
CVE-2026-663535.332.4woyliedoggoCWE-79Doggo vulnerable to cross-site scripting via unescaped date field values
CVE-2026-817218.732.3jahlivesopenssl_encryptCWE-400openssl_encrypt before 1.4.9 Denial of Service via KDF
CVE-2026-1888510.031.1ServiceNowServiceNow AI Platform—Unauthenticated Remote Code Execution in GraphQL Composite Data API
CVE-2026-324799.331.2CODEPRESS IT Solutions LLCVisitor Traffic Real Time Statistics ProCWE-89WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.17 - SQL Inje…
CVE-2026-782609.331.2ePaycoEpaycoCWE-89WordPress Epayco plugin <= 8.4.6 - SQL Injection vulnerability
CVE-2026-782889.331.2Jonathan de JongBeautiful Taxonomy FiltersCWE-89WordPress Beautiful Taxonomy Filters plugin <= 2.4.6 - SQL Injection vulnerab…
CVE-2026-804337.530.5Brainstorm ForceSureFeedback Client SiteCWE-862WordPress SureFeedback Client Site plugin <= 1.2.12 - Sensitive Data Exposure…
CVE-2026-817308.830.4DolibarrdolibarrCWE-22Dolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Attachment Fi…
CVE-2026-593549.630.1VMware by BroadcomSpring Security (OAuth2 Authorization Server module)CWE-20Spring Security OAuth2 Authorization Server: Insufficient validation of Dynam…
CVE-2026-796536.029.8Eclipse FoundationEclipse SW360CWE-22In Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if the syst…
CVE-2026-192237.229.8UnknownSmushCWE-94Smush < 4.3.2 - Admin+ Network-Wide RCE via Hub Connector on Multisite
CVE-2026-593176.529.5SpringSpring for Apache Kafka—In Spring for Apache Kafka, missing header validation in DeadLetterPublishing…
CVE-2026-769458.729.2EbyteEbyte NE2-D11 FirmwareCWE-603Ebyte NE2-D11 Use of Client-Side Authentication
CVE-2026-547133.729.2cakephpqueueCWE-1023CakePHP Queue: Incomplete Comparison in getUniqueId vulnerable to collisions
CVE-2026-100368.729.1speechbrainspeechbrainCWE-502SpeechBrain < 1.1.1 Arbitrary Code Execution via CKPT.yaml Parsing
CVE-2026-816739.328.5TOOOLSiSquadCWE-89Multiple Vulnerabilities in TOOOLS' iSquad
CVE-2026-769408.728.4EbyteEbyte NE2-D11 FirmwareCWE-307Ebyte NE2-D11 Improper Restriction of Excessive Authentication Attempts
CVE-2026-816998.728.0jahlivesopenssl_encryptCWE-770openssl_encrypt before 1.4.9 Denial of Service via unbounded KDF cost
CVE-2026-190929.827.8UnknownTutor LMSCWE-74Tutor LMS < 4.0.6 - Unauthenticated Arbitrary Zero-Argument Function Invocati…
CVE-2026-817535.127.9flowintelflowintelCWE-79Flowintel Stored XSS in Case Notes via Malicious Mermaid Diagram Content
CVE-2026-766407.727.3Unitree RoboticsG1 EDUCWE-306Unitree G1 EDU 1.5.2 BLE GATT RCE via WiFi Provisioning Stack
CVE-2026-593078.027.2SpringSpring Integration—Deserialization allow-list silently bypassed: setBeanClassLoader replaces des…
CVE-2026-817228.727.0nltknltkCWE-407nltk PorterStemmer before 3.10.3 Quadratic-time DoS
CVE-2026-816928.727.0jahlivesopenssl_encryptCWE-789openssl_encrypt before 1.4.9 Denial of Service via STREAMINFO
CVE-2026-816938.727.0jahlivesopenssl_encryptCWE-789openssl_encrypt before 1.4.9 Denial of Service via QR total field
CVE-2026-273308.626.9WeptileMobile App for WooCommerceCWE-862WordPress Mobile App for WooCommerce plugin <= 0.4.62 - Broken Access Control…
CVE-2026-810918.726.8mcp-usemcp-useCWE-918mcp-use Inspector Proxy Server-Side Request Forgery via Caller-Supplied Targe…
CVE-2026-325508.526.8Liquid Web, LLCKadence Shop KitCWE-89WordPress Kadence Shop Kit plugin <= 3.0.6 - SQL Injection vulnerability
CVE-2026-325648.526.8ACPTACPT (Pro) - Custom Post Types Plugin for WordPressCWE-89WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.6…
CVE-2026-782858.526.8LikeBtnLike Button RatingCWE-89WordPress Like Button Rating plugin <= 2.6.61 - SQL Injection vulnerability
CVE-2026-812778.526.8VillaThemeSuggestion Engine for WooCommerceCWE-89WordPress Suggestion Engine for WooCommerce plugin <= 2.0.11 - SQL Injection …
CVE-2026-593116.826.9SpringSpring Integration—Fixed predictable /tmp/ziptransformer work directory enables symlink pre-crea…
CVE-2026-818455.326.2arben-admmcp-sequential-thinkingCWE-22arben-adm mcp-sequential-thinking Import Session/Export Session server.py exp…
CVE-2026-818375.326.0RooCodeIncRoo-CodeCWE-22RooCodeInc Roo-Code ApplyPatchTool ApplyPatchTool.ts path.resolve path traversal
CVE-2026-817058.725.9jahlivesopenssl_encryptCWE-532openssl-encrypt before 1.4.9 Password Cleartext Leak via Debug
CVE-2026-675607.725.9BendixEC80ESP+ J1708CWE-121Stack-based Buffer Overflow in Bendix EC80 Brake ECU
CVE-2026-592847.625.7SpringSpring Cloud Commons—Spring Cloud Commons no allow list for writable env actuator endpoint
CVE-2026-540838.125.5wazuhwazuhCWE-22Wazuh: Path traversal in ip-customblock active response allows arbitrary file…
CVE-2026-818269.125.4flowintelflowintelCWE-384Flowintel Fails to Invalidate Active Sessions After Password Change
CVE-2026-780108.725.1WatchGuardFireware OSCWE-121Fireware OS Stack-Based Buffer Overflow in iked Allows Unauthenticated Denial…
CVE-2026-815767.725.0wibu-systems-agcodemeter-runtimeCWE-639Improper Authentication of Session Handles
CVE-2026-816786.925.1WWBNAVideoCWE-918AVideo SSRF Guard Bypass via IPv6 Transition Addresses
CVE-2026-300467.524.8n/an/aCWE-617A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.…
CVE-2026-300477.524.8n/an/aCWE-617A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts co…
CVE-2026-300507.524.8n/an/aCWE-770An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event…
CVE-2026-300567.524.8n/an/aCWE-476A NULL pointer dereference in the AMF NGAP Dispatcher component of free5gc v4…
CVE-2026-300577.524.8n/an/aCWE-770An issue in the CreateUEContext handler component of free5gc v4.1.0 allows at…
CVE-2026-300627.524.8n/an/aCWE-770An issue in the NGAP handler of free5gc v4.0.1 allows attackers to cause a De…
CVE-2026-478867.524.8SpringSpring FrameworkCWE-400Spring Framework Denial of Service via Unbounded Exponentiation in SpEL Expre…
CVE-2026-478887.524.8SpringSpring FrameworkCWE-401Spring Framework Memory Leak via SETUP Frame in RSocketMessageHandler
CVE-2026-68768.724.7ServiceNowNow Platform—Sandbox Escape in Now Platform
CVE-2026-786176.324.6WatchGuardDimensionCWE-203WatchGuard Dimension Web UI Authentication Brute-Force Due to Missing Rate Li…
CVE-2026-193148.724.5WatchGuardFireware OSCWE-191Fireware OS Integer Underflow in iked Allows Unauthenticated Denial of Servic…
CVE-2026-193168.724.5WatchGuardFireware OSCWE-415Fireware OS Pre-Authentication Double Free in iked Allows Denial of Service (…
CVE-2026-193178.724.5WatchGuardFireware OSCWE-125Fireware OS Pre-Authentication Out-of-Bounds Read in iked Allows Denial of Se…
CVE-2026-780098.724.5WatchGuardFireware OSCWE-125Fireware OS Out-of-Bounds Read in iked Allows Unauthenticated Denial of Servi…
CVE-2026-780118.724.5WatchGuardFireware OSCWE-191Fireware OS Integer Underflow in Iked Allows Unauthenticated Denial of Servic…
CVE-2026-811016.924.5Airtableairtable-mcp-cliCWE-200Airtable MCP CLI before 0.2.5 Credential Disclosure via Unvalidated Configure…
CVE-2026-817437.524.4flowintelflowintelCWE-22Flowintel Arbitrary Log File Path Allows Remote Code Execution via Template I…
CVE-2026-802134.024.1RubyresolvCWE-197An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS:…
CVE-2026-817199.323.9jahlivesopenssl_encryptCWE-94openssl_encrypt before 1.4.9 Remote Code Execution via Plugin
CVE-2026-478944.923.9SpringSpring Cloud Config—Spring Cloud Config Server Native Environment Repository Exposure
CVE-2026-478909.823.7SpringSpring FrameworkCWE-93Spring Framework Server Sent Event stream corruption while rendering fragments
CVE-2026-802088.823.5apitableapitableCWE-306APITable through 1.13.0-beta.1 Missing Authentication on the Internal Account…
CVE-2026-816628.623.4flowintelflowintelCWE-20Flowintel Alert Settings Configuration Allows Remote Code Execution via Arbit…
CVE-2026-780088.623.1WatchGuardFireware OSCWE-787Fireware OS Authenticated Buffer Overflow in wgagent
CVE-2026-818188.623.1flowintelflowintelCWE-269Flowintel Organization Administrator Can Reset Full Administrator Password an…
CVE-2026-812724.923.1WP Manage NinjaFluentPlayer ProCWE-862WordPress FluentPlayer Pro plugin <= 1.3.2 - Broken Access Control vulnerability
CVE-2026-781749.323.0WatchGuardDimensionCWE-200WatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic …
CVE-2026-817019.323.0jahlivesopenssl_encryptCWE-347openssl_encrypt before 1.4.9 Arbitrary Code Execution via unsigned plugin
CVE-2026-26897await22.8n/an/a—An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version …
CVE-2026-816768.822.4TOOOLSiSquadCWE-89Multiple Vulnerabilities in TOOOLS' iSquad
CVE-2026-820728.822.4GoogleChromeCWE-125Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a re…
CVE-2026-816597.122.5flowintelflowintelCWE-22Flowintel Note PDF Export Allows Arbitrary Local File Read via Pandoc/XeLaTeX…
CVE-2026-547326.522.2elwerenelibreoffice-convertCWE-22libreoffice-convert: path traversal / arbitrary file write
CVE-2026-754198.822.0n/an/a—go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. …
CVE-2026-592715.321.8SpringSpring AMQPCWE-209Admin password disclosed in BrokerNotAliveException message
CVE-2026-754187.521.7n/an/a—A path traversal vulnerability exists in the built-in preview/development web…
CVE-2026-818276.921.7flowintelflowintelCWE-20Flowintel Login Email Validation Bypass Allows Log Injection via Crafted Emai…
CVE-2026-659315.121.4LimeSurveyLimeSurveyCWE-862LimeSurvey Community Edition 7.0.5 - Improper authorization in survey menu en…
CVE-2026-593155.321.3SpringSpring Cloud Config—Spring Cloud Config Monitor Denial of Service
CVE-2026-818195.321.4flowintelflowintelCWE-862Flowintel Missing Authorization Allows Regular API Users to View Other Users’…
CVE-2026-816646.921.2openfaasfaasCWE-306OpenFaaS Gateway 0.27.11 through 0.27.13 Missing Authentication on the /syste…
CVE-2026-478919.821.1SpringSpring FrameworkCWE-770Spring Framework maxInMemorySize Bypassed in Jaxb2Decoder
CVE-2026-592709.421.0SpringSpring Security—Spring Security embedded UnboundID LDAP server exposes well-known administrat…
CVE-2026-192256.621.0UnknownDefender SecurityCWE-94Defender Security < 6.2.0 - Admin+ Network-Wide RCE via Hub Connector on Mult…
CVE-2026-593206.521.0SpringSpring AMQP—In Spring AMQP the link credit never replenished on listener exception path
CVE-2026-773588.220.7yhirosecpp-httplibCWE-416cpp-httplib: Use-after-free of TLS session in WebSocketClient::shutdown_and_c…
CVE-2026-819314.820.7RoskusProspero Flow CRMCWE-434Unrestricted upload of file with dangerous type in Prospero Flow CRM product …
CVE-2026-816798.320.6openremoteopenremoteCWE-200OpenRemote before 1.28.0 Cross-Realm Information Disclosure via Notification API
CVE-2026-802076.920.6apitableapitableCWE-306APITable through 1.13.0-beta.1 Missing Authentication on the Internal Notific…
CVE-2026-802095.320.7fonosterfonosterCWE-863Fonoster through 0.22.7 Incorrect Authorization in the Identity UpdateWorkspa…
CVE-2026-816989.320.5jahlivesopenssl_encryptCWE-78openssl_encrypt before 1.4.9 Shell Injection via info command
CVE-2026-816729.320.3TOOOLSiSquadCWE-89Multiple Vulnerabilities in TOOOLS' iSquad
CVE-2026-816749.320.3TOOOLSiSquadCWE-89Multiple Vulnerabilities in TOOOLS' iSquad
CVE-2026-812745.320.2metaphorcreationsDittyCWE-862WordPress Ditty plugin <= 3.1.67 - Broken Access Control vulnerability
CVE-2026-812765.320.2WP ChillKali FormsCWE-862WordPress Kali Forms plugin <= 2.4.23 - Broken Access Control vulnerability
CVE-2026-781377.520.1UnknownStoreGrowthCWE-862StoreGrowth: Smart Sales Booster for WooCommerce < 2.1.2 - Unauthenticated Ar…
CVE-2026-783338.819.6Unknown12 Step Meeting ListCWE-7912 Step Meeting List 3.17 - 3.19.16 - Unauthenticated Stored XSS via Geocode …
CVE-2026-535808.119.4TriliumNextTriliumCWE-73Trilium arbitrary file read and denial of service via file:// URLs in the aut…
CVE-2026-478815.919.3SpringSpring BatchCWE-400Denial of Service in Spring Batch FlatFileItemReader via Malformed Input File
CVE-2026-815258.619.2MongoDBPHP LibraryCWE-943Cross-tenant database retargeting via dot/NUL injection in namespace strings …
CVE-2026-773415.319.2yhirosecpp-httplibCWE-93cpp-httplib: CRLF injection via unvalidated HTTP trailer headers in chunked r…
CVE-2026-37006await18.8n/an/a—A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and befor…
CVE-2026-478497.118.5SpringSpring Data RESTCWE-915Spring Data REST allows mutation of identifier and version properties via JSO…
CVE-2026-57068.918.4Silicon LabsBT Mesh SDKCWE-130Buffer overflow in Bluetooth Mesh SDK when handling extended advertisements
CVE-2026-815228.618.1MongoDBC++ DriverCWE-116Cross-tenant database retargeting via dot/NUL injection in namespace strings …
CVE-2026-817268.318.0nltknltkCWE-73NLTK through 3.10.3 Path Traversal via Model-Artifact APIs
CVE-2026-1888610.018.0ServiceNowServiceNow AI Platform—Unauthenticated Privilege Escalation via System Configuration Image Upload Pr…
CVE-2026-751598.217.9MongoDBBI ConnectorCWE-415MongoDB BI Connector Improper Memory Handling During Failed Kerberos Authenti…
CVE-2026-30612await17.9n/an/a—An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS …
CVE-2026-799888.717.4craftcmscmsCWE-693Authenticated RCE through Twig sandbox escape
CVE-2026-478857.517.4SpringSpring FrameworkCWE-770Spring Framework maxPartSize Ignored in PartEventHttpMessageReader
CVE-2026-817246.917.2nltknltkCWE-674NLTK before 3.10.3 Denial of Service via Uncontrolled Recursion
CVE-2026-779895.317.2joomlaeventmanager.netJEM - Joomla Event Manager extension for JoomlaCWE-79Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export …
CVE-2026-37007await17.2n/an/a—A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remot…
CVE-2026-75357await17.2n/an/a—An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arb…
CVE-2026-689299.317.1labringFastGPTCWE-862FastGPT: Unauthenticated WeChat channel hijack and denial of service via shar…
CVE-2026-134157.217.1UnknownCMPCWE-269CMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Privilege Escalation via c…
CVE-2026-689677.117.1BendixEC80ESP+ J1708CWE-787Out-of-bounds Write in Bendix EC80 Brake ECU
CVE-2026-592765.917.1SpringSpring SecurityCWE-208Timing Attack via Non-Constant-Time Comparison of Sensitive Values
CVE-2026-781035.117.1WatchGuardDimensionCWE-841Dimension Log Server Configuration Lock Bypass Vulnerability
CVE-2026-817288.616.9DolibarrdolibarrCWE-89Dolibarr before 24.0.0 SQL Injection via the CSV and XLSX Import Update Keys
CVE-2026-197157.517.0UnknownWP OAuth Server ( Login with WordPress )CWE-200WP OAuth Server < 6.3.1 - Unauthenticated OAuth Token and User Data Disclosur…
CVE-2026-818145.116.9flowintelflowintelCWE-79Flowintel Stored XSS in Calendar via Malicious Case Title
CVE-2026-758138.716.9EbyteEbyte NE2-D11 FirmwareCWE-862Ebyte NE2-D11 Missing Authorization
CVE-2026-162799.316.6Dassault Systèmes3DSwymerCWE-285Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Re…
CVE-2026-817009.316.6jahlivesopenssl_encryptCWE-347openssl_encrypt before 1.4.9 GPG Signature Verification Bypass
CVE-2026-786186.916.8WatchGuardDimensionCWE-284Dimension Business Logic Flaw Allows Chained Backend Object Operations
CVE-2026-194544.416.7UnknownJetBackupCWE-863JetBackup 3.1.18.8 - 3.1.23.3 - Admin+ Multisite Network Backup Download
CVE-2026-816759.316.5TOOOLSiSquadCWE-89Multiple Vulnerabilities in TOOOLS' iSquad
CVE-2026-131088.716.5WatchGuardDimensionCWE-400Dimension Denial-of-Service
CVE-2026-478897.516.5SpringSpring FrameworkCWE-1275Spring Framework sameSite Attribute Dropped in JettyCoreServerHttpResponse
CVE-2026-592945.916.3SpringSpring AI—Arbitrary File Write via Path Traversal in ResourceCacheService
CVE-2026-801795.916.3Red HatRed Hat Ansible Automation Platform 2CWE-770Jwcrypto: jwcrypto: denial of service via malformed jwe tokens
CVE-2026-818205.116.4flowintelflowintelCWE-79Flowintel HTML Injection in MISP Case History Timeline via Crafted Object Att…
CVE-2026-816778.816.0TOOOLSiSquadCWE-89Multiple Vulnerabilities in TOOOLS' iSquad
CVE-2026-770177.716.1UnknownWorkeeraCWE-200Workeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Read via …
CVE-2026-478755.615.9SpringSpring BatchCWE-502JobParameterDeserializer bypasses the trusted-type allowlist
CVE-2026-478785.615.9SpringSpring BatchCWE-502Unsafe Java deserialization in DefaultExecutionContextSerializer without clas…
CVE-2026-37004await15.9n/an/a—BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SST…
CVE-2026-786154.615.8WatchGuardDimensionCWE-79WatchGuard Dimension Reflected DOM-Based XSS in Report Detail Page
CVE-2026-818516.915.6WatchGuardFireware OSCWE-122Fireware OS Heap-Based Buffer Overflow in iked Allows Denial of Service
CVE-2026-592756.615.7SpringSpring AMQPCWE-502Remote JVM termination: nested-array Java deserialization bypasses allowlist,…
CVE-2026-802118.215.4FrontAccountingFrontAccountingCWE-916FrontAccounting through 2.4.20 Use of Unsalted MD5 for Password Storage
CVE-2026-478797.715.2SpringSpring Cloud GatewayCWE-918Spring Cloud Gateway SSRF and native file access with gRPC
CVE-2026-43985.415.2GitLabGitLabCWE-639Authorization Bypass Through User-Controlled Key in GitLab
CVE-2026-770169.615.1UnknownWorkeeraCWE-73Workeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Deletion …
CVE-2026-774387.515.1TriliumNextTriliumCWE-200Trilium unauthenticated share-search discloses password-protected and hidden …
CVE-2026-117545.315.0Seres SoftwaresyWEBCWE-203User Enumeration in Seres Software's syWEB
CVE-2026-696589.314.8EbyteEbyte NE2-D11 FirmwareCWE-319Ebyte NE2-D11 Cleartext Transmission of Sensitive Information
CVE-2026-617837.014.8wazuhwazuhCWE-200Wazuh: RBAC permission-effect check in mask_sensitive_config allows low-privi…
CVE-2026-770346.914.9joomlaeventmanager.netJEM - Joomla Event Manager extension for JoomlaCWE-284Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite…
CVE-2026-7482010.014.6ServiceNowServiceNow AI Platform—Unauthenticated SQL Injection via Dynamic Schema ORDER BY Clause
CVE-2026-346747.814.7AdobeAdobe Substance 3D SamplerCWE-122Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122)
CVE-2026-593248.214.5SpringSpring Integration—fluxTransform shared RequestMessageHolder causes cross-message header leakage…
CVE-2026-782617.114.5RealtynaRealtyna Organic IDX pluginCWE-79WordPress Realtyna Organic IDX plugin plugin <= 5.4.1 - Cross Site Scripting …
CVE-2026-782817.114.5codepeopleCP Media PlayerCWE-79WordPress CP Media Player plugin <= 1.3.0 - Cross Site Scripting (XSS) vulner…
CVE-2026-782837.114.5codepeopleMusic Player for WooCommerceCWE-79WordPress Music Player for WooCommerce plugin <= 1.8.9 - Cross Site Scripting…
CVE-2026-782897.114.5LoftOceanCozyStayCWE-79WordPress CozyStay theme <= 1.10.0 - Cross Site Scripting (XSS) vulnerability
CVE-2026-782937.114.5axew3WP w3all phpBBCWE-79WordPress WP w3all phpBB plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnera…
CVE-2026-713965.314.4BendixEC80ESP+ J1708CWE-798Use of Hard-coded Credentials in Bendix EC80 Brake ECU
CVE-2026-540857.114.3wazuhwazuhCWE-88Wazuh: Missing input validation in multiple active response scripts allows ar…
CVE-2026-592746.514.2SpringSpring IntegrationCWE-409Unbounded decompression in UnZipTransformer enables zip-bomb DoS
CVE-2026-818475.114.3MAA-AIMaaMCPCWE-22MAA-AI MaaMCP pipeline_tools.py load_pipeline path traversal
CVE-2026-818342.114.1RooCodeIncRoo-CodeCWE-74RooCodeInc Roo-Code README File ExecaTerminalProcess code injection
CVE-2026-592804.313.8SpringSpring FrameworkCWE-22Spring Framework Path Traversal via Backslash in SpringTemplateLoader
CVE-2026-780475.113.7WatchGuardDimensionCWE-79Dimension Stored XSS in Scheduled Report Task
CVE-2026-779777.213.5EbyteEbyte NE2-D11 FirmwareCWE-306Ebyte NE2-D11 Missing Authentication for Critical Function
CVE-2026-770355.113.5joomlaeventmanager.netJEM - Joomla Event Manager extension for JoomlaCWE-639Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeov…
CVE-2026-784985.113.5WatchGuardDimensionCWE-918Dimension Server-Side Request Forgery via Email Server Test Settings
CVE-2026-784995.113.5WatchGuardDimensionCWE-918Dimension SSRF via FTP Server Test Connection
CVE-2026-785005.113.5WatchGuardDimensionCWE-208Dimension Blind SSRF via Database Test Connection Feature
CVE-2026-593556.113.1VMwareSpring Authorization ServerCWE-601Spring Authorization Server: Open Redirect via request_uri parameter
CVE-2026-37009await13.2n/an/a—A SQL injection vulnerability in NL2SQLTool in crewai-tools v1.10.2rc1 allows…
CVE-2026-817236.312.6nltknltkCWE-400NLTK before 3.10.3 Quadratic CPU Exhaustion via XMLCorpusView
CVE-2026-817256.312.6nltknltkCWE-400NLTK before 3.10.3 Regular Expression Denial of Service via Pl196xCorpusReader
CVE-2026-592936.612.5SpringSpring Integration—SMB minimum protocol dialect defaults to SMB1
CVE-2026-36102await12.4n/an/a—An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.…
CVE-2026-37012await12.4n/an/a—A vulnerability in pentestgpt/core/langfuse.py in PentestGPT 1.0.0 allows rem…
CVE-2026-817297.112.4DolibarrdolibarrCWE-863Dolibarr before 23.0.4 Incorrect Authorization on REST API Document Deletion
CVE-2026-812795.412.4MuraliPush Notification for Post and BuddyPressCWE-862WordPress Push Notification for Post and BuddyPress plugin <= 3.20 - Broken A…
CVE-2026-758897.712.2GrafanaAlloy—CVE-2026-75889 CVE Record
CVE-2026-187179.111.8Applied Systems EngineeringASE2000 V2CWE-295Improper Certificate Validation in ASE 2000
CVE-2026-593194.311.7SpringSpring AI—RediSearch Tag Injection in RedisChatMemoryRepository Allows Cross-Conversati…
CVE-2026-175626.511.7Summit Security SystemsAdisyonProCWE-639IDOR in Zirve Security's AdisyonPro
CVE-2026-489969.311.5TriliumNextTriliumCWE-79Trilium: Malicious import with GeoMap marker title XSS leads to RCE on the de…
CVE-2026-535789.311.5TriliumNextTriliumCWE-79Trilium: Note Import to RCE via Mind Elixir dangerouslySetInnerHtml
CVE-2026-535799.311.5TriliumNextTriliumCWE-79Trilium: Note Import to RCE via Book Note
CVE-2026-593063.111.5SpringSpring Cloud Stream—Potential for deserialization of untrusted types in Spring Cloud Stream
CVE-2026-816586.511.4Red HatRed Hat Satellite 6CWE-639Foreman: cross-tenant disclosure of template revisions via unauthorized audit…
CVE-2026-782736.511.3WP Manage NinjaFluent Boards ProCWE-79WordPress Fluent Boards Pro plugin <= 2.0.11 - Cross Site Scripting (XSS) vul…
CVE-2026-816878.710.9jahlivesopenssl_encryptCWE-400openssl_encrypt before 1.4.9 Denial of Service via KDF
CVE-2026-592773.710.9SpringSpring SecurityCWE-693Spring Security InetAddressMatchers Incomplete Internal Network Classification
CVE-2026-818177.210.8flowintelflowintelCWE-639Flowintel Missing Task-to-Case Authorization Allows Cross-Case Task Modification
CVE-2026-779905.310.8joomlaeventmanager.netJEM - Joomla Event Manager extension for JoomlaCWE-639Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any lo…
CVE-2026-784955.310.8WatchGuardDimensionCWE-918Dimension Server-Side Request Forgery via Remote Backup Connection Test
CVE-2026-593226.310.7SpringSpring Integration—EmbeddedHeadersJsonMessageMapper default gives wire peer full control of Mess…
CVE-2026-781255.310.6UnknownLearnPressCWE-200LearnPress – Sepay Payment < 4.0.3 - Unauthenticated Order Status Disclosure
CVE-2026-797186.810.5NetronNetronCWE-79Reflected XSS in Netron versions <=9.1.2 on desktop application through unsan…
CVE-2026-797196.810.5NetronNetronCWE-79Reflected XSS in Netron versions <=9.1.2 on desktop application through unsan…
CVE-2026-797206.810.5NetronNetronCWE-79Reflected XSS in Netron versions <=9.1.2 on desktop application through unsan…
CVE-2026-815818.810.4wibu-systems-agwibukeyCWE-119User input in WibuKey is used (without proper sanitization) to compute the ad…
CVE-2026-815217.110.2MongoDBGO DriverCWE-99Cross-database write retargeting via unvalidated dotted database name in Clie…
CVE-2026-815267.110.2MongoDBRust DriverCWE-74Cross-database write redirection via unvalidated dotted database name in bulk…
CVE-2026-816888.79.6jahlivesopenssl_encryptCWE-311openssl_encrypt before 1.4.9 Plaintext Confirmation Oracle via SHA-256
CVE-2026-816898.79.6jahlivesopenssl_encryptCWE-916openssl_encrypt before 1.4.9 Weak Pepper Key Derivation
CVE-2026-816918.79.6jahlivesopenssl_encryptCWE-319openssl_encrypt before 1.4.9 Credential Leakage via Unvalidated Server URLs
CVE-2026-817048.79.6jahlivesopenssl_encryptCWE-916openssl_encrypt before 1.4.9 Weak Key Derivation via D-Bus
CVE-2026-818485.19.4cyberchittascrapling-fetch-mcpCWE-918cyberchitta scrapling-fetch-mcp _fetcher.py s_fetch_pattern server-side reque…
CVE-2026-165675.39.0UnknownDocument EmbedderCWE-639Document Embedder < 2.3.1 - Unauthenticated Private Document Download via Tok…
CVE-2026-817168.78.9jahlivesopenssl_encryptCWE-22openssl_encrypt before 1.4.9 Plugin Sandbox Path Traversal
CVE-2026-198898.28.8GitLabGitLab AI GatewayCWE-918Server-Side Request Forgery (SSRF) in GitLab AI Gateway
CVE-2026-758718.28.8GitLabGitLab AI GatewayCWE-918Server-Side Request Forgery (SSRF) in GitLab AI Gateway
CVE-2026-37066await8.6n/an/a—Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vf…
CVE-2026-47892await8.5SpringSpring Framework—Spring Framework Header Predicate Bypass in WebFlux Functional Endpoints
CVE-2026-817158.78.5jahlivesopenssl_encryptCWE-532openssl_encrypt before 1.4.9 Credential Exposure via Debug Output
CVE-2026-478778.28.5SpringSpring SecurityCWE-79Spring Security Authorization Server Default Consent Page is vulnerable to Cr…
CVE-2025-623426.48.4HCL SoftwareIEMCWE-613HCL IntelliOps Event Management is affected by multiple security vulnerabilit…
CVE-2026-818366.38.4RooCodeIncRoo-CodeCWE-319RooCodeInc Roo-Code OAuth Callback oauth.ts cleartext transmission
CVE-2026-478836.18.3SpringSpring FrameworkCWE-601Spring Framework Open Redirect in UrlHandlerFilter
CVE-2026-593168.28.1SpringSpring Authorization Server—Spring Authorization Server Default Consent Page is vulnerable to Cross-Site …
CVE-2026-812718.88.0PaoloGeoDirectoryCWE-352WordPress GeoDirectory plugin <= 2.8.176 - Cross Site Request Forgery (CSRF) …
CVE-2025-623433.18.0HCL SoftwareHCL IEMCWE-557HCL IntelliOps Event Management is affected by multiple security vulnerabilit…
CVE-2026-815276.97.9MongoDBC# DriverCWE-943NoSQL injection via unquoted constant GroupBy keys in LINQ pipeline translation
CVE-2026-478805.47.9SpringSpring IntegrationCWE-20DefaultJmsHeaderMapper copies all JMS user properties into MessageHeaders wit…
CVE-2026-714015.37.9SUSEwickedCWE-191wicked: integer underflow of the UDP length in ni_capture_inspect_udp_header(…
CVE-2026-30067await7.8n/an/a—An issue in the complexQueryFilterSubprocess function in the NRF Discovery se…
CVE-2026-30072await7.8n/an/a—A NULL pointer dereference in the CDR processing path of free5gc v4.0.1 allow…
CVE-2026-30073await7.8n/an/a—An issue in the NssaiAvailabilitySubscriptionCreate component of free5gc v4.0…
CVE-2026-543308.17.8cephcephCWE-347Ceph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests…
CVE-2026-57386.17.7BilPark Informatics Technologies Industry and Trade Inc.DoXBASECWE-79Reflected XSS in BilPark's DoXBASE
CVE-2026-117476.17.7Seres SoftwaresyWEBCWE-79Reflected XSS in Seres Software's syWEB
CVE-2026-26899await7.4n/an/a—An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026…
CVE-2026-30045await7.4n/an/a—An integer overflow in the /nnrf-disc/v1/nf-instances component of open5gs v2…
CVE-2026-816859.37.3jahlivesopenssl_encryptCWE-116openssl_encrypt before 1.4.9 Text Injection via Recovery Slot Metadata
CVE-2026-816949.37.3jahlivesopenssl_encryptCWE-117verify-usb before 1.4.9 Output Injection via Unsanitized Filenames
CVE-2026-816959.37.3jahlivesopenssl_encryptCWE-117openssl_encrypt before 1.4.9 Terminal Injection via key_id
CVE-2026-816969.37.3jahlivesopenssl_encryptCWE-117openssl_encrypt before 1.4.9 Terminal Injection via info Command
CVE-2026-758148.67.2EbyteEbyte NE2-D11 FirmwareCWE-352Ebyte NE2-D11 Cross-Site Request Forgery
CVE-2026-781384.37.2UnknownFinale LiteCWE-200Finale Lite < 2.21.0 - Subscriber+ Campaign Configuration Disclosure via wcct…
CVE-2026-812738.17.0WP Manage NinjaFluentBooking ProCWE-352WordPress FluentBooking Pro plugin <= 2.2.4 - Cross Site Request Forgery (CSR…
CVE-2026-815297.17.0MongoDBC# DriverCWE-88Connection-option injection via unescaped settings in the canonical MongoDB U…
CVE-2026-661557.07.0SiemensElement maps-ng V47CWE-79A vulnerability has been identified in Element maps-ng V47 (All versions < V4…
CVE-2026-59281await6.8SpringSpring Framework—Spring Framework Cross-site Scripting via EscapedErrors
CVE-2026-810978.66.7maquina-apprails-mcp-serverCWE-78rails-mcp-server 1.4.0 through 1.6.0 OS Command Execution via execute_ruby PT…
CVE-2026-478876.16.7SpringSpring FrameworkCWE-601Spring Framework Open Redirect in UrlFileNameViewController
CVE-2026-26452await6.8n/an/a—ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 lcontains a vulnerability in t…
CVE-2026-26456await6.8n/an/a—A null pointer dereference vulnerability exists in the server-side session ma…
CVE-2026-26459await6.8n/an/a—ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a vulnerability in th…
CVE-2026-755485.36.6EbyteEbyte NE2-D11 FirmwareCWE-1021Ebyte NE2-D11 Improper Restriction of Rendered UI Layers or Frames
CVE-2026-817315.16.6frappefrappeCWE-79Frappe 15.11.0 through 16.32.0 Stored XSS via Workspace Link Description
CVE-2026-818355.16.6RooCodeIncRoo-CodeCWE-94RooCodeInc Roo-Code MCP Integration Trust Model malicious_mcp_server.py fetch…
CVE-2026-818332.06.6RooCodeIncRoo-CodeCWE-74RooCodeInc Roo-Code CodeIndexManager helpers.ts optimizeQuery code injection
CVE-2026-399448.86.6cephcephCWE-327Ceph: CephX AES Authentication error
CVE-2026-714025.36.4SUSEwickedCWE-125wicked: out-of-bounds read in the DHCPv4 option parser due to payload length …
CVE-2026-37198await6.3n/an/a—An integer overflow in the SMF component of Open5GS v2.7.6 allows attackers t…
CVE-2026-738098.76.2EbyteEbyte NE2-D11 FirmwareCWE-319Ebyte NE2-D11 Cleartext Transmission of Sensitive Information
CVE-2026-817038.76.1jahlivesopenssl_encryptCWE-287openssl_encrypt before 1.4.9 Authentication Bypass via Unencrypted PQC Key
CVE-2026-815727.86.0wibu-systems-agcodemeter-runtimeCWE-59Local Privilege Escalation in CodeMeter Runtime on Windows
CVE-2026-810927.66.0mark3labsmcp-goCWE-346mcp-go before 0.56.0 Missing Host Header Validation Enables DNS Rebinding
CVE-2026-815285.35.8MongoDBC# DriverCWE-943NoSQL injection via array replacement bypassing update shape validation in dr…
CVE-2026-786164.85.9WatchGuardDimensionCWE-79Dimension Stored XSS via Trusted CA Certificate Configuration
CVE-2026-52184.35.9Softtr Informatics Technology Trading Limited CompanyE-Commerce PackCWE-80HTML Injection in Softtr's E-Commerce Pack
CVE-2026-592726.85.8SpringSpring AMQPCWE-297Log4j2 AmqpAppender disables TLS hostname verification by default
CVE-2026-346165.55.7AdobeAdobe DNG Software Development Kit (SDK)CWE-125DNG SDK | Out-of-bounds Read (CWE-125)
CVE-2026-37067await5.7n/an/a—Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno …
CVE-2026-37069await5.7n/an/a—Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/R…
CVE-2026-37073await5.7n/an/a—Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manage…
CVE-2026-59313await5.8SpringSpring Framework—Server Sent Event stream corruption in Spring MVC functional web framework
CVE-2026-59314await5.8SpringSpring Framework—Spring Framework response splitting in ContentDisposition
CVE-2026-501529.15.7cephcephCWE-285Ceph Monitor subscription handler improperly authorizes config-key store read…
CVE-2026-802107.15.7FrontAccountingFrontAccountingCWE-352FrontAccounting through 2.4.20 Cross-Site Request Forgery on Financial Transa…
CVE-2026-165684.35.6UnknownMobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerceCWE-639ShopApper <= 0.4.62 - Subscriber+ Customer Data Disclosure via IDOR
CVE-2026-37064await5.7n/an/a—User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Projec…
CVE-2026-168955.15.6Rapid7Metasploit-frameworkCWE-305Authentication Bypass in Metasploit JSON-RPC Service When DB Health Check Fails
CVE-2026-810957.65.5timescalepg-aiguideCWE-346Timescale pg-aiguide through 0.5.0 DNS Rebinding via Disabled Host Header All…
CVE-2026-810997.65.5timescaletiger-slackCWE-346Timescale tiger-slack DNS Rebinding via Disabled Host Header Allow-List
CVE-2026-811007.65.5timescaletiger-gh-mcp-serverCWE-346Timescale tiger-gh-mcp-server DNS Rebinding via Disabled Host Header Allow-List
CVE-2026-592983.15.5SpringSpring Cloud Function—Potential for improper filtering of HTTP headers in Spring Cloud Function
CVE-2026-592786.55.4SpringSpring for Apache KafkaCWE-918In Spring for Apache Kafka, SSRF via DNS resolution triggered by untrusted ja…
CVE-2026-176106.05.3Silicon LabsSiSDKCWE-404RAIL 802.15.4 Mux missing ACK can lead to DoS
CVE-2026-592912.05.3SpringSpring Cloud Function—Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function
CVE-2026-37065await5.3n/an/a—Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /…
CVE-2026-59283await5.3SpringSpring Framework—Spring Framework Safety Guard Bypass via SpEL Expression Compilation
CVE-2026-815798.85.0wibu-systems-agwibukeyCWE-123An untrusted Pointer Dereference can be exploited to escalate privileges by a…
CVE-2026-815245.35.1MongoDBC DriverCWE-99Cross-tenant database retargeting via dot/NUL injection in namespace strings …
CVE-2026-37068await5.0n/an/a—Arbitrary file write in /vfm-admin/index.php?section=translations&action=upda…
CVE-2026-37070await5.0n/an/a—Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manage…
CVE-2026-37071await5.0n/an/a—Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile(…
CVE-2026-37072await5.0n/an/a—Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to In…
CVE-2026-59289await5.0SpringSpring for GraphQL—Spring for GraphQL Denial of Service via pagination support
CVE-2026-816809.34.9jahlivesopenssl_encryptCWE-347openssl_encrypt before 1.4.9 Authentication Bypass via Recovery Slot Removal
CVE-2026-26453await5.0n/an/a—ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer derefe…
CVE-2026-26457await5.0n/an/a—ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer derefe…
CVE-2026-738395.14.7EbyteEbyte NE2-D11 FirmwareCWE-522Ebyte NE2-D11 Insufficiently Protected Credentials
CVE-2026-566524.64.7scottchiefbakerdoolCWE-1236Formula Injection in dool project
CVE-2026-165694.34.7UnknownMobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerceCWE-284ShopApper <= 0.4.62 - Subscriber+ Arbitrary Product Stock Update
CVE-2026-781394.34.7UnknownNotifimaCWE-639Notifima < 3.1.4 - Subscriber+ Stock Alert Unsubscription via IDOR
CVE-2026-566512.04.6scottchiefbakerdoolCWE-59Arbitrary File Overwrite via Symlink Following in dool project
CVE-2026-38347await4.6n/an/a—A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.…
CVE-2026-183744.94.5The GNU C LibraryglibcCWE-787Passing an effectively empty string to the `,ccs=` syntax extension of the mo…
CVE-2026-592993.14.5SpringSpring Cloud Function—Composition lookup can potentially poison base function in Spring Cloud Function
CVE-2026-593003.14.5SpringSpring Cloud Function—Potential for logging sensitive data in Spring Cloud Function AWS
CVE-2026-593013.14.5SpringSpring Cloud Function—Potential for logging sensitive data in Spring Cloud Function Azure
CVE-2026-593023.14.5SpringSpring Cloud Stream—Potential for logging sensitive data in Spring Cloud Stream
CVE-2026-593033.14.5SpringSpring Cloud Stream—Dynamic destination cache size is not properly bound in Spring Cloud Stream
CVE-2026-593043.14.5SpringSpring Cloud Stream—Improper caching of the original content type in Spring Cloud Stream Avro
CVE-2026-593053.14.5SpringSpring Cloud Stream—Partition interceptor may be improperly added while sending message
CVE-2026-38343await4.5n/an/a—An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-12252…
CVE-2026-816978.74.4jahlivesopenssl_encryptCWE-426openssl_encrypt before 1.4.9 KDF Downgrade via CWD-relative Configuration
CVE-2026-30051await4.4n/an/a—An issue in the CreateUEContextProcedure function (/v1/ue-contexts/{supi}) of…
CVE-2026-30058await4.4n/an/a—Improper Input Validation in the HTTPModifySubscription handler of free5gc v4…
CVE-2026-30059await4.4n/an/a—An issue in the NAS decoder component of free5gc v4.0.1 allows attackers to c…
CVE-2026-30060await4.4n/an/a—An issue in free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS…
CVE-2026-30063await4.4n/an/a—An issue in the NF Discovery endpoint of free5gc v4.0.1 allows attackers to c…
CVE-2026-30064await4.4n/an/a—Improper input validation in the buildFilter function (processor/processor.go…
CVE-2026-30068await4.4n/an/a—Improper input validation in the HandleUpdate function (/sbi/parameter_provis…
CVE-2026-30069await4.4n/an/a—A NULL pointer dereference in the UDMC registration handler component of free…
CVE-2026-30070await4.4n/an/a—An issue in the HandleGetSharedData function of free5gc v4.0.1 allows attacke…
CVE-2026-30071await4.4n/an/a—An issue in the RechargePut function of free5gc v4.0.1 allows attackers to ca…
CVE-2026-38344await4.4n/an/a—A NULL pointer dereference in the get_min_buffer_size function (/libswscale/s…
CVE-2026-38345await4.4n/an/a—A Division-by-Zero vulnerability in the ff_sws_init_single_context function (…
CVE-2026-38346await4.4n/an/a—An integer overflow in the yuv2planeX_8_c() function (libswscale/output.c) of…
CVE-2026-38348await4.4n/an/a—An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gd…
CVE-2026-38349await4.4n/an/a—An integer overflow in the hScale16To19_c() function (libswscale/output.c) of…
CVE-2026-38350await4.4n/an/a—An integer overflow in the target_sws_fuzzer() function (libswscale/output.c)…
CVE-2026-59282await4.4SpringSpring Framework—Spring Framework Denial of Service via Unbounded List Growth in Data Binding
CVE-2026-59287await4.4SpringSpring for GraphQL—Spring for GraphQL WebSocket Client Denial of Service
CVE-2026-59288await4.4SpringSpring for GraphQL—Spring for GraphQL Information Exposure in GraphiQL support
CVE-2026-75337await4.4n/an/a—The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v…
CVE-2026-75339await4.4n/an/a—The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permis…
CVE-2026-75417await4.3n/an/a—A SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in th…

Results continue: ranks 401–437.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-27 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.