AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U H L L 6.4 .0344 88.1 —
AFFECTED Product Versions Fixed Spring Integration 7.1.0 – —
TIMELINE May 20 Reserved by CNA Aug 27 Published (CNA: vmware)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
CISA adds 3 to KEV; 437 CVEs published, led by Spring (64).
437 CVEs published August 27, 2026: 65 critical, 153 high, 131 medium, 22 low; 0 in the KEV catalog at press time; 6 with a public exploit reference; 66 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 37 on continuation pages.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 11277 | 33716 | — | — |
| KEV catalog size | 1685 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
1943 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 1509 | 3824 | 401 | 1914 | 637 | 1 | 12 | 3 | 0.1 | 7.8 | .0016 | +680 ▲ |
| 402 | 2164 | 270 | 838 | 927 | 73 | 77 | 6 | 0.3 | 7.5 | .0026 | +282 ▲ | |
| microsoft | 469 | 1891 | 145 | 1282 | 450 | 14 | 287 | 28 | 1.5 | 7.8 | .0044 | -194 ▼ |
| red hat | 217 | 610 | 42 | 254 | 281 | 32 | 2 | 0 | 0.0 | 6.8 | .0029 | +93 ▲ |
| apple | 44 | 316 | 59 | 85 | 165 | 7 | 88 | 8 | 2.5 | 6.5 | .0029 | -123 ▼ |
| freebsd | 32 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | +32 ▲ |
| canonical | 15 | 42 | 13 | 11 | 13 | 5 | 0 | 0 | 0.0 | 7.8 | .0020 | +8 ▲ |
| suse | 7 | 28 | 5 | 14 | 8 | 1 | 0 | 0 | 0.0 | 7.7 | .0038 | -1 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 46 | 84 | 21 | 39 | 24 | 0 | 56 | 13 | 15.5 | 7.5 | .0044 | +31 ▲ |
| ubiquiti | 23 | 59 | 36 | 22 | 1 | 0 | 3 | 3 | 5.1 | 9.1 | .0049 | -2 ▼ |
| palo alto networks | 12 | 37 | 1 | 3 | 21 | 12 | 13 | 2 | 5.4 | 4.7 | .0020 | -2 ▼ |
| netgear | 9 | 32 | 0 | 0 | 27 | 5 | 0 | 0 | 0.0 | 4.3 | .0025 | +3 ▲ |
| fortinet | 7 | 30 | 7 | 8 | 14 | 1 | 28 | 6 | 20.0 | 7.0 | .0050 | -7 ▼ |
| vmware | 2 | 19 | 5 | 9 | 3 | 2 | 7 | 2 | 10.5 | 8.3 | .0040 | -6 ▼ |
| f5 | 0 | 17 | 5 | 9 | 3 | 0 | 4 | 1 | 5.9 | 8.7 | .0057 | -8 ▼ |
| sonicwall | 12 | 14 | 3 | 7 | 4 | 0 | 17 | 2 | 14.3 | 7.8 | .0024 | +10 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 159 | 496 | 102 | 216 | 164 | 13 | 33 | 2 | 0.4 | 7.5 | .0049 | +39 ▲ |
| mozilla | 59 | 186 | 68 | 68 | 50 | 0 | 9 | 0 | 0.0 | 8.1 | .0030 | -12 ▼ |
| gitlab | 25 | 76 | 2 | 18 | 47 | 9 | 4 | 2 | 2.6 | 5.3 | .0028 | +18 ▲ |
| drupal | 17 | 68 | 10 | 7 | 46 | 5 | 4 | 1 | 1.5 | 5.9 | .0024 | -29 ▼ |
| github | 5 | 17 | 1 | 7 | 9 | 0 | 0 | 0 | 0.0 | 6.6 | .0043 | 0 |
| docker | 2 | 9 | 0 | 6 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0016 | +2 ▲ |
| wordpress | 2 | 5 | 1 | 3 | 1 | 0 | 2 | 2 | 40.0 | 8.8 | .3120 | 0 |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0035 | -1 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 890 | 2269 | 484 | 1170 | 519 | 96 | 28 | 4 | 0.2 | 7.8 | .0034 | -219 ▼ |
| adobe | 101 | 606 | 50 | 300 | 247 | 9 | 19 | 3 | 0.5 | 7.8 | .0021 | +6 ▲ |
| ibm | 374 | 603 | 144 | 280 | 171 | 8 | 6 | 1 | 0.2 | 7.6 | .0030 | +337 ▲ |
| progress | 19 | 61 | 14 | 37 | 10 | 0 | 6 | 1 | 1.6 | 8.1 | .0037 | -14 ▼ |
| solarwinds | 0 | 23 | 17 | 3 | 3 | 0 | 10 | 4 | 17.4 | 9.1 | .0058 | -15 ▼ |
| veeam | 13 | 19 | 6 | 10 | 3 | 0 | 1 | 0 | 0.0 | 8.6 | .0032 | +12 ▲ |
| zohocorp | 4 | 10 | 3 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0140 | +1 ▲ |
| atlassian | 3 | 6 | 1 | 5 | 0 | 0 | 13 | 0 | 0.0 | 8.1 | .0034 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| siemens | 21 | 37 | 2 | 24 | 8 | 3 | 0 | 0 | 0.0 | 7.3 | .0016 | +14 ▲ |
| d-link | 16 | 36 | 15 | 5 | 9 | 7 | 3 | 0 | 0.0 | 7.4 | .0157 | +8 ▲ |
| rockwell automation | 1 | 25 | 4 | 17 | 4 | 0 | 0 | 0 | 0.0 | 8.4 | .0024 | -16 ▼ |
| synology | 1 | 24 | 2 | 6 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +1 ▲ |
| schneider electric | 0 | 9 | 1 | 6 | 2 | 0 | 0 | 0 | 0.0 | 8.6 | .0037 | 0 |
| abb | 0 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -1 ▼ |
| hikvision | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0040 | -5 ▼ |
| mitsubishi electric | 0 | 5 | 0 | 4 | 1 | 0 | 0 | 0 | 0.0 | 7.2 | .0052 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| spring | 91 | 170 | 6 | 51 | 85 | 16 | 0 | 0 | 0.0 | 6.3 | .0022 | +91 ▲ |
| dell | 71 | 170 | 11 | 89 | 65 | 5 | 2 | 1 | 0.6 | 7.2 | .0019 | +28 ▲ |
| sourcecodester | 48 | 168 | 0 | 0 | 92 | 76 | 0 | 0 | 0.0 | 5.5 | .0029 | -1 ▼ |
| nvidia | 52 | 134 | 16 | 88 | 30 | 0 | 0 | 0 | 0.0 | 7.8 | .0034 | +10 ▲ |
| splunk | 110 | 128 | 6 | 47 | 70 | 5 | 1 | 1 | 0.8 | 6.5 | .0025 | +107 ▲ |
| openclaw | 0 | 111 | 0 | 58 | 39 | 14 | 0 | 0 | 0.0 | 7.0 | .0026 | -44 ▼ |
| getgrav | 66 | 104 | 15 | 59 | 28 | 2 | 0 | 0 | 0.0 | 8.4 | .0032 | +29 ▲ |
| zephyrproject | 50 | 103 | 3 | 33 | 56 | 11 | 0 | 0 | 0.0 | 6.4 | .0021 | +25 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-8037 | .9957 | 99.9 | 9.8 |
| CVE-2026-34486 | .9862 | 99.9 | 7.5 |
| CVE-2026-63077 | .8771 | 99.8 | 9.8 |
| CVE-2026-60004 | .8455 | 99.7 | 9.8 |
| CVE-2026-72898 | .7922 | 99.6 | 10.0 |
| CVE-2026-18577 | .5407 | 99.0 | 8.2 |
| CVE-2026-59310 | .4588 | 98.8 | 9.8 |
| CVE-2026-18556 | .4016 | 98.6 | 8.2 |
| CVE-2026-64638 | .3120 | 98.2 | 8.9 |
| CVE-2026-66066 | .2786 | 98.0 | 9.5 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-72898 | 10.0 | .7922 | KEV |
| CVE-2026-48362 | 10.0 | .0431 | |
| CVE-2026-19188 | 10.0 | .0193 | |
| CVE-2026-58231 | 10.0 | .0171 | |
| CVE-2026-69836 | 10.0 | .0155 | |
| CVE-2026-76195 | 10.0 | .0147 | |
| CVE-2026-76197 | 10.0 | .0147 | |
| CVE-2026-73299 | 10.0 | .0121 | |
| CVE-2026-73678 | 10.0 | .0114 | |
| CVE-2026-77554 | 10.0 | .0099 |
| Vendor | CVEs |
|---|---|
| linux | 1515 |
| oracle | 890 |
| 778 | |
| microsoft | 470 |
| ibm | 411 |
| red hat | 252 |
| apache | 216 |
| splunk | 110 |
| adobe | 104 |
| spring | 97 |
| Vendor | KEV |
|---|---|
| microsoft | 28 |
| cisco | 13 |
| apple | 8 |
| fortinet | 6 |
| 6 | |
| ivanti | 5 |
| oracle | 4 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 58 |
| Packagist | 27 |
| PyPI | 14 |
| npm | 12 |
| Go | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-18556 | N-able | 0 |
| CVE-2026-18577 | N-able | 0 |
| CVE-2026-20316 | Cisco | 0 |
| CVE-2026-20349 | Cisco | 0 |
| CVE-2026-34486 | Apache Software Foundation | 0 |
| CVE-2026-63077 | JetBrains | 0 |
| CVE-2026-72529 | TrueConf | 0 |
| CVE-2026-72530 | TrueConf | 0 |
| CVE-2026-72898 | Metabase | 0 |
| CVE-2026-8037 | Progress Software | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1744 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1744 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1744 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1744 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1744 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1744 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1744 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1744 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1744 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1744 |
ADDED TO KEV — CVE-2023-49105. Remediation due August 30, 2026.
ADDED TO KEV — CVE-2026-53362 (Linux). Remediation due August 30, 2026.
ADDED TO KEV — CVE-2026-66384 (jfrog artifactory). Remediation due September 10, 2026.
EXPLOIT PUBLISHED — nltk: 4 CVEs (CVE-2026-62383, CVE-2026-62388, CVE-2026-63311, CVE-2026-66393). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2021-23758 (AjaxPro.2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-0995 (kernel). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-13598 (Unknown RestrictMate). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18252 (GitLab). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-2332 (Eclipse Foundation Eclipse Jetty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-29181 (open-telemetry opentelemetry-go). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-41035 (Samba rsync). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44902 (open-telemetry opentelemetry-js). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56121 (feast-dev feast). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-78435 (Faveo Helpdesk). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-78638 (peerigon unzip-crx). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-79623 (FishCodeTech Muteki). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-79911 (TOTOLINK N600R). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-81202 (itsourcecode Payroll System). Public exploit reference added.
RESCORED — Google Chrome: 4 CVEs (CVE-2026-78983, CVE-2026-79054, CVE-2026-79210, CVE-2026-79224). CVSS rescored — before/after on each CVE page.
RESCORED — FreeBSD: 3 CVEs (CVE-2026-58092, CVE-2026-58095, CVE-2026-58096). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2021-23758 (AjaxPro.2). CVSS 8.1 → 9.8 (NVD).
RESCORED — CVE-2026-10573 (Rockwell Automation 1734 POINT I/O). CVSS 8.7 → 6.3 (NVD).
RESCORED — CVE-2026-13097 (Red Hat Enterprise Linux 10). CVSS 9.1 → 8.7 (NVD).
RESCORED — CVE-2026-65660 (Microsoft SharePoint Enterprise Server 2016). CVSS 6.5 → 8.8 (NVD).
RESCORED — CVE-2026-66299 (Apache Software Foundation Apache Tomcat). CVSS 7.5 → 5.3 (NVD).
RESCORED — CVE-2026-81421 (ddfourtwo sentry-selfhosted-mcp). CVSS 6.9 → 5.5 (NVD).
PATCH SHIPPED — CVE-2026-15538 (primefaces primereact). Fixed in primereact 10.9.9.
PATCH SHIPPED — CVE-2026-34621 (Adobe Acrobat DC). Fixed in Acrobat DC 26.001.21411.
How to read these box scores · glossary
437 CVEs published. 25 box scores and 375 table rows below; the remaining 37 continue on page 2 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U H L L 6.4 .0344 88.1 —
AFFECTED Product Versions Fixed Spring Integration 7.1.0 – —
TIMELINE May 20 Reserved by CNA Aug 27 Published (CNA: vmware)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0263 84.4 —
AFFECTED Product Versions Fixed WE1326 19.1101 – — WE2426-C 19.1112 – — WE357 19.1101 – — WE5926 19.1101 – — WE5926-EC_QP 20.0516 – — WE5926-WD 19.1101 – — WE826-Q 19.1101 – — WE826-T2 19.1101 – — WE826-WD 19.1101 – — WF3526-P 19.051 – — + 6 more
TIMELINE Aug 14 Reserved by CNA Aug 27 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0232 82.0 —
AFFECTED Product Versions Fixed Zoneminder 1.37.48 – 1.38.3
TIMELINE Aug 18 Reserved by CNA Aug 27 Published (CNA: icscert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0122 66.1 —
AFFECTED Product Versions Fixed Xiiaozet LK100W unspecified 2.1.240
TIMELINE Aug 25 Reserved by CNA Aug 27 Published (CNA: icscert)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0096 58.4 —
AFFECTED Product Versions Fixed core < 2.2.2 - 1103 – —
TIMELINE Jun 24 Reserved by CNA Aug 27 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0072 51.0 —
AFFECTED Product Versions Fixed silverstripe-advancedworkflow < 6.4.5 – —
TIMELINE Jun 15 Reserved by CNA Aug 27 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV A L N N N H H H 8.7 .0071 50.7 —
AFFECTED Product Versions Fixed G1 EDU unspecified —
TIMELINE Aug 19 Reserved by CNA Aug 27 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0070 50.1 —
AFFECTED Product Versions Fixed Dimension 2.0 – —
TIMELINE Aug 24 Reserved by CNA Aug 27 Published (CNA: WatchGuard)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0070 50.1 —
AFFECTED Product Versions Fixed Dimension 2.0 – —
TIMELINE Aug 24 Reserved by CNA Aug 27 Published (CNA: WatchGuard)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0067 49.2 —
AFFECTED Product Versions Fixed Xiiaozet LK100W unspecified 2.1.240
TIMELINE Aug 25 Reserved by CNA Aug 27 Published (CNA: icscert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N L N L L L 1.9 .0063 47.6 —
AFFECTED Product Versions Fixed claude-in-mobile 3.10.2 – 3.10.3
TIMELINE Aug 27 Reserved by CNA Aug 27 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H N N 7.1 .0062 47.1 —
AFFECTED Product Versions Fixed personal-management-system unspecified a0443570e105ed4835ce57f3c0a3e33d5b77418c
TIMELINE Apr 13 Reserved by CNA Aug 27 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0061 46.3 —
AFFECTED Product Versions Fixed Dimension 2.0 – —
TIMELINE Aug 24 Reserved by CNA Aug 27 Published (CNA: WatchGuard)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0061 46.3 —
AFFECTED Product Versions Fixed Red Hat Enterprise Linux 10 unspecified — Red Hat Enterprise Linux 6 unspecified — Red Hat Enterprise Linux 6 unspecified — Red Hat Enterprise Linux 7 unspecified — Red Hat Enterprise Linux 8 unspecified — Red Hat Enterprise Linux 9 unspecified —
TIMELINE Aug 21 Reserved by CNA Aug 27 Published (CNA: redhat)
CVSS EPSS %ile KEV — .0060 46.1 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA Aug 27 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0059 45.5 —
AFFECTED Product Versions Fixed wazuh >= 4.4.0, < 4.14.7 – —
TIMELINE Jul 10 Reserved by CNA Aug 27 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.2 .0059 45.3 —
AFFECTED Product Versions Fixed Redis 8.8.0 – 8.2.9
TIMELINE Aug 27 Reserved by CNA Aug 27 Published (CNA: cisa-cg)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0057 44.8 —
AFFECTED Product Versions Fixed ToolUniverse unspecified —
TIMELINE Aug 26 Reserved by CNA Aug 27 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0055 43.7 —
AFFECTED Product Versions Fixed Xiiaozet LK100W unspecified 2.1.240
TIMELINE Aug 25 Reserved by CNA Aug 27 Published (CNA: icscert)
CVSS EPSS %ile KEV — .0054 43.0 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA Aug 27 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0053 42.7 —
AFFECTED Product Versions Fixed UI-TARS-desktop unspecified c2ad42e3eb9b27830db41a3e6f51ca7179d9b168
TIMELINE Aug 27 Reserved by CNA Aug 27 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0053 42.5 —
AFFECTED Product Versions Fixed Ebyte NE2-D11 Firmware FW-9167-0-11 – —
TIMELINE Aug 20 Reserved by CNA Aug 27 Published (CNA: icscert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0053 42.5 —
AFFECTED Product Versions Fixed Greenbone OS 5.0 – — openvas-scanner 3.0 – —
TIMELINE Aug 27 Reserved by CNA Aug 27 Published (CNA: CERTVDE)
CVSS EPSS %ile KEV — .0053 42.4 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA Aug 27 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0053 42.2 —
AFFECTED Product Versions Fixed Geo Controller n/a – 8.9.9
TIMELINE Aug 24 Reserved by CNA Aug 27 Published (CNA: Patchstack)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-78292 | 9.8 | 42.2 | hashthemes | Hash Form | CWE-502 | WordPress Hash Form plugin <= 1.4.1 - PHP Object Injection vulnerability |
| CVE-2026-71187 | 9.3 | 41.9 | Ebyte | Ebyte NE2-D11 Firmware | CWE-603 | Ebyte NE2-D11 Use of Client-Side Authentication |
| CVE-2026-81098 | 9.3 | 40.9 | team-telnyx | telnyx-mcp | CWE-306 | Telnyx MCP Server through 6.83.0 Missing Authentication on Streamable HTTP Tr… |
| CVE-2026-78276 | 7.2 | 40.8 | WP Manage Ninja | Fluent Boards Pro | CWE-502 | WordPress Fluent Boards Pro plugin <= 2.0.11 - PHP Object Injection vulnerabi… |
| CVE-2026-75020 | 7.0 | 40.8 | Apache Software Foundation | Apache APISIX | CWE-90 | Apache APISIX: ldap-auth plugin cross-subtree identity impersonation |
| CVE-2026-78275 | 6.8 | 40.8 | WP Manage Ninja | Fluent Boards Pro | CWE-22 | WordPress Fluent Boards Pro plugin <= 2.0.11 - Arbitrary File Deletion vulner… |
| CVE-2026-80212 | 7.5 | 39.9 | Ruby | resolv | CWE-770 | An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS:… |
| CVE-2026-81690 | 8.7 | 39.8 | jahlives | openssl_encrypt | CWE-59 | verify-usb before 1.4.9 Symlink Directory Traversal Code Execution |
| CVE-2026-75005 | 8.7 | 39.7 | Apache Software Foundation | Apache APISIX | CWE-407 | Apache APISIX: Unauthenticated CPU-exhaustion DoS |
| CVE-2026-74848 | 7.0 | 39.7 | Apache Software Foundation | Apache APISIX | CWE-444 | Apache APISIX: Cross-user response poisoning in serverless plugins |
| CVE-2026-78257 | 8.8 | 39.5 | magepeopleteam | Booking and Rental Manager | CWE-502 | WordPress Booking and Rental Manager plugin <= 2.7.5 - PHP Object Injection v… |
| CVE-2026-81485 | 5.5 | 39.3 | danielpopamd | linkedin-ads-mcp | CWE-22 | danielpopamd linkedin-ads-mcp Media Upload campaign-management.ts fs.readFile… |
| CVE-2026-81486 | 5.5 | 39.3 | bsmi021 | mcp-file-context-server | CWE-22 | bsmi021 mcp-file-context-server Path Resolution index.ts read_context path tr… |
| CVE-2026-81560 | 5.5 | 39.3 | blackms | aistack | CWE-22 | blackms aistack Static File server.ts path traversal |
| CVE-2026-81093 | 8.7 | 39.1 | apify | actors-mcp-server | CWE-918 | Apify Actors MCP Server before 0.9.12 Server-Side Request Forgery via get-htm… |
| CVE-2026-74232 | 9.3 | 39.0 | Zbtlink | L3_V2_8 | CWE-300 | Zbtlink MQWrt yunmgrd Cloud C2 Implant |
| CVE-2026-19313 | 9.3 | 38.8 | WatchGuard | Fireware OS | CWE-122 | Fireware OS Pre-Authentication Heap Buffer Overflow in iked Allows Remote Cod… |
| CVE-2026-19318 | 9.3 | 38.8 | WatchGuard | Fireware OS | CWE-121 | Fireware OS Pre-Authentication Stack Buffer Overflow in iked Allows Remote Co… |
| CVE-2026-78274 | 9.1 | 38.3 | WP Manage Ninja | Fluent Boards Pro | CWE-434 | WordPress Fluent Boards Pro plugin <= 2.0.11 - Arbitrary File Upload vulnerab… |
| CVE-2026-54687 | 6.1 | 37.9 | DangerBlack | n8n-node-sqlite3 | CWE-22 | n8n-nodes-sqlite3: Path traversal via user-controlled database file path (db_… |
| CVE-2026-19315 | 9.3 | 37.8 | WatchGuard | Fireware OS | CWE-125 | Fireware OS Pre-Authentication Type Confusion in iked Allows Remote Code Exec… |
| CVE-2026-81573 | 8.6 | 37.7 | wibu-systems-ag | codemeter-runtime | CWE-284 | Improper Access Control in Local-Only Configuration Commands |
| CVE-2026-32566 | 9.8 | 37.3 | ACPT | ACPT (Pro) - Custom Post Types Plugin for WordPress | CWE-266 | WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.6… |
| CVE-2026-18965 | 8.7 | 36.7 | PayRange | PayRange API | CWE-862 | Missing Authorization in PayRange API |
| CVE-2026-13086 | 9.3 | 36.7 | WatchGuard | Fireware OS | CWE-121 | Fireware OS Stack-Based Buffer Overflow in Mobile Security epm Endpoint |
| CVE-2026-81575 | 7.5 | 36.6 | wibu-systems-ag | codemeter-runtime | CWE-130 | Missing Sanity Checks for Buffer Lengths |
| CVE-2026-59285 | await | 36.3 | Spring | Spring for GraphQL | — | Spring for GraphQL Unsafe Deserialization in pagination support |
| CVE-2026-76179 | 9.3 | 36.1 | Ebyte | Ebyte NE2-D11 Firmware | CWE-598 | Ebyte NE2-D11 Use of GET Request Method With Sensitive Query Strings |
| CVE-2026-47727 | 8.6 | 36.1 | TriliumNext | Trilium | CWE-94 | Trilium: RCE via `shareTemplate` relation missing `isDangerous` flag — Safe i… |
| CVE-2026-78271 | 7.2 | 35.7 | WP Manage Ninja | FluentCRM Pro | CWE-266 | WordPress FluentCRM Pro plugin <= 3.1.12 - Privilege Escalation vulnerability |
| CVE-2026-55758 | 6.9 | 35.4 | cc-tweaked | CC-Tweaked | CWE-918 | CC: Tweaked: Incomplete fix for GHSA-5jh9-2h63-pw4q: RFC 8215 NAT64 prefix (6… |
| CVE-2026-81094 | 9.3 | 35.1 | mcp-router | mcp-router | CWE-306 | mcp-router CLI before 0.6.3 Binds the MCP Aggregator to All Interfaces Withou… |
| CVE-2026-47884 | 9.8 | 35.1 | Spring | Spring Framework | CWE-22 | Spring Framework Improper Path Limitation in XsltView |
| CVE-2026-81335 | 8.7 | 35.0 | Baserow | Baserow | CWE-862 | Baserow before 2.3.1 Unauthenticated Data Disclosure via Discarded Permission… |
| CVE-2026-54721 | 8.8 | 34.4 | silverstripe | silverstripe-userforms | CWE-94 | Silverstripe UserForms: Remote code execution via userforms email subject |
| CVE-2026-77991 | 9.4 | 34.3 | joomlaeventmanager.net | JEM - Joomla Event Manager extension for Joomla | CWE-434 | Joomla Extension - joomlaeventmanager.net - Privileged remote code execution … |
| CVE-2026-81707 | 9.3 | 34.0 | jahlives | openssl_encrypt | CWE-20 | openssl_encrypt before 1.4.9 ANSI Escape Injection via Identity Email |
| CVE-2026-81491 | 5.5 | 33.9 | boxpositron | with-context-mcp | CWE-22 | boxpositron with-context-mcp index.ts project_folder path traversal |
| CVE-2026-81574 | 8.2 | 33.8 | wibu-systems-ag | codemeter-runtime | CWE-134 | Format String Vulnerability in Logger |
| CVE-2026-77018 | 8.8 | 33.6 | Unknown | Workeera | CWE-434 | Workeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Upload vi… |
| CVE-2026-5680 | 7.5 | 33.4 | Red Hat | Red Hat build of Apache Camel for Spring Boot 4 | CWE-770 | Undertow-core: undertow: denial of service via websocket permessage-deflate p… |
| CVE-2026-61802 | 6.5 | 33.0 | wazuh | wazuh | CWE-200 | Wazuh discloses cleartext cluster key to low-privilege API users via GET /clu… |
| CVE-2026-66353 | 5.3 | 32.4 | woylie | doggo | CWE-79 | Doggo vulnerable to cross-site scripting via unescaped date field values |
| CVE-2026-81721 | 8.7 | 32.3 | jahlives | openssl_encrypt | CWE-400 | openssl_encrypt before 1.4.9 Denial of Service via KDF |
| CVE-2026-18885 | 10.0 | 31.1 | ServiceNow | ServiceNow AI Platform | — | Unauthenticated Remote Code Execution in GraphQL Composite Data API |
| CVE-2026-32479 | 9.3 | 31.2 | CODEPRESS IT Solutions LLC | Visitor Traffic Real Time Statistics Pro | CWE-89 | WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.17 - SQL Inje… |
| CVE-2026-78260 | 9.3 | 31.2 | ePayco | Epayco | CWE-89 | WordPress Epayco plugin <= 8.4.6 - SQL Injection vulnerability |
| CVE-2026-78288 | 9.3 | 31.2 | Jonathan de Jong | Beautiful Taxonomy Filters | CWE-89 | WordPress Beautiful Taxonomy Filters plugin <= 2.4.6 - SQL Injection vulnerab… |
| CVE-2026-80433 | 7.5 | 30.5 | Brainstorm Force | SureFeedback Client Site | CWE-862 | WordPress SureFeedback Client Site plugin <= 1.2.12 - Sensitive Data Exposure… |
| CVE-2026-81730 | 8.8 | 30.4 | Dolibarr | dolibarr | CWE-22 | Dolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Attachment Fi… |
| CVE-2026-59354 | 9.6 | 30.1 | VMware by Broadcom | Spring Security (OAuth2 Authorization Server module) | CWE-20 | Spring Security OAuth2 Authorization Server: Insufficient validation of Dynam… |
| CVE-2026-79653 | 6.0 | 29.8 | Eclipse Foundation | Eclipse SW360 | CWE-22 | In Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if the syst… |
| CVE-2026-19223 | 7.2 | 29.8 | Unknown | Smush | CWE-94 | Smush < 4.3.2 - Admin+ Network-Wide RCE via Hub Connector on Multisite |
| CVE-2026-59317 | 6.5 | 29.5 | Spring | Spring for Apache Kafka | — | In Spring for Apache Kafka, missing header validation in DeadLetterPublishing… |
| CVE-2026-76945 | 8.7 | 29.2 | Ebyte | Ebyte NE2-D11 Firmware | CWE-603 | Ebyte NE2-D11 Use of Client-Side Authentication |
| CVE-2026-54713 | 3.7 | 29.2 | cakephp | queue | CWE-1023 | CakePHP Queue: Incomplete Comparison in getUniqueId vulnerable to collisions |
| CVE-2026-10036 | 8.7 | 29.1 | speechbrain | speechbrain | CWE-502 | SpeechBrain < 1.1.1 Arbitrary Code Execution via CKPT.yaml Parsing |
| CVE-2026-81673 | 9.3 | 28.5 | TOOOLS | iSquad | CWE-89 | Multiple Vulnerabilities in TOOOLS' iSquad |
| CVE-2026-76940 | 8.7 | 28.4 | Ebyte | Ebyte NE2-D11 Firmware | CWE-307 | Ebyte NE2-D11 Improper Restriction of Excessive Authentication Attempts |
| CVE-2026-81699 | 8.7 | 28.0 | jahlives | openssl_encrypt | CWE-770 | openssl_encrypt before 1.4.9 Denial of Service via unbounded KDF cost |
| CVE-2026-19092 | 9.8 | 27.8 | Unknown | Tutor LMS | CWE-74 | Tutor LMS < 4.0.6 - Unauthenticated Arbitrary Zero-Argument Function Invocati… |
| CVE-2026-81753 | 5.1 | 27.9 | flowintel | flowintel | CWE-79 | Flowintel Stored XSS in Case Notes via Malicious Mermaid Diagram Content |
| CVE-2026-76640 | 7.7 | 27.3 | Unitree Robotics | G1 EDU | CWE-306 | Unitree G1 EDU 1.5.2 BLE GATT RCE via WiFi Provisioning Stack |
| CVE-2026-59307 | 8.0 | 27.2 | Spring | Spring Integration | — | Deserialization allow-list silently bypassed: setBeanClassLoader replaces des… |
| CVE-2026-81722 | 8.7 | 27.0 | nltk | nltk | CWE-407 | nltk PorterStemmer before 3.10.3 Quadratic-time DoS |
| CVE-2026-81692 | 8.7 | 27.0 | jahlives | openssl_encrypt | CWE-789 | openssl_encrypt before 1.4.9 Denial of Service via STREAMINFO |
| CVE-2026-81693 | 8.7 | 27.0 | jahlives | openssl_encrypt | CWE-789 | openssl_encrypt before 1.4.9 Denial of Service via QR total field |
| CVE-2026-27330 | 8.6 | 26.9 | Weptile | Mobile App for WooCommerce | CWE-862 | WordPress Mobile App for WooCommerce plugin <= 0.4.62 - Broken Access Control… |
| CVE-2026-81091 | 8.7 | 26.8 | mcp-use | mcp-use | CWE-918 | mcp-use Inspector Proxy Server-Side Request Forgery via Caller-Supplied Targe… |
| CVE-2026-32550 | 8.5 | 26.8 | Liquid Web, LLC | Kadence Shop Kit | CWE-89 | WordPress Kadence Shop Kit plugin <= 3.0.6 - SQL Injection vulnerability |
| CVE-2026-32564 | 8.5 | 26.8 | ACPT | ACPT (Pro) - Custom Post Types Plugin for WordPress | CWE-89 | WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress plugin <= 2.0.6… |
| CVE-2026-78285 | 8.5 | 26.8 | LikeBtn | Like Button Rating | CWE-89 | WordPress Like Button Rating plugin <= 2.6.61 - SQL Injection vulnerability |
| CVE-2026-81277 | 8.5 | 26.8 | VillaTheme | Suggestion Engine for WooCommerce | CWE-89 | WordPress Suggestion Engine for WooCommerce plugin <= 2.0.11 - SQL Injection … |
| CVE-2026-59311 | 6.8 | 26.9 | Spring | Spring Integration | — | Fixed predictable /tmp/ziptransformer work directory enables symlink pre-crea… |
| CVE-2026-81845 | 5.3 | 26.2 | arben-adm | mcp-sequential-thinking | CWE-22 | arben-adm mcp-sequential-thinking Import Session/Export Session server.py exp… |
| CVE-2026-81837 | 5.3 | 26.0 | RooCodeInc | Roo-Code | CWE-22 | RooCodeInc Roo-Code ApplyPatchTool ApplyPatchTool.ts path.resolve path traversal |
| CVE-2026-81705 | 8.7 | 25.9 | jahlives | openssl_encrypt | CWE-532 | openssl-encrypt before 1.4.9 Password Cleartext Leak via Debug |
| CVE-2026-67560 | 7.7 | 25.9 | Bendix | EC80ESP+ J1708 | CWE-121 | Stack-based Buffer Overflow in Bendix EC80 Brake ECU |
| CVE-2026-59284 | 7.6 | 25.7 | Spring | Spring Cloud Commons | — | Spring Cloud Commons no allow list for writable env actuator endpoint |
| CVE-2026-54083 | 8.1 | 25.5 | wazuh | wazuh | CWE-22 | Wazuh: Path traversal in ip-customblock active response allows arbitrary file… |
| CVE-2026-81826 | 9.1 | 25.4 | flowintel | flowintel | CWE-384 | Flowintel Fails to Invalidate Active Sessions After Password Change |
| CVE-2026-78010 | 8.7 | 25.1 | WatchGuard | Fireware OS | CWE-121 | Fireware OS Stack-Based Buffer Overflow in iked Allows Unauthenticated Denial… |
| CVE-2026-81576 | 7.7 | 25.0 | wibu-systems-ag | codemeter-runtime | CWE-639 | Improper Authentication of Session Handles |
| CVE-2026-81678 | 6.9 | 25.1 | WWBN | AVideo | CWE-918 | AVideo SSRF Guard Bypass via IPv6 Transition Addresses |
| CVE-2026-30046 | 7.5 | 24.8 | n/a | n/a | CWE-617 | A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.… |
| CVE-2026-30047 | 7.5 | 24.8 | n/a | n/a | CWE-617 | A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts co… |
| CVE-2026-30050 | 7.5 | 24.8 | n/a | n/a | CWE-770 | An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event… |
| CVE-2026-30056 | 7.5 | 24.8 | n/a | n/a | CWE-476 | A NULL pointer dereference in the AMF NGAP Dispatcher component of free5gc v4… |
| CVE-2026-30057 | 7.5 | 24.8 | n/a | n/a | CWE-770 | An issue in the CreateUEContext handler component of free5gc v4.1.0 allows at… |
| CVE-2026-30062 | 7.5 | 24.8 | n/a | n/a | CWE-770 | An issue in the NGAP handler of free5gc v4.0.1 allows attackers to cause a De… |
| CVE-2026-47886 | 7.5 | 24.8 | Spring | Spring Framework | CWE-400 | Spring Framework Denial of Service via Unbounded Exponentiation in SpEL Expre… |
| CVE-2026-47888 | 7.5 | 24.8 | Spring | Spring Framework | CWE-401 | Spring Framework Memory Leak via SETUP Frame in RSocketMessageHandler |
| CVE-2026-6876 | 8.7 | 24.7 | ServiceNow | Now Platform | — | Sandbox Escape in Now Platform |
| CVE-2026-78617 | 6.3 | 24.6 | WatchGuard | Dimension | CWE-203 | WatchGuard Dimension Web UI Authentication Brute-Force Due to Missing Rate Li… |
| CVE-2026-19314 | 8.7 | 24.5 | WatchGuard | Fireware OS | CWE-191 | Fireware OS Integer Underflow in iked Allows Unauthenticated Denial of Servic… |
| CVE-2026-19316 | 8.7 | 24.5 | WatchGuard | Fireware OS | CWE-415 | Fireware OS Pre-Authentication Double Free in iked Allows Denial of Service (… |
| CVE-2026-19317 | 8.7 | 24.5 | WatchGuard | Fireware OS | CWE-125 | Fireware OS Pre-Authentication Out-of-Bounds Read in iked Allows Denial of Se… |
| CVE-2026-78009 | 8.7 | 24.5 | WatchGuard | Fireware OS | CWE-125 | Fireware OS Out-of-Bounds Read in iked Allows Unauthenticated Denial of Servi… |
| CVE-2026-78011 | 8.7 | 24.5 | WatchGuard | Fireware OS | CWE-191 | Fireware OS Integer Underflow in Iked Allows Unauthenticated Denial of Servic… |
| CVE-2026-81101 | 6.9 | 24.5 | Airtable | airtable-mcp-cli | CWE-200 | Airtable MCP CLI before 0.2.5 Credential Disclosure via Unvalidated Configure… |
| CVE-2026-81743 | 7.5 | 24.4 | flowintel | flowintel | CWE-22 | Flowintel Arbitrary Log File Path Allows Remote Code Execution via Template I… |
| CVE-2026-80213 | 4.0 | 24.1 | Ruby | resolv | CWE-197 | An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS:… |
| CVE-2026-81719 | 9.3 | 23.9 | jahlives | openssl_encrypt | CWE-94 | openssl_encrypt before 1.4.9 Remote Code Execution via Plugin |
| CVE-2026-47894 | 4.9 | 23.9 | Spring | Spring Cloud Config | — | Spring Cloud Config Server Native Environment Repository Exposure |
| CVE-2026-47890 | 9.8 | 23.7 | Spring | Spring Framework | CWE-93 | Spring Framework Server Sent Event stream corruption while rendering fragments |
| CVE-2026-80208 | 8.8 | 23.5 | apitable | apitable | CWE-306 | APITable through 1.13.0-beta.1 Missing Authentication on the Internal Account… |
| CVE-2026-81662 | 8.6 | 23.4 | flowintel | flowintel | CWE-20 | Flowintel Alert Settings Configuration Allows Remote Code Execution via Arbit… |
| CVE-2026-78008 | 8.6 | 23.1 | WatchGuard | Fireware OS | CWE-787 | Fireware OS Authenticated Buffer Overflow in wgagent |
| CVE-2026-81818 | 8.6 | 23.1 | flowintel | flowintel | CWE-269 | Flowintel Organization Administrator Can Reset Full Administrator Password an… |
| CVE-2026-81272 | 4.9 | 23.1 | WP Manage Ninja | FluentPlayer Pro | CWE-862 | WordPress FluentPlayer Pro plugin <= 1.3.2 - Broken Access Control vulnerability |
| CVE-2026-78174 | 9.3 | 23.0 | WatchGuard | Dimension | CWE-200 | WatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic … |
| CVE-2026-81701 | 9.3 | 23.0 | jahlives | openssl_encrypt | CWE-347 | openssl_encrypt before 1.4.9 Arbitrary Code Execution via unsigned plugin |
| CVE-2026-26897 | await | 22.8 | n/a | n/a | — | An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version … |
| CVE-2026-81676 | 8.8 | 22.4 | TOOOLS | iSquad | CWE-89 | Multiple Vulnerabilities in TOOOLS' iSquad |
| CVE-2026-82072 | 8.8 | 22.4 | Chrome | CWE-125 | Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a re… | |
| CVE-2026-81659 | 7.1 | 22.5 | flowintel | flowintel | CWE-22 | Flowintel Note PDF Export Allows Arbitrary Local File Read via Pandoc/XeLaTeX… |
| CVE-2026-54732 | 6.5 | 22.2 | elwerene | libreoffice-convert | CWE-22 | libreoffice-convert: path traversal / arbitrary file write |
| CVE-2026-75419 | 8.8 | 22.0 | n/a | n/a | — | go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. … |
| CVE-2026-59271 | 5.3 | 21.8 | Spring | Spring AMQP | CWE-209 | Admin password disclosed in BrokerNotAliveException message |
| CVE-2026-75418 | 7.5 | 21.7 | n/a | n/a | — | A path traversal vulnerability exists in the built-in preview/development web… |
| CVE-2026-81827 | 6.9 | 21.7 | flowintel | flowintel | CWE-20 | Flowintel Login Email Validation Bypass Allows Log Injection via Crafted Emai… |
| CVE-2026-65931 | 5.1 | 21.4 | LimeSurvey | LimeSurvey | CWE-862 | LimeSurvey Community Edition 7.0.5 - Improper authorization in survey menu en… |
| CVE-2026-59315 | 5.3 | 21.3 | Spring | Spring Cloud Config | — | Spring Cloud Config Monitor Denial of Service |
| CVE-2026-81819 | 5.3 | 21.4 | flowintel | flowintel | CWE-862 | Flowintel Missing Authorization Allows Regular API Users to View Other Users’… |
| CVE-2026-81664 | 6.9 | 21.2 | openfaas | faas | CWE-306 | OpenFaaS Gateway 0.27.11 through 0.27.13 Missing Authentication on the /syste… |
| CVE-2026-47891 | 9.8 | 21.1 | Spring | Spring Framework | CWE-770 | Spring Framework maxInMemorySize Bypassed in Jaxb2Decoder |
| CVE-2026-59270 | 9.4 | 21.0 | Spring | Spring Security | — | Spring Security embedded UnboundID LDAP server exposes well-known administrat… |
| CVE-2026-19225 | 6.6 | 21.0 | Unknown | Defender Security | CWE-94 | Defender Security < 6.2.0 - Admin+ Network-Wide RCE via Hub Connector on Mult… |
| CVE-2026-59320 | 6.5 | 21.0 | Spring | Spring AMQP | — | In Spring AMQP the link credit never replenished on listener exception path |
| CVE-2026-77358 | 8.2 | 20.7 | yhirose | cpp-httplib | CWE-416 | cpp-httplib: Use-after-free of TLS session in WebSocketClient::shutdown_and_c… |
| CVE-2026-81931 | 4.8 | 20.7 | Roskus | Prospero Flow CRM | CWE-434 | Unrestricted upload of file with dangerous type in Prospero Flow CRM product … |
| CVE-2026-81679 | 8.3 | 20.6 | openremote | openremote | CWE-200 | OpenRemote before 1.28.0 Cross-Realm Information Disclosure via Notification API |
| CVE-2026-80207 | 6.9 | 20.6 | apitable | apitable | CWE-306 | APITable through 1.13.0-beta.1 Missing Authentication on the Internal Notific… |
| CVE-2026-80209 | 5.3 | 20.7 | fonoster | fonoster | CWE-863 | Fonoster through 0.22.7 Incorrect Authorization in the Identity UpdateWorkspa… |
| CVE-2026-81698 | 9.3 | 20.5 | jahlives | openssl_encrypt | CWE-78 | openssl_encrypt before 1.4.9 Shell Injection via info command |
| CVE-2026-81672 | 9.3 | 20.3 | TOOOLS | iSquad | CWE-89 | Multiple Vulnerabilities in TOOOLS' iSquad |
| CVE-2026-81674 | 9.3 | 20.3 | TOOOLS | iSquad | CWE-89 | Multiple Vulnerabilities in TOOOLS' iSquad |
| CVE-2026-81274 | 5.3 | 20.2 | metaphorcreations | Ditty | CWE-862 | WordPress Ditty plugin <= 3.1.67 - Broken Access Control vulnerability |
| CVE-2026-81276 | 5.3 | 20.2 | WP Chill | Kali Forms | CWE-862 | WordPress Kali Forms plugin <= 2.4.23 - Broken Access Control vulnerability |
| CVE-2026-78137 | 7.5 | 20.1 | Unknown | StoreGrowth | CWE-862 | StoreGrowth: Smart Sales Booster for WooCommerce < 2.1.2 - Unauthenticated Ar… |
| CVE-2026-78333 | 8.8 | 19.6 | Unknown | 12 Step Meeting List | CWE-79 | 12 Step Meeting List 3.17 - 3.19.16 - Unauthenticated Stored XSS via Geocode … |
| CVE-2026-53580 | 8.1 | 19.4 | TriliumNext | Trilium | CWE-73 | Trilium arbitrary file read and denial of service via file:// URLs in the aut… |
| CVE-2026-47881 | 5.9 | 19.3 | Spring | Spring Batch | CWE-400 | Denial of Service in Spring Batch FlatFileItemReader via Malformed Input File |
| CVE-2026-81525 | 8.6 | 19.2 | MongoDB | PHP Library | CWE-943 | Cross-tenant database retargeting via dot/NUL injection in namespace strings … |
| CVE-2026-77341 | 5.3 | 19.2 | yhirose | cpp-httplib | CWE-93 | cpp-httplib: CRLF injection via unvalidated HTTP trailer headers in chunked r… |
| CVE-2026-37006 | await | 18.8 | n/a | n/a | — | A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and befor… |
| CVE-2026-47849 | 7.1 | 18.5 | Spring | Spring Data REST | CWE-915 | Spring Data REST allows mutation of identifier and version properties via JSO… |
| CVE-2026-5706 | 8.9 | 18.4 | Silicon Labs | BT Mesh SDK | CWE-130 | Buffer overflow in Bluetooth Mesh SDK when handling extended advertisements |
| CVE-2026-81522 | 8.6 | 18.1 | MongoDB | C++ Driver | CWE-116 | Cross-tenant database retargeting via dot/NUL injection in namespace strings … |
| CVE-2026-81726 | 8.3 | 18.0 | nltk | nltk | CWE-73 | NLTK through 3.10.3 Path Traversal via Model-Artifact APIs |
| CVE-2026-18886 | 10.0 | 18.0 | ServiceNow | ServiceNow AI Platform | — | Unauthenticated Privilege Escalation via System Configuration Image Upload Pr… |
| CVE-2026-75159 | 8.2 | 17.9 | MongoDB | BI Connector | CWE-415 | MongoDB BI Connector Improper Memory Handling During Failed Kerberos Authenti… |
| CVE-2026-30612 | await | 17.9 | n/a | n/a | — | An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS … |
| CVE-2026-79988 | 8.7 | 17.4 | craftcms | cms | CWE-693 | Authenticated RCE through Twig sandbox escape |
| CVE-2026-47885 | 7.5 | 17.4 | Spring | Spring Framework | CWE-770 | Spring Framework maxPartSize Ignored in PartEventHttpMessageReader |
| CVE-2026-81724 | 6.9 | 17.2 | nltk | nltk | CWE-674 | NLTK before 3.10.3 Denial of Service via Uncontrolled Recursion |
| CVE-2026-77989 | 5.3 | 17.2 | joomlaeventmanager.net | JEM - Joomla Event Manager extension for Joomla | CWE-79 | Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export … |
| CVE-2026-37007 | await | 17.2 | n/a | n/a | — | A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remot… |
| CVE-2026-75357 | await | 17.2 | n/a | n/a | — | An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arb… |
| CVE-2026-68929 | 9.3 | 17.1 | labring | FastGPT | CWE-862 | FastGPT: Unauthenticated WeChat channel hijack and denial of service via shar… |
| CVE-2026-13415 | 7.2 | 17.1 | Unknown | CMP | CWE-269 | CMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Privilege Escalation via c… |
| CVE-2026-68967 | 7.1 | 17.1 | Bendix | EC80ESP+ J1708 | CWE-787 | Out-of-bounds Write in Bendix EC80 Brake ECU |
| CVE-2026-59276 | 5.9 | 17.1 | Spring | Spring Security | CWE-208 | Timing Attack via Non-Constant-Time Comparison of Sensitive Values |
| CVE-2026-78103 | 5.1 | 17.1 | WatchGuard | Dimension | CWE-841 | Dimension Log Server Configuration Lock Bypass Vulnerability |
| CVE-2026-81728 | 8.6 | 16.9 | Dolibarr | dolibarr | CWE-89 | Dolibarr before 24.0.0 SQL Injection via the CSV and XLSX Import Update Keys |
| CVE-2026-19715 | 7.5 | 17.0 | Unknown | WP OAuth Server ( Login with WordPress ) | CWE-200 | WP OAuth Server < 6.3.1 - Unauthenticated OAuth Token and User Data Disclosur… |
| CVE-2026-81814 | 5.1 | 16.9 | flowintel | flowintel | CWE-79 | Flowintel Stored XSS in Calendar via Malicious Case Title |
| CVE-2026-75813 | 8.7 | 16.9 | Ebyte | Ebyte NE2-D11 Firmware | CWE-862 | Ebyte NE2-D11 Missing Authorization |
| CVE-2026-16279 | 9.3 | 16.6 | Dassault Systèmes | 3DSwymer | CWE-285 | Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Re… |
| CVE-2026-81700 | 9.3 | 16.6 | jahlives | openssl_encrypt | CWE-347 | openssl_encrypt before 1.4.9 GPG Signature Verification Bypass |
| CVE-2026-78618 | 6.9 | 16.8 | WatchGuard | Dimension | CWE-284 | Dimension Business Logic Flaw Allows Chained Backend Object Operations |
| CVE-2026-19454 | 4.4 | 16.7 | Unknown | JetBackup | CWE-863 | JetBackup 3.1.18.8 - 3.1.23.3 - Admin+ Multisite Network Backup Download |
| CVE-2026-81675 | 9.3 | 16.5 | TOOOLS | iSquad | CWE-89 | Multiple Vulnerabilities in TOOOLS' iSquad |
| CVE-2026-13108 | 8.7 | 16.5 | WatchGuard | Dimension | CWE-400 | Dimension Denial-of-Service |
| CVE-2026-47889 | 7.5 | 16.5 | Spring | Spring Framework | CWE-1275 | Spring Framework sameSite Attribute Dropped in JettyCoreServerHttpResponse |
| CVE-2026-59294 | 5.9 | 16.3 | Spring | Spring AI | — | Arbitrary File Write via Path Traversal in ResourceCacheService |
| CVE-2026-80179 | 5.9 | 16.3 | Red Hat | Red Hat Ansible Automation Platform 2 | CWE-770 | Jwcrypto: jwcrypto: denial of service via malformed jwe tokens |
| CVE-2026-81820 | 5.1 | 16.4 | flowintel | flowintel | CWE-79 | Flowintel HTML Injection in MISP Case History Timeline via Crafted Object Att… |
| CVE-2026-81677 | 8.8 | 16.0 | TOOOLS | iSquad | CWE-89 | Multiple Vulnerabilities in TOOOLS' iSquad |
| CVE-2026-77017 | 7.7 | 16.1 | Unknown | Workeera | CWE-200 | Workeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Read via … |
| CVE-2026-47875 | 5.6 | 15.9 | Spring | Spring Batch | CWE-502 | JobParameterDeserializer bypasses the trusted-type allowlist |
| CVE-2026-47878 | 5.6 | 15.9 | Spring | Spring Batch | CWE-502 | Unsafe Java deserialization in DefaultExecutionContextSerializer without clas… |
| CVE-2026-37004 | await | 15.9 | n/a | n/a | — | BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SST… |
| CVE-2026-78615 | 4.6 | 15.8 | WatchGuard | Dimension | CWE-79 | WatchGuard Dimension Reflected DOM-Based XSS in Report Detail Page |
| CVE-2026-81851 | 6.9 | 15.6 | WatchGuard | Fireware OS | CWE-122 | Fireware OS Heap-Based Buffer Overflow in iked Allows Denial of Service |
| CVE-2026-59275 | 6.6 | 15.7 | Spring | Spring AMQP | CWE-502 | Remote JVM termination: nested-array Java deserialization bypasses allowlist,… |
| CVE-2026-80211 | 8.2 | 15.4 | FrontAccounting | FrontAccounting | CWE-916 | FrontAccounting through 2.4.20 Use of Unsalted MD5 for Password Storage |
| CVE-2026-47879 | 7.7 | 15.2 | Spring | Spring Cloud Gateway | CWE-918 | Spring Cloud Gateway SSRF and native file access with gRPC |
| CVE-2026-4398 | 5.4 | 15.2 | GitLab | GitLab | CWE-639 | Authorization Bypass Through User-Controlled Key in GitLab |
| CVE-2026-77016 | 9.6 | 15.1 | Unknown | Workeera | CWE-73 | Workeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Deletion … |
| CVE-2026-77438 | 7.5 | 15.1 | TriliumNext | Trilium | CWE-200 | Trilium unauthenticated share-search discloses password-protected and hidden … |
| CVE-2026-11754 | 5.3 | 15.0 | Seres Software | syWEB | CWE-203 | User Enumeration in Seres Software's syWEB |
| CVE-2026-69658 | 9.3 | 14.8 | Ebyte | Ebyte NE2-D11 Firmware | CWE-319 | Ebyte NE2-D11 Cleartext Transmission of Sensitive Information |
| CVE-2026-61783 | 7.0 | 14.8 | wazuh | wazuh | CWE-200 | Wazuh: RBAC permission-effect check in mask_sensitive_config allows low-privi… |
| CVE-2026-77034 | 6.9 | 14.9 | joomlaeventmanager.net | JEM - Joomla Event Manager extension for Joomla | CWE-284 | Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite… |
| CVE-2026-74820 | 10.0 | 14.6 | ServiceNow | ServiceNow AI Platform | — | Unauthenticated SQL Injection via Dynamic Schema ORDER BY Clause |
| CVE-2026-34674 | 7.8 | 14.7 | Adobe | Adobe Substance 3D Sampler | CWE-122 | Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122) |
| CVE-2026-59324 | 8.2 | 14.5 | Spring | Spring Integration | — | fluxTransform shared RequestMessageHolder causes cross-message header leakage… |
| CVE-2026-78261 | 7.1 | 14.5 | Realtyna | Realtyna Organic IDX plugin | CWE-79 | WordPress Realtyna Organic IDX plugin plugin <= 5.4.1 - Cross Site Scripting … |
| CVE-2026-78281 | 7.1 | 14.5 | codepeople | CP Media Player | CWE-79 | WordPress CP Media Player plugin <= 1.3.0 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-78283 | 7.1 | 14.5 | codepeople | Music Player for WooCommerce | CWE-79 | WordPress Music Player for WooCommerce plugin <= 1.8.9 - Cross Site Scripting… |
| CVE-2026-78289 | 7.1 | 14.5 | LoftOcean | CozyStay | CWE-79 | WordPress CozyStay theme <= 1.10.0 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-78293 | 7.1 | 14.5 | axew3 | WP w3all phpBB | CWE-79 | WordPress WP w3all phpBB plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-71396 | 5.3 | 14.4 | Bendix | EC80ESP+ J1708 | CWE-798 | Use of Hard-coded Credentials in Bendix EC80 Brake ECU |
| CVE-2026-54085 | 7.1 | 14.3 | wazuh | wazuh | CWE-88 | Wazuh: Missing input validation in multiple active response scripts allows ar… |
| CVE-2026-59274 | 6.5 | 14.2 | Spring | Spring Integration | CWE-409 | Unbounded decompression in UnZipTransformer enables zip-bomb DoS |
| CVE-2026-81847 | 5.1 | 14.3 | MAA-AI | MaaMCP | CWE-22 | MAA-AI MaaMCP pipeline_tools.py load_pipeline path traversal |
| CVE-2026-81834 | 2.1 | 14.1 | RooCodeInc | Roo-Code | CWE-74 | RooCodeInc Roo-Code README File ExecaTerminalProcess code injection |
| CVE-2026-59280 | 4.3 | 13.8 | Spring | Spring Framework | CWE-22 | Spring Framework Path Traversal via Backslash in SpringTemplateLoader |
| CVE-2026-78047 | 5.1 | 13.7 | WatchGuard | Dimension | CWE-79 | Dimension Stored XSS in Scheduled Report Task |
| CVE-2026-77977 | 7.2 | 13.5 | Ebyte | Ebyte NE2-D11 Firmware | CWE-306 | Ebyte NE2-D11 Missing Authentication for Critical Function |
| CVE-2026-77035 | 5.1 | 13.5 | joomlaeventmanager.net | JEM - Joomla Event Manager extension for Joomla | CWE-639 | Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeov… |
| CVE-2026-78498 | 5.1 | 13.5 | WatchGuard | Dimension | CWE-918 | Dimension Server-Side Request Forgery via Email Server Test Settings |
| CVE-2026-78499 | 5.1 | 13.5 | WatchGuard | Dimension | CWE-918 | Dimension SSRF via FTP Server Test Connection |
| CVE-2026-78500 | 5.1 | 13.5 | WatchGuard | Dimension | CWE-208 | Dimension Blind SSRF via Database Test Connection Feature |
| CVE-2026-59355 | 6.1 | 13.1 | VMware | Spring Authorization Server | CWE-601 | Spring Authorization Server: Open Redirect via request_uri parameter |
| CVE-2026-37009 | await | 13.2 | n/a | n/a | — | A SQL injection vulnerability in NL2SQLTool in crewai-tools v1.10.2rc1 allows… |
| CVE-2026-81723 | 6.3 | 12.6 | nltk | nltk | CWE-400 | NLTK before 3.10.3 Quadratic CPU Exhaustion via XMLCorpusView |
| CVE-2026-81725 | 6.3 | 12.6 | nltk | nltk | CWE-400 | NLTK before 3.10.3 Regular Expression Denial of Service via Pl196xCorpusReader |
| CVE-2026-59293 | 6.6 | 12.5 | Spring | Spring Integration | — | SMB minimum protocol dialect defaults to SMB1 |
| CVE-2026-36102 | await | 12.4 | n/a | n/a | — | An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.… |
| CVE-2026-37012 | await | 12.4 | n/a | n/a | — | A vulnerability in pentestgpt/core/langfuse.py in PentestGPT 1.0.0 allows rem… |
| CVE-2026-81729 | 7.1 | 12.4 | Dolibarr | dolibarr | CWE-863 | Dolibarr before 23.0.4 Incorrect Authorization on REST API Document Deletion |
| CVE-2026-81279 | 5.4 | 12.4 | Murali | Push Notification for Post and BuddyPress | CWE-862 | WordPress Push Notification for Post and BuddyPress plugin <= 3.20 - Broken A… |
| CVE-2026-75889 | 7.7 | 12.2 | Grafana | Alloy | — | CVE-2026-75889 CVE Record |
| CVE-2026-18717 | 9.1 | 11.8 | Applied Systems Engineering | ASE2000 V2 | CWE-295 | Improper Certificate Validation in ASE 2000 |
| CVE-2026-59319 | 4.3 | 11.7 | Spring | Spring AI | — | RediSearch Tag Injection in RedisChatMemoryRepository Allows Cross-Conversati… |
| CVE-2026-17562 | 6.5 | 11.7 | Summit Security Systems | AdisyonPro | CWE-639 | IDOR in Zirve Security's AdisyonPro |
| CVE-2026-48996 | 9.3 | 11.5 | TriliumNext | Trilium | CWE-79 | Trilium: Malicious import with GeoMap marker title XSS leads to RCE on the de… |
| CVE-2026-53578 | 9.3 | 11.5 | TriliumNext | Trilium | CWE-79 | Trilium: Note Import to RCE via Mind Elixir dangerouslySetInnerHtml |
| CVE-2026-53579 | 9.3 | 11.5 | TriliumNext | Trilium | CWE-79 | Trilium: Note Import to RCE via Book Note |
| CVE-2026-59306 | 3.1 | 11.5 | Spring | Spring Cloud Stream | — | Potential for deserialization of untrusted types in Spring Cloud Stream |
| CVE-2026-81658 | 6.5 | 11.4 | Red Hat | Red Hat Satellite 6 | CWE-639 | Foreman: cross-tenant disclosure of template revisions via unauthorized audit… |
| CVE-2026-78273 | 6.5 | 11.3 | WP Manage Ninja | Fluent Boards Pro | CWE-79 | WordPress Fluent Boards Pro plugin <= 2.0.11 - Cross Site Scripting (XSS) vul… |
| CVE-2026-81687 | 8.7 | 10.9 | jahlives | openssl_encrypt | CWE-400 | openssl_encrypt before 1.4.9 Denial of Service via KDF |
| CVE-2026-59277 | 3.7 | 10.9 | Spring | Spring Security | CWE-693 | Spring Security InetAddressMatchers Incomplete Internal Network Classification |
| CVE-2026-81817 | 7.2 | 10.8 | flowintel | flowintel | CWE-639 | Flowintel Missing Task-to-Case Authorization Allows Cross-Case Task Modification |
| CVE-2026-77990 | 5.3 | 10.8 | joomlaeventmanager.net | JEM - Joomla Event Manager extension for Joomla | CWE-639 | Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any lo… |
| CVE-2026-78495 | 5.3 | 10.8 | WatchGuard | Dimension | CWE-918 | Dimension Server-Side Request Forgery via Remote Backup Connection Test |
| CVE-2026-59322 | 6.3 | 10.7 | Spring | Spring Integration | — | EmbeddedHeadersJsonMessageMapper default gives wire peer full control of Mess… |
| CVE-2026-78125 | 5.3 | 10.6 | Unknown | LearnPress | CWE-200 | LearnPress – Sepay Payment < 4.0.3 - Unauthenticated Order Status Disclosure |
| CVE-2026-79718 | 6.8 | 10.5 | Netron | Netron | CWE-79 | Reflected XSS in Netron versions <=9.1.2 on desktop application through unsan… |
| CVE-2026-79719 | 6.8 | 10.5 | Netron | Netron | CWE-79 | Reflected XSS in Netron versions <=9.1.2 on desktop application through unsan… |
| CVE-2026-79720 | 6.8 | 10.5 | Netron | Netron | CWE-79 | Reflected XSS in Netron versions <=9.1.2 on desktop application through unsan… |
| CVE-2026-81581 | 8.8 | 10.4 | wibu-systems-ag | wibukey | CWE-119 | User input in WibuKey is used (without proper sanitization) to compute the ad… |
| CVE-2026-81521 | 7.1 | 10.2 | MongoDB | GO Driver | CWE-99 | Cross-database write retargeting via unvalidated dotted database name in Clie… |
| CVE-2026-81526 | 7.1 | 10.2 | MongoDB | Rust Driver | CWE-74 | Cross-database write redirection via unvalidated dotted database name in bulk… |
| CVE-2026-81688 | 8.7 | 9.6 | jahlives | openssl_encrypt | CWE-311 | openssl_encrypt before 1.4.9 Plaintext Confirmation Oracle via SHA-256 |
| CVE-2026-81689 | 8.7 | 9.6 | jahlives | openssl_encrypt | CWE-916 | openssl_encrypt before 1.4.9 Weak Pepper Key Derivation |
| CVE-2026-81691 | 8.7 | 9.6 | jahlives | openssl_encrypt | CWE-319 | openssl_encrypt before 1.4.9 Credential Leakage via Unvalidated Server URLs |
| CVE-2026-81704 | 8.7 | 9.6 | jahlives | openssl_encrypt | CWE-916 | openssl_encrypt before 1.4.9 Weak Key Derivation via D-Bus |
| CVE-2026-81848 | 5.1 | 9.4 | cyberchitta | scrapling-fetch-mcp | CWE-918 | cyberchitta scrapling-fetch-mcp _fetcher.py s_fetch_pattern server-side reque… |
| CVE-2026-16567 | 5.3 | 9.0 | Unknown | Document Embedder | CWE-639 | Document Embedder < 2.3.1 - Unauthenticated Private Document Download via Tok… |
| CVE-2026-81716 | 8.7 | 8.9 | jahlives | openssl_encrypt | CWE-22 | openssl_encrypt before 1.4.9 Plugin Sandbox Path Traversal |
| CVE-2026-19889 | 8.2 | 8.8 | GitLab | GitLab AI Gateway | CWE-918 | Server-Side Request Forgery (SSRF) in GitLab AI Gateway |
| CVE-2026-75871 | 8.2 | 8.8 | GitLab | GitLab AI Gateway | CWE-918 | Server-Side Request Forgery (SSRF) in GitLab AI Gateway |
| CVE-2026-37066 | await | 8.6 | n/a | n/a | — | Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vf… |
| CVE-2026-47892 | await | 8.5 | Spring | Spring Framework | — | Spring Framework Header Predicate Bypass in WebFlux Functional Endpoints |
| CVE-2026-81715 | 8.7 | 8.5 | jahlives | openssl_encrypt | CWE-532 | openssl_encrypt before 1.4.9 Credential Exposure via Debug Output |
| CVE-2026-47877 | 8.2 | 8.5 | Spring | Spring Security | CWE-79 | Spring Security Authorization Server Default Consent Page is vulnerable to Cr… |
| CVE-2025-62342 | 6.4 | 8.4 | HCL Software | IEM | CWE-613 | HCL IntelliOps Event Management is affected by multiple security vulnerabilit… |
| CVE-2026-81836 | 6.3 | 8.4 | RooCodeInc | Roo-Code | CWE-319 | RooCodeInc Roo-Code OAuth Callback oauth.ts cleartext transmission |
| CVE-2026-47883 | 6.1 | 8.3 | Spring | Spring Framework | CWE-601 | Spring Framework Open Redirect in UrlHandlerFilter |
| CVE-2026-59316 | 8.2 | 8.1 | Spring | Spring Authorization Server | — | Spring Authorization Server Default Consent Page is vulnerable to Cross-Site … |
| CVE-2026-81271 | 8.8 | 8.0 | Paolo | GeoDirectory | CWE-352 | WordPress GeoDirectory plugin <= 2.8.176 - Cross Site Request Forgery (CSRF) … |
| CVE-2025-62343 | 3.1 | 8.0 | HCL Software | HCL IEM | CWE-557 | HCL IntelliOps Event Management is affected by multiple security vulnerabilit… |
| CVE-2026-81527 | 6.9 | 7.9 | MongoDB | C# Driver | CWE-943 | NoSQL injection via unquoted constant GroupBy keys in LINQ pipeline translation |
| CVE-2026-47880 | 5.4 | 7.9 | Spring | Spring Integration | CWE-20 | DefaultJmsHeaderMapper copies all JMS user properties into MessageHeaders wit… |
| CVE-2026-71401 | 5.3 | 7.9 | SUSE | wicked | CWE-191 | wicked: integer underflow of the UDP length in ni_capture_inspect_udp_header(… |
| CVE-2026-30067 | await | 7.8 | n/a | n/a | — | An issue in the complexQueryFilterSubprocess function in the NRF Discovery se… |
| CVE-2026-30072 | await | 7.8 | n/a | n/a | — | A NULL pointer dereference in the CDR processing path of free5gc v4.0.1 allow… |
| CVE-2026-30073 | await | 7.8 | n/a | n/a | — | An issue in the NssaiAvailabilitySubscriptionCreate component of free5gc v4.0… |
| CVE-2026-54330 | 8.1 | 7.8 | ceph | ceph | CWE-347 | Ceph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests… |
| CVE-2026-5738 | 6.1 | 7.7 | BilPark Informatics Technologies Industry and Trade Inc. | DoXBASE | CWE-79 | Reflected XSS in BilPark's DoXBASE |
| CVE-2026-11747 | 6.1 | 7.7 | Seres Software | syWEB | CWE-79 | Reflected XSS in Seres Software's syWEB |
| CVE-2026-26899 | await | 7.4 | n/a | n/a | — | An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026… |
| CVE-2026-30045 | await | 7.4 | n/a | n/a | — | An integer overflow in the /nnrf-disc/v1/nf-instances component of open5gs v2… |
| CVE-2026-81685 | 9.3 | 7.3 | jahlives | openssl_encrypt | CWE-116 | openssl_encrypt before 1.4.9 Text Injection via Recovery Slot Metadata |
| CVE-2026-81694 | 9.3 | 7.3 | jahlives | openssl_encrypt | CWE-117 | verify-usb before 1.4.9 Output Injection via Unsanitized Filenames |
| CVE-2026-81695 | 9.3 | 7.3 | jahlives | openssl_encrypt | CWE-117 | openssl_encrypt before 1.4.9 Terminal Injection via key_id |
| CVE-2026-81696 | 9.3 | 7.3 | jahlives | openssl_encrypt | CWE-117 | openssl_encrypt before 1.4.9 Terminal Injection via info Command |
| CVE-2026-75814 | 8.6 | 7.2 | Ebyte | Ebyte NE2-D11 Firmware | CWE-352 | Ebyte NE2-D11 Cross-Site Request Forgery |
| CVE-2026-78138 | 4.3 | 7.2 | Unknown | Finale Lite | CWE-200 | Finale Lite < 2.21.0 - Subscriber+ Campaign Configuration Disclosure via wcct… |
| CVE-2026-81273 | 8.1 | 7.0 | WP Manage Ninja | FluentBooking Pro | CWE-352 | WordPress FluentBooking Pro plugin <= 2.2.4 - Cross Site Request Forgery (CSR… |
| CVE-2026-81529 | 7.1 | 7.0 | MongoDB | C# Driver | CWE-88 | Connection-option injection via unescaped settings in the canonical MongoDB U… |
| CVE-2026-66155 | 7.0 | 7.0 | Siemens | Element maps-ng V47 | CWE-79 | A vulnerability has been identified in Element maps-ng V47 (All versions < V4… |
| CVE-2026-59281 | await | 6.8 | Spring | Spring Framework | — | Spring Framework Cross-site Scripting via EscapedErrors |
| CVE-2026-81097 | 8.6 | 6.7 | maquina-app | rails-mcp-server | CWE-78 | rails-mcp-server 1.4.0 through 1.6.0 OS Command Execution via execute_ruby PT… |
| CVE-2026-47887 | 6.1 | 6.7 | Spring | Spring Framework | CWE-601 | Spring Framework Open Redirect in UrlFileNameViewController |
| CVE-2026-26452 | await | 6.8 | n/a | n/a | — | ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 lcontains a vulnerability in t… |
| CVE-2026-26456 | await | 6.8 | n/a | n/a | — | A null pointer dereference vulnerability exists in the server-side session ma… |
| CVE-2026-26459 | await | 6.8 | n/a | n/a | — | ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a vulnerability in th… |
| CVE-2026-75548 | 5.3 | 6.6 | Ebyte | Ebyte NE2-D11 Firmware | CWE-1021 | Ebyte NE2-D11 Improper Restriction of Rendered UI Layers or Frames |
| CVE-2026-81731 | 5.1 | 6.6 | frappe | frappe | CWE-79 | Frappe 15.11.0 through 16.32.0 Stored XSS via Workspace Link Description |
| CVE-2026-81835 | 5.1 | 6.6 | RooCodeInc | Roo-Code | CWE-94 | RooCodeInc Roo-Code MCP Integration Trust Model malicious_mcp_server.py fetch… |
| CVE-2026-81833 | 2.0 | 6.6 | RooCodeInc | Roo-Code | CWE-74 | RooCodeInc Roo-Code CodeIndexManager helpers.ts optimizeQuery code injection |
| CVE-2026-39944 | 8.8 | 6.6 | ceph | ceph | CWE-327 | Ceph: CephX AES Authentication error |
| CVE-2026-71402 | 5.3 | 6.4 | SUSE | wicked | CWE-125 | wicked: out-of-bounds read in the DHCPv4 option parser due to payload length … |
| CVE-2026-37198 | await | 6.3 | n/a | n/a | — | An integer overflow in the SMF component of Open5GS v2.7.6 allows attackers t… |
| CVE-2026-73809 | 8.7 | 6.2 | Ebyte | Ebyte NE2-D11 Firmware | CWE-319 | Ebyte NE2-D11 Cleartext Transmission of Sensitive Information |
| CVE-2026-81703 | 8.7 | 6.1 | jahlives | openssl_encrypt | CWE-287 | openssl_encrypt before 1.4.9 Authentication Bypass via Unencrypted PQC Key |
| CVE-2026-81572 | 7.8 | 6.0 | wibu-systems-ag | codemeter-runtime | CWE-59 | Local Privilege Escalation in CodeMeter Runtime on Windows |
| CVE-2026-81092 | 7.6 | 6.0 | mark3labs | mcp-go | CWE-346 | mcp-go before 0.56.0 Missing Host Header Validation Enables DNS Rebinding |
| CVE-2026-81528 | 5.3 | 5.8 | MongoDB | C# Driver | CWE-943 | NoSQL injection via array replacement bypassing update shape validation in dr… |
| CVE-2026-78616 | 4.8 | 5.9 | WatchGuard | Dimension | CWE-79 | Dimension Stored XSS via Trusted CA Certificate Configuration |
| CVE-2026-5218 | 4.3 | 5.9 | Softtr Informatics Technology Trading Limited Company | E-Commerce Pack | CWE-80 | HTML Injection in Softtr's E-Commerce Pack |
| CVE-2026-59272 | 6.8 | 5.8 | Spring | Spring AMQP | CWE-297 | Log4j2 AmqpAppender disables TLS hostname verification by default |
| CVE-2026-34616 | 5.5 | 5.7 | Adobe | Adobe DNG Software Development Kit (SDK) | CWE-125 | DNG SDK | Out-of-bounds Read (CWE-125) |
| CVE-2026-37067 | await | 5.7 | n/a | n/a | — | Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno … |
| CVE-2026-37069 | await | 5.7 | n/a | n/a | — | Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/R… |
| CVE-2026-37073 | await | 5.7 | n/a | n/a | — | Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manage… |
| CVE-2026-59313 | await | 5.8 | Spring | Spring Framework | — | Server Sent Event stream corruption in Spring MVC functional web framework |
| CVE-2026-59314 | await | 5.8 | Spring | Spring Framework | — | Spring Framework response splitting in ContentDisposition |
| CVE-2026-50152 | 9.1 | 5.7 | ceph | ceph | CWE-285 | Ceph Monitor subscription handler improperly authorizes config-key store read… |
| CVE-2026-80210 | 7.1 | 5.7 | FrontAccounting | FrontAccounting | CWE-352 | FrontAccounting through 2.4.20 Cross-Site Request Forgery on Financial Transa… |
| CVE-2026-16568 | 4.3 | 5.6 | Unknown | Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce | CWE-639 | ShopApper <= 0.4.62 - Subscriber+ Customer Data Disclosure via IDOR |
| CVE-2026-37064 | await | 5.7 | n/a | n/a | — | User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Projec… |
| CVE-2026-16895 | 5.1 | 5.6 | Rapid7 | Metasploit-framework | CWE-305 | Authentication Bypass in Metasploit JSON-RPC Service When DB Health Check Fails |
| CVE-2026-81095 | 7.6 | 5.5 | timescale | pg-aiguide | CWE-346 | Timescale pg-aiguide through 0.5.0 DNS Rebinding via Disabled Host Header All… |
| CVE-2026-81099 | 7.6 | 5.5 | timescale | tiger-slack | CWE-346 | Timescale tiger-slack DNS Rebinding via Disabled Host Header Allow-List |
| CVE-2026-81100 | 7.6 | 5.5 | timescale | tiger-gh-mcp-server | CWE-346 | Timescale tiger-gh-mcp-server DNS Rebinding via Disabled Host Header Allow-List |
| CVE-2026-59298 | 3.1 | 5.5 | Spring | Spring Cloud Function | — | Potential for improper filtering of HTTP headers in Spring Cloud Function |
| CVE-2026-59278 | 6.5 | 5.4 | Spring | Spring for Apache Kafka | CWE-918 | In Spring for Apache Kafka, SSRF via DNS resolution triggered by untrusted ja… |
| CVE-2026-17610 | 6.0 | 5.3 | Silicon Labs | SiSDK | CWE-404 | RAIL 802.15.4 Mux missing ACK can lead to DoS |
| CVE-2026-59291 | 2.0 | 5.3 | Spring | Spring Cloud Function | — | Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function |
| CVE-2026-37065 | await | 5.3 | n/a | n/a | — | Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /… |
| CVE-2026-59283 | await | 5.3 | Spring | Spring Framework | — | Spring Framework Safety Guard Bypass via SpEL Expression Compilation |
| CVE-2026-81579 | 8.8 | 5.0 | wibu-systems-ag | wibukey | CWE-123 | An untrusted Pointer Dereference can be exploited to escalate privileges by a… |
| CVE-2026-81524 | 5.3 | 5.1 | MongoDB | C Driver | CWE-99 | Cross-tenant database retargeting via dot/NUL injection in namespace strings … |
| CVE-2026-37068 | await | 5.0 | n/a | n/a | — | Arbitrary file write in /vfm-admin/index.php?section=translations&action=upda… |
| CVE-2026-37070 | await | 5.0 | n/a | n/a | — | Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manage… |
| CVE-2026-37071 | await | 5.0 | n/a | n/a | — | Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile(… |
| CVE-2026-37072 | await | 5.0 | n/a | n/a | — | Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to In… |
| CVE-2026-59289 | await | 5.0 | Spring | Spring for GraphQL | — | Spring for GraphQL Denial of Service via pagination support |
| CVE-2026-81680 | 9.3 | 4.9 | jahlives | openssl_encrypt | CWE-347 | openssl_encrypt before 1.4.9 Authentication Bypass via Recovery Slot Removal |
| CVE-2026-26453 | await | 5.0 | n/a | n/a | — | ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer derefe… |
| CVE-2026-26457 | await | 5.0 | n/a | n/a | — | ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer derefe… |
| CVE-2026-73839 | 5.1 | 4.7 | Ebyte | Ebyte NE2-D11 Firmware | CWE-522 | Ebyte NE2-D11 Insufficiently Protected Credentials |
| CVE-2026-56652 | 4.6 | 4.7 | scottchiefbaker | dool | CWE-1236 | Formula Injection in dool project |
| CVE-2026-16569 | 4.3 | 4.7 | Unknown | Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce | CWE-284 | ShopApper <= 0.4.62 - Subscriber+ Arbitrary Product Stock Update |
| CVE-2026-78139 | 4.3 | 4.7 | Unknown | Notifima | CWE-639 | Notifima < 3.1.4 - Subscriber+ Stock Alert Unsubscription via IDOR |
| CVE-2026-56651 | 2.0 | 4.6 | scottchiefbaker | dool | CWE-59 | Arbitrary File Overwrite via Symlink Following in dool project |
| CVE-2026-38347 | await | 4.6 | n/a | n/a | — | A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.… |
| CVE-2026-18374 | 4.9 | 4.5 | The GNU C Library | glibc | CWE-787 | Passing an effectively empty string to the `,ccs=` syntax extension of the mo… |
| CVE-2026-59299 | 3.1 | 4.5 | Spring | Spring Cloud Function | — | Composition lookup can potentially poison base function in Spring Cloud Function |
| CVE-2026-59300 | 3.1 | 4.5 | Spring | Spring Cloud Function | — | Potential for logging sensitive data in Spring Cloud Function AWS |
| CVE-2026-59301 | 3.1 | 4.5 | Spring | Spring Cloud Function | — | Potential for logging sensitive data in Spring Cloud Function Azure |
| CVE-2026-59302 | 3.1 | 4.5 | Spring | Spring Cloud Stream | — | Potential for logging sensitive data in Spring Cloud Stream |
| CVE-2026-59303 | 3.1 | 4.5 | Spring | Spring Cloud Stream | — | Dynamic destination cache size is not properly bound in Spring Cloud Stream |
| CVE-2026-59304 | 3.1 | 4.5 | Spring | Spring Cloud Stream | — | Improper caching of the original content type in Spring Cloud Stream Avro |
| CVE-2026-59305 | 3.1 | 4.5 | Spring | Spring Cloud Stream | — | Partition interceptor may be improperly added while sending message |
| CVE-2026-38343 | await | 4.5 | n/a | n/a | — | An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-12252… |
| CVE-2026-81697 | 8.7 | 4.4 | jahlives | openssl_encrypt | CWE-426 | openssl_encrypt before 1.4.9 KDF Downgrade via CWD-relative Configuration |
| CVE-2026-30051 | await | 4.4 | n/a | n/a | — | An issue in the CreateUEContextProcedure function (/v1/ue-contexts/{supi}) of… |
| CVE-2026-30058 | await | 4.4 | n/a | n/a | — | Improper Input Validation in the HTTPModifySubscription handler of free5gc v4… |
| CVE-2026-30059 | await | 4.4 | n/a | n/a | — | An issue in the NAS decoder component of free5gc v4.0.1 allows attackers to c… |
| CVE-2026-30060 | await | 4.4 | n/a | n/a | — | An issue in free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS… |
| CVE-2026-30063 | await | 4.4 | n/a | n/a | — | An issue in the NF Discovery endpoint of free5gc v4.0.1 allows attackers to c… |
| CVE-2026-30064 | await | 4.4 | n/a | n/a | — | Improper input validation in the buildFilter function (processor/processor.go… |
| CVE-2026-30068 | await | 4.4 | n/a | n/a | — | Improper input validation in the HandleUpdate function (/sbi/parameter_provis… |
| CVE-2026-30069 | await | 4.4 | n/a | n/a | — | A NULL pointer dereference in the UDMC registration handler component of free… |
| CVE-2026-30070 | await | 4.4 | n/a | n/a | — | An issue in the HandleGetSharedData function of free5gc v4.0.1 allows attacke… |
| CVE-2026-30071 | await | 4.4 | n/a | n/a | — | An issue in the RechargePut function of free5gc v4.0.1 allows attackers to ca… |
| CVE-2026-38344 | await | 4.4 | n/a | n/a | — | A NULL pointer dereference in the get_min_buffer_size function (/libswscale/s… |
| CVE-2026-38345 | await | 4.4 | n/a | n/a | — | A Division-by-Zero vulnerability in the ff_sws_init_single_context function (… |
| CVE-2026-38346 | await | 4.4 | n/a | n/a | — | An integer overflow in the yuv2planeX_8_c() function (libswscale/output.c) of… |
| CVE-2026-38348 | await | 4.4 | n/a | n/a | — | An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gd… |
| CVE-2026-38349 | await | 4.4 | n/a | n/a | — | An integer overflow in the hScale16To19_c() function (libswscale/output.c) of… |
| CVE-2026-38350 | await | 4.4 | n/a | n/a | — | An integer overflow in the target_sws_fuzzer() function (libswscale/output.c)… |
| CVE-2026-59282 | await | 4.4 | Spring | Spring Framework | — | Spring Framework Denial of Service via Unbounded List Growth in Data Binding |
| CVE-2026-59287 | await | 4.4 | Spring | Spring for GraphQL | — | Spring for GraphQL WebSocket Client Denial of Service |
| CVE-2026-59288 | await | 4.4 | Spring | Spring for GraphQL | — | Spring for GraphQL Information Exposure in GraphiQL support |
| CVE-2026-75337 | await | 4.4 | n/a | n/a | — | The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v… |
| CVE-2026-75339 | await | 4.4 | n/a | n/a | — | The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permis… |
| CVE-2026-75417 | await | 4.3 | n/a | n/a | — | A SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in th… |
Results continue: ranks 401–437.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-08-27 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.