Security Box Score — August 27, 2026 — page 2
Edition of August 27, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-78610 | 8.4 | 4.1 | WatchGuard | Dimension | CWE-352 | Dimension CSRF Vulnerability in Administrator Passphrase Change Endpoint |
| CVE-2026-64896 | 5.2 | 4.2 | Johnson Controls | T2000 | CWE-284 | T2000 open debug port |
| CVE-2026-59292 | 3.2 | 4.0 | Spring | Spring Integration | — | World-readable metadata file in PropertiesPersistingMetadataStore (insecure t… |
| CVE-2026-81668 | 5.4 | 3.9 | Red Hat | Red Hat Satellite 6 | CWE-639 | Rubygem-katello: cross-tenant content view filter rule access and modificatio… |
| CVE-2026-34620 | 5.5 | 3.8 | Adobe | Adobe DNG Software Development Kit (SDK) | CWE-787 | DNG SDK | Out-of-bounds Write (CWE-787) |
| CVE-2026-13414 | 4.8 | 3.8 | Unknown | CMP | CWE-862 | CMP - Coming Soon & Maintenance < 4.1.18 - Unauthenticated Maintenance Mode D… |
| CVE-2026-13416 | 3.5 | 3.8 | Unknown | CMP | CWE-79 | CMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Stored XSS via niteoCS_soc… |
| CVE-2026-81102 | 2.3 | 3.6 | dropbox | mcp-server-dash | CWE-346 | Dropbox Dash MCP Server DNS Rebinding via Missing Host Header Validation |
| CVE-2026-81702 | 9.3 | 3.6 | jahlives | openssl_encrypt | CWE-345 | openssl_encrypt before 1.4.9 Key Substitution via Identity Load |
| CVE-2026-81714 | 9.3 | 3.5 | jahlives | openssl_encrypt | CWE-347 | openssl_encrypt before 1.4.9 Plugin Signing Trust Anchor Enrollment Bypass |
| CVE-2026-47893 | await | 3.6 | Spring | Spring Framework | — | Spring Framework Request Headers Included in Exception Reasons in HandshakeWe… |
| CVE-2026-81727 | 6.9 | 3.4 | nltk | nltk | CWE-59 | NLTK before 3.10.3 Hardlink File Overwrite via downloader |
| CVE-2026-81838 | 6.8 | 3.2 | aws | diagram-as-code | CWE-23 | Zip Slip Arbitrary File Write in AWS diagram-as-code (awsdac) |
| CVE-2026-81706 | 9.3 | 3.0 | jahlives | openssl_encrypt | CWE-345 | openssl_encrypt before 1.4.9 Key Substitution via Identity Shadowing |
| CVE-2026-81681 | 9.3 | 3.0 | jahlives | openssl_encrypt | CWE-311 | openssl_encrypt before 1.4.9 False Encryption via Cleartext Storage |
| CVE-2026-81718 | 8.7 | 3.0 | jahlives | openssl_encrypt | CWE-326 | openssl_encrypt before 1.4.9 Weak Cryptographic Parameters |
| CVE-2026-81334 | 6.9 | 2.9 | hank-ai | darknet | CWE-125 | darknet through 6.0 Out-of-Bounds Read and Write via Unchecked Layer Index in… |
| CVE-2026-81720 | 6.9 | 2.6 | jahlives | openssl_encrypt | CWE-400 | openssl_encrypt before 1.4.9 Denial of Service via Unbounded Argon2 |
| CVE-2026-59321 | 4.2 | 2.4 | Spring | Spring Integration | — | Shared JSR-223 ScriptEngine evaluated concurrently without THREADING check |
| CVE-2026-81684 | 6.9 | 2.3 | jahlives | openssl_encrypt | CWE-214 | openssl_encrypt before 1.4.9 Information Disclosure via Command Line |
| CVE-2026-81682 | 8.6 | 1.8 | jahlives | openssl_encrypt | CWE-276 | openssl_encrypt before 1.4.9 Insecure File Permissions |
| CVE-2026-81686 | 6.9 | 1.7 | jahlives | openssl_encrypt | CWE-20 | openssl_encrypt before 1.4.9 D-Bus Properties Authorization Bypass |
| CVE-2026-54084 | 5.3 | 1.7 | wazuh | wazuh | CWE-476 | Wazuh agent enrollment NULL pointer dereference via malformed manager response |
| CVE-2026-59286 | await | 1.6 | Spring | Spring for GraphQL | — | Spring for GraphQL loads Untrusted Resources in GraphiQL support |
| CVE-2026-19398 | 6.8 | 1.5 | ASUS | FA507NV | CWE-787 | “unsupported-when-assigned.” An out-of-bounds write in the SmiFlash SMM modul… |
| CVE-2026-81893 | 4.7 | 1.5 | Red Hat | Red Hat Enterprise Linux 10 | CWE-787 | Gdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc profile parser on error rec… |
| CVE-2026-44629 | 7.9 | 1.2 | Genetec Inc. | Synergis Softwire | CWE-922 | Improper access control to the Synergis Softwire installation folder. This vu… |
| CVE-2026-76549 | 5.9 | 0.8 | Unknown | UpdraftPlus: WP Backup & Migration Plugin | CWE-352 | UpdraftPlus < 1.26.7 - Backup Restoration via CSRF |
| CVE-2025-30156 | 8.9 | 0.6 | ceph | ceph | CWE-327 | Ceph: AES-CBC misuse in CephX and RADOSGW enables authentication bypass and c… |
| CVE-2026-81717 | 9.3 | 0.6 | jahlives | openssl_encrypt | CWE-347 | openssl_encrypt before 1.4.9 Integrity Bypass via Added Files |
| CVE-2026-75573 | 4.1 | 0.5 | MongoDB | BI Connector | CWE-532 | MongoDB Connector for BI mongodrdl Logs TLS Private-Key Password When Duplica… |
| CVE-2026-25250 | 6.0 | 0.5 | eazsolution | EazyFix | CWE-325 | EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Crypt… |
| CVE-2026-59297 | 3.1 | 0.3 | Spring | Spring Cloud Function | — | Spring Cloud Function can incorrectly determine if URI is secure |
| CVE-2026-81523 | 2.0 | 0.1 | MongoDB | libmongocrypt | CWE-74 | Cross-tenant database retargeting via dot/NUL injection in namespace strings … |
| CVE-2026-81530 | 6.8 | 0.0 | MongoDB | C# Driver | CWE-532 | KMS master key exposure via unredacted credential serialization in driver set… |
| CVE-2026-81683 | 8.6 | 0.0 | jahlives | openssl_encrypt | CWE-312 | openssl_encrypt before 1.4.9 Plaintext Private Key Storage |
| CVE-2026-19854 | 6.1 | 0.0 | Grafana | Clickhouse Datasource | CWE-319 | CVE-2026-19854 CVE Record |