boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Thursday, August 27, 2026 · all times UTC← 2026-08-26 · archive

Security Box Score — August 27, 2026 — page 2

Edition of August 27, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–437 of 437
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-786108.44.1WatchGuardDimensionCWE-352Dimension CSRF Vulnerability in Administrator Passphrase Change Endpoint
CVE-2026-648965.24.2Johnson ControlsT2000CWE-284T2000 open debug port
CVE-2026-592923.24.0SpringSpring Integration—World-readable metadata file in PropertiesPersistingMetadataStore (insecure t…
CVE-2026-816685.43.9Red HatRed Hat Satellite 6CWE-639Rubygem-katello: cross-tenant content view filter rule access and modificatio…
CVE-2026-346205.53.8AdobeAdobe DNG Software Development Kit (SDK)CWE-787DNG SDK | Out-of-bounds Write (CWE-787)
CVE-2026-134144.83.8UnknownCMPCWE-862CMP - Coming Soon & Maintenance < 4.1.18 - Unauthenticated Maintenance Mode D…
CVE-2026-134163.53.8UnknownCMPCWE-79CMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Stored XSS via niteoCS_soc…
CVE-2026-811022.33.6dropboxmcp-server-dashCWE-346Dropbox Dash MCP Server DNS Rebinding via Missing Host Header Validation
CVE-2026-817029.33.6jahlivesopenssl_encryptCWE-345openssl_encrypt before 1.4.9 Key Substitution via Identity Load
CVE-2026-817149.33.5jahlivesopenssl_encryptCWE-347openssl_encrypt before 1.4.9 Plugin Signing Trust Anchor Enrollment Bypass
CVE-2026-47893await3.6SpringSpring Framework—Spring Framework Request Headers Included in Exception Reasons in HandshakeWe…
CVE-2026-817276.93.4nltknltkCWE-59NLTK before 3.10.3 Hardlink File Overwrite via downloader
CVE-2026-818386.83.2awsdiagram-as-codeCWE-23Zip Slip Arbitrary File Write in AWS diagram-as-code (awsdac)
CVE-2026-817069.33.0jahlivesopenssl_encryptCWE-345openssl_encrypt before 1.4.9 Key Substitution via Identity Shadowing
CVE-2026-816819.33.0jahlivesopenssl_encryptCWE-311openssl_encrypt before 1.4.9 False Encryption via Cleartext Storage
CVE-2026-817188.73.0jahlivesopenssl_encryptCWE-326openssl_encrypt before 1.4.9 Weak Cryptographic Parameters
CVE-2026-813346.92.9hank-aidarknetCWE-125darknet through 6.0 Out-of-Bounds Read and Write via Unchecked Layer Index in…
CVE-2026-817206.92.6jahlivesopenssl_encryptCWE-400openssl_encrypt before 1.4.9 Denial of Service via Unbounded Argon2
CVE-2026-593214.22.4SpringSpring Integration—Shared JSR-223 ScriptEngine evaluated concurrently without THREADING check
CVE-2026-816846.92.3jahlivesopenssl_encryptCWE-214openssl_encrypt before 1.4.9 Information Disclosure via Command Line
CVE-2026-816828.61.8jahlivesopenssl_encryptCWE-276openssl_encrypt before 1.4.9 Insecure File Permissions
CVE-2026-816866.91.7jahlivesopenssl_encryptCWE-20openssl_encrypt before 1.4.9 D-Bus Properties Authorization Bypass
CVE-2026-540845.31.7wazuhwazuhCWE-476Wazuh agent enrollment NULL pointer dereference via malformed manager response
CVE-2026-59286await1.6SpringSpring for GraphQL—Spring for GraphQL loads Untrusted Resources in GraphiQL support
CVE-2026-193986.81.5ASUSFA507NVCWE-787“unsupported-when-assigned.” An out-of-bounds write in the SmiFlash SMM modul…
CVE-2026-818934.71.5Red HatRed Hat Enterprise Linux 10CWE-787Gdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc profile parser on error rec…
CVE-2026-446297.91.2Genetec Inc.Synergis SoftwireCWE-922Improper access control to the Synergis Softwire installation folder. This vu…
CVE-2026-765495.90.8UnknownUpdraftPlus: WP Backup & Migration PluginCWE-352UpdraftPlus < 1.26.7 - Backup Restoration via CSRF
CVE-2025-301568.90.6cephcephCWE-327Ceph: AES-CBC misuse in CephX and RADOSGW enables authentication bypass and c…
CVE-2026-817179.30.6jahlivesopenssl_encryptCWE-347openssl_encrypt before 1.4.9 Integrity Bypass via Added Files
CVE-2026-755734.10.5MongoDBBI ConnectorCWE-532MongoDB Connector for BI mongodrdl Logs TLS Private-Key Password When Duplica…
CVE-2026-252506.00.5eazsolutionEazyFixCWE-325EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Crypt…
CVE-2026-592973.10.3SpringSpring Cloud Function—Spring Cloud Function can incorrectly determine if URI is secure
CVE-2026-815232.00.1MongoDBlibmongocryptCWE-74Cross-tenant database retargeting via dot/NUL injection in namespace strings …
CVE-2026-815306.80.0MongoDBC# DriverCWE-532KMS master key exposure via unredacted credential serialization in driver set…
CVE-2026-816838.60.0jahlivesopenssl_encryptCWE-312openssl_encrypt before 1.4.9 Plaintext Private Key Storage
CVE-2026-198546.10.0GrafanaClickhouse DatasourceCWE-319CVE-2026-19854 CVE Record