AV AC PR UI S C I A CVSS EPSS %ile KEV A L N N U H H L 8.3 .0174 75.8 —
AFFECTED Product Versions Fixed openNDS unspecified —
TIMELINE Apr 6 Reserved by CNA Aug 28 Published (CNA: mitre)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
496 CVEs published, led by Linux (135).
496 CVEs published August 28, 2026: 49 critical, 184 high, 126 medium, 16 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 121 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 96 on continuation pages.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 11773 | 34212 | — | — |
| KEV catalog size | 1685 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
2023 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 1644 | 3959 | 418 | 1972 | 637 | 1 | 12 | 3 | 0.1 | 7.8 | .0016 | +815 ▲ |
| 402 | 2164 | 270 | 842 | 960 | 75 | 77 | 6 | 0.3 | 7.5 | .0026 | +282 ▲ | |
| microsoft | 477 | 1899 | 145 | 1283 | 457 | 14 | 287 | 28 | 1.5 | 7.8 | .0044 | -187 ▼ |
| red hat | 223 | 616 | 42 | 254 | 287 | 32 | 2 | 0 | 0.0 | 6.7 | .0029 | +94 ▲ |
| apple | 44 | 316 | 59 | 85 | 165 | 7 | 88 | 8 | 2.5 | 6.5 | .0029 | -123 ▼ |
| freebsd | 32 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | +32 ▲ |
| canonical | 15 | 42 | 13 | 11 | 13 | 5 | 0 | 0 | 0.0 | 7.8 | .0020 | +8 ▲ |
| suse | 7 | 28 | 5 | 14 | 8 | 1 | 0 | 0 | 0.0 | 7.7 | .0038 | -1 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 46 | 84 | 21 | 39 | 24 | 0 | 56 | 13 | 15.5 | 7.5 | .0044 | +31 ▲ |
| ubiquiti | 23 | 59 | 36 | 22 | 1 | 0 | 3 | 3 | 5.1 | 9.1 | .0049 | -2 ▼ |
| palo alto networks | 12 | 37 | 1 | 3 | 21 | 12 | 13 | 2 | 5.4 | 4.7 | .0020 | -2 ▼ |
| netgear | 9 | 32 | 0 | 0 | 27 | 5 | 0 | 0 | 0.0 | 4.3 | .0025 | +3 ▲ |
| fortinet | 7 | 30 | 7 | 8 | 14 | 1 | 28 | 6 | 20.0 | 7.0 | .0050 | -7 ▼ |
| vmware | 2 | 19 | 5 | 9 | 3 | 2 | 7 | 2 | 10.5 | 8.3 | .0040 | -6 ▼ |
| f5 | 0 | 17 | 5 | 9 | 3 | 0 | 4 | 1 | 5.9 | 8.7 | .0057 | -8 ▼ |
| sonicwall | 12 | 14 | 3 | 7 | 4 | 0 | 17 | 2 | 14.3 | 7.8 | .0024 | +10 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 159 | 496 | 102 | 216 | 164 | 13 | 33 | 2 | 0.4 | 7.5 | .0049 | +35 ▲ |
| mozilla | 59 | 186 | 68 | 68 | 50 | 0 | 9 | 0 | 0.0 | 8.1 | .0030 | -12 ▼ |
| gitlab | 25 | 76 | 2 | 18 | 47 | 9 | 4 | 2 | 2.6 | 5.3 | .0028 | +18 ▲ |
| drupal | 17 | 68 | 10 | 7 | 46 | 5 | 4 | 1 | 1.5 | 5.9 | .0024 | -29 ▼ |
| github | 5 | 17 | 1 | 7 | 9 | 0 | 0 | 0 | 0.0 | 6.6 | .0043 | -1 ▼ |
| docker | 2 | 9 | 0 | 6 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0016 | +2 ▲ |
| wordpress | 2 | 5 | 1 | 3 | 1 | 0 | 2 | 2 | 40.0 | 8.8 | .3120 | -1 ▼ |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0035 | -1 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 890 | 2269 | 484 | 1170 | 519 | 96 | 28 | 4 | 0.2 | 7.8 | .0034 | -219 ▼ |
| ibm | 390 | 619 | 148 | 286 | 177 | 8 | 6 | 1 | 0.2 | 7.6 | .0030 | +322 ▲ |
| adobe | 101 | 606 | 50 | 300 | 247 | 9 | 19 | 3 | 0.5 | 7.8 | .0021 | -4 ▼ |
| progress | 19 | 61 | 14 | 37 | 10 | 0 | 6 | 1 | 1.6 | 8.1 | .0037 | -14 ▼ |
| solarwinds | 0 | 23 | 17 | 3 | 3 | 0 | 10 | 4 | 17.4 | 9.1 | .0058 | -15 ▼ |
| veeam | 13 | 19 | 6 | 10 | 3 | 0 | 1 | 0 | 0.0 | 8.6 | .0032 | +12 ▲ |
| zohocorp | 4 | 10 | 3 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0140 | +1 ▲ |
| atlassian | 3 | 6 | 1 | 5 | 0 | 0 | 13 | 0 | 0.0 | 8.1 | .0034 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| siemens | 21 | 37 | 2 | 24 | 8 | 3 | 0 | 0 | 0.0 | 7.3 | .0016 | +14 ▲ |
| d-link | 16 | 36 | 15 | 5 | 9 | 7 | 3 | 0 | 0.0 | 7.4 | .0157 | +8 ▲ |
| synology | 4 | 27 | 3 | 6 | 15 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +4 ▲ |
| rockwell automation | 1 | 25 | 4 | 17 | 4 | 0 | 0 | 0 | 0.0 | 8.4 | .0024 | -16 ▼ |
| schneider electric | 0 | 9 | 1 | 6 | 2 | 0 | 0 | 0 | 0.0 | 8.6 | .0037 | 0 |
| abb | 0 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -1 ▼ |
| hikvision | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0040 | -5 ▼ |
| mitsubishi electric | 0 | 5 | 0 | 4 | 1 | 0 | 0 | 0 | 0.0 | 7.2 | .0052 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| spring | 91 | 170 | 9 | 53 | 86 | 16 | 0 | 0 | 0.0 | 6.4 | .0022 | +91 ▲ |
| dell | 71 | 170 | 11 | 90 | 64 | 5 | 2 | 1 | 0.6 | 7.2 | .0019 | +28 ▲ |
| sourcecodester | 48 | 168 | 0 | 0 | 92 | 76 | 0 | 0 | 0.0 | 5.5 | .0029 | -1 ▼ |
| nvidia | 52 | 134 | 16 | 88 | 30 | 0 | 0 | 0 | 0.0 | 7.8 | .0034 | +9 ▲ |
| splunk | 110 | 128 | 6 | 47 | 70 | 5 | 1 | 1 | 0.8 | 6.5 | .0025 | +107 ▲ |
| openclaw | 0 | 111 | 0 | 58 | 39 | 14 | 0 | 0 | 0.0 | 7.0 | .0026 | -44 ▼ |
| zephyrproject | 52 | 105 | 3 | 33 | 57 | 12 | 0 | 0 | 0.0 | 6.4 | .0021 | +27 ▲ |
| getgrav | 66 | 104 | 15 | 59 | 28 | 2 | 0 | 0 | 0.0 | 8.4 | .0032 | +29 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-8037 | .9957 | 99.9 | 9.8 |
| CVE-2026-34486 | .9862 | 99.9 | 7.5 |
| CVE-2026-63077 | .8771 | 99.8 | 9.8 |
| CVE-2026-60004 | .8455 | 99.7 | 9.8 |
| CVE-2026-72898 | .7922 | 99.6 | 10.0 |
| CVE-2026-18577 | .5407 | 99.0 | 8.2 |
| CVE-2026-59310 | .4588 | 98.8 | 9.8 |
| CVE-2026-18556 | .4016 | 98.6 | 8.2 |
| CVE-2026-64638 | .3120 | 98.2 | 8.9 |
| CVE-2026-66066 | .2786 | 98.0 | 9.5 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-72898 | 10.0 | .7922 | KEV |
| CVE-2026-48362 | 10.0 | .0431 | |
| CVE-2026-19188 | 10.0 | .0193 | |
| CVE-2026-58231 | 10.0 | .0171 | |
| CVE-2026-69836 | 10.0 | .0155 | |
| CVE-2026-76195 | 10.0 | .0147 | |
| CVE-2026-76197 | 10.0 | .0147 | |
| CVE-2026-73299 | 10.0 | .0121 | |
| CVE-2026-73678 | 10.0 | .0114 | |
| CVE-2026-77554 | 10.0 | .0099 |
| Vendor | CVEs |
|---|---|
| linux | 1645 |
| oracle | 890 |
| 777 | |
| microsoft | 478 |
| ibm | 425 |
| red hat | 254 |
| apache | 175 |
| splunk | 110 |
| adobe | 104 |
| spring | 97 |
| Vendor | KEV |
|---|---|
| microsoft | 28 |
| cisco | 13 |
| apple | 8 |
| fortinet | 6 |
| 6 | |
| ivanti | 5 |
| oracle | 4 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 56 |
| Packagist | 28 |
| PyPI | 13 |
| npm | 12 |
| Go | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-18556 | N-able | 0 |
| CVE-2026-18577 | N-able | 0 |
| CVE-2026-20349 | Cisco | 0 |
| CVE-2026-34486 | Apache Software Foundation | 0 |
| CVE-2026-63077 | JetBrains | 0 |
| CVE-2026-72529 | TrueConf | 0 |
| CVE-2026-72530 | TrueConf | 0 |
| CVE-2026-72898 | Metabase | 0 |
| CVE-2026-8037 | Progress Software | 0 |
| CVE-2026-64849 | mlflow | 1 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1745 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1745 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1745 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1745 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1745 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1745 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1745 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1745 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1745 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1745 |
EXPLOIT PUBLISHED — axios: 8 CVEs (CVE-2026-42264, CVE-2026-44486, CVE-2026-44487, CVE-2026-44488, CVE-2026-44492, CVE-2026-44494, CVE-2026-44495, CVE-2026-44496). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2023-43900. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2023-43901. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2023-43902. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-2609 (MagnusSolution MagnusBilling). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-2610 (MagnusSolution MagnusBilling). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-43955 (Convertigo). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-0545 (mlflow/mlflow). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10036 (speechbrain). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19092 (Unknown Tutor LMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-2614 (mlflow/mlflow). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-35397 (jupyter-server jupyter_server). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-38636. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-38638. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44513 (huggingface diffusers). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45736 (websockets ws). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-46625 (js-cookie). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47117 (maziyarpanahi openmed). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48526 (jpadilla pyjwt). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48710 (Kludex starlette). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48779 (websockets ws). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-5241 (huggingface/transformers). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54293 (nltk). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-74899 (jahlives openssl_encrypt). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75417. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-76640 (Unitree Robotics G1 EDU). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-76886 (Wireshark Foundation Wireshark). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-76888 (Wireshark Foundation Wireshark). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-79804 (SililaWijesinghe Food Ordering System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-81203 (SourceCodester Simple Online Food Ordering System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-81560 (blackms aistack). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-81834 (RooCodeInc Roo-Code). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-81934 (Redis). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-9147 (scikit-hep uproot). Public exploit reference added.
DUE DATE PASSED — CVE-2026-21962 (Oracle Corporation Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in). CISA remediation deadline was August 27, 2026; still in catalog.
RESCORED — Zimbra Collaboration: 5 CVEs (CVE-2026-73571, CVE-2026-73573, CVE-2026-73574, CVE-2026-73575, CVE-2026-73576). CVSS rescored — before/after on each CVE page.
RESCORED — RooCodeInc Roo-Code: 3 CVEs (CVE-2026-81835, CVE-2026-81836, CVE-2026-81837). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2023-43901. CVSS 5.4 → 7.5 (NVD).
RESCORED — CVE-2023-43902. CVSS 8.8 → 9.8 (NVD).
RESCORED — CVE-2024-58377 (sparklemotion nokogiri). CVSS 9.3 → 6.8 (NVD).
RESCORED — CVE-2025-2609 (MagnusSolution MagnusBilling). CVSS 8.2 → 6.1 (NVD).
RESCORED — CVE-2025-2610 (MagnusSolution MagnusBilling). CVSS 7.6 → 5.4 (NVD).
RESCORED — CVE-2025-43955 (Convertigo). CVSS 2.2 → 6.8 (NVD).
RESCORED — CVE-2026-0545 (mlflow/mlflow). CVSS 9.1 → 9.8 (NVD).
RESCORED — CVE-2026-16782 (Autodesk 3ds Max). CVSS 5.3 → 7.8 (NVD).
RESCORED — CVE-2026-50768. CVSS 9.8 → 8.8 (NVD).
RESCORED — CVE-2026-67275 (Dell PowerProtect One). CVSS 5.3 → 6.5 (NVD).
RESCORED — CVE-2026-73626 (jupyterlab). CVSS 0 → 7.7 (NVD).
RESCORED — CVE-2026-74774 (Dell PowerProtect One). CVSS 5.9 → 7.5 (NVD).
RESCORED — CVE-2026-74802 (siyuan-note siyuan). CVSS 0 → 7.1 (NVD).
RESCORED — CVE-2026-74887 (jahlives openssl_encrypt). CVSS 9.3 → 6.3 (NVD).
RESCORED — CVE-2026-76886 (Wireshark Foundation Wireshark). CVSS 8.1 → 9.8 (NVD).
RESCORED — CVE-2026-76888 (Wireshark Foundation Wireshark). CVSS 3.1 → 7.5 (NVD).
RESCORED — CVE-2026-80200 (kimai). CVSS 0 → 5.3 (NVD).
RESCORED — CVE-2026-81845 (arben-adm mcp-sequential-thinking). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-81847 (MAA-AI MaaMCP). CVSS 5.1 → 2 (NVD).
ENRICHED — CVE-2023-36664. Received CVSS 7.8 and CPE data from NVD.
ENRICHED — CVE-2026-78195. Received CVSS 5.1 and CPE data from NVD.
How to read these box scores · glossary
496 CVEs published. 25 box scores and 375 table rows below; the remaining 96 continue on page 2 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV A L N N U H H L 8.3 .0174 75.8 —
AFFECTED Product Versions Fixed openNDS unspecified —
TIMELINE Apr 6 Reserved by CNA Aug 28 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0150 72.0 —
AFFECTED Product Versions Fixed NUMail all – —
TIMELINE Aug 28 Reserved by CNA Aug 28 Published (CNA: twcert)
AV AC PR UI S C I A CVSS EPSS %ile KEV A L L N U H H L 7.6 .0085 55.1 —
AFFECTED Product Versions Fixed openNDS unspecified —
TIMELINE Apr 6 Reserved by CNA Aug 28 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U H H H 7.5 .0050 40.8 —
AFFECTED Product Versions Fixed One User Avatar | User Profile Picture unspecified —
TIMELINE Aug 5 Reserved by CNA Aug 28 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L R C H H H 9.0 .0048 39.4 —
AFFECTED Product Versions Fixed Synology Chat Server unspecified —
TIMELINE Apr 14 Reserved by CNA Aug 28 Published (CNA: synology)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C L L N 7.2 .0044 36.9 —
AFFECTED Product Versions Fixed Booking for Appointments and Events Calendar – Amelia unspecified —
TIMELINE Apr 14 Reserved by CNA Aug 28 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L L N 6.5 .0043 35.8 —
AFFECTED Product Versions Fixed Tutor LMS – eLearning and online course solution unspecified —
TIMELINE Jul 23 Reserved by CNA Aug 28 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0042 34.8 —
AFFECTED Product Versions Fixed SOY CMS unspecified —
TIMELINE Aug 24 Reserved by CNA Aug 28 Published (CNA: jpcert)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0041 34.1 —
AFFECTED Product Versions Fixed wpForo Forum unspecified —
TIMELINE Mar 29 Reserved by CNA Aug 28 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U L N N 4.3 .0040 32.9 —
AFFECTED Product Versions Fixed Synology Chat Server unspecified —
TIMELINE May 25 Reserved by CNA Aug 28 Published (CNA: synology)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0036 28.5 —
AFFECTED Product Versions Fixed User Frontend unspecified —
TIMELINE Jul 3 Reserved by CNA Aug 28 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0034 26.5 —
AFFECTED Product Versions Fixed WPMU DEV Dashboard unspecified —
TIMELINE Aug 19 Reserved by CNA Aug 28 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P L P H H L 8.8 .0033 25.1 —
AFFECTED Product Versions Fixed android-app unspecified —
TIMELINE Aug 28 Reserved by CNA Aug 28 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C L L N 7.2 .0031 23.2 —
AFFECTED Product Versions Fixed Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization unspecified —
TIMELINE Aug 20 Reserved by CNA Aug 28 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C L L N 7.2 .0030 22.5 —
AFFECTED Product Versions Fixed Forminator Forms – Contact Form, Payment Form & Custom Form Builder unspecified —
TIMELINE Jul 29 Reserved by CNA Aug 28 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C L L N 7.2 .0030 22.5 —
AFFECTED Product Versions Fixed TranslatePress – Translate Multilingual sites with AI Translation unspecified —
TIMELINE Aug 18 Reserved by CNA Aug 28 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.2 .0028 20.2 —
AFFECTED Product Versions Fixed Pocket unspecified —
TIMELINE Aug 28 Reserved by CNA Aug 28 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C L L N 7.2 .0027 19.3 —
AFFECTED Product Versions Fixed LiteSpeed Cache unspecified —
TIMELINE Aug 5 Reserved by CNA Aug 28 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C L L N 6.1 .0027 19.3 —
AFFECTED Product Versions Fixed ElementsKit Pro unspecified —
TIMELINE Mar 15 Reserved by CNA Aug 28 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L R C L L L 6.5 .0024 15.1 —
AFFECTED Product Versions Fixed Synology Chat Server unspecified —
TIMELINE May 26 Reserved by CNA Aug 28 Published (CNA: synology)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C L L N 6.4 .0024 14.2 —
AFFECTED Product Versions Fixed Smart Slider 3 unspecified —
TIMELINE Jul 14 Reserved by CNA Aug 28 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV A H N N U H H L 7.1 .0020 9.9 —
AFFECTED Product Versions Fixed openNDS unspecified —
TIMELINE Apr 6 Reserved by CNA Aug 28 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C L L N 6.4 .0019 8.3 —
AFFECTED Product Versions Fixed LiteSpeed Cache unspecified —
TIMELINE Feb 24 Reserved by CNA Aug 28 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0018 7.9 —
AFFECTED Product Versions Fixed Linux 56b99327a451917f1c17f85fc33ea8293c08a9ee – — Linux 6.19 – 6.18.40
TIMELINE Aug 26 Reserved by CNA Aug 28 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV L L N N C H H H 9.3 .0018 7.9 —
AFFECTED Product Versions Fixed Linux ec156764d424dd67283c2cd5e9f6f1b8388364ac – — Linux 2.6.32 – 6.18.40
TIMELINE Aug 26 Reserved by CNA Aug 28 Published (CNA: Linux)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-80640 | await | 7.9 | Linux | Linux | — | cxl/fwctl: Fix __fortify_panic |
| CVE-2026-80659 | await | 7.6 | Linux | Linux | — | mmc: vub300: defer reset until cmd_mutex is unlocked |
| CVE-2026-80606 | 7.8 | 7.4 | Linux | Linux | — | drm/xe/userptr: Hold notifier_lock for write on inject test path |
| CVE-2026-80665 | 7.1 | 7.4 | Linux | Linux | — | KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN |
| CVE-2026-80616 | await | 7.4 | Linux | Linux | — | ieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns() |
| CVE-2026-38819 | 5.3 | 7.4 | openNDS | openNDS | CWE-401 | Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attac… |
| CVE-2026-80600 | 9.8 | 7.2 | Linux | Linux | — | batman-adv: dat: acquire ARP hw source only after skb realloc |
| CVE-2026-80630 | 9.8 | 7.2 | Linux | Linux | — | net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek be… |
| CVE-2026-80681 | 9.8 | 7.2 | Linux | Linux | — | vxlan: re-fetch eth header after route_shortcircuit() |
| CVE-2026-80603 | 9.1 | 7.2 | Linux | Linux | — | netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read |
| CVE-2026-80670 | 9.1 | 7.2 | Linux | Linux | — | perf tools: Use perf_env__get_cpu_topology() in machine__resolve() |
| CVE-2026-80601 | 8.8 | 7.2 | Linux | Linux | — | batman-adv: gw: acquire ethernet header only after skb realloc |
| CVE-2026-80604 | 8.8 | 7.2 | Linux | Linux | — | HID: core: Fix OOB read in hid_get_report for numbered reports |
| CVE-2026-80590 | 8.6 | 7.2 | Linux | Linux | — | inet: frags: strip GSO state from fragments before reassembly |
| CVE-2026-80593 | 8.4 | 7.2 | Linux | Linux | — | hwmon: (asus_atk0110) Check package count before accessing element |
| CVE-2026-80599 | 8.1 | 7.2 | Linux | Linux | — | batman-adv: dat: ensure accessible eth_hdr proto field |
| CVE-2026-80645 | 8.1 | 7.2 | Linux | Linux | — | rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() |
| CVE-2026-80591 | 7.8 | 7.2 | Linux | Linux | — | f2fs: fix listxattr handling of corrupted xattr entries |
| CVE-2026-80619 | 7.8 | 7.2 | Linux | Linux | — | apparmor: fix potential UAF in aa_replace_profiles |
| CVE-2026-80622 | 7.8 | 7.2 | Linux | Linux | — | char: tlclk: fix use-after-free in tlclk_cleanup() |
| CVE-2026-80677 | 7.8 | 7.2 | Linux | Linux | — | driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() |
| CVE-2026-80680 | 7.8 | 7.2 | Linux | Linux | — | i2c: amd-mp2: Unregister callback on adapter add failure |
| CVE-2026-80646 | 7.5 | 7.2 | Linux | Linux | — | ipv6: guard against possible NULL deref in __in6_dev_stats_get() |
| CVE-2026-80664 | 7.3 | 7.2 | Linux | Linux | — | netfilter: xt_nat: reject unsupported target families |
| CVE-2026-82123 | 6.5 | 7.2 | Tangible | Loops & Logic | CWE-79 | WordPress Loops & Logic - Reflected XSS |
| CVE-2026-80594 | await | 7.2 | Linux | Linux | — | Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing |
| CVE-2026-80595 | await | 7.2 | Linux | Linux | — | Input: ims-pcu - add response length checks |
| CVE-2026-80597 | await | 7.2 | Linux | Linux | — | mtd: maps: vmu-flash: fix NULL pointer dereference in initialization |
| CVE-2026-80605 | await | 7.2 | Linux | Linux | — | HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() |
| CVE-2026-80626 | await | 7.2 | Linux | Linux | — | powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del |
| CVE-2026-80627 | await | 7.2 | Linux | Linux | — | MIPS: mm: Fix out-of-bounds write in maar_res_walk() |
| CVE-2026-80644 | await | 7.2 | Linux | Linux | — | ocfs2: don't BUG_ON an invalid journal dinode |
| CVE-2026-80647 | await | 7.2 | Linux | Linux | — | RDMA/hns: Fix warning in poll cq direct mode |
| CVE-2026-80652 | await | 7.2 | Linux | Linux | — | crypto: ccp - Treat zero-length cert chain as query for blob lengths |
| CVE-2026-80679 | await | 7.2 | Linux | Linux | — | s390/dasd: Fix potential NULL pointer dereference |
| CVE-2026-80609 | 9.8 | 6.8 | Linux | Linux | — | qede: fix out-of-bounds check for cqe->len_list[] |
| CVE-2026-80684 | 9.3 | 6.8 | Linux | Linux | — | KVM: s390: pci: Fix NULL dereference on AIBV allocation failure |
| CVE-2026-80635 | 8.8 | 6.8 | Linux | Linux | — | wifi: wcn36xx: fix OOB read from short trigger BA firmware response |
| CVE-2026-80678 | 8.4 | 6.8 | Linux | Linux | — | i2c: imx: Fix slave registration race and error handling |
| CVE-2026-80598 | 7.8 | 6.8 | Linux | Linux | — | ntfs3: fix out-of-bounds read in decompress_lznt |
| CVE-2026-80613 | 7.8 | 6.8 | Linux | Linux | — | veth: fix NAPI leak in XDP enable error path |
| CVE-2026-80649 | 7.8 | 6.8 | Linux | Linux | — | firmware: arm_scmi: Fix OOB in scmi_power_name_get() |
| CVE-2026-80682 | 7.8 | 6.8 | Linux | Linux | — | riscv/mm: use physical alignment for vmemmap_start_pfn |
| CVE-2026-80663 | 7.1 | 6.8 | Linux | Linux | — | tools/power/x86/intel-speed-select: Harden daemon pidfile open |
| CVE-2026-80618 | await | 6.8 | Linux | Linux | — | drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free |
| CVE-2026-80620 | await | 6.8 | Linux | Linux | — | Revert "PCI/MSI: Unmap MSI-X region on error" |
| CVE-2026-80660 | await | 6.8 | Linux | Linux | — | hwmon: (occ) unregister sysfs devices outside occ lock |
| CVE-2026-80669 | await | 6.8 | Linux | Linux | — | bpf: Disable xfrm_decode_session hook attachment |
| CVE-2026-80686 | await | 6.8 | Linux | Linux | — | mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE |
| CVE-2026-80615 | 8.2 | 6.7 | Linux | Linux | — | net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone |
| CVE-2026-80639 | await | 6.7 | Linux | Linux | — | cxl/test: Fix __fortify_panic |
| CVE-2026-73827 | 4.8 | 6.4 | Tsuyoshi Saito | SOY Calendar | CWE-79 | SOY Calendar contains a cross-site scripting vulnerability. An arbitrary scri… |
| CVE-2026-77838 | 4.8 | 6.4 | Tsuyoshi Saito | SOY Calendar | CWE-79 | SOY Calendar contains a cross-site scripting vulnerability. An arbitrary scri… |
| CVE-2026-78238 | 4.8 | 6.4 | Tsuyoshi Saito | SOY Gallery | CWE-79 | SOY Gallery contains a cross-site scripting vulnerability. An arbitrary scrip… |
| CVE-2026-80694 | 9.8 | 6.3 | Linux | Linux | — | net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller |
| CVE-2026-80596 | 8.4 | 6.3 | Linux | Linux | — | Input: ims-pcu - only expose sysfs attributes on control interface |
| CVE-2026-80696 | 7.8 | 6.3 | Linux | Linux | — | hwmon: (ltc4282) Fix reading the minimum alarm voltage |
| CVE-2026-80700 | 7.8 | 6.3 | Linux | Linux | — | drm/vmwgfx: validate external BO copy bounds for both stride paths |
| CVE-2026-80702 | 7.8 | 6.3 | Linux | Linux | — | drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size |
| CVE-2026-80637 | 7.5 | 6.3 | Linux | Linux | — | netfilter: synproxy: fix unaligned memory access in timestamp adjustment |
| CVE-2026-80691 | 7.5 | 6.3 | Linux | Linux | — | scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE |
| CVE-2026-80602 | await | 6.3 | Linux | Linux | — | perf/x86/amd/lbr: Fix kernel address leakage |
| CVE-2026-80611 | await | 6.3 | Linux | Linux | — | ACPI: processor_idle: Mark LPI enter functions as __cpuidle |
| CVE-2026-80624 | await | 6.3 | Linux | Linux | — | mfd: cs42l43: Sanity check firmware size |
| CVE-2026-80629 | await | 6.3 | Linux | Linux | — | octeontx2-af: npc: Fix size of entry2cntr_map |
| CVE-2026-80636 | await | 6.3 | Linux | Linux | — | netfilter: conntrack: revert ct extension genid infrastructure |
| CVE-2026-80650 | await | 6.3 | Linux | Linux | — | media: atomisp: gc2235: fix UAF and memory leak |
| CVE-2026-80654 | await | 6.3 | Linux | Linux | — | soc: xilinx: Shutdown and free rx mailbox channel |
| CVE-2026-80667 | await | 6.3 | Linux | Linux | — | net/mlx5: LAG, MPESW, Fix missing complete() on devcom error |
| CVE-2026-80676 | await | 6.3 | Linux | Linux | — | Drivers: hv: vmbus: use generic driver_override infrastructure |
| CVE-2026-80689 | await | 6.3 | Linux | Linux | — | tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions |
| CVE-2026-80695 | await | 6.3 | Linux | Linux | — | hwmon: (sht3x) Fix unaligned accesses |
| CVE-2026-80683 | 8.8 | 6.1 | Linux | Linux | — | Bluetooth: SCO: give the socket its own sco_conn reference |
| CVE-2026-80653 | 8.4 | 6.1 | Linux | Linux | — | scsi: hisi_sas: Add slave_destroy interface for v3 hw |
| CVE-2026-80628 | 7.8 | 6.1 | Linux | Linux | — | ALSA: seq: oss: Serialize readq reset state with q->lock |
| CVE-2026-80661 | 7.8 | 6.1 | Linux | Linux | — | ufs: core: tracing: Do not dereference pointers in TP_printk() |
| CVE-2026-80614 | 7.5 | 6.1 | Linux | Linux | — | net: emac: Fix NULL pointer dereference in emac_probe |
| CVE-2026-80662 | 7.1 | 6.1 | Linux | Linux | — | cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size |
| CVE-2026-80675 | 7.1 | 6.1 | Linux | Linux | — | libbpf: Reject non-exclusive metadata maps in the signed loader |
| CVE-2026-80685 | 7.1 | 6.1 | Linux | Linux | — | mm/util: don't read __page_2 for order-1 folios in snapshot_page() |
| CVE-2026-12513 | 6.8 | 6.1 | Unknown | Shared Files | CWE-73 | Shared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path Trav… |
| CVE-2026-80592 | await | 6.1 | Linux | Linux | — | samples/damon/mtier: fail early if address range parameters are invalid |
| CVE-2026-80607 | await | 6.1 | Linux | Linux | — | tracing/probes: Remove WARN_ON_ONCE from parse_btf_arg |
| CVE-2026-80621 | await | 6.1 | Linux | Linux | — | PCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when no RAS… |
| CVE-2026-80623 | await | 6.1 | Linux | Linux | — | coresight: ete: Always save state on power down |
| CVE-2026-80643 | await | 6.1 | Linux | Linux | — | EDAC/igen6: Fix call trace due to missing release() |
| CVE-2026-80648 | await | 6.1 | Linux | Linux | — | pinctrl: spacemit: fix NULL check in spacemit_pin_set_config |
| CVE-2026-80658 | await | 6.1 | Linux | Linux | — | drm/rockchip: dw_dp: Fix null-ptr-deref in dw_dp_remove() |
| CVE-2026-80666 | await | 6.1 | Linux | Linux | — | Bluetooth: sco: Fix a race condition in sco_sock_timeout() |
| CVE-2026-80687 | await | 6.1 | Linux | Linux | — | iommufd/viommu: Release the igroup lock on the vdevice_size error path |
| CVE-2026-80688 | await | 6.1 | Linux | Linux | — | riscv: drop __init from vec_check_unaligned_access_speed_all_cpus |
| CVE-2026-80701 | await | 6.1 | Linux | Linux | — | drm/vmwgfx: enforce cursor size limits for MOB cursors |
| CVE-2026-80714 | 9.8 | 5.9 | Linux | Linux | — | ipvs: do not propagate one-packet flag to synced conns |
| CVE-2026-80706 | 7.8 | 5.9 | Linux | Linux | — | can: softing: fw_parse(): validate firmware record spans |
| CVE-2026-80716 | 7.8 | 5.9 | Linux | Linux | — | ALSA: pcm: wake linked drain waiters on unlink |
| CVE-2026-80718 | 7.8 | 5.9 | Linux | Linux | — | mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() |
| CVE-2026-80707 | 7.5 | 5.9 | Linux | Linux | — | can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer |
| CVE-2026-80717 | 7.5 | 5.9 | Linux | Linux | — | sctp: validate Adaptation Indication parameter length |
| CVE-2026-80708 | await | 5.9 | Linux | Linux | — | s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() |
| CVE-2026-80722 | 8.8 | 5.5 | Linux | Linux | — | wifi: mac80211: validate individual TWT params before driver setup |
| CVE-2026-80709 | 7.8 | 5.5 | Linux | Linux | — | s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs |
| CVE-2026-80715 | await | 5.5 | Linux | Linux | — | igc: remove napi_synchronize() in igc_down() |
| CVE-2026-80704 | await | 5.4 | Linux | Linux | — | drm/amd/display: use proper context for logging |
| CVE-2026-80723 | 8.4 | 5.1 | Linux | Linux | — | of: reserved_mem: prevent OOB when too many dynamic regions are defined |
| CVE-2026-80710 | 7.8 | 5.1 | Linux | Linux | — | s390/dasd: Fix undersized format-check buffer |
| CVE-2026-19084 | 7.5 | 5.1 | Unknown | shared-files-pro | CWE-73 | Shared Files < 1.7.70 - Unauthenticated Arbitrary File Read |
| CVE-2026-16654 | 6.4 | 5.1 | themefusion | Avada (Fusion) Builder | CWE-79 | Avada (Fusion) Builder <= 3.15.6 - Authenticated (Contributor+) Stored Cross-… |
| CVE-2026-14567 | 5.3 | 5.1 | Unknown | User Frontend | CWE-200 | WP User Frontend < 4.3.10 - Unauthenticated User Email and Phone Disclosure v… |
| CVE-2026-79706 | 5.3 | 5.1 | Unknown | Breeze Cache | CWE-434 | Breeze Cache < 2.5.13 - Unauthenticated File Creation via Cache Path Traversal |
| CVE-2026-80703 | await | 5.1 | Linux | Linux | — | drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE |
| CVE-2026-80711 | await | 5.1 | Linux | Linux | — | power: supply: max17040: handle missing status supplier |
| CVE-2026-80612 | 9.8 | 5.0 | Linux | Linux | — | net: lwtunnel: Drop skb metadata before LWT encapsulation |
| CVE-2026-80634 | 9.8 | 5.0 | Linux | Linux | — | netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag |
| CVE-2026-80668 | 9.8 | 5.0 | Linux | Linux | — | netfilter: nf_conntrack_expect: use conntrack GC to reap expectations |
| CVE-2026-80673 | 9.8 | 5.0 | Linux | Linux | — | ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find() |
| CVE-2026-80674 | 9.8 | 5.0 | Linux | Linux | — | ntfs: validate resident attribute lists and harden the validator |
| CVE-2026-80693 | 9.3 | 5.0 | Linux | Linux | — | idpf: bound interrupt-vector register fill to the allocated array |
| CVE-2026-80608 | 8.8 | 5.0 | Linux | Linux | — | accel/amdxdna: Fix iommu domain lifetime race during device removal |
| CVE-2026-80633 | 8.8 | 5.0 | Linux | Linux | — | iommufd: Take dma_resv lock before dma_buf_unpin() in release path |
| CVE-2026-80638 | 8.8 | 5.0 | Linux | Linux | — | ocfs2: fix out-of-bounds write in ocfs2_remove_refcount_extent |
| CVE-2026-80672 | 8.8 | 5.0 | Linux | Linux | — | ntfs: fix u16 truncation of restart-area length check |
| CVE-2026-80692 | 8.8 | 5.0 | Linux | Linux | — | Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks |
| CVE-2026-80656 | 7.8 | 5.0 | Linux | Linux | — | hfsplus: Add a sanity check for btree node size |
| CVE-2026-80631 | 7.5 | 5.0 | Linux | Linux | — | btrfs: lzo: reject compressed segment that overflows the compressed input |
| CVE-2026-80610 | await | 5.0 | Linux | Linux | — | net: enetc: fix potential divide-by-zero when num_vsi is zero |
| CVE-2026-80625 | await | 5.0 | Linux | Linux | — | RDMA/hns: Fix memory leak of bonding resources |
| CVE-2026-80632 | await | 5.0 | Linux | Linux | — | wifi: mt76: mt7996: Fix NULL pointer dereference in mt7996_init_tx_queues() |
| CVE-2026-80641 | await | 5.0 | Linux | Linux | — | wifi: wlcore: enable the right set of ciphers |
| CVE-2026-80642 | await | 5.0 | Linux | Linux | — | liveupdate: Reference count incoming FLB data |
| CVE-2026-80651 | await | 5.0 | Linux | Linux | — | crypto: ccp/sev-dev-tsm - bail out early when pdev->bus is NULL |
| CVE-2026-80655 | await | 5.0 | Linux | Linux | — | soc: xilinx: Fix race condition in event registration |
| CVE-2026-80657 | await | 5.0 | Linux | Linux | — | accel/amdxdna: Guard management mailbox channel cleanup against NULL pointer |
| CVE-2026-80690 | await | 5.0 | Linux | Linux | — | scsi: ufs: core: Initialize hba->rpmbs list in ufshcd |
| CVE-2026-80697 | await | 5.0 | Linux | Linux | — | erofs: ensure valid f_path for page cache sharing |
| CVE-2026-80698 | await | 5.0 | Linux | Linux | — | dmaengine: idxd: fix double free of wq, engine, and group structs |
| CVE-2026-80699 | await | 5.0 | Linux | Linux | — | KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context |
| CVE-2026-80721 | 8.8 | 4.9 | Linux | Linux | — | Bluetooth: ISO: ensure no dangling hcon references in iso_conn |
| CVE-2026-80724 | 8.8 | 4.9 | Linux | Linux | — | ptp: vmclock: prevent read-only mappings from becoming writable |
| CVE-2026-80712 | 8.4 | 4.9 | Linux | Linux | — | spi: spi-qpic-snand: write the feature value before executing SET_FEATURE |
| CVE-2026-80720 | 7.5 | 4.9 | Linux | Linux | — | iomap: add a separate bio_set for iomap_split_ioend |
| CVE-2026-19423 | 8.1 | 4.2 | Unknown | Ultimate Member | CWE-269 | Ultimate Member 2.6.7 - 2.12.1 - Unauthenticated Privilege Escalation via Rol… |
| CVE-2026-82081 | 6.4 | 4.2 | wallabag | wallabag | CWE-918 | wallabag 2 through 2.6.14 allows SSRF because a crafted title or content fiel… |
| CVE-2026-12514 | 5.3 | 4.2 | Unknown | Shared Files | CWE-862 | Shared Files < 1.7.70 - Unauthenticated Limited File Upload |
| CVE-2026-77701 | 5.3 | 4.2 | Unknown | WCFM Marketplace | CWE-862 | WCFM Marketplace < 3.8.2 - Unauthenticated Refund Request Creation on Guest O… |
| CVE-2026-80713 | 8.4 | 4.0 | Linux | Linux | — | io_uring: preserve task restrictions across exec |
| CVE-2026-80705 | await | 4.0 | Linux | Linux | — | drm/amd/display: check if dml21_add_phantom_plane() is successful |
| CVE-2026-80719 | await | 4.0 | Linux | Linux | — | mm: mglru: fix stale batch updates after memcg reparenting |
| CVE-2026-79996 | 7.2 | 3.8 | Unknown | User Registration & Membership | CWE-269 | User Registration & Membership < 5.2.6 - Authenticated Privilege Escalation v… |
| CVE-2026-79995 | 4.3 | 3.8 | Unknown | User Registration & Membership | CWE-639 | User Registration & Membership < 5.2.5 - Subscriber+ Pending Email Change Can… |
| CVE-2026-79615 | 2.7 | 3.8 | Unknown | Quiz and Survey Master (QSM) | CWE-639 | Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Question Bank and A… |
| CVE-2026-54745 | 10.0 | — | kubeflow | pipelines | CWE-284 | Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipel… |
| CVE-2026-82222 | 10.0 | — | Liquid Web / StellarWP | GiveWP | CWE-502 | WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability |
| CVE-2026-18527 | 9.9 | — | IBM | Administration Runtime Expert for i | CWE-384 | IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gainin… |
| CVE-2026-19295 | 9.9 | — | IBM | Langflow OSS | CWE-95 | Langflow is affected by multiple remote code execution vulnerabilities due to… |
| CVE-2026-55565 | 9.9 | — | yamcs | yamcs | CWE-94 | Yamcs: Authenticated remote code execution via unescaped StreamSQL `LIKE` pat… |
| CVE-2026-55634 | 9.9 | — | pimcore | pimcore | CWE-89 | Pimcore: Remote Code Execution via DataObject Class-Definition Field Name |
| CVE-2026-19286 | 9.8 | — | IBM | Langflow OSS | CWE-94 | Langflow is affected by multiple remote code execution vulnerabilities due to… |
| CVE-2026-37751 | 9.8 | — | n/a | n/a | CWE-78 | An OS command injection vulnerability in the killSessionSync function (lib/ag… |
| CVE-2026-55559 | 9.8 | — | yamcs | yamcs | CWE-94 | Yamcs: Remote Code Execution via instance-template argument YAML injection (c… |
| CVE-2026-82329 | 9.8 | — | jfrog | artifactory | CWE-287 | Potential authentication bypass leading to administrative access in Artifactory |
| CVE-2026-54754 | 9.6 | — | klever-io | klever-go | CWE-191 | Klever-Go: Marketplace settlement mints KLV when referral % + royalty % excee… |
| CVE-2026-54755 | 9.6 | — | klever-io | klever-go | CWE-190 | Klever-Go: Integer overflow in split-royalty validation enables unbounded min… |
| CVE-2026-82078 | 9.4 | — | PaperCut | PaperCut MF/NG | CWE-470 | PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector |
| CVE-2026-82244 | 9.4 | — | budibase | server | CWE-94 | Budibase before 3.41.3 Remote Code Execution via Plugin eval() |
| CVE-2026-55068 | 9.3 | — | free5gc | free5gc | CWE-20 | free5GC: NRF nnrf-nfm lacks NF Profile input validation — enables NF Registra… |
| CVE-2026-55220 | 9.3 | — | pimcore | pimcore | CWE-502 | Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserializ… |
| CVE-2026-55378 | 9.3 | — | shriyanss | js-recon | CWE-78 | JS Recon: Command injection in PR Branch Checker workflow via untrusted pull … |
| CVE-2026-82266 | 9.3 | — | redpanda-data | redpanda | CWE-306 | Redpanda Admin API Unauthenticated Superuser Access via Default Configuration |
| CVE-2026-82277 | 9.3 | — | argoproj | argo-rollouts | CWE-306 | Argo Rollouts Dashboard Unauthenticated Mutating Operations |
| CVE-2026-3627 | 9.1 | — | IBM | Concert | — | Multiple Vulnerabilities in IBM Concert Software |
| CVE-2026-18918 | 9.1 | — | Eclipse Foundation | Eclipse Lyo | CWE-863 | OAuth 1.0 session-fixation chain via unauthenticated provisional-consumer reg… |
| CVE-2026-42007 | 9.1 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-416 | An attacker that has valid credentials can use a Sieve script with the edithe… |
| CVE-2026-55247 | 9.1 | — | plone | plone.app.event | CWE-400 | plone.app.event: Denial of service via iCalendar import |
| CVE-2026-55248 | 9.1 | — | plone | plone.app.portlets | CWE-400 | plone.app.portlets: Denial of service via RSS feed portlet |
| CVE-2026-55511 | 9.1 | — | yamcs | yamcs | CWE-94 | Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injecti… |
| CVE-2026-82281 | 9.1 | — | Cinnamon | kotaemon | CWE-639 | Kotaemon Missing Ownership Check in Conversation Functions |
| CVE-2026-82021 | 9.0 | — | NousResearch | hermes-agent | CWE-494 | Hermes Agent 0.18.2 < 0.19.0 MCP Catalog Supply Chain RCE via Mutable Branch … |
| CVE-2026-13761 | 8.8 | — | Pegasystems | Pega Infinity | CWE-606 | Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper valid… |
| CVE-2026-18729 | 8.8 | — | IBM | Langflow OSS | CWE-94 | Langflow is affected by multiple remote code execution vulnerabilities due to… |
| CVE-2026-55485 | 8.8 | — | piccolo-orm | piccolo_admin | CWE-200 | Piccolo Admin: Privilege escalation - admin to superuser via session-token di… |
| CVE-2026-55509 | 8.8 | — | mar10 | wsgidav | CWE-89 | WsgiDAV: Blind SQL injection in the MySQL provider |
| CVE-2026-55521 | 8.8 | — | yamcs | yamcs | CWE-862 | Yamcs : Multiple Missing Function Level Access Control vulnerabilities in Yam… |
| CVE-2026-72984 | 8.8 | — | Microsoft | Microsoft Edge (Chromium-based) | CWE-843 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-81578 | 8.8 | — | PaperCut | PaperCut MF/NG | CWE-305 | PaperCut MF/NG: Authentication Bypass |
| CVE-2026-82282 | 8.8 | — | runatlantis | atlantis | CWE-306 | Atlantis GitHub App Setup Endpoint Returns App Credentials to Unauthenticated… |
| CVE-2026-82285 | 8.8 | — | dataelement | bisheng | CWE-918 | BISHENG Unauthenticated Server-Side Request Forgery via Workflow Report Callback |
| CVE-2026-82286 | 8.8 | — | BuilderIO | gpt-crawler | CWE-22 | gpt-crawler Arbitrary File Write via outputFileName Parameter |
| CVE-2026-19412 | 8.7 | — | CP Plus | CP-XR-DE21-S Router | CWE-798 | Hardcoded Credentials Vulnerability in CP Plus CP-XR-DE21-S Router |
| CVE-2026-55245 | 8.7 | — | maximhq | bifrost | CWE-918 | Bifrost: SSRF deny-list incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64… |
| CVE-2026-55763 | 8.7 | — | klever-io | klever-go | CWE-841 | Klever-Go: Percentage-transfer royalty skips the source debit at exactly-100%… |
| CVE-2026-55764 | 8.7 | — | klever-io | klever-go | CWE-190 | Klever-Go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxS… |
| CVE-2026-75118 | 8.7 | — | TP-Link Systems Inc. | TL-MR100 v3.20 | CWE-121 | http_gdpr_decrypt Pre-Authentication Stack-Based Buffer Overflow |
| CVE-2026-75124 | 8.7 | — | PLANET Technology Corp. | PLANET GS-4210-16P2S | CWE-120 | PLANET GS-4210-16P2S Memory Corruption via dispatcher.cgi _readHttpParam |
| CVE-2026-78072 | 8.7 | — | Jefferson49 | Sexy Polling Reloaded extension for Joomla | CWE-89 | Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling R… |
| CVE-2026-81517 | 8.7 | — | MongoDB | BI Connector | CWE-248 | MongoDB Connector for BI Improper Error Handling of Log Write Failures May Ca… |
| CVE-2026-81518 | 8.7 | — | MongoDB | BI Connector | CWE-295 | BI Connector Optional Client Certificate Verification Allows Unauthenticated … |
| CVE-2026-81520 | 8.7 | — | MongoDB | BI Connector | CWE-1088 | MongoDB Connector for BI Unbounded Authentication Negotiation Leading to Conn… |
| CVE-2026-81532 | 8.7 | — | MongoDB | BI Connector ODBC Driver | CWE-121 | BI Connector ODBC Driver Improper Bounds Checking on Cursor Name Leading to M… |
| CVE-2026-81849 | 8.7 | — | amazon | amazon-ssm-agent | CWE-23 | Path traversal in the aws:downloadContent plugin in amazon-ssm-agent |
| CVE-2026-82247 | 8.7 | — | GitoxideLabs | gitoxide | CWE-522 | gitoxide before 0.37.1 HTTP Basic credential leak via URL parsing |
| CVE-2026-82251 | 8.7 | — | GitoxideLabs | gitoxide | CWE-22 | gitoxide before 0.52.1 Path Traversal via Submodule Name |
| CVE-2026-82252 | 8.7 | — | GitoxideLabs | gitoxide | CWE-59 | gitoxide before 0.52.1 Repository Boundary Violation via symlinked .gitmodules |
| CVE-2026-82253 | 8.7 | — | GitoxideLabs | gitoxide | CWE-22 | gitoxide before 0.82.0 Path Traversal via Submodule Name Validation Bypass |
| CVE-2026-82254 | 8.7 | — | GitoxideLabs | gitoxide | CWE-248 | gitoxide before 0.69.0 Denial of Service via gix-pack |
| CVE-2026-82259 | 8.7 | — | sveltejs | kit | CWE-502 | SvelteKit 2.49.0 before 2.53.3 Denial of Service via form |
| CVE-2026-82260 | 8.7 | — | sveltejs | kit | CWE-400 | SvelteKit before 2.52.2 Memory Exhaustion via Remote Form Deserialization |
| CVE-2026-82261 | 8.7 | — | sveltejs | kit | CWE-400 | SvelteKit before 2.52.2 CPU Exhaustion via Remote Form Deserialization |
| CVE-2026-82268 | 8.7 | — | QwenLM | Qwen-Agent | CWE-918 | Qwen-Agent Server-Side Request Forgery via Caller-Supplied Document URL |
| CVE-2026-82270 | 8.7 | — | Portkey-AI | gateway | CWE-918 | Portkey AI Gateway Server-Side Request Forgery via /v1/proxy/* |
| CVE-2026-82275 | 8.7 | — | QwenLM | Qwen-Agent | CWE-22 | Qwen-Agent Arbitrary File Read via Caller-Supplied Document Path |
| CVE-2026-82278 | 8.7 | — | dataelement | bisheng | CWE-94 | BISHENG Authenticated Arbitrary Python Code Execution via Workflow run_once |
| CVE-2026-82288 | 8.7 | — | AUTOMATIC1111 | stable-diffusion-webui | CWE-522 | Stable Diffusion WebUI Credential Disclosure via /sdapi/v1/cmd-flags |
| CVE-2026-55848 | 8.6 | — | mapfish | mapfish-print | CWE-611 | mapfish-print: XXE on MapFish Print allows reading arbitrary files of certain… |
| CVE-2026-56100 | 8.6 | — | SpringBlade | SpringBlade | CWE-862 | SpringBlade 2.7.3 < 5.0.0 Privilege Escalation via Exposed Feign Endpoint |
| CVE-2026-75121 | 8.6 | — | PLANET Technology Corp. | PLANET GS-4210-16P2S | CWE-78 | PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_vlan_membership… |
| CVE-2026-75122 | 8.6 | — | PLANET Technology Corp. | PLANET GS-4210-16P2S | CWE-78 | PLANET GS-4210-16P2S Command Injection via httpuploadcert.cgi |
| CVE-2026-75123 | 8.6 | — | PLANET Technology Corp. | PLANET GS-4210-16P2S | CWE-78 | PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_post |
| CVE-2026-82017 | 8.6 | — | IGEL | IGEL OS 12 | CWE-345 | IGEL OS 12 / 11 Boot Registry Parameter Injection via Unsigned Configuration … |
| CVE-2026-82239 | 8.6 | — | budibase | server | CWE-862 | Budibase before 3.41.3 Authorization Bypass via datasources/query |
| CVE-2026-82240 | 8.6 | — | budibase | server | CWE-862 | Budibase before 3.41.3 Privilege Escalation via User Update API |
| CVE-2026-82269 | 8.6 | — | gophish | gophish | CWE-288 | Gophish Account Lockout and Forced Password Change Bypassable via API Key |
| CVE-2026-82283 | 8.6 | — | VoltAgent | voltagent | CWE-639 | VoltAgent Memory API Handlers Missing Ownership Checks |
| CVE-2026-82284 | 8.6 | — | QuivrHQ | quivr | CWE-639 | Quivr Chat Endpoints Missing Ownership Validation |
| CVE-2026-82287 | 8.6 | — | rybbit-io | rybbit | CWE-942 | Rybbit Reflects Any Origin in CORS Responses While Allowing Credentials |
| CVE-2026-55108 | 8.5 | — | kubevela | kubevela | CWE-59 | KubeVela Terraform remote loader DoS via unbounded file read |
| CVE-2026-75486 | 8.5 | — | snyk | sweater-comb | CWE-78 | Synk Sweater Comb < 3.8.8 Command Injection via .vervet.yaml Branch Name |
| CVE-2026-77586 | 8.5 | — | MongoDB | BI Connector | CWE-89 | MongoDB Connector for BI Unescaped Object Names in Generated SHOW CREATE Output |
| CVE-2026-82227 | 8.5 | — | VillaTheme | WPBulky | CWE-89 | WordPress WPBulky plugin <= 1.2.2 - SQL Injection vulnerability |
| CVE-2026-82234 | 8.4 | — | siyuan-note | siyuan | CWE-918 | SiYuan before v3.8.1 SSRF via DNS-Rebinding TOCTOU |
| CVE-2026-81490 | 8.3 | — | MongoDB | BI Connector | CWE-476 | MongoDB Connector for BI Improper Error Handling During Schema Sampling May C… |
| CVE-2026-82242 | 8.3 | — | budibase | server | CWE-862 | Budibase before 3.41.3 Cross-Application Resource Injection via Missing Autho… |
| CVE-2026-82243 | 8.3 | — | budibase | server | CWE-918 | Budibase Server before 3.41.3 SSRF with Credential Leakage |
| CVE-2026-82289 | 8.3 | — | coderamp-labs | gitingest | CWE-918 | Gitingest Prefix-Based Git Host Check Enables Request Forgery and Token Discl… |
| CVE-2026-18891 | 8.2 | — | IBM | Langflow OSS | CWE-287 | Langflow is affected by multiple authentication bypass, path traversal, autho… |
| CVE-2026-18904 | 8.2 | — | IBM | Langflow OSS | CWE-639 | Langflow is affected by multiple authentication bypass, path traversal, autho… |
| CVE-2026-82235 | 8.2 | — | filebrowser | filebrowser | CWE-400 | filebrowser through 2.63.23 Denial of Service via named pipes |
| CVE-2026-82262 | 8.2 | — | logto-io | logto | CWE-918 | Logto Server-Side Request Forgery via webhook test endpoint |
| CVE-2026-82263 | 8.2 | — | logto-io | logto | CWE-918 | Logto Server-Side Request Forgery via OIDC SSO Connector Issuer URL |
| CVE-2026-50979 | 8.1 | — | n/a | n/a | CWE-77 | A command injection vulnerability in the 'advanced/curl' component of Osbil T… |
| CVE-2026-55065 | 8.1 | — | go-vikunja | vikunja | CWE-285 | Vikunja: Improper Authorization and Authorization Bypass Through User-Control… |
| CVE-2026-82291 | 8.1 | — | heyform | heyform | CWE-942 | HeyForm Reflects Any Origin in CORS Responses While Allowing Credentials |
| CVE-2026-82020 | 7.6 | — | NousResearch | hermes-agent | CWE-552 | Hermes Agent 0.16.0 < 0.17.0 Credential Store Overwrite via File-Write Tool |
| CVE-2026-82255 | 7.6 | — | GitoxideLabs | gitoxide | CWE-522 | gitoxide 0.25.4 HTTP Credential Leak via Redirect |
| CVE-2026-17203 | 7.5 | — | IBM | Administration Runtime Expert for i | CWE-287 | IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gainin… |
| CVE-2026-18899 | 7.5 | — | IBM | Langflow OSS | CWE-22 | Langflow is affected by multiple authentication bypass, path traversal, autho… |
| CVE-2026-27852 | 7.5 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-400 | An attacker that can send mail to a user can craft a message whose headers co… |
| CVE-2026-33605 | 7.5 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-400 | An unauthenticated attacker can crash the ManageSieve login process by sendin… |
| CVE-2026-37237 | 7.5 | — | n/a | n/a | CWE-400 | vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of … |
| CVE-2026-37736 | 7.5 | — | n/a | n/a | CWE-770 | An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1… |
| CVE-2026-38636 | 7.5 | — | n/a | n/a | CWE-400 | An issue in the seekdir() function (/dirent/mod.rs) of relibc commit 61f42d a… |
| CVE-2026-38638 | 7.5 | — | n/a | n/a | CWE-400 | An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d a… |
| CVE-2026-42391 | 7.5 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-400 | An unauthenticated attacker can send an IMAP ID command with a very large num… |
| CVE-2026-54788 | 7.5 | — | DataDog | dd-trace-rs | CWE-770 | dd-trace-rs: Unbounded W3C tracestate parsing may lead to DoS |
| CVE-2026-55215 | 7.5 | — | mariadb-corporation | mariadb-connector-nodejs | CWE-295 | MariaDB Connector/Node.js: Connector leaks the cleartext password to an MitM … |
| CVE-2026-55484 | 7.5 | — | guno1928 | alos-http | CWE-248 | ALOS HTTP: Unauthenticated remote DoS: malformed path starting with "?" trigg… |
| CVE-2026-55552 | 7.5 | — | yamcs | yamcs | CWE-22 | Yamcs: Unauthenticated Directory Traversal |
| CVE-2026-55584 | 7.5 | — | phpsysinfo | phpsysinfo | CWE-290 | phpSysInfo: IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / C… |
| CVE-2026-55784 | 7.5 | — | free5gc | free5gc | CWE-362 | free5GC AUSF authentication contexts can be overwritten by concurrent request… |
| CVE-2026-55841 | 7.5 | — | Graylog2 | graylog2-server | CWE-138 | Graylog: Fortigate syslog message parser can be exploited to modify or delete… |
| CVE-2026-56854 | 7.5 | — | golang.org/x/crypto | golang.org/x/crypto/ssh | CWE-863 | Source-address critical option not enforced for non-public-key auth callbacks… |
| CVE-2026-77037 | 7.5 | — | multer | multer | CWE-400 | multer vulnerable to Denial of Service via file descriptor leak on aborted up… |
| CVE-2026-77078 | 7.5 | — | multer | multer | CWE-248 | multer vulnerable to Denial of Service via crafted multipart field names |
| CVE-2026-78071 | 7.5 | — | digital-peak.com | DP Calendar extension for Joomla | CWE-79 | Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in… |
| CVE-2026-81285 | 7.5 | — | WPMU DEV | Smush Image Compression and Optimization | CWE-770 | WordPress Smush Image Compression and Optimization plugin <= 4.2.0 - Denial o… |
| CVE-2026-81767 | 7.5 | — | yalla ya! | Simple Payment | CWE-862 | WordPress Simple Payment plugin <= 2.5.2 - Broken Access Control vulnerability |
| CVE-2026-82333 | 7.5 | — | multer | multer | CWE-400 | multer vulnerable to Denial of Service via oversized array index in field names |
| CVE-2026-40018 | 7.4 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-89 | None None None No publicly available exploits are known. |
| CVE-2026-73208 | 7.4 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-287 | An attacker that holds a token intended for a different purpose can authentic… |
| CVE-2026-81019 | 7.4 | — | wolfSSL Inc. | wolfProvider | CWE-323 | wolfProvider reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record |
| CVE-2026-81020 | 7.4 | — | wolfSSL Inc. | wolfEngine | CWE-323 | wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record |
| CVE-2026-5934 | 7.2 | — | WP Media | WP Rocket | CWE-79 | WP Rocket <= 3.21.0.1 - Unauthenticated Stored Cross-Site Scripting via Pictu… |
| CVE-2026-6176 | 7.2 | — | ivole | Customer Reviews for WooCommerce | CWE-79 | Customer Reviews for WooCommerce <= 5.106.0 - Unauthenticated Stored Cross-Si… |
| CVE-2026-81757 | 7.2 | — | Rank Math SEO | Rank Math SEO | CWE-502 | WordPress Rank Math SEO plugin <= 1.0.276 - Remote Code Execution (RCE) vulne… |
| CVE-2026-82245 | 7.2 | — | budibase | server | CWE-862 | Budibase before 3.41.3 Missing Authorization License Management |
| CVE-2026-82279 | 7.2 | — | hyperdxio | hyperdx | CWE-862 | HyperDX Team Management Operations Missing Role-Based Access Control |
| CVE-2026-55066 | 7.1 | — | go-vikunja | vikunja | CWE-639 | Vikunja: Cross-tenant IDOR in kanban move-task endpoint via unauthorized body… |
| CVE-2026-55520 | 7.1 | — | scrapy | protego | CWE-400 | Protego: Exponential backtracking ReDoS in robots.txt URL wildcard matching |
| CVE-2026-55673 | 7.1 | — | powsybl | powsybl-core | CWE-78 | PowSyBl: Command Injection in LocalCommandExecutor-s |
| CVE-2026-77939 | 7.1 | — | flextype | flextype | CWE-94 | Flextype CMS 1.0.0-dev RCE via POST /api/v1/query Endpoint |
| CVE-2026-81760 | 7.1 | — | Crocoblock | JetEngine | CWE-79 | WordPress JetEngine plugin <= 3.8.14.2 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-82241 | 7.1 | — | budibase | server | CWE-918 | Budibase backend-core SSRF via incomplete default blacklist |
| CVE-2026-82246 | 7.1 | — | budibase | server | CWE-918 | Budibase Server before 3.41.3 SSRF via Query Import |
| CVE-2026-82250 | 7.1 | — | GitoxideLabs | gitoxide | CWE-191 | gitoxide gix-packetline before 0.21.5 Denial of Service |
| CVE-2026-82271 | 7.1 | — | SciPhi-AI | R2R | CWE-639 | R2R Missing Ownership Check Allows Modifying Other Users' Conversations |
| CVE-2026-82272 | 7.1 | — | immich-app | immich | CWE-863 | Immich Locked Assets Remain Readable Through Albums and Shared Links |
| CVE-2026-82273 | 7.1 | — | mastra-ai | mastra | CWE-862 | Mastra Memory API Thread Ownership Check Is a No-op When mapUserToResourceId … |
| CVE-2026-82280 | 7.1 | — | QuivrHQ | quivr | CWE-639 | Quivr Prompt Endpoints Missing Ownership Validation |
| CVE-2026-16821 | 7.0 | — | IBM | AIX | CWE-134 | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-55678 | 6.9 | — | Basekick-Labs | arc | CWE-284 | Arc: Unauthenticated cluster node admission when `cluster.shared_secret` is u… |
| CVE-2026-75125 | 6.9 | — | PLANET Technology Corp. | PLANET GS-4210-16P2S | CWE-476 | PLANET GS-4210-16P2S Null Pointer Dereference DoS via dispatcher.cgi web_poe_… |
| CVE-2026-75126 | 6.9 | — | PLANET Technology Corp. | PLANET GS-4210-16P2S | CWE-121 | PLANET GS-4210-16P2S Stack Buffer Overflow via dispatcher.cgi Standard Handlers |
| CVE-2026-76798 | 6.9 | — | MongoDB | BI Connector Transition Readiness Report | CWE-79 | MongoSQL Transition Readiness Tool Improper Output Encoding in Generated HTML… |
| CVE-2026-77217 | 6.9 | — | PLANET Technology Corp. | PLANET GS-4210-16P2S | CWE-121 | PLANET GS-4210-16P2S Stack Buffer Overflow and NULL Pointer Dereference via d… |
| CVE-2026-77218 | 6.9 | — | PLANET Technology Corp. | PLANET GS-4210-16P2S | CWE-121 | PLANET GS-4210-16P2S Stack Buffer Overflow via dispatcher.cgi Credential Hand… |
| CVE-2026-78070 | 6.9 | — | digital-peak.com | DP Calendar extension for Joomla | CWE-89 | Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL inj… |
| CVE-2026-81732 | 6.9 | — | WWBN | AVideo | CWE-200 | WWBN AVideo through 30.0 Information Disclosure via report4.json.php |
| CVE-2026-82233 | 6.9 | — | siyuan-note | siyuan | CWE-22 | SiYuan before v3.8.1 Path Traversal via asset.upload |
| CVE-2026-82256 | 6.9 | — | sveltejs | kit | CWE-400 | SvelteKit before 2.69.1 Denial of Service via Remote Form |
| CVE-2026-82265 | 6.9 | — | openzipkin | zipkin | CWE-306 | Zipkin Unauthenticated Spring Boot Actuator Endpoints Exposure |
| CVE-2026-82018 | 6.8 | — | IGEL | IGEL OS 12 | CWE-636 | IGEL OS 12 / 11 Secure Boot Bypass via Unsigned igel.conf File |
| CVE-2026-82181 | 6.8 | — | Le-yan | Medical Practice Management System | CWE-598 | Le-yan|Medical Practice Management System - Sensitive Data in URL |
| CVE-2026-55569 | 6.6 | — | aquaproj | aqua | CWE-22 | aqua: Archive extraction in aqua follows attacker-planted symlinks, allowing … |
| CVE-2026-13734 | 6.5 | — | zephyrproject | zephyr | CWE-294 | Zephyr WireGuard mutates peer state before anti-replay check, enabling captur… |
| CVE-2026-40014 | 6.5 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-400 | An attacker that can send mail to a user can craft a message header that make… |
| CVE-2026-40017 | 6.5 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-400 | An attacker that can send mail to a user can craft a message header whose val… |
| CVE-2026-52687 | 6.5 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-400 | An attacker that has valid credentials can select a compression algorithm for… |
| CVE-2026-55545 | 6.5 | — | yamcs | yamcs | CWE-862 | Yamcs: WebSocket subscription handlers omit the privilege checks their REST s… |
| CVE-2026-55549 | 6.5 | — | yamcs | yamcs | CWE-79 | Yamcs: Reflected XSS in the URL of the Authorize Endpoint |
| CVE-2026-55855 | 6.5 | — | mariadb-corporation | mariadb-connector-nodejs | CWE-89 | MariaDB Connector/Node.js: Possible SQL injection in Buffer parameter escapin… |
| CVE-2026-66324 | 6.5 | — | Microsoft | Microsoft Edge (Chromium-based) | CWE-73 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-73209 | 6.5 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-674 | An attacker that has valid credentials can send crafted compressed data that … |
| CVE-2026-81341 | 6.5 | — | wolfSSL Inc. | wolfEngine | CWE-323 | wolfEngine reuses the AES-CCM nonce on TLS 1.2 / DTLS 1.2 records |
| CVE-2026-82306 | 6.5 | — | StarRocks | starrocks | CWE-200 | StarRocks Query Detail Endpoint Returns Every User's Query History |
| CVE-2026-3423 | 6.4 | — | smub | Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More | CWE-79 | Envira Gallery <= 1.12.4 - Authenticated (Author+) Stored Cross-Site Scriptin… |
| CVE-2026-5510 | 6.4 | — | stellarwp | GiveWP – Donation Plugin and Fundraising Platform | CWE-79 | GiveWP <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting v… |
| CVE-2026-6128 | 6.4 | — | servmask | All-in-One WP Migration Unlimited Extension | CWE-79 | All-in-One WP Migration Unlimited Extension <= 2.84 - Authenticated (Subscrib… |
| CVE-2026-19294 | 6.4 | — | IBM | Langflow OSS | CWE-639 | Langflow is affected by multiple authentication bypass, path traversal, autho… |
| CVE-2026-54746 | 6.4 | — | hatchet-dev | hatchet | CWE-639 | Hatchet: Cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC… |
| CVE-2026-3686 | 6.2 | — | IBM | Cloud Pak for Data System | CWE-770 | Vulnerabilities exists in IBM Cloud Pak for Data System |
| CVE-2026-5800 | 6.1 | — | Dayneks Software Industry and Trade Inc. | E-Commerce Platform | CWE-79 | Reflected XSS in Dayneks Software's E-Commerce Platform |
| CVE-2026-5953 | 6.1 | — | Ceviz Informatics Inc. | Web Design | CWE-79 | Reflected XSS in Ceviz Informatics's Web Design |
| CVE-2026-37710 | 6.1 | — | n/a | n/a | CWE-79 | Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote attacke… |
| CVE-2026-82264 | 6.1 | — | gilbertchen | duplicacy | CWE-22 | Duplicacy Path Traversal during Restore via Unsanitized Snapshot Paths |
| CVE-2026-82324 | 6.1 | — | Red Hat | Red Hat Enterprise Linux 6 | CWE-125 | Gimp: heap out-of-bounds reads in iff/ilbm loader from ham row size mismatch … |
| CVE-2026-82328 | 6.1 | — | Red Hat | Red Hat Enterprise Linux 6 | CWE-125 | Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette… |
| CVE-2026-82330 | 6.1 | — | Red Hat | Red Hat Enterprise Linux 6 | CWE-125 | Gimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing b… |
| CVE-2026-82343 | 6.1 | — | Red Hat | Red Hat Enterprise Linux 6 | CWE-120 | Gimp: heap out-of-bounds read and stack out-of-bounds access in psd loader fr… |
| CVE-2026-81533 | 6.0 | — | MongoDB | BI Connector ODBC Driver | CWE-121 | MongoDB BI Connector ODBC Driver Memory-Safety Issue When Parsing Oversized L… |
| CVE-2026-82248 | 6.0 | — | GitoxideLabs | gitoxide | CWE-59 | gitoxide before 0.33.0 Path Traversal via symlink following |
| CVE-2026-82290 | 6.0 | — | Chainlit | chainlit | CWE-639 | Chainlit Feedback Endpoints Missing Ownership Validation |
| CVE-2025-36271 | 5.9 | — | IBM | Integrated Analytics System | CWE-759 | IBM Integrated Analytics System (IIAS) is affected by a predictable salt vuln… |
| CVE-2025-36290 | 5.9 | — | IBM | Integrated Analytics System | CWE-295 | IBM Integrated Analytics System (IIAS) is affected by improper SSL/TLS certif… |
| CVE-2025-64649 | 5.9 | — | IBM | Concert | CWE-295 | Multiple Vulnerabilities in IBM Concert Software |
| CVE-2026-33604 | 5.9 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-655 | An attacker that can get Dovecot to relay a message, for example through Siev… |
| CVE-2026-40019 | 5.9 | — | Open-Xchange GmbH | OX Dovecot CE | CWE-400 | An unauthenticated attacker can send a truncated quoted argument to the Manag… |
| CVE-2026-40205 | 5.9 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-287 | An attacker that holds an OAuth2 token granting only part of the required sco… |
| CVE-2026-55854 | 5.9 | — | mariadb-corporation | mariadb-connector-nodejs | CWE-319 | MariaDB Connector/Node.js: Cleartext Transmission of Sensitive Information an… |
| CVE-2026-55856 | 5.9 | — | mariadb-corporation | mariadb-connector-j | CWE-522 | MariaDB Connector/J: Cleartext password disclosure to a MITM on the initial-h… |
| CVE-2026-55857 | 5.9 | — | mariadb-corporation | mariadb-connector-j | CWE-319 | MariaDB Connector/J: Cleartext Transmission of Sensitive Information and Insu… |
| CVE-2026-55858 | 5.9 | — | mariadb-corporation | mariadb-connector-j | CWE-838 | MariaDB Connector/J: Inappropriate Encoding for Output Context in org.mariadb… |
| CVE-2026-55859 | 5.9 | — | mariadb-corporation | mariadb-connector-r2dbc | CWE-116 | MariaDB Connector/R2DBC: Inappropriate Encoding for Output Context and Improp… |
| CVE-2026-55860 | 5.9 | — | mariadb-corporation | mariadb-connector-r2dbc | CWE-319 | MariaDB Connector/R2DBC: Cleartext password disclosure to a man-in-the-middle… |
| CVE-2026-75758 | 5.9 | — | elixir-lang | elixir | CWE-674 | Unbounded recursion between Inspect.List charlist rendering and List.to_strin… |
| CVE-2026-82258 | 5.9 | — | sveltejs | kit | CWE-362 | SvelteKit 2.38.0 before 2.60.1 Cross-User Data Disclosure via query.batch |
| CVE-2026-76797 | 5.8 | — | MongoDB | BI Connector Transition Readiness Report | CWE-1236 | MongoSQL Transition Readiness Tool Improper Neutralization of Formula Element… |
| CVE-2026-77184 | 5.7 | — | MongoDB | BI Connector | CWE-89 | MongoDB Connector for BI Incomplete Escaping of Stored Metadata in Generated … |
| CVE-2026-58107 | 5.5 | — | Ericsson | CodeChecker | CWE-409 | Authenticated Remote Denial of Service via Unbounded zlib Decompression in ma… |
| CVE-2026-82327 | 5.5 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-129 | Libsolv: libsolv: out-of-bounds write in repo_write() via unvalidated directo… |
| CVE-2026-4378 | 5.4 | — | Akilli Ticaret Software Technologies Ltd. | E-Commerce Pack | CWE-79 | Stored XSS in Akıllı Ticaret's E-Commerce Pack |
| CVE-2026-18393 | 5.4 | — | Red Hat | Red Hat Enterprise Linux AI (RHEL AI) 3 | CWE-787 | Ffmpeg: ffmpeg: heap buffer overflow in tdsc_load_cursor() via cur_fmt_mono c… |
| CVE-2026-38725 | 5.4 | — | n/a | n/a | CWE-79 | xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote… |
| CVE-2026-55779 | 5.4 | — | silverstripe | silverstripe-versioned | CWE-79 | Silverstripe Versioned: XSS in archive admin restore |
| CVE-2026-62904 | 5.4 | — | Microsoft | Microsoft Edge (Chromium-based) | CWE-863 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2026-66323 | 5.4 | — | Microsoft | Microsoft Edge (Chromium-based) | CWE-141 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-70309 | 5.4 | — | Microsoft | Microsoft Edge (Chromium-based) | CWE-346 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2026-70331 | 5.4 | — | Microsoft | Microsoft Edge (Chromium-based) | CWE-1427 | Microsoft Edge for iOS Spoofing Vulnerability |
| CVE-2026-81759 | 5.4 | — | Magepeople inc. | WpEvently | CWE-862 | WordPress WpEvently plugin <= 5.5.0 - Broken Access Control vulnerability |
| CVE-2026-5096 | 5.3 | — | wpeverest | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI | CWE-918 | Everest Forms <= 3.4.4 - Unauthenticated Server-Side Request Forgery via Uplo… |
| CVE-2026-15603 | 5.3 | — | morgan | morgan | CWE-117 | morgan vulnerable to Log Forging via unescaped Unicode line separators |
| CVE-2026-54766 | 5.3 | — | go-vikunja | vikunja | CWE-285 | Vikunja: Project duplication bypasses write-permission check on the target pa… |
| CVE-2026-55867 | 5.3 | — | Graylog2 | graylog2-server | CWE-639 | Graylog token revocation endpoint allows authenticated users to delete other … |
| CVE-2026-76649 | 5.3 | — | TP-Link System Inc. | TL-WR841N v14 | CWE-476 | Pre-Authentication NULL Pointer Dereference in UPnP SOAP Action Request Proce… |
| CVE-2026-76650 | 5.3 | — | TP-Link System Inc. | TL-WR841N v14 | CWE-476 | Pre-Authentication NULL Pointer Dereference in UPnP SOAP State Variable Query… |
| CVE-2026-76651 | 5.3 | — | TP-Link System Inc. | TL-WR841N v14 | CWE-120 | Pre-Authentication Multipart Boundary Buffer Overflow in HTTP Service in TP-L… |
| CVE-2026-78073 | 5.3 | — | mrvinoth.com | All Video Share extension for Joomla | CWE-79 | Joomla Extension - j2commerce.com - Reflected XSS attribute in All Video Shar… |
| CVE-2026-81777 | 5.3 | — | WPDeveloper | Essential Addons for Elementor | CWE-290 | WordPress Essential Addons for Elementor plugin <= 6.8.0 - Bypass vulnerabili… |
| CVE-2026-82220 | 5.3 | — | WPMU DEV | Forminator | CWE-294 | WordPress Forminator plugin <= 1.57.1 - Other vulnerability Type vulnerability |
| CVE-2026-82257 | 5.3 | — | sveltejs | kit | CWE-1321 | SvelteKit before 2.69.1 Prototype Pollution via File Input |
| CVE-2026-82267 | 5.3 | — | moghtech | komodo | CWE-862 | Komodo Resource Identifier Disclosure and Audit Log Pollution Before Permissi… |
| CVE-2026-82274 | 5.3 | — | twentyhq | twenty | CWE-601 | Twenty Open Redirect via OAuth Propagator Callback |
| CVE-2026-82276 | 5.3 | — | StarRocks | starrocks | CWE-306 | StarRocks Frontend REST Handlers Bypass the Base Class Authentication Gate |
| CVE-2026-81733 | 5.1 | — | WWBN | AVideo | CWE-352 | WWBN AVideo through 30.0 CSRF via myLiveControls.save.json.php |
| CVE-2026-82112 | 5.1 | — | houtini-ai | houtini-lm | CWE-22 | houtini-ai houtini-lm code_task_files index.ts path traversal |
| CVE-2026-55067 | 5.0 | — | go-vikunja | vikunja | CWE-639 | Vikunja: Authenticated cross-tenant kanban-bucket relocation via `project_vie… |
| CVE-2026-55425 | 5.0 | — | Graylog2 | graylog2-server | CWE-213 | Graylog: System Catalog titles endpoint can be used to retrieve values of pro… |
Results continue: ranks 401–496.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-08-28 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.