boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Friday, August 28, 2026 · all times UTC← 2026-08-27 · archive

Security Box Score — August 28, 2026

496 CVEs published, led by Linux (135).

496 CVEs published August 28, 2026: 49 critical, 184 high, 126 medium, 16 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 121 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 96 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1177334212——
KEV catalog size1685

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2023 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux16443959418197263711230.17.8.0016+815 ▲
google4022164270842960757760.37.5.0026+282 ▲
microsoft4771899145128345714287281.57.8.0044-187 ▼
red hat2236164225428732200.06.7.0029+94 ▲
apple44316598516578882.56.5.0029-123 ▼
freebsd324823673000.07.8.0016+32 ▲
canonical15421311135000.07.8.0020+8 ▲
suse72851481000.07.7.0038-1 ▼
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco46842139240561315.57.5.0044+31 ▲
ubiquiti2359362210335.19.1.0049-2 ▼
palo alto networks12371321121325.44.7.0020-2 ▼
netgear93200275000.04.3.0025+3 ▲
fortinet7307814128620.07.0.0050-7 ▼
vmware21959327210.58.3.0040-6 ▼
f50175930415.98.7.0057-8 ▼
sonicwall1214374017214.37.8.0024+10 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache159496102216164133320.47.5.0049+35 ▲
mozilla591866868500900.08.1.0030-12 ▼
gitlab2576218479422.65.3.0028+18 ▲
drupal1768107465411.55.9.0024-29 ▼
github5171790000.06.6.0043-1 ▼
docker290630000.07.2.0016+2 ▲
wordpress2513102240.08.8.3120-1 ▼
kubernetes010001000.02.4.0035-1 ▼
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle89022694841170519962840.27.8.0034-219 ▼
ibm3906191482861778610.27.6.0030+322 ▲
adobe1016065030024791930.57.8.0021-4 ▼
progress19611437100611.68.1.0037-14 ▼
solarwinds0231733010417.49.1.0058-15 ▼
veeam131961030100.08.6.0032+12 ▲
zohocorp4103520000.08.7.0140+1 ▲
atlassian3615001300.08.1.00340
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
siemens213722483000.07.3.0016+14 ▲
d-link163615597300.07.4.0157+8 ▲
synology42736153000.05.6.0025+4 ▲
rockwell automation12541740000.08.4.0024-16 ▼
schneider electric091620000.08.6.00370
abb070430000.07.2.0018-1 ▼
hikvision060420000.07.2.0040-5 ▼
mitsubishi electric050410000.07.2.00520
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring911709538616000.06.4.0022+91 ▲
dell711701190645210.67.2.0019+28 ▲
sourcecodester48168009276000.05.5.0029-1 ▼
nvidia521341688300000.07.8.0034+9 ▲
splunk110128647705110.86.5.0025+107 ▲
openclaw01110583914000.07.0.0026-44 ▼
zephyrproject521053335712000.06.4.0021+27 ▲
getgrav661041559282000.08.4.0032+29 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.995799.99.8
CVE-2026-34486.986299.97.5
CVE-2026-63077.877199.89.8
CVE-2026-60004.845599.79.8
CVE-2026-72898.792299.610.0
CVE-2026-18577.540799.08.2
CVE-2026-59310.458898.89.8
CVE-2026-18556.401698.68.2
CVE-2026-64638.312098.28.9
CVE-2026-66066.278698.09.5
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.7922KEV
CVE-2026-4836210.0.0431
CVE-2026-1918810.0.0193
CVE-2026-5823110.0.0171
CVE-2026-6983610.0.0155
CVE-2026-7619510.0.0147
CVE-2026-7619710.0.0147
CVE-2026-7329910.0.0121
CVE-2026-7367810.0.0114
CVE-2026-7755410.0.0099
Most disclosures (vendor)
VendorCVEs
linux1645
oracle890
google777
microsoft478
ibm425
red hat254
apache175
splunk110
adobe104
spring97
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco13
apple8
fortinet6
google6
ivanti5
oracle4
solarwinds4
adobe3
berriai3
Most-affected ecosystems
EcosystemAdvisories
Maven56
Packagist28
PyPI13
npm12
Go1
Fastest to KEV
CVEVendorDays
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20349Cisco0
CVE-2026-34486Apache Software Foundation0
CVE-2026-63077JetBrains0
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
CVE-2026-72898Metabase0
CVE-2026-8037Progress Software0
CVE-2026-64849mlflow1
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171745
CVE-2021-27102n/a2021-11-171745
CVE-2021-27101n/a2021-11-171745
CVE-2021-27103n/a2021-11-171745
CVE-2021-21017Adobe2021-11-171745
CVE-2021-28550Adobe2021-11-171745
CVE-2021-42013Apache Software Foundation2021-11-171745
CVE-2021-41773Apache Software Foundation2021-11-171745
CVE-2021-30858Apple2021-11-171745
CVE-2021-30860Apple2021-11-171745

Transactions

EXPLOIT PUBLISHED — axios: 8 CVEs (CVE-2026-42264, CVE-2026-44486, CVE-2026-44487, CVE-2026-44488, CVE-2026-44492, CVE-2026-44494, CVE-2026-44495, CVE-2026-44496). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2023-43900. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-43901. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-43902. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-2609 (MagnusSolution MagnusBilling). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-2610 (MagnusSolution MagnusBilling). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-43955 (Convertigo). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-0545 (mlflow/mlflow). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-10036 (speechbrain). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19092 (Unknown Tutor LMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-2614 (mlflow/mlflow). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-35397 (jupyter-server jupyter_server). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-38636. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-38638. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-44513 (huggingface diffusers). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-45736 (websockets ws). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-46625 (js-cookie). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-47117 (maziyarpanahi openmed). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48526 (jpadilla pyjwt). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48710 (Kludex starlette). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48779 (websockets ws). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-5241 (huggingface/transformers). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54293 (nltk). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-74899 (jahlives openssl_encrypt). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-75417. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76640 (Unitree Robotics G1 EDU). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76886 (Wireshark Foundation Wireshark). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76888 (Wireshark Foundation Wireshark). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-79804 (SililaWijesinghe Food Ordering System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-81203 (SourceCodester Simple Online Food Ordering System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-81560 (blackms aistack). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-81834 (RooCodeInc Roo-Code). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-81934 (Redis). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-9147 (scikit-hep uproot). Public exploit reference added.

DUE DATE PASSED — CVE-2026-21962 (Oracle Corporation Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in). CISA remediation deadline was August 27, 2026; still in catalog.

RESCORED — Zimbra Collaboration: 5 CVEs (CVE-2026-73571, CVE-2026-73573, CVE-2026-73574, CVE-2026-73575, CVE-2026-73576). CVSS rescored — before/after on each CVE page.

RESCORED — RooCodeInc Roo-Code: 3 CVEs (CVE-2026-81835, CVE-2026-81836, CVE-2026-81837). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2023-43901. CVSS 5.4 → 7.5 (NVD).

RESCORED — CVE-2023-43902. CVSS 8.8 → 9.8 (NVD).

RESCORED — CVE-2024-58377 (sparklemotion nokogiri). CVSS 9.3 → 6.8 (NVD).

RESCORED — CVE-2025-2609 (MagnusSolution MagnusBilling). CVSS 8.2 → 6.1 (NVD).

RESCORED — CVE-2025-2610 (MagnusSolution MagnusBilling). CVSS 7.6 → 5.4 (NVD).

RESCORED — CVE-2025-43955 (Convertigo). CVSS 2.2 → 6.8 (NVD).

RESCORED — CVE-2026-0545 (mlflow/mlflow). CVSS 9.1 → 9.8 (NVD).

RESCORED — CVE-2026-16782 (Autodesk 3ds Max). CVSS 5.3 → 7.8 (NVD).

RESCORED — CVE-2026-50768. CVSS 9.8 → 8.8 (NVD).

RESCORED — CVE-2026-67275 (Dell PowerProtect One). CVSS 5.3 → 6.5 (NVD).

RESCORED — CVE-2026-73626 (jupyterlab). CVSS 0 → 7.7 (NVD).

RESCORED — CVE-2026-74774 (Dell PowerProtect One). CVSS 5.9 → 7.5 (NVD).

RESCORED — CVE-2026-74802 (siyuan-note siyuan). CVSS 0 → 7.1 (NVD).

RESCORED — CVE-2026-74887 (jahlives openssl_encrypt). CVSS 9.3 → 6.3 (NVD).

RESCORED — CVE-2026-76886 (Wireshark Foundation Wireshark). CVSS 8.1 → 9.8 (NVD).

RESCORED — CVE-2026-76888 (Wireshark Foundation Wireshark). CVSS 3.1 → 7.5 (NVD).

RESCORED — CVE-2026-80200 (kimai). CVSS 0 → 5.3 (NVD).

RESCORED — CVE-2026-81845 (arben-adm mcp-sequential-thinking). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-81847 (MAA-AI MaaMCP). CVSS 5.1 → 2 (NVD).

ENRICHED — CVE-2023-36664. Received CVSS 7.8 and CPE data from NVD.

ENRICHED — CVE-2026-78195. Received CVSS 5.1 and CPE data from NVD.

Yesterday's Results

How to read these box scores · glossary

496 CVEs published. 25 box scores and 375 table rows below; the remaining 96 continue on page 2 — every CVE is listed, nothing truncated.

openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection th…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   A   L   N   N  U  H  H  L    8.3   .0174   75.8     —
AFFECTED
  Product  Versions     Fixed
  openNDS  unspecified  —
TIMELINE
  Apr 6   Reserved by CNA
  Aug 28  Published (CNA: mitre)
CWE-78 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Received
Green-Computing|NUMail - OS Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0150   72.0     —
AFFECTED
  Product  Versions  Fixed
  NUMail   all –     —
TIMELINE
  Aug 28  Reserved by CNA
  Aug 28  Published (CNA: twcert)
CWE-78 · CNA: twcert · CVSS v4.0 · 2 references · NVD status: Deferred
openNDS openNDS — In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authentic…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   A   L   L   N  U  H  H  L    7.6   .0085   55.1     —
AFFECTED
  Product  Versions     Fixed
  openNDS  unspecified  —
TIMELINE
  Apr 6   Reserved by CNA
  Aug 28  Published (CNA: mitre)
CWE-78 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Received
onedesigns One User Avatar | User Profile Picture — One User Avatar | User Profile Picture <= 2.5.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0050   40.8     —
AFFECTED
  Product                                 Versions     Fixed
  One User Avatar | User Profile Picture  unspecified  —
TIMELINE
  Aug 5   Reserved by CNA
  Aug 28  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
Synology Synology Chat Server — An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in ex…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   R  C  H  H  H    9.0   .0048   39.4     —
AFFECTED
  Product               Versions     Fixed
  Synology Chat Server  unspecified  —
TIMELINE
  Apr 14  Reserved by CNA
  Aug 28  Published (CNA: synology)
CWE-79 · CNA: synology · CVSS v3.1 · 1 reference · NVD status: Received
melograno Booking for Appointments and Events Calendar – Amelia — Booking for Appointments and Events Calendar <= 2.2 - Unauthenticated Stored Cross-Site Scripting via Customer Name Fields in Booking Submission
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0044   36.9     —
AFFECTED
  Product                                                Versions     Fixed
  Booking for Appointments and Events Calendar – Amelia  unspecified  —
TIMELINE
  Apr 14  Reserved by CNA
  Aug 28  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 11 references · NVD status: Deferred
themeum Tutor LMS – eLearning and online course solution — Tutor LMS <= 4.0.5 - Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  N    6.5   .0043   35.8     —
AFFECTED
  Product                                           Versions     Fixed
  Tutor LMS – eLearning and online course solution  unspecified  —
TIMELINE
  Jul 23  Reserved by CNA
  Aug 28  Published (CNA: Wordfence)
CWE-74 · CNA: Wordfence · CVSS v3.1 · 9 references · NVD status: Deferred
Tsuyoshi Saito SOY CMS — SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an a…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0042   34.8     —
AFFECTED
  Product  Versions     Fixed
  SOY CMS  unspecified  —
TIMELINE
  Aug 24  Reserved by CNA
  Aug 28  Published (CNA: jpcert)
CWE-502 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Deferred
tomdever wpForo Forum — wpForo Forum <= 2.4.17 - Unauthenticated SQL Injection via 'referer' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0041   34.1     —
AFFECTED
  Product       Versions     Fixed
  wpForo Forum  unspecified  —
TIMELINE
  Mar 29  Reserved by CNA
  Aug 28  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
Synology Synology Chat Server — A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 all…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  L  N  N    4.3   .0040   32.9     —
AFFECTED
  Product               Versions     Fixed
  Synology Chat Server  unspecified  —
TIMELINE
  May 25  Reserved by CNA
  Aug 28  Published (CNA: synology)
CWE-918 · CNA: synology · CVSS v3.1 · 1 reference · NVD status: Received
Unknown User Frontend — WP User Frontend < 4.3.10 - Editor+ PHP Object Injection via AI Form Builder
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0036   28.5     —
AFFECTED
  Product        Versions     Fixed
  User Frontend  unspecified  —
TIMELINE
  Jul 3   Reserved by CNA
  Aug 28  Published (CNA: WPScan)
CWE-502 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Deferred
wpmudev WPMU DEV Dashboard — WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0034   26.5     —
AFFECTED
  Product             Versions     Fixed
  WPMU DEV Dashboard  unspecified  —
TIMELINE
  Aug 19  Reserved by CNA
  Aug 28  Published (CNA: Wordfence)
CWE-347 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
wallabag android-app — The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because /a…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   P   H   H   L    8.8   .0033   25.1     —
AFFECTED
  Product      Versions     Fixed
  android-app  unspecified  —
TIMELINE
  Aug 28  Reserved by CNA
  Aug 28  Published (CNA: mitre)
CWE-79 · CNA: mitre · CVSS v4.0 · 6 references · NVD status: Received
Optimole <= 4.2.10 - Unauthenticated Stored Cross-Site Scripting via 'a' (above_fold_images) Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0031   23.2     —
AFFECTED
  Product                                                                                  Versions     Fixed
  Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 28  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 13 references · NVD status: Deferred
wpmudev Forminator Forms – Contact Form, Payment Form & Custom Form Builder — Forminator Forms <= 1.57.0.1 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0030   22.5     —
AFFECTED
  Product                                                              Versions     Fixed
  Forminator Forms – Contact Form, Payment Form & Custom Form Builder  unspecified  —
TIMELINE
  Jul 29  Reserved by CNA
  Aug 28  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 13 references · NVD status: Deferred
cozmoslabs TranslatePress – Translate Multilingual sites with AI Translation — TranslatePress <= 3.3.3 - Unauthenticated Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0030   22.5     —
AFFECTED
  Product                                                            Versions     Fixed
  TranslatePress – Translate Multilingual sites with AI Translation  unspecified  —
TIMELINE
  Aug 18  Reserved by CNA
  Aug 28  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 15 references · NVD status: Deferred
getpocket Pocket — Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM. JavaScript …
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0028   20.2     —
AFFECTED
  Product  Versions     Fixed
  Pocket   unspecified  —
TIMELINE
  Aug 28  Reserved by CNA
  Aug 28  Published (CNA: mitre)
CWE-79 · CNA: mitre · CVSS v4.0 · 1 reference · NVD status: Received
litespeedtech LiteSpeed Cache — LiteSpeed Cache <= 7.8.1 - Unauthenticated Stored Cross-Site Scripting via Comment Content
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0027   19.3     —
AFFECTED
  Product          Versions     Fixed
  LiteSpeed Cache  unspecified  —
TIMELINE
  Aug 5   Reserved by CNA
  Aug 28  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
wpmet ElementsKit Pro — ElementsKit Pro <= 4.10.1 - Unauthenticated Stored Cross-Site Scripting via 's' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  L  N    6.1   .0027   19.3     —
AFFECTED
  Product          Versions     Fixed
  ElementsKit Pro  unspecified  —
TIMELINE
  Mar 15  Reserved by CNA
  Aug 28  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
Synology Synology Chat Server — An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in ex…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   R  C  L  L  L    6.5   .0024   15.1     —
AFFECTED
  Product               Versions     Fixed
  Synology Chat Server  unspecified  —
TIMELINE
  May 26  Reserved by CNA
  Aug 28  Published (CNA: synology)
CWE-79 · CNA: synology · CVSS v3.1 · 1 reference · NVD status: Received
nextendweb Smart Slider 3 — Smart Slider 3 <= 3.5.1.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'slider' Block Attribute
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0024   14.2     —
AFFECTED
  Product         Versions     Fixed
  Smart Slider 3  unspecified  —
TIMELINE
  Jul 14  Reserved by CNA
  Aug 28  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 9 references · NVD status: Deferred
openNDS openNDS — A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated a…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   A   H   N   N  U  H  H  L    7.1   .0020    9.9     —
AFFECTED
  Product  Versions     Fixed
  openNDS  unspecified  —
TIMELINE
  Apr 6   Reserved by CNA
  Aug 28  Published (CNA: mitre)
CWE-122 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Received
litespeedtech LiteSpeed Cache — LiteSpeed Cache <= 7.7 - Authenticated (Author+) Stored Cross-Site Scripting via img Tag Attributes
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0019    8.3     —
AFFECTED
  Product          Versions     Fixed
  LiteSpeed Cache  unspecified  —
TIMELINE
  Feb 24  Reserved by CNA
  Aug 28  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 4 references · NVD status: Deferred
Linux Linux — net: airoha: fix foe_check_time allocation size
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0018    7.9     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    56b99327a451917f1c17f85fc33ea8293c08a9ee –  —
  Linux    6.19 –                                      6.18.40
TIMELINE
  Aug 26  Reserved by CNA
  Aug 28  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 3 references · NVD status: Received
Linux Linux — perf sched: Fix register_pid() overflow, strcpy, and BUG_ON
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   N  C  H  H  H    9.3   .0018    7.9     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    ec156764d424dd67283c2cd5e9f6f1b8388364ac –  —
  Linux    2.6.32 –                                    6.18.40
TIMELINE
  Aug 26  Reserved by CNA
  Aug 28  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 3 references · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-80640await7.9LinuxLinux—cxl/fwctl: Fix __fortify_panic
CVE-2026-80659await7.6LinuxLinux—mmc: vub300: defer reset until cmd_mutex is unlocked
CVE-2026-806067.87.4LinuxLinux—drm/xe/userptr: Hold notifier_lock for write on inject test path
CVE-2026-806657.17.4LinuxLinux—KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN
CVE-2026-80616await7.4LinuxLinux—ieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns()
CVE-2026-388195.37.4openNDSopenNDSCWE-401Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attac…
CVE-2026-806009.87.2LinuxLinux—batman-adv: dat: acquire ARP hw source only after skb realloc
CVE-2026-806309.87.2LinuxLinux—net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek be…
CVE-2026-806819.87.2LinuxLinux—vxlan: re-fetch eth header after route_shortcircuit()
CVE-2026-806039.17.2LinuxLinux—netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read
CVE-2026-806709.17.2LinuxLinux—perf tools: Use perf_env__get_cpu_topology() in machine__resolve()
CVE-2026-806018.87.2LinuxLinux—batman-adv: gw: acquire ethernet header only after skb realloc
CVE-2026-806048.87.2LinuxLinux—HID: core: Fix OOB read in hid_get_report for numbered reports
CVE-2026-805908.67.2LinuxLinux—inet: frags: strip GSO state from fragments before reassembly
CVE-2026-805938.47.2LinuxLinux—hwmon: (asus_atk0110) Check package count before accessing element
CVE-2026-805998.17.2LinuxLinux—batman-adv: dat: ensure accessible eth_hdr proto field
CVE-2026-806458.17.2LinuxLinux—rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc()
CVE-2026-805917.87.2LinuxLinux—f2fs: fix listxattr handling of corrupted xattr entries
CVE-2026-806197.87.2LinuxLinux—apparmor: fix potential UAF in aa_replace_profiles
CVE-2026-806227.87.2LinuxLinux—char: tlclk: fix use-after-free in tlclk_cleanup()
CVE-2026-806777.87.2LinuxLinux—driver core: use READ_ONCE() for dev->driver in dev_has_sync_state()
CVE-2026-806807.87.2LinuxLinux—i2c: amd-mp2: Unregister callback on adapter add failure
CVE-2026-806467.57.2LinuxLinux—ipv6: guard against possible NULL deref in __in6_dev_stats_get()
CVE-2026-806647.37.2LinuxLinux—netfilter: xt_nat: reject unsupported target families
CVE-2026-821236.57.2TangibleLoops & LogicCWE-79WordPress Loops & Logic - Reflected XSS
CVE-2026-80594await7.2LinuxLinux—Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing
CVE-2026-80595await7.2LinuxLinux—Input: ims-pcu - add response length checks
CVE-2026-80597await7.2LinuxLinux—mtd: maps: vmu-flash: fix NULL pointer dereference in initialization
CVE-2026-80605await7.2LinuxLinux—HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait()
CVE-2026-80626await7.2LinuxLinux—powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del
CVE-2026-80627await7.2LinuxLinux—MIPS: mm: Fix out-of-bounds write in maar_res_walk()
CVE-2026-80644await7.2LinuxLinux—ocfs2: don't BUG_ON an invalid journal dinode
CVE-2026-80647await7.2LinuxLinux—RDMA/hns: Fix warning in poll cq direct mode
CVE-2026-80652await7.2LinuxLinux—crypto: ccp - Treat zero-length cert chain as query for blob lengths
CVE-2026-80679await7.2LinuxLinux—s390/dasd: Fix potential NULL pointer dereference
CVE-2026-806099.86.8LinuxLinux—qede: fix out-of-bounds check for cqe->len_list[]
CVE-2026-806849.36.8LinuxLinux—KVM: s390: pci: Fix NULL dereference on AIBV allocation failure
CVE-2026-806358.86.8LinuxLinux—wifi: wcn36xx: fix OOB read from short trigger BA firmware response
CVE-2026-806788.46.8LinuxLinux—i2c: imx: Fix slave registration race and error handling
CVE-2026-805987.86.8LinuxLinux—ntfs3: fix out-of-bounds read in decompress_lznt
CVE-2026-806137.86.8LinuxLinux—veth: fix NAPI leak in XDP enable error path
CVE-2026-806497.86.8LinuxLinux—firmware: arm_scmi: Fix OOB in scmi_power_name_get()
CVE-2026-806827.86.8LinuxLinux—riscv/mm: use physical alignment for vmemmap_start_pfn
CVE-2026-806637.16.8LinuxLinux—tools/power/x86/intel-speed-select: Harden daemon pidfile open
CVE-2026-80618await6.8LinuxLinux—drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free
CVE-2026-80620await6.8LinuxLinux—Revert "PCI/MSI: Unmap MSI-X region on error"
CVE-2026-80660await6.8LinuxLinux—hwmon: (occ) unregister sysfs devices outside occ lock
CVE-2026-80669await6.8LinuxLinux—bpf: Disable xfrm_decode_session hook attachment
CVE-2026-80686await6.8LinuxLinux—mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE
CVE-2026-806158.26.7LinuxLinux—net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone
CVE-2026-80639await6.7LinuxLinux—cxl/test: Fix __fortify_panic
CVE-2026-738274.86.4Tsuyoshi SaitoSOY CalendarCWE-79SOY Calendar contains a cross-site scripting vulnerability. An arbitrary scri…
CVE-2026-778384.86.4Tsuyoshi SaitoSOY CalendarCWE-79SOY Calendar contains a cross-site scripting vulnerability. An arbitrary scri…
CVE-2026-782384.86.4Tsuyoshi SaitoSOY GalleryCWE-79SOY Gallery contains a cross-site scripting vulnerability. An arbitrary scrip…
CVE-2026-806949.86.3LinuxLinux—net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller
CVE-2026-805968.46.3LinuxLinux—Input: ims-pcu - only expose sysfs attributes on control interface
CVE-2026-806967.86.3LinuxLinux—hwmon: (ltc4282) Fix reading the minimum alarm voltage
CVE-2026-807007.86.3LinuxLinux—drm/vmwgfx: validate external BO copy bounds for both stride paths
CVE-2026-807027.86.3LinuxLinux—drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size
CVE-2026-806377.56.3LinuxLinux—netfilter: synproxy: fix unaligned memory access in timestamp adjustment
CVE-2026-806917.56.3LinuxLinux—scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE
CVE-2026-80602await6.3LinuxLinux—perf/x86/amd/lbr: Fix kernel address leakage
CVE-2026-80611await6.3LinuxLinux—ACPI: processor_idle: Mark LPI enter functions as __cpuidle
CVE-2026-80624await6.3LinuxLinux—mfd: cs42l43: Sanity check firmware size
CVE-2026-80629await6.3LinuxLinux—octeontx2-af: npc: Fix size of entry2cntr_map
CVE-2026-80636await6.3LinuxLinux—netfilter: conntrack: revert ct extension genid infrastructure
CVE-2026-80650await6.3LinuxLinux—media: atomisp: gc2235: fix UAF and memory leak
CVE-2026-80654await6.3LinuxLinux—soc: xilinx: Shutdown and free rx mailbox channel
CVE-2026-80667await6.3LinuxLinux—net/mlx5: LAG, MPESW, Fix missing complete() on devcom error
CVE-2026-80676await6.3LinuxLinux—Drivers: hv: vmbus: use generic driver_override infrastructure
CVE-2026-80689await6.3LinuxLinux—tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions
CVE-2026-80695await6.3LinuxLinux—hwmon: (sht3x) Fix unaligned accesses
CVE-2026-806838.86.1LinuxLinux—Bluetooth: SCO: give the socket its own sco_conn reference
CVE-2026-806538.46.1LinuxLinux—scsi: hisi_sas: Add slave_destroy interface for v3 hw
CVE-2026-806287.86.1LinuxLinux—ALSA: seq: oss: Serialize readq reset state with q->lock
CVE-2026-806617.86.1LinuxLinux—ufs: core: tracing: Do not dereference pointers in TP_printk()
CVE-2026-806147.56.1LinuxLinux—net: emac: Fix NULL pointer dereference in emac_probe
CVE-2026-806627.16.1LinuxLinux—cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size
CVE-2026-806757.16.1LinuxLinux—libbpf: Reject non-exclusive metadata maps in the signed loader
CVE-2026-806857.16.1LinuxLinux—mm/util: don't read __page_2 for order-1 folios in snapshot_page()
CVE-2026-125136.86.1UnknownShared FilesCWE-73Shared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path Trav…
CVE-2026-80592await6.1LinuxLinux—samples/damon/mtier: fail early if address range parameters are invalid
CVE-2026-80607await6.1LinuxLinux—tracing/probes: Remove WARN_ON_ONCE from parse_btf_arg
CVE-2026-80621await6.1LinuxLinux—PCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when no RAS…
CVE-2026-80623await6.1LinuxLinux—coresight: ete: Always save state on power down
CVE-2026-80643await6.1LinuxLinux—EDAC/igen6: Fix call trace due to missing release()
CVE-2026-80648await6.1LinuxLinux—pinctrl: spacemit: fix NULL check in spacemit_pin_set_config
CVE-2026-80658await6.1LinuxLinux—drm/rockchip: dw_dp: Fix null-ptr-deref in dw_dp_remove()
CVE-2026-80666await6.1LinuxLinux—Bluetooth: sco: Fix a race condition in sco_sock_timeout()
CVE-2026-80687await6.1LinuxLinux—iommufd/viommu: Release the igroup lock on the vdevice_size error path
CVE-2026-80688await6.1LinuxLinux—riscv: drop __init from vec_check_unaligned_access_speed_all_cpus
CVE-2026-80701await6.1LinuxLinux—drm/vmwgfx: enforce cursor size limits for MOB cursors
CVE-2026-807149.85.9LinuxLinux—ipvs: do not propagate one-packet flag to synced conns
CVE-2026-807067.85.9LinuxLinux—can: softing: fw_parse(): validate firmware record spans
CVE-2026-807167.85.9LinuxLinux—ALSA: pcm: wake linked drain waiters on unlink
CVE-2026-807187.85.9LinuxLinux—mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()
CVE-2026-807077.55.9LinuxLinux—can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer
CVE-2026-807177.55.9LinuxLinux—sctp: validate Adaptation Indication parameter length
CVE-2026-80708await5.9LinuxLinux—s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey()
CVE-2026-807228.85.5LinuxLinux—wifi: mac80211: validate individual TWT params before driver setup
CVE-2026-807097.85.5LinuxLinux—s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs
CVE-2026-80715await5.5LinuxLinux—igc: remove napi_synchronize() in igc_down()
CVE-2026-80704await5.4LinuxLinux—drm/amd/display: use proper context for logging
CVE-2026-807238.45.1LinuxLinux—of: reserved_mem: prevent OOB when too many dynamic regions are defined
CVE-2026-807107.85.1LinuxLinux—s390/dasd: Fix undersized format-check buffer
CVE-2026-190847.55.1Unknownshared-files-proCWE-73Shared Files < 1.7.70 - Unauthenticated Arbitrary File Read
CVE-2026-166546.45.1themefusionAvada (Fusion) BuilderCWE-79Avada (Fusion) Builder <= 3.15.6 - Authenticated (Contributor+) Stored Cross-…
CVE-2026-145675.35.1UnknownUser FrontendCWE-200WP User Frontend < 4.3.10 - Unauthenticated User Email and Phone Disclosure v…
CVE-2026-797065.35.1UnknownBreeze CacheCWE-434Breeze Cache < 2.5.13 - Unauthenticated File Creation via Cache Path Traversal
CVE-2026-80703await5.1LinuxLinux—drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE
CVE-2026-80711await5.1LinuxLinux—power: supply: max17040: handle missing status supplier
CVE-2026-806129.85.0LinuxLinux—net: lwtunnel: Drop skb metadata before LWT encapsulation
CVE-2026-806349.85.0LinuxLinux—netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag
CVE-2026-806689.85.0LinuxLinux—netfilter: nf_conntrack_expect: use conntrack GC to reap expectations
CVE-2026-806739.85.0LinuxLinux—ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find()
CVE-2026-806749.85.0LinuxLinux—ntfs: validate resident attribute lists and harden the validator
CVE-2026-806939.35.0LinuxLinux—idpf: bound interrupt-vector register fill to the allocated array
CVE-2026-806088.85.0LinuxLinux—accel/amdxdna: Fix iommu domain lifetime race during device removal
CVE-2026-806338.85.0LinuxLinux—iommufd: Take dma_resv lock before dma_buf_unpin() in release path
CVE-2026-806388.85.0LinuxLinux—ocfs2: fix out-of-bounds write in ocfs2_remove_refcount_extent
CVE-2026-806728.85.0LinuxLinux—ntfs: fix u16 truncation of restart-area length check
CVE-2026-806928.85.0LinuxLinux—Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks
CVE-2026-806567.85.0LinuxLinux—hfsplus: Add a sanity check for btree node size
CVE-2026-806317.55.0LinuxLinux—btrfs: lzo: reject compressed segment that overflows the compressed input
CVE-2026-80610await5.0LinuxLinux—net: enetc: fix potential divide-by-zero when num_vsi is zero
CVE-2026-80625await5.0LinuxLinux—RDMA/hns: Fix memory leak of bonding resources
CVE-2026-80632await5.0LinuxLinux—wifi: mt76: mt7996: Fix NULL pointer dereference in mt7996_init_tx_queues()
CVE-2026-80641await5.0LinuxLinux—wifi: wlcore: enable the right set of ciphers
CVE-2026-80642await5.0LinuxLinux—liveupdate: Reference count incoming FLB data
CVE-2026-80651await5.0LinuxLinux—crypto: ccp/sev-dev-tsm - bail out early when pdev->bus is NULL
CVE-2026-80655await5.0LinuxLinux—soc: xilinx: Fix race condition in event registration
CVE-2026-80657await5.0LinuxLinux—accel/amdxdna: Guard management mailbox channel cleanup against NULL pointer
CVE-2026-80690await5.0LinuxLinux—scsi: ufs: core: Initialize hba->rpmbs list in ufshcd
CVE-2026-80697await5.0LinuxLinux—erofs: ensure valid f_path for page cache sharing
CVE-2026-80698await5.0LinuxLinux—dmaengine: idxd: fix double free of wq, engine, and group structs
CVE-2026-80699await5.0LinuxLinux—KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context
CVE-2026-807218.84.9LinuxLinux—Bluetooth: ISO: ensure no dangling hcon references in iso_conn
CVE-2026-807248.84.9LinuxLinux—ptp: vmclock: prevent read-only mappings from becoming writable
CVE-2026-807128.44.9LinuxLinux—spi: spi-qpic-snand: write the feature value before executing SET_FEATURE
CVE-2026-807207.54.9LinuxLinux—iomap: add a separate bio_set for iomap_split_ioend
CVE-2026-194238.14.2UnknownUltimate MemberCWE-269Ultimate Member 2.6.7 - 2.12.1 - Unauthenticated Privilege Escalation via Rol…
CVE-2026-820816.44.2wallabagwallabagCWE-918wallabag 2 through 2.6.14 allows SSRF because a crafted title or content fiel…
CVE-2026-125145.34.2UnknownShared FilesCWE-862Shared Files < 1.7.70 - Unauthenticated Limited File Upload
CVE-2026-777015.34.2UnknownWCFM MarketplaceCWE-862WCFM Marketplace < 3.8.2 - Unauthenticated Refund Request Creation on Guest O…
CVE-2026-807138.44.0LinuxLinux—io_uring: preserve task restrictions across exec
CVE-2026-80705await4.0LinuxLinux—drm/amd/display: check if dml21_add_phantom_plane() is successful
CVE-2026-80719await4.0LinuxLinux—mm: mglru: fix stale batch updates after memcg reparenting
CVE-2026-799967.23.8UnknownUser Registration & MembershipCWE-269User Registration & Membership < 5.2.6 - Authenticated Privilege Escalation v…
CVE-2026-799954.33.8UnknownUser Registration & MembershipCWE-639User Registration & Membership < 5.2.5 - Subscriber+ Pending Email Change Can…
CVE-2026-796152.73.8UnknownQuiz and Survey Master (QSM)CWE-639Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Question Bank and A…
CVE-2026-5474510.0—kubeflowpipelinesCWE-284Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipel…
CVE-2026-8222210.0—Liquid Web / StellarWPGiveWPCWE-502WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
CVE-2026-185279.9—IBMAdministration Runtime Expert for iCWE-384IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gainin…
CVE-2026-192959.9—IBMLangflow OSSCWE-95Langflow is affected by multiple remote code execution vulnerabilities due to…
CVE-2026-555659.9—yamcsyamcsCWE-94Yamcs: Authenticated remote code execution via unescaped StreamSQL `LIKE` pat…
CVE-2026-556349.9—pimcorepimcoreCWE-89Pimcore: Remote Code Execution via DataObject Class-Definition Field Name
CVE-2026-192869.8—IBMLangflow OSSCWE-94Langflow is affected by multiple remote code execution vulnerabilities due to…
CVE-2026-377519.8—n/an/aCWE-78An OS command injection vulnerability in the killSessionSync function (lib/ag…
CVE-2026-555599.8—yamcsyamcsCWE-94Yamcs: Remote Code Execution via instance-template argument YAML injection (c…
CVE-2026-823299.8—jfrogartifactoryCWE-287Potential authentication bypass leading to administrative access in Artifactory
CVE-2026-547549.6—klever-ioklever-goCWE-191Klever-Go: Marketplace settlement mints KLV when referral % + royalty % excee…
CVE-2026-547559.6—klever-ioklever-goCWE-190Klever-Go: Integer overflow in split-royalty validation enables unbounded min…
CVE-2026-820789.4—PaperCutPaperCut MF/NGCWE-470PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector
CVE-2026-822449.4—budibaseserverCWE-94Budibase before 3.41.3 Remote Code Execution via Plugin eval()
CVE-2026-550689.3—free5gcfree5gcCWE-20free5GC: NRF nnrf-nfm lacks NF Profile input validation — enables NF Registra…
CVE-2026-552209.3—pimcorepimcoreCWE-502Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserializ…
CVE-2026-553789.3—shriyanssjs-reconCWE-78JS Recon: Command injection in PR Branch Checker workflow via untrusted pull …
CVE-2026-822669.3—redpanda-dataredpandaCWE-306Redpanda Admin API Unauthenticated Superuser Access via Default Configuration
CVE-2026-822779.3—argoprojargo-rolloutsCWE-306Argo Rollouts Dashboard Unauthenticated Mutating Operations
CVE-2026-36279.1—IBMConcert—Multiple Vulnerabilities in IBM Concert Software
CVE-2026-189189.1—Eclipse FoundationEclipse LyoCWE-863OAuth 1.0 session-fixation chain via unauthenticated provisional-consumer reg…
CVE-2026-420079.1—Open-Xchange GmbHOX Dovecot ProCWE-416An attacker that has valid credentials can use a Sieve script with the edithe…
CVE-2026-552479.1—ploneplone.app.eventCWE-400plone.app.event: Denial of service via iCalendar import
CVE-2026-552489.1—ploneplone.app.portletsCWE-400plone.app.portlets: Denial of service via RSS feed portlet
CVE-2026-555119.1—yamcsyamcsCWE-94Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injecti…
CVE-2026-822819.1—CinnamonkotaemonCWE-639Kotaemon Missing Ownership Check in Conversation Functions
CVE-2026-820219.0—NousResearchhermes-agentCWE-494Hermes Agent 0.18.2 < 0.19.0 MCP Catalog Supply Chain RCE via Mutable Branch …
CVE-2026-137618.8—PegasystemsPega InfinityCWE-606Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper valid…
CVE-2026-187298.8—IBMLangflow OSSCWE-94Langflow is affected by multiple remote code execution vulnerabilities due to…
CVE-2026-554858.8—piccolo-ormpiccolo_adminCWE-200Piccolo Admin: Privilege escalation - admin to superuser via session-token di…
CVE-2026-555098.8—mar10wsgidavCWE-89WsgiDAV: Blind SQL injection in the MySQL provider
CVE-2026-555218.8—yamcsyamcsCWE-862Yamcs : Multiple Missing Function Level Access Control vulnerabilities in Yam…
CVE-2026-729848.8—MicrosoftMicrosoft Edge (Chromium-based)CWE-843Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-815788.8—PaperCutPaperCut MF/NGCWE-305PaperCut MF/NG: Authentication Bypass
CVE-2026-822828.8—runatlantisatlantisCWE-306Atlantis GitHub App Setup Endpoint Returns App Credentials to Unauthenticated…
CVE-2026-822858.8—dataelementbishengCWE-918BISHENG Unauthenticated Server-Side Request Forgery via Workflow Report Callback
CVE-2026-822868.8—BuilderIOgpt-crawlerCWE-22gpt-crawler Arbitrary File Write via outputFileName Parameter
CVE-2026-194128.7—CP PlusCP-XR-DE21-S RouterCWE-798Hardcoded Credentials Vulnerability in CP Plus CP-XR-DE21-S Router
CVE-2026-552458.7—maximhqbifrostCWE-918Bifrost: SSRF deny-list incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64…
CVE-2026-557638.7—klever-ioklever-goCWE-841Klever-Go: Percentage-transfer royalty skips the source debit at exactly-100%…
CVE-2026-557648.7—klever-ioklever-goCWE-190Klever-Go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxS…
CVE-2026-751188.7—TP-Link Systems Inc.TL-MR100 v3.20CWE-121http_gdpr_decrypt Pre-Authentication Stack-Based Buffer Overflow
CVE-2026-751248.7—PLANET Technology Corp.PLANET GS-4210-16P2SCWE-120PLANET GS-4210-16P2S Memory Corruption via dispatcher.cgi _readHttpParam
CVE-2026-780728.7—Jefferson49Sexy Polling Reloaded extension for JoomlaCWE-89Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling R…
CVE-2026-815178.7—MongoDBBI ConnectorCWE-248MongoDB Connector for BI Improper Error Handling of Log Write Failures May Ca…
CVE-2026-815188.7—MongoDBBI ConnectorCWE-295BI Connector Optional Client Certificate Verification Allows Unauthenticated …
CVE-2026-815208.7—MongoDBBI ConnectorCWE-1088MongoDB Connector for BI Unbounded Authentication Negotiation Leading to Conn…
CVE-2026-815328.7—MongoDBBI Connector ODBC DriverCWE-121BI Connector ODBC Driver Improper Bounds Checking on Cursor Name Leading to M…
CVE-2026-818498.7—amazonamazon-ssm-agentCWE-23Path traversal in the aws:downloadContent plugin in amazon-ssm-agent
CVE-2026-822478.7—GitoxideLabsgitoxideCWE-522gitoxide before 0.37.1 HTTP Basic credential leak via URL parsing
CVE-2026-822518.7—GitoxideLabsgitoxideCWE-22gitoxide before 0.52.1 Path Traversal via Submodule Name
CVE-2026-822528.7—GitoxideLabsgitoxideCWE-59gitoxide before 0.52.1 Repository Boundary Violation via symlinked .gitmodules
CVE-2026-822538.7—GitoxideLabsgitoxideCWE-22gitoxide before 0.82.0 Path Traversal via Submodule Name Validation Bypass
CVE-2026-822548.7—GitoxideLabsgitoxideCWE-248gitoxide before 0.69.0 Denial of Service via gix-pack
CVE-2026-822598.7—sveltejskitCWE-502SvelteKit 2.49.0 before 2.53.3 Denial of Service via form
CVE-2026-822608.7—sveltejskitCWE-400SvelteKit before 2.52.2 Memory Exhaustion via Remote Form Deserialization
CVE-2026-822618.7—sveltejskitCWE-400SvelteKit before 2.52.2 CPU Exhaustion via Remote Form Deserialization
CVE-2026-822688.7—QwenLMQwen-AgentCWE-918Qwen-Agent Server-Side Request Forgery via Caller-Supplied Document URL
CVE-2026-822708.7—Portkey-AIgatewayCWE-918Portkey AI Gateway Server-Side Request Forgery via /v1/proxy/*
CVE-2026-822758.7—QwenLMQwen-AgentCWE-22Qwen-Agent Arbitrary File Read via Caller-Supplied Document Path
CVE-2026-822788.7—dataelementbishengCWE-94BISHENG Authenticated Arbitrary Python Code Execution via Workflow run_once
CVE-2026-822888.7—AUTOMATIC1111stable-diffusion-webuiCWE-522Stable Diffusion WebUI Credential Disclosure via /sdapi/v1/cmd-flags
CVE-2026-558488.6—mapfishmapfish-printCWE-611mapfish-print: XXE on MapFish Print allows reading arbitrary files of certain…
CVE-2026-561008.6—SpringBladeSpringBladeCWE-862SpringBlade 2.7.3 < 5.0.0 Privilege Escalation via Exposed Feign Endpoint
CVE-2026-751218.6—PLANET Technology Corp.PLANET GS-4210-16P2SCWE-78PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_vlan_membership…
CVE-2026-751228.6—PLANET Technology Corp.PLANET GS-4210-16P2SCWE-78PLANET GS-4210-16P2S Command Injection via httpuploadcert.cgi
CVE-2026-751238.6—PLANET Technology Corp.PLANET GS-4210-16P2SCWE-78PLANET GS-4210-16P2S Command Injection via dispatcher.cgi web_smtp_test_post
CVE-2026-820178.6—IGELIGEL OS 12CWE-345IGEL OS 12 / 11 Boot Registry Parameter Injection via Unsigned Configuration …
CVE-2026-822398.6—budibaseserverCWE-862Budibase before 3.41.3 Authorization Bypass via datasources/query
CVE-2026-822408.6—budibaseserverCWE-862Budibase before 3.41.3 Privilege Escalation via User Update API
CVE-2026-822698.6—gophishgophishCWE-288Gophish Account Lockout and Forced Password Change Bypassable via API Key
CVE-2026-822838.6—VoltAgentvoltagentCWE-639VoltAgent Memory API Handlers Missing Ownership Checks
CVE-2026-822848.6—QuivrHQquivrCWE-639Quivr Chat Endpoints Missing Ownership Validation
CVE-2026-822878.6—rybbit-iorybbitCWE-942Rybbit Reflects Any Origin in CORS Responses While Allowing Credentials
CVE-2026-551088.5—kubevelakubevelaCWE-59KubeVela Terraform remote loader DoS via unbounded file read
CVE-2026-754868.5—snyksweater-combCWE-78Synk Sweater Comb < 3.8.8 Command Injection via .vervet.yaml Branch Name
CVE-2026-775868.5—MongoDBBI ConnectorCWE-89MongoDB Connector for BI Unescaped Object Names in Generated SHOW CREATE Output
CVE-2026-822278.5—VillaThemeWPBulkyCWE-89WordPress WPBulky plugin <= 1.2.2 - SQL Injection vulnerability
CVE-2026-822348.4—siyuan-notesiyuanCWE-918SiYuan before v3.8.1 SSRF via DNS-Rebinding TOCTOU
CVE-2026-814908.3—MongoDBBI ConnectorCWE-476MongoDB Connector for BI Improper Error Handling During Schema Sampling May C…
CVE-2026-822428.3—budibaseserverCWE-862Budibase before 3.41.3 Cross-Application Resource Injection via Missing Autho…
CVE-2026-822438.3—budibaseserverCWE-918Budibase Server before 3.41.3 SSRF with Credential Leakage
CVE-2026-822898.3—coderamp-labsgitingestCWE-918Gitingest Prefix-Based Git Host Check Enables Request Forgery and Token Discl…
CVE-2026-188918.2—IBMLangflow OSSCWE-287Langflow is affected by multiple authentication bypass, path traversal, autho…
CVE-2026-189048.2—IBMLangflow OSSCWE-639Langflow is affected by multiple authentication bypass, path traversal, autho…
CVE-2026-822358.2—filebrowserfilebrowserCWE-400filebrowser through 2.63.23 Denial of Service via named pipes
CVE-2026-822628.2—logto-iologtoCWE-918Logto Server-Side Request Forgery via webhook test endpoint
CVE-2026-822638.2—logto-iologtoCWE-918Logto Server-Side Request Forgery via OIDC SSO Connector Issuer URL
CVE-2026-509798.1—n/an/aCWE-77A command injection vulnerability in the 'advanced/curl' component of Osbil T…
CVE-2026-550658.1—go-vikunjavikunjaCWE-285Vikunja: Improper Authorization and Authorization Bypass Through User-Control…
CVE-2026-822918.1—heyformheyformCWE-942HeyForm Reflects Any Origin in CORS Responses While Allowing Credentials
CVE-2026-820207.6—NousResearchhermes-agentCWE-552Hermes Agent 0.16.0 < 0.17.0 Credential Store Overwrite via File-Write Tool
CVE-2026-822557.6—GitoxideLabsgitoxideCWE-522gitoxide 0.25.4 HTTP Credential Leak via Redirect
CVE-2026-172037.5—IBMAdministration Runtime Expert for iCWE-287IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gainin…
CVE-2026-188997.5—IBMLangflow OSSCWE-22Langflow is affected by multiple authentication bypass, path traversal, autho…
CVE-2026-278527.5—Open-Xchange GmbHOX Dovecot ProCWE-400An attacker that can send mail to a user can craft a message whose headers co…
CVE-2026-336057.5—Open-Xchange GmbHOX Dovecot ProCWE-400An unauthenticated attacker can crash the ManageSieve login process by sendin…
CVE-2026-372377.5—n/an/aCWE-400vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of …
CVE-2026-377367.5—n/an/aCWE-770An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1…
CVE-2026-386367.5—n/an/aCWE-400An issue in the seekdir() function (/dirent/mod.rs) of relibc commit 61f42d a…
CVE-2026-386387.5—n/an/aCWE-400An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d a…
CVE-2026-423917.5—Open-Xchange GmbHOX Dovecot ProCWE-400An unauthenticated attacker can send an IMAP ID command with a very large num…
CVE-2026-547887.5—DataDogdd-trace-rsCWE-770dd-trace-rs: Unbounded W3C tracestate parsing may lead to DoS
CVE-2026-552157.5—mariadb-corporationmariadb-connector-nodejsCWE-295MariaDB Connector/Node.js: Connector leaks the cleartext password to an MitM …
CVE-2026-554847.5—guno1928alos-httpCWE-248ALOS HTTP: Unauthenticated remote DoS: malformed path starting with "?" trigg…
CVE-2026-555527.5—yamcsyamcsCWE-22Yamcs: Unauthenticated Directory Traversal
CVE-2026-555847.5—phpsysinfophpsysinfoCWE-290phpSysInfo: IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / C…
CVE-2026-557847.5—free5gcfree5gcCWE-362free5GC AUSF authentication contexts can be overwritten by concurrent request…
CVE-2026-558417.5—Graylog2graylog2-serverCWE-138Graylog: Fortigate syslog message parser can be exploited to modify or delete…
CVE-2026-568547.5—golang.org/x/cryptogolang.org/x/crypto/sshCWE-863Source-address critical option not enforced for non-public-key auth callbacks…
CVE-2026-770377.5—multermulterCWE-400multer vulnerable to Denial of Service via file descriptor leak on aborted up…
CVE-2026-770787.5—multermulterCWE-248multer vulnerable to Denial of Service via crafted multipart field names
CVE-2026-780717.5—digital-peak.comDP Calendar extension for JoomlaCWE-79Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in…
CVE-2026-812857.5—WPMU DEVSmush Image Compression and OptimizationCWE-770WordPress Smush Image Compression and Optimization plugin <= 4.2.0 - Denial o…
CVE-2026-817677.5—yalla ya!Simple PaymentCWE-862WordPress Simple Payment plugin <= 2.5.2 - Broken Access Control vulnerability
CVE-2026-823337.5—multermulterCWE-400multer vulnerable to Denial of Service via oversized array index in field names
CVE-2026-400187.4—Open-Xchange GmbHOX Dovecot ProCWE-89None None None No publicly available exploits are known.
CVE-2026-732087.4—Open-Xchange GmbHOX Dovecot ProCWE-287An attacker that holds a token intended for a different purpose can authentic…
CVE-2026-810197.4—wolfSSL Inc.wolfProviderCWE-323wolfProvider reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record
CVE-2026-810207.4—wolfSSL Inc.wolfEngineCWE-323wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record
CVE-2026-59347.2—WP MediaWP RocketCWE-79WP Rocket <= 3.21.0.1 - Unauthenticated Stored Cross-Site Scripting via Pictu…
CVE-2026-61767.2—ivoleCustomer Reviews for WooCommerceCWE-79Customer Reviews for WooCommerce <= 5.106.0 - Unauthenticated Stored Cross-Si…
CVE-2026-817577.2—Rank Math SEORank Math SEOCWE-502WordPress Rank Math SEO plugin <= 1.0.276 - Remote Code Execution (RCE) vulne…
CVE-2026-822457.2—budibaseserverCWE-862Budibase before 3.41.3 Missing Authorization License Management
CVE-2026-822797.2—hyperdxiohyperdxCWE-862HyperDX Team Management Operations Missing Role-Based Access Control
CVE-2026-550667.1—go-vikunjavikunjaCWE-639Vikunja: Cross-tenant IDOR in kanban move-task endpoint via unauthorized body…
CVE-2026-555207.1—scrapyprotegoCWE-400Protego: Exponential backtracking ReDoS in robots.txt URL wildcard matching
CVE-2026-556737.1—powsyblpowsybl-coreCWE-78PowSyBl: Command Injection in LocalCommandExecutor-s
CVE-2026-779397.1—flextypeflextypeCWE-94Flextype CMS 1.0.0-dev RCE via POST /api/v1/query Endpoint
CVE-2026-817607.1—CrocoblockJetEngineCWE-79WordPress JetEngine plugin <= 3.8.14.2 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-822417.1—budibaseserverCWE-918Budibase backend-core SSRF via incomplete default blacklist
CVE-2026-822467.1—budibaseserverCWE-918Budibase Server before 3.41.3 SSRF via Query Import
CVE-2026-822507.1—GitoxideLabsgitoxideCWE-191gitoxide gix-packetline before 0.21.5 Denial of Service
CVE-2026-822717.1—SciPhi-AIR2RCWE-639R2R Missing Ownership Check Allows Modifying Other Users' Conversations
CVE-2026-822727.1—immich-appimmichCWE-863Immich Locked Assets Remain Readable Through Albums and Shared Links
CVE-2026-822737.1—mastra-aimastraCWE-862Mastra Memory API Thread Ownership Check Is a No-op When mapUserToResourceId …
CVE-2026-822807.1—QuivrHQquivrCWE-639Quivr Prompt Endpoints Missing Ownership Validation
CVE-2026-168217.0—IBMAIXCWE-134Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-556786.9—Basekick-LabsarcCWE-284Arc: Unauthenticated cluster node admission when `cluster.shared_secret` is u…
CVE-2026-751256.9—PLANET Technology Corp.PLANET GS-4210-16P2SCWE-476PLANET GS-4210-16P2S Null Pointer Dereference DoS via dispatcher.cgi web_poe_…
CVE-2026-751266.9—PLANET Technology Corp.PLANET GS-4210-16P2SCWE-121PLANET GS-4210-16P2S Stack Buffer Overflow via dispatcher.cgi Standard Handlers
CVE-2026-767986.9—MongoDBBI Connector Transition Readiness ReportCWE-79MongoSQL Transition Readiness Tool Improper Output Encoding in Generated HTML…
CVE-2026-772176.9—PLANET Technology Corp.PLANET GS-4210-16P2SCWE-121PLANET GS-4210-16P2S Stack Buffer Overflow and NULL Pointer Dereference via d…
CVE-2026-772186.9—PLANET Technology Corp.PLANET GS-4210-16P2SCWE-121PLANET GS-4210-16P2S Stack Buffer Overflow via dispatcher.cgi Credential Hand…
CVE-2026-780706.9—digital-peak.comDP Calendar extension for JoomlaCWE-89Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL inj…
CVE-2026-817326.9—WWBNAVideoCWE-200WWBN AVideo through 30.0 Information Disclosure via report4.json.php
CVE-2026-822336.9—siyuan-notesiyuanCWE-22SiYuan before v3.8.1 Path Traversal via asset.upload
CVE-2026-822566.9—sveltejskitCWE-400SvelteKit before 2.69.1 Denial of Service via Remote Form
CVE-2026-822656.9—openzipkinzipkinCWE-306Zipkin Unauthenticated Spring Boot Actuator Endpoints Exposure
CVE-2026-820186.8—IGELIGEL OS 12CWE-636IGEL OS 12 / 11 Secure Boot Bypass via Unsigned igel.conf File
CVE-2026-821816.8—Le-yanMedical Practice Management SystemCWE-598Le-yan|Medical Practice Management System - Sensitive Data in URL
CVE-2026-555696.6—aquaprojaquaCWE-22aqua: Archive extraction in aqua follows attacker-planted symlinks, allowing …
CVE-2026-137346.5—zephyrprojectzephyrCWE-294Zephyr WireGuard mutates peer state before anti-replay check, enabling captur…
CVE-2026-400146.5—Open-Xchange GmbHOX Dovecot ProCWE-400An attacker that can send mail to a user can craft a message header that make…
CVE-2026-400176.5—Open-Xchange GmbHOX Dovecot ProCWE-400An attacker that can send mail to a user can craft a message header whose val…
CVE-2026-526876.5—Open-Xchange GmbHOX Dovecot ProCWE-400An attacker that has valid credentials can select a compression algorithm for…
CVE-2026-555456.5—yamcsyamcsCWE-862Yamcs: WebSocket subscription handlers omit the privilege checks their REST s…
CVE-2026-555496.5—yamcsyamcsCWE-79Yamcs: Reflected XSS in the URL of the Authorize Endpoint
CVE-2026-558556.5—mariadb-corporationmariadb-connector-nodejsCWE-89MariaDB Connector/Node.js: Possible SQL injection in Buffer parameter escapin…
CVE-2026-663246.5—MicrosoftMicrosoft Edge (Chromium-based)CWE-73Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-732096.5—Open-Xchange GmbHOX Dovecot ProCWE-674An attacker that has valid credentials can send crafted compressed data that …
CVE-2026-813416.5—wolfSSL Inc.wolfEngineCWE-323wolfEngine reuses the AES-CCM nonce on TLS 1.2 / DTLS 1.2 records
CVE-2026-823066.5—StarRocksstarrocksCWE-200StarRocks Query Detail Endpoint Returns Every User's Query History
CVE-2026-34236.4—smubEnvira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & MoreCWE-79Envira Gallery <= 1.12.4 - Authenticated (Author+) Stored Cross-Site Scriptin…
CVE-2026-55106.4—stellarwpGiveWP – Donation Plugin and Fundraising PlatformCWE-79GiveWP <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting v…
CVE-2026-61286.4—servmaskAll-in-One WP Migration Unlimited ExtensionCWE-79All-in-One WP Migration Unlimited Extension <= 2.84 - Authenticated (Subscrib…
CVE-2026-192946.4—IBMLangflow OSSCWE-639Langflow is affected by multiple authentication bypass, path traversal, autho…
CVE-2026-547466.4—hatchet-devhatchetCWE-639Hatchet: Cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC…
CVE-2026-36866.2—IBMCloud Pak for Data SystemCWE-770Vulnerabilities exists in IBM Cloud Pak for Data System
CVE-2026-58006.1—Dayneks Software Industry and Trade Inc.E-Commerce PlatformCWE-79Reflected XSS in Dayneks Software's E-Commerce Platform
CVE-2026-59536.1—Ceviz Informatics Inc.Web DesignCWE-79Reflected XSS in Ceviz Informatics's Web Design
CVE-2026-377106.1—n/an/aCWE-79Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote attacke…
CVE-2026-822646.1—gilbertchenduplicacyCWE-22Duplicacy Path Traversal during Restore via Unsanitized Snapshot Paths
CVE-2026-823246.1—Red HatRed Hat Enterprise Linux 6CWE-125Gimp: heap out-of-bounds reads in iff/ilbm loader from ham row size mismatch …
CVE-2026-823286.1—Red HatRed Hat Enterprise Linux 6CWE-125Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette…
CVE-2026-823306.1—Red HatRed Hat Enterprise Linux 6CWE-125Gimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing b…
CVE-2026-823436.1—Red HatRed Hat Enterprise Linux 6CWE-120Gimp: heap out-of-bounds read and stack out-of-bounds access in psd loader fr…
CVE-2026-815336.0—MongoDBBI Connector ODBC DriverCWE-121MongoDB BI Connector ODBC Driver Memory-Safety Issue When Parsing Oversized L…
CVE-2026-822486.0—GitoxideLabsgitoxideCWE-59gitoxide before 0.33.0 Path Traversal via symlink following
CVE-2026-822906.0—ChainlitchainlitCWE-639Chainlit Feedback Endpoints Missing Ownership Validation
CVE-2025-362715.9—IBMIntegrated Analytics SystemCWE-759IBM Integrated Analytics System (IIAS) is affected by a predictable salt vuln…
CVE-2025-362905.9—IBMIntegrated Analytics SystemCWE-295IBM Integrated Analytics System (IIAS) is affected by improper SSL/TLS certif…
CVE-2025-646495.9—IBMConcertCWE-295Multiple Vulnerabilities in IBM Concert Software
CVE-2026-336045.9—Open-Xchange GmbHOX Dovecot ProCWE-655An attacker that can get Dovecot to relay a message, for example through Siev…
CVE-2026-400195.9—Open-Xchange GmbHOX Dovecot CECWE-400An unauthenticated attacker can send a truncated quoted argument to the Manag…
CVE-2026-402055.9—Open-Xchange GmbHOX Dovecot ProCWE-287An attacker that holds an OAuth2 token granting only part of the required sco…
CVE-2026-558545.9—mariadb-corporationmariadb-connector-nodejsCWE-319MariaDB Connector/Node.js: Cleartext Transmission of Sensitive Information an…
CVE-2026-558565.9—mariadb-corporationmariadb-connector-jCWE-522MariaDB Connector/J: Cleartext password disclosure to a MITM on the initial-h…
CVE-2026-558575.9—mariadb-corporationmariadb-connector-jCWE-319MariaDB Connector/J: Cleartext Transmission of Sensitive Information and Insu…
CVE-2026-558585.9—mariadb-corporationmariadb-connector-jCWE-838MariaDB Connector/J: Inappropriate Encoding for Output Context in org.mariadb…
CVE-2026-558595.9—mariadb-corporationmariadb-connector-r2dbcCWE-116MariaDB Connector/R2DBC: Inappropriate Encoding for Output Context and Improp…
CVE-2026-558605.9—mariadb-corporationmariadb-connector-r2dbcCWE-319MariaDB Connector/R2DBC: Cleartext password disclosure to a man-in-the-middle…
CVE-2026-757585.9—elixir-langelixirCWE-674Unbounded recursion between Inspect.List charlist rendering and List.to_strin…
CVE-2026-822585.9—sveltejskitCWE-362SvelteKit 2.38.0 before 2.60.1 Cross-User Data Disclosure via query.batch
CVE-2026-767975.8—MongoDBBI Connector Transition Readiness ReportCWE-1236MongoSQL Transition Readiness Tool Improper Neutralization of Formula Element…
CVE-2026-771845.7—MongoDBBI ConnectorCWE-89MongoDB Connector for BI Incomplete Escaping of Stored Metadata in Generated …
CVE-2026-581075.5—EricssonCodeCheckerCWE-409Authenticated Remote Denial of Service via Unbounded zlib Decompression in ma…
CVE-2026-823275.5—Red HatRed Hat Enterprise Linux 10CWE-129Libsolv: libsolv: out-of-bounds write in repo_write() via unvalidated directo…
CVE-2026-43785.4—Akilli Ticaret Software Technologies Ltd.E-Commerce PackCWE-79Stored XSS in Akıllı Ticaret's E-Commerce Pack
CVE-2026-183935.4—Red HatRed Hat Enterprise Linux AI (RHEL AI) 3CWE-787Ffmpeg: ffmpeg: heap buffer overflow in tdsc_load_cursor() via cur_fmt_mono c…
CVE-2026-387255.4—n/an/aCWE-79xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote…
CVE-2026-557795.4—silverstripesilverstripe-versionedCWE-79Silverstripe Versioned: XSS in archive admin restore
CVE-2026-629045.4—MicrosoftMicrosoft Edge (Chromium-based)CWE-863Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-663235.4—MicrosoftMicrosoft Edge (Chromium-based)CWE-141Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-703095.4—MicrosoftMicrosoft Edge (Chromium-based)CWE-346Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2026-703315.4—MicrosoftMicrosoft Edge (Chromium-based)CWE-1427Microsoft Edge for iOS Spoofing Vulnerability
CVE-2026-817595.4—Magepeople inc.WpEventlyCWE-862WordPress WpEvently plugin <= 5.5.0 - Broken Access Control vulnerability
CVE-2026-50965.3—wpeverestEverest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AICWE-918Everest Forms <= 3.4.4 - Unauthenticated Server-Side Request Forgery via Uplo…
CVE-2026-156035.3—morganmorganCWE-117morgan vulnerable to Log Forging via unescaped Unicode line separators
CVE-2026-547665.3—go-vikunjavikunjaCWE-285Vikunja: Project duplication bypasses write-permission check on the target pa…
CVE-2026-558675.3—Graylog2graylog2-serverCWE-639Graylog token revocation endpoint allows authenticated users to delete other …
CVE-2026-766495.3—TP-Link System Inc.TL-WR841N v14CWE-476Pre-Authentication NULL Pointer Dereference in UPnP SOAP Action Request Proce…
CVE-2026-766505.3—TP-Link System Inc.TL-WR841N v14CWE-476Pre-Authentication NULL Pointer Dereference in UPnP SOAP State Variable Query…
CVE-2026-766515.3—TP-Link System Inc.TL-WR841N v14CWE-120Pre-Authentication Multipart Boundary Buffer Overflow in HTTP Service in TP-L…
CVE-2026-780735.3—mrvinoth.comAll Video Share extension for JoomlaCWE-79Joomla Extension - j2commerce.com - Reflected XSS attribute in All Video Shar…
CVE-2026-817775.3—WPDeveloperEssential Addons for ElementorCWE-290WordPress Essential Addons for Elementor plugin <= 6.8.0 - Bypass vulnerabili…
CVE-2026-822205.3—WPMU DEVForminatorCWE-294WordPress Forminator plugin <= 1.57.1 - Other vulnerability Type vulnerability
CVE-2026-822575.3—sveltejskitCWE-1321SvelteKit before 2.69.1 Prototype Pollution via File Input
CVE-2026-822675.3—moghtechkomodoCWE-862Komodo Resource Identifier Disclosure and Audit Log Pollution Before Permissi…
CVE-2026-822745.3—twentyhqtwentyCWE-601Twenty Open Redirect via OAuth Propagator Callback
CVE-2026-822765.3—StarRocksstarrocksCWE-306StarRocks Frontend REST Handlers Bypass the Base Class Authentication Gate
CVE-2026-817335.1—WWBNAVideoCWE-352WWBN AVideo through 30.0 CSRF via myLiveControls.save.json.php
CVE-2026-821125.1—houtini-aihoutini-lmCWE-22houtini-ai houtini-lm code_task_files index.ts path traversal
CVE-2026-550675.0—go-vikunjavikunjaCWE-639Vikunja: Authenticated cross-tenant kanban-bucket relocation via `project_vie…
CVE-2026-554255.0—Graylog2graylog2-serverCWE-213Graylog: System Catalog titles endpoint can be used to retrieve values of pro…

Results continue: ranks 401–496.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-28 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.