boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Friday, August 28, 2026 · all times UTC← 2026-08-27 · archive

Security Box Score — August 28, 2026 — page 2

Edition of August 28, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–496 of 496
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-336064.8—Open-Xchange GmbHOX Dovecot ProCWE-93Mail content stored by a user can be crafted so that it is interpreted as dsy…
CVE-2026-767944.8—MongoDBBI Connector Transition Readiness ReportCWE-79MongoDB BI Connector Transition Readiness Report Improper HTML Encoding When …
CVE-2026-586164.4—MicrosoftMicrosoft Edge (Chromium-based)CWE-362Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
CVE-2026-185454.3—IBMLangflow OSSCWE-918Langflow is affected by multiple authentication bypass, path traversal, autho…
CVE-2026-332634.3—Open-Xchange GmbHOX Dovecot ProCWE-403When mail_max_userip_connections is set (default 10) and reached, submission-…
CVE-2026-336074.3—Open-Xchange GmbHOX Dovecot ProCWE-400An attacker that has valid credentials can use IMAP LIST command to consume C…
CVE-2026-400134.3—Open-Xchange GmbHOX Dovecot ProCWE-124An attacker that has valid credentials can submit a Sieve script containing a…
CVE-2026-400154.3—Open-Xchange GmbHOX Dovecot ProCWE-125An attacker that has valid credentials can open many connections to the imap-…
CVE-2026-420084.3—Open-Xchange GmbHOX Dovecot ProCWE-287Forwarding information received from a host listed as a trusted proxy is not …
CVE-2026-423924.3—Open-Xchange GmbHOX Dovecot ProCWE-200An attacker that has valid credentials can send an invalid IMAP URLFETCH comm…
CVE-2026-423954.3—Open-Xchange GmbHOX Dovecot ProCWE-400A host listed as a trusted proxy can send forwarding information containing a…
CVE-2026-550644.3—go-vikunjavikunjaCWE-862Vikunja incomplete fix for CVE-2026-35595: Write-only user can detach shared …
CVE-2026-555474.3—yamcsyamcsCWE-285Yamcs: Missing Authorization on Role and Privilege Enumeration Endpoints Allo…
CVE-2026-555664.3—yamcsyamcsCWE-79Yamcs: DOM XSS in Extension Routing
CVE-2026-556964.3—PrivateBinPrivateBinCWE-79PrivateBin: Stored Cross-Side-Scripting (XSS) vulnerability in attachment dow…
CVE-2026-558344.3—pocket-idpocket-idCWE-601Pocket ID: Open Redirect on the OIDC /authorize page via unvalidated redirect…
CVE-2026-667984.3—MicrosoftMicrosoft Edge (Chromium-based)CWE-416Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-812844.3—ACF ExtendedACF ExtendedCWE-862WordPress ACF Extended plugin <= 0.9.2.6 - Broken Access Control vulnerability
CVE-2026-812994.3—AhmadWP Job PortalCWE-639WordPress WP Job Portal plugin <= 2.5.9 - Insecure Direct Object References (…
CVE-2026-817614.3—Magepeople inc.WpEventlyCWE-862WordPress WpEvently plugin <= 5.5.0 - Broken Access Control vulnerability
CVE-2026-137353.7—zephyrprojectzephyrCWE-290WireGuard keepalive transport-data messages accepted without Poly1305 authent…
CVE-2026-402033.7—Open-Xchange GmbHOX Dovecot ProCWE-200When IMAP compression is enabled, the same compression state is reused across…
CVE-2026-557853.7—free5gcfree5gcCWE-208free5GC AUSF uses non-constant-time authentication comparisons and logs XRES*…
CVE-2026-770633.7—multermulterCWE-362multer vulnerable to file size limit bypass via async fileFilter race condition
CVE-2026-380933.3—n/an/aCWE-22file_picker (aka flutter_file_picker) for Flutter, all versions through 10.3.…
CVE-2026-402043.1—Open-Xchange GmbHOX Dovecot ProCWE-284None None None No publicly available exploits are known.
CVE-2026-423933.1—Open-Xchange GmbHOX Dovecot ProCWE-200The comparison used for the doveadm password and API key is not fully timing …
CVE-2026-526813.1—Open-Xchange GmbHOX Dovecot ProCWE-1050Sieve CPU resource usage is tracked in the compiled script, so an attacker th…
CVE-2026-220562.3—NetAppStorageGRIDCWE-774CVE-2026-22056 Denial of Service Vulnerability in StorageGRID (formerly Stora…
CVE-2026-822362.3—filebrowserfilebrowserCWE-459File Browser 2.63.6 through 2.63.23 Share Link Exposure via File Deletion
CVE-2026-822372.3—filebrowserfilebrowserCWE-459filebrowser through 2.63.23 Stale Share Link via File Rename
CVE-2026-822382.3—filebrowserfilebrowserCWE-367filebrowser 2.24.0 Race Condition via TUS concurrent PATCH uploads
CVE-2026-822492.3—GitoxideLabsgitoxideCWE-116gitoxide before 0.38.2 Credential Helper Protocol Field Injection
CVE-2026-821112.1—iswallegetnote-mcpCWE-22iswalle getnote-mcp upload_image index.ts fs.readFileSync path traversal
CVE-2026-581062.0—EricssonCodeCheckerCWE-787Incomplete fix for CVE-2025-40843: safe_strcpy is called with PATH_MAX into f…
CVE-2026-558910.0—PrivateBinPrivateBinCWE-116PrivateBin: Reflected JSON injection in backend responses via unescaped REQUE…
CVE-2026-37236await—n/an/a—grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The applicati…
CVE-2026-39070await—n/an/a—WordPress plugin (Bit Assist) before 1.7.2 is affected by Stored Cross-Site S…
CVE-2026-39071await—n/an/a—WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cross-Sit…
CVE-2026-50980await—n/an/a—Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management compone…
CVE-2026-51376await—n/an/a—An issue in BitChat for iOS v1.15.0 allows a remote attacker to cause a denia…
CVE-2026-51610await—n/an/a—Incorrect access control in the RebootSystem function of TOTOLINK T6 4.1.5cu.…
CVE-2026-51611await—n/an/a—Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.…
CVE-2026-51613await—n/an/a—Incorrect access control in the getDeviceInfo function of TOTOLINK T6 4.1.5cu…
CVE-2026-51614await—n/an/a—Incorrect access control in the getAccessDeviceCfg function of TOTOLINK T6 4.…
CVE-2026-51615await—n/an/a—Incorrect access control in the getLanCfg function of TOTOLINK T6 4.1.5cu.748…
CVE-2026-51616await—n/an/a—Incorrect access control in the getWanIeCfg function of TOTOLINK T6 4.1.5cu.7…
CVE-2026-51617await—n/an/a—Incorrect access control in the getSysStatusCfg function of TOTOLINK T6 4.1.5…
CVE-2026-51618await—n/an/a—Incorrect access control in the getWizardCfg function of TOTOLINK T6 4.1.5cu.…
CVE-2026-51619await—n/an/a—Incorrect access control in the getOnlineClient function of TOTOLINK T6 4.1.5…
CVE-2026-51620await—n/an/a—Incorrect access control in the getNetInfoCfg function of TOTOLINK T6 4.1.5cu…
CVE-2026-51621await—n/an/a—Incorrect access control in the getInitCfg function of TOTOLINK T6 4.1.5cu.74…
CVE-2026-51622await—n/an/a—Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748…
CVE-2026-51623await—n/an/a—Incorrect access control in the getDdnsStatus function of TOTOLINK T6 4.1.5cu…
CVE-2026-51624await—n/an/a—Incorrect access control in the getStationMacByIp function of TOTOLINK T6 4.1…
CVE-2026-51625await—n/an/a—Incorrect access control in the getWiFiEasyCfg function of TOTOLINK T6 4.1.5c…
CVE-2026-51626await—n/an/a—Incorrect access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu…
CVE-2026-51627await—n/an/a—Incorrect access control in the getIptvCfg function of TOTOLINK T6 4.1.5cu.74…
CVE-2026-51628await—n/an/a—Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6…
CVE-2026-51629await—n/an/a—Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.…
CVE-2026-51630await—n/an/a—Incorrect access control in the getDdnsCfg function of TOTOLINK T6 4.1.5cu.74…
CVE-2026-51631await—n/an/a—Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.…
CVE-2026-51632await—n/an/a—Incorrect access control in the getWiFiAdvancedCfg function of TOTOLINK T6 4.…
CVE-2026-51633await—n/an/a—Incorrect access control in the getWiFiEasyGuestCfg function of TOTOLINK T6 4…
CVE-2026-51634await—n/an/a—Incorrect access control in the getWiFiBasicCfg function of TOTOLINK T6 4.1.5…
CVE-2026-51635await—n/an/a—Incorrect access control in the getWiFiScheduleCfg function of TOTOLINK T6 4.…
CVE-2026-51636await—n/an/a—Incorrect access control in the getWiFiAclRules function of TOTOLINK T6 4.1.5…
CVE-2026-51637await—n/an/a—Incorrect access control in the getMeshPortalTable function of TOTOLINK T6 4.…
CVE-2026-51638await—n/an/a—Incorrect access control in the getWiFiGuestCfg function of TOTOLINK T6 4.1.5…
CVE-2026-51639await—n/an/a—Incorrect access control in the getApWiFiSchCfg function of TOTOLINK T6 4.1.5…
CVE-2026-51640await—n/an/a—Incorrect access control in the getMeshNeighborTable function of TOTOLINK T6 …
CVE-2026-51641await—n/an/a—Incorrect access control in the getWiFiMeshConfig function of TOTOLINK T6 4.1…
CVE-2026-51642await—n/an/a—Incorrect access control in the getMeshRoutingTable function of TOTOLINK T6 4…
CVE-2026-51643await—n/an/a—Incorrect access control in the getNtpCfg function of TOTOLINK T6 4.1.5cu.748…
CVE-2026-51644await—n/an/a—Incorrect access control in the getCrpcConfig function of TOTOLINK T6 4.1.5cu…
CVE-2026-51645await—n/an/a—Incorrect access control in the getPasswordCfg function of TOTOLINK T6 4.1.5c…
CVE-2026-51646await—n/an/a—Incorrect access control in the getParentalRules function of TOTOLINK T6 4.1.…
CVE-2026-51647await—n/an/a—Incorrect access control in the getCrpcCfg function of TOTOLINK T6 4.1.5cu.74…
CVE-2026-51648await—n/an/a—Incorrect access control in the getWanInfo function of TOTOLINK T6 4.1.5cu.74…
CVE-2026-51649await—n/an/a—Incorrect access control in the getDiagnosisCfg function of TOTOLINK T6 4.1.5…
CVE-2026-51650await—n/an/a—Incorrect access control in the getRemoteCfg function of TOTOLINK T6 4.1.5cu.…
CVE-2026-51651await—n/an/a—Incorrect access control in the getSmartQosCfg function of TOTOLINK T6 4.1.5c…
CVE-2026-51652await—n/an/a—Incorrect access control in the getUPnPCfg function of TOTOLINK T6 4.1.5cu.74…
CVE-2026-51653await—n/an/a—Incorrect access control in the getStorageCfg function of TOTOLINK T6 4.1.5cu…
CVE-2026-51654await—n/an/a—Incorrect access control in the getScheduleCfg function of TOTOLINK T6 4.1.5c…
CVE-2026-51655await—n/an/a—Incorrect access control in the getMacFilterRules function of TOTOLINK T6 4.1…
CVE-2026-51656await—n/an/a—Incorrect access control in the getVpnPassCfg function of TOTOLINK T6 4.1.5cu…
CVE-2026-51657await—n/an/a—Incorrect access control in the getSyslogCfg function of TOTOLINK T6 4.1.5cu.…
CVE-2026-51658await—n/an/a—Incorrect access control in the getDmzCfg function of TOTOLINK T6 4.1.5cu.748…
CVE-2026-51659await—n/an/a—Incorrect access control in the getUrlFilterRules function of TOTOLINK T6 4.1…
CVE-2026-51660await—n/an/a—Incorrect access control in the getIpPortFilterRules function of TOTOLINK T6 …
CVE-2026-51661await—n/an/a—Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4…
CVE-2026-51662await—n/an/a—Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T…
CVE-2026-51663await—n/an/a—Incorrect access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.…
CVE-2026-51664await—n/an/a—Incorrect access control in the getTelnetCfg function of TOTOLINK T6 4.1.5cu.…
CVE-2026-51665await—n/an/a—Incorrect access control in the getTracerouteCfg function of TOTOLINK T6 4.1.…