Security Box Score — August 28, 2026 — page 2
Edition of August 28, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-33606 | 4.8 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-93 | Mail content stored by a user can be crafted so that it is interpreted as dsy… |
| CVE-2026-76794 | 4.8 | — | MongoDB | BI Connector Transition Readiness Report | CWE-79 | MongoDB BI Connector Transition Readiness Report Improper HTML Encoding When … |
| CVE-2026-58616 | 4.4 | — | Microsoft | Microsoft Edge (Chromium-based) | CWE-362 | Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability |
| CVE-2026-18545 | 4.3 | — | IBM | Langflow OSS | CWE-918 | Langflow is affected by multiple authentication bypass, path traversal, autho… |
| CVE-2026-33263 | 4.3 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-403 | When mail_max_userip_connections is set (default 10) and reached, submission-… |
| CVE-2026-33607 | 4.3 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-400 | An attacker that has valid credentials can use IMAP LIST command to consume C… |
| CVE-2026-40013 | 4.3 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-124 | An attacker that has valid credentials can submit a Sieve script containing a… |
| CVE-2026-40015 | 4.3 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-125 | An attacker that has valid credentials can open many connections to the imap-… |
| CVE-2026-42008 | 4.3 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-287 | Forwarding information received from a host listed as a trusted proxy is not … |
| CVE-2026-42392 | 4.3 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-200 | An attacker that has valid credentials can send an invalid IMAP URLFETCH comm… |
| CVE-2026-42395 | 4.3 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-400 | A host listed as a trusted proxy can send forwarding information containing a… |
| CVE-2026-55064 | 4.3 | — | go-vikunja | vikunja | CWE-862 | Vikunja incomplete fix for CVE-2026-35595: Write-only user can detach shared … |
| CVE-2026-55547 | 4.3 | — | yamcs | yamcs | CWE-285 | Yamcs: Missing Authorization on Role and Privilege Enumeration Endpoints Allo… |
| CVE-2026-55566 | 4.3 | — | yamcs | yamcs | CWE-79 | Yamcs: DOM XSS in Extension Routing |
| CVE-2026-55696 | 4.3 | — | PrivateBin | PrivateBin | CWE-79 | PrivateBin: Stored Cross-Side-Scripting (XSS) vulnerability in attachment dow… |
| CVE-2026-55834 | 4.3 | — | pocket-id | pocket-id | CWE-601 | Pocket ID: Open Redirect on the OIDC /authorize page via unvalidated redirect… |
| CVE-2026-66798 | 4.3 | — | Microsoft | Microsoft Edge (Chromium-based) | CWE-416 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-81284 | 4.3 | — | ACF Extended | ACF Extended | CWE-862 | WordPress ACF Extended plugin <= 0.9.2.6 - Broken Access Control vulnerability |
| CVE-2026-81299 | 4.3 | — | Ahmad | WP Job Portal | CWE-639 | WordPress WP Job Portal plugin <= 2.5.9 - Insecure Direct Object References (… |
| CVE-2026-81761 | 4.3 | — | Magepeople inc. | WpEvently | CWE-862 | WordPress WpEvently plugin <= 5.5.0 - Broken Access Control vulnerability |
| CVE-2026-13735 | 3.7 | — | zephyrproject | zephyr | CWE-290 | WireGuard keepalive transport-data messages accepted without Poly1305 authent… |
| CVE-2026-40203 | 3.7 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-200 | When IMAP compression is enabled, the same compression state is reused across… |
| CVE-2026-55785 | 3.7 | — | free5gc | free5gc | CWE-208 | free5GC AUSF uses non-constant-time authentication comparisons and logs XRES*… |
| CVE-2026-77063 | 3.7 | — | multer | multer | CWE-362 | multer vulnerable to file size limit bypass via async fileFilter race condition |
| CVE-2026-38093 | 3.3 | — | n/a | n/a | CWE-22 | file_picker (aka flutter_file_picker) for Flutter, all versions through 10.3.… |
| CVE-2026-40204 | 3.1 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-284 | None None None No publicly available exploits are known. |
| CVE-2026-42393 | 3.1 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-200 | The comparison used for the doveadm password and API key is not fully timing … |
| CVE-2026-52681 | 3.1 | — | Open-Xchange GmbH | OX Dovecot Pro | CWE-1050 | Sieve CPU resource usage is tracked in the compiled script, so an attacker th… |
| CVE-2026-22056 | 2.3 | — | NetApp | StorageGRID | CWE-774 | CVE-2026-22056 Denial of Service Vulnerability in StorageGRID (formerly Stora… |
| CVE-2026-82236 | 2.3 | — | filebrowser | filebrowser | CWE-459 | File Browser 2.63.6 through 2.63.23 Share Link Exposure via File Deletion |
| CVE-2026-82237 | 2.3 | — | filebrowser | filebrowser | CWE-459 | filebrowser through 2.63.23 Stale Share Link via File Rename |
| CVE-2026-82238 | 2.3 | — | filebrowser | filebrowser | CWE-367 | filebrowser 2.24.0 Race Condition via TUS concurrent PATCH uploads |
| CVE-2026-82249 | 2.3 | — | GitoxideLabs | gitoxide | CWE-116 | gitoxide before 0.38.2 Credential Helper Protocol Field Injection |
| CVE-2026-82111 | 2.1 | — | iswalle | getnote-mcp | CWE-22 | iswalle getnote-mcp upload_image index.ts fs.readFileSync path traversal |
| CVE-2026-58106 | 2.0 | — | Ericsson | CodeChecker | CWE-787 | Incomplete fix for CVE-2025-40843: safe_strcpy is called with PATH_MAX into f… |
| CVE-2026-55891 | 0.0 | — | PrivateBin | PrivateBin | CWE-116 | PrivateBin: Reflected JSON injection in backend responses via unescaped REQUE… |
| CVE-2026-37236 | await | — | n/a | n/a | — | grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The applicati… |
| CVE-2026-39070 | await | — | n/a | n/a | — | WordPress plugin (Bit Assist) before 1.7.2 is affected by Stored Cross-Site S… |
| CVE-2026-39071 | await | — | n/a | n/a | — | WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cross-Sit… |
| CVE-2026-50980 | await | — | n/a | n/a | — | Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management compone… |
| CVE-2026-51376 | await | — | n/a | n/a | — | An issue in BitChat for iOS v1.15.0 allows a remote attacker to cause a denia… |
| CVE-2026-51610 | await | — | n/a | n/a | — | Incorrect access control in the RebootSystem function of TOTOLINK T6 4.1.5cu.… |
| CVE-2026-51611 | await | — | n/a | n/a | — | Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.… |
| CVE-2026-51613 | await | — | n/a | n/a | — | Incorrect access control in the getDeviceInfo function of TOTOLINK T6 4.1.5cu… |
| CVE-2026-51614 | await | — | n/a | n/a | — | Incorrect access control in the getAccessDeviceCfg function of TOTOLINK T6 4.… |
| CVE-2026-51615 | await | — | n/a | n/a | — | Incorrect access control in the getLanCfg function of TOTOLINK T6 4.1.5cu.748… |
| CVE-2026-51616 | await | — | n/a | n/a | — | Incorrect access control in the getWanIeCfg function of TOTOLINK T6 4.1.5cu.7… |
| CVE-2026-51617 | await | — | n/a | n/a | — | Incorrect access control in the getSysStatusCfg function of TOTOLINK T6 4.1.5… |
| CVE-2026-51618 | await | — | n/a | n/a | — | Incorrect access control in the getWizardCfg function of TOTOLINK T6 4.1.5cu.… |
| CVE-2026-51619 | await | — | n/a | n/a | — | Incorrect access control in the getOnlineClient function of TOTOLINK T6 4.1.5… |
| CVE-2026-51620 | await | — | n/a | n/a | — | Incorrect access control in the getNetInfoCfg function of TOTOLINK T6 4.1.5cu… |
| CVE-2026-51621 | await | — | n/a | n/a | — | Incorrect access control in the getInitCfg function of TOTOLINK T6 4.1.5cu.74… |
| CVE-2026-51622 | await | — | n/a | n/a | — | Incorrect access control in the getWanCfg function of TOTOLINK T6 4.1.5cu.748… |
| CVE-2026-51623 | await | — | n/a | n/a | — | Incorrect access control in the getDdnsStatus function of TOTOLINK T6 4.1.5cu… |
| CVE-2026-51624 | await | — | n/a | n/a | — | Incorrect access control in the getStationMacByIp function of TOTOLINK T6 4.1… |
| CVE-2026-51625 | await | — | n/a | n/a | — | Incorrect access control in the getWiFiEasyCfg function of TOTOLINK T6 4.1.5c… |
| CVE-2026-51626 | await | — | n/a | n/a | — | Incorrect access control in the getWiFiWpsCfg function of TOTOLINK T6 4.1.5cu… |
| CVE-2026-51627 | await | — | n/a | n/a | — | Incorrect access control in the getIptvCfg function of TOTOLINK T6 4.1.5cu.74… |
| CVE-2026-51628 | await | — | n/a | n/a | — | Incorrect access control in the getGenerateWiFiWpsPin function of TOTOLINK T6… |
| CVE-2026-51629 | await | — | n/a | n/a | — | Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.… |
| CVE-2026-51630 | await | — | n/a | n/a | — | Incorrect access control in the getDdnsCfg function of TOTOLINK T6 4.1.5cu.74… |
| CVE-2026-51631 | await | — | n/a | n/a | — | Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.… |
| CVE-2026-51632 | await | — | n/a | n/a | — | Incorrect access control in the getWiFiAdvancedCfg function of TOTOLINK T6 4.… |
| CVE-2026-51633 | await | — | n/a | n/a | — | Incorrect access control in the getWiFiEasyGuestCfg function of TOTOLINK T6 4… |
| CVE-2026-51634 | await | — | n/a | n/a | — | Incorrect access control in the getWiFiBasicCfg function of TOTOLINK T6 4.1.5… |
| CVE-2026-51635 | await | — | n/a | n/a | — | Incorrect access control in the getWiFiScheduleCfg function of TOTOLINK T6 4.… |
| CVE-2026-51636 | await | — | n/a | n/a | — | Incorrect access control in the getWiFiAclRules function of TOTOLINK T6 4.1.5… |
| CVE-2026-51637 | await | — | n/a | n/a | — | Incorrect access control in the getMeshPortalTable function of TOTOLINK T6 4.… |
| CVE-2026-51638 | await | — | n/a | n/a | — | Incorrect access control in the getWiFiGuestCfg function of TOTOLINK T6 4.1.5… |
| CVE-2026-51639 | await | — | n/a | n/a | — | Incorrect access control in the getApWiFiSchCfg function of TOTOLINK T6 4.1.5… |
| CVE-2026-51640 | await | — | n/a | n/a | — | Incorrect access control in the getMeshNeighborTable function of TOTOLINK T6 … |
| CVE-2026-51641 | await | — | n/a | n/a | — | Incorrect access control in the getWiFiMeshConfig function of TOTOLINK T6 4.1… |
| CVE-2026-51642 | await | — | n/a | n/a | — | Incorrect access control in the getMeshRoutingTable function of TOTOLINK T6 4… |
| CVE-2026-51643 | await | — | n/a | n/a | — | Incorrect access control in the getNtpCfg function of TOTOLINK T6 4.1.5cu.748… |
| CVE-2026-51644 | await | — | n/a | n/a | — | Incorrect access control in the getCrpcConfig function of TOTOLINK T6 4.1.5cu… |
| CVE-2026-51645 | await | — | n/a | n/a | — | Incorrect access control in the getPasswordCfg function of TOTOLINK T6 4.1.5c… |
| CVE-2026-51646 | await | — | n/a | n/a | — | Incorrect access control in the getParentalRules function of TOTOLINK T6 4.1.… |
| CVE-2026-51647 | await | — | n/a | n/a | — | Incorrect access control in the getCrpcCfg function of TOTOLINK T6 4.1.5cu.74… |
| CVE-2026-51648 | await | — | n/a | n/a | — | Incorrect access control in the getWanInfo function of TOTOLINK T6 4.1.5cu.74… |
| CVE-2026-51649 | await | — | n/a | n/a | — | Incorrect access control in the getDiagnosisCfg function of TOTOLINK T6 4.1.5… |
| CVE-2026-51650 | await | — | n/a | n/a | — | Incorrect access control in the getRemoteCfg function of TOTOLINK T6 4.1.5cu.… |
| CVE-2026-51651 | await | — | n/a | n/a | — | Incorrect access control in the getSmartQosCfg function of TOTOLINK T6 4.1.5c… |
| CVE-2026-51652 | await | — | n/a | n/a | — | Incorrect access control in the getUPnPCfg function of TOTOLINK T6 4.1.5cu.74… |
| CVE-2026-51653 | await | — | n/a | n/a | — | Incorrect access control in the getStorageCfg function of TOTOLINK T6 4.1.5cu… |
| CVE-2026-51654 | await | — | n/a | n/a | — | Incorrect access control in the getScheduleCfg function of TOTOLINK T6 4.1.5c… |
| CVE-2026-51655 | await | — | n/a | n/a | — | Incorrect access control in the getMacFilterRules function of TOTOLINK T6 4.1… |
| CVE-2026-51656 | await | — | n/a | n/a | — | Incorrect access control in the getVpnPassCfg function of TOTOLINK T6 4.1.5cu… |
| CVE-2026-51657 | await | — | n/a | n/a | — | Incorrect access control in the getSyslogCfg function of TOTOLINK T6 4.1.5cu.… |
| CVE-2026-51658 | await | — | n/a | n/a | — | Incorrect access control in the getDmzCfg function of TOTOLINK T6 4.1.5cu.748… |
| CVE-2026-51659 | await | — | n/a | n/a | — | Incorrect access control in the getUrlFilterRules function of TOTOLINK T6 4.1… |
| CVE-2026-51660 | await | — | n/a | n/a | — | Incorrect access control in the getIpPortFilterRules function of TOTOLINK T6 … |
| CVE-2026-51661 | await | — | n/a | n/a | — | Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4… |
| CVE-2026-51662 | await | — | n/a | n/a | — | Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T… |
| CVE-2026-51663 | await | — | n/a | n/a | — | Incorrect access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.… |
| CVE-2026-51664 | await | — | n/a | n/a | — | Incorrect access control in the getTelnetCfg function of TOTOLINK T6 4.1.5cu.… |
| CVE-2026-51665 | await | — | n/a | n/a | — | Incorrect access control in the getTracerouteCfg function of TOTOLINK T6 4.1.… |