AV AC PR UI S C I A CVSS EPSS %ile KEV N H H N U H H H 6.6 .0023 13.5 —
AFFECTED Product Versions Fixed User Profile Builder 3.3.4 – —
TIMELINE Aug 19 Reserved by CNA Aug 29 Published (CNA: WPScan)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
67 CVEs published, led by jeremyevans (5).
67 CVEs published August 29, 2026: 11 critical, 18 high, 29 medium, 7 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 2 awaiting enrichment. 25 rendered as box scores below; the remaining 42 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 11840 | 34279 | — | — |
| KEV catalog size | 1685 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
2049 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 1645 | 3960 | 418 | 1972 | 637 | 1 | 12 | 3 | 0.1 | 7.8 | .0016 | +811 ▲ |
| 402 | 2164 | 270 | 842 | 960 | 75 | 77 | 6 | 0.3 | 7.5 | .0026 | +281 ▲ | |
| microsoft | 477 | 1899 | 145 | 1283 | 457 | 14 | 287 | 28 | 1.5 | 7.8 | .0044 | -187 ▼ |
| red hat | 223 | 616 | 42 | 254 | 287 | 32 | 2 | 0 | 0.0 | 6.7 | .0029 | +90 ▲ |
| apple | 44 | 316 | 59 | 85 | 165 | 7 | 88 | 8 | 2.5 | 6.5 | .0029 | -123 ▼ |
| freebsd | 32 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | +32 ▲ |
| canonical | 15 | 42 | 13 | 11 | 13 | 5 | 0 | 0 | 0.0 | 7.8 | .0020 | +8 ▲ |
| suse | 7 | 28 | 5 | 14 | 8 | 1 | 0 | 0 | 0.0 | 7.7 | .0038 | -1 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 46 | 84 | 21 | 39 | 24 | 0 | 56 | 13 | 15.5 | 7.5 | .0044 | +30 ▲ |
| ubiquiti | 23 | 59 | 36 | 22 | 1 | 0 | 3 | 3 | 5.1 | 9.1 | .0049 | -2 ▼ |
| palo alto networks | 12 | 37 | 1 | 3 | 21 | 12 | 13 | 2 | 5.4 | 4.7 | .0020 | -2 ▼ |
| netgear | 9 | 32 | 0 | 0 | 27 | 5 | 0 | 0 | 0.0 | 4.3 | .0025 | +3 ▲ |
| fortinet | 7 | 30 | 7 | 8 | 14 | 1 | 28 | 6 | 20.0 | 7.0 | .0050 | -7 ▼ |
| vmware | 2 | 19 | 5 | 9 | 3 | 2 | 7 | 2 | 10.5 | 8.3 | .0040 | -6 ▼ |
| f5 | 0 | 17 | 5 | 9 | 3 | 0 | 4 | 1 | 5.9 | 8.7 | .0057 | -8 ▼ |
| sonicwall | 12 | 14 | 3 | 7 | 4 | 0 | 17 | 2 | 14.3 | 7.8 | .0024 | +10 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 159 | 496 | 102 | 216 | 164 | 13 | 33 | 2 | 0.4 | 7.5 | .0049 | -6 ▼ |
| mozilla | 59 | 186 | 68 | 68 | 50 | 0 | 9 | 0 | 0.0 | 8.1 | .0030 | -12 ▼ |
| gitlab | 25 | 76 | 2 | 18 | 47 | 9 | 4 | 2 | 2.6 | 5.3 | .0028 | +5 ▲ |
| drupal | 17 | 68 | 10 | 7 | 46 | 5 | 4 | 1 | 1.5 | 5.9 | .0024 | -29 ▼ |
| github | 5 | 17 | 1 | 7 | 9 | 0 | 0 | 0 | 0.0 | 6.6 | .0043 | -1 ▼ |
| docker | 2 | 9 | 0 | 6 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0016 | +2 ▲ |
| wordpress | 2 | 5 | 1 | 3 | 1 | 0 | 2 | 2 | 40.0 | 8.8 | .3120 | -1 ▼ |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0035 | -1 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 890 | 2269 | 484 | 1170 | 519 | 96 | 28 | 4 | 0.2 | 7.8 | .0034 | -219 ▼ |
| ibm | 390 | 619 | 148 | 286 | 177 | 8 | 6 | 1 | 0.2 | 7.6 | .0030 | +320 ▲ |
| adobe | 101 | 606 | 50 | 300 | 247 | 9 | 19 | 3 | 0.5 | 7.8 | .0021 | -4 ▼ |
| progress | 19 | 61 | 14 | 37 | 10 | 0 | 6 | 1 | 1.6 | 8.1 | .0037 | -14 ▼ |
| solarwinds | 0 | 23 | 17 | 3 | 3 | 0 | 10 | 4 | 17.4 | 9.1 | .0058 | -15 ▼ |
| veeam | 13 | 19 | 6 | 10 | 3 | 0 | 1 | 0 | 0.0 | 8.6 | .0032 | +12 ▲ |
| zohocorp | 4 | 10 | 3 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0140 | +1 ▲ |
| atlassian | 3 | 6 | 1 | 5 | 0 | 0 | 13 | 0 | 0.0 | 8.1 | .0032 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| siemens | 21 | 37 | 2 | 24 | 8 | 3 | 0 | 0 | 0.0 | 7.3 | .0016 | +14 ▲ |
| d-link | 16 | 36 | 15 | 5 | 9 | 7 | 3 | 0 | 0.0 | 7.4 | .0157 | +8 ▲ |
| synology | 4 | 27 | 3 | 6 | 15 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +4 ▲ |
| rockwell automation | 1 | 25 | 4 | 17 | 4 | 0 | 0 | 0 | 0.0 | 8.4 | .0024 | -16 ▼ |
| schneider electric | 0 | 9 | 1 | 6 | 2 | 0 | 0 | 0 | 0.0 | 8.6 | .0037 | -3 ▼ |
| abb | 0 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -1 ▼ |
| hikvision | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0040 | -5 ▼ |
| mitsubishi electric | 0 | 5 | 0 | 4 | 1 | 0 | 0 | 0 | 0.0 | 7.2 | .0052 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| spring | 91 | 170 | 9 | 53 | 86 | 16 | 0 | 0 | 0.0 | 6.4 | .0022 | +91 ▲ |
| dell | 71 | 170 | 11 | 90 | 64 | 5 | 2 | 1 | 0.6 | 7.2 | .0019 | +28 ▲ |
| sourcecodester | 48 | 168 | 0 | 0 | 92 | 76 | 0 | 0 | 0.0 | 5.5 | .0029 | -1 ▼ |
| nvidia | 52 | 134 | 16 | 88 | 30 | 0 | 0 | 0 | 0.0 | 7.8 | .0034 | +9 ▲ |
| splunk | 110 | 128 | 6 | 47 | 70 | 5 | 1 | 1 | 0.8 | 6.5 | .0025 | +107 ▲ |
| openclaw | 0 | 111 | 0 | 58 | 39 | 14 | 0 | 0 | 0.0 | 7.0 | .0026 | -44 ▼ |
| zephyrproject | 52 | 105 | 3 | 33 | 57 | 12 | 0 | 0 | 0.0 | 6.4 | .0021 | +26 ▲ |
| getgrav | 66 | 104 | 15 | 59 | 28 | 2 | 0 | 0 | 0.0 | 8.4 | .0032 | +28 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-8037 | .9957 | 99.9 | 9.8 |
| CVE-2026-34486 | .9862 | 99.9 | 7.5 |
| CVE-2026-63077 | .8771 | 99.8 | 9.8 |
| CVE-2026-60004 | .8455 | 99.7 | 9.8 |
| CVE-2026-72898 | .7922 | 99.6 | 10.0 |
| CVE-2026-18577 | .5407 | 99.0 | 8.2 |
| CVE-2026-18556 | .4016 | 98.6 | 8.2 |
| CVE-2026-64638 | .3120 | 98.2 | 8.9 |
| CVE-2026-71362 | .2514 | 97.8 | 9.1 |
| CVE-2026-73570 | .2053 | 97.4 | 8.9 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-72898 | 10.0 | .7922 | KEV |
| CVE-2026-48362 | 10.0 | .0431 | |
| CVE-2026-19188 | 10.0 | .0193 | |
| CVE-2026-58231 | 10.0 | .0171 | |
| CVE-2026-69836 | 10.0 | .0155 | |
| CVE-2026-76195 | 10.0 | .0147 | |
| CVE-2026-76197 | 10.0 | .0147 | |
| CVE-2026-73299 | 10.0 | .0121 | |
| CVE-2026-73678 | 10.0 | .0114 | |
| CVE-2026-77554 | 10.0 | .0099 |
| Vendor | CVEs |
|---|---|
| linux | 1645 |
| oracle | 890 |
| microsoft | 477 |
| 407 | |
| ibm | 390 |
| red hat | 239 |
| apache | 162 |
| splunk | 110 |
| adobe | 102 |
| spring | 91 |
| Vendor | KEV |
|---|---|
| microsoft | 28 |
| cisco | 13 |
| apple | 8 |
| fortinet | 6 |
| 6 | |
| ivanti | 5 |
| oracle | 4 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 53 |
| Packagist | 28 |
| npm | 14 |
| PyPI | 13 |
| Go | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-18556 | N-able | 0 |
| CVE-2026-18577 | N-able | 0 |
| CVE-2026-20349 | Cisco | 0 |
| CVE-2026-34486 | Apache Software Foundation | 0 |
| CVE-2026-63077 | JetBrains | 0 |
| CVE-2026-72529 | TrueConf | 0 |
| CVE-2026-72530 | TrueConf | 0 |
| CVE-2026-72898 | Metabase | 0 |
| CVE-2026-8037 | Progress Software | 0 |
| CVE-2026-64849 | mlflow | 1 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1746 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1746 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1746 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1746 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1746 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1746 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1746 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1746 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1746 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1746 |
EXPLOIT PUBLISHED — dolibarr: 9 CVEs (CVE-2026-71503, CVE-2026-71504, CVE-2026-71505, CVE-2026-71506, CVE-2026-71507, CVE-2026-71508, CVE-2026-71509, CVE-2026-71510, CVE-2026-71511). Public exploit references added.
EXPLOIT PUBLISHED — rocq-prover rocq: 3 CVEs (CVE-2026-72703, CVE-2026-72704, CVE-2026-72705). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2026-10036 (speechbrain). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56100 (SpringBlade). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65053 (horde imp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-72711 (leanprover lean4). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-77939 (flextype). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-78122 (Tecnativa docker-socket-proxy). Public exploit reference added.
DUE DATE PASSED — CVE-2026-60004 (Gitea). CISA remediation deadline was August 28, 2026; still in catalog.
How to read these box scores · glossary
67 CVEs published. 25 box scores, 42 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N H H N U H H H 6.6 .0023 13.5 —
AFFECTED Product Versions Fixed User Profile Builder 3.3.4 – —
TIMELINE Aug 19 Reserved by CNA Aug 29 Published (CNA: WPScan)
CVSS EPSS %ile KEV — .0019 8.8 —
AFFECTED Product Versions Fixed Linux 0fe79f28bfaf73b66b7b1562d2468f94aa03bd12 – — Linux 5.19 – 6.1.185
TIMELINE Aug 26 Reserved by CNA Aug 29 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H N N 8.6 .0018 7.3 —
AFFECTED Product Versions Fixed Rest Routes unspecified —
TIMELINE Jul 17 Reserved by CNA Aug 29 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N L L 6.5 .0018 7.3 —
AFFECTED Product Versions Fixed HEL Online Classroom: AI-powered Online Classrooms unspecified —
TIMELINE Aug 20 Reserved by CNA Aug 29 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C L N N 4.1 .0016 5.1 —
AFFECTED Product Versions Fixed WP Ultimate CSV Importer unspecified —
TIMELINE Aug 26 Reserved by CNA Aug 29 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H R U H H H 6.8 .0015 4.7 —
AFFECTED Product Versions Fixed User Profile Builder 3.3.4 – —
TIMELINE Aug 19 Reserved by CNA Aug 29 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U L L N 4.8 .0015 4.4 —
AFFECTED Product Versions Fixed MasterStudy LMS WordPress Plugin unspecified —
TIMELINE Aug 26 Reserved by CNA Aug 29 Published (CNA: WPScan)
CVSS EPSS %ile KEV — .0015 4.2 —
AFFECTED Product Versions Fixed MemberHero unspecified —
TIMELINE Jun 1 Reserved by CNA Aug 29 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0014 4.1 —
AFFECTED Product Versions Fixed HEL Online Classroom: AI-powered Online Classrooms unspecified —
TIMELINE Aug 20 Reserved by CNA Aug 29 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0014 3.4 —
AFFECTED Product Versions Fixed Uix UserCenter unspecified —
TIMELINE Jul 20 Reserved by CNA Aug 29 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H L N 9.3 .0014 3.4 —
AFFECTED Product Versions Fixed 爱采集数据采集和发布插件 unspecified —
TIMELINE Aug 20 Reserved by CNA Aug 29 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0014 3.4 —
AFFECTED Product Versions Fixed Total processing card payments for WooCommerce unspecified —
TIMELINE Jul 24 Reserved by CNA Aug 29 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H N 7.5 .0014 3.4 —
AFFECTED Product Versions Fixed Appointment Booking Calendar Plugin and Scheduling Plugin 1.5.6 – —
TIMELINE Aug 19 Reserved by CNA Aug 29 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L L N 6.5 .0014 3.4 —
AFFECTED Product Versions Fixed HEL Online Classroom: AI-powered Online Classrooms unspecified —
TIMELINE Aug 20 Reserved by CNA Aug 29 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L N N 5.3 .0014 3.4 —
AFFECTED Product Versions Fixed Catfolders Document Gallery Pro 2.0.6 – —
TIMELINE Aug 10 Reserved by CNA Aug 29 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C L N N 4.7 .0014 3.4 —
AFFECTED Product Versions Fixed MasterStudy LMS WordPress Plugin unspecified —
TIMELINE Aug 26 Reserved by CNA Aug 29 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L H N 8.2 .0013 3.1 —
AFFECTED Product Versions Fixed User Profile Builder 3.8.1 – —
TIMELINE Aug 19 Reserved by CNA Aug 29 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H N N 7.7 .0013 3.1 —
AFFECTED Product Versions Fixed SmartAIPress unspecified —
TIMELINE Jul 22 Reserved by CNA Aug 29 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N H N 6.5 .0013 3.1 —
AFFECTED Product Versions Fixed MStore API unspecified —
TIMELINE Jul 29 Reserved by CNA Aug 29 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N H N 6.5 .0013 3.1 —
AFFECTED Product Versions Fixed MStore API unspecified —
TIMELINE Jul 29 Reserved by CNA Aug 29 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U N H N 4.9 .0013 3.1 —
AFFECTED Product Versions Fixed Rank Math SEO 1.0.271 – —
TIMELINE Aug 21 Reserved by CNA Aug 29 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N L N 4.3 .0013 3.1 —
AFFECTED Product Versions Fixed Stripe Payment Forms by WP Full Pay unspecified —
TIMELINE Aug 26 Reserved by CNA Aug 29 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N L N 4.3 .0013 3.1 —
AFFECTED Product Versions Fixed Frontend Admin by DynamiApps unspecified —
TIMELINE Aug 26 Reserved by CNA Aug 29 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U N L N 2.7 .0013 3.1 —
AFFECTED Product Versions Fixed Booking for Appointments and Events Calendar 1.2.32 – —
TIMELINE Aug 21 Reserved by CNA Aug 29 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U L N N 2.7 .0013 3.1 —
AFFECTED Product Versions Fixed MasterStudy LMS WordPress Plugin unspecified —
TIMELINE Aug 26 Reserved by CNA Aug 29 Published (CNA: WPScan)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-17520 | 4.8 | 0.9 | Unknown | Newsletters | CWE-326 | Newsletters < 4.17 - Unauthenticated API Access via Predictable API Key |
| CVE-2026-17522 | 5.4 | 0.8 | Unknown | Newsletters | CWE-352 | Newsletters < 4.17 - Arbitrary Plugin Option Update via CSRF |
| CVE-2026-41012 | 7.7 | 0.7 | Cloud Foundry | bosh-vsphere-cpi-release | CWE-295 | BOSH vSphere CPI Improper Cert Validation |
| CVE-2026-82456 | 10.0 | — | argoproj-labs | argocd-mcp | CWE-1327 | argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTP |
| CVE-2026-14494 | 9.8 | — | bdthemes | SigmaForms Pro – AI Generated Forms | CWE-434 | Sigma Forms Pro <= 1.4.5 - Unauthenticated Unauthenticated Arbitrary File Upl… |
| CVE-2026-15369 | 9.8 | — | Addify | Custom User Registration Fields for WooCommerce | CWE-269 | Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Pr… |
| CVE-2026-82466 | 9.4 | — | jeremyevans | rodauth | CWE-287 | Rodauth before 2.46.0 Authentication Bypass via webauthn_login |
| CVE-2026-82448 | 9.3 | — | Shinobi Systems | Shinobi | CWE-798 | Shinobi before commit 5a76c74f Arbitrary Database Query Execution via Hardcod… |
| CVE-2026-82452 | 9.3 | — | iot-ecology | rust-iot-platform | CWE-306 | rust-iot-platform Authentication Bypass via Missing Request Guards |
| CVE-2026-82454 | 9.3 | — | omnivore-app | omnivore | CWE-347 | Omnivore before android-0.227.0 Authentication Bypass via Apple Sign-in |
| CVE-2026-82460 | 9.3 | — | coderaiser | cloudcmd | CWE-22 | Cloud Commander before 19.20.2 Directory Traversal via REST and Markdown |
| CVE-2026-82473 | 8.8 | — | kubeedge | kubeedge | CWE-306 | KubeEdge CloudCore through 1.23.1 Missing Authentication on Node Task Endpoints |
| CVE-2026-82447 | 8.7 | — | Skyvern-AI | skyvern | CWE-1336 | Skyvern before 1.0.45 Sandbox Escape via TextPromptBlock |
| CVE-2026-82450 | 8.7 | — | bookstackapp | bookstack | CWE-434 | BookStack before 26.05.4 Remote Code Execution via Book Cover |
| CVE-2026-82453 | 8.7 | — | iot-ecology | rust-iot-platform | CWE-256 | rust-iot-platform Cleartext Password Storage via User Model |
| CVE-2026-82472 | 8.7 | — | documenso | documenso | CWE-306 | Documenso before 2.13.0 Unauthenticated File Upload via /api/files/upload-pdf |
| CVE-2026-82481 | 8.7 | — | mirage | cohttp | CWE-180 | The cohttp package before 6.3.0 for OCaml allows directory traversal. |
| CVE-2026-82461 | 8.6 | — | pac4j | pac4j | CWE-347 | pac4j-oidc before 6.5.6 Privilege Escalation via Unverified Keycloak Access T… |
| CVE-2026-82463 | 8.6 | — | pac4j | pac4j | CWE-863 | pac4j-core before 6.5.6 Authorization Bypass via Reversed Profile Type Check |
| CVE-2026-82475 | 8.6 | — | iflytek | astron-agent | CWE-862 | iFlytek astron-agent through 1.1.1 Workflow Hijacking via Missing Ownership C… |
| CVE-2026-82457 | 8.5 | — | ncopa | su-exec | CWE-681 | su-exec through 0.3 Privilege Escalation via Numeric User ID |
| CVE-2026-82474 | 8.5 | — | sudo-project | sudo | CWE-693 | Sudo through 1.9.17p2 Intercept Policy Bypass via execveat |
| CVE-2026-75807 | 7.5 | — | cyberlord92 | SAML Single Sign On – SSO Login | CWE-287 | SAML Single Sign On <= 5.4.6 - Unauthenticated Authentication Bypass via X.50… |
| CVE-2026-82449 | 6.9 | — | cockpit-hq | cockpit | CWE-208 | Cockpit CMS before 2.14.1 Account Enumeration via Auth Timing |
| CVE-2026-82455 | 6.9 | — | ruby | rubygems | CWE-59 | RubyGems before 4.0.13 Path Traversal via Symlink Resolution |
| CVE-2026-82462 | 6.9 | — | pac4j | pac4j | CWE-345 | pac4j-oidc before 6.5.6 Authentication Bypass via Access Token Substitution |
| CVE-2026-82465 | 6.9 | — | pac4j | pac4j | CWE-345 | pac4j-saml before 6.5.6 Session Destruction via Unsigned LogoutRequest |
| CVE-2026-82476 | 6.9 | — | usememos | memos | CWE-918 | Memos through 0.30.0 SSRF via Omitted CGNAT Address Range |
| CVE-2026-82417 | 6.3 | — | ljharb | qs | CWE-248 | qs.stringify throws TypeError on objects with a non-callable constructor.isBu… |
| CVE-2026-82562 | 6.3 | — | ljharb | qs | CWE-770 | qs.parse does not enforce arrayLimit on comma groups under bracket-push keys … |
| CVE-2026-82477 | 5.8 | — | MITRE | Heimdall | CWE-918 | In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allo… |
| CVE-2026-82451 | 5.3 | — | getformwork | Formwork | CWE-79 | Formwork through 2.3.14 Stored XSS via Referer Header |
| CVE-2026-82464 | 5.3 | — | pac4j | pac4j | CWE-601 | pac4j-core before 6.5.6 Open Redirect via Backslash Logout |
| CVE-2026-82469 | 5.1 | — | jeremyevans | rodauth | CWE-613 | Rodauth before 2.47.0 Authentication Bypass via jwt_refresh |
| CVE-2026-82470 | 5.1 | — | jeremyevans | rodauth | CWE-294 | Rodauth before 2.47.0 TOTP Code Reuse via Drift Window |
| CVE-2026-82467 | 4.9 | — | jeremyevans | rodauth | CWE-601 | Rodauth before 2.47.0 Open Redirect via Return-to Path |
| CVE-2026-82468 | 4.9 | — | jeremyevans | rodauth | CWE-352 | Rodauth before 2.47.0 CSRF Protection Bypass via Content-Type |
| CVE-2026-82364 | 2.3 | — | macrozheng | mall | CWE-362 | macrozheng mall Order Submission submit race condition |
| CVE-2026-82421 | 2.1 | — | itsourcecode | Sales and Inventory System | CWE-74 | itsourcecode Sales and Inventory System emp_edit.php sql injection |
| CVE-2026-82422 | 2.1 | — | itsourcecode | Sales and Inventory System | CWE-74 | itsourcecode Sales and Inventory System emp_del.php sql injection |
| CVE-2026-82423 | 2.1 | — | macrozheng | mall | CWE-840 | macrozheng mall Payment Status Endpoint paySuccess behavioral workflow |
| CVE-2026-82424 | 2.1 | — | PHPGurukul | Student Information System | CWE-74 | PHPGurukul Student Information System student_edit1.php sql injection |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-08-29 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.