boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Saturday, August 29, 2026 · all times UTC← 2026-08-28 · archive

Security Box Score — August 29, 2026

67 CVEs published, led by jeremyevans (5).

67 CVEs published August 29, 2026: 11 critical, 18 high, 29 medium, 7 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 2 awaiting enrichment. 25 rendered as box scores below; the remaining 42 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1184034279——
KEV catalog size1685

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2049 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux16453960418197263711230.17.8.0016+811 ▲
google4022164270842960757760.37.5.0026+281 ▲
microsoft4771899145128345714287281.57.8.0044-187 ▼
red hat2236164225428732200.06.7.0029+90 ▲
apple44316598516578882.56.5.0029-123 ▼
freebsd324823673000.07.8.0016+32 ▲
canonical15421311135000.07.8.0020+8 ▲
suse72851481000.07.7.0038-1 ▼
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco46842139240561315.57.5.0044+30 ▲
ubiquiti2359362210335.19.1.0049-2 ▼
palo alto networks12371321121325.44.7.0020-2 ▼
netgear93200275000.04.3.0025+3 ▲
fortinet7307814128620.07.0.0050-7 ▼
vmware21959327210.58.3.0040-6 ▼
f50175930415.98.7.0057-8 ▼
sonicwall1214374017214.37.8.0024+10 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache159496102216164133320.47.5.0049-6 ▼
mozilla591866868500900.08.1.0030-12 ▼
gitlab2576218479422.65.3.0028+5 ▲
drupal1768107465411.55.9.0024-29 ▼
github5171790000.06.6.0043-1 ▼
docker290630000.07.2.0016+2 ▲
wordpress2513102240.08.8.3120-1 ▼
kubernetes010001000.02.4.0035-1 ▼
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle89022694841170519962840.27.8.0034-219 ▼
ibm3906191482861778610.27.6.0030+320 ▲
adobe1016065030024791930.57.8.0021-4 ▼
progress19611437100611.68.1.0037-14 ▼
solarwinds0231733010417.49.1.0058-15 ▼
veeam131961030100.08.6.0032+12 ▲
zohocorp4103520000.08.7.0140+1 ▲
atlassian3615001300.08.1.00320
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
siemens213722483000.07.3.0016+14 ▲
d-link163615597300.07.4.0157+8 ▲
synology42736153000.05.6.0025+4 ▲
rockwell automation12541740000.08.4.0024-16 ▼
schneider electric091620000.08.6.0037-3 ▼
abb070430000.07.2.0018-1 ▼
hikvision060420000.07.2.0040-5 ▼
mitsubishi electric050410000.07.2.00520
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring911709538616000.06.4.0022+91 ▲
dell711701190645210.67.2.0019+28 ▲
sourcecodester48168009276000.05.5.0029-1 ▼
nvidia521341688300000.07.8.0034+9 ▲
splunk110128647705110.86.5.0025+107 ▲
openclaw01110583914000.07.0.0026-44 ▼
zephyrproject521053335712000.06.4.0021+26 ▲
getgrav661041559282000.08.4.0032+28 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.995799.99.8
CVE-2026-34486.986299.97.5
CVE-2026-63077.877199.89.8
CVE-2026-60004.845599.79.8
CVE-2026-72898.792299.610.0
CVE-2026-18577.540799.08.2
CVE-2026-18556.401698.68.2
CVE-2026-64638.312098.28.9
CVE-2026-71362.251497.89.1
CVE-2026-73570.205397.48.9
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.7922KEV
CVE-2026-4836210.0.0431
CVE-2026-1918810.0.0193
CVE-2026-5823110.0.0171
CVE-2026-6983610.0.0155
CVE-2026-7619510.0.0147
CVE-2026-7619710.0.0147
CVE-2026-7329910.0.0121
CVE-2026-7367810.0.0114
CVE-2026-7755410.0.0099
Most disclosures (vendor)
VendorCVEs
linux1645
oracle890
microsoft477
google407
ibm390
red hat239
apache162
splunk110
adobe102
spring91
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco13
apple8
fortinet6
google6
ivanti5
oracle4
solarwinds4
adobe3
berriai3
Most-affected ecosystems
EcosystemAdvisories
Maven53
Packagist28
npm14
PyPI13
Go1
Fastest to KEV
CVEVendorDays
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20349Cisco0
CVE-2026-34486Apache Software Foundation0
CVE-2026-63077JetBrains0
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
CVE-2026-72898Metabase0
CVE-2026-8037Progress Software0
CVE-2026-64849mlflow1
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171746
CVE-2021-27102n/a2021-11-171746
CVE-2021-27101n/a2021-11-171746
CVE-2021-27103n/a2021-11-171746
CVE-2021-21017Adobe2021-11-171746
CVE-2021-28550Adobe2021-11-171746
CVE-2021-42013Apache Software Foundation2021-11-171746
CVE-2021-41773Apache Software Foundation2021-11-171746
CVE-2021-30858Apple2021-11-171746
CVE-2021-30860Apple2021-11-171746

Transactions

EXPLOIT PUBLISHED — dolibarr: 9 CVEs (CVE-2026-71503, CVE-2026-71504, CVE-2026-71505, CVE-2026-71506, CVE-2026-71507, CVE-2026-71508, CVE-2026-71509, CVE-2026-71510, CVE-2026-71511). Public exploit references added.

EXPLOIT PUBLISHED — rocq-prover rocq: 3 CVEs (CVE-2026-72703, CVE-2026-72704, CVE-2026-72705). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-10036 (speechbrain). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56100 (SpringBlade). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-65053 (horde imp). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-72711 (leanprover lean4). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-77939 (flextype). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78122 (Tecnativa docker-socket-proxy). Public exploit reference added.

DUE DATE PASSED — CVE-2026-60004 (Gitea). CISA remediation deadline was August 28, 2026; still in catalog.

Yesterday's Results

How to read these box scores · glossary

67 CVEs published. 25 box scores, 42 table rows — nothing truncated.

Unknown User Profile Builder — Profile Builder < 4.0.1 - Admin+ PHP Object Injection via Import/Export
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  H  H  H    6.6   .0023   13.5     —
AFFECTED
  Product               Versions  Fixed
  User Profile Builder  3.3.4 –   —
TIMELINE
  Aug 19  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-502 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
CVE-2026-80725AWAITING ENRICHMENT
Linux Linux — net: gro: properly validate BIG TCP aggregation criteria
  CVSS   EPSS    %ile   KEV
  —      .0019   8.8    —
AFFECTED
  Product  Versions                                    Fixed
  Linux    0fe79f28bfaf73b66b7b1562d2468f94aa03bd12 –  —
  Linux    5.19 –                                      6.1.185
TIMELINE
  Aug 26  Reserved by CNA
  Aug 29  Published (CNA: Linux)
CNA: Linux · 5 references · NVD status: Received
Unknown Rest Routes — Rest Routes <= 5.5.5 - Unauthenticated SQLi via custom-tables/tables/{table_name}
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  N  N    8.6   .0018    7.3     —
AFFECTED
  Product      Versions     Fixed
  Rest Routes  unspecified  —
TIMELINE
  Jul 17  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-89 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown HEL Online Classroom: AI-powered Online Classrooms — HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Plugin Settings Update
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  L    6.5   .0018    7.3     —
AFFECTED
  Product                                             Versions     Fixed
  HEL Online Classroom: AI-powered Online Classrooms  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-284 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown WP Ultimate CSV Importer — WP Ultimate CSV Importer < 9.0 - Admin+ SQLi via AIOSEO Import Fields
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  L  N  N    4.1   .0016    5.1     —
AFFECTED
  Product                   Versions     Fixed
  WP Ultimate CSV Importer  unspecified  —
TIMELINE
  Aug 26  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-89 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown User Profile Builder — Profile Builder < 4.0.1 - Contributor+ Stored XSS via Format Date Shortcode
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   R  U  H  H  H    6.8   .0015    4.7     —
AFFECTED
  Product               Versions  Fixed
  User Profile Builder  3.3.4 –   —
TIMELINE
  Aug 19  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-79 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown MasterStudy LMS WordPress Plugin — MasterStudy LMS < 3.7.40 - Unauthenticated Payment Bypass via PayPal IPN
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  L  L  N    4.8   .0015    4.4     —
AFFECTED
  Product                           Versions     Fixed
  MasterStudy LMS WordPress Plugin  unspecified  —
TIMELINE
  Aug 26  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-284 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
CVE-2026-10522AWAITING ENRICHMENT
Unknown MemberHero — Simple User Registration <= 6.9 - Unauthenticated Privilege Escalation to Administrator
  CVSS   EPSS    %ile   KEV
  —      .0015   4.2    —
AFFECTED
  Product     Versions     Fixed
  MemberHero  unspecified  —
TIMELINE
  Jun 1   Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CNA: WPScan · 1 reference · NVD status: Received
Unknown HEL Online Classroom: AI-powered Online Classrooms — HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated BigBlueButton API Secret Disclosure
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0014    4.1     —
AFFECTED
  Product                                             Versions     Fixed
  HEL Online Classroom: AI-powered Online Classrooms  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-200 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown Uix UserCenter — Uix UserCenter <= 1.0.3 - Unauthenticated Privilege Escalation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0014    3.4     —
AFFECTED
  Product         Versions     Fixed
  Uix UserCenter  unspecified  —
TIMELINE
  Jul 20  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-269 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown 爱采集数据采集和发布插件 — Icollect <= 1.0.0 - Unauthenticated Arbitrary File Read, SSRF and Path Traversal File Write via Default Publishing Password
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  L  N    9.3   .0014    3.4     —
AFFECTED
  Product       Versions     Fixed
  爱采集数据采集和发布插件  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-918 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown Total processing card payments for WooCommerce — Total Processing Card Payments for WooCommerce <= 7.3 - Unauthenticated SSRF leading to Payment Bypass and Gateway Credential Disclosure
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0014    3.4     —
AFFECTED
  Product                                         Versions     Fixed
  Total processing card payments for WooCommerce  unspecified  —
TIMELINE
  Jul 24  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-918 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown Appointment Booking Calendar Plugin and Scheduling Plugin — BookingPress 1.5.6 - 1.6.2 - Unauthenticated Booking Price Manipulation via PayPal Payment Confirmation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  N    7.5   .0014    3.4     —
AFFECTED
  Product                                                    Versions  Fixed
  Appointment Booking Calendar Plugin and Scheduling Plugin  1.5.6 –   —
TIMELINE
  Aug 19  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-284 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown HEL Online Classroom: AI-powered Online Classrooms — HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Moderator Join URL Disclosure and Class Access Code Bypass
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  N    6.5   .0014    3.4     —
AFFECTED
  Product                                             Versions     Fixed
  HEL Online Classroom: AI-powered Online Classrooms  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-284 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown Catfolders Document Gallery Pro — CatFolders Document Gallery Pro < 2.0.7 - Unauthenticated Missing Authorization via download-all
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0014    3.4     —
AFFECTED
  Product                          Versions  Fixed
  Catfolders Document Gallery Pro  2.0.6 –   —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-862 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown MasterStudy LMS WordPress Plugin — MasterStudy LMS < 3.7.43 - Unauthenticated Open Redirect
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  N  N    4.7   .0014    3.4     —
AFFECTED
  Product                           Versions     Fixed
  MasterStudy LMS WordPress Plugin  unspecified  —
TIMELINE
  Aug 26  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-601 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown User Profile Builder — Profile Builder < 4.0.1 - Unauthenticated Unpublished Content and Media Modification via Front-End Upload Auth Bypass
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  H  N    8.2   .0013    3.1     —
AFFECTED
  Product               Versions  Fixed
  User Profile Builder  3.8.1 –   —
TIMELINE
  Aug 19  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-287 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown SmartAIPress — SmartAIPress <= 1.2.0 - Subscriber+ Server-Side Request Forgery via smartaipress_openai_upload_and_set_featured_image
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  N  N    7.7   .0013    3.1     —
AFFECTED
  Product       Versions     Fixed
  SmartAIPress  unspecified  —
TIMELINE
  Jul 22  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-918 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown MStore API — MStore API < 4.21.1 - Subscriber+ Arbitrary Order Completion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  N    6.5   .0013    3.1     —
AFFECTED
  Product     Versions     Fixed
  MStore API  unspecified  —
TIMELINE
  Jul 29  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-862 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown MStore API — MStore API < 4.21.1 - Subscriber+ Arbitrary Order Payment Bypass via Wallet
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  N    6.5   .0013    3.1     —
AFFECTED
  Product     Versions     Fixed
  MStore API  unspecified  —
TIMELINE
  Jul 29  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-862 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown Rank Math SEO — Rank Math SEO < 1.0.277 - Editor+ Core Settings Modification via fix-site-seo Ability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  N  H  N    4.9   .0013    3.1     —
AFFECTED
  Product        Versions   Fixed
  Rank Math SEO  1.0.271 –  —
TIMELINE
  Aug 21  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-863 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown Stripe Payment Forms by WP Full Pay — Stripe Payment Forms by WP Full Pay < 8.5.5 - Cross-Customer Subscription Cancellation via IDOR
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  N    4.3   .0013    3.1     —
AFFECTED
  Product                              Versions     Fixed
  Stripe Payment Forms by WP Full Pay  unspecified  —
TIMELINE
  Aug 26  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-639 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown Frontend Admin by DynamiApps — Frontend Admin by DynamiApps < 3.29.11 - Subscriber+ Arbitrary Membership Plan Deletion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  N    4.3   .0013    3.1     —
AFFECTED
  Product                       Versions     Fixed
  Frontend Admin by DynamiApps  unspecified  —
TIMELINE
  Aug 26  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-862 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown Booking for Appointments and Events Calendar — Amelia 1.2.32 - 2.4.8 - Amelia Customer+ Appointment Status Update and Self-Approval
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  N  L  N    2.7   .0013    3.1     —
AFFECTED
  Product                                       Versions  Fixed
  Booking for Appointments and Events Calendar  1.2.32 –  —
TIMELINE
  Aug 21  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-863 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown MasterStudy LMS WordPress Plugin — MasterStudy LMS < 3.7.42 - Instructor+ Cross-Tenant Order Billing PII Disclosure via IDOR
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  L  N  N    2.7   .0013    3.1     —
AFFECTED
  Product                           Versions     Fixed
  MasterStudy LMS WordPress Plugin  unspecified  —
TIMELINE
  Aug 26  Reserved by CNA
  Aug 29  Published (CNA: WPScan)
CWE-639 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-175204.80.9UnknownNewslettersCWE-326Newsletters < 4.17 - Unauthenticated API Access via Predictable API Key
CVE-2026-175225.40.8UnknownNewslettersCWE-352Newsletters < 4.17 - Arbitrary Plugin Option Update via CSRF
CVE-2026-410127.70.7Cloud Foundrybosh-vsphere-cpi-releaseCWE-295BOSH vSphere CPI Improper Cert Validation
CVE-2026-8245610.0—argoproj-labsargocd-mcpCWE-1327argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTP
CVE-2026-144949.8—bdthemesSigmaForms Pro – AI Generated FormsCWE-434Sigma Forms Pro <= 1.4.5 - Unauthenticated Unauthenticated Arbitrary File Upl…
CVE-2026-153699.8—AddifyCustom User Registration Fields for WooCommerceCWE-269Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Pr…
CVE-2026-824669.4—jeremyevansrodauthCWE-287Rodauth before 2.46.0 Authentication Bypass via webauthn_login
CVE-2026-824489.3—Shinobi SystemsShinobiCWE-798Shinobi before commit 5a76c74f Arbitrary Database Query Execution via Hardcod…
CVE-2026-824529.3—iot-ecologyrust-iot-platformCWE-306rust-iot-platform Authentication Bypass via Missing Request Guards
CVE-2026-824549.3—omnivore-appomnivoreCWE-347Omnivore before android-0.227.0 Authentication Bypass via Apple Sign-in
CVE-2026-824609.3—coderaisercloudcmdCWE-22Cloud Commander before 19.20.2 Directory Traversal via REST and Markdown
CVE-2026-824738.8—kubeedgekubeedgeCWE-306KubeEdge CloudCore through 1.23.1 Missing Authentication on Node Task Endpoints
CVE-2026-824478.7—Skyvern-AIskyvernCWE-1336Skyvern before 1.0.45 Sandbox Escape via TextPromptBlock
CVE-2026-824508.7—bookstackappbookstackCWE-434BookStack before 26.05.4 Remote Code Execution via Book Cover
CVE-2026-824538.7—iot-ecologyrust-iot-platformCWE-256rust-iot-platform Cleartext Password Storage via User Model
CVE-2026-824728.7—documensodocumensoCWE-306Documenso before 2.13.0 Unauthenticated File Upload via /api/files/upload-pdf
CVE-2026-824818.7—miragecohttpCWE-180The cohttp package before 6.3.0 for OCaml allows directory traversal.
CVE-2026-824618.6—pac4jpac4jCWE-347pac4j-oidc before 6.5.6 Privilege Escalation via Unverified Keycloak Access T…
CVE-2026-824638.6—pac4jpac4jCWE-863pac4j-core before 6.5.6 Authorization Bypass via Reversed Profile Type Check
CVE-2026-824758.6—iflytekastron-agentCWE-862iFlytek astron-agent through 1.1.1 Workflow Hijacking via Missing Ownership C…
CVE-2026-824578.5—ncopasu-execCWE-681su-exec through 0.3 Privilege Escalation via Numeric User ID
CVE-2026-824748.5—sudo-projectsudoCWE-693Sudo through 1.9.17p2 Intercept Policy Bypass via execveat
CVE-2026-758077.5—cyberlord92SAML Single Sign On – SSO LoginCWE-287SAML Single Sign On <= 5.4.6 - Unauthenticated Authentication Bypass via X.50…
CVE-2026-824496.9—cockpit-hqcockpitCWE-208Cockpit CMS before 2.14.1 Account Enumeration via Auth Timing
CVE-2026-824556.9—rubyrubygemsCWE-59RubyGems before 4.0.13 Path Traversal via Symlink Resolution
CVE-2026-824626.9—pac4jpac4jCWE-345pac4j-oidc before 6.5.6 Authentication Bypass via Access Token Substitution
CVE-2026-824656.9—pac4jpac4jCWE-345pac4j-saml before 6.5.6 Session Destruction via Unsigned LogoutRequest
CVE-2026-824766.9—usememosmemosCWE-918Memos through 0.30.0 SSRF via Omitted CGNAT Address Range
CVE-2026-824176.3—ljharbqsCWE-248qs.stringify throws TypeError on objects with a non-callable constructor.isBu…
CVE-2026-825626.3—ljharbqsCWE-770qs.parse does not enforce arrayLimit on comma groups under bracket-push keys …
CVE-2026-824775.8—MITREHeimdallCWE-918In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allo…
CVE-2026-824515.3—getformworkFormworkCWE-79Formwork through 2.3.14 Stored XSS via Referer Header
CVE-2026-824645.3—pac4jpac4jCWE-601pac4j-core before 6.5.6 Open Redirect via Backslash Logout
CVE-2026-824695.1—jeremyevansrodauthCWE-613Rodauth before 2.47.0 Authentication Bypass via jwt_refresh
CVE-2026-824705.1—jeremyevansrodauthCWE-294Rodauth before 2.47.0 TOTP Code Reuse via Drift Window
CVE-2026-824674.9—jeremyevansrodauthCWE-601Rodauth before 2.47.0 Open Redirect via Return-to Path
CVE-2026-824684.9—jeremyevansrodauthCWE-352Rodauth before 2.47.0 CSRF Protection Bypass via Content-Type
CVE-2026-823642.3—macrozhengmallCWE-362macrozheng mall Order Submission submit race condition
CVE-2026-824212.1—itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System emp_edit.php sql injection
CVE-2026-824222.1—itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System emp_del.php sql injection
CVE-2026-824232.1—macrozhengmallCWE-840macrozheng mall Payment Status Endpoint paySuccess behavioral workflow
CVE-2026-824242.1—PHPGurukulStudent Information SystemCWE-74PHPGurukul Student Information System student_edit1.php sql injection

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-29 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.