AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0045 37.7 —
AFFECTED Product Versions Fixed MyHome Core unspecified —
TIMELINE Jul 16 Reserved by CNA Aug 30 Published (CNA: Wordfence)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
92 CVEs published, led by ash-project (20).
92 CVEs published August 30, 2026: 6 critical, 19 high, 32 medium, 28 low; 0 in the KEV catalog at press time; 3 with a public exploit reference; 7 awaiting enrichment. 25 rendered as box scores below; the remaining 67 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 11932 | 34373 | — | — |
| KEV catalog size | 1685 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
2062 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 1645 | 3960 | 418 | 1972 | 637 | 1 | 12 | 3 | 0.1 | 7.8 | .0016 | +810 ▲ |
| 402 | 2164 | 270 | 842 | 960 | 75 | 77 | 6 | 0.3 | 7.5 | .0026 | -89 ▼ | |
| microsoft | 477 | 1899 | 145 | 1283 | 457 | 14 | 287 | 28 | 1.5 | 7.8 | .0044 | -188 ▼ |
| red hat | 223 | 617 | 42 | 254 | 288 | 32 | 2 | 0 | 0.0 | 6.7 | .0029 | +75 ▲ |
| apple | 44 | 316 | 59 | 85 | 165 | 7 | 88 | 8 | 2.5 | 6.5 | .0029 | -123 ▼ |
| freebsd | 32 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | +32 ▲ |
| canonical | 15 | 42 | 13 | 11 | 13 | 5 | 0 | 0 | 0.0 | 7.8 | .0020 | +8 ▲ |
| suse | 7 | 28 | 5 | 14 | 8 | 1 | 0 | 0 | 0.0 | 7.7 | .0038 | -1 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 46 | 84 | 21 | 39 | 24 | 0 | 56 | 13 | 15.5 | 7.5 | .0044 | +30 ▲ |
| ubiquiti | 23 | 59 | 36 | 22 | 1 | 0 | 3 | 3 | 5.1 | 9.1 | .0049 | -2 ▼ |
| palo alto networks | 12 | 37 | 1 | 3 | 21 | 12 | 13 | 2 | 5.4 | 4.7 | .0020 | -2 ▼ |
| netgear | 9 | 32 | 0 | 0 | 27 | 5 | 0 | 0 | 0.0 | 4.3 | .0025 | +3 ▲ |
| fortinet | 7 | 30 | 7 | 8 | 14 | 1 | 28 | 6 | 20.0 | 7.0 | .0050 | -7 ▼ |
| vmware | 2 | 19 | 5 | 9 | 3 | 2 | 7 | 2 | 10.5 | 8.3 | .0040 | -11 ▼ |
| f5 | 0 | 17 | 5 | 9 | 3 | 0 | 4 | 1 | 5.9 | 8.7 | .0057 | -8 ▼ |
| sonicwall | 12 | 14 | 3 | 7 | 4 | 0 | 17 | 2 | 14.3 | 7.8 | .0024 | +10 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 159 | 496 | 102 | 216 | 164 | 13 | 33 | 2 | 0.4 | 7.5 | .0049 | -19 ▼ |
| mozilla | 59 | 186 | 68 | 68 | 50 | 0 | 9 | 0 | 0.0 | 8.1 | .0030 | -12 ▼ |
| gitlab | 25 | 76 | 2 | 18 | 47 | 9 | 4 | 2 | 2.6 | 5.3 | .0028 | +5 ▲ |
| drupal | 17 | 68 | 10 | 7 | 46 | 5 | 4 | 1 | 1.5 | 5.9 | .0024 | -29 ▼ |
| github | 5 | 17 | 1 | 7 | 9 | 0 | 0 | 0 | 0.0 | 6.6 | .0044 | -1 ▼ |
| docker | 2 | 9 | 0 | 6 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0016 | +2 ▲ |
| wordpress | 2 | 5 | 1 | 3 | 1 | 0 | 2 | 2 | 40.0 | 8.8 | .3120 | -1 ▼ |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0035 | -1 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 890 | 2269 | 484 | 1170 | 519 | 96 | 28 | 4 | 0.2 | 7.8 | .0034 | -219 ▼ |
| ibm | 390 | 619 | 148 | 286 | 177 | 8 | 6 | 1 | 0.2 | 7.6 | .0030 | +285 ▲ |
| adobe | 101 | 606 | 50 | 300 | 247 | 9 | 19 | 3 | 0.5 | 7.8 | .0021 | -6 ▼ |
| progress | 19 | 61 | 14 | 37 | 10 | 0 | 6 | 1 | 1.6 | 8.1 | .0037 | -14 ▼ |
| solarwinds | 0 | 23 | 17 | 3 | 3 | 0 | 10 | 4 | 17.4 | 9.1 | .0058 | -16 ▼ |
| veeam | 13 | 19 | 6 | 10 | 3 | 0 | 1 | 0 | 0.0 | 8.6 | .0032 | +11 ▲ |
| zohocorp | 4 | 10 | 3 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0140 | +1 ▲ |
| atlassian | 3 | 6 | 1 | 5 | 0 | 0 | 13 | 0 | 0.0 | 8.1 | .0032 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 19 | 39 | 16 | 6 | 10 | 7 | 3 | 0 | 0.0 | 7.4 | .0157 | +11 ▲ |
| siemens | 21 | 37 | 2 | 24 | 8 | 3 | 0 | 0 | 0.0 | 7.3 | .0016 | +14 ▲ |
| synology | 4 | 27 | 3 | 6 | 15 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +4 ▲ |
| rockwell automation | 1 | 25 | 4 | 17 | 4 | 0 | 0 | 0 | 0.0 | 8.4 | .0024 | -16 ▼ |
| schneider electric | 0 | 9 | 1 | 6 | 2 | 0 | 0 | 0 | 0.0 | 8.6 | .0037 | -3 ▼ |
| abb | 0 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -1 ▼ |
| hikvision | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0040 | -5 ▼ |
| mitsubishi electric | 0 | 5 | 0 | 4 | 1 | 0 | 0 | 0 | 0.0 | 7.2 | .0052 | -1 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| spring | 91 | 170 | 9 | 53 | 86 | 16 | 0 | 0 | 0.0 | 6.4 | .0022 | +85 ▲ |
| dell | 71 | 170 | 11 | 90 | 64 | 5 | 2 | 1 | 0.6 | 7.2 | .0019 | +28 ▲ |
| sourcecodester | 49 | 169 | 0 | 0 | 92 | 77 | 0 | 0 | 0.0 | 5.5 | .0029 | 0 |
| nvidia | 52 | 134 | 16 | 88 | 30 | 0 | 0 | 0 | 0.0 | 7.8 | .0034 | +9 ▲ |
| splunk | 110 | 128 | 6 | 47 | 70 | 5 | 1 | 1 | 0.8 | 6.5 | .0025 | +107 ▲ |
| openclaw | 0 | 111 | 0 | 58 | 39 | 14 | 0 | 0 | 0.0 | 7.0 | .0026 | -44 ▼ |
| itsourcecode | 37 | 108 | 0 | 0 | 26 | 82 | 0 | 0 | 0.0 | 2.1 | .0027 | +19 ▲ |
| zephyrproject | 52 | 105 | 3 | 33 | 57 | 12 | 0 | 0 | 0.0 | 6.4 | .0021 | +26 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-8037 | .9957 | 99.9 | 9.8 |
| CVE-2026-34486 | .9862 | 99.9 | 7.5 |
| CVE-2026-63077 | .8771 | 99.7 | 9.8 |
| CVE-2026-60004 | .8455 | 99.7 | 9.8 |
| CVE-2026-72898 | .7922 | 99.6 | 10.0 |
| CVE-2026-18577 | .5407 | 98.9 | 8.2 |
| CVE-2026-18556 | .4016 | 98.5 | 8.2 |
| CVE-2026-64638 | .3120 | 98.1 | 8.9 |
| CVE-2026-71362 | .2514 | 97.8 | 9.1 |
| CVE-2026-73570 | .2053 | 97.3 | 8.9 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-72898 | 10.0 | .7922 | KEV |
| CVE-2026-48362 | 10.0 | .0431 | |
| CVE-2026-19188 | 10.0 | .0193 | |
| CVE-2026-58231 | 10.0 | .0171 | |
| CVE-2026-69836 | 10.0 | .0155 | |
| CVE-2026-76195 | 10.0 | .0147 | |
| CVE-2026-76197 | 10.0 | .0147 | |
| CVE-2026-73299 | 10.0 | .0121 | |
| CVE-2026-73678 | 10.0 | .0114 | |
| CVE-2026-77554 | 10.0 | .0099 |
| Vendor | CVEs |
|---|---|
| linux | 1645 |
| oracle | 890 |
| microsoft | 477 |
| 402 | |
| ibm | 390 |
| red hat | 223 |
| apache | 159 |
| splunk | 110 |
| adobe | 101 |
| spring | 91 |
| Vendor | KEV |
|---|---|
| microsoft | 28 |
| cisco | 13 |
| apple | 8 |
| fortinet | 6 |
| 6 | |
| ivanti | 5 |
| oracle | 4 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 51 |
| Packagist | 28 |
| npm | 14 |
| PyPI | 13 |
| Go | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-18556 | N-able | 0 |
| CVE-2026-18577 | N-able | 0 |
| CVE-2026-20349 | Cisco | 0 |
| CVE-2026-34486 | Apache Software Foundation | 0 |
| CVE-2026-63077 | JetBrains | 0 |
| CVE-2026-72529 | TrueConf | 0 |
| CVE-2026-72530 | TrueConf | 0 |
| CVE-2026-72898 | Metabase | 0 |
| CVE-2026-8037 | Progress Software | 0 |
| CVE-2026-64849 | mlflow | 1 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1747 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1747 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1747 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1747 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1747 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1747 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1747 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1747 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1747 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1747 |
EXPLOIT PUBLISHED — Unknown HEL Online Classroom: AI-powered Online Classrooms: 3 CVEs (CVE-2026-77007, CVE-2026-77008, CVE-2026-77010). Public exploit references added.
EXPLOIT PUBLISHED — Unknown MasterStudy LMS WordPress Plugin: 3 CVEs (CVE-2026-81026, CVE-2026-81200, CVE-2026-81342). Public exploit references added.
EXPLOIT PUBLISHED — Unknown User Profile Builder: 3 CVEs (CVE-2026-76546, CVE-2026-76547, CVE-2026-76548). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2026-11819 (Red Hat Enterprise Linux 10). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-12965 (Unknown Super Store Finder WordPress). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16061 (Unknown Rest Routes). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16259 (Unknown Uix UserCenter). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16600 (Unknown SmartAIPress). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16739 (Unknown Epeken All Kurir for Woocommerce). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16947 (Unknown Total processing card payments for WooCommerce). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17520 (Unknown Newsletters). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17522 (Unknown Newsletters). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18233 (Unknown MStore API). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18234 (Unknown MStore API). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19430 (Unknown Catfolders Document Gallery Pro). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-76586 (Unknown Appointment Booking Calendar Plugin and Scheduling Plugin). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-77012 (Unknown 爱采集数据采集和发布插件). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-77704 (Unknown Booking for Appointments and Events Calendar). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-77786 (Unknown Rank Math SEO). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-80311 (Unknown Stripe Payment Forms by WP Full Pay). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-80488 (Unknown WP Ultimate CSV Importer). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-81346 (Unknown Frontend Admin by DynamiApps). Public exploit reference added.
DUE DATE PASSED — CVE-2019-1068 (Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)). CISA remediation deadline was August 29, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-8452 (NetScaler ADC). CISA remediation deadline was August 29, 2026; still in catalog.
PATCH SHIPPED — CVE-2026-14324 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:1.4.11-1.el10_2.1.
PATCH SHIPPED — CVE-2026-14330 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 0:1.4.11-1.el9_8.2.
PATCH SHIPPED — CVE-2026-71217 (Red Hat Enterprise Linux 8). Fixed in Red Hat Enterprise Linux 8 0:3.5-12.el8_10.1.
How to read these box scores · glossary
92 CVEs published. 25 box scores, 67 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0045 37.7 —
AFFECTED Product Versions Fixed MyHome Core unspecified —
TIMELINE Jul 16 Reserved by CNA Aug 30 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 6.9 .0033 25.6 —
AFFECTED Product Versions Fixed Trick 19.6.0 – —
TIMELINE Aug 29 Reserved by CNA Aug 30 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV A L N N N L L L 5.3 .0025 16.7 —
AFFECTED Product Versions Fixed cFS 7.0.0 – —
TIMELINE Aug 29 Reserved by CNA Aug 30 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 5.3 .0022 12.9 —
AFFECTED Product Versions Fixed cFS 7.0.0 – —
TIMELINE Aug 29 Reserved by CNA Aug 30 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0020 9.9 —
AFFECTED Product Versions Fixed Sales and Inventory System 1.0 – —
TIMELINE Aug 29 Reserved by CNA Aug 30 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0020 9.9 —
AFFECTED Product Versions Fixed Sales and Inventory System 1.0 – —
TIMELINE Aug 29 Reserved by CNA Aug 30 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L P N L N 2.0 .0020 9.7 —
AFFECTED Product Versions Fixed Coppermine Photo Gallery 1.6.0 – 1.6.29
TIMELINE Aug 29 Reserved by CNA Aug 30 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L P N L N 2.0 .0020 9.7 —
AFFECTED Product Versions Fixed Coppermine Photo Gallery 1.6.0 – 1.6.29
TIMELINE Aug 29 Reserved by CNA Aug 30 Published (CNA: VulDB)
CVSS EPSS %ile KEV — .0017 6.8 —
AFFECTED Product Versions Fixed geotargetingwp unspecified —
TIMELINE Jul 1 Reserved by CNA Aug 30 Published (CNA: WPScan)
CVSS EPSS %ile KEV — .0017 6.7 —
AFFECTED Product Versions Fixed WPvivid — Backup, Migration & Staging unspecified —
TIMELINE Aug 13 Reserved by CNA Aug 30 Published (CNA: WPScan)
CVSS EPSS %ile KEV — .0017 6.8 —
AFFECTED Product Versions Fixed Customer Reviews for WooCommerce unspecified —
TIMELINE Aug 19 Reserved by CNA Aug 30 Published (CNA: WPScan)
CVSS EPSS %ile KEV — .0017 6.8 —
AFFECTED Product Versions Fixed Groundhogg — CRM, Newsletters, and Marketing Automation unspecified —
TIMELINE Aug 27 Reserved by CNA Aug 30 Published (CNA: WPScan)
CVSS EPSS %ile KEV — .0015 4.7 —
AFFECTED Product Versions Fixed SOGO Add Script to Individual Pages Header Footer unspecified —
TIMELINE Jul 6 Reserved by CNA Aug 30 Published (CNA: WPScan)
CVSS EPSS %ile KEV — .0015 4.7 —
AFFECTED Product Versions Fixed MW WP Form unspecified —
TIMELINE Aug 24 Reserved by CNA Aug 30 Published (CNA: WPScan)
CVSS EPSS %ile KEV — .0015 4.3 —
AFFECTED Product Versions Fixed Really Simple Security unspecified —
TIMELINE Aug 27 Reserved by CNA Aug 30 Published (CNA: WPScan)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L P N N L N N 2.1 .0014 3.5 —
AFFECTED Product Versions Fixed ash_sqlite 0.1.2-rc.0 – — ash_sqlite c12be48a5b6295593199b0e445b70a4aef81d1cd – —
TIMELINE Aug 30 Reserved by CNA Aug 30 Published (CNA: EEF)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L P N N N N L 2.1 .0014 3.5 —
AFFECTED Product Versions Fixed ash_paper_trail 0.1.1 – — ash_paper_trail 449cd2a93416853066378fa61c715e89f80dc854 – —
TIMELINE Aug 27 Reserved by CNA Aug 30 Published (CNA: EEF)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N P H H N 7.6 .0014 3.3 —
AFFECTED Product Versions Fixed oidcc 3.2.0-beta.1 – — oidcc 37a1361f704889816db2873f72d744d63ec39568 – —
TIMELINE Aug 21 Reserved by CNA Aug 30 Published (CNA: EEF)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L P N N H N N 5.9 .0010 0.8 —
AFFECTED Product Versions Fixed ash_paper_trail 0.1.1 – — ash_paper_trail e379ca90a0c4db54d07a9d1556fd12f2413f6e98 – —
TIMELINE Aug 20 Reserved by CNA Aug 30 Published (CNA: EEF)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L P N N H N N 5.9 .0010 0.8 —
AFFECTED Product Versions Fixed ash_paper_trail 0.3.0 – — ash_paper_trail ffe5e03b14d26b73bff17f3eca811591788aba9c – —
TIMELINE Aug 24 Reserved by CNA Aug 30 Published (CNA: EEF)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 9.4 — — —
AFFECTED Product Versions Fixed DIR-825M 1.1.8 – —
TIMELINE Aug 30 Reserved by CNA Aug 30 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 — — —
AFFECTED Product Versions Fixed HG10 300001138 – —
TIMELINE Aug 29 Reserved by CNA Aug 30 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L P H H L 9.3 — — —
AFFECTED Product Versions Fixed siyuan unspecified 3.8.1
TIMELINE Aug 30 Reserved by CNA Aug 30 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L P H H L 9.3 — — —
AFFECTED Product Versions Fixed siyuan unspecified 3.8.1
TIMELINE Aug 30 Reserved by CNA Aug 30 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 9.2 — — —
AFFECTED Product Versions Fixed AVideo unspecified —
TIMELINE Aug 30 Reserved by CNA Aug 30 Published (CNA: VulnCheck)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-82635 | 8.8 | — | tw93 | Pake | CWE-22 | Pake arbitrary file write via unsanitized download_file filename |
| CVE-2026-82641 | 8.8 | — | keploy | keploy | CWE-306 | keploy 3.1.0 through 3.6.25 Unauthenticated TLS Key Exposure |
| CVE-2026-82642 | 8.8 | — | readest | readest | CWE-79 | Readest: unsanitized iframe srcdoc attribute in the EPUB sanitizer can lead t… |
| CVE-2026-56718 | 8.7 | — | AJCloud | AJY IPC Firmware | CWE-22 | AJCloud AJY IPC Firmware Path Traversal via jdbhttpd |
| CVE-2026-81636 | 8.7 | — | ash-project | ash_graphql | CWE-770 | Query-complexity limit bypass via first/last pagination arguments in AshGraph… |
| CVE-2026-82638 | 8.7 | — | jina-ai | reader | CWE-918 | jina-ai reader Server-Side Request Forgery via disabled private-address guard |
| CVE-2026-82639 | 8.7 | — | ChatGPTNextWeb | NextChat | CWE-20 | NextChat 2.15.8 through 2.16.1 OpenAI API Key Disclosure |
| CVE-2026-82644 | 8.7 | — | WWBN | AVideo | CWE-307 | WWBN AVideo Brute-force Rate Limiting Bypass via Missing User-Agent |
| CVE-2026-82655 | 8.7 | — | Admidio | admidio | CWE-89 | Admidio before 5.0.12 SQL Injection via relation_type_list |
| CVE-2026-82657 | 8.7 | — | Admidio | admidio | CWE-200 | Admidio before 5.0.12 Authentication Bypass via RSS feeds |
| CVE-2026-82592 | 8.6 | — | D-Link | DIR-825M | CWE-119 | D-Link DIR-825M Disk Formatting Handler Endpoint formDiskFormat sub_46725C st… |
| CVE-2026-82539 | 8.5 | — | TOTOLINK | A720R | CWE-119 | TOTOLINK A720R MAC Filtering cstecgi.cgi setMacFilterRules memory corruption |
| CVE-2026-82636 | 7.9 | — | Qubes OS | Qubes OS | CWE-78 | Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection duri… |
| CVE-2026-78699 | 7.2 | — | ash-project | ash_postgres | CWE-252 | rename_tenant returns :ok on a failed rename, enabling cross-tenant access in… |
| CVE-2026-80223 | 7.1 | — | ash-project | ash_graphql | CWE-863 | Cross-tenant subscription disclosure in AshGraphql authorizes notifications i… |
| CVE-2026-82634 | 7.1 | — | frappe | frappe | CWE-863 | Frappe Framework Development Branch Incorrect Authorization via Jinja Templat… |
| CVE-2026-82648 | 7.1 | — | WWBN | AVideo | CWE-20 | WWBN AVideo SSRF Filter Bypass via NAT64 Hex Address |
| CVE-2026-82649 | 7.0 | — | siyuan-note | siyuan | CWE-427 | SiYuan before 3.8.1 Local Privilege Escalation via Uncontrolled Search Path |
| CVE-2026-78693 | 6.9 | — | ash-project | ash_graphql | CWE-209 | Incomplete redaction re-attaches the original error path in AshGraphql, leaki… |
| CVE-2026-81633 | 6.9 | — | ash-project | ash_graphql | CWE-20 | Unhandled KeyError in AshGraphql relay node resolution crashes queries via an… |
| CVE-2026-82637 | 6.9 | — | browser-use | web-ui | CWE-73 | browser-use web-ui 2.0.0 through 3.0.0 Arbitrary Directory Creation |
| CVE-2026-82643 | 6.9 | — | WWBN | AVideo | CWE-307 | WWBN AVideo Unauthenticated Rate Limit Bypass via preauthorize.json.php |
| CVE-2026-82651 | 6.9 | — | siyuan-note | siyuan | CWE-200 | SiYuan before v3.8.1 Missing Authorization via /history and /repo/diff |
| CVE-2026-82652 | 6.9 | — | siyuan-note | siyuan | CWE-668 | SiYuan before v3.8.1 Information Disclosure via Publish Access |
| CVE-2026-82640 | 6.8 | — | browser-use | web-ui | CWE-312 | browser-use web-ui 2.0.0 through 3.0.0 Cleartext API Key Storage |
| CVE-2026-77454 | 5.9 | — | ash-project | ash_sql | CWE-863 | exists/2 predicate silently dropped on limited relationships with a parent() … |
| CVE-2026-78038 | 5.9 | — | ash-project | ash_oban | CWE-915 | Job argument injection via :args overrides primary_key and tenant in AshOban |
| CVE-2026-78228 | 5.9 | — | ash-project | ash_oban | CWE-674 | Unbounded handle_error recursion enables denial of service in AshOban triggers |
| CVE-2026-81319 | 5.9 | — | ash-project | ash_cloak | CWE-502 | Unsafe deserialization of decrypted terms enables node DoS in AshCloak |
| CVE-2026-82650 | 5.9 | — | siyuan-note | siyuan | CWE-668 | SiYuan before v3.8.1 Path Traversal via /api/template/render |
| CVE-2026-82543 | 5.5 | — | vastsa | FileCodeBox | CWE-362 | vastsa FileCodeBox Pickup Limit views.py update_file_usage race condition |
| CVE-2026-82547 | 5.5 | — | Linux Foundation | Magma | CWE-287 | Linux Foundation Magma Registration Complete Message amf_fsm.cpp improper aut… |
| CVE-2026-82548 | 5.5 | — | Linux Foundation | Magma | CWE-200 | Linux Foundation Magma InitialUEMessage information disclosure |
| CVE-2026-82549 | 5.5 | — | Linux Foundation | Magma | CWE-345 | Linux Foundation Magma SecurityModeComplete integrity check |
| CVE-2026-82550 | 5.5 | — | Linux Foundation | Magma | CWE-20 | Linux Foundation Magma NGSetupRequest input validation |
| CVE-2026-82551 | 5.5 | — | Linux Foundation | Magma | CWE-371 | Linux Foundation Magma NGSetup ngap_amf_handlers.c state issue |
| CVE-2026-82544 | 5.3 | — | wger-project | wger | CWE-352 | wger-project wger Password Reset gym.py reset_user_password cross-site reques… |
| CVE-2026-82588 | 5.3 | — | n/a | Open5GS | CWE-404 | Open5GS Transfer Endpoint namf-handler.c null pointer dereference |
| CVE-2026-82590 | 5.3 | — | n/a | Open5GS | CWE-617 | Open5GS SMF nudm-handler.c smf_nudm_sdm_handle_get assertion |
| CVE-2026-82595 | 5.3 | — | D-Link | DIR-825M | CWE-77 | D-Link DIR-825M System Command Execution formSysCmd sub_456CF4 command injection |
| CVE-2026-82633 | 5.3 | — | Dolibarr | dolibarr | CWE-862 | Dolibarr 10.0.0 before 24.0.0 Missing Authorization on REST Users Groups Endp… |
| CVE-2026-82646 | 5.3 | — | WWBN | AVideo | CWE-79 | WWBN AVideo Unauthenticated Reflected XSS via url2Embed.json.php |
| CVE-2026-82647 | 5.3 | — | WWBN | AVideo | CWE-352 | WWBN AVideo Cross-Site Request Forgery via sendEmail.json.php |
| CVE-2026-82658 | 5.3 | — | Admidio | admidio | CWE-285 | Admidio before 5.0.12 Broken Access Control via profile_function.php |
| CVE-2026-82591 | 4.8 | — | Open Asset Import Library | Assimp | CWE-119 | Open Asset Import Library Assimp MD5Loader.cpp MakeDataUnique heap-based over… |
| CVE-2026-82555 | 2.9 | — | TOTOLINK | N600R | CWE-310 | TOTOLINK N600R Authentication cstecgi.cgi loginAuth random values |
| CVE-2026-81643 | 2.3 | — | ash-project | ash_graphql | CWE-863 | Broken access control in AshGraphql subscription batcher applies authorizatio… |
| CVE-2026-82367 | 2.3 | — | ash-project | ash_graphql | CWE-488 | Re-entrant synchronous publish in AshGraphql subscription batcher delivers on… |
| CVE-2026-82486 | 2.3 | — | SiteServer | SSCMS | CWE-266 | SiteServer SSCMS Agent Installation Workflow access control |
| CVE-2026-82594 | 2.3 | — | LogNet | grpc-spring-boot-starter | CWE-285 | LogNet grpc-spring-boot-starter Annotation Processing improper authorization |
| CVE-2026-78691 | 2.1 | — | ash-project | ash_sql | CWE-943 | Unescaped backslash allows LIKE wildcard injection in AshSql string search |
| CVE-2026-80227 | 2.1 | — | ash-project | ash_sql | CWE-697 | SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql |
| CVE-2026-81316 | 2.1 | — | ash-project | ash_sql | CWE-863 | Same-named aggregates with differing filters are conflated in AshSql |
| CVE-2026-81318 | 2.1 | — | ash-project | ash_sql | CWE-863 | Distinct-query aggregate drops the tenant schema prefix, leaking across tenan… |
| CVE-2026-81322 | 2.1 | — | ash-project | ash_cloak | CWE-200 | Cloaked plaintext leaks through a non-sensitive action argument in AshCloak |
| CVE-2026-82487 | 2.1 | — | Beetel | 450TC3 | CWE-640 | Beetel 450TC3 password recovery |
| CVE-2026-82540 | 2.1 | — | itsourcecode | Sales and Inventory System | CWE-74 | itsourcecode Sales and Inventory System cust_searchfrm.php sql injection |
| CVE-2026-82541 | 2.1 | — | itsourcecode | Sales and Inventory System | CWE-74 | itsourcecode Sales and Inventory System sup_edit.php sql injection |
| CVE-2026-82545 | 2.1 | — | itsourcecode | Sales and Inventory System | CWE-74 | itsourcecode Sales and Inventory System sup_searchfrm.php sql injection |
| CVE-2026-82552 | 2.1 | — | Linux Foundation | Magma | CWE-404 | Linux Foundation Magma gNB Termination ngap_amf.c denial of service |
| CVE-2026-82553 | 2.1 | — | sambitraj | Student Management System | CWE-266 | sambitraj Student Management System Student Dashboard student_dashboard.php m… |
| CVE-2026-82554 | 2.1 | — | SourceCodester | Queue Management System | CWE-79 | SourceCodester Queue Management System add_customer.php cross site scripting |
| CVE-2026-82556 | 2.1 | — | n/a | Forgejo | CWE-918 | Forgejo Repository Migration is_migrate_allowed.go net.LookupIP server-side r… |
| CVE-2026-82587 | 2.1 | — | n/a | Open5GS | CWE-119 | Open5GS AMF namf-handler.c amf_namf_comm_decode_ue_mm_context_list memory cor… |
| CVE-2026-82589 | 2.1 | — | n/a | Open5GS | CWE-404 | Open5GS N1-N2 Message namf-handler.c amf_namf_comm_handle_n1_n2_message_trans… |
| CVE-2026-82656 | 2.1 | — | Admidio | admidio | CWE-22 | Admidio before 5.0.12 Path Traversal via Photo ZIP Download |
| CVE-2026-82488 | 2.0 | — | Beetel | 450TC3 | CWE-79 | Beetel 450TC3 User Management cross site scripting |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-08-30 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.