boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Sunday, August 30, 2026 · all times UTC← 2026-08-29 · archive

Security Box Score — August 30, 2026

92 CVEs published, led by ash-project (20).

92 CVEs published August 30, 2026: 6 critical, 19 high, 32 medium, 28 low; 0 in the KEV catalog at press time; 3 with a public exploit reference; 7 awaiting enrichment. 25 rendered as box scores below; the remaining 67 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1193234373——
KEV catalog size1685

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2062 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux16453960418197263711230.17.8.0016+810 ▲
google4022164270842960757760.37.5.0026-89 ▼
microsoft4771899145128345714287281.57.8.0044-188 ▼
red hat2236174225428832200.06.7.0029+75 ▲
apple44316598516578882.56.5.0029-123 ▼
freebsd324823673000.07.8.0016+32 ▲
canonical15421311135000.07.8.0020+8 ▲
suse72851481000.07.7.0038-1 ▼
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco46842139240561315.57.5.0044+30 ▲
ubiquiti2359362210335.19.1.0049-2 ▼
palo alto networks12371321121325.44.7.0020-2 ▼
netgear93200275000.04.3.0025+3 ▲
fortinet7307814128620.07.0.0050-7 ▼
vmware21959327210.58.3.0040-11 ▼
f50175930415.98.7.0057-8 ▼
sonicwall1214374017214.37.8.0024+10 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache159496102216164133320.47.5.0049-19 ▼
mozilla591866868500900.08.1.0030-12 ▼
gitlab2576218479422.65.3.0028+5 ▲
drupal1768107465411.55.9.0024-29 ▼
github5171790000.06.6.0044-1 ▼
docker290630000.07.2.0016+2 ▲
wordpress2513102240.08.8.3120-1 ▼
kubernetes010001000.02.4.0035-1 ▼
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle89022694841170519962840.27.8.0034-219 ▼
ibm3906191482861778610.27.6.0030+285 ▲
adobe1016065030024791930.57.8.0021-6 ▼
progress19611437100611.68.1.0037-14 ▼
solarwinds0231733010417.49.1.0058-16 ▼
veeam131961030100.08.6.0032+11 ▲
zohocorp4103520000.08.7.0140+1 ▲
atlassian3615001300.08.1.00320
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link1939166107300.07.4.0157+11 ▲
siemens213722483000.07.3.0016+14 ▲
synology42736153000.05.6.0025+4 ▲
rockwell automation12541740000.08.4.0024-16 ▼
schneider electric091620000.08.6.0037-3 ▼
abb070430000.07.2.0018-1 ▼
hikvision060420000.07.2.0040-5 ▼
mitsubishi electric050410000.07.2.0052-1 ▼
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring911709538616000.06.4.0022+85 ▲
dell711701190645210.67.2.0019+28 ▲
sourcecodester49169009277000.05.5.00290
nvidia521341688300000.07.8.0034+9 ▲
splunk110128647705110.86.5.0025+107 ▲
openclaw01110583914000.07.0.0026-44 ▼
itsourcecode37108002682000.02.1.0027+19 ▲
zephyrproject521053335712000.06.4.0021+26 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.995799.99.8
CVE-2026-34486.986299.97.5
CVE-2026-63077.877199.79.8
CVE-2026-60004.845599.79.8
CVE-2026-72898.792299.610.0
CVE-2026-18577.540798.98.2
CVE-2026-18556.401698.58.2
CVE-2026-64638.312098.18.9
CVE-2026-71362.251497.89.1
CVE-2026-73570.205397.38.9
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.7922KEV
CVE-2026-4836210.0.0431
CVE-2026-1918810.0.0193
CVE-2026-5823110.0.0171
CVE-2026-6983610.0.0155
CVE-2026-7619510.0.0147
CVE-2026-7619710.0.0147
CVE-2026-7329910.0.0121
CVE-2026-7367810.0.0114
CVE-2026-7755410.0.0099
Most disclosures (vendor)
VendorCVEs
linux1645
oracle890
microsoft477
google402
ibm390
red hat223
apache159
splunk110
adobe101
spring91
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco13
apple8
fortinet6
google6
ivanti5
oracle4
solarwinds4
adobe3
berriai3
Most-affected ecosystems
EcosystemAdvisories
Maven51
Packagist28
npm14
PyPI13
Go1
Fastest to KEV
CVEVendorDays
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20349Cisco0
CVE-2026-34486Apache Software Foundation0
CVE-2026-63077JetBrains0
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
CVE-2026-72898Metabase0
CVE-2026-8037Progress Software0
CVE-2026-64849mlflow1
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171747
CVE-2021-27102n/a2021-11-171747
CVE-2021-27101n/a2021-11-171747
CVE-2021-27103n/a2021-11-171747
CVE-2021-21017Adobe2021-11-171747
CVE-2021-28550Adobe2021-11-171747
CVE-2021-42013Apache Software Foundation2021-11-171747
CVE-2021-41773Apache Software Foundation2021-11-171747
CVE-2021-30858Apple2021-11-171747
CVE-2021-30860Apple2021-11-171747

Transactions

EXPLOIT PUBLISHED — Unknown HEL Online Classroom: AI-powered Online Classrooms: 3 CVEs (CVE-2026-77007, CVE-2026-77008, CVE-2026-77010). Public exploit references added.

EXPLOIT PUBLISHED — Unknown MasterStudy LMS WordPress Plugin: 3 CVEs (CVE-2026-81026, CVE-2026-81200, CVE-2026-81342). Public exploit references added.

EXPLOIT PUBLISHED — Unknown User Profile Builder: 3 CVEs (CVE-2026-76546, CVE-2026-76547, CVE-2026-76548). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-11819 (Red Hat Enterprise Linux 10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-12965 (Unknown Super Store Finder WordPress). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16061 (Unknown Rest Routes). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16259 (Unknown Uix UserCenter). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16600 (Unknown SmartAIPress). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16739 (Unknown Epeken All Kurir for Woocommerce). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16947 (Unknown Total processing card payments for WooCommerce). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-17520 (Unknown Newsletters). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-17522 (Unknown Newsletters). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-18233 (Unknown MStore API). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-18234 (Unknown MStore API). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19430 (Unknown Catfolders Document Gallery Pro). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76586 (Unknown Appointment Booking Calendar Plugin and Scheduling Plugin). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-77012 (Unknown 爱采集数据采集和发布插件). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-77704 (Unknown Booking for Appointments and Events Calendar). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-77786 (Unknown Rank Math SEO). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-80311 (Unknown Stripe Payment Forms by WP Full Pay). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-80488 (Unknown WP Ultimate CSV Importer). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-81346 (Unknown Frontend Admin by DynamiApps). Public exploit reference added.

DUE DATE PASSED — CVE-2019-1068 (Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)). CISA remediation deadline was August 29, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-8452 (NetScaler ADC). CISA remediation deadline was August 29, 2026; still in catalog.

PATCH SHIPPED — CVE-2026-14324 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:1.4.11-1.el10_2.1.

PATCH SHIPPED — CVE-2026-14330 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 0:1.4.11-1.el9_8.2.

PATCH SHIPPED — CVE-2026-71217 (Red Hat Enterprise Linux 8). Fixed in Red Hat Enterprise Linux 8 0:3.5-12.el8_10.1.

Yesterday's Results

How to read these box scores · glossary

92 CVEs published. 25 box scores, 67 table rows — nothing truncated.

TangibleWP MyHome Core — MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0045   37.7     —
AFFECTED
  Product      Versions     Fixed
  MyHome Core  unspecified  —
TIMELINE
  Jul 16  Reserved by CNA
  Aug 30  Published (CNA: Wordfence)
CWE-289 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Received
NASA Trick TCP Socket JSONVariableServerThread.cpp parse_request stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    6.9   .0033   25.6     —
AFFECTED
  Product  Versions  Fixed
  Trick    19.6.0 –  —
TIMELINE
  Aug 29  Reserved by CNA
  Aug 30  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Received
NASA cFS SBN TCP sbn_tcp_if.c OS_read buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   N   N   L   L   L    5.3   .0025   16.7     —
AFFECTED
  Product  Versions  Fixed
  cFS      7.0.0 –   —
TIMELINE
  Aug 29  Reserved by CNA
  Aug 30  Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Received
NASA cFS cFE Software Bus cfe_sb_util.c CFE_SB_GetUserDataLength integer underflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    5.3   .0022   12.9     —
AFFECTED
  Product  Versions  Fixed
  cFS      7.0.0 –   —
TIMELINE
  Aug 29  Reserved by CNA
  Aug 30  Published (CNA: VulDB)
CWE-189, CWE-191 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Received
itsourcecode Sales and Inventory System emp_searchfrm.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0020    9.9     —
AFFECTED
  Product                     Versions  Fixed
  Sales and Inventory System  1.0 –     —
TIMELINE
  Aug 29  Reserved by CNA
  Aug 30  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
itsourcecode Sales and Inventory System pro_edit.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0020    9.9     —
AFFECTED
  Product                     Versions  Fixed
  Sales and Inventory System  1.0 –     —
TIMELINE
  Aug 29  Reserved by CNA
  Aug 30  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
coppermine-gallery Coppermine Photo Gallery edit_profile Endpoint profile.php cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   P   N   L   N    2.0   .0020    9.7     —
AFFECTED
  Product                   Versions  Fixed
  Coppermine Photo Gallery  1.6.0 –   1.6.29
TIMELINE
  Aug 29  Reserved by CNA
  Aug 30  Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
coppermine-gallery Coppermine Photo Gallery Hidden Album Update Endpoint db_input.php cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   P   N   L   N    2.0   .0020    9.7     —
AFFECTED
  Product                   Versions  Fixed
  Coppermine Photo Gallery  1.6.0 –   1.6.29
TIMELINE
  Aug 29  Reserved by CNA
  Aug 30  Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
CVE-2026-14307AWAITING ENRICHMENT
Unknown geotargetingwp — Geotargeting WP < 3.5.6.2 - Reflected XSS
  CVSS   EPSS    %ile   KEV
  —      .0017   6.8    —
AFFECTED
  Product         Versions     Fixed
  geotargetingwp  unspecified  —
TIMELINE
  Jul 1   Reserved by CNA
  Aug 30  Published (CNA: WPScan)
CNA: WPScan · 1 reference · NVD status: Received
CVE-2026-19722AWAITING ENRICHMENT
Unknown WPvivid — Backup, Migration & Staging — WPvivid Backup & Migration < 0.9.133 - Admin+ Arbitrary File Write via Zip Slip in Backup Restore
  CVSS   EPSS    %ile   KEV
  —      .0017   6.7    —
AFFECTED
  Product                                Versions     Fixed
  WPvivid — Backup, Migration & Staging  unspecified  —
TIMELINE
  Aug 13  Reserved by CNA
  Aug 30  Published (CNA: WPScan)
CNA: WPScan · 1 reference · NVD status: Received
CVE-2026-76585AWAITING ENRICHMENT
Unknown Customer Reviews for WooCommerce — Customer Reviews for WooCommerce < 5.118.0 - Unauthenticated Stored XSS via 'comment' Parameter
  CVSS   EPSS    %ile   KEV
  —      .0017   6.8    —
AFFECTED
  Product                           Versions     Fixed
  Customer Reviews for WooCommerce  unspecified  —
TIMELINE
  Aug 19  Reserved by CNA
  Aug 30  Published (CNA: WPScan)
CNA: WPScan · 1 reference · NVD status: Received
CVE-2026-81660AWAITING ENRICHMENT
Unknown Groundhogg — CRM, Newsletters, and Marketing Automation — Groundhogg < 4.5.13 - Unauthenticated Stored XSS via Web Form Dropdown/Radio Field
  CVSS   EPSS    %ile   KEV
  —      .0017   6.8    —
AFFECTED
  Product                                                  Versions     Fixed
  Groundhogg — CRM, Newsletters, and Marketing Automation  unspecified  —
TIMELINE
  Aug 27  Reserved by CNA
  Aug 30  Published (CNA: WPScan)
CNA: WPScan · 1 reference · NVD status: Received
CVE-2026-14835AWAITING ENRICHMENT
Unknown SOGO Add Script to Individual Pages Header Footer — SOGO Add Script to Individual Pages Header Footer <= 3.9 - Contributor+ Stored XSS via Post Metabox
  CVSS   EPSS    %ile   KEV
  —      .0015   4.7    —
AFFECTED
  Product                                            Versions     Fixed
  SOGO Add Script to Individual Pages Header Footer  unspecified  —
TIMELINE
  Jul 6   Reserved by CNA
  Aug 30  Published (CNA: WPScan)
CNA: WPScan · 1 reference · NVD status: Received
CVE-2026-78364AWAITING ENRICHMENT
Unknown MW WP Form — MW WP Form < 5.1.6 - Editor+ Stored XSS via Inquiry Data List
  CVSS   EPSS    %ile   KEV
  —      .0015   4.7    —
AFFECTED
  Product     Versions     Fixed
  MW WP Form  unspecified  —
TIMELINE
  Aug 24  Reserved by CNA
  Aug 30  Published (CNA: WPScan)
CNA: WPScan · 1 reference · NVD status: Received
CVE-2026-81766AWAITING ENRICHMENT
Unknown Really Simple Security — Really Simple Security < 9.8.0 - Multisite Subsite Admin+ Arbitrary Plugin Installation via rsp_upgrade_install_plugin
  CVSS   EPSS    %ile   KEV
  —      .0015   4.3    —
AFFECTED
  Product                 Versions     Fixed
  Really Simple Security  unspecified  —
TIMELINE
  Aug 27  Reserved by CNA
  Aug 30  Published (CNA: WPScan)
CNA: WPScan · 1 reference · NVD status: Received
ash-project ash_sqlite — JSON path injection via unescaped get_path segments in AshSqlite
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   P   N   N   L   N   N    2.1   .0014    3.5     —
AFFECTED
  Product     Versions                                    Fixed
  ash_sqlite  0.1.2-rc.0 –                                —
  ash_sqlite  c12be48a5b6295593199b0e445b70a4aef81d1cd –  —
TIMELINE
  Aug 30  Reserved by CNA
  Aug 30  Published (CNA: EEF)
CWE-943 · CNA: EEF · CVSS v4.0 · 4 references · NVD status: Received
ash-project ash_paper_trail — Algorithmic-complexity denial of service in AshPaperTrail full-diff list tracking
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   P   N   N   N   N   L    2.1   .0014    3.5     —
AFFECTED
  Product          Versions                                    Fixed
  ash_paper_trail  0.1.1 –                                     —
  ash_paper_trail  449cd2a93416853066378fa61c715e89f80dc854 –  —
TIMELINE
  Aug 27  Reserved by CNA
  Aug 30  Published (CNA: EEF)
CWE-407 · CNA: EEF · CVSS v4.0 · 4 references · NVD status: Received
erlef oidcc — Encrypted ID token or JARM response accepted without a nested signature in erlef oidcc
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   P   H   H   N    7.6   .0014    3.3     —
AFFECTED
  Product  Versions                                    Fixed
  oidcc    3.2.0-beta.1 –                              —
  oidcc    37a1361f704889816db2873f72d744d63ec39568 –  —
TIMELINE
  Aug 21  Reserved by CNA
  Aug 30  Published (CNA: EEF)
CWE-347 · CNA: EEF · CVSS v4.0 · 4 references · NVD status: Received
ash-project ash_paper_trail — Sensitive attribute values stored in a non-sensitive public changes map in AshPaperTrail
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   P   N   N   H   N   N    5.9   .0010    0.8     —
AFFECTED
  Product          Versions                                    Fixed
  ash_paper_trail  0.1.1 –                                     —
  ash_paper_trail  e379ca90a0c4db54d07a9d1556fd12f2413f6e98 –  —
TIMELINE
  Aug 20  Reserved by CNA
  Aug 30  Published (CNA: EEF)
CWE-312 · CNA: EEF · CVSS v4.0 · 4 references · NVD status: Received
ash-project ash_paper_trail — Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   P   N   N   H   N   N    5.9   .0010    0.8     —
AFFECTED
  Product          Versions                                    Fixed
  ash_paper_trail  0.3.0 –                                     —
  ash_paper_trail  ffe5e03b14d26b73bff17f3eca811591788aba9c –  —
TIMELINE
  Aug 24  Reserved by CNA
  Aug 30  Published (CNA: EEF)
CWE-312 · CNA: EEF · CVSS v4.0 · 4 references · NVD status: Received
D-Link DIR-825M LTE Module Firmware Upgrade formLtefotaUpgradeFibocom sub_41802C stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4      —      —     —
AFFECTED
  Product   Versions  Fixed
  DIR-825M  1.1.8 –   —
TIMELINE
  Aug 30  Reserved by CNA
  Aug 30  Published (CNA: VulDB)
CWE-121, CWE-119 · CNA: VulDB · CVSS v4.0 · 6 references
Tenda HG10 Boa Web Server formIPv6Routing buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3      —      —     —
AFFECTED
  Product  Versions     Fixed
  HG10     300001138 –  —
TIMELINE
  Aug 29  Reserved by CNA
  Aug 30  Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
siyuan-note siyuan — SiYuan before v3.8.1 Stored XSS via confirmDialog
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   L   P   H   H   L    9.3      —      —     —
AFFECTED
  Product  Versions     Fixed
  siyuan   unspecified  3.8.1
TIMELINE
  Aug 30  Reserved by CNA
  Aug 30  Published (CNA: VulnCheck)
CWE-79 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
siyuan-note siyuan — SiYuan before v3.8.1 Stored XSS via block name
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   L   P   H   H   L    9.3      —      —     —
AFFECTED
  Product  Versions     Fixed
  siyuan   unspecified  3.8.1
TIMELINE
  Aug 30  Reserved by CNA
  Aug 30  Published (CNA: VulnCheck)
CWE-79 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
WWBN AVideo — AVideo Unauthenticated Stream Credential Disclosure via Forgeable Token
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    9.2      —      —     —
AFFECTED
  Product  Versions     Fixed
  AVideo   unspecified  —
TIMELINE
  Aug 30  Reserved by CNA
  Aug 30  Published (CNA: VulnCheck)
CWE-347 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-826358.8—tw93PakeCWE-22Pake arbitrary file write via unsanitized download_file filename
CVE-2026-826418.8—keploykeployCWE-306keploy 3.1.0 through 3.6.25 Unauthenticated TLS Key Exposure
CVE-2026-826428.8—readestreadestCWE-79Readest: unsanitized iframe srcdoc attribute in the EPUB sanitizer can lead t…
CVE-2026-567188.7—AJCloudAJY IPC FirmwareCWE-22AJCloud AJY IPC Firmware Path Traversal via jdbhttpd
CVE-2026-816368.7—ash-projectash_graphqlCWE-770Query-complexity limit bypass via first/last pagination arguments in AshGraph…
CVE-2026-826388.7—jina-aireaderCWE-918jina-ai reader Server-Side Request Forgery via disabled private-address guard
CVE-2026-826398.7—ChatGPTNextWebNextChatCWE-20NextChat 2.15.8 through 2.16.1 OpenAI API Key Disclosure
CVE-2026-826448.7—WWBNAVideoCWE-307WWBN AVideo Brute-force Rate Limiting Bypass via Missing User-Agent
CVE-2026-826558.7—AdmidioadmidioCWE-89Admidio before 5.0.12 SQL Injection via relation_type_list
CVE-2026-826578.7—AdmidioadmidioCWE-200Admidio before 5.0.12 Authentication Bypass via RSS feeds
CVE-2026-825928.6—D-LinkDIR-825MCWE-119D-Link DIR-825M Disk Formatting Handler Endpoint formDiskFormat sub_46725C st…
CVE-2026-825398.5—TOTOLINKA720RCWE-119TOTOLINK A720R MAC Filtering cstecgi.cgi setMacFilterRules memory corruption
CVE-2026-826367.9—Qubes OSQubes OSCWE-78Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection duri…
CVE-2026-786997.2—ash-projectash_postgresCWE-252rename_tenant returns :ok on a failed rename, enabling cross-tenant access in…
CVE-2026-802237.1—ash-projectash_graphqlCWE-863Cross-tenant subscription disclosure in AshGraphql authorizes notifications i…
CVE-2026-826347.1—frappefrappeCWE-863Frappe Framework Development Branch Incorrect Authorization via Jinja Templat…
CVE-2026-826487.1—WWBNAVideoCWE-20WWBN AVideo SSRF Filter Bypass via NAT64 Hex Address
CVE-2026-826497.0—siyuan-notesiyuanCWE-427SiYuan before 3.8.1 Local Privilege Escalation via Uncontrolled Search Path
CVE-2026-786936.9—ash-projectash_graphqlCWE-209Incomplete redaction re-attaches the original error path in AshGraphql, leaki…
CVE-2026-816336.9—ash-projectash_graphqlCWE-20Unhandled KeyError in AshGraphql relay node resolution crashes queries via an…
CVE-2026-826376.9—browser-useweb-uiCWE-73browser-use web-ui 2.0.0 through 3.0.0 Arbitrary Directory Creation
CVE-2026-826436.9—WWBNAVideoCWE-307WWBN AVideo Unauthenticated Rate Limit Bypass via preauthorize.json.php
CVE-2026-826516.9—siyuan-notesiyuanCWE-200SiYuan before v3.8.1 Missing Authorization via /history and /repo/diff
CVE-2026-826526.9—siyuan-notesiyuanCWE-668SiYuan before v3.8.1 Information Disclosure via Publish Access
CVE-2026-826406.8—browser-useweb-uiCWE-312browser-use web-ui 2.0.0 through 3.0.0 Cleartext API Key Storage
CVE-2026-774545.9—ash-projectash_sqlCWE-863exists/2 predicate silently dropped on limited relationships with a parent() …
CVE-2026-780385.9—ash-projectash_obanCWE-915Job argument injection via :args overrides primary_key and tenant in AshOban
CVE-2026-782285.9—ash-projectash_obanCWE-674Unbounded handle_error recursion enables denial of service in AshOban triggers
CVE-2026-813195.9—ash-projectash_cloakCWE-502Unsafe deserialization of decrypted terms enables node DoS in AshCloak
CVE-2026-826505.9—siyuan-notesiyuanCWE-668SiYuan before v3.8.1 Path Traversal via /api/template/render
CVE-2026-825435.5—vastsaFileCodeBoxCWE-362vastsa FileCodeBox Pickup Limit views.py update_file_usage race condition
CVE-2026-825475.5—Linux FoundationMagmaCWE-287Linux Foundation Magma Registration Complete Message amf_fsm.cpp improper aut…
CVE-2026-825485.5—Linux FoundationMagmaCWE-200Linux Foundation Magma InitialUEMessage information disclosure
CVE-2026-825495.5—Linux FoundationMagmaCWE-345Linux Foundation Magma SecurityModeComplete integrity check
CVE-2026-825505.5—Linux FoundationMagmaCWE-20Linux Foundation Magma NGSetupRequest input validation
CVE-2026-825515.5—Linux FoundationMagmaCWE-371Linux Foundation Magma NGSetup ngap_amf_handlers.c state issue
CVE-2026-825445.3—wger-projectwgerCWE-352wger-project wger Password Reset gym.py reset_user_password cross-site reques…
CVE-2026-825885.3—n/aOpen5GSCWE-404Open5GS Transfer Endpoint namf-handler.c null pointer dereference
CVE-2026-825905.3—n/aOpen5GSCWE-617Open5GS SMF nudm-handler.c smf_nudm_sdm_handle_get assertion
CVE-2026-825955.3—D-LinkDIR-825MCWE-77D-Link DIR-825M System Command Execution formSysCmd sub_456CF4 command injection
CVE-2026-826335.3—DolibarrdolibarrCWE-862Dolibarr 10.0.0 before 24.0.0 Missing Authorization on REST Users Groups Endp…
CVE-2026-826465.3—WWBNAVideoCWE-79WWBN AVideo Unauthenticated Reflected XSS via url2Embed.json.php
CVE-2026-826475.3—WWBNAVideoCWE-352WWBN AVideo Cross-Site Request Forgery via sendEmail.json.php
CVE-2026-826585.3—AdmidioadmidioCWE-285Admidio before 5.0.12 Broken Access Control via profile_function.php
CVE-2026-825914.8—Open Asset Import LibraryAssimpCWE-119Open Asset Import Library Assimp MD5Loader.cpp MakeDataUnique heap-based over…
CVE-2026-825552.9—TOTOLINKN600RCWE-310TOTOLINK N600R Authentication cstecgi.cgi loginAuth random values
CVE-2026-816432.3—ash-projectash_graphqlCWE-863Broken access control in AshGraphql subscription batcher applies authorizatio…
CVE-2026-823672.3—ash-projectash_graphqlCWE-488Re-entrant synchronous publish in AshGraphql subscription batcher delivers on…
CVE-2026-824862.3—SiteServerSSCMSCWE-266SiteServer SSCMS Agent Installation Workflow access control
CVE-2026-825942.3—LogNetgrpc-spring-boot-starterCWE-285LogNet grpc-spring-boot-starter Annotation Processing improper authorization
CVE-2026-786912.1—ash-projectash_sqlCWE-943Unescaped backslash allows LIKE wildcard injection in AshSql string search
CVE-2026-802272.1—ash-projectash_sqlCWE-697SQL string_trim removes only spaces, diverging from in-memory trimming in AshSql
CVE-2026-813162.1—ash-projectash_sqlCWE-863Same-named aggregates with differing filters are conflated in AshSql
CVE-2026-813182.1—ash-projectash_sqlCWE-863Distinct-query aggregate drops the tenant schema prefix, leaking across tenan…
CVE-2026-813222.1—ash-projectash_cloakCWE-200Cloaked plaintext leaks through a non-sensitive action argument in AshCloak
CVE-2026-824872.1—Beetel450TC3CWE-640Beetel 450TC3 password recovery
CVE-2026-825402.1—itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System cust_searchfrm.php sql injection
CVE-2026-825412.1—itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System sup_edit.php sql injection
CVE-2026-825452.1—itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System sup_searchfrm.php sql injection
CVE-2026-825522.1—Linux FoundationMagmaCWE-404Linux Foundation Magma gNB Termination ngap_amf.c denial of service
CVE-2026-825532.1—sambitrajStudent Management SystemCWE-266sambitraj Student Management System Student Dashboard student_dashboard.php m…
CVE-2026-825542.1—SourceCodesterQueue Management SystemCWE-79SourceCodester Queue Management System add_customer.php cross site scripting
CVE-2026-825562.1—n/aForgejoCWE-918Forgejo Repository Migration is_migrate_allowed.go net.LookupIP server-side r…
CVE-2026-825872.1—n/aOpen5GSCWE-119Open5GS AMF namf-handler.c amf_namf_comm_decode_ue_mm_context_list memory cor…
CVE-2026-825892.1—n/aOpen5GSCWE-404Open5GS N1-N2 Message namf-handler.c amf_namf_comm_handle_n1_n2_message_trans…
CVE-2026-826562.1—AdmidioadmidioCWE-22Admidio before 5.0.12 Path Traversal via Photo ZIP Download
CVE-2026-824882.0—Beetel450TC3CWE-79Beetel 450TC3 User Management cross site scripting

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-30 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.