boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Monday, August 31, 2026 · all times UTC← 2026-08-30 · archive

Security Box Score — August 31, 2026

CISA adds 2 to KEV; 357 CVEs published, led by ash-project (17).

357 CVEs published August 31, 2026: 35 critical, 95 high, 97 medium, 53 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 77 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 332 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1228934738——
KEV catalog size1687

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2160 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux16453960418197263711230.17.8.0016+810 ▲
google4022164270843968837760.37.5.0026-94 ▼
microsoft4771899145128345615287281.57.8.0044-188 ▼
red hat2296274226129132200.06.8.0029+65 ▲
apple44316598516578882.56.5.0029-123 ▼
freebsd324823673000.07.8.0016+32 ▲
canonical15421311135000.07.8.0020+8 ▲
suse72851481000.07.7.0038-1 ▼
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco46842139240561315.57.5.0044+30 ▲
ubiquiti2359362210335.19.1.0049-2 ▼
palo alto networks12371321121325.44.7.0020-2 ▼
netgear93200275000.04.3.0025+3 ▲
fortinet7307814128620.07.0.0050-7 ▼
vmware21959327210.58.3.0040-11 ▼
f50175930415.98.7.0057-8 ▼
sonicwall1214374017214.37.8.0024+10 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache169506102216173133320.47.5.0049-12 ▼
mozilla601876868510900.08.1.0030-11 ▼
gitlab2576218479422.65.3.0028+5 ▲
drupal1768107465411.55.9.0024-29 ▼
github5171790000.06.6.0044-1 ▼
docker290630000.07.2.0016+2 ▲
wordpress2513102240.08.8.3120-1 ▼
kubernetes010001000.02.4.0035-1 ▼
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle89022694841170519962840.27.8.0034-219 ▼
ibm3906191482861778610.27.6.0030+285 ▲
adobe1016065030024791930.57.8.0021-7 ▼
progress19611437100611.68.1.0037-14 ▼
solarwinds0231733010417.49.1.0058-16 ▼
veeam131961030100.08.6.0032+11 ▲
zohocorp4103520000.08.7.0140+1 ▲
atlassian3615001300.08.1.00320
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link2545151398300.08.5.0157+17 ▲
siemens213722483000.07.3.0016+14 ▲
synology42736153000.05.6.0025+4 ▲
rockwell automation12541740000.08.4.0024-16 ▼
schneider electric091620000.08.6.0037-3 ▼
abb070430000.07.2.0018-1 ▼
hikvision060420000.07.2.0040-6 ▼
mitsubishi electric050410000.07.2.0052-1 ▼
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell721711290645210.67.2.0019+29 ▲
spring911709578816000.06.5.0022+85 ▲
sourcecodester49169009277000.05.5.00290
nvidia521341688300000.07.8.0034+9 ▲
splunk110128647705110.86.5.0025+107 ▲
itsourcecode45116003284000.02.1.0027+27 ▲
openclaw01110583914000.07.0.0026-44 ▼
zephyrproject571103336212000.06.4.0021+29 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.995799.99.8
CVE-2026-34486.986299.97.5
CVE-2026-63077.877199.79.8
CVE-2026-60004.845599.79.8
CVE-2026-72898.823299.610.0
CVE-2026-18577.540798.98.2
CVE-2026-18556.401698.58.2
CVE-2026-64638.312098.18.9
CVE-2026-71362.251497.89.1
CVE-2026-73570.205397.38.9
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.8232KEV
CVE-2026-4836210.0.0431
CVE-2026-1918810.0.0193
CVE-2026-5823110.0.0171
CVE-2026-7619510.0.0159
CVE-2026-7619710.0.0159
CVE-2026-6983610.0.0155
CVE-2026-7329910.0.0121
CVE-2026-7367810.0.0114
CVE-2026-7755410.0.0099
Most disclosures (vendor)
VendorCVEs
linux1645
oracle890
microsoft477
google402
ibm390
red hat229
apache169
splunk110
adobe101
spring91
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco13
apple8
fortinet6
google6
ivanti5
oracle4
solarwinds4
adobe3
berriai3
Most-affected ecosystems
EcosystemAdvisories
Maven61
Packagist28
npm14
PyPI13
Go1
Fastest to KEV
CVEVendorDays
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20349Cisco0
CVE-2026-34486Apache Software Foundation0
CVE-2026-63077JetBrains0
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
CVE-2026-72898Metabase0
CVE-2026-8037Progress Software0
CVE-2026-64849mlflow1
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171748
CVE-2021-27102n/a2021-11-171748
CVE-2021-27101n/a2021-11-171748
CVE-2021-27103n/a2021-11-171748
CVE-2021-21017Adobe2021-11-171748
CVE-2021-28550Adobe2021-11-171748
CVE-2021-42013Apache Software Foundation2021-11-171748
CVE-2021-41773Apache Software Foundation2021-11-171748
CVE-2021-30858Apple2021-11-171748
CVE-2021-30860Apple2021-11-171748

Transactions

ADDED TO KEV — CVE-2026-81578 (PaperCut MF/NG). Remediation due September 14, 2026.

ADDED TO KEV — CVE-2026-82078 (PaperCut MF/NG). Remediation due September 14, 2026.

EXPLOIT PUBLISHED — Wireshark Foundation Wireshark: 17 CVEs (CVE-2026-76882, CVE-2026-76883, CVE-2026-76884, CVE-2026-76885, CVE-2026-76889, CVE-2026-76890, CVE-2026-76891, CVE-2026-76917, CVE-2026-76918, CVE-2026-76919, CVE-2026-76920, CVE-2026-76921, CVE-2026-76922, CVE-2026-76923, CVE-2026-76927, CVE-2026-76928, CVE-2026-76929). Public exploit references added.

EXPLOIT PUBLISHED — nltk: 14 CVEs (CVE-2026-62385, CVE-2026-63310, CVE-2026-63312, CVE-2026-65915, CVE-2026-70626, CVE-2026-78682, CVE-2026-78683, CVE-2026-79657, CVE-2026-79674, CVE-2026-79676, CVE-2026-81722, CVE-2026-81724, CVE-2026-81726, CVE-2026-81727). Public exploit references added.

EXPLOIT PUBLISHED — itsourcecode Sales and Inventory System: 7 CVEs (CVE-2026-82421, CVE-2026-82422, CVE-2026-82484, CVE-2026-82485, CVE-2026-82540, CVE-2026-82541, CVE-2026-82545). Public exploit references added.

EXPLOIT PUBLISHED — Linux Foundation Magma: 4 CVEs (CVE-2026-82549, CVE-2026-82550, CVE-2026-82551, CVE-2026-82552). Public exploit references added.

EXPLOIT PUBLISHED — Red Hat Hardened Images: 4 CVEs (CVE-2026-0989, CVE-2026-0990, CVE-2026-0992, CVE-2026-6732). Public exploit references added.

EXPLOIT PUBLISHED — Red Hat Enterprise Linux 10: 3 CVEs (CVE-2026-4878, CVE-2026-48864, CVE-2026-55653). Public exploit references added.

EXPLOIT PUBLISHED — zephyrproject zephyr: 3 CVEs (CVE-2026-13479, CVE-2026-13480, CVE-2026-13481). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2024-6387 (OpenSSH). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-13601 (glib). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-4598 (systemd-coredump). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-5914 (libarchive). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-6021 (libxml2). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-62718 (axios). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-14307 (Unknown geotargetingwp). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-14835 (Unknown SOGO Add Script to Individual Pages Header Footer). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-22244 (open-metadata OpenMetadata). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-29063 (immutable-js). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-29181 (open-telemetry opentelemetry-go). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-32141 (WebReflection flatted). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-33228 (WebReflection flatted). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-33891 (digitalbazaar forge). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-33896 (digitalbazaar forge). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-33937 (handlebars-lang handlebars.js). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-33938 (handlebars-lang handlebars.js). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-3832 (gnutls). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48779 (websockets ws). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-59090 (gimp). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-62382 (pglombardo PasswordPusher). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-71225 (Stephan Muelle libkcapi). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-71227 (Stephan Muelle libkcapi). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76585 (Unknown Customer Reviews for WooCommerce). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76639 (Unitree Robotics G1 EDU). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78364 (Unknown MW WP Form). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-81578 (PaperCut MF/NG). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-81660 (Unknown Groundhogg — CRM, Newsletters, and Marketing Automation). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-81766 (Unknown Really Simple Security). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-81833 (RooCodeInc Roo-Code). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-81836 (RooCodeInc Roo-Code). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-81845 (arben-adm mcp-sequential-thinking). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-81934 (Redis). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82017 (IGEL OS 12). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82078 (PaperCut MF/NG). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82111 (iswalle getnote-mcp). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82280 (QuivrHQ quivr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82424 (PHPGurukul Student Information System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82473 (kubeedge). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82483 (coppermine-gallery Coppermine Photo Gallery). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82488 (Beetel 450TC3). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82543 (vastsa FileCodeBox). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82554 (SourceCodester Queue Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82555 (TOTOLINK N600R). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82556 (Forgejo). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82587 (Open5GS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82589 (Open5GS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82592 (D-Link DIR-825M). Public exploit reference added.

DUE DATE PASSED — CVE-2023-49105. CISA remediation deadline was August 30, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-53362 (Linux). CISA remediation deadline was August 30, 2026; still in catalog.

RESCORED — Wireshark Foundation Wireshark: 12 CVEs (CVE-2026-76882, CVE-2026-76883, CVE-2026-76884, CVE-2026-76885, CVE-2026-76887, CVE-2026-76889, CVE-2026-76890, CVE-2026-76891, CVE-2026-76919, CVE-2026-76920, CVE-2026-76927, CVE-2026-76929). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2025-31104 (Fortinet FortiADC). CVSS 7 → 7.2 (NVD).

RESCORED — CVE-2026-10053 (GitLab). CVSS 8.5 → 8.8 (NVD).

RESCORED — CVE-2026-13479 (zephyrproject zephyr). CVSS 3.1 → 4.3 (NVD).

RESCORED — CVE-2026-18252 (GitLab). CVSS 7.3 → 8.1 (NVD).

RESCORED — CVE-2026-19294 (IBM Langflow OSS). CVSS 6.4 → 6.5 (NVD).

RESCORED — CVE-2026-33896 (digitalbazaar forge). CVSS 7.4 → 9.1 (NVD).

RESCORED — CVE-2026-57826. CVSS 9.8 → 6.8 (NVD).

RESCORED — CVE-2026-58616 (Microsoft Edge (Chromium-based)). CVSS 4.4 → 3 (NVD).

RESCORED — CVE-2026-59291 (Spring Cloud Function). CVSS 2 → 5.5 (NVD).

RESCORED — CVE-2026-59294 (Spring AI). CVSS 5.9 → 6.5 (NVD).

RESCORED — CVE-2026-59321 (Spring Integration). CVSS 4.2 → 5.4 (NVD).

RESCORED — CVE-2026-73055 (ericcornelissen shescape). CVSS 9.3 → 6.3 (NVD).

RESCORED — CVE-2026-79088 (Google Chrome). CVSS 5.4 → 6.5 (NVD).

RESCORED — CVE-2026-81934 (Redis). CVSS 9.2 → 7.5 (NVD).

RESCORED — CVE-2026-82593 (D-Link DIR-825M). CVSS 9.4 → 8.6 (NVD).

RESCORED — CVE-2026-82594 (LogNet grpc-spring-boot-starter). CVSS 2.3 → 1.3 (NVD).

RESCORED — CVE-2026-82595 (D-Link DIR-825M). CVSS 5.3 → 2.1 (NVD).

PATCH SHIPPED — CVE-2026-16730 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:36-5.el10_2.

PATCH SHIPPED — CVE-2026-5704 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 2:1.34-13.el9_8.

PATCH SHIPPED — CVE-2026-59090 (gimp). Fixed in Red Hat Enterprise Linux 9 2:3.0.4-4.el9_8.10.

ENRICHED — Spring for GraphQL: 5 CVEs (CVE-2026-59285, CVE-2026-59286, CVE-2026-59287, CVE-2026-59288, CVE-2026-59289). Received CVSS/CPE analysis.

ENRICHED — CVE-2026-59314 (Spring Framework). Received CVSS 3.7 and CPE data from NVD.

Yesterday's Results

How to read these box scores · glossary

357 CVEs published. 25 box scores, 332 table rows — nothing truncated.

ZTE ZXDU68 S202 V5.0 — Unauthenticated RCE Vulnerability in ZTE ZXDU68 S202 V5.0 Product
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   A   L   N   N  C  H  H  H    9.6   .0240   82.9     —
AFFECTED
  Product           Versions                                                                                                                                                        Fixed
  ZXDU68 S202 V5.0  ZXDU68 S202 V5.0R02M02 ACB V1.30.01.00 、ZXDU68 S202 V5.0R02M02 ACB V1.30.01.01、ZXDU68 S202 V5.0R02M02 ACB V1.30.01.02、ZXDU68 S202 V5.0R02M02 ACB V1.30.01.03 –  —
TIMELINE
  May 27  Reserved by CNA
  Aug 31  Published (CNA: zte)
CWE-287 · CNA: zte · CVSS v3.1 · 1 reference · NVD status: Received
klaussilveira GitList Git Command Line CommandLine.php getDefaultBranch os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0166   74.9     —
AFFECTED
  Product  Versions  Fixed
  GitList  2.0.0 –   3.0.0-beta
TIMELINE
  Aug 30  Reserved by CNA
  Aug 31  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Deferred
Nodemailer before 8.0.3 SMTP Command Injection via envelope.size
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0113   64.2     —
AFFECTED
  Product     Versions     Fixed
  nodemailer  unspecified  8.0.3
TIMELINE
  Aug 31  Reserved by CNA
  Aug 31  Published (CNA: VulnCheck)
CWE-93 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
TOTOLINK NR1800X cstecgi.cgi setUssd command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0113   64.1     —
AFFECTED
  Product  Versions                 Fixed
  NR1800X  9.1.0u.6681_B20230703 –  —
TIMELINE
  Aug 30  Reserved by CNA
  Aug 31  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
klaussilveira GitList XML Parsing CommandLine.php SimpleXMLElement denial of service
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    5.5   .0074   52.1     —
AFFECTED
  Product  Versions  Fixed
  GitList  2.0.0 –   3.0.0-beta
TIMELINE
  Aug 30  Reserved by CNA
  Aug 31  Published (CNA: VulDB)
CWE-404 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Deferred
Nodemailer before 8.0.5 SMTP Command Injection via CRLF
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   N   H   N    6.9   .0073   51.9     —
AFFECTED
  Product     Versions     Fixed
  nodemailer  unspecified  8.0.5
TIMELINE
  Aug 31  Reserved by CNA
  Aug 31  Published (CNA: VulnCheck)
CWE-93 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
TOTOLINK NR1800X cstecgi.cgi setUploadSetting stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0061   46.9     —
AFFECTED
  Product  Versions                 Fixed
  NR1800X  9.1.0u.6681_B20230703 –  —
TIMELINE
  Aug 30  Reserved by CNA
  Aug 31  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
ash-project ash_admin — Path traversal in AshAdmin file uploads via unsanitized client filename
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   H   N    8.3   .0059   45.6     —
AFFECTED
  Product    Versions                                    Fixed
  ash_admin  0.13.7 –                                    —
  ash_admin  e8f496b6a064ad67dc1cd30433e5921d2192d254 –  —
TIMELINE
  Aug 30  Reserved by CNA
  Aug 31  Published (CNA: EEF)
CWE-22 · CNA: EEF · CVSS v4.0 · 4 references · NVD status: Received
yaojingang GEOFlow Image Library Cleanup ImageLibraryController.php unlink path traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   N   L   L    2.0   .0044   36.4     —
AFFECTED
  Product  Versions  Fixed
  GEOFlow  2.0 –     2.1.1
TIMELINE
  Aug 30  Reserved by CNA
  Aug 31  Published (CNA: VulDB)
CWE-22 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Deferred
n/a open62541 — open62541 History Backend ua_history_data_backend_memory.c UA_DataValue_backend_copyRange use after free
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    5.5   .0040   33.6     —
AFFECTED
  Product    Versions  Fixed
  open62541  1.5.0 –   —
TIMELINE
  Aug 30  Reserved by CNA
  Aug 31  Published (CNA: VulDB)
CWE-119, CWE-416 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
n/a PowerJob — PowerJob Transport Endpoint TestController.java MuConnectionManager.getOrCreateConnection server-side request forgery
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0039   31.9     —
AFFECTED
  Product   Versions  Fixed
  PowerJob  5.1.0 –   —
TIMELINE
  Aug 30  Reserved by CNA
  Aug 31  Published (CNA: VulDB)
CWE-918 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Soarkey StudentManagement/学生信息管理系统 Administrative Servlet AdminDao.java AdminDao.doGet authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0039   31.7     —
AFFECTED
  Product            Versions                                    Fixed
  StudentManagement  e08f7f1d5015af407aa4cca0ada3dea189b4937e –  —
  学生信息管理系统           e08f7f1d5015af407aa4cca0ada3dea189b4937e –  —
TIMELINE
  Aug 30  Reserved by CNA
  Aug 31  Published (CNA: VulDB)
CWE-285, CWE-639 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
ash-project ash_ai — EEx template evaluation of prompt content in AshAi enables remote code execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   P   N   N   H   H   H    8.9   .0038   31.0     —
AFFECTED
  Product  Versions                                    Fixed
  ash_ai   0.1.0 –                                     —
  ash_ai   4aab131d40a0bd5a8cf0b3c4eaaa59d49565f3d1 –  —
TIMELINE
  Aug 30  Reserved by CNA
  Aug 31  Published (CNA: EEF)
CWE-94 · CNA: EEF · CVSS v4.0 · 4 references · NVD status: Received
yaojingang GEOFlow Superadmin Theme Editor SiteThemeEditorController.php preview code injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   L   L   L    2.0   .0037   30.3     —
AFFECTED
  Product  Versions  Fixed
  GEOFlow  2.0 –     2.1.1
TIMELINE
  Aug 30  Reserved by CNA
  Aug 31  Published (CNA: VulDB)
CWE-74, CWE-94 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Deferred
valkey-io valkey Blocked-on-keys blocked.c handleClientsBlockedOnKey use after free
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   H   N   N   N   L    1.2   .0036   28.8     —
AFFECTED
  Product  Versions  Fixed
  valkey   9.1.0 –   —
TIMELINE
  Aug 30  Reserved by CNA
  Aug 31  Published (CNA: VulDB)
CWE-119, CWE-416 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Deferred
yaojingang GEOFlow GenericHttpEndpointResolver.php DistributionController.isValidHttpEndpoint server-side request forgery
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   L   L   L    2.0   .0034   26.9     —
AFFECTED
  Product  Versions  Fixed
  GEOFlow  2.0 –     2.1.1
TIMELINE
  Aug 30  Reserved by CNA
  Aug 31  Published (CNA: VulDB)
CWE-918 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Deferred
yaojingang GEOFlow JSON-LD Theme HomeController.php cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   L   N    2.1   .0034   26.8     —
AFFECTED
  Product  Versions  Fixed
  GEOFlow  2.0 –     2.1.1
TIMELINE
  Aug 30  Reserved by CNA
  Aug 31  Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Deferred
itsourcecode Online Medicine Delivery System Login login.php employeeAuthentication sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0034   26.8     —
AFFECTED
  Product                          Versions  Fixed
  Online Medicine Delivery System  1.0 –     —
TIMELINE
  Aug 30  Reserved by CNA
  Aug 31  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
itsourcecode Online Medicine Delivery System Customer Login login.php cusAuthentication sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0034   26.8     —
AFFECTED
  Product                          Versions  Fixed
  Online Medicine Delivery System  1.0 –     —
TIMELINE
  Aug 30  Reserved by CNA
  Aug 31  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated a…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0034   26.3     —
AFFECTED
  Product           Versions     Fixed
  PowerStore 500T   unspecified  —
  PowerStore 1000T  unspecified  —
  PowerStore 1200T  unspecified  —
  PowerStore 3000T  unspecified  —
  PowerStore 3200Q  unspecified  —
  PowerStore 3200T  unspecified  —
  PowerStore 5000T  unspecified  —
  PowerStore 5200Q  unspecified  —
  PowerStore 5200T  unspecified  —
  PowerStore 7000T  unspecified  —
  + 14 more
TIMELINE
  Jul 1   Reserved by CNA
  Aug 31  Published (CNA: dell)
CWE-306 · CNA: dell · CVSS v3.1 · 1 reference · NVD status: Received
GROWI, Inc. GROWI — GROWI contains an incorrect authorization vulnerability. If this vulnerability is exploited, an unauthentic…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    6.9   .0033   26.1     —
AFFECTED
  Product  Versions     Fixed
  GROWI    unspecified  —
TIMELINE
  Aug 5   Reserved by CNA
  Aug 31  Published (CNA: jpcert)
CWE-863 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Deferred
Red Hat Red Hat build of Apache Camel for Spring Boot 4 — Undertow-core: undertow: websocketcontainer defaults for buffers and timeouts are infinite
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0033   25.8     —
AFFECTED
  Product                                          Versions     Fixed
  Red Hat build of Apache Camel for Spring Boot 4  unspecified  —
  Red Hat Enterprise Linux 10                      unspecified  —
  Red Hat Enterprise Linux 8                       unspecified  —
  Red Hat Enterprise Linux 8                       unspecified  —
  Red Hat Enterprise Linux 9                       unspecified  —
  Red Hat Fuse 7                                   unspecified  —
  Red Hat JBoss Enterprise Application Platform 7  unspecified  —
  Red Hat JBoss Enterprise Application Platform 7  unspecified  —
  Red Hat JBoss Enterprise Application Platform 7  unspecified  —
  Red Hat JBoss Enterprise Application Platform 7  unspecified  —
  + 3 more
TIMELINE
  Aug 27  Reserved by CNA
  Aug 31  Published (CNA: redhat)
CWE-770 · CNA: redhat · CVSS v3.1 · 2 references · NVD status: Received
BareBones BBEdit Java Language recursion
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   N   L    5.3   .0033   25.5     —
AFFECTED
  Product  Versions  Fixed
  BBEdit   15.5.0 –  16.0
TIMELINE
  Aug 30  Reserved by CNA
  Aug 31  Published (CNA: VulDB)
CWE-404, CWE-674 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
BareBones BBEdit Lasso Language Tokenizer infinite loop
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   N   L    5.3   .0033   25.5     —
AFFECTED
  Product  Versions  Fixed
  BBEdit   15.5.0 –  16.0
TIMELINE
  Aug 30  Reserved by CNA
  Aug 31  Published (CNA: VulDB)
CWE-404, CWE-835 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
hulumi policies — @hulumi/policies before 1.3.2 Evidence Validation Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0033   25.2     —
AFFECTED
  Product   Versions     Fixed
  policies  unspecified  1.3.2
TIMELINE
  Aug 31  Reserved by CNA
  Aug 31  Published (CNA: VulnCheck)
CWE-693 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-825985.523.4n/aSeaCMSCWE-74SeaCMS Template search.php parseIf code injection
CVE-2026-826245.523.4code-projectsSimple Inventory SystemCWE-200code-projects Simple Inventory System Database Backup File inventorymanagemen…
CVE-2026-825647.123.3ash-projectash_aiCWE-639Identity tool filter in AshAi accepts operator maps, allowing update or destr…
CVE-2026-825992.123.3n/aSeaCMSCWE-22SeaCMS Avatar Upload member.php unlink path traversal
CVE-2026-826025.522.9n/aSeaCMSCWE-285SeaCMS ass.php authorization
CVE-2026-826292.022.8jeecgbootjeewx-bootCWE-284jeecgboot jeewx-boot doUpload Endpoint MyJwWebJwid3Controller.java MyJwWebJwi…
CVE-2024-583796.922.6nodemailernodemailerCWE-1333nodemailer before 6.9.9 ReDoS via attachDataUrls parameter
CVE-2026-818522.122.6ash-projectash_adminCWE-330AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass
CVE-2026-826032.122.6n/aSeaCMSCWE-22SeaCMS Comment Cache member.php del_pl path traversal
CVE-2026-826192.122.4SysterelS2OPCCWE-119Systerel S2OPC subscription_mgr.c use after free
CVE-2026-828599.322.3kerberosmansourhulumiCWE-284hulumi before v1.3.2 SCP Template Tag-on-Create Bypass
CVE-2026-828609.322.3hulumipoliciesCWE-269@hulumi/policies before 1.3.2 Admin Policy Bypass
CVE-2026-757578.322.3ash-projectash_adminCWE-565AshAdmin cookie reader matches names by substring, enabling actor/session sha…
CVE-2026-827266.322.3ash-projectash_phoenixCWE-178AshPhoenix get_subdomain maps a crafted or differently-cased Host header to a…
CVE-2026-536205.320.9GROWI, Inc.GROWICWE-639GROWI contains a vulnerability with an authorization bypass through user-cont…
CVE-2026-826075.520.9CozmoslabsProfile Builder PluginCWE-284Cozmoslabs Profile Builder Plugin Avatar Simple Upload AJAX admin-ajax.php wp…
CVE-2026-828569.320.5hulumipoliciesCWE-284@hulumi/policies before 1.3.2 OIDC Trust Policy Bypass
CVE-2026-828579.320.5kerberosmansourhulumiCWE-269hulumi before v1.3.2 Privilege Escalation via IAM Policy
CVE-2026-757607.120.4ash-projectash_aiCWE-209AshAi vectorize change leaks raw embedding-provider errors, including credent…
CVE-2026-778508.419.8ash-projectash_adminCWE-79Stored XSS in AshAdmin relationship typeahead via unescaped label_field content
CVE-2026-826012.119.9n/aSeaCMSCWE-79SeaCMS err.php cross site scripting
CVE-2026-826185.319.7SysterelS2OPCCWE-119Systerel S2OPC String Array Range Writing sopc_builtintypes.c set_range_matri…
CVE-2026-826252.119.2code-projectsSimple Inventory SystemCWE-79code-projects Simple Inventory System User Registration register.php cross si…
CVE-2026-826155.518.6itsourcecodeOnline Medicine Delivery SystemCWE-74itsourcecode Online Medicine Delivery System Password Recovery passwordrecove…
CVE-2026-827228.318.6ash-projectash_adminCWE-770AshAdmin LiveView events intern atoms from client input, exhausting the atom …
CVE-2026-825796.018.6ash-projectash_aiCWE-835AshAi tool loop never terminates when all tool calls are filtered out, enabli…
CVE-2026-825805.318.6ash-projectash_aiCWE-209AshAi echoes raw tool exception messages into the conversation, disclosing in…
CVE-2026-827272.318.6ash-projectash_phoenixCWE-209AshPhoenix Form.Auto leaks submitted params in an unknown _union_type error m…
CVE-2026-826812.018.6ash-projectash_adminCWE-116Query-parameter injection in AshAdmin row-action links via unencoded string p…
CVE-2026-826125.517.9itsourcecodeOnline Medicine Delivery SystemCWE-74itsourcecode Online Medicine Delivery System Product Detail index.php loadRes…
CVE-2026-826135.517.9itsourcecodeOnline Medicine Delivery SystemCWE-74itsourcecode Online Medicine Delivery System Product Search index.php loadRes…
CVE-2026-826145.517.9itsourcecodeOnline Medicine Delivery SystemCWE-74itsourcecode Online Medicine Delivery System Product Category Filter index.ph…
CVE-2026-828727.117.2ToolJetToolJetCWE-639ToolJet before v3.16.208 Cross-Workspace Authorization Bypass
CVE-2026-818532.317.3ash-projectash_adminCWE-639AshAdmin composite primary key decoding accepts arbitrary fields, enabling a …
CVE-2026-827252.317.3ash-projectash_phoenixCWE-639AshPhoenix FilterForm allows filtering across non-public relationships, discl…
CVE-2026-828742.417.2ToolJetToolJetCWE-639ToolJet before v3.16.208 Cross-Tenant Authorization Bypass via tooljet-db
CVE-2026-828618.717.0hulumipoliciesCWE-284@hulumi/policies before 1.3.2 SecureBucket Parent Spoof Bypass
CVE-2026-826597.116.7nodemailernodemailerCWE-73nodemailer before 9.0.1 File Read and SSRF via raw option
CVE-2026-826005.516.7n/aSeaCMSCWE-74SeaCMS zyapi.php sql injection
CVE-2026-828647.116.0pdfmepdf-libCWE-409pdfme pdf-lib before 5.5.10 Denial of Service via Decompression Bomb
CVE-2026-827247.615.7ash-projectash_phoenixCWE-863Broken access control in AshPhoenix SubdomainHook via a nil tenant in handle_…
CVE-2026-583015.914.4Apache Software FoundationApache ShiroCWE-918Apache Shiro: Server-side POST request may be steered to an alternate host
CVE-2026-828386.414.1pretixvenuelessCWE-80Default webserver configuration with incorrect CSP
CVE-2026-826082.114.1n/aKamailioCWE-119Kamailio AVP cxdx_avp.c get_4bytes out-of-bounds
CVE-2026-828698.212.2ToolJetToolJetCWE-639ToolJet Database before v3.16.44 Privilege Escalation via join_tables
CVE-2026-828718.212.2ToolJetToolJetCWE-862ToolJet before v3.16.208 Cross-Organization Data Read via Database Routes
CVE-2026-828707.012.1ToolJetToolJetCWE-639ToolJet before v3.16.208 Cross-Tenant Database Manipulation
CVE-2026-828668.912.0pdfmecommonCWE-918@pdfme/common before 5.5.10 SSRF via Unvalidated URL Fetch
CVE-2026-826202.110.4SoarkeyStudentManagementCWE-74Soarkey StudentManagement/学生信息管理系统 CourseDao.java CourseDao.course_ranking sq…
CVE-2026-826092.19.9itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System inv_edit.php sql injection
CVE-2026-826222.09.7code-projectsEmployee Leave Managing SystemCWE-79code-projects Employee Leave Managing System Employee Profile Update editacti…
CVE-2026-194109.49.5Google CloudGoogle Cloud BuildCWE-345Google Cloud Build Comment Control Bypass via Webhook Suppression
CVE-2026-813157.48.7ash-projectash_aiCWE-346MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-…
CVE-2026-826615.38.7nodemailernodemailerCWE-93Nodemailer CRLF Injection via List-* Header Comments
CVE-2026-826605.38.6nodemailernodemailerCWE-862Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess
CVE-2026-828589.38.5hulumidriftCWE-345@hulumi/drift before 1.3.2 Unsafe Execute Plan Acceptance
CVE-2026-828675.37.9pdfmeschemasCWE-79@pdfme/schemas before 5.5.9 Cross-Site Scripting via Select
CVE-2026-828735.37.9ToolJetToolJetCWE-639ToolJet through 3.0.0-ee-beta.2 Cross-workspace Schema Disclosure via Export
CVE-2026-826714.65.3IObitUnlockerCWE-266IObit Unlocker IRP_MJ_DEVICE_CONTROL IObitUnlocker.sys ZwTerminateProcess pri…
CVE-2026-828685.34.9pdfmeschemasCWE-79@pdfme/schemas before 5.5.9 Cross-Site Scripting via SVG
CVE-2026-828638.74.1hulumibaselineCWE-778@hulumi/baseline before 1.3.2 CloudTrail Selector Tampering Detection
CVE-2026-826704.84.1IObitUninstallerCWE-266IObit Uninstaller IOCTL IUForceDelete.sys IRP_MJ_DEVICE_CONTROL privileges ma…
CVE-2026-404637.63.8NokiaWaveSuiteCWE-284An Insufficient Role-based Access Control Vulnerability in WaveSuite
CVE-2026-404655.33.6NokiaNSPCWE-601An Open Re-direct Vulnerability in Nokia NSP
CVE-2026-828755.13.6ToolJetToolJetCWE-863ToolJet before v3.16.208 Authorization Bypass via organizationId
CVE-2026-404645.43.4NokiaNSPCWE-79A Stored Cross-Site Scripting (XSS) Vulnerability in Nokia NSP
CVE-2026-770135.33.4Unknown爱采集数据采集和发布插件CWE-862Icollect <= 1.0.0 - Unauthenticated User and Term Creation via Unrestricted M…
CVE-2026-828628.63.0kerberosmansourhulumiCWE-426Hulumi before v1.3.2 Helper Script Shadowing via Workspace Files
CVE-2026-828652.12.6pdfmeschemasCWE-79pdfme schemas before 5.5.10 Cross-Site Scripting via i18n Label
CVE-2026-826628.32.4nodemailernodemailerCWE-295Nodemailer before 8.0.8 TLS Certificate Validation Bypass
CVE-2026-826289.31.8ColorfuliGameCenterCWE-266Colorful iGameCenter IOCTL Dispatch WinRing0x64.sys sub_11504 privileges mana…
CVE-2026-825961.91.6n/aLatencyUtilsCWE-119LatencyUtils PauseDetector LatencyStats.java LatencyStats.recordDetectedPause…
CVE-2026-8177910.0—Silk ThemesNewspapers XCWE-1284WordPress Newspapers X theme 1.0.46-1.0.48 - Backdoor vulnerability
CVE-2026-8178010.0—hashthemesHash FormCWE-434WordPress Hash Form plugin <= 1.4.2 - Arbitrary File Upload vulnerability
CVE-2026-8297010.0—WP Legal PagesWP Cookie Notice for GDPR, CCPA & ePrivacy ConsentCWE-434WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.4.1 …
CVE-2026-797489.9—samanhappymcphubCWE-862MCPHub: Authenticated non-admin user achieves RCE via POST /api/servers (miss…
CVE-2026-822269.8—TickeraTickeraCWE-502WordPress Tickera plugin <= 3.6.0.2 - PHP Object Injection vulnerability
CVE-2026-535529.6—zhenorzzgoployCWE-639Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and …
CVE-2026-591119.3—Ministry of the Interior (MVČR)eObčanka-IdentifikaceCWE-78Command Injection vulnerability in eObčanka-Identifikace
CVE-2026-738199.3—EbyteEbyte NA111-M FirmwareCWE-1390Ebyte NA111-M Weak Authentication
CVE-2026-761339.3—EbyteEbyte NA111-M FirmwareCWE-327Ebyte NA111-M Use of a Broken or Risky Cryptographic Algorithm
CVE-2026-812939.3—Passionate Programmer PeterWP Data AccessCWE-89WordPress WP Data Access plugin <= 5.5.81 - SQL Injection vulnerability
CVE-2026-817569.3—Autorius E-goiSmart Marketing SMS and Newsletters FormsCWE-89WordPress Smart Marketing SMS and Newsletters Forms plugin <= 5.1.24 - SQL In…
CVE-2026-817639.3—ウェブ屋のさとーさんThrows SPAM AwayCWE-89WordPress Throws SPAM Away plugin <= 3.8.2 - SQL Injection vulnerability
CVE-2026-826939.3—TendaAC1206CWE-287Tenda AC1206 Web UI telnet TendaTelnet missing authentication
CVE-2026-826949.3—TendaAC1206CWE-287Tenda AC1206 Web UI ate R7WebsSecurityHandler missing authentication
CVE-2026-826959.3—TendaAC18CWE-287Tenda AC18 Telnet telnet missing authentication
CVE-2026-828769.3—Phison Electronics CorporationPS3111-S11 Controller FirmwareCWE-347Phison PS3111-S11 Controller Firmware Signature Verification Bypass
CVE-2026-829719.3—QVidiumOpera11CWE-74QVidium Opera11 CGI Script net_tr.cgi command injection
CVE-2026-660479.2—Proper FractionProfilePressCWE-306ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Insta…
CVE-2026-516799.1—n/an/aCWE-284Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5c…
CVE-2026-516809.1—n/an/aCWE-284Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748…
CVE-2026-516819.1—n/an/aCWE-284Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.…
CVE-2026-517209.1—n/an/aCWE-284Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 …
CVE-2026-517259.1—n/an/aCWE-284Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5…
CVE-2026-517309.1—n/an/aCWE-284Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5…
CVE-2026-780788.9—joomshaper.comHelix Ultimate extension for JoomlaCWE-434Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content…
CVE-2026-59568.8—Ankara HostingSite Management PanelCWE-89SQLi in Ankara Hosting's Site Management Panel
CVE-2026-128948.8—Red HatRed Hat build of Apache Camel 4 for Quarkus 3CWE-1336Quarkus-qute: io.quarkus.qute.reflectionvalueresolver: quarkus:server-side te…
CVE-2026-780748.8—miniorgange.comminiOrange Oauth Client (free) extension for JoomlaCWE-284Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension dein…
CVE-2026-797448.8—samanhappymcphubCWE-269MCPHub: Missing Authorization on `PUT /api/system-config` Lets Any Non-Admin …
CVE-2026-822178.8—Eclipse FoundationEclipse TheiaCWE-22In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agen…
CVE-2026-835968.8—Red HatRed Hat Enterprise Linux 6CWE-120Webkitgtk: validate the full featurelist array once in opentypeverticaldata f…
CVE-2026-751338.7—Fahad MahmoodKeep Backup DailyCWE-306Keep Backup Daily WordPress Plugin < 2.1.4 Sensitive Information Exposure via…
CVE-2026-779668.7—EbyteEbyte NA111-M FirmwareCWE-862Ebyte NA111-M Missing Authorization
CVE-2026-828808.7—yacyyacy_search_serverCWE-611YaCy Search Server through 1.941 XML External Entity Injection via Parsers
CVE-2026-828828.7—devtron-labsdevtronCWE-862Devtron through 2.2.0 Missing Authorization via webhook API token endpoint
CVE-2026-834978.7—OpenSearchOpenSearchCWE-502Unrestricted Java Deserialization in OpenSearch SQL Plugin Cursor Pagination
CVE-2026-720018.6—PangolinPangolinCWE-639Pangolin < 1.22.0 Authentication Bypass via Share-Link Endpoint
CVE-2026-780778.6—joomshaper.comHelix Ultimate extension for JoomlaCWE-79Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in Mega…
CVE-2026-818898.6—Studio-42elFinderCWE-918elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents…
CVE-2026-826898.6—D-LinkDNS-320LCWE-77D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 ISO Image isomount_mgr.cgi os comma…
CVE-2026-826928.6—D-LinkDNS-340LCWE-77D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection
CVE-2026-829548.6—n/aDokployCWE-22Dokploy Settings application.ts writeTraefikConfigInPath path traversal
CVE-2026-835248.6—RedPortOptimizer wXa-203CWE-74RedPort Optimizer wXa-223 System Clock datetime.php exec command injection
CVE-2026-616398.5—elliteWallosCWE-22Wallos: Zip Slip path traversal in database restore writes files to webroot
CVE-2026-616408.5—elliteWallosCWE-918Wallos: SSRF via OIDC Token/UserInfo URL Configuration
CVE-2026-812878.5—Syed BalkhiCharitableCWE-89WordPress Charitable plugin <= 1.8.12.1 - SQL Injection vulnerability
CVE-2026-826888.5—D-LinkDNS-340LCWE-77D-Link DNS-340L/DNS-345 Virtual Volume virtual_vol.cgi os command injection
CVE-2026-826908.5—D-LinkDNS-327LCWE-77D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection
CVE-2026-826918.5—D-LinkDNS-320LCWE-77D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injec…
CVE-2026-828078.5—ieungSoftUltra RAMDisk ProCWE-266ieungSoft Ultra RAMDisk Pro Kernel Driver URDSCSI.sys privileges management
CVE-2026-829088.5—MSIDragon CenterCWE-189MSI Dragon Center MMIO Write Path NTIOLib_X64.sys MmioWritePath integer overflow
CVE-2026-535078.3—oasdiffoasdiff-actionCWE-200oasdiff actions resolve external $refs by default, enabling SSRF and disclosu…
CVE-2026-546008.2—elliteWallosCWE-287Wallos: Unauthenticated database replacement via import endpoint on fresh ins…
CVE-2026-616388.2—elliteWallosCWE-918Wallos: SSRF via Test Email Notification - unvalidated SMTP host/port
CVE-2026-755948.2—getkirbykirbyCWE-22Kirby: Access to image files and limited access to JSON files outside of the …
CVE-2026-773488.2—elliteWallosCWE-441Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still …
CVE-2026-616418.1—elliteWallosCWE-287Wallos: OIDC account takeover via email-based account linking without `email_…
CVE-2026-797468.1—samanhappymcphubCWE-863MCPHub: Server-scoped bearer key gains access to an entire group via partial …
CVE-2026-818918.1—Studio-42elFinderCWE-434elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file up…
CVE-2026-818928.1—EasyCorpEasyAdminBundleCWE-639EasyAdmin custom-action dispatcher bypasses access_control on other routes
CVE-2026-822288.1—SiteGroundSiteGround SecurityCWE-290WordPress SiteGround Security plugin <= 1.6.6 - 2FA Bypass vulnerability
CVE-2026-137327.8—Red HatRed Hat Enterprise Linux 10CWE-787Gdb: gdb: out-of-bounds write in stabs parser read_member_functions() via cra…
CVE-2026-197027.8—TÜBİTAK BİLGEM Software Technologies Research InstitutePardus Boot RepairCWE-78OS Command Injection in TÜBİTAK BİLGEM's Pardus Boot Repair
CVE-2026-535537.7—zhenorzzgoployCWE-22Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Rem…
CVE-2026-797507.7—samanhappymcphubCWE-639MCPHub authenticated horizontal IDOR: any non-admin user executes tools on ot…
CVE-2026-797497.6—samanhappymcphubCWE-918MCPHub: SSRF Guard Bypass via IPv6 Transition Addresses in URL Validation
CVE-2026-176157.5—Red HatRed Hat build of Apache Camel 4 for Quarkus 3CWE-611Resteasy-core: resteasy sourceprovider remote unauthenticated file read
CVE-2026-196167.5—TBC Technology Inc.KitLogisticCWE-862Information Disclosure in TBC Technology's KitLogistic
CVE-2026-198737.5——HTML-FormFuCWE-770HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an …
CVE-2026-545987.5—elliteWallosCWE-306Missing Authentication for Critical Function in wallos
CVE-2026-545997.5—elliteWallosCWE-352Wallos: OIDC state parameter never validated — login CSRF / account takeover
CVE-2026-767637.5—Red HatRed Hat build of QuarkusCWE-1284Io.smallrye/smallrye-graphql: smallrye graphql: unauthenticated denial of ser…
CVE-2026-812967.5—WP Manage NinjaFluent Forms Pro Add On PackCWE-862WordPress Fluent Forms Pro Add On Pack plugin <= 6.2.12 - Broken Access Contr…
CVE-2026-812977.5—WP Manage NinjaFluent Forms Pro Add On PackCWE-266WordPress Fluent Forms Pro Add On Pack plugin <= 6.2.12 - Privilege Escalatio…
CVE-2026-823937.5—pnpmpnpmCWE-22pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary…
CVE-2026-823977.5—tornadowebtornadoCWE-400Tornado: Urlencoded body parsing omits max_num_fields, so one request can sta…
CVE-2026-822257.4—MetagaussRegistrationMagicCWE-288WordPress RegistrationMagic plugin <= 6.0.9.8 - Broken Authentication vulnera…
CVE-2026-826807.4—D-LinkDSM-G600CWE-119D-Link DSM-G600 Multipart load_file.cgi out-of-bounds write
CVE-2026-784227.3—z-galaxyzbus_polkitCWE-367zbus_polkit: polkit authorization bypass via PID reuse due to incorrect D-Bus…
CVE-2026-714157.1—getkirbykirbyCWE-862Kirby: File upload permissions are not checked during processing of chunk data
CVE-2026-751327.1—Tranquil_ITWAPTCWE-89WAPT Server SQL Injection via /api/v3/hosts Endpoint
CVE-2026-779757.1—EbyteEbyte NE2-D11 FirmwareCWE-312Ebyte NA111-M Cleartext Storage of Sensitive Information
CVE-2026-797457.1—samanhappymcphubCWE-862MCPHub: Missing Authorization on Built-in Prompt & Resource CRUD (Unauthorize…
CVE-2026-797477.1—samanhappymcphubCWE-918MCPHub vulnerable to SSRF: a non-admin user can make mcphub request arbitrary…
CVE-2026-812907.1—IcegramEmail Subscribers & NewslettersCWE-79WordPress Email Subscribers & Newsletters plugin <= 5.9.33 - Cross Site Scrip…
CVE-2026-812917.1—UncodeUncodeCWE-79WordPress Uncode theme <= 2.12.7 - Cross Site Scripting (XSS) vulnerability
CVE-2026-812987.1—varunvairavanlcLeadConnectorCWE-79WordPress LeadConnector plugin <= 4.0.5 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-817647.1—AcatoEmail EssentialsCWE-79WordPress Email Essentials plugin <= 6.0.6 - Cross Site Scripting (XSS) vulne…
CVE-2026-817657.1—Tailored MediaTailored ToolsCWE-79WordPress Tailored Tools plugin <= 3.0.2 - Cross Site Scripting (XSS) vulnera…
CVE-2026-817687.1—highwardenSuper Store FinderCWE-79WordPress Super Store Finder plugin <= 7.10 - Cross Site Scripting (XSS) vuln…
CVE-2026-822217.1—MetagaussRegistrationMagicCWE-79WordPress RegistrationMagic plugin <= 6.0.9.8 - Cross Site Scripting (XSS) vu…
CVE-2026-822247.1—iova.mihaiSliceWPCWE-79WordPress SliceWP plugin <= 1.2.10 - Cross Site Scripting (XSS) vulnerability
CVE-2026-822297.1—miniOrangeWordPress Social Login and RegisterCWE-79WordPress WordPress Social Login and Register plugin <= 7.8.2 - Cross Site Sc…
CVE-2026-823927.1—pnpmpnpmCWE-22pnpm: Virtual store linker path traversal via unvalidated depPath name in loc…
CVE-2026-828777.1—ILIAS-eLearning e.V.ILIASCWE-22ILIAS before 9.22 Arbitrary File Read via SOAP addFile
CVE-2026-823467.0—HP IncHP ImageDiagsCWE-379HP ImageDiags - Potential Escalation of Privilege
CVE-2026-629936.9—smarty-phpsmartyCWE-918Smarty: SSRF via redirect bypass of trusted_uri using {fetch}
CVE-2026-755926.9—getkirbykirbyCWE-22Kirby: Access to image files outside of the site root via path traversal in t…
CVE-2026-797436.9—samanhappymcphubCWE-22MCPHub: Path Traversal via Malicious MCPB Manifest Name
CVE-2026-823986.9—py-pdfpypdfCWE-407pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace
CVE-2026-834926.9—Extend ThemesKubio AI Website BuilderCWE-20WordPress Kubio AI Website Builder - Denial Of Service
CVE-2026-146966.5—zephyrprojectzephyrCWE-401Ethernet bridge RX packet leak enables denial of service via RX buffer-pool e…
CVE-2026-146976.5—zephyrprojectzephyrCWE-401IPv6 Neighbor Solicitation packet leak causes TX pool exhaustion denial of se…
CVE-2026-812806.5—UKR SolutionPrint Barcode Labels for your WooCommerce products/ordersCWE-201WordPress Print Barcode Labels for your WooCommerce products/orders plugin <=…
CVE-2026-817626.5—magepeopleteamBooking and Rental ManagerCWE-862WordPress Booking and Rental Manager plugin <= 2.7.6 - Broken Access Control …
CVE-2026-817786.5—The4Kalles AddonsCWE-79WordPress Kalles Addons plugin <= 1.0.6 - Cross Site Scripting (XSS) vulnerab…
CVE-2023-205116.4—AMDAMD Radeon™ Instinct™ MI25 Graphics ProductsCWE-763Release of an invalid pointer in the AMD kernel mode driver (KMD) could allow…
CVE-2026-143666.4—zephyrprojectzephyrCWE-416SiWx91x WiFi driver double-unref / use-after-free of caller-owned TX net_pkt
CVE-2026-817586.3—OwnerRezOwnerRez APICWE-862WordPress OwnerRez API plugin <= 1.2.6 - Broken Access Control vulnerability
CVE-2026-769866.1—Apache Software FoundationApache WicketCWE-79Apache Wicket: XSS in AbstractSingleSelectChoice via getNullValidDisplayValue
CVE-2026-535086.0—oasdiffoasdiffCWE-73oasdiff does not enforce --allow-external-refs=false on the git-revision load…
CVE-2026-826985.5—sambitrajStudent-Management-SystemCWE-1393sambitraj Student-Management-System aca.sql default password
CVE-2026-827015.5—code-projectsOnline Shopping SystemCWE-74code-projects Online Shopping System Search Functionality action.php sql inje…
CVE-2026-827975.5—Samsung Open SourcerlottieCWE-674Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Se…
CVE-2026-828015.5—NASAearthdata-searchCWE-918NASA earthdata-search scale Endpoint handler.js scaleImage server-side reques…
CVE-2026-828025.5—NASAearthdata-searchCWE-918NASA earthdata-search granules Endpoint handler.js OpenSearchGranuleSearchLam…
CVE-2026-828035.5—arminkstruct2jsonCWE-404armink struct2json JSON Deserialization s2jdef.h S2J_STRUCT_GET_string_ELEMEN…
CVE-2026-828085.5—Inbox FoundryActiveInbox ExtensionCWE-259Inbox Foundry ActiveInbox Extension Google OAuth Client Secret service-worker…
CVE-2026-828155.5—MegaEaseEaseProbeCWE-266MegaEase EaseProbe Middleware server.go realIP access control
CVE-2026-829145.5—kishan0725Hospital-Management-SystemCWE-74kishan0725 Hospital-Management-System search.php sql injection
CVE-2026-829195.5—cusiliconCWE-287cu silicon edit Endpoint views.py create_app missing authentication
CVE-2026-829215.5—ShopExECShopCWE-284ShopEx ECShop pack.php check_img_type unrestricted upload
CVE-2026-829225.5—ShopExECShopCWE-74ShopEx ECShop flow.php flow_update_cart sql injection
CVE-2026-829575.5—hyperledger-fireflyfireflyCWE-918hyperledger-firefly Webhook Subscription webhooks.go ValidateOptions server-s…
CVE-2026-143685.4—zephyrprojectzephyrCWE-193Off-by-one out-of-bounds NUL write in Zephyr LwM2M JSON string parser
CVE-2026-812675.4—MozillaFirefox for iOSCWE-451Stalled popup navigation could allow address bar origin spoofing in Firefox f…
CVE-2026-812785.4—WPExpertsPost SMTPCWE-862WordPress Post SMTP plugin 4.0.0-beta.1 - Settings Change vulnerability
CVE-2026-818885.4—honojs@hono/oauth-providersCWE-352@hono/oauth-providers: OAuth state check fails open on omitted state, enablin…
CVE-2026-818905.4—Studio-42elFinderCWE-352elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP conne…
CVE-2026-823965.4—sulusuluCWE-79Sulu: Stored XSS via media download inline-disposition override
CVE-2026-828525.4—MapSVGMapSVGCWE-918WordPress MapSVG plugin <= 8.15.0 - Server Side Request Forgery (SSRF) vulner…
CVE-2026-704495.3—Apache Software FoundationApache WicketCWE-22Apache Wicket: Path traversal in resource style/variation/locale
CVE-2026-740105.3—John James JacobybbPressCWE-862WordPress bbPress plugin <= 2.6.14 - Broken Access Control vulnerability
CVE-2026-780795.3—joomshaper.comHelix Ultimate extension for JoomlaCWE-601Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content…
CVE-2026-823945.3—sulusuluCWE-862Sulu: Fix authorization bypass when creating preview links
CVE-2026-823955.3—sulusuluCWE-639Sulu: Media move/update authorization bypass (IDOR)
CVE-2026-828785.3—dataeasedataeaseCWE-862DataEase before 2.10.26 Missing Object-Level Authorization on Geographic, Lin…
CVE-2026-828795.3—dataeasedataeaseCWE-863DataEase before 2.10.26 Access Control Bypass via Share Tickets
CVE-2026-758025.1—Apache Software FoundationApache WicketCWE-79Apache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRendere…
CVE-2026-769825.1—Apache Software FoundationApache WicketCWE-79Apache Wicket: XSS in Button via its model object
CVE-2026-769835.1—Apache Software FoundationApache WicketCWE-79Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabel
CVE-2026-769845.1—Apache Software FoundationApache WicketCWE-79Apache Wicket: XSS in MetaDataHeaderItem via addTagAttribute
CVE-2026-769855.1—Apache Software FoundationApache WicketCWE-79Apache Wicket: XSS in Palette via getAdditionalAttributes
CVE-2026-780755.1—joomshaper.comHelix Ultimate extension for JoomlaCWE-639Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog…
CVE-2026-780765.1—joomshaper.comHelix Ultimate extension for JoomlaCWE-284Joomla Extension - joomshaper.com - Broken Access Control & Missing Authoriza…
CVE-2026-818875.1—livewirelivewireCWE-79Livewire DOM-based cross-site scripting during client-side state handling
CVE-2026-828815.1—apconwAix-DBCWE-79Aix-DB through 1.2.4 Stored Cross-Site Scripting via Markdown
CVE-2026-713784.6—Apache Software FoundationApache WicketCWE-352Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in Resourc…
CVE-2026-773534.6—elliteWallosCWE-74Wallos: iCalendar Injection via CRLF in Subscription Name/Notes Export
CVE-2026-541794.4—Laravel-BackpackCRUDCWE-79backpack/crud: SingleBase64Image accepts any base64 payload behind a `data:im…
CVE-2026-501984.3—elliteWallosCWE-639Wallos: Cross-user subscription cost inference via replacement_subscription_id
CVE-2026-501994.3—elliteWallosCWE-863Wallos: Cross-user Fixer/API Layer credential consumption in exchange-rate re…
CVE-2026-527304.3—xibosignagexibo-cmsCWE-862Xibo CMS Missing Authorization in Module::settingsForm due to PHP operator pr…
CVE-2026-773524.3—elliteWallosCWE-918Wallos: Authenticated SSRF via per-user SMTP notification host (low-privilege…
CVE-2026-773513.5—elliteWallosCWE-918Wallos: SSRF via Unvalidated User-Level SMTP Host in Email Notification Settings
CVE-2023-313083.3—AMDAMD Radeon™ PRO V620 Graphics ProductsCWE-129A malicious virtual function can invoke the certain command handlers in the S…
CVE-2026-143673.1—zephyrprojectzephyrCWE-362I3C IBI work-node free-list data race between ISR and workqueue thread
CVE-2026-218273.1—HCLSoftwareConnectionsCWE-359HCL Connections is vulnerable to an information disclosure vulnerability
CVE-2026-826972.9—sambitrajStudent-Management-SystemCWE-732sambitraj Student-Management-System session_start cookie httponly flag
CVE-2026-829062.9—sdcbchatsCWE-287sdcb chats Signed File Download Endpoint FileController.cs DownloadPublic mis…
CVE-2026-826792.1—diem-projectdiemCWE-284diem-project diem Widget Editor dmWidgetContentBaseMediaForm.php unrestricted…
CVE-2026-826962.1—itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System inv_searchfrm.php sql injection
CVE-2026-827002.1—code-projectsOnline Shopping SystemCWE-79code-projects Online Shopping System Newsletter Subscription offersmail.php c…
CVE-2026-828052.1—n/aTyporaCWE-79Typora Mermaid Rendering cross site scripting
CVE-2026-828092.1—vidIQVision for YouTube ExtensionCWE-200vidIQ Vision for YouTube Extension postMessage window.addEventListener inform…
CVE-2026-828112.1—Toggl OÜToggl Track ExtensionCWE-345Toggl OÜ Toggl Track Extension postMessage origin validation
CVE-2026-828132.1—BEN GroupTubeBuddy for YouTube ExtensionCWE-345BEN Group TubeBuddy for YouTube Extension tubebuddymaster1.js TBGlobal.GetTok…
CVE-2026-828162.1—dibo-softwaredibootCWE-285dibo-software diboot AI Session Endpoint ai-session authorization
CVE-2026-828172.1—dibo-softwaredibootCWE-266dibo-software diboot Tenant Administrator Management API admin access control
CVE-2026-828182.1—dibo-softwaredibootCWE-266dibo-software diboot Tenant Resource Assignment resource access control
CVE-2026-828202.1—n/aFLVMetaCWE-119FLVMeta AMF String Processing amf.c amf_string_new heap-based overflow
CVE-2026-828212.1—n/aFLVMetaCWE-404FLVMeta AMF Object Parsing amf.c amf_object_get null pointer dereference
CVE-2026-828332.1—DoccanoOpen Source Annotation Tools for Machine Learning PractitionersCWE-266Doccano Open Source Annotation Tools for Machine Learning Practitioners Proje…
CVE-2026-828342.1—DoccanoOpen Source Annotation Tools for Machine Learning PractitionersCWE-266Doccano Open Source Annotation Tools for Machine Learning Practitioners Bulk-…
CVE-2026-828352.1—caoqianmingdjango-vue-adminCWE-266caoqianming django-vue-admin file access control
CVE-2026-829052.1—sdcbchatsCWE-918sdcb chats fetch-tools Endpoint McpController.cs McpController server-side re…
CVE-2026-829092.1—QuantumNousnew-apiCWE-613QuantumNous new-api Revoked API Token token session expiration
CVE-2026-826782.0—diem-projectdiemCWE-77diem-project diem Administrative Console actions.class.php executeCommand os …
CVE-2026-826992.0—sambitrajStudent Management SystemCWE-310sambitraj Student Management System Password aca.sql cleartext storage
CVE-2026-827022.0—EdimaxBR-6214KCWE-77Edimax BR-6214K asp_WlanMP Endpoint wlanMP.asp system os command injection
CVE-2026-827032.0—EdimaxBR-6214KCWE-77Edimax BR-6214K asp_setPing Endpoint ping.asp system os command injection
CVE-2026-826771.9—valkey-iovalkeyCWE-119valkey-io valkey Module Timer module.c moduleTimerHandler double free
CVE-2026-828101.9—extension.vn2FA Authenticator ExtensionCWE-200extension.vn 2FA Authenticator Extension Background Service Worker chrome.run…
CVE-2025-63607await—n/an/a—TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display…
CVE-2026-19953await——URICWE-1289URI versions before 5.36 for Perl encode non-NFC host names to non-standard p…
CVE-2026-38577await—n/an/a—Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-2603…
CVE-2026-51152await—n/an/a—Server-side request forgery (SSRF) in the /har/test endpoint in QD 20220208 t…
CVE-2026-51153await—n/an/a—Stored Cross-Site Scripting (XSS) in TaskRunHandler.post() in web/handlers/ta…
CVE-2026-51666await—n/an/a—Incorrect access control in the setWizardCfg function of TOTOLINK T6 4.1.5cu.…
CVE-2026-51667await—n/an/a—Incorrect access control in the getWiFiIpMacTable function of TOTOLINK T6 4.1…
CVE-2026-51668await—n/an/a—Incorrect access control in the setLanguageCfg function of TOTOLINK T6 4.1.5c…
CVE-2026-51669await—n/an/a—Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.5cu.74…
CVE-2026-51670await—n/an/a—Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 4.1.5c…
CVE-2026-51671await—n/an/a—Incorrect access control in the getCloudDownloadStatus function of TOTOLINK T…
CVE-2026-51672await—n/an/a—Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4.1.5cu…
CVE-2026-51673await—n/an/a—Incorrect access control in the setNtpCfg function of TOTOLINK T6 4.1.5cu.748…
CVE-2026-51674await—n/an/a—Incorrect access control in the setScheduleCfg function of TOTOLINK T6 4.1.5c…
CVE-2026-51675await—n/an/a—Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1.5cu.7…
CVE-2026-51676await—n/an/a—Incorrect access control in the setAccessDeviceCfg function of TOTOLINK T6 4.…
CVE-2026-51677await—n/an/a—Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.74…
CVE-2026-51678await—n/an/a—Incorrect access control in the setSyslogCfg function of TOTOLINK T6 4.1.5cu.…
CVE-2026-51683await—n/an/a—Incorrect access control in the setLanCfg function of TOTOLINK T6 4.1.5cu.748…
CVE-2026-51684await—n/an/a—Incorrect access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu…
CVE-2026-51686await—n/an/a—Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 4.1.5c…
CVE-2026-51687await—n/an/a—Incorrect access control in the setWiFiEasyGuestCf function of TOTOLINK T6 4.…
CVE-2026-51688await—n/an/a—Incorrect access control in the setWiFiSignalCfg function of TOTOLINK T6 4.1.…
CVE-2026-51689await—n/an/a—Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.…
CVE-2026-51690await—n/an/a—Incorrect access control in the setWanCfg function of TOTOLINK T6 4.1.5cu.748…
CVE-2026-51691await—n/an/a—Incorrect access control in the setUploadSetting function of TOTOLINK T6 4.1.…
CVE-2026-51692await—n/an/a—Incorrect access control in the setWiFiGuestCfg function of TOTOLINK T6 4.1.5…
CVE-2026-51693await—n/an/a—Incorrect access control in the setVpnPassCfg function of TOTOLINK T6 4.1.5cu…
CVE-2026-51694await—n/an/a—Incorrect access control in the setStaticDhcpRules function of TOTOLINK T6 4.…
CVE-2026-51695await—n/an/a—Incorrect access control in the setDdnsCfg function of TOTOLINK T6 4.1.5cu.74…
CVE-2026-51696await—n/an/a—Incorrect access control in the setPortForwardRules function of TOTOLINK T6 4…
CVE-2026-51697await—n/an/a—Incorrect access control in the setIptvCfg function of TOTOLINK T6 4.1.5cu.74…
CVE-2026-51698await—n/an/a—Incorrect access control in the setUrlFilterRules function of TOTOLINK T6 4.1…
CVE-2026-51699await—n/an/a—Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5cu.748…
CVE-2026-51700await—n/an/a—Incorrect access control in the setWiFiAdvancedCfg function of TOTOLINK T6 4.…
CVE-2026-51701await—n/an/a—Incorrect access control in the setMacFilterRules function of TOTOLINK T6 4.1…
CVE-2026-51702await—n/an/a—Incorrect access control in the setIpPortFilterRules function of TOTOLINK T6 …
CVE-2026-51703await—n/an/a—Incorrect access control in the setWiFiScheduleCfg function of TOTOLINK T6 4.…
CVE-2026-51704await—n/an/a—Incorrect access control in the setWiFiMeshConfig function of TOTOLINK T6 4.1…
CVE-2026-51705await—n/an/a—Incorrect access control in the setWiFiMeshName function of TOTOLINK T6 4.1.5…
CVE-2026-51706await—n/an/a—Incorrect access control in the setSmartQosCfg function of TOTOLINK T6 4.1.5c…
CVE-2026-51708await—n/an/a—Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 4.1.5cu…
CVE-2026-51709await—n/an/a—Incorrect access control in the setWiFiBasicCfg function of TOTOLINK T6 4.1.5…
CVE-2026-51710await—n/an/a—Incorrect access control in the setParentalRules function of TOTOLINK T6 4.1.…
CVE-2026-51711await—n/an/a—Incorrect access control in the setWiFiWpsStart function of TOTOLINK T6 4.1.5…
CVE-2026-51712await—n/an/a—Incorrect access control in the setApWiFiSchCfg function of TOTOLINK T6 4.1.5…
CVE-2026-51713await—n/an/a—Incorrect access control in the setManualDialCfg function of TOTOLINK T6 4.1.…
CVE-2026-51714await—n/an/a—Incorrect access control in the setRoamingCfg function of TOTOLINK T6 4.1.5cu…
CVE-2026-51715await—n/an/a—Incorrect access control in the delMacFilterRules function of TOTOLINK T6 4.1…
CVE-2026-51716await—n/an/a—Incorrect access control in the delPortForwardRules function of TOTOLINK T6 4…
CVE-2026-51717await—n/an/a—Incorrect access control in the setOpModeCfg function of TOTOLINK T6 4.1.5cu.…
CVE-2026-51718await—n/an/a—Incorrect access control in the delStaticDhcpRules function of TOTOLINK T6 4.…
CVE-2026-51719await—n/an/a—Incorrect access control in the delUrlFilterRules function of TOTOLINK T6 4.1…
CVE-2026-51721await—n/an/a—Incorrect access control in the setPairCfg function of TOTOLINK T6 4.1.5cu.74…
CVE-2026-51722await—n/an/a—Incorrect access control in the setWiFiRepeaterCfg function of TOTOLINK T6 4.…
CVE-2026-51723await—n/an/a—Incorrect access control in the UploadCustomModule function of TOTOLINK T6 4.…
CVE-2026-51724await—n/an/a—Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5c…
CVE-2026-51726await—n/an/a—Incorrect access control in the delParentalRules function of TOTOLINK T6 4.1.…
CVE-2026-51727await—n/an/a—Incorrect access control in the SystemSettings function of TOTOLINK T6 4.1.5c…
CVE-2026-51728await—n/an/a—Incorrect access control in the UploadFirmwareFile function of TOTOLINK T6 4.…
CVE-2026-51729await—n/an/a—Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748…
CVE-2026-51731await—n/an/a—Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.74…
CVE-2026-51732await—n/an/a—Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.…
CVE-2026-51733await—n/an/a—Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5…
CVE-2026-51734await—n/an/a—Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1…
CVE-2026-51735await—n/an/a—Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.5cu.74…
CVE-2026-51736await—n/an/a—Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.7…
CVE-2026-51737await—n/an/a—Incorrect access control in the clearTracerouteLog function of TOTOLINK T6 4.…
CVE-2026-51738await—n/an/a—Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5…
CVE-2026-51739await—n/an/a—Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 …
CVE-2026-51740await—n/an/a—Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.7…
CVE-2026-71257await—Apache Software FoundationApache WicketCWE-770Apache Wicket: Configured file upload limits are not enforced when the multip…
CVE-2026-75458await—n/an/a—The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiSi Open…
CVE-2026-75460await—n/an/a—XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation vulnerab…
CVE-2026-79407await—n/an/a—A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows a…
CVE-2026-79408await—n/an/a—An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to …
CVE-2026-79483await—n/an/a—FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL inj…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-31 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.