boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, September 1, 2026 · all times UTC← 2026-08-31 · archive

Security Box Score — September 1, 2026

477 CVEs published, led by Hewlett Packard Enterprise (HPE) (86).

477 CVEs published September 1, 2026: 34 critical, 194 high, 151 medium, 30 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 68 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 77 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published47735211——
KEV catalog size1687

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2200 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux03960418197263711230.17.8.00160
google262190272848972837760.37.5.0026+26 ▲
microsoft01899145128345615287281.57.8.00440
red hat126393926230235200.06.5.0029+12 ▲
apple0316598516578882.56.5.00290
freebsd04823673000.07.8.00160
canonical0421311135000.07.8.00200
suse33151781000.07.8.0039+3 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco0842139240561315.57.5.00440
ubiquiti059362210335.19.1.00490
palo alto networks0371321121325.44.7.00200
netgear03200275000.04.3.00250
fortinet0307814128620.07.0.00500
vmware019410327210.58.3.00400
f50175930415.98.7.00570
sonicwall216384017212.57.8.0024+2 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache0507103217173133320.47.5.00490
mozilla342217073580900.08.1.0030+34 ▲
gitlab076317479422.65.3.00290
drupal068107465411.55.9.00240
github32011090000.07.3.0044+3 ▲
docker090630000.07.2.00160
wordpress0513102240.08.8.31200
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle022694841170519962840.27.8.00340
ibm06191482861778610.27.6.00300
adobe06065030024791930.57.8.00210
progress0611437100611.68.1.00370
solarwinds0231733010417.49.1.00580
veeam01961030100.08.6.00320
zohocorp0103520000.08.7.01400
atlassian0615001300.08.1.00320
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link045151398300.08.5.01570
rockwell automation164153060000.08.7.0024+16 ▲
siemens03722483000.07.3.00160
synology02736153000.05.6.00250
schneider electric4131840000.08.2.0037+4 ▲
abb070430000.07.2.00180
hikvision060420000.07.2.00400
mitsubishi electric050410000.07.2.00520
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1318413102645210.57.3.0019+13 ▲
spring01709608516000.06.5.00230
sourcecodester0169009277000.05.5.00290
nvidia3016419115300000.07.8.0034+30 ▲
splunk0128647705110.86.5.00250
itsourcecode0116003284000.02.1.00270
openclaw01110583914000.07.0.00260
zephyrproject01103336212000.06.4.0020-2 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.995799.99.8
CVE-2026-34486.986299.97.5
CVE-2026-63077.877199.79.8
CVE-2026-60004.867899.79.8
CVE-2026-72898.823299.610.0
CVE-2026-18577.540798.98.2
CVE-2026-18556.401698.58.2
CVE-2026-64638.312098.18.9
CVE-2026-71362.251497.89.1
CVE-2026-73570.205397.38.9
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.8232KEV
CVE-2026-4836210.0.0431
CVE-2026-1918810.0.0193
CVE-2026-5823110.0.0171
CVE-2026-7619510.0.0159
CVE-2026-7619710.0.0159
CVE-2026-6983610.0.0155
CVE-2026-7329910.0.0121
CVE-2026-7367810.0.0114
CVE-2026-7755410.0.0099
Most disclosures (vendor)
VendorCVEs
linux1645
oracle890
microsoft477
google428
ibm390
red hat237
apache169
splunk110
adobe101
mozilla94
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco13
apple8
fortinet6
google6
ivanti5
oracle4
solarwinds4
adobe3
berriai3
Most-affected ecosystems
EcosystemAdvisories
Maven63
Packagist29
npm15
PyPI14
Go1
Fastest to KEV
CVEVendorDays
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20349Cisco0
CVE-2026-34486Apache Software Foundation0
CVE-2026-63077JetBrains0
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
CVE-2026-72898Metabase0
CVE-2026-8037Progress Software0
CVE-2026-64849mlflow1
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171749
CVE-2021-27102n/a2021-11-171749
CVE-2021-27101n/a2021-11-171749
CVE-2021-27103n/a2021-11-171749
CVE-2021-21017Adobe2021-11-171749
CVE-2021-28550Adobe2021-11-171749
CVE-2021-42013Apache Software Foundation2021-11-171749
CVE-2021-41773Apache Software Foundation2021-11-171749
CVE-2021-30858Apple2021-11-171749
CVE-2021-30860Apple2021-11-171749

Transactions

EXPLOIT PUBLISHED — thorsten phpMyFAQ: 11 CVEs (CVE-2026-75918, CVE-2026-75919, CVE-2026-75920, CVE-2026-76205, CVE-2026-76208, CVE-2026-76209, CVE-2026-76210, CVE-2026-76211, CVE-2026-76212, CVE-2026-76213, CVE-2026-76215). Public exploit references added.

EXPLOIT PUBLISHED — axios: 10 CVEs (CVE-2026-67312, CVE-2026-67313, CVE-2026-67314, CVE-2026-67315, CVE-2026-67316, CVE-2026-67317, CVE-2026-67318, CVE-2026-67319, CVE-2026-67320, CVE-2026-67321). Public exploit references added.

EXPLOIT PUBLISHED — zephyrproject zephyr: 10 CVEs (CVE-2026-2411, CVE-2026-7007, CVE-2026-10659, CVE-2026-10683, CVE-2026-10685, CVE-2026-10773, CVE-2026-10774, CVE-2026-10848, CVE-2026-10849, CVE-2026-11368). Public exploit references added.

EXPLOIT PUBLISHED — Wireshark Foundation Wireshark: 7 CVEs (CVE-2026-19694, CVE-2026-19695, CVE-2026-19696, CVE-2026-76879, CVE-2026-76881, CVE-2026-76924, CVE-2026-76926). Public exploit references added.

EXPLOIT PUBLISHED — GNOME GLib: 5 CVEs (CVE-2026-58010, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015). Public exploit references added.

EXPLOIT PUBLISHED — nltk: 5 CVEs (CVE-2026-78681, CVE-2026-79675, CVE-2026-80205, CVE-2026-80206, CVE-2026-81725). Public exploit references added.

EXPLOIT PUBLISHED — Red Hat Enterprise Linux 10: 4 CVEs (CVE-2026-5704, CVE-2026-48864, CVE-2026-55653, CVE-2026-55654). Public exploit references added.

EXPLOIT PUBLISHED — handlebars-lang handlebars.js: 3 CVEs (CVE-2026-33939, CVE-2026-33940, CVE-2026-33941). Public exploit references added.

EXPLOIT PUBLISHED — openemr: 3 CVEs (CVE-2026-39931, CVE-2026-39932, CVE-2026-67611). Public exploit references added.

EXPLOIT PUBLISHED — Red Hat Hardened Images: 3 CVEs (CVE-2026-0989, CVE-2026-0990, CVE-2026-0992). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2023-39533 (libp2p go-libp2p). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2024-6387 (OpenSSH). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-4598 (systemd-coredump). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-5914 (libarchive). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-6021 (libxml2). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-24049 (pypa wheel). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-26899. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-29786 (isaacs node-tar). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-3832 (gnutls). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-41523 (vllm-project vllm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-43500 (Linux). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-53622 (traefik). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-58049 (FFmpeg). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-62911 (Microsoft Exchange Server 2016 Cumulative Update 23). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-67307 (wazuh). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-71225 (Stephan Muelle libkcapi). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-71227 (Stephan Muelle libkcapi). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-74883 (jahlives openssl_encrypt). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78465 (GNOME GIMP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-79720 (Netron). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82482 (coppermine-gallery Coppermine Photo Gallery). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82487 (Beetel 450TC3). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82539 (TOTOLINK A720R). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82542 (Tenda HG10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82548 (Linux Foundation Magma). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82553 (sambitraj Student Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82593 (D-Link DIR-825M). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82598 (SeaCMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82603 (SeaCMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82609 (itsourcecode Sales and Inventory System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82614 (itsourcecode Online Medicine Delivery System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82616 (TOTOLINK NR1800X). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82620 (Soarkey StudentManagement). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82625 (code-projects Simple Inventory System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82664 (yaojingang GEOFlow). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82688 (D-Link DNS-340L). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82807 (ieungSoft Ultra RAMDisk Pro). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82820 (FLVMeta). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82833 (Doccano Open Source Annotation Tools for Machine Learning Practitioners). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82835 (caoqianming django-vue-admin). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82906 (sdcb chats). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82908 (MSI Dragon Center). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82914 (kishan0725 Hospital-Management-System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82921 (ShopEx ECShop). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82922 (ShopEx ECShop). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82971 (QVidium Opera11). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-83524 (RedPort Optimizer wXa-203). Public exploit reference added.

REJECTED — CVE-2024-58377 (sparklemotion nokogiri). Record withdrawn by the CNA.

REJECTED — CVE-2024-58378 (sparklemotion nokogiri). Record withdrawn by the CNA.

REJECTED — CVE-2025-71346 (sparklemotion nokogiri). Record withdrawn by the CNA.

REJECTED — CVE-2025-71406 (sparklemotion nokogiri). Record withdrawn by the CNA.

REJECTED — CVE-2025-71407 (sparklemotion nokogiri). Record withdrawn by the CNA.

REJECTED — CVE-2026-78477 (MVPThemes Jawn). Record withdrawn by the CNA.

REJECTED — CVE-2026-78562 (Mikado-Themes Verdure Core). Record withdrawn by the CNA.

REJECTED — CVE-2026-78563 (WPDeveloper NotificationX Pro). Record withdrawn by the CNA.

REJECTED — CVE-2026-78566 (Edge-Themes Shuffle). Record withdrawn by the CNA.

REJECTED — CVE-2026-78568 (KlbTheme Total Donations). Record withdrawn by the CNA.

REJECTED — CVE-2026-78570 (KlbTheme Total Donations). Record withdrawn by the CNA.

REJECTED — CVE-2026-78572 (unknown Kalles Addons). Record withdrawn by the CNA.

REJECTED — CVE-2026-78576 (Readabler). Record withdrawn by the CNA.

RESCORED — NVIDIA NemoClaw: 6 CVEs (CVE-2026-65081, CVE-2026-65082, CVE-2026-65084, CVE-2026-65087, CVE-2026-65097, CVE-2026-65098). CVSS rescored — before/after on each CVE page.

RESCORED — Red Hat Advanced Cluster Management for Kubernetes 2: 6 CVEs (CVE-2026-66780, CVE-2026-66782, CVE-2026-66783, CVE-2026-66785, CVE-2026-66787, CVE-2026-66788). CVSS rescored — before/after on each CVE page.

RESCORED — Wireshark Foundation Wireshark: 5 CVEs (CVE-2026-19694, CVE-2026-19695, CVE-2026-19696, CVE-2026-76881, CVE-2026-76926). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2026-33941 (handlebars-lang handlebars.js). CVSS 8.3 → 8.2 (NVD).

RESCORED — CVE-2026-34714 (Vim). CVSS 9.2 → 8.6 (NVD).

RESCORED — CVE-2026-47863 (Spring Reactor Core). CVSS 5.9 → 7.5 (NVD).

RESCORED — CVE-2026-47881 (Spring Batch). CVSS 5.9 → 7.5 (NVD).

RESCORED — CVE-2026-47894 (Spring Cloud Config). CVSS 4.9 → 7.5 (NVD).

RESCORED — CVE-2026-5704 (Red Hat Enterprise Linux 10). CVSS 5 → 5.5 (NVD).

RESCORED — CVE-2026-59270 (Spring Security). CVSS 9.4 → 9.1 (NVD).

RESCORED — CVE-2026-59271 (Spring AMQP). CVSS 5.3 → 6.5 (NVD).

RESCORED — CVE-2026-59275 (Spring AMQP). CVSS 6.6 → 4.9 (NVD).

RESCORED — CVE-2026-59354 (VMware by Broadcom Spring Security (OAuth2 Authorization Server module)). CVSS 9.6 → 8.8 (NVD).

RESCORED — CVE-2026-66781 (Red Hat Advanced Cluster Management for Kubernetes 2.11). CVSS 6.5 → 5.4 (NVD).

RESCORED — CVE-2026-66795 (Red Hat multicluster engine for Kubernetes 2.10). CVSS 9.1 → 9.9 (NVD).

RESCORED — CVE-2026-6876 (ServiceNow AI Platform). CVSS 8.7 → 10 (NVD).

RESCORED — CVE-2026-75052 (JetBrains IntelliJ IDEA). CVSS 3.6 → 4.4 (NVD).

RESCORED — CVE-2026-75871 (GitLab AI Gateway). CVSS 8.2 → 9.6 (NVD).

RESCORED — CVE-2026-79938 (Dell Power Protect Cyber Recovery). CVSS 7.6 → 8.8 (NVD).

RESCORED — CVE-2026-79939 (Dell Power Protect Cyber Recovery). CVSS 5.8 → 7.8 (NVD).

PATCH SHIPPED — CVE-2026-28191 (ThemeOne The Grid). Fixed in The Grid 2.8.1.

Yesterday's Results

How to read these box scores · glossary

477 CVEs published. 25 box scores and 375 table rows below; the remaining 77 continue on page 2 — every CVE is listed, nothing truncated.

SUSE yast2-users — yast2-users: OS command injection via LDAP-supplied shadowLastChange/shadowExpire attribute
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   P   H   H   H    8.6   .0234   82.4     —
AFFECTED
  Product      Versions     Fixed
  yast2-users  unspecified  —
TIMELINE
  Jul 6   Reserved by CNA
  Sep 1   Published (CNA: suse)
CWE-78, CWE-1287 · CNA: suse · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
Cobham SATCOM VSAT7090 Maritime Satellite Router JSON Parsing mail-report.sh c_set_reports_decode command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0169   75.4     —
AFFECTED
  Product                                    Versions    Fixed
  SATCOM VSAT7090 Maritime Satellite Router  20260704 –  —
TIMELINE
  Aug 31  Reserved by CNA
  Sep 1   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
WebPros Plesk — A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk f…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   H   H   H    9.0   .0117   65.2     —
AFFECTED
  Product  Versions   Fixed
  Plesk    18.0.34 –  —
TIMELINE
  Jul 29  Reserved by CNA
  Sep 1   Published (CNA: hackerone)
CWE-78 · CNA: hackerone · CVSS v4.0 · 1 reference · NVD status: Received
SUSE yast2-auth-client — yast2-auth-client: OS command injection via unsanitized Organizational Unit / dnsHostName in AD join
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    8.7   .0115   64.6     —
AFFECTED
  Product            Versions     Fixed
  yast2-auth-client  unspecified  —
TIMELINE
  Jul 6   Reserved by CNA
  Sep 1   Published (CNA: suse)
CWE-78 · CNA: suse · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
Sage Employee Self Service — A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to impr…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  N  N    5.9   .0084   55.3     —
AFFECTED
  Product                Versions   Fixed
  Employee Self Service  Q2 2026 –  —
TIMELINE
  Jul 29  Reserved by CNA
  Sep 1   Published (CNA: hackerone)
CWE-22 · CNA: hackerone · CVSS v3.0 · 1 reference · NVD status: Received
shabti Frontend Admin by DynamiApps — Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Arbitrary File Deletion via Path Traversal via custom_directory_name Merge Tag
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0078   53.4     —
AFFECTED
  Product                       Versions     Fixed
  Frontend Admin by DynamiApps  unspecified  —
TIMELINE
  Aug 15  Reserved by CNA
  Sep 1   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
WebPros cPanel — Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0064   48.3     —
AFFECTED
  Product  Versions     Fixed
  cPanel   unspecified  —
TIMELINE
  Jul 22  Reserved by CNA
  Sep 1   Published (CNA: hackerone)
CWE-95 · CNA: hackerone · CVSS v4.0 · 1 reference · NVD status: Received
pixarlabs Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits — Master Addons for Elementor <= 3.1.9 - Incorrect Authorization to Authenticated (Editor+) Arbitrary File Upload via upload_template_kit AJAX ZIP Extraction
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0063   47.7     —
AFFECTED
  Product                                                                                                                    Versions     Fixed
  Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits  unspecified  —
TIMELINE
  Aug 18  Reserved by CNA
  Sep 1   Published (CNA: Wordfence)
CWE-863 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
wplegalpages WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode — WPLP Cookie Consent <= 4.4.1 - Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0051   41.6     —
AFFECTED
  Product                                                                                        Versions     Fixed
  WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode  unspecified  —
TIMELINE
  Aug 18  Reserved by CNA
  Sep 1   Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
uscnanbu Welcart e-Commerce — Welcart e-Commerce <= 2.12.1 - Unauthenticated Stored Cross-Site Scripting via 'custom_order' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0047   38.7     —
AFFECTED
  Product             Versions     Fixed
  Welcart e-Commerce  unspecified  —
TIMELINE
  Aug 14  Reserved by CNA
  Sep 1   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
FasterXML jackson-databind — jackson-databind resolves attacker-controlled URI schemes when deserializing java.nio.file.Path
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  L    5.3   .0046   38.4     —
AFFECTED
  Product           Versions  Fixed
  jackson-databind  2.8.0 –   —
  jackson-databind  3.0.0 –   —
TIMELINE
  Aug 6   Reserved by CNA
  Sep 1   Published (CNA: HeroDevs)
CWE-470, CWE-610 · CNA: HeroDevs · CVSS v3.1 · 5 references · NVD status: Received
SUSE yast2-samba-client — yast2-samba-client: OS command injection via attacker-controlled Organizational Unit (Active Directory-supplied)
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   A   H   H   H    7.5   .0044   36.8     —
AFFECTED
  Product             Versions     Fixed
  yast2-samba-client  unspecified  —
TIMELINE
  Feb 5   Reserved by CNA
  Sep 1   Published (CNA: suse)
CWE-78 · CNA: suse · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
Sauter modu680-AS — TOCTOU Vulnerability in file exchange
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0040   33.6     —
AFFECTED
  Product     Versions  Fixed
  modu680-AS  1.0.0 –   —
  modu660-AS  1.0.0 –   —
  modu612-LC  1.0.0 –   —
  ecos504     1.0.0 –   —
  ecos505     1.0.0 –   —
TIMELINE
  Aug 24  Reserved by CNA
  Sep 1   Published (CNA: CERTVDE)
CWE-367 · CNA: CERTVDE · CVSS v4.0 · 2 references · NVD status: Received
devitemsllc Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System — Support Genix <= 1.4.52 - Authenticated (Subscriber+) Authentication Bypass to Administrator Account Takeover via 'p' Parameter Forged Guest Token
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0040   32.7     —
AFFECTED
  Product                                                                                   Versions     Fixed
  Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System  unspecified  —
TIMELINE
  Aug 13  Reserved by CNA
  Sep 1   Published (CNA: Wordfence)
CWE-287 · CNA: Wordfence · CVSS v3.1 · 12 references · NVD status: Deferred
cozythemes Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates — Cozy Blocks <= 2.2.17 - Missing Authorization to Unauthenticated Unpublished Product Information Disclosure via 'wishlistData' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0039   32.5     —
AFFECTED
  Product                                                                                          Versions     Fixed
  Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates  unspecified  —
TIMELINE
  Aug 15  Reserved by CNA
  Sep 1   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 9 references · NVD status: Deferred
ash-project ash_typescript — Declared argument constraints not enforced on AshTypescript typed controller routes
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   L   N    6.3   .0039   32.0     —
AFFECTED
  Product         Versions                                    Fixed
  ash_typescript  0.15.0 –                                    —
  ash_typescript  546a15e1a2d7dbf1df2d5a6ee4404bc3da87852e –  —
TIMELINE
  Aug 31  Reserved by CNA
  Sep 1   Published (CNA: EEF)
CWE-20 · CNA: EEF · CVSS v4.0 · 4 references · NVD status: Deferred
thimpress LearnPress – WordPress LMS Plugin for Create and Sell Online Courses — LearnPress <= 4.4.4 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0035   28.1     —
AFFECTED
  Product                                                               Versions     Fixed
  LearnPress – WordPress LMS Plugin for Create and Sell Online Courses  unspecified  —
TIMELINE
  Aug 21  Reserved by CNA
  Sep 1   Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Deferred
ays-pro Photo Gallery by Ays – Responsive Image Gallery — Photo Gallery by Ays <= 6.8.2 - Authenticated (Administrator+) SQL Injection via 's' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0035   28.0     —
AFFECTED
  Product                                          Versions     Fixed
  Photo Gallery by Ays – Responsive Image Gallery  unspecified  —
TIMELINE
  Aug 18  Reserved by CNA
  Sep 1   Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
livecomposer Live Composer – Free WordPress Website Builder — Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via dslc_module_testimonials_output Shortcode
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0033   26.1     —
AFFECTED
  Product                                         Versions     Fixed
  Live Composer – Free WordPress Website Builder  unspecified  —
TIMELINE
  Jul 23  Reserved by CNA
  Sep 1   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
livecomposer Live Composer – Free WordPress Website Builder — Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via dslc_module_projects_output Shortcode
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0033   26.1     —
AFFECTED
  Product                                         Versions     Fixed
  Live Composer – Free WordPress Website Builder  unspecified  —
TIMELINE
  Jul 23  Reserved by CNA
  Sep 1   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
creativethemeshq Blocksy Companion — Blocksy Companion <= 2.1.51 - Authenticated (Author+) Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0033   25.5     —
AFFECTED
  Product            Versions     Fixed
  Blocksy Companion  unspecified  —
TIMELINE
  Jul 31  Reserved by CNA
  Sep 1   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 11 references · NVD status: Deferred
Backblaze Client for Windows Improper Link Resolution Vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   N    7.8   .0033   25.3     —
AFFECTED
  Product           Versions       Fixed
  Backblaze Client  10.0.0.1029 –  —
TIMELINE
  Aug 14  Reserved by CNA
  Sep 1   Published (CNA: Bugcrowd)
CWE-59 · CNA: Bugcrowd · CVSS v4.0 · 2 references · NVD status: Received
WPBakery Page Builder <= 8.7.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'data' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0032   24.1     —
AFFECTED
  Product                Versions     Fixed
  WPBakery Page Builder  unspecified  —
TIMELINE
  Jul 8   Reserved by CNA
  Sep 1   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Deferred
ash-project ash_typescript — Unbounded atom creation from client-supplied RPC field names in AshTypescript field formatter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0032   23.8     —
AFFECTED
  Product         Versions                                    Fixed
  ash_typescript  0.1.0 –                                     —
  ash_typescript  1a3d4c343430c8e4784acfcd33122a807fafa086 –  —
TIMELINE
  Aug 30  Reserved by CNA
  Sep 1   Published (CNA: EEF)
CWE-770 · CNA: EEF · CVSS v4.0 · 4 references · NVD status: Deferred
ash-project ash_typescript — Unbounded atom creation from typed struct field names in AshTypescript field selector
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   H    8.2   .0032   23.8     —
AFFECTED
  Product         Versions                                    Fixed
  ash_typescript  0.11.0 –                                    —
  ash_typescript  7c3d30896f2f9a54edea17e3787549776b1b288d –  —
TIMELINE
  Aug 30  Reserved by CNA
  Sep 1   Published (CNA: EEF)
CWE-770 · CNA: EEF · CVSS v4.0 · 4 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-779506.323.8ash-projectash_typescriptCWE-209RPC error handler fails open in AshTypescript, disclosing unredacted errors
CVE-2026-827336.323.8ash-projectash_typescriptCWE-209Route handler return value echoed into AshTypescript error response
CVE-2026-827312.320.9ash-projectash_typescriptCWE-601Unescaped path parameters in AshTypescript generated TypeScript client allow …
CVE-2026-771896.520.8smubCharitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns)CWE-89Charitable <= 1.8.12.1 - Authenticated (Contributor+) SQL Injection via 'orde…
CVE-2026-827308.220.6ash-projectash_typescriptCWE-863Authorization-redacted field values disclosed through AshTypescript result no…
CVE-2026-175894.920.0levelfourstorefrontShopping Cart & eCommerce StoreCWE-89Shopping Cart & eCommerce Store <= 5.9.2 - Authenticated (Administrator+) SQL…
CVE-2026-187526.516.1lukeseagerPersistent LoginCWE-89Persistent Login <= 3.1.0 - Authenticated (Subscriber+) SQL Injection via 'wp…
CVE-2026-195737.215.1worschtebrotAffiliate Super AssistentCWE-79Affiliate Super Assistent <= 1.10.2 - Unauthenticated Stored Cross-Site Scrip…
CVE-2026-197967.215.1webiliaListdom: AI-powered Business Directory with Classifieds Ads ListingsCWE-79Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 5.8.1…
CVE-2026-132036.415.1livecomposerLive Composer – Free WordPress Website BuilderCWE-79Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-837432.112.4invoiceninjaInvoice NinjaCWE-285invoiceninja Invoice Ninja Vendor Portal Profile Update profile authorization
CVE-2026-759646.112.3cozmoslabsUser Profile Builder – Beautiful User Registration Forms, User Profiles & User Role EditorCWE-79User Profile Builder <= 4.0.0 - Unauthenticated Stored Cross-Site Scripting v…
CVE-2026-759806.410.5wpdevteamBetterDocs – AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ & ChatbotCWE-79BetterDocs <= 4.8.1 - Authenticated (Contributor+) Stored Cross-Site Scriptin…
CVE-2026-837442.110.2invoiceninjaInvoice NinjaCWE-918invoiceninja Invoice Ninja invoices Endpoint Purify.php isHostSafe server-sid…
CVE-2026-127476.410.0shabtiFrontend Admin by DynamiAppsCWE-79Frontend Admin by DynamiApps <= 3.29.11 - Authenticated (Contributor+) Stored…
CVE-2026-167876.49.1livecomposerLive Composer – Free WordPress Website BuilderCWE-79Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-759656.49.1cozmoslabsUser Profile Builder – Beautiful User Registration Forms, User Profiles & User Role EditorCWE-79User Profile Builder <= 4.0.0 - Authenticated (Contributor+) Stored Cross-Sit…
CVE-2026-136115.39.0UnknownKiviCareCWE-200KiviCare – Clinic & Patient Management System (EHR) < 4.5.5 - Unauthenticated…
CVE-2026-489323.75.6nodejsnodeCWE-444A flaw in Node.js HTTP client can cause a request desynchronization for Node.…
CVE-2026-783634.84.9UnknownMW WP FormCWE-74MW WP Form < 5.1.5 - Unauthenticated Arbitrary Shortcode Execution via Comple…
CVE-2026-827355.93.5ash-projectashCWE-400Match regex runs on over-length input in Ash.Type.String, enabling regex deni…
CVE-2026-827375.93.5ash-projectashCWE-190Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements…
CVE-2026-827385.93.5ash-projectashCWE-20Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persiste…
CVE-2026-827362.13.5ash-projectashCWE-180Ash.Type.CiString validates length and match constraints before case folding,…
CVE-2026-827342.13.1ash-projectashCWE-1284Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.…
CVE-2026-827412.13.1ash-projectashCWE-1287Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling ta…
CVE-2026-827442.13.1ash-projectashCWE-636Ash.Reactor change step fails open, skipping a change when its where guard ra…
CVE-2026-827425.92.6ash-projectashCWE-400Ash.Filter.Runtime materializes a combinatorial cross-product over to-many re…
CVE-2026-827392.12.6ash-projectashCWE-209Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the…
CVE-2026-827402.12.6ash-projectashCWE-20Ash.Type ignores outer array constraints on nested {:array, {:array, type}} i…
CVE-2026-827432.12.6ash-projectashCWE-400Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow asyn…
CVE-2026-187432.52.5rpm-software-managementpoptCWE-131Popt-devel: popt-static: short realloc in poptconfigfiletostring
CVE-2026-827455.92.3ash-projectashCWE-284ETS and Mnesia data layers overwrite an existing record on create instead of …
CVE-2026-827465.92.0ash-projectashCWE-862Ash.update_many/4 atomic path skips resource policy authorization, allowing u…
CVE-2026-827475.92.0ash-projectashCWE-863Ash.Policy.Authorizer returns records denied by a runtime read policy to any …
CVE-2026-827495.92.0ash-projectashCWE-863Ash relationship parent(...) filter degrades to an IS NULL match when the par…
CVE-2026-827482.12.0ash-projectashCWE-863Ash.Actions.Aggregate authorizes an aggregate under one action but computes i…
CVE-2026-749166.51.2UnknownWP Fastest CacheCWE-349WP Fastest Cache 0.8.7.7 - 1.5.0 - Unauthenticated Cache Poisoning via Unkeye…
CVE-2026-7665710.0—Hewlett Packard Enterprise (HPE)Fabric ComposerCWE-287Authentication Bypass in HPE Networking Fabric Composer API allows Administra…
CVE-2026-7665810.0—Hewlett Packard Enterprise (HPE)Fabric ComposerCWE-287Unauthenticated Remote Code Execution in HPE Networking Fabric Composer SSH D…
CVE-2026-8414710.0—Manacle TechnologiesMulti-tenant ERP SystemCWE-434Remote Code Execution Vulnerability in Manacle Technologies ERP System
CVE-2026-182109.8—TRtek Technological Products Computer Software Hardware Industry and Trade Limited CompanyProducts's StoreCWE-89SQL Injection in TRtek Technological Products's Store
CVE-2026-185509.8—scriptsbundleNokri – Job Board WordPress ThemeCWE-269Nokri - Job Board WordPress Theme <= 1.6.6 - Unauthenticated Privilege Escala…
CVE-2026-187659.8—Teracity Software Technologies Inc.E-OSBCWE-89SQL Injection in Teracity Sotware's Teracity E-OSB Platform
CVE-2026-188089.8—Klemsan Electrical Electronics Inc.KIO (Klemsan Internet Objects)CWE-94Unauthenticated Remote Code Execution via Code Injection in Klemsan's KIO
CVE-2026-737499.8—Hewlett Packard Enterprise (HPE)AOS-CX—Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution…
CVE-2026-843729.8—predispredisCWE-93Predis: Redis command injection and denial of service via CRLF smuggling in p…
CVE-2026-197669.6—Hewlett Packard Enterprise (HPE)Fabric Composer—Authentication Bypass leads to Administrative control of adjacent network hos…
CVE-2026-841199.6—MozillaFirefoxCWE-416Sandbox escape due to use-after-free in the DOM: Navigation component
CVE-2026-841219.6—MozillaFirefoxCWE-416Sandbox escape due to use-after-free in the DOM: Security component
CVE-2026-843339.6—GoogleChromeCWE-416Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 …
CVE-2026-48139.4—LuteceLutece CoreCWE-94Code injection in the Lutece Core
CVE-2026-842009.4—kyvernokyvernoCWE-284Kyverno before v1.13.0 Policy Bypass via Multiple Exceptions
CVE-2023-543569.3—kyvernokyvernoCWE-326Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suites
CVE-2023-543919.3—Proxmox Server Solutions GmbHProxmox Virtual Environment (VE)CWE-304Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter
CVE-2026-780129.3—Pyramid SolutionsEtherNet/IP Adapter DLL Kit (EIPA)CWE-121Stack-based Buffer Overflow in Pyramid Solutions NetStaX EtherNet/IP Stack
CVE-2026-844799.3—WWBNAVideoCWE-290WWBN AVideo Authentication Bypass via User-Agent Header
CVE-2026-844809.3—WWBNAVideoCWE-613WWBN AVideo Password Recovery Token Expiration Bypass
CVE-2026-96219.2—Rockwell AutomationRSLinx Classic®CWE-190RSLinx Classic® - Multiple Vulnerabilities
CVE-2026-841489.2—Manacle TechnologiesMulti-tenant ERP SystemCWE-639Insecure Direct Object Reference Vulnerability in Manacle Technologies ERP Sy…
CVE-2026-841499.2—Manacle TechnologiesMulti-tenant ERP SystemCWE-527Information Disclosure Vulnerability in Manacle Technologies ERP System
CVE-2026-841899.2—librenmslibrenmsCWE-79LibreNMS before 26.7.0 Stored XSS via Oxidized API
CVE-2026-189319.1—TMT Machine Industry and Trade Ltd. Co.Talassoft Industrial Management SoftwareCWE-798Hardcoded Credentials in TMT Machine's Talassoft Industrial Management Software
CVE-2026-517439.1—n/an/aCWE-284Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5…
CVE-2026-737009.0—Hewlett Packard Enterprise (HPE)Fabric Composer—Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in HPE Networki…
CVE-2026-737019.0—Hewlett Packard Enterprise (HPE)Fabric Composer—Unauthenticated Remote Code Execution in HPE Networking Fabric Composer
CVE-2026-756049.0—vercelnext.jsCWE-22Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
CVE-2026-796879.0—DellPowerStore 500TCWE-306Dell PowerStore SDNAS contains a Missing Authentication for Critical Function…
CVE-2026-843249.0—GoogleChromeCWE-416Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a rem…
CVE-2026-101958.8—fs-codeFS Poster - WordPress Social media Auto Poster & Scheduler [Facebook, Instagram, Twitter, Pinterest]CWE-77FS Poster <= 8.0.1 - Authenticated (Subscriber+) Remote Code Execution via FF…
CVE-2026-186308.8—TMT Machine Industry and Trade Ltd. Co.Talassoft Industrial Management SoftwareCWE-89SQL Injection in TMT Machine's Talassoft Industrial Management Software
CVE-2026-585668.8—DellPowerStore 500TCWE-863Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged a…
CVE-2026-585678.8—DellPowerStore 500TCWE-78Dell PowerStore contains an OS Command Injection vulnerability. An authentica…
CVE-2026-585698.8—DellPowerStore 500TCWE-829Dell PowerStore contains an Inclusion of Functionality from Untrusted Control…
CVE-2026-585718.8—DellPowerStore 500TCWE-78Dell PowerStore contains an OS Command Injection vulnerability. An authentica…
CVE-2026-585728.8—DellPowerStore 500TCWE-94Dell PowerStore contains a Code Injection vulnerability. An authenticated use…
CVE-2026-585758.8—DellPowerStore 500TCWE-290Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. …
CVE-2026-726498.8—ElasticElasticsearchCWE-502Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Exe…
CVE-2026-737028.8—Hewlett Packard Enterprise (HPE)Fabric Composer—Authenticated Privilege Escalation Vulnerability in the API of HPE Networking…
CVE-2026-737038.8—Hewlett Packard Enterprise (HPE)Fabric Composer—Unauthenticated Stored Cross-Site Scripting (XSS) Vulnerability in HPE Networ…
CVE-2026-737048.8—Hewlett Packard Enterprise (HPE)Fabric Composer—Authenticated Command Injection Leading to Administrative Access in HPE Netwo…
CVE-2026-737058.8—Hewlett Packard Enterprise (HPE)Fabric Composer—Authenticated Arbitrary File Write leads to Remote Code Execution in HPE Netw…
CVE-2026-737508.8—Hewlett Packard Enterprise (HPE)AOS-CX—Authenticated Buffer Overflow Vulnerabilities in AOS-CX API Endpoint Leads to…
CVE-2026-737518.8—Hewlett Packard Enterprise (HPE)AOS-CX—Authenticated Remote Command Injection in AOS-CX Web-based Management Interface
CVE-2026-737528.8—Hewlett Packard Enterprise (HPE)AOS-CX—Unauthenticated Arbitrary File Write Vulnerability Leads to Remote Code Execu…
CVE-2026-737538.8—Hewlett Packard Enterprise (HPE)AOS-CX—Authenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line…
CVE-2026-737828.8—Hewlett Packard Enterprise (HPE)AOS-CX—Unauthenticated Format String Vulnerability leads to Remote Code Execution in…
CVE-2026-761118.8—DellPowerStore 500TCWE-863Dell PowerStore contains an Incorrect Authorization vulnerability. An authent…
CVE-2026-796828.8—DellPowerStore 500TCWE-77Dell PowerStore contains a Command Injection vulnerability. An authenticated …
CVE-2026-796838.8—DellPowerStore 500TCWE-693Dell PowerStore contains a Protection Mechanism Failure vulnerability. An aut…
CVE-2026-796848.8—DellPowerStore 500TCWE-693Dell PowerStore contains a Protection Mechanism Failure vulnerability. An aut…
CVE-2026-796868.8—DellPowerStore 500TCWE-693Dell PowerStore contains a Protection Mechanism Failure vulnerability. An aut…
CVE-2026-841178.8—MozillaFirefoxCWE-284Privilege escalation in Firefox for Android
CVE-2026-841238.8—MozillaFirefoxCWE-416Privilege escalation due to use-after-free in the Graphics: WebGPU component
CVE-2026-841288.8—MozillaFirefoxCWE-284Privilege escalation in the WebDriver BiDi component
CVE-2026-841318.8—MozillaFirefoxCWE-763Privilege escalation due to invalid pointer in the Graphics component
CVE-2026-841878.8—WWBNAVideoCWE-284AVideo on_publish.php Missing Authentication Check via RTMP Callback
CVE-2026-842688.8—Red HatRed Hat Enterprise Linux 10CWE-122Gvfs: sftp: heap-based buffer overflow in read_reply()
CVE-2026-843478.8—GoogleChromeCWE-416Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a re…
CVE-2026-843508.8—GoogleChromeCWE-416Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a …
CVE-2024-79528.7—Rockwell AutomationDataEdgePlatform DataMosaix™ Private CloudCWE-798DataEdgePlatform DataMosaix™ Private Cloud
CVE-2024-79538.7—Rockwell AutomationDataEdgePlatform DataMosaix™ Private CloudCWE-284DataEdgePlatform DataMosaix™ Private Cloud
CVE-2026-96228.7—Rockwell AutomationRSLinx Classic®CWE-191RSLinx Classic® - Multiple Vulnerabilities
CVE-2026-96248.7—Rockwell AutomationRSLinx Classic®CWE-191RSLinx Classic® - Multiple Vulnerabilities
CVE-2026-96258.7—Rockwell AutomationRSLinx Classic®CWE-120RSLinx Classic® - Multiple Vulnerabilities
CVE-2026-96378.7—Rockwell AutomationCompactLogix® 5380 / ControlLogix® 5580CWE-119CompactLogix® 5380 / ControlLogix® 5580 - Multiple Vulnerabilities
CVE-2026-194728.7—Rockwell AutomationArmorStart® LTCWE-770Rockwell Automation ArmorStart® LT Denial Of Service
CVE-2026-696648.7—ErlangOTPCWE-772httpd parks a request worker indefinitely on a malformed chunk size sent afte…
CVE-2026-703998.7—ErlangOTPCWE-770httpd does not enforce the documented default max_clients connection limit
CVE-2026-713808.7—ErlangOTPCWE-772httpd applies no timeout while receiving a request body, parking a worker on …
CVE-2026-719818.7—cypht-orgcyphtCWE-502Cypht < 2.12.2 PHP Object Injection RCE via back_query Parameter
CVE-2026-748358.7—ErlangOTPCWE-770inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Bo…
CVE-2026-836058.7—xmldomxmldomCWE-91xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed
CVE-2026-836068.7—xmldomxmldomCWE-400xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated process…
CVE-2026-836078.7—xmldomxmldomCWE-91xmldom: Element name injection via createElement() bypasses requireWellFormed
CVE-2026-836088.7—xmldomxmldomCWE-91xmldom: DocType `name` Injection Bypasses requireWellFormed
CVE-2026-836098.7—xmldomxmldomCWE-91xmldom: Creation-time XML Name/QName validation is bypassable via an embedded…
CVE-2026-836128.7—xmldomxmldomCWE-178xmldom: HTML raw-text closing-tag case mismatch causes output amplification
CVE-2026-836138.7—xmldomxmldomCWE-407xmldom: Quadratic-time attribute deduplication
CVE-2026-836148.7—xmldomxmldomCWE-400xmldom: Quadratic-time parsing via the malformed-input recovery path — `parse…
CVE-2026-836158.7—xmldomxmldomCWE-770xmldom: Quadratic-memory consumption
CVE-2026-836168.7—xmldomxmldomCWE-91xmldom: Processing Instruction Target Injection Bypasses requireWellFormed
CVE-2026-836178.7—xmldomxmldomCWE-91xmldom: requireWellFormed element/attribute name validation is bypassable via…
CVE-2026-836188.7—xmldomxmldomCWE-91xmldom: requireWellFormed DocType publicId/systemId validation is bypassable …
CVE-2026-836198.7—xmldomxmldomCWE-400xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0…
CVE-2026-841658.7—OpenNebula SystemsOpenNebulaCWE-284Lack of authorisation in OpenNebula by OpenNebula Systems
CVE-2026-841908.7—librenmslibrenmsCWE-77LibreNMS before 26.5.0 Remote Code Execution via AboutController
CVE-2026-842028.7—modelscopemodelscopeCWE-502ModelScope through 1.40.0 Unsafe YAML Deserialization in Model Config Loading
CVE-2026-842088.7—WWBNAVideoCWE-89AVideo User_Location Plugin Unauthenticated SQL Injection
CVE-2026-842358.7—Rockwell Automation1756-ENBT ModuleCWE-400Rockwell Automation 1756-ENBT Denial of Service Vulnerability
CVE-2026-843048.7—grpcgrpc-goCWE-400gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
CVE-2026-844768.7—WWBNAVideoCWE-290WWBN AVideo Authentication Bypass via X-Real-IP Header
CVE-2026-844828.7—WWBNAVideoCWE-346WWBN AVideo Cross-Site Request Forgery via get_domain() validation
CVE-2025-127688.6—Rockwell AutomationFactoryTalk® Historian Machine EditionCWE-787FactoryTalk® Historian Machine Edition - Out-of-Bounds Write Vulnerability
CVE-2026-737068.6—Hewlett Packard Enterprise (HPE)Fabric Composer—Authentication Bypass in the API of HPE Networking Fabric Composer allows Dat…
CVE-2026-841948.6—librenmslibrenmsCWE-78LibreNMS 23.10.0 before 26.4.0 OS Command Injection via Hostname
CVE-2026-842038.6—usememosmemosCWE-613Memos 0.26.0 through 0.30.0 Insufficient Session Expiration on Password Change
CVE-2026-166758.5—Rockwell AutomationFactoryTalk® Activation ManagerCWE-307Rockwell Automation FactoryTalk® Activation Manager - Privilege Escalation
CVE-2026-452218.5—EASYBYTE SoftwareKongaCWE-427Konga < 2.1.0 Privilege Escalation via Hardcoded OpenSSL Path
CVE-2026-737078.5—Hewlett Packard Enterprise (HPE)Fabric Composer—Authenticated Privilege Escalation via Broken Access Control in HPE Networkin…
CVE-2026-835518.5—AWSsagemaker-python-sdkCWE-312Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK @step/@r…
CVE-2026-737818.4—Hewlett Packard Enterprise (HPE)AOS-CX—Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in AOS-CX Web-B…
CVE-2026-631378.3—ElasticKibanaCWE-863Incorrect Authorization in Kibana Leading to Privilege Escalation
CVE-2026-663578.3—ErlangOTPCWE-444inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation
CVE-2026-732768.3—ErlangOTPCWE-444inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropp…
CVE-2026-737088.3—Hewlett Packard Enterprise (HPE)Fabric Composer—Fault in Business Logic allows Authenticated Sensitive Information Disclosure…
CVE-2026-737098.3—Hewlett Packard Enterprise (HPE)Fabric Composer—Unauthenticated Remote Code Execution during HPE Networking Fabric Composer I…
CVE-2026-737808.3—Hewlett Packard Enterprise (HPE)AOS-CX—Lack of Cross-Site Request Forgery (CSRF) Protections for Certificate-Authent…
CVE-2026-738128.3—ErlangOTPCWE-444inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length
CVE-2026-841958.3—kyvernokyvernoCWE-200Kyverno before 1.16.4 Credential Leak via apiCall
CVE-2026-841968.3—kyvernokyvernoCWE-918Kyverno before 1.18.0 Server-Side Request Forgery via apiCall
CVE-2026-843358.3—GoogleChromeCWE-863Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 a…
CVE-2026-843518.3—GoogleChromeCWE-121Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 …
CVE-2024-100858.2—Schneider ElectricEcoStruxure™ OPC UA Server ExpertCWE-770CWE-770: Allocation of Resources Without Limits or Throttling vulnerability e…
CVE-2026-187308.2—GitHubEnterprise ServerCWE-918Server-side request forgery vulnerability in GitHub Enterprise Server Manage …
CVE-2026-559518.2—ErlangOTPCWE-770httpc memory exhaustion via unbounded response header accumulation
CVE-2026-668358.2—ErlangOTPCWE-50httpd mod_auth directory protection bypassed by a doubled slash in the reques…
CVE-2026-732708.2—ErlangOTPCWE-178httpd mod_auth directory protection bypassed by request path casing on case-i…
CVE-2026-737108.2—Hewlett Packard Enterprise (HPE)Fabric Composer—Unauthenticated Denial of Service Vulnerabilities in API Endpoint of HPE Netw…
CVE-2026-737798.2—Hewlett Packard Enterprise (HPE)AOS-CX—Authentication Bypass Vulnerabilities Leading to Information Disclosure, Unau…
CVE-2026-755388.2—ErlangOTPCWE-122A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receiv…
CVE-2026-843708.2—svgsvgoCWE-79SVGO: removeScripts allows executable links through namespace and control-cha…
CVE-2026-195138.1—Gravity FormsGravity FormsCWE-434Gravity Forms <= 3.0.2 - Unauthenticated Arbitrary File Upload via State/Chun…
CVE-2026-737118.1—Hewlett Packard Enterprise (HPE)Fabric Composer—Unauthenticated Privilege Escalation allows Administrative Access in HPE Netw…
CVE-2026-737128.1—Hewlett Packard Enterprise (HPE)Fabric Composer—Unauthenticated Remote Code Execution in HPE Networking Fabric Composer API
CVE-2026-737778.1—Hewlett Packard Enterprise (HPE)AOS-CX—Authorization Bypass Vulnerabilities Leading to Privilege Escalation in AOS-C…
CVE-2026-737788.1—Hewlett Packard Enterprise (HPE)AOS-CX—Credential Manager Vulnerability Allows Unauthorized Administrative Access
CVE-2026-842188.1—Red HatRed Hat AMQ Broker 7CWE-184Org.jolokia/jolokia-core: incomplete jndi denylist in jolokia jsr-160 proxy (…
CVE-2026-843348.1—GoogleChromeCWE-863Incorrect authorization in Chromoting in Google Chrome on on Windows prior to…
CVE-2026-737767.9—Hewlett Packard Enterprise (HPE)AOS-CX—Authenticated Signature Verification Bypass Leading to Arbitrary Code Executi…
CVE-2026-617507.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617517.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617527.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617537.8—NVIDIAMegatron BridgeCWE-22NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617547.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617557.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617567.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617577.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617587.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617597.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617607.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617617.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617627.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617637.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617647.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617657.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617667.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617677.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617687.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617697.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617707.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617717.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617727.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617737.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617747.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617757.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617767.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617777.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617787.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-617797.8—NVIDIAMegatron BridgeCWE-502NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause…
CVE-2026-737137.8—Hewlett Packard Enterprise (HPE)Fabric Composer—Local Privilege Escalation Vulnerabilities in HPE Networking Fabric Composer
CVE-2026-835497.8—SonicWallSMA1000CWE-78Post-authentication Improper Neutralization of Special Elements used in an OS…
CVE-2026-191187.7—GitHubEnterprise ServerCWE-367Race condition vulnerability was identified in GitHub Enterprise Server that …
CVE-2026-737757.7—Hewlett Packard Enterprise (HPE)AOS-CX—Authenticated Sensitive Information Disclosure Vulnerabilities in AOS-CX
CVE-2026-768517.7—GitHubEnterprise ServerCWE-918Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed…
CVE-2026-843617.7—composercomposerCWE-78Composer: Perforce source URL permits P4PORT `rsh:` command execution
CVE-2026-737147.6—Hewlett Packard Enterprise (HPE)Fabric Composer—Authenticated Sensitive Information Disclosure in HPE Networking Fabric Compo…
CVE-2026-737747.6—Hewlett Packard Enterprise (HPE)AOS-CX—Unauthenticated Buffer Overflow Vulnerability leads to Sensitive Information …
CVE-2026-187717.5—TMT Machine Industry and Trade Ltd. Co.Talassoft Industrial Management SoftwareCWE-306Missing Authentication for Critical Function in TMT Machine's Talassoft Indus…
CVE-2026-493297.5—Red HatRed Hat OpenShift Container Platform 4CWE-407Openshift/oauth-server: openshift/oauth-server: quadratic-time dos via accept…
CVE-2026-517667.5—n/an/aCWE-284Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.…
CVE-2026-521307.5—n/an/aCWE-674llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/…
CVE-2026-737157.5—Hewlett Packard Enterprise (HPE)Fabric Composer—Unauthenticated Denial-of-Service (DoS) Vulnerability in the API of HPE Netwo…
CVE-2026-737167.5—Hewlett Packard Enterprise (HPE)Fabric Composer—Unauthenticated Remote Code Execution in HPE Networking Fabric Composer
CVE-2026-737177.5—Hewlett Packard Enterprise (HPE)Fabric Composer—Unauthenticated Command Injection Vulnerability in HPE Networking Fabric Comp…
CVE-2026-737717.5—Hewlett Packard Enterprise (HPE)AOS-CX—Improper Authentication Handling in AOS-CX Management Interface and API
CVE-2026-737737.5—Hewlett Packard Enterprise (HPE)AOS-CX—Unauthenticated Denial-of-Service (DoS) Vulnerability in AOS-CX
CVE-2026-841457.5—MozillaFirefoxCWE-119Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thu…
CVE-2026-843747.5—SpartnerNLLaravel-ExcelCWE-22Laravel Excel writes exports outside the configured filesystem disk when give…
CVE-2026-843757.5—nodecajs-yamlCWE-400js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
CVE-2026-737187.4—Hewlett Packard Enterprise (HPE)Fabric Composer—Unauthenticated Information Disclosure in Web Interface allows Sensitive Data…
CVE-2026-843667.4—scrapyscrapyCWE-319Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by def…
CVE-2026-133367.3—Schneider ElectricNetBotz 5 - 750/755CWE-78CWE-78: Improper Neutralization of Special Elements used in an OS Command ('O…
CVE-2026-737687.3—Hewlett Packard Enterprise (HPE)AOS-CX—Local Privilege Escalation in AOS-CX Command Line Interface
CVE-2026-737707.3—Hewlett Packard Enterprise (HPE)AOS-CX—Authenticated Arbitrary File Write Vulnerability Leading to Remote Code Execu…
CVE-2026-785927.3—ElasticKibanaCWE-22Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading…
CVE-2024-140477.2—ElasticElastic SecurityCWE-59Improper Link Resolution Before File Access ('Link Following') in Winlogbeat …
CVE-2026-737197.2—Hewlett Packard Enterprise (HPE)Fabric Composer—Authenticated Arbitrary File Write Vulnerability leads to Remote Code Executi…
CVE-2026-737207.2—Hewlett Packard Enterprise (HPE)Fabric Composer—Authenticated Insecure File Handling allows Remote Code Execution in HPE Netw…
CVE-2026-737217.2—Hewlett Packard Enterprise (HPE)Fabric Composer—Authenticated SQL Injection Vulnerabilities in HPE Networking Fabric Composer
CVE-2026-737227.2—Hewlett Packard Enterprise (HPE)Fabric Composer—Authenticated Command Injection Vulnerabilities in HPE Networking Fabric Comp…
CVE-2026-737657.2—Hewlett Packard Enterprise (HPE)AOS-CX—Authenticated Path Traversal Vulnerabilities Lead to Remote Code Execution in…
CVE-2026-737667.2—Hewlett Packard Enterprise (HPE)AOS-CX—Authenticated Command Injection Vulnerabilities in the API Endpoint of AOS-CX
CVE-2026-737677.2—Hewlett Packard Enterprise (HPE)AOS-CX—Authenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line…
CVE-2026-835957.2—WWBNAVideoCWE-352AVideo Cross-Site Request Forgery via plugin/API/set.json.php
CVE-2026-187807.1—TMT Machine Industry and Trade Ltd. Co.Talassoft Industrial Management SoftwareCWE-352CSRF in TMT Machine's Talassoft Industrial Management Software
CVE-2026-737237.1—Hewlett Packard Enterprise (HPE)Fabric Composer—Authenticated Privilege Escalation Leading to Unauthorized State Changes in H…
CVE-2026-737247.1—Hewlett Packard Enterprise (HPE)Fabric Composer—Authenticated Privilege Escalation via Broken Access Control in HPE Networkin…
CVE-2026-737637.1—Hewlett Packard Enterprise (HPE)AOS-CX—Unauthenticated Remote Command Execution in Management Component
CVE-2026-737647.1—Hewlett Packard Enterprise (HPE)AOS-CX—Authentication Bypass Vulnerabilities Leading to Unauthorized Modification an…
CVE-2026-841927.1—librenmslibrenmsCWE-79LibreNMS before 26.3.1 Stored XSS via SNMP/Syslog Data
CVE-2026-842047.1—growilabsgrowiCWE-862GROWI through 8.0.2 Missing Authorization on apiv3 Attachment Retrieval
CVE-2026-842057.1—growilabsgrowiCWE-639GROWI through 8.0.2 Authorization Bypass Through User-Controlled Key on apiv3…
CVE-2026-96337.0—Rockwell AutomationRedundancy Module Configuration ToolCWE-276Redundancy Module Configuration Tool - Multiple Vulnerabilities
CVE-2026-96347.0—Rockwell AutomationRedundancy Module Configuration ToolCWE-276Redundancy Module Configuration Tool - Multiple Vulnerabilities
CVE-2026-126637.0—Rockwell AutomationControlFLASH ®CWE-306ControlFLASH ® – Improper Access Control
CVE-2026-737257.0—Hewlett Packard Enterprise (HPE)Fabric Composer—Local Privilege Escalation leads to Arbitrary Code Execution in HPE Networkin…
CVE-2026-842337.0—Red HatRed Hat Enterprise Linux 10CWE-78Rpm: command execution via macro expansion in `rpmuncompress -x` for crafted …
CVE-2025-156136.9—kyvernokyvernoCWE-918Kyverno before v1.13.4 SSRF via Service Call
CVE-2026-87126.9—OHF-VoicewyomingCWE-918Wyoming < 1.10.2 SSRF via uri Query Parameter
CVE-2026-133486.9—Schneider ElectricPowerChute™ Serial ShutdownCWE-307CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerabil…
CVE-2026-194716.9—Rockwell AutomationArmorStart® LTCWE-79Rockwell Automation ArmorStart® LT Stored Cross-site scripting
CVE-2026-596966.9—ErlangOTPCWE-1284uri_string does not bound the port component of a URI before integer conversion
CVE-2026-836116.9—xmldomxmldomCWE-1286xmldom: Parser silently accepts a not-well-formed end tag whose name is follo…
CVE-2026-841996.9—kyvernokyvernoCWE-918Kyverno before 1.16.2 SSRF via APICall Feature
CVE-2026-842016.9—argneshuappium-mcp-serverCWE-22appium-mcp-server through 0.1.61 Path Traversal in write_file and write_files…
CVE-2026-843096.9—py-pdfpypdfCWE-835pypdf: Possible infinite loop for TreeObject.insert_child
CVE-2026-844786.9—WWBNAVideoCWE-73WWBN AVideo Unauthenticated Arbitrary Log File Deletion
CVE-2026-844816.9—WWBNAVideoCWE-200WWBN AVideo through 30.0 Information Disclosure via MobileManager
CVE-2026-844836.9—WWBNAVideoCWE-321WWBN AVideo Unauthenticated Password Hash Oracle via encryptPass.json.php
CVE-2026-737266.8—Hewlett Packard Enterprise (HPE)Fabric Composer—Authentication Bypass in HPE Networking Fabric Composer allows Unauthorized A…
CVE-2026-737626.6—Hewlett Packard Enterprise (HPE)AOS-CX—Authorization Bypass in the API Endpoint of AOS-CX Leads to Unauthorized Access
CVE-2026-118736.5—Red HatRed Hat Certificate System 9CWE-209Pki-core: dogtag-pki: empty request to dogtag /ca/rest/certrequests causes ht…
CVE-2026-334656.5—ElasticKibanaCWE-770Allocation of Resources Without Limits or Throttling in Kibana Leading to Den…
CVE-2026-631386.5—ElasticKibanaCWE-943Improper Neutralization of Special Elements in Data Query Logic in Kibana Lea…
CVE-2026-726286.5—ElasticKibanaCWE-409Improper Handling of Highly Compressed Data in Kibana Leading to Denial of Se…
CVE-2026-726446.5—ElasticKibanaCWE-248Uncaught Exception in Kibana Leading to Denial of Service
CVE-2026-726526.5—ElasticKibanaCWE-770Allocation of Resources Without Limits or Throttling in Kibana Leading to Den…
CVE-2026-726546.5—ElasticKibanaCWE-250Execution with Unnecessary Privileges in Kibana Leading to Information Disclo…
CVE-2026-726826.5—ElasticKibanaCWE-770Allocation of Resources Without Limits or Throttling in Kibana Leading to Den…
CVE-2026-737276.5—Hewlett Packard Enterprise (HPE)Fabric Composer—Authenticated Sensitive Information Disclosure in HPE Networking Fabric Compo…
CVE-2026-737286.5—Hewlett Packard Enterprise (HPE)Fabric Composer—Authenticated Denial of Service Vulnerabilities in HPE Networking Fabric Comp…
CVE-2026-737296.5—Hewlett Packard Enterprise (HPE)Fabric Composer—Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer
CVE-2026-737306.5—Hewlett Packard Enterprise (HPE)Fabric Composer—Authenticated Privilege Escalation via Broken Access Control in HPE Networkin…
CVE-2026-737586.5—Hewlett Packard Enterprise (HPE)AOS-CX—Authenticated Privilege Escalation Vulnerability via Broken Access Control in…
CVE-2026-737596.5—Hewlett Packard Enterprise (HPE)AOS-CX—Unauthenticated Denial-of-Service Vulnerabilities in AOS-CX
CVE-2026-737606.5—Hewlett Packard Enterprise (HPE)AOS-CX—Authenticated Path Traversal Vulnerability Leads to Remote Unauthorized Acces…
CVE-2026-737616.5—Hewlett Packard Enterprise (HPE)AOS-CX—Unauthenticated Out-of-Bounds Read Vulnerability leads to Information Disclos…
CVE-2026-737726.5—Hewlett Packard Enterprise (HPE)AOS-CX—Unauthenticated Buffer Overflow Vulnerabilities lead to Denial-of-Service in …
CVE-2026-786086.5—ElasticKibanaCWE-862Missing Authorization in Kibana Leading to Information Disclosure
CVE-2026-796856.5—DellPowerStore 500TCWE-88Dell PowerStore contains an Argument Injection vulnerability. An authenticate…
CVE-2026-842696.5—Red HatRed Hat Enterprise Linux 10CWE-122Gvfs: afp: heap-based buffer overflow in dsi read path
CVE-2026-843066.5—filamentphpfilamentCWE-294Filament: Multi-factor authentication (app) codes can still be used after a n…
CVE-2026-843276.5—GoogleChromeCWE-863Incorrect authorization in Autofill in Google Chrome on on Android prior to 1…
CVE-2026-843486.5—GoogleChromeCWE-200Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allo…
CVE-2026-843656.5—honojshonoCWE-22Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside…
CVE-2026-78776.4—Bootstrapped VenturesWP Recipe Maker PremiumCWE-79WP Recipe Maker Premium <= 10.5.0 - Authenticated (Contributor+) Stored Cross…
CVE-2026-737576.4—Hewlett Packard Enterprise (HPE)AOS-CX—Authenticated Server-Side Request Forgery (SSRF) Leading to Information Discl…
CVE-2026-844706.4—Red HatRed Hat Ansible Automation Platform 2CWE-862Automation-controller: automation-controller-container: automation-controller…
CVE-2026-704056.3—ErlangOTPCWE-1284snmp BER INTEGER decoder applies no size limit to attacker-supplied integer f…
CVE-2026-704096.3—ErlangOTPCWE-1284eldap does not bound the port component of a referral URL before integer conv…
CVE-2026-715626.3—ErlangOTPCWE-1284httpc does not bound server-supplied numeric header values before integer con…
CVE-2026-836106.3—xmldomxmldomCWE-116xmldom: XML fragment injection via invalid EntityReference.nodeName during re…
CVE-2026-843036.3—grpcgrpc-goCWE-178gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC …
CVE-2026-843086.3—phpseclibphpseclibCWE-208phpseclib — non-constant-time X25519 scalar multiplication permits full priva…
CVE-2026-737316.1—Hewlett Packard Enterprise (HPE)Fabric Composer—Unauthenticated Reflected Cross-Site Scripting (XSS) Vulnerability in HPE Net…
CVE-2026-843696.1—svgsvgoCWE-79SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObje…
CVE-2026-749946.0—ErlangOTPCWE-863inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd…
CVE-2026-517425.9—n/an/aCWE-284Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.7…
CVE-2026-517485.9—n/an/aCWE-284Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T…
CVE-2026-517565.9—n/an/aCWE-284Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5c…
CVE-2026-737565.9—Hewlett Packard Enterprise (HPE)AOS-CX—Unauthenticated Sensitive Information Disclosure via Man-in-the-Middle in AOS…
CVE-2026-786055.9—ElasticElasticsearchCWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in El…
CVE-2026-843635.9—honojshonoCWE-444Hono: Query parser reads parameters after the URL fragment, causing cache-key…
CVE-2026-843735.9—vitest-devvitestCWE-22Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock
CVE-2026-841935.8—librenmslibrenmsCWE-79LibreNMS through 26.2.0 Stored Cross-Site Scripting via SNMP
CVE-2026-737555.7—Hewlett Packard Enterprise (HPE)AOS-CX—Privilege Escalation via Unauthorized Access to Sensitive Session Information
CVE-2026-737325.6—Hewlett Packard Enterprise (HPE)Fabric ComposerCWE-200Local Authenticated Sensitive Information Disclosure in HPE Networking Fabric…
CVE-2026-835575.6—FasterXMLjackson-databindCWE-502jackson-databind omits java.lang.Comparable from DefaultBaseTypeLimitingValid…
CVE-2026-104205.5—Samsung Open SourcemTowerCWE-822Untrusted pointer dereference vulnerability in Samsung Open Source mTower all…
CVE-2026-829265.5—Samsung Open SourcemTowerCWE-476NULL pointer dereference vulnerability in Samsung Open Source mTower allows P…
CVE-2026-829275.5—Samsung Open SourcemTowerCWE-822Untrusted pointer dereference vulnerability in Samsung Open Source mTower all…
CVE-2026-841105.5—ReleasitReleasit COD Form & UpsellsCWE-602Releasit Releasit COD Form & Upsells OTP Validation client-side enforcement o…
CVE-2026-841115.5—ChanjetCRMCWE-74Chanjet CRM jxf_dump_table.php sql injection
CVE-2026-841155.5—CleoHarmonyCWE-266Cleo Harmony JWT Refresh Token connections privileges management
CVE-2026-844235.5—n/aCasdoorCWE-287Casdoor upload-resource API resource.go missing authentication
CVE-2026-726415.4—ElasticKibanaCWE-863Incorrect Authorization in Kibana Leading to Unauthorized Modification of Data
CVE-2026-737335.4—Hewlett Packard Enterprise (HPE)Fabric ComposerCWE-287Authentication Bypasses in API allow Continued Authenticated Access in HPE Ne…
CVE-2026-737345.4—Hewlett Packard Enterprise (HPE)Fabric ComposerCWE-601Unauthenticated Open Redirect allows URL Manipulation in HPE Networking Fabri…
CVE-2026-737355.4—Hewlett Packard Enterprise (HPE)Fabric ComposerCWE-552Authenticated Access Control Vulnerabilities allow Information Disclosure in …
CVE-2026-786075.4—ElasticElasticsearchCWE-862Missing Authorization in Elasticsearch Leading to Information Disclosure
CVE-2026-841185.4—MozillaFirefoxCWE-416Use-after-free in the JavaScript: GC component
CVE-2026-841205.4—MozillaFirefoxCWE-416Use-after-free in the Audio/Video component
CVE-2026-841225.4—MozillaFirefoxCWE-416Use-after-free in the Audio/Video component
CVE-2026-841245.4—MozillaFirefoxCWE-416Use-after-free in the DOM: Core & HTML component
CVE-2026-841255.4—MozillaFirefoxCWE-416Use-after-free in the DOM: Core & HTML component
CVE-2026-842325.4—Red HatRed Hat Ansible Automation Platform 2CWE-79Pulpcore: python-pulpcore: stored cross-site scripting via inline rendering o…
CVE-2026-843715.4—apostrophecmsapostropheCWE-79ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass
CVE-2026-517455.3—n/an/aCWE-284Incorrect access control in the updatePriStaList function of TOTOLINK T6 4.1.…
CVE-2026-517525.3—n/an/aCWE-284Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5c…
CVE-2026-517615.3—n/an/aCWE-284Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.7…
CVE-2026-536825.3—Red HatRed Hat Certificate System 9CWE-200Pki-core: dogtag-pki: unauthenticated dogtag ca rest api exposes security dom…
CVE-2026-634355.3—mikelmailCWE-436Mail: Email address spoofing via malformed RFC 2047 encoded-words
CVE-2026-737365.3—Hewlett Packard Enterprise (HPE)Fabric ComposerCWE-552Unauthenticated Limited Information Disclosure leads to Data Exposure in HPE …
CVE-2026-737545.3—Hewlett Packard Enterprise (HPE)AOS-CX—Authenticated Denial-of-Service Vulnerabilities in the Command Line Interface…
CVE-2026-771945.3—wpinsider-1Simple MembershipCWE-287Simple Membership <= 4.8.1 - Unauthenticated Authentication Bypass to Adminis…
CVE-2026-840615.3—zhongyu09OpenChatBICWE-74zhongyu09 OpenChatBI generate_sql.py _validate_sql_safety sql injection
CVE-2026-841915.3—librenmslibrenmsCWE-79LibreNMS before 26.5.0 Stored XSS via SNMP VRF fields
CVE-2026-842065.3—grokabilitysnipe-itCWE-863Snipe-IT before 8.7.0 Authorization Bypass via Bulk Restore
CVE-2026-842075.3—heymrunheymCWE-918Heym before 0.0.98 SSRF via WebSocket endpoints
CVE-2026-843235.3—GoogleChromeCWE-862Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 a…
CVE-2026-843295.3—GoogleChromeCWE-441Confused deputy in CredentialProvider in Google Chrome on on Windows prior to…
CVE-2026-843645.3—honojshonoCWE-400Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaus…
CVE-2026-133375.1—Schneider ElectricNetBotz 5 - 750/755CWE-564CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the i…
CVE-2026-735245.1—cypht-orgcyphtCWE-79Cypht < 2.12.2 XSS via FROM Email Header in Contacts Module
CVE-2026-843055.1—andialbrechtsqlparseCWE-407sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption
CVE-2026-844775.1—WWBNAVideoCWE-79AVideo Stored XSS via Live Schedule Title Description
CVE-2026-561434.9—ElasticElasticsearchCWE-770Allocation of Resources Without Limits or Throttling in Elasticsearch Leading…
CVE-2026-737834.9—Hewlett Packard Enterprise (HPE)AOS-CX—Authenticated Stack Overflow Vulnerabilities lead to Denial-of-Service in AOS-CX
CVE-2026-126614.8—Rockwell AutomationFactoryTalk® Historian Machine EditionCWE-121FactoryTalk® Historian Machine Edition - Out-of-Bounds Write Vulnerability
CVE-2026-737374.8—Hewlett Packard Enterprise (HPE)Fabric ComposerCWE-22Unauthenticated Path Traversal in HPE Networking Fabric Composer API Endpoint…
CVE-2026-841884.8—librenmslibrenmsCWE-79librenms before 26.7.0 Stored XSS via graph_descr settings
CVE-2026-843104.8—py-pdfpypdfCWE-405pypdf: Possible long runtimes/large memory usage when retrieving outlines
CVE-2026-843114.8—py-pdfpypdfCWE-834pypdf: Possible long runtimes/large memory usage when extracting XForm objects
CVE-2026-737384.7—Hewlett Packard Enterprise (HPE)Fabric ComposerCWE-200Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer
CVE-2026-737394.4—Hewlett Packard Enterprise (HPE)Fabric ComposerCWE-200Authenticated Sensitive Information Disclosure in HPE Networking Fabric Compo…
CVE-2026-737404.4—Hewlett Packard Enterprise (HPE)Fabric ComposerCWE-269Local Privilege Escalation in HPE Networking Fabric Composer
CVE-2026-726334.3—ElasticKibanaCWE-863Incorrect Authorization in Kibana Leading to Unauthorized Disabling of Privil…
CVE-2026-737414.3—Hewlett Packard Enterprise (HPE)Fabric ComposerCWE-284Authenticated Limited File Read allows Data Exposure in HPE Networking Fabric…
CVE-2026-737424.3—Hewlett Packard Enterprise (HPE)Fabric ComposerCWE-290Improper Client Address Validation allows Request Attribution Spoofing in Fab…
CVE-2026-785974.3—ElasticKibanaCWE-862Missing Authorization in Kibana Entity Store Leading to Unauthorized API Key …
CVE-2026-786034.3—ElasticKibanaCWE-862Missing Authorization in Kibana Leading to Unauthorized Disclosure of Fleet D…
CVE-2026-841264.3—MozillaFirefoxCWE-120Incorrect boundary conditions in the Layout: Grid component
CVE-2026-841274.3—MozillaFirefoxCWE-200Information disclosure in the WebExtensions component in Firefox for Android
CVE-2026-842674.3—Red HatRed Hat Enterprise Linux 10CWE-908Gvfs: sftp: uninitialized heap disclosure in read_string()
CVE-2026-842704.3—Red HatRed Hat Enterprise Linux 10CWE-125Gvfs: mtp: out-of-bounds read in do_read()
CVE-2026-786064.2—ElasticKibanaCWE-863Incorrect Authorization in Kibana Leading to Unauthorized Disclosure, Modific…
CVE-2026-737433.7—Hewlett Packard Enterprise (HPE)Fabric ComposerCWE-319Unauthenticated Information Disclosure Leading to Data Exposure in HPE Networ…
CVE-2026-843073.7—filamentphpfilamentCWE-204Filament: Password validity disclosure for accounts denied panel access on lo…
CVE-2026-843673.7—hapijsjoiCWE-1321joi: object().rename() with a template target can set the validated object's …
CVE-2026-843683.7—hapijsjoiCWE-1321joi: Prototype pollution via a `__proto__` language key in custom messages
CVE-2026-737443.5—Hewlett Packard Enterprise (HPE)Fabric ComposerCWE-400Authenticated Denial of Service Vulnerability in HPE Networking Fabric Compos…
CVE-2026-818463.5—runZeroPlatformCWE-639runZero MCP 'Findings summaries' Data Leak
CVE-2026-737453.1—Hewlett Packard Enterprise (HPE)Fabric Composer—Unauthenticated Limited Information Disclosure allows Data Exposure in the AP…
CVE-2026-737463.1—Hewlett Packard Enterprise (HPE)Fabric ComposerCWE-400Authenticated Denial of Service Vulnerability in HPE Networking Fabric Compos…

Results continue: ranks 401–477.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-01 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.