AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L P H H H 8.6 .0234 82.4 —
AFFECTED Product Versions Fixed yast2-users unspecified —
TIMELINE Jul 6 Reserved by CNA Sep 1 Published (CNA: suse)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
477 CVEs published, led by Hewlett Packard Enterprise (HPE) (86).
477 CVEs published September 1, 2026: 34 critical, 194 high, 151 medium, 30 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 68 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 77 on continuation pages.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 477 | 35211 | — | — |
| KEV catalog size | 1687 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
2200 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 0 | 3960 | 418 | 1972 | 637 | 1 | 12 | 3 | 0.1 | 7.8 | .0016 | 0 |
| 26 | 2190 | 272 | 848 | 972 | 83 | 77 | 6 | 0.3 | 7.5 | .0026 | +26 ▲ | |
| microsoft | 0 | 1899 | 145 | 1283 | 456 | 15 | 287 | 28 | 1.5 | 7.8 | .0044 | 0 |
| red hat | 12 | 639 | 39 | 262 | 302 | 35 | 2 | 0 | 0.0 | 6.5 | .0029 | +12 ▲ |
| apple | 0 | 316 | 59 | 85 | 165 | 7 | 88 | 8 | 2.5 | 6.5 | .0029 | 0 |
| freebsd | 0 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| canonical | 0 | 42 | 13 | 11 | 13 | 5 | 0 | 0 | 0.0 | 7.8 | .0020 | 0 |
| suse | 3 | 31 | 5 | 17 | 8 | 1 | 0 | 0 | 0.0 | 7.8 | .0039 | +3 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 0 | 84 | 21 | 39 | 24 | 0 | 56 | 13 | 15.5 | 7.5 | .0044 | 0 |
| ubiquiti | 0 | 59 | 36 | 22 | 1 | 0 | 3 | 3 | 5.1 | 9.1 | .0049 | 0 |
| palo alto networks | 0 | 37 | 1 | 3 | 21 | 12 | 13 | 2 | 5.4 | 4.7 | .0020 | 0 |
| netgear | 0 | 32 | 0 | 0 | 27 | 5 | 0 | 0 | 0.0 | 4.3 | .0025 | 0 |
| fortinet | 0 | 30 | 7 | 8 | 14 | 1 | 28 | 6 | 20.0 | 7.0 | .0050 | 0 |
| vmware | 0 | 19 | 4 | 10 | 3 | 2 | 7 | 2 | 10.5 | 8.3 | .0040 | 0 |
| f5 | 0 | 17 | 5 | 9 | 3 | 0 | 4 | 1 | 5.9 | 8.7 | .0057 | 0 |
| sonicwall | 2 | 16 | 3 | 8 | 4 | 0 | 17 | 2 | 12.5 | 7.8 | .0024 | +2 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 0 | 507 | 103 | 217 | 173 | 13 | 33 | 2 | 0.4 | 7.5 | .0049 | 0 |
| mozilla | 34 | 221 | 70 | 73 | 58 | 0 | 9 | 0 | 0.0 | 8.1 | .0030 | +34 ▲ |
| gitlab | 0 | 76 | 3 | 17 | 47 | 9 | 4 | 2 | 2.6 | 5.3 | .0029 | 0 |
| drupal | 0 | 68 | 10 | 7 | 46 | 5 | 4 | 1 | 1.5 | 5.9 | .0024 | 0 |
| github | 3 | 20 | 1 | 10 | 9 | 0 | 0 | 0 | 0.0 | 7.3 | .0044 | +3 ▲ |
| docker | 0 | 9 | 0 | 6 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0016 | 0 |
| wordpress | 0 | 5 | 1 | 3 | 1 | 0 | 2 | 2 | 40.0 | 8.8 | .3120 | 0 |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0035 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 2269 | 484 | 1170 | 519 | 96 | 28 | 4 | 0.2 | 7.8 | .0034 | 0 |
| ibm | 0 | 619 | 148 | 286 | 177 | 8 | 6 | 1 | 0.2 | 7.6 | .0030 | 0 |
| adobe | 0 | 606 | 50 | 300 | 247 | 9 | 19 | 3 | 0.5 | 7.8 | .0021 | 0 |
| progress | 0 | 61 | 14 | 37 | 10 | 0 | 6 | 1 | 1.6 | 8.1 | .0037 | 0 |
| solarwinds | 0 | 23 | 17 | 3 | 3 | 0 | 10 | 4 | 17.4 | 9.1 | .0058 | 0 |
| veeam | 0 | 19 | 6 | 10 | 3 | 0 | 1 | 0 | 0.0 | 8.6 | .0032 | 0 |
| zohocorp | 0 | 10 | 3 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0140 | 0 |
| atlassian | 0 | 6 | 1 | 5 | 0 | 0 | 13 | 0 | 0.0 | 8.1 | .0032 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 0 | 45 | 15 | 13 | 9 | 8 | 3 | 0 | 0.0 | 8.5 | .0157 | 0 |
| rockwell automation | 16 | 41 | 5 | 30 | 6 | 0 | 0 | 0 | 0.0 | 8.7 | .0024 | +16 ▲ |
| siemens | 0 | 37 | 2 | 24 | 8 | 3 | 0 | 0 | 0.0 | 7.3 | .0016 | 0 |
| synology | 0 | 27 | 3 | 6 | 15 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | 0 |
| schneider electric | 4 | 13 | 1 | 8 | 4 | 0 | 0 | 0 | 0.0 | 8.2 | .0037 | +4 ▲ |
| abb | 0 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | 0 |
| hikvision | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0040 | 0 |
| mitsubishi electric | 0 | 5 | 0 | 4 | 1 | 0 | 0 | 0 | 0.0 | 7.2 | .0052 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dell | 13 | 184 | 13 | 102 | 64 | 5 | 2 | 1 | 0.5 | 7.3 | .0019 | +13 ▲ |
| spring | 0 | 170 | 9 | 60 | 85 | 16 | 0 | 0 | 0.0 | 6.5 | .0023 | 0 |
| sourcecodester | 0 | 169 | 0 | 0 | 92 | 77 | 0 | 0 | 0.0 | 5.5 | .0029 | 0 |
| nvidia | 30 | 164 | 19 | 115 | 30 | 0 | 0 | 0 | 0.0 | 7.8 | .0034 | +30 ▲ |
| splunk | 0 | 128 | 6 | 47 | 70 | 5 | 1 | 1 | 0.8 | 6.5 | .0025 | 0 |
| itsourcecode | 0 | 116 | 0 | 0 | 32 | 84 | 0 | 0 | 0.0 | 2.1 | .0027 | 0 |
| openclaw | 0 | 111 | 0 | 58 | 39 | 14 | 0 | 0 | 0.0 | 7.0 | .0026 | 0 |
| zephyrproject | 0 | 110 | 3 | 33 | 62 | 12 | 0 | 0 | 0.0 | 6.4 | .0020 | -2 ▼ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-8037 | .9957 | 99.9 | 9.8 |
| CVE-2026-34486 | .9862 | 99.9 | 7.5 |
| CVE-2026-63077 | .8771 | 99.7 | 9.8 |
| CVE-2026-60004 | .8678 | 99.7 | 9.8 |
| CVE-2026-72898 | .8232 | 99.6 | 10.0 |
| CVE-2026-18577 | .5407 | 98.9 | 8.2 |
| CVE-2026-18556 | .4016 | 98.5 | 8.2 |
| CVE-2026-64638 | .3120 | 98.1 | 8.9 |
| CVE-2026-71362 | .2514 | 97.8 | 9.1 |
| CVE-2026-73570 | .2053 | 97.3 | 8.9 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-72898 | 10.0 | .8232 | KEV |
| CVE-2026-48362 | 10.0 | .0431 | |
| CVE-2026-19188 | 10.0 | .0193 | |
| CVE-2026-58231 | 10.0 | .0171 | |
| CVE-2026-76195 | 10.0 | .0159 | |
| CVE-2026-76197 | 10.0 | .0159 | |
| CVE-2026-69836 | 10.0 | .0155 | |
| CVE-2026-73299 | 10.0 | .0121 | |
| CVE-2026-73678 | 10.0 | .0114 | |
| CVE-2026-77554 | 10.0 | .0099 |
| Vendor | CVEs |
|---|---|
| linux | 1645 |
| oracle | 890 |
| microsoft | 477 |
| 428 | |
| ibm | 390 |
| red hat | 237 |
| apache | 169 |
| splunk | 110 |
| adobe | 101 |
| mozilla | 94 |
| Vendor | KEV |
|---|---|
| microsoft | 28 |
| cisco | 13 |
| apple | 8 |
| fortinet | 6 |
| 6 | |
| ivanti | 5 |
| oracle | 4 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 63 |
| Packagist | 29 |
| npm | 15 |
| PyPI | 14 |
| Go | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-18556 | N-able | 0 |
| CVE-2026-18577 | N-able | 0 |
| CVE-2026-20349 | Cisco | 0 |
| CVE-2026-34486 | Apache Software Foundation | 0 |
| CVE-2026-63077 | JetBrains | 0 |
| CVE-2026-72529 | TrueConf | 0 |
| CVE-2026-72530 | TrueConf | 0 |
| CVE-2026-72898 | Metabase | 0 |
| CVE-2026-8037 | Progress Software | 0 |
| CVE-2026-64849 | mlflow | 1 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1749 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1749 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1749 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1749 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1749 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1749 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1749 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1749 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1749 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1749 |
EXPLOIT PUBLISHED — thorsten phpMyFAQ: 11 CVEs (CVE-2026-75918, CVE-2026-75919, CVE-2026-75920, CVE-2026-76205, CVE-2026-76208, CVE-2026-76209, CVE-2026-76210, CVE-2026-76211, CVE-2026-76212, CVE-2026-76213, CVE-2026-76215). Public exploit references added.
EXPLOIT PUBLISHED — axios: 10 CVEs (CVE-2026-67312, CVE-2026-67313, CVE-2026-67314, CVE-2026-67315, CVE-2026-67316, CVE-2026-67317, CVE-2026-67318, CVE-2026-67319, CVE-2026-67320, CVE-2026-67321). Public exploit references added.
EXPLOIT PUBLISHED — zephyrproject zephyr: 10 CVEs (CVE-2026-2411, CVE-2026-7007, CVE-2026-10659, CVE-2026-10683, CVE-2026-10685, CVE-2026-10773, CVE-2026-10774, CVE-2026-10848, CVE-2026-10849, CVE-2026-11368). Public exploit references added.
EXPLOIT PUBLISHED — Wireshark Foundation Wireshark: 7 CVEs (CVE-2026-19694, CVE-2026-19695, CVE-2026-19696, CVE-2026-76879, CVE-2026-76881, CVE-2026-76924, CVE-2026-76926). Public exploit references added.
EXPLOIT PUBLISHED — GNOME GLib: 5 CVEs (CVE-2026-58010, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015). Public exploit references added.
EXPLOIT PUBLISHED — nltk: 5 CVEs (CVE-2026-78681, CVE-2026-79675, CVE-2026-80205, CVE-2026-80206, CVE-2026-81725). Public exploit references added.
EXPLOIT PUBLISHED — Red Hat Enterprise Linux 10: 4 CVEs (CVE-2026-5704, CVE-2026-48864, CVE-2026-55653, CVE-2026-55654). Public exploit references added.
EXPLOIT PUBLISHED — handlebars-lang handlebars.js: 3 CVEs (CVE-2026-33939, CVE-2026-33940, CVE-2026-33941). Public exploit references added.
EXPLOIT PUBLISHED — openemr: 3 CVEs (CVE-2026-39931, CVE-2026-39932, CVE-2026-67611). Public exploit references added.
EXPLOIT PUBLISHED — Red Hat Hardened Images: 3 CVEs (CVE-2026-0989, CVE-2026-0990, CVE-2026-0992). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2023-39533 (libp2p go-libp2p). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2024-6387 (OpenSSH). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-4598 (systemd-coredump). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-5914 (libarchive). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-6021 (libxml2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-24049 (pypa wheel). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-26899. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-29786 (isaacs node-tar). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-3832 (gnutls). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-41523 (vllm-project vllm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-43500 (Linux). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-53622 (traefik). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58049 (FFmpeg). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-62911 (Microsoft Exchange Server 2016 Cumulative Update 23). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-67307 (wazuh). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-71225 (Stephan Muelle libkcapi). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-71227 (Stephan Muelle libkcapi). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-74883 (jahlives openssl_encrypt). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-78465 (GNOME GIMP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-79720 (Netron). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82482 (coppermine-gallery Coppermine Photo Gallery). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82487 (Beetel 450TC3). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82539 (TOTOLINK A720R). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82542 (Tenda HG10). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82548 (Linux Foundation Magma). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82553 (sambitraj Student Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82593 (D-Link DIR-825M). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82598 (SeaCMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82603 (SeaCMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82609 (itsourcecode Sales and Inventory System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82614 (itsourcecode Online Medicine Delivery System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82616 (TOTOLINK NR1800X). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82620 (Soarkey StudentManagement). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82625 (code-projects Simple Inventory System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82664 (yaojingang GEOFlow). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82688 (D-Link DNS-340L). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82807 (ieungSoft Ultra RAMDisk Pro). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82820 (FLVMeta). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82833 (Doccano Open Source Annotation Tools for Machine Learning Practitioners). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82835 (caoqianming django-vue-admin). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82906 (sdcb chats). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82908 (MSI Dragon Center). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82914 (kishan0725 Hospital-Management-System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82921 (ShopEx ECShop). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82922 (ShopEx ECShop). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82971 (QVidium Opera11). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-83524 (RedPort Optimizer wXa-203). Public exploit reference added.
REJECTED — CVE-2024-58377 (sparklemotion nokogiri). Record withdrawn by the CNA.
REJECTED — CVE-2024-58378 (sparklemotion nokogiri). Record withdrawn by the CNA.
REJECTED — CVE-2025-71346 (sparklemotion nokogiri). Record withdrawn by the CNA.
REJECTED — CVE-2025-71406 (sparklemotion nokogiri). Record withdrawn by the CNA.
REJECTED — CVE-2025-71407 (sparklemotion nokogiri). Record withdrawn by the CNA.
REJECTED — CVE-2026-78477 (MVPThemes Jawn). Record withdrawn by the CNA.
REJECTED — CVE-2026-78562 (Mikado-Themes Verdure Core). Record withdrawn by the CNA.
REJECTED — CVE-2026-78563 (WPDeveloper NotificationX Pro). Record withdrawn by the CNA.
REJECTED — CVE-2026-78566 (Edge-Themes Shuffle). Record withdrawn by the CNA.
REJECTED — CVE-2026-78568 (KlbTheme Total Donations). Record withdrawn by the CNA.
REJECTED — CVE-2026-78570 (KlbTheme Total Donations). Record withdrawn by the CNA.
REJECTED — CVE-2026-78572 (unknown Kalles Addons). Record withdrawn by the CNA.
REJECTED — CVE-2026-78576 (Readabler). Record withdrawn by the CNA.
RESCORED — NVIDIA NemoClaw: 6 CVEs (CVE-2026-65081, CVE-2026-65082, CVE-2026-65084, CVE-2026-65087, CVE-2026-65097, CVE-2026-65098). CVSS rescored — before/after on each CVE page.
RESCORED — Red Hat Advanced Cluster Management for Kubernetes 2: 6 CVEs (CVE-2026-66780, CVE-2026-66782, CVE-2026-66783, CVE-2026-66785, CVE-2026-66787, CVE-2026-66788). CVSS rescored — before/after on each CVE page.
RESCORED — Wireshark Foundation Wireshark: 5 CVEs (CVE-2026-19694, CVE-2026-19695, CVE-2026-19696, CVE-2026-76881, CVE-2026-76926). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2026-33941 (handlebars-lang handlebars.js). CVSS 8.3 → 8.2 (NVD).
RESCORED — CVE-2026-34714 (Vim). CVSS 9.2 → 8.6 (NVD).
RESCORED — CVE-2026-47863 (Spring Reactor Core). CVSS 5.9 → 7.5 (NVD).
RESCORED — CVE-2026-47881 (Spring Batch). CVSS 5.9 → 7.5 (NVD).
RESCORED — CVE-2026-47894 (Spring Cloud Config). CVSS 4.9 → 7.5 (NVD).
RESCORED — CVE-2026-5704 (Red Hat Enterprise Linux 10). CVSS 5 → 5.5 (NVD).
RESCORED — CVE-2026-59270 (Spring Security). CVSS 9.4 → 9.1 (NVD).
RESCORED — CVE-2026-59271 (Spring AMQP). CVSS 5.3 → 6.5 (NVD).
RESCORED — CVE-2026-59275 (Spring AMQP). CVSS 6.6 → 4.9 (NVD).
RESCORED — CVE-2026-59354 (VMware by Broadcom Spring Security (OAuth2 Authorization Server module)). CVSS 9.6 → 8.8 (NVD).
RESCORED — CVE-2026-66781 (Red Hat Advanced Cluster Management for Kubernetes 2.11). CVSS 6.5 → 5.4 (NVD).
RESCORED — CVE-2026-66795 (Red Hat multicluster engine for Kubernetes 2.10). CVSS 9.1 → 9.9 (NVD).
RESCORED — CVE-2026-6876 (ServiceNow AI Platform). CVSS 8.7 → 10 (NVD).
RESCORED — CVE-2026-75052 (JetBrains IntelliJ IDEA). CVSS 3.6 → 4.4 (NVD).
RESCORED — CVE-2026-75871 (GitLab AI Gateway). CVSS 8.2 → 9.6 (NVD).
RESCORED — CVE-2026-79938 (Dell Power Protect Cyber Recovery). CVSS 7.6 → 8.8 (NVD).
RESCORED — CVE-2026-79939 (Dell Power Protect Cyber Recovery). CVSS 5.8 → 7.8 (NVD).
PATCH SHIPPED — CVE-2026-28191 (ThemeOne The Grid). Fixed in The Grid 2.8.1.
How to read these box scores · glossary
477 CVEs published. 25 box scores and 375 table rows below; the remaining 77 continue on page 2 — every CVE is listed, nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L P H H H 8.6 .0234 82.4 —
AFFECTED Product Versions Fixed yast2-users unspecified —
TIMELINE Jul 6 Reserved by CNA Sep 1 Published (CNA: suse)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0169 75.4 —
AFFECTED Product Versions Fixed SATCOM VSAT7090 Maritime Satellite Router 20260704 – —
TIMELINE Aug 31 Reserved by CNA Sep 1 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P L N H H H 9.0 .0117 65.2 —
AFFECTED Product Versions Fixed Plesk 18.0.34 – —
TIMELINE Jul 29 Reserved by CNA Sep 1 Published (CNA: hackerone)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N P H H H 8.7 .0115 64.6 —
AFFECTED Product Versions Fixed yast2-auth-client unspecified —
TIMELINE Jul 6 Reserved by CNA Sep 1 Published (CNA: suse)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H N N 5.9 .0084 55.3 —
AFFECTED Product Versions Fixed Employee Self Service Q2 2026 – —
TIMELINE Jul 29 Reserved by CNA Sep 1 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0078 53.4 —
AFFECTED Product Versions Fixed Frontend Admin by DynamiApps unspecified —
TIMELINE Aug 15 Reserved by CNA Sep 1 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0064 48.3 —
AFFECTED Product Versions Fixed cPanel unspecified —
TIMELINE Jul 22 Reserved by CNA Sep 1 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0063 47.7 —
AFFECTED Product Versions Fixed Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits unspecified —
TIMELINE Aug 18 Reserved by CNA Sep 1 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0051 41.6 —
AFFECTED Product Versions Fixed WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode unspecified —
TIMELINE Aug 18 Reserved by CNA Sep 1 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C L L N 7.2 .0047 38.7 —
AFFECTED Product Versions Fixed Welcart e-Commerce unspecified —
TIMELINE Aug 14 Reserved by CNA Sep 1 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N L 5.3 .0046 38.4 —
AFFECTED Product Versions Fixed jackson-databind 2.8.0 – — jackson-databind 3.0.0 – —
TIMELINE Aug 6 Reserved by CNA Sep 1 Published (CNA: HeroDevs)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N A H H H 7.5 .0044 36.8 —
AFFECTED Product Versions Fixed yast2-samba-client unspecified —
TIMELINE Feb 5 Reserved by CNA Sep 1 Published (CNA: suse)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0040 33.6 —
AFFECTED Product Versions Fixed modu680-AS 1.0.0 – — modu660-AS 1.0.0 – — modu612-LC 1.0.0 – — ecos504 1.0.0 – — ecos505 1.0.0 – —
TIMELINE Aug 24 Reserved by CNA Sep 1 Published (CNA: CERTVDE)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0040 32.7 —
AFFECTED Product Versions Fixed Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System unspecified —
TIMELINE Aug 13 Reserved by CNA Sep 1 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L N N 5.3 .0039 32.5 —
AFFECTED Product Versions Fixed Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates unspecified —
TIMELINE Aug 15 Reserved by CNA Sep 1 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N N L N 6.3 .0039 32.0 —
AFFECTED Product Versions Fixed ash_typescript 0.15.0 – — ash_typescript 546a15e1a2d7dbf1df2d5a6ee4404bc3da87852e – —
TIMELINE Aug 31 Reserved by CNA Sep 1 Published (CNA: EEF)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H N N 4.9 .0035 28.1 —
AFFECTED Product Versions Fixed LearnPress – WordPress LMS Plugin for Create and Sell Online Courses unspecified —
TIMELINE Aug 21 Reserved by CNA Sep 1 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H N N 4.9 .0035 28.0 —
AFFECTED Product Versions Fixed Photo Gallery by Ays – Responsive Image Gallery unspecified —
TIMELINE Aug 18 Reserved by CNA Sep 1 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C L L N 6.4 .0033 26.1 —
AFFECTED Product Versions Fixed Live Composer – Free WordPress Website Builder unspecified —
TIMELINE Jul 23 Reserved by CNA Sep 1 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C L L N 6.4 .0033 26.1 —
AFFECTED Product Versions Fixed Live Composer – Free WordPress Website Builder unspecified —
TIMELINE Jul 23 Reserved by CNA Sep 1 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C L L N 6.4 .0033 25.5 —
AFFECTED Product Versions Fixed Blocksy Companion unspecified —
TIMELINE Jul 31 Reserved by CNA Sep 1 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N N 7.8 .0033 25.3 —
AFFECTED Product Versions Fixed Backblaze Client 10.0.0.1029 – —
TIMELINE Aug 14 Reserved by CNA Sep 1 Published (CNA: Bugcrowd)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C L L N 6.4 .0032 24.1 —
AFFECTED Product Versions Fixed WPBakery Page Builder unspecified —
TIMELINE Jul 8 Reserved by CNA Sep 1 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0032 23.8 —
AFFECTED Product Versions Fixed ash_typescript 0.1.0 – — ash_typescript 1a3d4c343430c8e4784acfcd33122a807fafa086 – —
TIMELINE Aug 30 Reserved by CNA Sep 1 Published (CNA: EEF)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N N N H 8.2 .0032 23.8 —
AFFECTED Product Versions Fixed ash_typescript 0.11.0 – — ash_typescript 7c3d30896f2f9a54edea17e3787549776b1b288d – —
TIMELINE Aug 30 Reserved by CNA Sep 1 Published (CNA: EEF)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-77950 | 6.3 | 23.8 | ash-project | ash_typescript | CWE-209 | RPC error handler fails open in AshTypescript, disclosing unredacted errors |
| CVE-2026-82733 | 6.3 | 23.8 | ash-project | ash_typescript | CWE-209 | Route handler return value echoed into AshTypescript error response |
| CVE-2026-82731 | 2.3 | 20.9 | ash-project | ash_typescript | CWE-601 | Unescaped path parameters in AshTypescript generated TypeScript client allow … |
| CVE-2026-77189 | 6.5 | 20.8 | smub | Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) | CWE-89 | Charitable <= 1.8.12.1 - Authenticated (Contributor+) SQL Injection via 'orde… |
| CVE-2026-82730 | 8.2 | 20.6 | ash-project | ash_typescript | CWE-863 | Authorization-redacted field values disclosed through AshTypescript result no… |
| CVE-2026-17589 | 4.9 | 20.0 | levelfourstorefront | Shopping Cart & eCommerce Store | CWE-89 | Shopping Cart & eCommerce Store <= 5.9.2 - Authenticated (Administrator+) SQL… |
| CVE-2026-18752 | 6.5 | 16.1 | lukeseager | Persistent Login | CWE-89 | Persistent Login <= 3.1.0 - Authenticated (Subscriber+) SQL Injection via 'wp… |
| CVE-2026-19573 | 7.2 | 15.1 | worschtebrot | Affiliate Super Assistent | CWE-79 | Affiliate Super Assistent <= 1.10.2 - Unauthenticated Stored Cross-Site Scrip… |
| CVE-2026-19796 | 7.2 | 15.1 | webilia | Listdom: AI-powered Business Directory with Classifieds Ads Listings | CWE-79 | Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 5.8.1… |
| CVE-2026-13203 | 6.4 | 15.1 | livecomposer | Live Composer – Free WordPress Website Builder | CWE-79 | Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scri… |
| CVE-2026-83743 | 2.1 | 12.4 | invoiceninja | Invoice Ninja | CWE-285 | invoiceninja Invoice Ninja Vendor Portal Profile Update profile authorization |
| CVE-2026-75964 | 6.1 | 12.3 | cozmoslabs | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor | CWE-79 | User Profile Builder <= 4.0.0 - Unauthenticated Stored Cross-Site Scripting v… |
| CVE-2026-75980 | 6.4 | 10.5 | wpdevteam | BetterDocs – AI Documentation, Knowledge Base, MCP Server, Docs, Wikis, FAQ & Chatbot | CWE-79 | BetterDocs <= 4.8.1 - Authenticated (Contributor+) Stored Cross-Site Scriptin… |
| CVE-2026-83744 | 2.1 | 10.2 | invoiceninja | Invoice Ninja | CWE-918 | invoiceninja Invoice Ninja invoices Endpoint Purify.php isHostSafe server-sid… |
| CVE-2026-12747 | 6.4 | 10.0 | shabti | Frontend Admin by DynamiApps | CWE-79 | Frontend Admin by DynamiApps <= 3.29.11 - Authenticated (Contributor+) Stored… |
| CVE-2026-16787 | 6.4 | 9.1 | livecomposer | Live Composer – Free WordPress Website Builder | CWE-79 | Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scri… |
| CVE-2026-75965 | 6.4 | 9.1 | cozmoslabs | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor | CWE-79 | User Profile Builder <= 4.0.0 - Authenticated (Contributor+) Stored Cross-Sit… |
| CVE-2026-13611 | 5.3 | 9.0 | Unknown | KiviCare | CWE-200 | KiviCare – Clinic & Patient Management System (EHR) < 4.5.5 - Unauthenticated… |
| CVE-2026-48932 | 3.7 | 5.6 | nodejs | node | CWE-444 | A flaw in Node.js HTTP client can cause a request desynchronization for Node.… |
| CVE-2026-78363 | 4.8 | 4.9 | Unknown | MW WP Form | CWE-74 | MW WP Form < 5.1.5 - Unauthenticated Arbitrary Shortcode Execution via Comple… |
| CVE-2026-82735 | 5.9 | 3.5 | ash-project | ash | CWE-400 | Match regex runs on over-length input in Ash.Type.String, enabling regex deni… |
| CVE-2026-82737 | 5.9 | 3.5 | ash-project | ash | CWE-190 | Ash.Vector wraps the 16-bit dimension header for vectors over 65,535 elements… |
| CVE-2026-82738 | 5.9 | 3.5 | ash-project | ash | CWE-20 | Ash.Type.UUIDv7 accepts non-v7 UUIDs that then fail to load, causing persiste… |
| CVE-2026-82736 | 2.1 | 3.5 | ash-project | ash | CWE-180 | Ash.Type.CiString validates length and match constraints before case folding,… |
| CVE-2026-82734 | 2.1 | 3.1 | ash-project | ash | CWE-1284 | Non-finite Infinity/NaN decimal values bypass bounds constraints in Ash.Type.… |
| CVE-2026-82741 | 2.1 | 3.1 | ash-project | ash | CWE-1287 | Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling ta… |
| CVE-2026-82744 | 2.1 | 3.1 | ash-project | ash | CWE-636 | Ash.Reactor change step fails open, skipping a change when its where guard ra… |
| CVE-2026-82742 | 5.9 | 2.6 | ash-project | ash | CWE-400 | Ash.Filter.Runtime materializes a combinatorial cross-product over to-many re… |
| CVE-2026-82739 | 2.1 | 2.6 | ash-project | ash | CWE-209 | Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the… |
| CVE-2026-82740 | 2.1 | 2.6 | ash-project | ash | CWE-20 | Ash.Type ignores outer array constraints on nested {:array, {:array, type}} i… |
| CVE-2026-82743 | 2.1 | 2.6 | ash-project | ash | CWE-400 | Ash.Actions.Read.AsyncLimiter busy-spins a scheduler while awaiting slow asyn… |
| CVE-2026-18743 | 2.5 | 2.5 | rpm-software-management | popt | CWE-131 | Popt-devel: popt-static: short realloc in poptconfigfiletostring |
| CVE-2026-82745 | 5.9 | 2.3 | ash-project | ash | CWE-284 | ETS and Mnesia data layers overwrite an existing record on create instead of … |
| CVE-2026-82746 | 5.9 | 2.0 | ash-project | ash | CWE-862 | Ash.update_many/4 atomic path skips resource policy authorization, allowing u… |
| CVE-2026-82747 | 5.9 | 2.0 | ash-project | ash | CWE-863 | Ash.Policy.Authorizer returns records denied by a runtime read policy to any … |
| CVE-2026-82749 | 5.9 | 2.0 | ash-project | ash | CWE-863 | Ash relationship parent(...) filter degrades to an IS NULL match when the par… |
| CVE-2026-82748 | 2.1 | 2.0 | ash-project | ash | CWE-863 | Ash.Actions.Aggregate authorizes an aggregate under one action but computes i… |
| CVE-2026-74916 | 6.5 | 1.2 | Unknown | WP Fastest Cache | CWE-349 | WP Fastest Cache 0.8.7.7 - 1.5.0 - Unauthenticated Cache Poisoning via Unkeye… |
| CVE-2026-76657 | 10.0 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | CWE-287 | Authentication Bypass in HPE Networking Fabric Composer API allows Administra… |
| CVE-2026-76658 | 10.0 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | CWE-287 | Unauthenticated Remote Code Execution in HPE Networking Fabric Composer SSH D… |
| CVE-2026-84147 | 10.0 | — | Manacle Technologies | Multi-tenant ERP System | CWE-434 | Remote Code Execution Vulnerability in Manacle Technologies ERP System |
| CVE-2026-18210 | 9.8 | — | TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company | Products's Store | CWE-89 | SQL Injection in TRtek Technological Products's Store |
| CVE-2026-18550 | 9.8 | — | scriptsbundle | Nokri – Job Board WordPress Theme | CWE-269 | Nokri - Job Board WordPress Theme <= 1.6.6 - Unauthenticated Privilege Escala… |
| CVE-2026-18765 | 9.8 | — | Teracity Software Technologies Inc. | E-OSB | CWE-89 | SQL Injection in Teracity Sotware's Teracity E-OSB Platform |
| CVE-2026-18808 | 9.8 | — | Klemsan Electrical Electronics Inc. | KIO (Klemsan Internet Objects) | CWE-94 | Unauthenticated Remote Code Execution via Code Injection in Klemsan's KIO |
| CVE-2026-73749 | 9.8 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution… |
| CVE-2026-84372 | 9.8 | — | predis | predis | CWE-93 | Predis: Redis command injection and denial of service via CRLF smuggling in p… |
| CVE-2026-19766 | 9.6 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Authentication Bypass leads to Administrative control of adjacent network hos… |
| CVE-2026-84119 | 9.6 | — | Mozilla | Firefox | CWE-416 | Sandbox escape due to use-after-free in the DOM: Navigation component |
| CVE-2026-84121 | 9.6 | — | Mozilla | Firefox | CWE-416 | Sandbox escape due to use-after-free in the DOM: Security component |
| CVE-2026-84333 | 9.6 | — | Chrome | CWE-416 | Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 … | |
| CVE-2026-4813 | 9.4 | — | Lutece | Lutece Core | CWE-94 | Code injection in the Lutece Core |
| CVE-2026-84200 | 9.4 | — | kyverno | kyverno | CWE-284 | Kyverno before v1.13.0 Policy Bypass via Multiple Exceptions |
| CVE-2023-54356 | 9.3 | — | kyverno | kyverno | CWE-326 | Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suites |
| CVE-2023-54391 | 9.3 | — | Proxmox Server Solutions GmbH | Proxmox Virtual Environment (VE) | CWE-304 | Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter |
| CVE-2026-78012 | 9.3 | — | Pyramid Solutions | EtherNet/IP Adapter DLL Kit (EIPA) | CWE-121 | Stack-based Buffer Overflow in Pyramid Solutions NetStaX EtherNet/IP Stack |
| CVE-2026-84479 | 9.3 | — | WWBN | AVideo | CWE-290 | WWBN AVideo Authentication Bypass via User-Agent Header |
| CVE-2026-84480 | 9.3 | — | WWBN | AVideo | CWE-613 | WWBN AVideo Password Recovery Token Expiration Bypass |
| CVE-2026-9621 | 9.2 | — | Rockwell Automation | RSLinx Classic® | CWE-190 | RSLinx Classic® - Multiple Vulnerabilities |
| CVE-2026-84148 | 9.2 | — | Manacle Technologies | Multi-tenant ERP System | CWE-639 | Insecure Direct Object Reference Vulnerability in Manacle Technologies ERP Sy… |
| CVE-2026-84149 | 9.2 | — | Manacle Technologies | Multi-tenant ERP System | CWE-527 | Information Disclosure Vulnerability in Manacle Technologies ERP System |
| CVE-2026-84189 | 9.2 | — | librenms | librenms | CWE-79 | LibreNMS before 26.7.0 Stored XSS via Oxidized API |
| CVE-2026-18931 | 9.1 | — | TMT Machine Industry and Trade Ltd. Co. | Talassoft Industrial Management Software | CWE-798 | Hardcoded Credentials in TMT Machine's Talassoft Industrial Management Software |
| CVE-2026-51743 | 9.1 | — | n/a | n/a | CWE-284 | Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5… |
| CVE-2026-73700 | 9.0 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in HPE Networki… |
| CVE-2026-73701 | 9.0 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Unauthenticated Remote Code Execution in HPE Networking Fabric Composer |
| CVE-2026-75604 | 9.0 | — | vercel | next.js | CWE-22 | Next.js: Unauthenticated Remote Code Execution on windows-hosted servers |
| CVE-2026-79687 | 9.0 | — | Dell | PowerStore 500T | CWE-306 | Dell PowerStore SDNAS contains a Missing Authentication for Critical Function… |
| CVE-2026-84324 | 9.0 | — | Chrome | CWE-416 | Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a rem… | |
| CVE-2026-10195 | 8.8 | — | fs-code | FS Poster - WordPress Social media Auto Poster & Scheduler [Facebook, Instagram, Twitter, Pinterest] | CWE-77 | FS Poster <= 8.0.1 - Authenticated (Subscriber+) Remote Code Execution via FF… |
| CVE-2026-18630 | 8.8 | — | TMT Machine Industry and Trade Ltd. Co. | Talassoft Industrial Management Software | CWE-89 | SQL Injection in TMT Machine's Talassoft Industrial Management Software |
| CVE-2026-58566 | 8.8 | — | Dell | PowerStore 500T | CWE-863 | Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged a… |
| CVE-2026-58567 | 8.8 | — | Dell | PowerStore 500T | CWE-78 | Dell PowerStore contains an OS Command Injection vulnerability. An authentica… |
| CVE-2026-58569 | 8.8 | — | Dell | PowerStore 500T | CWE-829 | Dell PowerStore contains an Inclusion of Functionality from Untrusted Control… |
| CVE-2026-58571 | 8.8 | — | Dell | PowerStore 500T | CWE-78 | Dell PowerStore contains an OS Command Injection vulnerability. An authentica… |
| CVE-2026-58572 | 8.8 | — | Dell | PowerStore 500T | CWE-94 | Dell PowerStore contains a Code Injection vulnerability. An authenticated use… |
| CVE-2026-58575 | 8.8 | — | Dell | PowerStore 500T | CWE-290 | Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. … |
| CVE-2026-72649 | 8.8 | — | Elastic | Elasticsearch | CWE-502 | Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Exe… |
| CVE-2026-73702 | 8.8 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Authenticated Privilege Escalation Vulnerability in the API of HPE Networking… |
| CVE-2026-73703 | 8.8 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Unauthenticated Stored Cross-Site Scripting (XSS) Vulnerability in HPE Networ… |
| CVE-2026-73704 | 8.8 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Authenticated Command Injection Leading to Administrative Access in HPE Netwo… |
| CVE-2026-73705 | 8.8 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Authenticated Arbitrary File Write leads to Remote Code Execution in HPE Netw… |
| CVE-2026-73750 | 8.8 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Authenticated Buffer Overflow Vulnerabilities in AOS-CX API Endpoint Leads to… |
| CVE-2026-73751 | 8.8 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Authenticated Remote Command Injection in AOS-CX Web-based Management Interface |
| CVE-2026-73752 | 8.8 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Unauthenticated Arbitrary File Write Vulnerability Leads to Remote Code Execu… |
| CVE-2026-73753 | 8.8 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Authenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line… |
| CVE-2026-73782 | 8.8 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Unauthenticated Format String Vulnerability leads to Remote Code Execution in… |
| CVE-2026-76111 | 8.8 | — | Dell | PowerStore 500T | CWE-863 | Dell PowerStore contains an Incorrect Authorization vulnerability. An authent… |
| CVE-2026-79682 | 8.8 | — | Dell | PowerStore 500T | CWE-77 | Dell PowerStore contains a Command Injection vulnerability. An authenticated … |
| CVE-2026-79683 | 8.8 | — | Dell | PowerStore 500T | CWE-693 | Dell PowerStore contains a Protection Mechanism Failure vulnerability. An aut… |
| CVE-2026-79684 | 8.8 | — | Dell | PowerStore 500T | CWE-693 | Dell PowerStore contains a Protection Mechanism Failure vulnerability. An aut… |
| CVE-2026-79686 | 8.8 | — | Dell | PowerStore 500T | CWE-693 | Dell PowerStore contains a Protection Mechanism Failure vulnerability. An aut… |
| CVE-2026-84117 | 8.8 | — | Mozilla | Firefox | CWE-284 | Privilege escalation in Firefox for Android |
| CVE-2026-84123 | 8.8 | — | Mozilla | Firefox | CWE-416 | Privilege escalation due to use-after-free in the Graphics: WebGPU component |
| CVE-2026-84128 | 8.8 | — | Mozilla | Firefox | CWE-284 | Privilege escalation in the WebDriver BiDi component |
| CVE-2026-84131 | 8.8 | — | Mozilla | Firefox | CWE-763 | Privilege escalation due to invalid pointer in the Graphics component |
| CVE-2026-84187 | 8.8 | — | WWBN | AVideo | CWE-284 | AVideo on_publish.php Missing Authentication Check via RTMP Callback |
| CVE-2026-84268 | 8.8 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-122 | Gvfs: sftp: heap-based buffer overflow in read_reply() |
| CVE-2026-84347 | 8.8 | — | Chrome | CWE-416 | Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a re… | |
| CVE-2026-84350 | 8.8 | — | Chrome | CWE-416 | Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a … | |
| CVE-2024-7952 | 8.7 | — | Rockwell Automation | DataEdgePlatform DataMosaix™ Private Cloud | CWE-798 | DataEdgePlatform DataMosaix™ Private Cloud |
| CVE-2024-7953 | 8.7 | — | Rockwell Automation | DataEdgePlatform DataMosaix™ Private Cloud | CWE-284 | DataEdgePlatform DataMosaix™ Private Cloud |
| CVE-2026-9622 | 8.7 | — | Rockwell Automation | RSLinx Classic® | CWE-191 | RSLinx Classic® - Multiple Vulnerabilities |
| CVE-2026-9624 | 8.7 | — | Rockwell Automation | RSLinx Classic® | CWE-191 | RSLinx Classic® - Multiple Vulnerabilities |
| CVE-2026-9625 | 8.7 | — | Rockwell Automation | RSLinx Classic® | CWE-120 | RSLinx Classic® - Multiple Vulnerabilities |
| CVE-2026-9637 | 8.7 | — | Rockwell Automation | CompactLogix® 5380 / ControlLogix® 5580 | CWE-119 | CompactLogix® 5380 / ControlLogix® 5580 - Multiple Vulnerabilities |
| CVE-2026-19472 | 8.7 | — | Rockwell Automation | ArmorStart® LT | CWE-770 | Rockwell Automation ArmorStart® LT Denial Of Service |
| CVE-2026-69664 | 8.7 | — | Erlang | OTP | CWE-772 | httpd parks a request worker indefinitely on a malformed chunk size sent afte… |
| CVE-2026-70399 | 8.7 | — | Erlang | OTP | CWE-770 | httpd does not enforce the documented default max_clients connection limit |
| CVE-2026-71380 | 8.7 | — | Erlang | OTP | CWE-772 | httpd applies no timeout while receiving a request body, parking a worker on … |
| CVE-2026-71981 | 8.7 | — | cypht-org | cypht | CWE-502 | Cypht < 2.12.2 PHP Object Injection RCE via back_query Parameter |
| CVE-2026-74835 | 8.7 | — | Erlang | OTP | CWE-770 | inets,httpd: Memory Exhaustion via Unenforced max_body_size During Chunked Bo… |
| CVE-2026-83605 | 8.7 | — | xmldom | xmldom | CWE-91 | xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed |
| CVE-2026-83606 | 8.7 | — | xmldom | xmldom | CWE-400 | xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated process… |
| CVE-2026-83607 | 8.7 | — | xmldom | xmldom | CWE-91 | xmldom: Element name injection via createElement() bypasses requireWellFormed |
| CVE-2026-83608 | 8.7 | — | xmldom | xmldom | CWE-91 | xmldom: DocType `name` Injection Bypasses requireWellFormed |
| CVE-2026-83609 | 8.7 | — | xmldom | xmldom | CWE-91 | xmldom: Creation-time XML Name/QName validation is bypassable via an embedded… |
| CVE-2026-83612 | 8.7 | — | xmldom | xmldom | CWE-178 | xmldom: HTML raw-text closing-tag case mismatch causes output amplification |
| CVE-2026-83613 | 8.7 | — | xmldom | xmldom | CWE-407 | xmldom: Quadratic-time attribute deduplication |
| CVE-2026-83614 | 8.7 | — | xmldom | xmldom | CWE-400 | xmldom: Quadratic-time parsing via the malformed-input recovery path — `parse… |
| CVE-2026-83615 | 8.7 | — | xmldom | xmldom | CWE-770 | xmldom: Quadratic-memory consumption |
| CVE-2026-83616 | 8.7 | — | xmldom | xmldom | CWE-91 | xmldom: Processing Instruction Target Injection Bypasses requireWellFormed |
| CVE-2026-83617 | 8.7 | — | xmldom | xmldom | CWE-91 | xmldom: requireWellFormed element/attribute name validation is bypassable via… |
| CVE-2026-83618 | 8.7 | — | xmldom | xmldom | CWE-91 | xmldom: requireWellFormed DocType publicId/systemId validation is bypassable … |
| CVE-2026-83619 | 8.7 | — | xmldom | xmldom | CWE-400 | xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0… |
| CVE-2026-84165 | 8.7 | — | OpenNebula Systems | OpenNebula | CWE-284 | Lack of authorisation in OpenNebula by OpenNebula Systems |
| CVE-2026-84190 | 8.7 | — | librenms | librenms | CWE-77 | LibreNMS before 26.5.0 Remote Code Execution via AboutController |
| CVE-2026-84202 | 8.7 | — | modelscope | modelscope | CWE-502 | ModelScope through 1.40.0 Unsafe YAML Deserialization in Model Config Loading |
| CVE-2026-84208 | 8.7 | — | WWBN | AVideo | CWE-89 | AVideo User_Location Plugin Unauthenticated SQL Injection |
| CVE-2026-84235 | 8.7 | — | Rockwell Automation | 1756-ENBT Module | CWE-400 | Rockwell Automation 1756-ENBT Denial of Service Vulnerability |
| CVE-2026-84304 | 8.7 | — | grpc | grpc-go | CWE-400 | gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation |
| CVE-2026-84476 | 8.7 | — | WWBN | AVideo | CWE-290 | WWBN AVideo Authentication Bypass via X-Real-IP Header |
| CVE-2026-84482 | 8.7 | — | WWBN | AVideo | CWE-346 | WWBN AVideo Cross-Site Request Forgery via get_domain() validation |
| CVE-2025-12768 | 8.6 | — | Rockwell Automation | FactoryTalk® Historian Machine Edition | CWE-787 | FactoryTalk® Historian Machine Edition - Out-of-Bounds Write Vulnerability |
| CVE-2026-73706 | 8.6 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Authentication Bypass in the API of HPE Networking Fabric Composer allows Dat… |
| CVE-2026-84194 | 8.6 | — | librenms | librenms | CWE-78 | LibreNMS 23.10.0 before 26.4.0 OS Command Injection via Hostname |
| CVE-2026-84203 | 8.6 | — | usememos | memos | CWE-613 | Memos 0.26.0 through 0.30.0 Insufficient Session Expiration on Password Change |
| CVE-2026-16675 | 8.5 | — | Rockwell Automation | FactoryTalk® Activation Manager | CWE-307 | Rockwell Automation FactoryTalk® Activation Manager - Privilege Escalation |
| CVE-2026-45221 | 8.5 | — | EASYBYTE Software | Konga | CWE-427 | Konga < 2.1.0 Privilege Escalation via Hardcoded OpenSSL Path |
| CVE-2026-73707 | 8.5 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Authenticated Privilege Escalation via Broken Access Control in HPE Networkin… |
| CVE-2026-83551 | 8.5 | — | AWS | sagemaker-python-sdk | CWE-312 | Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK @step/@r… |
| CVE-2026-73781 | 8.4 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in AOS-CX Web-B… |
| CVE-2026-63137 | 8.3 | — | Elastic | Kibana | CWE-863 | Incorrect Authorization in Kibana Leading to Privilege Escalation |
| CVE-2026-66357 | 8.3 | — | Erlang | OTP | CWE-444 | inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation |
| CVE-2026-73276 | 8.3 | — | Erlang | OTP | CWE-444 | inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropp… |
| CVE-2026-73708 | 8.3 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Fault in Business Logic allows Authenticated Sensitive Information Disclosure… |
| CVE-2026-73709 | 8.3 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Unauthenticated Remote Code Execution during HPE Networking Fabric Composer I… |
| CVE-2026-73780 | 8.3 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Lack of Cross-Site Request Forgery (CSRF) Protections for Certificate-Authent… |
| CVE-2026-73812 | 8.3 | — | Erlang | OTP | CWE-444 | inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length |
| CVE-2026-84195 | 8.3 | — | kyverno | kyverno | CWE-200 | Kyverno before 1.16.4 Credential Leak via apiCall |
| CVE-2026-84196 | 8.3 | — | kyverno | kyverno | CWE-918 | Kyverno before 1.18.0 Server-Side Request Forgery via apiCall |
| CVE-2026-84335 | 8.3 | — | Chrome | CWE-863 | Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 a… | |
| CVE-2026-84351 | 8.3 | — | Chrome | CWE-121 | Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 … | |
| CVE-2024-10085 | 8.2 | — | Schneider Electric | EcoStruxure™ OPC UA Server Expert | CWE-770 | CWE-770: Allocation of Resources Without Limits or Throttling vulnerability e… |
| CVE-2026-18730 | 8.2 | — | GitHub | Enterprise Server | CWE-918 | Server-side request forgery vulnerability in GitHub Enterprise Server Manage … |
| CVE-2026-55951 | 8.2 | — | Erlang | OTP | CWE-770 | httpc memory exhaustion via unbounded response header accumulation |
| CVE-2026-66835 | 8.2 | — | Erlang | OTP | CWE-50 | httpd mod_auth directory protection bypassed by a doubled slash in the reques… |
| CVE-2026-73270 | 8.2 | — | Erlang | OTP | CWE-178 | httpd mod_auth directory protection bypassed by request path casing on case-i… |
| CVE-2026-73710 | 8.2 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Unauthenticated Denial of Service Vulnerabilities in API Endpoint of HPE Netw… |
| CVE-2026-73779 | 8.2 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Authentication Bypass Vulnerabilities Leading to Information Disclosure, Unau… |
| CVE-2026-75538 | 8.2 | — | Erlang | OTP | CWE-122 | A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receiv… |
| CVE-2026-84370 | 8.2 | — | svg | svgo | CWE-79 | SVGO: removeScripts allows executable links through namespace and control-cha… |
| CVE-2026-19513 | 8.1 | — | Gravity Forms | Gravity Forms | CWE-434 | Gravity Forms <= 3.0.2 - Unauthenticated Arbitrary File Upload via State/Chun… |
| CVE-2026-73711 | 8.1 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Unauthenticated Privilege Escalation allows Administrative Access in HPE Netw… |
| CVE-2026-73712 | 8.1 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Unauthenticated Remote Code Execution in HPE Networking Fabric Composer API |
| CVE-2026-73777 | 8.1 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Authorization Bypass Vulnerabilities Leading to Privilege Escalation in AOS-C… |
| CVE-2026-73778 | 8.1 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Credential Manager Vulnerability Allows Unauthorized Administrative Access |
| CVE-2026-84218 | 8.1 | — | Red Hat | Red Hat AMQ Broker 7 | CWE-184 | Org.jolokia/jolokia-core: incomplete jndi denylist in jolokia jsr-160 proxy (… |
| CVE-2026-84334 | 8.1 | — | Chrome | CWE-863 | Incorrect authorization in Chromoting in Google Chrome on on Windows prior to… | |
| CVE-2026-73776 | 7.9 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Authenticated Signature Verification Bypass Leading to Arbitrary Code Executi… |
| CVE-2026-61750 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61751 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61752 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61753 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-22 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61754 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61755 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61756 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61757 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61758 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61759 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61760 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61761 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61762 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61763 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61764 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61765 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61766 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61767 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61768 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61769 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61770 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61771 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61772 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61773 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61774 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61775 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61776 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61777 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61778 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-61779 | 7.8 | — | NVIDIA | Megatron Bridge | CWE-502 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause… |
| CVE-2026-73713 | 7.8 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Local Privilege Escalation Vulnerabilities in HPE Networking Fabric Composer |
| CVE-2026-83549 | 7.8 | — | SonicWall | SMA1000 | CWE-78 | Post-authentication Improper Neutralization of Special Elements used in an OS… |
| CVE-2026-19118 | 7.7 | — | GitHub | Enterprise Server | CWE-367 | Race condition vulnerability was identified in GitHub Enterprise Server that … |
| CVE-2026-73775 | 7.7 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Authenticated Sensitive Information Disclosure Vulnerabilities in AOS-CX |
| CVE-2026-76851 | 7.7 | — | GitHub | Enterprise Server | CWE-918 | Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed… |
| CVE-2026-84361 | 7.7 | — | composer | composer | CWE-78 | Composer: Perforce source URL permits P4PORT `rsh:` command execution |
| CVE-2026-73714 | 7.6 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Authenticated Sensitive Information Disclosure in HPE Networking Fabric Compo… |
| CVE-2026-73774 | 7.6 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Unauthenticated Buffer Overflow Vulnerability leads to Sensitive Information … |
| CVE-2026-18771 | 7.5 | — | TMT Machine Industry and Trade Ltd. Co. | Talassoft Industrial Management Software | CWE-306 | Missing Authentication for Critical Function in TMT Machine's Talassoft Indus… |
| CVE-2026-49329 | 7.5 | — | Red Hat | Red Hat OpenShift Container Platform 4 | CWE-407 | Openshift/oauth-server: openshift/oauth-server: quadratic-time dos via accept… |
| CVE-2026-51766 | 7.5 | — | n/a | n/a | CWE-284 | Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.… |
| CVE-2026-52130 | 7.5 | — | n/a | n/a | CWE-674 | llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/… |
| CVE-2026-73715 | 7.5 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Unauthenticated Denial-of-Service (DoS) Vulnerability in the API of HPE Netwo… |
| CVE-2026-73716 | 7.5 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Unauthenticated Remote Code Execution in HPE Networking Fabric Composer |
| CVE-2026-73717 | 7.5 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Unauthenticated Command Injection Vulnerability in HPE Networking Fabric Comp… |
| CVE-2026-73771 | 7.5 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Improper Authentication Handling in AOS-CX Management Interface and API |
| CVE-2026-73773 | 7.5 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Unauthenticated Denial-of-Service (DoS) Vulnerability in AOS-CX |
| CVE-2026-84145 | 7.5 | — | Mozilla | Firefox | CWE-119 | Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thu… |
| CVE-2026-84374 | 7.5 | — | SpartnerNL | Laravel-Excel | CWE-22 | Laravel Excel writes exports outside the configured filesystem disk when give… |
| CVE-2026-84375 | 7.5 | — | nodeca | js-yaml | CWE-400 | js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources |
| CVE-2026-73718 | 7.4 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Unauthenticated Information Disclosure in Web Interface allows Sensitive Data… |
| CVE-2026-84366 | 7.4 | — | scrapy | scrapy | CWE-319 | Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by def… |
| CVE-2026-13336 | 7.3 | — | Schneider Electric | NetBotz 5 - 750/755 | CWE-78 | CWE-78: Improper Neutralization of Special Elements used in an OS Command ('O… |
| CVE-2026-73768 | 7.3 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Local Privilege Escalation in AOS-CX Command Line Interface |
| CVE-2026-73770 | 7.3 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Authenticated Arbitrary File Write Vulnerability Leading to Remote Code Execu… |
| CVE-2026-78592 | 7.3 | — | Elastic | Kibana | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading… |
| CVE-2024-14047 | 7.2 | — | Elastic | Elastic Security | CWE-59 | Improper Link Resolution Before File Access ('Link Following') in Winlogbeat … |
| CVE-2026-73719 | 7.2 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Authenticated Arbitrary File Write Vulnerability leads to Remote Code Executi… |
| CVE-2026-73720 | 7.2 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Authenticated Insecure File Handling allows Remote Code Execution in HPE Netw… |
| CVE-2026-73721 | 7.2 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Authenticated SQL Injection Vulnerabilities in HPE Networking Fabric Composer |
| CVE-2026-73722 | 7.2 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Authenticated Command Injection Vulnerabilities in HPE Networking Fabric Comp… |
| CVE-2026-73765 | 7.2 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Authenticated Path Traversal Vulnerabilities Lead to Remote Code Execution in… |
| CVE-2026-73766 | 7.2 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Authenticated Command Injection Vulnerabilities in the API Endpoint of AOS-CX |
| CVE-2026-73767 | 7.2 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Authenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line… |
| CVE-2026-83595 | 7.2 | — | WWBN | AVideo | CWE-352 | AVideo Cross-Site Request Forgery via plugin/API/set.json.php |
| CVE-2026-18780 | 7.1 | — | TMT Machine Industry and Trade Ltd. Co. | Talassoft Industrial Management Software | CWE-352 | CSRF in TMT Machine's Talassoft Industrial Management Software |
| CVE-2026-73723 | 7.1 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Authenticated Privilege Escalation Leading to Unauthorized State Changes in H… |
| CVE-2026-73724 | 7.1 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Authenticated Privilege Escalation via Broken Access Control in HPE Networkin… |
| CVE-2026-73763 | 7.1 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Unauthenticated Remote Command Execution in Management Component |
| CVE-2026-73764 | 7.1 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Authentication Bypass Vulnerabilities Leading to Unauthorized Modification an… |
| CVE-2026-84192 | 7.1 | — | librenms | librenms | CWE-79 | LibreNMS before 26.3.1 Stored XSS via SNMP/Syslog Data |
| CVE-2026-84204 | 7.1 | — | growilabs | growi | CWE-862 | GROWI through 8.0.2 Missing Authorization on apiv3 Attachment Retrieval |
| CVE-2026-84205 | 7.1 | — | growilabs | growi | CWE-639 | GROWI through 8.0.2 Authorization Bypass Through User-Controlled Key on apiv3… |
| CVE-2026-9633 | 7.0 | — | Rockwell Automation | Redundancy Module Configuration Tool | CWE-276 | Redundancy Module Configuration Tool - Multiple Vulnerabilities |
| CVE-2026-9634 | 7.0 | — | Rockwell Automation | Redundancy Module Configuration Tool | CWE-276 | Redundancy Module Configuration Tool - Multiple Vulnerabilities |
| CVE-2026-12663 | 7.0 | — | Rockwell Automation | ControlFLASH ® | CWE-306 | ControlFLASH ® – Improper Access Control |
| CVE-2026-73725 | 7.0 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Local Privilege Escalation leads to Arbitrary Code Execution in HPE Networkin… |
| CVE-2026-84233 | 7.0 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-78 | Rpm: command execution via macro expansion in `rpmuncompress -x` for crafted … |
| CVE-2025-15613 | 6.9 | — | kyverno | kyverno | CWE-918 | Kyverno before v1.13.4 SSRF via Service Call |
| CVE-2026-8712 | 6.9 | — | OHF-Voice | wyoming | CWE-918 | Wyoming < 1.10.2 SSRF via uri Query Parameter |
| CVE-2026-13348 | 6.9 | — | Schneider Electric | PowerChute™ Serial Shutdown | CWE-307 | CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerabil… |
| CVE-2026-19471 | 6.9 | — | Rockwell Automation | ArmorStart® LT | CWE-79 | Rockwell Automation ArmorStart® LT Stored Cross-site scripting |
| CVE-2026-59696 | 6.9 | — | Erlang | OTP | CWE-1284 | uri_string does not bound the port component of a URI before integer conversion |
| CVE-2026-83611 | 6.9 | — | xmldom | xmldom | CWE-1286 | xmldom: Parser silently accepts a not-well-formed end tag whose name is follo… |
| CVE-2026-84199 | 6.9 | — | kyverno | kyverno | CWE-918 | Kyverno before 1.16.2 SSRF via APICall Feature |
| CVE-2026-84201 | 6.9 | — | argneshu | appium-mcp-server | CWE-22 | appium-mcp-server through 0.1.61 Path Traversal in write_file and write_files… |
| CVE-2026-84309 | 6.9 | — | py-pdf | pypdf | CWE-835 | pypdf: Possible infinite loop for TreeObject.insert_child |
| CVE-2026-84478 | 6.9 | — | WWBN | AVideo | CWE-73 | WWBN AVideo Unauthenticated Arbitrary Log File Deletion |
| CVE-2026-84481 | 6.9 | — | WWBN | AVideo | CWE-200 | WWBN AVideo through 30.0 Information Disclosure via MobileManager |
| CVE-2026-84483 | 6.9 | — | WWBN | AVideo | CWE-321 | WWBN AVideo Unauthenticated Password Hash Oracle via encryptPass.json.php |
| CVE-2026-73726 | 6.8 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Authentication Bypass in HPE Networking Fabric Composer allows Unauthorized A… |
| CVE-2026-73762 | 6.6 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Authorization Bypass in the API Endpoint of AOS-CX Leads to Unauthorized Access |
| CVE-2026-11873 | 6.5 | — | Red Hat | Red Hat Certificate System 9 | CWE-209 | Pki-core: dogtag-pki: empty request to dogtag /ca/rest/certrequests causes ht… |
| CVE-2026-33465 | 6.5 | — | Elastic | Kibana | CWE-770 | Allocation of Resources Without Limits or Throttling in Kibana Leading to Den… |
| CVE-2026-63138 | 6.5 | — | Elastic | Kibana | CWE-943 | Improper Neutralization of Special Elements in Data Query Logic in Kibana Lea… |
| CVE-2026-72628 | 6.5 | — | Elastic | Kibana | CWE-409 | Improper Handling of Highly Compressed Data in Kibana Leading to Denial of Se… |
| CVE-2026-72644 | 6.5 | — | Elastic | Kibana | CWE-248 | Uncaught Exception in Kibana Leading to Denial of Service |
| CVE-2026-72652 | 6.5 | — | Elastic | Kibana | CWE-770 | Allocation of Resources Without Limits or Throttling in Kibana Leading to Den… |
| CVE-2026-72654 | 6.5 | — | Elastic | Kibana | CWE-250 | Execution with Unnecessary Privileges in Kibana Leading to Information Disclo… |
| CVE-2026-72682 | 6.5 | — | Elastic | Kibana | CWE-770 | Allocation of Resources Without Limits or Throttling in Kibana Leading to Den… |
| CVE-2026-73727 | 6.5 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Authenticated Sensitive Information Disclosure in HPE Networking Fabric Compo… |
| CVE-2026-73728 | 6.5 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Authenticated Denial of Service Vulnerabilities in HPE Networking Fabric Comp… |
| CVE-2026-73729 | 6.5 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer |
| CVE-2026-73730 | 6.5 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Authenticated Privilege Escalation via Broken Access Control in HPE Networkin… |
| CVE-2026-73758 | 6.5 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Authenticated Privilege Escalation Vulnerability via Broken Access Control in… |
| CVE-2026-73759 | 6.5 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Unauthenticated Denial-of-Service Vulnerabilities in AOS-CX |
| CVE-2026-73760 | 6.5 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Authenticated Path Traversal Vulnerability Leads to Remote Unauthorized Acces… |
| CVE-2026-73761 | 6.5 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Unauthenticated Out-of-Bounds Read Vulnerability leads to Information Disclos… |
| CVE-2026-73772 | 6.5 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Unauthenticated Buffer Overflow Vulnerabilities lead to Denial-of-Service in … |
| CVE-2026-78608 | 6.5 | — | Elastic | Kibana | CWE-862 | Missing Authorization in Kibana Leading to Information Disclosure |
| CVE-2026-79685 | 6.5 | — | Dell | PowerStore 500T | CWE-88 | Dell PowerStore contains an Argument Injection vulnerability. An authenticate… |
| CVE-2026-84269 | 6.5 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-122 | Gvfs: afp: heap-based buffer overflow in dsi read path |
| CVE-2026-84306 | 6.5 | — | filamentphp | filament | CWE-294 | Filament: Multi-factor authentication (app) codes can still be used after a n… |
| CVE-2026-84327 | 6.5 | — | Chrome | CWE-863 | Incorrect authorization in Autofill in Google Chrome on on Android prior to 1… | |
| CVE-2026-84348 | 6.5 | — | Chrome | CWE-200 | Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allo… | |
| CVE-2026-84365 | 6.5 | — | honojs | hono | CWE-22 | Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside… |
| CVE-2026-7877 | 6.4 | — | Bootstrapped Ventures | WP Recipe Maker Premium | CWE-79 | WP Recipe Maker Premium <= 10.5.0 - Authenticated (Contributor+) Stored Cross… |
| CVE-2026-73757 | 6.4 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Authenticated Server-Side Request Forgery (SSRF) Leading to Information Discl… |
| CVE-2026-84470 | 6.4 | — | Red Hat | Red Hat Ansible Automation Platform 2 | CWE-862 | Automation-controller: automation-controller-container: automation-controller… |
| CVE-2026-70405 | 6.3 | — | Erlang | OTP | CWE-1284 | snmp BER INTEGER decoder applies no size limit to attacker-supplied integer f… |
| CVE-2026-70409 | 6.3 | — | Erlang | OTP | CWE-1284 | eldap does not bound the port component of a referral URL before integer conv… |
| CVE-2026-71562 | 6.3 | — | Erlang | OTP | CWE-1284 | httpc does not bound server-supplied numeric header values before integer con… |
| CVE-2026-83610 | 6.3 | — | xmldom | xmldom | CWE-116 | xmldom: XML fragment injection via invalid EntityReference.nodeName during re… |
| CVE-2026-84303 | 6.3 | — | grpc | grpc-go | CWE-178 | gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC … |
| CVE-2026-84308 | 6.3 | — | phpseclib | phpseclib | CWE-208 | phpseclib — non-constant-time X25519 scalar multiplication permits full priva… |
| CVE-2026-73731 | 6.1 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Unauthenticated Reflected Cross-Site Scripting (XSS) Vulnerability in HPE Net… |
| CVE-2026-84369 | 6.1 | — | svg | svgo | CWE-79 | SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObje… |
| CVE-2026-74994 | 6.0 | — | Erlang | OTP | CWE-863 | inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd… |
| CVE-2026-51742 | 5.9 | — | n/a | n/a | CWE-284 | Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.7… |
| CVE-2026-51748 | 5.9 | — | n/a | n/a | CWE-284 | Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T… |
| CVE-2026-51756 | 5.9 | — | n/a | n/a | CWE-284 | Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5c… |
| CVE-2026-73756 | 5.9 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Unauthenticated Sensitive Information Disclosure via Man-in-the-Middle in AOS… |
| CVE-2026-78605 | 5.9 | — | Elastic | Elasticsearch | CWE-444 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in El… |
| CVE-2026-84363 | 5.9 | — | honojs | hono | CWE-444 | Hono: Query parser reads parameters after the URL fragment, causing cache-key… |
| CVE-2026-84373 | 5.9 | — | vitest-dev | vitest | CWE-22 | Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock |
| CVE-2026-84193 | 5.8 | — | librenms | librenms | CWE-79 | LibreNMS through 26.2.0 Stored Cross-Site Scripting via SNMP |
| CVE-2026-73755 | 5.7 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Privilege Escalation via Unauthorized Access to Sensitive Session Information |
| CVE-2026-73732 | 5.6 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | CWE-200 | Local Authenticated Sensitive Information Disclosure in HPE Networking Fabric… |
| CVE-2026-83557 | 5.6 | — | FasterXML | jackson-databind | CWE-502 | jackson-databind omits java.lang.Comparable from DefaultBaseTypeLimitingValid… |
| CVE-2026-10420 | 5.5 | — | Samsung Open Source | mTower | CWE-822 | Untrusted pointer dereference vulnerability in Samsung Open Source mTower all… |
| CVE-2026-82926 | 5.5 | — | Samsung Open Source | mTower | CWE-476 | NULL pointer dereference vulnerability in Samsung Open Source mTower allows P… |
| CVE-2026-82927 | 5.5 | — | Samsung Open Source | mTower | CWE-822 | Untrusted pointer dereference vulnerability in Samsung Open Source mTower all… |
| CVE-2026-84110 | 5.5 | — | Releasit | Releasit COD Form & Upsells | CWE-602 | Releasit Releasit COD Form & Upsells OTP Validation client-side enforcement o… |
| CVE-2026-84111 | 5.5 | — | Chanjet | CRM | CWE-74 | Chanjet CRM jxf_dump_table.php sql injection |
| CVE-2026-84115 | 5.5 | — | Cleo | Harmony | CWE-266 | Cleo Harmony JWT Refresh Token connections privileges management |
| CVE-2026-84423 | 5.5 | — | n/a | Casdoor | CWE-287 | Casdoor upload-resource API resource.go missing authentication |
| CVE-2026-72641 | 5.4 | — | Elastic | Kibana | CWE-863 | Incorrect Authorization in Kibana Leading to Unauthorized Modification of Data |
| CVE-2026-73733 | 5.4 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | CWE-287 | Authentication Bypasses in API allow Continued Authenticated Access in HPE Ne… |
| CVE-2026-73734 | 5.4 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | CWE-601 | Unauthenticated Open Redirect allows URL Manipulation in HPE Networking Fabri… |
| CVE-2026-73735 | 5.4 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | CWE-552 | Authenticated Access Control Vulnerabilities allow Information Disclosure in … |
| CVE-2026-78607 | 5.4 | — | Elastic | Elasticsearch | CWE-862 | Missing Authorization in Elasticsearch Leading to Information Disclosure |
| CVE-2026-84118 | 5.4 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the JavaScript: GC component |
| CVE-2026-84120 | 5.4 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the Audio/Video component |
| CVE-2026-84122 | 5.4 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the Audio/Video component |
| CVE-2026-84124 | 5.4 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the DOM: Core & HTML component |
| CVE-2026-84125 | 5.4 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the DOM: Core & HTML component |
| CVE-2026-84232 | 5.4 | — | Red Hat | Red Hat Ansible Automation Platform 2 | CWE-79 | Pulpcore: python-pulpcore: stored cross-site scripting via inline rendering o… |
| CVE-2026-84371 | 5.4 | — | apostrophecms | apostrophe | CWE-79 | ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass |
| CVE-2026-51745 | 5.3 | — | n/a | n/a | CWE-284 | Incorrect access control in the updatePriStaList function of TOTOLINK T6 4.1.… |
| CVE-2026-51752 | 5.3 | — | n/a | n/a | CWE-284 | Incorrect access control in the staticInfoSend function of TOTOLINK T6 4.1.5c… |
| CVE-2026-51761 | 5.3 | — | n/a | n/a | CWE-284 | Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1.5cu.7… |
| CVE-2026-53682 | 5.3 | — | Red Hat | Red Hat Certificate System 9 | CWE-200 | Pki-core: dogtag-pki: unauthenticated dogtag ca rest api exposes security dom… |
| CVE-2026-63435 | 5.3 | — | mikel | CWE-436 | Mail: Email address spoofing via malformed RFC 2047 encoded-words | |
| CVE-2026-73736 | 5.3 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | CWE-552 | Unauthenticated Limited Information Disclosure leads to Data Exposure in HPE … |
| CVE-2026-73754 | 5.3 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Authenticated Denial-of-Service Vulnerabilities in the Command Line Interface… |
| CVE-2026-77194 | 5.3 | — | wpinsider-1 | Simple Membership | CWE-287 | Simple Membership <= 4.8.1 - Unauthenticated Authentication Bypass to Adminis… |
| CVE-2026-84061 | 5.3 | — | zhongyu09 | OpenChatBI | CWE-74 | zhongyu09 OpenChatBI generate_sql.py _validate_sql_safety sql injection |
| CVE-2026-84191 | 5.3 | — | librenms | librenms | CWE-79 | LibreNMS before 26.5.0 Stored XSS via SNMP VRF fields |
| CVE-2026-84206 | 5.3 | — | grokability | snipe-it | CWE-863 | Snipe-IT before 8.7.0 Authorization Bypass via Bulk Restore |
| CVE-2026-84207 | 5.3 | — | heymrun | heym | CWE-918 | Heym before 0.0.98 SSRF via WebSocket endpoints |
| CVE-2026-84323 | 5.3 | — | Chrome | CWE-862 | Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 a… | |
| CVE-2026-84329 | 5.3 | — | Chrome | CWE-441 | Confused deputy in CredentialProvider in Google Chrome on on Windows prior to… | |
| CVE-2026-84364 | 5.3 | — | honojs | hono | CWE-400 | Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaus… |
| CVE-2026-13337 | 5.1 | — | Schneider Electric | NetBotz 5 - 750/755 | CWE-564 | CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the i… |
| CVE-2026-73524 | 5.1 | — | cypht-org | cypht | CWE-79 | Cypht < 2.12.2 XSS via FROM Email Header in Contacts Module |
| CVE-2026-84305 | 5.1 | — | andialbrecht | sqlparse | CWE-407 | sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption |
| CVE-2026-84477 | 5.1 | — | WWBN | AVideo | CWE-79 | AVideo Stored XSS via Live Schedule Title Description |
| CVE-2026-56143 | 4.9 | — | Elastic | Elasticsearch | CWE-770 | Allocation of Resources Without Limits or Throttling in Elasticsearch Leading… |
| CVE-2026-73783 | 4.9 | — | Hewlett Packard Enterprise (HPE) | AOS-CX | — | Authenticated Stack Overflow Vulnerabilities lead to Denial-of-Service in AOS-CX |
| CVE-2026-12661 | 4.8 | — | Rockwell Automation | FactoryTalk® Historian Machine Edition | CWE-121 | FactoryTalk® Historian Machine Edition - Out-of-Bounds Write Vulnerability |
| CVE-2026-73737 | 4.8 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | CWE-22 | Unauthenticated Path Traversal in HPE Networking Fabric Composer API Endpoint… |
| CVE-2026-84188 | 4.8 | — | librenms | librenms | CWE-79 | librenms before 26.7.0 Stored XSS via graph_descr settings |
| CVE-2026-84310 | 4.8 | — | py-pdf | pypdf | CWE-405 | pypdf: Possible long runtimes/large memory usage when retrieving outlines |
| CVE-2026-84311 | 4.8 | — | py-pdf | pypdf | CWE-834 | pypdf: Possible long runtimes/large memory usage when extracting XForm objects |
| CVE-2026-73738 | 4.7 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | CWE-200 | Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer |
| CVE-2026-73739 | 4.4 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | CWE-200 | Authenticated Sensitive Information Disclosure in HPE Networking Fabric Compo… |
| CVE-2026-73740 | 4.4 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | CWE-269 | Local Privilege Escalation in HPE Networking Fabric Composer |
| CVE-2026-72633 | 4.3 | — | Elastic | Kibana | CWE-863 | Incorrect Authorization in Kibana Leading to Unauthorized Disabling of Privil… |
| CVE-2026-73741 | 4.3 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | CWE-284 | Authenticated Limited File Read allows Data Exposure in HPE Networking Fabric… |
| CVE-2026-73742 | 4.3 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | CWE-290 | Improper Client Address Validation allows Request Attribution Spoofing in Fab… |
| CVE-2026-78597 | 4.3 | — | Elastic | Kibana | CWE-862 | Missing Authorization in Kibana Entity Store Leading to Unauthorized API Key … |
| CVE-2026-78603 | 4.3 | — | Elastic | Kibana | CWE-862 | Missing Authorization in Kibana Leading to Unauthorized Disclosure of Fleet D… |
| CVE-2026-84126 | 4.3 | — | Mozilla | Firefox | CWE-120 | Incorrect boundary conditions in the Layout: Grid component |
| CVE-2026-84127 | 4.3 | — | Mozilla | Firefox | CWE-200 | Information disclosure in the WebExtensions component in Firefox for Android |
| CVE-2026-84267 | 4.3 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-908 | Gvfs: sftp: uninitialized heap disclosure in read_string() |
| CVE-2026-84270 | 4.3 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Gvfs: mtp: out-of-bounds read in do_read() |
| CVE-2026-78606 | 4.2 | — | Elastic | Kibana | CWE-863 | Incorrect Authorization in Kibana Leading to Unauthorized Disclosure, Modific… |
| CVE-2026-73743 | 3.7 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | CWE-319 | Unauthenticated Information Disclosure Leading to Data Exposure in HPE Networ… |
| CVE-2026-84307 | 3.7 | — | filamentphp | filament | CWE-204 | Filament: Password validity disclosure for accounts denied panel access on lo… |
| CVE-2026-84367 | 3.7 | — | hapijs | joi | CWE-1321 | joi: object().rename() with a template target can set the validated object's … |
| CVE-2026-84368 | 3.7 | — | hapijs | joi | CWE-1321 | joi: Prototype pollution via a `__proto__` language key in custom messages |
| CVE-2026-73744 | 3.5 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | CWE-400 | Authenticated Denial of Service Vulnerability in HPE Networking Fabric Compos… |
| CVE-2026-81846 | 3.5 | — | runZero | Platform | CWE-639 | runZero MCP 'Findings summaries' Data Leak |
| CVE-2026-73745 | 3.1 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | — | Unauthenticated Limited Information Disclosure allows Data Exposure in the AP… |
| CVE-2026-73746 | 3.1 | — | Hewlett Packard Enterprise (HPE) | Fabric Composer | CWE-400 | Authenticated Denial of Service Vulnerability in HPE Networking Fabric Compos… |
Results continue: ranks 401–477.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-09-01 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.