AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .8293 99.6 YES
AFFECTED Product Versions Fixed Apache Tomcat 11.0.20 – —
TIMELINE Mar 30 Reserved by CNA Aug 4 Added to CISA KEV, due Aug 7 Aug 4 Published (CNA: apache)
273 CVEs published August 4, 2026: 45 critical, 119 high, 81 medium, 27 low; 2 in KEV; 3 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 248 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 779 | 9584 | 1391 | 2563 |
| KEV catalog size | 1670 | |||
447 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 5 | 1590 | 208 | 1130 | 98 | 0 | 27 | 3 | 0.2 | 7.8 | .0016 | -7 |
| microsoft | 16 | 1377 | 106 | 936 | 310 | 8 | 378 | 32 | 2.3 | 7.8 | .0039 | -34 |
| 2 | 414 | 65 | 104 | 227 | 15 | 73 | 5 | 1.2 | 6.5 | .0022 | +2 | |
| apple | 0 | 244 | 56 | 67 | 112 | 2 | 93 | 7 | 2.9 | 7.1 | .0027 | 0 |
| red hat | 19 | 241 | 9 | 112 | 105 | 15 | 4 | 0 | 0.0 | 7.0 | .0025 | +13 |
| canonical | 0 | 3 | 0 | 2 | 1 | 0 | 0 | 0 | 0.0 | 7.8 | .0013 | 0 |
| android | 0 | 1 | 0 | 1 | 0 | 0 | 16 | 1 | 100.0 | 8.4 | .0171 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 0 | 20 | 4 | 6 | 2 | 0 | 96 | 13 | 65.0 | 8.2 | .1853 | 0 |
| fortinet | 0 | 18 | 2 | 4 | 9 | 0 | 28 | 6 | 33.3 | 6.1 | .0054 | 0 |
| palo alto networks | 0 | 15 | 0 | 1 | 7 | 5 | 14 | 2 | 13.3 | 4.7 | .0028 | 0 |
| vmware | 0 | 12 | 4 | 7 | 0 | 1 | 21 | 0 | 0.0 | 8.7 | .0044 | 0 |
| checkpoint | 1 | 5 | 4 | 1 | 0 | 0 | 3 | 2 | 40.0 | 9.3 | .2062 | +1 |
| f5 | 0 | 5 | 4 | 0 | 0 | 0 | 7 | 1 | 20.0 | 9.2 | .0402 | 0 |
| ivanti | 0 | 5 | 1 | 0 | 0 | 0 | 33 | 5 | 100.0 | 10.0 | .8152 | 0 |
| zyxel | 3 | 4 | 0 | 3 | 1 | 0 | 11 | 0 | 0.0 | 7.2 | .0075 | +3 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 6 | 143 | 24 | 78 | 40 | 1 | 40 | 2 | 1.4 | 7.5 | .0051 | +6 |
| mozilla | 1 | 73 | 42 | 26 | 5 | 0 | 13 | 0 | 0.0 | 9.1 | .0031 | +1 |
| gitlab | 0 | 15 | 0 | 2 | 10 | 1 | 4 | 2 | 13.3 | 4.9 | .0029 | 0 |
| docker | 0 | 3 | 0 | 1 | 2 | 0 | 1 | 0 | 0.0 | 5.7 | .0015 | 0 |
| wordpress | 0 | 3 | 1 | 1 | 1 | 0 | 5 | 2 | 66.7 | 8.6 | .7310 | 0 |
| github | 0 | 2 | 0 | 1 | 1 | 0 | 0 | 0 | 0.0 | 6.1 | .0029 | 0 |
| drupal | 0 | 1 | 1 | 0 | 0 | 0 | 5 | 1 | 100.0 | 9.8 | .8832 | 0 |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0024 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 1113 | 212 | 539 | 304 | 57 | 40 | 3 | 0.3 | 7.6 | .0031 | 0 |
| ibm | 0 | 108 | 31 | 43 | 34 | 0 | 7 | 1 | 0.9 | 7.5 | .0026 | 0 |
| adobe | 7 | 47 | 16 | 23 | 4 | 0 | 75 | 4 | 8.5 | 8.6 | .0047 | +7 |
| progress | 0 | 23 | 3 | 15 | 5 | 0 | 9 | 0 | 0.0 | 8.1 | .0032 | 0 |
| solarwinds | 0 | 20 | 16 | 1 | 1 | 0 | 11 | 4 | 20.0 | 9.1 | .0050 | 0 |
| veeam | 10 | 12 | 3 | 7 | 2 | 0 | 4 | 0 | 0.0 | 8.6 | .0027 | +10 |
| atlassian | 0 | 3 | 0 | 3 | 0 | 0 | 13 | 0 | 0.0 | 8.0 | .0026 | 0 |
| zohocorp | 0 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 7.1 | .0048 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 0 | 8 | 0 | 0 | 6 | 1 | 26 | 1 | 12.5 | 5.5 | .0073 | 0 |
| hikvision | 0 | 7 | 0 | 4 | 2 | 0 | 2 | 1 | 14.3 | 7.2 | .0025 | 0 |
| bosch | 0 | 3 | 0 | 3 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0028 | 0 |
| schneider electric | 0 | 3 | 1 | 2 | 0 | 0 | 1 | 0 | 0.0 | 8.7 | .0020 | 0 |
| synology | 1 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0.0 | 7.3 | .0013 | +1 |
| honeywell | 0 | 1 | 0 | 0 | 1 | 0 | 0 | 0 | 0.0 | 6.9 | .0031 | 0 |
| mitsubishi electric | 0 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0.0 | 7.1 | .0013 | 0 |
| rockwell automation | 0 | 1 | 1 | 0 | 0 | 0 | 0 | 0 | 0.0 | 9.2 | .0030 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| surrealdb | 0 | 57 | 3 | 26 | 25 | 3 | 0 | 0 | 0.0 | 7.1 | .0025 | 0 |
| grafana | 0 | 41 | 2 | 14 | 22 | 3 | 0 | 0 | 0.0 | 6.5 | .0033 | 0 |
| netty | 0 | 41 | 6 | 27 | 7 | 1 | 0 | 0 | 0.0 | 7.5 | .0046 | 0 |
| legion of the bouncy castle | 32 | 39 | 5 | 25 | 9 | 0 | 0 | 0 | 0.0 | 8.7 | .0026 | +32 |
| open ises | 0 | 37 | 2 | 14 | 21 | 0 | 0 | 0 | 0.0 | 6.9 | .0021 | 0 |
| mediatek | 34 | 34 | 0 | 4 | 30 | 0 | 1 | 0 | 0.0 | 6.0 | .0011 | +34 |
| erlang | 0 | 32 | 1 | 14 | 14 | 3 | 1 | 0 | 0.0 | 6.9 | .0033 | -6 |
| freerdp | 23 | 31 | 8 | 18 | 4 | 1 | 0 | 0 | 0.0 | 8.7 | .0034 | +23 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-48282 | .9924 | 99.9 | — |
| CVE-2026-63030 | .9560 | 99.9 | 9.8 |
| CVE-2026-39808 | .9121 | 99.8 | — |
| CVE-2026-48908 | .8813 | 99.8 | 10.0 |
| CVE-2026-56290 | .8325 | 99.7 | 10.0 |
| CVE-2026-34486 | .8293 | 99.6 | 7.5 |
| CVE-2026-48939 | .8250 | 99.6 | 10.0 |
| CVE-2026-50522 | .7698 | 99.5 | 9.8 |
| CVE-2026-15410 | .7635 | 99.5 | 7.2 |
| CVE-2026-56291 | .7607 | 99.5 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-48908 | 10.0 | .8813 | KEV |
| CVE-2026-56290 | 10.0 | .8325 | KEV |
| CVE-2026-48939 | 10.0 | .8250 | KEV |
| CVE-2026-56291 | 10.0 | .7607 | KEV |
| CVE-2026-15409 | 10.0 | .7422 | KEV |
| CVE-2026-8985 | 10.0 | .0660 | |
| CVE-2026-6516 | 10.0 | .0473 | |
| CVE-2026-47668 | 10.0 | .0434 | |
| CVE-2026-44359 | 10.0 | .0100 | |
| CVE-2025-71389 | 10.0 | .0093 |
| Vendor | CVEs |
|---|---|
| oracle | 1109 |
| linux | 660 |
| microsoft | 624 |
| 405 | |
| apple | 167 |
| red hat | 136 |
| apache | 111 |
| ibm | 100 |
| mozilla | 68 |
| surrealdb | 57 |
| Vendor | KEV |
|---|---|
| microsoft | 32 |
| cisco | 13 |
| apple | 7 |
| fortinet | 6 |
| 5 | |
| ivanti | 5 |
| adobe | 4 |
| langflow | 4 |
| solarwinds | 4 |
| synacor | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 31 |
| PyPI | 5 |
| Go | 3 |
| crates.io | 2 |
| npm | 2 |
| NuGet | 1 |
| Packagist | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4128 | Cisco | 0 |
| CVE-2021-27137 | DD-WRT | 0 |
| CVE-2023-4346 | KNX Association | 0 |
| CVE-2025-68686 | Fortinet | 0 |
| CVE-2026-0770 | Langflow | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-16232 | checkpoint | 0 |
| CVE-2026-16812 | Arista Networks | 0 |
| CVE-2026-18556 | N-able | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1721 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1721 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1721 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1721 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1721 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1721 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1721 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1721 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1721 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1721 |
EXPLOIT PUBLISHED — CVE-2021-44529 (Ivanti EPM). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2021-47102 (Linux). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2021-47103 (Linux). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2021-47107 (Linux). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-27925. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-30333. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-37042. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-48629 (Linux). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2023-46805 (Ivanti ICS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2023-4853 (Red Hat Openshift Serverless 1 on RHEL 8). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2023-52927 (Linux). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2024-0012 (Palo Alto Networks Cloud NGFW). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2024-21887 (Ivanti ICS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2024-24919 (checkpoint Check Point Quantum Gateway, Spark Gateway and CloudGuard Network). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2024-51567. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-15672 (Unknown ChamaWP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-15673 (Unknown Import and export users and customers). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-37947 (Linux). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-53770 (Microsoft SharePoint Enterprise Server 2016). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-57631. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10050 (Eclipse Foundation Eclipse Jetty - EE8). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10827 (Unknown Spectra Legacy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-11368 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-11872 (Unknown Clever Mega Menu for Visual Composer). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-11882 (Unknown Builderall for WordPress). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-12872 (Unknown Webinfos). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-13157 (Unknown Theme Demo Import). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-13158 (Unknown Everest Toolkit). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-13604 (Unknown Pixelavo). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-13725 (Unknown Dynamic Pricing With Discount Rules for WooCommerce). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-13729 (Unknown Podlove Podcast Publisher). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14195 (Unknown Brizy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14197 (Unknown Fluent Support). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14214 (Unknown Booking for Appointments and Events Calendar). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14309 (Unknown Chat On Desk Order Notifications). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14557 (Unknown SoftMarket — Digital Marketplace). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14596 (Unknown DynamicKit for Elementor). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14822 (Unknown Event Tickets and Registration). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14823 (Unknown Event Tickets and Registration). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14836 (Unknown Login & Register Forms). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14840 (Unknown YOP Poll). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14938 (Unknown FluentBoards). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-15231 (Unknown Tag, Category, and Taxonomy Manager). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-15244 (Unknown HUSKY). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-15248 (Unknown Meta Box). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-15368 (Unknown User Profile Builder). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-15932 (Unknown Support Genix). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-15939 (Unknown Simple Restrict). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16057 (Unknown Contest Gallery). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16060 (Unknown Insert or Embed Articulate Content into WordPress). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16250 (Unknown Personal QR Message). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16256 (Unknown POUCO Import Users). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16274 (Unknown Classified Listing). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16276 (Unknown Classified Listing). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18616 (GL-iNet GL-MT3000). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18631 (jeequan jeepay). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18641 (Sangfor Operation and Maintenance Security Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18645 (danpros HTMLy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18646 (danpros HTMLy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18647 (jina-ai reader). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18648 (Blix Email Blue Mail Calendar App). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18682 (OpenAkita). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18684 (GL.iNet GL-MT3000). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-32141 (WebReflection flatted). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-33228 (WebReflection flatted). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-33870 (netty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-39363 (vitejs vite). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-39364 (vitejs vite). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-46331 (Linux). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-53264 (Linux). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56722 (dompdf). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-59941 (dompdf). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-59942 (dompdf). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-59943 (dompdf). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-67599 (ClearFoundation ClearOS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-67617 (microweber). Public exploit reference added.
RESCORED — CVE-2019-25160 (Linux). CVSS 9.1 → 7.1 (NVD).
RESCORED — CVE-2020-36787 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2020-36791 (Linux). CVSS 7.8 → 7.1 (NVD).
RESCORED — CVE-2021-4454 (Linux). CVSS 7.5 → 5.5 (NVD).
RESCORED — CVE-2021-46908 (Linux). CVSS 7.1 → 5.5 (NVD).
RESCORED — CVE-2021-46910 (Linux). CVSS 7 → 5.5 (NVD).
RESCORED — CVE-2021-46911 (Linux). CVSS 9.8 → 5.5 (NVD).
RESCORED — CVE-2021-46912 (Linux). CVSS 7.3 → 5.5 (NVD).
RESCORED — CVE-2021-46913 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2021-46921 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2021-46922 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2021-46925 (Linux). CVSS 7.8 → 4.7 (NVD).
RESCORED — CVE-2021-46929 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2021-46933 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2021-46948 (Linux). CVSS 7.5 → 5.5 (NVD).
RESCORED — CVE-2021-46955 (Linux). CVSS 8.2 → 7.1 (NVD).
RESCORED — CVE-2021-46958 (Linux). CVSS 7.8 → 4.7 (NVD).
RESCORED — CVE-2021-46960 (Linux). CVSS 7.5 → 5.5 (NVD).
RESCORED — CVE-2021-46963 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2021-46967 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2021-46974 (Linux). CVSS 7.1 → 5.5 (NVD).
RESCORED — CVE-2021-46977 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2021-46983 (Linux). CVSS 7.5 → 5.5 (NVD).
RESCORED — CVE-2021-46992 (Linux). CVSS 7.8 → 7.1 (NVD).
RESCORED — CVE-2021-46993 (Linux). CVSS 7.8 → 7.1 (NVD).
RESCORED — CVE-2021-46999 (Linux). CVSS 9.8 → 7.8 (NVD).
RESCORED — CVE-2021-47001 (Linux). CVSS 7.5 → 4.7 (NVD).
RESCORED — CVE-2021-47011 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2021-47013 (Linux). CVSS 9.8 → 7.8 (NVD).
RESCORED — CVE-2021-47017 (Linux). CVSS 8.8 → 7.8 (NVD).
RESCORED — CVE-2021-47028 (Linux). CVSS 7.1 → 7.8 (NVD).
RESCORED — CVE-2021-47035 (Linux). CVSS 8.8 → 5.5 (NVD).
RESCORED — CVE-2021-47036 (Linux). CVSS 9.8 → 5.5 (NVD).
RESCORED — CVE-2021-47041 (Linux). CVSS 7.5 → 5.5 (NVD).
RESCORED — CVE-2021-47049 (Linux). CVSS 8.4 → 7.8 (NVD).
RESCORED — CVE-2021-47055 (Linux). CVSS 7.1 → 5.5 (NVD).
RESCORED — CVE-2021-47066 (Linux). CVSS 7.1 → 5.5 (NVD).
RESCORED — CVE-2021-47069 (Linux). CVSS 7.8 → 7 (NVD).
RESCORED — CVE-2021-47103 (Linux). CVSS 9.8 → 7.8 (NVD).
RESCORED — CVE-2021-47107 (Linux). CVSS 9.8 → 7.8 (NVD).
RESCORED — CVE-2021-47109 (Linux). CVSS 7.5 → 5.5 (NVD).
RESCORED — CVE-2021-47111 (Linux). CVSS 8.8 → 7.8 (NVD).
RESCORED — CVE-2021-47112 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2021-47113 (Linux). CVSS 7.1 → 5.5 (NVD).
RESCORED — CVE-2021-47124 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2021-47131 (Linux). CVSS 8.1 → 7.8 (NVD).
RESCORED — CVE-2021-47132 (Linux). CVSS 7.5 → 7.1 (NVD).
RESCORED — CVE-2021-47136 (Linux). CVSS 8.6 → 5.5 (NVD).
RESCORED — CVE-2021-47142 (Linux). CVSS 7.8 → 5.5 (NVD).
RESCORED — CVE-2021-47152 (Linux). CVSS 7.8 → 5.5 (NVD).
PATCH SHIPPED — CVE-2023-35078 (Ivanti Endpoint Manager Mobile). Fixed in Endpoint Manager Mobile 11.10.
PATCH SHIPPED — CVE-2026-31431 (Linux). Fixed in Linux 5.10.254.
+ 1346 more transactions — continued on page 2 (of 3). Every change is listed; nothing truncated.
273 CVEs published. 25 box scores, 248 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .8293 99.6 YES
AFFECTED Product Versions Fixed Apache Tomcat 11.0.20 – —
TIMELINE Mar 30 Reserved by CNA Aug 4 Added to CISA KEV, due Aug 7 Aug 4 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N N H N N 8.2 .0049 40.1 YES
AFFECTED Product Versions Fixed N-central unspecified —
TIMELINE Aug 1 Reserved by CNA Aug 4 Added to CISA KEV, due Aug 7 Aug 4 Published (CNA: N-able)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 7.3 .0271 84.7 —
AFFECTED Product Versions Fixed NX15 V100R017 – —
TIMELINE Aug 4 Reserved by CNA Aug 4 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0261 84.1 —
AFFECTED Product Versions Fixed GL-MT3000 4.4.0 – —
TIMELINE Aug 3 Reserved by CNA Aug 4 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 7.3 .0226 81.5 —
AFFECTED Product Versions Fixed NX15 V100R017 – —
TIMELINE Aug 4 Reserved by CNA Aug 4 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 7.3 .0226 81.5 —
AFFECTED Product Versions Fixed NX15 V100R017 – —
TIMELINE Aug 4 Reserved by CNA Aug 4 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 7.3 .0226 81.5 —
AFFECTED Product Versions Fixed NX15 V100R017 – —
TIMELINE Aug 4 Reserved by CNA Aug 4 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0224 81.4 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Mar 11 Reserved by CNA Aug 4 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 7.4 .0165 74.5 —
AFFECTED Product Versions Fixed AX1800 4.8.0 – —
TIMELINE Aug 4 Reserved by CNA Aug 4 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0158 73.4 —
AFFECTED Product Versions Fixed IP Camera 2.x – —
TIMELINE Jul 10 Reserved by CNA Aug 4 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0116 64.4 —
AFFECTED Product Versions Fixed perspective unspecified —
TIMELINE Jul 28 Reserved by CNA Aug 4 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0095 58.3 —
AFFECTED Product Versions Fixed WAX650S firmware <= 7.10(ABRM.4)C0 – —
TIMELINE Apr 22 Reserved by CNA Aug 4 Published (CNA: Zyxel)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0088 56.1 —
AFFECTED Product Versions Fixed MaxSite CMS 105.2 – 109.6
TIMELINE Aug 4 Reserved by CNA Aug 4 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0085 55.2 —
AFFECTED Product Versions Fixed MaxSite CMS 0.78 – 109.6
TIMELINE Aug 4 Reserved by CNA Aug 4 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H H N U H N N 4.4 .0085 55.1 —
AFFECTED Product Versions Fixed Red Hat JBoss Enterprise Application Platform 7 unspecified — Red Hat JBoss Enterprise Application Platform 7 unspecified — Red Hat JBoss Enterprise Application Platform 7 unspecified — Red Hat JBoss Enterprise Application Platform 7 unspecified — Red Hat JBoss Enterprise Application Platform 7 unspecified — Red Hat JBoss Enterprise Application Platform 7 unspecified — Red Hat JBoss Enterprise Application Platform 8 unspecified — Red Hat JBoss Enterprise Application Platform Expansion Pack unspecified — Red Hat Single Sign-On 7 unspecified —
TIMELINE Jul 27 Reserved by CNA Aug 4 Published (CNA: redhat)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P L N H H H 9.0 .0079 53.3 —
AFFECTED Product Versions Fixed Flowise < 3.1.3 – — flowise-components < 3.1.3 – —
TIMELINE Aug 3 Reserved by CNA Aug 4 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0077 52.7 —
AFFECTED Product Versions Fixed Hawkeye unspecified 6.0.7 IxChariot unspecified 10.0.254 IxTap unspecified 3.13.0 IxProbe unspecified 3.13.0 IxByPass unspecified 3.13.0.69
TIMELINE May 29 Reserved by CNA Aug 4 Published (CNA: cisa-cg)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0072 50.8 —
AFFECTED Product Versions Fixed IxChariot unspecified 9.5.102
TIMELINE May 29 Reserved by CNA Aug 4 Published (CNA: cisa-cg)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0072 50.8 —
AFFECTED Product Versions Fixed IxChariot unspecified 9.5.102
TIMELINE May 29 Reserved by CNA Aug 4 Published (CNA: cisa-cg)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0062 47.0 —
AFFECTED Product Versions Fixed node 24.18.0 – —
TIMELINE Jun 23 Reserved by CNA Aug 4 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0062 47.0 —
AFFECTED Product Versions Fixed node 26.5.0 – —
TIMELINE Jun 23 Reserved by CNA Aug 4 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H H 9.1 .0059 45.3 —
AFFECTED Product Versions Fixed opensips >= 3.4.0-beta, < 3.6.6 – —
TIMELINE May 8 Reserved by CNA Aug 4 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 9.4 .0058 44.9 —
AFFECTED Product Versions Fixed Flowise < 3.1.3 – —
TIMELINE Aug 3 Reserved by CNA Aug 4 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0057 44.3 —
AFFECTED Product Versions Fixed perspective unspecified —
TIMELINE Jul 28 Reserved by CNA Aug 4 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0057 44.3 —
AFFECTED Product Versions Fixed MaxSite CMS 0.78 – 109.6
TIMELINE Aug 4 Reserved by CNA Aug 4 Published (CNA: VulnCheck)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-47612 | 7.5 | 43.5 | NVIDIA | Dynamo | CWE-22 | NVIDIA Dynamo for Linux contains a vulnerability in the image loading compone… |
| CVE-2026-69100 | 8.7 | 43.5 | dromara | lamp-cloud | CWE-94 | LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Execution |
| CVE-2026-69110 | 9.3 | 43.4 | Microck | opencode-studio | CWE-22 | OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/music |
| CVE-2026-8508 | 6.5 | 43.1 | Zyxel | WAX650S firmware | CWE-287 | An improper authentication vulnerability in the "social_login.cgi" CGI progra… |
| CVE-2026-24254 | 9.8 | 43.0 | NVIDIA | Dynamo | CWE-288 | NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving to… |
| CVE-2026-15307 | 8.7 | 42.8 | djangoproject | Django | CWE-73 | Server-side file-write and request forgery via spatial lookups |
| CVE-2026-70470 | 9.5 | 42.0 | FlowiseAI | Flowise | CWE-184 | Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE |
| CVE-2026-15830 | 6.9 | 41.9 | djangoproject | Django | CWE-674 | Potential denial-of-service vulnerability via nested geometry collections |
| CVE-2026-15337 | 6.9 | 41.9 | djangoproject | Django | CWE-789 | Potential denial-of-service vulnerability in check_for_language() |
| CVE-2026-69098 | 9.3 | 41.1 | Cinnamon | kotaemon | CWE-502 | kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserializ… |
| CVE-2026-15314 | 7.1 | 40.5 | TP-Link Systems Inc. | P110 v1 | CWE-120 | Authenticated Denial-of-Service Vulnerability in TP-Link Tapo P110 |
| CVE-2026-46334 | 8.7 | 39.9 | OpenSIPS | opensips | CWE-20 | OpenSIPS: Denial of Service in SDP bandwidth parsing via QoS SDP cloning |
| CVE-2026-67858 | 7.5 | 39.8 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discov… |
| CVE-2026-45538 | 9.8 | 39.4 | OpenSIPS | opensips | CWE-121 | OpenSIPS: Stack Buffer Overflow in sip_to_json() Header Name Copy |
| CVE-2026-64564 | 9.8 | 39.1 | Linux | Linux | — | sctp: don't free the ASCONF's own transport in DEL-IP processing |
| CVE-2026-10050 | 8.7 | 38.6 | Eclipse Foundation | Eclipse Jetty - EE8 | CWE-173 | Digest authentication lossy encoding |
| CVE-2026-67859 | 7.5 | 38.4 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to… |
| CVE-2026-45084 | 8.7 | 38.3 | OpenSIPS | opensips | CWE-476 | OpenSIPS: Denial of service in presence.handle_publish() from unchecked Conte… |
| CVE-2026-16618 | 9.8 | 38.2 | Unknown | Improve SEO | CWE-434 | ImproveSEO <= 2.0.11 - Unauthenticated Arbitrary File Upload Leading to Remot… |
| CVE-2026-58042 | 5.9 | 38.0 | nodejs | node | CWE-400 | A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When … |
| CVE-2026-69703 | 9.3 | 37.9 | maximeAmini | Atals-Livre | CWE-306 | Atlas-Livre Unauthenticated Access via Admin Controllers Missing Exit |
| CVE-2026-47619 | 8.1 | 37.1 | NVIDIA | Dynamo | CWE-1357 | NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an… |
| CVE-2026-70477 | 9.5 | 36.9 | FlowiseAI | Flowise | CWE-94 | Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability |
| CVE-2026-66902 | 9.8 | 36.7 | CJCOLLIER | Google::Auth | CWE-78 | Google::Auth versions before 0.06 for Perl run a command named in an external… |
| CVE-2026-61514 | 9.3 | 36.1 | Puwell Technology Inc. | IP Camera | CWE-306 | Puwell IP Camera 2.x - 4.x Unauthenticated Access via TCP Port 23456 |
| CVE-2026-63455 | 9.8 | 35.7 | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Orchestrator | CWE-306 | Authentication bypass via spoofed HTTP headers Orchestrator REST API |
| CVE-2026-63456 | 9.8 | 35.7 | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Orchestrator | CWE-287 | Authentication bypass via spoofed HTTP headers Orchestrator REST API |
| CVE-2026-67856 | 7.5 | 35.2 | n/a | n/a | CWE-400 | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a … |
| CVE-2026-67861 | 7.5 | 34.8 | n/a | n/a | CWE-400 | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a … |
| CVE-2026-63252 | 8.7 | 34.4 | Eclipse Foundation | Eclipse Milo | CWE-401 | In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers … |
| CVE-2026-56845 | 7.5 | 33.3 | Rocket.Chat | Rocket.Chat | CWE-22 | An unauthenticated path traversal (LFI) vulnerability exists under /custom-so… |
| CVE-2026-18103 | 4.9 | 33.2 | Red Hat | Red Hat Enterprise Linux 6 | CWE-120 | Dhcp-server: dhcp-server: persistent denial of service due to buffer overflow… |
| CVE-2026-14175 | 9.8 | 32.7 | Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | CWE-434 | Unrestricted File Upload in Bilin Software's HUMANIST Digital Human Resources |
| CVE-2026-69256 | 9.4 | 32.2 | FlowiseAI | Flowise | CWE-94 | Flowise: Remote Code Execution Vulnerability in CSVAgent |
| CVE-2026-45809 | 8.7 | 31.9 | OpenSIPS | opensips | CWE-121 | OpenSIPS: Denial of Service in watcherinfo XML generation from oversized watc… |
| CVE-2026-24255 | 7.5 | 31.6 | NVIDIA | Dynamo | CWE-1023 | NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding … |
| CVE-2026-60007 | 9.1 | 31.5 | Eclipse Foundation | Eclipse Milo | CWE-204 | In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing retur… |
| CVE-2026-69258 | 8.8 | 31.5 | FlowiseAI | Flowise | CWE-639 | Flowise: Unauthenticated Property Injection into Flow Execution Context via U… |
| CVE-2026-18810 | 6.9 | 31.5 | H3C | NX15 | CWE-287 | H3C NX15 networkSetup missing authentication |
| CVE-2026-70478 | 9.2 | 31.3 | FlowiseAI | Flowise | CWE-200 | Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens … |
| CVE-2026-47623 | 8.2 | 31.2 | NVIDIA | Dynamo | CWE-502 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could caus… |
| CVE-2026-58072 | 9.0 | 30.7 | Veeam | Service Provider Console | CWE-22 | A vulnerability in Veeam Service Provider Console allowing arbitrary file wri… |
| CVE-2026-18788 | 5.5 | 30.6 | Trippo | ResponsiveFilemanager | CWE-284 | Trippo ResponsiveFilemanager dialog.php unrestricted upload |
| CVE-2026-70486 | 8.2 | 30.6 | open-webui | open-webui | CWE-79 | Open WebUI: Same-origin XSS to account takeover via terminal file-preview ifr… |
| CVE-2026-68494 | 8.7 | 30.3 | FasterXML | jackson-core | CWE-770 | jackson-core: Async parser maxNumberLength bypass via chunked digit accumulat… |
| CVE-2026-64633 | 10.0 | 30.0 | Veeam | ONE | CWE-94 | A vulnerability allowing remote unauthenticated code execution on the agent h… |
| CVE-2026-70619 | 8.7 | 29.5 | odysseus-dev | odysseus | CWE-862 | Odysseus Missing Admin Authorization via Embedding Endpoint Routes |
| CVE-2026-69254 | 9.4 | 29.3 | FlowiseAI | Flowise | CWE-94 | Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptio… |
| CVE-2026-14818 | 7.2 | 29.0 | Zyxel | ATP series firmware | CWE-22 | A path traversal vulnerability in the CLI command used to execute configurati… |
| CVE-2026-45537 | 9.1 | 28.9 | OpenSIPS | opensips | CWE-120 | OpenSIPS: Global Buffer Overflow in construct_uri |
| CVE-2026-16793 | 8.7 | 28.6 | Lenovo | XClarity Orchestrator | CWE-20 | Remote Command Injection via OS Profile Password in Lenovo XClarity Orchestrator |
| CVE-2026-69259 | 9.4 | 28.5 | FlowiseAI | Flowise | CWE-94 | Flowise RCE via SQLite Record Manager Node |
| CVE-2026-58074 | 8.6 | 28.5 | Veeam | ONE | CWE-94 | A vulnerability allowing a high-privileged user to execute arbitrary code on … |
| CVE-2026-24253 | 8.2 | 28.3 | NVIDIA | Dynamo | CWE-787 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could caus… |
| CVE-2026-70368 | 6.5 | 28.4 | Mobi-Com Polska Sp. z o.o. | stunnel | CWE-125 | Stunnel: stack-based out-of-bounds read/write in stunnel s_vlog via oversized… |
| CVE-2026-67857 | 7.5 | 28.1 | n/a | n/a | CWE-125 | open62541 1.5.5 contains an out-of-bounds read in the client-side function re… |
| CVE-2026-61387 | 6.9 | 27.5 | Eclipse Foundation | Eclipse Milo | CWE-400 | In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting… |
| CVE-2026-69250 | 8.5 | 27.2 | FlowiseAI | Flowise | CWE-639 | Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exf… |
| CVE-2026-18816 | 2.3 | 26.9 | n/a | Baserow | CWE-287 | Baserow 2FA Verify Endpoint views.py verify improper authentication |
| CVE-2026-70482 | 8.1 | 26.7 | open-webui | open-webui | CWE-287 | Open WebUI: Account takeover via OAuth token exchange accepting tokens issued… |
| CVE-2026-66901 | 7.5 | 26.2 | CJCOLLIER | Google::Auth | CWE-201 | Google::Auth versions before 0.09 for Perl allow server side request forgery … |
| CVE-2026-67862 | 7.5 | 26.1 | n/a | n/a | CWE-400 | open62541 1.5.5 contains a buffer-overflow in the high-level attribute readin… |
| CVE-2026-0163 | 9.8 | 25.7 | Android | CWE-416 | In multiple functions of vpu_ioctl.c, there is a possible use after free due … | |
| CVE-2026-45103 | 7.5 | 25.6 | OpenSIPS | opensips | CWE-190 | OpenSIPS: SIP Message Smuggling via TCP Content-Length Integer Overflow |
| CVE-2026-58041 | 5.3 | 24.8 | nodejs | node | CWE-367 | A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created th… |
| CVE-2026-47613 | 7.5 | 24.6 | NVIDIA | Dynamo | CWE-918 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause … |
| CVE-2026-47614 | 7.5 | 24.6 | NVIDIA | Dynamo | CWE-918 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause … |
| CVE-2026-47615 | 7.5 | 24.6 | NVIDIA | Dynamo | CWE-918 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause … |
| CVE-2026-47616 | 7.5 | 24.6 | NVIDIA | Dynamo | CWE-918 | NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetc… |
| CVE-2026-47617 | 7.5 | 24.6 | NVIDIA | Dynamo | CWE-918 | NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetc… |
| CVE-2026-47618 | 7.5 | 24.6 | NVIDIA | Dynamo | CWE-918 | NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media… |
| CVE-2026-69255 | 9.2 | 24.0 | FlowiseAI | Flowise | CWE-94 | Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Sh… |
| CVE-2026-18753 | 9.1 | 24.0 | GeoVision Inc. | GV-AS1620 (AS-Manager) | CWE-321 | Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-ASManager) |
| CVE-2026-18754 | 9.1 | 24.0 | GeoVision Inc. | GV-AS1620 (GV-Cloud) | CWE-321 | Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-Cloud) |
| CVE-2026-69253 | 9.0 | 23.9 | FlowiseAI | Flowise | CWE-95 | Flowise Sandbox Escape to RCE |
| CVE-2026-18401 | 6.9 | 23.6 | FasterXML | jackson-core | CWE-770 | jackson-core: Number length constraint bypass in non-blocking (async) JSON pa… |
| CVE-2026-70369 | 8.8 | 23.3 | Koha Community | Koha | CWE-89 | Koha - SQL Injection in reports/acquisitions_stats.pl |
| CVE-2026-70370 | 8.8 | 23.2 | Koha Community | Koha | CWE-89 | Koha - SQL Injection in reports/catalogue_stats.pl |
| CVE-2026-70371 | 8.8 | 23.2 | Koha Community | Koha | CWE-89 | Koha - SQL Injection in reports/issues_avg_stats.pl |
| CVE-2026-70372 | 8.8 | 23.2 | Koha Community | Koha | CWE-89 | Koha - SQL Injection in reports/bor_issues_top.pl |
| CVE-2026-70373 | 8.8 | 23.3 | Koha Community | Koha | CWE-89 | Koha - SQL Injection in reports/issues_stats.pl |
| CVE-2026-14804 | 9.1 | 23.1 | Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | CWE-321 | Hardcoded Cryptographic Key in Bilin Software's HUMANIST Digital Human Resources |
| CVE-2026-69702 | 7.1 | 23.1 | aizuda | SnailJob (snail-job) | CWE-789 | SnailJob 1.7.0 Denial of Service via FuryUtil.deserialize OOM |
| CVE-2026-70493 | 6.5 | 23.1 | open-webui | open-webui | CWE-1333 | Open WebUI: Any authenticated user can stall a worker via a knowledge-search … |
| CVE-2026-18770 | 5.5 | 23.0 | vibesurf-ai | VibeSurf | CWE-74 | vibesurf-ai VibeSurf Python Validation code code injection |
| CVE-2026-15920 | 5.1 | 23.0 | djangoproject | Django | CWE-83 | Potential cross-site scripting via URLField values in the admin |
| CVE-2026-47682 | 7.1 | 22.9 | cvat-ai | cvat | CWE-22 | CVAT: Missing path-containment validation in multiple entry points allows arb… |
| CVE-2026-67243 | 8.6 | 22.7 | refirio | freo2 | CWE-434 | freo2 provided by refirio contains an unrestricted upload of file with danger… |
| CVE-2026-58044 | 3.7 | 22.7 | nodejs | node | CWE-444 | A flaw in Node.js HTTP client can cause a request desynchronization for Node.… |
| CVE-2026-58067 | 8.7 | 22.6 | Veeam | Service Provider Console | CWE-789 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated… |
| CVE-2026-70481 | 5.4 | 22.5 | open-webui | open-webui | CWE-284 | Open WebUI: Any member with write access to a standard channel can edit or de… |
| CVE-2026-62927 | 8.7 | 22.4 | Eclipse Foundation | Eclipse Milo | CWE-863 | In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the… |
| CVE-2026-70592 | 5.5 | 22.4 | TryGhost | Ghost | CWE-22 | Ghost: Database Backup Path Traversal |
| CVE-2026-70494 | 8.1 | 22.3 | open-webui | open-webui | CWE-862 | Open WebUI: A folder write-collaborator can permanently delete the owner's ch… |
| CVE-2026-67199 | 7.1 | 22.2 | perspective-dev | perspective | CWE-770 | Perspective 5.0.0 DoS via Loop Expression Evaluation |
| CVE-2026-70475 | 7.1 | 22.2 | FlowiseAI | Flowise | CWE-862 | Flowise: Missing Authorization on Execution Update Endpoint |
| CVE-2026-14194 | 6.5 | 22.1 | Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | CWE-22 | Path Traversal Allows Arbitrary File Download in Bilin Software's HUMANIST Di… |
| CVE-2026-70489 | 6.5 | 22.1 | open-webui | open-webui | CWE-400 | Open WebUI: Instance-wide stall via automation recurrence rules that force mu… |
| CVE-2026-18830 | 8.6 | 21.6 | AWS | Amazon Bedrock AgentCore harness | CWE-1287 | Insufficient input validation in Amazon Bedrock AgentCore harness InvokeHarne… |
| CVE-2026-45705 | 5.3 | 21.6 | OpenSIPS | opensips | CWE-125 | OpenSIPS: OOB Read in Multipart Body Boundary Parsing |
| CVE-2026-67855 | 7.5 | 21.5 | n/a | n/a | CWE-400 | open62541 contains a heap use-after-free in the GDS PushManagement certificat… |
| CVE-2026-70593 | 6.6 | 21.5 | TryGhost | Ghost | CWE-22 | Ghost: Theme Upload Path Traversal |
| CVE-2026-66883 | 6.3 | 21.5 | Erlang Ecosystem Foundation | oidcc_plug | CWE-178 | Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive h… |
| CVE-2026-70474 | 7.6 | 21.3 | FlowiseAI | Flowise | CWE-863 | Flowise: Cross-Workspace OAuth2 Credential Metadata Leak |
| CVE-2026-67979 | 9.1 | 21.1 | n/a | n/a | CWE-284 | Incorrect access control in the Executive Services dynamic application start … |
| CVE-2026-17070 | 8.8 | 21.1 | HAVELSAN Inc. | Liman MYS | CWE-862 | Vault Credential Confusion via Authorization Bypass in HAVELSAN's Liman MYS |
| CVE-2026-70476 | 8.3 | 21.1 | FlowiseAI | Flowise | CWE-284 | Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-… |
| CVE-2026-18720 | 5.5 | 21.1 | kalcaddle | kodbox | CWE-266 | kalcaddle kodbox msgWarning Plugin action improper authorization |
| CVE-2026-58075 | 8.7 | 20.6 | Veeam | ONE | CWE-287 | A vulnerability allowing an unauthenticated attacker to read arbitrary files … |
| CVE-2026-58071 | 8.2 | 20.6 | Veeam | Service Provider Console | CWE-306 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated… |
| CVE-2026-70471 | 7.1 | 20.4 | FlowiseAI | Flowise | CWE-863 | Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure |
| CVE-2026-69704 | 7.0 | 20.0 | maximeAmini | Atals-Livre | CWE-89 | Atals-Livre SQL Injection via Unsanitized GET Parameter in supp() |
| CVE-2026-18772 | 6.5 | 19.3 | Samsung Open Source | rlottie | CWE-1325 | Improperly controlled sequential memory allocation vulnerability in Samsung O… |
| CVE-2026-18775 | 2.1 | 19.4 | NousResearch | hermes-agent | CWE-918 | NousResearch hermes-agent Browser Tooling browser_tool.py browser_snapshot se… |
| CVE-2026-14465 | 6.5 | 19.2 | Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | CWE-613 | Session Fixation in Bilin Software's HUMANIST Digital Human Resources |
| CVE-2026-58080 | 8.8 | 19.2 | Eclipse Foundation | Eclipse Milo | CWE-862 | In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fail… |
| CVE-2026-69263 | 8.7 | 19.0 | FlowiseAI | Flowise | CWE-184 | Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment … |
| CVE-2026-67860 | 7.5 | 18.9 | n/a | n/a | CWE-122 | open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryR… |
| CVE-2026-70484 | 4.3 | 18.9 | open-webui | open-webui | CWE-862 | Open WebUI: Users denied the image-generation permission can still generate i… |
| CVE-2026-64631 | 8.5 | 18.6 | Veeam | ONE | CWE-89 | A vulnerability allowing a low-privileged user to inject SQL and extract data… |
| CVE-2026-70620 | 6.1 | 18.3 | odysseus-dev | odysseus | CWE-918 | Odysseus SSRF via Embedding Endpoint Configuration |
| CVE-2026-47622 | 5.3 | 18.4 | NVIDIA | Dynamo | CWE-209 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could caus… |
| CVE-2026-16881 | 8.7 | 18.1 | LY Corporation | LINE client for Android | — | A code injection vulnerability exists in the LINE Android app prior to versio… |
| CVE-2026-70492 | 8.7 | 18.0 | open-webui | open-webui | CWE-79 | Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered … |
| CVE-2026-70479 | 7.7 | 17.8 | open-webui | open-webui | CWE-918 | Open WebUI: SSRF into internal services via unvalidated sub-resource requests… |
| CVE-2026-69252 | 7.2 | 17.9 | FlowiseAI | Flowise | CWE-862 | Flowise: Missing authorization on `/api/v1/files` allows low-privileged API k… |
| CVE-2026-70491 | 6.5 | 17.9 | open-webui | open-webui | CWE-200 | Open WebUI: Tool source code disclosed to read-only users via the tool list a… |
| CVE-2026-70588 | 5.0 | 17.6 | TryGhost | Ghost | CWE-79 | Ghost: Cross-Site Scripting in Universal Import |
| CVE-2026-14838 | 7.4 | 17.6 | Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | CWE-598 | Session Token Exposure in URL Leading to Account Takeover in Bilin Software's… |
| CVE-2026-16548 | 6.5 | 17.3 | Unknown | Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat | CWE-434 | Bit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response Endpoint |
| CVE-2026-47620 | 6.5 | 17.1 | NVIDIA | Dynamo | CWE-362 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could caus… |
| CVE-2026-47621 | 6.5 | 17.1 | NVIDIA | Dynamo | CWE-367 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could caus… |
| CVE-2026-14816 | 6.5 | 16.6 | Unknown | The GDPR Framework By Data443 | CWE-284 | The GDPR Framework < 2.4.0 - Unauthenticated Consent Record Forgery and Do No… |
| CVE-2026-70487 | 5.3 | 16.7 | open-webui | open-webui | CWE-862 | Open WebUI: Cross-user file content disclosure via request-scoped direct mode… |
| CVE-2026-18721 | 2.1 | 16.6 | kalcaddle | kodbox | CWE-601 | kalcaddle kodbox SSO API Login apiLogin redirect |
| CVE-2026-48154 | 5.9 | 16.2 | pilinux | gorest | CWE-362 | GoRest: InMemorySecret2FA race condition allows process crash via concurrent … |
| CVE-2026-14337 | 4.6 | 16.2 | Pegasystems | Pega Infinity | CWE-79 | Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-… |
| CVE-2026-70473 | 8.3 | 16.1 | FlowiseAI | Flowise | CWE-200 | Flowise: Information Disclosure in GET /api/v1/upsert-history returns the ent… |
| CVE-2026-69257 | 7.6 | 16.1 | FlowiseAI | Flowise | CWE-918 | Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses |
| CVE-2026-13227 | 7.1 | 16.1 | Frappe | ERPNext | CWE-862 | ERPNext v16.25.0 - Improper authorization in Prospect opportunities API |
| CVE-2026-13229 | 7.1 | 16.1 | Zammad | Zammad | CWE-862 | Zammad 7.0.1 - Improper authorization in ticket article attachment cloning |
| CVE-2026-69262 | 7.1 | 16.1 | FlowiseAI | Flowise | CWE-863 | Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allo… |
| CVE-2026-70472 | 7.1 | 16.1 | FlowiseAI | Flowise | CWE-285 | Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store |
| CVE-2026-16547 | 5.9 | 16.1 | Unknown | REST API Log | CWE-284 | REST API Log < 1.7.1 - Unauthenticated Sensitive Log Data Disclosure via Down… |
| CVE-2026-70483 | 3.1 | 15.9 | open-webui | open-webui | CWE-862 | Open WebUI: Any authenticated user can cancel another user's chat generation … |
| CVE-2026-65986 | 8.5 | 15.2 | cvat-ai | cvat | CWE-79 | CVAT has stored XSS via annotation guide assets |
| CVE-2026-16623 | 8.0 | 15.0 | Unknown | Create Block Theme | CWE-94 | Create Block Theme < 2.10.0 - Admin+ PHP Code Injection via Pattern Save (Mul… |
| CVE-2026-64630 | 5.3 | 14.8 | Veeam | ONE | CWE-863 | A vulnerability allowing a low-privileged user to retrieve report data outsid… |
| CVE-2026-14939 | 6.8 | 14.6 | Unknown | Visualizer | CWE-918 | Visualizer: Tables and Charts Manager < 4.0.6 - Contributor+ Server-Side Requ… |
| CVE-2026-16069 | 6.8 | 14.7 | Unknown | Brizy | CWE-79 | Brizy - Page Builder < 2.8.19 - Contributor+ Stored XSS via Featured Image Fo… |
| CVE-2026-16293 | 6.8 | 14.7 | Unknown | PowerPress Podcasting plugin by Blubrry | CWE-79 | Blubrry PowerPress < 11.16.11 - Contributor+ Stored XSS via Podcast Episode C… |
| CVE-2026-18650 | 8.8 | 14.3 | HAVELSAN Inc. | Liman MYS | CWE-862 | Missing Authorization Leading to Root Code Execution in HAVELSAN's Liman MYS |
| CVE-2026-15721 | 9.8 | 14.2 | Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | CWE-312 | Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Sof… |
| CVE-2026-14872 | 6.8 | 14.1 | Unknown | Database for Contact Form 7, WPforms, Elementor forms | CWE-89 | Database for Contact Form 7, WPforms, Elementor forms < 1.5.5 - Authenticated… |
| CVE-2026-48121 | 6.7 | 14.0 | langchain-ai | langgraphjs | CWE-943 | @langchain/langgraph-checkpoint-mongodb: NoSQL parameter injection in MongoDB… |
| CVE-2026-18801 | 9.3 | 13.8 | openmeter | openmeter | CWE-20 | Stored Clickhouse SQL Injection Through Customer Usage Attribution |
| CVE-2026-10526 | 5.8 | 13.8 | Unknown | EmbedPress | CWE-918 | EmbedPress < 4.6.1 - Unauthenticated Blind SSRF |
| CVE-2026-70591 | 4.1 | 13.5 | TryGhost | Ghost | CWE-918 | Ghost: Server-Side Request Forgery in Image Fetching |
| CVE-2026-58073 | 9.5 | 13.3 | Veeam | Service Provider Console | CWE-288 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated… |
| CVE-2026-70485 | 7.1 | 13.1 | open-webui | open-webui | CWE-918 | Open WebUI: Any authenticated user can reach internal services and cloud meta… |
| CVE-2026-51144 | 6.1 | 12.0 | n/a | n/a | CWE-79 | Cross Site Scripting vulnerability in Soliton Systems MailZen Management Prot… |
| CVE-2026-66884 | 2.1 | 12.0 | Erlang Ecosystem Foundation | oidcc_plug | CWE-352 | Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session … |
| CVE-2026-54020 | 6.3 | 11.9 | open-webui | open-webui | CWE-367 | Open WebUI: DNS Rebinding SSRF Bypass |
| CVE-2026-70488 | 4.3 | 11.9 | open-webui | open-webui | CWE-639 | Open WebUI: Deletion of directories and file embeddings in other knowledge ba… |
| CVE-2026-18809 | 6.5 | 11.6 | Mozilla | Firefox | CWE-200 | Information disclosure in Firefox for Android and Firefox Focus for Android |
| CVE-2026-18818 | 5.3 | 11.7 | Ehco1996 | django-sspanel | CWE-285 | Ehco1996 django-sspanel Support Ticket views.py TicketDetailView authorization |
| CVE-2026-18722 | 2.1 | 11.7 | diaowen | DWSurvey | CWE-285 | diaowen DWSurvey dev-survey.do in DwDeisgnSurveyController.devSurvey. authori… |
| CVE-2026-70490 | 6.3 | 11.1 | open-webui | open-webui | CWE-863 | Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket au… |
| CVE-2026-15958 | 9.3 | 10.7 | Unknown | Easy Integration for Dropbox | CWE-862 | Easy Dropbox Integration < 2.2.0 - Unauthenticated Arbitrary Connected Dropbo… |
| CVE-2026-18723 | 2.1 | 10.4 | diaowen | DWSurvey | CWE-266 | diaowen DWSurvey Survey Status up-survey-status.do improper authorization |
| CVE-2026-18773 | 2.1 | 10.4 | NousResearch | hermes-agent | CWE-285 | NousResearch hermes-agent Quick run.py _check_slash_access authorization |
| CVE-2026-18774 | 2.1 | 10.4 | NousResearch | hermes-agent | CWE-918 | NousResearch hermes-agent xAI Image Generation Provider image_gen_provider.py… |
| CVE-2026-67198 | 8.7 | 10.2 | perspective-dev | perspective | CWE-616 | Perspective 5.0.0 DoS via VirtualServer Protocol Dispatcher |
| CVE-2026-67618 | 7.1 | 10.0 | marimo-team | marimo | CWE-345 | marimo < 0.23.15 API Key Exfiltration via Malicious Notebook PEP-723 Metadata |
| CVE-2026-58045 | 6.2 | 10.0 | nodejs | node | CWE-400 | A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a rea… |
| CVE-2026-10032 | 6.1 | 9.7 | @a2ui/web_core | CWE-79 | Arbitrary JavaScript Execution via openUrl in @a2ui/web_core | |
| CVE-2026-14202 | 5.3 | 9.8 | Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | CWE-204 | Username Enumeration via Differential Login Responses in Bilin Software's HUM… |
| CVE-2026-70590 | 4.8 | 9.5 | TryGhost | Ghost | CWE-200 | Ghost: Blind Password Hash Disclosure in Ghost Admin API |
| CVE-2026-16035 | 4.3 | 9.5 | Unknown | miniOrange 2FA | CWE-862 | miniOrange 2FA < 6.2.7 - Subscriber+ Arbitrary-Recipient OTP Send |
| CVE-2026-16536 | 5.3 | 9.3 | Unknown | Simple Google Calendar Outlook Events Widget | CWE-918 | Simple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF v… |
| CVE-2026-70480 | 4.1 | 9.2 | open-webui | open-webui | CWE-918 | Open WebUI: Client-side SSRF via unrestricted external resource loading in Ve… |
| CVE-2026-11366 | 3.7 | 9.2 | Unknown | MonsterInsights | CWE-287 | MonsterInsights < 11.1.0 - Unauthenticated Measurement Protocol Secret Update… |
| CVE-2026-18719 | 2.1 | 9.2 | cemtan | sar2html | CWE-74 | cemtan sar2html Search sar2html.py sql injection |
| CVE-2026-18766 | 2.1 | 9.2 | chetans9 | core-php-admin-panel | CWE-74 | chetans9 core-php-admin-panel customers.php sql injection |
| CVE-2026-52370 | 6.1 | 8.8 | n/a | n/a | CWE-79 | A reflected cross-site scripting (XSS) vulnerability in the Forum posting fun… |
| CVE-2026-11368 | 6.5 | 8.3 | zephyrproject | zephyr | CWE-416 | Use-after-free in Bluetooth host ATT TX completion on disconnect mid-transfer |
| CVE-2026-12698 | 4.3 | 8.4 | Unknown | wpForo Forum | CWE-284 | wpForo Forum < 3.1.3 - Subscriber+ Account Status and Reputation Manipulation… |
| CVE-2026-47487 | 7.1 | 8.2 | NVIDIA | Triton Inference Server | CWE-22 | NVIDIA Triton Inference Server for Linux contains a vulnerability where a use… |
| CVE-2026-66300 | 2.3 | 8.0 | SNOMED International | Snowstorm | CWE-79 | SNOMED International Snowstorm reflected XSS |
| CVE-2026-14192 | 5.4 | 7.2 | Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | CWE-79 | Stored XSS in Bilin Software's HUMANIST Digital Human Resources |
| CVE-2026-14824 | 4.8 | 7.1 | Unknown | Quiz and Survey Master (QSM) | CWE-79 | Quiz And Survey Master < 11.2.2 - Contributor+ Stored XSS via Polar Question |
| CVE-2026-64565 | await | 7.0 | Linux | Linux | — | Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() |
| CVE-2026-70589 | 4.8 | 6.9 | TryGhost | Ghost | CWE-20 | Ghost: Archived Offers can be Redeemed |
| CVE-2026-16296 | 4.7 | 6.8 | Unknown | Clearfy Cache | CWE-601 | Clearfy < 2.4.3 - Open Redirect via Cyrlitera 404 Handler |
| CVE-2026-14848 | 5.4 | 6.7 | Unknown | Paid Membership Subscriptions | CWE-284 | Paid Member Subscriptions < 3.0.8 - Subscriber+ Cross-User Subscription Hijac… |
| CVE-2026-16070 | 2.7 | 6.6 | Unknown | Brizy | CWE-639 | Brizy - Page Builder < 2.8.19 - Contributor+ Template Type Update via IDOR |
| CVE-2026-18853 | 1.9 | 6.4 | ZomboDroid | Meme Generator App | CWE-22 | ZomboDroid Meme Generator App com.zombodroid.MemeGenerator t5.l.c path traversal |
| CVE-2026-16056 | 4.3 | 5.8 | Unknown | Contest Gallery | CWE-862 | Contest Gallery < 30.0.7 - Subscriber+ OpenAI Prompt History Disclosure via p… |
| CVE-2026-16295 | 4.3 | 5.8 | Unknown | Clearfy Cache | CWE-284 | Clearfy < 2.4.3 - Subscriber+ Sensitive Information Disclosure via Factory Pa… |
| CVE-2026-70594 | 6.7 | 5.7 | TryGhost | Ghost | CWE-384 | Ghost: Session Fixation in Ghost Admin |
| CVE-2026-14219 | 5.4 | 5.7 | Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | CWE-601 | URL Redirection in Bilin Software's HUMANIST Digital Human Resources |
| CVE-2026-18569 | 3.7 | 5.7 | Red Hat | Red Hat Build of Keycloak | CWE-347 | Keycloak-services: keycloak-services: oidc backchannel logout accepts unsigne… |
| CVE-2026-18656 | 8.5 | 5.6 | Amazon | Kiro IDE | CWE-427 | Executable Resolution from Untrusted Project Directory in Kiro IDE on Windows |
| CVE-2026-18657 | 8.5 | 5.6 | Amazon | Kiro CLI | CWE-427 | Executable Resolution from Untrusted Project Directory in Kiro CLI on Windows |
| CVE-2026-18819 | 2.1 | 5.5 | n/a | RackTables | CWE-352 | RackTables cross-site request forgery |
| CVE-2026-63248 | 6.9 | 5.2 | Eclipse Foundation | Eclipse Milo | CWE-862 | In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes… |
| CVE-2026-70367 | 5.4 | 5.2 | Mobi-Com Polska Sp. z o.o. | stunnel | CWE-918 | Stunnel: ssrf bypass in stunnel socks proxy via ipv4-mapped ipv6 loopback and… |
| CVE-2026-16546 | 4.3 | 4.9 | Unknown | Wired Impact Volunteer Management | CWE-862 | Wired Impact Volunteer Management < 2.8.2 - Subscriber+ Arbitrary RSVP Remova… |
| CVE-2026-47763 | 6.8 | 4.8 | pdm-project | pdm | CWE-61 | pdm: Project-Local State and Config Writes Follow Symlinks |
| CVE-2026-67196 | 5.1 | 4.7 | perspective-dev | perspective | CWE-79 | Perspective 5.0.0 XSS via Debug Plugin innerHTML Interpolation |
| CVE-2026-47764 | 8.4 | 4.5 | pdm-project | pdm | CWE-22 | pdm: Path traversal in wheel installation via overridden write_to_fs |
| CVE-2026-24084 | 7.5 | 4.5 | Qualcomm, Inc. | Snapdragon | CWE-1294 | Insecure Security Identifier Mechanism in Multi-Mode Call Processor |
| CVE-2026-10709 | 7.8 | 4.3 | Autodesk | FBX SDK | CWE-121 | FBX BinaryReadSectionHeader Stack-Based Buffer Overflow Vulnerability in Auto… |
| CVE-2026-10710 | 7.8 | 4.3 | Autodesk | FBX SDK | CWE-121 | FBX ExtractDrive Stack-Based Buffer Overflow Vulnerability in Autodesk FBX SDK |
| CVE-2026-15233 | 4.8 | 4.0 | Unknown | Nested Pages | CWE-79 | Nested Pages < 3.2.15 - Editor+ Stored XSS via Post Title |
| CVE-2026-16068 | 3.5 | 4.0 | Unknown | Brizy | CWE-79 | Brizy - Page Builder < 2.8.19 - Author+ Stored XSS via brizy_set_project Glob… |
| CVE-2026-51401 | 7.7 | 3.7 | n/a | n/a | CWE-94 | An issue in Vim Project v9.2.0389 and earlier allows a local attacker to exec… |
| CVE-2026-42169 | 7.3 | 3.3 | Red Hat | Red Hat Enterprise Linux 9 | CWE-131 | Gimp: gimp apng loader heap-buffer-overflow when fctl width exceeds ihdr widt… |
| CVE-2026-68743 | 7.1 | 3.3 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length … |
| CVE-2026-47781 | 8.4 | 3.2 | pdm-project | pdm | CWE-94 | pdm: Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing |
| CVE-2026-18755 | 7.3 | 2.9 | GeoVision Inc. | GV-ASManager | CWE-428 | GV-ASManager DLL hijacking vulnerability |
| CVE-2026-24079 | 8.1 | 2.8 | Qualcomm, Inc. | Snapdragon | CWE-306 | Missing Authentication for Critical Function in Data Modem |
| CVE-2026-51400 | 8.4 | 2.5 | n/a | n/a | CWE-401 | An issue in Vim Project v9.2.0389 and earlier allows a local attacker to exec… |
| CVE-2026-18784 | 1.9 | 2.5 | o6 | open62541 | CWE-119 | o6 open62541 ua_client_highlevel.c UA_Client_readNodeClassAttribute heap-base… |
| CVE-2026-64561 | 8.8 | 2.2 | Linux | Linux | — | KVM: x86: Check for invalid/obsolete root *after* making MMU pages available |
| CVE-2026-64562 | 8.8 | 2.2 | Linux | Linux | — | KVM: nVMX: Hide shadow VMCS right after VMCLEAR |
| CVE-2026-18790 | 1.9 | 2.2 | Systerel | S2OPC | CWE-119 | Systerel S2OPC DeleteMonitoredItemsRequest state_machine.c out-of-bounds |
| CVE-2026-64563 | 7.8 | 1.9 | Linux | Linux | — | rhashtable: clear stale iter->p on table restart |
| CVE-2026-25289 | 9.6 | 1.9 | Qualcomm, Inc. | Snapdragon | CWE-121 | Stack-based Buffer Overflow in WLAN Firmware |
| CVE-2026-18759 | 8.5 | 1.8 | ASUSTOR Inc. | ABP | CWE-269 | An improper authentication and path traversal vulnerability exists in ASUSTOR… |
| CVE-2026-64634 | 8.4 | 1.8 | Veeam | ONE | CWE-269 | A vulnerability allowing local privilege escalation to the Reporter service c… |
| CVE-2026-18785 | 1.9 | 1.6 | o6 | open62541 | CWE-119 | o6 open62541 client_types_custom.c UA_Client_getRemoteDataTypes use after free |
| CVE-2026-18852 | 1.9 | 1.6 | epsilla-cloud | vectordb | CWE-754 | epsilla-cloud vectordb Filter expr.cpp ShuntingYard unusual condition |
| CVE-2026-24077 | 6.5 | 1.2 | Qualcomm, Inc. | Snapdragon | CWE-191 | Integer Underflow (Wrap or Wraparound) in WLAN Host |
| CVE-2026-24078 | 6.5 | 1.2 | Qualcomm, Inc. | Snapdragon | CWE-359 | Exposure of Private Personal Information to an Unauthorized Actor in Data Modem |
| CVE-2026-25292 | 7.6 | 1.1 | Qualcomm, Inc. | Snapdragon | CWE-1286 | Improper Validation of Syntactic Correctness of Input in Automotive Linux OS |
| CVE-2026-18806 | 7.1 | 1.0 | TÜBİTAK BİLGEM Software Technologies Research Institute | pardus-image-writer | CWE-73 | Arbitrary Block Device Write via Missing Validation in TÜBİTAK BİLGEM's pardu… |
| CVE-2026-25288 | 7.4 | 1.0 | Qualcomm, Inc. | Snapdragon | CWE-126 | Buffer Over-read in WLAN Firmware |
| CVE-2026-68744 | 3.3 | 0.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-908 | Sssd: sssd: nss responder uninitialized heap disclosure in initgroups reply |
| CVE-2026-18739 | 2.5 | 0.7 | rpm-software-management | popt | CWE-787 | Popt-devel: popt-static: off-by-one in poptstuffargs |
| CVE-2026-16791 | 1.0 | 0.4 | Lenovo | XClarity Essentials OneCLI | CWE-377 | Predictable Temporary File Symlink Vulnerability in Lenovo XClarity Essential… |
| CVE-2026-11835 | 5.6 | 0.3 | Caliptra | Core ROM | CWE-20 | Caliptra Update-Reset Secure-Boot Bypass via Attacker-Chosen AXI Staging Addr… |
| CVE-2026-11836 | 1.8 | 0.2 | Caliptra | Core ROM | CWE-345 | Production Debug-Unlock Token Verification Missing Device Binding |
| CVE-2026-16792 | 7.0 | 0.1 | Lenovo | XClarity Orchestrator | CWE-295 | Global TLS Certificate Validation Bypass in Lenovo XClarity Orchestrator |
| CVE-2026-24076 | 6.7 | 0.1 | Qualcomm, Inc. | Snapdragon | CWE-120 | Buffer Copy Without Checking Size of Input in Bluetooth HOST |
| CVE-2026-21366 | 7.8 | 0.0 | Qualcomm, Inc. | Snapdragon | CWE-190 | Integer Overflow or Wraparound in Data Network Stack & Connectivity |
| CVE-2026-24080 | 7.8 | 0.0 | Qualcomm, Inc. | Snapdragon | CWE-120 | Buffer Copy Without Checking Size of Input in Biometrics |
| CVE-2026-24083 | 7.8 | 0.0 | Qualcomm, Inc. | Snapdragon | CWE-822 | Untrusted Pointer Dereference in Automotive Security |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-08-04 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.