boxscore/security
Tuesday, August 4, 2026 · all times UTC← 2026-08-03 · archive · 2026-08-05 →

273 CVEs published August 4, 2026: 45 critical, 119 high, 81 medium, 27 low; 2 in KEV; 3 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 248 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published779958413912563
KEV catalog size1670

447 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux5159020811309802730.27.8.0016-7
microsoft1613771069363108378322.37.8.0039-34
google241465104227157351.26.5.0022+2
apple0244566711229372.97.1.00270
red hat19241911210515400.07.0.0025+13
canonical030210000.07.8.00130
android010100161100.08.4.01710
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco0204620961365.08.2.18530
fortinet018249028633.36.1.00540
palo alto networks015017514213.34.7.00280
vmware01247012100.08.7.00440
checkpoint1541003240.09.3.2062+1
f50540007120.09.2.04020
ivanti051000335100.010.0.81520
zyxel3403101100.07.2.0075+3
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache614324784014021.47.5.0051+6
mozilla1734226501300.09.1.0031+1
gitlab015021014213.34.9.00290
docker030120100.05.7.00150
wordpress0311105266.78.6.73100
github020110000.06.1.00290
drupal01100051100.09.8.88320
kubernetes010001000.02.4.00240
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle01113212539304574030.37.6.00310
ibm01083143340710.97.5.00260
adobe7471623407548.58.6.0047+7
progress02331550900.08.1.00320
solarwinds0201611011420.09.1.00500
veeam10123720400.08.6.0027+10
atlassian0303001300.08.0.00260
zohocorp031110000.07.1.00480
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link08006126112.55.5.00730
hikvision0704202114.37.2.00250
bosch030300000.08.1.00280
schneider electric031200100.08.7.00200
synology110100000.07.3.0013+1
honeywell010010000.06.9.00310
mitsubishi electric010100000.07.1.00130
rockwell automation011000000.09.2.00300
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
surrealdb057326253000.07.1.00250
grafana041214223000.06.5.00330
netty04162771000.07.5.00460
legion of the bouncy castle323952590000.08.7.0026+32
open ises037214210000.06.9.00210
mediatek343404300100.06.0.0011+34
erlang032114143100.06.9.0033-6
freerdp233181841000.08.7.0034+23

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-48282.992499.9
CVE-2026-63030.956099.99.8
CVE-2026-39808.912199.8
CVE-2026-48908.881399.810.0
CVE-2026-56290.832599.710.0
CVE-2026-34486.829399.67.5
CVE-2026-48939.825099.610.0
CVE-2026-50522.769899.59.8
CVE-2026-15410.763599.57.2
CVE-2026-56291.760799.510.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4890810.0.8813KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-1540910.0.7422KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0473
CVE-2026-4766810.0.0434
CVE-2026-4435910.0.0100
CVE-2025-7138910.0.0093
Most disclosures (vendor)
VendorCVEs
oracle1109
linux660
microsoft624
google405
apple167
red hat136
apache111
ibm100
mozilla68
surrealdb57
Most KEV additions (YTD)
VendorKEV
microsoft32
cisco13
apple7
fortinet6
google5
ivanti5
adobe4
langflow4
solarwinds4
synacor4
Most-affected ecosystems
EcosystemAdvisories
Maven31
PyPI5
Go3
crates.io2
npm2
NuGet1
Packagist1
Fastest to KEV
CVEVendorDays
CVE-2008-4128Cisco0
CVE-2021-27137DD-WRT0
CVE-2023-4346KNX Association0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-18556N-able0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171721
CVE-2021-27102Accellion2021-11-171721
CVE-2021-27101Accellion2021-11-171721
CVE-2021-27103Accellion2021-11-171721
CVE-2021-21017Adobe2021-11-171721
CVE-2021-28550Adobe2021-11-171721
CVE-2021-42013Apache2021-11-171721
CVE-2021-41773Apache2021-11-171721
CVE-2021-30858Apple2021-11-171721
CVE-2021-30860Apple2021-11-171721

Transactions

EXPLOIT PUBLISHEDCVE-2021-44529 (Ivanti EPM). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2021-47102 (Linux). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2021-47103 (Linux). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2021-47107 (Linux). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2022-27925. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2022-30333. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2022-37042. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2022-48629 (Linux). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2023-46805 (Ivanti ICS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2023-4853 (Red Hat Openshift Serverless 1 on RHEL 8). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2023-52927 (Linux). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2024-0012 (Palo Alto Networks Cloud NGFW). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2024-21887 (Ivanti ICS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2024-24919 (checkpoint Check Point Quantum Gateway, Spark Gateway and CloudGuard Network). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2024-51567. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-15672 (Unknown ChamaWP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-15673 (Unknown Import and export users and customers). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-37947 (Linux). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-53770 (Microsoft SharePoint Enterprise Server 2016). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-57631. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10050 (Eclipse Foundation Eclipse Jetty - EE8). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10827 (Unknown Spectra Legacy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-11368 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-11872 (Unknown Clever Mega Menu for Visual Composer). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-11882 (Unknown Builderall for WordPress). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-12872 (Unknown Webinfos). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-13157 (Unknown Theme Demo Import). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-13158 (Unknown Everest Toolkit). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-13604 (Unknown Pixelavo). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-13725 (Unknown Dynamic Pricing With Discount Rules for WooCommerce). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-13729 (Unknown Podlove Podcast Publisher). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-14195 (Unknown Brizy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-14197 (Unknown Fluent Support). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-14214 (Unknown Booking for Appointments and Events Calendar). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-14309 (Unknown Chat On Desk Order Notifications). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-14557 (Unknown SoftMarket — Digital Marketplace). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-14596 (Unknown DynamicKit for Elementor). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-14822 (Unknown Event Tickets and Registration). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-14823 (Unknown Event Tickets and Registration). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-14836 (Unknown Login & Register Forms). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-14840 (Unknown YOP Poll). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-14938 (Unknown FluentBoards). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-15231 (Unknown Tag, Category, and Taxonomy Manager). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-15244 (Unknown HUSKY). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-15248 (Unknown Meta Box). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-15368 (Unknown User Profile Builder). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-15932 (Unknown Support Genix). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-15939 (Unknown Simple Restrict). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16057 (Unknown Contest Gallery). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16060 (Unknown Insert or Embed Articulate Content into WordPress). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16250 (Unknown Personal QR Message). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16256 (Unknown POUCO Import Users). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16274 (Unknown Classified Listing). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16276 (Unknown Classified Listing). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18616 (GL-iNet GL-MT3000). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18631 (jeequan jeepay). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18641 (Sangfor Operation and Maintenance Security Management System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18645 (danpros HTMLy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18646 (danpros HTMLy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18647 (jina-ai reader). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18648 (Blix Email Blue Mail Calendar App). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18682 (OpenAkita). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18684 (GL.iNet GL-MT3000). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-32141 (WebReflection flatted). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-33228 (WebReflection flatted). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-33870 (netty). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-39363 (vitejs vite). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-39364 (vitejs vite). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-46331 (Linux). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-53264 (Linux). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-56722 (dompdf). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59941 (dompdf). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59942 (dompdf). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59943 (dompdf). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-67599 (ClearFoundation ClearOS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-67617 (microweber). Public exploit reference added.

RESCOREDCVE-2019-25160 (Linux). CVSS 9.1 → 7.1 (NVD).

RESCOREDCVE-2020-36787 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2020-36791 (Linux). CVSS 7.8 → 7.1 (NVD).

RESCOREDCVE-2021-4454 (Linux). CVSS 7.5 → 5.5 (NVD).

RESCOREDCVE-2021-46908 (Linux). CVSS 7.1 → 5.5 (NVD).

RESCOREDCVE-2021-46910 (Linux). CVSS 7 → 5.5 (NVD).

RESCOREDCVE-2021-46911 (Linux). CVSS 9.8 → 5.5 (NVD).

RESCOREDCVE-2021-46912 (Linux). CVSS 7.3 → 5.5 (NVD).

RESCOREDCVE-2021-46913 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2021-46921 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2021-46922 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2021-46925 (Linux). CVSS 7.8 → 4.7 (NVD).

RESCOREDCVE-2021-46929 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2021-46933 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2021-46948 (Linux). CVSS 7.5 → 5.5 (NVD).

RESCOREDCVE-2021-46955 (Linux). CVSS 8.2 → 7.1 (NVD).

RESCOREDCVE-2021-46958 (Linux). CVSS 7.8 → 4.7 (NVD).

RESCOREDCVE-2021-46960 (Linux). CVSS 7.5 → 5.5 (NVD).

RESCOREDCVE-2021-46963 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2021-46967 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2021-46974 (Linux). CVSS 7.1 → 5.5 (NVD).

RESCOREDCVE-2021-46977 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2021-46983 (Linux). CVSS 7.5 → 5.5 (NVD).

RESCOREDCVE-2021-46992 (Linux). CVSS 7.8 → 7.1 (NVD).

RESCOREDCVE-2021-46993 (Linux). CVSS 7.8 → 7.1 (NVD).

RESCOREDCVE-2021-46999 (Linux). CVSS 9.8 → 7.8 (NVD).

RESCOREDCVE-2021-47001 (Linux). CVSS 7.5 → 4.7 (NVD).

RESCOREDCVE-2021-47011 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2021-47013 (Linux). CVSS 9.8 → 7.8 (NVD).

RESCOREDCVE-2021-47017 (Linux). CVSS 8.8 → 7.8 (NVD).

RESCOREDCVE-2021-47028 (Linux). CVSS 7.1 → 7.8 (NVD).

RESCOREDCVE-2021-47035 (Linux). CVSS 8.8 → 5.5 (NVD).

RESCOREDCVE-2021-47036 (Linux). CVSS 9.8 → 5.5 (NVD).

RESCOREDCVE-2021-47041 (Linux). CVSS 7.5 → 5.5 (NVD).

RESCOREDCVE-2021-47049 (Linux). CVSS 8.4 → 7.8 (NVD).

RESCOREDCVE-2021-47055 (Linux). CVSS 7.1 → 5.5 (NVD).

RESCOREDCVE-2021-47066 (Linux). CVSS 7.1 → 5.5 (NVD).

RESCOREDCVE-2021-47069 (Linux). CVSS 7.8 → 7 (NVD).

RESCOREDCVE-2021-47103 (Linux). CVSS 9.8 → 7.8 (NVD).

RESCOREDCVE-2021-47107 (Linux). CVSS 9.8 → 7.8 (NVD).

RESCOREDCVE-2021-47109 (Linux). CVSS 7.5 → 5.5 (NVD).

RESCOREDCVE-2021-47111 (Linux). CVSS 8.8 → 7.8 (NVD).

RESCOREDCVE-2021-47112 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2021-47113 (Linux). CVSS 7.1 → 5.5 (NVD).

RESCOREDCVE-2021-47124 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2021-47131 (Linux). CVSS 8.1 → 7.8 (NVD).

RESCOREDCVE-2021-47132 (Linux). CVSS 7.5 → 7.1 (NVD).

RESCOREDCVE-2021-47136 (Linux). CVSS 8.6 → 5.5 (NVD).

RESCOREDCVE-2021-47142 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2021-47152 (Linux). CVSS 7.8 → 5.5 (NVD).

PATCH SHIPPEDCVE-2023-35078 (Ivanti Endpoint Manager Mobile). Fixed in Endpoint Manager Mobile 11.10.

PATCH SHIPPEDCVE-2026-31431 (Linux). Fixed in Linux 5.10.254.

+ 1346 more transactions — continued on page 2 (of 3). Every change is listed; nothing truncated.

Yesterday's Results

273 CVEs published. 25 box scores, 248 table rows — nothing truncated.

Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .8293   99.6   YES
AFFECTED
  Product        Versions   Fixed
  Apache Tomcat  11.0.20 –  —
TIMELINE
  Mar 30  Reserved by CNA
  Aug 4   Added to CISA KEV, due Aug 7
  Aug 4   Published (CNA: apache)
CWE-311, CWE-807 · CNA: apache · 21 references · NVD status: Analyzed · KEV due August 7, 2026
N-able N-central — Unauthenticated administrative account takeover
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   H   N   N    8.2   .0049   40.1   YES
AFFECTED
  Product    Versions     Fixed
  N-central  unspecified  —
TIMELINE
  Aug 1   Reserved by CNA
  Aug 4   Added to CISA KEV, due Aug 7
  Aug 4   Published (CNA: N-able)
CWE-288 · CNA: N-able · 3 references · NVD status: Analyzed · KEV due August 7, 2026
H3C NX15 esps reload.reload_config command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    7.3   .0271   84.7     —
AFFECTED
  Product  Versions    Fixed
  NX15     V100R017 –  —
TIMELINE
  Aug 4   Reserved by CNA
  Aug 4   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 5 references · NVD status: Deferred
GL.iNet GL-MT3000 nas-web RPC Wrapper glc nas-web.add_user command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0261   84.1     —
AFFECTED
  Product    Versions  Fixed
  GL-MT3000  4.4.0 –   —
TIMELINE
  Aug 3   Reserved by CNA
  Aug 4   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 5 references · NVD status: Deferred
H3C NX15 esps add command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    7.3   .0226   81.5     —
AFFECTED
  Product  Versions    Fixed
  NX15     V100R017 –  —
TIMELINE
  Aug 4   Reserved by CNA
  Aug 4   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 5 references · NVD status: Deferred
H3C NX15 esps esps.ipv6.wan command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    7.3   .0226   81.5     —
AFFECTED
  Product  Versions    Fixed
  NX15     V100R017 –  —
TIMELINE
  Aug 4   Reserved by CNA
  Aug 4   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 5 references · NVD status: Deferred
H3C NX15 esps delete command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    7.3   .0226   81.5     —
AFFECTED
  Product  Versions    Fixed
  NX15     V100R017 –  —
TIMELINE
  Aug 4   Reserved by CNA
  Aug 4   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 5 references · NVD status: Deferred
n/a n/a — H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0224   81.4     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Mar 11  Reserved by CNA
  Aug 4   Published (CNA: mitre)
CWE-77 · CNA: mitre · 2 references · NVD status: Received
GL.iNet AX1800 RPC Endpoint oui-rpc.lua remove_rule command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0165   74.5     —
AFFECTED
  Product  Versions  Fixed
  AX1800   4.8.0 –   —
TIMELINE
  Aug 4   Reserved by CNA
  Aug 4   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 5 references · NVD status: Deferred
Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0158   73.4     —
AFFECTED
  Product    Versions  Fixed
  IP Camera  2.x –     —
TIMELINE
  Jul 10  Reserved by CNA
  Aug 4   Published (CNA: VulnCheck)
CWE-912 · CNA: VulnCheck · 3 references · NVD status: Received
perspective-dev perspective — Perspective 5.0.0 RCE via eval() Expression Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0116   64.4     —
AFFECTED
  Product      Versions     Fixed
  perspective  unspecified  —
TIMELINE
  Jul 28  Reserved by CNA
  Aug 4   Published (CNA: VulnCheck)
CWE-95 · CNA: VulnCheck · 2 references · NVD status: Received
Zyxel WAX650S firmware — A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firm…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0095   58.3     —
AFFECTED
  Product           Versions             Fixed
  WAX650S firmware  <= 7.10(ABRM.4)C0 –  —
TIMELINE
  Apr 22  Reserved by CNA
  Aug 4   Published (CNA: Zyxel)
CWE-78 · CNA: Zyxel · 1 reference · NVD status: Awaiting Analysis
MaxSite CMS Unauthenticated RCE via Install Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0088   56.1     —
AFFECTED
  Product      Versions  Fixed
  MaxSite CMS  105.2 –   109.6
TIMELINE
  Aug 4   Reserved by CNA
  Aug 4   Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · 3 references · NVD status: Received
MaxSite CMS Unauthenticated PHP Object Injection via maxsite_comuser Cookie
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0085   55.2     —
AFFECTED
  Product      Versions  Fixed
  MaxSite CMS  0.78 –    109.6
TIMELINE
  Aug 4   Reserved by CNA
  Aug 4   Published (CNA: VulnCheck)
CWE-502 · CNA: VulnCheck · 3 references · NVD status: Received
Red Hat Red Hat JBoss Enterprise Application Platform 7 — Wildfly-core: path traversal on wildfly domain controller
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  H  N  N    4.4   .0085   55.1     —
AFFECTED
  Product                                                       Versions     Fixed
  Red Hat JBoss Enterprise Application Platform 7               unspecified  —
  Red Hat JBoss Enterprise Application Platform 7               unspecified  —
  Red Hat JBoss Enterprise Application Platform 7               unspecified  —
  Red Hat JBoss Enterprise Application Platform 7               unspecified  —
  Red Hat JBoss Enterprise Application Platform 7               unspecified  —
  Red Hat JBoss Enterprise Application Platform 7               unspecified  —
  Red Hat JBoss Enterprise Application Platform 8               unspecified  —
  Red Hat JBoss Enterprise Application Platform Expansion Pack  unspecified  —
  Red Hat Single Sign-On 7                                      unspecified  —
TIMELINE
  Jul 27  Reserved by CNA
  Aug 4   Published (CNA: redhat)
CWE-22 · CNA: redhat · 2 references · NVD status: Awaiting Analysis
FlowiseAI Flowise — Flowise RCE via TypeORM DataSource
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   H   H   H    9.0   .0079   53.3     —
AFFECTED
  Product             Versions   Fixed
  Flowise             < 3.1.3 –  —
  flowise-components  < 3.1.3 –  —
TIMELINE
  Aug 3   Reserved by CNA
  Aug 4   Published (CNA: GitHub_M)
CWE-94 · CNA: GitHub_M · 1 reference · NVD status: Received
Keysight IxChariot-related products stack-based buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0077   52.7     —
AFFECTED
  Product    Versions     Fixed
  Hawkeye    unspecified  6.0.7
  IxChariot  unspecified  10.0.254
  IxTap      unspecified  3.13.0
  IxProbe    unspecified  3.13.0
  IxByPass   unspecified  3.13.0.69
TIMELINE
  May 29  Reserved by CNA
  Aug 4   Published (CNA: cisa-cg)
CWE-121 · CNA: cisa-cg · 7 references · NVD status: Received
Keysight IxChariot Endpoint heap-based buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0072   50.8     —
AFFECTED
  Product    Versions     Fixed
  IxChariot  unspecified  9.5.102
TIMELINE
  May 29  Reserved by CNA
  Aug 4   Published (CNA: cisa-cg)
CWE-122 · CNA: cisa-cg · 3 references · NVD status: Received
Keysight IxChariot Endpoint stack-based buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0072   50.8     —
AFFECTED
  Product    Versions     Fixed
  IxChariot  unspecified  9.5.102
TIMELINE
  May 29  Reserved by CNA
  Aug 4   Published (CNA: cisa-cg)
CWE-121 · CNA: cisa-cg · 3 references · NVD status: Received
nodejs node — A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0062   47.0     —
AFFECTED
  Product  Versions   Fixed
  node     24.18.0 –  —
TIMELINE
  Jun 23  Reserved by CNA
  Aug 4   Published (CNA: hackerone)
CWE-400 · CNA: hackerone · 1 reference · NVD status: Received
nodejs node — A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nght…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0062   47.0     —
AFFECTED
  Product  Versions  Fixed
  node     26.5.0 –  —
TIMELINE
  Jun 23  Reserved by CNA
  Aug 4   Published (CNA: hackerone)
CWE-416 · CNA: hackerone · 1 reference · NVD status: Received
OpenSIPS: Buffer Overflow in Base64 Encode Transformation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0059   45.3     —
AFFECTED
  Product   Versions                  Fixed
  opensips  >= 3.4.0-beta, < 3.6.6 –  —
TIMELINE
  May 8   Reserved by CNA
  Aug 4   Published (CNA: GitHub_M)
CWE-120 · CNA: GitHub_M · 3 references · NVD status: Received
FlowiseAI Flowise — Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0058   44.9     —
AFFECTED
  Product  Versions   Fixed
  Flowise  < 3.1.3 –  —
TIMELINE
  Aug 3   Reserved by CNA
  Aug 4   Published (CNA: GitHub_M)
CWE-94, CWE-95 · CNA: GitHub_M · 4 references · NVD status: Received
perspective-dev perspective — Perspective 5.0.0 Path Traversal via cwd_static_file_handler
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0057   44.3     —
AFFECTED
  Product      Versions     Fixed
  perspective  unspecified  —
TIMELINE
  Jul 28  Reserved by CNA
  Aug 4   Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · 2 references · NVD status: Received
MaxSite CMS 109.5 Unauthenticated AJAX Dispatcher Bypass via ajax.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0057   44.3     —
AFFECTED
  Product      Versions  Fixed
  MaxSite CMS  0.78 –    109.6
TIMELINE
  Aug 4   Reserved by CNA
  Aug 4   Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · 3 references · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-476127.543.5NVIDIADynamoCWE-22NVIDIA Dynamo for Linux contains a vulnerability in the image loading compone…
CVE-2026-691008.743.5dromaralamp-cloudCWE-94LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Execution
CVE-2026-691109.343.4Microckopencode-studioCWE-22OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/music
CVE-2026-85086.543.1ZyxelWAX650S firmwareCWE-287An improper authentication vulnerability in the "social_login.cgi" CGI progra…
CVE-2026-242549.843.0NVIDIADynamoCWE-288NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving to…
CVE-2026-153078.742.8djangoprojectDjangoCWE-73Server-side file-write and request forgery via spatial lookups
CVE-2026-704709.542.0FlowiseAIFlowiseCWE-184Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
CVE-2026-158306.941.9djangoprojectDjangoCWE-674Potential denial-of-service vulnerability via nested geometry collections
CVE-2026-153376.941.9djangoprojectDjangoCWE-789Potential denial-of-service vulnerability in check_for_language()
CVE-2026-690989.341.1CinnamonkotaemonCWE-502kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserializ…
CVE-2026-153147.140.5TP-Link Systems Inc.P110 v1CWE-120Authenticated Denial-of-Service Vulnerability in TP-Link Tapo P110
CVE-2026-463348.739.9OpenSIPSopensipsCWE-20OpenSIPS: Denial of Service in SDP bandwidth parsing via QoS SDP cloning
CVE-2026-678587.539.8n/an/aCWE-120Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discov…
CVE-2026-455389.839.4OpenSIPSopensipsCWE-121OpenSIPS: Stack Buffer Overflow in sip_to_json() Header Name Copy
CVE-2026-645649.839.1LinuxLinuxsctp: don't free the ASCONF's own transport in DEL-IP processing
CVE-2026-100508.738.6Eclipse FoundationEclipse Jetty - EE8CWE-173Digest authentication lossy encoding
CVE-2026-678597.538.4n/an/aCWE-120Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to…
CVE-2026-450848.738.3OpenSIPSopensipsCWE-476OpenSIPS: Denial of service in presence.handle_publish() from unchecked Conte…
CVE-2026-166189.838.2UnknownImprove SEOCWE-434ImproveSEO <= 2.0.11 - Unauthenticated Arbitrary File Upload Leading to Remot…
CVE-2026-580425.938.0nodejsnodeCWE-400A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When …
CVE-2026-697039.337.9maximeAminiAtals-LivreCWE-306Atlas-Livre Unauthenticated Access via Admin Controllers Missing Exit
CVE-2026-476198.137.1NVIDIADynamoCWE-1357NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an…
CVE-2026-704779.536.9FlowiseAIFlowiseCWE-94Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
CVE-2026-669029.836.7CJCOLLIERGoogle::AuthCWE-78Google::Auth versions before 0.06 for Perl run a command named in an external…
CVE-2026-615149.336.1Puwell Technology Inc.IP CameraCWE-306Puwell IP Camera 2.x - 4.x Unauthenticated Access via TCP Port 23456
CVE-2026-634559.835.7Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN OrchestratorCWE-306Authentication bypass via spoofed HTTP headers Orchestrator REST API
CVE-2026-634569.835.7Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN OrchestratorCWE-287Authentication bypass via spoofed HTTP headers Orchestrator REST API
CVE-2026-678567.535.2n/an/aCWE-400An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a …
CVE-2026-678617.534.8n/an/aCWE-400An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a …
CVE-2026-632528.734.4Eclipse FoundationEclipse MiloCWE-401In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers …
CVE-2026-568457.533.3Rocket.ChatRocket.ChatCWE-22An unauthenticated path traversal (LFI) vulnerability exists under /custom-so…
CVE-2026-181034.933.2Red HatRed Hat Enterprise Linux 6CWE-120Dhcp-server: dhcp-server: persistent denial of service due to buffer overflow…
CVE-2026-141759.832.7Bilin Software and Informatics Consultancy Inc.HUMANIST Digital Human ResourcesCWE-434Unrestricted File Upload in Bilin Software's HUMANIST Digital Human Resources
CVE-2026-692569.432.2FlowiseAIFlowiseCWE-94Flowise: Remote Code Execution Vulnerability in CSVAgent
CVE-2026-458098.731.9OpenSIPSopensipsCWE-121OpenSIPS: Denial of Service in watcherinfo XML generation from oversized watc…
CVE-2026-242557.531.6NVIDIADynamoCWE-1023NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding …
CVE-2026-600079.131.5Eclipse FoundationEclipse MiloCWE-204In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing retur…
CVE-2026-692588.831.5FlowiseAIFlowiseCWE-639Flowise: Unauthenticated Property Injection into Flow Execution Context via U…
CVE-2026-188106.931.5H3CNX15CWE-287H3C NX15 networkSetup missing authentication
CVE-2026-704789.231.3FlowiseAIFlowiseCWE-200Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens …
CVE-2026-476238.231.2NVIDIADynamoCWE-502NVIDIA Dynamo for Linux contains a vulnerability where an attacker could caus…
CVE-2026-580729.030.7VeeamService Provider ConsoleCWE-22A vulnerability in Veeam Service Provider Console allowing arbitrary file wri…
CVE-2026-187885.530.6TrippoResponsiveFilemanagerCWE-284Trippo ResponsiveFilemanager dialog.php unrestricted upload
CVE-2026-704868.230.6open-webuiopen-webuiCWE-79Open WebUI: Same-origin XSS to account takeover via terminal file-preview ifr…
CVE-2026-684948.730.3FasterXMLjackson-coreCWE-770jackson-core: Async parser maxNumberLength bypass via chunked digit accumulat…
CVE-2026-6463310.030.0VeeamONECWE-94A vulnerability allowing remote unauthenticated code execution on the agent h…
CVE-2026-706198.729.5odysseus-devodysseusCWE-862Odysseus Missing Admin Authorization via Embedding Endpoint Routes
CVE-2026-692549.429.3FlowiseAIFlowiseCWE-94Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptio…
CVE-2026-148187.229.0ZyxelATP series firmwareCWE-22A path traversal vulnerability in the CLI command used to execute configurati…
CVE-2026-455379.128.9OpenSIPSopensipsCWE-120OpenSIPS: Global Buffer Overflow in construct_uri
CVE-2026-167938.728.6LenovoXClarity OrchestratorCWE-20Remote Command Injection via OS Profile Password in Lenovo XClarity Orchestrator
CVE-2026-692599.428.5FlowiseAIFlowiseCWE-94Flowise RCE via SQLite Record Manager Node
CVE-2026-580748.628.5VeeamONECWE-94A vulnerability allowing a high-privileged user to execute arbitrary code on …
CVE-2026-242538.228.3NVIDIADynamoCWE-787NVIDIA Dynamo for Linux contains a vulnerability where an attacker could caus…
CVE-2026-703686.528.4Mobi-Com Polska Sp. z o.o.stunnelCWE-125Stunnel: stack-based out-of-bounds read/write in stunnel s_vlog via oversized…
CVE-2026-678577.528.1n/an/aCWE-125open62541 1.5.5 contains an out-of-bounds read in the client-side function re…
CVE-2026-613876.927.5Eclipse FoundationEclipse MiloCWE-400In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting…
CVE-2026-692508.527.2FlowiseAIFlowiseCWE-639Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exf…
CVE-2026-188162.326.9n/aBaserowCWE-287Baserow 2FA Verify Endpoint views.py verify improper authentication
CVE-2026-704828.126.7open-webuiopen-webuiCWE-287Open WebUI: Account takeover via OAuth token exchange accepting tokens issued…
CVE-2026-669017.526.2CJCOLLIERGoogle::AuthCWE-201Google::Auth versions before 0.09 for Perl allow server side request forgery …
CVE-2026-678627.526.1n/an/aCWE-400open62541 1.5.5 contains a buffer-overflow in the high-level attribute readin…
CVE-2026-01639.825.7GoogleAndroidCWE-416In multiple functions of vpu_ioctl.c, there is a possible use after free due …
CVE-2026-451037.525.6OpenSIPSopensipsCWE-190OpenSIPS: SIP Message Smuggling via TCP Content-Length Integer Overflow
CVE-2026-580415.324.8nodejsnodeCWE-367A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created th…
CVE-2026-476137.524.6NVIDIADynamoCWE-918NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause …
CVE-2026-476147.524.6NVIDIADynamoCWE-918NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause …
CVE-2026-476157.524.6NVIDIADynamoCWE-918NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause …
CVE-2026-476167.524.6NVIDIADynamoCWE-918NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetc…
CVE-2026-476177.524.6NVIDIADynamoCWE-918NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetc…
CVE-2026-476187.524.6NVIDIADynamoCWE-918NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media…
CVE-2026-692559.224.0FlowiseAIFlowiseCWE-94Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Sh…
CVE-2026-187539.124.0GeoVision Inc.GV-AS1620 (AS-Manager)CWE-321Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-ASManager)
CVE-2026-187549.124.0GeoVision Inc.GV-AS1620 (GV-Cloud)CWE-321Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-Cloud)
CVE-2026-692539.023.9FlowiseAIFlowiseCWE-95Flowise Sandbox Escape to RCE
CVE-2026-184016.923.6FasterXMLjackson-coreCWE-770jackson-core: Number length constraint bypass in non-blocking (async) JSON pa…
CVE-2026-703698.823.3Koha CommunityKohaCWE-89Koha - SQL Injection in reports/acquisitions_stats.pl
CVE-2026-703708.823.2Koha CommunityKohaCWE-89Koha - SQL Injection in reports/catalogue_stats.pl
CVE-2026-703718.823.2Koha CommunityKohaCWE-89Koha - SQL Injection in reports/issues_avg_stats.pl
CVE-2026-703728.823.2Koha CommunityKohaCWE-89Koha - SQL Injection in reports/bor_issues_top.pl
CVE-2026-703738.823.3Koha CommunityKohaCWE-89Koha - SQL Injection in reports/issues_stats.pl
CVE-2026-148049.123.1Bilin Software and Informatics Consultancy Inc.HUMANIST Digital Human ResourcesCWE-321Hardcoded Cryptographic Key in Bilin Software's HUMANIST Digital Human Resources
CVE-2026-697027.123.1aizudaSnailJob (snail-job)CWE-789SnailJob 1.7.0 Denial of Service via FuryUtil.deserialize OOM
CVE-2026-704936.523.1open-webuiopen-webuiCWE-1333Open WebUI: Any authenticated user can stall a worker via a knowledge-search …
CVE-2026-187705.523.0vibesurf-aiVibeSurfCWE-74vibesurf-ai VibeSurf Python Validation code code injection
CVE-2026-159205.123.0djangoprojectDjangoCWE-83Potential cross-site scripting via URLField values in the admin
CVE-2026-476827.122.9cvat-aicvatCWE-22CVAT: Missing path-containment validation in multiple entry points allows arb…
CVE-2026-672438.622.7refiriofreo2CWE-434freo2 provided by refirio contains an unrestricted upload of file with danger…
CVE-2026-580443.722.7nodejsnodeCWE-444A flaw in Node.js HTTP client can cause a request desynchronization for Node.…
CVE-2026-580678.722.6VeeamService Provider ConsoleCWE-789A vulnerability in Veeam Service Provider Console allowing an unauthenticated…
CVE-2026-704815.422.5open-webuiopen-webuiCWE-284Open WebUI: Any member with write access to a standard channel can edit or de…
CVE-2026-629278.722.4Eclipse FoundationEclipse MiloCWE-863In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the…
CVE-2026-705925.522.4TryGhostGhostCWE-22Ghost: Database Backup Path Traversal
CVE-2026-704948.122.3open-webuiopen-webuiCWE-862Open WebUI: A folder write-collaborator can permanently delete the owner's ch…
CVE-2026-671997.122.2perspective-devperspectiveCWE-770Perspective 5.0.0 DoS via Loop Expression Evaluation
CVE-2026-704757.122.2FlowiseAIFlowiseCWE-862Flowise: Missing Authorization on Execution Update Endpoint
CVE-2026-141946.522.1Bilin Software and Informatics Consultancy Inc.HUMANIST Digital Human ResourcesCWE-22Path Traversal Allows Arbitrary File Download in Bilin Software's HUMANIST Di…
CVE-2026-704896.522.1open-webuiopen-webuiCWE-400Open WebUI: Instance-wide stall via automation recurrence rules that force mu…
CVE-2026-188308.621.6AWSAmazon Bedrock AgentCore harnessCWE-1287Insufficient input validation in Amazon Bedrock AgentCore harness InvokeHarne…
CVE-2026-457055.321.6OpenSIPSopensipsCWE-125OpenSIPS: OOB Read in Multipart Body Boundary Parsing
CVE-2026-678557.521.5n/an/aCWE-400open62541 contains a heap use-after-free in the GDS PushManagement certificat…
CVE-2026-705936.621.5TryGhostGhostCWE-22Ghost: Theme Upload Path Traversal
CVE-2026-668836.321.5Erlang Ecosystem Foundationoidcc_plugCWE-178Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive h…
CVE-2026-704747.621.3FlowiseAIFlowiseCWE-863Flowise: Cross-Workspace OAuth2 Credential Metadata Leak
CVE-2026-679799.121.1n/an/aCWE-284Incorrect access control in the Executive Services dynamic application start …
CVE-2026-170708.821.1HAVELSAN Inc.Liman MYSCWE-862Vault Credential Confusion via Authorization Bypass in HAVELSAN's Liman MYS
CVE-2026-704768.321.1FlowiseAIFlowiseCWE-284Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-…
CVE-2026-187205.521.1kalcaddlekodboxCWE-266kalcaddle kodbox msgWarning Plugin action improper authorization
CVE-2026-580758.720.6VeeamONECWE-287A vulnerability allowing an unauthenticated attacker to read arbitrary files …
CVE-2026-580718.220.6VeeamService Provider ConsoleCWE-306A vulnerability in Veeam Service Provider Console allowing an unauthenticated…
CVE-2026-704717.120.4FlowiseAIFlowiseCWE-863Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
CVE-2026-697047.020.0maximeAminiAtals-LivreCWE-89Atals-Livre SQL Injection via Unsanitized GET Parameter in supp()
CVE-2026-187726.519.3Samsung Open SourcerlottieCWE-1325Improperly controlled sequential memory allocation vulnerability in Samsung O…
CVE-2026-187752.119.4NousResearchhermes-agentCWE-918NousResearch hermes-agent Browser Tooling browser_tool.py browser_snapshot se…
CVE-2026-144656.519.2Bilin Software and Informatics Consultancy Inc.HUMANIST Digital Human ResourcesCWE-613Session Fixation in Bilin Software's HUMANIST Digital Human Resources
CVE-2026-580808.819.2Eclipse FoundationEclipse MiloCWE-862In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fail…
CVE-2026-692638.719.0FlowiseAIFlowiseCWE-184Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment …
CVE-2026-678607.518.9n/an/aCWE-122open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryR…
CVE-2026-704844.318.9open-webuiopen-webuiCWE-862Open WebUI: Users denied the image-generation permission can still generate i…
CVE-2026-646318.518.6VeeamONECWE-89A vulnerability allowing a low-privileged user to inject SQL and extract data…
CVE-2026-706206.118.3odysseus-devodysseusCWE-918Odysseus SSRF via Embedding Endpoint Configuration
CVE-2026-476225.318.4NVIDIADynamoCWE-209NVIDIA Dynamo for Linux contains a vulnerability where an attacker could caus…
CVE-2026-168818.718.1LY CorporationLINE client for AndroidA code injection vulnerability exists in the LINE Android app prior to versio…
CVE-2026-704928.718.0open-webuiopen-webuiCWE-79Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered …
CVE-2026-704797.717.8open-webuiopen-webuiCWE-918Open WebUI: SSRF into internal services via unvalidated sub-resource requests…
CVE-2026-692527.217.9FlowiseAIFlowiseCWE-862Flowise: Missing authorization on `/api/v1/files` allows low-privileged API k…
CVE-2026-704916.517.9open-webuiopen-webuiCWE-200Open WebUI: Tool source code disclosed to read-only users via the tool list a…
CVE-2026-705885.017.6TryGhostGhostCWE-79Ghost: Cross-Site Scripting in Universal Import
CVE-2026-148387.417.6Bilin Software and Informatics Consultancy Inc.HUMANIST Digital Human ResourcesCWE-598Session Token Exposure in URL Leading to Account Takeover in Bilin Software's…
CVE-2026-165486.517.3UnknownChat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and ChatCWE-434Bit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response Endpoint
CVE-2026-476206.517.1NVIDIADynamoCWE-362NVIDIA Dynamo for Linux contains a vulnerability where an attacker could caus…
CVE-2026-476216.517.1NVIDIADynamoCWE-367NVIDIA Dynamo for Linux contains a vulnerability where an attacker could caus…
CVE-2026-148166.516.6UnknownThe GDPR Framework By Data443CWE-284The GDPR Framework < 2.4.0 - Unauthenticated Consent Record Forgery and Do No…
CVE-2026-704875.316.7open-webuiopen-webuiCWE-862Open WebUI: Cross-user file content disclosure via request-scoped direct mode…
CVE-2026-187212.116.6kalcaddlekodboxCWE-601kalcaddle kodbox SSO API Login apiLogin redirect
CVE-2026-481545.916.2pilinuxgorestCWE-362GoRest: InMemorySecret2FA race condition allows process crash via concurrent …
CVE-2026-143374.616.2PegasystemsPega InfinityCWE-79Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-…
CVE-2026-704738.316.1FlowiseAIFlowiseCWE-200Flowise: Information Disclosure in GET /api/v1/upsert-history returns the ent…
CVE-2026-692577.616.1FlowiseAIFlowiseCWE-918Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
CVE-2026-132277.116.1FrappeERPNextCWE-862ERPNext v16.25.0 - Improper authorization in Prospect opportunities API
CVE-2026-132297.116.1ZammadZammadCWE-862Zammad 7.0.1 - Improper authorization in ticket article attachment cloning
CVE-2026-692627.116.1FlowiseAIFlowiseCWE-863Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allo…
CVE-2026-704727.116.1FlowiseAIFlowiseCWE-285Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
CVE-2026-165475.916.1UnknownREST API LogCWE-284REST API Log < 1.7.1 - Unauthenticated Sensitive Log Data Disclosure via Down…
CVE-2026-704833.115.9open-webuiopen-webuiCWE-862Open WebUI: Any authenticated user can cancel another user's chat generation …
CVE-2026-659868.515.2cvat-aicvatCWE-79CVAT has stored XSS via annotation guide assets
CVE-2026-166238.015.0UnknownCreate Block ThemeCWE-94Create Block Theme < 2.10.0 - Admin+ PHP Code Injection via Pattern Save (Mul…
CVE-2026-646305.314.8VeeamONECWE-863A vulnerability allowing a low-privileged user to retrieve report data outsid…
CVE-2026-149396.814.6UnknownVisualizerCWE-918Visualizer: Tables and Charts Manager < 4.0.6 - Contributor+ Server-Side Requ…
CVE-2026-160696.814.7UnknownBrizyCWE-79Brizy - Page Builder < 2.8.19 - Contributor+ Stored XSS via Featured Image Fo…
CVE-2026-162936.814.7UnknownPowerPress Podcasting plugin by BlubrryCWE-79Blubrry PowerPress < 11.16.11 - Contributor+ Stored XSS via Podcast Episode C…
CVE-2026-186508.814.3HAVELSAN Inc.Liman MYSCWE-862Missing Authorization Leading to Root Code Execution in HAVELSAN's Liman MYS
CVE-2026-157219.814.2Bilin Software and Informatics Consultancy Inc.HUMANIST Digital Human ResourcesCWE-312Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Sof…
CVE-2026-148726.814.1UnknownDatabase for Contact Form 7, WPforms, Elementor formsCWE-89Database for Contact Form 7, WPforms, Elementor forms < 1.5.5 - Authenticated…
CVE-2026-481216.714.0langchain-ailanggraphjsCWE-943@langchain/langgraph-checkpoint-mongodb: NoSQL parameter injection in MongoDB…
CVE-2026-188019.313.8openmeteropenmeterCWE-20Stored Clickhouse SQL Injection Through Customer Usage Attribution
CVE-2026-105265.813.8UnknownEmbedPressCWE-918EmbedPress < 4.6.1 - Unauthenticated Blind SSRF
CVE-2026-705914.113.5TryGhostGhostCWE-918Ghost: Server-Side Request Forgery in Image Fetching
CVE-2026-580739.513.3VeeamService Provider ConsoleCWE-288A vulnerability in Veeam Service Provider Console allowing an unauthenticated…
CVE-2026-704857.113.1open-webuiopen-webuiCWE-918Open WebUI: Any authenticated user can reach internal services and cloud meta…
CVE-2026-511446.112.0n/an/aCWE-79Cross Site Scripting vulnerability in Soliton Systems MailZen Management Prot…
CVE-2026-668842.112.0Erlang Ecosystem Foundationoidcc_plugCWE-352Oidcc.Plug.AuthorizationCallback accepts callbacks with no authorize session …
CVE-2026-540206.311.9open-webuiopen-webuiCWE-367Open WebUI: DNS Rebinding SSRF Bypass
CVE-2026-704884.311.9open-webuiopen-webuiCWE-639Open WebUI: Deletion of directories and file embeddings in other knowledge ba…
CVE-2026-188096.511.6MozillaFirefoxCWE-200Information disclosure in Firefox for Android and Firefox Focus for Android
CVE-2026-188185.311.7Ehco1996django-sspanelCWE-285Ehco1996 django-sspanel Support Ticket views.py TicketDetailView authorization
CVE-2026-187222.111.7diaowenDWSurveyCWE-285diaowen DWSurvey dev-survey.do in DwDeisgnSurveyController.devSurvey. authori…
CVE-2026-704906.311.1open-webuiopen-webuiCWE-863Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket au…
CVE-2026-159589.310.7UnknownEasy Integration for DropboxCWE-862Easy Dropbox Integration < 2.2.0 - Unauthenticated Arbitrary Connected Dropbo…
CVE-2026-187232.110.4diaowenDWSurveyCWE-266diaowen DWSurvey Survey Status up-survey-status.do improper authorization
CVE-2026-187732.110.4NousResearchhermes-agentCWE-285NousResearch hermes-agent Quick run.py _check_slash_access authorization
CVE-2026-187742.110.4NousResearchhermes-agentCWE-918NousResearch hermes-agent xAI Image Generation Provider image_gen_provider.py…
CVE-2026-671988.710.2perspective-devperspectiveCWE-616Perspective 5.0.0 DoS via VirtualServer Protocol Dispatcher
CVE-2026-676187.110.0marimo-teammarimoCWE-345marimo < 0.23.15 API Key Exfiltration via Malicious Notebook PEP-723 Metadata
CVE-2026-580456.210.0nodejsnodeCWE-400A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a rea…
CVE-2026-100326.19.7Google@a2ui/web_coreCWE-79Arbitrary JavaScript Execution via openUrl in @a2ui/web_core
CVE-2026-142025.39.8Bilin Software and Informatics Consultancy Inc.HUMANIST Digital Human ResourcesCWE-204Username Enumeration via Differential Login Responses in Bilin Software's HUM…
CVE-2026-705904.89.5TryGhostGhostCWE-200Ghost: Blind Password Hash Disclosure in Ghost Admin API
CVE-2026-160354.39.5UnknownminiOrange 2FACWE-862miniOrange 2FA < 6.2.7 - Subscriber+ Arbitrary-Recipient OTP Send
CVE-2026-165365.39.3UnknownSimple Google Calendar Outlook Events WidgetCWE-918Simple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF v…
CVE-2026-704804.19.2open-webuiopen-webuiCWE-918Open WebUI: Client-side SSRF via unrestricted external resource loading in Ve…
CVE-2026-113663.79.2UnknownMonsterInsightsCWE-287MonsterInsights < 11.1.0 - Unauthenticated Measurement Protocol Secret Update…
CVE-2026-187192.19.2cemtansar2htmlCWE-74cemtan sar2html Search sar2html.py sql injection
CVE-2026-187662.19.2chetans9core-php-admin-panelCWE-74chetans9 core-php-admin-panel customers.php sql injection
CVE-2026-523706.18.8n/an/aCWE-79A reflected cross-site scripting (XSS) vulnerability in the Forum posting fun…
CVE-2026-113686.58.3zephyrprojectzephyrCWE-416Use-after-free in Bluetooth host ATT TX completion on disconnect mid-transfer
CVE-2026-126984.38.4UnknownwpForo ForumCWE-284wpForo Forum < 3.1.3 - Subscriber+ Account Status and Reputation Manipulation…
CVE-2026-474877.18.2NVIDIATriton Inference ServerCWE-22NVIDIA Triton Inference Server for Linux contains a vulnerability where a use…
CVE-2026-663002.38.0SNOMED InternationalSnowstormCWE-79SNOMED International Snowstorm reflected XSS
CVE-2026-141925.47.2Bilin Software and Informatics Consultancy Inc.HUMANIST Digital Human ResourcesCWE-79Stored XSS in Bilin Software's HUMANIST Digital Human Resources
CVE-2026-148244.87.1UnknownQuiz and Survey Master (QSM)CWE-79Quiz And Survey Master < 11.2.2 - Contributor+ Stored XSS via Polar Question
CVE-2026-64565await7.0LinuxLinuxInput: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()
CVE-2026-705894.86.9TryGhostGhostCWE-20Ghost: Archived Offers can be Redeemed
CVE-2026-162964.76.8UnknownClearfy CacheCWE-601Clearfy < 2.4.3 - Open Redirect via Cyrlitera 404 Handler
CVE-2026-148485.46.7UnknownPaid Membership SubscriptionsCWE-284Paid Member Subscriptions < 3.0.8 - Subscriber+ Cross-User Subscription Hijac…
CVE-2026-160702.76.6UnknownBrizyCWE-639Brizy - Page Builder < 2.8.19 - Contributor+ Template Type Update via IDOR
CVE-2026-188531.96.4ZomboDroidMeme Generator AppCWE-22ZomboDroid Meme Generator App com.zombodroid.MemeGenerator t5.l.c path traversal
CVE-2026-160564.35.8UnknownContest GalleryCWE-862Contest Gallery < 30.0.7 - Subscriber+ OpenAI Prompt History Disclosure via p…
CVE-2026-162954.35.8UnknownClearfy CacheCWE-284Clearfy < 2.4.3 - Subscriber+ Sensitive Information Disclosure via Factory Pa…
CVE-2026-705946.75.7TryGhostGhostCWE-384Ghost: Session Fixation in Ghost Admin
CVE-2026-142195.45.7Bilin Software and Informatics Consultancy Inc.HUMANIST Digital Human ResourcesCWE-601URL Redirection in Bilin Software's HUMANIST Digital Human Resources
CVE-2026-185693.75.7Red HatRed Hat Build of KeycloakCWE-347Keycloak-services: keycloak-services: oidc backchannel logout accepts unsigne…
CVE-2026-186568.55.6AmazonKiro IDECWE-427Executable Resolution from Untrusted Project Directory in Kiro IDE on Windows
CVE-2026-186578.55.6AmazonKiro CLICWE-427Executable Resolution from Untrusted Project Directory in Kiro CLI on Windows
CVE-2026-188192.15.5n/aRackTablesCWE-352RackTables cross-site request forgery
CVE-2026-632486.95.2Eclipse FoundationEclipse MiloCWE-862In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes…
CVE-2026-703675.45.2Mobi-Com Polska Sp. z o.o.stunnelCWE-918Stunnel: ssrf bypass in stunnel socks proxy via ipv4-mapped ipv6 loopback and…
CVE-2026-165464.34.9UnknownWired Impact Volunteer ManagementCWE-862Wired Impact Volunteer Management < 2.8.2 - Subscriber+ Arbitrary RSVP Remova…
CVE-2026-477636.84.8pdm-projectpdmCWE-61pdm: Project-Local State and Config Writes Follow Symlinks
CVE-2026-671965.14.7perspective-devperspectiveCWE-79Perspective 5.0.0 XSS via Debug Plugin innerHTML Interpolation
CVE-2026-477648.44.5pdm-projectpdmCWE-22pdm: Path traversal in wheel installation via overridden write_to_fs
CVE-2026-240847.54.5Qualcomm, Inc.SnapdragonCWE-1294Insecure Security Identifier Mechanism in Multi-Mode Call Processor
CVE-2026-107097.84.3AutodeskFBX SDKCWE-121FBX BinaryReadSectionHeader Stack-Based Buffer Overflow Vulnerability in Auto…
CVE-2026-107107.84.3AutodeskFBX SDKCWE-121FBX ExtractDrive Stack-Based Buffer Overflow Vulnerability in Autodesk FBX SDK
CVE-2026-152334.84.0UnknownNested PagesCWE-79Nested Pages < 3.2.15 - Editor+ Stored XSS via Post Title
CVE-2026-160683.54.0UnknownBrizyCWE-79Brizy - Page Builder < 2.8.19 - Author+ Stored XSS via brizy_set_project Glob…
CVE-2026-514017.73.7n/an/aCWE-94An issue in Vim Project v9.2.0389 and earlier allows a local attacker to exec…
CVE-2026-421697.33.3Red HatRed Hat Enterprise Linux 9CWE-131Gimp: gimp apng loader heap-buffer-overflow when fctl width exceeds ihdr widt…
CVE-2026-687437.13.3Red HatRed Hat Enterprise Linux 10CWE-125Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length …
CVE-2026-477818.43.2pdm-projectpdmCWE-94pdm: Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing
CVE-2026-187557.32.9GeoVision Inc.GV-ASManagerCWE-428GV-ASManager DLL hijacking vulnerability
CVE-2026-240798.12.8Qualcomm, Inc.SnapdragonCWE-306Missing Authentication for Critical Function in Data Modem
CVE-2026-514008.42.5n/an/aCWE-401An issue in Vim Project v9.2.0389 and earlier allows a local attacker to exec…
CVE-2026-187841.92.5o6open62541CWE-119o6 open62541 ua_client_highlevel.c UA_Client_readNodeClassAttribute heap-base…
CVE-2026-645618.82.2LinuxLinuxKVM: x86: Check for invalid/obsolete root *after* making MMU pages available
CVE-2026-645628.82.2LinuxLinuxKVM: nVMX: Hide shadow VMCS right after VMCLEAR
CVE-2026-187901.92.2SysterelS2OPCCWE-119Systerel S2OPC DeleteMonitoredItemsRequest state_machine.c out-of-bounds
CVE-2026-645637.81.9LinuxLinuxrhashtable: clear stale iter->p on table restart
CVE-2026-252899.61.9Qualcomm, Inc.SnapdragonCWE-121Stack-based Buffer Overflow in WLAN Firmware
CVE-2026-187598.51.8ASUSTOR Inc.ABPCWE-269An improper authentication and path traversal vulnerability exists in ASUSTOR…
CVE-2026-646348.41.8VeeamONECWE-269A vulnerability allowing local privilege escalation to the Reporter service c…
CVE-2026-187851.91.6o6open62541CWE-119o6 open62541 client_types_custom.c UA_Client_getRemoteDataTypes use after free
CVE-2026-188521.91.6epsilla-cloudvectordbCWE-754epsilla-cloud vectordb Filter expr.cpp ShuntingYard unusual condition
CVE-2026-240776.51.2Qualcomm, Inc.SnapdragonCWE-191Integer Underflow (Wrap or Wraparound) in WLAN Host
CVE-2026-240786.51.2Qualcomm, Inc.SnapdragonCWE-359Exposure of Private Personal Information to an Unauthorized Actor in Data Modem
CVE-2026-252927.61.1Qualcomm, Inc.SnapdragonCWE-1286Improper Validation of Syntactic Correctness of Input in Automotive Linux OS
CVE-2026-188067.11.0TÜBİTAK BİLGEM Software Technologies Research Institutepardus-image-writerCWE-73Arbitrary Block Device Write via Missing Validation in TÜBİTAK BİLGEM's pardu…
CVE-2026-252887.41.0Qualcomm, Inc.SnapdragonCWE-126Buffer Over-read in WLAN Firmware
CVE-2026-687443.30.9Red HatRed Hat Enterprise Linux 10CWE-908Sssd: sssd: nss responder uninitialized heap disclosure in initgroups reply
CVE-2026-187392.50.7rpm-software-managementpoptCWE-787Popt-devel: popt-static: off-by-one in poptstuffargs
CVE-2026-167911.00.4LenovoXClarity Essentials OneCLICWE-377Predictable Temporary File Symlink Vulnerability in Lenovo XClarity Essential…
CVE-2026-118355.60.3CaliptraCore ROMCWE-20Caliptra Update-Reset Secure-Boot Bypass via Attacker-Chosen AXI Staging Addr…
CVE-2026-118361.80.2CaliptraCore ROMCWE-345Production Debug-Unlock Token Verification Missing Device Binding
CVE-2026-167927.00.1LenovoXClarity OrchestratorCWE-295Global TLS Certificate Validation Bypass in Lenovo XClarity Orchestrator
CVE-2026-240766.70.1Qualcomm, Inc.SnapdragonCWE-120Buffer Copy Without Checking Size of Input in Bluetooth HOST
CVE-2026-213667.80.0Qualcomm, Inc.SnapdragonCWE-190Integer Overflow or Wraparound in Data Network Stack & Connectivity
CVE-2026-240807.80.0Qualcomm, Inc.SnapdragonCWE-120Buffer Copy Without Checking Size of Input in Biometrics
CVE-2026-240837.80.0Qualcomm, Inc.SnapdragonCWE-822Untrusted Pointer Dereference in Automotive Security

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-04 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.