boxscore/security
Wednesday, August 5, 2026 · all times UTC← 2026-08-04 · archive · 2026-08-06 →

432 CVEs published August 5, 2026: 61 critical, 203 high, 146 medium, 17 low; 1 in KEV; 7 with a public exploit reference; 5 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 407 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published12111001613962563
KEV catalog size1670

485 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux22160720911419802730.27.8.0016+10
microsoft1613771069363108378322.37.8.0039-34
google241465104227157351.26.5.0022+2
red hat342561311611116400.07.0.0025+28
apple0244566711229372.97.1.00270
suse551220000.07.3.0022+5
canonical030210000.07.8.00130
android010100161100.08.4.01710
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco234391790961330.28.6.0032+23
fortinet018249028633.36.1.00540
palo alto networks015017514213.34.7.00280
vmware01247012100.08.7.00440
checkpoint1541003240.09.3.2062+1
f50540007120.09.2.04020
ivanti051000335100.010.0.81520
zyxel3403101100.07.2.0075+3
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache4017727965314021.17.5.0049+40
mozilla1734226501300.09.1.0031+1
gitlab015021014213.34.9.00290
github240220000.07.0.0040+2
docker030120100.05.7.00150
wordpress0311105266.78.6.73100
drupal01100051100.09.8.88320
kubernetes010001000.02.4.00240
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle01113212539304574030.37.6.00310
ibm321403661421710.77.5.0027+32
adobe7471623407548.58.6.0047+7
progress1033101850900.08.1.0029+10
solarwinds0201611011420.09.1.00500
veeam10123720400.08.6.0027+10
atlassian0303001300.08.0.00260
zohocorp031110000.07.1.00480
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link08006126112.55.5.00730
hikvision0704202114.37.2.00250
bosch030300000.08.1.00280
schneider electric031200100.08.7.00200
synology110100000.07.3.0013+1
honeywell010010000.06.9.00310
mitsubishi electric010100000.07.1.00130
rockwell automation011000000.09.2.00300
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
surrealdb057326253000.07.1.00250
grafana041214223000.06.5.00330
netty04162771000.07.5.00460
legion of the bouncy castle323952590000.08.7.0026+32
open ises037214210000.06.9.00210
mediatek343404300100.06.0.0011+34
erlang032114143100.06.9.0033-6
freerdp233181841000.08.7.0034+23

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-48282.992499.9
CVE-2026-63030.956099.99.8
CVE-2026-39808.912199.8
CVE-2026-48908.881399.810.0
CVE-2026-56290.832599.710.0
CVE-2026-34486.829399.67.5
CVE-2026-48939.825099.610.0
CVE-2026-50522.769899.59.8
CVE-2026-15410.763599.57.2
CVE-2026-56291.760799.510.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4890810.0.8813KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-1540910.0.7422KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0473
CVE-2026-4766810.0.0434
CVE-2026-4435910.0.0100
CVE-2025-7138910.0.0093
Most disclosures (vendor)
VendorCVEs
oracle1109
linux677
microsoft624
google405
apple167
red hat150
apache145
ibm132
mozilla68
surrealdb57
Most KEV additions (YTD)
VendorKEV
microsoft32
cisco13
apple7
fortinet6
google5
ivanti5
adobe4
langflow4
solarwinds4
synacor4
Most-affected ecosystems
EcosystemAdvisories
Maven49
PyPI5
Go3
crates.io2
npm2
NuGet1
Packagist1
Fastest to KEV
CVEVendorDays
CVE-2008-4128Cisco0
CVE-2021-27137DD-WRT0
CVE-2023-4346KNX Association0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-18556N-able0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171722
CVE-2021-27102Accellion2021-11-171722
CVE-2021-27101Accellion2021-11-171722
CVE-2021-27103Accellion2021-11-171722
CVE-2021-21017Adobe2021-11-171722
CVE-2021-28550Adobe2021-11-171722
CVE-2021-42013Apache2021-11-171722
CVE-2021-41773Apache2021-11-171722
CVE-2021-30858Apple2021-11-171722
CVE-2021-30860Apple2021-11-171722

Transactions

EXPLOIT PUBLISHEDCVE-2023-0669 (Fortra Goanywhere MFT). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2023-35078 (Ivanti Endpoint Manager Mobile). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2023-3519 (Citrix NetScaler ADC). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2023-38831. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2024-51378. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2024-55956. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-26633 (Microsoft Windows 10 Version 1507). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-66024 (xwiki-contrib application-blog-ui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18766 (chetans9 core-php-admin-panel). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18774 (NousResearch hermes-agent). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18784 (o6 open62541). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18788 (Trippo ResponsiveFilemanager). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18811 (H3C NX15). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18812 (H3C NX15). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18813 (H3C NX15). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18814 (H3C NX15). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18819 (RackTables). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-3609 (Wellbia XIGNCODE3). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-4629 (Red Hat build of Keycloak 26.4). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-46581 (Eclipse Foundation Eclipse Mojarra). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54904 (ruby-concurrency concurrent-ruby). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55554 (dompdf). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-61515 (Puwell Technology Inc. IP Camera). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66297 (livebook-dev livebook). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66881 (livebook-dev livebook). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-67196 (perspective-dev perspective). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-67200 (perspective-dev perspective). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-69098 (Cinnamon kotaemon). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-70619 (odysseus-dev odysseus). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-70620 (odysseus-dev odysseus). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-71225 (Stephan Muelle libkcapi). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-71227 (Stephan Muelle libkcapi). Public exploit reference added.

DUE DATE PASSEDCVE-2026-60137 (WordPress). CISA remediation deadline was August 4, 2026; still in catalog.

RESCOREDCVE-2023-35078 (Ivanti Endpoint Manager Mobile). CVSS 10 → 9.8 (NVD).

RESCOREDCVE-2023-41265. CVSS 9.6 → 9.9 (NVD).

RESCOREDCVE-2023-41266. CVSS 8.2 → 6.5 (NVD).

RESCOREDCVE-2024-11667 (Zyxel ATP series firmware). CVSS 7.5 → 9.8 (NVD).

RESCOREDCVE-2024-51378. CVSS 10 → 9.8 (NVD).

RESCOREDCVE-2024-55591 (Fortinet FortiOS). CVSS 9.6 → 9.8 (NVD).

RESCOREDCVE-2026-16158 (@fastify/reply-from). CVSS 8.7 → 10 (NVD).

RESCOREDCVE-2026-18852 (epsilla-cloud vectordb). CVSS 4.8 → 1.9 (NVD).

RESCOREDCVE-2026-18853 (ZomboDroid Meme Generator App). CVSS 4.8 → 1.9 (NVD).

RESCOREDCVE-2026-24457 (Eclipse Foundation Eclipse OpenMQ). CVSS 9.1 → 9.8 (NVD).

RESCOREDCVE-2026-3609 (Wellbia XIGNCODE3). CVSS 5.3 → 7.8 (NVD).

RESCOREDCVE-2026-9793 (Red Hat build of Keycloak 26.4). CVSS 5.9 → 7.5 (NVD).

ENRICHEDCVE-2021-3483 (Linux kernel). Received CVSS 7.8 and CPE data from NVD.

ENRICHEDCVE-2021-3501 (Linux kernel). Received CVSS 7.1 and CPE data from NVD.

ENRICHEDCVE-2022-1353 (Linux kernel). Received CVSS 7.1 and CPE data from NVD.

Yesterday's Results

432 CVEs published. 25 box scores and 375 table rows below; the remaining 32 continue on page 2 — every CVE is listed, nothing truncated.

JetBrains TeamCity
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .1072   95.4   YES
AFFECTED
  Product   Versions     Fixed
  TeamCity  unspecified  —
TIMELINE
  Jul 15  Reserved by CNA
  Aug 5   Added to CISA KEV, due Aug 8
  Aug 5   Published (CNA: JetBrains)
CWE-502 · CNA: JetBrains · 2 references · NVD status: Analyzed · KEV due August 8, 2026
H3C NX15 Backend RPC esps file.exec os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    7.3   .0238   82.5     —
AFFECTED
  Product  Versions    Fixed
  NX15     V100R017 –  —
TIMELINE
  Aug 4   Reserved by CNA
  Aug 5   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 6 references · NVD status: Deferred
H3C NX15 esps repeaterproc command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    7.3   .0238   82.5     —
AFFECTED
  Product  Versions    Fixed
  NX15     V100R017 –  —
TIMELINE
  Aug 4   Reserved by CNA
  Aug 5   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 6 references · NVD status: Deferred
inisev Backup Migration — Backup Migration <= 2.1.5.1 - Authenticated (Administrator+) OS Command Injection via 'file' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0223   81.3     —
AFFECTED
  Product           Versions     Fixed
  Backup Migration  unspecified  —
TIMELINE
  May 2   Reserved by CNA
  Aug 5   Published (CNA: Wordfence)
CWE-77 · CNA: Wordfence · 8 references · NVD status: Deferred
advplyr audiobookshelf — audiobookshelf - %2F Encoding Discrepancy Bypasses Cover/Image Auth Exemption Regex, Enabling Unauthenticated Path Traversal
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0176   76.1     —
AFFECTED
  Product         Versions  Fixed
  audiobookshelf  2.19.1 –  —
TIMELINE
  Aug 5   Reserved by CNA
  Aug 5   Published (CNA: TuranSec)
CWE-22 · CNA: TuranSec · 2 references · NVD status: Received
livebook-dev livebook — Unescaped deployment environment variables in generated setup commands
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   H   A   N   N   N    4.9   .0155   73.0     —
AFFECTED
  Product   Versions                                    Fixed
  livebook  0.13.0 –                                    —
  livebook  0.13.0 –                                    —
  livebook  7cf4af5c10ec645f55a10f30e5661c54f6a6b319 –  b2a8416d149043132fe5a14ed611e0fefc9dc9cd
TIMELINE
  Jul 24  Reserved by CNA
  Aug 5   Public exploit reference published
  Aug 5   Published (CNA: EEF)
CWE-78 · CNA: EEF · 6 references · NVD status: Analyzed
HashBrownCMS hashbrown-cms — HashBrown CMS - OS Command Injection via Git Deployer Branch Field
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0098   59.3     —
AFFECTED
  Product        Versions     Fixed
  hashbrown-cms  unspecified  —
TIMELINE
  Aug 4   Reserved by CNA
  Aug 5   Published (CNA: TuranSec)
CWE-78 · CNA: TuranSec · 2 references · NVD status: Received
HashBrownCMS hashbrown-cms — HashBrown CMS - OS Command Injection in Media Upload Thumbnail Generation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0097   59.0     —
AFFECTED
  Product        Versions     Fixed
  hashbrown-cms  unspecified  —
TIMELINE
  Aug 4   Reserved by CNA
  Aug 5   Published (CNA: TuranSec)
CWE-78 · CNA: TuranSec · 2 references · NVD status: Received
IBM Langflow OSS — Langflow is affected OS Command Injection in Model Context Protocol features
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0096   58.7     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  Jul 27  Reserved by CNA
  Aug 5   Published (CNA: ibm)
CWE-78 · CNA: ibm · 1 reference · NVD status: Analyzed
MervinPraison PraisonAI — PraisonAI: GitHub Actions Claude workflow command injection via unquoted PR branch name
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0091   56.9     —
AFFECTED
  Product    Versions    Fixed
  PraisonAI  < 4.6.40 –  —
TIMELINE
  May 20  Reserved by CNA
  Aug 5   Published (CNA: GitHub_M)
CWE-862 · CNA: GitHub_M · 2 references · NVD status: Received
fledge-iot fledge — Fledge IoT Gateway Backup Restore OS Command Injection via Tar Member Filename
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0089   56.4     —
AFFECTED
  Product  Versions     Fixed
  fledge   unspecified  —
TIMELINE
  Aug 5   Reserved by CNA
  Aug 5   Published (CNA: TuranSec)
CWE-78 · CNA: TuranSec · 2 references · NVD status: Received
Cisco Integrated Management Controller Argument Injection and Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0084   54.9     —
AFFECTED
  Product                                      Versions         Fixed
  Cisco Unified Computing System (Standalone)  4.3(1.230097) –  —
TIMELINE
  Oct 8   Reserved by CNA
  Aug 5   Published (CNA: cisco)
CWE-141 · CNA: cisco · 1 reference · NVD status: Awaiting Analysis
cozmoslabs TranslatePress – Translate Multilingual sites with AI Translation — TranslatePress <= 3.2.5 - Reflected Cross-Site Scripting
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  L  N    6.1   .0080   53.7     —
AFFECTED
  Product                                                            Versions     Fixed
  TranslatePress – Translate Multilingual sites with AI Translation  unspecified  —
TIMELINE
  Jul 26  Reserved by CNA
  Aug 5   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · 5 references · NVD status: Deferred
IBM Langflow OSS — Langflow is affected by OS Command Injection in Model Context Protocol features
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0078   52.9     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  Jul 27  Reserved by CNA
  Aug 5   Published (CNA: ibm)
CWE-78 · CNA: ibm · 1 reference · NVD status: Analyzed
keywordrush Content Egg – Affiliate Product Importer & Price Comparison — Content Egg <= 11.3.0 - Authenticated (Author+) Arbitrary File Deletion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  H    8.1   .0077   52.7     —
AFFECTED
  Product                                                      Versions     Fixed
  Content Egg – Affiliate Product Importer & Price Comparison  unspecified  —
TIMELINE
  Jul 16  Reserved by CNA
  Aug 5   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · 10 references · NVD status: Deferred
ZTE NX799J (Red Magic 11 Air) — PostgreSQL Misconfiguration and Command Injection Vulnerability in ZTE NX799J (Red Magic 11 Air) Product
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   P   L   L   N  C  H  L  L    6.5   .0069   49.8     —
AFFECTED
  Product                    Versions                  Fixed
  NX799J (Red Magic 11 Air)  GEN_CN_NX799JV1.0.0B15 –  —
TIMELINE
  May 27  Reserved by CNA
  Aug 5   Published (CNA: zte)
CWE-89 · CNA: zte · 1 reference · NVD status: Received
cyberlord92 Page and Post Restriction — Page and Post Restriction <= 1.4.1 - Unauthenticated Missing Authorization to Sensitive Information Exposure via REST API
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0066   48.7     —
AFFECTED
  Product                    Versions     Fixed
  Page and Post Restriction  unspecified  —
TIMELINE
  Jun 11  Reserved by CNA
  Aug 5   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 10 references · NVD status: Deferred
lightsyncpro LightSync Pro – Connect & Sync Cloud Assets | Lightroom, Canva, Figma, Dropbox & Shutterstock — LightSync Pro <= 2.1.6 - Authenticated (Author+) Arbitrary File Upload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0066   48.5     —
AFFECTED
  Product                                                                                        Versions     Fixed
  LightSync Pro – Connect & Sync Cloud Assets | Lightroom, Canva, Figma, Dropbox & Shutterstock  unspecified  —
TIMELINE
  Apr 12  Reserved by CNA
  Aug 5   Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · 4 references · NVD status: Deferred
saadiqbal WPFormify – Stripe Payments with Form and Checkout — WPFormify <= 1.1.1 - Missing Authorization
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  L    8.2   .0062   46.6     —
AFFECTED
  Product                                             Versions     Fixed
  WPFormify – Stripe Payments with Form and Checkout  unspecified  —
TIMELINE
  Apr 19  Reserved by CNA
  Aug 5   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · 4 references · NVD status: Deferred
TECNO Mobile Hi Browser — PathTravelsal Vulnerability in com.talpa.hibrowser
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0059   45.3     —
AFFECTED
  Product     Versions    Fixed
  Hi Browser  2.23.1.1 –  —
TIMELINE
  Aug 5   Reserved by CNA
  Aug 5   Published (CNA: TECNOMobile)
CWE-23 · CNA: TECNOMobile · 1 reference · NVD status: Received
Zbtlink CPE2801 Firmware — ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0058   44.9     —
AFFECTED
  Product                Versions      Fixed
  CPE2801 Firmware       22.10.09 –    —
  WE1026-5G-WD Firmware  21.04.07 –    —
  WE1326 Firmware        22.02.18_1 –  —
  WE2007 Firmware        23.08.12 –    —
  WE2008-DSIM Firmware   23.08.11 –    —
  WE2416 Firmware        21.03.22_1 –  —
  WE3326 Firmware        20.09.30 –    —
  WE5927 Firmware        22.08.10 –    —
  WE5931 Firmware        22.05.31 –    —
  WE5931AC Firmware      22.05.31 –    —
  + 10 more
TIMELINE
  Jul 27  Reserved by CNA
  Aug 5   Published (CNA: VulnCheck)
CWE-506 · CNA: VulnCheck · 4 references · NVD status: Received
n/a n/a — In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw fo…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0058   44.8     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jul 30  Reserved by CNA
  Aug 5   Published (CNA: mitre)
CWE-476 · CNA: mitre · 4 references · NVD status: Received
milvus-io milvus — Milvus 2.6.22, 3.0.0 Unauthenticated Denial of Service via /management/stop
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0057   44.4     —
AFFECTED
  Product  Versions     Fixed
  milvus   unspecified  —
TIMELINE
  Aug 3   Reserved by CNA
  Aug 5   Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · 4 references · NVD status: Received
UTT HiPER 1250GW APSecurity_5g strcpy stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0057   44.3     —
AFFECTED
  Product       Versions               Fixed
  HiPER 1250GW  3.2.7-210907-180535 –  —
TIMELINE
  Aug 4   Reserved by CNA
  Aug 5   Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 5 references · NVD status: Deferred
UTT HiPER 1250GW getOneApConfTempEntry strcpy stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0057   44.3     —
AFFECTED
  Product       Versions                Fixed
  HiPER 1250GW  v3.2.7-210907-180535 –  —
TIMELINE
  Aug 4   Reserved by CNA
  Aug 5   Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 5 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-614869.844.3Apache Software FoundationApache LucyCWE-121Apache Lucy: stack-buffer-overflow in JSON parser error reporter on malformed…
CVE-2026-175326.144.0seraphinitesoftSeraphinite AcceleratorCWE-79Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting
CVE-2026-614849.843.6Apache Software FoundationApache LucyCWE-502Apache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::tha…
CVE-2026-60207.242.8devitemsllcShopLentor – All-in-One WooCommerce Growth & Store Enhancement PluginCWE-470ShopLentor <= 3.3.7 - Authenticated (Administrator+) Arbitrary Function Execu…
CVE-2026-645777.542.7LinuxLinuxgtp: check skb_pull_data() return in gtp1u_send_echo_resp()
CVE-2026-712079.842.4mrswapnilsahuStock-Inventory-Management-SystemCWE-89Stock-Inventory-Management-System - Unauthenticated SQL Injection and Hardcod…
CVE-2026-676238.642.3mistralaimistral-vibeCWE-829Mistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor Hook
CVE-2026-614837.541.9Apache Software FoundationApache LucyCWE-674Apache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stac…
CVE-2026-614857.541.9Apache Software FoundationApache LucyCWE-789Apache Lucy: Freezer/InStream deserialization bomb - unbounded allocation rea…
CVE-2026-488347.540.2Apache Software FoundationApache AnswerCWE-400Apache Answer: Denial of service via crafted Accept-Language header parsing
CVE-2026-662747.540.2Apache Software FoundationApache Qpid Proton-JCWE-674Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication s…
CVE-2026-674657.540.2Apache Software FoundationApache Qpid Proton DotnetCWE-770Apache Qpid Proton Dotnet: Unbounded symbol value caching can lead to pre-aut…
CVE-2026-675517.540.2Apache Software FoundationApache Qpid Proton DotnetCWE-789Apache Qpid Proton Dotnet: Type size/count handling can lead to excessive all…
CVE-2026-675897.540.2Apache Software FoundationApache Qpid ProtonJ2CWE-789Apache Qpid ProtonJ2: Type size/count handling can lead to excessive allocati…
CVE-2026-675907.540.2Apache Software FoundationApache Qpid ProtonJ2CWE-674Apache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication s…
CVE-2026-680747.540.2Apache Software FoundationApache Qpid Broker-JCWE-770Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authenti…
CVE-2026-557077.139.8OpenStackNeutronCWE-863In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not ve…
CVE-2026-675527.539.5Apache Software FoundationApache Qpid Proton DotnetCWE-674Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authenticat…
CVE-2026-675887.539.5Apache Software FoundationApache Qpid ProtonJ2CWE-770Apache Qpid ProtonJ2: Unbounded symbol value caching can lead to pre-authenti…
CVE-2026-680607.539.5Apache Software FoundationApache Qpid Broker-JCWE-770Apache Qpid Broker-J: Type size/count handling can lead to excessive allocati…
CVE-2026-680737.539.5Apache Software FoundationApache Qpid Broker-JCWE-674Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication s…
CVE-2026-84009.839.5IBMWebSphere Application ServerCWE-470Multiple Vulnerabilities in IBM® Java SDK affect IBM WebSphere Application Se…
CVE-2026-160227.839.4Swiss Federal Office of Information Technology, Systems and Telecommunication@oblique/cliCWE-78Command Injection in @oblique/cli
CVE-2026-675927.539.2Apache Software FoundationApache Qpid ProtonJ2CWE-770Apache Qpid ProtonJ2: Unable to govern the maximum number of transfer frames …
CVE-2026-91929.838.9Progress Software CorporationMarkLogic ServerCWE-287Authentication bypass in Progress MarkLogic Server ODBC App Server
CVE-2026-188987.438.7UTTHiPER 1200GWCWE-119UTT HiPER 1200GW ConfigAdvideo strcpy stack-based overflow
CVE-2026-711908.738.4OpenStackSwiftCWE-1333In OpenStack Swift through 2.38.0, the proxy server Accept header parser cont…
CVE-2026-678667.538.4n/an/aCWE-121Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacke…
CVE-2026-678677.538.4n/an/aCWE-122Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacke…
CVE-2026-678697.538.4n/an/aCWE-120Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to…
CVE-2026-678717.538.4n/an/aCWE-120Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacke…
CVE-2026-175568.838.3GitHubEnterprise ServerCWE-22Path traversal in GitHub Enterprise Server allowed unauthenticated deletion o…
CVE-2026-55819.137.8sh1zenMulti Uploader for Gravity FormsCWE-862Multi Uploader for Gravity Forms <= 1.1.8 - Missing Authorization to Unauthen…
CVE-2026-189017.337.6H3CNX15CWE-749H3C NX15 Web API esps service.add routine
CVE-2026-618917.537.5Eclipse FoundationEclipse TheiaCWE-22In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem`…
CVE-2026-176328.837.3IBMLangflow OSSCWE-94Langflow OSS is affected by arbitrary code execution in component generation,…
CVE-2026-687467.737.2livebook-devlivebookCWE-636Livebook Teams identity check fails open when the deployment group is unresol…
CVE-2026-713208.136.5nuxtnuxtCWE-74Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nux…
CVE-2025-638239.836.4n/an/aCWE-798My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the …
CVE-2026-675319.336.1agentfrontfrontmcpCWE-94FrontMCP: CodeCall sandbox escape -> host RCE via live Zod schema exposure by…
CVE-2026-596757.536.0SUSERancherCWE-770Rancher Audit-Log Middleware Unauthenticated Memory Exhaustion Denial of Service
CVE-2026-145538.136.0UnknownzportalsCWE-434Zportals < 6.3.4 - Subscriber+ Arbitrary File Upload
CVE-2026-662577.535.6Apache Software FoundationApache Qpid Proton-JCWE-770Apache Qpid Proton-J: Unbounded symbol value caching can lead to pre-authenti…
CVE-2026-662737.535.6Apache Software FoundationApache Qpid Proton-JCWE-789Apache Qpid Proton-J: Type size/count handling can lead to excessive allocati…
CVE-2026-91909.135.2Progress Software CorporationMarkLogic ServerCWE-444HTTP request smuggling in Progress MarkLogic Server
CVE-2026-176137.535.3PenpotPenpotCWE-862CVE-2026-17613
CVE-2026-678647.535.2n/an/aCWE-400An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a …
CVE-2026-678657.535.2n/an/aCWE-125S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handling. Thi…
CVE-2026-678727.535.2n/an/aCWE-400An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial o…
CVE-2026-713217.535.3nuxtnuxtCWE-407Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endp…
CVE-2026-176308.835.1IBMLangflow OSSCWE-184Langflow is affected by security vulnerabilities in Model Context Protocol fe…
CVE-2026-662756.535.2Apache Software FoundationApache Qpid Proton-JCWE-770Apache Qpid Proton-J: Incoming session flow control window can be exceeded
CVE-2026-662766.535.2Apache Software FoundationApache Qpid Proton-JCWE-606Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial…
CVE-2026-662776.535.2Apache Software FoundationApache Qpid Proton-JCWE-770Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames …
CVE-2026-675916.535.2Apache Software FoundationApache Qpid ProtonJ2CWE-770Apache Qpid ProtonJ2: Incoming session flow control window can be exceeded
CVE-2026-680756.535.2Apache Software FoundationApache Qpid Broker-JCWE-770Apache Qpid Broker-J: Incoming session flow control window can be exceeded
CVE-2026-680776.535.2Apache Software FoundationApache Qpid Broker-JCWE-606Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial…
CVE-2026-680806.535.2Apache Software FoundationApache Qpid Broker-JCWE-406Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of ser…
CVE-2026-712379.835.1MiantangIoT-PHPCWE-89Miantang IoT-PHP - Unauthenticated SQL Injection in /userlogin
CVE-2026-675536.534.4Apache Software FoundationApache Qpid Proton DotnetCWE-770Apache Qpid Proton Dotnet: Incoming session flow control window can be exceeded
CVE-2026-675546.534.4Apache Software FoundationApache Qpid Proton DotnetCWE-606Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to d…
CVE-2026-675556.534.4Apache Software FoundationApache Qpid Proton DotnetCWE-770Apache Qpid Proton Dotnet: Unable to govern the maximum number of transfer fr…
CVE-2026-680786.534.4Apache Software FoundationApache Qpid Broker-JCWE-770Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames …
CVE-2026-678637.534.2n/an/aCWE-416In open62541 1.5.5, a server-side use-after-free exists in the local Monitore…
CVE-2026-126097.534.0Eclipse FoundationEclipse TheiaCWE-22In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/p…
CVE-2026-712489.833.4Harsh21PatelInventory-Management-System-PHPCWE-89Inventory-Management-System-PHP - Unauthenticated SQL Injection in Login and …
CVE-2026-678739.833.3n/an/aCWE-122A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side Fi…
CVE-2026-713147.533.2nuxtnuxtCWE-400Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in is…
CVE-2026-159966.633.2GitHubEnterprise ServerCWE-674Denial of service vulnerability in GitHub Enterprise Server allowed unauthent…
CVE-2026-1694010.033.2UnknownCustom FieldsCWE-22Custom Fields for WooCommerce < 1.5.1 - Unauthenticated Arbitrary File Deleti…
CVE-2026-176338.832.9IBMLangflow OSSCWE-94Langflow OSS is affected by arbitrary code execution in component generation,…
CVE-2026-114546.532.7trainingbusinessprosGroundhogg — CRM, Newsletters, and Marketing AutomationCWE-639Groundhogg — CRM, Newsletters, and Marketing Automation <= 4.5.2 - Insecure D…
CVE-2026-600237.532.5Apache Software FoundationApache AnswerCWE-200Apache Answer: Unauthorized disclosure of deleted or pending answer content
CVE-2026-60797.332.6ho3einieMaterial DashboardCWE-862Material Dashboard <= 1.4.10 - Missing Authorization to Unauthenticated Task …
CVE-2026-203109.132.3CiscoCisco Catalyst SD-WAN ControllerCWE-59Cisco SD-WAN Software Security Hardening Release - Improper Link Resolution B…
CVE-2026-91959.332.0Progress Software CorporationMarkLogic ServerCWE-22Cross-site scripting in Progress MarkLogic Server Query Console
CVE-2026-159187.532.0e4jvikwpVikAppointments Services Booking CalendarCWE-89VikAppointments – Services Booking Calendar <= 1.2.19 - Unauthenticated SQL I…
CVE-2026-81828.831.5IBMLangflow OSSCWE-94Langflow OSS is affected by arbitrary code execution in component generation,…
CVE-2026-706105.431.4electronelectronCWE-1321Electron: contextBridge object copy honors prototype setters
CVE-2025-709627.531.3n/an/aCWE-284Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The …
CVE-2026-712697.231.2node-rednode-redCWE-22Node-RED Library API Path Traversal Leading to Arbitrary File Read/Write
CVE-2026-145875.531.2neo4jEnterprise EditionCWE-130Unathenticated connection can hold Bolt channel open
CVE-2026-185315.330.9IBMMaximo Application SuiteCWE-330IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerab…
CVE-2026-56514.930.92wstechnologiesAskeet — Talk to Your WooCommerce DataCWE-89Askeet <= 3.0 - Authenticated (Administrator+) SQL Injection via 'sql_query' …
CVE-2026-668817.030.8livebook-devlivebookCWE-23Path traversal in imported file_entries name allows arbitrary file write via …
CVE-2026-176248.830.7IBMLangflow OSSCWE-94Langflow OSS is affected by arbitrary code execution in component generation,…
CVE-2026-188817.530.7realmag777TableOn – WordPress Posts Table FilterableCWE-89TableOn <= 1.0.5.1 - Unauthenticated Blind SQL Injection via 'comment_count' …
CVE-2026-704318.830.5Jenkins ProjectJenkins Multijob PluginCWE-94Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scrip…
CVE-2026-81837.730.5IBMLangflow OSSCWE-22Langflow OSS is affected by arbitrary code execution in custom component vali…
CVE-2026-489117.530.5Apache Software FoundationApache AnswerCWE-306Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Exist…
CVE-2026-713105.930.4rclonercloneCWE-400rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory
CVE-2026-712157.530.4art-templateart-templateCWE-22art-template - Path Traversal in Sub-Template Resolution via include()/extend()
CVE-2026-189592.130.3yushineInnoShopCWE-22yushine InnoShop Files Endpoint panel-api.php destroyFiles path traversal
CVE-2026-84788.830.2IBMLangflow OSSCWE-94Langflow OSS is affected by arbitrary code execution in component generation,…
CVE-2026-465817.530.2Eclipse FoundationEclipse MojarraCWE-22In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFacelet…
CVE-2026-87618.829.9dokanincDokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, EtsyCWE-862Dokan <= 5.0.2 - Missing Authorization to Authenticated (Vendor+) Privilege E…
CVE-2026-712899.829.8NASA-AMMOSanmsCWE-306NASA-AMMOS ANMS / JHUAPL dtnma-tools Unauthenticated Remote Command Execution…
CVE-2026-66397.529.8wupsalesAI Copilot – Content GeneratorCWE-862AI Chatbot & Workflow Automation by AIWU <= 1.4.6 - Missing Authorization to …
CVE-2026-712689.929.6thiagoralvesOpenPLC_v3CWE-22OpenPLC Runtime v3 Path Traversal in Structured Text FILE Directive Leading t…
CVE-2026-202729.829.5CiscoCisco IOS XE SoftwareCWE-74Cisco IOS XE Software Security Hardening Release
CVE-2026-153727.529.5UnknownWP 2FACWE-287WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via Passkeys Provider
CVE-2026-712798.029.4Koenkkzigbee2mqttCWE-22Zigbee2MQTT External JS Extension Path Traversal Leading to Remote Code Execu…
CVE-2026-706125.429.2electronelectronCWE-284Electron: Sandboxed iframes can launch external protocol handlers
CVE-2026-712319.828.9thebradleysandersIOTSmartHomeCWE-89IOTSmartHome - Unauthenticated SQL Injection via lastLogin Cookie
CVE-2026-712789.828.9iot-ecologyrust-iot-platformCWE-94rust-iot-platform Unauthenticated Remote Code Execution via Unsandboxed Calc-…
CVE-2026-703777.528.8theotherphilimagecliCWE-789imagecli - Uncontrolled Memory Allocation via Unbounded scale Ratio Causes De…
CVE-2026-189032.128.8yeqifuwarehouseCWE-22yeqifu warehouse FileController.java path traversal
CVE-2026-77536.528.6stylemixCost Calculator BuilderCWE-862Cost Calculator Builder <= 3.6.17 - Missing Authorization to Authenticated (S…
CVE-2026-645669.828.2LinuxLinuxxfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()
CVE-2026-75297.528.2wisematticwiseCampaign – WooCommerce Conversions Made EasyCWE-862wiseCampaign <= 1.1.16 - Missing Authorization to Unauthenticated Plugin Conf…
CVE-2026-712629.828.1IoTSharpIoTSharpCWE-306IoTSharp BlobStorageController Missing Authentication and Path Traversal
CVE-2026-600539.127.9Apache Software FoundationApache AnswerCWE-613Apache Answer: Residual Administrative API Key Access After Role or Account R…
CVE-2026-155728.827.9Red HatRed Hat build of Keycloak 26.4CWE-843Keycloak-services: keycloak-services: dcr protocol mapper type-swap policy by…
CVE-2026-100259.827.8IBMQRadarCWE-611IBM QRadar SIEM has an XML External Entity (XXE) injection vulnerability
CVE-2026-202886.527.6CiscoCisco Unified Computing System (Standalone)CWE-146Cisco IMC Remote Code Execution Vulnerability Remote Code Execution Vulnerabi…
CVE-2026-201247.727.5CiscoCisco IOS XE SoftwareCWE-772Cisco IOS XE Software SNMP Denial of Service Vulnerability
CVE-2026-555237.727.3MervinPraisonPraisonAICWE-918PraisonAI has a`web_crawl` SSRF protection bypass via unchecked redirect targets
CVE-2026-544167.227.2pluck-cmsPluck CMSCWE-434Pluck CMS - Unrestricted File Upload via Missing .php8 Extension in Upload Bl…
CVE-2026-176179.826.5IBMApplication Gateway OperatorCWE-918Server-Side Request Forgery (SSRF) in IBM Application Gateway Operator
CVE-2026-152816.526.5gm_alexUser Access ManagerCWE-89User Access Manager <= 2.3.12 - Authenticated (Subscriber+) SQL Injection
CVE-2026-184117.226.4AcrisureKARR BTCWE-321Use of hard-coded cryptographic key in Acrisure KARR BT and DR-100
CVE-2026-76586.526.4IBMLangflow OSSCWE-22Langflow OSS is affected by arbitrary code execution in custom component vali…
CVE-2026-706075.326.4electronelectronCWE-20Electron: window.open features string controls some window options considered…
CVE-2026-44319.126.3themerubyEasy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPressCWE-862Easy Post Submission <= 2.3.0 - Missing Authorization
CVE-2026-114216.525.6wedevsERP: Complete HR, Accounting & CRM Suite Built for WooCommerceCWE-89ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support <= 1.17…
CVE-2026-202638.625.6CiscoCisco IOS XE SoftwareCWE-388Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service V…
CVE-2026-203018.625.6CiscoCisco IOS XE SoftwareCWE-606Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol D…
CVE-2026-713199.625.3nuxtdevtoolsCWE-94Nuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code Execution
CVE-2026-153609.125.2UnknownAjax Load MoreCWE-89Ajax Load More < 8.0.1 - Unauthenticated SQL Injection via custom_args
CVE-2026-712139.125.1typemilltypemillCWE-307typemill - No Rate Limiting on Login Endpoint Enables Unlimited Password Brut…
CVE-2026-600098.825.1Eclipse FoundationEclipse TheiaCWE-22In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem`…
CVE-2026-706095.725.0electronelectronCWE-94Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
CVE-2026-203084.324.7CiscoCisco IOS XE SoftwareCWE-269Cisco IOS XE Software Web-Based Management Interface Vulnerability
CVE-2026-712927.224.6intelliantssubrionCWE-89Subrion CMS Admin Grid SQL Injection via Unwhitelisted ORDER BY sort Parameter
CVE-2026-73299.924.5Progress Software CorporationMarkLogic ServerCWE-269Privilege escalation in Progress MarkLogic Server REST query interfaces
CVE-2026-645788.224.4LinuxLinuxksmbd: validate compound request size before reading StructureSize2
CVE-2026-166027.524.3UnknownPasssterCWE-200Content Protector (Passster) < 4.3.6 - Unauthenticated Non-Public Post Conten…
CVE-2026-166037.524.3UnknownPasssterCWE-200Content Protector (Passster) < 4.3.6 - Unauthenticated Category-Locked Conten…
CVE-2026-166047.524.3UnknownPasssterCWE-200Content Protector (Passster) < 4.3.6 - Unauthenticated Protected Content Disc…
CVE-2026-166057.224.4UnknownMultiVendorXCWE-862MultiVendorX < 5.0.11 - Store Owner+ Cross-Vendor Store Takeover and Deletion…
CVE-2026-183228.824.1supsysticcomSmart Popup by SupsysticCWE-269Smart Popup by Supsystic <= 1.12.0 - Unauthenticated Privilege Escalation to …
CVE-2026-713098.624.1rclonercloneCWE-22rclone: Incomplete path validation allows backend root escape in serve restic
CVE-2026-349668.324.1GiteaGiteaCWE-918Gitea prior to 1.27.0 SSRF via Migration URI Fetch Bypass
CVE-2026-712389.124.0DjangoCRMdjango-crmCWE-798DjangoCRM - Hardcoded Django SECRET_KEY Enables Session and CSRF Token Forgery
CVE-2026-712708.624.0Stirling-ToolsStirling-PDFCWE-918Stirling-PDF Server-Side Request Forgery via /api/v1/convert/url/pdf WeasyPri…
CVE-2026-107167.523.7DirectusDirectusCWE-89Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostG…
CVE-2026-203039.923.5CiscoCisco Catalyst SD-WAN ControllerCWE-20Cisco Catalyst SD-WAN Security Hardening Release - Input Validation Vulnerabi…
CVE-2026-90778.523.6IBMLangflow OSSCWE-807Reliance on Untrusted Inputs in a Security Decision vulnerabilities in Model …
CVE-2026-712549.823.4debevvnanoMODBUSCWE-787nanoMODBUS Server-Side Out-of-Bounds Write in handle_read_file_record()
CVE-2026-712569.823.4debevvnanoMODBUSCWE-125nanoMODBUS Client-Side Out-of-Bounds Read Leading to Wild-Pointer Write via o…
CVE-2026-712679.823.4rximicrotarCWE-121microtar Stack Buffer Overflow in mtar_write_file_header() and mtar_write_dir…
CVE-2026-161006.523.3Red HatRed Hat build of Keycloak 26.6CWE-770Keycloak-services: keycloak-services: unbounded metric cardinality in user ev…
CVE-2026-712878.823.1CacticactiCWE-89Cacti sanitize_sql_column() Regex Allowlist Permits SQL Time-Delay Functions …
CVE-2026-712888.823.1Koha CommunityKohaCWE-89Koha SQL Injection via order_by and {order}_ovalue Parameters in guided_repor…
CVE-2026-712918.823.1boltcoreCWE-1336Bolt CMS Server-Side Template Injection via Unsandboxed allow_twig Field Rend…
CVE-2026-489126.523.2Apache Software FoundationApache AnswerCWE-639Apache Answer: Improper authorization in avatar update cleanup allows authent…
CVE-2026-507496.523.2Apache Software FoundationApache AnswerCWE-863Apache Answer: Missing authorization in revision audit reject allows authenti…
CVE-2026-160557.523.0UnknownContest GalleryCWE-287Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass vi…
CVE-2026-449459.122.9SUSERancherCWE-441Cross-Cluster Impersonation Confused-Deputy Privilege Escalation
CVE-2026-76466.522.8IBMLangflow OSSCWE-22Langflow is affected by security vulnerabilities in Model Context Protocol fe…
CVE-2026-119694.922.7jgwhite33WP TripAdvisor Review SliderCWE-89WP TripAdvisor Review Slider <= 14.3 - Authenticated (Administrator+) SQL Inj…
CVE-2026-160367.522.5UnknownminiOrange 2FACWE-287miniOrange 2FA < 6.2.7 - 2FA Bypass via Password-Only Second-Factor Rebinding
CVE-2026-712327.222.6magicblackmaccms10CWE-94MacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authentic…
CVE-2026-713167.522.3nuxtnuxtCWE-524Nuxt runtime payload cache discloses another user's SSR data across users and…
CVE-2026-51164.422.3sevensparkDTX – Dynamic Text Extension for Contact Form 7CWE-79Contact Form 7 – Dynamic Text Extension <= 5.0.5 - Authenticated (Editor+) St…
CVE-2026-152109.122.2UnknownOTP Login With Phone Number, OTP VerificationCWE-287Login/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated A…
CVE-2026-165617.522.2UnknownSunshine Photo CartCWE-862Sunshine Photo Cart < 3.6.12 - Unauthenticated Private Gallery Comment Disclo…
CVE-2026-167367.522.2UnknownUser Registration & MembershipCWE-284User Registration & Membership < 5.2.6 - Unauthenticated Account Creation Whi…
CVE-2026-704269.021.8Jenkins ProjectJenkinsCWE-502In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, i…
CVE-2026-155738.121.5Red HatRed Hat build of Keycloak 26.4CWE-178Keycloak-services: keycloak-services: authorization bypass via unnormalized u…
CVE-2026-119204.921.5beardevJoomSport – for Sports: Team & League, Football, Hockey & moreCWE-89JoomSport <= 5.7.9 - Authenticated (Administrator+) SQL Injection via 'order'…
CVE-2026-712358.821.3absmachmagistralaCWE-94Magistrala IoT Platform - Unrestricted Go/Lua Script Execution in Rules Engine
CVE-2026-712438.821.3adaltasbackmeupCWE-78backmeup (npm) - OS Command Injection via Backup Option Values
CVE-2026-176268.821.1IBMLangflow OSSCWE-266Langflow is affected by security vulnerabilities in Model Context Protocol fe…
CVE-2026-712834.921.1fledge-iotfledgeCWE-22Fledge IoT Gateway Backup Restore Tar Path Traversal
CVE-2026-712528.220.9raghav993toner-managementCWE-862toner-management - Unauthenticated State-Changing Admin Actions
CVE-2026-84467.520.9IBMLangflow OSSCWE-306Langflow is affected by security vulnerabilities in Model Context Protocol fe…
CVE-2026-712417.520.7lyric777Book-Management-SystemCWE-306Book-Management-System - Unauthenticated Disclosure of Student PII and Borrow…
CVE-2026-145745.720.7Eclipse FoundationEclipse TheiaCWE-1321In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `Preferenc…
CVE-2026-712639.120.3cwalter-atFreeModbusCWE-787FreeModbus LINUXTCP Port Off-by-One Global Buffer Overflow in xMBPortTCPPool()
CVE-2026-703787.520.2theotherphilimagecliCWE-1284imagecli - Negative carve Ratio Bypasses Bounds Check and Crashes Process via…
CVE-2026-189337.220.2wp-downloadmanagerwp-downloadmanagerCWE-434wp-downloadmanager - Unrestricted File Upload via Missing Extension/MIME Vali…
CVE-2026-189695.520.3RongzhitongVisual Integrated Command and Dispatch PlatformCWE-284Rongzhitong Visual Integrated Command and Dispatch Platform upload unrestrict…
CVE-2026-92739.320.0stellarwpMembership Plugin – Kadence MembershipsCWE-640Membership Plugin – Kadence Memberships <= 4.0.0 - Unauthenticated Password R…
CVE-2026-713128.020.0rclonercloneCWE-78rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Co…
CVE-2026-100599.119.6Red HatMulticluster Engine for KubernetesCWE-266Cluster-curator-controller: cluster-curator-controller: namespace admin can e…
CVE-2026-712818.819.5huggingfacepeftCWE-502peft Unsafe Deserialization via torch.load() Without weights_only in LoRA-GA …
CVE-2026-75208.119.2mailmunchMailmunch Forms for MailchimpCWE-862MailChimp Forms by MailMunch <= 3.2.7 - Missing Authorization to Authenticate…
CVE-2026-203049.919.1CiscoCisco Catalyst SD-WAN ControllerCWE-284Cisco Catalyst SD-WAN Security Hardening Release - Access Control Vulnerabili…
CVE-2026-524669.819.0n/an/aCWE-863Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect A…
CVE-2026-712149.819.0NASA-AMMOSplandev (sequencing-server)CWE-306NASA-AMMOS plandev - Client-Supplied session_variables Bypass Hasura-Origin A…
CVE-2026-202688.618.9CiscoCisco IOS XE SoftwareCWE-119Cisco IOS XE Software Security Hardening Release
CVE-2026-202698.618.9CiscoCisco IOS XE SoftwareCWE-664Cisco IOS XE Software Security Hardening Release
CVE-2026-202708.618.9CiscoCisco IOS XE SoftwareCWE-682Cisco IOS XE Software Security Hardening Release
CVE-2026-202718.618.9CiscoCisco IOS XE SoftwareCWE-691Cisco IOS XE Software Security Hardening Release
CVE-2026-202738.618.9CiscoCisco IOS XE SoftwareCWE-20Cisco IOS XE Software Security Hardening Release
CVE-2026-713158.218.9nuxtnuxtCWE-178Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddlewa…
CVE-2026-165737.518.9UnknownBit FormCWE-79Bit Form < 3.2.0 - Unauthenticated Stored XSS via SVG Signature Upload
CVE-2026-77266.518.9techeshtaLayouts for WPBakeryCWE-862Layouts for WPBakery <= 1.1.3 - Missing Authorization to Unauthenticated Temp…
CVE-2026-75579.118.6Progress Software CorporationMarkLogic ServerCWE-347SAML authentication bypass in Progress MarkLogic Server
CVE-2026-50624.918.8supercleansePrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short LinksCWE-89PrettyLinks <= 3.6.20 - Authenticated (Administrator+) SQL Injection via 's' …
CVE-2026-91968.818.5IBMLangflow OSSCWE-94Langflow OSS is affected by arbitrary code execution in component generation,…
CVE-2026-557398.318.5crater-invoiceCraterCWE-639Crater - Missing Tenant-Ownership Check in CustomerPolicy Allows Cross-Compan…
CVE-2026-203137.718.3CiscoCisco Catalyst SD-WAN ControllerCWE-1284Cisco Catalyst SD-WAN Security Hardening Release - Memory Corruption Vulnerab…
CVE-2026-712027.518.2kosinixrasterCWE-191raster - Integer Underflow in crop() Offset Handling Causes Capacity-Overflow…
CVE-2026-189682.118.3ttttonyheOBlogCWE-79ttttonyhe OBlog tags.php cross site scripting
CVE-2026-548767.518.0OpenSSLOpenSSLCWE-401Client-Side Memory Leak in OCSP Response Checking
CVE-2026-399239.217.9FlarumFlarum FrameworkCWE-324Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset
CVE-2026-134778.817.8IBMQRadarCWE-78IBM QRadar SIEM is vulnerable to remote code execution by privileged users
CVE-2026-706087.217.7electronelectronCWE-693Electron: Sandboxed iframe can bypass the allow-popups restriction via the Op…
CVE-2026-557476.817.6The-PocketPocketFlow (pocketflow-coding-agent cookbook example)CWE-22PocketFlow - Path Traversal in pocketflow-coding-agent Cookbook Example File …
CVE-2026-87099.917.6Progress Software CorporationMarkLogic ServerCWE-269Privilege escalation in Progress MarkLogic Server REST document patch operation
CVE-2026-91939.917.6Progress Software CorporationMarkLogic ServerCWE-269Privilege escalation in Progress MarkLogic Server Hadoop integration
CVE-2026-188545.517.1Shandong HoteamPDM Product Data Management SystemCWE-74Shandong Hoteam PDM Product Data Management System DataService GetStoredClass…
CVE-2026-188595.517.1ESAFENETCDGCWE-74ESAFENET CDG usbkey;logindojojs sql injection
CVE-2026-189585.517.1imranrisal-devStudent-Management-SystemCWE-74imranrisal-dev Student-Management-System Login loginCheckTest.php sql injection
CVE-2026-189705.517.1RongzhitongVisual Integrated Command and Dispatch PlatformCWE-74Rongzhitong Visual Integrated Command and Dispatch Platform findAll sql injec…
CVE-2026-161028.117.0Red HatRed Hat build of Keycloak 26.4CWE-284Keycloak-services: keycloak-services: default dcr policy allows role forgery …
CVE-2026-713136.917.0rclonercloneCWE-22rclone: Local Encoding Path Traversal
CVE-2026-711926.016.9OpenStackSwiftCWE-863In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swi…
CVE-2026-711916.016.8OpenStackSwiftCWE-863In OpenStack Swift through 2.38.0, S3API middleware does not enforce that sem…
CVE-2026-200285.016.8CiscoCisco Terminal Services AgentCWE-266Cisco Terminal Services Agent Firewall Rules Bypass Vulnerability
CVE-2026-119776.516.5afthemesWP Post Author – Author Box, Multiple Authors, Guest Authors & Custom AvatarsCWE-89WP Post Author <= 3.9.1 - Authenticated (Author+) SQL Injection
CVE-2026-159416.516.5RelevanssiRelevanssi Premium – A Better SearchCWE-89Relevanssi <= 4.27.1 and Relevanssi Premium <= 2.30.2 - Authenticated (Contri…
CVE-2026-152308.116.3UnknownYayPricingCWE-284YayPricing < 3.5.7 - Subscriber+ Pricing Configuration Modification and Coupo…
CVE-2026-544188.116.3LeantimeLeantimeCWE-862Leantime - Missing Authorization on TwoFA JSON-RPC Methods Allows Cross-Accou…
CVE-2026-704274.316.4Jenkins ProjectJenkinsCWE-59Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle sym…
CVE-2026-100909.016.3Red HatRed Hat Advanced Cluster Management for Kubernetes 2CWE-267Multicluster-operators-subscription: multicluster-operators-subscription: nam…
CVE-2026-74566.516.2webocodersUdimi ToolsCWE-862Udimi Tools <= 3.2 - Missing Authorization to Authenticated (Subscriber+) Plu…
CVE-2026-202679.015.9CiscoCisco IOS XE SoftwareCWE-284Cisco IOS XE Software Security Hardening Release
CVE-2026-712347.516.0documizecommunityCWE-863Documize Community - Attachment Download Authorization Bypass via Non-Validat…
CVE-2026-51084.416.0superpwaSuper Progressive Web AppsCWE-79Super Progressive Web Apps <= 2.2.43 - Authenticated (Administrator+) Stored …
CVE-2026-704284.315.9Jenkins ProjectJenkinsCWE-22Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file…
CVE-2026-09316.915.6M-Files CorporationM-Files ServerCWE-1286Denial-of-service vulnerability in M-Files Server
CVE-2026-712779.115.5iot-ecologyrust-iot-platformCWE-287rust-iot-platform Authentication Bypass via Non-Validated Authorization Header
CVE-2026-704298.115.5Jenkins ProjectJenkinsCWE-178Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity…
CVE-2026-712256.515.4Stephan MuellelibkcapiCWE-330Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes ciph…
CVE-2026-127625.315.4IBMCloud Pak For Business AutomationCWE-538Insertion of Sensitive Information into Externally-Accessible File in IBM Bus…
CVE-2026-712718.515.2usememosmemosCWE-918Memos Webhook SSRF via 0.0.0.0 Reserved-IP Bypass
CVE-2026-154524.715.2smubSmash Balloon Social Photo Feed – Easy Social Feeds PluginCWE-79Smash Balloon Social Photo Feed <= 6.11.3 - Reflected Cross-Site Scripting vi…
CVE-2026-713116.415.0rclonercloneCWE-93rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Pres…
CVE-2026-161437.214.9e4jvikwpVikRentItems Flexible Rental Management SystemCWE-79VikRentItems Flexible Rental Management System <= 1.2.1 - Unauthenticated Sto…
CVE-2026-92018.814.3IBMLangflow OSSCWE-326Langflow OSS is affected by arbitrary code execution in component generation,…
CVE-2026-712606.514.3esphomeesphomeCWE-522ESPHome web_server Plaintext Password Disclosure via JSON "value" Field
CVE-2026-92059.814.2IBMLangflow OSSCWE-338Langflow is affected by weaknesses in secret handling and sensitive configura…
CVE-2026-706178.614.1Spacebar ServerSpacebar ServerCWE-862Spacebar Server Missing Authorization via Group DM Recipient Endpoint
CVE-2026-539925.114.1ProjectSendProjectSendCWE-79Reflected XSS in ProjectSend thumbnails-regenerate.php via start_date / end_d…
CVE-2026-175067.214.0bensibleyIndependent Analytics – WordPress Analytics PluginCWE-79Independent Analytics <= 2.15.0 - Unauthenticated Stored Cross-Site Scripting
CVE-2026-712826.513.7chirpstackchirpstackCWE-89ChirpStack SQLite Backend SQL Injection via Device Tag Key in ListDevices Filter
CVE-2026-188562.013.6PoesisRhymix CMSCWE-918Poesis Rhymix CMS Data Import importer.admin.controller.php procImporterAdmin…
CVE-2026-105478.113.4IBMLangflow OSSCWE-284Langflow OSS is affected by arbitrary code execution in custom component vali…
CVE-2026-712398.113.4DjangoCRMdjango-crmCWE-1336DjangoCRM - Server-Side Template Injection in Mass Mail Message Rendering
CVE-2026-399247.613.4FlarumFlarum FrameworkCWE-613Flarum < 1.8.16 Session Persistence via Improper Access Token Revocation
CVE-2026-712947.613.3CotontiCotontiCWE-502Cotonti CMS Comments Plugin PHP Object Injection via Unrestricted unserialize…
CVE-2026-257037.313.3SUSENeuVectorCWE-202Potential information leakage from manager /network/graph API in NeuVector
CVE-2026-101286.513.2IBMLangflow OSSCWE-200Langflow is affected by weaknesses in secret handling and sensitive configura…
CVE-2026-73278.113.0Progress Software CorporationMarkLogic ServerCWE-269Privilege escalation in Progress MarkLogic Server REST API document processing
CVE-2025-638228.112.9n/an/aCWE-284SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Contro…
CVE-2026-704364.312.8Jenkins ProjectJenkins External Workspace Manager PluginCWE-862Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform …
CVE-2026-712558.612.7debevvnanoMODBUSCWE-787nanoMODBUS Client-Side Out-of-Bounds Write via object_length in recv_read_dev…
CVE-2026-87906.112.8antoinehFootball PoolCWE-79Football Pool <= 2.13.4 - Authenticated (Subscriber+) Reflected Cross-Site Sc…
CVE-2026-169686.512.6UnknownGeoDirectoryCWE-200GeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_s…
CVE-2026-167462.712.5UnknownMultiVendorXCWE-639MultiVendorX < 5.0.11 - Store Owner+ Cross-Store Commission Data Disclosure v…
CVE-2026-712504.312.3firefly-iiifirefly-iiiCWE-918Firefly III - Webhook URL Validation Explicitly Allows Loopback and Is Bypass…
CVE-2026-78695.412.3IBMLangflow OSSCWE-22Langflow OSS is affected by arbitrary code execution in custom component vali…
CVE-2026-706158.512.1boringproxyboringproxyCWE-93boringproxy 0.10.0 SSH authorized_keys Injection via Tunnel Creation
CVE-2026-712068.312.1go-shiorishioriCWE-613shiori - JWT CheckToken Never Re-Validates Account State, Allowing Stale-Priv…
CVE-2026-712428.312.1crater-invoicecraterCWE-639Crater - Cross-Company IDOR on Notes via Missing Company-Ownership Check in N…
CVE-2026-712858.112.2louislamuptime-kumaCWE-79Uptime Kuma Stored XSS via Matomo Analytics Site ID on Public Status Pages
CVE-2026-712936.212.2statamiccmsCWE-200Statamic CMS Unguarded Exposure of 2FA Recovery Codes via Antlers current_use…
CVE-2026-92038.511.7Progress Software CorporationMarkLogic ServerCWE-918Server-side request forgery in Progress MarkLogic Server
CVE-2026-712086.511.3kubesphereKubeSphereCWE-918KubeSphere - SSRF via Unvalidated Cluster CRD Connection Endpoint in Cluster …
CVE-2026-713184.811.4nuxtnuxtCWE-20Nuxt: Unauthorized Component Instantiation via Server Island Props
CVE-2026-704328.811.0Jenkins ProjectJenkins Multijob PluginCWE-352A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin …
CVE-2026-201984.811.0CiscoCisco Enterprise NFV Infrastructure SoftwareCWE-79Cisco Integrated Management Controller Cross-Site Scripting Vulnerability
CVE-2026-706047.410.9electronelectronCWE-942Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cro…
CVE-2026-05166.510.8SonicWallSonicOSCWE-644A improper neutralization of HTTP Headers for Scripting Syntax vulnerability …
CVE-2026-559985.310.8SUSERancherCWE-204Cluster Existence Oracle via Unauthenticated Import Endpoint
CVE-2026-71054.310.6xproXpro Addons — 140+ Widgets for ElementorCWE-862Xpro Addons <= 1.5.1 - Missing Authorization to Authenticated (Subscriber+) A…
CVE-2026-164429.810.4Red HatRed Hat build of Keycloak 26.4CWE-346Keycloak-services: keycloak-services: saml idp-initiated broker login bypasse…
CVE-2026-76576.510.3IBMLangflow OSSCWE-918Langflow OSS is affected by server-side request forgery in provider validatio…
CVE-2026-712446.510.3paperless-ngxpaperless-ngxCWE-918Paperless-ngx - Mail Account Test Connection Leaks Stored IMAP/OAuth Credenti…
CVE-2026-712516.510.3akauntingakauntingCWE-639Akaunting - Cross-Company Media IDOR in Customer Portal Download Endpoint
CVE-2026-69726.410.3sonalsinha21SKT Skill BarCWE-79SKT Skill Bar <= 2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2026-74416.410.3alphawolfSimple Yearly ArchiveCWE-79Simple Yearly Archive <= 2.2.4 - Authenticated (Contributor+) Stored Cross-Si…
CVE-2026-189272.110.4imranrisal-devStudent-Management-SystemCWE-284imranrisal-dev Student-Management-System Shared Upload Helper student_profile…
CVE-2026-712338.710.0invoiceninjainvoiceninjaCWE-79InvoiceNinja - Stored XSS via Invoice/Quote Terms Field
CVE-2026-712368.710.0grocygrocyCWE-79Grocy - Stored XSS via HTMLPurifier Output Double-Decode
CVE-2026-203128.810.0CiscoCisco Catalyst SD-WAN ControllerCWE-312Cisco Catalyst SD-WAN Security Hardening Release - Information Disclosure Vul…
CVE-2026-706167.110.0boringproxyboringproxyCWE-833boringproxy 0.10.0 Resource Exhaustion DoS via GET /loading endpoint
CVE-2026-706055.99.8electronelectronCWE-918Electron: HTTP redirect followed into local file loader
CVE-2026-712046.29.6dgtlmoonchangedetection.ioCWE-284changedetection.io - Omitted Checkbox in /settings Save Silently Disables API…
CVE-2026-712648.29.5AircoookieWLEDCWE-862WLED Unauthenticated Configuration Disclosure via /json/cfg and Global Settin…
CVE-2026-555247.59.4MervinPraisonPraisonAICWE-367PraisonAI: SSRF in web_crawl tool via redirect-following and DNS rebinding (v…
CVE-2026-704487.19.4Jenkins ProjectJenkins Ivy Report PluginCWE-611Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser t…
CVE-2026-712657.59.3domoticzdomoticzCWE-121Domoticz MochadTCP Stack Buffer Overflow via MOCHAD_RFSEC strcpy()
CVE-2026-169815.39.3UnknownDHL Shipping Germany for WooCommerceCWE-639DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Download via IDOR
CVE-2026-706185.39.3Spacebar ServerSpacebar ServerCWE-862Spacebar Server Missing Authorization via member-ids Endpoint
CVE-2026-202896.59.2CiscoCisco RoomOS SoftwareCWE-532Cisco RoomOS Logging Subsystem Information Disclosure Vulnerability
CVE-2026-188962.19.2lavkush-mauryaStudent-Registration-SystemCWE-74lavkush-maurya Student-Registration-System changepass.php sql injection
CVE-2026-712767.19.0absmachmagistralaCWE-89Magistrala (formerly Mainflux) IoT Platform SQL Injection via format Query Pa…
CVE-2026-712404.38.9DjangoCRMdjango-crmCWE-601DjangoCRM - Unauthenticated Open Redirect via toggle_default_sorting next_url…
CVE-2026-706017.58.7electronelectronCWE-693Electron: Context isolation bypass via Function.prototype.bind hijack
CVE-2026-712035.38.6dgtlmoonchangedetection.ioCWE-306changedetection.io - Missing Authentication on /api/v1/full-spec Discloses Fu…
CVE-2026-156564.38.6IBMMaximo Application SuiteCWE-614IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerab…
CVE-2026-64572await8.5LinuxLinuxipv4: fib: free fib_alias with kfree_rcu() on insert error path
CVE-2026-165836.18.0UnknownOrbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & MoreCWE-79Orbit Fox by ThemeIsle < 3.0.8 - Author+ Stored XSS via SVG Upload
CVE-2026-160715.48.0Red HatRed Hat build of Keycloak 26.4CWE-269Keycloak-services: keycloak-services: ldap entry-dn user search bypasses conf…
CVE-2026-217665.48.0HCLSoftwareHCL Digital Experience and Digital Experience ComposeCWE-522HCL Digital Experience and Digital Experience Compose insufficiently protects…
CVE-2026-705964.37.8TryGhostGhostCWE-79Ghost: Cross-Site Scripting in Feature Image Captions
CVE-2026-704302.77.8Jenkins ProjectJenkinsCWE-284Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the type…
CVE-2026-704444.37.7Jenkins ProjectJenkins Violation Comments to GitLab PluginCWE-693A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.6…
CVE-2026-712808.57.6go-shiorishioriCWE-918go-shiori Server-Side Request Forgery via Unrestricted Bookmark URL Fetch
CVE-2026-705954.07.4TryGhostGhostCWE-918Ghost: Server-Side Request Forgery Mitigation Issue
CVE-2026-91307.17.3IBMLangflow OSSCWE-639Langflow OSS is affected by arbitrary code execution in custom component vali…
CVE-2026-712476.57.2documensodocumensoCWE-863Documenso - Assistant Recipient Can Forge Another Signer's Signature in Seque…
CVE-2026-712748.57.1openshwprojectsOpenBK7231T_AppCWE-79OpenBK7231T Stored XSS via Unsanitized MQTT-Set Channel Labels
CVE-2026-704373.77.0Jenkins ProjectJenkins Webhook Secret Credentials Provider PluginCWE-208Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earl…
CVE-2025-156773.57.1UnknownGeoDirectoryCWE-79GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories
CVE-2026-143044.67.0Eclipse FoundationEclipse Accessibility Tools Framework (ACTF)CWE-611In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (includi…
CVE-2026-90817.16.8IBMLangflow OSSCWE-918Langflow OSS is affected by server-side request forgery in provider validatio…
CVE-2026-712117.16.8mlflowmlflowCWE-918mlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy E…
CVE-2026-169933.76.8UnknownDHL Shipping Germany for WooCommerceCWE-200DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Disclosure via U…
CVE-2026-704334.36.8Jenkins ProjectJenkins HCL AppScan PluginCWE-862Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier all…
CVE-2026-704384.36.8Jenkins ProjectJenkins Parameterized Remote Trigger PluginCWE-862A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2…
CVE-2026-704424.36.8Jenkins ProjectJenkins Google Chat Notification PluginCWE-285Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does n…
CVE-2026-704454.36.8Jenkins ProjectJenkins Sauce OnDemand PluginCWE-862Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier …
CVE-2026-704464.36.8Jenkins ProjectJenkins CodeSonar PluginCWE-862Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow…
CVE-2026-74448.16.6cornelraiu-1Search Analytics for WPCWE-352Search Analytics for WP <= 1.4.16 - Cross-Site Request Forgery
CVE-2026-712015.06.5OpenStackIronicCWE-863In OpenStack Ironic through 38.0.0, a project reader that makes a crafted req…
CVE-2026-662988.66.4livebook-devlivebookCWE-346JS-view sandboxed output can synthesize keyboard events to trigger unconfirme…
CVE-2026-127303.86.3IBMBusiness Automation Workflow containers and traditionalCWE-297Improper Validation of Certificate with Host Mismatch in IBM Business Automat…
CVE-2026-712728.56.2usememosmemosCWE-367Memos Webhook DNS Rebinding TOCTOU SSRF in safeDialContext()
CVE-2026-634576.56.2Hewlett Packard Enterprise (HPE)HPE Integrated Lights-Out 6 (iLO 6)CWE-400A potential denial of service vulnerability exists in HPE Integrated Lights-O…
CVE-2026-704434.36.0Jenkins ProjectJenkins Horreum PluginCWE-269Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set th…
CVE-2026-704474.36.0Jenkins ProjectJenkins AWS CodeBuild PluginCWE-862Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier al…
CVE-2026-712464.35.8pixelfedpixelfedCWE-918Pixelfed - Authenticated SSRF via Remote URL Search
CVE-2026-155879.45.8Google CloudGoogle SecOps (Chronicle SOAR)CWE-346Privilege Escalation in Google SecOps (Chronicle SOAR) via Crafted Authentica…
CVE-2026-706026.65.7electronelectronCWE-284Electron: Extension tab APIs operate across session boundaries
CVE-2026-704396.55.8Jenkins ProjectJenkins XML Job to Job DSL PluginCWE-862Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permiss…
CVE-2026-668856.85.7livebook-devlivebookCWE-352Livebook Teams identity callback lacks state binding, allowing login CSRF
CVE-2026-712056.55.6dgtlmoonchangedetection.ioCWE-307changedetection.io - No Rate Limiting on /login Enables Unlimited Password Br…
CVE-2026-203116.35.4CiscoCisco IOS XE SoftwareCWE-126Cisco IOS XE Software Web UI Denial of Service Vulnerability
CVE-2026-706065.95.4electronelectronCWE-668Electron: ProtocolResponse.url reuses the default session cache instead of th…
CVE-2026-712105.35.3mealie-recipesmealieCWE-367mealie - DNS-Rebinding TOCTOU in SSRF Guard Allows Internal Network and Cloud…
CVE-2026-64569await5.3LinuxLinuxmpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
CVE-2026-64571await5.3LinuxLinuxwifi: p54: validate RX frame length in p54_rx_eeprom_readback()
CVE-2026-64573await5.3LinuxLinuxBluetooth: qca: fix NVM tag length underflow in TLV parser
CVE-2026-64579await5.3LinuxLinuxxfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert
CVE-2026-712866.15.1miguelcobainember-dynamic-render-templateCWE-1336ember-dynamic-render-template Client-Side Template Injection via Unsanitized …
CVE-2026-164439.15.1Red HatRed Hat build of Keycloak 26.4CWE-347Keycloak-services: keycloak-services: saml broker metadata import disables re…
CVE-2026-555227.84.9MervinPraisonPraisonAICWE-94PraisonAI workflow include bypasses tools.py autoload opt-in and executes inc…
CVE-2026-645707.84.9LinuxLinuxwifi: mac80211: fix fils_discovery double free on alloc failure
CVE-2026-559964.34.7SUSERancherCWE-770Unauthenticated Denial-of-Service via TLS SAN Stuffing in Rancher and cattle-…
CVE-2026-175782.34.7KongKong Event GatewayCWE-323Kong Event Gateway AES-GCM nonce reuse due to missing key rotation enforcement
CVE-2026-712496.14.6299ko299KoCWE-79299Ko - Unauthenticated Reflected XSS in Public Contact Form
CVE-2026-189536.34.2AWSaws-transform-mcp-serverCWE-22Improper limitation of a pathname to a restricted directory in aws-transform-…
CVE-2026-705995.94.0electronelectronCWE-346Electron: Permission Check Handler Receives Main Frame Origin Instead of Requ…
CVE-2026-704405.43.9Jenkins ProjectJenkins Qualys Container Scanning Connector PluginCWE-79Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does n…
CVE-2026-704415.43.9Jenkins ProjectJenkins Summary Display PluginCWE-79Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name …
CVE-2026-73267.53.6Progress Software CorporationMarkLogic ServerCWE-352Cross-site request forgery in Progress MarkLogic Server Admin UI
CVE-2026-175838.33.5Thermo FisherApplied Biosystems 3500/3500xL Series Data Collection SoftwareCWE-353Thermo Fisher Applied Biosystems Genetic Analyzers Missing Support for Integr…
CVE-2026-706003.13.5electronelectronCWE-1021Electron: Cross-origin iframe can position native autofill popup
CVE-2026-668398.43.5Integrated Systems Technologies, Inc.NetKids iMarkCWE-428NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an…
CVE-2026-446055.53.5Red HatRed Hat Hardened ImagesCWE-190Rpm: heap buffer overflow in ndb slot table parsing
CVE-2026-706116.93.3electronelectronCWE-78Electron: DevTools embedder handler executes arbitrary files via shell open
CVE-2026-202946.53.4CiscoCisco Catalyst SD-WAN ManagerCWE-319Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability
CVE-2026-80293.93.3ZTESmartLifeCWE-89SQL Injection Vulnerability in ZTE SmartLife App
CVE-2026-169425.43.3UnknownWP Custom HTML PageCWE-79WP Custom HTML Pages <= 0.6.2 - Author+ Stored XSS
CVE-2026-712755.43.3openshwprojectsOpenBK7231T_AppCWE-79OpenBK7231T - Reflected XSS via OTA host Parameter
CVE-2026-703769.63.1pluck-cmsPluck CMSCWE-352Pluck CMS - CSRF via Spoofable Missing-Referer Bypass Leads to Stored XSS and…
CVE-2026-493316.53.1Red HatRed Hat OpenShift Container Platform 4CWE-345Openshift/oauth-proxy: openshift/oauth-proxy: unauthenticated identity header…
CVE-2026-166134.33.0UnknownGDPR Cookie ComplianceCWE-352GDPR Cookie Compliance < 5.1.0 - Cookie Deletion and Forced Logout via CSRF
CVE-2026-124107.82.8Gen DigitalCCleanerCWE-59CCleaner local privilege escalation via link following on uninstall
CVE-2026-712617.82.8mackrondr_libsCWE-190dr_wav.h W64 CUE Chunk Metadata Parsing Integer Overflow Leading to Heap Buff…

Results continue: ranks 401–432.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-05 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.