Edition of August 5, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-71266 | 7.8 | 2.8 | syoyo | tinyobjloader-c | CWE-121 | tinyobjloader-c Stack Buffer Overflow in MTL Material File Line Parsing |
| CVE-2026-19027 | 6.9 | 2.8 | The HDF Group | HDF5 | CWE-125 | HDF5 out-of-bounds heap read in N-Bit filter decompression |
| CVE-2026-19026 | 6.8 | 2.8 | The HDF Group | HDF5 | CWE-476 | Nbit filter NULL/short parameter-array dereference |
| CVE-2026-19028 | 6.8 | 2.8 | The HDF Group | HDF5 | CWE-125 | HDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds read |
| CVE-2026-19024 | 8.2 | 2.7 | The HDF Group | HDF5 | CWE-476 | HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message |
| CVE-2026-70435 | 4.2 | 2.3 | Jenkins Project | Jenkins SCM-Manager Plugin | CWE-862 | A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier a… |
| CVE-2026-64567 | 7.8 | 2.1 | Linux | Linux | — | btrfs: reject free space cache with more entries than pages |
| CVE-2026-64568 | 7.8 | 2.1 | Linux | Linux | — | wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure |
| CVE-2026-64580 | 7.8 | 2.1 | Linux | Linux | — | xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() |
| CVE-2026-71259 | 8.6 | 2.0 | esphome | esphome | CWE-184 | ESPHome external_components file:// Scheme Validation Bypass Leading to Remot… |
| CVE-2026-64575 | 7.8 | 2.0 | Linux | Linux | — | bpf: tcp: fix double sock release on batch realloc |
| CVE-2026-64582 | 7.8 | 1.9 | Linux | Linux | — | RDMA/rxe: Fix a use-after-free problem in rxe_mmap |
| CVE-2026-19023 | 6.8 | 2.0 | The HDF Group | HDF5 | CWE-822 | HDF5 h5dump Untrusted Pointer Dereference in Binary Output of Variable-Length… |
| CVE-2026-19025 | 6.8 | 2.0 | The HDF Group | HDF5 | CWE-369 | HDF5 divide-by-zero (SIGFPE) via mismatched chunk-layout dimensionality and d… |
| CVE-2026-71273 | 6.5 | 1.9 | openshwprojects | OpenBK7231T_App | CWE-352 | OpenBK7231T CSRF in /cfg_wifi_set Leading to Implicit Web Password Disable an… |
| CVE-2026-64574 | 7.8 | 1.9 | Linux | Linux | — | wifi: mac80211: tear down new links on vif update error path |
| CVE-2026-71226 | 7.3 | 1.9 | Stephan Muelle | libkcapi | CWE-416 | Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi'… |
| CVE-2026-64576 | 7.1 | 1.9 | Linux | Linux | — | nexthop: initialize extack in nh_res_bucket_migrate() |
| CVE-2026-66344 | 5.4 | 1.9 | Integrated Systems Technologies, Inc. | NetKids iMark | CWE-427 | NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an… |
| CVE-2026-18485 | 8.5 | 1.7 | NI | NI-PAL | CWE-1285 | Local Privilege Escalation in NI-PAL |
| CVE-2026-64581 | 7.8 | 1.6 | Linux | Linux | — | xfrm: fix sk_dst_cache double-free in xfrm_user_policy() |
| CVE-2026-71227 | 5.1 | 1.6 | Stephan Muelle | libkcapi | CWE-835 | Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() d… |
| CVE-2026-17515 | 4.3 | 1.6 | Unknown | MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings | CWE-200 | MLS Import < 7.0.4 - Subscriber+ Sensitive Information Disclosure via mlsimpo… |
| CVE-2026-8470 | 9.1 | 1.5 | IBM | Langflow OSS | CWE-327 | Langflow is affected by weaknesses in secret handling and sensitive configura… |
| CVE-2026-71212 | 4.4 | 1.5 | indravoyager | xidown | CWE-88 | xidown - Argument Injection via Unterminated yt-dlp Command Line Construction |
| CVE-2026-18954 | 5.7 | 1.4 | AWS | documentdb-mcp-server | CWE-863 | Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs D… |
| CVE-2026-70603 | 6.0 | 1.0 | electron | electron | CWE-20 | Electron: shell.openPath path validation bypass via embedded null byte |
| CVE-2026-70598 | 3.9 | 1.0 | electron | electron | CWE-125 | Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memor… |
| CVE-2026-70434 | 4.2 | 0.4 | Jenkins Project | Jenkins SCM-Manager Plugin | CWE-352 | A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plug… |
| CVE-2026-18839 | 2.2 | 0.3 | rpm-software-management | popt | CWE-191 | Popt-devel: popt-static: size_t underflow in singleoptionhelp |
| CVE-2026-70597 | 6.3 | 0.2 | electron | electron | CWE-367 | Electron: Parent process code-sign check is spoofable |
| CVE-2026-55997 | 8.8 | 0.2 | rancher | rancher | CWE-312 | Long-lived Rancher registration token exposed in plaintext |