AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .1354 96.1 —
AFFECTED Product Versions Fixed WGDashboard unspecified —
TIMELINE Jul 14 Reserved by CNA Aug 6 Published (CNA: certcc)
482 CVEs published August 6, 2026: 87 critical, 187 high, 145 medium, 51 low; 0 in KEV; 5 with a public exploit reference; 12 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 457 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 1693 | 10498 | 1397 | 2563 |
| KEV catalog size | 1670 | |||
545 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 44 | 1629 | 210 | 1150 | 98 | 0 | 27 | 3 | 0.2 | 7.8 | .0016 | +32 |
| microsoft | 33 | 1394 | 120 | 939 | 310 | 8 | 378 | 32 | 2.3 | 7.8 | .0040 | -17 |
| 43 | 455 | 72 | 134 | 228 | 18 | 73 | 5 | 1.1 | 6.5 | .0023 | +43 | |
| red hat | 37 | 259 | 13 | 119 | 111 | 16 | 4 | 0 | 0.0 | 7.1 | .0024 | +30 |
| apple | 1 | 245 | 57 | 67 | 112 | 2 | 93 | 7 | 2.9 | 7.1 | .0028 | +1 |
| suse | 5 | 5 | 1 | 2 | 2 | 0 | 0 | 0 | 0.0 | 7.3 | .0022 | +5 |
| canonical | 0 | 3 | 0 | 2 | 1 | 0 | 0 | 0 | 0.0 | 7.8 | .0013 | 0 |
| android | 0 | 1 | 0 | 1 | 0 | 0 | 16 | 1 | 100.0 | 8.4 | .0171 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 23 | 43 | 9 | 17 | 9 | 0 | 96 | 13 | 30.2 | 8.6 | .0032 | +23 |
| fortinet | 0 | 18 | 2 | 4 | 9 | 0 | 28 | 6 | 33.3 | 6.1 | .0054 | 0 |
| palo alto networks | 0 | 15 | 0 | 1 | 7 | 5 | 14 | 2 | 13.3 | 4.7 | .0028 | 0 |
| vmware | 0 | 12 | 4 | 7 | 0 | 1 | 21 | 0 | 0.0 | 8.7 | .0044 | 0 |
| checkpoint | 1 | 5 | 4 | 1 | 0 | 0 | 3 | 2 | 40.0 | 9.3 | .2062 | +1 |
| f5 | 0 | 5 | 4 | 0 | 0 | 0 | 7 | 1 | 20.0 | 9.2 | .0402 | 0 |
| ivanti | 0 | 5 | 1 | 0 | 0 | 0 | 33 | 5 | 100.0 | 10.0 | .8152 | 0 |
| zyxel | 3 | 4 | 0 | 3 | 1 | 0 | 11 | 0 | 0.0 | 7.2 | .0075 | +3 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 58 | 195 | 34 | 106 | 54 | 1 | 40 | 2 | 1.0 | 7.5 | .0048 | +58 |
| mozilla | 1 | 73 | 42 | 26 | 5 | 0 | 13 | 0 | 0.0 | 9.1 | .0031 | +1 |
| gitlab | 0 | 15 | 0 | 2 | 10 | 1 | 4 | 2 | 13.3 | 4.9 | .0029 | 0 |
| github | 2 | 4 | 0 | 2 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0040 | +2 |
| docker | 0 | 3 | 0 | 1 | 2 | 0 | 1 | 0 | 0.0 | 5.7 | .0015 | 0 |
| wordpress | 0 | 3 | 1 | 1 | 1 | 0 | 5 | 2 | 66.7 | 8.6 | .7310 | 0 |
| drupal | 0 | 1 | 1 | 0 | 0 | 0 | 5 | 1 | 100.0 | 9.8 | .8832 | 0 |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0024 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 1113 | 212 | 539 | 304 | 57 | 40 | 3 | 0.3 | 7.6 | .0031 | 0 |
| ibm | 32 | 140 | 36 | 61 | 42 | 1 | 7 | 1 | 0.7 | 7.5 | .0027 | +32 |
| adobe | 7 | 47 | 16 | 23 | 4 | 0 | 75 | 4 | 8.5 | 8.6 | .0047 | +7 |
| progress | 10 | 33 | 10 | 18 | 5 | 0 | 9 | 0 | 0.0 | 8.1 | .0029 | +10 |
| solarwinds | 0 | 20 | 16 | 1 | 1 | 0 | 11 | 4 | 20.0 | 9.1 | .0050 | 0 |
| veeam | 10 | 12 | 3 | 7 | 2 | 0 | 4 | 0 | 0.0 | 8.6 | .0027 | +10 |
| atlassian | 0 | 3 | 0 | 3 | 0 | 0 | 13 | 0 | 0.0 | 8.0 | .0026 | 0 |
| zohocorp | 0 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 7.1 | .0048 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 0 | 8 | 0 | 0 | 6 | 1 | 26 | 1 | 12.5 | 5.5 | .0073 | 0 |
| hikvision | 0 | 7 | 0 | 4 | 2 | 0 | 2 | 1 | 14.3 | 7.2 | .0025 | 0 |
| bosch | 0 | 3 | 0 | 3 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0028 | 0 |
| schneider electric | 0 | 3 | 1 | 2 | 0 | 0 | 1 | 0 | 0.0 | 8.7 | .0020 | 0 |
| synology | 1 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0.0 | 7.3 | .0013 | +1 |
| honeywell | 0 | 1 | 0 | 0 | 1 | 0 | 0 | 0 | 0.0 | 6.9 | .0031 | 0 |
| mitsubishi electric | 0 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0.0 | 7.1 | .0013 | 0 |
| rockwell automation | 0 | 1 | 1 | 0 | 0 | 0 | 0 | 0 | 0.0 | 9.2 | .0030 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| surrealdb | 0 | 57 | 3 | 26 | 25 | 3 | 0 | 0 | 0.0 | 7.1 | .0025 | 0 |
| grafana | 0 | 41 | 2 | 14 | 22 | 3 | 0 | 0 | 0.0 | 6.5 | .0033 | 0 |
| netty | 0 | 41 | 6 | 27 | 7 | 1 | 0 | 0 | 0.0 | 7.5 | .0046 | 0 |
| legion of the bouncy castle | 32 | 39 | 5 | 25 | 9 | 0 | 0 | 0 | 0.0 | 8.7 | .0026 | +32 |
| open ises | 0 | 37 | 2 | 14 | 21 | 0 | 0 | 0 | 0.0 | 6.9 | .0021 | 0 |
| mediatek | 34 | 34 | 0 | 4 | 30 | 0 | 1 | 0 | 0.0 | 6.0 | .0011 | +34 |
| erlang | 0 | 32 | 1 | 14 | 14 | 3 | 1 | 0 | 0.0 | 6.9 | .0033 | -6 |
| freerdp | 23 | 31 | 8 | 18 | 4 | 1 | 0 | 0 | 0.0 | 8.7 | .0034 | +23 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-63030 | .9560 | 99.9 | 9.8 |
| CVE-2026-39808 | .9121 | 99.8 | — |
| CVE-2026-34486 | .8293 | 99.6 | 7.5 |
| CVE-2026-48939 | .8250 | 99.6 | 10.0 |
| CVE-2026-50522 | .7698 | 99.5 | 9.8 |
| CVE-2026-15410 | .7635 | 99.5 | 7.2 |
| CVE-2026-56291 | .7607 | 99.5 | 10.0 |
| CVE-2026-15409 | .7422 | 99.4 | 10.0 |
| CVE-2026-25089 | .7360 | 99.4 | 9.8 |
| CVE-2026-16232 | .7330 | 99.4 | 9.3 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-48939 | 10.0 | .8250 | KEV |
| CVE-2026-56291 | 10.0 | .7607 | KEV |
| CVE-2026-15409 | 10.0 | .7422 | KEV |
| CVE-2026-8985 | 10.0 | .0660 | |
| CVE-2026-6516 | 10.0 | .0473 | |
| CVE-2026-47668 | 10.0 | .0434 | |
| CVE-2026-44359 | 10.0 | .0100 | |
| CVE-2025-71389 | 10.0 | .0093 | |
| CVE-2026-48168 | 10.0 | .0091 | |
| CVE-2026-56163 | 10.0 | .0090 |
| Vendor | CVEs |
|---|---|
| oracle | 1109 |
| linux | 699 |
| microsoft | 641 |
| 446 | |
| apple | 168 |
| apache | 163 |
| red hat | 150 |
| ibm | 132 |
| mozilla | 68 |
| surrealdb | 57 |
| Vendor | KEV |
|---|---|
| microsoft | 32 |
| cisco | 13 |
| apple | 7 |
| fortinet | 6 |
| 5 | |
| ivanti | 5 |
| adobe | 4 |
| langflow | 4 |
| solarwinds | 4 |
| synacor | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 61 |
| PyPI | 5 |
| Go | 3 |
| npm | 3 |
| crates.io | 2 |
| NuGet | 1 |
| Packagist | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4128 | Cisco | 0 |
| CVE-2021-27137 | DD-WRT | 0 |
| CVE-2023-4346 | KNX Association | 0 |
| CVE-2025-68686 | Fortinet | 0 |
| CVE-2026-0770 | Langflow | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-16232 | checkpoint | 0 |
| CVE-2026-16812 | Arista Networks | 0 |
| CVE-2026-18556 | N-able | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1723 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1723 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1723 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1723 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1723 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1723 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1723 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1723 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1723 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1723 |
EXPLOIT PUBLISHED — CVE-2012-4681. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2019-15107. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2021-22205 (GitLab). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2021-43890 (Microsoft App Installer). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-30190 (Microsoft Windows 10 Version 1809). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-40684 (Fortinet FortiOS, FortiProxy, FortiSwitchManager). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2023-42753 (Red Hat Enterprise Linux 7). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10634 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10639 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10646 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10647 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10652 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10653 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10670 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-12605 (Eclipse Foundation Eclipse GlassFish). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16746 (Unknown MultiVendorX). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16940 (Unknown Custom Fields). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16981 (Unknown DHL Shipping Germany for WooCommerce). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18958 (imranrisal-dev Student-Management-System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18959 (yushine InnoShop). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-43997 (patriksimek vm2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-43998 (patriksimek vm2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-43999 (patriksimek vm2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44001 (patriksimek vm2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44004 (patriksimek vm2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44005 (patriksimek vm2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44006 (patriksimek vm2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44007 (patriksimek vm2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44008 (patriksimek vm2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44009 (patriksimek vm2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44210 (kata-containers). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45411 (patriksimek vm2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47429 (vitest-dev vitest). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54656 (koxudaxi datamodel-code-generator). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54690 (koxudaxi datamodel-code-generator). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54894 (ueberauth guardian). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55389 (koxudaxi datamodel-code-generator). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55415 (koxudaxi datamodel-code-generator). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55733 (ueberauth guardian). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55734 (ueberauth guardian). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55735 (ueberauth guardian). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-64827 (Telenia Software TVox). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-64828 (Froiden TableTrack). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-67623 (mistralai mistral-vibe). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-69111 (milvus-io milvus). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-70615 (boringproxy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-70616 (boringproxy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-7656 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-8037 (Progress Software LoadMaster). Public exploit reference added.
RESCORED — CVE-2023-42753 (Red Hat Enterprise Linux 7). CVSS 7 → 7.8 (NVD).
RESCORED — CVE-2023-5090 (Red Hat Enterprise Linux 8). CVSS 6 → 5.5 (NVD).
RESCORED — CVE-2024-0646 (kernel). CVSS 7 → 7.8 (NVD).
RESCORED — CVE-2024-1488 (unbound). CVSS 8 → 7.3 (NVD).
RESCORED — CVE-2024-21549 (spatie/browsershot). CVSS 7.7 → 6.6 (NVD).
RESCORED — CVE-2026-10634 (zephyrproject zephyr). CVSS 4.8 → 5.3 (NVD).
RESCORED — CVE-2026-10643 (zephyrproject zephyr). CVSS 8.7 → 7.8 (NVD).
RESCORED — CVE-2026-10652 (zephyrproject zephyr). CVSS 4.8 → 7.4 (NVD).
RESCORED — CVE-2026-10653 (zephyrproject zephyr). CVSS 6.4 → 8.1 (NVD).
RESCORED — CVE-2026-11714 (IBM WebSphere Application Server - Liberty). CVSS 8.5 → 9.8 (NVD).
RESCORED — CVE-2026-16108 (Red Hat Build of Keycloak). CVSS 4.3 → 6.5 (NVD).
RESCORED — CVE-2026-18968 (ttttonyhe OBlog). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-18969 (Rongzhitong Visual Integrated Command and Dispatch Platform). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-18970 (Rongzhitong Visual Integrated Command and Dispatch Platform). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-47429 (vitest-dev vitest). CVSS 9.8 → 5.9 (NVD).
RESCORED — CVE-2026-7656 (zephyrproject zephyr). CVSS 8.1 → 6.8 (NVD).
482 CVEs published. 25 box scores and 375 table rows below; the remaining 82 continue on page 2 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .1354 96.1 —
AFFECTED Product Versions Fixed WGDashboard unspecified —
TIMELINE Jul 14 Reserved by CNA Aug 6 Published (CNA: certcc)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 7.3 .0247 83.1 —
AFFECTED Product Versions Fixed Tomato 1.28.0000 – —
TIMELINE Aug 6 Reserved by CNA Aug 6 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 7.3 .0247 83.1 —
AFFECTED Product Versions Fixed Tomato 1.28.0000 – —
TIMELINE Aug 6 Reserved by CNA Aug 6 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 7.3 .0247 83.1 —
AFFECTED Product Versions Fixed Tomato 1.28.0000 – —
TIMELINE Aug 6 Reserved by CNA Aug 6 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H N 9.3 .0190 77.9 —
AFFECTED Product Versions Fixed OpenChamber unspecified —
TIMELINE Jun 11 Reserved by CNA Aug 6 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0166 74.7 —
AFFECTED Product Versions Fixed mcp-api 1.11.0 – 1.11.9
TIMELINE Aug 6 Reserved by CNA Aug 6 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0160 73.8 —
AFFECTED Product Versions Fixed Virtual Storage Integrator for VMware vSphere Client unspecified —
TIMELINE Jul 29 Reserved by CNA Aug 6 Published (CNA: dell)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0133 68.6 —
AFFECTED Product Versions Fixed ironclaw 0.29.0 – —
TIMELINE Aug 5 Reserved by CNA Aug 6 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 5.3 .0129 67.9 —
AFFECTED Product Versions Fixed OpenHands 0.1 – —
TIMELINE Aug 5 Reserved by CNA Aug 6 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0108 62.4 —
AFFECTED Product Versions Fixed OpenChamber unspecified —
TIMELINE Jun 11 Reserved by CNA Aug 6 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0091 57.0 —
AFFECTED Product Versions Fixed Azure Service Bus - – —
TIMELINE Jun 4 Reserved by CNA Aug 6 Published (CNA: microsoft)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0089 56.3 —
AFFECTED Product Versions Fixed sonic3air unspecified 2492d1882cd2cf1cc1d7415729ce5c4fd686cd4f
TIMELINE Jul 27 Reserved by CNA Aug 6 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N A H N N 5.9 .0076 52.1 —
AFFECTED Product Versions Fixed anki >= 25.09.3 – —
TIMELINE Jul 20 Reserved by CNA Aug 6 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N P N N N 5.3 .0074 51.5 —
AFFECTED Product Versions Fixed cli < 2.97.0 – —
TIMELINE Jul 20 Reserved by CNA Aug 6 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N A L L N 5.1 .0071 50.4 —
AFFECTED Product Versions Fixed cti-transmute unspecified —
TIMELINE Aug 6 Reserved by CNA Aug 6 Published (CNA: CIRCL)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L P N P H H H 7.3 .0070 50.2 —
AFFECTED Product Versions Fixed PHP_CodeSniffer < 3.13.6 – —
TIMELINE Jul 29 Reserved by CNA Aug 6 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N L N L L L 1.9 .0070 50.0 —
AFFECTED Product Versions Fixed godot-mcp 0.1.0 – —
TIMELINE Aug 6 Reserved by CNA Aug 6 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0069 49.9 —
AFFECTED Product Versions Fixed Apache CXF 4.2.0 – —
TIMELINE Jul 28 Reserved by CNA Aug 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0069 49.8 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Jun 21 Reserved by CNA Aug 6 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0069 49.6 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Jul 30 Reserved by CNA Aug 6 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N L N L L L 1.9 .0068 49.5 —
AFFECTED Product Versions Fixed LudusMCP 1.0.0 – —
TIMELINE Aug 6 Reserved by CNA Aug 6 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0068 49.3 —
AFFECTED Product Versions Fixed WGDashboard unspecified —
TIMELINE Jul 14 Reserved by CNA Aug 6 Published (CNA: certcc)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0063 47.5 —
AFFECTED Product Versions Fixed Microsoft Entra Provisioning Service - – —
TIMELINE Jul 2 Reserved by CNA Aug 6 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0062 46.9 —
AFFECTED Product Versions Fixed Application Insights Profiler - – —
TIMELINE May 27 Reserved by CNA Aug 6 Published (CNA: microsoft)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N L N L L L 1.9 .0062 46.9 —
AFFECTED Product Versions Fixed LudusMCP 1.0.0 – —
TIMELINE Aug 6 Reserved by CNA Aug 6 Published (CNA: VulDB)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-43629 | 9.2 | 46.8 | ggml-org | llama.cpp | CWE-787 | llama.cpp b4882–b9058 Buffer Overflow in KV Cache State Restore |
| CVE-2026-15991 | 8.8 | 46.2 | bitpressadmin | File Manager | CWE-862 | File Manager 6.0 - 6.9 - Missing Authorization to Authenticated (Subscriber+)… |
| CVE-2026-18649 | 7.5 | 45.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-770 | Gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay a… |
| CVE-2026-70558 | 9.3 | 45.7 | DataLinkDC | Dinky | CWE-434 | Dinky Unauthenticated Arbitrary File Write via /download/uploadFromRsByLocal … |
| CVE-2026-67688 | 9.8 | 45.3 | n/a | n/a | CWE-434 | ICS-Park Smart Park Management System v2.0 contains an unrestricted file uplo… |
| CVE-2026-71476 | 8.7 | 45.0 | nrwl | nx | CWE-22 | Nx: Zip-Slip in the self-hosted remote cache |
| CVE-2026-67422 | 7.5 | 45.0 | facelessuser | pymdown-extensions | CWE-1333 | pymdown-extensions: Exponential-backtracking ReDoS in caret, tilde, betterem,… |
| CVE-2026-14812 | 10.0 | 44.4 | Unknown | Premium SEO | CWE-912 | Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content… |
| CVE-2026-50159 | 5.3 | 44.4 | mermaid-js | mermaid | CWE-94 | Mermaid allows CSS injection applying to sibling elements of the diagram |
| CVE-2026-48085 | 9.8 | 43.6 | open-reception | appointment-booking-software | CWE-862 | OpenReception has unauthenticated GLOBAL_ADMIN account creation post-bootstrap |
| CVE-2026-71324 | 7.0 | 43.5 | traefik | traefik | CWE-444 | Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's share… |
| CVE-2026-19150 | 8.8 | 43.2 | Chrome | CWE-693 | Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 a… | |
| CVE-2026-19151 | 8.8 | 43.2 | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remot… | |
| CVE-2026-19168 | 8.8 | 43.2 | Chrome | CWE-693 | Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 a… | |
| CVE-2026-5857 | 9.2 | 42.7 | Contiki-NG | Contiki-NG | CWE-787 | Contiki-NG MQTT Client Out-of-Bounds Write in PUBLISH Topic Parser via Persis… |
| CVE-2026-5855 | 8.7 | 42.8 | Contiki-NG | Contiki-NG | CWE-125 | Contiki-NG LwM2M TLV Parser Out-of-Bounds Read via Unchecked Buffer Length in… |
| CVE-2026-34501 | 7.5 | 42.3 | Apache Software Foundation | Apache Portable Runtime Utility | CWE-122 | Apache Portable Runtime Utility: Heap buffer overflow in APR redis client |
| CVE-2026-34502 | 7.5 | 42.3 | Apache Software Foundation | Apache Portable Runtime Utility | CWE-122 | Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client |
| CVE-2026-67687 | 8.8 | 42.2 | n/a | n/a | CWE-284 | Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker… |
| CVE-2026-3418 | 9.1 | 41.9 | WSO2 | WSO2 API Manager | CWE-434 | Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Re… |
| CVE-2026-53977 | 8.7 | 41.8 | Bohdan Triapitsyn | OpenChamber | CWE-306 | OpenChamber 1.11.7 Unauthenticated DoS via /api/system/shutdown |
| CVE-2026-15459 | 8.1 | 41.2 | wpmudev | WPMU DEV Dashboard | CWE-287 | WPMU DEV Dashboard <= 5.0.0 - Authentication Bypass to Arbitrary Plugin Insta… |
| CVE-2026-70633 | 7.1 | 41.0 | timescale | timescaledb | CWE-191 | TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Gorilla Compression Reverse Ite… |
| CVE-2026-64653 | 5.1 | 40.8 | cli | cli | CWE-22 | GitHub CLI: Unescaped variable components in request URLs could allow path tr… |
| CVE-2026-19149 | 9.6 | 40.6 | Chrome | CWE-416 | Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allo… | |
| CVE-2026-68823 | 9.1 | 40.6 | Microsoft | Azure Confidential Ledger | CWE-749 | Azure Confidential Ledger Remote Code Execution Vulnerability |
| CVE-2026-66829 | 2.3 | 40.6 | rrrene | html_sanitize_ex | CWE-601 | html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowin… |
| CVE-2026-65400 | 9.8 | 40.4 | Apple | macOS | CWE-287 | An authentication issue was addressed with improved state management. This is… |
| CVE-2026-18991 | 5.5 | 40.1 | nanocoai | NanoClaw | CWE-22 | nanocoai NanoClaw send_file core.ts path traversal |
| CVE-2026-19176 | 7.5 | 40.1 | Chrome | CWE-416 | Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a rem… | |
| CVE-2026-11976 | 10.0 | 39.7 | Unknown | MonsterInsights Pro | CWE-912 | MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise |
| CVE-2026-56162 | 10.0 | 39.6 | Microsoft | Azure SQL Database | CWE-287 | Azure SQL Database Elevation of Privilege Vulnerability |
| CVE-2026-66709 | 9.1 | 39.5 | WebAppick | CTX Feed | CWE-94 | WordPress CTX Feed plugin <= 6.6.42 - Remote Code Execution (RCE) vulnerability |
| CVE-2026-70332 | 9.6 | 39.4 | Microsoft | Microsoft SharePoint Online | CWE-79 | Microsoft Office SharePoint Spoofing Vulnerability |
| CVE-2026-65553 | 10.0 | 39.2 | wbolt.com | Spider Analyser – WordPress搜索引擎蜘蛛分析插件 | CWE-94 | WordPress Spider Analyser – WordPress搜索引擎蜘蛛分析插件 plugin <= 2.1.3 - Remote Code… |
| CVE-2026-32327 | 9.1 | 39.1 | Apache Software Foundation | Apache Portable Runtime Utility | CWE-674 | Apache Portable Runtime Utility: apr-util XML stack recursion crash |
| CVE-2026-19038 | 2.1 | 39.0 | MonomythDevelopment | la-forge-mcp | CWE-22 | MonomythDevelopment la-forge-mcp screenshot_element Tool index.ts screenshotE… |
| CVE-2026-54225 | 7.5 | 38.5 | Apache Software Foundation | Apache CXF | CWE-770 | Apache CXF: Denial of Service attack via large attachments |
| CVE-2026-57819 | 7.5 | 38.5 | Apache Software Foundation | Apache CXF | CWE-400 | Apache CXF: No default restriction on the amount of form parameters per message |
| CVE-2026-18427 | 7.5 | 37.9 | @fastify/static | @fastify/static | CWE-22 | @fastify/static vulnerable to route guard bypass via non-canonical path segments |
| CVE-2026-48087 | 9.8 | 37.9 | open-reception | appointment-booking-software | CWE-287 | OpenReception: WebAuthn passkey injection allows account takeover |
| CVE-2026-50481 | 9.9 | 37.8 | Microsoft | Azure Active Directory | CWE-471 | Azure Active Directory Elevation of Privilege Vulnerability |
| CVE-2026-48054 | 8.8 | 37.7 | OpenZeppelin | contracts-wizard | CWE-94 | OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Fou… |
| CVE-2026-19137 | 8.3 | 37.6 | Chrome | CWE-416 | Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 a… | |
| CVE-2026-43630 | 6.3 | 37.6 | ggml-org | llama.cpp | CWE-125 | llama.cpp b5702–b7653 Out-of-Bounds Read Information Disclosure |
| CVE-2026-19177 | 8.3 | 37.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in UI in Google Chrome prior to 15… | |
| CVE-2026-57817 | 8.1 | 36.8 | Apache Software Foundation | Apache CXF | CWE-20 | Apache CXF: The authorization code hash (c_hash) is not enforced for the hybr… |
| CVE-2026-63508 | 10.0 | 36.8 | Microsoft | Microsoft Planetary Computer Pro (GeoCatalog) | CWE-306 | Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability |
| CVE-2026-65667 | 10.0 | 36.8 | Microsoft | Microsoft Teams | CWE-862 | Microsoft Teams Elevation of Privilege Vulnerability |
| CVE-2026-68749 | 8.2 | 36.7 | rrrene | html_sanitize_ex | CWE-1333 | Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-… |
| CVE-2026-68750 | 8.2 | 36.7 | rrrene | html_sanitize_ex | CWE-407 | Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allo… |
| CVE-2026-61466 | 9.1 | 36.6 | Apache Software Foundation | Apache CXF | CWE-304 | Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation |
| CVE-2026-65548 | 9.9 | 36.5 | Muffingroup | Betheme | CWE-94 | WordPress Betheme theme <= 28.4.2 - Remote Code Execution (RCE) vulnerability |
| CVE-2026-16268 | 8.2 | 36.4 | Unknown | Newsletters | CWE-918 | Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Boun… |
| CVE-2026-19145 | 8.8 | 36.3 | Chrome | CWE-416 | Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed … | |
| CVE-2026-19162 | 8.8 | 36.3 | Chrome | CWE-787 | Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a … | |
| CVE-2026-19174 | 8.8 | 36.3 | Chrome | CWE-190 | Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a rem… | |
| CVE-2026-47765 | 7.1 | 35.9 | frappe | frappe | CWE-862 | Frappe: Lack of Permissions in restore/bulk_restore |
| CVE-2026-65552 | 9.8 | 35.5 | qstudio | Export User Data | CWE-502 | WordPress Export User Data plugin <= 2.2.6 - PHP Object Injection vulnerability |
| CVE-2026-68481 | 7.5 | 35.5 | Apache Software Foundation | Apache CXF | CWE-672 | Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider |
| CVE-2026-54489 | 9.8 | 35.4 | Dell | Virtual Storage Integrator for VMware vSphere Client | CWE-200 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to … |
| CVE-2026-19166 | 9.6 | 35.3 | Chrome | CWE-416 | Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109… | |
| CVE-2026-19141 | 8.3 | 35.2 | Chrome | CWE-416 | Use after free in Resources in Google Chrome on Android prior to 151.0.7922.1… | |
| CVE-2026-19142 | 7.5 | 35.3 | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a re… | |
| CVE-2026-19158 | 7.5 | 35.3 | Chrome | CWE-416 | Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 a… | |
| CVE-2026-19159 | 7.5 | 35.3 | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a re… | |
| CVE-2026-62830 | 9.9 | 34.8 | Microsoft | Azure SRE Agent | CWE-862 | Azure SRE Agent Elevation of Privilege Vulnerability |
| CVE-2026-65668 | 8.8 | 34.8 | Microsoft | Microsoft Purview eDiscovery | CWE-284 | Microsoft Purview eDiscovery Elevation of Privilege Vulnerability |
| CVE-2026-19011 | 5.5 | 34.7 | n/a | TinyAGI | CWE-73 | TinyAGI agents.ts buildSystemPrompt file inclusion |
| CVE-2026-70634 | 7.2 | 34.5 | timescale | timescaledb | CWE-129 | TimescaleDB 2.29.1 Out-of-Bounds Read Information Disclosure via Dictionary C… |
| CVE-2026-43631 | 9.2 | 34.3 | ggml-org | llama.cpp | CWE-416 | llama.cpp b7492–b9060 Use-After-Free RCE via llama-server |
| CVE-2026-68079 | 9.8 | 34.3 | Apache Software Foundation | Apache CXF | CWE-294 | Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization … |
| CVE-2026-65432 | 7.5 | 34.1 | Apache Software Foundation | Apache CXF | CWE-611 | Apache CXF: XXE via WSDL/XSD import parsing |
| CVE-2026-19040 | 2.1 | 34.1 | MissionSquad | mcp-api | CWE-918 | MissionSquad mcp-api dcrClients.ts server-side request forgery |
| CVE-2026-64958 | 7.5 | 33.9 | Apache Software Foundation | Apache CXF | CWE-400 | Apache CXF: Denial of service via message header attachments |
| CVE-2026-61632 | 5.3 | 33.6 | facelessuser | pymdown-extensions | CWE-22 | PyMdown Extensions: Path traversal in the b64 extension lets <img src> read f… |
| CVE-2026-19157 | 9.6 | 33.2 | Chrome | CWE-787 | Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.… | |
| CVE-2026-19170 | 9.6 | 33.2 | Chrome | CWE-416 | Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 a… | |
| CVE-2026-65543 | 7.5 | 33.0 | vimeodev | Vimeo | CWE-201 | WordPress Vimeo plugin <= 1.2.2 - Sensitive Data Exposure vulnerability |
| CVE-2026-18990 | 5.5 | 32.9 | letta-ai | LettaBot | CWE-287 | letta-ai LettaBot API Status Route server.ts missing authentication |
| CVE-2026-45415 | 6.0 | 32.8 | decidim | decidim | CWE-862 | Decidim: CSV census record endpoints improper authorization |
| CVE-2026-5336 | 6.8 | 32.7 | Unknown | DataPress (Dataverse Integration) | CWE-200 | Dataverse Integration < 2.91 - Contributor+ Server-Side Template Injection (S… |
| CVE-2025-49506 | 7.5 | 32.6 | Apache Software Foundation | Apache Portable Runtime Utility | CWE-208 | Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing… |
| CVE-2026-47185 | 5.1 | 32.5 | frappe | frappe | CWE-79 | Frappe Has Broken Access Control in its Workspace Save API |
| CVE-2026-48075 | 6.5 | 32.3 | open-reception | appointment-booking-software | CWE-862 | OpenReception's unauthenticated add-to-tunnel endpoint accepts arbitrary appo… |
| CVE-2026-71439 | 5.3 | 32.3 | mermaid-js | mermaid | CWE-606 | Mermaid radar diagrams are vulnerable to DoS |
| CVE-2026-59118 | 9.3 | 32.2 | Microsoft | Copilot Cowork | CWE-285 | Copilot Cowork Elevation of Privilege Vulnerability |
| CVE-2026-19009 | 5.5 | 32.1 | n/a | TinyAGI | CWE-73 | TinyAGI Message API Endpoint response.ts collectFiles file inclusion |
| CVE-2026-28139 | 9.8 | 31.8 | wpdreams | Ajax Search Lite | CWE-502 | WordPress Ajax Search Lite plugin <= 4.14.4 - PHP Object Injection vulnerability |
| CVE-2025-14561 | 9.0 | 31.7 | WSO2 | WSO2 API Manager | CWE-284 | Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allow… |
| CVE-2026-48079 | 7.4 | 31.7 | open-reception | appointment-booking-software | CWE-613 | OpenReception's logout page clears local access_token before server-side revo… |
| CVE-2026-15732 | 9.8 | 31.3 | WGDashboard | WGDashboard | CWE-918 | WGDashboard Server-Side Request Forgery Vulnerability |
| CVE-2026-56161 | 9.6 | 31.3 | Microsoft | Azure Logic Apps | CWE-284 | Azure Logic Apps Information Disclosure Vulnerability |
| CVE-2026-62896 | 9.6 | 31.3 | Microsoft | Microsoft Teams | CWE-287 | Microsoft Teams Elevation of Privilege Vulnerability |
| CVE-2026-53984 | 8.8 | 31.2 | Efstratios Goudelis | Ground Station | CWE-306 | Ground Station prior to 0.6.0 Unauthenticated Database Wipe and Arbitrary Dat… |
| CVE-2026-53985 | 8.7 | 31.2 | Efstratios Goudelis | Ground Station | CWE-306 | Ground Station prior to 0.6.0 Unauthenticated DoS via service_control Socket.IO |
| CVE-2026-48071 | 5.8 | 31.1 | open-reception | appointment-booking-software | CWE-307 | OpenReception's client PIN challenge throttle is keyed by emailHash only, all… |
| CVE-2026-17032 | 9.8 | 30.5 | Unknown | google-maps-easy-pro | CWE-912 | Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server |
| CVE-2026-70636 | 8.7 | 30.5 | FlowiseAI | Flowise | CWE-862 | Flowise 3.1.4 Authentication Bypass via OAuth2 Credential Refresh Endpoint |
| CVE-2026-19164 | 9.6 | 30.3 | Chrome | CWE-20 | Insufficient validation of untrusted input in Codecs in Google Chrome prior t… | |
| CVE-2026-19171 | 9.6 | 30.3 | Chrome | CWE-416 | Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 a… | |
| CVE-2026-19175 | 9.6 | 30.3 | Chrome | CWE-416 | Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a… | |
| CVE-2025-15039 | 9.4 | 30.3 | WSO2 | WSO2 Identity Server | CWE-693 | Account Takeover via Conditional Authentication Script Logic in Multiple WSO2… |
| CVE-2026-19144 | 8.8 | 30.3 | Chrome | CWE-416 | Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a rem… | |
| CVE-2026-19169 | 8.8 | 30.3 | Chrome | CWE-20 | Insufficient validation of untrusted input in Contextual Tasks in Google Chro… | |
| CVE-2026-19138 | 8.3 | 30.3 | Chrome | CWE-122 | Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.1… | |
| CVE-2026-19010 | 5.5 | 30.3 | n/a | TinyAGI | CWE-862 | TinyAGI Message API Endpoint index.ts processMessage authorization |
| CVE-2026-19111 | 8.6 | 30.1 | AWS | strands-agents-tools | CWE-639 | Insecure direct object reference in Strands Agents Tools memory tool namespac… |
| CVE-2026-65549 | 7.2 | 30.1 | jegtheme | Jeg Kit for Elementor | CWE-502 | WordPress Jeg Elementor Kit plugin <= 3.2.10 - PHP Object Injection vulnerabi… |
| CVE-2026-48082 | 3.7 | 30.1 | open-reception | appointment-booking-software | CWE-770 | OpenReception's bootstrap challenge proof-of-work difficulty hardcoded to 16 … |
| CVE-2026-19153 | 8.1 | 29.8 | Chrome | CWE-20 | Insufficient validation of untrusted input in Workers in Google Chrome prior … | |
| CVE-2026-64597 | 9.8 | 29.5 | Linux | Linux | — | smb: client: fix double-free in SMB2_close() replay |
| CVE-2026-71327 | 7.6 | 29.5 | traefik | traefik | CWE-694 | Traefik: Gateway API route identity collision allows cross-namespace backend … |
| CVE-2026-19146 | 5.3 | 29.4 | Chrome | CWE-457 | Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 … | |
| CVE-2026-34191 | 9.1 | 29.3 | Apache Software Foundation | Apache Portable Runtime Utility | CWE-89 | Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle |
| CVE-2026-19154 | 8.3 | 29.3 | Chrome | CWE-416 | Use after free in Skia in Google Chrome on Android prior to 151.0.7922.109 al… | |
| CVE-2026-19172 | 8.3 | 29.3 | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a re… | |
| CVE-2026-48084 | 7.4 | 29.2 | open-reception | appointment-booking-software | CWE-307 | OpenReception doesn't rate limit passphrase login attempts |
| CVE-2026-62836 | 10.0 | 29.0 | Microsoft | Azure SQL Managed Instance | CWE-923 | Azure SQL Managed Instance Elevation of Privilege Vulnerability |
| CVE-2026-70635 | 7.1 | 29.0 | timescale | timescaledb | CWE-129 | TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Bulk Dictionary Decompression N… |
| CVE-2026-64640 | 5.3 | 29.0 | Apache Software Foundation | Apache Polaris | CWE-863 | Apache Polaris: register endpoint reads attacker-controlled storage location … |
| CVE-2026-19064 | 5.3 | 28.9 | SourceCodester | Online Examination & Learning Management System | CWE-285 | SourceCodester Online Examination & Learning Management System view.php autho… |
| CVE-2026-19160 | 3.1 | 28.9 | Chrome | CWE-457 | Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a … | |
| CVE-2026-71326 | 2.1 | 28.7 | traefik | traefik | CWE-287 | Traefik: BasicAuth singleflight key collision allows authenticated identity s… |
| CVE-2026-19037 | 2.1 | 28.2 | n/a | WonderTrader | CWE-840 | WonderTrader Internal Limit Order Book Cache MatchEngine.cpp update_lob behav… |
| CVE-2026-70646 | 7.5 | 28.0 | vovchic17 | aiosend | CWE-400 | aiosend: Deserialization of request body before signature verification (Pre-a… |
| CVE-2026-48083 | 6.5 | 27.9 | open-reception | appointment-booking-software | CWE-117 | OpenReception: Unauthenticated POST /api/log accepts arbitrary content with C… |
| CVE-2026-71488 | 7.5 | 27.6 | thephpleague | commonmark | CWE-407 | league/commonmark: Quadratic-time denial of service when parsing crafted Mark… |
| CVE-2026-57818 | 8.1 | 27.4 | Apache Software Foundation | Apache CXF | CWE-367 | Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProv… |
| CVE-2026-62873 | 9.8 | 27.3 | Microsoft | Microsoft 365 Admin Center | CWE-347 | Microsoft 365 Admin Center Elevation of Privilege Vulnerability |
| CVE-2026-49391 | 5.1 | 27.3 | frappe | frappe | CWE-79 | Frappe: Stored XSS in Column Headers via Data Import |
| CVE-2026-3415 | 8.7 | 27.2 | WSO2 | WSO2 API Manager | CWE-776 | XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Pr… |
| CVE-2026-19008 | 2.1 | 27.2 | mf-yang | openclaw-cn | CWE-59 | mf-yang openclaw-cn apply_patch Tool sandbox-paths.ts assertNoSymlinkEscape l… |
| CVE-2026-70557 | 7.1 | 26.8 | diboot | diboot-core | CWE-639 | diboot-core Authenticated Arbitrary Field Read via loadRelatedData Discloses … |
| CVE-2026-19140 | 8.3 | 26.6 | Chrome | CWE-416 | Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remo… | |
| CVE-2026-19147 | 8.3 | 26.6 | Chrome | CWE-416 | Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allo… | |
| CVE-2026-19148 | 8.3 | 26.6 | Chrome | CWE-787 | Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 … | |
| CVE-2026-19152 | 8.3 | 26.6 | Chrome | CWE-693 | Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0… | |
| CVE-2026-19155 | 8.3 | 26.6 | Chrome | CWE-416 | Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a… | |
| CVE-2026-19163 | 8.3 | 26.6 | Chrome | CWE-416 | Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 a… | |
| CVE-2026-19173 | 8.3 | 26.6 | Chrome | CWE-787 | Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed … | |
| CVE-2026-5423 | 8.2 | 26.4 | neo4j | graphql | CWE-302 | Subscription Authentication Bypass via Unverified connectionParams.jwt |
| CVE-2026-48086 | 9.9 | 26.3 | open-reception | appointment-booking-software | CWE-269 | OpenReception: Tenant admin self-promotes to GLOBAL_ADMIN |
| CVE-2026-28005 | 9.8 | 26.0 | Nexcess | Kadence WooCommerce Email Designer | CWE-862 | WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19 - Privilege Esc… |
| CVE-2026-65507 | 9.8 | 26.0 | Sergey | AIWU | CWE-266 | WordPress AIWU plugin <= 1.5.6 - Privilege Escalation vulnerability |
| CVE-2026-43632 | 9.2 | 25.8 | ggml-org | llama.cpp | CWE-416 | llama.cpp b7492–b9060 Use-After-Free in Tokenization Endpoints |
| CVE-2026-19167 | 3.1 | 25.7 | Chrome | CWE-190 | Integer overflow in GPU in Google Chrome prior to 151.0.7922.109 allowed a re… | |
| CVE-2026-64655 | 2.1 | 25.7 | cli | cli | CWE-185 | GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacter… |
| CVE-2026-70559 | 8.7 | 25.7 | DataLinkDC | Dinky | CWE-306 | Dinky Unauthenticated System Configuration and Credential Disclosure via GET … |
| CVE-2026-28146 | 6.5 | 25.7 | Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | CWE-22 | WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) … |
| CVE-2026-71436 | 5.3 | 25.4 | mermaid-js | mermaid | CWE-835 | Mermaid XY Charts are vulnerable to an infinite loop DoS |
| CVE-2026-53983 | 9.2 | 25.3 | Efstratios Goudelis | Ground Station | CWE-918 | Ground Station prior to 0.6.0 Unauthenticated Persistent Blind Server-Side Re… |
| CVE-2026-71554 | 5.3 | 25.3 | python-hyper | h2 | CWE-444 | h2: Duplicate Host header could facilitate request smuggling |
| CVE-2026-45414 | 8.5 | 25.2 | decidim | decidim | CWE-639 | Decidim: JWT-backed authentication can be replayed across organizations |
| CVE-2026-71445 | 8.2 | 24.6 | ail-project | ail-framework | CWE-79 | Authenticated Reflected Cross-Site Scripting in Tag Error Responses in ail-fr… |
| CVE-2026-19069 | 2.1 | 24.7 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System treatmentrecord.php sql injection |
| CVE-2026-19070 | 2.1 | 24.7 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System viewadmin.php sql injection |
| CVE-2026-19071 | 2.1 | 24.7 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System viewappointment.php sql injection |
| CVE-2026-18487 | 5.4 | 24.6 | GNOME | Epiphany | CWE-451 | Epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_ho… |
| CVE-2026-65559 | 7.2 | 24.4 | tychesoftwares | Order Delivery Date for WooCommerce | CWE-266 | WordPress Order Delivery Date for WooCommerce plugin <= 4.6.0 - Privilege Esc… |
| CVE-2026-65554 | 7.1 | 24.3 | lattepress | AnsPress – Question and answer | CWE-862 | WordPress AnsPress – Question and answer plugin 4.4.4 - Broken Access Control… |
| CVE-2026-65556 | 9.8 | 24.1 | MihChe | WPBruiser {no- Captcha anti-Spam} | CWE-502 | WordPress WPBruiser {no- Captcha anti-Spam} plugin <= 3.1.43 - PHP Object Inj… |
| CVE-2026-65571 | 9.8 | 24.1 | Axiomthemes | 69 Clothing | CWE-502 | WordPress 69 Clothing theme <= 1.2.11.1 - PHP Object Injection vulnerability |
| CVE-2026-65572 | 9.8 | 24.1 | Axiomthemes | A.Williams | CWE-502 | WordPress A.Williams theme <= 1.3.1 - PHP Object Injection vulnerability |
| CVE-2026-65573 | 9.8 | 24.1 | ThemeREX | Abelle | CWE-502 | WordPress Abelle theme <= 1.22 - PHP Object Injection vulnerability |
| CVE-2026-65574 | 9.8 | 24.1 | AncoraThemes | Abogado | CWE-502 | WordPress Abogado theme <= 1.18 - PHP Object Injection vulnerability |
| CVE-2026-65575 | 9.8 | 24.1 | AncoraThemes | Accalia | CWE-502 | WordPress Accalia theme <= 1.5.3 - PHP Object Injection vulnerability |
| CVE-2026-65576 | 9.8 | 24.1 | AncoraThemes | Adrena | CWE-502 | WordPress Adrena theme <= 1.2.14 - PHP Object Injection vulnerability |
| CVE-2026-65577 | 9.8 | 24.1 | AncoraThemes | Advice | CWE-502 | WordPress Advice theme <= 1.18.0 - PHP Object Injection vulnerability |
| CVE-2026-65578 | 9.8 | 24.1 | AncoraThemes | Agora | CWE-502 | WordPress Agora theme <= 1.9 - PHP Object Injection vulnerability |
| CVE-2026-65579 | 9.8 | 24.1 | axiomthemes | Agricola | CWE-502 | WordPress Agricola theme <= 1.21.0 - PHP Object Injection vulnerability |
| CVE-2026-65581 | 9.8 | 24.1 | Axiomthemes | AI ANN | CWE-502 | WordPress AI ANN theme <= 1.29.0 - PHP Object Injection vulnerability |
| CVE-2026-19062 | 5.5 | 24.0 | chiuwingyan | house | CWE-74 | chiuwingyan house selectall.action sql injection |
| CVE-2026-64665 | 8.1 | 23.8 | statamic | cms | CWE-287 | Statamic: Account takeover via OAuth email matching without email-verificatio… |
| CVE-2026-18974 | 5.5 | 23.8 | heshengtao | super-agent-party | CWE-200 | heshengtao super-agent-party execute_tool_manually Endpoint server.py get_fil… |
| CVE-2026-18258 | 8.8 | 23.7 | Scripta | eScriptorium | CWE-639 | Authorization Bypass Through User-Controlled Key in eScriptorium |
| CVE-2026-14831 | 5.3 | 23.7 | Unknown | Easy Booking | CWE-602 | Easy Booking < 3.5.0 - Unauthenticated Minimum Booking Duration Bypass |
| CVE-2026-45573 | 6.4 | 23.5 | decidim | decidim | CWE-918 | Decidim: Push subscriptions can be abused for server-side requests |
| CVE-2026-66470 | 7.1 | 23.3 | Shabti Kaplan | Frontend Admin by DynamiApps | CWE-862 | WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Broken Access Cont… |
| CVE-2026-48077 | 5.3 | 23.3 | open-reception | appointment-booking-software | CWE-862 | OpenReception: GET appointment by ID returns full appointment record without … |
| CVE-2026-16636 | 7.2 | 23.2 | wpmanageninja | FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, Mailgun, Postmark, Cloudflare, toSend, Gmail and Any SMTP | CWE-79 | FluentSMTP <= 2.2.95 - Unauthenticated Stored Cross-Site Scripting via Recipi… |
| CVE-2026-64662 | 6.5 | 23.1 | statamic | cms | CWE-639 | Statamic: Missing authorization on navigation endpoint allows disclosure of r… |
| CVE-2026-19019 | 2.9 | 23.1 | poco-ai | poco-agent | CWE-459 | poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_p… |
| CVE-2026-66710 | 8.1 | 22.9 | E2Pdf | e2pdf | CWE-98 | WordPress e2pdf plugin <= 1.32.40 - Local File Inclusion vulnerability |
| CVE-2026-45378 | 7.5 | 22.8 | decidim | decidim | CWE-200 | Decidim: Verification documents can be downloaded through reusable links |
| CVE-2026-18973 | 5.5 | 22.3 | heshengtao | super-agent-party | CWE-918 | heshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_u… |
| CVE-2026-1728 | 9.8 | 22.2 | WSO2 | WSO2 API Manager | CWE-269 | Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits A… |
| CVE-2026-64663 | 6.5 | 22.1 | statamic | cms | CWE-470 | Statamic: Unsafe method invocation via Antlers template resolution allows dat… |
| CVE-2026-19161 | 3.1 | 22.1 | Chrome | CWE-457 | Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a … | |
| CVE-2026-66425 | 6.5 | 22.1 | Saad Iqbal | Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder | CWE-288 | WordPress Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Fo… |
| CVE-2026-48088 | 9.4 | 21.9 | open-reception | appointment-booking-software | CWE-862 | OpenReception vulnerable to unauthenticated staff crypto poisoning that break… |
| CVE-2026-62918 | 7.5 | 21.8 | Microsoft | Microsoft Teams | CWE-347 | Microsoft Teams Spoofing Vulnerability |
| CVE-2026-65508 | 9.3 | 21.6 | NSquared | Simply Schedule Appointments | CWE-89 | WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - SQL Injection vu… |
| CVE-2026-65520 | 9.3 | 21.6 | miniOrange | WP OAuth Server | CWE-89 | WordPress WP OAuth Server plugin <= 6.2.0 - SQL Injection vulnerability |
| CVE-2026-19000 | 5.5 | 21.6 | n/a | JeecgBoot | CWE-918 | JeecgBoot Anonymous Chat Attachment send server-side request forgery |
| CVE-2026-14842 | 5.3 | 21.6 | Unknown | Events Made Easy | CWE-639 | Events Made Easy < 3.1.2 - Unauthenticated Payment Bypass |
| CVE-2026-66665 | 10.0 | 21.5 | Brandexponents | Type Hub | CWE-434 | WordPress Type Hub plugin <= 2.0.6 - Arbitrary File Upload vulnerability |
| CVE-2026-71437 | 6.5 | 21.5 | mermaid-js | mermaid | CWE-1321 | Mermaid Architecture diagrams are vulnerable to prototype pollution |
| CVE-2026-66843 | 2.3 | 21.5 | rrrene | html_sanitize_ex | CWE-829 | html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, … |
| CVE-2026-17264 | 5.3 | 21.2 | Medixant | RadiAnt DICOM | CWE-787 | Medixant RadiAnt DICOM Out-of-bounds write |
| CVE-2026-65504 | 7.5 | 21.2 | ivanbebek | BOX NOW Delivery Croatia | CWE-862 | WordPress BOX NOW Delivery Croatia plugin <= 3.3.0 - Broken Access Control vu… |
| CVE-2026-65523 | 7.5 | 21.2 | approveme | Formidable Forms Signature Online Contract Automation | CWE-639 | WordPress Formidable Forms Signature Online Contract Automation plugin <= 2.0… |
| CVE-2026-28111 | 8.8 | 21.1 | WPMU DEV | Forminator | CWE-266 | WordPress Forminator plugin <= 1.56.0 - Privilege Escalation vulnerability |
| CVE-2026-19127 | 6.5 | 21.1 | GitroomHQ | postiz-app | CWE-345 | Insufficient verification of lifetime-deal redemption codes allows forgery of… |
| CVE-2026-13399 | 7.5 | 20.8 | Unknown | Payment Plugins for PayPal WooCommerce | CWE-639 | Payment Plugins for PayPal WooCommerce < 2.0.20 - Unauthenticated Payment Byp… |
| CVE-2026-64598 | 8.8 | 20.7 | Linux | Linux | — | smb/client: Fix error code in smb2_aead_req_alloc() |
| CVE-2026-18995 | 2.1 | 20.7 | netease-youdao | LobsterAI | CWE-200 | netease-youdao LobsterAI MEDIA Path artifactParser.ts parseMediaTokensFromTex… |
| CVE-2026-48074 | 2.7 | 20.5 | open-reception | appointment-booking-software | CWE-863 | OpenReception: Staff deletion removes pending invites cross-tenant by email m… |
| CVE-2026-18325 | 7.2 | 20.3 | wpmudev | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | CWE-79 | Forminator Forms <= 1.56.1 - Unauthenticated Stored Cross-Site Scripting via … |
| CVE-2026-65547 | 8.5 | 20.2 | Constant Contact | Creative Mail | CWE-89 | WordPress Creative Mail plugin <= 1.6.9 - SQL Injection vulnerability |
| CVE-2026-65569 | 8.5 | 20.2 | wpjobportal | WP Job Portal | CWE-89 | WordPress WP Job Portal plugin <= 2.5.6 - SQL Injection vulnerability |
| CVE-2026-48080 | 8.0 | 20.1 | open-reception | appointment-booking-software | CWE-200 | OpenReception's tenant detail endpoint discloses live PostgreSQL connection s… |
| CVE-2026-16731 | 8.3 | 19.9 | OMICRON electronics GmbH | OMICRON StationScout | CWE-208 | Authentication and authorization bypass via cryptographic timing side-channel… |
| CVE-2026-16054 | 9.1 | 19.8 | Unknown | Drag and Drop Multiple File Upload for WooCommerce | CWE-73 | Drag and Drop Multiple File Upload for WooCommerce < 1.1.8 - Unauthenticated … |
| CVE-2026-67621 | 7.2 | 19.8 | FlowiseAI | Flowise | CWE-862 | Flowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints |
| CVE-2026-19066 | 5.3 | 19.8 | SourceCodester | Online Examination & Learning Management System | CWE-285 | SourceCodester Online Examination & Learning Management System view_students.… |
| CVE-2026-19165 | 7.5 | 19.7 | Chrome | CWE-416 | Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed… | |
| CVE-2026-66695 | 6.5 | 19.5 | BoldGrid | W3 Total Cache | CWE-35 | WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability |
| CVE-2026-10524 | 7.5 | 19.3 | Unknown | CoCart | CWE-472 | CoCart < 4.9.0 - Unauthenticated Arbitrary Price Manipulation |
| CVE-2026-66662 | 9.8 | 19.0 | Shabti Kaplan | Frontend Admin by DynamiApps | CWE-266 | WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Privilege Escalati… |
| CVE-2026-19156 | 7.5 | 18.8 | Chrome | CWE-122 | Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed… | |
| CVE-2026-5134 | 9.8 | 18.5 | Loca Software Informatics Technology Ltd. Co. | CMS | CWE-89 | SQLi in Loca Software's CMS |
| CVE-2026-63687 | 9.1 | 18.5 | Apache Software Foundation | Apache CXF | CWE-345 | Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce para… |
| CVE-2026-18276 | 4.3 | 18.5 | Scripta | eScriptorium | CWE-862 | Missing Authorization in eScriptorium |
| CVE-2026-19021 | 5.5 | 18.2 | SourceCodester | Computer Repair Shop Management System | CWE-74 | SourceCodester Computer Repair Shop Management System Master.php delete_produ… |
| CVE-2026-12713 | 9.1 | 18.1 | Unknown | WPCargo Track & Trace | CWE-89 | WPCargo Track & Trace < 8.0.4 - Unauthenticated SQL Injection via wpcargo_tra… |
| CVE-2026-65583 | 9.1 | 18.1 | Apache Software Foundation | Apache CXF | CWE-345 | Apache CXF: Self-issued ID token claims validation skipped |
| CVE-2026-65542 | 8.8 | 18.1 | Rajat Varlani | Super Socializer | CWE-288 | WordPress Super Socializer plugin <= 7.14.5 - Broken Authentication vulnerabi… |
| CVE-2026-16620 | 7.5 | 17.7 | Unknown | WPC Name Your Price for WooCommerce | CWE-472 | WPC Name Your Price for WooCommerce < 2.2.5 - Unauthenticated Price Manipulat… |
| CVE-2026-16315 | 8.1 | 17.7 | OMICRON electronics GmbH | OMICRON StationGuard | CWE-208 | Authentication and authorization bypass via cryptographic timing side-channel… |
| CVE-2026-63725 | 8.6 | 17.5 | nuxsmin | sysPass | CWE-78 | sysPass FileBackupService Authenticated OS Command Injection via Backup Path |
| CVE-2026-13153 | 7.5 | 17.4 | Unknown | Gutenberg Essential Blocks | CWE-200 | Essential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure … |
| CVE-2026-13154 | 7.5 | 17.4 | Unknown | Gutenberg Essential Blocks | CWE-200 | Essential Blocks < 6.4.0 - Unauthenticated Non-Public Custom Post Type Conten… |
| CVE-2026-18050 | 7.5 | 17.4 | Unknown | Events Manager | CWE-200 | Events Manager < 7.4 - Unauthenticated Pending Upload Disclosure via events-m… |
| CVE-2024-6541 | 6.8 | 17.4 | WSO2 | WSO2 Micro Integrator | CWE-20 | Information Disclosure and Integrity Violation via Improper Message Context H… |
| CVE-2026-19065 | 5.3 | 17.4 | SourceCodester | Online Examination & Learning Management System | CWE-284 | SourceCodester Online Examination & Learning Management System upload_files.p… |
| CVE-2026-68747 | 2.3 | 17.1 | rrrene | html_sanitize_ex | CWE-74 | CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input |
| CVE-2026-19110 | 1.9 | 17.1 | n/a | DataGear | CWE-79 | DataGear Chart Name HtmlTplDashboardWidgetHtmlRenderer.java HtmlTplDashboardW… |
| CVE-2026-5856 | 7.1 | 17.0 | Contiki-NG | Contiki-NG | CWE-125 | Contiki-NG DNS/mDNS Resolver Out-of-Bounds Read via Unchecked skip_name Trave… |
| CVE-2026-13342 | 5.3 | 16.9 | Unknown | Security Optimizer | CWE-693 | Security Optimizer – The All-In-One Protection Plugin < 1.6.5 - Login Access … |
| CVE-2026-11983 | 5.3 | 16.7 | spacetime | Ad Inserter – Ad Manager & AdSense Ads | CWE-862 | Ad Inserter <= 2.8.16 - Missing Authorization to Block Visibility Bypass via … |
| CVE-2026-64664 | 4.3 | 16.7 | statamic | cms | CWE-200 | Statamic: Missing authorization on Control Panel endpoint allows disclosure o… |
| CVE-2026-18400 | 6.4 | 16.7 | metaslider | Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider | CWE-79 | Slider, Gallery, and Carousel by MetaSlider <= 3.111.0 - Authenticated (Autho… |
| CVE-2026-48078 | 5.3 | 16.6 | open-reception | appointment-booking-software | CWE-200 | OpenReception's schedule endpoint discloses isPublic=false channels and slot … |
| CVE-2026-19067 | 2.1 | 16.6 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System treatment.php sql injection |
| CVE-2026-19068 | 2.1 | 16.6 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System treatmentdetail.php sql injection |
| CVE-2026-62857 | 8.8 | 16.5 | fedify-dev | fedify | CWE-918 | Fedify: Server-Side Request Forgery in getNodeInfo() Allows Access to Interna… |
| CVE-2026-16954 | 6.5 | 16.5 | Unknown | AI Engine | CWE-200 | AI Engine < 3.6.4 - Editor+ Sensitive Information Disclosure of API Key and B… |
| CVE-2026-67622 | 8.5 | 16.2 | FlowiseAI | Flowise | CWE-639 | Flowise 3.1.4 IDOR in OpenAI Assistants Integration |
| CVE-2026-71446 | 6.9 | 16.3 | ail-project | ail-framework | CWE-79 | Stored Cross-Site Scripting in AIL Framework Domain Screenshot View |
| CVE-2026-28140 | 7.5 | 16.0 | jetmonsters | JetFormBuilder | CWE-862 | WordPress JetFormBuilder plugin <= 3.6.4.1 - Broken Access Control vulnerability |
| CVE-2026-18996 | 2.1 | 15.9 | cosmicstack-labs | mercury-agent | CWE-266 | cosmicstack-labs mercury-agent run_command permissions.ts PermissionManager.c… |
| CVE-2026-18510 | 7.2 | 15.7 | cozmoslabs | TranslatePress – Translate Multilingual sites with AI Translation | CWE-79 | TranslatePress <= 3.2.6 - Unauthenticated Stored Cross-Site Scripting via Com… |
| CVE-2026-48076 | 6.5 | 15.6 | open-reception | appointment-booking-software | CWE-863 | OpenReception's bootstrap booking flow allows unauthenticated booking on isPu… |
| CVE-2026-66452 | 6.5 | 15.6 | IT-Recht Kanzlei | Legal Text Connector of the IT-Recht Kanzlei | CWE-862 | WordPress Legal Text Connector of the IT-Recht Kanzlei plugin <= 1.0.13 - Bro… |
| CVE-2026-3430 | 8.6 | 15.5 | Unknown | Creative Mail | CWE-89 | Creative Mail 1.6.5 - 1.6.9 - Unauthenticated SQLi |
| CVE-2026-63637 | 8.6 | 15.4 | dgraph-io | dgraph | CWE-943 | Dgraph: DQL Injection via unvalidated regexp filter argument in GraphQL query… |
| CVE-2024-6832 | 7.5 | 15.4 | WSO2 | WSO2 Enterprise Integrator | CWE-693 | Account Lockout Failure via Secondary User Store Inaccessibility in Multiple … |
| CVE-2026-54717 | 5.4 | 15.4 | silverstripe | silverstripe-cms | CWE-79 | Silverstripe: XSS in breadcrumbs in page list view |
| CVE-2026-28169 | 5.3 | 15.4 | YITHEMES | YITH WooCommerce Zoom Magnifier | CWE-497 | WordPress YITH WooCommerce Zoom Magnifier plugin <= 2.52.0 - Sensitive Data E… |
| CVE-2026-66683 | 5.3 | 15.4 | WP Zone | Custom CSS and JavaScript | CWE-201 | WordPress Custom CSS and JavaScript plugin <= 2.0.16 - Sensitive Data Exposur… |
| CVE-2026-66684 | 5.3 | 15.4 | Akshay Menariya | Export Import Menus | CWE-201 | WordPress Export Import Menus plugin <= 1.9.2 - Sensitive Data Exposure vulne… |
| CVE-2026-71434 | 5.3 | 15.4 | statamic | cms | CWE-434 | Statamic: Missing file upload validation on frontend forms allows uploading d… |
| CVE-2025-12317 | 5.0 | 15.4 | WSO2 | WSO2 Enterprise Integrator | CWE-613 | Improper Token Revocation via SOAP Services in Multiple WSO2 Products Allows … |
| CVE-2026-64586 | 8.8 | 15.2 | Linux | Linux | — | wifi: brcmfmac: drain bus_reset work on device removal |
| CVE-2026-32469 | 5.3 | 15.2 | WPKube | CAPTCHA 4WP | CWE-290 | WordPress CAPTCHA 4WP plugin <= 7.6.0 - Captcha Bypass vulnerability |
| CVE-2026-65502 | 5.3 | 15.2 | bdthemes | Element Pack Elementor Addons | CWE-290 | WordPress Element Pack Elementor Addons plugin <= 8.7.13 - Captcha Bypass vul… |
| CVE-2026-18277 | 7.1 | 14.9 | Scripta | eScriptorium | CWE-862 | Missing Authorization in eScriptorium |
| CVE-2026-18275 | 6.5 | 15.0 | Scripta | eScriptorium | CWE-639 | Authorization Bypass Through User-Controlled Key in eScriptorium |
| CVE-2026-12605 | 9.6 | 14.8 | Eclipse Foundation | Eclipse GlassFish | CWE-918 | In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServ… |
| CVE-2026-65546 | 9.3 | 14.9 | QODE | Qode Tours | CWE-89 | WordPress Qode Tours plugin <= 3.1.3.1 - SQL Injection vulnerability |
| CVE-2026-66447 | 9.3 | 14.9 | nickboss | WordPress File Upload | CWE-89 | WordPress WordPress File Upload plugin <= 5.1.7 - SQL Injection vulnerability |
| CVE-2026-15149 | 5.3 | 14.8 | Unknown | WP Hotel Booking | CWE-20 | WP Hotel Booking < 2.3.3 - Unauthenticated Payment Bypass via Price Manipulation |
| CVE-2026-16067 | 5.3 | 14.8 | Unknown | Event Booking Manager for WooCommerce (Pro) | CWE-472 | Event Booking Manager for WooCommerce (Pro) < 5.0.3 - Unauthenticated Payment… |
| CVE-2026-16619 | 7.5 | 14.6 | Unknown | miniOrange 2FA | CWE-307 | miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts |
| CVE-2026-14314 | 5.3 | 14.7 | Unknown | PeproDev WooCommerce Receipt Uploader | CWE-200 | PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Image Attach… |
| CVE-2026-65570 | 8.1 | 14.5 | Hamid Alinia | Login with phone number | CWE-290 | WordPress Login with phone number plugin <= 1.8.70 - Bypass vulnerability vul… |
| CVE-2026-71447 | 6.9 | 14.5 | ail-project | ail-framework | CWE-79 | Stored Cross-Site Scripting in Chat and Forum Translation Controls in ail-fra… |
| CVE-2026-65551 | 7.5 | 14.3 | Soflyy | Breakdance | CWE-862 | WordPress Breakdance plugin < 2.7 - Broken Access Control vulnerability |
| CVE-2026-66451 | 6.5 | 14.3 | Arraytics | WP Event SOlution | CWE-288 | WordPress WP Event SOlution plugin <= 4.1.9 - Broken Authentication vulnerabi… |
| CVE-2026-16065 | 6.5 | 14.1 | Unknown | Welcart e-Commerce | CWE-89 | Welcart e-Commerce < 2.11.32 - Editor+ SQL Injection via CSV Import |
| CVE-2026-14225 | 2.7 | 14.0 | Unknown | Easy Appointments | CWE-20 | Easy Appointments < 3.12.28 - Contributor+ Shortcode Allowlist Bypass |
| CVE-2026-28180 | 5.3 | 13.7 | Mercado Pago | Mercado Pago payments for WooCommerce | CWE-639 | WordPress Mercado Pago payments for WooCommerce plugin <= 8.9.0 - Insecure Di… |
| CVE-2026-32548 | 5.3 | 13.7 | SureCart | SureCart | CWE-862 | WordPress SureCart plugin <= 4.6.2 - Broken Access Control vulnerability |
| CVE-2026-66370 | 4.8 | 13.8 | rrrene | html_sanitize_ex | CWE-601 | html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attr… |
| CVE-2026-70637 | 8.2 | 13.7 | hfiref0x | LightFTP | CWE-820 | LightFTP 2.4 Data Race Condition via ABOR Command in ftpserv.c |
| CVE-2026-68480 | await | 13.6 | Linux | Linux | — | x86/bugs: Make Safe-RET robust against interrupt injection |
| CVE-2026-71433 | 5.3 | 13.4 | langchain-ai | langgraph | CWE-200 | LangGraph: Namespace prefix matching crosses segment boundaries in Postgres a… |
| CVE-2026-5430 | 10.0 | 13.1 | WSO2 | WSO2 Universal Gateway | CWE-347 | Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Al… |
| CVE-2026-66708 | 8.2 | 12.9 | BoldGrid | Total Upkeep | CWE-862 | WordPress Total Upkeep plugin <= 1.17.2 - Broken Access Control vulnerability |
| CVE-2026-18359 | 8.5 | 12.8 | Scripta | eScriptorium | CWE-918 | Server-Side Request Forgery (SSRF) in eScriptorium |
| CVE-2026-65541 | 7.3 | 12.6 | solutioned | Staff Training | CWE-862 | WordPress Staff Training plugin <= 1.0.7 - Broken Access Control vulnerability |
| CVE-2025-15674 | 2.7 | 12.5 | Unknown | Passster | CWE-863 | Content Protector (Passster) < 4.3.7 - Contributor+ Protected Content Disclos… |
| CVE-2026-66712 | 7.5 | 12.3 | wp.insider | Simple Membership | CWE-862 | WordPress Simple Membership plugin <= 4.7.8 - Broken Access Control vulnerabi… |
| CVE-2026-18993 | 2.1 | 12.1 | NousResearch | hermes-agent | CWE-266 | NousResearch hermes-agent Memory Toolset model_tools.py access control |
| CVE-2026-66692 | 4.3 | 11.8 | Colissimo | Colissimo Officiel : Méthodes de livraison pour WooCommerce | CWE-639 | WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin … |
| CVE-2026-61959 | 6.5 | 11.7 | Strategy11 Team | Business Directory | CWE-79 | WordPress Business Directory plugin <= 6.4.24 - Cross Site Scripting (XSS) vu… |
| CVE-2026-0673 | 5.3 | 11.5 | bdthemes | Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons | CWE-93 | Element Pack Addons for Elementor <= 8.3.15 - Unauthenticated SMTP Header Inj… |
| CVE-2026-16290 | 5.3 | 11.4 | Unknown | ProfileGrid | CWE-862 | ProfileGrid < 6.0.0.0 - Unauthenticated Group Member List Disclosure via pm_g… |
| CVE-2026-70632 | 8.5 | 11.3 | FFmpeg | FFmpeg | CWE-787 | FFmpeg 4.4 < 9.0 Heap Out-of-Bounds Write in CFHD Decoder via AVI Demuxing |
| CVE-2026-18976 | 2.1 | 11.4 | NousResearch | hermes-agent | CWE-266 | NousResearch hermes-agent disabled_toolsets agent_init.py get_tool_definition… |
| CVE-2026-18992 | 2.1 | 11.4 | zhayujie | CowAgent | CWE-285 | zhayujie CowAgent Self-Evolution Review Agent executor.py _select_tools autho… |
| CVE-2026-18997 | 2.1 | 11.4 | cosmicstack-labs | mercury-agent | CWE-285 | cosmicstack-labs mercury-agent bg agent.ts Agent.handleBgCommand authorization |
| CVE-2026-18998 | 2.1 | 11.4 | cosmicstack-labs | mercury-agent | CWE-266 | cosmicstack-labs mercury-agent delegate_task Tool sub-agent.ts SubAgent.run i… |
| CVE-2026-19005 | 2.1 | 11.4 | nanocoai | NanoClaw | CWE-266 | nanocoai NanoClaw Child-Agent Creation create-agent.ts handleCreateAgent priv… |
| CVE-2026-19006 | 2.1 | 11.4 | mf-yang | openclaw-cn | CWE-285 | mf-yang openclaw-cn Ggateway Exec Approval Flow bash-tools.exec.ts authorization |
| CVE-2026-19007 | 2.1 | 11.4 | mf-yang | openclaw-cn | CWE-266 | mf-yang openclaw-cn reply-elevated.ts isApprovedElevatedSender privileges man… |
| CVE-2026-14240 | 5.3 | 11.0 | Unknown | tourmaster | CWE-200 | Tourmaster < 5.4.9 - Unauthenticated Sensitive Data Disclosure via Order Export |
| CVE-2025-13909 | 4.3 | 10.9 | WSO2 | WSO2 Identity Server | CWE-20 | Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity… |
| CVE-2026-66711 | 7.1 | 10.7 | Amir Helzer | WooCommerce Multilingual & Multicurrency | CWE-79 | WordPress WooCommerce Multilingual & Multicurrency plugin <= 5.5.6 - Cross Si… |
| CVE-2026-19059 | 1.9 | 10.5 | FoundationAgents | MetaGPT | CWE-22 | FoundationAgents MetaGPT editor.py read path traversal |
| CVE-2026-43628 | 8.5 | 10.4 | ggml-org | llama.cpp | CWE-191 | llama.cpp b3978–b9058 Integer Underflow via DRY Sampler |
| CVE-2026-16734 | 7.5 | 10.4 | Unknown | Stripe Payment Forms by WP Full Pay | CWE-862 | Stripe Payment Forms by WP Full Pay < 8.5.2 - Unauthenticated Payment Intent … |
| CVE-2026-47194 | 8.6 | 10.3 | frappe | frappe | CWE-346 | Frappe: Host header poisoning can redirect magic login links to an attacker-c… |
| CVE-2026-71478 | 6.1 | 10.3 | thephpleague | commonmark | CWE-79 | league/commonmark: AttributesExtension href/src unsafe-link filter bypass via… |
| CVE-2025-6508 | 4.3 | 10.2 | WSO2 | WSO2 API Manager | CWE-79 | User Interface Misrepresentation via Swagger UI Try-out Console in WSO2 API M… |
| CVE-2026-19020 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System servicetype.php sql injection |
| CVE-2026-66685 | 5.3 | 9.8 | Alex | Featured Video Plus | CWE-201 | WordPress Featured Video Plus plugin <= 2.3.3 - Sensitive Data Exposure vulne… |
| CVE-2026-14306 | 4.3 | 9.8 | Unknown | Tutor LMS | CWE-639 | Tutor LMS < 3.9.14 - Subscriber+ Paid Course Content Disclosure via Enrollmen… |
| CVE-2026-66678 | 4.3 | 9.8 | Justin Kruit | Advanced Custom Fields: Font Awesome Field | CWE-862 | WordPress Advanced Custom Fields: Font Awesome Field plugin <= 6.1.1 - Broken… |
| CVE-2026-25403 | 6.5 | 9.4 | bdthemes | Ultimate Store Kit Elementor Addons | CWE-862 | WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Broken Access… |
| CVE-2026-14829 | 8.2 | 9.3 | Unknown | Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps | CWE-284 | Checkimate <= 1.0.13 - Unauthenticated License Deactivation via Hardcoded Secret |
| CVE-2026-66439 | 7.1 | 9.1 | BeRocket | Advanced AJAX Product Filters | CWE-79 | WordPress Advanced AJAX Product Filters plugin <= 3.2.0.3 - Cross Site Script… |
| CVE-2026-66440 | 7.1 | 9.1 | XplodedThemes | WPIDE – File Manager & Code Editor | CWE-79 | WordPress WPIDE – File Manager & Code Editor plugin <= 3.5.7 - Cross Site Scr… |
| CVE-2026-66457 | 7.1 | 9.1 | @msykes | Events Manager | CWE-79 | WordPress Events Manager plugin <= 7.4.1 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-66663 | 7.1 | 9.1 | Passionate Programmer Peter | WP Data Access | CWE-79 | WordPress WP Data Access plugin <= 5.5.79 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-66664 | 7.1 | 9.1 | SEO Squirrly | SEO Plugin by Squirrly SEO | CWE-79 | WordPress SEO plugin by Squirrly SEO plugin <= 14.2.0 - Cross Site Scripting … |
| CVE-2026-71435 | 6.1 | 9.1 | statamic | cms | CWE-79 | Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Te… |
| CVE-2025-15028 | 7.2 | 9.0 | wpwax | FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More | CWE-79 | FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, P… |
| CVE-2026-71497 | 4.7 | 9.0 | jhy | jsoup | CWE-79 | jsoup: Cleaner may expose markup with custom raw-text elements |
| CVE-2026-15256 | 4.8 | 8.7 | Unknown | Ninja Forms | CWE-74 | Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Que… |
| CVE-2025-14779 | 3.8 | 8.7 | WSO2 | WSO2 Identity Server | CWE-281 | Improper Access Control via Secret Type Management API in WSO2 Identity Server |
| CVE-2026-19058 | 1.9 | 8.6 | FoundationAgents | MetaGPT | CWE-74 | FoundationAgents MetaGPT data_interpreter.py DataInterpreter code injection |
| CVE-2026-19060 | 1.9 | 8.7 | FoundationAgents | MetaGPT | CWE-74 | FoundationAgents MetaGPT code injection |
| CVE-2026-18597 | 8.5 | 8.3 | Foxit Software Inc. | Foxit PDF Services API | CWE-918 | Blind SSRF on Foxit PDF Services API |
| CVE-2026-65517 | 7.1 | 8.3 | Scott Paterson | Easy PayPal Buy Now Button | CWE-79 | WordPress Easy PayPal Buy Now Button plugin <= 2.0.4 - Cross Site Scripting (… |
| CVE-2026-66699 | 5.3 | 8.3 | Dokan, Inc. | Dokan | CWE-862 | WordPress Dokan plugin <= 5.0.10 - Broken Access Control vulnerability |
| CVE-2026-66701 | 5.3 | 8.3 | Cozmoslabs | Profile Builder | CWE-862 | WordPress Profile Builder plugin <= 3.16.5 - Broken Access Control vulnerability |
| CVE-2026-14547 | 5.3 | 8.0 | Unknown | Estatik Real Estate Plugin | CWE-287 | Estatik Real Estate Plugin < 4.3.3 - Unauthenticated Arbitrary-Recipient Mail… |
| CVE-2026-19061 | 6.3 | 8.0 | Insta | InstaKNXServiceApp | CWE-345 | Insta InstaKNXServiceApp Firmware Update CreateWebClientAndDownloadFileList d… |
| CVE-2026-28082 | 7.1 | 7.8 | Crocoblock. Jetimpex Inc. | JetEngine | CWE-79 | WordPress JetEngine plugin <= 3.8.13.1 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-28141 | 7.1 | 7.8 | Syed Balkhi | NextGEN Gallery | CWE-79 | WordPress NextGEN Gallery plugin <= 4.2.3 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-28143 | 7.1 | 7.8 | WPMU DEV | Forminator | CWE-79 | WordPress Forminator plugin <= 1.56.0 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-28177 | 7.1 | 7.8 | Daniel Iser | Popup Maker | CWE-79 | WordPress Popup Maker plugin <= 1.23.0 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-61961 | 7.1 | 7.8 | WPDeveloper | EmbedPress | CWE-79 | WordPress EmbedPress plugin <= 4.5.6 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-61963 | 7.1 | 7.8 | David Lingren | Media LIbrary Assistant | CWE-79 | WordPress Media LIbrary Assistant plugin <= 3.38 - Cross Site Scripting (XSS)… |
| CVE-2026-61964 | 7.1 | 7.8 | WPManageNinja | Ninja Tables | CWE-79 | WordPress Ninja Tables plugin <= 5.2.9 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-61982 | 7.1 | 7.8 | jp-secure | SiteGuard WP Plugin | CWE-79 | WordPress SiteGuard WP Plugin plugin <= 1.8.6 - Cross Site Scripting (XSS) vu… |
| CVE-2026-65509 | 7.1 | 7.8 | wpDataTables | wpDataTables | CWE-79 | WordPress wpDataTables plugin <= 7.5.1 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-65513 | 7.1 | 7.8 | NSquared | Simply Schedule Appointments | CWE-79 | WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - Cross Site Scrip… |
| CVE-2026-65515 | 7.1 | 7.8 | AffiliateWP | AffiliateWP | CWE-79 | WordPress AffiliateWP plugin <= 2.35.0 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-65544 | 7.1 | 7.8 | Rajat Varlani | Super Socializer | CWE-79 | WordPress Super Socializer plugin <= 7.14.5 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-65545 | 7.1 | 7.8 | Jordy Meow | AI Engine | CWE-79 | WordPress AI Engine plugin <= 3.6.8 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-65560 | 7.1 | 7.8 | Property Hive | Houzez Property Feed | CWE-79 | WordPress Houzez Property Feed plugin <= 2.5.48 - Cross Site Scripting (XSS) … |
| CVE-2026-65565 | 7.1 | 7.8 | Ays Pro | Survey Maker | CWE-79 | WordPress Survey Maker plugin <= 5.2.3.3 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-45572 | 4.8 | 7.9 | decidim | decidim | CWE-94 | Decidim: HTML content blocks allow stored script execution |
| CVE-2026-12584 | 7.5 | 7.7 | Unknown | Payment Gateway for Redsys & WooCommerce Lite | — | Payment Gateway for Redsys & WooCommerce Lite < 7.0.2 - Unauthenticated Payme… |
| CVE-2025-11850 | 4.3 | 7.6 | WSO2 | WSO2 Identity Server | CWE-639 | Improper Implicit Association via User Store Initialization in WSO2 Identity … |
| CVE-2026-66696 | 4.3 | 7.4 | Nexcess | Gutenberg Blocks by Kadence Blocks | CWE-201 | WordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.7.8 - Sensitive Data… |
| CVE-2026-7867 | 7.8 | 7.3 | Red Hat | Red Hat Enterprise Linux 10 | CWE-863 | Udisks2: udisks2: local privilege escalation via as-user option spoofing |
| CVE-2024-10302 | 5.8 | 7.2 | WSO2 | WSO2 API Control Plane | CWE-20 | Improper Input Validation via Signup Process in Multiple WSO2 Products Enable… |
| CVE-2026-28179 | 5.9 | 6.9 | Damian Góra | FiboSearch | CWE-79 | WordPress FiboSearch plugin <= 1.33.0 - Cross Site Scripting (XSS) vulnerability |
| CVE-2025-13736 | 3.7 | 6.8 | WSO2 | WSO2 Identity Server as Key Manager | CWE-203 | Username Enumeration via Login Interface in Multiple WSO2 Products Allows Use… |
| CVE-2026-71555 | 4.1 | 6.5 | THM-Health | PILOS | CWE-1022 | PILOS: Reverse tabnabbing in room description |
| CVE-2026-71438 | 2.4 | 6.4 | mermaid-js | mermaid | CWE-1321 | Mermaid configuration APIs allow prototype pollution |
| CVE-2026-64591 | await | 6.1 | Linux | Linux | — | iommu/vt-d: Avoid WARNING in sva unbind path |
| CVE-2026-64593 | await | 6.1 | Linux | Linux | — | btrfs: do not trim a device which is not writeable |
| CVE-2026-64594 | await | 6.1 | Linux | Linux | — | usb: gadget: f_fs: initialize reset_work at allocation time |
| CVE-2026-64602 | await | 6.1 | Linux | Linux | — | iio: adc: spear: Initialize completion before requesting IRQ |
| CVE-2026-64604 | await | 6.1 | Linux | Linux | — | KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode |
| CVE-2026-11588 | 6.1 | 5.9 | Unknown | EONSR AEO Agent | CWE-79 | EONSR AEO Agent <= 3.7.9 - Unauthenticated Stored XSS via Scheduled Post Crea… |
| CVE-2026-28178 | 6.5 | 5.8 | codesupplyco | Powerkit | CWE-79 | WordPress Powerkit plugin <= 3.1.0 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-10599 | 7.5 | 5.7 | Unknown | Integrate PhonePe with WooCommerce | CWE-345 | Integrate PhonePe with WooCommerce <= 1.2.1 - Unauthenticated Payment Bypass … |
| CVE-2026-70640 | 7.3 | 5.6 | ggml-org | llama.cpp | CWE-476 | llama.cpp b1886–b7445 Race Condition Use-After-Free via llama-android.cpp |
| CVE-2025-9266 | 4.3 | 5.5 | themegrill | Accelerate | CWE-862 | Accelerate <= 1.5.3 - Missing Authorization to Authenticated (Subscriber+) Th… |
Results continue: ranks 401–482.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-08-06 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.