boxscore/security
Thursday, August 6, 2026 · all times UTC← 2026-08-05 · archive · 2026-08-07 →

482 CVEs published August 6, 2026: 87 critical, 187 high, 145 medium, 51 low; 0 in KEV; 5 with a public exploit reference; 12 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 457 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published16931049813972563
KEV catalog size1670

545 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux44162921011509802730.27.8.0016+32
microsoft3313941209393108378322.37.8.0040-17
google4345572134228187351.16.5.0023+43
red hat372591311911116400.07.1.0024+30
apple1245576711229372.97.1.0028+1
suse551220000.07.3.0022+5
canonical030210000.07.8.00130
android010100161100.08.4.01710
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco234391790961330.28.6.0032+23
fortinet018249028633.36.1.00540
palo alto networks015017514213.34.7.00280
vmware01247012100.08.7.00440
checkpoint1541003240.09.3.2062+1
f50540007120.09.2.04020
ivanti051000335100.010.0.81520
zyxel3403101100.07.2.0075+3
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache58195341065414021.07.5.0048+58
mozilla1734226501300.09.1.0031+1
gitlab015021014213.34.9.00290
github240220000.07.0.0040+2
docker030120100.05.7.00150
wordpress0311105266.78.6.73100
drupal01100051100.09.8.88320
kubernetes010001000.02.4.00240
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle01113212539304574030.37.6.00310
ibm321403661421710.77.5.0027+32
adobe7471623407548.58.6.0047+7
progress1033101850900.08.1.0029+10
solarwinds0201611011420.09.1.00500
veeam10123720400.08.6.0027+10
atlassian0303001300.08.0.00260
zohocorp031110000.07.1.00480
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link08006126112.55.5.00730
hikvision0704202114.37.2.00250
bosch030300000.08.1.00280
schneider electric031200100.08.7.00200
synology110100000.07.3.0013+1
honeywell010010000.06.9.00310
mitsubishi electric010100000.07.1.00130
rockwell automation011000000.09.2.00300
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
surrealdb057326253000.07.1.00250
grafana041214223000.06.5.00330
netty04162771000.07.5.00460
legion of the bouncy castle323952590000.08.7.0026+32
open ises037214210000.06.9.00210
mediatek343404300100.06.0.0011+34
erlang032114143100.06.9.0033-6
freerdp233181841000.08.7.0034+23

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-63030.956099.99.8
CVE-2026-39808.912199.8
CVE-2026-34486.829399.67.5
CVE-2026-48939.825099.610.0
CVE-2026-50522.769899.59.8
CVE-2026-15410.763599.57.2
CVE-2026-56291.760799.510.0
CVE-2026-15409.742299.410.0
CVE-2026-25089.736099.49.8
CVE-2026-16232.733099.49.3
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-1540910.0.7422KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0473
CVE-2026-4766810.0.0434
CVE-2026-4435910.0.0100
CVE-2025-7138910.0.0093
CVE-2026-4816810.0.0091
CVE-2026-5616310.0.0090
Most disclosures (vendor)
VendorCVEs
oracle1109
linux699
microsoft641
google446
apple168
apache163
red hat150
ibm132
mozilla68
surrealdb57
Most KEV additions (YTD)
VendorKEV
microsoft32
cisco13
apple7
fortinet6
google5
ivanti5
adobe4
langflow4
solarwinds4
synacor4
Most-affected ecosystems
EcosystemAdvisories
Maven61
PyPI5
Go3
npm3
crates.io2
NuGet1
Packagist1
Fastest to KEV
CVEVendorDays
CVE-2008-4128Cisco0
CVE-2021-27137DD-WRT0
CVE-2023-4346KNX Association0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-18556N-able0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171723
CVE-2021-27102Accellion2021-11-171723
CVE-2021-27101Accellion2021-11-171723
CVE-2021-27103Accellion2021-11-171723
CVE-2021-21017Adobe2021-11-171723
CVE-2021-28550Adobe2021-11-171723
CVE-2021-42013Apache2021-11-171723
CVE-2021-41773Apache2021-11-171723
CVE-2021-30858Apple2021-11-171723
CVE-2021-30860Apple2021-11-171723

Transactions

EXPLOIT PUBLISHEDCVE-2012-4681. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2019-15107. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2021-22205 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2021-43890 (Microsoft App Installer). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2022-30190 (Microsoft Windows 10 Version 1809). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2022-40684 (Fortinet FortiOS, FortiProxy, FortiSwitchManager). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2023-42753 (Red Hat Enterprise Linux 7). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10634 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10639 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10646 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10647 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10652 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10653 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10670 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-12605 (Eclipse Foundation Eclipse GlassFish). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16746 (Unknown MultiVendorX). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16940 (Unknown Custom Fields). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16981 (Unknown DHL Shipping Germany for WooCommerce). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18958 (imranrisal-dev Student-Management-System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18959 (yushine InnoShop). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-43997 (patriksimek vm2). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-43998 (patriksimek vm2). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-43999 (patriksimek vm2). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44001 (patriksimek vm2). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44004 (patriksimek vm2). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44005 (patriksimek vm2). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44006 (patriksimek vm2). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44007 (patriksimek vm2). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44008 (patriksimek vm2). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44009 (patriksimek vm2). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-44210 (kata-containers). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45411 (patriksimek vm2). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47429 (vitest-dev vitest). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54656 (koxudaxi datamodel-code-generator). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54690 (koxudaxi datamodel-code-generator). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54894 (ueberauth guardian). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55389 (koxudaxi datamodel-code-generator). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55415 (koxudaxi datamodel-code-generator). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55733 (ueberauth guardian). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55734 (ueberauth guardian). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-55735 (ueberauth guardian). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-64827 (Telenia Software TVox). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-64828 (Froiden TableTrack). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-67623 (mistralai mistral-vibe). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-69111 (milvus-io milvus). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-70615 (boringproxy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-70616 (boringproxy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-7656 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-8037 (Progress Software LoadMaster). Public exploit reference added.

RESCOREDCVE-2023-42753 (Red Hat Enterprise Linux 7). CVSS 7 → 7.8 (NVD).

RESCOREDCVE-2023-5090 (Red Hat Enterprise Linux 8). CVSS 6 → 5.5 (NVD).

RESCOREDCVE-2024-0646 (kernel). CVSS 7 → 7.8 (NVD).

RESCOREDCVE-2024-1488 (unbound). CVSS 8 → 7.3 (NVD).

RESCOREDCVE-2024-21549 (spatie/browsershot). CVSS 7.7 → 6.6 (NVD).

RESCOREDCVE-2026-10634 (zephyrproject zephyr). CVSS 4.8 → 5.3 (NVD).

RESCOREDCVE-2026-10643 (zephyrproject zephyr). CVSS 8.7 → 7.8 (NVD).

RESCOREDCVE-2026-10652 (zephyrproject zephyr). CVSS 4.8 → 7.4 (NVD).

RESCOREDCVE-2026-10653 (zephyrproject zephyr). CVSS 6.4 → 8.1 (NVD).

RESCOREDCVE-2026-11714 (IBM WebSphere Application Server - Liberty). CVSS 8.5 → 9.8 (NVD).

RESCOREDCVE-2026-16108 (Red Hat Build of Keycloak). CVSS 4.3 → 6.5 (NVD).

RESCOREDCVE-2026-18968 (ttttonyhe OBlog). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-18969 (Rongzhitong Visual Integrated Command and Dispatch Platform). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-18970 (Rongzhitong Visual Integrated Command and Dispatch Platform). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-47429 (vitest-dev vitest). CVSS 9.8 → 5.9 (NVD).

RESCOREDCVE-2026-7656 (zephyrproject zephyr). CVSS 8.1 → 6.8 (NVD).

Yesterday's Results

482 CVEs published. 25 box scores and 375 table rows below; the remaining 82 continue on page 2 — every CVE is listed, nothing truncated.

WGDashboard Remote Code Execution vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .1354   96.1     —
AFFECTED
  Product      Versions     Fixed
  WGDashboard  unspecified  —
TIMELINE
  Jul 14  Reserved by CNA
  Aug 6   Published (CNA: certcc)
CWE-78 · CNA: certcc · 2 references · NVD status: Received
Shibby Tomato qoslimittc_stop.sh new_qoslimit_stop os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    7.3   .0247   83.1     —
AFFECTED
  Product  Versions     Fixed
  Tomato   1.28.0000 –  —
TIMELINE
  Aug 6   Reserved by CNA
  Aug 6   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Shibby Tomato qoslimit new_qoslimit_start os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    7.3   .0247   83.1     —
AFFECTED
  Product  Versions     Fixed
  Tomato   1.28.0000 –  —
TIMELINE
  Aug 6   Reserved by CNA
  Aug 6   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Shibby Tomato wanoptions sub_40F88C os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    7.3   .0247   83.1     —
AFFECTED
  Product  Versions     Fixed
  Tomato   1.28.0000 –  —
TIMELINE
  Aug 6   Reserved by CNA
  Aug 6   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Bohdan Triapitsyn OpenChamber — OpenChamber 1.11.7 Path Traversal File Read via allowOutsideWorkspace Parameter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   N    9.3   .0190   77.9     —
AFFECTED
  Product      Versions     Fixed
  OpenChamber  unspecified  —
TIMELINE
  Jun 11  Reserved by CNA
  Aug 6   Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · 3 references · NVD status: Received
MissionSquad mcp-api NPM Package Version packages.ts this.packageService.installPackage command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0166   74.7     —
AFFECTED
  Product  Versions  Fixed
  mcp-api  1.11.0 –  1.11.9
TIMELINE
  Aug 6   Reserved by CNA
  Aug 6   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 9 references · NVD status: Deferred
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Co…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0160   73.8     —
AFFECTED
  Product                                               Versions     Fixed
  Virtual Storage Integrator for VMware vSphere Client  unspecified  —
TIMELINE
  Jul 29  Reserved by CNA
  Aug 6   Published (CNA: dell)
CWE-78 · CNA: dell · 1 reference · NVD status: Analyzed
nearai ironclaw shell.rs classify_command_risk command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0133   68.6     —
AFFECTED
  Product   Versions  Fixed
  ironclaw  0.29.0 –  —
TIMELINE
  Aug 5   Reserved by CNA
  Aug 6   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 13 references · NVD status: Deferred
n/a OpenHands — OpenHands send_pull_request.py initialize_repo command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    5.3   .0129   67.9     —
AFFECTED
  Product    Versions  Fixed
  OpenHands  0.1 –     —
TIMELINE
  Aug 5   Reserved by CNA
  Aug 6   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 6 references · NVD status: Deferred
Bohdan Triapitsyn OpenChamber — OpenChamber 1.11.7 Unauthenticated RCE via /api/fs/exec
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0108   62.4     —
AFFECTED
  Product      Versions     Fixed
  OpenChamber  unspecified  —
TIMELINE
  Jun 11  Reserved by CNA
  Aug 6   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 3 references · NVD status: Received
Microsoft Azure Service Bus — Azure Service Bus Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0091   57.0     —
AFFECTED
  Product            Versions  Fixed
  Azure Service Bus  - –       —
TIMELINE
  Jun 4   Reserved by CNA
  Aug 6   Published (CNA: microsoft)
CWE-502 · CNA: microsoft · 1 reference · NVD status: Analyzed
Eukaryot sonic3air — Sonic 3 A.I.R. Unbounded Memory Allocation DoS via ReceivedPacketCache
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0089   56.3     —
AFFECTED
  Product    Versions     Fixed
  sonic3air  unspecified  2492d1882cd2cf1cc1d7415729ce5c4fd686cd4f
TIMELINE
  Jul 27  Reserved by CNA
  Aug 6   Published (CNA: VulnCheck)
CWE-789 · CNA: VulnCheck · 2 references · NVD status: Received
ankitects anki — Anki's local HTTP server is vulnerable to directory traversal attacks
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   A   H   N   N    5.9   .0076   52.1     —
AFFECTED
  Product  Versions      Fixed
  anki     >= 25.09.3 –  —
TIMELINE
  Jul 20  Reserved by CNA
  Aug 6   Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · 2 references · NVD status: Received
cli cli — GitHub CLI: Terminal escape sequence injection in multiple `gh` commands
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   N   N    5.3   .0074   51.5     —
AFFECTED
  Product  Versions    Fixed
  cli      < 2.97.0 –  —
TIMELINE
  Jul 20  Reserved by CNA
  Aug 6   Published (CNA: GitHub_M)
CWE-150 · CNA: GitHub_M · 3 references · NVD status: Received
misp cti-transmute — Unauthenticated Stored Vue Template Injection Leads to Cross-Site Scripting in CTI-Transmute
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   L   L   N    5.1   .0071   50.4     —
AFFECTED
  Product        Versions     Fixed
  cti-transmute  unspecified  —
TIMELINE
  Aug 6   Reserved by CNA
  Aug 6   Published (CNA: CIRCL)
CWE-79, CWE-1336 · CNA: CIRCL · 4 references · NVD status: Received
PHPCSStandards PHP_CodeSniffer — PHP_CodeSniffer gitblame report command injection via crafted filename
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   P   N   P   H   H   H    7.3   .0070   50.2     —
AFFECTED
  Product          Versions    Fixed
  PHP_CodeSniffer  < 3.13.6 –  —
TIMELINE
  Jul 29  Reserved by CNA
  Aug 6   Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 6 references · NVD status: Received
LeeSinLiang godot-mcp create_scene/add_node index.ts executeOperation command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    1.9   .0070   50.0     —
AFFECTED
  Product    Versions  Fixed
  godot-mcp  0.1.0 –   —
TIMELINE
  Aug 6   Reserved by CNA
  Aug 6   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 6 references · NVD status: Deferred
Apache CXF: Unsafe deserialization of inbound JMS ObjectMessage
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0069   49.9     —
AFFECTED
  Product     Versions  Fixed
  Apache CXF  4.2.0 –   —
TIMELINE
  Jul 28  Reserved by CNA
  Aug 6   Published (CNA: apache)
CWE-502 · CNA: apache · 2 references · NVD status: Modified
n/a n/a — In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0069   49.8     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 21  Reserved by CNA
  Aug 6   Published (CNA: mitre)
CWE-79 · CNA: mitre · 1 reference · NVD status: Received
n/a n/a — SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `f…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0069   49.6     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jul 30  Reserved by CNA
  Aug 6   Published (CNA: mitre)
CWE-89 · CNA: mitre · 2 references · NVD status: Received
NocteDefensor LudusMCP ludus_cli_execute cliWrapper.ts executeCommand command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    1.9   .0068   49.5     —
AFFECTED
  Product   Versions  Fixed
  LudusMCP  1.0.0 –   —
TIMELINE
  Aug 6   Reserved by CNA
  Aug 6   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 7 references · NVD status: Deferred
WGDashboard Server-Side Template Injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0068   49.3     —
AFFECTED
  Product      Versions     Fixed
  WGDashboard  unspecified  —
TIMELINE
  Jul 14  Reserved by CNA
  Aug 6   Published (CNA: certcc)
CWE-1336 · CNA: certcc · 2 references · NVD status: Received
Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0063   47.5     —
AFFECTED
  Product                               Versions  Fixed
  Microsoft Entra Provisioning Service  - –       —
TIMELINE
  Jul 2   Reserved by CNA
  Aug 6   Published (CNA: microsoft)
CWE-35 · CNA: microsoft · 1 reference · NVD status: Analyzed
Microsoft Application Insights Profiler — Application Insights Profiler Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0062   46.9     —
AFFECTED
  Product                        Versions  Fixed
  Application Insights Profiler  - –       —
TIMELINE
  May 27  Reserved by CNA
  Aug 6   Published (CNA: microsoft)
CWE-22 · CNA: microsoft · 1 reference · NVD status: Analyzed
NocteDefensor LudusMCP get_credential_from_user secretDialog.ts SecretDialog.showSecretDialog command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    1.9   .0062   46.9     —
AFFECTED
  Product   Versions  Fixed
  LudusMCP  1.0.0 –   —
TIMELINE
  Aug 6   Reserved by CNA
  Aug 6   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 7 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-436299.246.8ggml-orgllama.cppCWE-787llama.cpp b4882–b9058 Buffer Overflow in KV Cache State Restore
CVE-2026-159918.846.2bitpressadminFile ManagerCWE-862File Manager 6.0 - 6.9 - Missing Authorization to Authenticated (Subscriber+)…
CVE-2026-186497.545.9Red HatRed Hat Enterprise Linux 10CWE-770Gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay a…
CVE-2026-705589.345.7DataLinkDCDinkyCWE-434Dinky Unauthenticated Arbitrary File Write via /download/uploadFromRsByLocal …
CVE-2026-676889.845.3n/an/aCWE-434ICS-Park Smart Park Management System v2.0 contains an unrestricted file uplo…
CVE-2026-714768.745.0nrwlnxCWE-22Nx: Zip-Slip in the self-hosted remote cache
CVE-2026-674227.545.0facelessuserpymdown-extensionsCWE-1333pymdown-extensions: Exponential-backtracking ReDoS in caret, tilde, betterem,…
CVE-2026-1481210.044.4UnknownPremium SEOCWE-912Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content…
CVE-2026-501595.344.4mermaid-jsmermaidCWE-94Mermaid allows CSS injection applying to sibling elements of the diagram
CVE-2026-480859.843.6open-receptionappointment-booking-softwareCWE-862OpenReception has unauthenticated GLOBAL_ADMIN account creation post-bootstrap
CVE-2026-713247.043.5traefiktraefikCWE-444Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's share…
CVE-2026-191508.843.2GoogleChromeCWE-693Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 a…
CVE-2026-191518.843.2GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remot…
CVE-2026-191688.843.2GoogleChromeCWE-693Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 a…
CVE-2026-58579.242.7Contiki-NGContiki-NGCWE-787Contiki-NG MQTT Client Out-of-Bounds Write in PUBLISH Topic Parser via Persis…
CVE-2026-58558.742.8Contiki-NGContiki-NGCWE-125Contiki-NG LwM2M TLV Parser Out-of-Bounds Read via Unchecked Buffer Length in…
CVE-2026-345017.542.3Apache Software FoundationApache Portable Runtime UtilityCWE-122Apache Portable Runtime Utility: Heap buffer overflow in APR redis client
CVE-2026-345027.542.3Apache Software FoundationApache Portable Runtime UtilityCWE-122Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client
CVE-2026-676878.842.2n/an/aCWE-284Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker…
CVE-2026-34189.141.9WSO2WSO2 API ManagerCWE-434Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Re…
CVE-2026-539778.741.8Bohdan TriapitsynOpenChamberCWE-306OpenChamber 1.11.7 Unauthenticated DoS via /api/system/shutdown
CVE-2026-154598.141.2wpmudevWPMU DEV DashboardCWE-287WPMU DEV Dashboard <= 5.0.0 - Authentication Bypass to Arbitrary Plugin Insta…
CVE-2026-706337.141.0timescaletimescaledbCWE-191TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Gorilla Compression Reverse Ite…
CVE-2026-646535.140.8clicliCWE-22GitHub CLI: Unescaped variable components in request URLs could allow path tr…
CVE-2026-191499.640.6GoogleChromeCWE-416Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allo…
CVE-2026-688239.140.6MicrosoftAzure Confidential LedgerCWE-749Azure Confidential Ledger Remote Code Execution Vulnerability
CVE-2026-668292.340.6rrrenehtml_sanitize_exCWE-601html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowin…
CVE-2026-654009.840.4ApplemacOSCWE-287An authentication issue was addressed with improved state management. This is…
CVE-2026-189915.540.1nanocoaiNanoClawCWE-22nanocoai NanoClaw send_file core.ts path traversal
CVE-2026-191767.540.1GoogleChromeCWE-416Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a rem…
CVE-2026-1197610.039.7UnknownMonsterInsights ProCWE-912MonsterInsights Pro 10.2.0/10.2.2 - Backdoored via AWS S3 bucket compromise
CVE-2026-5616210.039.6MicrosoftAzure SQL DatabaseCWE-287Azure SQL Database Elevation of Privilege Vulnerability
CVE-2026-667099.139.5WebAppickCTX FeedCWE-94WordPress CTX Feed plugin <= 6.6.42 - Remote Code Execution (RCE) vulnerability
CVE-2026-703329.639.4MicrosoftMicrosoft SharePoint OnlineCWE-79Microsoft Office SharePoint Spoofing Vulnerability
CVE-2026-6555310.039.2wbolt.comSpider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件CWE-94WordPress Spider Analyser – WordPress搜索引擎蜘蛛分析插件 plugin <= 2.1.3 - Remote Code…
CVE-2026-323279.139.1Apache Software FoundationApache Portable Runtime UtilityCWE-674Apache Portable Runtime Utility: apr-util XML stack recursion crash
CVE-2026-190382.139.0MonomythDevelopmentla-forge-mcpCWE-22MonomythDevelopment la-forge-mcp screenshot_element Tool index.ts screenshotE…
CVE-2026-542257.538.5Apache Software FoundationApache CXFCWE-770Apache CXF: Denial of Service attack via large attachments
CVE-2026-578197.538.5Apache Software FoundationApache CXFCWE-400Apache CXF: No default restriction on the amount of form parameters per message
CVE-2026-184277.537.9@fastify/static@fastify/staticCWE-22@fastify/static vulnerable to route guard bypass via non-canonical path segments
CVE-2026-480879.837.9open-receptionappointment-booking-softwareCWE-287OpenReception: WebAuthn passkey injection allows account takeover
CVE-2026-504819.937.8MicrosoftAzure Active DirectoryCWE-471Azure Active Directory Elevation of Privilege Vulnerability
CVE-2026-480548.837.7OpenZeppelincontracts-wizardCWE-94OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Fou…
CVE-2026-191378.337.6GoogleChromeCWE-416Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 a…
CVE-2026-436306.337.6ggml-orgllama.cppCWE-125llama.cpp b5702–b7653 Out-of-Bounds Read Information Disclosure
CVE-2026-191778.337.4GoogleChromeCWE-20Insufficient validation of untrusted input in UI in Google Chrome prior to 15…
CVE-2026-578178.136.8Apache Software FoundationApache CXFCWE-20Apache CXF: The authorization code hash (c_hash) is not enforced for the hybr…
CVE-2026-6350810.036.8MicrosoftMicrosoft Planetary Computer Pro (GeoCatalog)CWE-306Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability
CVE-2026-6566710.036.8MicrosoftMicrosoft TeamsCWE-862Microsoft Teams Elevation of Privilege Vulnerability
CVE-2026-687498.236.7rrrenehtml_sanitize_exCWE-1333Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-…
CVE-2026-687508.236.7rrrenehtml_sanitize_exCWE-407Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allo…
CVE-2026-614669.136.6Apache Software FoundationApache CXFCWE-304Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation
CVE-2026-655489.936.5MuffingroupBethemeCWE-94WordPress Betheme theme <= 28.4.2 - Remote Code Execution (RCE) vulnerability
CVE-2026-162688.236.4UnknownNewslettersCWE-918Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Boun…
CVE-2026-191458.836.3GoogleChromeCWE-416Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed …
CVE-2026-191628.836.3GoogleChromeCWE-787Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a …
CVE-2026-191748.836.3GoogleChromeCWE-190Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a rem…
CVE-2026-477657.135.9frappefrappeCWE-862Frappe: Lack of Permissions in restore/bulk_restore
CVE-2026-655529.835.5qstudioExport User DataCWE-502WordPress Export User Data plugin <= 2.2.6 - PHP Object Injection vulnerability
CVE-2026-684817.535.5Apache Software FoundationApache CXFCWE-672Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider
CVE-2026-544899.835.4DellVirtual Storage Integrator for VMware vSphere ClientCWE-200Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to …
CVE-2026-191669.635.3GoogleChromeCWE-416Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109…
CVE-2026-191418.335.2GoogleChromeCWE-416Use after free in Resources in Google Chrome on Android prior to 151.0.7922.1…
CVE-2026-191427.535.3GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a re…
CVE-2026-191587.535.3GoogleChromeCWE-416Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 a…
CVE-2026-191597.535.3GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a re…
CVE-2026-628309.934.8MicrosoftAzure SRE AgentCWE-862Azure SRE Agent Elevation of Privilege Vulnerability
CVE-2026-656688.834.8MicrosoftMicrosoft Purview eDiscoveryCWE-284Microsoft Purview eDiscovery Elevation of Privilege Vulnerability
CVE-2026-190115.534.7n/aTinyAGICWE-73TinyAGI agents.ts buildSystemPrompt file inclusion
CVE-2026-706347.234.5timescaletimescaledbCWE-129TimescaleDB 2.29.1 Out-of-Bounds Read Information Disclosure via Dictionary C…
CVE-2026-436319.234.3ggml-orgllama.cppCWE-416llama.cpp b7492–b9060 Use-After-Free RCE via llama-server
CVE-2026-680799.834.3Apache Software FoundationApache CXFCWE-294Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization …
CVE-2026-654327.534.1Apache Software FoundationApache CXFCWE-611Apache CXF: XXE via WSDL/XSD import parsing
CVE-2026-190402.134.1MissionSquadmcp-apiCWE-918MissionSquad mcp-api dcrClients.ts server-side request forgery
CVE-2026-649587.533.9Apache Software FoundationApache CXFCWE-400Apache CXF: Denial of service via message header attachments
CVE-2026-616325.333.6facelessuserpymdown-extensionsCWE-22PyMdown Extensions: Path traversal in the b64 extension lets <img src> read f…
CVE-2026-191579.633.2GoogleChromeCWE-787Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.…
CVE-2026-191709.633.2GoogleChromeCWE-416Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 a…
CVE-2026-655437.533.0vimeodevVimeoCWE-201WordPress Vimeo plugin <= 1.2.2 - Sensitive Data Exposure vulnerability
CVE-2026-189905.532.9letta-aiLettaBotCWE-287letta-ai LettaBot API Status Route server.ts missing authentication
CVE-2026-454156.032.8decidimdecidimCWE-862Decidim: CSV census record endpoints improper authorization
CVE-2026-53366.832.7UnknownDataPress (Dataverse Integration)CWE-200Dataverse Integration < 2.91 - Contributor+ Server-Side Template Injection (S…
CVE-2025-495067.532.6Apache Software FoundationApache Portable Runtime UtilityCWE-208Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing…
CVE-2026-471855.132.5frappefrappeCWE-79Frappe Has Broken Access Control in its Workspace Save API
CVE-2026-480756.532.3open-receptionappointment-booking-softwareCWE-862OpenReception's unauthenticated add-to-tunnel endpoint accepts arbitrary appo…
CVE-2026-714395.332.3mermaid-jsmermaidCWE-606Mermaid radar diagrams are vulnerable to DoS
CVE-2026-591189.332.2MicrosoftCopilot CoworkCWE-285Copilot Cowork Elevation of Privilege Vulnerability
CVE-2026-190095.532.1n/aTinyAGICWE-73TinyAGI Message API Endpoint response.ts collectFiles file inclusion
CVE-2026-281399.831.8wpdreamsAjax Search LiteCWE-502WordPress Ajax Search Lite plugin <= 4.14.4 - PHP Object Injection vulnerability
CVE-2025-145619.031.7WSO2WSO2 API ManagerCWE-284Access Control Bypass via Publisher REST APIs in Multiple WSO2 Products Allow…
CVE-2026-480797.431.7open-receptionappointment-booking-softwareCWE-613OpenReception's logout page clears local access_token before server-side revo…
CVE-2026-157329.831.3WGDashboardWGDashboardCWE-918WGDashboard Server-Side Request Forgery Vulnerability
CVE-2026-561619.631.3MicrosoftAzure Logic AppsCWE-284Azure Logic Apps Information Disclosure Vulnerability
CVE-2026-628969.631.3MicrosoftMicrosoft TeamsCWE-287Microsoft Teams Elevation of Privilege Vulnerability
CVE-2026-539848.831.2Efstratios GoudelisGround StationCWE-306Ground Station prior to 0.6.0 Unauthenticated Database Wipe and Arbitrary Dat…
CVE-2026-539858.731.2Efstratios GoudelisGround StationCWE-306Ground Station prior to 0.6.0 Unauthenticated DoS via service_control Socket.IO
CVE-2026-480715.831.1open-receptionappointment-booking-softwareCWE-307OpenReception's client PIN challenge throttle is keyed by emailHash only, all…
CVE-2026-170329.830.5Unknowngoogle-maps-easy-proCWE-912Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server
CVE-2026-706368.730.5FlowiseAIFlowiseCWE-862Flowise 3.1.4 Authentication Bypass via OAuth2 Credential Refresh Endpoint
CVE-2026-191649.630.3GoogleChromeCWE-20Insufficient validation of untrusted input in Codecs in Google Chrome prior t…
CVE-2026-191719.630.3GoogleChromeCWE-416Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 a…
CVE-2026-191759.630.3GoogleChromeCWE-416Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a…
CVE-2025-150399.430.3WSO2WSO2 Identity ServerCWE-693Account Takeover via Conditional Authentication Script Logic in Multiple WSO2…
CVE-2026-191448.830.3GoogleChromeCWE-416Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a rem…
CVE-2026-191698.830.3GoogleChromeCWE-20Insufficient validation of untrusted input in Contextual Tasks in Google Chro…
CVE-2026-191388.330.3GoogleChromeCWE-122Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.1…
CVE-2026-190105.530.3n/aTinyAGICWE-862TinyAGI Message API Endpoint index.ts processMessage authorization
CVE-2026-191118.630.1AWSstrands-agents-toolsCWE-639Insecure direct object reference in Strands Agents Tools memory tool namespac…
CVE-2026-655497.230.1jegthemeJeg Kit for ElementorCWE-502WordPress Jeg Elementor Kit plugin <= 3.2.10 - PHP Object Injection vulnerabi…
CVE-2026-480823.730.1open-receptionappointment-booking-softwareCWE-770OpenReception's bootstrap challenge proof-of-work difficulty hardcoded to 16 …
CVE-2026-191538.129.8GoogleChromeCWE-20Insufficient validation of untrusted input in Workers in Google Chrome prior …
CVE-2026-645979.829.5LinuxLinuxsmb: client: fix double-free in SMB2_close() replay
CVE-2026-713277.629.5traefiktraefikCWE-694Traefik: Gateway API route identity collision allows cross-namespace backend …
CVE-2026-191465.329.4GoogleChromeCWE-457Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 …
CVE-2026-341919.129.3Apache Software FoundationApache Portable Runtime UtilityCWE-89Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
CVE-2026-191548.329.3GoogleChromeCWE-416Use after free in Skia in Google Chrome on Android prior to 151.0.7922.109 al…
CVE-2026-191728.329.3GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a re…
CVE-2026-480847.429.2open-receptionappointment-booking-softwareCWE-307OpenReception doesn't rate limit passphrase login attempts
CVE-2026-6283610.029.0MicrosoftAzure SQL Managed InstanceCWE-923Azure SQL Managed Instance Elevation of Privilege Vulnerability
CVE-2026-706357.129.0timescaletimescaledbCWE-129TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Bulk Dictionary Decompression N…
CVE-2026-646405.329.0Apache Software FoundationApache PolarisCWE-863Apache Polaris: register endpoint reads attacker-controlled storage location …
CVE-2026-190645.328.9SourceCodesterOnline Examination & Learning Management SystemCWE-285SourceCodester Online Examination & Learning Management System view.php autho…
CVE-2026-191603.128.9GoogleChromeCWE-457Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a …
CVE-2026-713262.128.7traefiktraefikCWE-287Traefik: BasicAuth singleflight key collision allows authenticated identity s…
CVE-2026-190372.128.2n/aWonderTraderCWE-840WonderTrader Internal Limit Order Book Cache MatchEngine.cpp update_lob behav…
CVE-2026-706467.528.0vovchic17aiosendCWE-400aiosend: Deserialization of request body before signature verification (Pre-a…
CVE-2026-480836.527.9open-receptionappointment-booking-softwareCWE-117OpenReception: Unauthenticated POST /api/log accepts arbitrary content with C…
CVE-2026-714887.527.6thephpleaguecommonmarkCWE-407league/commonmark: Quadratic-time denial of service when parsing crafted Mark…
CVE-2026-578188.127.4Apache Software FoundationApache CXFCWE-367Apache CXF: OAuth2 Authorization Code Replay via TOCTOU in JCacheCodeDataProv…
CVE-2026-628739.827.3MicrosoftMicrosoft 365 Admin CenterCWE-347Microsoft 365 Admin Center Elevation of Privilege Vulnerability
CVE-2026-493915.127.3frappefrappeCWE-79Frappe: Stored XSS in Column Headers via Data Import
CVE-2026-34158.727.2WSO2WSO2 API ManagerCWE-776XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Pr…
CVE-2026-190082.127.2mf-yangopenclaw-cnCWE-59mf-yang openclaw-cn apply_patch Tool sandbox-paths.ts assertNoSymlinkEscape l…
CVE-2026-705577.126.8dibootdiboot-coreCWE-639diboot-core Authenticated Arbitrary Field Read via loadRelatedData Discloses …
CVE-2026-191408.326.6GoogleChromeCWE-416Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remo…
CVE-2026-191478.326.6GoogleChromeCWE-416Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allo…
CVE-2026-191488.326.6GoogleChromeCWE-787Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 …
CVE-2026-191528.326.6GoogleChromeCWE-693Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0…
CVE-2026-191558.326.6GoogleChromeCWE-416Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a…
CVE-2026-191638.326.6GoogleChromeCWE-416Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 a…
CVE-2026-191738.326.6GoogleChromeCWE-787Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed …
CVE-2026-54238.226.4neo4jgraphqlCWE-302Subscription Authentication Bypass via Unverified connectionParams.jwt
CVE-2026-480869.926.3open-receptionappointment-booking-softwareCWE-269OpenReception: Tenant admin self-promotes to GLOBAL_ADMIN
CVE-2026-280059.826.0NexcessKadence WooCommerce Email DesignerCWE-862WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19 - Privilege Esc…
CVE-2026-655079.826.0SergeyAIWUCWE-266WordPress AIWU plugin <= 1.5.6 - Privilege Escalation vulnerability
CVE-2026-436329.225.8ggml-orgllama.cppCWE-416llama.cpp b7492–b9060 Use-After-Free in Tokenization Endpoints
CVE-2026-191673.125.7GoogleChromeCWE-190Integer overflow in GPU in Google Chrome prior to 151.0.7922.109 allowed a re…
CVE-2026-646552.125.7clicliCWE-185GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacter…
CVE-2026-705598.725.7DataLinkDCDinkyCWE-306Dinky Unauthenticated System Configuration and Credential Disclosure via GET …
CVE-2026-281466.525.7Unlimited ElementsUnlimited Elements For Elementor (Free Widgets, Addons, Templates)CWE-22WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) …
CVE-2026-714365.325.4mermaid-jsmermaidCWE-835Mermaid XY Charts are vulnerable to an infinite loop DoS
CVE-2026-539839.225.3Efstratios GoudelisGround StationCWE-918Ground Station prior to 0.6.0 Unauthenticated Persistent Blind Server-Side Re…
CVE-2026-715545.325.3python-hyperh2CWE-444h2: Duplicate Host header could facilitate request smuggling
CVE-2026-454148.525.2decidimdecidimCWE-639Decidim: JWT-backed authentication can be replayed across organizations
CVE-2026-714458.224.6ail-projectail-frameworkCWE-79Authenticated Reflected Cross-Site Scripting in Tag Error Responses in ail-fr…
CVE-2026-190692.124.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System treatmentrecord.php sql injection
CVE-2026-190702.124.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System viewadmin.php sql injection
CVE-2026-190712.124.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System viewappointment.php sql injection
CVE-2026-184875.424.6GNOMEEpiphanyCWE-451Epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_ho…
CVE-2026-655597.224.4tychesoftwaresOrder Delivery Date for WooCommerceCWE-266WordPress Order Delivery Date for WooCommerce plugin <= 4.6.0 - Privilege Esc…
CVE-2026-655547.124.3lattepressAnsPress – Question and answerCWE-862WordPress AnsPress – Question and answer plugin 4.4.4 - Broken Access Control…
CVE-2026-655569.824.1MihCheWPBruiser {no- Captcha anti-Spam}CWE-502WordPress WPBruiser {no- Captcha anti-Spam} plugin <= 3.1.43 - PHP Object Inj…
CVE-2026-655719.824.1Axiomthemes69 ClothingCWE-502WordPress 69 Clothing theme <= 1.2.11.1 - PHP Object Injection vulnerability
CVE-2026-655729.824.1AxiomthemesA.WilliamsCWE-502WordPress A.Williams theme <= 1.3.1 - PHP Object Injection vulnerability
CVE-2026-655739.824.1ThemeREXAbelleCWE-502WordPress Abelle theme <= 1.22 - PHP Object Injection vulnerability
CVE-2026-655749.824.1AncoraThemesAbogadoCWE-502WordPress Abogado theme <= 1.18 - PHP Object Injection vulnerability
CVE-2026-655759.824.1AncoraThemesAccaliaCWE-502WordPress Accalia theme <= 1.5.3 - PHP Object Injection vulnerability
CVE-2026-655769.824.1AncoraThemesAdrenaCWE-502WordPress Adrena theme <= 1.2.14 - PHP Object Injection vulnerability
CVE-2026-655779.824.1AncoraThemesAdviceCWE-502WordPress Advice theme <= 1.18.0 - PHP Object Injection vulnerability
CVE-2026-655789.824.1AncoraThemesAgoraCWE-502WordPress Agora theme <= 1.9 - PHP Object Injection vulnerability
CVE-2026-655799.824.1axiomthemesAgricolaCWE-502WordPress Agricola theme <= 1.21.0 - PHP Object Injection vulnerability
CVE-2026-655819.824.1AxiomthemesAI ANNCWE-502WordPress AI ANN theme <= 1.29.0 - PHP Object Injection vulnerability
CVE-2026-190625.524.0chiuwingyanhouseCWE-74chiuwingyan house selectall.action sql injection
CVE-2026-646658.123.8statamiccmsCWE-287Statamic: Account takeover via OAuth email matching without email-verificatio…
CVE-2026-189745.523.8heshengtaosuper-agent-partyCWE-200heshengtao super-agent-party execute_tool_manually Endpoint server.py get_fil…
CVE-2026-182588.823.7ScriptaeScriptoriumCWE-639Authorization Bypass Through User-Controlled Key in eScriptorium
CVE-2026-148315.323.7UnknownEasy BookingCWE-602Easy Booking < 3.5.0 - Unauthenticated Minimum Booking Duration Bypass
CVE-2026-455736.423.5decidimdecidimCWE-918Decidim: Push subscriptions can be abused for server-side requests
CVE-2026-664707.123.3Shabti KaplanFrontend Admin by DynamiAppsCWE-862WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Broken Access Cont…
CVE-2026-480775.323.3open-receptionappointment-booking-softwareCWE-862OpenReception: GET appointment by ID returns full appointment record without …
CVE-2026-166367.223.2wpmanageninjaFluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, Mailgun, Postmark, Cloudflare, toSend, Gmail and Any SMTPCWE-79FluentSMTP <= 2.2.95 - Unauthenticated Stored Cross-Site Scripting via Recipi…
CVE-2026-646626.523.1statamiccmsCWE-639Statamic: Missing authorization on navigation endpoint allows disclosure of r…
CVE-2026-190192.923.1poco-aipoco-agentCWE-459poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_p…
CVE-2026-667108.122.9E2Pdfe2pdfCWE-98WordPress e2pdf plugin <= 1.32.40 - Local File Inclusion vulnerability
CVE-2026-453787.522.8decidimdecidimCWE-200Decidim: Verification documents can be downloaded through reusable links
CVE-2026-189735.522.3heshengtaosuper-agent-partyCWE-918heshengtao super-agent-party extension_proxy Route server.py sanitize_proxy_u…
CVE-2026-17289.822.2WSO2WSO2 API ManagerCWE-269Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits A…
CVE-2026-646636.522.1statamiccmsCWE-470Statamic: Unsafe method invocation via Antlers template resolution allows dat…
CVE-2026-191613.122.1GoogleChromeCWE-457Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a …
CVE-2026-664256.522.1Saad IqbalGutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form BuilderCWE-288WordPress Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Fo…
CVE-2026-480889.421.9open-receptionappointment-booking-softwareCWE-862OpenReception vulnerable to unauthenticated staff crypto poisoning that break…
CVE-2026-629187.521.8MicrosoftMicrosoft TeamsCWE-347Microsoft Teams Spoofing Vulnerability
CVE-2026-655089.321.6NSquaredSimply Schedule AppointmentsCWE-89WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - SQL Injection vu…
CVE-2026-655209.321.6miniOrangeWP OAuth ServerCWE-89WordPress WP OAuth Server plugin <= 6.2.0 - SQL Injection vulnerability
CVE-2026-190005.521.6n/aJeecgBootCWE-918JeecgBoot Anonymous Chat Attachment send server-side request forgery
CVE-2026-148425.321.6UnknownEvents Made EasyCWE-639Events Made Easy < 3.1.2 - Unauthenticated Payment Bypass
CVE-2026-6666510.021.5BrandexponentsType HubCWE-434WordPress Type Hub plugin <= 2.0.6 - Arbitrary File Upload vulnerability
CVE-2026-714376.521.5mermaid-jsmermaidCWE-1321Mermaid Architecture diagrams are vulnerable to prototype pollution
CVE-2026-668432.321.5rrrenehtml_sanitize_exCWE-829html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, …
CVE-2026-172645.321.2MedixantRadiAnt DICOMCWE-787Medixant RadiAnt DICOM Out-of-bounds write
CVE-2026-655047.521.2ivanbebekBOX NOW Delivery CroatiaCWE-862WordPress BOX NOW Delivery Croatia plugin <= 3.3.0 - Broken Access Control vu…
CVE-2026-655237.521.2approvemeFormidable Forms Signature Online Contract AutomationCWE-639WordPress Formidable Forms Signature Online Contract Automation plugin <= 2.0…
CVE-2026-281118.821.1WPMU DEVForminatorCWE-266WordPress Forminator plugin <= 1.56.0 - Privilege Escalation vulnerability
CVE-2026-191276.521.1GitroomHQpostiz-appCWE-345Insufficient verification of lifetime-deal redemption codes allows forgery of…
CVE-2026-133997.520.8UnknownPayment Plugins for PayPal WooCommerceCWE-639Payment Plugins for PayPal WooCommerce < 2.0.20 - Unauthenticated Payment Byp…
CVE-2026-645988.820.7LinuxLinuxsmb/client: Fix error code in smb2_aead_req_alloc()
CVE-2026-189952.120.7netease-youdaoLobsterAICWE-200netease-youdao LobsterAI MEDIA Path artifactParser.ts parseMediaTokensFromTex…
CVE-2026-480742.720.5open-receptionappointment-booking-softwareCWE-863OpenReception: Staff deletion removes pending invites cross-tenant by email m…
CVE-2026-183257.220.3wpmudevForminator Forms – Contact Form, Payment Form & Custom Form BuilderCWE-79Forminator Forms <= 1.56.1 - Unauthenticated Stored Cross-Site Scripting via …
CVE-2026-655478.520.2Constant ContactCreative MailCWE-89WordPress Creative Mail plugin <= 1.6.9 - SQL Injection vulnerability
CVE-2026-655698.520.2wpjobportalWP Job PortalCWE-89WordPress WP Job Portal plugin <= 2.5.6 - SQL Injection vulnerability
CVE-2026-480808.020.1open-receptionappointment-booking-softwareCWE-200OpenReception's tenant detail endpoint discloses live PostgreSQL connection s…
CVE-2026-167318.319.9OMICRON electronics GmbHOMICRON StationScoutCWE-208Authentication and authorization bypass via cryptographic timing side-channel…
CVE-2026-160549.119.8UnknownDrag and Drop Multiple File Upload for WooCommerceCWE-73Drag and Drop Multiple File Upload for WooCommerce < 1.1.8 - Unauthenticated …
CVE-2026-676217.219.8FlowiseAIFlowiseCWE-862Flowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints
CVE-2026-190665.319.8SourceCodesterOnline Examination & Learning Management SystemCWE-285SourceCodester Online Examination & Learning Management System view_students.…
CVE-2026-191657.519.7GoogleChromeCWE-416Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed…
CVE-2026-666956.519.5BoldGridW3 Total CacheCWE-35WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability
CVE-2026-105247.519.3UnknownCoCartCWE-472CoCart < 4.9.0 - Unauthenticated Arbitrary Price Manipulation
CVE-2026-666629.819.0Shabti KaplanFrontend Admin by DynamiAppsCWE-266WordPress Frontend Admin by DynamiApps plugin <= 3.29.10 - Privilege Escalati…
CVE-2026-191567.518.8GoogleChromeCWE-122Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed…
CVE-2026-51349.818.5Loca Software Informatics Technology Ltd. Co.CMSCWE-89SQLi in Loca Software's CMS
CVE-2026-636879.118.5Apache Software FoundationApache CXFCWE-345Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce para…
CVE-2026-182764.318.5ScriptaeScriptoriumCWE-862Missing Authorization in eScriptorium
CVE-2026-190215.518.2SourceCodesterComputer Repair Shop Management SystemCWE-74SourceCodester Computer Repair Shop Management System Master.php delete_produ…
CVE-2026-127139.118.1UnknownWPCargo Track & TraceCWE-89WPCargo Track & Trace < 8.0.4 - Unauthenticated SQL Injection via wpcargo_tra…
CVE-2026-655839.118.1Apache Software FoundationApache CXFCWE-345Apache CXF: Self-issued ID token claims validation skipped
CVE-2026-655428.818.1Rajat VarlaniSuper SocializerCWE-288WordPress Super Socializer plugin <= 7.14.5 - Broken Authentication vulnerabi…
CVE-2026-166207.517.7UnknownWPC Name Your Price for WooCommerceCWE-472WPC Name Your Price for WooCommerce < 2.2.5 - Unauthenticated Price Manipulat…
CVE-2026-163158.117.7OMICRON electronics GmbHOMICRON StationGuardCWE-208Authentication and authorization bypass via cryptographic timing side-channel…
CVE-2026-637258.617.5nuxsminsysPassCWE-78sysPass FileBackupService Authenticated OS Command Injection via Backup Path
CVE-2026-131537.517.4UnknownGutenberg Essential BlocksCWE-200Essential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure …
CVE-2026-131547.517.4UnknownGutenberg Essential BlocksCWE-200Essential Blocks < 6.4.0 - Unauthenticated Non-Public Custom Post Type Conten…
CVE-2026-180507.517.4UnknownEvents ManagerCWE-200Events Manager < 7.4 - Unauthenticated Pending Upload Disclosure via events-m…
CVE-2024-65416.817.4WSO2WSO2 Micro IntegratorCWE-20Information Disclosure and Integrity Violation via Improper Message Context H…
CVE-2026-190655.317.4SourceCodesterOnline Examination & Learning Management SystemCWE-284SourceCodester Online Examination & Learning Management System upload_files.p…
CVE-2026-687472.317.1rrrenehtml_sanitize_exCWE-74CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input
CVE-2026-191101.917.1n/aDataGearCWE-79DataGear Chart Name HtmlTplDashboardWidgetHtmlRenderer.java HtmlTplDashboardW…
CVE-2026-58567.117.0Contiki-NGContiki-NGCWE-125Contiki-NG DNS/mDNS Resolver Out-of-Bounds Read via Unchecked skip_name Trave…
CVE-2026-133425.316.9UnknownSecurity OptimizerCWE-693Security Optimizer – The All-In-One Protection Plugin < 1.6.5 - Login Access …
CVE-2026-119835.316.7spacetimeAd Inserter – Ad Manager & AdSense AdsCWE-862Ad Inserter <= 2.8.16 - Missing Authorization to Block Visibility Bypass via …
CVE-2026-646644.316.7statamiccmsCWE-200Statamic: Missing authorization on Control Panel endpoint allows disclosure o…
CVE-2026-184006.416.7metasliderSlider, Gallery, and Carousel by MetaSlider – Image Slider, Video SliderCWE-79Slider, Gallery, and Carousel by MetaSlider <= 3.111.0 - Authenticated (Autho…
CVE-2026-480785.316.6open-receptionappointment-booking-softwareCWE-200OpenReception's schedule endpoint discloses isPublic=false channels and slot …
CVE-2026-190672.116.6itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System treatment.php sql injection
CVE-2026-190682.116.6itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System treatmentdetail.php sql injection
CVE-2026-628578.816.5fedify-devfedifyCWE-918Fedify: Server-Side Request Forgery in getNodeInfo() Allows Access to Interna…
CVE-2026-169546.516.5UnknownAI EngineCWE-200AI Engine < 3.6.4 - Editor+ Sensitive Information Disclosure of API Key and B…
CVE-2026-676228.516.2FlowiseAIFlowiseCWE-639Flowise 3.1.4 IDOR in OpenAI Assistants Integration
CVE-2026-714466.916.3ail-projectail-frameworkCWE-79Stored Cross-Site Scripting in AIL Framework Domain Screenshot View
CVE-2026-281407.516.0jetmonstersJetFormBuilderCWE-862WordPress JetFormBuilder plugin <= 3.6.4.1 - Broken Access Control vulnerability
CVE-2026-189962.115.9cosmicstack-labsmercury-agentCWE-266cosmicstack-labs mercury-agent run_command permissions.ts PermissionManager.c…
CVE-2026-185107.215.7cozmoslabsTranslatePress – Translate Multilingual sites with AI TranslationCWE-79TranslatePress <= 3.2.6 - Unauthenticated Stored Cross-Site Scripting via Com…
CVE-2026-480766.515.6open-receptionappointment-booking-softwareCWE-863OpenReception's bootstrap booking flow allows unauthenticated booking on isPu…
CVE-2026-664526.515.6IT-Recht KanzleiLegal Text Connector of the IT-Recht KanzleiCWE-862WordPress Legal Text Connector of the IT-Recht Kanzlei plugin <= 1.0.13 - Bro…
CVE-2026-34308.615.5UnknownCreative MailCWE-89Creative Mail 1.6.5 - 1.6.9 - Unauthenticated SQLi
CVE-2026-636378.615.4dgraph-iodgraphCWE-943Dgraph: DQL Injection via unvalidated regexp filter argument in GraphQL query…
CVE-2024-68327.515.4WSO2WSO2 Enterprise IntegratorCWE-693Account Lockout Failure via Secondary User Store Inaccessibility in Multiple …
CVE-2026-547175.415.4silverstripesilverstripe-cmsCWE-79Silverstripe: XSS in breadcrumbs in page list view
CVE-2026-281695.315.4YITHEMESYITH WooCommerce Zoom MagnifierCWE-497WordPress YITH WooCommerce Zoom Magnifier plugin <= 2.52.0 - Sensitive Data E…
CVE-2026-666835.315.4WP ZoneCustom CSS and JavaScriptCWE-201WordPress Custom CSS and JavaScript plugin <= 2.0.16 - Sensitive Data Exposur…
CVE-2026-666845.315.4Akshay MenariyaExport Import MenusCWE-201WordPress Export Import Menus plugin <= 1.9.2 - Sensitive Data Exposure vulne…
CVE-2026-714345.315.4statamiccmsCWE-434Statamic: Missing file upload validation on frontend forms allows uploading d…
CVE-2025-123175.015.4WSO2WSO2 Enterprise IntegratorCWE-613Improper Token Revocation via SOAP Services in Multiple WSO2 Products Allows …
CVE-2026-645868.815.2LinuxLinuxwifi: brcmfmac: drain bus_reset work on device removal
CVE-2026-324695.315.2WPKubeCAPTCHA 4WPCWE-290WordPress CAPTCHA 4WP plugin <= 7.6.0 - Captcha Bypass vulnerability
CVE-2026-655025.315.2bdthemesElement Pack Elementor AddonsCWE-290WordPress Element Pack Elementor Addons plugin <= 8.7.13 - Captcha Bypass vul…
CVE-2026-182777.114.9ScriptaeScriptoriumCWE-862Missing Authorization in eScriptorium
CVE-2026-182756.515.0ScriptaeScriptoriumCWE-639Authorization Bypass Through User-Controlled Key in eScriptorium
CVE-2026-126059.614.8Eclipse FoundationEclipse GlassFishCWE-918In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServ…
CVE-2026-655469.314.9QODEQode ToursCWE-89WordPress Qode Tours plugin <= 3.1.3.1 - SQL Injection vulnerability
CVE-2026-664479.314.9nickbossWordPress File UploadCWE-89WordPress WordPress File Upload plugin <= 5.1.7 - SQL Injection vulnerability
CVE-2026-151495.314.8UnknownWP Hotel BookingCWE-20WP Hotel Booking < 2.3.3 - Unauthenticated Payment Bypass via Price Manipulation
CVE-2026-160675.314.8UnknownEvent Booking Manager for WooCommerce (Pro)CWE-472Event Booking Manager for WooCommerce (Pro) < 5.0.3 - Unauthenticated Payment…
CVE-2026-166197.514.6UnknownminiOrange 2FACWE-307miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts
CVE-2026-143145.314.7UnknownPeproDev WooCommerce Receipt UploaderCWE-200PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Image Attach…
CVE-2026-655708.114.5Hamid AliniaLogin with phone numberCWE-290WordPress Login with phone number plugin <= 1.8.70 - Bypass vulnerability vul…
CVE-2026-714476.914.5ail-projectail-frameworkCWE-79Stored Cross-Site Scripting in Chat and Forum Translation Controls in ail-fra…
CVE-2026-655517.514.3SoflyyBreakdanceCWE-862WordPress Breakdance plugin < 2.7 - Broken Access Control vulnerability
CVE-2026-664516.514.3ArrayticsWP Event SOlutionCWE-288WordPress WP Event SOlution plugin <= 4.1.9 - Broken Authentication vulnerabi…
CVE-2026-160656.514.1UnknownWelcart e-CommerceCWE-89Welcart e-Commerce < 2.11.32 - Editor+ SQL Injection via CSV Import
CVE-2026-142252.714.0UnknownEasy AppointmentsCWE-20Easy Appointments < 3.12.28 - Contributor+ Shortcode Allowlist Bypass
CVE-2026-281805.313.7Mercado PagoMercado Pago payments for WooCommerceCWE-639WordPress Mercado Pago payments for WooCommerce plugin <= 8.9.0 - Insecure Di…
CVE-2026-325485.313.7SureCartSureCartCWE-862WordPress SureCart plugin <= 4.6.2 - Broken Access Control vulnerability
CVE-2026-663704.813.8rrrenehtml_sanitize_exCWE-601html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attr…
CVE-2026-706378.213.7hfiref0xLightFTPCWE-820LightFTP 2.4 Data Race Condition via ABOR Command in ftpserv.c
CVE-2026-68480await13.6LinuxLinuxx86/bugs: Make Safe-RET robust against interrupt injection
CVE-2026-714335.313.4langchain-ailanggraphCWE-200LangGraph: Namespace prefix matching crosses segment boundaries in Postgres a…
CVE-2026-543010.013.1WSO2WSO2 Universal GatewayCWE-347Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Al…
CVE-2026-667088.212.9BoldGridTotal UpkeepCWE-862WordPress Total Upkeep plugin <= 1.17.2 - Broken Access Control vulnerability
CVE-2026-183598.512.8ScriptaeScriptoriumCWE-918Server-Side Request Forgery (SSRF) in eScriptorium
CVE-2026-655417.312.6solutionedStaff TrainingCWE-862WordPress Staff Training plugin <= 1.0.7 - Broken Access Control vulnerability
CVE-2025-156742.712.5UnknownPasssterCWE-863Content Protector (Passster) < 4.3.7 - Contributor+ Protected Content Disclos…
CVE-2026-667127.512.3wp.insiderSimple MembershipCWE-862WordPress Simple Membership plugin <= 4.7.8 - Broken Access Control vulnerabi…
CVE-2026-189932.112.1NousResearchhermes-agentCWE-266NousResearch hermes-agent Memory Toolset model_tools.py access control
CVE-2026-666924.311.8ColissimoColissimo Officiel : Méthodes de livraison pour WooCommerceCWE-639WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin …
CVE-2026-619596.511.7Strategy11 TeamBusiness DirectoryCWE-79WordPress Business Directory plugin <= 6.4.24 - Cross Site Scripting (XSS) vu…
CVE-2026-06735.311.5bdthemesElement Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor AddonsCWE-93Element Pack Addons for Elementor <= 8.3.15 - Unauthenticated SMTP Header Inj…
CVE-2026-162905.311.4UnknownProfileGridCWE-862ProfileGrid < 6.0.0.0 - Unauthenticated Group Member List Disclosure via pm_g…
CVE-2026-706328.511.3FFmpegFFmpegCWE-787FFmpeg 4.4 < 9.0 Heap Out-of-Bounds Write in CFHD Decoder via AVI Demuxing
CVE-2026-189762.111.4NousResearchhermes-agentCWE-266NousResearch hermes-agent disabled_toolsets agent_init.py get_tool_definition…
CVE-2026-189922.111.4zhayujieCowAgentCWE-285zhayujie CowAgent Self-Evolution Review Agent executor.py _select_tools autho…
CVE-2026-189972.111.4cosmicstack-labsmercury-agentCWE-285cosmicstack-labs mercury-agent bg agent.ts Agent.handleBgCommand authorization
CVE-2026-189982.111.4cosmicstack-labsmercury-agentCWE-266cosmicstack-labs mercury-agent delegate_task Tool sub-agent.ts SubAgent.run i…
CVE-2026-190052.111.4nanocoaiNanoClawCWE-266nanocoai NanoClaw Child-Agent Creation create-agent.ts handleCreateAgent priv…
CVE-2026-190062.111.4mf-yangopenclaw-cnCWE-285mf-yang openclaw-cn Ggateway Exec Approval Flow bash-tools.exec.ts authorization
CVE-2026-190072.111.4mf-yangopenclaw-cnCWE-266mf-yang openclaw-cn reply-elevated.ts isApprovedElevatedSender privileges man…
CVE-2026-142405.311.0UnknowntourmasterCWE-200Tourmaster < 5.4.9 - Unauthenticated Sensitive Data Disclosure via Order Export
CVE-2025-139094.310.9WSO2WSO2 Identity ServerCWE-20Information Disclosure via Multi-Tenant Authentication Flows in WSO2 Identity…
CVE-2026-667117.110.7Amir HelzerWooCommerce Multilingual & MulticurrencyCWE-79WordPress WooCommerce Multilingual & Multicurrency plugin <= 5.5.6 - Cross Si…
CVE-2026-190591.910.5FoundationAgentsMetaGPTCWE-22FoundationAgents MetaGPT editor.py read path traversal
CVE-2026-436288.510.4ggml-orgllama.cppCWE-191llama.cpp b3978–b9058 Integer Underflow via DRY Sampler
CVE-2026-167347.510.4UnknownStripe Payment Forms by WP Full PayCWE-862Stripe Payment Forms by WP Full Pay < 8.5.2 - Unauthenticated Payment Intent …
CVE-2026-471948.610.3frappefrappeCWE-346Frappe: Host header poisoning can redirect magic login links to an attacker-c…
CVE-2026-714786.110.3thephpleaguecommonmarkCWE-79league/commonmark: AttributesExtension href/src unsafe-link filter bypass via…
CVE-2025-65084.310.2WSO2WSO2 API ManagerCWE-79User Interface Misrepresentation via Swagger UI Try-out Console in WSO2 API M…
CVE-2026-190202.110.2itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System servicetype.php sql injection
CVE-2026-666855.39.8AlexFeatured Video PlusCWE-201WordPress Featured Video Plus plugin <= 2.3.3 - Sensitive Data Exposure vulne…
CVE-2026-143064.39.8UnknownTutor LMSCWE-639Tutor LMS < 3.9.14 - Subscriber+ Paid Course Content Disclosure via Enrollmen…
CVE-2026-666784.39.8Justin KruitAdvanced Custom Fields: Font Awesome FieldCWE-862WordPress Advanced Custom Fields: Font Awesome Field plugin <= 6.1.1 - Broken…
CVE-2026-254036.59.4bdthemesUltimate Store Kit Elementor AddonsCWE-862WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Broken Access…
CVE-2026-148298.29.3UnknownCheckimate — WooCommerce Checkout, Abandoned Cart Recovery & Order BumpsCWE-284Checkimate <= 1.0.13 - Unauthenticated License Deactivation via Hardcoded Secret
CVE-2026-664397.19.1BeRocketAdvanced AJAX Product FiltersCWE-79WordPress Advanced AJAX Product Filters plugin <= 3.2.0.3 - Cross Site Script…
CVE-2026-664407.19.1XplodedThemesWPIDE – File Manager & Code EditorCWE-79WordPress WPIDE – File Manager & Code Editor plugin <= 3.5.7 - Cross Site Scr…
CVE-2026-664577.19.1@msykesEvents ManagerCWE-79WordPress Events Manager plugin <= 7.4.1 - Cross Site Scripting (XSS) vulnera…
CVE-2026-666637.19.1Passionate Programmer PeterWP Data AccessCWE-79WordPress WP Data Access plugin <= 5.5.79 - Cross Site Scripting (XSS) vulner…
CVE-2026-666647.19.1SEO SquirrlySEO Plugin by Squirrly SEOCWE-79WordPress SEO plugin by Squirrly SEO plugin <= 14.2.0 - Cross Site Scripting …
CVE-2026-714356.19.1statamiccmsCWE-79Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Te…
CVE-2025-150287.29.0wpwaxFormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & MoreCWE-79FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, P…
CVE-2026-714974.79.0jhyjsoupCWE-79jsoup: Cleaner may expose markup with custom raw-text elements
CVE-2026-152564.88.7UnknownNinja FormsCWE-74Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Que…
CVE-2025-147793.88.7WSO2WSO2 Identity ServerCWE-281Improper Access Control via Secret Type Management API in WSO2 Identity Server
CVE-2026-190581.98.6FoundationAgentsMetaGPTCWE-74FoundationAgents MetaGPT data_interpreter.py DataInterpreter code injection
CVE-2026-190601.98.7FoundationAgentsMetaGPTCWE-74FoundationAgents MetaGPT code injection
CVE-2026-185978.58.3Foxit Software Inc.Foxit PDF Services APICWE-918Blind SSRF on Foxit PDF Services API
CVE-2026-655177.18.3Scott PatersonEasy PayPal Buy Now ButtonCWE-79WordPress Easy PayPal Buy Now Button plugin <= 2.0.4 - Cross Site Scripting (…
CVE-2026-666995.38.3Dokan, Inc.DokanCWE-862WordPress Dokan plugin <= 5.0.10 - Broken Access Control vulnerability
CVE-2026-667015.38.3CozmoslabsProfile BuilderCWE-862WordPress Profile Builder plugin <= 3.16.5 - Broken Access Control vulnerability
CVE-2026-145475.38.0UnknownEstatik Real Estate PluginCWE-287Estatik Real Estate Plugin < 4.3.3 - Unauthenticated Arbitrary-Recipient Mail…
CVE-2026-190616.38.0InstaInstaKNXServiceAppCWE-345Insta InstaKNXServiceApp Firmware Update CreateWebClientAndDownloadFileList d…
CVE-2026-280827.17.8Crocoblock. Jetimpex Inc.JetEngineCWE-79WordPress JetEngine plugin <= 3.8.13.1 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-281417.17.8Syed BalkhiNextGEN GalleryCWE-79WordPress NextGEN Gallery plugin <= 4.2.3 - Cross Site Scripting (XSS) vulner…
CVE-2026-281437.17.8WPMU DEVForminatorCWE-79WordPress Forminator plugin <= 1.56.0 - Cross Site Scripting (XSS) vulnerability
CVE-2026-281777.17.8Daniel IserPopup MakerCWE-79WordPress Popup Maker plugin <= 1.23.0 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-619617.17.8WPDeveloperEmbedPressCWE-79WordPress EmbedPress plugin <= 4.5.6 - Cross Site Scripting (XSS) vulnerability
CVE-2026-619637.17.8David LingrenMedia LIbrary AssistantCWE-79WordPress Media LIbrary Assistant plugin <= 3.38 - Cross Site Scripting (XSS)…
CVE-2026-619647.17.8WPManageNinjaNinja TablesCWE-79WordPress Ninja Tables plugin <= 5.2.9 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-619827.17.8jp-secureSiteGuard WP PluginCWE-79WordPress SiteGuard WP Plugin plugin <= 1.8.6 - Cross Site Scripting (XSS) vu…
CVE-2026-655097.17.8wpDataTableswpDataTablesCWE-79WordPress wpDataTables plugin <= 7.5.1 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-655137.17.8NSquaredSimply Schedule AppointmentsCWE-79WordPress Simply Schedule Appointments plugin <= 1.6.12.10 - Cross Site Scrip…
CVE-2026-655157.17.8AffiliateWPAffiliateWPCWE-79WordPress AffiliateWP plugin <= 2.35.0 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-655447.17.8Rajat VarlaniSuper SocializerCWE-79WordPress Super Socializer plugin <= 7.14.5 - Cross Site Scripting (XSS) vuln…
CVE-2026-655457.17.8Jordy MeowAI EngineCWE-79WordPress AI Engine plugin <= 3.6.8 - Cross Site Scripting (XSS) vulnerability
CVE-2026-655607.17.8Property HiveHouzez Property FeedCWE-79WordPress Houzez Property Feed plugin <= 2.5.48 - Cross Site Scripting (XSS) …
CVE-2026-655657.17.8Ays ProSurvey MakerCWE-79WordPress Survey Maker plugin <= 5.2.3.3 - Cross Site Scripting (XSS) vulnera…
CVE-2026-455724.87.9decidimdecidimCWE-94Decidim: HTML content blocks allow stored script execution
CVE-2026-125847.57.7UnknownPayment Gateway for Redsys & WooCommerce LitePayment Gateway for Redsys & WooCommerce Lite < 7.0.2 - Unauthenticated Payme…
CVE-2025-118504.37.6WSO2WSO2 Identity ServerCWE-639Improper Implicit Association via User Store Initialization in WSO2 Identity …
CVE-2026-666964.37.4NexcessGutenberg Blocks by Kadence BlocksCWE-201WordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.7.8 - Sensitive Data…
CVE-2026-78677.87.3Red HatRed Hat Enterprise Linux 10CWE-863Udisks2: udisks2: local privilege escalation via as-user option spoofing
CVE-2024-103025.87.2WSO2WSO2 API Control PlaneCWE-20Improper Input Validation via Signup Process in Multiple WSO2 Products Enable…
CVE-2026-281795.96.9Damian GóraFiboSearchCWE-79WordPress FiboSearch plugin <= 1.33.0 - Cross Site Scripting (XSS) vulnerability
CVE-2025-137363.76.8WSO2WSO2 Identity Server as Key ManagerCWE-203Username Enumeration via Login Interface in Multiple WSO2 Products Allows Use…
CVE-2026-715554.16.5THM-HealthPILOSCWE-1022PILOS: Reverse tabnabbing in room description
CVE-2026-714382.46.4mermaid-jsmermaidCWE-1321Mermaid configuration APIs allow prototype pollution
CVE-2026-64591await6.1LinuxLinuxiommu/vt-d: Avoid WARNING in sva unbind path
CVE-2026-64593await6.1LinuxLinuxbtrfs: do not trim a device which is not writeable
CVE-2026-64594await6.1LinuxLinuxusb: gadget: f_fs: initialize reset_work at allocation time
CVE-2026-64602await6.1LinuxLinuxiio: adc: spear: Initialize completion before requesting IRQ
CVE-2026-64604await6.1LinuxLinuxKVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode
CVE-2026-115886.15.9UnknownEONSR AEO AgentCWE-79EONSR AEO Agent <= 3.7.9 - Unauthenticated Stored XSS via Scheduled Post Crea…
CVE-2026-281786.55.8codesupplycoPowerkitCWE-79WordPress Powerkit plugin <= 3.1.0 - Cross Site Scripting (XSS) vulnerability
CVE-2026-105997.55.7UnknownIntegrate PhonePe with WooCommerceCWE-345Integrate PhonePe with WooCommerce <= 1.2.1 - Unauthenticated Payment Bypass …
CVE-2026-706407.35.6ggml-orgllama.cppCWE-476llama.cpp b1886–b7445 Race Condition Use-After-Free via llama-android.cpp
CVE-2025-92664.35.5themegrillAccelerateCWE-862Accelerate <= 1.5.3 - Missing Authorization to Authenticated (Subscriber+) Th…

Results continue: ranks 401–482.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-06 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.