Edition of August 6, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-5158 | 6.4 | 5.3 | wpxpo | Post Grid Gutenberg Blocks – PostX | CWE-79 | PostX <= 5.0.13 - Authenticated (Contributor+) Stored Cross-Site Scripting vi… |
| CVE-2026-5391 | 6.4 | 5.3 | latepoint | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress | CWE-79 | LatePoint <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting… |
| CVE-2026-18501 | 6.4 | 5.3 | stiofansisland | UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP | CWE-79 | UsersWP <= 1.2.69 - Authenticated (Subscriber+) Stored Cross-Site Scripting v… |
| CVE-2026-12501 | 5.3 | 5.2 | Unknown | WP Travel Engine | CWE-345 | WP Travel Engine < 6.8.2 - Unauthenticated Payment Bypass via Missing PayPal … |
| CVE-2026-14936 | 5.3 | 5.2 | Unknown | Simple Membership | CWE-345 | Simple Membership < 4.7.7 - Unauthenticated Payment Bypass via Missing PayPal… |
| CVE-2026-71498 | 5.1 | 5.2 | uhop | node-re2 | CWE-125 | node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending … |
| CVE-2026-64589 | await | 5.3 | Linux | Linux | — | i2c: core: fix NULL-deref on adapter registration failure |
| CVE-2026-64590 | await | 5.3 | Linux | Linux | — | dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning |
| CVE-2026-64592 | await | 5.3 | Linux | Linux | — | riscv: mm: Unconditionally sfence.vma for spurious fault |
| CVE-2026-64603 | await | 5.3 | Linux | Linux | — | platform/x86: intel-hid: Protect ACPI notify handler against recursion |
| CVE-2026-66690 | 7.1 | 5.2 | Nexcess | GiveWP | CWE-79 | WordPress GiveWP plugin <= 4.16.5 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-66694 | 7.1 | 5.2 | Thrive Themes Coupon | Thrive Architect | CWE-79 | WordPress Thrive Architect plugin <= 10.9.3.1 - Cross Site Scripting (XSS) vu… |
| CVE-2026-66702 | 7.1 | 5.2 | Rank Math SEO | Rank Math SEO | CWE-79 | WordPress Rank Math SEO plugin <= 1.0.274.1 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-66707 | 7.1 | 5.2 | Facebook for WooCommerce | CWE-79 | WordPress Facebook for WooCommerce plugin <= 3.7.5 - Cross Site Scripting (XS… | |
| CVE-2026-64596 | await | 5.1 | Linux | Linux | — | libfs: set SB_I_NOEXEC and SB_I_NODEV by default in init_pseudo() |
| CVE-2026-41861 | 4.2 | 4.9 | CloudFoundry Foundation | BOSH | CWE-22 | Arbitrary Root File Write via Path Traversal in BOSH agent |
| CVE-2026-16316 | 1.3 | 4.9 | OMICRON electronics GmbH | OMICRON StationGuard | CWE-20 | Malformed IEC 61850 Sampled Values frames cause partial denial of service in … |
| CVE-2026-70628 | 8.5 | 4.7 | FFmpeg | FFmpeg | CWE-190 | FFmpeg 0.5 < 9.0 DVB Subtitle Parser Heap Buffer Overflow via WTV File |
| CVE-2025-15678 | 6.1 | 4.6 | Unknown | Nexter Blocks | CWE-79 | Nexter Blocks < 5.0.2 - Author+ Stored XSS via SVG Upload |
| CVE-2026-55978 | 8.4 | 4.5 | SecureAge | CatchPulse | CWE-284 | Improper access control vulnerability in CatchPulse |
| CVE-2026-66706 | 5.9 | 4.6 | Mark Jaquith | Subscribe to Comments | CWE-79 | WordPress Subscribe to Comments plugin <= 2.3.1 - Cross Site Scripting (XSS) … |
| CVE-2026-66705 | 7.1 | 4.4 | Facebook for WordPress | CWE-79 | WordPress Facebook for WordPress plugin <= 5.2.1 - Cross Site Scripting (XSS)… | |
| CVE-2026-64595 | await | 4.3 | Linux | Linux | — | HID: hid-lenovo-go: cancel cfg_setup work in hid_go_cfg_remove() |
| CVE-2026-18967 | 8.1 | 4.2 | Red Hat | Red Hat Build of Keycloak | CWE-294 | Keycloak-services: keycloak-services: saml onetimeuse assertion replay in idp… |
| CVE-2026-48081 | 8.1 | 4.2 | open-reception | appointment-booking-software | CWE-79 | OpenReception vulnerable to stored click-triggered XSS via javascript: tenant… |
| CVE-2026-55980 | 5.5 | 4.1 | SecureAge | CatchPulse | CWE-121 | Denial-of-service vulnerability in CatchPulse |
| CVE-2026-1289 | 7.8 | 3.9 | Autodesk | Revit | CWE-416 | PDF File Parsing Use-After-Free Vulnerability in Autodesk Revit |
| CVE-2026-11803 | 7.8 | 3.9 | Autodesk | Revit | CWE-125 | PDF File Parsing Out-of-Bounds Read Vulnerability in Autodesk Revit |
| CVE-2026-11361 | 5.9 | 4.0 | Unknown | Formidable Forms | CWE-345 | Formidable Forms < 6.32.1 - Unauthenticated Payment Bypass via PayPal APPROVA… |
| CVE-2026-19054 | 1.9 | 3.8 | Lspace-io | lspace-server | CWE-22 | Lspace-io lspace-server Repositories File API repository.ts deleteFile path t… |
| CVE-2026-64993 | 9.1 | 3.7 | Dell | RVTools | CWE-295 | Dell RVTools versions prior to 4.8.1, contains an improper certificate valida… |
| CVE-2026-43627 | 8.5 | 3.8 | ggml-org | llama.cpp | CWE-190 | llama.cpp b1283–b9058 Integer Overflow in llama_batch_init() Function |
| CVE-2026-66688 | 6.5 | 3.7 | Brainstorm Force | Ultimate Addons for Elementor | CWE-79 | WordPress Ultimate Addons for Elementor plugin <= 1.45.2 - Cross Site Scripti… |
| CVE-2026-66703 | 6.5 | 3.7 | properfraction | MailOptin | CWE-79 | WordPress MailOptin plugin <= 1.2.78.0 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-13703 | 5.4 | 3.6 | Unknown | SEO Redirection Plugin | CWE-284 | SEO Redirection Plugin – 301 Redirect Manager < 9.19 - Subscriber+ Redirect R… |
| CVE-2026-19046 | 4.8 | 3.6 | NocteDefensor | LudusMCP | CWE-22 | NocteDefensor LudusMCP ludus_environment_guides_search ludusEnvironmentGuides… |
| CVE-2026-70631 | 6.8 | 3.4 | FFmpeg | FFmpeg | CWE-908 | FFmpeg 0.5 < 9.0 Uninitialized Heap Memory Read in TIFF Decoder |
| CVE-2026-43622 | 8.5 | 3.4 | ggml-org | llama.cpp | CWE-762 | llama.cpp b1886–b7445 Double Free via llama-android.cpp |
| CVE-2026-70638 | 8.5 | 3.4 | ggml-org | llama.cpp | CWE-190 | llama.cpp b1886–b7445 Integer Overflow via new_1batch() in llama-android.cpp |
| CVE-2026-7406 | 7.8 | 3.4 | Autodesk | Revit | CWE-822 | BMP File Parsing Untrusted Pointer Dereference in certain Autodesk products |
| CVE-2026-8166 | 5.4 | 3.3 | Logo Software Industry and Trade Inc. | e-Logo Purchasing Portal | CWE-79 | Stored XSS in Logo Software's e-Logo Purchasing Portal |
| CVE-2026-16537 | 5.4 | 3.3 | Unknown | Slick Slider | CWE-79 | Slick Slider < 0.5.3 - Contributor+ Stored XSS via Gallery Shortcode |
| CVE-2026-18395 | 5.4 | 3.3 | Unknown | Child Pages Card | CWE-79 | Child Pages Card < 1.09 - Contributor+ Stored XSS via Shortcode Attributes |
| CVE-2026-55979 | 5.2 | 3.3 | SecureAge | CatchPulse | CWE-284 | Improper access control check in CatchPulse's named pipe communication interface |
| CVE-2026-70629 | 6.8 | 3.2 | FFmpeg | FFmpeg | CWE-908 | FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in RSCC Decoder |
| CVE-2026-70630 | 6.8 | 3.2 | FFmpeg | FFmpeg | CWE-908 | FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in Screenpresso Decoder |
| CVE-2026-71325 | 4.8 | 3.2 | traefik | traefik | CWE-653 | Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikServi… |
| CVE-2026-18367 | 9.3 | 3.2 | Sophos | Sophos Endpoint for macOS | CWE-285 | A privilege escalation vulnerability allows local users to execute arbitrary … |
| CVE-2026-8325 | 7.8 | 3.2 | Autodesk | Revit | CWE-787 | PDF File Parsing Out-of-Bounds Write Vulnerability in Autodesk Revit |
| CVE-2026-70639 | 6.8 | 3.0 | ggml-org | llama.cpp | CWE-476 | llama.cpp b1886–b7445 Null Pointer Dereference DoS via llama-android.cpp |
| CVE-2025-12627 | 2.4 | 3.0 | WSO2 | WSO2 Identity Server | CWE-613 | Improper Refresh Token Implementation via User Impersonation Flow in WSO2 Ide… |
| CVE-2026-70556 | 5.1 | 2.9 | Hubzilla | Hubzilla | CWE-352 | Hubzilla version prior to 11.4 CSRF via OAuth2 /authorize Endpoint App Regist… |
| CVE-2026-19143 | 8.6 | 2.8 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebAPKs in Google Chrome on And… | |
| CVE-2026-12901 | 5.9 | 2.6 | Unknown | GetPaid | CWE-345 | GetPaid < 2.8.55 - Unauthenticated Worldpay Payment Bypass via Insufficient I… |
| CVE-2026-15147 | 5.3 | 2.6 | Unknown | Five Star Restaurant Reservations | CWE-345 | Five Star Restaurant Reservations < 2.7.23 - Unauthenticated Payment Bypass a… |
| CVE-2026-15152 | 5.3 | 2.6 | Unknown | WP Hotel Booking | CWE-345 | WP Hotel Booking < 2.3.2 - Unauthenticated PayPal Payment Bypass |
| CVE-2026-15208 | 5.3 | 2.6 | Unknown | RegistrationMagic | CWE-345 | RegistrationMagic < 6.0.9.5 - Unauthenticated Payment Bypass via Amount-Blind… |
| CVE-2026-64601 | 7.8 | 2.5 | Linux | Linux | — | ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anch… |
| CVE-2026-66686 | 6.5 | 2.5 | Vladimir Garagulya | Plugins Garbage Collector (Database Cleanup) | CWE-352 | WordPress Plugins Garbage Collector (Database Cleanup) plugin <= 0.14 - Cross… |
| CVE-2026-66732 | 8.3 | 2.4 | Eukaryot | sonic3air | CWE-346 | Sonic 3 A.I.R. Missing Source Address Validation in ConnectionManager |
| CVE-2026-64587 | 7.0 | 2.3 | Linux | Linux | — | net: ethernet: arc: emac: quiesce interrupts before requesting IRQ |
| CVE-2026-14204 | 6.5 | 2.3 | Unknown | Google Authenticator | CWE-352 | Google Authenticator < 0.56 - 2FA Secret Overwrite via CSRF |
| CVE-2026-14313 | 5.3 | 2.3 | Unknown | PeproDev WooCommerce Receipt Uploader | CWE-352 | PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Order Receip… |
| CVE-2026-64585 | 7.8 | 2.2 | Linux | Linux | — | can: esd_usb: kill anchored URBs before freeing netdevs |
| CVE-2026-19108 | 1.9 | 2.2 | MZ Automation | libiec61850 | CWE-119 | MZ Automation libiec61850 URCB Revalidation reporting.c deleteDataSetValuesSh… |
| CVE-2024-8995 | 4.9 | 2.1 | WSO2 | WSO2 API Manager | CWE-613 | Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Al… |
| CVE-2026-64588 | 7.8 | 2.0 | Linux | Linux | — | fuse-uring: fix data races on ring->ready |
| CVE-2026-64599 | 7.8 | 1.9 | Linux | Linux | — | crypto: amlogic - avoid double cleanup in meson_crypto_probe() |
| CVE-2026-64652 | 3.3 | 2.0 | cli | cli | CWE-201 | GitHub CLI: Partial token disclosure in `gh auth status` output |
| CVE-2026-64583 | 7.8 | 1.9 | Linux | Linux | — | usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown |
| CVE-2026-64584 | 7.8 | 1.9 | Linux | Linux | — | usb: gadget: f_midi: cancel pending IN work before freeing the midi object |
| CVE-2026-7405 | 5.5 | 1.8 | Autodesk | Revit | CWE-125 | TIF File Parsing Out-of-Bounds Read in certain Autodesk products |
| CVE-2026-66681 | 4.3 | 1.7 | Jeff Farthing | Theme My Login | CWE-352 | WordPress theme My Login plugin <= 7.1.14 - Cross Site Request Forgery (CSRF)… |
| CVE-2026-0637 | 4.4 | 1.7 | WSO2 | WSO2 API Manager | CWE-532 | Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2… |
| CVE-2026-71430 | 6.2 | 1.5 | uhop | node-re2 | CWE-617 | node-re2: String.prototype.replace(re2, template) aborts the Node process (un… |
| CVE-2026-15246 | 4.3 | 1.4 | Unknown | RealHomes Memberships | CWE-345 | RealHomes Memberships < 3.1.0 - Subscriber+ Membership Payment Bypass |
| CVE-2026-18915 | 5.0 | 1.0 | TÜBİTAK BİLGEM Software Technologies Research Institute | eta-otp-lock | CWE-214 | Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLG… |
| CVE-2026-28172 | 7.1 | 0.9 | Data443 Risk Mitigation, Inc. | Tracking Code Manager | CWE-352 | WordPress Tracking Code Manager plugin <= 2.6.0 - CSRF to Stored XSS vulnerab… |
| CVE-2025-13394 | 5.4 | 0.9 | WSO2 | WSO2 Identity Server | CWE-352 | Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Prod… |
| CVE-2026-19139 | 7.4 | 0.6 | Chrome | CWE-362 | Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.10… | |
| CVE-2026-15599 | 3.3 | 0.5 | TÜBİTAK BİLGEM Software Technologies Research Institute | pardus-domain-joiner | CWE-283 | Arbitrary Process Termination in TÜBİTAK BİLGEM's pardus-domain-joiner |
| CVE-2026-18909 | 5.6 | 0.3 | ELAN Microelectronics Corp. | ELAN Smart-Pad | CWE-121 | A stack-based buffer overflow vulnerability exists in ELAN Microelectronics C… |