boxscore/security
Thursday, August 6, 2026 · all times UTC← 2026-08-05 · archive · 2026-08-07 →

Edition of August 6, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–482 of 482
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-51586.45.3wpxpoPost Grid Gutenberg Blocks – PostXCWE-79PostX <= 5.0.13 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…
CVE-2026-53916.45.3latepointAppointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPressCWE-79LatePoint <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting…
CVE-2026-185016.45.3stiofansislandUsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WPCWE-79UsersWP <= 1.2.69 - Authenticated (Subscriber+) Stored Cross-Site Scripting v…
CVE-2026-125015.35.2UnknownWP Travel EngineCWE-345WP Travel Engine < 6.8.2 - Unauthenticated Payment Bypass via Missing PayPal …
CVE-2026-149365.35.2UnknownSimple MembershipCWE-345Simple Membership < 4.7.7 - Unauthenticated Payment Bypass via Missing PayPal…
CVE-2026-714985.15.2uhopnode-re2CWE-125node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending …
CVE-2026-64589await5.3LinuxLinuxi2c: core: fix NULL-deref on adapter registration failure
CVE-2026-64590await5.3LinuxLinuxdma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning
CVE-2026-64592await5.3LinuxLinuxriscv: mm: Unconditionally sfence.vma for spurious fault
CVE-2026-64603await5.3LinuxLinuxplatform/x86: intel-hid: Protect ACPI notify handler against recursion
CVE-2026-666907.15.2NexcessGiveWPCWE-79WordPress GiveWP plugin <= 4.16.5 - Cross Site Scripting (XSS) vulnerability
CVE-2026-666947.15.2Thrive Themes CouponThrive ArchitectCWE-79WordPress Thrive Architect plugin <= 10.9.3.1 - Cross Site Scripting (XSS) vu…
CVE-2026-667027.15.2Rank Math SEORank Math SEOCWE-79WordPress Rank Math SEO plugin <= 1.0.274.1 - Cross Site Scripting (XSS) vuln…
CVE-2026-667077.15.2FacebookFacebook for WooCommerceCWE-79WordPress Facebook for WooCommerce plugin <= 3.7.5 - Cross Site Scripting (XS…
CVE-2026-64596await5.1LinuxLinuxlibfs: set SB_I_NOEXEC and SB_I_NODEV by default in init_pseudo()
CVE-2026-418614.24.9CloudFoundry FoundationBOSHCWE-22Arbitrary Root File Write via Path Traversal in BOSH agent
CVE-2026-163161.34.9OMICRON electronics GmbHOMICRON StationGuardCWE-20Malformed IEC 61850 Sampled Values frames cause partial denial of service in …
CVE-2026-706288.54.7FFmpegFFmpegCWE-190FFmpeg 0.5 < 9.0 DVB Subtitle Parser Heap Buffer Overflow via WTV File
CVE-2025-156786.14.6UnknownNexter BlocksCWE-79Nexter Blocks < 5.0.2 - Author+ Stored XSS via SVG Upload
CVE-2026-559788.44.5SecureAgeCatchPulseCWE-284Improper access control vulnerability in CatchPulse
CVE-2026-667065.94.6Mark JaquithSubscribe to CommentsCWE-79WordPress Subscribe to Comments plugin <= 2.3.1 - Cross Site Scripting (XSS) …
CVE-2026-667057.14.4FacebookFacebook for WordPressCWE-79WordPress Facebook for WordPress plugin <= 5.2.1 - Cross Site Scripting (XSS)…
CVE-2026-64595await4.3LinuxLinuxHID: hid-lenovo-go: cancel cfg_setup work in hid_go_cfg_remove()
CVE-2026-189678.14.2Red HatRed Hat Build of KeycloakCWE-294Keycloak-services: keycloak-services: saml onetimeuse assertion replay in idp…
CVE-2026-480818.14.2open-receptionappointment-booking-softwareCWE-79OpenReception vulnerable to stored click-triggered XSS via javascript: tenant…
CVE-2026-559805.54.1SecureAgeCatchPulseCWE-121Denial-of-service vulnerability in CatchPulse
CVE-2026-12897.83.9AutodeskRevitCWE-416PDF File Parsing Use-After-Free Vulnerability in Autodesk Revit
CVE-2026-118037.83.9AutodeskRevitCWE-125PDF File Parsing Out-of-Bounds Read Vulnerability in Autodesk Revit
CVE-2026-113615.94.0UnknownFormidable FormsCWE-345Formidable Forms < 6.32.1 - Unauthenticated Payment Bypass via PayPal APPROVA…
CVE-2026-190541.93.8Lspace-iolspace-serverCWE-22Lspace-io lspace-server Repositories File API repository.ts deleteFile path t…
CVE-2026-649939.13.7DellRVToolsCWE-295Dell RVTools versions prior to 4.8.1, contains an improper certificate valida…
CVE-2026-436278.53.8ggml-orgllama.cppCWE-190llama.cpp b1283–b9058 Integer Overflow in llama_batch_init() Function
CVE-2026-666886.53.7Brainstorm ForceUltimate Addons for ElementorCWE-79WordPress Ultimate Addons for Elementor plugin <= 1.45.2 - Cross Site Scripti…
CVE-2026-667036.53.7properfractionMailOptinCWE-79WordPress MailOptin plugin <= 1.2.78.0 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-137035.43.6UnknownSEO Redirection PluginCWE-284SEO Redirection Plugin – 301 Redirect Manager < 9.19 - Subscriber+ Redirect R…
CVE-2026-190464.83.6NocteDefensorLudusMCPCWE-22NocteDefensor LudusMCP ludus_environment_guides_search ludusEnvironmentGuides…
CVE-2026-706316.83.4FFmpegFFmpegCWE-908FFmpeg 0.5 < 9.0 Uninitialized Heap Memory Read in TIFF Decoder
CVE-2026-436228.53.4ggml-orgllama.cppCWE-762llama.cpp b1886–b7445 Double Free via llama-android.cpp
CVE-2026-706388.53.4ggml-orgllama.cppCWE-190llama.cpp b1886–b7445 Integer Overflow via new_1batch() in llama-android.cpp
CVE-2026-74067.83.4AutodeskRevitCWE-822BMP File Parsing Untrusted Pointer Dereference in certain Autodesk products
CVE-2026-81665.43.3Logo Software Industry and Trade Inc.e-Logo Purchasing PortalCWE-79Stored XSS in Logo Software's e-Logo Purchasing Portal
CVE-2026-165375.43.3UnknownSlick SliderCWE-79Slick Slider < 0.5.3 - Contributor+ Stored XSS via Gallery Shortcode
CVE-2026-183955.43.3UnknownChild Pages CardCWE-79Child Pages Card < 1.09 - Contributor+ Stored XSS via Shortcode Attributes
CVE-2026-559795.23.3SecureAgeCatchPulseCWE-284Improper access control check in CatchPulse's named pipe communication interface
CVE-2026-706296.83.2FFmpegFFmpegCWE-908FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in RSCC Decoder
CVE-2026-706306.83.2FFmpegFFmpegCWE-908FFmpeg 3.0 < 9.0 Uninitialized Heap Memory Read in Screenpresso Decoder
CVE-2026-713254.83.2traefiktraefikCWE-653Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikServi…
CVE-2026-183679.33.2SophosSophos Endpoint for macOSCWE-285A privilege escalation vulnerability allows local users to execute arbitrary …
CVE-2026-83257.83.2AutodeskRevitCWE-787PDF File Parsing Out-of-Bounds Write Vulnerability in Autodesk Revit
CVE-2026-706396.83.0ggml-orgllama.cppCWE-476llama.cpp b1886–b7445 Null Pointer Dereference DoS via llama-android.cpp
CVE-2025-126272.43.0WSO2WSO2 Identity ServerCWE-613Improper Refresh Token Implementation via User Impersonation Flow in WSO2 Ide…
CVE-2026-705565.12.9HubzillaHubzillaCWE-352Hubzilla version prior to 11.4 CSRF via OAuth2 /authorize Endpoint App Regist…
CVE-2026-191438.62.8GoogleChromeCWE-20Insufficient validation of untrusted input in WebAPKs in Google Chrome on And…
CVE-2026-129015.92.6UnknownGetPaidCWE-345GetPaid < 2.8.55 - Unauthenticated Worldpay Payment Bypass via Insufficient I…
CVE-2026-151475.32.6UnknownFive Star Restaurant ReservationsCWE-345Five Star Restaurant Reservations < 2.7.23 - Unauthenticated Payment Bypass a…
CVE-2026-151525.32.6UnknownWP Hotel BookingCWE-345WP Hotel Booking < 2.3.2 - Unauthenticated PayPal Payment Bypass
CVE-2026-152085.32.6UnknownRegistrationMagicCWE-345RegistrationMagic < 6.0.9.5 - Unauthenticated Payment Bypass via Amount-Blind…
CVE-2026-646017.82.5LinuxLinuxALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anch…
CVE-2026-666866.52.5Vladimir GaragulyaPlugins Garbage Collector (Database Cleanup)CWE-352WordPress Plugins Garbage Collector (Database Cleanup) plugin <= 0.14 - Cross…
CVE-2026-667328.32.4Eukaryotsonic3airCWE-346Sonic 3 A.I.R. Missing Source Address Validation in ConnectionManager
CVE-2026-645877.02.3LinuxLinuxnet: ethernet: arc: emac: quiesce interrupts before requesting IRQ
CVE-2026-142046.52.3UnknownGoogle AuthenticatorCWE-352Google Authenticator < 0.56 - 2FA Secret Overwrite via CSRF
CVE-2026-143135.32.3UnknownPeproDev WooCommerce Receipt UploaderCWE-352PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Order Receip…
CVE-2026-645857.82.2LinuxLinuxcan: esd_usb: kill anchored URBs before freeing netdevs
CVE-2026-191081.92.2MZ Automationlibiec61850CWE-119MZ Automation libiec61850 URCB Revalidation reporting.c deleteDataSetValuesSh…
CVE-2024-89954.92.1WSO2WSO2 API ManagerCWE-613Authorization Code issued for Deleted User reuse in Multiple WSO2 Products Al…
CVE-2026-645887.82.0LinuxLinuxfuse-uring: fix data races on ring->ready
CVE-2026-645997.81.9LinuxLinuxcrypto: amlogic - avoid double cleanup in meson_crypto_probe()
CVE-2026-646523.32.0clicliCWE-201GitHub CLI: Partial token disclosure in `gh auth status` output
CVE-2026-645837.81.9LinuxLinuxusb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown
CVE-2026-645847.81.9LinuxLinuxusb: gadget: f_midi: cancel pending IN work before freeing the midi object
CVE-2026-74055.51.8AutodeskRevitCWE-125TIF File Parsing Out-of-Bounds Read in certain Autodesk products
CVE-2026-666814.31.7Jeff FarthingTheme My LoginCWE-352WordPress theme My Login plugin <= 7.1.14 - Cross Site Request Forgery (CSRF)…
CVE-2026-06374.41.7WSO2WSO2 API ManagerCWE-532Sensitive Information Disclosure via Event Publisher Logging in Multiple WSO2…
CVE-2026-714306.21.5uhopnode-re2CWE-617node-re2: String.prototype.replace(re2, template) aborts the Node process (un…
CVE-2026-152464.31.4UnknownRealHomes MembershipsCWE-345RealHomes Memberships < 3.1.0 - Subscriber+ Membership Payment Bypass
CVE-2026-189155.01.0TÜBİTAK BİLGEM Software Technologies Research Instituteeta-otp-lockCWE-214Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLG…
CVE-2026-281727.10.9Data443 Risk Mitigation, Inc.Tracking Code ManagerCWE-352WordPress Tracking Code Manager plugin <= 2.6.0 - CSRF to Stored XSS vulnerab…
CVE-2025-133945.40.9WSO2WSO2 Identity ServerCWE-352Cross-Site Request Forgery via Ajax Processor Endpoints in Multiple WSO2 Prod…
CVE-2026-191397.40.6GoogleChromeCWE-362Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.10…
CVE-2026-155993.30.5TÜBİTAK BİLGEM Software Technologies Research Institutepardus-domain-joinerCWE-283Arbitrary Process Termination in TÜBİTAK BİLGEM's pardus-domain-joiner
CVE-2026-189095.60.3ELAN Microelectronics Corp.ELAN Smart-PadCWE-121A stack-based buffer overflow vulnerability exists in ELAN Microelectronics C…