AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0263 84.3 —
AFFECTED Product Versions Fixed Apache Ranger 0.6 – —
TIMELINE Mar 2 Reserved by CNA Aug 10 Published (CNA: apache)
670 CVEs published August 10, 2026: 84 critical, 252 high, 129 medium, 17 low; 0 in KEV; 6 with a public exploit reference; 188 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 645 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 2718 | 11523 | 1401 | 2563 |
| KEV catalog size | 1670 | |||
654 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 390 | 1975 | 233 | 1285 | 98 | 0 | 27 | 3 | 0.2 | 7.8 | .0017 | +377 |
| microsoft | 33 | 1394 | 120 | 939 | 310 | 8 | 378 | 32 | 2.3 | 7.8 | .0040 | -19 |
| 43 | 455 | 72 | 134 | 228 | 18 | 73 | 5 | 1.1 | 6.5 | .0023 | +43 | |
| red hat | 75 | 297 | 15 | 143 | 121 | 18 | 4 | 0 | 0.0 | 7.1 | .0025 | +61 |
| apple | 1 | 245 | 57 | 67 | 112 | 2 | 93 | 7 | 2.9 | 7.1 | .0028 | +1 |
| suse | 5 | 5 | 1 | 2 | 2 | 0 | 0 | 0 | 0.0 | 7.3 | .0022 | +5 |
| canonical | 0 | 3 | 0 | 2 | 1 | 0 | 0 | 0 | 0.0 | 7.8 | .0013 | 0 |
| android | 0 | 1 | 0 | 1 | 0 | 0 | 16 | 1 | 100.0 | 8.4 | .0171 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 30 | 50 | 9 | 24 | 9 | 0 | 96 | 13 | 26.0 | 7.8 | .0033 | +30 |
| fortinet | 0 | 18 | 2 | 4 | 9 | 0 | 28 | 6 | 33.3 | 6.1 | .0054 | 0 |
| palo alto networks | 0 | 15 | 0 | 1 | 7 | 5 | 14 | 2 | 13.3 | 4.7 | .0028 | -10 |
| vmware | 0 | 12 | 4 | 7 | 0 | 1 | 21 | 0 | 0.0 | 8.7 | .0044 | 0 |
| checkpoint | 1 | 5 | 4 | 1 | 0 | 0 | 3 | 2 | 40.0 | 9.3 | .2062 | +1 |
| f5 | 0 | 5 | 4 | 0 | 0 | 0 | 7 | 1 | 20.0 | 9.2 | .0402 | 0 |
| ivanti | 0 | 5 | 1 | 0 | 0 | 0 | 33 | 5 | 100.0 | 10.0 | .8152 | 0 |
| zyxel | 3 | 4 | 0 | 3 | 1 | 0 | 11 | 0 | 0.0 | 7.2 | .0075 | +3 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 76 | 213 | 42 | 112 | 58 | 1 | 40 | 2 | 0.9 | 7.5 | .0048 | +76 |
| mozilla | 1 | 73 | 42 | 26 | 5 | 0 | 13 | 0 | 0.0 | 9.1 | .0031 | +1 |
| gitlab | 0 | 15 | 0 | 2 | 10 | 1 | 4 | 2 | 13.3 | 4.9 | .0029 | 0 |
| github | 2 | 4 | 0 | 2 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0040 | +2 |
| wordpress | 1 | 4 | 1 | 2 | 1 | 0 | 5 | 2 | 50.0 | 8.8 | .3700 | +1 |
| docker | 0 | 3 | 0 | 1 | 2 | 0 | 1 | 0 | 0.0 | 5.7 | .0015 | 0 |
| drupal | 0 | 1 | 1 | 0 | 0 | 0 | 5 | 1 | 100.0 | 9.8 | .8832 | 0 |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0024 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 1113 | 212 | 539 | 304 | 57 | 40 | 3 | 0.3 | 7.6 | .0031 | 0 |
| ibm | 32 | 140 | 36 | 61 | 42 | 1 | 7 | 1 | 0.7 | 7.5 | .0027 | +32 |
| adobe | 8 | 48 | 16 | 23 | 5 | 0 | 75 | 4 | 8.3 | 8.6 | .0047 | +7 |
| progress | 11 | 34 | 11 | 18 | 5 | 0 | 9 | 1 | 2.9 | 8.1 | .0030 | +11 |
| solarwinds | 0 | 20 | 16 | 1 | 1 | 0 | 11 | 4 | 20.0 | 9.1 | .0050 | 0 |
| veeam | 10 | 12 | 3 | 7 | 2 | 0 | 4 | 0 | 0.0 | 8.6 | .0027 | +10 |
| atlassian | 0 | 3 | 0 | 3 | 0 | 0 | 13 | 0 | 0.0 | 8.0 | .0026 | 0 |
| zohocorp | 0 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 7.1 | .0048 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 15 | 23 | 15 | 0 | 6 | 1 | 26 | 1 | 4.3 | 9.3 | .0209 | +15 |
| hikvision | 0 | 7 | 0 | 4 | 2 | 0 | 2 | 1 | 14.3 | 7.2 | .0025 | 0 |
| bosch | 0 | 3 | 0 | 3 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0028 | 0 |
| schneider electric | 0 | 3 | 1 | 2 | 0 | 0 | 1 | 0 | 0.0 | 8.7 | .0020 | 0 |
| synology | 1 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0.0 | 7.3 | .0013 | +1 |
| honeywell | 0 | 1 | 0 | 0 | 1 | 0 | 0 | 0 | 0.0 | 6.9 | .0031 | 0 |
| mitsubishi electric | 0 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0.0 | 7.1 | .0013 | 0 |
| rockwell automation | 0 | 1 | 1 | 0 | 0 | 0 | 0 | 0 | 0.0 | 9.2 | .0030 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| surrealdb | 0 | 57 | 3 | 26 | 25 | 3 | 0 | 0 | 0.0 | 7.1 | .0025 | 0 |
| netty | 1 | 42 | 6 | 27 | 8 | 1 | 0 | 0 | 0.0 | 7.5 | .0046 | +1 |
| legion of the bouncy castle | 34 | 41 | 5 | 27 | 9 | 0 | 0 | 0 | 0.0 | 8.7 | .0026 | +34 |
| grafana | 0 | 41 | 2 | 14 | 22 | 3 | 0 | 0 | 0.0 | 6.5 | .0033 | -4 |
| open ises | 0 | 37 | 2 | 14 | 21 | 0 | 0 | 0 | 0.0 | 6.9 | .0021 | 0 |
| dokploy | 35 | 35 | 23 | 8 | 3 | 0 | 0 | 0 | 0.0 | 9.9 | .0037 | +35 |
| zephyrproject | 13 | 35 | 0 | 14 | 16 | 5 | 0 | 0 | 0.0 | 6.5 | .0018 | +13 |
| mediatek | 34 | 34 | 0 | 4 | 30 | 0 | 1 | 0 | 0.0 | 6.0 | .0011 | +34 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-8037 | .9931 | 99.9 | 9.8 |
| CVE-2026-63030 | .9560 | 99.9 | 9.8 |
| CVE-2026-39808 | .9121 | 99.8 | — |
| CVE-2026-34486 | .8293 | 99.6 | 7.5 |
| CVE-2026-50522 | .7698 | 99.5 | 9.8 |
| CVE-2026-15410 | .7635 | 99.5 | 7.2 |
| CVE-2026-15409 | .7422 | 99.4 | 10.0 |
| CVE-2026-25089 | .7360 | 99.4 | 9.8 |
| CVE-2026-16232 | .7330 | 99.4 | 9.3 |
| CVE-2026-60137 | .7310 | 99.4 | 5.9 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-15409 | 10.0 | .7422 | KEV |
| CVE-2026-8985 | 10.0 | .0660 | |
| CVE-2026-6516 | 10.0 | .0473 | |
| CVE-2026-47668 | 10.0 | .0434 | |
| CVE-2026-44359 | 10.0 | .0100 | |
| CVE-2025-71389 | 10.0 | .0093 | |
| CVE-2026-48168 | 10.0 | .0091 | |
| CVE-2026-56163 | 10.0 | .0090 | |
| CVE-2026-57106 | 10.0 | .0090 | |
| CVE-2026-16812 | 10.0 | .0088 | KEV |
| Vendor | CVEs |
|---|---|
| oracle | 1109 |
| linux | 1044 |
| microsoft | 638 |
| 446 | |
| red hat | 184 |
| apache | 181 |
| apple | 168 |
| ibm | 132 |
| mozilla | 68 |
| surrealdb | 57 |
| Vendor | KEV |
|---|---|
| microsoft | 32 |
| cisco | 13 |
| apple | 7 |
| fortinet | 6 |
| 5 | |
| ivanti | 5 |
| adobe | 4 |
| langflow | 4 |
| solarwinds | 4 |
| synacor | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 63 |
| PyPI | 5 |
| Go | 3 |
| npm | 3 |
| crates.io | 2 |
| NuGet | 1 |
| Packagist | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4128 | Cisco | 0 |
| CVE-2021-27137 | DD-WRT | 0 |
| CVE-2023-4346 | KNX Association | 0 |
| CVE-2025-68686 | Fortinet | 0 |
| CVE-2026-0770 | Langflow | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-16232 | checkpoint | 0 |
| CVE-2026-16812 | Arista Networks | 0 |
| CVE-2026-18556 | N-able | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1727 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1727 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1727 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1727 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1727 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1727 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1727 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1727 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1727 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1727 |
EXPLOIT PUBLISHED — CVE-2021-34473 (Microsoft Exchange Server 2013 Cumulative Update 23). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2021-34523 (Microsoft Exchange Server 2013 Cumulative Update 23). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2021-34527 (Microsoft Windows 10 Version 1507). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2021-36942 (Microsoft Windows Server 2008 R2 Service Pack 1). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2021-38647 (Microsoft Azure Automation State Configuration, DSC Extension). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2021-38648 (Microsoft Azure Automation State Configuration, DSC Extension). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2021-40444 (Microsoft Windows 10 Version 1507). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2024-21338 (Microsoft Windows 10 Version 1809). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2024-21413 (Microsoft 365 Apps for Enterprise). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2024-38217 (Microsoft Windows 10 Version 1507). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10774 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10848 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-15038 (Unknown InfiniteWP Client). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16032 (Unknown LWS Optimize). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16267 (Unknown Newsletters). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16269 (Unknown Newsletters). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16282 (Unknown Appointment Hour Booking). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16548 (Unknown Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16559 (Unknown YMC Filter). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16574 (Unknown Dokan: AI Powered WooCommerce Multivendor Marketplace Solution). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16589 (Unknown WP Directory Kit). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16608 (Unknown Download Monitor). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16948 (Unknown Solace Extra). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16953 (Unknown AI Engine). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16955 (Unknown AI Engine). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16957 (Unknown Slim SEO). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16965 (Unknown Solace Extra). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16988 (Unknown GeoDirectory). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16992 (Unknown Create). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17011 (Unknown Nexter Blocks). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17014 (Unknown WP Photo Album Plus). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17017 (Unknown CubeWP Framework). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17044 (Unknown Iptanus File Upload). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18032 (Unknown WP Data Access). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18037 (Unknown Create). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18357 (Unknown WPC Order Tip for WooCommerce). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18464 (Unknown WP MAPS PRO). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18465 (Unknown WP MAPS PRO). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18473 (Unknown WP Directory Kit). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-18603 (Unknown PiWeb Cancel order / Refund request for WooCommerce). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19243 (HKUDS nanobot). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19341 (UTT HiPER 1200GW). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19342 (code-projects Task Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19343 (code-projects Task Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19344 (code-projects Task Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19346 (Tenda CH22). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19347 (itsourcecode Hospital Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19348 (Shenzhen Aitemi M300 Wi-Fi Repeater). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19352 (mifi lossless-cut). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19353 (DedeCMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19364 (itsourcecode Hospital Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19373 (PhialsBasement KoboldCPP-MCP-Server). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-31842 (Tinyproxy Project Tinyproxy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48710 (Kludex starlette). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66297 (livebook-dev livebook). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66757 (GNOME GIMP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66881 (livebook-dev livebook). Public exploit reference added.
RESCORED — CVE-2023-35384 (Microsoft Windows 10 Version 1507). CVSS 5.4 → 6.5 (NVD).
RESCORED — CVE-2023-35391 (Microsoft .NET 6.0). CVSS 6.2 → 7.5 (NVD).
RESCORED — CVE-2023-36741 (Microsoft Edge (Chromium-based)). CVSS 8.3 → 7.5 (NVD).
RESCORED — CVE-2023-36769 (Microsoft Office 2019). CVSS 4.6 → 5.4 (NVD).
RESCORED — CVE-2023-36873 (Microsoft .NET Framework 3.5 and 4.6.2). CVSS 7.4 → 5.9 (NVD).
RESCORED — CVE-2023-36897 (Microsoft 365 Apps for Enterprise). CVSS 8.1 → 6.5 (NVD).
RESCORED — CVE-2023-36903 (Microsoft Windows 10 Version 1507). CVSS 7.8 → 9.8 (NVD).
RESCORED — CVE-2023-36905 (Microsoft Windows 10 Version 1507). CVSS 5.5 → 7.5 (NVD).
RESCORED — CVE-2023-36906 (Microsoft Windows 10 Version 1507). CVSS 5.5 → 7.5 (NVD).
RESCORED — CVE-2023-36907 (Microsoft Windows 10 Version 1507). CVSS 5.5 → 7.5 (NVD).
RESCORED — CVE-2023-36913 (Microsoft Windows 10 Version 1507). CVSS 6.5 → 7.5 (NVD).
RESCORED — CVE-2023-38186 (Microsoft Windows 10 Version 21H2). CVSS 8.8 → 9.8 (NVD).
RESCORED — CVE-2024-0565 (Linux kernel). CVSS 6.8 → 7.4 (NVD).
RESCORED — CVE-2024-0775 (Linux kernel). CVSS 6.7 → 7.1 (NVD).
RESCORED — CVE-2024-21343 (Microsoft Windows 10 Version 1507). CVSS 5.9 → 7.5 (NVD).
RESCORED — CVE-2024-21416 (Microsoft Windows 10 Version 1809). CVSS 8.1 → 9.8 (NVD).
RESCORED — CVE-2024-21489 (uplot). CVSS 8.8 → 7.8 (NVD).
RESCORED — CVE-2024-37337 (Microsoft SQL Server 2017 (CU 31)). CVSS 7.1 → 4.3 (NVD).
RESCORED — CVE-2024-37341 (Microsoft SQL Server 2016 Service Pack 3 (GDR)). CVSS 8.8 → 9.8 (NVD).
RESCORED — CVE-2024-37342 (Microsoft SQL Server 2017 (CU 31)). CVSS 7.1 → 4.3 (NVD).
RESCORED — CVE-2024-37980 (Microsoft SQL Server 2016 Service Pack 3 (GDR)). CVSS 8.8 → 9.8 (NVD).
RESCORED — CVE-2024-38194 (Microsoft Azure Web Apps). CVSS 8.4 → 9.9 (NVD).
RESCORED — CVE-2024-38216 (Microsoft Azure Stack Hub). CVSS 8.2 → 9 (NVD).
RESCORED — CVE-2024-38225 (Microsoft Dynamics 365 Business Central 2023 Release Wave 1). CVSS 8.8 → 9.8 (NVD).
RESCORED — CVE-2024-38230 (Microsoft Windows Server 2012 R2). CVSS 6.5 → 7.5 (NVD).
RESCORED — CVE-2024-38231 (Microsoft Windows Server 2008 Service Pack 2). CVSS 6.5 → 7.5 (NVD).
RESCORED — CVE-2024-38240 (Microsoft Windows 10 Version 1507). CVSS 8.1 → 9.8 (NVD).
RESCORED — CVE-2024-38254 (Microsoft Windows 10 Version 1507). CVSS 5.5 → 6.2 (NVD).
RESCORED — CVE-2024-38258 (Microsoft Windows Server 2008 Service Pack 2). CVSS 6.5 → 7.5 (NVD).
RESCORED — CVE-2024-43455 (Microsoft Windows Server 2008 Service Pack 2). CVSS 8.8 → 9.8 (NVD).
RESCORED — CVE-2024-43460 (Microsoft Dynamics 365 Business Central Online). CVSS 8.1 → 8.8 (NVD).
RESCORED — CVE-2024-43474 (Microsoft SQL Server 2017 (CU 31)). CVSS 7.6 → 7.5 (NVD).
RESCORED — CVE-2024-43476 (Microsoft Dynamics 365 (on-premises) version 9.1). CVSS 7.6 → 5.4 (NVD).
RESCORED — CVE-2024-43489 (Microsoft Edge (Chromium-based)). CVSS 6.5 → 8.8 (NVD).
RESCORED — CVE-2024-43496 (Microsoft Edge (Chromium-based)). CVSS 6.5 → 8.8 (NVD).
RESCORED — CVE-2025-38525 (Linux). CVSS 7.5 → 5.5 (NVD).
RESCORED — CVE-2026-19375 (dmitriiweb article-scraper-mcp). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-19376 (Uasoft Badaso). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-19378 (code-projects Task Management System). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-48618 (nodejs node). CVSS 7.7 → 6.5 (NVD).
RESCORED — CVE-2026-8037 (Progress Software LoadMaster). CVSS 9.6 → 9.8 (NVD).
670 CVEs published. 25 box scores and 375 table rows below; the remaining 270 continue on page 2 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0263 84.3 —
AFFECTED Product Versions Fixed Apache Ranger 0.6 – —
TIMELINE Mar 2 Reserved by CNA Aug 10 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0208 79.9 —
AFFECTED Product Versions Fixed cyberpanel unspecified eca0c3cbeb35af8eaae9fafb094e8ef3cd923643
TIMELINE Aug 8 Reserved by CNA Aug 10 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0166 74.6 —
AFFECTED Product Versions Fixed ipTIME AX8004M 15.09.0 – —
TIMELINE Aug 9 Reserved by CNA Aug 10 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0128 67.6 —
AFFECTED Product Versions Fixed crontab-ui unspecified —
TIMELINE Aug 10 Reserved by CNA Aug 10 Published (CNA: TuranSec)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0127 67.3 —
AFFECTED Product Versions Fixed WAH7601 unspecified —
TIMELINE Jun 24 Reserved by CNA Aug 10 Published (CNA: TR-CERT)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0122 66.2 —
AFFECTED Product Versions Fixed crontab-ui unspecified —
TIMELINE Aug 10 Reserved by CNA Aug 10 Published (CNA: TuranSec)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0120 65.6 —
AFFECTED Product Versions Fixed Apache Ranger unspecified —
TIMELINE Apr 28 Reserved by CNA Aug 10 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0116 64.4 —
AFFECTED Product Versions Fixed Apache Ranger unspecified —
TIMELINE May 6 Reserved by CNA Aug 10 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0113 63.8 —
AFFECTED Product Versions Fixed Apache Ranger unspecified —
TIMELINE Jun 17 Reserved by CNA Aug 10 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0093 57.7 —
AFFECTED Product Versions Fixed xiaoai-patch unspecified —
TIMELINE Aug 10 Reserved by CNA Aug 10 Published (CNA: TuranSec)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0091 56.9 —
AFFECTED Product Versions Fixed pm2panel unspecified —
TIMELINE Aug 10 Reserved by CNA Aug 10 Published (CNA: TuranSec)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0086 55.3 —
AFFECTED Product Versions Fixed fprime-gds unspecified —
TIMELINE Aug 10 Reserved by CNA Aug 10 Published (CNA: TuranSec)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0077 52.6 —
AFFECTED Product Versions Fixed xmysql unspecified —
TIMELINE Aug 10 Reserved by CNA Aug 10 Published (CNA: TuranSec)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0077 52.5 —
AFFECTED Product Versions Fixed cast-localvideo unspecified —
TIMELINE Aug 10 Reserved by CNA Aug 10 Published (CNA: TuranSec)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0073 51.3 —
AFFECTED Product Versions Fixed Apache Ranger unspecified —
TIMELINE Apr 15 Reserved by CNA Aug 10 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0069 49.8 —
AFFECTED Product Versions Fixed Red Hat OpenShift AI 2.25 unspecified 1786110051 Red Hat OpenShift AI 3.3 unspecified 1786110033 Red Hat OpenShift AI 3.4 unspecified 1786107278 Red Hat OpenShift AI (RHOAI) unspecified — Red Hat OpenShift AI (RHOAI) unspecified — Red Hat OpenShift AI (RHOAI) unspecified — Red Hat OpenShift AI (RHOAI) unspecified — Red Hat OpenShift AI (RHOAI) unspecified — Red Hat OpenShift AI (RHOAI) unspecified — Red Hat OpenShift AI (RHOAI) unspecified — + 6 more
TIMELINE Aug 5 Reserved by CNA Aug 10 Published (CNA: redhat)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0068 49.3 —
AFFECTED Product Versions Fixed Linux a8599bd821d084d04a3290fffae1071624ec00ea – — Linux 2.6.34 – 6.6.148
TIMELINE Jul 30 Reserved by CNA Aug 10 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N R U H H H 7.5 .0065 48.0 —
AFFECTED Product Versions Fixed HyperCP unspecified —
TIMELINE Aug 10 Reserved by CNA Aug 10 Published (CNA: TuranSec)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N N H H 7.0 .0064 47.9 —
AFFECTED Product Versions Fixed sucuri-wordpress-plugin unspecified —
TIMELINE Aug 10 Reserved by CNA Aug 10 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0064 47.7 —
AFFECTED Product Versions Fixed Apache Ranger unspecified —
TIMELINE Mar 11 Reserved by CNA Aug 10 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0063 47.5 —
AFFECTED Product Versions Fixed dokploy < 0.29.13 – —
TIMELINE Aug 10 Reserved by CNA Aug 10 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0063 47.2 —
AFFECTED Product Versions Fixed Apache Ranger unspecified —
TIMELINE Jun 17 Reserved by CNA Aug 10 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0063 47.1 —
AFFECTED Product Versions Fixed Linux f24e9980eb860d8600cbe5ef3d2fd9295320d229 – — Linux 2.6.34 – 6.6.148
TIMELINE Jul 30 Reserved by CNA Aug 10 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0063 47.1 —
AFFECTED Product Versions Fixed Linux 930c532869774ebf8af9efe9484c597f896a7d46 – — Linux 4.7 – 6.6.148
TIMELINE Jul 30 Reserved by CNA Aug 10 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0063 47.1 —
AFFECTED Product Versions Fixed Linux 046c052b475e7119b6a30e3483e2888fc606a2f8 – — Linux 5.11 – 6.6.151
TIMELINE Jul 30 Reserved by CNA Aug 10 Published (CNA: Linux)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-65945 | 6.5 | 46.3 | Apache Software Foundation | Apache Ranger | CWE-532 | Apache Ranger: Logs contain replayable JWT bearer tokens |
| CVE-2026-68379 | 7.5 | 46.3 | Linux | Linux | — | tcp: fix TIME_WAIT socket reference leak on PSP policy failure |
| CVE-2026-68156 | 9.8 | 46.3 | Linux | Linux | — | libceph: refresh auth->authorizer_buf{,_len} after authorizer update |
| CVE-2026-68155 | 7.5 | 46.0 | Linux | Linux | — | libceph: Reject monmaps advertising zero monitors |
| CVE-2026-68157 | 7.5 | 46.0 | Linux | Linux | — | libceph: guard missing CRUSH type name lookup |
| CVE-2026-66915 | 10.0 | 45.9 | fabrikar.com | Fabrik extension for Joomla | CWE-94 | Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fa… |
| CVE-2026-72735 | 9.9 | 45.8 | Dokploy | dokploy | CWE-77 | Dokploy: Command injection in writeTraefikConfigRemote via shell interpolatio… |
| CVE-2026-65948 | 7.3 | 45.5 | Apache Software Foundation | Apache Ranger | CWE-307 | Apache Ranger: UnixAuth lacks brute-force protection |
| CVE-2026-18941 | 7.7 | 45.4 | Red Hat | Red Hat OpenShift AI 2.25 | CWE-306 | Feast: feast-operator: feast: default authentication mode is no_auth — shared… |
| CVE-2026-72885 | 0.0 | 44.8 | Dokploy | dokploy | CWE-78 | Dokploy: Authenticated Command Injection in Dokploy Dockerfile Builder |
| CVE-2026-10754 | 8.6 | 44.7 | Pegasystems | Pega Infinity | CWE-347 | Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper valid… |
| CVE-2026-18951 | 8.8 | 44.6 | Red Hat | Red Hat OpenShift AI 3.3 | CWE-284 | Odh-training-operator-rhel9: [trainer v2 security] trn-02: rhoai overlay aggr… |
| CVE-2026-72899 | 10.0 | 44.3 | Metabase | Metabase | CWE-89 | Metabase SQL injection via public card or dashboard |
| CVE-2026-68341 | 8.8 | 44.2 | Linux | Linux | — | ovpn: fix use after free in unlock_ovpn() |
| CVE-2026-44630 | 7.5 | 44.2 | Apache Software Foundation | Apache IoTDB | CWE-400 | Apache IoTDB: RPC service denial of service via unchecked Thrift string length |
| CVE-2026-65942 | 7.5 | 44.2 | Apache Software Foundation | Apache Ranger | CWE-297 | Apache Ranger: Clients accept TLS certificates issued for other hostnames |
| CVE-2026-68159 | 9.8 | 43.6 | Linux | Linux | — | libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE |
| CVE-2026-69118 | 8.7 | 43.6 | cachethq | cachet | CWE-863 | Cachet 2.4.1 Authenticated Server-Side Template Injection RCE |
| CVE-2026-72567 | 9.8 | 43.5 | AsyncFuncAI | deepwiki-open | CWE-22 | deepwiki-open - Unauthenticated Path Traversal Leading to Arbitrary File Writ… |
| CVE-2026-72902 | 9.9 | 42.9 | Dokploy | dokploy | CWE-78 | Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / r… |
| CVE-2026-72875 | 8.8 | 42.9 | Dokploy | dokploy | CWE-78 | Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTr… |
| CVE-2026-18618 | 7.5 | 42.9 | Red Hat | Red Hat OpenShift AI 2.25 | CWE-770 | Ml-metdata: bundled grpc 1.46.3 (2022) with published http/2 dos cves — direc… |
| CVE-2026-72592 | 9.8 | 42.7 | dulldusk | phpfm | CWE-434 | dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP F… |
| CVE-2026-68300 | 9.8 | 42.4 | Linux | Linux | — | sctp: auth: verify auth requirement when auth_chunk is NULL |
| CVE-2026-72593 | 9.8 | 42.2 | dulldusk | phpfm | CWE-306 | dulldusk phpfm - Missing Authentication by Default Allows Full Filesystem Access |
| CVE-2026-72738 | 9.9 | 41.9 | Dokploy | dokploy | CWE-78 | Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles se… |
| CVE-2026-72740 | 9.9 | 41.9 | Dokploy | dokploy | CWE-78 | Dokploy: OS Command Injection via SSH-form `customGitUrl` domain in `ssh-keys… |
| CVE-2026-68170 | 9.8 | 41.5 | Linux | Linux | — | mptcp: fix stale skb->sk reference on subflow close |
| CVE-2026-72569 | 9.1 | 41.4 | cube-root | directory-serve | CWE-22 | cube-root directory-serve - Unauthenticated Path Traversal Arbitrary File Del… |
| CVE-2025-15683 | 8.8 | 41.0 | TBEA | TBEA TLogger (TBEA Communication Box 3rd Generation) | CWE-121 | Multiple Unauthenticated Denial-of-Service Conditions |
| CVE-2026-66405 | 8.7 | 41.0 | ECOVACS ROBOTICS | DEEBOT PRO M1 | CWE-489 | DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The teln… |
| CVE-2026-72688 | 7.5 | 40.6 | OpenSignLabs | opensignserver | CWE-306 | OpenSignLabs opensignserver - Missing Authentication for Critical Function |
| CVE-2026-68123 | 9.8 | 40.4 | Linux | Linux | — | openvswitch: fix GSO userspace truncation underflow |
| CVE-2026-68136 | 9.8 | 40.4 | Linux | Linux | — | net: gro: fix double aggregation of flush-marked skbs |
| CVE-2026-68385 | 9.8 | 40.4 | Linux | Linux | — | s390/checksum: Fix csum_partial() without vector facility |
| CVE-2026-18982 | 8.8 | 40.2 | Red Hat | Red Hat OpenShift AI 2.25 | CWE-250 | Odh-training-operator-rhel9: rhoai fork aggregates training job create onto n… |
| CVE-2025-30241 | 8.6 | 40.1 | TP-Link Systems Inc. | HB810(US2) V1.0/1.6/2.0/2.6 | CWE-78 | OS Command Injection in Web Interface in Multiple TP-Link Aginet Devices |
| CVE-2026-72867 | 9.9 | 40.0 | Dokploy | dokploy | CWE-20 | Dokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated … |
| CVE-2026-48159 | 9.3 | 39.9 | dai-shi | use-reducer-async | CWE-506 | use-reducer-async was vulnerable to malicious code execution via compromised … |
| CVE-2026-68287 | 7.5 | 39.8 | Linux | Linux | — | drop_monitor: fix size calculations for 64-bit attributes |
| CVE-2026-68343 | 9.1 | 39.6 | Linux | Linux | — | smb: client: validate DFS referral PathConsumed |
| CVE-2026-72733 | 9.9 | 39.5 | Dokploy | dokploy | CWE-78 | Dokploy: OS Command Injection via `databaseName` / `backupFile` in database r… |
| CVE-2026-68127 | 9.8 | 39.5 | Linux | Linux | — | ila: reload IPv6 header after pskb_may_pull in checksum adjust |
| CVE-2026-68137 | 9.8 | 39.5 | Linux | Linux | — | net/x25: fix use-after-free in x25_kill_by_neigh() |
| CVE-2026-68144 | 9.8 | 39.5 | Linux | Linux | — | phonet: pep: fix use-after-free in pep_get_sb() |
| CVE-2025-15681 | 9.2 | 39.3 | TBEA | TBEA TLogger (TBEA Communication Box 3rd Generation) | CWE-306 | Insufficient Webserver Authentication |
| CVE-2026-68096 | 7.5 | 39.0 | Linux | Linux | — | audit: fix recursive locking deadlock in audit_dupe_exe() |
| CVE-2026-72881 | 6.4 | 39.0 | Dokploy | dokploy | CWE-78 | Dokploy: Command Injection via database credentials in backup/restore commands |
| CVE-2026-68117 | 9.8 | 38.8 | Linux | Linux | — | tipc: clear sock->sk on the failed-insert path in tipc_sk_create() |
| CVE-2026-72876 | 9.9 | 38.6 | Dokploy | dokploy | CWE-78 | Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server… |
| CVE-2026-72565 | 9.8 | 38.6 | Tencent | APIJSON | CWE-89 | Tencent APIJSON - Unauthenticated SQL Injection via @having Operator Map-Form… |
| CVE-2026-68129 | 7.5 | 38.4 | Linux | Linux | — | gve: fix Rx queue stall on alloc failure |
| CVE-2026-68131 | 7.5 | 38.4 | Linux | Linux | — | rbd: Reset positive result codes to zero in object map update path |
| CVE-2026-68141 | 7.5 | 38.4 | Linux | Linux | — | net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() |
| CVE-2026-68381 | 9.8 | 38.2 | Linux | Linux | — | ksmbd: pin conn during async oplock break notification |
| CVE-2026-68388 | 9.8 | 38.2 | Linux | Linux | — | smb/client: handle overlapping allocated ranges in fallocate |
| CVE-2026-19089 | 9.8 | 38.2 | Unknown | Product Input Fields for WooCommerce | CWE-434 | Product Input Fields for WooCommerce < 2.0.2 - Unauthenticated Arbitrary File… |
| CVE-2026-72914 | 7.5 | 37.7 | mastodon | mastodon | CWE-405 | Mastodon: Exhausting data by an unauthenticated request to the admin retentio… |
| CVE-2026-14450 | 9.9 | 37.5 | Red Hat | Red Hat OpenShift AI 3.4 | CWE-290 | Maas-billing: maas api: privilege escalation via forged http headers due to m… |
| CVE-2026-68302 | 9.8 | 37.4 | Linux | Linux | — | amt: re-read skb header pointers after every pull |
| CVE-2026-18617 | 8.8 | 37.2 | Red Hat | Red Hat OpenShift AI 2.25 | CWE-915 | Data-science-pipelines-operator: dspo: mysql dsn parameter injection via cust… |
| CVE-2026-71962 | 8.7 | 37.3 | FlowiseAI | Flowise | CWE-862 | Flowise 2.2.4 - 3.1.4 Missing Authorization via openai-assistants-file/download |
| CVE-2026-68083 | 9.1 | 37.1 | Linux | Linux | — | ksmbd: fix path resolution in ksmbd_vfs_kern_path_create |
| CVE-2026-68120 | 7.5 | 37.1 | Linux | Linux | — | rtase: Workaround for TX hang caused by hardware packet parsing |
| CVE-2026-68299 | 7.5 | 37.1 | Linux | Linux | — | vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets |
| CVE-2026-68315 | 7.5 | 37.1 | Linux | Linux | — | sctp: validate stream count in sctp_process_strreset_inreq() |
| CVE-2026-72739 | 6.5 | 37.0 | Dokploy | dokploy | CWE-78 | Dokploy: Command Injection via Compose Shell Execution |
| CVE-2026-18608 | 8.7 | 36.3 | Red Hat | Red Hat OpenShift AI 2.25 | CWE-250 | Data-science-pipelines-operator: dspo: operator clusterrole grants pods/exec:… |
| CVE-2026-72736 | 9.9 | 36.1 | Dokploy | dokploy | CWE-77 | Dokploy: OS Command Injection in registry credential testing and Swarm cluste… |
| CVE-2026-72862 | 9.9 | 36.1 | Dokploy | dokploy | CWE-78 | Dokploy: OS Command Injection via dockerImage field in database service deplo… |
| CVE-2026-66403 | 8.7 | 36.0 | ECOVACS ROBOTICS | DEEBOT PRO M1 | CWE-489 | DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purpose… |
| CVE-2026-18947 | 8.5 | 36.0 | Red Hat | Red Hat OpenShift AI 2.25 | CWE-862 | Feast: feast: authorization bypass in /materialize endpoints enables dos via … |
| CVE-2026-72721 | 5.3 | 35.7 | discourse | discourse | CWE-178 | Discourse: Onebox Domain Blocklist Bypass via Case-Sensitive Comparison |
| CVE-2026-72884 | 8.7 | 35.5 | Dokploy | dokploy | CWE-78 | Dokploy: Command Injection via Compose Custom Command |
| CVE-2026-68376 | 8.1 | 35.3 | Linux | Linux | — | sctp: fix auth_hmacs array size in struct sctp_cookie |
| CVE-2026-48161 | 9.3 | 34.9 | dai-shi | react18-use | CWE-506 | react18-use was vulnerable to malicious code execution via compromised commits |
| CVE-2026-19404 | 6.5 | 34.7 | Red Hat | Red Hat Directory Server 11 | CWE-862 | 389-ds-base: 389-ds-base: missing authorization allows anonymous clients to s… |
| CVE-2026-18949 | 8.8 | 34.6 | Red Hat | Red Hat OpenShift AI 2.25 | CWE-250 | Odh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets… |
| CVE-2026-68097 | 8.8 | 34.6 | Linux | Linux | — | ksmbd: validate ACE size against SID sub-authorities |
| CVE-2026-68098 | 8.8 | 34.6 | Linux | Linux | — | ksmbd: bound DACL dedup walk to copied ACEs |
| CVE-2026-61899 | 7.5 | 34.5 | Apache Software Foundation | Apache Tapestry | CWE-200 | Apache Tapestry: Possible classpath file download through URL manipulation |
| CVE-2026-72719 | 6.7 | 34.2 | chatwoot | chatwoot | CWE-915 | Chatwoot: Cross-Account Resource Transfer via `account_id` Parameter |
| CVE-2026-16985 | 8.8 | 33.8 | Unknown | Squeeze | CWE-434 | Squeeze < 1.7.12 - Author+ Arbitrary File Upload |
| CVE-2026-68196 | 8.3 | 33.7 | Linux | Linux | — | wifi: wilc1000: validate assoc response length before subtracting header |
| CVE-2026-68352 | 8.3 | 33.7 | Linux | Linux | — | wifi: ath6kl: fix OOB read from firmware IE lengths in connect event |
| CVE-2026-68100 | 8.1 | 33.6 | Linux | Linux | — | ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl |
| CVE-2026-72877 | 9.6 | 33.4 | Dokploy | dokploy | CWE-78 | Dokploy: Command Injection via dockerImage in buildRemoteDocker |
| CVE-2025-13294 | 9.3 | 33.3 | TBEA | TBEA TLogger (TBEA Communication Box 3rd Generation) | CWE-89 | Unauthenticated SQL Injection |
| CVE-2026-72883 | 8.8 | 33.3 | Dokploy | dokploy | CWE-862 | Dokploy: WebSocket Terminal Missing Service-Level Access Control |
| CVE-2026-66738 | 7.7 | 33.2 | SPIP | SPIP | CWE-94 | SPIP < 4.4.18 Code Injection via Navigation Endpoint on SQLite |
| CVE-2026-64940 | 8.8 | 33.0 | Nishishi Factory | Tegalog -Fumy Otegaru Memo Logger- | CWE-625 | Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vu… |
| CVE-2026-68192 | 8.8 | 33.0 | Linux | Linux | — | wifi: brcmfmac: make release_scratchbuffers idempotent |
| CVE-2026-68199 | 8.8 | 33.0 | Linux | Linux | — | wifi: ath6kl: fix OOB access from firmware ADDBA window size |
| CVE-2026-13170 | 7.2 | 33.0 | Unknown | Eventin | CWE-22 | Eventin < 4.1.20 - Editor+ Local File Inclusion via speaker_template Setting |
| CVE-2026-48158 | 9.3 | 32.8 | dai-shi | use-context-selector | CWE-506 | use-context-selector was vulnerable to malicious code execution via compromis… |
| CVE-2026-48160 | 9.3 | 32.8 | dai-shi | react-tracked | CWE-506 | react-tracked was vulnerable to malicious code execution via compromised commits |
| CVE-2025-15682 | 8.7 | 32.8 | TBEA | TBEA TLogger (TBEA Communication Box 3rd Generation) | CWE-770 | Unauthenticated Resource Exhaustion |
| CVE-2026-18611 | 7.5 | 32.8 | Red Hat | Red Hat OpenShift AI 2.25 | CWE-338 | Data-science-pipelines-operator: dspo: cryptographically weak secret generati… |
| CVE-2026-72691 | 7.5 | 32.5 | OpenSignLabs | opensignserver | CWE-288 | OpenSignLabs opensignserver - Authentication Bypass |
| CVE-2026-66411 | 6.9 | 32.2 | ECOVACS ROBOTICS | DEEBOT PRO M1 | CWE-303 | DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algor… |
| CVE-2026-71392 | 5.3 | 32.2 | GNU | Emacs | CWE-190 | Integer Overflow in GNU Emacs for Android |
| CVE-2026-71393 | 5.3 | 32.2 | GNU | Emacs | CWE-190 | Heap Buffer Overflow in GNU Emacs for Android |
| CVE-2026-72723 | 5.3 | 31.6 | discourse | discourse | CWE-862 | Discourse: Anonymous sidebar serialization exposes descriptions of category-r… |
| CVE-2026-68118 | 8.2 | 31.5 | Linux | Linux | — | tcp: challenge ACK for non-exact RST in SYN-RECEIVED |
| CVE-2026-72911 | 9.9 | 31.5 | frappe | erpnext | CWE-1336 | ERPNext: Possibility of server-side template injection due to missing validation |
| CVE-2026-15467 | 8.1 | 31.3 | Red Hat | Red Hat OpenShift AI 2.25 | CWE-266 | Trustyai-service-operator: trustyai-service-operator: lmevaljob sidecar conta… |
| CVE-2026-72575 | 9.1 | 30.6 | daptin | daptin | CWE-284 | daptin - Authentication Bypass via Null Owner Permission Check on usergroup O… |
| CVE-2026-73030 | 7.2 | 30.6 | frostming | unearth | CWE-22 | unearth 0.18.2 Path Traversal via Unnormalized Paths and Symlink Escape |
| CVE-2026-68283 | 8.8 | 30.5 | Linux | Linux | — | tracing: Fix use-after-free freeing trigger private data |
| CVE-2026-68119 | 7.5 | 30.4 | Linux | Linux | — | tcp: initialize standalone TCP-AO response padding |
| CVE-2026-72872 | 9.9 | 30.3 | Dokploy | dokploy | CWE-78 | Dokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone` |
| CVE-2025-13293 | 9.3 | 30.2 | TBEA | TBEA TLogger (TBEA Communication Box 3rd Generation) | CWE-798 | Backdoor / default root credentials |
| CVE-2026-72586 | 7.5 | 29.9 | frangoteam | FUXA | CWE-306 | frangoteam FUXA - Missing Authentication on DAQ_QUERY Socket.IO Event Handler |
| CVE-2026-68426 | 9.8 | 29.8 | Linux | Linux | — | xfrm: fix stale skb->prev after async crypto steals a GSO segment |
| CVE-2026-72868 | 9.9 | 29.4 | Dokploy | dokploy | CWE-78 | Dokploy: Member-role RCE as host root via destination.testConnection rclone s… |
| CVE-2026-72581 | 8.6 | 29.4 | duhow | xiaoai-patch | CWE-918 | duhow xiaoai-patch - Server-Side Request Forgery in /auth Endpoint |
| CVE-2026-72761 | 6.9 | 29.3 | vulnerability-lookup | vulnerability-lookup | CWE-918 | Webhook SSRF guard bypassed by IPv6 transition addresses (NAT64/6to4/Teredo p… |
| CVE-2026-72886 | 9.9 | 29.2 | Dokploy | dokploy | CWE-269 | Dokploy: Non-admin member gains root on the host by bypassing the owner/admin… |
| CVE-2026-18950 | 8.8 | 29.2 | Red Hat | Red Hat OpenShift AI 2.25 | CWE-269 | Odh-dashboard: odh-dashboard: confused-deputy privilege escalation via unchec… |
| CVE-2026-48048 | 7.5 | 29.1 | xwiki | xwiki-platform | CWE-359 | XWiki Platform's Livetable results still allow reconstructing password hashes… |
| CVE-2026-21075 | 5.3 | 29.0 | Samsung Mobile | My Galaxy | CWE-939 | Improper authorization in handler for custom URL scheme in My Galaxy prior to… |
| CVE-2026-72916 | 6.3 | 29.0 | mastodon | mastodon | CWE-918 | Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses |
| CVE-2026-72882 | 9.9 | 28.6 | Dokploy | dokploy | CWE-78 | Dokploy: Authenticated blind command injection via file mounts leads to direc… |
| CVE-2026-13717 | 8.8 | 28.6 | Red Hat | Red Hat OpenShift AI 3.4 | CWE-284 | Rhoai maas: llm-d: maas/llm-d inference gateway: default allowedroutes.namesp… |
| CVE-2026-72874 | 8.7 | 28.5 | Dokploy | dokploy | CWE-78 | Dokploy: Command Injection via Unescaped Git URL in Clone Commands |
| CVE-2026-72865 | 9.9 | 28.2 | Dokploy | dokploy | CWE-78 | Dokploy: OS Command Injection via compose `composePath` |
| CVE-2026-72869 | 9.9 | 28.2 | Dokploy | dokploy | CWE-77 | Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (… |
| CVE-2026-18412 | 9.1 | 28.0 | OpenCart | OpenCart | — | The OpenCart v4.2.0.0 extension installer contains a directory traversal vuln… |
| CVE-2026-18621 | 7.6 | 28.0 | Red Hat | Red Hat OpenShift AI 2.25 | CWE-266 | Data-sciences-pipeline: dsp: v1 argo template path accepts arbitrary workflow… |
| CVE-2026-72582 | 7.5 | 27.7 | fastschema | fastschema | CWE-476 | fastschema - Unauthenticated NULL Pointer Dereference DoS in Account Recovery… |
| CVE-2026-71965 | 8.7 | 27.5 | usmannasir | cyberpanel | CWE-345 | CyberPanel 2.4.3 Authenticated RCE via Remote Backup Feature |
| CVE-2026-68124 | 9.6 | 27.4 | Linux | Linux | — | mctp: serial: handle zero-length frames to prevent rx buffer overflow |
| CVE-2026-16298 | 9.8 | 27.2 | Unknown | FoodBoxBooker | CWE-269 | FoodBoxBooker < 1.0.7 - Unauthenticated Arbitrary Password Reset |
| CVE-2026-16299 | 9.8 | 27.2 | Unknown | Single Sign On For TNG | CWE-287 | Single Sign On For TNG < 2.2.0 - Unauthenticated Arbitrary Password Reset |
| CVE-2026-13600 | 8.1 | 27.1 | Unknown | AutoNetTV Relay | CWE-287 | AutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled… |
| CVE-2026-70622 | 7.1 | 27.1 | composefs | tar-rs | CWE-59 | tar-rs 0.4.11 - 0.4.46 Symlink Escape via append_dir_all() |
| CVE-2026-64941 | 2.1 | 27.1 | phoenixframework | phoenix_live_view | CWE-601 | Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR |
| CVE-2026-47754 | 9.3 | 26.7 | NCEAS | metacat | CWE-22 | unauthenticated path traversal in Metacat 2.x |
| CVE-2026-72726 | 6.5 | 26.0 | discourse | discourse | CWE-200 | Discourse: Unauthorized eavesdropping on private AI bot conversations. |
| CVE-2026-72873 | 6.5 | 26.0 | Dokploy | dokploy | CWE-200 | Dokploy: Cross-tenant Git provider secrets are disclosed to low-privileged se… |
| CVE-2026-21061 | 6.0 | 26.1 | Samsung Mobile | Samsung Mobile Devices | CWE-20 | Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 a… |
| CVE-2026-16626 | 9.3 | 25.9 | Jaspersoft | JasperReports Server | CWE-611 | JasperReports Server: XXE Injection Vulnerability (Unauthenticated) |
| CVE-2026-66407 | 7.7 | 25.8 | ECOVACS ROBOTICS | DEEBOT PRO M1 | CWE-327 | DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in Web… |
| CVE-2026-11810 | 7.5 | 25.8 | zephyrproject | zephyr | CWE-476 | NULL-pointer dereference in UpdateHub OTA agent on empty inner metadata array… |
| CVE-2026-68871 | 6.5 | 25.7 | Apache Software Foundation | Apache Airflow Yandex provider | CWE-639 | Apache Airflow Yandex provider: yandex Lockbox backend: team-scope guard bypa… |
| CVE-2026-68872 | 6.5 | 25.7 | Apache Software Foundation | Apache Airflow Amazon provider | CWE-639 | Apache Airflow Amazon provider: amazon SSM / Secrets Manager backends: team-s… |
| CVE-2026-71391 | 5.3 | 25.5 | GNU | Emacs | CWE-193 | Off-by-One Error in GNU Emacs for Android |
| CVE-2026-66409 | 6.9 | 25.3 | ECOVACS ROBOTICS | DEEBOT PRO M1 | CWE-1391 | DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for the… |
| CVE-2026-72689 | 7.5 | 25.2 | OpenSignLabs | opensignserver | CWE-639 | OpenSignLabs opensignserver - Broken Object Level Authorization |
| CVE-2026-72722 | 4.3 | 25.2 | discourse | discourse | CWE-862 | Discourse: Duplicate lookup reveals restricted topic titles through canonical… |
| CVE-2026-72724 | 4.3 | 25.2 | discourse | discourse | CWE-639 | Discourse: Private Chat Threat Message Disclosure via Chat Onebox Channel/Thr… |
| CVE-2026-18620 | 7.1 | 24.8 | Red Hat | Red Hat OpenShift AI 2.25 | CWE-639 | Data-sciences-pipeline: user-controlled serviceaccount for workflow pods with… |
| CVE-2026-71964 | 7.1 | 24.5 | usmannasir | cyberpanel | CWE-59 | CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Upload |
| CVE-2026-14206 | 7.5 | 24.3 | Unknown | HT Contact Form | CWE-200 | HT Contact Form < 2.9.3 - Unauthenticated Saved Form Draft Data Disclosure |
| CVE-2026-17541 | 7.5 | 24.3 | Unknown | File Manager | CWE-200 | Bit File Manager < 6.9.1 - Unauthenticated File Activity Log Disclosure |
| CVE-2026-18470 | 7.5 | 24.3 | Unknown | Login & Register Forms | CWE-200 | Login & Register Forms < 4.0.2 - Unauthenticated Registered User Email Addres… |
| CVE-2026-57279 | 6.0 | 24.3 | Cybozu, Inc | Cybozu Garoon | CWE-79 | Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerab… |
| CVE-2026-72564 | 9.6 | 24.1 | fosrl | Pangolin | CWE-639 | fosrl Pangolin - Access Token Scope Bypass Allows Cross-Resource Authentication |
| CVE-2026-72903 | 8.1 | 23.8 | Eugeny | tabby | CWE-22 | Tabby: Windows SFTP path traversal allows a malicious server to write files o… |
| CVE-2026-68125 | 8.8 | 23.6 | Linux | Linux | — | mac802154: llsec: reject frames shorter than the authentication tag |
| CVE-2026-12339 | 6.9 | 23.7 | TP-Link Systems Inc. | TL-MR6400 v5.3 | CWE-22 | Authenticated Arbitrary File Write Vulnerability in multiple devices |
| CVE-2026-16456 | 6.5 | 23.6 | Red Hat | Red Hat OpenShift AI 2.25 | CWE-441 | Odh-model-controller: odh-model-controller: cross-namespace secret read via n… |
| CVE-2026-72866 | 8.8 | 23.4 | Dokploy | dokploy | CWE-862 | WebSocket Terminal Auth Bypass |
| CVE-2026-59090 | 8.4 | 23.5 | Red Hat | Red Hat Enterprise Linux 6 | CWE-191 | Gimp: gimp: arbitrary code execution in psd plugin due to unsigned underflow |
| CVE-2026-18942 | 5.5 | 23.4 | Red Hat | Red Hat OpenShift AI 2.25 | CWE-94 | Feast-operator: feast: feast apply cronjob runs user python with feature-serv… |
| CVE-2026-17542 | 7.5 | 22.8 | Unknown | File Manager | CWE-200 | Bit File Manager < 6.9.1 - Subscriber+ Sensitive Data Disclosure via bitapps_… |
| CVE-2026-19049 | 8.6 | 22.6 | Unknown | ProSolution WP Client | CWE-89 | ProSolution WP Client < 2.0.9 - Unauthenticated SQLi and Plugin Data Deletion… |
| CVE-2026-72900 | 7.1 | 22.6 | Metabase | Metabase | CWE-862 | Metabase information exposure |
| CVE-2026-72720 | 6.4 | 22.4 | discourse | discourse | CWE-79 | Discourse: HTML injection in PrettyText.format_for_email from cooked-attribut… |
| CVE-2026-72863 | 9.9 | 22.4 | Dokploy | dokploy | CWE-269 | Dokploy: Missing authorization in WebSocket handlers allows a low-privilege m… |
| CVE-2026-72880 | 9.9 | 22.4 | Dokploy | dokploy | CWE-78 | Dokploy: Arbitrary File Write + Remote OS Command Injection via `certificateP… |
| CVE-2026-72734 | 8.4 | 22.2 | Dokploy | dokploy | CWE-639 | Dokploy: Cross-organization authorization bypass in server.remove allows dele… |
| CVE-2026-72871 | 7.5 | 21.9 | Dokploy | dokploy | CWE-306 | Dokploy: Unauthenticated Git Provider Injection via GitHub OAuth Callback |
| CVE-2026-63106 | 9.3 | 21.7 | Razinsoft | Ready eCommerce | CWE-89 | ReadyEcommerce < 4.5.2 Unauthenticated SQL Injection via ProductController.php |
| CVE-2026-17540 | 8.8 | 21.6 | Unknown | File Manager | CWE-284 | Bit File Manager < 6.9.1 - Subscriber+ Arbitrary File Read and Deletion via C… |
| CVE-2026-71959 | 6.9 | 21.4 | bitwarden | server | CWE-862 | Bitwarden Server < 2026.7.2 Audit Log Injection via POST /collect |
| CVE-2026-72904 | 9.3 | 21.3 | firecrawl | firecrawl | CWE-77 | Firecrawl: Arbitrary file read via JSON Schema $ref expansion |
| CVE-2026-18786 | 8.8 | 21.2 | Unknown | CheckView | CWE-287 | CheckView < 2.3.2 - Administrator Account Creation via REST API Authenticatio… |
| CVE-2026-72908 | 6.5 | 21.2 | frappe | erpnext | CWE-89 | ERPNext: Possibility of SQL injection due to missing validation |
| CVE-2026-72759 | 6.9 | 20.7 | misp | cti-transmute | CWE-862 | cti-transmute Conversion History Authorization Bypass Leads to Sensitive Data… |
| CVE-2026-18478 | 5.1 | 20.6 | Magnolia DXP | Magnolia CMS | CWE-79 | Stored XSS in Magnolia CMS |
| CVE-2026-68353 | 8.1 | 20.5 | Linux | Linux | — | wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler |
| CVE-2026-18030 | 8.1 | 20.4 | Unknown | BricksForge | CWE-862 | Bricksforge < 3.1.8.8 - Unauthenticated Arbitrary Password Reset via Pro Forms |
| CVE-2026-18468 | 8.1 | 20.4 | Unknown | Login & Register Forms | CWE-287 | Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Passwor… |
| CVE-2026-18469 | 8.1 | 20.4 | Unknown | Login & Register Forms | CWE-287 | Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Passwor… |
| CVE-2026-71394 | 5.3 | 20.4 | GNU | Emacs | CWE-1284 | Heap Use of Uninitialized Memory in GNU Emacs for Android |
| CVE-2026-72879 | 9.4 | 20.3 | Dokploy | dokploy | CWE-78 | Dokploy: Command Injection via Registry Credentials in Swarm Upload |
| CVE-2026-72870 | 8.7 | 20.3 | Dokploy | dokploy | CWE-78 | Dokploy: Command Injection via Docker Credentials in buildRemoteDocker |
| CVE-2026-72729 | 2.0 | 20.3 | discourse | discourse | CWE-79 | Discourse: Stored XSS in discourse-local-dates plugin |
| CVE-2026-72915 | 7.5 | 20.2 | mastodon | mastodon | CWE-200 | Mastodon: Personally-identifying information disclosure due to incorrect acce… |
| CVE-2026-69114 | 7.1 | 20.2 | Spacebar Server | Spacebar Server | CWE-639 | Spacebar Server Cross-Channel Message Deletion via Permission Check Bypass |
| CVE-2026-14293 | 8.8 | 20.0 | Unknown | Autopay | CWE-79 | Autopay / Blue Media for WooCommerce < 5.0.1 - Unauthenticated Stored XSS via… |
| CVE-2026-68354 | 8.8 | 20.0 | Linux | Linux | — | firewire: net: Fix fragmented datagram reassembly |
| CVE-2026-72910 | 7.1 | 19.9 | frappe | erpnext | CWE-862 | ERPNext: Unauthorised modification of master data due to missing validation |
| CVE-2026-72864 | 9.9 | 19.8 | Dokploy | dokploy | CWE-862 | Dokploy Broken Access Control on docker-container-terminal WebSocket (Member … |
| CVE-2026-11809 | 3.7 | 19.7 | zephyrproject | zephyr | CWE-125 | UpdateHub probe: uninitialized-heap out-of-bounds read of network-supplied me… |
| CVE-2026-72692 | 7.5 | 19.6 | OpenSignLabs | opensignserver | CWE-862 | OpenSignLabs opensignserver - Missing Authorization |
| CVE-2026-72591 | 7.7 | 19.3 | gabehf | Koito | CWE-918 | Koito - Authenticated Server-Side Request Forgery via Album Image URL Parameter |
| CVE-2026-72909 | 7.1 | 19.1 | frappe | erpnext | CWE-284 | ERPNext: Broken Access Control on certain endpoints |
| CVE-2026-68140 | 8.8 | 19.0 | Linux | Linux | — | net/iucv: fix use-after-free of a severed iucv_path |
| CVE-2026-68198 | 8.8 | 19.0 | Linux | Linux | — | wifi: ath6kl: fix use-after-free in aggr_reset_state() |
| CVE-2026-68373 | 8.1 | 19.0 | Linux | Linux | — | wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() |
| CVE-2026-72917 | 5.9 | 19.0 | Mintplex-Labs | anything-llm | CWE-180 | AnythingLLM: Password recovery accepts one recovery code twice after whitespa… |
| CVE-2026-72751 | 5.1 | 19.0 | misp | cti-transmute | CWE-79 | Stored Cross-Site Scripting in CTI-Transmute Conversion Graph via Malicious S… |
| CVE-2026-72878 | 9.6 | 18.9 | Dokploy | dokploy | CWE-78 | Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-c… |
| CVE-2026-68091 | 8.8 | 18.5 | Linux | Linux | — | HID: wacom: stop hardware after post-start probe failures |
| CVE-2026-19384 | 5.5 | 18.2 | SourceCodester | Simple Doctors Appointment System | CWE-74 | SourceCodester Simple Doctors Appointment System ajax.php set_appointment sql… |
| CVE-2026-19389 | 7.1 | 17.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-190 | Gstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflo… |
| CVE-2026-68402 | 7.1 | 17.8 | Linux | Linux | — | wifi: cfg80211: bound element ID read when checking non-inheritance |
| CVE-2026-72566 | 7.7 | 17.6 | automatisch | automatisch | CWE-918 | automatisch - Server-Side Request Forgery via HTTP Request Custom Action |
| CVE-2026-68326 | 8.8 | 17.5 | Linux | Linux | — | wifi: mwifiex: bound uAP association event IEs to the event buffer |
| CVE-2026-68389 | 8.8 | 17.5 | Linux | Linux | — | Bluetooth: hci_qca: Clear memdump state on invalid dump size |
| CVE-2026-68397 | 8.8 | 17.5 | Linux | Linux | — | net/iucv: take a reference on the socket found in afiucv_hs_rcv() |
| CVE-2026-14237 | 7.2 | 17.5 | Unknown | vitepos | CWE-269 | Vitepos < 3.6.0 - Outlet Manager+ Privilege Escalation |
| CVE-2026-17022 | 7.5 | 17.4 | Unknown | Salon Booking System | CWE-200 | Salon Booking System – Free Version < 10.30.34 - Unauthenticated Booking Info… |
| CVE-2026-18946 | 7.5 | 17.4 | Unknown | Contact Form to Any API | CWE-200 | Contact Form to Any API < 3.0.7 - Unauthenticated Sensitive File Disclosure v… |
| CVE-2026-12984 | 8.2 | 17.2 | Zyxel Networks | WAH7601 | CWE-522 | Exposure of Sensitive Information to an Unauthorized Actor in Zyxel's WAH7601 |
| CVE-2026-16257 | 8.2 | 17.2 | Unknown | Arvow AI SEO Writer | CWE-287 | Arvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Creation via Web… |
| CVE-2026-68425 | 7.1 | 17.2 | Linux | Linux | — | IB/mad: Drop unmatched RMPP responses before reassembly |
| CVE-2026-72690 | 7.1 | 17.1 | Attendize | Attendize | CWE-639 | Attendize Attendize - Cross-Tenant Authorization Bypass |
| CVE-2026-19433 | 8.6 | 16.9 | Roskus | Prospero Flow CRM | CWE-639 | Authorization Bypass Through User-Controlled Key in Prospero Flow CRM contact… |
| CVE-2026-15581 | 8.0 | 16.8 | Red Hat | Red Hat OpenShift AI 2.25 | CWE-306 | Trustyai-service-operator: trustyai-service-operator: tas internal service by… |
| CVE-2026-11811 | 3.7 | 16.9 | zephyrproject | zephyr | CWE-772 | Socket file-descriptor leak in UpdateHub OTA client start_coap_client() leadi… |
| CVE-2026-68085 | 8.0 | 16.7 | Linux | Linux | — | Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled |
| CVE-2026-72588 | 5.3 | 16.7 | bluewave-labs | Checkmate | CWE-204 | bluewave-labs Checkmate - User Enumeration via Differential HTTP Response in … |
| CVE-2026-72732 | 4.3 | 16.7 | discourse | discourse | CWE-862 | Discourse: Templates endpoint exposes hidden tag names |
| CVE-2026-72737 | 9.6 | 16.3 | Dokploy | dokploy | CWE-639 | Dokploy: Cross-organization IDOR in Dokploy backup destinations exposes anoth… |
| CVE-2026-72584 | 7.4 | 16.1 | fastschema | fastschema | CWE-367 | fastschema - TOCTOU Race Condition Bypasses OTP Attempt Limit in Account Reco… |
| CVE-2026-72907 | 6.5 | 16.2 | frappe | erpnext | CWE-285 | ERPNext: Broken Access Control on certain endpoint |
| CVE-2026-19387 | 7.6 | 15.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-787 | Gstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write i… |
| CVE-2026-69116 | 5.3 | 15.8 | xpf0000 | FlyEnv | CWE-79 | FlyEnv < 4.18.0 Cross-Site Scripting via v-html |
| CVE-2026-68393 | 8.8 | 15.6 | Linux | Linux | — | Bluetooth: hci_sync: extend conn_hash lookup critical sections |
| CVE-2026-68409 | 8.8 | 15.6 | Linux | Linux | — | wifi: mac80211: defer link RX stats percpu free to RCU |
| CVE-2026-19053 | 9.1 | 15.5 | Unknown | ProSolution WP Client | CWE-89 | ProSolution WP Client < 2.0.6 - Unauthenticated Blind SQLi via 'jobID' Parameter |
| CVE-2026-72574 | 6.1 | 15.5 | picocms | Pico | CWE-644 | picocms Pico - Host Header Injection Enables Script Source Hijacking |
| CVE-2026-14886 | 8.2 | 15.3 | HashiCorp | Vault Enterprise | CWE-862 | Vault Enterprise vulnerable to cross-namespace entity deletion |
| CVE-2026-72760 | 5.3 | 15.1 | MISP | cti-transmute | CWE-200 | cti-transmute Following List Exposes User Email Addresses to Authenticated Users |
| CVE-2026-6426 | 4.4 | 15.2 | Red Hat | Red Hat Enterprise Linux 10 | CWE-681 | Qemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-o… |
| CVE-2026-59233 | 8.7 | 15.1 | Roskus | Prospero Flow CRM | CWE-639 | Missing Authorization in Prospero Flow CRM permission save endpoint allows pr… |
| CVE-2026-72919 | 4.3 | 15.1 | RocketChat | Rocket.Chat | CWE-862 | Rocket.Chat: Broken Access Control in channels.convertToTeam Allows Unauthori… |
| CVE-2026-72730 | 8.7 | 14.9 | discourse | discourse | CWE-79 | Discourse: Stored XSS chat-transcript username unescaped in Rich Text Editor |
| CVE-2026-15047 | 6.8 | 14.7 | Unknown | s2Member | CWE-79 | s2Member < 260805 - Contributor+ Stored XSS via Shortcode |
| CVE-2026-14860 | 5.3 | 14.7 | Unknown | Podcast Player | CWE-918 | Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery |
| CVE-2026-72727 | 4.8 | 14.5 | discourse | discourse | CWE-79 | Discourse: Stored XSS in the moderation review queue |
| CVE-2026-19077 | 6.5 | 14.4 | Unknown | Duplicate Post | CWE-639 | Copy & Delete Posts < 1.5.5 - Authenticated Arbitrary Post Deletion via Missi… |
| CVE-2026-6374 | 7.3 | 14.1 | Zyxel Networks | WAH7601 | CWE-798 | Hardcoded Credentials in Zyxel WAH7601 Router |
| CVE-2026-72731 | 7.1 | 14.2 | discourse | discourse | CWE-89 | Discourse: Strip SQL comments and use non-recursive parameter interpolation i… |
| CVE-2026-68414 | 7.5 | 14.1 | Linux | Linux | — | wifi: cfg80211: cancel sched scan results work on unregister |
| CVE-2026-44401 | 4.6 | 14.1 | Typemill | Typemill | CWE-79 | Typemill CMS 2.x Persistent XSS via Markdown javascript URI |
| CVE-2026-59087 | 7.8 | 13.6 | Red Hat | Red Hat Enterprise Linux 6 | CWE-787 | Gimp: heap buffer overflow in `file-seattle-filmworks` load — `fread` writes … |
| CVE-2026-68278 | await | 13.5 | Linux | Linux | — | drm/dp/mst: fix buffer overflows in sideband chunk accumulation |
| CVE-2026-68870 | 5.3 | 13.4 | Apache Software Foundation | Apache Airflow Microsoft Azure provider | CWE-639 | Apache Airflow Microsoft Azure provider: microsoft.azure Key Vault backend: t… |
| CVE-2026-68359 | await | 13.3 | Linux | Linux | — | hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop |
| CVE-2026-68360 | await | 13.3 | Linux | Linux | — | hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop |
| CVE-2026-17018 | 4.9 | 13.0 | Unknown | CubeWP Framework | CWE-639 | CubeWP Framework <= 1.1.30 - Contributor+ Arbitrary Post and User Meta Disclo… |
| CVE-2026-15237 | 5.3 | 12.9 | Unknown | MotoPress Hotel Booking | CWE-862 | Hotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Chec… |
| CVE-2025-30237 | 8.7 | 12.6 | TP-Link Systems Inc. | HB810(US2) V1.0/1.6/2.0/2.6 | CWE-862 | Authentication Bypass via Broken Access Control in Web Server in Multiple TP-… |
| CVE-2026-68390 | 8.8 | 12.5 | Linux | Linux | — | Bluetooth: hci_sync: hold hdev->lock for hci_conn_params lookups |
| CVE-2026-19383 | 2.0 | 12.5 | saithink | SaiAdmin | CWE-284 | saithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestric… |
| CVE-2026-72725 | 5.4 | 12.1 | discourse | discourse | CWE-79 | Discourse: Stored XSS in staff action logs injects staff UI |
| CVE-2026-56620 | 4.3 | 12.1 | HCLSoftware | HCL BigFix Mobile | CWE-209 | HCL BigFix Mobile is vulnerable to information disclosure |
| CVE-2026-17012 | 5.3 | 12.0 | Unknown | Accept PayPal & Stripe with Subscriptions for WooCommerce | CWE-284 | Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via Unvalid… |
| CVE-2026-73035 | 5.3 | 12.0 | raineorshine | npm-check-updates | CWE-150 | npm-check-updates 23.0.2 Terminal Injection via Unsanitized Escape Sequences |
| CVE-2026-16949 | 5.8 | 11.7 | Unknown | Term Pages | CWE-89 | Term Pages < 2.0.0 - Unauthenticated SQL Injection via tp_lookup |
| CVE-2026-19278 | 6.8 | 11.5 | Red Hat | Red Hat Advanced Cluster Security 4 | CWE-625 | Stackrox: stackrox: privilege escalation via unanchored regular expressions i… |
| CVE-2026-68130 | await | 11.5 | Linux | Linux | — | ksmbd: defer destroy_previous_session() until after NTLM authentication |
| CVE-2026-68164 | await | 11.3 | Linux | Linux | — | mm/damon/core: disallow overlapping input ranges for damon_set_regions() |
| CVE-2026-68187 | await | 11.3 | Linux | Linux | — | exec: fix unsigned loop counter wrap in transfer_args_to_stack() |
| CVE-2026-68203 | await | 11.3 | Linux | Linux | — | media: vivid: fix cleanup bugs in vivid_init() |
| CVE-2026-68205 | await | 11.3 | Linux | Linux | — | media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subde… |
| CVE-2026-68207 | await | 11.3 | Linux | Linux | — | media: ti: vpe: unwind v4l2 device registration on probe error |
| CVE-2026-68212 | await | 11.3 | Linux | Linux | — | media: saa7134: Fix a possible memory leak in saa7134_video_init1 |
| CVE-2026-68214 | await | 11.3 | Linux | Linux | — | media: rtl2832: fix use-after-free in rtl2832_remove() |
| CVE-2026-68215 | await | 11.3 | Linux | Linux | — | media: radio-si476x: Unregister v4l2_device on probe failure |
| CVE-2026-68217 | await | 11.3 | Linux | Linux | — | media: pwc: Drain fill_buf on start_streaming() failure |
| CVE-2026-68218 | await | 11.3 | Linux | Linux | — | media: pci: dm1105: Free allocated workqueue |
| CVE-2026-68220 | await | 11.3 | Linux | Linux | — | media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe |
| CVE-2026-68221 | await | 11.3 | Linux | Linux | — | media: nuvoton: npcm-video: fix memory leaks in probe and remove |
| CVE-2026-68223 | await | 11.3 | Linux | Linux | — | media: meson: vdec: Fix memory leak in error path of vdec_open |
| CVE-2026-68225 | await | 11.3 | Linux | Linux | — | media: i2c: alvium: fix critical pointer access in alvium_ctrl_init |
| CVE-2026-68226 | await | 11.3 | Linux | Linux | — | media: cx23885: add ioremap return check and cleanup |
| CVE-2026-68227 | await | 11.3 | Linux | Linux | — | media: cx231xx: fix devres lifetime |
| CVE-2026-68231 | await | 11.3 | Linux | Linux | — | media: airspy: Return queued buffers on start_streaming() failure |
| CVE-2026-68251 | await | 11.3 | Linux | Linux | — | drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() |
| CVE-2026-68261 | await | 11.3 | Linux | Linux | — | drm/imagination: fix error checking of pvr_vm_context_lookup() |
| CVE-2026-68277 | await | 11.3 | Linux | Linux | — | drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers |
| CVE-2026-68339 | await | 11.3 | Linux | Linux | — | Bluetooth: btusb: validate Realtek vendor event length |
| CVE-2026-68346 | await | 11.3 | Linux | Linux | — | ALSA: hda: cs35l41: validate and free ACPI mute object |
| CVE-2026-68351 | await | 11.3 | Linux | Linux | — | wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read |
| CVE-2026-68405 | await | 11.3 | Linux | Linux | — | wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock |
| CVE-2026-68422 | await | 11.3 | Linux | Linux | — | btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() |
| CVE-2026-6791 | 6.6 | 11.1 | The GNU C Library | glibc | CWE-121 | Potential stack-based buffer clash during tilde expansion in wordexp |
| CVE-2026-68268 | await | 11.0 | Linux | Linux | — | drm/xe: Return error on non-migratable faults requiring devmem |
| CVE-2026-68270 | await | 11.0 | Linux | Linux | — | drm/sysfb: Avoid possible truncation with calculating visible size |
| CVE-2026-66408 | 5.1 | 10.7 | ECOVACS ROBOTICS | DEEBOT PRO M1 | CWE-1391 | The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with w… |
| CVE-2026-72906 | 4.3 | 10.6 | frappe | erpnext | CWE-862 | ERPNext: Unauthorised triggering of automated emails due to missing validation |
| CVE-2026-66404 | 6.0 | 10.6 | ECOVACS ROBOTICS | DEEBOT PRO M1 | CWE-295 | DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQT… |
| CVE-2026-72918 | 5.4 | 10.1 | RocketChat | Rocket.Chat | CWE-862 | Rocket.Chat: Insecure implementation of websocket notifications |
| CVE-2026-68165 | await | 10.2 | Linux | Linux | — | mm/damon/core: validate ranges in damon_set_regions() |
| CVE-2026-68169 | await | 10.2 | Linux | Linux | — | mptcp: pm: userspace: fix use-after-free in get_local_id |
| CVE-2026-68175 | await | 10.2 | Linux | Linux | — | tracing: Fix resource leak on mmiotrace trace_pipe close |
| CVE-2026-68176 | await | 10.2 | Linux | Linux | — | tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev |
| CVE-2026-68180 | await | 10.2 | Linux | Linux | — | intel_th: fix MSC output device reference leak |
| CVE-2026-68181 | await | 10.2 | Linux | Linux | — | mei: bus: access mei_device under device_lock on cleanup |
| CVE-2026-68182 | await | 10.1 | Linux | Linux | — | comedi: comedi_parport: deal with premature interrupt |
| CVE-2026-68183 | await | 10.2 | Linux | Linux | — | firmware: stratix10-svc: fix memory leaks and list corruption bugs |
| CVE-2026-68184 | await | 10.2 | Linux | Linux | — | cdrom: fix stack out-of-bounds read in CDROMVOLCTRL |
| CVE-2026-68185 | await | 10.2 | Linux | Linux | — | LoongArch: Move jump_label_init() before parse_early_param() |
| CVE-2026-68186 | await | 10.2 | Linux | Linux | — | binfmt_misc: set have_execfd only once the interpreter is opened |
| CVE-2026-68188 | await | 10.1 | Linux | Linux | — | Bluetooth: RFCOMM: Fix session UAF in set_termios |
| CVE-2026-68190 | await | 10.1 | Linux | Linux | — | staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() |
| CVE-2026-68193 | await | 10.2 | Linux | Linux | — | wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses |
| CVE-2026-68194 | await | 10.2 | Linux | Linux | — | wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses |
| CVE-2026-68195 | await | 10.2 | Linux | Linux | — | wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses |
| CVE-2026-68197 | await | 10.2 | Linux | Linux | — | wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper |
| CVE-2026-68250 | await | 10.2 | Linux | Linux | — | drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() |
| CVE-2026-68269 | await | 10.2 | Linux | Linux | — | drm/i915/gem: Add missing nospec on parallel submit slot |
| CVE-2026-68296 | await | 10.1 | Linux | Linux | — | net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM |
| CVE-2026-68304 | await | 10.1 | Linux | Linux | — | wifi: brcmfmac: fix 802.1X-SHA256 call trace warning |
| CVE-2026-68313 | await | 10.2 | Linux | Linux | — | tipc: fix infinite loop in __tipc_nl_compat_dumpit |
| CVE-2026-68321 | await | 10.2 | Linux | Linux | — | net: txgbe: fix FDIR filter leak on remove |
| CVE-2026-68322 | await | 10.1 | Linux | Linux | — | rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled |
| CVE-2026-68344 | await | 10.1 | Linux | Linux | — | usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect |
| CVE-2026-68368 | await | 10.1 | Linux | Linux | — | usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() |
| CVE-2026-68369 | await | 10.1 | Linux | Linux | — | usb: gadget: printer: fix infinite loop in printer_read() |
| CVE-2026-68378 | await | 10.1 | Linux | Linux | — | dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync() |
| CVE-2026-68386 | await | 10.1 | Linux | Linux | — | bpf, sockmap: Reject unhashed UDP sockets on sockmap update |
| CVE-2026-68395 | await | 10.1 | Linux | Linux | — | ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered |
| CVE-2026-68396 | await | 10.1 | Linux | Linux | — | scsi: core: wake eh reliably when using scsi_schedule_eh |
| CVE-2026-68410 | await | 10.2 | Linux | Linux | — | wifi: libertas: fix memory leak in helper_firmware_cb() |
| CVE-2026-18666 | 4.3 | 10.0 | Unknown | Library Management System | CWE-89 | Library Management System < 3.6.7 - Subscriber+ SQL Injection via Filter Value |
| CVE-2026-68166 | await | 9.9 | Linux | Linux | — | userfaultfd: prevent registration of special VMAs |
| CVE-2026-68168 | await | 9.9 | Linux | Linux | — | afs: Fix afs_edit_dir_remove() to get, not find, block 0 |
| CVE-2026-68174 | await | 9.9 | Linux | Linux | — | tracing: Fix union collision of module and refcnt for dynamic events |
| CVE-2026-68208 | await | 9.9 | Linux | Linux | — | media: ti: vpe: Fix the error code of devm_kzalloc() in vip_probe_slice() |
| CVE-2026-68224 | await | 9.9 | Linux | Linux | — | media: mali-c55: Fix possible ERR_PTR in enable_streams |
| CVE-2026-68232 | await | 9.9 | Linux | Linux | — | drm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict |
| CVE-2026-68235 | await | 9.9 | Linux | Linux | — | drm/amd/display: dce100: skip non-DP stream encoders for DP MST |
| CVE-2026-68241 | await | 9.9 | Linux | Linux | — | drm/i915/mst: limit DP MST ESI service loop |
| CVE-2026-68345 | await | 9.9 | Linux | Linux | — | arm_mpam: guard MBWU state before adding it to garbage |
| CVE-2026-68412 | await | 9.9 | Linux | Linux | — | wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan() |
| CVE-2026-12624 | 4.3 | 9.8 | HashiCorp | Vault | CWE-863 | Vault vulnerable to LIST authorization bypass via trailing-slash strip |
| CVE-2026-68276 | await | 9.4 | Linux | Linux | — | drm/amdgpu/gfx: fix cleaner shader IB buffer overflow |
| CVE-2026-68349 | await | 9.4 | Linux | Linux | — | wifi: carl9170: fix buffer overflow in rx_stream failover path |
| CVE-2026-68421 | await | 9.2 | Linux | Linux | — | sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx() |
| CVE-2026-71577 | 6.3 | 9.1 | Red Hat | Multicluster Global Hub | CWE-522 | Multicluster-global-hub: multicluster-global-hub: spec-topic read acl leaks b… |
| CVE-2026-68255 | 7.7 | 9.0 | Linux | Linux | — | drm/virtio: bound EDID block reads to the response buffer |
| CVE-2026-12971 | 2.2 | 8.8 | Unknown | LearnPress | CWE-918 | LearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply… |
| CVE-2026-68167 | await | 8.9 | Linux | Linux | — | btrfs: do not try compression for data reloc inodes |
| CVE-2026-68191 | await | 8.9 | Linux | Linux | — | wifi: ath12k: fix NULL pointer dereference in rhash table destroy |
| CVE-2026-68242 | await | 8.9 | Linux | Linux | — | drm/i915/gt: Fix NULL deref on sched_engine alloc failure |
| CVE-2026-68286 | await | 8.9 | Linux | Linux | — | drop_monitor: perform u64_stats updates under IRQ-disabled section |
| CVE-2026-68303 | await | 8.9 | Linux | Linux | — | drm/vc4: hvs/v3d: Fix null dereference in unbind |
| CVE-2026-68312 | await | 8.9 | Linux | Linux | — | cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths |
| CVE-2026-68358 | await | 8.8 | Linux | Linux | — | hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop |
| CVE-2026-68361 | await | 8.8 | Linux | Linux | — | hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop |
| CVE-2026-17016 | 3.7 | 8.6 | Unknown | Accept PayPal & Stripe with Subscriptions for WooCommerce | CWE-284 | Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via PDT Und… |
| CVE-2026-14238 | 4.1 | 8.5 | Unknown | vitepos | CWE-89 | Vitepos < 3.6.0 - Admin+ SQL Injection via product-details-report |
| CVE-2026-68413 | await | 8.5 | Linux | Linux | — | wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() |
| CVE-2026-72728 | 6.3 | 8.3 | discourse | discourse | CWE-20 | Discourse: Onebox iframe origin allowlist enforces URL authority boundary |
| CVE-2026-72587 | 6.1 | 8.4 | CoreBunch | Instatic | CWE-444 | Instatic - Cache Poisoning via Unauthenticated Server Island Endpoint |
| CVE-2026-72912 | 4.3 | 8.4 | gchq | CyberChef | CWE-400 | CyberChef’s pretty-recipe parser vulnerable to client-side ReDoS / CPU exhaus… |
| CVE-2026-72578 | 8.8 | 8.1 | FreePBX | FreePBX Framework | CWE-352 | FreePBX Framework - Missing CSRF Protection in Admin Panel Ajax Dispatcher |
| CVE-2026-68179 | 8.4 | 8.1 | Linux | Linux | — | misc: nsm: only unlock nsm_dev on post-lock error paths |
| CVE-2026-68371 | 8.4 | 8.1 | Linux | Linux | — | usb: musb: omap2430: Do not put borrowed of_node in probe |
| CVE-2026-15229 | 5.3 | 8.0 | Unknown | Pinpoint Booking System | CWE-863 | Pinpoint Booking System <= 2.9.9.7.1 - Unauthenticated Arbitrary Booking Pric… |
| CVE-2026-17021 | 5.3 | 8.0 | Unknown | Salon Booking System | CWE-862 | Salon Booking System – Free Version < 10.30.34 - Unauthenticated Arbitrary Bo… |
| CVE-2026-68093 | await | 7.9 | Linux | Linux | — | KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after ho… |
| CVE-2026-18934 | 5.5 | 7.7 | Unknown | RSS Aggregator by Feedzy | CWE-863 | RSS Aggregator by Feedzy < 5.2.6 - Author+ Cross-User Import Job Manipulation… |
| CVE-2026-68342 | await | 7.5 | Linux | Linux | — | ovpn: avoid putting unrelated P2P peer on socket release |
| CVE-2026-72522 | 6.2 | 7.5 | libexpat project | libexpat | CWE-125 | libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop b… |
| CVE-2026-68088 | await | 7.5 | Linux | Linux | — | usb: gadget: function: rndis: add length check to response query |
| CVE-2026-68090 | await | 7.5 | Linux | Linux | — | debugobjects: Plug race against a concurrent OOM disable |
| CVE-2026-68202 | 7.8 | 7.3 | Linux | Linux | — | ALSA: seq: close a re-opened queue timer in the destructor |
| CVE-2026-68204 | 7.8 | 7.3 | Linux | Linux | — | media: vivid: check for vb2_is_busy() when toggling caps |
Results continue: ranks 401–670.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-08-10 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.