boxscore/security
Monday, August 10, 2026 · all times UTC← 2026-08-09 · archive · 2026-08-11 →

670 CVEs published August 10, 2026: 84 critical, 252 high, 129 medium, 17 low; 0 in KEV; 6 with a public exploit reference; 188 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 645 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published27181152314012563
KEV catalog size1670

654 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux390197523312859802730.27.8.0017+377
microsoft3313941209393108378322.37.8.0040-19
google4345572134228187351.16.5.0023+43
red hat752971514312118400.07.1.0025+61
apple1245576711229372.97.1.0028+1
suse551220000.07.3.0022+5
canonical030210000.07.8.00130
android010100161100.08.4.01710
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco305092490961326.07.8.0033+30
fortinet018249028633.36.1.00540
palo alto networks015017514213.34.7.0028-10
vmware01247012100.08.7.00440
checkpoint1541003240.09.3.2062+1
f50540007120.09.2.04020
ivanti051000335100.010.0.81520
zyxel3403101100.07.2.0075+3
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache76213421125814020.97.5.0048+76
mozilla1734226501300.09.1.0031+1
gitlab015021014213.34.9.00290
github240220000.07.0.0040+2
wordpress1412105250.08.8.3700+1
docker030120100.05.7.00150
drupal01100051100.09.8.88320
kubernetes010001000.02.4.00240
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle01113212539304574030.37.6.00310
ibm321403661421710.77.5.0027+32
adobe8481623507548.38.6.0047+7
progress1134111850912.98.1.0030+11
solarwinds0201611011420.09.1.00500
veeam10123720400.08.6.0027+10
atlassian0303001300.08.0.00260
zohocorp031110000.07.1.00480
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link1523150612614.39.3.0209+15
hikvision0704202114.37.2.00250
bosch030300000.08.1.00280
schneider electric031200100.08.7.00200
synology110100000.07.3.0013+1
honeywell010010000.06.9.00310
mitsubishi electric010100000.07.1.00130
rockwell automation011000000.09.2.00300
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
surrealdb057326253000.07.1.00250
netty14262781000.07.5.0046+1
legion of the bouncy castle344152790000.08.7.0026+34
grafana041214223000.06.5.0033-4
open ises037214210000.06.9.00210
dokploy353523830000.09.9.0037+35
zephyrproject1335014165000.06.5.0018+13
mediatek343404300100.06.0.0011+34

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.993199.99.8
CVE-2026-63030.956099.99.8
CVE-2026-39808.912199.8
CVE-2026-34486.829399.67.5
CVE-2026-50522.769899.59.8
CVE-2026-15410.763599.57.2
CVE-2026-15409.742299.410.0
CVE-2026-25089.736099.49.8
CVE-2026-16232.733099.49.3
CVE-2026-60137.731099.45.9
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1540910.0.7422KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0473
CVE-2026-4766810.0.0434
CVE-2026-4435910.0.0100
CVE-2025-7138910.0.0093
CVE-2026-4816810.0.0091
CVE-2026-5616310.0.0090
CVE-2026-5710610.0.0090
CVE-2026-1681210.0.0088KEV
Most disclosures (vendor)
VendorCVEs
oracle1109
linux1044
microsoft638
google446
red hat184
apache181
apple168
ibm132
mozilla68
surrealdb57
Most KEV additions (YTD)
VendorKEV
microsoft32
cisco13
apple7
fortinet6
google5
ivanti5
adobe4
langflow4
solarwinds4
synacor4
Most-affected ecosystems
EcosystemAdvisories
Maven63
PyPI5
Go3
npm3
crates.io2
NuGet1
Packagist1
Fastest to KEV
CVEVendorDays
CVE-2008-4128Cisco0
CVE-2021-27137DD-WRT0
CVE-2023-4346KNX Association0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-18556N-able0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171727
CVE-2021-27102Accellion2021-11-171727
CVE-2021-27101Accellion2021-11-171727
CVE-2021-27103Accellion2021-11-171727
CVE-2021-21017Adobe2021-11-171727
CVE-2021-28550Adobe2021-11-171727
CVE-2021-42013Apache2021-11-171727
CVE-2021-41773Apache2021-11-171727
CVE-2021-30858Apple2021-11-171727
CVE-2021-30860Apple2021-11-171727

Transactions

EXPLOIT PUBLISHEDCVE-2021-34473 (Microsoft Exchange Server 2013 Cumulative Update 23). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2021-34523 (Microsoft Exchange Server 2013 Cumulative Update 23). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2021-34527 (Microsoft Windows 10 Version 1507). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2021-36942 (Microsoft Windows Server 2008 R2 Service Pack 1). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2021-38647 (Microsoft Azure Automation State Configuration, DSC Extension). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2021-38648 (Microsoft Azure Automation State Configuration, DSC Extension). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2021-40444 (Microsoft Windows 10 Version 1507). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2024-21338 (Microsoft Windows 10 Version 1809). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2024-21413 (Microsoft 365 Apps for Enterprise). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2024-38217 (Microsoft Windows 10 Version 1507). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10774 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-10848 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-15038 (Unknown InfiniteWP Client). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16032 (Unknown LWS Optimize). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16267 (Unknown Newsletters). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16269 (Unknown Newsletters). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16282 (Unknown Appointment Hour Booking). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16548 (Unknown Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16559 (Unknown YMC Filter). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16574 (Unknown Dokan: AI Powered WooCommerce Multivendor Marketplace Solution). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16589 (Unknown WP Directory Kit). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16608 (Unknown Download Monitor). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16948 (Unknown Solace Extra). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16953 (Unknown AI Engine). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16955 (Unknown AI Engine). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16957 (Unknown Slim SEO). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16965 (Unknown Solace Extra). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16988 (Unknown GeoDirectory). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16992 (Unknown Create). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-17011 (Unknown Nexter Blocks). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-17014 (Unknown WP Photo Album Plus). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-17017 (Unknown CubeWP Framework). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-17044 (Unknown Iptanus File Upload). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18032 (Unknown WP Data Access). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18037 (Unknown Create). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18357 (Unknown WPC Order Tip for WooCommerce). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18464 (Unknown WP MAPS PRO). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18465 (Unknown WP MAPS PRO). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18473 (Unknown WP Directory Kit). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18603 (Unknown PiWeb Cancel order / Refund request for WooCommerce). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19243 (HKUDS nanobot). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19341 (UTT HiPER 1200GW). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19342 (code-projects Task Management System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19343 (code-projects Task Management System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19344 (code-projects Task Management System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19346 (Tenda CH22). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19347 (itsourcecode Hospital Management System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19348 (Shenzhen Aitemi M300 Wi-Fi Repeater). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19352 (mifi lossless-cut). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19353 (DedeCMS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19364 (itsourcecode Hospital Management System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19373 (PhialsBasement KoboldCPP-MCP-Server). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-31842 (Tinyproxy Project Tinyproxy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-48710 (Kludex starlette). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66297 (livebook-dev livebook). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66757 (GNOME GIMP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66881 (livebook-dev livebook). Public exploit reference added.

RESCOREDCVE-2023-35384 (Microsoft Windows 10 Version 1507). CVSS 5.4 → 6.5 (NVD).

RESCOREDCVE-2023-35391 (Microsoft .NET 6.0). CVSS 6.2 → 7.5 (NVD).

RESCOREDCVE-2023-36741 (Microsoft Edge (Chromium-based)). CVSS 8.3 → 7.5 (NVD).

RESCOREDCVE-2023-36769 (Microsoft Office 2019). CVSS 4.6 → 5.4 (NVD).

RESCOREDCVE-2023-36873 (Microsoft .NET Framework 3.5 and 4.6.2). CVSS 7.4 → 5.9 (NVD).

RESCOREDCVE-2023-36897 (Microsoft 365 Apps for Enterprise). CVSS 8.1 → 6.5 (NVD).

RESCOREDCVE-2023-36903 (Microsoft Windows 10 Version 1507). CVSS 7.8 → 9.8 (NVD).

RESCOREDCVE-2023-36905 (Microsoft Windows 10 Version 1507). CVSS 5.5 → 7.5 (NVD).

RESCOREDCVE-2023-36906 (Microsoft Windows 10 Version 1507). CVSS 5.5 → 7.5 (NVD).

RESCOREDCVE-2023-36907 (Microsoft Windows 10 Version 1507). CVSS 5.5 → 7.5 (NVD).

RESCOREDCVE-2023-36913 (Microsoft Windows 10 Version 1507). CVSS 6.5 → 7.5 (NVD).

RESCOREDCVE-2023-38186 (Microsoft Windows 10 Version 21H2). CVSS 8.8 → 9.8 (NVD).

RESCOREDCVE-2024-0565 (Linux kernel). CVSS 6.8 → 7.4 (NVD).

RESCOREDCVE-2024-0775 (Linux kernel). CVSS 6.7 → 7.1 (NVD).

RESCOREDCVE-2024-21343 (Microsoft Windows 10 Version 1507). CVSS 5.9 → 7.5 (NVD).

RESCOREDCVE-2024-21416 (Microsoft Windows 10 Version 1809). CVSS 8.1 → 9.8 (NVD).

RESCOREDCVE-2024-21489 (uplot). CVSS 8.8 → 7.8 (NVD).

RESCOREDCVE-2024-37337 (Microsoft SQL Server 2017 (CU 31)). CVSS 7.1 → 4.3 (NVD).

RESCOREDCVE-2024-37341 (Microsoft SQL Server 2016 Service Pack 3 (GDR)). CVSS 8.8 → 9.8 (NVD).

RESCOREDCVE-2024-37342 (Microsoft SQL Server 2017 (CU 31)). CVSS 7.1 → 4.3 (NVD).

RESCOREDCVE-2024-37980 (Microsoft SQL Server 2016 Service Pack 3 (GDR)). CVSS 8.8 → 9.8 (NVD).

RESCOREDCVE-2024-38194 (Microsoft Azure Web Apps). CVSS 8.4 → 9.9 (NVD).

RESCOREDCVE-2024-38216 (Microsoft Azure Stack Hub). CVSS 8.2 → 9 (NVD).

RESCOREDCVE-2024-38225 (Microsoft Dynamics 365 Business Central 2023 Release Wave 1). CVSS 8.8 → 9.8 (NVD).

RESCOREDCVE-2024-38230 (Microsoft Windows Server 2012 R2). CVSS 6.5 → 7.5 (NVD).

RESCOREDCVE-2024-38231 (Microsoft Windows Server 2008 Service Pack 2). CVSS 6.5 → 7.5 (NVD).

RESCOREDCVE-2024-38240 (Microsoft Windows 10 Version 1507). CVSS 8.1 → 9.8 (NVD).

RESCOREDCVE-2024-38254 (Microsoft Windows 10 Version 1507). CVSS 5.5 → 6.2 (NVD).

RESCOREDCVE-2024-38258 (Microsoft Windows Server 2008 Service Pack 2). CVSS 6.5 → 7.5 (NVD).

RESCOREDCVE-2024-43455 (Microsoft Windows Server 2008 Service Pack 2). CVSS 8.8 → 9.8 (NVD).

RESCOREDCVE-2024-43460 (Microsoft Dynamics 365 Business Central Online). CVSS 8.1 → 8.8 (NVD).

RESCOREDCVE-2024-43474 (Microsoft SQL Server 2017 (CU 31)). CVSS 7.6 → 7.5 (NVD).

RESCOREDCVE-2024-43476 (Microsoft Dynamics 365 (on-premises) version 9.1). CVSS 7.6 → 5.4 (NVD).

RESCOREDCVE-2024-43489 (Microsoft Edge (Chromium-based)). CVSS 6.5 → 8.8 (NVD).

RESCOREDCVE-2024-43496 (Microsoft Edge (Chromium-based)). CVSS 6.5 → 8.8 (NVD).

RESCOREDCVE-2025-38525 (Linux). CVSS 7.5 → 5.5 (NVD).

RESCOREDCVE-2026-19375 (dmitriiweb article-scraper-mcp). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-19376 (Uasoft Badaso). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-19378 (code-projects Task Management System). CVSS 5.3 → 2.1 (NVD).

RESCOREDCVE-2026-48618 (nodejs node). CVSS 7.7 → 6.5 (NVD).

RESCOREDCVE-2026-8037 (Progress Software LoadMaster). CVSS 9.6 → 9.8 (NVD).

Yesterday's Results

670 CVEs published. 25 box scores and 375 table rows below; the remaining 270 continue on page 2 — every CVE is listed, nothing truncated.

Apache Ranger: OS Command Injection via Username in UnixUserGroupBuilder
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0263   84.3     —
AFFECTED
  Product        Versions  Fixed
  Apache Ranger  0.6 –     —
TIMELINE
  Mar 2   Reserved by CNA
  Aug 10  Published (CNA: apache)
CWE-77 · CNA: apache · 2 references · NVD status: Analyzed
usmannasir cyberpanel — CyberPanel 2.4.3 Authenticated Command Injection via starRemoteTransfer
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0208   79.9     —
AFFECTED
  Product     Versions     Fixed
  cyberpanel  unspecified  eca0c3cbeb35af8eaae9fafb094e8ef3cd923643
TIMELINE
  Aug 8   Reserved by CNA
  Aug 10  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 3 references · NVD status: Received
EFM ipTIME AX8004M CGI Endpoint d.cgi popen os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0166   74.6     —
AFFECTED
  Product         Versions   Fixed
  ipTIME AX8004M  15.09.0 –  —
TIMELINE
  Aug 9   Reserved by CNA
  Aug 10  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0128   67.6     —
AFFECTED
  Product     Versions     Fixed
  crontab-ui  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 10  Published (CNA: TuranSec)
CWE-93 · CNA: TuranSec · 2 references · NVD status: Received
Zyxel Networks WAH7601 — Multiple Vulnerabilities in Zyxel's WAH7601 - OS Command Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0127   67.3     —
AFFECTED
  Product  Versions     Fixed
  WAH7601  unspecified  —
TIMELINE
  Jun 24  Reserved by CNA
  Aug 10  Published (CNA: TR-CERT)
CWE-78 · CNA: TR-CERT · 1 reference · NVD status: Received
alseambusher crontab-ui - Unauthenticated RCE via Shell Injection in Imported Database hook Field
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0122   66.2     —
AFFECTED
  Product     Versions     Fixed
  crontab-ui  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 10  Published (CNA: TuranSec)
CWE-78 · CNA: TuranSec · 2 references · NVD status: Received
Apache Ranger: Remote Code Execution via JDBC URL Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0120   65.6     —
AFFECTED
  Product        Versions     Fixed
  Apache Ranger  unspecified  —
TIMELINE
  Apr 28  Reserved by CNA
  Aug 10  Published (CNA: apache)
CWE-94, CWE-20 · CNA: apache · 2 references · NVD status: Analyzed
Apache Ranger: Remote Code Execution via Arbitrary Class Instantiation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0116   64.4     —
AFFECTED
  Product        Versions     Fixed
  Apache Ranger  unspecified  —
TIMELINE
  May 6   Reserved by CNA
  Aug 10  Published (CNA: apache)
CWE-94, CWE-470 · CNA: apache · 2 references · NVD status: Analyzed
Apache Ranger: Remote Code Execution Vulnerability in GraalScriptEngineCreator
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0113   63.8     —
AFFECTED
  Product        Versions     Fixed
  Apache Ranger  unspecified  —
TIMELINE
  Jun 17  Reserved by CNA
  Aug 10  Published (CNA: apache)
CWE-94 · CNA: apache · 2 references · NVD status: Analyzed
duhow xiaoai-patch - OS Command Injection in /mute and /unmute Endpoints
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0093   57.7     —
AFFECTED
  Product       Versions     Fixed
  xiaoai-patch  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 10  Published (CNA: TuranSec)
CWE-78 · CNA: TuranSec · 2 references · NVD status: Received
4xmen pm2panel - Authenticated OS Command Injection via id Query Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0091   56.9     —
AFFECTED
  Product   Versions     Fixed
  pm2panel  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 10  Published (CNA: TuranSec)
CWE-78 · CNA: TuranSec · 2 references · NVD status: Received
NASA fprime-gds - Missing Authentication and Path Traversal Enable Unauthenticated RCE and Spacecraft Command Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0086   55.3     —
AFFECTED
  Product     Versions     Fixed
  fprime-gds  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 10  Published (CNA: TuranSec)
CWE-306 · CNA: TuranSec · 4 references · NVD status: Received
o1lab xmysql - Unauthenticated Path Traversal via name Query Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0077   52.6     —
AFFECTED
  Product  Versions     Fixed
  xmysql   unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 10  Published (CNA: TuranSec)
CWE-22 · CNA: TuranSec · 2 references · NVD status: Received
mustafaakin cast-localvideo - Unauthenticated Path Traversal via dir Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0077   52.5     —
AFFECTED
  Product          Versions     Fixed
  cast-localvideo  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 10  Published (CNA: TuranSec)
CWE-22 · CNA: TuranSec · 2 references · NVD status: Received
Apache Ranger: Privilege Escalation via URL Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0073   51.3     —
AFFECTED
  Product        Versions     Fixed
  Apache Ranger  unspecified  —
TIMELINE
  Apr 15  Reserved by CNA
  Aug 10  Published (CNA: apache)
CWE-269, CWE-20, CWE-287 · CNA: apache · 2 references · NVD status: Analyzed
Red Hat Red Hat OpenShift AI 2.25 — Feast: feast: unsafe dill deserialization of registry-stored udfs — rce on feature server and registry server
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0069   49.8     —
AFFECTED
  Product                       Versions     Fixed
  Red Hat OpenShift AI 2.25     unspecified  1786110051
  Red Hat OpenShift AI 3.3      unspecified  1786110033
  Red Hat OpenShift AI 3.4      unspecified  1786107278
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  Red Hat OpenShift AI (RHOAI)  unspecified  —
  + 6 more
TIMELINE
  Aug 5   Reserved by CNA
  Aug 10  Published (CNA: redhat)
CWE-502 · CNA: redhat · 5 references · NVD status: Awaiting Analysis
Linux Linux — ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0068   49.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    a8599bd821d084d04a3290fffae1071624ec00ea –  —
  Linux    2.6.34 –                                    6.6.148
TIMELINE
  Jul 30  Reserved by CNA
  Aug 10  Published (CNA: Linux)
CNA: Linux · 5 references · NVD status: Received
NASA HyperCP - OS Command Injection via Malicious HTTP Response from Data Server
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   R  U  H  H  H    7.5   .0065   48.0     —
AFFECTED
  Product  Versions     Fixed
  HyperCP  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 10  Published (CNA: TuranSec)
CWE-78 · CNA: TuranSec · 2 references · NVD status: Received
Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   N   H   H    7.0   .0064   47.9     —
AFFECTED
  Product                  Versions     Fixed
  sucuri-wordpress-plugin  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 10  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · 2 references · NVD status: Received
Apache Ranger: SQL Injection vulnerability in lookup functionality
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0064   47.7     —
AFFECTED
  Product        Versions     Fixed
  Apache Ranger  unspecified  —
TIMELINE
  Mar 11  Reserved by CNA
  Aug 10  Published (CNA: apache)
CWE-89 · CNA: apache · 2 references · NVD status: Analyzed
Dokploy: Remote Code Execution via volume-backup
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0063   47.5     —
AFFECTED
  Product  Versions     Fixed
  dokploy  < 0.29.13 –  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 10  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 4 references · NVD status: Received
Apache Ranger: Download APIs expose plugin data without authentication
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0063   47.2     —
AFFECTED
  Product        Versions     Fixed
  Apache Ranger  unspecified  —
TIMELINE
  Jun 17  Reserved by CNA
  Aug 10  Published (CNA: apache)
CWE-306 · CNA: apache · 2 references · NVD status: Analyzed
Linux Linux — libceph: reject zero bucket types in crush_decode
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0063   47.1     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    f24e9980eb860d8600cbe5ef3d2fd9295320d229 –  —
  Linux    2.6.34 –                                    6.6.148
TIMELINE
  Jul 30  Reserved by CNA
  Aug 10  Published (CNA: Linux)
CNA: Linux · 5 references · NVD status: Received
Linux Linux — libceph: Fix multiplication overflow in decode_new_up_state_weight()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0063   47.1     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    930c532869774ebf8af9efe9484c597f896a7d46 –  —
  Linux    4.7 –                                       6.6.148
TIMELINE
  Jul 30  Reserved by CNA
  Aug 10  Published (CNA: Linux)
CNA: Linux · 5 references · NVD status: Received
Linux Linux — sctp: close UDP tunnel sockets during netns teardown
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0063   47.1     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    046c052b475e7119b6a30e3483e2888fc606a2f8 –  —
  Linux    5.11 –                                      6.6.151
TIMELINE
  Jul 30  Reserved by CNA
  Aug 10  Published (CNA: Linux)
CNA: Linux · 5 references · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-659456.546.3Apache Software FoundationApache RangerCWE-532Apache Ranger: Logs contain replayable JWT bearer tokens
CVE-2026-683797.546.3LinuxLinuxtcp: fix TIME_WAIT socket reference leak on PSP policy failure
CVE-2026-681569.846.3LinuxLinuxlibceph: refresh auth->authorizer_buf{,_len} after authorizer update
CVE-2026-681557.546.0LinuxLinuxlibceph: Reject monmaps advertising zero monitors
CVE-2026-681577.546.0LinuxLinuxlibceph: guard missing CRUSH type name lookup
CVE-2026-6691510.045.9fabrikar.comFabrik extension for JoomlaCWE-94Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fa…
CVE-2026-727359.945.8DokploydokployCWE-77Dokploy: Command injection in writeTraefikConfigRemote via shell interpolatio…
CVE-2026-659487.345.5Apache Software FoundationApache RangerCWE-307Apache Ranger: UnixAuth lacks brute-force protection
CVE-2026-189417.745.4Red HatRed Hat OpenShift AI 2.25CWE-306Feast: feast-operator: feast: default authentication mode is no_auth — shared…
CVE-2026-728850.044.8DokploydokployCWE-78Dokploy: Authenticated Command Injection in Dokploy Dockerfile Builder
CVE-2026-107548.644.7PegasystemsPega InfinityCWE-347Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper valid…
CVE-2026-189518.844.6Red HatRed Hat OpenShift AI 3.3CWE-284Odh-training-operator-rhel9: [trainer v2 security] trn-02: rhoai overlay aggr…
CVE-2026-7289910.044.3MetabaseMetabaseCWE-89Metabase SQL injection via public card or dashboard
CVE-2026-683418.844.2LinuxLinuxovpn: fix use after free in unlock_ovpn()
CVE-2026-446307.544.2Apache Software FoundationApache IoTDBCWE-400Apache IoTDB: RPC service denial of service via unchecked Thrift string length
CVE-2026-659427.544.2Apache Software FoundationApache RangerCWE-297Apache Ranger: Clients accept TLS certificates issued for other hostnames
CVE-2026-681599.843.6LinuxLinuxlibceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE
CVE-2026-691188.743.6cachethqcachetCWE-863Cachet 2.4.1 Authenticated Server-Side Template Injection RCE
CVE-2026-725679.843.5AsyncFuncAIdeepwiki-openCWE-22deepwiki-open - Unauthenticated Path Traversal Leading to Arbitrary File Writ…
CVE-2026-729029.942.9DokploydokployCWE-78Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / r…
CVE-2026-728758.842.9DokploydokployCWE-78Dokploy: Remote Code Execution (RCE) via Command Injection in settings.readTr…
CVE-2026-186187.542.9Red HatRed Hat OpenShift AI 2.25CWE-770Ml-metdata: bundled grpc 1.46.3 (2022) with published http/2 dos cves — direc…
CVE-2026-725929.842.7dullduskphpfmCWE-434dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP F…
CVE-2026-683009.842.4LinuxLinuxsctp: auth: verify auth requirement when auth_chunk is NULL
CVE-2026-725939.842.2dullduskphpfmCWE-306dulldusk phpfm - Missing Authentication by Default Allows Full Filesystem Access
CVE-2026-727389.941.9DokploydokployCWE-78Dokploy: Authenticated RCE via Command Injection in backup.listBackupFiles se…
CVE-2026-727409.941.9DokploydokployCWE-78Dokploy: OS Command Injection via SSH-form `customGitUrl` domain in `ssh-keys…
CVE-2026-681709.841.5LinuxLinuxmptcp: fix stale skb->sk reference on subflow close
CVE-2026-725699.141.4cube-rootdirectory-serveCWE-22cube-root directory-serve - Unauthenticated Path Traversal Arbitrary File Del…
CVE-2025-156838.841.0TBEATBEA TLogger (TBEA Communication Box 3rd Generation)CWE-121Multiple Unauthenticated Denial-of-Service Conditions
CVE-2026-664058.741.0ECOVACS ROBOTICSDEEBOT PRO M1CWE-489DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The teln…
CVE-2026-726887.540.6OpenSignLabsopensignserverCWE-306OpenSignLabs opensignserver - Missing Authentication for Critical Function
CVE-2026-681239.840.4LinuxLinuxopenvswitch: fix GSO userspace truncation underflow
CVE-2026-681369.840.4LinuxLinuxnet: gro: fix double aggregation of flush-marked skbs
CVE-2026-683859.840.4LinuxLinuxs390/checksum: Fix csum_partial() without vector facility
CVE-2026-189828.840.2Red HatRed Hat OpenShift AI 2.25CWE-250Odh-training-operator-rhel9: rhoai fork aggregates training job create onto n…
CVE-2025-302418.640.1TP-Link Systems Inc.HB810(US2) V1.0/1.6/2.0/2.6CWE-78OS Command Injection in Web Interface in Multiple TP-Link Aginet Devices
CVE-2026-728679.940.0DokploydokployCWE-20Dokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated …
CVE-2026-481599.339.9dai-shiuse-reducer-asyncCWE-506use-reducer-async was vulnerable to malicious code execution via compromised …
CVE-2026-682877.539.8LinuxLinuxdrop_monitor: fix size calculations for 64-bit attributes
CVE-2026-683439.139.6LinuxLinuxsmb: client: validate DFS referral PathConsumed
CVE-2026-727339.939.5DokploydokployCWE-78Dokploy: OS Command Injection via `databaseName` / `backupFile` in database r…
CVE-2026-681279.839.5LinuxLinuxila: reload IPv6 header after pskb_may_pull in checksum adjust
CVE-2026-681379.839.5LinuxLinuxnet/x25: fix use-after-free in x25_kill_by_neigh()
CVE-2026-681449.839.5LinuxLinuxphonet: pep: fix use-after-free in pep_get_sb()
CVE-2025-156819.239.3TBEATBEA TLogger (TBEA Communication Box 3rd Generation)CWE-306Insufficient Webserver Authentication
CVE-2026-680967.539.0LinuxLinuxaudit: fix recursive locking deadlock in audit_dupe_exe()
CVE-2026-728816.439.0DokploydokployCWE-78Dokploy: Command Injection via database credentials in backup/restore commands
CVE-2026-681179.838.8LinuxLinuxtipc: clear sock->sk on the failed-insert path in tipc_sk_create()
CVE-2026-728769.938.6DokploydokployCWE-78Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server…
CVE-2026-725659.838.6TencentAPIJSONCWE-89Tencent APIJSON - Unauthenticated SQL Injection via @having Operator Map-Form…
CVE-2026-681297.538.4LinuxLinuxgve: fix Rx queue stall on alloc failure
CVE-2026-681317.538.4LinuxLinuxrbd: Reset positive result codes to zero in object map update path
CVE-2026-681417.538.4LinuxLinuxnet/af_iucv: fix NULL deref in afiucv_hs_callback_syn()
CVE-2026-683819.838.2LinuxLinuxksmbd: pin conn during async oplock break notification
CVE-2026-683889.838.2LinuxLinuxsmb/client: handle overlapping allocated ranges in fallocate
CVE-2026-190899.838.2UnknownProduct Input Fields for WooCommerceCWE-434Product Input Fields for WooCommerce < 2.0.2 - Unauthenticated Arbitrary File…
CVE-2026-729147.537.7mastodonmastodonCWE-405Mastodon: Exhausting data by an unauthenticated request to the admin retentio…
CVE-2026-144509.937.5Red HatRed Hat OpenShift AI 3.4CWE-290Maas-billing: maas api: privilege escalation via forged http headers due to m…
CVE-2026-683029.837.4LinuxLinuxamt: re-read skb header pointers after every pull
CVE-2026-186178.837.2Red HatRed Hat OpenShift AI 2.25CWE-915Data-science-pipelines-operator: dspo: mysql dsn parameter injection via cust…
CVE-2026-719628.737.3FlowiseAIFlowiseCWE-862Flowise 2.2.4 - 3.1.4 Missing Authorization via openai-assistants-file/download
CVE-2026-680839.137.1LinuxLinuxksmbd: fix path resolution in ksmbd_vfs_kern_path_create
CVE-2026-681207.537.1LinuxLinuxrtase: Workaround for TX hang caused by hardware packet parsing
CVE-2026-682997.537.1LinuxLinuxvmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets
CVE-2026-683157.537.1LinuxLinuxsctp: validate stream count in sctp_process_strreset_inreq()
CVE-2026-727396.537.0DokploydokployCWE-78Dokploy: Command Injection via Compose Shell Execution
CVE-2026-186088.736.3Red HatRed Hat OpenShift AI 2.25CWE-250Data-science-pipelines-operator: dspo: operator clusterrole grants pods/exec:…
CVE-2026-727369.936.1DokploydokployCWE-77Dokploy: OS Command Injection in registry credential testing and Swarm cluste…
CVE-2026-728629.936.1DokploydokployCWE-78Dokploy: OS Command Injection via dockerImage field in database service deplo…
CVE-2026-664038.736.0ECOVACS ROBOTICSDEEBOT PRO M1CWE-489DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purpose…
CVE-2026-189478.536.0Red HatRed Hat OpenShift AI 2.25CWE-862Feast: feast: authorization bypass in /materialize endpoints enables dos via …
CVE-2026-727215.335.7discoursediscourseCWE-178Discourse: Onebox Domain Blocklist Bypass via Case-Sensitive Comparison
CVE-2026-728848.735.5DokploydokployCWE-78Dokploy: Command Injection via Compose Custom Command
CVE-2026-683768.135.3LinuxLinuxsctp: fix auth_hmacs array size in struct sctp_cookie
CVE-2026-481619.334.9dai-shireact18-useCWE-506react18-use was vulnerable to malicious code execution via compromised commits
CVE-2026-194046.534.7Red HatRed Hat Directory Server 11CWE-862389-ds-base: 389-ds-base: missing authorization allows anonymous clients to s…
CVE-2026-189498.834.6Red HatRed Hat OpenShift AI 2.25CWE-250Odh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets…
CVE-2026-680978.834.6LinuxLinuxksmbd: validate ACE size against SID sub-authorities
CVE-2026-680988.834.6LinuxLinuxksmbd: bound DACL dedup walk to copied ACEs
CVE-2026-618997.534.5Apache Software FoundationApache TapestryCWE-200Apache Tapestry: Possible classpath file download through URL manipulation
CVE-2026-727196.734.2chatwootchatwootCWE-915Chatwoot: Cross-Account Resource Transfer via `account_id` Parameter
CVE-2026-169858.833.8UnknownSqueezeCWE-434Squeeze < 1.7.12 - Author+ Arbitrary File Upload
CVE-2026-681968.333.7LinuxLinuxwifi: wilc1000: validate assoc response length before subtracting header
CVE-2026-683528.333.7LinuxLinuxwifi: ath6kl: fix OOB read from firmware IE lengths in connect event
CVE-2026-681008.133.6LinuxLinuxksmbd: validate num_subauth when copying ACE in set_ntacl_dacl
CVE-2026-728779.633.4DokploydokployCWE-78Dokploy: Command Injection via dockerImage in buildRemoteDocker
CVE-2025-132949.333.3TBEATBEA TLogger (TBEA Communication Box 3rd Generation)CWE-89Unauthenticated SQL Injection
CVE-2026-728838.833.3DokploydokployCWE-862Dokploy: WebSocket Terminal Missing Service-Level Access Control
CVE-2026-667387.733.2SPIPSPIPCWE-94SPIP < 4.4.18 Code Injection via Navigation Endpoint on SQLite
CVE-2026-649408.833.0Nishishi FactoryTegalog -Fumy Otegaru Memo Logger-CWE-625Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vu…
CVE-2026-681928.833.0LinuxLinuxwifi: brcmfmac: make release_scratchbuffers idempotent
CVE-2026-681998.833.0LinuxLinuxwifi: ath6kl: fix OOB access from firmware ADDBA window size
CVE-2026-131707.233.0UnknownEventinCWE-22Eventin < 4.1.20 - Editor+ Local File Inclusion via speaker_template Setting
CVE-2026-481589.332.8dai-shiuse-context-selectorCWE-506use-context-selector was vulnerable to malicious code execution via compromis…
CVE-2026-481609.332.8dai-shireact-trackedCWE-506react-tracked was vulnerable to malicious code execution via compromised commits
CVE-2025-156828.732.8TBEATBEA TLogger (TBEA Communication Box 3rd Generation)CWE-770Unauthenticated Resource Exhaustion
CVE-2026-186117.532.8Red HatRed Hat OpenShift AI 2.25CWE-338Data-science-pipelines-operator: dspo: cryptographically weak secret generati…
CVE-2026-726917.532.5OpenSignLabsopensignserverCWE-288OpenSignLabs opensignserver - Authentication Bypass
CVE-2026-664116.932.2ECOVACS ROBOTICSDEEBOT PRO M1CWE-303DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algor…
CVE-2026-713925.332.2GNUEmacsCWE-190Integer Overflow in GNU Emacs for Android
CVE-2026-713935.332.2GNUEmacsCWE-190Heap Buffer Overflow in GNU Emacs for Android
CVE-2026-727235.331.6discoursediscourseCWE-862Discourse: Anonymous sidebar serialization exposes descriptions of category-r…
CVE-2026-681188.231.5LinuxLinuxtcp: challenge ACK for non-exact RST in SYN-RECEIVED
CVE-2026-729119.931.5frappeerpnextCWE-1336ERPNext: Possibility of server-side template injection due to missing validation
CVE-2026-154678.131.3Red HatRed Hat OpenShift AI 2.25CWE-266Trustyai-service-operator: trustyai-service-operator: lmevaljob sidecar conta…
CVE-2026-725759.130.6daptindaptinCWE-284daptin - Authentication Bypass via Null Owner Permission Check on usergroup O…
CVE-2026-730307.230.6frostmingunearthCWE-22unearth 0.18.2 Path Traversal via Unnormalized Paths and Symlink Escape
CVE-2026-682838.830.5LinuxLinuxtracing: Fix use-after-free freeing trigger private data
CVE-2026-681197.530.4LinuxLinuxtcp: initialize standalone TCP-AO response padding
CVE-2026-728729.930.3DokploydokployCWE-78Dokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone`
CVE-2025-132939.330.2TBEATBEA TLogger (TBEA Communication Box 3rd Generation)CWE-798Backdoor / default root credentials
CVE-2026-725867.529.9frangoteamFUXACWE-306frangoteam FUXA - Missing Authentication on DAQ_QUERY Socket.IO Event Handler
CVE-2026-684269.829.8LinuxLinuxxfrm: fix stale skb->prev after async crypto steals a GSO segment
CVE-2026-728689.929.4DokploydokployCWE-78Dokploy: Member-role RCE as host root via destination.testConnection rclone s…
CVE-2026-725818.629.4duhowxiaoai-patchCWE-918duhow xiaoai-patch - Server-Side Request Forgery in /auth Endpoint
CVE-2026-727616.929.3vulnerability-lookupvulnerability-lookupCWE-918Webhook SSRF guard bypassed by IPv6 transition addresses (NAT64/6to4/Teredo p…
CVE-2026-728869.929.2DokploydokployCWE-269Dokploy: Non-admin member gains root on the host by bypassing the owner/admin…
CVE-2026-189508.829.2Red HatRed Hat OpenShift AI 2.25CWE-269Odh-dashboard: odh-dashboard: confused-deputy privilege escalation via unchec…
CVE-2026-480487.529.1xwikixwiki-platformCWE-359XWiki Platform's Livetable results still allow reconstructing password hashes…
CVE-2026-210755.329.0Samsung MobileMy GalaxyCWE-939Improper authorization in handler for custom URL scheme in My Galaxy prior to…
CVE-2026-729166.329.0mastodonmastodonCWE-918Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses
CVE-2026-728829.928.6DokploydokployCWE-78Dokploy: Authenticated blind command injection via file mounts leads to direc…
CVE-2026-137178.828.6Red HatRed Hat OpenShift AI 3.4CWE-284Rhoai maas: llm-d: maas/llm-d inference gateway: default allowedroutes.namesp…
CVE-2026-728748.728.5DokploydokployCWE-78Dokploy: Command Injection via Unescaped Git URL in Clone Commands
CVE-2026-728659.928.2DokploydokployCWE-78Dokploy: OS Command Injection via compose `composePath`
CVE-2026-728699.928.2DokploydokployCWE-77Dokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (…
CVE-2026-184129.128.0OpenCartOpenCartThe OpenCart v4.2.0.0 extension installer contains a directory traversal vuln…
CVE-2026-186217.628.0Red HatRed Hat OpenShift AI 2.25CWE-266Data-sciences-pipeline: dsp: v1 argo template path accepts arbitrary workflow…
CVE-2026-725827.527.7fastschemafastschemaCWE-476fastschema - Unauthenticated NULL Pointer Dereference DoS in Account Recovery…
CVE-2026-719658.727.5usmannasircyberpanelCWE-345CyberPanel 2.4.3 Authenticated RCE via Remote Backup Feature
CVE-2026-681249.627.4LinuxLinuxmctp: serial: handle zero-length frames to prevent rx buffer overflow
CVE-2026-162989.827.2UnknownFoodBoxBookerCWE-269FoodBoxBooker < 1.0.7 - Unauthenticated Arbitrary Password Reset
CVE-2026-162999.827.2UnknownSingle Sign On For TNGCWE-287Single Sign On For TNG < 2.2.0 - Unauthenticated Arbitrary Password Reset
CVE-2026-136008.127.1UnknownAutoNetTV RelayCWE-287AutoNetTV Relay < 3.0.14 - Unauthenticated Privilege Escalation via Scheduled…
CVE-2026-706227.127.1composefstar-rsCWE-59tar-rs 0.4.11 - 0.4.46 Symlink Escape via append_dir_all()
CVE-2026-649412.127.1phoenixframeworkphoenix_live_viewCWE-601Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR
CVE-2026-477549.326.7NCEASmetacatCWE-22unauthenticated path traversal in Metacat 2.x
CVE-2026-727266.526.0discoursediscourseCWE-200Discourse: Unauthorized eavesdropping on private AI bot conversations.
CVE-2026-728736.526.0DokploydokployCWE-200Dokploy: Cross-tenant Git provider secrets are disclosed to low-privileged se…
CVE-2026-210616.026.1Samsung MobileSamsung Mobile DevicesCWE-20Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 a…
CVE-2026-166269.325.9JaspersoftJasperReports ServerCWE-611JasperReports Server: XXE Injection Vulnerability (Unauthenticated)
CVE-2026-664077.725.8ECOVACS ROBOTICSDEEBOT PRO M1CWE-327DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in Web…
CVE-2026-118107.525.8zephyrprojectzephyrCWE-476NULL-pointer dereference in UpdateHub OTA agent on empty inner metadata array…
CVE-2026-688716.525.7Apache Software FoundationApache Airflow Yandex providerCWE-639Apache Airflow Yandex provider: yandex Lockbox backend: team-scope guard bypa…
CVE-2026-688726.525.7Apache Software FoundationApache Airflow Amazon providerCWE-639Apache Airflow Amazon provider: amazon SSM / Secrets Manager backends: team-s…
CVE-2026-713915.325.5GNUEmacsCWE-193Off-by-One Error in GNU Emacs for Android
CVE-2026-664096.925.3ECOVACS ROBOTICSDEEBOT PRO M1CWE-1391DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for the…
CVE-2026-726897.525.2OpenSignLabsopensignserverCWE-639OpenSignLabs opensignserver - Broken Object Level Authorization
CVE-2026-727224.325.2discoursediscourseCWE-862Discourse: Duplicate lookup reveals restricted topic titles through canonical…
CVE-2026-727244.325.2discoursediscourseCWE-639Discourse: Private Chat Threat Message Disclosure via Chat Onebox Channel/Thr…
CVE-2026-186207.124.8Red HatRed Hat OpenShift AI 2.25CWE-639Data-sciences-pipeline: user-controlled serviceaccount for workflow pods with…
CVE-2026-719647.124.5usmannasircyberpanelCWE-59CyberPanel 2.4.3 Arbitrary File Read via File Manager ZIP Upload
CVE-2026-142067.524.3UnknownHT Contact FormCWE-200HT Contact Form < 2.9.3 - Unauthenticated Saved Form Draft Data Disclosure
CVE-2026-175417.524.3UnknownFile ManagerCWE-200Bit File Manager < 6.9.1 - Unauthenticated File Activity Log Disclosure
CVE-2026-184707.524.3UnknownLogin & Register FormsCWE-200Login & Register Forms < 4.0.2 - Unauthenticated Registered User Email Addres…
CVE-2026-572796.024.3Cybozu, IncCybozu GaroonCWE-79Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerab…
CVE-2026-725649.624.1fosrlPangolinCWE-639fosrl Pangolin - Access Token Scope Bypass Allows Cross-Resource Authentication
CVE-2026-729038.123.8EugenytabbyCWE-22Tabby: Windows SFTP path traversal allows a malicious server to write files o…
CVE-2026-681258.823.6LinuxLinuxmac802154: llsec: reject frames shorter than the authentication tag
CVE-2026-123396.923.7TP-Link Systems Inc.TL-MR6400 v5.3CWE-22Authenticated Arbitrary File Write Vulnerability in multiple devices
CVE-2026-164566.523.6Red HatRed Hat OpenShift AI 2.25CWE-441Odh-model-controller: odh-model-controller: cross-namespace secret read via n…
CVE-2026-728668.823.4DokploydokployCWE-862WebSocket Terminal Auth Bypass
CVE-2026-590908.423.5Red HatRed Hat Enterprise Linux 6CWE-191Gimp: gimp: arbitrary code execution in psd plugin due to unsigned underflow
CVE-2026-189425.523.4Red HatRed Hat OpenShift AI 2.25CWE-94Feast-operator: feast: feast apply cronjob runs user python with feature-serv…
CVE-2026-175427.522.8UnknownFile ManagerCWE-200Bit File Manager < 6.9.1 - Subscriber+ Sensitive Data Disclosure via bitapps_…
CVE-2026-190498.622.6UnknownProSolution WP ClientCWE-89ProSolution WP Client < 2.0.9 - Unauthenticated SQLi and Plugin Data Deletion…
CVE-2026-729007.122.6MetabaseMetabaseCWE-862Metabase information exposure
CVE-2026-727206.422.4discoursediscourseCWE-79Discourse: HTML injection in PrettyText.format_for_email from cooked-attribut…
CVE-2026-728639.922.4DokploydokployCWE-269Dokploy: Missing authorization in WebSocket handlers allows a low-privilege m…
CVE-2026-728809.922.4DokploydokployCWE-78Dokploy: Arbitrary File Write + Remote OS Command Injection via `certificateP…
CVE-2026-727348.422.2DokploydokployCWE-639Dokploy: Cross-organization authorization bypass in server.remove allows dele…
CVE-2026-728717.521.9DokploydokployCWE-306Dokploy: Unauthenticated Git Provider Injection via GitHub OAuth Callback
CVE-2026-631069.321.7RazinsoftReady eCommerceCWE-89ReadyEcommerce < 4.5.2 Unauthenticated SQL Injection via ProductController.php
CVE-2026-175408.821.6UnknownFile ManagerCWE-284Bit File Manager < 6.9.1 - Subscriber+ Arbitrary File Read and Deletion via C…
CVE-2026-719596.921.4bitwardenserverCWE-862Bitwarden Server < 2026.7.2 Audit Log Injection via POST /collect
CVE-2026-729049.321.3firecrawlfirecrawlCWE-77Firecrawl: Arbitrary file read via JSON Schema $ref expansion
CVE-2026-187868.821.2UnknownCheckViewCWE-287CheckView < 2.3.2 - Administrator Account Creation via REST API Authenticatio…
CVE-2026-729086.521.2frappeerpnextCWE-89ERPNext: Possibility of SQL injection due to missing validation
CVE-2026-727596.920.7mispcti-transmuteCWE-862cti-transmute Conversion History Authorization Bypass Leads to Sensitive Data…
CVE-2026-184785.120.6Magnolia DXPMagnolia CMSCWE-79Stored XSS in Magnolia CMS
CVE-2026-683538.120.5LinuxLinuxwifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler
CVE-2026-180308.120.4UnknownBricksForgeCWE-862Bricksforge < 3.1.8.8 - Unauthenticated Arbitrary Password Reset via Pro Forms
CVE-2026-184688.120.4UnknownLogin & Register FormsCWE-287Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Passwor…
CVE-2026-184698.120.4UnknownLogin & Register FormsCWE-287Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Passwor…
CVE-2026-713945.320.4GNUEmacsCWE-1284Heap Use of Uninitialized Memory in GNU Emacs for Android
CVE-2026-728799.420.3DokploydokployCWE-78Dokploy: Command Injection via Registry Credentials in Swarm Upload
CVE-2026-728708.720.3DokploydokployCWE-78Dokploy: Command Injection via Docker Credentials in buildRemoteDocker
CVE-2026-727292.020.3discoursediscourseCWE-79Discourse: Stored XSS in discourse-local-dates plugin
CVE-2026-729157.520.2mastodonmastodonCWE-200Mastodon: Personally-identifying information disclosure due to incorrect acce…
CVE-2026-691147.120.2Spacebar ServerSpacebar ServerCWE-639Spacebar Server Cross-Channel Message Deletion via Permission Check Bypass
CVE-2026-142938.820.0UnknownAutopayCWE-79Autopay / Blue Media for WooCommerce < 5.0.1 - Unauthenticated Stored XSS via…
CVE-2026-683548.820.0LinuxLinuxfirewire: net: Fix fragmented datagram reassembly
CVE-2026-729107.119.9frappeerpnextCWE-862ERPNext: Unauthorised modification of master data due to missing validation
CVE-2026-728649.919.8DokploydokployCWE-862Dokploy Broken Access Control on docker-container-terminal WebSocket (Member …
CVE-2026-118093.719.7zephyrprojectzephyrCWE-125UpdateHub probe: uninitialized-heap out-of-bounds read of network-supplied me…
CVE-2026-726927.519.6OpenSignLabsopensignserverCWE-862OpenSignLabs opensignserver - Missing Authorization
CVE-2026-725917.719.3gabehfKoitoCWE-918Koito - Authenticated Server-Side Request Forgery via Album Image URL Parameter
CVE-2026-729097.119.1frappeerpnextCWE-284ERPNext: Broken Access Control on certain endpoints
CVE-2026-681408.819.0LinuxLinuxnet/iucv: fix use-after-free of a severed iucv_path
CVE-2026-681988.819.0LinuxLinuxwifi: ath6kl: fix use-after-free in aggr_reset_state()
CVE-2026-683738.119.0LinuxLinuxwifi: at76c50x-usb: avoid length underflow in at76_guess_freq()
CVE-2026-729175.919.0Mintplex-Labsanything-llmCWE-180AnythingLLM: Password recovery accepts one recovery code twice after whitespa…
CVE-2026-727515.119.0mispcti-transmuteCWE-79Stored Cross-Site Scripting in CTI-Transmute Conversion Graph via Malicious S…
CVE-2026-728789.618.9DokploydokployCWE-78Dokploy: OS Command Injection in backup/restore pipeline via unescaped user-c…
CVE-2026-680918.818.5LinuxLinuxHID: wacom: stop hardware after post-start probe failures
CVE-2026-193845.518.2SourceCodesterSimple Doctors Appointment SystemCWE-74SourceCodester Simple Doctors Appointment System ajax.php set_appointment sql…
CVE-2026-193897.117.9Red HatRed Hat Enterprise Linux 10CWE-190Gstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflo…
CVE-2026-684027.117.8LinuxLinuxwifi: cfg80211: bound element ID read when checking non-inheritance
CVE-2026-725667.717.6automatischautomatischCWE-918automatisch - Server-Side Request Forgery via HTTP Request Custom Action
CVE-2026-683268.817.5LinuxLinuxwifi: mwifiex: bound uAP association event IEs to the event buffer
CVE-2026-683898.817.5LinuxLinuxBluetooth: hci_qca: Clear memdump state on invalid dump size
CVE-2026-683978.817.5LinuxLinuxnet/iucv: take a reference on the socket found in afiucv_hs_rcv()
CVE-2026-142377.217.5UnknownviteposCWE-269Vitepos < 3.6.0 - Outlet Manager+ Privilege Escalation
CVE-2026-170227.517.4UnknownSalon Booking SystemCWE-200Salon Booking System – Free Version < 10.30.34 - Unauthenticated Booking Info…
CVE-2026-189467.517.4UnknownContact Form to Any APICWE-200Contact Form to Any API < 3.0.7 - Unauthenticated Sensitive File Disclosure v…
CVE-2026-129848.217.2Zyxel NetworksWAH7601CWE-522Exposure of Sensitive Information to an Unauthorized Actor in Zyxel's WAH7601
CVE-2026-162578.217.2UnknownArvow AI SEO WriterCWE-287Arvow AI SEO Writer < 1.5.4 - Unauthenticated Arbitrary Post Creation via Web…
CVE-2026-684257.117.2LinuxLinuxIB/mad: Drop unmatched RMPP responses before reassembly
CVE-2026-726907.117.1AttendizeAttendizeCWE-639Attendize Attendize - Cross-Tenant Authorization Bypass
CVE-2026-194338.616.9RoskusProspero Flow CRMCWE-639Authorization Bypass Through User-Controlled Key in Prospero Flow CRM contact…
CVE-2026-155818.016.8Red HatRed Hat OpenShift AI 2.25CWE-306Trustyai-service-operator: trustyai-service-operator: tas internal service by…
CVE-2026-118113.716.9zephyrprojectzephyrCWE-772Socket file-descriptor leak in UpdateHub OTA client start_coap_client() leadi…
CVE-2026-680858.016.7LinuxLinuxBluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled
CVE-2026-725885.316.7bluewave-labsCheckmateCWE-204bluewave-labs Checkmate - User Enumeration via Differential HTTP Response in …
CVE-2026-727324.316.7discoursediscourseCWE-862Discourse: Templates endpoint exposes hidden tag names
CVE-2026-727379.616.3DokploydokployCWE-639Dokploy: Cross-organization IDOR in Dokploy backup destinations exposes anoth…
CVE-2026-725847.416.1fastschemafastschemaCWE-367fastschema - TOCTOU Race Condition Bypasses OTP Attempt Limit in Account Reco…
CVE-2026-729076.516.2frappeerpnextCWE-285ERPNext: Broken Access Control on certain endpoint
CVE-2026-193877.615.8Red HatRed Hat Enterprise Linux 10CWE-787Gstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write i…
CVE-2026-691165.315.8xpf0000FlyEnvCWE-79FlyEnv < 4.18.0 Cross-Site Scripting via v-html
CVE-2026-683938.815.6LinuxLinuxBluetooth: hci_sync: extend conn_hash lookup critical sections
CVE-2026-684098.815.6LinuxLinuxwifi: mac80211: defer link RX stats percpu free to RCU
CVE-2026-190539.115.5UnknownProSolution WP ClientCWE-89ProSolution WP Client < 2.0.6 - Unauthenticated Blind SQLi via 'jobID' Parameter
CVE-2026-725746.115.5picocmsPicoCWE-644picocms Pico - Host Header Injection Enables Script Source Hijacking
CVE-2026-148868.215.3HashiCorpVault EnterpriseCWE-862Vault Enterprise vulnerable to cross-namespace entity deletion
CVE-2026-727605.315.1MISPcti-transmuteCWE-200cti-transmute Following List Exposes User Email Addresses to Authenticated Users
CVE-2026-64264.415.2Red HatRed Hat Enterprise Linux 10CWE-681Qemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-o…
CVE-2026-592338.715.1RoskusProspero Flow CRMCWE-639Missing Authorization in Prospero Flow CRM permission save endpoint allows pr…
CVE-2026-729194.315.1RocketChatRocket.ChatCWE-862Rocket.Chat: Broken Access Control in channels.convertToTeam Allows Unauthori…
CVE-2026-727308.714.9discoursediscourseCWE-79Discourse: Stored XSS chat-transcript username unescaped in Rich Text Editor
CVE-2026-150476.814.7Unknowns2MemberCWE-79s2Member < 260805 - Contributor+ Stored XSS via Shortcode
CVE-2026-148605.314.7UnknownPodcast PlayerCWE-918Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery
CVE-2026-727274.814.5discoursediscourseCWE-79Discourse: Stored XSS in the moderation review queue
CVE-2026-190776.514.4UnknownDuplicate PostCWE-639Copy & Delete Posts < 1.5.5 - Authenticated Arbitrary Post Deletion via Missi…
CVE-2026-63747.314.1Zyxel NetworksWAH7601CWE-798Hardcoded Credentials in Zyxel WAH7601 Router
CVE-2026-727317.114.2discoursediscourseCWE-89Discourse: Strip SQL comments and use non-recursive parameter interpolation i…
CVE-2026-684147.514.1LinuxLinuxwifi: cfg80211: cancel sched scan results work on unregister
CVE-2026-444014.614.1TypemillTypemillCWE-79Typemill CMS 2.x Persistent XSS via Markdown javascript URI
CVE-2026-590877.813.6Red HatRed Hat Enterprise Linux 6CWE-787Gimp: heap buffer overflow in `file-seattle-filmworks` load — `fread` writes …
CVE-2026-68278await13.5LinuxLinuxdrm/dp/mst: fix buffer overflows in sideband chunk accumulation
CVE-2026-688705.313.4Apache Software FoundationApache Airflow Microsoft Azure providerCWE-639Apache Airflow Microsoft Azure provider: microsoft.azure Key Vault backend: t…
CVE-2026-68359await13.3LinuxLinuxhwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop
CVE-2026-68360await13.3LinuxLinuxhwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop
CVE-2026-170184.913.0UnknownCubeWP FrameworkCWE-639CubeWP Framework <= 1.1.30 - Contributor+ Arbitrary Post and User Meta Disclo…
CVE-2026-152375.312.9UnknownMotoPress Hotel BookingCWE-862Hotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Chec…
CVE-2025-302378.712.6TP-Link Systems Inc.HB810(US2) V1.0/1.6/2.0/2.6CWE-862Authentication Bypass via Broken Access Control in Web Server in Multiple TP-…
CVE-2026-683908.812.5LinuxLinuxBluetooth: hci_sync: hold hdev->lock for hci_conn_params lookups
CVE-2026-193832.012.5saithinkSaiAdminCWE-284saithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestric…
CVE-2026-727255.412.1discoursediscourseCWE-79Discourse: Stored XSS in staff action logs injects staff UI
CVE-2026-566204.312.1HCLSoftwareHCL BigFix MobileCWE-209HCL BigFix Mobile is vulnerable to information disclosure
CVE-2026-170125.312.0UnknownAccept PayPal & Stripe with Subscriptions for WooCommerceCWE-284Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via Unvalid…
CVE-2026-730355.312.0raineorshinenpm-check-updatesCWE-150npm-check-updates 23.0.2 Terminal Injection via Unsanitized Escape Sequences
CVE-2026-169495.811.7UnknownTerm PagesCWE-89Term Pages < 2.0.0 - Unauthenticated SQL Injection via tp_lookup
CVE-2026-192786.811.5Red HatRed Hat Advanced Cluster Security 4CWE-625Stackrox: stackrox: privilege escalation via unanchored regular expressions i…
CVE-2026-68130await11.5LinuxLinuxksmbd: defer destroy_previous_session() until after NTLM authentication
CVE-2026-68164await11.3LinuxLinuxmm/damon/core: disallow overlapping input ranges for damon_set_regions()
CVE-2026-68187await11.3LinuxLinuxexec: fix unsigned loop counter wrap in transfer_args_to_stack()
CVE-2026-68203await11.3LinuxLinuxmedia: vivid: fix cleanup bugs in vivid_init()
CVE-2026-68205await11.3LinuxLinuxmedia: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subde…
CVE-2026-68207await11.3LinuxLinuxmedia: ti: vpe: unwind v4l2 device registration on probe error
CVE-2026-68212await11.3LinuxLinuxmedia: saa7134: Fix a possible memory leak in saa7134_video_init1
CVE-2026-68214await11.3LinuxLinuxmedia: rtl2832: fix use-after-free in rtl2832_remove()
CVE-2026-68215await11.3LinuxLinuxmedia: radio-si476x: Unregister v4l2_device on probe failure
CVE-2026-68217await11.3LinuxLinuxmedia: pwc: Drain fill_buf on start_streaming() failure
CVE-2026-68218await11.3LinuxLinuxmedia: pci: dm1105: Free allocated workqueue
CVE-2026-68220await11.3LinuxLinuxmedia: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe
CVE-2026-68221await11.3LinuxLinuxmedia: nuvoton: npcm-video: fix memory leaks in probe and remove
CVE-2026-68223await11.3LinuxLinuxmedia: meson: vdec: Fix memory leak in error path of vdec_open
CVE-2026-68225await11.3LinuxLinuxmedia: i2c: alvium: fix critical pointer access in alvium_ctrl_init
CVE-2026-68226await11.3LinuxLinuxmedia: cx23885: add ioremap return check and cleanup
CVE-2026-68227await11.3LinuxLinuxmedia: cx231xx: fix devres lifetime
CVE-2026-68231await11.3LinuxLinuxmedia: airspy: Return queued buffers on start_streaming() failure
CVE-2026-68251await11.3LinuxLinuxdrm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON()
CVE-2026-68261await11.3LinuxLinuxdrm/imagination: fix error checking of pvr_vm_context_lookup()
CVE-2026-68277await11.3LinuxLinuxdrm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
CVE-2026-68339await11.3LinuxLinuxBluetooth: btusb: validate Realtek vendor event length
CVE-2026-68346await11.3LinuxLinuxALSA: hda: cs35l41: validate and free ACPI mute object
CVE-2026-68351await11.3LinuxLinuxwifi: carl9170: bound memcpy length in cmd callback to prevent OOB read
CVE-2026-68405await11.3LinuxLinuxwifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock
CVE-2026-68422await11.3LinuxLinuxbtrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()
CVE-2026-67916.611.1The GNU C LibraryglibcCWE-121Potential stack-based buffer clash during tilde expansion in wordexp
CVE-2026-68268await11.0LinuxLinuxdrm/xe: Return error on non-migratable faults requiring devmem
CVE-2026-68270await11.0LinuxLinuxdrm/sysfb: Avoid possible truncation with calculating visible size
CVE-2026-664085.110.7ECOVACS ROBOTICSDEEBOT PRO M1CWE-1391The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with w…
CVE-2026-729064.310.6frappeerpnextCWE-862ERPNext: Unauthorised triggering of automated emails due to missing validation
CVE-2026-664046.010.6ECOVACS ROBOTICSDEEBOT PRO M1CWE-295DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQT…
CVE-2026-729185.410.1RocketChatRocket.ChatCWE-862Rocket.Chat: Insecure implementation of websocket notifications
CVE-2026-68165await10.2LinuxLinuxmm/damon/core: validate ranges in damon_set_regions()
CVE-2026-68169await10.2LinuxLinuxmptcp: pm: userspace: fix use-after-free in get_local_id
CVE-2026-68175await10.2LinuxLinuxtracing: Fix resource leak on mmiotrace trace_pipe close
CVE-2026-68176await10.2LinuxLinuxtracing: Fix mmiotrace possible NULL dereferencing of hiter->dev
CVE-2026-68180await10.2LinuxLinuxintel_th: fix MSC output device reference leak
CVE-2026-68181await10.2LinuxLinuxmei: bus: access mei_device under device_lock on cleanup
CVE-2026-68182await10.1LinuxLinuxcomedi: comedi_parport: deal with premature interrupt
CVE-2026-68183await10.2LinuxLinuxfirmware: stratix10-svc: fix memory leaks and list corruption bugs
CVE-2026-68184await10.2LinuxLinuxcdrom: fix stack out-of-bounds read in CDROMVOLCTRL
CVE-2026-68185await10.2LinuxLinuxLoongArch: Move jump_label_init() before parse_early_param()
CVE-2026-68186await10.2LinuxLinuxbinfmt_misc: set have_execfd only once the interpreter is opened
CVE-2026-68188await10.1LinuxLinuxBluetooth: RFCOMM: Fix session UAF in set_termios
CVE-2026-68190await10.1LinuxLinuxstaging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()
CVE-2026-68193await10.2LinuxLinuxwifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses
CVE-2026-68194await10.2LinuxLinuxwifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses
CVE-2026-68195await10.2LinuxLinuxwifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses
CVE-2026-68197await10.2LinuxLinuxwifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper
CVE-2026-68250await10.2LinuxLinuxdrm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON()
CVE-2026-68269await10.2LinuxLinuxdrm/i915/gem: Add missing nospec on parallel submit slot
CVE-2026-68296await10.1LinuxLinuxnet: gre: fix lltx regression for GRE tunnels with SEQ/CSUM
CVE-2026-68304await10.1LinuxLinuxwifi: brcmfmac: fix 802.1X-SHA256 call trace warning
CVE-2026-68313await10.2LinuxLinuxtipc: fix infinite loop in __tipc_nl_compat_dumpit
CVE-2026-68321await10.2LinuxLinuxnet: txgbe: fix FDIR filter leak on remove
CVE-2026-68322await10.1LinuxLinuxrds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled
CVE-2026-68344await10.1LinuxLinuxusb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect
CVE-2026-68368await10.1LinuxLinuxusb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
CVE-2026-68369await10.1LinuxLinuxusb: gadget: printer: fix infinite loop in printer_read()
CVE-2026-68378await10.1LinuxLinuxdpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync()
CVE-2026-68386await10.1LinuxLinuxbpf, sockmap: Reject unhashed UDP sockets on sockmap update
CVE-2026-68395await10.1LinuxLinuxata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered
CVE-2026-68396await10.1LinuxLinuxscsi: core: wake eh reliably when using scsi_schedule_eh
CVE-2026-68410await10.2LinuxLinuxwifi: libertas: fix memory leak in helper_firmware_cb()
CVE-2026-186664.310.0UnknownLibrary Management SystemCWE-89Library Management System < 3.6.7 - Subscriber+ SQL Injection via Filter Value
CVE-2026-68166await9.9LinuxLinuxuserfaultfd: prevent registration of special VMAs
CVE-2026-68168await9.9LinuxLinuxafs: Fix afs_edit_dir_remove() to get, not find, block 0
CVE-2026-68174await9.9LinuxLinuxtracing: Fix union collision of module and refcnt for dynamic events
CVE-2026-68208await9.9LinuxLinuxmedia: ti: vpe: Fix the error code of devm_kzalloc() in vip_probe_slice()
CVE-2026-68224await9.9LinuxLinuxmedia: mali-c55: Fix possible ERR_PTR in enable_streams
CVE-2026-68232await9.9LinuxLinuxdrm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict
CVE-2026-68235await9.9LinuxLinuxdrm/amd/display: dce100: skip non-DP stream encoders for DP MST
CVE-2026-68241await9.9LinuxLinuxdrm/i915/mst: limit DP MST ESI service loop
CVE-2026-68345await9.9LinuxLinuxarm_mpam: guard MBWU state before adding it to garbage
CVE-2026-68412await9.9LinuxLinuxwifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan()
CVE-2026-126244.39.8HashiCorpVaultCWE-863Vault vulnerable to LIST authorization bypass via trailing-slash strip
CVE-2026-68276await9.4LinuxLinuxdrm/amdgpu/gfx: fix cleaner shader IB buffer overflow
CVE-2026-68349await9.4LinuxLinuxwifi: carl9170: fix buffer overflow in rx_stream failover path
CVE-2026-68421await9.2LinuxLinuxsched_ext: Don't warn on core-sched forced idle in put_prev_task_scx()
CVE-2026-715776.39.1Red HatMulticluster Global HubCWE-522Multicluster-global-hub: multicluster-global-hub: spec-topic read acl leaks b…
CVE-2026-682557.79.0LinuxLinuxdrm/virtio: bound EDID block reads to the response buffer
CVE-2026-129712.28.8UnknownLearnPressCWE-918LearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply…
CVE-2026-68167await8.9LinuxLinuxbtrfs: do not try compression for data reloc inodes
CVE-2026-68191await8.9LinuxLinuxwifi: ath12k: fix NULL pointer dereference in rhash table destroy
CVE-2026-68242await8.9LinuxLinuxdrm/i915/gt: Fix NULL deref on sched_engine alloc failure
CVE-2026-68286await8.9LinuxLinuxdrop_monitor: perform u64_stats updates under IRQ-disabled section
CVE-2026-68303await8.9LinuxLinuxdrm/vc4: hvs/v3d: Fix null dereference in unbind
CVE-2026-68312await8.9LinuxLinuxcifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths
CVE-2026-68358await8.8LinuxLinuxhwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop
CVE-2026-68361await8.8LinuxLinuxhwmon: (corsair-psu) Stop device IO before calling hid_hw_stop
CVE-2026-170163.78.6UnknownAccept PayPal & Stripe with Subscriptions for WooCommerceCWE-284Restore PayPal Standard for WooCommerce <= 3.1.0 - Payment Bypass via PDT Und…
CVE-2026-142384.18.5UnknownviteposCWE-89Vitepos < 3.6.0 - Admin+ SQL Injection via product-details-report
CVE-2026-68413await8.5LinuxLinuxwifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
CVE-2026-727286.38.3discoursediscourseCWE-20Discourse: Onebox iframe origin allowlist enforces URL authority boundary
CVE-2026-725876.18.4CoreBunchInstaticCWE-444Instatic - Cache Poisoning via Unauthenticated Server Island Endpoint
CVE-2026-729124.38.4gchqCyberChefCWE-400CyberChef’s pretty-recipe parser vulnerable to client-side ReDoS / CPU exhaus…
CVE-2026-725788.88.1FreePBXFreePBX FrameworkCWE-352FreePBX Framework - Missing CSRF Protection in Admin Panel Ajax Dispatcher
CVE-2026-681798.48.1LinuxLinuxmisc: nsm: only unlock nsm_dev on post-lock error paths
CVE-2026-683718.48.1LinuxLinuxusb: musb: omap2430: Do not put borrowed of_node in probe
CVE-2026-152295.38.0UnknownPinpoint Booking SystemCWE-863Pinpoint Booking System <= 2.9.9.7.1 - Unauthenticated Arbitrary Booking Pric…
CVE-2026-170215.38.0UnknownSalon Booking SystemCWE-862Salon Booking System – Free Version < 10.30.34 - Unauthenticated Arbitrary Bo…
CVE-2026-68093await7.9LinuxLinuxKVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after ho…
CVE-2026-189345.57.7UnknownRSS Aggregator by FeedzyCWE-863RSS Aggregator by Feedzy < 5.2.6 - Author+ Cross-User Import Job Manipulation…
CVE-2026-68342await7.5LinuxLinuxovpn: avoid putting unrelated P2P peer on socket release
CVE-2026-725226.27.5libexpat projectlibexpatCWE-125libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop b…
CVE-2026-68088await7.5LinuxLinuxusb: gadget: function: rndis: add length check to response query
CVE-2026-68090await7.5LinuxLinuxdebugobjects: Plug race against a concurrent OOM disable
CVE-2026-682027.87.3LinuxLinuxALSA: seq: close a re-opened queue timer in the destructor
CVE-2026-682047.87.3LinuxLinuxmedia: vivid: check for vb2_is_busy() when toggling caps

Results continue: ranks 401–670.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-10 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.