boxscore/security
Wednesday, August 12, 2026 · all times UTC← 2026-08-11 · archive · 2026-08-13 →

Edition of August 12, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–433 of 433
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-599147.82.5DellDisplay and Peripheral Manager (DDPM Windows)CWE-284Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.1…
CVE-2026-195485.52.3Red HatRed Hat Enterprise Linux 10CWE-416Binutils: binutils: multiple use-after-free in add_archive_element via lto pl…
CVE-2026-684467.82.1LinuxLinuxdrm/vmwgfx: Validate vmw_surface_metadata::array_size
CVE-2026-186795.82.1Kong Inc.Kong MeshCWE-295Kong Mesh: kuma-dp connects to the control plane without verifying the TLS ce…
CVE-2026-151415.32.0TP-Link Systems Inc.TL-WR820N v2CWE-346Referer Validation Bypass in TL-WR820N Web Management Interface
CVE-2026-684427.81.9LinuxLinuxbtrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps
CVE-2026-718466.51.8Red HatRed Hat Advanced Cluster Management for Kubernetes 2CWE-250Insights-client: insights-client: clusterrole grants cluster-wide secrets get…
CVE-2026-144795.51.7AutodeskInstallerCWE-1285Denial of Service in Autodesk Installer IPC Channel
CVE-2026-166215.31.8UnknownPayment Gateway for PayPal on WooCommercePayment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment B…
CVE-2026-195026.81.7MongoDBSchema Builder CLICWE-532Insufficient redaction of sensitive configuration values in diagnostic output…
CVE-2026-152135.31.5UnknownWelcart e-CommerceWelcart e-Commerce < 2.11.33 - Unauthenticated Payment Bypass via Forged Sett…
CVE-2026-170085.31.5UnknownQuick Paypal PaymentsQuick PayPal Payments <= 5.7.50 - Unauthenticated Payment Bypass via PayPal IPN
CVE-2026-134339.61.5IBMi Access Client SolutionsCWE-494IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
CVE-2026-144787.81.4AutodeskInstallerCWE-732Incorrect Permission Assignment in Autodesk Installer Named Pipes
CVE-2026-599167.81.4DellDisplay and Peripheral Manager (DDPM Windows)CWE-290Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.1…
CVE-2026-599177.81.4DellDisplay and Peripheral Manager (DDPM Windows)CWE-284Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.1…
CVE-2026-684477.11.4LinuxLinuxdrm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size
CVE-2026-472285.21.4AdmidioadmidioCWE-352Admidio's CSRF in registration `send_login` mode resets arbitrary user passwords
CVE-2026-181715.71.2DockerDocker SandboxesCWE-863Docker Sandboxes read-only runtime mount writable through its shared-export a…
CVE-2026-472324.31.2AdmidioadmidioCWE-352Admidio PKCS#12 private key export action lacks CSRF protection
CVE-2025-593238.41.2n/an/aCWE-345CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the …
CVE-2026-122326.11.2zephyrprojectzephyrCWE-125Out-of-bounds read via unvalidated stream_id in Intel ALH DAI get_properties
CVE-2026-133677.81.0IBMInformix Dynamic ServerCWE-284IBM Informix Dynamic Server Privilege Escalation Vulnerability in oninit Utility
CVE-2026-180443.71.0UnknownEstatik Real Estate PluginCWE-345Estatik Real Estate Plugin < 4.3.4 - Unauthenticated Arbitrary-Recipient Mail…
CVE-2026-186785.50.8Kong Inc.Kong MeshCWE-295Kong Mesh: kumactl connects to the control plane without verifying the TLS ce…
CVE-2026-122356.30.8zephyrprojectzephyrCWE-787Out-of-bounds write in Xtensa llext PLT relocation from malformed ELF (CWE-787)
CVE-2026-472295.40.8AdmidioadmidioCWE-352Admidio: CSRF in SSO client `enable` action toggles SAML/OIDC clients without…
CVE-2026-539967.30.7The NetBSD FoundationNetBSDCWE-862NetBSD hdaudio(4) Driver Privilege Bypass Use-After-Free via HDAUDIO_FGRP_SET…
CVE-2026-148667.10.6IBMi Access Client SolutionsCWE-798IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
CVE-2026-505446.30.5NortheBridgeluminalshineCWE-379NortheBridge/luminalshine has Incorrect Permission Assignment for Critical Re…
CVE-2026-122347.80.2zephyrprojectzephyrCWE-367TOCTOU double-fetch in `zsock_sendmsg`/`recvmsg` userspace verifiers allows k…
CVE-2026-660166.70.2jfrogartifactoryCWE-312Rendered Artifactory Helm manifests may contain generated TLS private keys
CVE-2026-487912.00.0sigstoresigstore-javaCWE-347Sigstore Java has a vulnerability with bundle verification of integratedTime