Edition of August 12, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-59914 | 7.8 | 2.5 | Dell | Display and Peripheral Manager (DDPM Windows) | CWE-284 | Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.1… |
| CVE-2026-19548 | 5.5 | 2.3 | Red Hat | Red Hat Enterprise Linux 10 | CWE-416 | Binutils: binutils: multiple use-after-free in add_archive_element via lto pl… |
| CVE-2026-68446 | 7.8 | 2.1 | Linux | Linux | — | drm/vmwgfx: Validate vmw_surface_metadata::array_size |
| CVE-2026-18679 | 5.8 | 2.1 | Kong Inc. | Kong Mesh | CWE-295 | Kong Mesh: kuma-dp connects to the control plane without verifying the TLS ce… |
| CVE-2026-15141 | 5.3 | 2.0 | TP-Link Systems Inc. | TL-WR820N v2 | CWE-346 | Referer Validation Bypass in TL-WR820N Web Management Interface |
| CVE-2026-68442 | 7.8 | 1.9 | Linux | Linux | — | btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps |
| CVE-2026-71846 | 6.5 | 1.8 | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | CWE-250 | Insights-client: insights-client: clusterrole grants cluster-wide secrets get… |
| CVE-2026-14479 | 5.5 | 1.7 | Autodesk | Installer | CWE-1285 | Denial of Service in Autodesk Installer IPC Channel |
| CVE-2026-16621 | 5.3 | 1.8 | Unknown | Payment Gateway for PayPal on WooCommerce | — | Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment B… |
| CVE-2026-19502 | 6.8 | 1.7 | MongoDB | Schema Builder CLI | CWE-532 | Insufficient redaction of sensitive configuration values in diagnostic output… |
| CVE-2026-15213 | 5.3 | 1.5 | Unknown | Welcart e-Commerce | — | Welcart e-Commerce < 2.11.33 - Unauthenticated Payment Bypass via Forged Sett… |
| CVE-2026-17008 | 5.3 | 1.5 | Unknown | Quick Paypal Payments | — | Quick PayPal Payments <= 5.7.50 - Unauthenticated Payment Bypass via PayPal IPN |
| CVE-2026-13433 | 9.6 | 1.5 | IBM | i Access Client Solutions | CWE-494 | IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities |
| CVE-2026-14478 | 7.8 | 1.4 | Autodesk | Installer | CWE-732 | Incorrect Permission Assignment in Autodesk Installer Named Pipes |
| CVE-2026-59916 | 7.8 | 1.4 | Dell | Display and Peripheral Manager (DDPM Windows) | CWE-290 | Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.1… |
| CVE-2026-59917 | 7.8 | 1.4 | Dell | Display and Peripheral Manager (DDPM Windows) | CWE-284 | Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.1… |
| CVE-2026-68447 | 7.1 | 1.4 | Linux | Linux | — | drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size |
| CVE-2026-47228 | 5.2 | 1.4 | Admidio | admidio | CWE-352 | Admidio's CSRF in registration `send_login` mode resets arbitrary user passwords |
| CVE-2026-18171 | 5.7 | 1.2 | Docker | Docker Sandboxes | CWE-863 | Docker Sandboxes read-only runtime mount writable through its shared-export a… |
| CVE-2026-47232 | 4.3 | 1.2 | Admidio | admidio | CWE-352 | Admidio PKCS#12 private key export action lacks CSRF protection |
| CVE-2025-59323 | 8.4 | 1.2 | n/a | n/a | CWE-345 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the … |
| CVE-2026-12232 | 6.1 | 1.2 | zephyrproject | zephyr | CWE-125 | Out-of-bounds read via unvalidated stream_id in Intel ALH DAI get_properties |
| CVE-2026-13367 | 7.8 | 1.0 | IBM | Informix Dynamic Server | CWE-284 | IBM Informix Dynamic Server Privilege Escalation Vulnerability in oninit Utility |
| CVE-2026-18044 | 3.7 | 1.0 | Unknown | Estatik Real Estate Plugin | CWE-345 | Estatik Real Estate Plugin < 4.3.4 - Unauthenticated Arbitrary-Recipient Mail… |
| CVE-2026-18678 | 5.5 | 0.8 | Kong Inc. | Kong Mesh | CWE-295 | Kong Mesh: kumactl connects to the control plane without verifying the TLS ce… |
| CVE-2026-12235 | 6.3 | 0.8 | zephyrproject | zephyr | CWE-787 | Out-of-bounds write in Xtensa llext PLT relocation from malformed ELF (CWE-787) |
| CVE-2026-47229 | 5.4 | 0.8 | Admidio | admidio | CWE-352 | Admidio: CSRF in SSO client `enable` action toggles SAML/OIDC clients without… |
| CVE-2026-53996 | 7.3 | 0.7 | The NetBSD Foundation | NetBSD | CWE-862 | NetBSD hdaudio(4) Driver Privilege Bypass Use-After-Free via HDAUDIO_FGRP_SET… |
| CVE-2026-14866 | 7.1 | 0.6 | IBM | i Access Client Solutions | CWE-798 | IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities |
| CVE-2026-50544 | 6.3 | 0.5 | NortheBridge | luminalshine | CWE-379 | NortheBridge/luminalshine has Incorrect Permission Assignment for Critical Re… |
| CVE-2026-12234 | 7.8 | 0.2 | zephyrproject | zephyr | CWE-367 | TOCTOU double-fetch in `zsock_sendmsg`/`recvmsg` userspace verifiers allows k… |
| CVE-2026-66016 | 6.7 | 0.2 | jfrog | artifactory | CWE-312 | Rendered Artifactory Helm manifests may contain generated TLS private keys |
| CVE-2026-48791 | 2.0 | 0.0 | sigstore | sigstore-java | CWE-347 | Sigstore Java has a vulnerability with bundle verification of integratedTime |