boxscore/security
Thursday, August 13, 2026 · all times UTC← 2026-08-12 · archive · 2026-08-14 →

606 CVEs published August 13, 2026: 80 critical, 263 high, 233 medium, 29 low; 0 in KEV; 5 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 581 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published46901349514142563
KEV catalog size1670

832 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux416200123412969802730.17.8.0017+401
microsoft439180013112164288378331.87.8.0038+385
google4946172140228187351.16.5.0023+49
red hat1313532216614718400.07.1.0025+117
apple2246576811229372.87.1.0027+2
canonical11149320000.09.9.0029+11
suse551220000.07.3.0022+5
android010100161100.08.4.01710
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco315192590961427.57.8.0033+30
palo alto networks12270114101427.44.5.0019+2
fortinet7253612128624.06.0.0051+7
sonicwall1012354017216.77.8.0024+10
vmware01247012100.08.7.00440
netgear990054800.04.3.0031+9
ivanti38130033562.57.9.5751+3
checkpoint1541003240.09.3.2062+1
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache96233451177014020.97.5.0048+96
mozilla1734226501300.09.1.0031+1
gitlab132808162427.15.1.0026+13
github570520000.08.6.0041+5
docker140130100.05.7.0014+1
wordpress1412105250.08.8.3700+1
drupal01100051100.09.8.88320
kubernetes010001000.02.4.00240
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle01113212539304574030.37.6.00310
ibm17428257131886710.47.5.0029+174
adobe6010022512217544.07.8.0036+59
progress1639112080912.68.1.0027+16
solarwinds0201611011420.09.1.00500
veeam10123720400.08.6.0027+10
zohocorp472410000.08.8.0099+4
atlassian0303001300.08.0.00260
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link1523150612614.39.3.0209+15
siemens171811610100.07.3.0011+17
hikvision0704202114.37.2.00250
bosch030300000.08.1.00280
schneider electric031200100.08.7.00200
synology110100000.07.3.0013+1
honeywell010010000.06.9.00310
mitsubishi electric010100000.07.1.00130
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
elastic4867013540300.06.5.0027+48
mongodb3258337162200.07.1.0024+32
surrealdb057326253000.07.1.00250
gitea4848715224000.06.5.0027+48
zephyrproject2345015246000.06.5.0017+23
netty34462891000.07.5.0046+3
siyuan-note3643195190000.08.3.0024+36
grafana142314223000.06.5.0033-3

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.993199.99.8
CVE-2026-63030.956099.99.8
CVE-2026-39808.912199.8
CVE-2026-34486.829399.67.5
CVE-2026-25089.736099.49.8
CVE-2026-16232.733099.49.3
CVE-2026-60137.731099.45.9
CVE-2026-0770.568899.09.8
CVE-2026-62144.206297.39.1
CVE-2026-9198.173596.99.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.1040KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0473
CVE-2026-4766810.0.0434
CVE-2026-4836210.0.0207
CVE-2026-7329910.0.0121
CVE-2026-4435910.0.0100
CVE-2026-4561810.0.0095
CVE-2025-7138910.0.0093
CVE-2026-4816810.0.0091
Most disclosures (vendor)
VendorCVEs
oracle1109
linux1068
microsoft473
google451
ibm274
red hat239
apache201
apple169
adobe75
elastic67
Most KEV additions (YTD)
VendorKEV
microsoft33
cisco14
apple7
fortinet6
google5
ivanti5
adobe4
langflow4
solarwinds4
synacor4
Most-affected ecosystems
EcosystemAdvisories
Maven65
PyPI5
Go3
npm3
Packagist2
crates.io2
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2021-27137DD-WRT0
CVE-2023-4346KNX Association0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20316Cisco0
CVE-2026-20349Cisco0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171730
CVE-2021-27102Accellion2021-11-171730
CVE-2021-27101Accellion2021-11-171730
CVE-2021-27103Accellion2021-11-171730
CVE-2021-21017Adobe2021-11-171730
CVE-2021-28550Adobe2021-11-171730
CVE-2021-42013Apache2021-11-171730
CVE-2021-41773Apache2021-11-171730
CVE-2021-30858Apple2021-11-171730
CVE-2021-30860Apple2021-11-171730

Transactions

EXPLOIT PUBLISHEDCVE-2015-1701. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2016-20097 (Weaver Network Co., Ltd. E-cology 8.0). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2017-0144 (Microsoft Corporation Windows SMB). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2017-0145 (Microsoft Corporation Windows SMB). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2017-11357. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2017-18362. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2018-19320. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2018-19321. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2018-19322. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2018-19323. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2018-20753. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2018-6882. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2018-8453 (Microsoft Windows 7). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2022-1055 (Linux Kernel). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2022-2586 (Linux Kernel). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2022-4995 (Weaver Network Co., Ltd. E-cology 9.0). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2022-50997 (Weaver Network Co., Ltd. E-cology 9.0). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2023-7028 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-15684 (Open5GS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2025-9486 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-13177 (Unknown Eventin). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-13612 (Unknown KiviCare). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-14857 (Unknown WP Crowdfunding). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-15216 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-15217 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-15423 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16494 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16627 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18433 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19246 (HKUDS nanobot). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19345 (code-projects Task Management System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-3087 (Python Software Foundation CPython). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-39931 (openemr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-39932 (openemr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-41453 (krayin laravel-crm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-42578 (netty). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-42579 (netty). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-42581 (netty). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-42584 (netty). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-42587 (netty). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-4879 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50559 (quarkusio quarkus). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-50656 (Microsoft Malware Protection Engine). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-61523 (WebsiteBaker Org e.V. WebsiteBaker CMS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-61524 (WebsiteBaker Org e.V. WebsiteBaker CMS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-63720 (koxudaxi datamodel-code-generator). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66748 (owen2345 camaleon-cms). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66752 (tiny-http). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-66753 (tiny-http). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-67610 (openemr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-67611 (openemr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-67612 (openemr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-67617 (microweber). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-67620 (FlowiseAI Flowise). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-67621 (FlowiseAI Flowise). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-67622 (FlowiseAI Flowise). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-6821 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-69100 (dromara lamp-cloud). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-70636 (FlowiseAI Flowise). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-70637 (hfiref0x LightFTP). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-71959 (bitwarden server). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-71962 (FlowiseAI Flowise). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-71964 (usmannasir cyberpanel). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-71965 (usmannasir cyberpanel). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-71966 (usmannasir cyberpanel). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-71969 (OP-TEE optee_os). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-73678 (MindsDB Minds Platform). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-7427 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-8667 (GitLab). Public exploit reference added.

RESCOREDCVE-2018-19943 (QNAP Systems Inc. QTS). CVSS 8 → 5.4 (NVD).

RESCOREDCVE-2022-48979 (Linux). CVSS 7.8 → 5.5 (NVD).

RESCOREDCVE-2022-49159 (Linux). CVSS 8.8 → 5.5 (NVD).

RESCOREDCVE-2026-12539 (Docker Sandboxes). CVSS 5.1 → 5.7 (NVD).

RESCOREDCVE-2026-42579 (netty). CVSS 7.5 → 9.1 (NVD).

RESCOREDCVE-2026-42581 (netty). CVSS 5.8 → 9.8 (NVD).

RESCOREDCVE-2026-42584 (netty). CVSS 7.3 → 9.1 (NVD).

RESCOREDCVE-2026-45674 (netty). CVSS 8.7 → 10 (NVD).

RESCOREDCVE-2026-47691 (netty). CVSS 8.7 → 10 (NVD).

RESCOREDCVE-2026-48043 (netty). CVSS 5.3 → 7.5 (NVD).

RESCOREDCVE-2026-54230 (Red Hat Enterprise Linux 8). CVSS 7 → 7.8 (NVD).

ENRICHEDCVE-2022-2586 (Linux Kernel). Received CVSS 7.8 and CPE data from NVD.

ENRICHEDCVE-2022-48633 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-48823 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-48825 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-49044 (Linux). Received CVSS 7.8 and CPE data from NVD.

ENRICHEDCVE-2022-49051 (Linux). Received CVSS 6.8 and CPE data from NVD.

ENRICHEDCVE-2022-49069 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-49109 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-49112 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-49118 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-49132 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-49133 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-49169 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHEDCVE-2022-49286 (Linux). Received CVSS 4.7 and CPE data from NVD.

ENRICHEDCVE-2022-49309 (Linux). Received CVSS 5.5 and CPE data from NVD.

Yesterday's Results

606 CVEs published. 25 box scores and 375 table rows below; the remaining 206 continue on page 2 — every CVE is listed, nothing truncated.

Tenda CH7 ATE Module Kylin HandleCmd command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0236   82.4     —
AFFECTED
  Product  Versions    Fixed
  CH7      20260625 –  —
  CH7G     20260625 –  —
  CH10     20260625 –  —
  CP3      20260625 –  —
  CP3 Pro  20260625 –  —
  CP7      20260625 –  —
  TC3B14C  20260625 –  —
  TC3B15C  20260625 –  —
  TC3T14C  20260625 –  —
  TC3T15C  20260625 –  —
TIMELINE
  Aug 13  Reserved by CNA
  Aug 13  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · 6 references · NVD status: Deferred
Zohocorp ManageEngine Password Manager Pro — SQL Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0158   73.5     —
AFFECTED
  Product                            Versions     Fixed
  ManageEngine Password Manager Pro  unspecified  —
  ManageEngine PAM360                unspecified  —
TIMELINE
  Jun 10  Reserved by CNA
  Aug 13  Published (CNA: Zohocorp)
CWE-89 · CNA: Zohocorp · 1 reference · NVD status: Received
FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0095   58.4     —
AFFECTED
  Product     Versions     Fixed
  missedcall  < 16.0.11 –  —
TIMELINE
  Aug 13  Reserved by CNA
  Aug 13  Published (CNA: GitHub_M)
CWE-89 · CNA: GitHub_M · 3 references · NVD status: Received
Fosowl AgenticSeek — AgenticSeek Unauthenticated RCE via /query API Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0084   54.8     —
AFFECTED
  Product      Versions     Fixed
  AgenticSeek  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Aug 13  Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · 4 references · NVD status: Received
Zohocorp ManageEngine Password Manager Pro — Authentication Bypass
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0070   50.0     —
AFFECTED
  Product                            Versions     Fixed
  ManageEngine Password Manager Pro  unspecified  —
  ManageEngine PAM360                unspecified  —
TIMELINE
  Jun 15  Reserved by CNA
  Aug 13  Published (CNA: Zohocorp)
CWE-347 · CNA: Zohocorp · 1 reference · NVD status: Received
gitpython-developers GitPython — GitPython before 3.1.54 Remote Code Execution via --template
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   L   N   H   H   H    7.7   .0069   49.9     —
AFFECTED
  Product    Versions     Fixed
  GitPython  unspecified  3.1.54
TIMELINE
  Aug 13  Reserved by CNA
  Aug 13  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 2 references · NVD status: Received
AWS Opensearch — SQL Query Validation Bypass in OpenSearch Direct Query
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0069   49.8     —
AFFECTED
  Product     Versions  Fixed
  Opensearch  2.13 –    —
  Opensearch  2.13 –    —
TIMELINE
  Jul 30  Reserved by CNA
  Aug 13  Published (CNA: AMZN)
CWE-693 · CNA: AMZN · 5 references · NVD status: Awaiting Analysis
FreePBX music — Authenticated FreePBX Music RCE via mpg123 and Asterisk Call Files
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   H   H   N    7.6   .0066   48.6     —
AFFECTED
  Product  Versions    Fixed
  music    < 17.0.7 –  —
TIMELINE
  Aug 13  Reserved by CNA
  Aug 13  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 2 references · NVD status: Received
n/a PostgreSQL — PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0066   48.4     —
AFFECTED
  Product     Versions  Fixed
  PostgreSQL  18 –      —
TIMELINE
  Jul 3   Reserved by CNA
  Aug 13  Published (CNA: PostgreSQL)
CWE-190 · CNA: PostgreSQL · 1 reference · NVD status: Undergoing Analysis
FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0065   48.3     —
AFFECTED
  Product  Versions                   Fixed
  backup   >= 17.0.5.34, < 17.0.11 –  —
TIMELINE
  Aug 13  Reserved by CNA
  Aug 13  Published (CNA: GitHub_M)
CWE-269, CWE-284, CWE-732 · CNA: GitHub_M · 1 reference · NVD status: Received
vitest-dev vitest — Vitest: Browser Mode provider commands bypass the file-access permission gate
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  L    9.4   .0064   47.9     —
AFFECTED
  Product  Versions   Fixed
  vitest   < 3.2.7 –  —
TIMELINE
  Aug 13  Reserved by CNA
  Aug 13  Published (CNA: GitHub_M)
CWE-22, CWE-552, CWE-862 · CNA: GitHub_M · 10 references · NVD status: Received
nextauthjs next-auth — NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   N    9.1   .0064   47.9     —
AFFECTED
  Product    Versions                            Fixed
  next-auth  >= 5.0.0-beta.4, < 5.0.0-beta.32 –  —
TIMELINE
  Aug 12  Reserved by CNA
  Aug 13  Published (CNA: GitHub_M)
CWE-285, CWE-636 · CNA: GitHub_M · 3 references · NVD status: Received
OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0062   46.6     —
AFFECTED
  Product     Versions   Fixed
  openchoreo  < 1.0.4 –  —
TIMELINE
  Aug 13  Reserved by CNA
  Aug 13  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · 12 references · NVD status: Received
FlowiseAI Flowise — Flowise before 3.1.3 Remote Code Execution via Custom MCP
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   H   H   H    9.0   .0061   46.2     —
AFFECTED
  Product  Versions     Fixed
  Flowise  unspecified  3.1.3
  Flowise  unspecified  3.1.3
TIMELINE
  Aug 13  Reserved by CNA
  Aug 13  Published (CNA: VulnCheck)
CWE-95 · CNA: VulnCheck · 2 references · NVD status: Received
n/a PostgreSQL — PostgreSQL regexp heap buffer overflow executes arbitrary code
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0060   45.7     —
AFFECTED
  Product     Versions  Fixed
  PostgreSQL  18 –      —
TIMELINE
  Jul 3   Reserved by CNA
  Aug 13  Published (CNA: PostgreSQL)
CWE-122 · CNA: PostgreSQL · 1 reference · NVD status: Undergoing Analysis
n/a PostgreSQL — PostgreSQL to_char heap buffer overflow executes arbitrary code
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0060   45.7     —
AFFECTED
  Product     Versions  Fixed
  PostgreSQL  18 –      —
TIMELINE
  Jul 3   Reserved by CNA
  Aug 13  Published (CNA: PostgreSQL)
CWE-122 · CNA: PostgreSQL · 1 reference · NVD status: Undergoing Analysis
n/a PostgreSQL — PostgreSQL plperl tied object heap buffer overflow executes arbitrary code
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0060   45.7     —
AFFECTED
  Product     Versions  Fixed
  PostgreSQL  18 –      —
TIMELINE
  Jul 3   Reserved by CNA
  Aug 13  Published (CNA: PostgreSQL)
CWE-122 · CNA: PostgreSQL · 1 reference · NVD status: Undergoing Analysis
n/a PostgreSQL — PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0060   45.7     —
AFFECTED
  Product     Versions  Fixed
  PostgreSQL  18 –      —
TIMELINE
  Jul 3   Reserved by CNA
  Aug 13  Published (CNA: PostgreSQL)
CWE-122 · CNA: PostgreSQL · 1 reference · NVD status: Undergoing Analysis
n/a PostgreSQL — PostgreSQL pg_dump heap buffer overflow executes arbitrary code
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0060   45.7     —
AFFECTED
  Product     Versions  Fixed
  PostgreSQL  18 –      —
TIMELINE
  Aug 9   Reserved by CNA
  Aug 13  Published (CNA: PostgreSQL)
CWE-122 · CNA: PostgreSQL · 1 reference · NVD status: Undergoing Analysis
n/a PostgreSQL — PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparound
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0059   45.5     —
AFFECTED
  Product     Versions  Fixed
  PostgreSQL  18 –      —
TIMELINE
  Jul 3   Reserved by CNA
  Aug 13  Published (CNA: PostgreSQL)
CWE-190 · CNA: PostgreSQL · 1 reference · NVD status: Undergoing Analysis
n/a PostgreSQL — PostgreSQL type confusion via "internal" arguments
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0059   45.5     —
AFFECTED
  Product     Versions  Fixed
  PostgreSQL  18 –      —
TIMELINE
  Jul 3   Reserved by CNA
  Aug 13  Published (CNA: PostgreSQL)
CWE-843 · CNA: PostgreSQL · 1 reference · NVD status: Undergoing Analysis
n/a PostgreSQL — PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0059   45.5     —
AFFECTED
  Product     Versions  Fixed
  PostgreSQL  18 –      —
TIMELINE
  Jul 20  Reserved by CNA
  Aug 13  Published (CNA: PostgreSQL)
CWE-843 · CNA: PostgreSQL · 1 reference · NVD status: Undergoing Analysis
n/a PostgreSQL — PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0059   45.5     —
AFFECTED
  Product     Versions  Fixed
  PostgreSQL  18 –      —
TIMELINE
  Jul 20  Reserved by CNA
  Aug 13  Published (CNA: PostgreSQL)
CWE-843 · CNA: PostgreSQL · 1 reference · NVD status: Undergoing Analysis
Go standard library net/http — Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0059   45.4     —
AFFECTED
  Product   Versions     Fixed
  net/http  unspecified  —
TIMELINE
  Jun 23  Reserved by CNA
  Aug 13  Published (CNA: Go)
CWE-770 · CNA: Go · 4 references · NVD status: Received
QuarkA QA Analytics — WordPress QA Analytics plugin <= 5.2.0.0 - Remote Code Execution (RCE) vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0059   45.4     —
AFFECTED
  Product       Versions  Fixed
  QA Analytics  n/a –     5.2.0.1
TIMELINE
  Feb 20  Reserved by CNA
  Aug 13  Published (CNA: Patchstack)
CWE-94 · CNA: Patchstack · 1 reference · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2019-257658.745.3ASP-CMS ProjectASP-CMSCWE-89ASP-CMS SQL Injection via commentList.asp id Parameter
CVE-2026-537957.245.0RsyncProjectrsyncCWE-59rsync < 3.5.0 Arbitrary File Write via --temp-dir/--link-dest
CVE-2026-584439.144.9GiteaGitea Open Source Git ServerCWE-863Public-only repository tokens can update private PR head branches
CVE-2026-704648.744.6RsyncProjectrsyncCWE-770rsync 2.0.0 < 3.5.0 Connection Slot Exhaustion DoS via Handshake Stall
CVE-2026-174819.844.5IBMDocumentation OfflineCWE-117IBM Documentation Offline is vulnerable to information disclosure, session fo…
CVE-2026-676149.343.6usmannasircyberpanelCWE-798CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal
CVE-2026-734178.643.6jupyterlabjupyterlabCWE-79JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.…
CVE-2026-145259.443.5IBMWebSphere Application Server - LibertyCWE-306IBM WebSphere Application Server Liberty is affected by an authenication bypass
CVE-2026-174829.843.2IBMDocumentation OfflineCWE-73IBM Documentation Offline is vulnerable to information disclosure, session fo…
CVE-2026-735708.942.9ZimbraCollaborationCWE-78A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) be…
CVE-2026-105715.342.3IBMWebSphere Application Server - LibertyCWE-502IBM WebSphere Application Server Liberty is affected by a denial of service
CVE-2026-734209.142.3nextauthjsnext-authCWE-180NextAuth.js: Email normalizer validates the address before Unicode normalizat…
CVE-2026-169758.842.2IBMiCWE-787IBM i is Affected By A Remote Code Execution Vulnerability []
CVE-2026-184088.842.2n/aPostgreSQLCWE-829PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute a…
CVE-2026-704538.742.1RsyncProjectrsyncCWE-407rsync < 3.5.0 Algorithmic Complexity DoS via hash_search()
CVE-2026-662567.241.9Apache Software FoundationApache Shindig CommonCWE-502Apache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via X…
CVE-2026-537909.241.5RsyncProjectrsyncCWE-78rsync < 3.5.0 Command Injection via Multiple Code Paths
CVE-2026-64717.241.3n/aPostgreSQLCWE-862PostgreSQL logical decoding can dlopen arbitrary file
CVE-2026-704618.841.1RsyncProjectrsyncCWE-787rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from Entry
CVE-2026-736258.740.7gitpython-developersGitPythonCWE-78GitPython before 3.1.54 Remote Code Execution via kwarg value smuggling
CVE-2026-736499.840.6shepherdwindvelocity.jsCWE-94Velocity.js: Remote Code Execution via property-read to Function constructor …
CVE-2026-64648.140.1n/aPostgreSQLCWE-829PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql co…
CVE-2026-734166.139.8jupyterlabjupyterlabCWE-178jupyterlab: PyPI extension blocklist package-name canonicalization bypass
CVE-2026-568597.539.5Go standard libraryencoding/xmlCWE-770Add recursion depth guard during decode in encoding/xml
CVE-2026-568627.539.5Go standard librarycrypto/tlsCWE-770Limit handshake messages we are willing to accept post-handshake in crypto/tls
CVE-2022-49939.139.4HTML-FormHandlerCWE-470HTML::FormHandler versions through 0.40068 for Perl allow attacker selected m…
CVE-2026-736668.239.4openchoreobackstage-pluginsCWE-306OpenChoreo: Unauthenticated Backstage developer-portal API exposes OpenChoreo…
CVE-2026-498279.839.3SMEWebifyWebErpMesv2CWE-20WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expens…
CVE-2026-157428.839.3n/aPostgreSQLCWE-190PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer …
CVE-2026-704558.739.3RsyncProjectrsyncCWE-770rsync 3.4.2 < 3.5.0 DoS via --zt Zstandard Compression Thread Exhaustion
CVE-2026-597147.139.2open-webuiopen-webuiCWE-862Open WebUI: Cross-channel message overwrite via chat completion API (single-m…
CVE-2026-6196210.039.1Hakan OzevinWP BASE BookingCWE-94WordPress WP BASE Booking plugin <= 6.3.0 - Arbitrary Code Execution vulnerab…
CVE-2024-583748.739.0Hongjing Centurye-HRCWE-89Hongjing e-HR Unauthenticated SQL Injection via getSdutyTree
CVE-2026-130488.239.0Data-MuFormCWE-22Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a me…
CVE-2026-197508.239.0TendaCHCWE-255Tenda CH/CP/TX3 SSH hard-coded password
CVE-2026-194847.538.8@fastify/busboy@fastify/busboyCWE-835@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary
CVE-2026-537919.138.8RsyncProjectrsyncCWE-290rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header
CVE-2026-144567.538.4OpenSSLOpenSSLCWE-770Unbounded Memory Growth in QUIC Server Incoming Channel Queue
CVE-2026-338187.538.4Go standard libraryencoding/asn1CWE-400Enforce maximum recursion depth in encoding/asn1
CVE-2026-735329.338.2WPManageNinjaFluent Forms ProCWE-506Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build
CVE-2026-704529.138.2RsyncProjectrsyncCWE-636rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure
CVE-2026-174737.538.2IBMDocumentation OfflineCWE-22IBM Documentation Offline is vulnerable to information disclosure, session fo…
CVE-2026-487027.538.1sigstorerekorCWE-770Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK …
CVE-2026-735077.538.1nettynettyCWE-400Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
CVE-2026-146688.137.6n/aPostgreSQLCWE-843PostgreSQL ctid type confusion in selectivity estimator discloses derivative …
CVE-2026-130519.137.4Form-ProcessorCWE-470Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl…
CVE-2026-735339.337.2WPManageNinjaNinja Tables ProCWE-506Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build
CVE-2026-704609.237.2RsyncProjectrsyncCWE-22rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink
CVE-2026-735148.737.0PostGISaddress_standardizerCWE-787PostGIS address_standardizer Out-of-Bounds Write via standardize_address()
CVE-2026-736607.537.0FreePBXttsCWE-78FreePBX: Authenticated TTS AGI Command Injection Through TTS Name
CVE-2026-568605.936.7Go standard librarynet/urlCWE-407Avoid quadratic complexity in resolvePath in net/url
CVE-2026-736029.036.4FlowiseAIFlowiseCWE-95Flowise before 3.1.3 Sandbox Escape to RCE
CVE-2026-194875.336.2perlCWE-670Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression m…
CVE-2026-735617.536.0anephenixhubCWE-400Hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
CVE-2026-172238.835.6IBMiCWE-787IBM i is Affected By Multiple Vulnerabilities in Host Servers
CVE-2026-655827.735.4LiquidThemesAI HubCWE-22WordPress AI Hub theme <= 1.3.10 - Arbitrary File Download vulnerability
CVE-2026-197575.535.4Dromaralamp-cloudCWE-22Dromara lamp-cloud File-Upload Controller FileAnyoneController.java path trav…
CVE-2026-197585.535.4dromaralamp-cloudCWE-22dromara lamp-cloud chunk-check endpoint FileChunkController.java path traversal
CVE-2026-728419.435.3openwrtluciCWE-73luci-app-openvpn Path Traversal RCE via instance_name2
CVE-2026-728429.435.3openwrtluciCWE-73OpenWrt luci-app-lxc ACL Inconsistency Authentication Bypass
CVE-2026-728509.435.3budibaseserverCWE-22Budibase before 3.40.0 Arbitrary File Write via Path Traversal
CVE-2026-192979.134.9IBMLangflow OSSCWE-307Insufficient Authentication Brute Force Protection on Login Endpoint
CVE-2026-166748.834.6IBMiCWE-426IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server…
CVE-2026-735157.234.6PostGISPostGISCWE-125PostGIS < 3.7.0beta2 Out-of-Bounds Read via FlatGeobuf Buffer
CVE-2026-168679.834.3IBMiCWE-287IBM i is Affected By Multiple Vulnerabilities in NetServer
CVE-2026-566549.834.1GiteaGitea Open Source Git ServerCWE-284Privilege Escalation via Access Token Scope Escalation in API
CVE-2026-157418.834.0n/aPostgreSQLCWE-89PostgreSQL expression deparse allows SQL injection via EXTRACT argument
CVE-2026-171018.333.8IBMiCWE-287IBM i is Affected By Multiple Vulnerabilities in Navigator for i
CVE-2026-146718.833.7n/aPostgreSQLCWE-843PostgreSQL refint plan cache type confusion executes arbitrary code
CVE-2026-169088.833.7IBMiCWE-22IBM i is Affected By Multiple SQL Vulnerabilities [, ]
CVE-2026-280089.833.6miniOrangeOAuth Single Sign On – SSO (OAuth Client)CWE-290WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.0.0 - Broken …
CVE-2026-664539.833.6Dimitri GrassiSalon booking systemCWE-288WordPress Salon booking system plugin <= 10.30.26 - Broken Authentication vul…
CVE-2026-664659.833.6AgniHDCartifyCWE-288WordPress Cartify theme <= 1.3.0.1 - Account Takeover vulnerability
CVE-2026-197492.933.4TendaCH7CWE-287Tenda CH7 RTSP/ONVIF missing authentication
CVE-2026-146798.233.1n/aPostgreSQLCWE-121PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to serv…
CVE-2026-197615.133.2DTStackTaierCWE-22DTStack Taier Upload Controller UploadController.java MultipartFile.getOrigin…
CVE-2026-595039.133.0PriorityPortal Generator addon to Priority ERP (developed by Soft Solutions)CWE-200Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Acto…
CVE-2026-595049.133.0PriorityPortal Generator addon to Priority ERP (developed by Soft Solutions)CWE-602Priority – CWE-602: Client-Side Enforcement of Server-Side Security
CVE-2026-736708.633.0SaurusSaurus CMS Community EditionCWE-89CMS Admin SQL Injection via db_data.php table_name Parameter
CVE-2026-664327.533.0denishuaWPJAM BasicCWE-1258WordPress WPJAM Basic plugin <= 7.0.2.1 - Sensitive Data Exposure vulnerability
CVE-2026-664437.533.0Pete NelsonREST API LogCWE-201WordPress REST API Log plugin <= 1.7.1 - Sensitive Data Exposure vulnerability
CVE-2026-704568.832.7RsyncProjectrsyncCWE-787rsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args()
CVE-2026-704588.832.7RsyncProjectrsyncCWE-787rsync 3.0.0 < 3.5.0 Out-of-Bounds Write via FLAG_HLINKED Handling
CVE-2026-736485.132.7railsrails-html-sanitizerCWE-79rails-html-sanitizer: Possible XSS vulnerability with certain configurations
CVE-2026-595069.332.7PriorityPortal Generator addon to Priority ERP (developed by Soft Solutions)CWE-306Priority – CWE-306: Missing Authentication for Critical Function
CVE-2026-728399.332.5filebrowserfilebrowserCWE-266filebrowser through 2.63.16 Privilege Escalation via Signup
CVE-2026-146725.332.5n/aPostgreSQLCWE-204PostgreSQL observable response discrepancy with non-default scram_iterations …
CVE-2026-537939.132.5RsyncProjectrsyncCWE-59rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode
CVE-2026-172208.232.3IBMiCWE-120IBM i is Affected By Multiple Vulnerabilities in Host Servers
CVE-2026-169827.532.4IBMiCWE-787IBM i is Affected By Multiple Vulnerabilities in Host Servers
CVE-2026-188467.532.4IBMiCWE-787IBM i is Affected By Multiple Vulnerabilities in Host Servers
CVE-2026-734879.032.1FlowiseAIFlowiseCWE-94Flowise before 3.1.3 Prompt Injection RCE via CSV Agent
CVE-2026-281618.832.1AonethemeService Finder BookingCWE-266WordPress Service Finder Booking plugin <= 6.2 - Privilege Escalation vulnera…
CVE-2026-676136.932.1usmannasircyberpanelCWE-22CyberPanel < 3.0.0 Path Traversal File Read via cloudAPI ReadReport
CVE-2026-735596.532.0vllm-projectvllmCWE-400vLLM: Completion prompt lists fan out into unbounded engine requests
CVE-2026-735655.332.0honojsnode-serverCWE-401@hono/node-server: Unauthenticated memory-leak DoS via aborted WebSocket hand…
CVE-2026-281499.831.8miniOrangeHeadless Single Sign OnCWE-502WordPress Headless Single Sign On plugin <= 1.6 - PHP Object Injection vulner…
CVE-2026-168877.531.8IBMiCWE-787IBM i is Affected By A Denial of Service Vulnerability DST/SST []
CVE-2026-170047.531.8IBMiCWE-835IBM i is Affected By Multiple Vulnerabilities in Host Servers
CVE-2026-171997.531.8IBMiCWE-770IBM i is Affected By Multiple Vulnerabilities in Host Servers
CVE-2026-172297.531.8IBMiCWE-835IBM i is Affected By Multiple Vulnerabilities in Host Servers
CVE-2026-735648.731.5fatedierfrpCWE-129frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway v…
CVE-2026-736456.631.5OpenZeppelinopenzeppelin-confidential-contractsCWE-190OpenZeppelin Confidential Contracts ERC7984ERC20Wrapper: once a wrapper is fi…
CVE-2026-619669.331.5denishuaWPJAM BasicCWE-89WordPress WPJAM Basic plugin <= 7.0.1 - SQL Injection vulnerability
CVE-2026-664469.331.5If-So Dynamic ContentIf-So Dynamic Content PersonalizationCWE-89WordPress If-So Dynamic Content Personalization plugin <= 1.10 - SQL Injectio…
CVE-2026-704596.931.5RsyncProjectrsyncCWE-908rsync 3.0.0 < 3.5.0 Daemon Crash via Malformed File List Entry
CVE-2026-5950010.031.3PriorityPortal Generator addon to Priority ERP (developed by Soft Solutions)CWE-287Priority - CWE-287: Improper Authentication
CVE-2026-172069.831.3IBMiCWE-787IBM i is Affected By Multiple Vulnerabilities in Host Servers
CVE-2026-281577.531.3Lasso Analytics, Inc.Do LassoCWE-35WordPress Do Lasso plugin <= 358 - Path Traversal vulnerability
CVE-2026-735667.531.1isaacsnode-tarCWE-400node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable sta…
CVE-2026-595058.630.8PriorityPortal Generator addon to Priority ERP (developed by Soft Solutions)CWE-284Priority - CWE-284: Improper Access Control
CVE-2026-664417.530.8MultiVendorXMultiVendorXCWE-862WordPress MultiVendorX plugin <= 5.0.10 - Broken Access Control vulnerability
CVE-2026-429316.530.7GiteaGitea Open Source Git ServerCWE-770Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
CVE-2026-734839.430.6FlowiseAIFlowiseCWE-78Flowise before 3.1.3 Sandbox Escape via Puppeteer
CVE-2026-537838.630.5RsyncProjectrsyncCWE-59rsync < 3.5.0 TOCTOU Race Condition Directory Escape via rrsync
CVE-2026-619807.530.4Daan.devOMGF ProCWE-22WordPress OMGF Pro plugin <= 5.2.7 - Arbitrary File Download vulnerability
CVE-2026-735097.630.3OpenListTeamOpenListCWE-22OpenList: Authenticated users can rename files outside their base path via ba…
CVE-2026-537946.930.3RsyncProjectrsyncCWE-1284rsync < 3.5.0 Denial of Service via --max-alloc=0 Logic Error
CVE-2026-735698.730.2NaturalIntelligencefast-xml-parserCWE-776fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
CVE-2026-457746.930.2oscal-compasscompliance-trestleCWE-22compliance-trestle Profile Import has an Arbitrary File Read via trestle:// U…
CVE-2026-458196.630.2web-platform-dxbaseline-browser-mappingCWE-705baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of th…
CVE-2026-273807.230.1magepeopleteamCar Rental ManagerCWE-502WordPress Car Rental Manager plugin <= 1.3.9 - PHP Object Injection vulnerabi…
CVE-2026-735626.529.9AutomatticmongooseCWE-1321Mongoose: Prototype pollution in the update casting via __proto__-prefixed do…
CVE-2026-559829.129.9GiteaGitea Open Source Git ServerCWE-200OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Sc…
CVE-2026-733058.829.9BudibasebudibaseCWE-269Budibase: Privilege escalation via public role assignment API missing app-lev…
CVE-2026-584204.429.6GiteaGitea Open Source Git ServerCWE-284Local File Inclusion via file:// URI in Migration Restore
CVE-2026-736158.729.5JovancodingNetwork-AICWE-436Network-AI SandboxPolicy before 5.15.1 Blocklist Bypass via Quote Mismatch
CVE-2026-736137.229.5filebrowserfilebrowserCWE-59filebrowser before 2.63.19 Out-of-Scope File Deletion via Symlink
CVE-2026-564439.629.3GiteaGitea Open Source Git ServerCWE-863Token public-only scope bypassed on Limited-visibility owners (Repository + P…
CVE-2026-736557.429.3triggerdotdevtrigger.devCWE-287Trigger.dev: Account Takeover via Cross-Provider OAuth Email Matching in Goog…
CVE-2026-704578.329.2RsyncProjectrsyncCWE-131rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg()
CVE-2026-679917.529.1n/an/aCWE-1333crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a …
CVE-2026-170884.329.1IBMiCWE-22IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager
CVE-2026-726606.529.0ElasticKibanaCWE-248Uncaught Exception in Kibana Leading to Denial of Service
CVE-2026-726836.529.0ElasticElasticsearchCWE-674Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
CVE-2026-726866.529.0ElasticElasticsearchCWE-674Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
CVE-2026-736148.728.9JovancodingNetwork-AICWE-436Network-AI ClaudeHookBridge Deny Pattern Bypass via Truncation
CVE-2026-197445.128.9maalferPentestifyCWE-79Stored Cross-site Scripting in Pentestify Markdown renderer via unescaped quotes
CVE-2026-726766.528.8ElasticFleet ServerCWE-94Improper Control of Generation of Code in Fleet Server Leading to Code Injection
CVE-2026-168615.328.8IBMiCWE-125IBM i is Affected By Multiple Vulnerabilities in NetServer
CVE-2026-170765.328.8IBMiCWE-770IBM i is Affected By Multiple Vulnerabilities in DRDA / DDM
CVE-2026-170775.328.8IBMiCWE-457IBM i is Affected By Multiple Vulnerabilities in DRDA / DDM
CVE-2026-170785.328.8IBMiCWE-400IBM i is Affected By A Denial of Service Vulnerability in DRDA / DDM []
CVE-2026-172125.328.8IBMiCWE-125IBM i is Affected By Multiple Vulnerabilities in NetServer
CVE-2026-172165.328.8IBMiCWE-190IBM i is Affected By Multiple Vulnerabilities in DRDA / DDM
CVE-2026-181467.228.7wpmanageninjaFluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form BuilderCWE-79Fluent Forms <= 6.2.11 - Unauthenticated Stored Cross-Site Scripting via Noti…
CVE-2026-733044.928.7BudibasebudibaseCWE-200Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role …
CVE-2026-664446.528.6kendysondPayment Forms for PaystackCWE-497WordPress Payment Forms for Paystack plugin <= 4.0.5 - Sensitive Data Exposur…
CVE-2026-738418.828.4openchoreoopenchoreoCWE-639OpenChoreo: Cross-project command execution and wirelog view access via OpenC…
CVE-2026-168687.528.4IBMiCWE-908IBM i is Affected By Multiple Vulnerabilities in NetServer
CVE-2026-281868.128.3themeficTravelfic ToolkitCWE-862WordPress Travelfic Toolkit plugin <= 1.5.1 - Broken Access Control vulnerabi…
CVE-2026-281596.528.3AonethemeService Finder BookingCWE-862WordPress Service Finder Booking plugin <= 6.2 - Broken Access Control vulner…
CVE-2026-170433.828.3IBMiCWE-22IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager
CVE-2026-735687.528.1libp2ppy-libp2pCWE-400py-libp2p: yamux connection DoS via oversized data frame
CVE-2026-664508.127.9Dylan KuhnGeo MashupCWE-98WordPress Geo Mashup plugin <= 1.13.18 - Local File Inclusion vulnerability
CVE-2026-666538.127.9Edge-ThemesBaristaCWE-98WordPress Barista theme <= 2.5.1 - Local File Inclusion vulnerability
CVE-2026-666568.127.9Mikado-ThemesFoton CoreCWE-98WordPress Foton Core plugin <= 1.1.1 - Local File Inclusion vulnerability
CVE-2026-666578.127.9Mikado-ThemesBiagiotti CoreCWE-98WordPress Biagiotti Core plugin <= 2.1.1 - Local File Inclusion vulnerability
CVE-2026-498577.427.7ymw0407auth-fetch-mcpCWE-918auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback
CVE-2026-584294.927.6GiteaGitea Open Source Git ServerCWE-284Public-Only Personal access tokens scope bypass in Organization and Permissio…
CVE-2026-197452.127.5CalixGigaSpireCWE-404Calix GigaSpire Web Management utilities_configurationsave.cgi denial of service
CVE-2026-197462.127.5CalixGigaSpireCWE-404Calix GigaSpire traceroute.cmd denial of service
CVE-2026-704638.627.3RsyncProjectrsyncCWE-863rsync 3.1.0 < 3.5.0 Authorization Bypass via auth users Directive Parsing
CVE-2026-736598.127.3triggerdotdevtrigger.devCWE-22Trigger.dev: Cross-tenant object read/write via path traversal in packet pres…
CVE-2026-736437.527.3nodecajs-yamlCWE-407js-yaml: Exponential parsing time in the flow collections leads to denial of …
CVE-2026-197165.127.3maalferPentestifyCWE-79Stored Cross-site Scripting in Pentestify user account deletion via unescaped…
CVE-2026-736569.927.2triggerdotdevtrigger.devCWE-639Trigger.dev: Cross-project deployment worker registration can modify another …
CVE-2026-567509.127.2GiteaGitea Open Source Git ServerCWE-284Gitea Remember-Me Token Theft Not Invalidating Attacker Session
CVE-2026-281568.527.2Lasso Analytics, Inc.Do LassoCWE-89WordPress Do Lasso plugin <= 358 - SQL Injection vulnerability
CVE-2026-281688.527.2Imran TauqeerCubeWPCWE-89WordPress CubeWP plugin <= 1.1.30 - SQL Injection vulnerability
CVE-2026-664308.527.2CODEPRESSVisitor Traffic Real Time Statistics ProCWE-89WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.10 - SQL Inje…
CVE-2026-666588.527.2MVPThemesReviewerCWE-89WordPress Reviewer plugin <= 3.14.2 - SQL Injection vulnerability
CVE-2026-172728.227.2IBMiCWE-787IBM i is Affected By a Denial of Service in HTTP Server []
CVE-2026-584177.527.2GiteaGitea Open Source Git ServerCWE-284REST API exposes organization membership of private organizations to public
CVE-2026-584277.527.2GiteaGitea Open Source Git ServerCWE-200Private org member list leaked via /members API endpoint — incomplete fix for…
CVE-2026-171979.827.0IBMiCWE-287IBM i is Affected By Multiple Vulnerabilities in Host Servers
CVE-2026-559842.726.5GiteaGitea Open Source Git ServerCWE-284Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
CVE-2026-736618.626.4FreePBXframeworkCWE-15FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup
CVE-2026-584367.526.4GiteaGitea Open Source Git ServerCWE-407ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticat…
CVE-2026-162413.826.5n/aPostgreSQLCWE-191PostgreSQL ECPG integer underflow can crash the client
CVE-2026-736548.526.3triggerdotdevtrigger.devCWE-1321Trigger.dev: Prototype pollution via run metadata operations → process-wide c…
CVE-2026-735085.326.2nettynettyCWE-772Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
CVE-2026-736588.226.0triggerdotdevtrigger.devCWE-20Trigger.dev: Cross-tenant object store read and write via URL path traversal
CVE-2026-619679.826.0miniOrangeminiorange otp verificationCWE-640WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation …
CVE-2026-664249.826.0Cozy Vision Technologies Pvt. Ltd.SMS Alert Order NotificationsCWE-266WordPress SMS Alert Order Notifications plugin <= 3.9.7 - Privilege Escalatio…
CVE-2026-666919.826.0scriptsbundleNokriCWE-640WordPress Nokri theme <= 1.6.6 - Broken Access Control vulnerability
CVE-2026-736207.225.9gitpython-developersGitPythonCWE-22GitPython before 3.1.57 Arbitrary File Overwrite and Read
CVE-2026-480997.126.0mar10wsgidavCWE-22WsgiDAV encoded dot segments can escape filesystem share roots
CVE-2026-584286.526.0GiteaGitea Open Source Git ServerCWE-424Release attachment extension allowlist bypass via web release edit form (vari…
CVE-2026-734087.625.9BudibasebudibaseCWE-89Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Databas…
CVE-2026-169296.525.9IBMiCWE-787IBM i is Affected By Multiple Vulnerabilities in Host Servers
CVE-2026-64704.325.8n/aPostgreSQLCWE-862PostgreSQL fails to check type USAGE privilege
CVE-2026-734869.025.6FlowiseAIFlowiseCWE-94Flowise before 3.1.3 Code Injection via CSV Agent customReadCSV
CVE-2026-726428.825.7ElasticElasticsearchCWE-823Use of Out-of-range Pointer Offset in the Elasticsearch Machine Learning Nati…
CVE-2026-197105.525.7SourceCodesterSimple Student Information SystemCWE-74SourceCodester Simple Student Information System view_department.php sql inje…
CVE-2026-197348.625.6RoskusProspero Flow CRMCWE-639IDOR in Prospero Flow CRM allows cross-tenant product disclosure and hijacking
CVE-2026-728568.625.6BudibasebudibaseCWE-640Budibase before 3.40.0 Authentication Bypass via Tenant Owner Email
CVE-2026-168537.525.5IBMiCWE-125IBM i is Affected By Multiple Vulnerabilities in NetServer
CVE-2026-170997.325.4IBMiCWE-287IBM i is Affected By Multiple Vulnerabilities in Navigator for i
CVE-2026-279996.525.4themeficTourficCWE-862WordPress Tourfic plugin <= 2.23.1 - Broken Access Control vulnerability
CVE-2026-281816.525.4AcyMailing Newsletter TeamAcyMailing SMTP NewsletterCWE-862WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Broken Access Contro…
CVE-2026-181938.925.3IBMiCWE-269IBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java Ru…
CVE-2026-170712.725.4IBMiCWE-22IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager
CVE-2026-498648.625.1butlerxwettyCWE-79wetty vulnerable to DOM XSS via file-download filename
CVE-2026-594998.625.0PriorityPortal Generator addon to Priority ERP (developed by Soft Solutions).CWE-200Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2026-595079.324.9PriorityPortal Generator addon to Priority ERP (developed by Soft Solutions)CWE-798Priority – CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensit…
CVE-2026-735679.124.9JuneAndGreensm-cryptoCWE-338sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.r…
CVE-2026-595018.224.9PriorityPortal Generator addon to Priority ERP (developed by Soft Solutions)CWE-284Priority – CWE-284: Improper Access Control
CVE-2026-87159.624.6HashiCorpToolingCWE-552Vault Secrets Operator vulnerable to arbitrary file read and credential exfil…
CVE-2026-180777.524.6IBMiCWE-787IBM i is Affected By Multiple Vulnerabilities in Simple Mail Transfer Protocol
CVE-2026-64693.824.5n/aPostgreSQLCWE-708PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership
CVE-2026-727777.724.4DayuanJiangnext-ai-draw-ioCWE-918Next AI Draw.io 0.4.16 SSRF via DNS Rebinding in parse-url
CVE-2026-736036.324.4FlowiseAIFlowiseCWE-862Flowise before 3.1.4 Credential Abuse via Text-to-Speech
CVE-2026-595025.324.3PriorityPortal Generator addon to Priority ERP (developed by Soft Solutions)CWE-203Priority - CWE-203: Observable Discrepancy
CVE-2026-735565.324.2vllm-projectvllmCWE-400vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (n…
CVE-2026-733029.024.1BudibasebudibaseCWE-287Budibase: OIDC SSO account takeover: incoming identity linked by email withou…
CVE-2026-03011.724.0Palo Alto NetworksCloud NGFWCWE-908PAN-OS: Information Disclosure Vulnerability in URL Filtering
CVE-2026-554028.723.8Absolute SecuritySecure AccessCWE-125CVE-2026-55402 is an out of bounds read vulnerability in Secure Access server…
CVE-2026-591098.723.9Zalktis Programmas (SIA "Zalktis Programmas")ZalktisCWE-20Zalktis: SQL injection via partner-controlled fields in imported e-invoices
CVE-2026-666617.723.9OnokazuDirectories ProCWE-266WordPress Directories Pro plugin <= 2.0.5 - Privilege Escalation vulnerability
CVE-2026-554016.923.9Absolute SecuritySecure AccessCWE-476CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-…
CVE-2026-735306.324.0flytohubflyto-coreCWE-918Flyto2 Core < 2.28.0 SSRF Guard Bypass via is_private_ip()
CVE-2026-281768.823.8Booking Activities TeamBooking ActivitiesCWE-502WordPress Booking Activities plugin <= 1.18.4 - PHP Object Injection vulnerab…
CVE-2026-537897.123.7RsyncProjectrsyncCWE-807rsync < 3.5.0 Arbitrary File Deletion via Malicious File List
CVE-2026-537927.123.7RsyncProjectrsyncCWE-129rsync < 3.5.0 Out-of-Bounds Read via Zero-Length Checksum Block
CVE-2026-169619.823.5IBMiCWE-89IBM i is Affected By SQL Injection Vulnerability in Db2 Mirror []
CVE-2026-197482.923.4TendaCH7CWE-330Tenda CH7 Kylin Web Service CWebSessionManager_ParseSession entropy
CVE-2026-275357.123.3solacewpSolace ExtraCWE-862WordPress Solace Extra plugin <= 1.6.0 - Broken Access Control vulnerability
CVE-2026-170756.523.3IBMiCWE-287IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager
CVE-2026-736475.623.2quasarframeworkquasarCWE-1321Quasar Framework: Prototype pollution in Quasar extend() utility
CVE-2026-175028.623.1IBMiCWE-787IBM i is Affected By Multiple Vulnerabilities in NetServer
CVE-2026-726707.723.0ElasticKibanaCWE-200Exposure of Sensitive Information to an Unauthorized Actor in Kibana Leading …
CVE-2026-240596.523.0GiteaGitea Open Source Git ServerCWE-269Gitea runner registration-token GET endpoint performs a write under a read-on…
CVE-2026-141829.822.9UnknownCustomer Email Verification for WooCommerceCWE-287Customer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account…
CVE-2026-728408.722.9openwrtluciCWE-266OpenWrt LuCI luci-mod-system-mounts ACL Root RCE via Crontab Write
CVE-2026-664627.522.8BookingWPWooCommerce AppointmentsCWE-497WordPress WooCommerce Appointments plugin <= 5.3.8 - Sensitive Data Exposure …
CVE-2026-664637.522.8Hassan FakihiCARRYCWE-201WordPress iCARRY plugin <= 2.9 - Sensitive Data Exposure vulnerability
CVE-2026-170458.122.8IBMiCWE-294IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager
CVE-2026-597657.522.6GiteaGitea Open Source Git ServerCWE-918SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal File…
CVE-2026-281897.422.6Roland BarkerParticipants DatabaseCWE-22WordPress Participants Database plugin <= 2.7.8.4 - Arbitrary File Deletion v…
CVE-2026-578976.522.5GiteaGitea Open Source Git ServerCWE-200Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
CVE-2026-168786.522.4IBMiCWE-125IBM i is Affected By Multiple Vulnerabilities in NetServer
CVE-2026-736659.322.1FreePBXucpCWE-862FreePBX UCP: Unauthenticated remote code execution via socket.io namespace au…
CVE-2026-559878.122.0GiteaGitea Open Source Git ServerCWE-863OAuth2 sign-in reactivates an administrator-deactivated account on auth sourc…
CVE-2026-583147.722.0GiteaGitea Open Source Git ServerCWE-918Two SSRF findings in Gitea 1.26.2
CVE-2026-172265.422.1IBMiCWE-125IBM i is Affected By Multiple Vulnerabilities in NetServer
CVE-2026-146784.322.0n/aPostgreSQLCWE-126PostgreSQL pg_trgm picksplit reads past end of buffer
CVE-2026-180244.322.0n/aPostgreSQLCWE-126PostgreSQL ascii() function reads past end of buffer
CVE-2026-736449.622.0OpenIdentityPlatformOpenDJCWE-285OpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder t…
CVE-2026-726366.521.9ElasticElasticsearchCWE-674Uncontrolled Recursion in Elasticsearch Wildcard Matching Leading to Denial o…
CVE-2026-168595.321.8IBMiCWE-125IBM i is Affected By Multiple Vulnerabilities in NetServer
CVE-2026-726297.121.7ElasticKibanaCWE-639Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-S…
CVE-2026-738439.621.6openchoreoopenchoreoCWE-306OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cl…
CVE-2026-280019.321.6WPDirectoryKitWP Directory KitCWE-89WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability
CVE-2026-281429.321.6ShamalliWeb Directory FreeCWE-89WordPress Web Directory Free plugin <= 1.7.13 - SQL Injection vulnerability
CVE-2026-619699.321.6Webilia Inc.ListdomCWE-89WordPress Listdom plugin <= 5.6.0 - SQL Injection vulnerability
CVE-2026-664369.321.6RealMag777Active Products Tables for WooCommerceCWE-89WordPress Active Products Tables for WooCommerce plugin <= 1.1.1 - SQL Inject…
CVE-2026-664589.321.6ThimPressRealPressCWE-89WordPress RealPress plugin <= 1.1.2 - SQL Injection vulnerability
CVE-2026-664729.321.6everestthemesEverest BackupCWE-89WordPress Everest Backup plugin <= 2.3.12 - SQL Injection vulnerability
CVE-2026-664789.321.6andy_moyleChurch AdminCWE-89WordPress Church Admin plugin <= 5.1.1 - SQL Injection vulnerability
CVE-2026-166926.521.5IBMiCWE-787IBM i is Affected By Multiple Vulnerabilities in Simple Mail Transfer Protocol
CVE-2026-498204.721.6getproboproboCWE-601Probo has an open redirect bypass via path normalization
CVE-2026-1541310.021.5UnknownLink FactoryCWE-912Link Factory - Backdoor
CVE-2026-736188.721.5budibaseserverCWE-943Budibase Server before 3.40.0 NoSQL Injection via JSON Parameter
CVE-2026-490896.521.5ElasticKibanaCWE-770Allocation of Resources Without Limits or Throttling in Kibana Leading to Den…
CVE-2026-734848.621.4FlowiseAIFlowiseCWE-184Flowise before 3.1.3 Sandbox Escape via Pandas Methods
CVE-2026-726386.521.4ElasticElasticsearchCWE-674Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
CVE-2026-726396.521.4ElasticElasticsearchCWE-789Memory Allocation with Excessive Size Value in Elasticsearch Highlighting Lea…
CVE-2026-726456.521.4ElasticElasticsearchCWE-789Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denia…
CVE-2026-726476.521.4ElasticElasticsearchCWE-674Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
CVE-2026-726516.521.4ElasticKibanaCWE-770Allocation of Resources Without Limits or Throttling in Kibana Leading to Den…
CVE-2026-726536.521.4ElasticKibanaCWE-770Allocation of Resources Without Limits or Throttling in Kibana Leading to Den…
CVE-2026-726566.521.4ElasticElasticsearchCWE-789Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denia…
CVE-2026-726596.521.4ElasticKibanaCWE-770Allocation of Resources Without Limits or Throttling in Kibana Leading to Den…
CVE-2026-726636.521.4ElasticKibanaCWE-407Inefficient Algorithmic Complexity in Kibana Leading to Denial of Service
CVE-2026-726676.521.4ElasticKibanaCWE-770Allocation of Resources Without Limits or Throttling in Kibana Leading to Den…
CVE-2026-726746.521.4ElasticKibanaCWE-770Allocation of Resources Without Limits or Throttling in Kibana Leading to Den…
CVE-2026-726786.521.4ElasticElasticsearchCWE-789Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denia…
CVE-2026-726796.521.4ElasticElasticsearchCWE-674Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
CVE-2026-726846.521.4ElasticElasticsearchCWE-770Allocation of Resources Without Limits or Throttling in Elasticsearch Leading…
CVE-2026-726876.521.4ElasticElasticsearchCWE-789Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denia…
CVE-2026-180205.321.4IBMiCWE-125IBM i is Affected By Multiple Vulnerabilities in NetServer
CVE-2026-197562.121.3Dromaralamp-cloudCWE-22Dromara lamp-cloud Code Generator DefGenProjectController.java path traversal
CVE-2026-619847.521.2AmauriWPMobile.AppCWE-862WordPress WPMobile.App plugin <= 11.77 - Broken Access Control vulnerability
CVE-2026-728519.021.1budibaseserverCWE-89Budibase before 3.40.0 SQL Injection via Unauthenticated Webhook
CVE-2026-538018.221.1RsyncProjectrsyncCWE-59rsync < 3.5.0 Symlink Race Condition Directory Traversal
CVE-2026-584339.120.9GiteaGitea Open Source Git ServerCWE-862Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organ…
CVE-2026-584398.120.9GiteaGitea Open Source Git ServerCWE-284Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approv…
CVE-2026-734859.020.8FlowiseAIFlowiseCWE-94Flowise before 3.1.3 Remote Code Execution via Airtable Agent
CVE-2026-584347.520.8GiteaGitea Open Source Git ServerCWE-200Private Repository Metadata Remains Accessible After Access Revocation
CVE-2026-494788.720.6sigstorefulcioCWE-918Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitutio…
CVE-2026-736228.720.7gitpython-developersGitPythonCWE-200GitPython before 3.1.55 Environment Variable Exfiltration via Remote.add()
CVE-2026-134607.520.7IBMStorage ScaleCWE-798The following vulnerabilities that can affect IBM Storage Scale and the Manag…
CVE-2026-736047.120.6FlowiseAIFlowiseCWE-200Flowise before 3.1.3 Credential Exposure via API
CVE-2026-733467.620.4MailchimpMailChimp For WooCommerceCWE-89WordPress MailChimp For WooCommerce plugin < 6.2 - SQL Injection vulnerability
CVE-2026-666936.520.4StylemixMotorsCWE-862WordPress Motors plugin <= 1.4.113 - Broken Access Control vulnerability
CVE-2026-194817.520.3@fastify/busboy@fastify/busboyCWE-754@fastify/busboy vulnerable to Denial of Service via prototype-named multipart…
CVE-2026-537986.920.2RsyncProjectrsyncCWE-704rsync < 3.5.0 Privilege Confusion via name-converter uid/gid mapping
CVE-2026-584406.820.2GiteaGitea Open Source Git ServerCWE-284Webhooks created by a collaborator keep firing after their repo access is rev…
CVE-2026-197535.520.3Model Context Protocolmcp-rdf-explorerCWE-918Model Context Protocol mcp-rdf-explorer MCP Server server.py explore_url serv…
CVE-2026-167228.820.1IBMiCWE-269IBM i is Affected By An Unauthorized Privileges Vulnerability in SQL []
CVE-2026-726666.820.1ElasticKibanaCWE-639Authorization Bypass Through User-Controlled Key in Kibana Leading to Unautho…
CVE-2026-736247.220.1gitpython-developersGitPythonCWE-88GitPython before 3.1.54 Arbitrary File Overwrite via diff
CVE-2026-726486.519.9ElasticEck OperatorCWE-526Cleartext Storage of Sensitive Information in an Environment Variable in Elas…
CVE-2026-728558.419.7budibaseserverCWE-918Budibase before 3.40.0 DNS Rebinding SSRF via OpenAPI and REST
CVE-2026-38355.319.7buildwpsPrevent Direct Access – Protect WordPress FilesCWE-285Prevent Direct Access – Protect WordPress Files <= 2.8.8.8 - Unauthenticated …
CVE-2026-726777.319.6ElasticKibanaCWE-23Relative Path Traversal in Kibana Fleet Leading to Unauthorized Deletion of U…
CVE-2026-537866.919.6RsyncProjectrsyncCWE-863rsync < 3.5.0 Filter Rule Bypass via --filter Merge Directive
CVE-2026-275438.119.5FluxBuilderMStore APICWE-266WordPress MStore API plugin <= 4.20.0 - Privilege Escalation vulnerability
CVE-2026-619798.119.5miniOrangeSAML SP Single Sign OnCWE-266WordPress SAML SP Single Sign On plugin <= 5.4.3 - Privilege Escalation vulne…
CVE-2026-168714.319.4IBMiCWE-787IBM i is Affected By Multiple Vulnerabilities in NetServer
CVE-2026-726504.319.3ElasticKibanaCWE-639Authorization Bypass Through User-Controlled Key in Kibana Leading to Informa…
CVE-2026-281746.519.2ArrayticsWP Event SOlutionCWE-201WordPress WP Event SOlution plugin <= 4.1.18 - Sensitive Data Exposure vulner…
CVE-2026-197512.119.2EnzoVezzaromcp-dominican-layerCWE-918EnzoVezzaro mcp-dominican-layer parse-csv tool index.ts axios.get server-side…
CVE-2026-197522.119.2EnzoVezzaromcp-dominican-layerCWE-918EnzoVezzaro mcp-dominican-layer PDF Parsing index.ts parse-pdf server-side re…
CVE-2026-146733.819.1n/aPostgreSQLCWE-426PostgreSQL amcheck does not clear untrusted search path
CVE-2026-585089.119.0GiteaGitea Open Source Git ServerCWE-284Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing r…
CVE-2026-584387.519.0GiteaGitea Open Source Git ServerCWE-862Cross-repository IDOR in issue-dependency removal lets an attacker tamper wit…
CVE-2026-457257.119.0oscal-compasscompliance-trestleCWE-73compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via …
CVE-2026-726576.519.0ElasticFleet ServerCWE-639Authorization Bypass Through User-Controlled Key in Fleet Server Leading to I…
CVE-2026-584325.919.0GiteaGitea Open Source Git ServerCWE-200Missing Authorization and Authorization Bypass Through User-Controlled Key an…
CVE-2026-578948.518.9GiteaGitea Open Source Git ServerCWE-918Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validat…
CVE-2026-736128.618.6filebrowserfilebrowserCWE-639File Browser before v2.63.22 Authorization Bypass via Recursive Operations
CVE-2026-736117.618.5filebrowserfilebrowserCWE-613File Browser 2.50.0 through 2.63.21 JWT Expiration Bypass
CVE-2026-168159.118.5IBMiCWE-787IBM i is Affected By Multiple Vulnerabilities in Simple Mail Transfer Protocol
CVE-2026-182498.418.5IBMiCWE-269IBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java Ru…
CVE-2026-734886.018.5FlowiseAIFlowiseCWE-639Flowise before 3.1.3 IDOR via customer-default-source endpoint
CVE-2026-726646.518.3ElasticKibanaCWE-862Missing Authorization in Kibana Leading to Unauthorized Execution of Endpoint…
CVE-2026-501054.318.3GiteaGitea Open Source Git ServerCWE-200RSS/Atom feed handlers bypass API-token scope & public-only confinement (inco…
CVE-2026-568586.118.3Go standard libraryhtml/templateCWE-79Fix Javascript regexp context tracking in html/template
CVE-2026-174764.818.2IBMiCWE-787IBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java Ru…
CVE-2026-136107.518.1UnknownKiviCareCWE-269KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration
CVE-2026-490964.318.0ElasticKibanaCWE-248Uncaught Exception in Kibana Cases Leading to Denial of Service
CVE-2026-726854.318.0ElasticElasticsearchCWE-407Inefficient Algorithmic Complexity in Elasticsearch Leading to Denial of Service
CVE-2026-174685.317.9IBMDocumentation OfflineCWE-321IBM Documentation Offline is vulnerable to information disclosure, session fo…
CVE-2026-735585.318.0vllm-projectvllmCWE-190vLLM: Cross-User Data Leak Vulnerability
CVE-2026-280028.517.9ArrayticsBookticsCWE-89WordPress Booktics plugin 1.0.22 - SQL Injection vulnerability
CVE-2026-704627.117.7RsyncProjectrsyncCWE-190rsync 3.1.0 < 3.5.0 Signed Integer Overflow via MSG_IO_TIMEOUT
CVE-2026-734894.317.8EugenyrusshCWE-129Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode re…
CVE-2026-728578.317.6BudibasebudibaseCWE-522Budibase before 3.40.0 Credential Exposure via STRING Fields
CVE-2026-36396.417.3buildwpsPPWP – Password Protect PagesCWE-79PPWP – Password Protect Pages <= 1.9.21 - Authenticated (Contributor+) Stored…
CVE-2026-735555.317.2vllm-projectvllmCWE-209vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Er…
CVE-2026-169677.517.1IBMiCWE-367IBM i is Affected By Multiple SQL Vulnerabilities [, ]
CVE-2026-726437.116.9ElasticKibanaCWE-863Incorrect Authorization in Kibana Agent Builder Leading to Disclosure and Tam…
CVE-2026-735733.116.9ZimbraCollaborationCWE-24In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability …
CVE-2026-726658.116.8ElasticKibanaCWE-862Missing Authorization in Kibana Leading to Unauthorized Execution of Host Res…
CVE-2026-584167.116.9GiteaGitea Open Source Git ServerCWE-280Fork-PR Actions task can read a third private repository via the collaborativ…
CVE-2026-726616.516.9ElasticKibanaCWE-862Missing Authorization in Kibana Leading to Information Disclosure
CVE-2026-726816.516.9ElasticKibanaCWE-862Missing Authorization in Kibana Leading to Privilege Escalation and Informati…
CVE-2026-578865.916.9GiteaGitea Open Source Git ServerCWE-639Cross-repository issue/comment attachment re-linking can expose private attac…
CVE-2026-167135.316.8IBMDocumentation OfflineCWE-1327IBM Documentation Offline is vulnerable to information disclosure, session fo…
CVE-2026-537886.916.8RsyncProjectrsyncCWE-93rsync < 3.5.0 Newline Injection via name-converter uid/gid mapping
CVE-2026-735576.316.7vllm-projectvllmCWE-362vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent pro…
CVE-2026-247918.116.6GiteaGitea Open Source Git ServerCWE-863Public-only tokens bypass private-resource restrictions on `/api/v1/user` sel…
CVE-2026-187156.516.4IBMiCWE-611IBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server…
CVE-2026-736276.016.5jupyterlabjupyterlabCWE-602JupyterLab 4.6.0 Plugin Manager Lock-Rule Enforcement Bypass
CVE-2026-726727.716.3ElasticKibanaCWE-863Incorrect Authorization in Kibana Leading to Disclosure of Elastic Defend End…
CVE-2026-568647.516.4Go toolchaincmd/goCWE-347Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
CVE-2026-726406.516.3ElasticEck OperatorCWE-441Unintended Proxy or Intermediary in Elastic Cloud on Kubernetes Leading to Cr…
CVE-2026-275387.516.3WPDirectoryKitWP Directory KitCWE-89WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability
CVE-2026-273457.516.0magepeopleteamTaxi Booking Manager for WooCommerceCWE-862WordPress Taxi Booking Manager for WooCommerce plugin <= 2.0.3 - Broken Acces…
CVE-2026-664317.516.0WoompaLoompaBitcoin Lightning Payment Gateway for WooCommerce (via CLINK)CWE-862WordPress Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) plugi…
CVE-2026-664617.516.0smepaySMEPay: UPI Gateway for WooCommerceCWE-862WordPress SMEPay: UPI Gateway for WooCommerce plugin <= 1.0.5 - Payment Bypas…
CVE-2026-664667.516.0weDevsStoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side CartCWE-862WordPress StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, D…
CVE-2026-664697.516.0Afonso MatosArvow AI SEO WriterCWE-862WordPress Arvow AI SEO Writer plugin <= 1.5.3 - Broken Access Control vulnera…
CVE-2026-728538.816.0BudibasebudibaseCWE-89Budibase before 3.40.0 SQL Injection via Oracle connector
CVE-2026-584426.516.0GiteaGitea Open Source Git ServerCWE-200Repository migration SSRF via multi-answer DNS allow-list bypass
CVE-2026-734827.215.8phplistphplist3CWE-352phpList < 3.7.0-RC5 Cross-Site Request Forgery via admins.php
CVE-2026-584254.315.7GiteaGitea Open Source Git ServerCWE-200OAuth token introspection returns metadata of tokens issued to other clients …
CVE-2026-736508.215.7svgsvgoCWE-79SVGO: removeScripts plugin leaves some executable scripts intact
CVE-2026-281556.515.6Lasso Analytics, Inc.Do LassoCWE-639WordPress Do Lasso plugin <= 358 - Insecure Direct Object References (IDOR) v…
CVE-2026-619786.515.6webhosting4ugrSecure Card Gateway for ePay Paycenter (Piraeus Bank)CWE-862WordPress Secure Card Gateway for ePay Paycenter (Piraeus Bank) plugin <= 1.0…
CVE-2026-664546.515.6Maruti MohantyWP Social AvatarCWE-862WordPress WP Social Avatar plugin <= 1.5 - Broken Access Control vulnerability
CVE-2026-664596.515.6Space CodesAI for SEOCWE-862WordPress AI for SEO plugin <= 2.4.2 - Broken Access Control vulnerability
CVE-2026-666606.515.6Scott PatersonContact Form 7 – PayPal & Stripe Add-onCWE-862WordPress Contact Form 7 – PayPal & Stripe Add-on plugin <= 2.5.1 - Broken Ac…

Results continue: ranks 401–606.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-13 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.