boxscore/security
Friday, August 14, 2026 · all times UTC← 2026-08-13 · archive · 2026-08-15 →

202 CVEs published August 14, 2026: 25 critical, 81 high, 75 medium, 20 low; 0 in KEV; 2 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 177 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published48921369714142563
KEV catalog size1670

837 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux416200123412969802730.17.8.0017+401
microsoft442180313112194288378331.87.8.0038-182
google4946172140228187351.16.5.0023+48
red hat1423642216615818400.07.1.0025+127
apple2246576811229372.87.1.0027+2
canonical11149320000.09.9.0029+11
suse551220000.07.3.0022+5
android010100161100.08.4.01710
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco315192590961427.57.8.0033+30
palo alto networks12270114101427.44.5.0019+2
fortinet7253612128624.06.0.0051-1
sonicwall1012354017216.77.8.0024+8
vmware01247012100.08.7.00440
netgear990054800.04.3.0031+9
ivanti38130033562.57.9.5751+3
checkpoint1541003240.09.3.2062+1
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache97234451187014020.97.5.0048+97
mozilla1734226501300.09.1.0031-1
gitlab132808162427.15.1.0026+13
github570520000.08.6.0041+5
docker140130100.05.7.0014+1
wordpress1412105250.08.8.3700+1
drupal01100051100.09.8.88320
kubernetes010001000.02.4.00240
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle01113212539304574030.37.6.00310
ibm19230061139946710.37.5.0030+192
adobe6010022512217544.07.8.0036+46
progress1639112080912.68.1.0027+16
solarwinds0201611011420.09.1.00500
veeam10123720400.08.6.0027+10
zohocorp472410000.08.8.0099+4
atlassian0303001300.08.0.00260
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link1523150612614.39.3.0209+15
siemens192011612100.07.3.0011+19
hikvision0704202114.37.2.00250
bosch030300000.08.1.00280
schneider electric031200100.08.7.00200
synology110100000.07.3.0013+1
honeywell010010000.06.9.00310
mitsubishi electric010100000.07.1.00130
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
elastic4867013540300.06.5.0027+48
mongodb3258337162200.07.1.0024+32
surrealdb057326253000.07.1.00250
siyuan-note4249215230000.07.1.0024+42
zephyrproject2749017266000.06.5.0016+26
gitea4848715224000.06.5.0027+48
netty34462891000.07.5.0046+3
grafana142314223000.06.5.0033-3

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.993199.99.8
CVE-2026-63030.956099.99.8
CVE-2026-39808.912199.8
CVE-2026-34486.829399.67.5
CVE-2026-25089.736099.49.8
CVE-2026-16232.733099.49.3
CVE-2026-60137.731099.45.9
CVE-2026-0770.568899.09.8
CVE-2026-62144.206297.39.1
CVE-2026-9198.173596.99.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.1040KEV
CVE-2026-898510.0.0660
CVE-2026-651610.0.0473
CVE-2026-4766810.0.0434
CVE-2026-4836210.0.0207
CVE-2026-1918810.0.0189
CVE-2026-7329910.0.0121
CVE-2026-4435910.0.0100
CVE-2026-4561810.0.0095
CVE-2025-7138910.0.0093
Most disclosures (vendor)
VendorCVEs
oracle1108
linux1068
microsoft476
google451
ibm292
red hat249
apache201
apple169
adobe75
elastic67
Most KEV additions (YTD)
VendorKEV
microsoft33
cisco14
apple7
fortinet6
google5
ivanti5
adobe4
langflow4
solarwinds4
synacor4
Most-affected ecosystems
EcosystemAdvisories
Maven66
PyPI5
Go3
npm3
Packagist2
crates.io2
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2021-27137DD-WRT0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-18556N-able0
CVE-2026-18577N-able0
CVE-2026-20316Cisco0
CVE-2026-20349Cisco0
CVE-2026-25089Fortinet0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171731
CVE-2021-27102Accellion2021-11-171731
CVE-2021-27101Accellion2021-11-171731
CVE-2021-27103Accellion2021-11-171731
CVE-2021-21017Adobe2021-11-171731
CVE-2021-28550Adobe2021-11-171731
CVE-2021-42013Apache2021-11-171731
CVE-2021-41773Apache2021-11-171731
CVE-2021-30858Apple2021-11-171731
CVE-2021-30860Apple2021-11-171731

Transactions

EXPLOIT PUBLISHEDCVE-2010-0738. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2010-1428. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2010-2861. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2012-0507. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2016-3351. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2019-25765 (ASP-CMS Project ASP-CMS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2021-30116. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2021-30119. Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-13328 (Unknown Food Menu). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-13610 (Unknown KiviCare). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-14229 (Unknown ECS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-14230 (Unknown ECS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16007 (AppFlowy-IO AppFlowy-Cloud). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16541 (Unknown Simply Schedule Appointments). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16611 (Unknown Product Feed PRO for WooCommerce by AdTribes). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18216 (Unknown Backup Migration). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-18807 (Unknown ECS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19710 (SourceCodester Simple Student Information System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19750 (Tenda CH). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19752 (EnzoVezzaro mcp-dominican-layer). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19753 (Model Context Protocol mcp-rdf-explorer). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19895 (opensourcepos Open Source Point of Sale). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19897 (mangroup dtale). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19900 (LB-LINK X-PRO). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19903 (SourceCodester Online Clothing Store). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19917 (code-projects Online Food Order System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-19920 (code-projects Online Shopping System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-34881 (OpenStack Glance). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-39883 (open-telemetry opentelemetry-go). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-4035 (mlflow/mlflow). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-43001 (OpenStack Keystone). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-54297 (lostisland faraday). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-59109 (Zalktis Programmas (SIA "Zalktis Programmas") Zalktis). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-62241 (MohibShaikh clawvet). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-72741 (goodrain rainbond). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-72777 (DayuanJiang next-ai-draw-io). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-73037 (DayuanJiang next-ai-draw-io). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-73481 (phplist3). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-73482 (phplist3). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-73506 (JanDeDobbeleer oh-my-posh). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-73514 (PostGIS address_standardizer). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-73515 (PostGIS). Public exploit reference added.

RESCOREDCVE-2016-1019. CVSS 7.8 → 9.8 (NVD).

RESCOREDCVE-2021-30116. CVSS 10 → 9.8 (NVD).

RESCOREDCVE-2021-30120. CVSS 9.9 → 7.5 (NVD).

RESCOREDCVE-2026-13601 (Red Hat Enterprise Linux 8). CVSS 7.1 → 6.5 (NVD).

RESCOREDCVE-2026-19757 (Dromara lamp-cloud). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-19758 (dromara lamp-cloud). CVSS 6.9 → 5.5 (NVD).

RESCOREDCVE-2026-20156 (Cisco RoomOS Software). CVSS 8.1 → 9.8 (NVD).

RESCOREDCVE-2026-20157 (Cisco RoomOS Software). CVSS 7.5 → 9.8 (NVD).

RESCOREDCVE-2026-34993 (aio-libs aiohttp). CVSS 6.4 → 7.3 (NVD).

RESCOREDCVE-2026-4035 (mlflow/mlflow). CVSS 9.1 → 7.7 (NVD).

RESCOREDCVE-2026-43001 (OpenStack Keystone). CVSS 7.9 → 8 (NVD).

Yesterday's Results

202 CVEs published. 25 box scores, 177 table rows — nothing truncated.

Baicells EG3661M LuCI Web luci os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    7.3   .0279   85.2     —
AFFECTED
  Product  Versions                Fixed
  EG3661M  BaiCE_BQ6_2.0.5.3_NA –  —
TIMELINE
  Aug 13  Reserved by CNA
  Aug 14  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 5 references · NVD status: Deferred
Tenable, Inc. Security Center — Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0224   81.3     —
AFFECTED
  Product          Versions     Fixed
  Security Center  unspecified  —
TIMELINE
  Aug 12  Reserved by CNA
  Aug 14  Published (CNA: tenable)
CWE-78 · CNA: tenable · 1 reference · NVD status: Undergoing Analysis
Tenable, Inc. Security Center — Remote Code Execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0200   79.2     —
AFFECTED
  Product          Versions     Fixed
  Security Center  unspecified  —
TIMELINE
  Aug 12  Reserved by CNA
  Aug 14  Published (CNA: tenable)
CWE-78 · CNA: tenable · 1 reference · NVD status: Undergoing Analysis
Tenable, Inc. Security Center — Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0193   78.3     —
AFFECTED
  Product          Versions     Fixed
  Security Center  unspecified  —
TIMELINE
  Aug 12  Reserved by CNA
  Aug 14  Published (CNA: tenable)
CWE-78 · CNA: tenable · 1 reference · NVD status: Undergoing Analysis
Haiwell IoT Cloud HMI Gateway OS Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0189   77.8     —
AFFECTED
  Product                        Versions     Fixed
  Haiwell IoT Cloud HMI Gateway  3.40.1.12 –  3.50.1.19
TIMELINE
  Aug 6   Reserved by CNA
  Aug 14  Published (CNA: icscert)
CWE-78 · CNA: icscert · 3 references · NVD status: Received
Tenable, Inc. Security Center — Improper Input Validation
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0156   73.2     —
AFFECTED
  Product          Versions     Fixed
  Security Center  unspecified  —
TIMELINE
  Aug 12  Reserved by CNA
  Aug 14  Published (CNA: tenable)
CWE-78 · CNA: tenable · 1 reference · NVD status: Undergoing Analysis
semaphoreui semaphore — Semaphore prior to version 2.18.20 OS Command Injection via git_url Repository Handling
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0156   73.1     —
AFFECTED
  Product    Versions     Fixed
  semaphore  unspecified  —
TIMELINE
  Aug 13  Reserved by CNA
  Aug 14  Published (CNA: VulnCheck)
CWE-88 · CNA: VulnCheck · 4 references · NVD status: Received
Cockpit CMS 2.14.0 Authenticated Command Injection via FFmpeg Filename
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0148   71.7     —
AFFECTED
  Product      Versions     Fixed
  Cockpit CMS  unspecified  —
TIMELINE
  Aug 13  Reserved by CNA
  Aug 14  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · 4 references · NVD status: Received
IBM Db2 Mirror for i is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  N  L  H    8.5   .0101   60.2     —
AFFECTED
  Product           Versions  Fixed
  Db2 Mirror for i  7.4 –     —
TIMELINE
  Jul 24  Reserved by CNA
  Aug 14  Published (CNA: ibm)
CWE-78 · CNA: ibm · 1 reference · NVD status: Received
IBM Db2 Mirror for i is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0085   55.3     —
AFFECTED
  Product           Versions  Fixed
  Db2 Mirror for i  7.4 –     —
TIMELINE
  Jul 24  Reserved by CNA
  Aug 14  Published (CNA: ibm)
CWE-22 · CNA: ibm · 1 reference · NVD status: Received
IBM Db2 Mirror for i is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0085   55.3     —
AFFECTED
  Product           Versions  Fixed
  Db2 Mirror for i  7.4 –     —
TIMELINE
  Aug 1   Reserved by CNA
  Aug 14  Published (CNA: ibm)
CWE-22 · CNA: ibm · 1 reference · NVD status: Received
MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0082   54.1     —
AFFECTED
  Product         Versions     Fixed
  Minds Platform  unspecified  —
TIMELINE
  Aug 13  Public exploit reference published
  Aug 13  Reserved by CNA
  Aug 14  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · 4 references · NVD status: Received
IBM Db2 Mirror for i is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0080   53.4     —
AFFECTED
  Product           Versions  Fixed
  Db2 Mirror for i  7.4 –     —
TIMELINE
  Jul 24  Reserved by CNA
  Aug 14  Published (CNA: ibm)
CWE-73 · CNA: ibm · 1 reference · NVD status: Received
Tenable, Inc. Security Center — Remote Code Execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0079   53.3     —
AFFECTED
  Product          Versions     Fixed
  Security Center  unspecified  —
TIMELINE
  Aug 12  Reserved by CNA
  Aug 14  Published (CNA: tenable)
CWE-95 · CNA: tenable · 1 reference · NVD status: Undergoing Analysis
IBM Db2 Mirror for i is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0077   52.5     —
AFFECTED
  Product           Versions  Fixed
  Db2 Mirror for i  7.4 –     —
TIMELINE
  Jul 24  Reserved by CNA
  Aug 14  Published (CNA: ibm)
CWE-287 · CNA: ibm · 1 reference · NVD status: Received
IBM Db2 Mirror for i is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0064   47.7     —
AFFECTED
  Product           Versions  Fixed
  Db2 Mirror for i  7.4 –     —
TIMELINE
  Jul 24  Reserved by CNA
  Aug 14  Published (CNA: ibm)
CWE-22 · CNA: ibm · 1 reference · NVD status: Received
ImpressCMS Authenticated RCE via PHP Custom Tag eval()
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0061   46.3     —
AFFECTED
  Product     Versions     Fixed
  ImpressCMS  unspecified  —
TIMELINE
  Aug 13  Reserved by CNA
  Aug 14  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · 3 references · NVD status: Received
IBM Db2 Mirror for i is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0060   45.9     —
AFFECTED
  Product           Versions  Fixed
  Db2 Mirror for i  7.4 –     —
TIMELINE
  Jul 24  Reserved by CNA
  Aug 14  Published (CNA: ibm)
CWE-287 · CNA: ibm · 1 reference · NVD status: Received
TOTOLINK A800R firewall.so cstecgi.cgi setMacFilterRules stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0060   45.9     —
AFFECTED
  Product  Versions                  Fixed
  A800R    4.1.2cu.5137_B20200730 –  —
TIMELINE
  Aug 14  Reserved by CNA
  Aug 14  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 6 references · NVD status: Deferred
Tenda W20E QoS Edit editQos lstAdd stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0060   45.9     —
AFFECTED
  Product  Versions                           Fixed
  W20E     15.11.0.6(1068_1546_841)_CN_TDC –  —
TIMELINE
  Aug 14  Reserved by CNA
  Aug 14  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 6 references · NVD status: Deferred
TOTOLINK A800R wps.so cstecgi.cgi setWiFiWpsConfig stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0060   45.9     —
AFFECTED
  Product  Versions                  Fixed
  A800R    4.1.2cu.5137_B20200730 –  —
TIMELINE
  Aug 14  Reserved by CNA
  Aug 14  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · 6 references · NVD status: Deferred
IBM Db2 Mirror for i is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  N  H  L    9.3   .0059   45.6     —
AFFECTED
  Product           Versions  Fixed
  Db2 Mirror for i  7.4 –     —
TIMELINE
  Jul 24  Reserved by CNA
  Aug 14  Published (CNA: ibm)
CWE-22 · CNA: ibm · 1 reference · NVD status: Received
IBM Db2 Mirror for i is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  L    8.2   .0059   45.6     —
AFFECTED
  Product           Versions  Fixed
  Db2 Mirror for i  7.4 –     —
TIMELINE
  Jul 24  Reserved by CNA
  Aug 14  Published (CNA: ibm)
CWE-22 · CNA: ibm · 1 reference · NVD status: Received
AVEVA Enterprise SCADA Deserialization of Untrusted Data
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   L   N   L   H   H    6.1   .0057   44.5     —
AFFECTED
  Product                                                                     Versions     Fixed
  AVEVA Enterprise SCADA                                                      2025 –       2025 P1
  AVEVA Enterprise SCADA HMI                                                  2024 –       2024 R2 HF7
  AVEVA Pipeline Operations for Gas/Liquids                                   unspecified  2025 P1
  AVEVA Pipeline Integrity Monitor (delivered on Pipeline Simulation media)   unspecified  2025 SP1 P2
  AVEVA Pipeline Training Simulator (delivered on Pipeline Simulation media)  unspecified  2025 SP1 P2
  Measurement Advisor                                                         unspecified  2025 P1
TIMELINE
  Jul 14  Reserved by CNA
  Aug 14  Published (CNA: icscert)
CWE-502 · CNA: icscert · 3 references · NVD status: Received
IBM Db2 Mirror for i is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0055   43.4     —
AFFECTED
  Product           Versions  Fixed
  Db2 Mirror for i  7.4 –     —
TIMELINE
  Jul 24  Reserved by CNA
  Aug 14  Published (CNA: ibm)
CWE-674 · CNA: ibm · 1 reference · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-736738.743.2Netis Systems Co., Ltd.Netis NC63 Wireless AC1200 RouterCWE-306Netis NC63 V3.0.0.3327 Unauthenticated Firmware Update with Missing Cryptogra…
CVE-2026-505237.842.7MicrosoftPowerShell 7.4CWE-77Microsoft PowerShell Remote Code Execution Vulnerability
CVE-2026-168798.842.3IBMDb2 Mirror for iCWE-285IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-662717.241.9DellWyse Management Suite (WMS)CWE-434Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unre…
CVE-2026-729708.341.3MicrosoftMicrosoft Edge (Chromium-based)CWE-122Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-500279.840.7doobidoomcp-memory-serviceCWE-306mcp-memory-service: Missing Authentication on Document API Endpoints Allows U…
CVE-2026-728198.740.7getgravgravCWE-94Grav CMS before 2.0.13 Remote Code Execution via ZIP Upload
CVE-2026-198127.440.2TOTOLINKA800RCWE-119TOTOLINK A800R product.so cstecgi.cgi UploadCustomModule stack-based overflow
CVE-2026-198447.440.2TOTOLINKA800RCWE-119TOTOLINK A800R ipv6.so cstecgi.cgi setRadvdCfg stack-based overflow
CVE-2026-738499.839.6emlogemlogCWE-306emlog allows unauthenticated reinstallation via `install.php?action=reinstall`.
CVE-2026-198275.539.3alldatacenteralldataCWE-22alldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputSt…
CVE-2026-198305.539.0TRENDnetTEW-816DRMCWE-400TRENDnet TEW-816DRM bftpd bftpd.conf allocation of resources
CVE-2026-728278.738.9getgravgravCWE-1336Grav CMS before 2.0.13 Remote Code Execution via Twig
CVE-2026-169055.338.6IBMDb2 Mirror for iCWE-287IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-171869.938.6IBMDb2 Mirror for iCWE-78IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-728249.338.5getgravgravCWE-862Grav before 1.0.13 API Key Scope Bypass via PagesController
CVE-2026-197887.438.4TendaAC1206CWE-119Tenda AC1206 httpd web management interface SetOnlineDevName set_device_name …
CVE-2026-197897.438.4TendaAC1206CWE-119Tenda AC1206 httpd web management interface WifiGuestSet set_wl_guest_iplist …
CVE-2026-197907.438.4TendaG0CWE-119Tenda G0 httpd Web Management module formSetPortMirror stack-based overflow
CVE-2026-197917.438.4TendaG0CWE-119Tenda G0 httpd web management interface module addStaticRoute stack-based ove…
CVE-2026-197927.438.4TendaG0CWE-119Tenda G0 httpd web management interface module setPortMapping buffer overflow
CVE-2026-198117.438.4TOTOLINKA800RCWE-119TOTOLINK A800R firewall.so cstecgi.cgi setIpQosRules stack-based overflow
CVE-2026-198147.438.4TOTOLINKA800RCWE-119TOTOLINK A800R firewall.so cstecgi.cgi setMacQos stack-based overflow
CVE-2026-198157.438.4TOTOLINKA800RCWE-119TOTOLINK A800R firewall.so cstecgi.cgi setParentalRules stack-based overflow
CVE-2026-198217.438.4TendaAC12CWE-119Tenda AC12 httpd web management interface SetSysAutoRebbotCfg formSetRebootTi…
CVE-2026-198237.438.4TendaW20ECWE-119Tenda W20E QoS Rule Deletion delQos formQOSRuleDel stack-based overflow
CVE-2026-198247.438.4TendaW20ECWE-119Tenda W20E addIpMacBind ipMacBindListStore stack-based overflow
CVE-2026-198457.438.4TOTOLINKA800RCWE-119TOTOLINK A800R lan.so cstecgi.cgi setStaticDhcpConfig stack-based overflow
CVE-2026-198467.438.4TOTOLINKA800RCWE-119TOTOLINK A800R firewall.so cstecgi.cgi setUrlFilterRules stack-based overflow
CVE-2026-181785.436.9IBMDb2 Mirror for iCWE-22IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-736839.236.7LaravelSocialiteCWE-294Laravel Socialite Facebook Provider Authentication Bypass via Nonce Replay
CVE-2026-728309.336.7getgravgravCWE-269Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass
CVE-2026-344927.035.7Johnson ControlsAirwallCWE-73Airwall - Arbitrary file read
CVE-2026-172096.335.5IBMDb2 Mirror for iCWE-79IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-197625.535.4DTStackTaierCWE-22DTStack Taier Chunk-Check Endpoint FileChunkController.java Paths.ge path tra…
CVE-2026-662707.235.3DellWyse Management Suite (WMS)CWE-434Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unre…
CVE-2026-466037.534.8golang.org/x/imagegolang.org/x/image/vp8lCWE-789Excessive memory allocation during VP8L decoding in golang.org/x/image
CVE-2026-198255.534.4SourceCodesterSimple Client Management SystemCWE-74SourceCodester Simple Client Management System Master.php save_service sql in…
CVE-2026-167088.334.1IBMDb2 Mirror for iCWE-15IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-582246.533.7Red HatRed Hat Enterprise Linux 10CWE-353Samba: ctdb fails to do integrity checking of received packets
CVE-2026-485289.833.6NCEASmetacatCWE-89Metacat has an unauthenticated SQL injection vulnerability
CVE-2026-728156.932.9go-chichiCWE-290go-chi chi v5.2.1 IP Spoofing via X-Forwarded-For Header
CVE-2026-728136.932.6actixactix-webCWE-248actix-files before 0.6.10 Denial of Service via empty Range header
CVE-2026-196316.932.3Tenable, Inc.Security CenterCWE-89SQL Injection
CVE-2026-198719.331.8RoskusProspero Flow CRMCWE-798Use of hard-coded credentials in Prospero Flow CRM employee onboarding
CVE-2026-728146.331.4actixactix-webCWE-22actix-web before 0.6.10 Information Disclosure via Files
CVE-2026-197635.131.3DTStackTaierCWE-22DTStack Taier Cluster Creation ClusterController.java FileUtils.deleteDirecto…
CVE-2026-198372.030.4WebkulBagistoCWE-200Webkul Bagisto Customer Search search information disclosure
CVE-2026-196298.630.3Tenable, Inc.Security CenterCWE-863Privilege Escalation
CVE-2026-170796.329.7IBMDb2 Mirror for iCWE-693IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-198292.129.6648540858wvp-GB28181-proCWE-22648540858 wvp-GB28181-pro Log File Download Endpoint LogController.java path …
CVE-2026-636502.029.5OpenVPNOpenVPNCWE-295OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated us…
CVE-2026-728229.327.6getgravgravCWE-306Grav before 1.0.13 Authentication Bypass via disable2fa
CVE-2026-691018.327.0datavanetisCWE-611Datavane TIS v5.0.0 XXE Injection via doEditWorkflow Endpoint
CVE-2026-129499.826.9Wishlist MemberWishlist MemberCWE-640Wishlist Member X <= 3.34.1 - Unauthenticated Account Takeover via 'mergewith…
CVE-2026-728206.926.9getgravgravCWE-22Grav 2.0.11 Path Traversal via Backup Profile Configuration
CVE-2026-728357.626.7filebrowserfilebrowserCWE-41filebrowser before v2.63.21 Access Rule Bypass via Path Canonicalization
CVE-2026-456997.526.4NetatalknetatalkCWE-191Netatalk has Integer Underflow → Stack Buffer Overflow in copydir()
CVE-2026-730516.326.4actixactix-webCWE-444actix-http before 3.12.1 HTTP Request Smuggling via CL.TE
CVE-2026-199097.526.3PAX TechnologyQ80CWE-59PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vuln…
CVE-2026-172275.426.1IBMDb2 Mirror for iCWE-89IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-198806.326.0QOS.CH SarlLogback-classicCWE-22Incomplete protection against CVE-2025-11226
CVE-2026-636494.125.7OpenVPNOpenVPNCWE-183The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha…
CVE-2026-198265.525.7alldatacenteralldataCWE-20alldatacenter alldata xxl-rpc Listener HessianSerializer.java Hessian2Input.r…
CVE-2026-152058.625.2UnknownPaymob for WooCommerceCWE-89Paymob for WooCommerce < 4.1.9 - Unauthenticated SQL Injection via Paymob Cal…
CVE-2026-736337.525.2Apache Software FoundationApache StrutsCWE-400Apache Struts: Unbounded read of a JSON request body
CVE-2026-728369.224.9filebrowserfilebrowserCWE-178FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass
CVE-2026-728109.224.0siyuan-notesiyuanCWE-862SiYuan before v3.7.4 Publish-Boundary Bypass via WebSocket
CVE-2026-196807.123.8Tenable, Inc.Security CenterCWE-89SQL Injection
CVE-2026-198342.023.5WebkulBagistoCWE-285Webkul Bagisto Admin Customer Impersonation Feature login-as-customer authori…
CVE-2025-714055.123.3go-chichiCWE-601go-chi chi before v5.2.2 Open Redirect via RedirectSlashes
CVE-2026-742455.923.2Red HatRed Hat OpenShift Update ServiceCWE-306Quay: unauthenticated exported logs download in quay
CVE-2026-633618.523.1LimeSurveyLimeSurveyCWE-79LimeSurvey Community Edition 7.0.5+260623 - Reflected XSS in HTML editor popup
CVE-2026-728269.322.8getgravgravCWE-266Grav before 1.0.13 Scope Bypass via createApiKey
CVE-2026-728299.322.8getgravgravCWE-269Grav before 1.0.13 API Key Scope Bypass via UsersController
CVE-2026-728318.722.8getgravgravCWE-863Grav through 2.0.11 Authentication Bypass via Flex Objects
CVE-2026-728378.722.6filebrowserfilebrowserCWE-284File Browser before 2.63.20 Privilege Escalation via Proxy Authentication
CVE-2026-498260.022.4concourseconcourseCWE-601Concourse login flow has an open redirect issue
CVE-2026-728387.122.0filebrowserfilebrowserCWE-770FileBrowser before 2.63.19 Disk Exhaustion via TUS Upload
CVE-2026-196395.322.0Tenable, Inc.Security CenterCWE-1284Improper Access Control
CVE-2026-198362.121.9WebkulBagistoCWE-285Webkul Bagisto Backend Customer Detail Feature view authorization
CVE-2026-198382.121.9WebkulBagistoCWE-285Webkul Bagisto Backend Reporting Endpoint sales authorization
CVE-2026-142906.821.5UnknownEmbed Google Photos albumCWE-79Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link …
CVE-2026-198282.121.3648540858wvp-GB28181-proCWE-22648540858 wvp-GB28181-pro Snapshot Endpoint PlayController.java path traversal
CVE-2026-16215.321.1Universal Software Inc.E-MunicipalityCWE-305Register Bypass in Universal Sotware's E-Municipality
CVE-2026-198708.620.6RoskusProspero Flow CRMCWE-639IDOR in Prospero Flow CRM allows cross-tenant payroll disclosure and creation
CVE-2026-184036.020.5LimeSurveyLimeSurveyCWE-89LimeSurvey Community Edition 7.0.5 - Authenticated SQL injection in CPDB
CVE-2026-180398.120.4UnknownEssential Addons for ElementorCWE-269Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation…
CVE-2026-197688.120.2DevolutionsPowerShell UniversalCWE-94Improper control of generation of code ('Code Injection') in the settings fea…
CVE-2026-728126.919.9siyuan-notesiyuanCWE-862SiYuan before v3.7.4 Missing Authorization via refreshBacklink
CVE-2026-728288.619.6getgravgravCWE-269Grav before 1.0.13 API Key Scope Bypass via InvitationsController
CVE-2026-738508.619.1emlogemlogCWE-89Emlog: Arbitrary SQL Execution Vulnerability in ai.php within queryDatabase()…
CVE-2026-499897.119.1cratecrateCWE-863CrateDB's Blob HTTP handler bypasses authorization
CVE-2026-278712.919.1Johnson ControlsTL280CWE-327TL280
CVE-2026-197842.119.0francoisjacquetRosarioSISCWE-285francoisjacquet RosarioSIS Referrals.php DBUpdate authorization
CVE-2026-168106.518.8bitpressadminBit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form BuilderCWE-89Bit Form <= 3.2.0 - Authenticated (Administrator+) SQL Injection via 'filterT…
CVE-2026-127434.918.8cservitaffiliate-toolkit – Multi-Network Affiliate & Amazon Product DisplayCWE-89affiliate-toolkit <= 3.8.8 - Authenticated (Administrator+) SQL Injection via…
CVE-2026-181097.218.4boldgridW3 Total CacheCWE-79W3 Total Cache <= 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Co…
CVE-2026-198352.018.1WebkulBagistoCWE-266Webkul Bagisto Customer Item Deletion Endpoint access control
CVE-2026-728338.718.0getgravgravCWE-269Grav 1.0.6 through 1.0.11 Privilege Escalation via Scoped API Keys
CVE-2026-196366.017.5Tenable, Inc.Security CenterCWE-1270Insuffucient Protections Lead to Brute Force
CVE-2026-742425.317.5Red HatRed Hat OpenShift Update ServiceCWE-639Quay: repository notification uuid idor in quay api
CVE-2026-742436.517.4Red HatRed Hat OpenShift Update ServiceCWE-306Quay: unauthenticated secscan notification endpoint in quay when psk is unset
CVE-2026-742506.317.1OpenStackIronicCWE-226In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail t…
CVE-2026-197645.517.1RaisecomCommunication Command and Dispatch Management PlatformCWE-74Raisecom Communication Command and Dispatch Management Platform getpwd.php sq…
CVE-2026-662725.317.1DellWyse Management Suite (WMS)CWE-200Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missi…
CVE-2026-728119.916.7siyuan-notesiyuanCWE-89SiYuan before v3.7.4 SQL Injection via backlink search
CVE-2026-197672.116.6itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System viewdoctortimings.php sql injection
CVE-2026-534726.316.4migration-plannerCWE-79Migration-planner: credentialurl validator accepts javascript: urls
CVE-2026-715705.115.7icagenda.comiCagenda extension for JoomlaCWE-284Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumerat…
CVE-2026-694147.815.0MicrosoftMicrosoft Malware Protection EngineCWE-269Microsoft Defender Elevation of Privilege Vulnerability
CVE-2026-198795.314.7Red HatRed Hat build of Apache Camel for Spring Boot 4CWE-681Io.undertow/undertow: undertow: http response header integrity issue due to c…
CVE-2026-500295.314.3sunnyadnjs-tomlCWE-697js-toml has silent type confusion via falsy-primitive duplicate-key bypass
CVE-2026-673659.213.7icagenda.comiCagenda extension for JoomlaCWE-89Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda <…
CVE-2026-728345.313.8filebrowserfilebrowserCWE-200filebrowser before 2.63.19 Permission Bypass via checksum
CVE-2026-198392.013.6SourceCodesterSimple Doctors Appointment SystemCWE-284SourceCodester Simple Doctors Appointment System save_file.php save_doctor un…
CVE-2026-199087.113.3PAX TechnologyQ80CWE-306PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability
CVE-2026-738455.313.3ondatackan-mcp-serverCWE-20CKAN MCP Server: MQA server allowlist bypass via unanchored regex (`isValidMq…
CVE-2026-574695.113.3KUNBUSPiCtoryCWE-352Cross-Site Request Forgery (CSRF) in KUNBUS PiCtory
CVE-2026-738443.713.1ondatackan-mcp-serverCWE-209CKAN MCP Server: Information disclosure via verbose error reflection
CVE-2026-167395.912.8UnknownEpeken All Kurir for WoocommerceCWE-287Epeken All Kurir <= 2.1.2 - Unauthenticated Order Payment Confirmation Forgery
CVE-2026-728166.912.6go-chichiCWE-290go-chi chi before 5.3.0 IP Spoofing via RealIP Middleware
CVE-2026-715718.612.5icagenda.comiCagenda extension for JoomlaCWE-89Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped n…
CVE-2026-197872.011.5SourceCodesterAir Cargo Management SystemCWE-74SourceCodester Air Cargo Management System Master.php save_cargo_type sql inj…
CVE-2026-197652.111.4eyaushevswagger-testcase-mcpCWE-918eyaushev swagger-testcase-mcp fetch_swagger swagger-parser.ts loadSource serv…
CVE-2026-736306.910.8siyuan-notesiyuanCWE-203SiYuan before v3.7.4 Information Disclosure via authFilePublishAccess
CVE-2026-197855.310.8francoisjacquetRosarioSISCWE-74francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injection
CVE-2026-167728.110.3AkauntingAkauntingCWE-269CVE-2026-16772
CVE-2026-728257.210.0getgravgravCWE-862Grav before 1.0.13 API-key scope cap bypass via ReportsController
CVE-2026-730486.99.5siyuan-notesiyuanCWE-862SiYuan before v3.7.4 Information Disclosure via getRefIDsByFileAnnotationID
CVE-2026-730496.99.5siyuan-notesiyuanCWE-863SiYuan before v3.7.4 Information Disclosure via getAttributeViewBacklinks
CVE-2026-728235.39.3getgravgravCWE-862Grav before 1.0.13 API-key scope cap bypass via DemoController
CVE-2026-196358.59.1Tenable, Inc.Security CenterCWE-78Local Privilege Escalation
CVE-2026-197947.29.0gamerzWP-StatsCWE-79WP-Stats <= 2.56 - Unauthenticated Stored Cross-Site Scripting
CVE-2026-742405.48.9Red HatRed Hat OpenShift Update ServiceCWE-287Quay: jwt claim validation bypasses in quay federated robot and sso authentic…
CVE-2026-742484.38.9OpenStackOctaviaCWE-863OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy a…
CVE-2026-199107.58.5PAX TechnologyQ80CWE-347PAX Technology Q80 Application Installer Signature Verification Bypass Remote…
CVE-2026-198412.38.4TRENDNETTEW-813DRUCWE-266TRENDNET TEW-813DRU vsftpd vsftpd.conf default permission
CVE-2026-742414.88.2Red HatRed Hat OpenShift Update ServiceCWE-90Quay: ldap referral filter injection in quay external ldap authentication
CVE-2026-728598.38.0budibaseserverCWE-863Budibase 3.39.4 before 3.40.0 Authorization Regression via S3 Presigned URL
CVE-2026-728325.17.9getgravgravCWE-79Grav before 2.0.12 Stored XSS via quoted-attribute bypass
CVE-2026-464397.87.5oscal-compasscompliance-trestleCWE-94compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-S…
CVE-2026-539707.56.8lucasgelfondZeroBrewCWE-494ZeroBrew version 0.3.1 and prior Missing Checksum Verification RCE via shim.rb
CVE-2026-123634.26.5zephyrprojectzephyrCWE-787Out-of-bounds write in LoRaWAN fragmented transport from a fragment index of 0
CVE-2026-738476.86.4emlogemlogCWE-352Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full dat…
CVE-2026-197865.36.3francoisjacquetRosarioSISCWE-352francoisjacquet RosarioSIS Modules.php cross-site request forgery
CVE-2026-471922.16.1siemenskasCWE-347kas's late signature validation may allow unnoticed repository manipulations
CVE-2026-477665.15.8containerscrunCWE-61crun follows rootfs /dev symlink while creating default devices
CVE-2026-471912.15.6siemenskasCWE-347kas checks out SHA-like git branches as valid commits
CVE-2026-648877.05.5Johnson ControlsAirwallCWE-321Airwall - Hardcoded Secrets
CVE-2026-673665.34.8icagenda.comiCagenda extension for JoomlaCWE-352Joomla Extension - icagenda.com - CSRF on frontend registration actions in iC…
CVE-2025-103084.34.8alianAstro Booking EngineCWE-352Astro Booking Engine <= 1.4.0 - Cross-Site Request Forgery to Settings Reset
CVE-2026-728176.94.7go-chichiCWE-345go-chi chi 0.9.0 before 5.3.0 IP Spoofing via X-Forwarded-For
CVE-2026-494579.14.6benoitcerlang_quicCWE-295QUIC has Broken TLS verification
CVE-2026-742445.94.0Red HatRed Hat OpenShift Update ServiceCWE-347Quay: stripe webhook accepts forged events without signature verification in …
CVE-2026-728215.13.7getgravgravCWE-79Grav Form Plugin before 9.1.15 Stored XSS via Radio Toggle
CVE-2026-738466.53.6ondatackan-mcp-serverCWE-345CKAN MCP Server: Cache-key canonicalization collision enables cache confusion…
CVE-2026-492825.13.2capstone-enginecapstoneCWE-125Capstone M68K and RISCV `cs_insn_name()` invalid IDs can trigger out-of-bound…
CVE-2026-742474.23.2Red HatRed Hat OpenShift Update ServiceCWE-918Quay: ssrf via build archive_url in quay build api
CVE-2026-198848.43.1Eclipse FoundationEclipse TheiaCWE-829In Eclipse Theia versions up to and including 1.69.0, opening a folder starts…
CVE-2026-492632.02.9capstone-enginecapstoneCWE-197Capstone WASM `br_table` instruction-size truncation can cause no-progress di…
CVE-2026-574726.92.5KUNBUSRevPiPyLoadCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'…
CVE-2026-574716.82.5KUNBUSRevPiPyLoadCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'…
CVE-2026-123668.82.2zephyrprojectzephyrCWE-416Use-after-free freeing an armed dynamically-allocated k_timer in Zephyr users…
CVE-2026-123648.42.1zephyrprojectzephyrCWE-822Missing user-space pointer validation in logging syscall z_log_msg_static_cre…
CVE-2026-499867.11.6cdeustCortexCWE-829Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR`
CVE-2026-196175.51.5Red HatRed Hat Enterprise Linux 10CWE-770Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config pa…
CVE-2026-197701.91.5feedmobfm-mcp-serversCWE-918feedmob fm-mcp-servers Download Endpoint index.ts downloadReport server-side …
CVE-2026-130024.41.4Red HatRed Hat Enterprise Linux 10CWE-835Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing
CVE-2026-463806.71.0oscal-compasscompliance-trestleCWE-918compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem
CVE-2026-123655.81.0zephyrprojectzephyrCWE-416Use-after-free in Zephyr delayable work-queue cancellation under SMP timing race
CVE-2026-131967.30.9KUNBUSpiControlCWE-787Out-of-bounds Write in KUNBUS piControl
CVE-2026-131977.30.8KUNBUSpiControlCWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Ra…
CVE-2026-131985.90.8KUNBUSpiControlCWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Ra…
CVE-2026-637007.80.4DellWyse Management Suite (WMS)CWE-269Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Inco…
CVE-2026-637017.80.2DellWyse Management Suite (WMS)CWE-269Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Impr…
CVE-2026-637025.50.2DellWyse Management Suite (WMS)CWE-798Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use o…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-08-14 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.