AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N H N 8.7 .0236 82.3 —
AFFECTED Product Versions Fixed Open1722 unspecified —
TIMELINE Aug 12 Reserved by CNA Aug 17 Published (CNA: VulnCheck)
338 CVEs published August 17, 2026: 66 critical, 111 high, 122 medium, 37 low; 0 in KEV; 40 with a public exploit reference; 2 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 313 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 6265 | 15070 | 1444 | 2563 |
| KEV catalog size | 1670 | |||
903 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 1264 | 2849 | 363 | 1678 | 98 | 0 | 27 | 3 | 0.1 | 7.8 | .0017 | +1248 |
| microsoft | 443 | 1804 | 131 | 1219 | 429 | 8 | 378 | 33 | 1.8 | 7.8 | .0038 | -196 |
| 49 | 461 | 72 | 140 | 228 | 18 | 73 | 5 | 1.1 | 6.5 | .0023 | +48 | |
| red hat | 147 | 369 | 25 | 168 | 158 | 18 | 4 | 0 | 0.0 | 7.1 | .0025 | +123 |
| apple | 34 | 278 | 57 | 71 | 139 | 4 | 93 | 7 | 2.5 | 6.5 | .0022 | +34 |
| canonical | 11 | 14 | 9 | 3 | 2 | 0 | 0 | 0 | 0.0 | 9.9 | .0029 | +11 |
| suse | 5 | 5 | 1 | 2 | 2 | 0 | 0 | 0 | 0.0 | 7.3 | .0022 | +5 |
| android | 0 | 1 | 0 | 1 | 0 | 0 | 16 | 1 | 100.0 | 8.4 | .0171 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 31 | 51 | 9 | 25 | 9 | 0 | 96 | 14 | 27.5 | 7.8 | .0033 | +24 |
| palo alto networks | 12 | 27 | 0 | 1 | 14 | 10 | 14 | 2 | 7.4 | 4.5 | .0019 | +2 |
| fortinet | 7 | 25 | 3 | 6 | 12 | 1 | 28 | 6 | 24.0 | 6.0 | .0051 | -3 |
| sonicwall | 10 | 12 | 3 | 5 | 4 | 0 | 17 | 2 | 16.7 | 7.8 | .0024 | +8 |
| vmware | 0 | 12 | 4 | 7 | 0 | 1 | 21 | 0 | 0.0 | 8.7 | .0044 | 0 |
| netgear | 9 | 9 | 0 | 0 | 5 | 4 | 8 | 0 | 0.0 | 4.3 | .0031 | +9 |
| ivanti | 3 | 8 | 1 | 3 | 0 | 0 | 33 | 5 | 62.5 | 7.9 | .5751 | +3 |
| checkpoint | 1 | 5 | 4 | 1 | 0 | 0 | 3 | 2 | 40.0 | 9.3 | .2062 | +1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 101 | 238 | 45 | 120 | 72 | 1 | 40 | 2 | 0.8 | 7.5 | .0048 | +100 |
| mozilla | 1 | 73 | 42 | 26 | 5 | 0 | 13 | 0 | 0.0 | 9.1 | .0031 | -1 |
| gitlab | 15 | 30 | 1 | 9 | 16 | 2 | 4 | 2 | 6.7 | 5.3 | .0026 | +15 |
| github | 5 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.6 | .0041 | +4 |
| wordpress | 2 | 5 | 1 | 3 | 1 | 0 | 5 | 2 | 40.0 | 8.8 | .0089 | +2 |
| docker | 1 | 4 | 0 | 1 | 3 | 0 | 1 | 0 | 0.0 | 5.7 | .0014 | +1 |
| drupal | 0 | 1 | 1 | 0 | 0 | 0 | 5 | 1 | 100.0 | 9.8 | .8832 | 0 |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0024 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 1113 | 212 | 539 | 304 | 57 | 40 | 3 | 0.3 | 7.6 | .0031 | -1 |
| ibm | 192 | 300 | 61 | 139 | 94 | 6 | 7 | 1 | 0.3 | 7.5 | .0030 | +161 |
| adobe | 60 | 100 | 22 | 51 | 22 | 1 | 75 | 4 | 4.0 | 7.8 | .0036 | +45 |
| progress | 19 | 42 | 11 | 23 | 8 | 0 | 9 | 1 | 2.4 | 8.1 | .0028 | +19 |
| solarwinds | 0 | 20 | 16 | 1 | 1 | 0 | 11 | 4 | 20.0 | 9.1 | .0050 | 0 |
| veeam | 10 | 12 | 3 | 7 | 2 | 0 | 4 | 0 | 0.0 | 8.6 | .0027 | +10 |
| zohocorp | 4 | 7 | 2 | 4 | 1 | 0 | 0 | 0 | 0.0 | 8.8 | .0099 | +4 |
| atlassian | 0 | 3 | 0 | 3 | 0 | 0 | 13 | 0 | 0.0 | 8.0 | .0026 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 16 | 24 | 15 | 0 | 6 | 2 | 26 | 1 | 4.2 | 9.3 | .0209 | +16 |
| siemens | 19 | 20 | 1 | 16 | 1 | 2 | 1 | 0 | 0.0 | 7.3 | .0011 | +19 |
| hikvision | 0 | 7 | 0 | 4 | 2 | 0 | 2 | 1 | 14.3 | 7.2 | .0025 | 0 |
| bosch | 0 | 3 | 0 | 3 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0028 | 0 |
| schneider electric | 0 | 3 | 1 | 2 | 0 | 0 | 1 | 0 | 0.0 | 8.7 | .0020 | 0 |
| synology | 1 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0.0 | 7.3 | .0013 | +1 |
| honeywell | 0 | 1 | 0 | 0 | 1 | 0 | 0 | 0 | 0.0 | 6.9 | .0031 | 0 |
| mitsubishi electric | 0 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0.0 | 7.1 | .0013 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| siyuan-note | 61 | 68 | 33 | 10 | 23 | 1 | 0 | 0 | 0.0 | 8.8 | .0025 | +61 |
| elastic | 48 | 67 | 0 | 13 | 54 | 0 | 3 | 0 | 0.0 | 6.5 | .0027 | +48 |
| mongodb | 32 | 58 | 3 | 37 | 16 | 2 | 2 | 0 | 0.0 | 7.1 | .0024 | +32 |
| surrealdb | 0 | 57 | 3 | 26 | 25 | 3 | 0 | 0 | 0.0 | 7.1 | .0025 | -2 |
| zephyrproject | 31 | 53 | 0 | 18 | 29 | 6 | 0 | 0 | 0.0 | 6.3 | .0016 | +30 |
| gitea | 48 | 48 | 7 | 15 | 22 | 4 | 0 | 0 | 0.0 | 6.5 | .0027 | +48 |
| netty | 5 | 46 | 6 | 29 | 10 | 1 | 0 | 0 | 0.0 | 7.5 | .0046 | +4 |
| grafana | 2 | 43 | 3 | 14 | 23 | 3 | 0 | 0 | 0.0 | 6.5 | .0033 | -4 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-8037 | .9931 | 99.9 | 9.8 |
| CVE-2026-63030 | .9560 | 99.9 | 9.8 |
| CVE-2026-34486 | .8293 | 99.6 | 7.5 |
| CVE-2026-16232 | .7330 | 99.4 | 9.3 |
| CVE-2026-60137 | .7310 | 99.4 | 5.9 |
| CVE-2026-0770 | .5688 | 99.0 | 9.8 |
| CVE-2026-62144 | .2062 | 97.3 | 9.1 |
| CVE-2021-27137 | .1649 | 96.7 | 8.1 |
| CVE-2026-15733 | .1354 | 96.1 | 9.8 |
| CVE-2026-63077 | .1072 | 95.4 | 9.8 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-72898 | 10.0 | .1040 | KEV |
| CVE-2026-8985 | 10.0 | .0660 | |
| CVE-2026-6516 | 10.0 | .0473 | |
| CVE-2026-47668 | 10.0 | .0434 | |
| CVE-2026-48362 | 10.0 | .0207 | |
| CVE-2026-19188 | 10.0 | .0189 | |
| CVE-2026-73299 | 10.0 | .0121 | |
| CVE-2026-44359 | 10.0 | .0100 | |
| CVE-2026-45618 | 10.0 | .0095 | |
| CVE-2025-71389 | 10.0 | .0093 |
| Vendor | CVEs |
|---|---|
| linux | 1915 |
| oracle | 1108 |
| microsoft | 462 |
| 451 | |
| ibm | 261 |
| red hat | 246 |
| apache | 204 |
| apple | 201 |
| adobe | 74 |
| siyuan-note | 68 |
| Vendor | KEV |
|---|---|
| microsoft | 33 |
| cisco | 14 |
| apple | 7 |
| fortinet | 6 |
| 5 | |
| ivanti | 5 |
| adobe | 4 |
| langflow | 4 |
| solarwinds | 4 |
| synacor | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 66 |
| PyPI | 5 |
| npm | 4 |
| Go | 3 |
| Packagist | 2 |
| crates.io | 2 |
| NuGet | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2021-27137 | DD-WRT | 0 |
| CVE-2025-68686 | Fortinet | 0 |
| CVE-2026-0770 | Langflow | 0 |
| CVE-2026-16232 | checkpoint | 0 |
| CVE-2026-16812 | Arista Networks | 0 |
| CVE-2026-18556 | N-able | 0 |
| CVE-2026-18577 | N-able | 0 |
| CVE-2026-20316 | Cisco | 0 |
| CVE-2026-20349 | Cisco | 0 |
| CVE-2026-34486 | Apache Software Foundation | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1734 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1734 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1734 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1734 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1734 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1734 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1734 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1734 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1734 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1734 |
ADDED TO KEV — CVE-2025-62593 (ray-project ray). Remediation due August 20, 2026.
EXPLOIT PUBLISHED — CVE-2018-8727. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2019-10869. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-23368 (wildfly-core). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-2332 (Eclipse Foundation Eclipse Jetty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-24842 (isaacs node-tar). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-27606 (rollup). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-27727 (swaldman mchange-commons-java). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-27962 (authlib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-28498 (authlib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-28802 (authlib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-29074 (svgo). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-32597 (jpadilla pyjwt). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-33487 (russellhaering goxmldsig). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-35172 (distribution). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-40938 (tektoncd pipeline). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-41134 (microsoft kiota). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-42041 (axios). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-42880 (argoproj argo-cd). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-42945 (F5 NGINX Plus). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-4598 (jsrsasign). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-4599 (jsrsasign). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-4600 (jsrsasign). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-4601 (jsrsasign). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-4602 (jsrsasign). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48526 (jpadilla pyjwt). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-4878 (Red Hat Enterprise Linux 10). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58010 (GNOME GLib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58012 (GNOME GLib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58013 (GNOME GLib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58014 (GNOME GLib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58015 (GNOME GLib). Public exploit reference added.
RESCORED — CVE-2023-6931 (Linux Kernel). CVSS 7.8 → 7 (NVD).
RESCORED — CVE-2025-6666 (motogadget mo.lock Ignition Lock). CVSS 1 → 0.3 (NVD).
RESCORED — CVE-2026-15370 (Red Hat Enterprise Linux 10). CVSS 6.7 → 7.3 (NVD).
RESCORED — CVE-2026-16713 (IBM Documentation Offline). CVSS 4.3 → 5.3 (NVD).
RESCORED — CVE-2026-16929 (IBM i). CVSS 5.3 → 6.5 (NVD).
RESCORED — CVE-2026-19895 (opensourcepos Open Source Point of Sale). CVSS 6.3 → 2.9 (NVD).
RESCORED — CVE-2026-19897 (mangroup dtale). CVSS 6.3 → 2.9 (NVD).
RESCORED — CVE-2026-19900 (LB-LINK X-PRO). CVSS 9.2 → 8.2 (NVD).
RESCORED — CVE-2026-19903 (SourceCodester Online Clothing Store). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-19917 (code-projects Online Food Order System). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-19920 (code-projects Online Shopping System). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-19922 (code-projects Online Shopping System). CVSS 5.1 → 2 (NVD).
RESCORED — CVE-2026-19925 (SourceCodester Stock Management System). CVSS 5.1 → 2 (NVD).
RESCORED — CVE-2026-19927 (OpenBoxes). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-19930 (Dolibarr). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-19933 (DefaultFuction Customer-Relationship-Management-In-C-Project). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-19958 (iatsiuk pptr-mcp). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-19961 (Edimax EW-7478APC). CVSS 9.4 → 8.6 (NVD).
RESCORED — CVE-2026-19962 (Edimax EW-7478APC). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-19963 (Edimax EW-7478APC). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-19964 (Jij-Inc Jij-MCP-Server). CVSS 5.1 → 2 (NVD).
RESCORED — CVE-2026-2100 (p11-glue p11-kit). CVSS 5.3 → 7.5 (NVD).
RESCORED — CVE-2026-2332 (Eclipse Foundation Eclipse Jetty). CVSS 7.4 → 9.1 (NVD).
RESCORED — CVE-2026-32591 (Red Hat Quay 3.1). CVSS 5.2 → 5.5 (NVD).
RESCORED — CVE-2026-33216 (nats-io nats-server). CVSS 8.6 → 7.5 (NVD).
RESCORED — CVE-2026-33217 (nats-io nats-server). CVSS 7.1 → 6.5 (NVD).
RESCORED — CVE-2026-33247 (nats-io nats-server). CVSS 7.4 → 5.3 (NVD).
RESCORED — CVE-2026-33997 (moby). CVSS 6.8 → 8.1 (NVD).
RESCORED — CVE-2026-35425 (Microsoft Azure API Management (APIM)). CVSS 8 → 7.2 (NVD).
RESCORED — CVE-2026-40938 (tektoncd pipeline). CVSS 7.5 → 8.5 (NVD).
RESCORED — CVE-2026-42041 (axios). CVSS 4.8 → 6.5 (NVD).
RESCORED — CVE-2026-4598 (jsrsasign). CVSS 8.7 → 7.7 (NVD).
RESCORED — CVE-2026-45998 (Linux). CVSS 7 → 7.8 (NVD).
RESCORED — CVE-2026-4600 (jsrsasign). CVSS 9.1 → 8.1 (NVD).
RESCORED — CVE-2026-4601 (jsrsasign). CVSS 9.4 → 8.8 (NVD).
RESCORED — CVE-2026-4602 (jsrsasign). CVSS 8.7 → 7.7 (NVD).
RESCORED — CVE-2026-46579 (Red Hat OpenShift Container Platform 4.12). CVSS 7.4 → 7.5 (NVD).
RESCORED — CVE-2026-4878 (Red Hat Enterprise Linux 10). CVSS 6.7 → 7 (NVD).
RESCORED — CVE-2026-52972 (Linux). CVSS 7 → 5.5 (NVD).
RESCORED — CVE-2026-53059 (Linux). CVSS 6.3 → 7.8 (NVD).
RESCORED — CVE-2026-57104 (Microsoft Azure Storage Explorer). CVSS 8.8 → 9.6 (NVD).
RESCORED — CVE-2026-58010 (GNOME GLib). CVSS 6.5 → 8.2 (NVD).
RESCORED — CVE-2026-58011 (GNOME GLib). CVSS 6.5 → 7.5 (NVD).
RESCORED — CVE-2026-58012 (GNOME GLib). CVSS 6.5 → 8.2 (NVD).
RESCORED — CVE-2026-58013 (GNOME GLib). CVSS 6.5 → 8.2 (NVD).
RESCORED — CVE-2026-58014 (GNOME GLib). CVSS 7.3 → 8.6 (NVD).
RESCORED — CVE-2026-58015 (GNOME GLib). CVSS 5.9 → 7.5 (NVD).
RESCORED — CVE-2026-58612 (Microsoft PowerShell 7.4). CVSS 7.4 → 7.5 (NVD).
RESCORED — CVE-2026-59845 (Red Hat Enterprise Linux 10). CVSS 5.3 → 5.9 (NVD).
RESCORED — CVE-2026-59847 (Red Hat Enterprise Linux 10). CVSS 5.9 → 7.5 (NVD).
ENRICHED — CVE-2018-8727. Received CVSS 7.5 and CPE data from NVD.
ENRICHED — CVE-2019-10869. Received CVSS 8.1 and CPE data from NVD.
ENRICHED — CVE-2026-53325 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-53382 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-53385 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-53393 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-53403 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-63794 (Linux). Received CVSS 7.8 and CPE data from NVD.
ENRICHED — CVE-2026-63798 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-63804 (Linux). Received CVSS 7.8 and CPE data from NVD.
ENRICHED — CVE-2026-64187 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64192 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64205 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64207 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64244 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64245 (Linux). Received CVSS 7.8 and CPE data from NVD.
ENRICHED — CVE-2026-64246 (Linux). Received CVSS 7.8 and CPE data from NVD.
ENRICHED — CVE-2026-64248 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64249 (Linux). Received CVSS 7.8 and CPE data from NVD.
ENRICHED — CVE-2026-64250 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64252 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64253 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64254 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64256 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64258 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64262 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64263 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64264 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64267 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64270 (Linux). Received CVSS 7.8 and CPE data from NVD.
ENRICHED — CVE-2026-64271 (Linux). Received CVSS 7.8 and CPE data from NVD.
ENRICHED — CVE-2026-64272 (Linux). Received CVSS 7.8 and CPE data from NVD.
ENRICHED — CVE-2026-64273 (Linux). Received CVSS 7.8 and CPE data from NVD.
ENRICHED — CVE-2026-64274 (Linux). Received CVSS 7.8 and CPE data from NVD.
ENRICHED — CVE-2026-64275 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64278 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64282 (Linux). Received CVSS 4.7 and CPE data from NVD.
ENRICHED — CVE-2026-64283 (Linux). Received CVSS 7.0 and CPE data from NVD.
ENRICHED — CVE-2026-64285 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64288 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64289 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64290 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64291 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64292 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64294 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64295 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-64297 (Linux). Received CVSS 5.5 and CPE data from NVD.
+ 6 more transactions — continued on page 2. Every change is listed; nothing truncated.
338 CVEs published. 25 box scores, 313 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N H N 8.7 .0236 82.3 —
AFFECTED Product Versions Fixed Open1722 unspecified —
TIMELINE Aug 12 Reserved by CNA Aug 17 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N L L L 2.0 .0205 79.7 —
AFFECTED Product Versions Fixed CF-N1-S 2.6.0.1 – —
TIMELINE Aug 16 Public exploit reference published Aug 16 Reserved by CNA Aug 17 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N A N N N 6.1 .0148 71.7 —
AFFECTED Product Versions Fixed kiota >= 1.30.0, < 1.34.0 – —
TIMELINE Aug 13 Reserved by CNA Aug 17 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U H H L 7.1 .0132 68.5 —
AFFECTED Product Versions Fixed Webmail 1.6.0 – —
TIMELINE Aug 17 Reserved by CNA Aug 17 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 6.9 .0131 68.2 —
AFFECTED Product Versions Fixed A1300 4.8.* – 4.9.0 AX1800 4.8.* – 4.9.0 AXT1800 4.8.* – 4.9.0 MT2500 4.8.* – 4.9.0 MT3000 4.8.* – 4.9.0 MT6000 4.8.* – 4.9.0 X3000 4.8.* – 4.9.0 XE3000 4.8.* – 4.9.0
TIMELINE Aug 16 Reserved by CNA Aug 17 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0109 62.5 —
AFFECTED Product Versions Fixed NetForensicMCP 2.1.0 – —
TIMELINE Aug 16 Public exploit reference published Aug 17 Reserved by CNA Aug 17 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 5.3 .0105 61.4 —
AFFECTED Product Versions Fixed A1300 4.0 – — AX1800 4.0 – — AXT1800 4.0 – — BE1400 4.0 – — BE3600 4.0 – — BE6500 4.0 – — BE9300 4.0 – — BE10000 4.0 – — E5800 4.0 – — MT2500 4.0 – — + 7 more
TIMELINE Aug 16 Reserved by CNA Aug 17 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 5.3 .0105 61.4 —
AFFECTED Product Versions Fixed BE9300 4.8.* – 4.9.0 MT6000 4.8.* – 4.9.0
TIMELINE Aug 16 Reserved by CNA Aug 17 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0097 58.9 —
AFFECTED Product Versions Fixed WN531P3 V250922 – — WN535M1 V250922 – —
TIMELINE Aug 16 Public exploit reference published Aug 17 Reserved by CNA Aug 17 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N N H 6.5 .0086 55.5 —
AFFECTED Product Versions Fixed YouTrack unspecified —
TIMELINE Aug 17 Reserved by CNA Aug 17 Published (CNA: JetBrains)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 7.4 .0083 54.4 —
AFFECTED Product Versions Fixed uptrain <= 0.7.1 – —
TIMELINE Mar 6 Reserved by CNA Aug 17 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 7.4 .0083 54.4 —
AFFECTED Product Versions Fixed uptrain <= 0.7.1 – —
TIMELINE Mar 6 Reserved by CNA Aug 17 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 7.4 .0083 54.4 —
AFFECTED Product Versions Fixed uptrain <= 0.7.1 – —
TIMELINE Mar 6 Reserved by CNA Aug 17 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0081 54.0 —
AFFECTED Product Versions Fixed WordPress unspecified —
TIMELINE Jul 22 Reserved by CNA Aug 17 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U L N H 7.1 .0080 53.5 —
AFFECTED Product Versions Fixed YouTrack unspecified —
TIMELINE Aug 17 Reserved by CNA Aug 17 Published (CNA: JetBrains)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0077 52.5 —
AFFECTED Product Versions Fixed Webmail 1.6.0 – —
TIMELINE Aug 17 Reserved by CNA Aug 17 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L H H 9.4 .0072 50.8 —
AFFECTED Product Versions Fixed GitLab 18.2 – —
TIMELINE Aug 10 Reserved by CNA Aug 16 Public exploit reference published Aug 17 Published (CNA: GitLab)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0071 50.6 —
AFFECTED Product Versions Fixed ipTIME A3004T 14.19.0 – —
TIMELINE Aug 16 Public exploit reference published Aug 16 Reserved by CNA Aug 17 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N L N L L L 1.9 .0069 49.9 —
AFFECTED Product Versions Fixed android-mcp-server cfb872b2446794193b58edd63f4dbf6af48a6292 – —
TIMELINE Aug 16 Public exploit reference published Aug 16 Reserved by CNA Aug 17 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0068 49.6 —
AFFECTED Product Versions Fixed netty < 4.1.137.Final – —
TIMELINE Jul 7 Reserved by CNA Aug 17 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0065 48.3 —
AFFECTED Product Versions Fixed ShareFile Storage Zones Controller unspecified —
TIMELINE Jul 17 Reserved by CNA Aug 17 Published (CNA: ProgressSoftware)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0065 48.2 —
AFFECTED Product Versions Fixed Official Document Management System unspecified —
TIMELINE Aug 17 Reserved by CNA Aug 17 Published (CNA: twcert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0062 47.0 —
AFFECTED Product Versions Fixed SWE-agent unspecified —
TIMELINE Aug 17 Reserved by CNA Aug 17 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0059 45.3 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Jun 7 Reserved by CNA Aug 17 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0056 43.8 —
AFFECTED Product Versions Fixed erpnext < 15.111.0 – —
TIMELINE Jul 23 Reserved by CNA Aug 17 Published (CNA: GitHub_M)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-71479 | 9.1 | 41.8 | QuantumNous | new-api | CWE-190 | New API: Integer overflow in quota billing yields negative charges (self-cred… |
| CVE-2026-16137 | 7.2 | 41.7 | Progress | ShareFile Storage Zones Controller | CWE-22 | Path traversal via unsanitized upload filename leads to arbitrary file write … |
| CVE-2026-75110 | 9.3 | 41.5 | MemTensor | MemOS | CWE-697 | MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET |
| CVE-2026-56685 | 7.3 | 41.1 | Dell | ObjectScale | CWE-78 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutraliz… |
| CVE-2026-44845 | 6.7 | 40.6 | jumpserver | jumpserver | CWE-1336 | JumpServer: Remote Command Execution (RCE) via Jinja Template Injection in Ap… |
| CVE-2026-47698 | 9.8 | 40.1 | patriksimek | vm2 | CWE-913 | vm2: Sandbox Breakout Using Dangerous Host Proto Mutators |
| CVE-2026-71979 | 8.7 | 39.4 | indilib | indi | CWE-121 | INDI indiserver 2.2.4.2 Stack Buffer Overflow via XML Tag Parsing |
| CVE-2026-57233 | 8.1 | 39.3 | notepad-plus-plus | notepad-plus-plus | CWE-22 | Notepad++: Path Traversal (Zip Slip) in WinGup Plugin Extraction |
| CVE-2026-64868 | 7.5 | 38.5 | QuantumNous | new-api | CWE-400 | New API: Unauthenticated payment webhooks allow memory and disk DoS via unbou… |
| CVE-2026-35219 | 7.1 | 38.4 | Budibase | budibase | CWE-918 | Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Byp… |
| CVE-2026-64859 | 9.1 | 38.3 | QuantumNous | new-api | CWE-200 | New API: User List API Leaks Root User Access Token Leading to Privilege Esca… |
| CVE-2026-74872 | 9.3 | 38.0 | jahlives | openssl_encrypt | CWE-426 | openssl_encrypt before 1.4.0 Arbitrary Code Execution via Whirlpool |
| CVE-2025-27621 | 7.7 | 37.9 | uptrain-ai | uptrain | CWE-287 | UpTrain has a Constant Default API Key |
| CVE-2026-56686 | 7.8 | 37.6 | Dell | ObjectScale | CWE-78 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutraliz… |
| CVE-2026-59910 | 7.8 | 37.6 | Dell | ObjectScale | CWE-78 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutraliz… |
| CVE-2026-40506 | 7.0 | 37.3 | openemr | openemr | CWE-22 | OpenEMR Path Traversal Arbitrary Directory Deletion via standard_tables_manag… |
| CVE-2026-15218 | 7.9 | 35.7 | Red Hat | Red Hat OpenShift AI (RHOAI) | CWE-266 | Models-as-a-service: red hat openshift ai: maas-api and maas-controller servi… |
| CVE-2026-68004 | 9.8 | 35.1 | n/a | n/a | CWE-284 | An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote atta… |
| CVE-2026-74895 | 9.3 | 34.0 | jahlives | openssl_encrypt | CWE-693 | openssl_encrypt before 1.4.0 Plugin Sandbox Bypass via Process Isolation |
| CVE-2026-68005 | 7.5 | 34.1 | n/a | n/a | CWE-400 | An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause … |
| CVE-2026-50776 | 7.5 | 33.6 | n/a | n/a | CWE-22 | Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/20… |
| CVE-2026-51346 | 9.1 | 33.5 | n/a | n/a | CWE-89 | SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4… |
| CVE-2026-74886 | 9.3 | 32.8 | jahlives | openssl_encrypt | CWE-184 | openssl_encrypt before 1.4.0 Plugin Import Guard Bypass |
| CVE-2026-19965 | 2.9 | 32.8 | n/a | automad | CWE-204 | automad Password Reset Endpoint UserController.php requestPasswordResetToken … |
| CVE-2026-59903 | 6.5 | 32.7 | netty | netty | CWE-524 | Netty: Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite |
| CVE-2026-74894 | 9.3 | 32.5 | jahlives | openssl_encrypt | CWE-287 | openssl_encrypt before 1.4.0 Authentication Bypass via Bearer Token |
| CVE-2026-19979 | 6.9 | 32.5 | GL.iNet | A1300 | CWE-639 | GL.iNet XE3000 WebDAV Service MOVE authorization |
| CVE-2026-19997 | 2.0 | 32.5 | Webkul | Bagisto | CWE-639 | Webkul Bagisto Backend Sales RMA Endpoint requests authorization |
| CVE-2026-75111 | 8.7 | 32.1 | evidentlyai | evidently | CWE-22 | Evidently UI Path Traversal via Dataset Materialization Filename |
| CVE-2026-71472 | 9.1 | 31.8 | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | CWE-78 | Acm-search-v2-rhel9: search-v2-operator: shell-command and sql injection in p… |
| CVE-2026-74799 | 9.2 | 31.7 | siyuan-note | siyuan | CWE-215 | SiYuan before 3.7.4 Unauthenticated Debug Endpoint Information Disclosure |
| CVE-2026-71518 | 8.7 | 31.6 | typemill | typemill | CWE-863 | Typemill < 2.26.0 Authorization Bypass via Media File Download Route |
| CVE-2026-73646 | 7.5 | 30.8 | postcss | postcss | CWE-22 | PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL… |
| CVE-2026-74238 | 8.7 | 30.6 | tier4 | nebula | CWE-125 | TIER IV Nebula 1.2.0 Heap Out-of-Bounds Read via VLP32 UDP Decoder |
| CVE-2026-74868 | 8.7 | 30.6 | siyuan-note | siyuan | CWE-307 | SiYuan before 3.7.4 Brute-Force Authentication via Publish Service |
| CVE-2026-19968 | 2.1 | 30.4 | Open Asset Import Library | Assimp | CWE-122 | Open Asset Import Library Assimp 3DGS MDL7 Model LWOLoader.h ReadFaces_3DGS_M… |
| CVE-2026-74878 | 9.3 | 30.3 | jahlives | openssl_encrypt | CWE-770 | openssl_encrypt before 1.4.0 TOTP Rate Limiter Bypass |
| CVE-2026-74798 | 9.3 | 29.6 | siyuan-note | siyuan | CWE-22 | SiYuan kernel Path Traversal via database_clean MCP tool |
| CVE-2026-19974 | 2.9 | 29.5 | treefrogframework | treefrog-framework | CWE-287 | treefrogframework treefrog-framework Session Cookie tsessioncookiestore.cpp s… |
| CVE-2026-64866 | 5.1 | 29.3 | QuantumNous | new-api | CWE-862 | New API: Admin can reset passkeys for same-level or higher-privileged users |
| CVE-2026-19971 | 5.3 | 29.3 | LB-Link | WR1210M | CWE-306 | LB-Link WR1210M Backup Endpoint backup.cgi main missing authentication |
| CVE-2026-75012 | 5.7 | 29.1 | TOTOLINK | EX1200L | CWE-476 | TOTOLINK EX1200L Password Configuration cstecgi.cgi setPasswordCfg null point… |
| CVE-2026-75013 | 5.7 | 29.1 | TOTOLINK | EX1200L | CWE-476 | TOTOLINK EX1200L cstecgi.cgi setWizardCfg null pointer dereference |
| CVE-2026-75479 | 8.7 | 28.7 | jeecgboot | jimureport | CWE-306 | JimuReport Unauthenticated Report Listing and Share Token Disclosure |
| CVE-2026-54356 | 7.1 | 28.2 | Budibase | budibase | CWE-862 | Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/atta… |
| CVE-2026-64849 | 9.3 | 27.9 | mlflow | mlflow | CWE-918 | MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook… |
| CVE-2026-19998 | 2.1 | 27.8 | code-projects | Online Shopping System | CWE-79 | code-projects Online Shopping System offersmail.php cross site scripting |
| CVE-2026-19996 | 2.1 | 27.4 | Webkul | Bagisto | CWE-269 | Webkul Bagisto Backend Customer Behavior Data Endpoint customers privileges m… |
| CVE-2026-63667 | 6.5 | 27.1 | apostrophecms | apostrophe | CWE-22 | ApostropheCMS: Arbitrary file read via import-export attachment-name path tra… |
| CVE-2026-71486 | 4.3 | 27.2 | vllm-project | vllm | CWE-400 | vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs wi… |
| CVE-2026-19970 | 2.1 | 27.1 | Open Asset Import Library | Assimp | CWE-122 | Open Asset Import Library Assimp Node MDLLoader.cpp AddBonesToNodeGraph_3DGS_… |
| CVE-2026-75006 | 5.8 | 27.1 | Roundcube | Webmail | CWE-918 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Casca… |
| CVE-2026-74899 | 9.3 | 26.9 | jahlives | openssl_encrypt | CWE-95 | openssl_encrypt before 1.4.0 Sandbox Escape via Type Hierarchy |
| CVE-2026-71980 | 8.7 | 26.8 | BelledonneCommunications | bcg729 | CWE-125 | Belledonne Communications bcg729 1.1.2 Out-of-Bounds Read via decodeSIDframe() |
| CVE-2026-61666 | 8.9 | 26.8 | faye | websocket-driver-ruby | CWE-248 | websocket-driver: Denial of service via malformed Host header |
| CVE-2026-75103 | 8.7 | 26.8 | crawlab-team | crawlab | CWE-639 | Crawlab Missing Authorization on Password Change Endpoint Allows Account Take… |
| CVE-2026-55674 | 9.3 | 26.6 | discourse | discourse | CWE-79 | Discourse: Cache poisoning/XSS via color scheme cookies |
| CVE-2026-74896 | 9.3 | 26.6 | jahlives | openssl_encrypt | CWE-693 | openssl_encrypt before 1.4.0 Sandbox Escape via Dunder Attribute Traversal |
| CVE-2026-74900 | 9.3 | 26.6 | jahlives | openssl_encrypt | CWE-391 | openssl_encrypt before 1.4.0 Weak Shared Secret via PQC Simulation Mode |
| CVE-2026-44846 | 6.2 | 25.7 | jumpserver | jumpserver | CWE-863 | JumpServer: Privilege Overwrite via Organization Invite Logic Flaw |
| CVE-2026-75014 | 5.5 | 25.7 | SourceCodester | Pet Grooming Management Software | CWE-89 | SourceCodester Pet Grooming Management Software get_barcode_data.php sql inje… |
| CVE-2026-73523 | 8.7 | 25.2 | COVESA | Open1722 | CWE-197 | COVESA Open1722 0.9.2 Stack Memory Disclosure via acf-can-listener.c Integer … |
| CVE-2026-75531 | 7.0 | 25.3 | pandora-analysis | pandora | CWE-79 | Stored Cross-Site Scripting in URL Observables via Lookyloo Submission Handle… |
| CVE-2026-74253 | 10.0 | 25.1 | regularlabs.com | Sourcerer extension for Joomla | CWE-94 | Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified r… |
| CVE-2026-45791 | 5.9 | 25.0 | Dokploy | dokploy | CWE-613 | Dokploy: Password Change Does Not Revoke Active Sessions |
| CVE-2026-75000 | 5.8 | 25.0 | Roundcube | Webmail | CWE-669 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS … |
| CVE-2026-73560 | 6.5 | 24.7 | vllm-project | vllm | CWE-918 | vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fet… |
| CVE-2026-47686 | 9.9 | 24.2 | patriksimek | vm2 | CWE-693 | vm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCE |
| CVE-2026-65976 | 6.5 | 24.2 | deskflow | deskflow | CWE-400 | Deskflow: Clipboard receiver can accumulate data beyond Deskflow's configured… |
| CVE-2026-12553 | 8.9 | 23.8 | HP Inc. | Web Jetadmin | CWE-787 | HP Web Jetadmin (WJA) - Potential Arbitrary File Read/Write |
| CVE-2026-71553 | 7.1 | 24.0 | apostrophecms | apostrophe | CWE-1321 | ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-requ… |
| CVE-2026-47683 | 8.7 | 23.6 | patriksimek | vm2 | CWE-770 | vm2: bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike |
| CVE-2026-74880 | 9.3 | 23.4 | jahlives | openssl_encrypt | CWE-598 | openssl_encrypt before 1.4.0 Token Leakage via Query Parameters |
| CVE-2026-65832 | 8.2 | 23.3 | deskflow | deskflow | CWE-125 | Deskflow - Unauthenticated server-controlled out-of-bounds read in ServerProx… |
| CVE-2026-75003 | 5.8 | 23.3 | Roundcube | Webmail | CWE-669 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() … |
| CVE-2026-74892 | 8.7 | 23.2 | jahlives | openssl_encrypt | CWE-798 | openssl_encrypt before 1.4.0 Hardcoded Secret Key |
| CVE-2026-75106 | 9.3 | 23.1 | OpnForm | OpnForm | CWE-340 | OpnForm Editable Submission Secret Derivation via Empty Hashids Salt |
| CVE-2026-19992 | 1.3 | 23.1 | Orange View Limited | DualSafe Password Manager & Digital Vault Extension | CWE-200 | Orange View Limited DualSafe Password Manager & Digital Vault Extension postM… |
| CVE-2026-66792 | 9.9 | 22.9 | Red Hat | Multicluster Global Hub | CWE-863 | Multicloud-operators-subscription: multicloud-operators-subscription: isclust… |
| CVE-2026-19987 | 6.9 | 22.8 | SourceCodester | Best Employee Management System | CWE-548 | SourceCodester Best Employee Management System Profile exposure of informatio… |
| CVE-2026-75045 | 9.1 | 22.4 | JetBrains | YouTrack | CWE-288 | In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an una… |
| CVE-2026-40126 | 4.8 | 22.3 | OutSystems | Service Center | CWE-79 | DOM-based Cross-Site Scripting in OutSystems Service Center |
| CVE-2026-67919 | 9.8 | 21.8 | n/a | n/a | CWE-94 | An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code vi… |
| CVE-2026-16467 | 7.5 | 21.8 | Dolusoft Software Technologies | Fortilogger | CWE-862 | Broken Access Control in Dolusoft Software's Fortilogger |
| CVE-2026-19969 | 2.1 | 21.8 | Open Asset Import Library | Assimp | CWE-120 | Open Asset Import Library Assimp 3DGS MDL7 Model Output Mesh Generator MDLLoa… |
| CVE-2026-71424 | 9.6 | 21.6 | onyx-dot-app | onyx | CWE-200 | Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers |
| CVE-2026-17639 | 6.9 | 21.4 | HP Inc | HP Smart Tank 5101 All-in-One Printer | CWE-400 | Certain HP Smart Tank All in One – Potential Denial of Service |
| CVE-2026-10080 | 6.5 | 21.4 | Mattermost | Mattermost | CWE-704 | Boards plugin panics on WebSocket command with non-string field types |
| CVE-2026-74800 | 9.4 | 21.3 | siyuan-note | siyuan | CWE-79 | SiYuan before v3.7.4 Stored XSS via assets endpoint |
| CVE-2026-68762 | 5.9 | 21.1 | JetBrains | Ktor | CWE-835 | In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompressi… |
| CVE-2026-75004 | 4.3 | 21.1 | Roundcube | Webmail | CWE-77 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name… |
| CVE-2026-63178 | 6.5 | 21.0 | onyx-dot-app | onyx | CWE-639 | Onyx Curator-scope IDOR: any curator can modify membership of arbitrary user … |
| CVE-2026-19994 | 2.1 | 21.0 | Webkul | Bagisto | CWE-639 | Webkul Bagisto Configuration Management execute authorization |
| CVE-2026-74891 | 8.7 | 20.9 | jahlives | openssl_encrypt | CWE-798 | openssl_encrypt before 1.4.0 Hardcoded Database Credentials |
| CVE-2026-45790 | 8.0 | 20.9 | Dokploy | dokploy | CWE-269 | Dokploy: Invitation Role Escalation Allows Organization Takeover |
| CVE-2026-75481 | 8.7 | 20.8 | skypilot-org | skypilot | CWE-269 | SkyPilot Authentication Bypass via Service Account Role Escalation |
| CVE-2026-48053 | 5.8 | 20.6 | learningequality | kolibri | CWE-918 | Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacil… |
| CVE-2026-74254 | 9.3 | 20.6 | joomlack.fr | Page Builder CK extension for Joomla | CWE-89 | Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 |
| CVE-2026-19693 | 8.1 | 20.5 | max-mapper | extract-zip | CWE-59 | extract-zip arbitrary file write outside the destination directory via a syml… |
| CVE-2026-74881 | 7.1 | 20.5 | jahlives | openssl_encrypt | CWE-942 | openssl_encrypt before 1.4.0 CORS Misconfiguration via Wildcard Origins |
| CVE-2026-74234 | 5.1 | 20.5 | Legora | Legora | CWE-95 | Legora < 2026-08-14 XSS via Mermaid gray-matter JavaScript Engine |
| CVE-2026-59893 | 7.5 | 20.4 | andialbrecht | sqlparse | CWE-1333 | sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to R… |
| CVE-2026-75010 | 6.4 | 20.3 | Roundcube | Webmail | CWE-669 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver… |
| CVE-2026-33437 | 8.1 | 20.3 | Stirling-Tools | Stirling-PDF | CWE-79 | Stirling PDF: Stored XSS in Info Summary |
| CVE-2026-75077 | 2.1 | 20.3 | SourceCodester | Class and Exam Timetabling System | CWE-79 | SourceCodester Class and Exam Timetabling System BSCE2.php cross site scripting |
| CVE-2026-75105 | 8.7 | 20.1 | phpipam | phpipam | CWE-639 | phpIPAM Temporary Subnet Share Information Disclosure via Address Parameter |
| CVE-2026-75529 | 6.9 | 20.1 | pandora-analysis | pandora | CWE-79 | Stored Cross-Site Scripting via MIME-Type Confusion in PDF Downloads of Pandora |
| CVE-2026-13700 | 5.9 | 19.7 | Unknown | WooMS | CWE-918 | WooMS <= 9.14 - Unauthenticated Server-Side Request Forgery and Sensitive Inf… |
| CVE-2026-19999 | 2.1 | 19.7 | Open Asset Import Library Assimp | Assimp | CWE-120 | Open Asset Import Library Assimp 3DGS MDL7 Bone Transformation Key MDLLoader.… |
| CVE-2026-75078 | 2.1 | 19.7 | SourceCodester | Class and Exam Timetabling System | CWE-79 | SourceCodester Class and Exam Timetabling System BSHRM1.php cross site scripting |
| CVE-2026-67868 | 9.8 | 19.6 | n/a | n/a | CWE-122 | A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in serve… |
| CVE-2026-45698 | 7.5 | 19.5 | Netatalk | netatalk | CWE-191 | Netatalk has Integer Underflow → Stack Buffer Overflow in deletedir() |
| CVE-2026-38165 | 9.8 | 19.3 | n/a | n/a | CWE-94 | A Server-Side Template Injection (SSTI) vulnerability in the Velocity templat… |
| CVE-2026-56677 | 8.6 | 19.4 | decolua | 9router | CWE-306 | 9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider T… |
| CVE-2026-75081 | 5.3 | 19.4 | Webkul | Bagisto | CWE-841 | Webkul Bagisto store behavioral workflow |
| CVE-2026-19993 | 2.1 | 19.4 | Webkul | Bagisto | CWE-841 | Webkul Bagisto RMA State Validation update-status behavioral workflow |
| CVE-2026-74998 | 7.2 | 19.0 | Roundcube | Webmail | CWE-79 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the… |
| CVE-2026-74884 | 8.7 | 18.6 | jahlives | openssl_encrypt | CWE-73 | openssl_encrypt before 1.4.0 Path Traversal via plugin_id |
| CVE-2026-54336 | 5.4 | 18.6 | jumpserver | jumpserver | CWE-22 | JumpServer: KoKo Web Terminal SFTP Path Traversal on Authorized Asset |
| CVE-2026-74801 | 8.6 | 18.4 | siyuan-note | siyuan | CWE-78 | SiYuan before 3.7.4 Local Privilege Escalation via elevator.exe |
| CVE-2026-74893 | 8.7 | 18.3 | jahlives | openssl_encrypt | CWE-798 | openssl_encrypt before 1.4.0 JWT Token Forgery via Hardcoded Secrets |
| CVE-2026-65822 | 7.6 | 18.3 | frappe | erpnext | CWE-89 | ERPNext: SQL Injection in "Inactive Customers" report via unvalidated `doctyp… |
| CVE-2026-19967 | 2.1 | 18.4 | Open Asset Import Library | Assimp | CWE-122 | Open Asset Import Library Assimp File Compression.cpp decompressBlock heap-ba… |
| CVE-2026-54284 | 8.7 | 18.2 | andialbrecht | sqlparse | CWE-407 | sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing… |
| CVE-2026-71491 | 8.7 | 18.2 | andialbrecht | sqlparse | CWE-400 | sqlparse: Quadratic O(n²) DoS in group_comments |
| CVE-2026-75079 | 6.9 | 18.2 | SourceCodester | Class and Exam Timetabling System | CWE-89 | SourceCodester Class and Exam Timetabling System edit_subject2.php sql injection |
| CVE-2026-75080 | 6.9 | 18.2 | SourceCodester | Class and Exam Timetabling System | CWE-89 | SourceCodester Class and Exam Timetabling System edit_subject1.php sql injection |
| CVE-2026-19988 | 2.1 | 18.3 | Alaev | SEO Tools Extension | CWE-80 | Alaev SEO Tools Extension Popup UI popup.html addDiv cross site scripting |
| CVE-2026-13202 | 7.3 | 18.1 | OpenText | Opentext Directory Services | CWE-79 | HTML Injection in OTDS Swagger UI |
| CVE-2026-74842 | 2.1 | 18.1 | Kira-Pgr | PromptShopMCP | CWE-918 | Kira-Pgr PromptShopMCP Image-Toolkit-MCP-Server server.py download_image serv… |
| CVE-2026-74877 | 8.7 | 18.0 | jahlives | openssl_encrypt | CWE-639 | openssl_encrypt before 1.4.0 Missing Ownership Verification via revoke_key |
| CVE-2026-74879 | 8.7 | 17.7 | jahlives | openssl_encrypt | CWE-209 | openssl_encrypt before 1.4.0 Information Disclosure via /ready endpoint |
| CVE-2026-75049 | 6.5 | 17.7 | JetBrains | YouTrack | CWE-862 | In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user… |
| CVE-2026-67678 | 9.8 | 17.7 | n/a | n/a | CWE-434 | File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote… |
| CVE-2026-74869 | 8.3 | 17.6 | stoatchat | stoatchat | CWE-862 | stoatchat before 0.15.0 Missing Authorization via Subscribe |
| CVE-2026-63409 | 8.2 | 17.6 | deskflow | deskflow | CWE-125 | Deskflow: Odd-length DSOP options vector causes out-of-bounds read in Deskflo… |
| CVE-2026-67918 | 7.5 | 17.6 | n/a | n/a | CWE-22 | Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote a… |
| CVE-2026-14832 | 5.3 | 17.5 | Unknown | ShopSmart Loyalty for WooCommerce | CWE-639 | ShopSmart Loyalty for WooCommerce <= 1.0.0 - Unauthenticated Sensitive Inform… |
| CVE-2026-74883 | 8.7 | 17.4 | jahlives | openssl_encrypt | CWE-693 | openssl_encrypt before 1.4.0 Sandbox Bypass via pathlib and io |
| CVE-2026-57485 | 8.5 | 17.3 | Stirling-Tools | Stirling-PDF | CWE-200 | Stirling-PDF: Internal Service Account API Key Disclosure via Pipeline Endpoint |
| CVE-2026-68517 | 6.5 | 17.4 | nicolargo | glances | CWE-942 | Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membersh… |
| CVE-2026-74874 | 8.7 | 17.2 | jahlives | openssl_encrypt | CWE-338 | openssl_encrypt before 1.4.0 Weak PRNG Steganography Pixel Selection |
| CVE-2026-16138 | 8.0 | 17.3 | Progress | ShareFile Storage Zones Controller | CWE-502 | Remote code execution via unsafe deserialization in Progress ShareFile Storag… |
| CVE-2026-11817 | 5.3 | 17.3 | Grafana | Grafana OSS | CWE-863 | CVE-2026-11817 CVE Record |
| CVE-2026-22072 | 8.3 | 16.9 | OPPO | OPPO Health | CWE-20 | Arbitrary URL Loading in WebView Leading to Token Leakage Risk |
| CVE-2026-9859 | 6.5 | 17.0 | Mattermost | Mattermost | CWE-863 | Mattermost Boards plugin didn’t enforce role-based authorization on board cha… |
| CVE-2026-19972 | 2.1 | 16.6 | itsourcecode | Hospital Management System | CWE-89 | itsourcecode Hospital Management System viewpatient.php sql injection |
| CVE-2026-75007 | 5.4 | 16.4 | Roundcube | Webmail | CWE-77 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search fi… |
| CVE-2026-9816 | 8.3 | 16.0 | Mattermost | Mattermost | CWE-863 | Insufficient server-side validation of board member role fields permits privi… |
| CVE-2026-64657 | 8.4 | 15.8 | Budibase | budibase | CWE-89 | Budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL |
| CVE-2026-75109 | 7.1 | 15.7 | determined-ai | determined | CWE-862 | Determined Missing Authorization Check on Generic Task Endpoints |
| CVE-2026-64865 | 6.0 | 15.8 | QuantumNous | new-api | CWE-362 | New API: Redis user quota cache overwrite via PUT /api/user/self allows quota… |
| CVE-2026-19986 | 2.1 | 15.6 | n/a | Adblock for Youtube Extension | CWE-285 | Adblock for Youtube Extension Event Listener contentscript.js updateDynamicRu… |
| CVE-2026-50772 | 9.8 | 15.4 | n/a | n/a | CWE-94 | An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to exe… |
| CVE-2026-50775 | 9.8 | 15.4 | n/a | n/a | CWE-918 | A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute … |
| CVE-2026-74901 | 9.3 | 15.4 | jahlives | openssl_encrypt | CWE-347 | openssl_encrypt before 1.4.0 Authentication Bypass via AES-CTR Fallback |
| CVE-2026-19650 | 7.1 | 15.3 | GitLab | GitLab | CWE-352 | Cross-Site Request Forgery (CSRF) in GitLab |
| CVE-2026-50601 | 6.6 | 15.3 | Acer | Planet9 desktop application | CWE-798 | Planet9 Hardcoded Credentials Vulnerability Information |
| CVE-2026-14564 | 9.0 | 15.0 | Innotim Software Telecommunications and Consulting Trade Ltd. Co. | Logsign SIEM | CWE-522 | Sensitive Data Exposure in Innotim Software's Logsign SIEM |
| CVE-2026-75480 | 7.1 | 15.1 | volcengine | OpenViking | CWE-863 | OpenViking Debug Vector Endpoints Multi-tenant Data Exposure |
| CVE-2026-68520 | 5.3 | 14.9 | nicolargo | glances | CWE-200 | Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values … |
| CVE-2026-63670 | 6.1 | 14.8 | apostrophecms | apostrophe | CWE-79 | ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` s… |
| CVE-2026-19966 | 2.1 | 14.7 | CodeCanyon | TimeCamp Integration for CRM | CWE-639 | CodeCanyon TimeCamp Integration for CRM Contact Information Update save_conta… |
| CVE-2026-18674 | 7.0 | 14.6 | Kong Inc. | Kong Mesh | CWE-345 | Kong Mesh multi-zone: the global control plane attributes KDS-synced resource… |
| CVE-2026-16471 | 7.5 | 14.3 | Dolusoft Software Technologies | Sonlogger | CWE-862 | Broken Access Control in Dolusoft Software's Sonlogger |
| CVE-2026-75044 | 8.1 | 14.1 | JetBrains | YouTrack | CWE-862 | In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missin… |
| CVE-2026-19980 | 5.3 | 13.7 | GL.iNet | A1300 | CWE-94 | GL.iNet XE3000 Language Update ui.update_langs code injection |
| CVE-2026-59829 | 4.3 | 13.7 | discourse | discourse | CWE-862 | Discourse: Review queue exposes flag-related private message excerpts to cate… |
| CVE-2026-74873 | 8.7 | 13.7 | jahlives | openssl_encrypt | CWE-214 | openssl_encrypt before 1.4.0 Password Exposure via CLI Argument |
| CVE-2026-67917 | 9.8 | 13.6 | n/a | n/a | CWE-89 | zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerab… |
| CVE-2026-73424 | 6.5 | 13.3 | withastro | astro | CWE-441 | Astro: Unauthenticated path override in the @astrojs/vercel ISR function |
| CVE-2026-63669 | 6.5 | 12.8 | apostrophecms | apostrophe | CWE-639 | ApostropheCMS: Missing destination-parent authorization in page `move()` allo… |
| CVE-2026-69146 | 6.5 | 12.9 | mlflow | mlflow | CWE-862 | MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth |
| CVE-2026-75051 | 8.1 | 12.7 | JetBrains | YouTrack | CWE-862 | In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer betwe… |
| CVE-2026-65343 | 7.5 | 12.7 | Apple | iOS and iPadOS | CWE-416 | A use after free issue was addressed with improved memory management. This is… |
| CVE-2026-16049 | 4.3 | 12.5 | Mattermost | Mattermost | CWE-862 | _GitLab Plugin allows cross-channel post injection and phishing via missing c… |
| CVE-2026-69148 | 7.1 | 12.3 | mlflow | mlflow | CWE-862 | MLflow: CreateModelVersion source validation does not check READ permission o… |
| CVE-2026-66795 | 9.1 | 12.3 | Red Hat | Multicluster Engine for Kubernetes | CWE-295 | Managedcluster-import-controller: managedcluster-import-controller: csr auto-… |
| CVE-2026-74999 | 5.4 | 12.1 | Roundcube | Webmail | CWE-79 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to addres… |
| CVE-2026-39254 | 9.8 | 11.7 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a re… |
| CVE-2026-39255 | 9.8 | 11.7 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a re… |
| CVE-2026-71566 | 9.3 | 11.7 | openshift-metal3 | fakefish | CWE-306 | KubeVirt backend is not authenticated |
| CVE-2026-74858 | 5.3 | 11.4 | jae-jae | fetcher-mcp | CWE-918 | jae-jae fetcher-mcp URL Validation security-credentials fetch_urls server-sid… |
| CVE-2026-19984 | 2.1 | 11.4 | jkawamoto | mcp-florence2 | CWE-918 | jkawamoto mcp-florence2 __init__.py get_images server-side request forgery |
| CVE-2026-67926 | 9.8 | 11.3 | n/a | n/a | CWE-94 | An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary c… |
| CVE-2026-67965 | 9.8 | 11.3 | n/a | n/a | CWE-78 | An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute … |
| CVE-2026-67925 | 6.1 | 11.3 | n/a | n/a | CWE-79 | Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attac… |
| CVE-2026-74887 | 9.3 | 11.0 | jahlives | openssl_encrypt | CWE-338 | openssl_encrypt before 1.4.0 Insecure Random Import in PQC Module |
| CVE-2026-50770 | 9.8 | 10.9 | n/a | n/a | CWE-269 | An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker… |
| CVE-2026-50774 | 9.8 | 10.9 | n/a | n/a | CWE-269 | An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privil… |
| CVE-2026-50773 | 7.8 | 10.9 | n/a | n/a | CWE-427 | An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20 allows … |
| CVE-2026-75046 | 4.3 | 10.9 | JetBrains | YouTrack | CWE-862 | In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumera… |
| CVE-2026-15623 | 9.4 | 10.6 | Google Cloud | Google SecOps (Chronicle SOAR) | CWE-89 | Authenticated Blind SQL Injection in Google Cloud SecOps SOAR Dashboard Widge… |
| CVE-2026-74876 | 9.3 | 10.4 | jahlives | openssl_encrypt | CWE-347 | openssl_encrypt before 1.4.0 Unverified Key Bundle Encryption |
| CVE-2026-74889 | 9.3 | 10.4 | jahlives | openssl_encrypt | CWE-326 | openssl_encrypt before 1.4.0 Weak Key Derivation via HKDF |
| CVE-2026-75048 | 8.2 | 10.2 | JetBrains | YouTrack | CWE-79 | In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-bloc… |
| CVE-2026-19973 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-89 | itsourcecode Hospital Management System viewpaymentreport.php sql injection |
| CVE-2026-20000 | 2.1 | 10.2 | itsourcecode | Hospital Management System | CWE-89 | itsourcecode Hospital Management System viewprescriptionrecord.php sql injection |
| CVE-2026-67854 | 9.8 | 10.1 | n/a | n/a | CWE-89 | SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execu… |
| CVE-2026-71567 | 7.7 | 9.6 | openshift-metal3 | fakefish | CWE-78 | User-controlled variables inserted unescaped into shell scripts and Kubernete… |
| CVE-2026-65329 | 5.9 | 9.5 | Apple | iOS and iPadOS | CWE-287 | An authentication issue was addressed with improved state management. This is… |
| CVE-2026-53960 | 5.3 | 9.6 | discourse | discourse | CWE-862 | Discourse: Hidden first-post excerpt is emitted in Q&A schema JSON-LD |
| CVE-2026-16045 | 4.3 | 9.5 | Mattermost | Mattermost | CWE-863 | Delegated OAuth tokens could revoke unrelated OAuth application authorizations |
| CVE-2026-54758 | 7.8 | 9.4 | notepad-plus-plus | notepad-plus-plus | CWE-121 | Notepad++: Stack Buffer Overflow in expandNppEnvironmentStrs |
| CVE-2026-70412 | 3.5 | 9.4 | Dell | iDRAC9 | CWE-1330 | Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to… |
| CVE-2026-19995 | 2.0 | 9.1 | Webkul | Bagisto | CWE-79 | Webkul Bagisto RMA Message send-message cross site scripting |
| CVE-2026-75104 | 6.8 | 8.9 | huggingface | transformers | CWE-22 | Hugging Face Transformers Path Traversal via Checkpoint Index |
| CVE-2026-67966 | 9.8 | 8.8 | n/a | n/a | CWE-306 | Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated re… |
| CVE-2026-74875 | 9.3 | 8.8 | jahlives | openssl_encrypt | CWE-345 | openssl_encrypt before 1.4.0 Schema Validation Bypass |
| CVE-2026-74870 | 8.7 | 8.7 | jahlives | openssl_encrypt | CWE-532 | openssl_encrypt before 1.4.8 Hardware Pepper Information Disclosure |
| CVE-2026-50771 | 6.1 | 8.3 | n/a | n/a | CWE-79 | Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allow… |
| CVE-2026-75053 | 5.4 | 8.1 | JetBrains | IntelliJ IDEA | CWE-918 | In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit d… |
| CVE-2026-52886 | 5.1 | 8.1 | notepad-plus-plus | notepad-plus-plus | CWE-22 | Notepad++: session.xml backupFilePath starts_with Bypass |
| CVE-2026-65339 | 5.0 | 6.9 | Apple | iOS and iPadOS | CWE-693 | A logic issue was addressed with improved checks. This issue is fixed in iOS … |
| CVE-2026-12630 | 4.3 | 7.0 | zephyrproject | zephyr | CWE-125 | 6LoWPAN IPHC uncompression out-of-bounds read on reserved destination address… |
| CVE-2026-73410 | 8.5 | 6.8 | Budibase | budibase | CWE-367 | Budibase: SSRF via DNS rebinding in the REST datasource integration |
| CVE-2026-75108 | 5.3 | 6.9 | next-terminal | next-terminal | CWE-862 | Next Terminal Missing Per-Asset Authorization on Portal Endpoints |
| CVE-2026-16044 | 5.4 | 6.7 | Mattermost | Mattermost | CWE-863 | Insufficient validation of guest board admin privileges on archive import |
| CVE-2026-19975 | 1.3 | 6.7 | Azuriom | CMS | CWE-367 | Azuriom CMS Money Transfer ProfileController.php transferMoney toctou |
| CVE-2026-67967 | 9.8 | 6.6 | n/a | n/a | CWE-121 | Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attack… |
| CVE-2026-65346 | 8.8 | 6.7 | Apple | iOS and iPadOS | CWE-190 | An integer overflow was addressed with improved input validation. This issue … |
| CVE-2026-55704 | 4.3 | 6.6 | discourse | discourse | CWE-862 | Discourse: Shared-draft titles and excerpts leak through group post serializa… |
| CVE-2026-74888 | 8.7 | 6.4 | jahlives | openssl_encrypt | CWE-327 | openssl_encrypt before 1.4.0 Non-Standard PBKDF2 Key Derivation |
| CVE-2026-12629 | 4.6 | 6.3 | zephyrproject | zephyr | CWE-835 | PL011 UART error interrupts never cleared, enabling an external-peer interrup… |
| CVE-2026-74890 | 9.3 | 6.2 | jahlives | openssl_encrypt | CWE-345 | openssl_encrypt before 1.4.0 HMAC Authentication Bypass via Environment Variable |
| CVE-2026-12519 | 5.0 | 6.0 | zephyrproject | zephyr | CWE-787 | Out-of-bounds stack read and write in Zephyr WNC-M14A2A modem socket-notify p… |
| CVE-2026-50769 | 9.8 | 5.9 | n/a | n/a | CWE-89 | The CRM+ application before and including version 2025.6 from Brainformatik i… |
| CVE-2026-16047 | 4.3 | 5.8 | Mattermost | Mattermost | CWE-862 | Board channel linking without read channel permission validation |
| CVE-2026-67960 | 9.8 | 5.5 | n/a | n/a | CWE-94 | An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code vi… |
| CVE-2026-46345 | 8.4 | 5.5 | oscal-compass | compliance-trestle | CWE-22 | compliance-trestle - jinja has an Arbitrary File Write via Path Traversal |
| CVE-2026-74579 | await | 5.3 | Linux | Linux | — | netfilter: nft_payload: fix mask build for partial field offload |
| CVE-2026-9693 | 3.5 | 5.3 | Mattermost | Mattermost | CWE-459 | Mattermost thread memberships persist after team removal, exposing private ch… |
| CVE-2026-65349 | 6.6 | 5.1 | Apple | iOS and iPadOS | CWE-125 | An out-of-bounds read was addressed with improved input validation. This issu… |
| CVE-2026-65330 | 6.5 | 5.1 | Apple | iOS and iPadOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-65347 | 6.5 | 5.1 | Apple | iOS and iPadOS | CWE-400 | The issue was addressed with improved checks. This issue is fixed in iOS 26.6… |
| CVE-2026-10527 | 6.3 | 5.0 | Mattermost | Mattermost | CWE-863 | Boards plugin retains Board Admin rights for users demoted to System Guest |
| CVE-2026-16048 | 6.3 | 5.0 | Mattermost | Mattermost | CWE-863 | Channel member roles accept out-of-scope roles |
| CVE-2026-34398 | 7.8 | 5.0 | FreeCAD | FreeCAD | CWE-95 | FreeCAD: Arbitrary Code Execution via eval() on untrusted project file metada… |
| CVE-2026-43667 | 6.5 | 5.0 | Apple | iOS and iPadOS | CWE-617 | A reachable assertion was addressed with improved input validation. This issu… |
| CVE-2026-75056 | 7.8 | 4.9 | JetBrains | IntelliJ IDEA | CWE-78 | In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was p… |
| CVE-2026-16046 | 4.3 | 4.9 | Mattermost | Mattermost | CWE-863 | Missing run-state validation on finished playbook runs |
| CVE-2026-67961 | 7.8 | 4.8 | n/a | n/a | CWE-94 | An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code v… |
| CVE-2026-42163 | 9.8 | 4.7 | n/a | n/a | CWE-284 | Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to int… |
| CVE-2026-51977 | 9.1 | 4.7 | n/a | n/a | CWE-321 | An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1… |
| CVE-2026-15754 | 4.2 | 4.7 | Mattermost | Mattermost | CWE-863 | Missing per-channel team-scope check in ABAC access control policy unassign a… |
| CVE-2026-64715 | 6.5 | 4.4 | Apple | Safari | CWE-416 | A use-after-free issue was addressed with improved memory management. This is… |
| CVE-2026-64780 | 4.3 | 4.4 | Apple | Safari | CWE-119 | The issue was addressed with improved checks. This issue is fixed in Safari 2… |
| CVE-2026-64781 | 4.3 | 4.4 | Apple | Safari | CWE-20 | The issue was addressed with improved input validation. This issue is fixed i… |
| CVE-2026-64779 | 3.1 | 4.4 | Apple | Safari | CWE-362 | A memory corruption vulnerability was addressed with improved locking. This i… |
| CVE-2026-42164 | 9.8 | 4.3 | n/a | n/a | CWE-200 | Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section fun… |
| CVE-2026-42162 | 9.1 | 4.3 | n/a | n/a | CWE-22 | Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible… |
| CVE-2026-75060 | 8.4 | 4.3 | JetBrains | PyCharm | CWE-306 | In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthen… |
| CVE-2026-19589 | 7.1 | 4.2 | HashiCorp | Packer | CWE-22 | Packer vulnerable to arbitrary file write via crafted plugin archive during i… |
| CVE-2026-64760 | 5.5 | 4.1 | Apple | iOS and iPadOS | CWE-200 | An information leakage was addressed with additional validation. This issue i… |
| CVE-2026-75059 | 4.4 | 3.9 | JetBrains | PyCharm | CWE-79 | In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation w… |
| CVE-2026-68518 | 8.8 | 3.8 | nicolargo | glances | CWE-78 | Glances: Command injection bypass of action-template sanitizer via cross-fiel… |
| CVE-2026-62982 | 8.8 | 3.7 | nicolargo | glances | CWE-78 | Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypas… |
| CVE-2026-34789 | 7.0 | 3.6 | FreeCAD | FreeCAD | CWE-94 | FreeCAD: Arbitrary code execution via unsandboxed PyImport_ImportModule in Pr… |
| CVE-2026-56089 | 3.3 | 3.6 | Dell | ObjectScale | CWE-35 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vuln… |
| CVE-2026-43794 | 8.8 | 3.5 | Apple | Safari | CWE-119 | A memory corruption issue was addressed with improved memory handling. This i… |
| CVE-2026-64778 | 6.5 | 3.5 | Apple | Safari | CWE-200 | The issue was addressed with improved checks. This issue is fixed in Safari 2… |
| CVE-2026-65341 | 5.4 | 3.5 | Apple | Safari | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-43795 | 4.3 | 3.5 | Apple | Safari | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-64784 | 4.3 | 3.5 | Apple | Safari | CWE-125 | An out-of-bounds access issue was addressed with improved bounds checking. Th… |
| CVE-2026-65331 | 4.3 | 3.5 | Apple | Safari | CWE-703 | This issue was addressed through improved state management. This issue is fix… |
| CVE-2026-65332 | 4.3 | 3.5 | Apple | Safari | CWE-703 | This issue was addressed through improved state management. This issue is fix… |
| CVE-2026-65333 | 4.3 | 3.5 | Apple | Safari | CWE-119 | This issue was addressed through improved state management. This issue is fix… |
| CVE-2026-65334 | 4.3 | 3.5 | Apple | Safari | CWE-119 | A memory corruption issue was addressed with improved state management. This … |
| CVE-2026-65335 | 4.3 | 3.5 | Apple | Safari | CWE-119 | This issue was addressed through improved state management. This issue is fix… |
| CVE-2026-65336 | 4.3 | 3.5 | Apple | Safari | CWE-20 | This issue was addressed through improved state management. This issue is fix… |
| CVE-2026-65337 | 4.3 | 3.5 | Apple | Safari | CWE-20 | This issue was addressed through improved state management. This issue is fix… |
| CVE-2026-65338 | 4.3 | 3.5 | Apple | Safari | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-65340 | 4.3 | 3.5 | Apple | Safari | CWE-20 | This issue was addressed through improved state management. This issue is fix… |
| CVE-2026-64782 | 3.1 | 3.5 | Apple | Safari | CWE-362 | A memory corruption vulnerability was addressed with improved locking. This i… |
| CVE-2026-34399 | 7.8 | 3.4 | FreeCAD | FreeCAD | CWE-95 | FreeCAD: Arbitrary Code Execution via eval() on untrusted SVG template scale … |
| CVE-2026-64787 | 6.5 | 3.3 | Apple | Safari | CWE-416 | A use-after-free issue was addressed with improved memory management. This is… |
| CVE-2026-64788 | 5.4 | 3.3 | Apple | iOS and iPadOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-65351 | 4.3 | 3.3 | Apple | Safari | CWE-703 | This issue was addressed through improved state management. This issue is fix… |
| CVE-2026-75057 | 6.2 | 3.2 | JetBrains | IntelliJ IDEA | CWE-532 | In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in pl… |
| CVE-2026-75052 | 3.6 | 3.2 | JetBrains | IntelliJ IDEA | CWE-77 | In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Mark… |
| CVE-2026-74882 | 8.7 | 3.0 | jahlives | openssl_encrypt | CWE-345 | openssl_encrypt before 1.4.0 Insecure Default Configuration |
| CVE-2026-59894 | 6.2 | 3.0 | andialbrecht | sqlparse | CWE-94 | sqlparse: Generated Python and PHP snippets allow SQL string breakout through… |
| CVE-2026-68765 | 5.2 | 3.0 | hashcat | hashcat | CWE-122 | hashcat KeePass KDBX v4 Module Heap Buffer Overflow via Token Field |
| CVE-2026-56090 | 7.3 | 2.7 | Dell | ObjectScale | CWE-427 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Searc… |
| CVE-2026-68519 | 7.1 | 2.7 | nicolargo | glances | CWE-78 | Glances: `--disable-config-exec` does not cover on-alert action commands (inc… |
| CVE-2026-74885 | 9.3 | 2.3 | jahlives | openssl_encrypt | CWE-117 | openssl_encrypt before 1.4.0 Logging Bug and Race Condition |
| CVE-2026-28984 | 4.3 | 2.4 | Apple | iOS and iPadOS | CWE-119 | The issue was addressed with improved memory handling. This issue is fixed in… |
| CVE-2026-75054 | 6.3 | 2.1 | JetBrains | IntelliJ IDEA | CWE-918 | In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI … |
| CVE-2026-75055 | 5.5 | 2.1 | JetBrains | IntelliJ IDEA | CWE-611 | In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read … |
| CVE-2026-75058 | 5.5 | 2.1 | JetBrains | IntelliJ IDEA | CWE-611 | In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse se… |
| CVE-2026-75483 | 4.8 | 2.2 | romkatv | powerlevel10k | CWE-150 | powerlevel10k Control Character Injection via package.json Version |
| CVE-2026-59909 | 7.1 | 2.0 | Dell | ObjectScale | CWE-35 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vuln… |
| CVE-2026-59911 | 5.5 | 1.4 | Dell | ObjectScale | CWE-532 | Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensi… |
| CVE-2026-40145 | 7.1 | 1.4 | BeyondTrust | Endpoint Privilege Management (Windows deployment) | CWE-1220 | Control protections bypass in BeyondTrust Endpoint Privilege Management (Wind… |
| CVE-2026-40144 | 7.3 | 1.3 | BeyondTrust | Endpoint Privilege Management (Windows deployments) | CWE-125 | Memory corruption vulnerability in Endpoint Privilege Management (Windows dep… |
| CVE-2026-9771 | 8.8 | 1.3 | zephyrproject | zephyr | CWE-822 | Missing device-pointer validation in flash_copy() syscall allows userspace pr… |
| CVE-2026-75587 | 3.6 | 1.2 | Mattermost | Mattermost | CWE-200 | Plaintext pre-auth secret exposure via Desktop App diagnostics report |
| CVE-2026-74802 | 0.0 | 1.2 | siyuan-note | siyuan | CWE-346 | SiYuan 3.7.3 Cross-Site WebSocket Hijacking via network proxy |
| CVE-2026-74867 | 2.3 | 1.2 | siyuan-note | siyuan | CWE-352 | SiYuan before 3.7.4 Cross-Site Request Forgery via CheckAuth |
| CVE-2026-70495 | 8.8 | 1.0 | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | CWE-269 | Search-v2-operator: search-v2-operator: cluster-wide impersonate on users/gro… |
| CVE-2026-50602 | 8.5 | 1.0 | Acer | Planet9 background service | CWE-732 | Planet9 Incorrect Permission Assignment Vulnerability Information |
| CVE-2026-71858 | 5.4 | 0.9 | notepad-plus-plus | notepad-plus-plus | CWE-78 | Notepad++: shortcuts.xml Macro HMAC Bypass Enables Conditional Elevated Comma… |
| CVE-2026-74871 | 6.9 | 0.7 | jahlives | openssl_encrypt | CWE-916 | openssl_encrypt before 1.4.6 KDF Bypass via Sequential-XOR |
| CVE-2026-49302 | 6.2 | 0.6 | Huawei | HarmonyOS | CWE-200 | Permission control vulnerability in the notification service module. Impact: … |
| CVE-2026-49307 | 6.2 | 0.6 | Huawei | HarmonyOS | CWE-200 | Permission control vulnerability in the multi-mode input module. Impact: Succ… |
| CVE-2026-58560 | 4.0 | 0.5 | Huawei | HarmonyOS | CWE-476 | Null pointer dereference issue in the image codec module. Impact: Successful … |
| CVE-2026-58561 | 4.0 | 0.5 | Huawei | HarmonyOS | CWE-476 | Null pointer dereference issue in the image codec module. Impact: Successful … |
| CVE-2026-49308 | 5.5 | 0.4 | Huawei | HarmonyOS | CWE-264 | Permission control vulnerability in the clipboard module. Impact: Successful … |
| CVE-2026-49301 | 6.2 | 0.4 | Huawei | HarmonyOS | CWE-200 | Permission control vulnerability in the Gallery module. Impact: Successful ex… |
| CVE-2026-49304 | 6.2 | 0.2 | Huawei | HarmonyOS | CWE-264 | Permission control vulnerability in the device key management module. Impact:… |
| CVE-2026-49305 | 6.2 | 0.2 | Huawei | HarmonyOS | CWE-755 | Permission control vulnerability in the Wi-Fi enhancement module. Impact: Suc… |
| CVE-2026-49306 | 3.3 | 0.2 | Huawei | HarmonyOS | CWE-416 | UAF vulnerability in the time and time zone module. Impact: Successful exploi… |
| CVE-2026-49303 | 5.1 | 0.2 | Huawei | HarmonyOS | CWE-264 | Permission control vulnerability in the notification module. Impact: Successf… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-08-17 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.