boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Wednesday, May 20, 2026 · all times UTCarchive · 2026-05-21 →

Security Box Score — May 20, 2026

202 CVEs published, led by Google (16).

202 CVEs published May 20, 2026: 29 critical, 72 high, 98 medium, 3 low; 2 in the KEV catalog at press time; 1 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 177 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published7421954——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

31 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux217543664403701120.47.8.0014+165 ▲
microsoft148518403651112286193.77.8.0046-24 ▼
red hat1062526247200.06.8.0041-6 ▼
apple154511528188715.66.2.0028+15 ▲
google16230176077417.48.8.0034+15 ▲
suse220200000.08.2.0020+2 ▲
ubuntu010001100.02.7.02180
debian00000010———0
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco512534056866.77.8.1576+5 ▲
fortinet17430028342.99.1.8584-2 ▼
ivanti142200254100.09.2.8104+1 ▲
palo alto networks22110013150.08.6.6281+2 ▲
f511100041100.09.2.6805+1 ▲
ubiquiti010100300.08.8.00360
vmware01010071100.08.1.17420
check point00000010———0
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache417210503315.97.5.0093+1 ▲
mozilla553200900.09.6.0045+5 ▲
drupal00000040———0
gitlab00000042———0
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
progress440400600.07.5.0036+4 ▲
oracle0312002700.07.5.00880
solarwinds032100103100.09.8.83620
adobe020200192100.08.6.0368-2 ▼
atlassian000000130———0
ibm00000060———0
sap00000060———0
servicenow00000020———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
siemens110100000.08.7.0032+1 ▲
d-link00000030———0
tp-link00000010———0
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
grafana102727162200.06.5.0033+7 ▲
nvidia16167900000.08.4.0060+16 ▲
givanz11152760000.08.3.0028+7 ▲
python software foundation2141391000.06.0.0042-2 ▼
nlnet labs11111280000.06.9.0058+11 ▲
patriksimek11118300000.09.8.0081+11 ▲
watchguard5110920200.07.1.0025+4 ▲
openises101000100000.05.1.0022+10 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-31431.9991100.07.8
CVE-2026-41940.985399.99.3
CVE-2026-0257.939199.87.8
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2026-20182.915299.810.0
CVE-2026-42208.894299.89.3
CVE-2024-1708.875699.78.4
CVE-2026-42271.835499.78.7
CVE-2026-41089.796299.69.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-2018210.0.9152KEV
CVE-2026-4399710.0.0098
CVE-2026-3381910.0.0084
CVE-2026-4282610.0.0084
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
CVE-2026-3543110.0.0051
CVE-2026-4282210.0.0049
CVE-2026-4544410.0.0028
Most disclosures (vendor)
VendorCVEs
linux330
microsoft160
red hat17
google16
nvidia16
apple15
givanz11
grafana11
nlnet labs11
patriksimek11
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco8
apple7
google4
ivanti4
fortinet3
smartertools3
solarwinds3
adobe2
berriai2
Most-affected ecosystems
EcosystemAdvisories
Maven1
Fastest to KEV
CVEVendorDays
CVE-2024-1708ConnectWise0
CVE-2024-57726n/a0
CVE-2024-57728n/a0
CVE-2026-31431Linux0
CVE-2026-32202Microsoft0
CVE-2026-33825Microsoft0
CVE-2026-41091Microsoft0
CVE-2026-41940WebPros0
CVE-2026-42208BerriAI0
CVE-2026-42897Microsoft0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171645
CVE-2021-27102n/a2021-11-171645
CVE-2021-27101n/a2021-11-171645
CVE-2021-27103n/a2021-11-171645
CVE-2021-21017Adobe2021-11-171645
CVE-2021-28550Adobe2021-11-171645
CVE-2021-42013Apache Software Foundation2021-11-171645
CVE-2021-41773Apache Software Foundation2021-11-171645
CVE-2021-30858Apple2021-11-171645
CVE-2021-30860Apple2021-11-171645

Transactions

EXPLOIT PUBLISHED — CVE-2026-40102 (makeplane plane). Public exploit reference added.

Yesterday's Results

How to read these box scores · glossary

202 CVEs published. 25 box scores, 177 table rows — nothing truncated.

Microsoft Defender Denial of Service Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .6308   99.1   YES
AFFECTED
  Product                                  Versions   Fixed
  Microsoft Defender Antimalware Platform  4.0.0.0 –  —
TIMELINE
  May 12  Reserved by CNA
  May 20  Added to CISA KEV, due Jun 3
  May 20  Published (CNA: microsoft)
CWE-400 · CNA: microsoft · CVSS v3.1 · 2 references · NVD status: Analyzed · KEV due June 3, 2026
Microsoft Defender Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0820   94.4   YES
AFFECTED
  Product                              Versions   Fixed
  Microsoft Malware Protection Engine  1.1.0.0 –  —
TIMELINE
  Apr 16  Reserved by CNA
  May 20  Added to CISA KEV, due Jun 3
  May 20  Published (CNA: microsoft)
CWE-59 · CNA: microsoft · CVSS v3.1 · 2 references · NVD status: Analyzed · KEV due June 3, 2026
XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slash
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .1956   97.2     —
AFFECTED
  Product        Versions                          Fixed
  xwiki-commons  >= 4.2-milestone-2, < 16.10.17 –  —
TIMELINE
  Jan 15  Reserved by CNA
  May 20  Published (CNA: GitHub_M)
CWE-23 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Deferred
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issu…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0518   91.8     —
AFFECTED
  Product                  Versions     Fixed
  Triton Inference Server  unspecified  —
TIMELINE
  Jan 21  Reserved by CNA
  May 20  Published (CNA: nvidia)
CWE-22 · CNA: nvidia · CVSS v3.1 · 3 references · NVD status: Analyzed
HP Linux Imaging and Printing Software – Potential Escalation of Privilege and Arbitrary Code Execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   H   H   H    8.5   .0411   90.0     —
AFFECTED
  Product                                 Versions     Fixed
  HP Linux Imaging and Printing Software  unspecified  —
TIMELINE
  May 14  Reserved by CNA
  May 20  Published (CNA: hp)
CWE-77, CWE-78 · CNA: hp · CVSS v4.0 · 14 references · NVD status: Modified
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication byp…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0255   83.8     —
AFFECTED
  Product                  Versions                        Fixed
  Triton Inference Server  All versions prior to r26.03 –  —
TIMELINE
  Jan 21  Reserved by CNA
  May 20  Published (CNA: nvidia)
CWE-288 · CNA: nvidia · CVSS v3.1 · 3 references · NVD status: Analyzed
ISC BIND 9 — Invalid handling of CLASS != IN
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0187   77.8     —
AFFECTED
  Product  Versions  Fixed
  BIND 9   9.11.0 –  —
TIMELINE
  Apr 9   Reserved by CNA
  May 20  Published (CNA: isc)
CWE-20, CWE-125, CWE-617, CWE-754, CWE-843, CWE-1287 · CNA: isc · CVSS v3.1 · 15 references · NVD status: Modified
HP Linux Imaging and Printing Software – Potential Escalation of Privilege and Arbitrary Code Execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0181   77.0     —
AFFECTED
  Product                                 Versions     Fixed
  HP Linux Imaging and Printing Software  unspecified  —
TIMELINE
  May 14  Reserved by CNA
  May 20  Published (CNA: hp)
CWE-190, CWE-122 · CNA: hp · CVSS v4.0 · 14 references · NVD status: Modified
ISC BIND 9 — Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0154   72.9     —
AFFECTED
  Product  Versions  Fixed
  BIND 9   9.20.0 –  9.18.0
TIMELINE
  Mar 5   Reserved by CNA
  May 20  Published (CNA: isc)
CWE-416 · CNA: isc · CVSS v3.1 · 7 references · NVD status: Modified
ISC BIND 9 — SIG(0) validation during query flood may lead to undefined behavior
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  N  N  H    5.9   .0139   70.1     —
AFFECTED
  Product  Versions  Fixed
  BIND 9   9.20.0 –  9.18.28
TIMELINE
  Apr 9   Reserved by CNA
  May 20  Published (CNA: isc)
CWE-362, CWE-416 · CNA: isc · CVSS v3.1 · 7 references · NVD status: Modified
Frappe has an Arbitrary File Read via Path Traversal in render_include
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0128   67.8     —
AFFECTED
  Product  Versions      Fixed
  frappe   < 15.105.0 –  —
TIMELINE
  Apr 6   Reserved by CNA
  May 20  Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · CVSS v4.0 · 2 references · NVD status: Deferred
NLnet Labs Unbound — Possible arbitrary code execution during DNSSEC validation
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.1   .0127   67.6     —
AFFECTED
  Product  Versions  Fixed
  Unbound  1.19.1 –  —
TIMELINE
  May 7   Reserved by CNA
  May 20  Published (CNA: NLnet Labs)
CWE-416, CWE-672 · CNA: NLnet Labs · CVSS v4.0 · 7 references · NVD status: Modified
memcached memcached — In memcached before 1.6.42, username data for SASL password database authentication has a timing side chann…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0126   67.4     —
AFFECTED
  Product    Versions     Fixed
  memcached  unspecified  —
TIMELINE
  May 20  Reserved by CNA
  May 20  Published (CNA: mitre)
CWE-208 · CNA: mitre · CVSS v3.1 · 8 references · NVD status: Modified
ISC BIND 9 — BIND 9 server memory exhaustion during GSS-API TKEY negotiation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0105   61.6     —
AFFECTED
  Product  Versions  Fixed
  BIND 9   9.0.0 –   —
TIMELINE
  Feb 23  Reserved by CNA
  May 20  Published (CNA: isc)
CWE-771, CWE-770 · CNA: isc · CVSS v3.1 · 15 references · NVD status: Modified
ProSolution WP Client <= 2.0.0 - Unauthenticated Arbitrary File Upload via 'files'
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0098   59.5     —
AFFECTED
  Product                Versions     Fixed
  ProSolution WP Client  unspecified  —
TIMELINE
  Apr 17  Reserved by CNA
  May 20  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
phenixdigital phoenix_storybook — Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.5   .0091   57.2     —
AFFECTED
  Product            Versions                                    Fixed
  phoenix_storybook  0.5.0 –                                     —
  phoenix_storybook  e35379dfe2ef1a71b141899e36f431017c55265d –  —
TIMELINE
  May 13  Reserved by CNA
  May 20  Published (CNA: EEF)
CWE-94 · CNA: EEF · CVSS v4.0 · 4 references · NVD status: Deferred
Microsoft Defender Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0085   55.5     —
AFFECTED
  Product                              Versions   Fixed
  Microsoft Malware Protection Engine  1.1.0.0 –  —
TIMELINE
  May 12  Reserved by CNA
  May 20  Published (CNA: microsoft)
CWE-122 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
NLnet Labs Unbound — Heap overflow with multiple NSID, COOKIE, PADDING EDNS options
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0084   55.1     —
AFFECTED
  Product  Versions  Fixed
  Unbound  1.14.0 –  —
TIMELINE
  May 7   Reserved by CNA
  May 20  Published (CNA: NLnet Labs)
CWE-197, CWE-787 · CNA: NLnet Labs · CVSS v4.0 · 8 references · NVD status: Modified
Cisco Secure Workload Unauthorized API Access Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  N   10.0   .0083   55.0     —
AFFECTED
  Product                Versions    Fixed
  Cisco Secure Workload  2.2.1.41 –  —
TIMELINE
  Oct 8   Reserved by CNA
  May 20  Published (CNA: cisco)
CWE-306 · CNA: cisco · CVSS v3.1 · 1 reference · NVD status: Analyzed
389-ds-base: 389-ds-base: unbounded ldap controls count in get_ldapmessage_controls_ext() causes cpu and heap amplification (remote dos)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0081   54.3     —
AFFECTED
  Product                                                Versions     Fixed
  389-ds-base                                            unspecified  —
  Red Hat Directory Server 11.5 E4S for RHEL 8           unspecified  8060020260609102432.0ca98e7e
  Red Hat Directory Server 11.7 E4S for RHEL 8           unspecified  8080020260610130252.f969626e
  Red Hat Directory Server 11.9 for RHEL 8               unspecified  8100020260601104139.37ed7c03
  Red Hat Directory Server 12.2 E4S for RHEL 9           unspecified  9020020260615123354.1674d574
  Red Hat Directory Server 12.4 E4S for RHEL 9           unspecified  9040020260611130021.1674d574
  Red Hat Enterprise Linux 10                            unspecified  0:3.2.0-7.el10_2
  Red Hat Enterprise Linux 10.0 Extended Update Support  unspecified  0:3.0.6-18.el10_0
  Red Hat Enterprise Linux 7 Extended Lifecycle Support  unspecified  0:1.3.11.1-12.el7_9
  Red Hat Enterprise Linux 8                             unspecified  8100020260601102239.25e700aa
  + 14 more
TIMELINE
  May 20  Reserved by CNA
  May 20  Published (CNA: redhat)
CWE-770 · CNA: redhat · CVSS v3.1 · 20 references · NVD status: Modified
Google Chrome — Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to exe…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0080   53.7     —
AFFECTED
  Product  Versions          Fixed
  Chrome   148.0.7778.179 –  —
TIMELINE
  May 20  Reserved by CNA
  May 20  Published (CNA: Chrome)
CWE-416 · CNA: Chrome · CVSS v3.1 · 2 references · NVD status: Analyzed
RsyncProject rsync — Rsync < 3.4.3 Integer Overflow Information Disclosure
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   H   N   H    6.1   .0078   53.2     —
AFFECTED
  Product  Versions     Fixed
  rsync    unspecified  —
TIMELINE
  May 1   Reserved by CNA
  May 20  Published (CNA: VulnCheck)
CWE-125, CWE-190 · CNA: VulnCheck · CVSS v4.0 · 10 references · NVD status: Modified
NLnet Labs Unbound — Crash during DNSSEC validation of malicious content
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0078   53.1     —
AFFECTED
  Product  Versions     Fixed
  Unbound  unspecified  —
TIMELINE
  May 7   Reserved by CNA
  May 20  Published (CNA: NLnet Labs)
CWE-824 · CNA: NLnet Labs · CVSS v4.0 · 8 references · NVD status: Modified
NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0076   52.7     —
AFFECTED
  Product            Versions     Fixed
  BioNeMo Framework  unspecified  —
TIMELINE
  Jan 21  Reserved by CNA
  May 20  Published (CNA: nvidia)
CWE-29 · CNA: nvidia · CVSS v3.1 · 3 references · NVD status: Analyzed
twigphp Twig — Twig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterface
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0076   52.4     —
AFFECTED
  Product  Versions  Fixed
  Twig     3.9.0 –   —
TIMELINE
  Jan 22  Reserved by CNA
  May 20  Published (CNA: VulnCheck)
CWE-693 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-75228.852.3SigmaPluginAdvanced Database Cleaner – PremiumCWE-98Advanced Database Cleaner – Premium <= 4.1.0 - Authenticated (Subscriber+) Lo…
CVE-2026-412926.651.2NLnet LabsUnboundCWE-407Long list of incoming EDNS options degrades performance
CVE-2026-242149.851.1NVIDIATriton Inference ServerCWE-190NVIDIA Triton Inference Server contains a vulnerability in the DALI backend w…
CVE-2026-242139.851.0NVIDIATriton Inference ServerCWE-125NVIDIA Triton Inference Server contains a vulnerability in the DALI backend w…
CVE-2026-59505.348.8ISCBIND 9CWE-606Unbounded resend loop in BIND 9 resolver
CVE-2026-242097.548.4NVIDIATriton Inference ServerCWE-22NVIDIA Triton Inference Server contains a vulnerability where an attacker cou…
CVE-2026-390477.548.3n/an/aCWE-121Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker…
CVE-2026-400927.547.3nimiqcore-rs-albatrossCWE-252nimiq-keys: Unchecked Ed25519 signature length in TaggedPublicKey::verify cau…
CVE-2026-443906.947.3NLnet LabsUnboundCWE-407Unbounded name compression in certain cases causes degradation of service
CVE-2026-242107.546.1NVIDIATriton Inference ServerCWE-190NVIDIA Triton Inference Server contains a vulnerability where an attacker cou…
CVE-2026-242188.145.9NVIDIADGX SparkCWE-321NVIDIA DGX OS contains a vulnerability in the factory provisioning process, w…
CVE-2026-241639.845.7NVIDIATensorRT-LLMCWE-502NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, wher…
CVE-2026-331379.345.8xwikixwiki-platformCWE-862XWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName}
CVE-2026-425346.945.2NLnet LabsUnboundCWE-440Jostle logic bypass degrades resolution performance
CVE-2026-76379.844.7PixelYourSiteBoostCWE-502Boost <= 2.0.3 - Unauthenticated PHP Object Injection via STYXKEY-BOOST_USER_…
CVE-2025-332559.844.4NVIDIATensorRT-LLMCWE-502NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where…
CVE-2026-91029.444.2AltiumAltium Enterprise ServerCWE-22Path Traversal in Altium Enterprise Server ComparisonService Allows Arbitrary…
CVE-2026-477848.143.5memcachedmemcachedCWE-208In memcached before 1.6.42, password data for SASL password database authenti…
CVE-2026-242069.843.5NVIDIATriton Inference ServerCWE-288NVIDIA Triton Inference Server contains a vulnerability where an attacker cou…
CVE-2026-90038.743.0TONNETTPR7308CWE-89TONNET|E-LAN Hybrid Recording System - SQL Injection
CVE-2026-91198.842.9GoogleChromeCWE-122Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 al…
CVE-2026-84698.242.8phenixdigitalphoenix_storybookCWE-770Unauthenticated denial-of-service via BEAM atom table exhaustion in phoenix_s…
CVE-2026-85989.140.9ZKTecoSSC335-GC2063-Face-0b77 Solution CameraCWE-288Unauthenticated Export Service in ZKTeco CCTV Cameras
CVE-2026-401658.740.6goauthentikauthentikCWE-91authentik: SAML NameID XML Comment Injection Enables Authentication Bypass vi…
CVE-2026-91208.840.6GoogleChromeCWE-416Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a r…
CVE-2026-72849.840.1themewantEasy Elements for Elementor – Addons & Website TemplatesCWE-269Easy Elements for Elementor <= 1.4.4 - Unauthenticated Privilege Escalation v…
CVE-2026-202396.539.5SplunkSplunk EnterpriseCWE-532Sensitive Information Disclosure through Log Files in Splunk Enterprise
CVE-2026-91419.339.3Taiko Network Communications Pte Ltd.AG1000-01A SMS Alert GatewayCWE-306Taiko AG1000-01A Rev 7.3/8 Authentication Bypass via Web Interface
CVE-2026-60726.538.9oliverposOliver POS – A WooCommerce Point of Sale (POS)CWE-639Oliver POS <= 2.4.2.6 - Unauthenticated Authorization Bypass Through User-Con…
CVE-2026-241607.538.4NVIDIATensorRT-LLMCWE-690NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker co…
CVE-2026-201716.838.3CiscoCisco NX-OS SoftwareCWE-670Cisco Nexus 3000 and 9000 Series Border Gateway Protocol Denial of Service Vu…
CVE-2026-398507.437.6yiisoftyii2CWE-20Yii 2: Local file inclusion via view parameter name collision
CVE-2026-91399.337.4Taiko Network Communications Pte Ltd.AG1000-01A SMS Alert GatewayCWE-798Taiko AG1000-01A Rev 7.3/8 Hard-coded Credentials via login.zhtml
CVE-2026-350706.737.3DellSmartFabric Storage SoftwareCWE-77Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Impro…
CVE-2026-470682.337.1phenixdigitalphoenix_storybookCWE-639Cross-session PubSub topic injection via URL parameter in phoenix_storybook
CVE-2026-74724.937.1edmonparkerRead More & AccordionCWE-89Read More & Accordion <= 3.5.7 - Authenticated (Administrator+) SQL Injection…
CVE-2026-91448.436.5Taiko Network Communications Pte Ltd.AG1000-01A SMS Alert GatewayCWE-79Taiko AG1000-01A Rev 7.3/8 Stored XSS via Web Configuration Interface
CVE-2026-201997.236.3CiscoCisco ThousandEyes Enterprise AgentCWE-74A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual…
CVE-2026-436206.935.4RsyncProjectrsyncCWE-125Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files()
CVE-2026-202066.334.4CiscoCisco ThousandEyes Enterprise AgentCWE-78Cisco ThousandEyes BrowserBot Command Injection Vulnerability
CVE-2026-242157.533.9NVIDIATriton Inference ServerCWE-400NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, …
CVE-2026-91015.333.9MongoDB, Inc.CompassCWE-1321Prototype pollution in csv parsing
CVE-2026-91506.533.7Red HatRed Hat Enterprise Linux 10CWE-121Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when…
CVE-2026-428347.833.7MicrosoftWindows Admin Center in Azure PortalCWE-59Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability
CVE-2026-35925.333.4ISCBIND 9CWE-408Amplification vulnerabilities via self-pointed glue records
CVE-2026-39857.533.4constantcontactCreative Mail – Easier WordPress & WooCommerce Email MarketingCWE-89Creative Mail – Easier WordPress & WooCommerce Email Marketing <= 1.6.9 - Una…
CVE-2026-473729.132.5RRWOCrypt::SaltedHashCWE-338Crypt::SaltedHash versions through 0.09 for Perl generate insecure random val…
CVE-2026-91128.832.4GoogleChromeCWE-416Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 all…
CVE-2026-91188.832.4GoogleChromeCWE-416Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allo…
CVE-2026-91268.832.4GoogleChromeCWE-416Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a r…
CVE-2026-202406.532.5SplunkSplunk EnterpriseCWE-20Denial of Service through coldToFrozen.sh Script in Splunk Enterprise
CVE-2026-84867.532.3Progress SoftwareMOVEit AutomationCWE-770Allocation of resources without limits or throttling vulnerability in Progres…
CVE-2026-473737.532.1RRWOCrypt::SaltedHashCWE-208Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing att…
CVE-2026-393108.631.9TriliumNextTriliumCWE-284Trilium Notes: Authentication Bypass in Clipper API for Electron (Desktop) Bu…
CVE-2026-223149.031.4MesalvoMeona Client Launcher ComponentCWE-94Improper Control of Generation of Code ('Code Injection') vulnerability in Me…
CVE-2026-64568.831.3beycanpressAccount SwitcherCWE-287Account Switcher <= 1.0.2 - Authenticated (Subscriber+) Authentication Bypass…
CVE-2026-241887.531.2NVIDIATensorRTCWE-787NVIDIA TensorRT contains a vulnerability where an attacker could cause an out…
CVE-2026-241429.830.7NVIDIATensorRT-LLMCWE-502NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and …
CVE-2026-449268.830.2n/an/aCWE-284InfoScale CmdServer before 7.4.2 mishandles access control.
CVE-2026-90107.529.3PixelYourSiteBoostCWE-89Boost <= 2.0.3 - Unauthenticated Blind SQL Injection via Multiple Parameters
CVE-2026-91148.829.2GoogleChromeCWE-416Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a …
CVE-2026-91375.129.2mispmispCWE-400CSP Report Endpoint Log Flooding in MISP via Incorrect Size Limit
CVE-2026-84887.529.0Progress SoftwareMOVEit AutomationCWE-770Allocation of resources without limits or throttling vulnerability in Progres…
CVE-2026-28125.328.6EsriArcGIS ServerCWE-287Improper Authentication issue in ArcGIS Server
CVE-2026-86856.528.5infilityInfility GlobalCWE-89Infility Global <= 2.15.16 - Authenticated (Subscriber+) SQL Injection via 'o…
CVE-2026-470992.128.4storybookjstelejsonCWE-79TeleJSON < 6.0.0 DOM-based XSS via parse() Function
CVE-2026-74678.828.3edmonparkerRead More & AccordionCWE-269Read More & Accordion <= 3.5.7 - Privilege Escalation via importData
CVE-2025-327507.527.6DellPowerFlex Manager (Appliance)CWE-548Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Informa…
CVE-2026-223157.227.5MesalvoMeona Client Launcher ComponentCWE-266Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher…
CVE-2026-84857.527.3Progress SoftwareMOVEit AutomationCWE-789Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Auto…
CVE-2026-91338.327.0AWSRabbitMQ AWSCWE-489Arbitrary file read in rabbitmq-aws plugin
CVE-2026-429236.926.3NLnet LabsUnboundCWE-407Degradation of service with unbounded NSEC3 hash calculations
CVE-2026-90659.326.2brainstormforceSurecartCWE-89Surecart - SQL Injection
CVE-2026-327924.626.1NLnet LabsUnboundCWE-125Packet of death with DNSCrypt
CVE-2026-91104.226.2GoogleChromeCWE-451Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0…
CVE-2026-452322.126.2RsyncProjectrsyncCWE-193Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy
CVE-2026-52008.826.0acybaAcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPressCWE-862AcyMailing <= 10.8.2 - Missing Authorization to Authenticated (Subscriber+) P…
CVE-2026-67285.325.5Revolution SliderSlider RevolutionCWE-200Slider Revolution <= 7.0.9 - Unauthenticated Sensitive Information Exposure v…
CVE-2026-91218.825.4GoogleChromeCWE-125Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed…
CVE-2026-74607.424.2mailcowmailcow-dockerizedCWE-79mailcow-dockerized 2026-03b - Stored XSS in Queue Manager via unescaped
CVE-2026-202386.524.2SplunkSplunk AI ToolkitCWE-863Improper Access Control through Role Inheritance in Splunk AI Toolkit app
CVE-2026-63945.423.7wpdiveNexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSECWE-918Nexa Blocks <= 1.1.1 - Unauthenticated Blind Server-Side Request Forgery via …
CVE-2026-90878.123.3Red HatRed Hat build of Keycloak 26.4CWE-639Keycloak: cross-session email verification proof not bound to upstream identi…
CVE-2026-91496.523.4Red HatRed Hat Enterprise Linux 10CWE-122Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize f…
CVE-2026-449236.523.0n/an/aCWE-89SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to esca…
CVE-2026-52936.422.9olivesystem診断ジェネレータ作成プラグインCWE-79診断ジェネレータ作成プラグイン <= 1.4.16 - Authenticated (Subscriber+) Stored Cross-Site Scr…
CVE-2026-274056.522.8Magepeople inc.WpBookinglyCWE-862WordPress WpBookingly plugin <= 1.2.9 - Broken Access Control vulnerability
CVE-2026-394059.422.4frappelmsCWE-22Frappe has Path Transversal via SCORM
CVE-2026-400944.322.2nimiqcore-rs-albatrossCWE-754nimiq-blockchain: network-libp2p untrusted peer can crash address book via em…
CVE-2026-28134.122.0EsriArcGIS ServerCWE-601Unvalidated Redirect in ArcGIS Server
CVE-2026-306916.121.9n/an/aCWE-79Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1…
CVE-2026-401026.521.5makeplaneplaneCWE-943Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analytics
CVE-2026-91006.021.4MongoDB, Inc.C DriverCWE-1285Heap memory out of bounds read and crash in C Driver legacy GridFS file reader
CVE-2026-86104.321.4conohaTypeSquare Webfonts for ConoHaCWE-862TypeSquare Webfonts for ConoHa <= 2.0.4 - Missing Authorization to Authentica…
CVE-2026-242167.820.9NVIDIABioNeMo FrameworkCWE-502NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a …
CVE-2026-423837.620.8YITHYITH WooCommerce Product Add-OnsCWE-89WordPress YITH WooCommerce Product Add-Ons plugin <= 4.29.0 - SQL Injection v…
CVE-2026-393116.820.7TriliumNextTriliumCWE-79Trilium Notes: Stored XSS Leads to Unauthorized Remote Code Execution (RCE) v…
CVE-2026-90599.320.6awesomemotiveNextGEN GalleryCWE-89NextGEN Gallery - SQL Injection
CVE-2026-50754.320.4smubAll in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase TrafficCWE-200All in One SEO <= 4.9.7 - Authenticated (Contributor+) Sensitive Information …
CVE-2026-4544410.020.1WP SwingsGift Cards For WooCommerce ProCWE-434WordPress Gift Cards For WooCommerce Pro plugin <= 4.2.6 - Arbitrary File Upl…
CVE-2026-436176.320.1RsyncProjectrsyncCWE-289Rsync < 3.4.3 Authorization Bypass via Hostname Resolution
CVE-2026-84877.519.9Progress SoftwareMOVEit AutomationCWE-276Incorrect default permissions vulnerability in Progress Software MOVEit Autom…
CVE-2026-74626.119.4vatanyazilimVatanSMS WP SMSCWE-79VatanSMS WP SMS <= 1.01 - Reflected Cross-Site Scripting via 'page' Parameter
CVE-2026-73855.818.8UnknownDecent Comments—Decent Comments < 3.0.2 - Unauthenticated Email Address Disclosure
CVE-2026-42935.318.8Kieback & PeterDDC4002CWE-79Kieback & Peter DDC Building Controllers Cross-site Scripting
CVE-2026-91226.518.5GoogleChromeCWE-125Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 all…
CVE-2026-86246.118.3etspringLJ comments import: reloadedCWE-79LJ comments import: reloaded <= 0.97.1 - Reflected Cross-Site Scripting via P…
CVE-2026-86266.118.3owencutajarSponsorMeCWE-79SponsorMe <= 0.5.2 - Reflected Cross-Site Scripting via PHP_SELF Parameter
CVE-2026-91177.517.9GoogleChromeCWE-843Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778…
CVE-2026-218366.517.8HCLSoftwareDominoIQCWE-862HCL DominoIQ is affected by broken access control
CVE-2026-65664.317.9smubPhoto Gallery, Sliders, Proofing and Themes – NextGEN GalleryCWE-639Photo Gallery, Sliders, Proofing and Themes <= 4.2.0 - Insecure Direct Object…
CVE-2026-90578.217.4TalendTalend Administration Center—Security fix for Qlik Talend Administration Center URL access control vulnera…
CVE-2026-91245.317.4GoogleChromeCWE-20Insufficient validation of untrusted input in Input in Google Chrome on prior…
CVE-2026-76137.216.8pixelyoursiteCost of Goods by PixelYourSiteCWE-79Cost of Goods by PixelYourSite <= 1.2.12 - Unauthenticated Stored Cross-Site …
CVE-2026-446084.616.8NLnet LabsUnboundCWE-413Use after free and crash under special conditions in RPZ code
CVE-2026-57766.116.3UnknownEmail Encoder—Email Encoder < 2.4.7 - Unauthenticated Stored XSS
CVE-2026-429605.716.0NLnet LabsUnboundCWE-349Possible cache poisoning via promiscuous records for the authority section
CVE-2026-443925.316.0Six Apart Ltd.Movable TypeCWE-862Missing authorization vulnerability exists in Movable Type. Under certain con…
CVE-2025-153695.315.9xproXpro Addons — 140+ Widgets for ElementorCWE-862Xpro Addons — 140+ Widgets for Elementor <= 1.5.0 - Missing Authorization to …
CVE-2026-80386.415.5mcinvaleFaces of UsersCWE-79Faces of Users <= 0.0.3 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-63976.415.5cvmhStickyCWE-79Sticky <= 2.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…
CVE-2026-65496.415.5goback2Logo Manager For EnamadCWE-79Logo Manager For Enamad <= 0.7.4 - Authenticated (Contributor+) Stored Cross-…
CVE-2026-260286.115.1cryptpadcryptpadCWE-79CryptPad: Sanitizer Bypass in Diffmarked.js Allows Arbitrary HTML Injection a…
CVE-2026-91299.414.7AltiumAltium Enterprise ServerCWE-22Path Traversal in Altium Enterprise Server Viewer StorageController Allows Ar…
CVE-2026-64044.414.7simonhollidayAnomify AI – Anomaly Detection and AlertingCWE-79Anomify AI <= 0.3.6 - Authenticated (Administrator+) Stored Cross-Site Script…
CVE-2026-225547.814.4MediaAreaMediaInfoLibCWE-122MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerabi…
CVE-2026-399605.413.6mantisbtmantisbtCWE-79MantisBT is Vulnerable to Stored XSS through Custom Field Textarea Values
CVE-2026-63994.413.6yog2515General OptionsCWE-79General Options <= 1.1.0 - Authenticated (Administrator+) Stored Cross-Site S…
CVE-2026-91368.313.5mispmispCWE-639Unauthorized ShadowAttribute modification in MISP via client-supplied identifier
CVE-2026-350145.113.4openisesticketsCWE-79Open ISES Tickets < 3.44.2 Reflected XSS via routes_nm.php ticket_id Parameter
CVE-2026-57837.613.0Beyaz Computer Software Design Industry and Trade Ltd. Co.CityPLusCWE-79Reflected XSS in Beyaz Computer's CityPLus
CVE-2026-91154.312.9GoogleChromeCWE-693Insufficient policy enforcement in Service Worker in Google Chrome on prior t…
CVE-2026-29556.412.7wupsalesAI Chatbot & Workflow Automation by AIWUCWE-79AI Chatbot & Workflow Automation by AIWU <= 1.4.14 - Unauthenticated Stored C…
CVE-2026-86276.112.5lykichCorrect PricesCWE-79Correct Prices <= 1.0 - Reflected Cross-Site Scripting via PHP_SELF Parameter
CVE-2026-350075.112.4openisesticketsCWE-79Open ISES Tickets < 3.44.2 Reflected XSS via single_unit.php id Parameter
CVE-2026-350085.112.4openisesticketsCWE-79Open ISES Tickets < 3.44.2 Reflected XSS via single.php ticket_id Parameter
CVE-2026-350095.112.4openisesticketsCWE-79Open ISES Tickets < 3.44.2 Reflected XSS via add_note.php ticket_id Parameter
CVE-2026-350105.112.4openisesticketsCWE-79Open ISES Tickets < 3.44.2 Reflected XSS via patient_JF.php ticket_id Parameter
CVE-2026-350115.112.4openisesticketsCWE-79Open ISES Tickets < 3.44.2 Reflected XSS via opena.php frm_call Parameter
CVE-2026-350125.112.4openisesticketsCWE-79Open ISES Tickets < 3.44.2 Reflected XSS via add_facnote.php ticket_id Parameter
CVE-2026-350135.112.4openisesticketsCWE-79Open ISES Tickets < 3.44.2 Reflected XSS via street_view.php thelat and theln…
CVE-2026-350155.112.4openisesticketsCWE-79Open ISES Tickets < 3.44.2 Reflected XSS via do_unit_mail.php the_ticket Para…
CVE-2026-350165.112.4openisesticketsCWE-79Open ISES Tickets < 3.44.2 Reflected XSS via search.php frm_query Parameter
CVE-2026-449338.512.3SUSESUSE Linux EnterpriseCWE-35Path Traversal in Plugin Loading in libzypp
CVE-2026-91134.312.0GoogleChromeCWE-125Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 all…
CVE-2026-91164.312.0GoogleChromeCWE-693Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to…
CVE-2026-449245.410.8n/an/aCWE-79InfoScale VIOM 9.1.3 allows XSS.
CVE-2026-274244.310.6WP ChillImage Photo Gallery Final Tiles GridCWE-862WordPress Image Photo Gallery Final Tiles Grid plugin <= 3.6.11 - Broken Acce…
CVE-2026-449258.89.6n/an/aCWE-352Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operatio…
CVE-2026-454435.09.1ADD-ONS.ORGPDF for Elementor Forms + Drag And Drop Template BuilderCWE-862WordPress PDF for Elementor Forms + Drag And Drop Template Builder plugin <= …
CVE-2026-84194.38.7submoneAmazon ScraperCWE-352Amazon Scraper <= 1.1 - Cross-Site Request Forgery to Stored Cross-Site Scrip…
CVE-2026-91237.58.3GoogleChromeCWE-122Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, Chrome…
CVE-2026-64014.38.3svil4okBottom BarCWE-352Bottom Bar <= 0.1.7 - Cross-Site Request Forgery to Settings Update
CVE-2026-410547.88.0SUSEContainer suse/sle-micro-rancher/5.3:latestCWE-305Missing exit out of permission check in haveged could lead to root exploit
CVE-2026-90846.07.8mispmispCWE-287MISP OIDC authentication bypass via automatic email-based account linking und…
CVE-2026-84234.37.5javibolaJaviBola Custom Theme TestCWE-352JaviBola Custom Theme Test <= 2.0.5 - Cross-Site Request Forgery
CVE-2025-319739.87.3HCLBigFix Service Management (SM)CWE-1395HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insec…
CVE-2026-90565.47.4TalendTalend Administration Center—Security fix for Qlik Talend Administration Center cross-site scripting vulne…
CVE-2026-63916.16.9eazyserverSentence To SEO (keywords, description and tags)CWE-352Sentence To SEO (keywords, description and tags) <= 1.0 - Cross-Site Request …
CVE-2026-84206.16.9rdbeachBLOGCHAT Chat SystemCWE-352BLOGCHAT Chat System <= 1.3.6.3 - Cross-Site Request Forgery to Stored Cross-…
CVE-2026-64054.36.3simonhollidayAnomify AI – Anomaly Detection and AlertingCWE-352Anomify AI <= 0.3.6 - Cross-Site Request Forgery
CVE-2025-119548.06.0Sitemio Information Technologies Trade Ltd. Co.WISECPCWE-352CSRF in Sitemio's WISECP
CVE-2026-245736.56.1ThemeisleVisualizerCWE-79WordPress Visualizer plugin < 4.0.0 - Cross Site Scripting (XSS) vulnerability
CVE-2026-64004.35.7helpstringChild Height Predictor by OstheimerCWE-352Child Height Predictor by Ostheimer <= 1.3 - Cross-Site Request Forgery to Se…
CVE-2026-84184.35.7askywhaleGames CatalogCWE-352Games Catalog <= 1.2.0 - Cross-Site Request Forgery to Arbitrary Game/Post De…
CVE-2026-64524.35.2ktulhuBigfishgames SyndicateCWE-352Bigfishgames Syndicate <= 1.2 - Cross-Site Request Forgery to Settings Reset …
CVE-2026-84244.35.2jay_patelRemove Yellow BGBOXCWE-352Remove Yellow BGBOX <= 1.0 - Cross-Site Request Forgery
CVE-2025-319856.55.1HCLBigFix Service Management (SM)CWE-200HCL BigFix Service Management (SM) is affected by a security misconfiguration…
CVE-2026-63956.14.7winkingWord 2 CashCWE-352Word 2 Cash <= 0.9.2 - Cross-Site Request Forgeryto Stored Cross-Site Scripti…
CVE-2026-295187.34.6RsyncProjectrsyncCWE-367Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write
CVE-2023-73464.13.6LedgerLedger Bitcoin appCWE-682Ledger Bitcoin App 2.1.0 Address Derivation Error via Miniscript
CVE-2026-436197.23.2RsyncProjectrsyncCWE-59Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls
CVE-2026-406226.63.2NLnet LabsUnboundCWE-346Another 'ghost domain names' attack variant
CVE-2026-477824.63.0Siber Systems, Inc.Android App "RoboForm Password Manager"CWE-357Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handl…
CVE-2026-08567.82.5MesalvoMeona Client Launcher ComponentCWE-284Improper Access Control vulnerability in Mesalvo Meona Client Launcher Compon…
CVE-2026-08576.01.0MesalvoMeona Client Launcher ComponentCWE-316Cleartext Storage of Sensitive Information in Memory vulnerability in Mesalvo…
CVE-2026-256024.40.5MesalvoMeona Client Launcher ComponentCWE-345Insufficient Verification of Data Authenticity vulnerability in Mesalvo Meona…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-05-20 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.