CVSS EPSS %ile KEV — .8384 99.7 YES
AFFECTED Product Versions Fixed Langflow unspecified —
TIMELINE May 21 Added to CISA KEV, due Jun 4 May 21 Published
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
187 CVEs published, led by Concrete CMS (41).
187 CVEs published May 21, 2026: 15 critical, 74 high, 69 medium, 28 low; 2 in the KEV catalog at press time; 7 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 162 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 922 | 2114 | 1010 | 2564 |
| KEV catalog size | 1671 | |||
30 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 225 | 552 | 67 | 446 | 36 | 0 | 27 | 2 | 0.4 | 7.8 | .0014 | +173 ▲ |
| microsoft | 152 | 527 | 40 | 365 | 111 | 2 | 380 | 27 | 5.1 | 7.8 | .0047 | -24 ▼ |
| apple | 13 | 40 | 0 | 10 | 22 | 1 | 94 | 7 | 17.5 | 6.2 | .0037 | +13 ▲ |
| red hat | 9 | 32 | 5 | 17 | 8 | 2 | 4 | 0 | 0.0 | 7.5 | .0041 | 0 |
| 16 | 22 | 0 | 13 | 6 | 0 | 74 | 4 | 18.2 | 8.4 | .0035 | +15 ▲ | |
| freebsd | 7 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0020 | +7 ▲ |
| suse | 2 | 2 | 0 | 2 | 0 | 0 | 0 | 0 | 0.0 | 8.2 | .0020 | +2 ▲ |
| android | 0 | 0 | 0 | 0 | 0 | 0 | 15 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 5 | 13 | 3 | 1 | 2 | 0 | 96 | 8 | 61.5 | 8.6 | .1247 | +2 ▲ |
| fortinet | 1 | 6 | 1 | 3 | 0 | 0 | 28 | 3 | 50.0 | 7.9 | .4330 | -2 ▼ |
| ivanti | 1 | 4 | 0 | 0 | 0 | 0 | 33 | 4 | 100.0 | — | .8104 | 0 |
| f5 | 1 | 2 | 1 | 0 | 0 | 0 | 7 | 1 | 50.0 | 9.2 | .3413 | +1 ▲ |
| broadcom | 0 | 2 | 0 | 0 | 0 | 0 | 4 | 2 | 100.0 | — | .1990 | 0 |
| palo alto networks | 1 | 1 | 0 | 0 | 0 | 0 | 14 | 1 | 100.0 | — | .3207 | +1 ▲ |
| citrix | 0 | 1 | 0 | 0 | 0 | 0 | 19 | 1 | 100.0 | — | .8447 | 0 |
| ubiquiti | 0 | 1 | 0 | 1 | 0 | 0 | 4 | 0 | 0.0 | 8.8 | .0036 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 6 | 17 | 3 | 11 | 3 | 0 | 40 | 1 | 5.9 | 7.5 | .0092 | +3 ▲ |
| mozilla | 5 | 5 | 3 | 2 | 0 | 0 | 13 | 0 | 0.0 | 9.6 | .0045 | +5 ▲ |
| drupal | 2 | 2 | 0 | 0 | 2 | 0 | 5 | 0 | 0.0 | 5.1 | .0019 | +2 ▲ |
| gitlab | 0 | 2 | 0 | 0 | 0 | 0 | 4 | 2 | 100.0 | — | .4451 | 0 |
| docker | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| wordpress | 0 | 0 | 0 | 0 | 0 | 0 | 5 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| progress | 4 | 4 | 0 | 4 | 0 | 0 | 9 | 0 | 0.0 | 7.5 | .0036 | +4 ▲ |
| adobe | 1 | 4 | 0 | 1 | 0 | 0 | 75 | 3 | 75.0 | 8.6 | .2776 | -2 ▼ |
| solarwinds | 0 | 3 | 1 | 0 | 0 | 0 | 11 | 3 | 100.0 | 9.8 | .8362 | 0 |
| oracle | 0 | 2 | 0 | 2 | 0 | 0 | 40 | 0 | 0.0 | 7.5 | .0066 | 0 |
| zohocorp | 1 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | +1 ▲ |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| ibm | 0 | 0 | 0 | 0 | 0 | 0 | 7 | 0 | — | — | — | 0 |
| sap | 0 | 0 | 0 | 0 | 0 | 0 | 12 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| siemens | 1 | 1 | 0 | 1 | 0 | 0 | 1 | 0 | 0.0 | 8.7 | .0032 | +1 ▲ |
| d-link | 0 | 1 | 0 | 0 | 0 | 0 | 26 | 1 | 100.0 | — | .8964 | 0 |
| hikvision | 0 | 1 | 0 | 0 | 0 | 0 | 2 | 1 | 100.0 | — | 1.0000 | 0 |
| dahua | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| qnap | 0 | 0 | 0 | 0 | 0 | 0 | 8 | 0 | — | — | — | 0 |
| schneider electric | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| tp-link | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| concrete cms | 41 | 41 | 1 | 9 | 13 | 18 | 0 | 0 | 0.0 | 6.3 | .0015 | +41 ▲ |
| open ises | 37 | 37 | 2 | 14 | 21 | 0 | 0 | 0 | 0.0 | 6.9 | .0021 | +37 ▲ |
| netatalk | 33 | 33 | 1 | 13 | 9 | 10 | 0 | 0 | 0.0 | 6.4 | .0030 | +33 ▲ |
| grafana | 10 | 27 | 2 | 7 | 16 | 2 | 0 | 0 | 0.0 | 6.5 | .0033 | +7 ▲ |
| nvidia | 16 | 16 | 7 | 9 | 0 | 0 | 0 | 0 | 0.0 | 8.4 | .0059 | +16 ▲ |
| trend micro | 16 | 16 | 2 | 13 | 1 | 0 | 12 | 1 | 6.3 | 7.8 | .0030 | +16 ▲ |
| givanz | 11 | 15 | 2 | 7 | 6 | 0 | 0 | 0 | 0.0 | 8.3 | .0028 | +7 ▲ |
| python software foundation | 2 | 14 | 1 | 3 | 9 | 1 | 0 | 0 | 0.0 | 6.0 | .0042 | -3 ▼ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-31431 | .9991 | 100.0 | 7.8 |
| CVE-2008-4250 | .9875 | 99.9 | — |
| CVE-2026-41940 | .9793 | 99.9 | 9.3 |
| CVE-2026-39987 | .9658 | 99.9 | — |
| CVE-2026-43284 | .9324 | 99.8 | 8.8 |
| CVE-2026-43500 | .9285 | 99.8 | 7.8 |
| CVE-2024-7399 | .9194 | 99.8 | — |
| CVE-2010-0249 | .9188 | 99.8 | — |
| CVE-2026-20182 | .9152 | 99.8 | — |
| CVE-2025-29635 | .8964 | 99.8 | — |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-43997 | 10.0 | .0098 | |
| CVE-2026-33819 | 10.0 | .0084 | |
| CVE-2026-42826 | 10.0 | .0084 | |
| CVE-2026-20223 | 10.0 | .0083 | |
| CVE-2026-44005 | 10.0 | .0083 | |
| CVE-2026-44006 | 10.0 | .0081 | |
| CVE-2026-35431 | 10.0 | .0051 | |
| CVE-2026-42822 | 10.0 | .0049 | |
| CVE-2026-9152 | 10.0 | .0034 | |
| CVE-2026-45444 | 10.0 | .0028 |
| Vendor | CVEs |
|---|---|
| linux | 338 |
| microsoft | 163 |
| concrete cms | 41 |
| open ises | 37 |
| netatalk | 33 |
| 16 | |
| nvidia | 16 |
| trend micro | 16 |
| red hat | 14 |
| apple | 13 |
| Vendor | KEV |
|---|---|
| microsoft | 27 |
| cisco | 8 |
| apple | 7 |
| 4 | |
| ivanti | 4 |
| synacor | 4 |
| adobe | 3 |
| fortinet | 3 |
| smartertools | 3 |
| solarwinds | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 1 |
| PyPI | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4250 | Microsoft | 0 |
| CVE-2009-1537 | Microsoft | 0 |
| CVE-2009-3459 | Adobe | 0 |
| CVE-2010-0249 | Microsoft | 0 |
| CVE-2010-0806 | Microsoft | 0 |
| CVE-2024-1708 | ConnectWise | 0 |
| CVE-2024-57726 | n/a | 0 |
| CVE-2024-57728 | n/a | 0 |
| CVE-2024-7399 | Samsung | 0 |
| CVE-2025-29635 | D-Link | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1646 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1646 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1646 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1646 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1646 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1646 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1646 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1646 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1646 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1646 |
EXPLOIT PUBLISHED — CVE-2026-2734 (mlflow/mlflow). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-28764 (MediaArea MediaInfoLib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-4093 (Drupal Term Reference Tree). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-43494 (Linux). Public exploit reference added.
How to read these box scores · glossary
187 CVEs published. 25 box scores, 162 table rows — nothing truncated.
CVSS EPSS %ile KEV — .8384 99.7 YES
AFFECTED Product Versions Fixed Langflow unspecified —
TIMELINE May 21 Added to CISA KEV, due Jun 4 May 21 Published
AV AC PR UI S C I A CVSS EPSS %ile KEV L H H N C H L L 6.7 .1268 95.9 YES
AFFECTED Product Versions Fixed TrendAI Apex One 2019 (14.0) – — TrendAI Apex One as a Service SaaS – —
TIMELINE Mar 31 Reserved by CNA May 21 Added to CISA KEV, due Jun 4 May 21 Published (CNA: trendmicro)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0381 89.2 —
AFFECTED Product Versions Fixed TrendAI Apex One 2019 (14.0) – — TrendAI Apex One as a Service SaaS – —
TIMELINE Feb 11 Reserved by CNA May 21 Published (CNA: trendmicro)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0375 89.0 —
AFFECTED Product Versions Fixed TrendAI Apex One 2019 (14.0) – — TrendAI Apex One as a Service SaaS – —
TIMELINE Feb 11 Reserved by CNA May 21 Published (CNA: trendmicro)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0216 80.8 —
AFFECTED Product Versions Fixed Avada (Fusion) Builder unspecified —
TIMELINE Apr 14 Reserved by CNA May 21 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N C H H L 8.4 .0170 75.4 —
AFFECTED Product Versions Fixed ManageEngine ADSelfService Plus unspecified — ManageEngine DataSecurity Plus unspecified — ManageEngine RecoveryManager Plus unspecified —
TIMELINE Feb 19 Reserved by CNA May 21 Published (CNA: Zohocorp)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0097 59.2 —
AFFECTED Product Versions Fixed Control Network Module (CNM) 100.1 – —
TIMELINE Apr 2 Reserved by CNA May 21 Published (CNA: Honeywell)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 9.4 .0074 51.8 —
AFFECTED Product Versions Fixed Concrete CMS 5.0 – —
TIMELINE May 7 Reserved by CNA May 21 Published (CNA: ConcreteCMS)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0074 51.8 —
AFFECTED Product Versions Fixed litellm unspecified —
TIMELINE May 18 Reserved by CNA May 21 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV L L L N U H H H 7.8 .0073 51.2 —
AFFECTED Product Versions Fixed Linux 8161239a8bcce9ad6b537c04a1fa3b5c68bae693 – — Linux 2.6.39 – 5.10.261
TIMELINE May 1 Reserved by CNA May 21 Published (CNA: Linux)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N A H H H 8.6 .0070 50.4 —
AFFECTED Product Versions Fixed iina unspecified —
TIMELINE May 18 Reserved by CNA May 21 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0067 49.3 —
AFFECTED Product Versions Fixed BookingPress Appointment Booking Pro unspecified —
TIMELINE Apr 24 Reserved by CNA May 21 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0065 48.6 —
AFFECTED Product Versions Fixed litellm unspecified —
TIMELINE May 18 Reserved by CNA May 21 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0060 45.8 —
AFFECTED Product Versions Fixed Linux 8610c7c6e3bd647ff98d21c8bc0580e77bc2f8b3 – — Linux 5.7 – 5.10.258
TIMELINE May 1 Reserved by CNA May 21 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0057 44.9 —
AFFECTED Product Versions Fixed Apache Fory 0.13.0 – —
TIMELINE May 21 Reserved by CNA May 21 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L N N 6.9 .0056 44.3 —
AFFECTED Product Versions Fixed Concrete CMS 5.0 – —
TIMELINE Apr 21 Reserved by CNA May 21 Published (CNA: ConcreteCMS)
AV AC PR UI S C I A CVSS EPSS %ile KEV L L L N U H H H 7.8 .0054 43.4 —
AFFECTED Product Versions Fixed TrendAI Apex One 2019 (14.0) – — TrendAI Apex One as a Service SaaS – —
TIMELINE Feb 11 Reserved by CNA May 21 Published (CNA: trendmicro)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0053 42.7 —
AFFECTED Product Versions Fixed Netatalk 2.2.2 – 4.5.0
TIMELINE May 5 Reserved by CNA May 21 Published (CNA: securin)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U H H H 7.5 .0052 41.8 —
AFFECTED Product Versions Fixed Netatalk 2.0.4 – 4.4.3
TIMELINE May 5 Reserved by CNA May 21 Published (CNA: securin)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0049 40.0 —
AFFECTED Product Versions Fixed Divi Form Builder unspecified —
TIMELINE Mar 30 Reserved by CNA May 21 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H N 8.1 .0048 39.3 —
AFFECTED Product Versions Fixed Netatalk 3.0.2 – 4.4.3
TIMELINE May 5 Reserved by CNA May 21 Published (CNA: securin)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P H N H H H 8.9 .0047 38.9 —
AFFECTED Product Versions Fixed Concrete CMS 5.0 – —
TIMELINE May 7 Reserved by CNA May 21 Published (CNA: ConcreteCMS)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0044 36.9 —
AFFECTED Product Versions Fixed mlflow/mlflow unspecified – —
TIMELINE Feb 19 Reserved by CNA May 21 Public exploit reference published May 21 Published (CNA: @huntr_ai)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0042 35.1 —
AFFECTED Product Versions Fixed Netatalk 2.0.0 – 4.4.3
TIMELINE May 5 Reserved by CNA May 21 Published (CNA: securin)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0042 35.1 —
AFFECTED Product Versions Fixed Netatalk 2.0.4 – 4.4.3
TIMELINE May 5 Reserved by CNA May 21 Published (CNA: securin)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-46473 | 7.5 | 34.9 | TCHATZI | Authen::TOTP | CWE-331 | Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand |
| CVE-2026-45250 | 7.8 | 34.3 | FreeBSD | FreeBSD | CWE-121 | Stack buffer overflow via setcred(2) |
| CVE-2026-44061 | 5.9 | 32.2 | Netatalk | Netatalk | CWE-208 | DES-ECB auth with timing side channel |
| CVE-2026-44047 | 8.8 | 30.4 | Netatalk | Netatalk | CWE-89 | SQL injection in MySQL CNID backend |
| CVE-2026-42001 | 7.5 | 29.8 | PowerDNS | Authoritative | CWE-400 | Insufficient Validation of Autoprimary SOA Queries |
| CVE-2026-44055 | 7.5 | 29.3 | Netatalk | Netatalk | CWE-78 | Bitwise OR logic bug enables shell injection |
| CVE-2025-71214 | 7.8 | 29.0 | Trend Micro, Inc. | TrendAI Apex One (Mac) | CWE-346 | An origin validation error vulnerability in the Trend Micro Apex One (mac) ag… |
| CVE-2026-44062 | 7.5 | 28.9 | Netatalk | Netatalk | CWE-787 | Missing o_len bounds check in pull_charset_flags() |
| CVE-2026-42396 | 6.5 | 28.5 | PowerDNS | Authoritative | CWE-94 | Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer t… |
| CVE-2026-9152 | 10.0 | 27.0 | Altium | Altium 365 | CWE-306 | Unauthenticated SOAP Endpoint in Altium 365 SearchService Allows Cross-Tenant… |
| CVE-2025-71213 | 7.8 | 26.8 | Trend Micro, Inc. | TrendAI Apex One | CWE-346 | An origin validation error vulnerability in Trend Micro Apex One could allow … |
| CVE-2026-1543 | 6.4 | 26.7 | themefusion | Avada (Fusion) Builder | CWE-79 | Avada (Fusion) Builder <= 3.15.2 - Authenticated (Subscriber+) Stored Cross-S… |
| CVE-2026-44071 | 3.7 | 26.5 | Netatalk | Netatalk | CWE-693 | FORTIFY_SOURCE disabled |
| CVE-2026-44074 | 3.7 | 25.9 | Netatalk | Netatalk | CWE-682 | Bitwise OR of errno values |
| CVE-2026-44075 | 3.7 | 25.9 | Netatalk | Netatalk | CWE-484 | Missing break in DSI OpenSession |
| CVE-2026-44060 | 7.5 | 25.7 | Netatalk | Netatalk | CWE-191 | Integer underflow in dsi_writeinit() leads to denial of service |
| CVE-2026-4858 | 9.9 | 25.7 | Mattermost | Mattermost | CWE-22 | Path traversal in integration action URL leading to arbitrary API execution v… |
| CVE-2026-45760 | 8.1 | 25.5 | Apache Software Foundation | Apache Camel K | CWE-610 | Apache Camel K: Camel K Cross-Namespace Build Deputy Attack |
| CVE-2025-71216 | 7.8 | 25.2 | Trend Micro, Inc. | TrendAI Apex One (Mac) | CWE-367 | A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) a… |
| CVE-2026-44068 | 7.6 | 25.1 | Netatalk | Netatalk | CWE-22 | EA path traversal via incomplete sanitization |
| CVE-2026-7835 | 3.1 | 24.7 | Netatalk | Netatalk | CWE-134 | Format string argument mismatch |
| CVE-2026-44070 | 3.1 | 24.7 | Netatalk | Netatalk | CWE-770 | Unbounded realloc in charset conversion |
| CVE-2026-9089 | 8.8 | 23.9 | ConnectWise | Automate | CWE-494 | The ConnectWise Automate™ Agent does not fully verify the authenticity of com… |
| CVE-2026-4811 | 4.9 | 23.9 | wpbean | WPB Floating Menu or Categories – Sticky Floating Side Menu & Categories with Icons | CWE-79 | WPB Floating Menu or Categories – Sticky Floating Side Menu & Categories with… |
| CVE-2026-39593 | 6.5 | 23.4 | VillaTheme | HAPPY | CWE-862 | WordPress HAPPY plugin <= 1.0.10 - Broken Access Control vulnerability |
| CVE-2026-48241 | 9.2 | 23.2 | Open ISES | Tickets | CWE-798 | Open ISES Tickets < 3.44.2 Hardcoded MySQL Database Credentials in loader.php |
| CVE-2026-45255 | 7.5 | 23.2 | FreeBSD | FreeBSD | CWE-78 | Remote code execution via installer Wi-Fi access point scans |
| CVE-2026-8350 | 7.5 | 22.7 | Concrete CMS | Concrete CMS | CWE-863 | Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bu… |
| CVE-2026-44053 | 7.4 | 22.8 | Netatalk | Netatalk | CWE-327 | Weak cryptography in DHCAST128 UAM |
| CVE-2025-71215 | 7.0 | 22.8 | Trend Micro, Inc. | TrendAI Apex One (Mac) | CWE-367 | A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) a… |
| CVE-2026-45208 | 7.8 | 22.6 | Trend Micro, Inc. | TrendAI Apex One | CWE-367 | A time-of-check time-of-use vulnerability in the Apex One/SEP agent could all… |
| CVE-2026-43494 | 7.8 | 22.5 | Linux | Linux | CWE-1341 | net/rds: reset op_nents when zerocopy page pin fails |
| CVE-2026-48242 | 9.2 | 22.3 | Open ISES | Tickets | CWE-798 | Open ISES Tickets < 3.44.2 Hardcoded MySQL Database Credentials in import_mdb… |
| CVE-2025-71217 | 7.8 | 22.2 | Trend Micro, Inc. | TrendAI Apex One (Mac) | CWE-346 | An origin validation error vulnerability in the Trend Micro Apex One (mac) ag… |
| CVE-2026-44067 | 4.2 | 21.8 | Netatalk | Netatalk | CWE-125 | EA header parsing heap over-read |
| CVE-2026-44066 | 7.1 | 21.6 | Netatalk | Netatalk | CWE-125 | Heap out-of-bounds reads in Spotlight RPC unmarshalling |
| CVE-2026-7886 | 2.3 | 21.4 | Concrete CMS | Concrete CMS | CWE-639 | Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessag… |
| CVE-2026-45252 | 5.5 | 21.0 | FreeBSD | FreeBSD | CWE-122 | Heap overflow in FUSE_LISTXATTR |
| CVE-2026-44054 | 6.5 | 20.6 | Netatalk | Netatalk | CWE-330 | Predictable afpd session token |
| CVE-2026-44073 | 5.0 | 20.2 | Netatalk | Netatalk | CWE-273 | seteuid failure ignored in auth modules |
| CVE-2026-42002 | 7.5 | 18.4 | PowerDNS | Authoritative | CWE-364 | Concurrency and locking defects in GSS-TSIG |
| CVE-2026-43495 | 8.8 | 18.1 | Linux | Linux | CWE-125 | net: wwan: t7xx: validate port_count against message length in t7xx_port_enum… |
| CVE-2026-48218 | 5.1 | 17.8 | Open ISES | Tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via icons/buttons/landb.php frm_name… |
| CVE-2026-48224 | 5.1 | 17.8 | Open ISES | Tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via ics214.php frm_add_str Parameter |
| CVE-2026-7836 | 3.1 | 17.6 | Netatalk | Netatalk | CWE-682 | hextoint macro uppercase bug |
| CVE-2026-44056 | 6.4 | 17.0 | Netatalk | Netatalk | CWE-121 | Stack buffer overflow in desktop.c |
| CVE-2025-13479 | 7.5 | 16.7 | PosCube Hardware Software and Consulting Ltd. | QR Menu | CWE-639 | IDOR in PosCube's QR Menu |
| CVE-2026-34927 | 7.8 | 16.1 | Trend Micro, Inc. | TrendAI Apex One | CWE-346 | An origin validation vulnerability in the Apex One/SEP agent could allow a lo… |
| CVE-2026-34929 | 7.8 | 16.1 | Trend Micro, Inc. | TrendAI Apex One | CWE-346 | An origin validation vulnerability in the Apex One/SEP agent could allow a lo… |
| CVE-2026-44052 | 7.5 | 16.1 | Netatalk | Netatalk | CWE-532 | LDAP simple-bind password exposure in log output |
| CVE-2026-0393 | 6.9 | 15.9 | CODESYS | Visualization | CWE-522 | CODESYS Visualization - Insufficiently Protected Credentials |
| CVE-2026-39531 | 9.3 | 15.7 | Wp Directory Kit | WP Directory Kit | CWE-89 | WordPress WP Directory Kit plugin <= 1.5.0 - SQL Injection vulnerability |
| CVE-2026-42000 | 8.6 | 15.6 | PowerDNS | Authoritative | CWE-77 | Insufficient Validation of Names During AXFR |
| CVE-2026-48235 | 8.8 | 15.4 | Open ISES | Tickets | CWE-89 | Open ISES Tickets < 3.44.2 SQL Injection in incs/remotes.inc.php via External… |
| CVE-2026-7837 | 3.7 | 14.8 | Netatalk | Netatalk | CWE-367 | TOCTOU with root privilege in ad_flush |
| CVE-2026-6841 | 5.1 | 14.7 | Best Practical | Request Tracker | CWE-79 | Reflected XSS in Request Tracker |
| CVE-2025-13477 | 7.1 | 13.3 | Digital Operations Services Inc. | WifiBurada | CWE-359 | OTP Bypass in Digital Operation Services' WifiBurada |
| CVE-2026-48243 | 6.9 | 13.3 | Open ISES | Tickets | CWE-798 | Open ISES Tickets < 3.44.2 Hardcoded WhitePages API Key in wp1.php |
| CVE-2026-48244 | 6.9 | 13.3 | Open ISES | Tickets | CWE-798 | Open ISES Tickets < 3.44.2 Hardcoded Google Maps API Key in settings.inc.php |
| CVE-2026-48245 | 6.9 | 13.3 | Open ISES | Tickets | CWE-798 | Open ISES Tickets < 3.44.2 Hardcoded Google Maps API Key in tables.php |
| CVE-2026-7879 | 6.3 | 13.4 | Concrete CMS | Concrete CMS | CWE-862 | Concrete CMS 9.5.0 and below is vulnerable to File Download Authorization Byp… |
| CVE-2026-22678 | 5.1 | 13.0 | Webmin | Webmin | CWE-79 | Webmin < 2.641 Stored XSS via System and Server Status |
| CVE-2026-1881 | 4.3 | 12.7 | broadstreetads | Broadstreet | CWE-639 | Broadstreet <= 1.52.2 - Authenticated (Subscriber+) Private Post Meta Disclos… |
| CVE-2026-48240 | 7.1 | 12.6 | Open ISES | Tickets | CWE-89 | Open ISES Tickets < 3.44.2 SQL Injection via ajax/statistics.php tick_id and … |
| CVE-2026-48231 | 7.1 | 12.0 | Open ISES | Tickets | CWE-89 | Open ISES Tickets < 3.44.2 SQL Injection via tables.php Multiple Parameters |
| CVE-2026-48232 | 7.1 | 12.0 | Open ISES | Tickets | CWE-89 | Open ISES Tickets < 3.44.2 SQL Injection via ajax/fullsit_incidents.php offse… |
| CVE-2026-48233 | 7.1 | 12.0 | Open ISES | Tickets | CWE-89 | Open ISES Tickets < 3.44.2 SQL Injection via ajax/sit_incidents.php offset Pa… |
| CVE-2026-48234 | 7.1 | 12.0 | Open ISES | Tickets | CWE-89 | Open ISES Tickets < 3.44.2 SQL Injection via portal/ajax/list_requests.php so… |
| CVE-2026-48236 | 7.1 | 12.0 | Open ISES | Tickets | CWE-89 | Open ISES Tickets < 3.44.2 SQL Injection via db_loader.php Multiple Parameters |
| CVE-2026-48237 | 7.1 | 12.0 | Open ISES | Tickets | CWE-89 | Open ISES Tickets < 3.44.2 SQL Injection via message.php frm_ticket_id and fr… |
| CVE-2026-48238 | 7.1 | 12.0 | Open ISES | Tickets | CWE-89 | Open ISES Tickets < 3.44.2 SQL Injection via ajax/mobile_main.php id Parameter |
| CVE-2026-48239 | 7.1 | 12.0 | Open ISES | Tickets | CWE-89 | Open ISES Tickets < 3.44.2 SQL Injection via ajax/reports.php tick_id Parameter |
| CVE-2026-34928 | 7.8 | 11.9 | Trend Micro, Inc. | TrendAI Apex One | CWE-346 | An origin validation vulnerability in the Apex One/SEP agent could allow a lo… |
| CVE-2026-34930 | 7.8 | 11.9 | Trend Micro, Inc. | TrendAI Apex One | CWE-346 | An origin validation vulnerability in the Apex One/SEP agent could allow a lo… |
| CVE-2026-45206 | 7.8 | 11.9 | Trend Micro, Inc. | TrendAI Apex One | CWE-346 | An origin validation vulnerability in the Apex One/SEP agent could allow a lo… |
| CVE-2026-45207 | 7.8 | 11.9 | Trend Micro, Inc. | TrendAI Apex One | CWE-346 | An origin validation vulnerability in the Apex One/SEP agent could allow a lo… |
| CVE-2026-44063 | 4.2 | 11.9 | Netatalk | Netatalk | CWE-90 | LDAP filter injection |
| CVE-2026-48214 | 5.1 | 11.8 | Open ISES | Tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via add_nm.php ticket_id Parameter |
| CVE-2026-48215 | 5.1 | 11.8 | Open ISES | Tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via circle.php frm_id Parameter |
| CVE-2026-48216 | 5.1 | 11.8 | Open ISES | Tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via db_loader.php Multiple POST Para… |
| CVE-2026-48217 | 5.1 | 11.8 | Open ISES | Tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via delete_module.php Multiple POST … |
| CVE-2026-48219 | 5.1 | 11.8 | Open ISES | Tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via ics202.php frm_add_str Parameter |
| CVE-2026-48220 | 5.1 | 11.8 | Open ISES | Tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via ics205.php frm_add_str Parameter |
| CVE-2026-48221 | 5.1 | 11.8 | Open ISES | Tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via ics205a.php frm_add_str Parameter |
| CVE-2026-48222 | 5.1 | 11.8 | Open ISES | Tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via ics213.php frm_add_str Parameter |
| CVE-2026-48223 | 5.1 | 11.8 | Open ISES | Tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via ics213rr.php frm_add_str Parameter |
| CVE-2026-48225 | 5.1 | 11.8 | Open ISES | Tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via landb.php _type Parameter |
| CVE-2026-48230 | 5.1 | 11.7 | Open ISES | Tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via ticketsmdb_import.php Multiple P… |
| CVE-2026-8204 | 6.3 | 11.7 | Concrete CMS | Concrete CMS | CWE-639 | Concrete CMS 9.5.0 and below is vulnerable to Authorization Bypass in the Cal… |
| CVE-2026-8205 | 6.3 | 11.7 | Concrete CMS | Concrete CMS | CWE-425 | Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in Calenda… |
| CVE-2026-5434 | 5.9 | 11.2 | Honeywell International Inc. | Control Network Module (CNM) | CWE-538 | Improper storage of sensitive information |
| CVE-2026-48248 | 8.2 | 10.8 | Open ISES | Tickets | CWE-295 | Open ISES Tickets < 3.44.2 Disabled TLS Certificate Verification in incs/logi… |
| CVE-2026-7881 | 6.3 | 10.8 | Concrete CMS | Concrete CMS | CWE-639 | Concrete CMS 9.5.0 and below is vulnerable to IDOR in the Express Entry Detai… |
| CVE-2026-4929 | 5.1 | 10.8 | Drupal | Simple Hierarchical Select (shs) | CWE-79 | Simple Hierarchical Select (Drupal 7) XSS in term-derived output |
| CVE-2026-28764 | 7.8 | 10.6 | MediaArea | MediaInfoLib | CWE-823 | MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow vulnera… |
| CVE-2026-8236 | 6.3 | 10.5 | Concrete CMS | Concrete CMS | CWE-862 | Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing au… |
| CVE-2026-8237 | 6.3 | 10.4 | Concrete CMS | Concrete CMS | CWE-862 | Concrete CMS 9.5.0 and below is vulnerable to IDOR in the`/ccm/frontend/conve… |
| CVE-2026-8238 | 6.3 | 10.4 | Concrete CMS | Concrete CMS | CWE-862 | Concrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversa… |
| CVE-2026-45253 | 8.4 | 9.7 | FreeBSD | FreeBSD | CWE-787 | Missing validation in ptrace(PT_SC_REMOTE) |
| CVE-2026-5091 | 5.1 | 9.7 | JJNAPIORK | Catalyst::Plugin::Authentication | CWE-208 | Catalyst::Plugin::Authentication versions through 0.10024 for Perl is suscept… |
| CVE-2026-8239 | 6.3 | 9.6 | Concrete CMS | Concrete CMS | CWE-862 | Concrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversa… |
| CVE-2026-8240 | 6.3 | 9.6 | Concrete CMS | Concrete CMS | CWE-284 | Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata d… |
| CVE-2026-45254 | 6.5 | 9.5 | FreeBSD | FreeBSD | CWE-269 | Incorrect libcap_net limitation list manipulation |
| CVE-2026-8337 | 6.3 | 9.5 | Concrete CMS | Concrete CMS | CWE-565 | Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys when sites are … |
| CVE-2026-4843 | 4.3 | 9.2 | mrdollar4444 | GSheet For Woo Importer | CWE-862 | GSheet For Woo Importer <= 2.3.1 - Missing Authorization to Authenticated (Su… |
| CVE-2026-44057 | 3.1 | 8.6 | Netatalk | Netatalk | CWE-561 | Dead bounds check in Spotlight RPC unmarshaller |
| CVE-2026-1816 | 6.3 | 8.3 | Turkiye Electricity Transmission Corporation (TEİAŞ) | Mobile Application | CWE-307 | OTP Bypass in TEİAŞ's Mobile Application |
| CVE-2026-8197 | 7.3 | 8.1 | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integratio… |
| CVE-2026-8327 | 5.3 | 8.2 | Concrete CMS | Concrete CMS | CWE-269 | Concrete CMS below 9.5.0 and below is vulnerable to password change without r… |
| CVE-2026-1815 | 5.7 | 7.6 | Turkiye Electricity Transmission Corporation (TEİAŞ) | Mobile Application | CWE-613 | Session Hijacking in TEİAŞ's Mobile Application |
| CVE-2026-48247 | 8.2 | 7.0 | Open ISES | Tickets | CWE-295 | Open ISES Tickets < 3.44.2 Disabled TLS Certificate Verification in incs/func… |
| CVE-2026-48249 | 8.2 | 7.0 | Open ISES | Tickets | CWE-295 | Open ISES Tickets < 3.44.2 Disabled TLS Certificate Verification in rm/incs/m… |
| CVE-2026-39461 | 8.8 | 7.0 | FreeBSD | FreeBSD | CWE-121 | select(2) file descriptor set overflow causes stack overflow |
| CVE-2026-4093 | 5.1 | 6.9 | Drupal | Term Reference Tree | CWE-79 | Stored XSS in Drupal 7 Term Reference Tree module (token display templates an… |
| CVE-2026-48213 | 5.1 | 7.0 | Open ISES | Tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via add.php ticket_id Parameter |
| CVE-2026-7887 | 2.3 | 7.0 | Concrete CMS | Concrete CMS | CWE-1287 | For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypass… |
| CVE-2026-8421 | 7.5 | 6.8 | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9.5.0 and below is vulnerable to CSRF on install_package() with … |
| CVE-2026-8426 | 7.5 | 6.8 | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9.5.0 and below is vulnerable to CSRF on prepare_remote_upgrade(… |
| CVE-2026-44064 | 7.1 | 6.8 | Netatalk | Netatalk | CWE-125 | ASP session ID out-of-bounds access |
| CVE-2026-27393 | 5.3 | 6.9 | Tobias | CF7 WOW Styler | CWE-862 | WordPress CF7 WOW Styler plugin <= 1.7.6 - Broken Access Control vulnerability |
| CVE-2026-27349 | 4.3 | 6.9 | WPFunnels Team | Mail Mint | CWE-497 | WordPress Mail Mint plugin <= 1.19.5 - Sensitive Data Exposure vulnerability |
| CVE-2026-45251 | 7.8 | 6.8 | FreeBSD | FreeBSD | CWE-416 | Kernel use-after-free via file descriptor syscalls |
| CVE-2026-48246 | 8.2 | 6.7 | Open ISES | Tickets | CWE-295 | Open ISES Tickets < 3.44.2 Disabled TLS Certificate Verification in ajax/repo… |
| CVE-2026-48226 | 5.1 | 6.7 | Open ISES | Tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via os_watch.php ref and mode_orig P… |
| CVE-2026-48227 | 5.1 | 6.7 | Open ISES | Tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via patient.php id and ticket_id Par… |
| CVE-2026-48228 | 5.1 | 6.7 | Open ISES | Tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via patient_w.php id and ticket_id P… |
| CVE-2026-48229 | 5.1 | 6.7 | Open ISES | Tickets | CWE-79 | Open ISES Tickets < 3.44.2 Reflected XSS via routes_i.php ticket_id Parameter |
| CVE-2026-4055 | 4.3 | 4.9 | Mattermost | Mattermost | CWE-863 | Insufficient permission validation on cross-team playbook run creation |
| CVE-2026-7890 | 2.1 | 4.9 | Concrete CMS | Concrete CMS | CWE-918 | Concrete CMS 9.5.0 is vulnerable to SSRF via RSS Displayer Block |
| CVE-2026-8139 | 2.0 | 4.7 | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link pa… |
| CVE-2026-41999 | 4.8 | 4.0 | PowerDNS | Authoritative | CWE-284 | Incorrect Behaviour of Views with TCP PROXY Requests |
| CVE-2026-8409 | 2.3 | 4.0 | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF… |
| CVE-2026-8410 | 2.3 | 4.0 | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF… |
| CVE-2026-8245 | 6.0 | 3.8 | Concrete CMS | Concrete CMS | CWE-83 | Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Paginat… |
| CVE-2026-36189 | 6.2 | 3.3 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in Uncrustify Project Affected v.Uncrustify_d-0… |
| CVE-2026-8428 | 7.5 | 3.2 | Concrete CMS | Concrete CMS | CWE-352 | CSRF token is not validated in the core CMS update controller for Concrete CM… |
| CVE-2026-44076 | 6.7 | 3.1 | Netatalk | Netatalk | CWE-78 | Shell injection via volume path |
| CVE-2026-44065 | 4.2 | 3.1 | Netatalk | Netatalk | CWE-193 | Off-by-two in papd lp_write() |
| CVE-2026-8411 | 2.3 | 3.1 | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF… |
| CVE-2026-8412 | 2.3 | 3.1 | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF… |
| CVE-2026-8413 | 2.3 | 3.1 | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF… |
| CVE-2026-8414 | 2.3 | 3.1 | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF… |
| CVE-2026-8415 | 2.3 | 3.1 | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF… |
| CVE-2026-8416 | 2.3 | 3.1 | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF… |
| CVE-2026-8427 | 2.3 | 3.1 | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF… |
| CVE-2026-8432 | 2.3 | 3.1 | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF… |
| CVE-2026-8433 | 2.3 | 3.1 | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF… |
| CVE-2026-8434 | 2.3 | 3.1 | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF… |
| CVE-2026-43502 | 7.8 | 2.5 | Linux | Linux | — | net/rds: handle zerocopy send cleanup before the message is queued |
| CVE-2026-8417 | 7.5 | 2.3 | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9.5.0 and below is vulnerable to CSRF in do_update() in the pack… |
| CVE-2026-8203 | 7.3 | 2.3 | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS 9.5.0 and below has Stored XSS on the height parameter |
| CVE-2026-9157 | 8.6 | 2.1 | Gmission | Web Fax | CWE-20 | Remote Code Execution in Gmission Web FAX |
| CVE-2026-8140 | 7.5 | 2.0 | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9.5.0 and below is vulnerable to CSRF on download() in the packa… |
| CVE-2026-43496 | 5.5 | 2.0 | Linux | Linux | CWE-476 | net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_p… |
| CVE-2026-22880 | 6.1 | 2.0 | Mattermost | Mattermost | CWE-352 | Mobile SSO authentication flow allows credential theft via malicious server |
| CVE-2026-7882 | 2.3 | 1.9 | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9.5.0 and below is vulnerable to CSRF via the DeleteFile controller |
| CVE-2026-8435 | 2.3 | 1.8 | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF… |
| CVE-2026-43498 | 7.8 | 1.6 | Linux | Linux | CWE-787 | accel/ivpu: Disallow re-exporting imported GEM objects |
| CVE-2026-43497 | 7.3 | 1.7 | Linux | Linux | CWE-416 | fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free |
| CVE-2026-44069 | 3.9 | 0.7 | Netatalk | Netatalk | CWE-191 | Integer underflow in volxlate |
| CVE-2026-44072 | 3.0 | 0.6 | Netatalk | Netatalk | CWE-78 | system() after failed chdir() |
| CVE-2026-44059 | 4.5 | 0.0 | Netatalk | Netatalk | CWE-362 | Non-reentrant privilege toggle |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-05-21 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion.