boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Friday, May 22, 2026 · all times UTC← 2026-05-21 · archive · 2026-05-23 →

Security Box Score — May 22, 2026

148 CVEs published, led by golang.org/x/crypto (13).

148 CVEs published May 22, 2026: 25 critical, 52 high, 61 medium, 10 low; 1 in the KEV catalog at press time; 5 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 123 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published10762288——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

40 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux225551674463801120.47.8.0014+130 ▲
microsoft160530463711112286193.67.8.0047-15 ▼
red hat1062526247200.06.8.0041-8 ▼
apple154511528188715.66.2.0028+15 ▲
google16230176077417.48.8.0034+15 ▲
freebsd770520000.07.8.0020+7 ▲
suse220200000.08.2.0020+2 ▲
ubuntu010001100.02.7.02180
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco512534056866.77.8.1576+5 ▲
fortinet17430028342.99.1.8584-2 ▼
ivanti25230025480.08.8.8056+2 ▲
ubiquiti231200300.08.8.0068+2 ▲
f52220004150.09.2.3901+2 ▲
palo alto networks22110013150.08.6.6281+2 ▲
vmware01010071100.08.1.17420
check point00000010———0
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache922412603314.57.5.0080+6 ▲
mozilla553200900.09.6.0045+5 ▲
docker330300000.08.8.0022+3 ▲
drupal3310204133.35.1.0021+3 ▲
gitlab00000042———0
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
progress440400600.07.5.0036+4 ▲
oracle0312002700.07.5.00880
solarwinds032100103100.09.8.83620
adobe020200192100.08.6.0368-2 ▼
zohocorp110100000.08.4.0170+1 ▲
atlassian000000130———0
ibm00000060———0
sap00000060———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
siemens110100000.08.7.0032+1 ▲
d-link00000030———0
tp-link00000010———0
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
concrete cms4444191321000.05.7.0015+44 ▲
open ises3737214210000.06.9.0021+37 ▲
netatalk3333113910000.06.4.0030+33 ▲
grafana102727162200.06.5.0033+7 ▲
dell121816110215.66.7.0019+7 ▲
nvidia16167900000.08.4.0060+16 ▲
trend micro1616213101216.37.8.0030+16 ▲
givanz11152760000.08.3.0028+7 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-31431.9991100.07.8
CVE-2026-41940.985399.99.3
CVE-2026-0257.939199.87.8
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2026-20182.915299.810.0
CVE-2026-42208.894299.89.3
CVE-2026-9082.883299.89.8
CVE-2024-1708.875699.78.4
CVE-2026-42271.835499.78.7
Highest CVSS
CVECVSSEPSSNote
CVE-2026-2018210.0.9152KEV
CVE-2026-4399710.0.0098
CVE-2026-3381910.0.0084
CVE-2026-4282610.0.0084
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
CVE-2026-3543110.0.0051
CVE-2026-4659510.0.0050
CVE-2026-4282210.0.0049
Most disclosures (vendor)
VendorCVEs
linux295
microsoft169
concrete cms44
open ises37
netatalk33
google16
nvidia16
trend micro16
apache15
apple15
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco8
apple7
google4
ivanti4
fortinet3
smartertools3
solarwinds3
adobe2
berriai2
Most-affected ecosystems
EcosystemAdvisories
Maven4
PyPI1
npm1
Fastest to KEV
CVEVendorDays
CVE-2024-1708ConnectWise0
CVE-2024-57726n/a0
CVE-2024-57728n/a0
CVE-2026-31431Linux0
CVE-2026-32202Microsoft0
CVE-2026-34926Trend Micro, Inc.0
CVE-2026-41091Microsoft0
CVE-2026-41940WebPros0
CVE-2026-42208BerriAI0
CVE-2026-42897Microsoft0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171647
CVE-2021-27102n/a2021-11-171647
CVE-2021-27101n/a2021-11-171647
CVE-2021-27103n/a2021-11-171647
CVE-2021-21017Adobe2021-11-171647
CVE-2021-28550Adobe2021-11-171647
CVE-2021-42013Apache Software Foundation2021-11-171647
CVE-2021-41773Apache Software Foundation2021-11-171647
CVE-2021-30858Apple2021-11-171647
CVE-2021-30860Apple2021-11-171647

Transactions

EXPLOIT PUBLISHED — CVE-2026-32253 (LizardByte Sunshine). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-40610 (BentoML). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-41069 (strukturag libheif). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-41071 (strukturag libheif). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-5072 (zephyrproject-rtos Zephyr). Public exploit reference added.

Yesterday's Results

How to read these box scores · glossary

148 CVEs published. 25 box scores, 123 table rows — nothing truncated.

Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .8832   99.8   YES
AFFECTED
  Product      Versions  Fixed
  Drupal core  8.9.0 –   —
TIMELINE
  May 20  Reserved by CNA
  May 22  Added to CISA KEV, due May 27
  May 22  Published (CNA: drupal)
CWE-89 · CNA: drupal · CVSS v3.1 · 2 references · NVD status: Analyzed · KEV due May 27, 2026
F5 NGINX Plus — NGINX ngx_http_rewrite_module vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   N   H   H   H    9.2   .0996   95.2     —
AFFECTED
  Product            Versions  Fixed
  NGINX Plus         37.0 –    —
  NGINX Open Source  1.31.0 –  —
TIMELINE
  May 21  Reserved by CNA
  May 22  Published (CNA: f5)
CWE-122 · CNA: f5 · CVSS v4.0 · 14 references · NVD status: Analyzed
golang.org/x/crypto golang.org/x/crypto/ssh/knownhosts — Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0731   93.9     —
AFFECTED
  Product                             Versions     Fixed
  golang.org/x/crypto/ssh/knownhosts  unspecified  —
TIMELINE
  Apr 28  Reserved by CNA
  May 22  Published (CNA: Go)
CWE-295 · CNA: Go · CVSS v3.1 · 42 references · NVD status: Modified
cssigniterteam AudioIgniter Music Player — AudioIgniter Music Player <= 2.0.2 - Unauthenticated Insecure Direct Object Reference to 'audioigniter_playlist_id' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0157   73.4     —
AFFECTED
  Product                    Versions     Fixed
  AudioIgniter Music Player  unspecified  —
TIMELINE
  May 15  Reserved by CNA
  May 22  Published (CNA: Wordfence)
CWE-639 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Deferred
Ubiquiti Inc UniFi OS Server — A malicious actor with access to the network and high privileges could exploit an Improper Input Validation…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0125   67.1     —
AFFECTED
  Product          Versions     Fixed
  UniFi OS Server  unspecified  —
TIMELINE
  Mar 17  Reserved by CNA
  May 22  Published (CNA: hackerone)
CWE-20 · CNA: hackerone · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Planetary Computer Pro Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0092   57.6     —
AFFECTED
  Product                                        Versions  Fixed
  Microsoft Planetary Computer Pro (GeoCatalog)  - –       —
TIMELINE
  Apr 16  Reserved by CNA
  May 22  Published (CNA: microsoft)
CWE-502 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
n/a n/a — Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive info…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  N    6.5   .0087   55.9     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  May 22  Published (CNA: mitre)
CWE-22 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Deferred
shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0085   55.3     —
AFFECTED
  Product      Versions  Fixed
  shell-quote  1.1.0 –   —
TIMELINE
  May 22  Reserved by CNA
  May 22  Published (CNA: harborist)
CWE-78, CWE-77 · CNA: harborist · CVSS v4.0 · 34 references · NVD status: Deferred
n/a n/a — Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 allows…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0072   51.0     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 22  Reserved by CNA
  May 22  Published (CNA: mitre)
CWE-22 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
techjewel FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution — FluentCRM <= 2.9.87 - Unauthenticated Blind Server-Side Request Forgery via 'SubscribeURL' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  C  L  L  N    5.4   .0069   50.2     —
AFFECTED
  Product                                                                                                      Versions     Fixed
  FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution  unspecified  —
TIMELINE
  May 4   Reserved by CNA
  May 22  Published (CNA: Wordfence)
CWE-918 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0069   50.2     —
AFFECTED
  Product     Versions  Fixed
  Apache CXF  4.2.0 –   —
TIMELINE
  May 8   Reserved by CNA
  May 22  Published (CNA: apache)
CWE-90 · CNA: apache · CVSS v3.1 · 6 references · NVD status: Modified
Go standard library net/http — Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  N    9.6   .0069   50.1     —
AFFECTED
  Product                  Versions     Fixed
  net/http                 unspecified  —
  net/http/internal/http2  unspecified  —
  golang.org/x/net/idna    unspecified  —
TIMELINE
  Apr 7   Reserved by CNA
  May 22  Published (CNA: Go)
CWE-1289 · CNA: Go · CVSS v3.1 · 127 references · NVD status: Modified
Ubiquiti Inc UniFi OS Server — A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerabilit…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  N  N    7.7   .0068   49.6     —
AFFECTED
  Product          Versions     Fixed
  UniFi OS Server  unspecified  —
  UDM              unspecified  —
  UDM-Pro          unspecified  —
  UDM-SE           unspecified  —
  UDM-Pro-Max      unspecified  —
  UDM-Beast        unspecified  —
  EFG              unspecified  —
  UDW              unspecified  —
  UDR              unspecified  —
  UDR7             unspecified  —
  + 21 more
TIMELINE
  Mar 31  Reserved by CNA
  May 22  Published (CNA: hackerone)
CWE-22 · CNA: hackerone · CVSS v3.1 · 1 reference · NVD status: Analyzed
Apache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to RCE)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0064   47.9     —
AFFECTED
  Product     Versions  Fixed
  Apache CXF  4.2.0 –   —
TIMELINE
  May 6   Reserved by CNA
  May 22  Published (CNA: apache)
CWE-20, CWE-15 · CNA: apache · CVSS v3.1 · 5 references · NVD status: Modified
golang.org/x/crypto golang.org/x/crypto/ssh — Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  H    9.1   .0062   47.1     —
AFFECTED
  Product                  Versions     Fixed
  golang.org/x/crypto/ssh  unspecified  —
TIMELINE
  Apr 7   Reserved by CNA
  May 22  Published (CNA: Go)
CWE-772 · CNA: Go · CVSS v3.1 · 52 references · NVD status: Modified
golang.org/x/crypto golang.org/x/crypto/ssh/agent — Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0060   46.1     —
AFFECTED
  Product                        Versions     Fixed
  golang.org/x/crypto/ssh/agent  unspecified  —
TIMELINE
  Apr 7   Reserved by CNA
  May 22  Published (CNA: Go)
CWE-281 · CNA: Go · CVSS v3.1 · 37 references · NVD status: Modified
Microsoft Azure Stack HCI — Azure Stack HCI Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  N  N    7.7   .0058   45.0     —
AFFECTED
  Product          Versions  Fixed
  Azure Stack HCI  - –       —
TIMELINE
  Feb 11  Reserved by CNA
  May 22  Published (CNA: microsoft)
CWE-20 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Power Pages Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0058   44.9     —
AFFECTED
  Product                Versions  Fixed
  Microsoft Power Pages  - –       —
TIMELINE
  Jan 14  Reserved by CNA
  May 22  Published (CNA: microsoft)
CWE-77 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
ivanti Secure Access Client — An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remo…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0056   44.3     —
AFFECTED
  Product               Versions     Fixed
  Secure Access Client  unspecified  22.8R6
TIMELINE
  May 19  Reserved by CNA
  May 22  Published (CNA: ivanti)
CWE-295 · CNA: ivanti · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0055   43.6     —
AFFECTED
  Product                               Versions  Fixed
  Microsoft Global Secure Access (GSA)  - –       —
TIMELINE
  Jan 14  Reserved by CNA
  May 22  Published (CNA: microsoft)
CWE-269 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
themewant Easy Elements for Elementor – Addons & Website Templates — Easy Elements for Elementor – Addons & Website Templates <= 1.4.5 - Unauthenticated Privilege Escalation via 'custom_meta' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0054   43.1     —
AFFECTED
  Product                                                   Versions     Fixed
  Easy Elements for Elementor – Addons & Website Templates  unspecified  —
TIMELINE
  May 19  Reserved by CNA
  May 22  Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Deferred
goauthentik authentik — authentik: Privilege Escalation via User PATCH: Superuser Group Assignment Bypasses enable_group_superuser
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  H    8.1   .0053   42.7     —
AFFECTED
  Product    Versions       Fixed
  authentik  < 2025.12.5 –  —
TIMELINE
  Apr 9   Reserved by CNA
  May 22  Published (CNA: GitHub_M)
CWE-269 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Deferred
Microsoft Azure Orbital Spatio — Azure Orbital Spatio Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0053   42.6     —
AFFECTED
  Product               Versions  Fixed
  Azure Orbital Spatio  - –       —
TIMELINE
  Apr 13  Reserved by CNA
  May 22  Published (CNA: microsoft)
CWE-434 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
golang.org/x/crypto golang.org/x/crypto/ssh — Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0053   42.1     —
AFFECTED
  Product                  Versions     Fixed
  golang.org/x/crypto/ssh  unspecified  —
TIMELINE
  Apr 7   Reserved by CNA
  May 22  Published (CNA: Go)
CWE-190 · CNA: Go · CVSS v3.1 · 4 references · NVD status: Analyzed
Microsoft Azure Virtual Network Gateway — Azure Virtual Network Gateway Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0053   42.1     —
AFFECTED
  Product                        Versions  Fixed
  Azure Virtual Network Gateway  - –       —
TIMELINE
  Apr 13  Reserved by CNA
  May 22  Published (CNA: microsoft)
CWE-20 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-398355.340.7golang.org/x/cryptogolang.org/x/crypto/sshCWE-476Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto…
CVE-2026-4659510.040.7golang.org/x/cryptogolang.org/x/crypto/sshCWE-863Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org…
CVE-2026-428277.540.7MicrosoftMicrosoft 365 CopilotCWE-77M365 Copilot Information Disclosure Vulnerability
CVE-2026-405977.640.4mantisbtmantisbtCWE-79MantisBT has a Content Security Policy bypass via attachments
CVE-2026-472809.840.1MicrosoftAzure Resource ManagerCWE-287Azure Resource Manager Elevation of Privilege Vulnerability
CVE-2026-467278.139.1ruby-langRubyCWE-362An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a…
CVE-2026-338439.838.8MicrosoftMicrosoft EntraCWE-288Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
CVE-2026-465977.538.8golang.org/x/cryptogolang.org/x/crypto/sshCWE-704Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh
CVE-2026-398297.538.3golang.org/x/cryptogolang.org/x/crypto/sshCWE-1284Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto…
CVE-2026-90117.538.1metaphorcreationsDitty – Responsive News Tickers, Sliders, and ListsCWE-862Ditty <= 3.1.65 - Missing Authorization to Unauthenticated Sensitive Informat…
CVE-2026-401667.137.9goauthentikauthentikCWE-200authentik: Non-admin user can retrieve confidential OAuth client_secret via /…
CVE-2026-405986.937.0mantisbtmantisbtCWE-79MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Up…
CVE-2026-354308.835.3MicrosoftAzure Privileged Identity Management (PIM)CWE-639Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability
CVE-2026-362287.335.2n/an/aCWE-120Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacke…
CVE-2026-405967.235.1mantisbtmantisbtCWE-79MantisBT is vulnerable to XSS and potential account takeover via user font fa…
CVE-2026-411478.735.0nukevietnukevietCWE-79NukeViet CMS: Stored Cross-Site Scripting (XSS) via insufficient server-side …
CVE-2026-410909.334.8MicrosoftMicrosoft 365 Copilot for iOSCWE-77Microsoft Copilot Tampering Vulnerability
CVE-2026-398319.134.8golang.org/x/cryptogolang.org/x/crypto/sshCWE-862Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/…
CVE-2026-406077.534.6mantisbtmantisbtCWE-79MantisBT is Vulnerable to Stored XSS Through its Saved-Filter Owner Column
CVE-2026-398339.134.0golang.org/x/cryptogolang.org/x/crypto/ssh/agentCWE-862Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent
CVE-2026-465985.334.0golang.org/x/cryptogolang.org/x/crypto/ssh/agentCWE-129Invoking pathological inputs can lead to client panic in golang.org/x/crypto/…
CVE-2026-411495.332.9mermaid-jsmermaidCWE-94Mermaid: Improper sanitization of `classDef` in state diagrams leads to HTML …
CVE-2026-32948.732.6TP-Link Systems Inc.Archer RE650 v1CWE-862Authentication Logic Vulnerability on Multiple TP-Link Range Extenders
CVE-2026-410768.132.0bestpracticalrtCWE-287RT: LDAP authentication bypass via empty password
CVE-2026-92917.530.8AWSAmazon Braket Python SDKCWE-502Insecure Deserialization in Amazon Braket SDK Job Results Processing
CVE-2026-398286.329.6golang.org/x/cryptogolang.org/x/crypto/sshCWE-281Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh
CVE-2026-3371210.027.2baptisteArnotypebot.ioCWE-862TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint …
CVE-2022-312317.527.1DellECSCWE-284Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Ide…
CVE-2026-410758.826.9bestpracticalrtCWE-89RT: SQL injection via entry_aggregator parameter in JSON search
CVE-2026-57407.526.5MattermostMattermostCWE-789Unauthenticated WebSocket binary frame causes denial of service in Mattermost…
CVE-2026-411485.326.2mermaid-jsmermaidCWE-94Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injection
CVE-2026-256806.524.9golang.org/x/netgolang.org/x/net/htmlCWE-400Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html
CVE-2026-374707.324.6n/an/aCWE-1021An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary cod…
CVE-2026-90477.624.1DevolutionsServerCWE-305Improper handling of factor key state in the multi-factor authentication mana…
CVE-2026-284446.523.8baptisteArnotypebot.ioCWE-639Typebot: IDOR in Result Logs Endpoint Allows Cross-Workspace Data Disclosure
CVE-2026-446185.322.3Apache Software FoundationApache CXFCWE-611Apache CXF: XXE vulnerability in WS-Transfer functionality
CVE-2026-410715.122.2strukturaglibheifCWE-125libheif: Heap buffer over-read in SampleAuxInfoReader via crafted HEIF sequen…
CVE-2026-4290110.022.1MicrosoftMicrosoft EntraCWE-346Microsoft Entra ID Elevation of Privilege Vulnerability
CVE-2026-50726.522.0zephyrproject-rtosZephyrCWE-1335ptp: Potential Denial of Service via PTP Interval Shift
CVE-2026-322539.821.1LizardByteSunshineCWE-287Sunshine: Authentication bypass via improper client certificate validation
CVE-2026-90549.221.19front9frontCWE-130Invalid IP packets cause a kernel panic
CVE-2026-406105.520.3bentomlBentoMLCWE-59BentoML has Information Disclosure in `bentoml build` via symlink traversal i…
CVE-2026-398276.519.9golang.org/x/cryptogolang.org/x/crypto/sshCWE-924Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/…
CVE-2026-86845.319.7jetmonstersMotoPress Hotel BookingCWE-862MotoPress Hotel Booking <= 6.0.1 - Missing Authorization to Unauthenticated A…
CVE-2026-399708.519.5baptisteArnotypebot.ioCWE-79TypeBot: Stored Cross-Site Scripting (XSS) via SVG File Upload On Profile Pic…
CVE-2026-90536.919.59front9frontCWE-434Mothra would respect a default value given by a website for HTML file upload …
CVE-2026-48347.519.1weDevsWP ERP ProCWE-89WP ERP Pro <= 1.5.1 - Unauthenticated SQL Injection via 'search_key' Parameter
CVE-2026-399687.118.8baptisteArnotypebot.ioCWE-284TypeBot: Cross-Workspace Credential Theft via Bot-Engine Preview Endpoint
CVE-2026-68646.117.8manchumaharaCBX 5 Star Rating & ReviewCWE-79CBX 5 Star Rating & Review <= 1.0.7 - Reflected Cross-Site Scripting via 'pag…
CVE-2026-284458.717.0baptisteArnotypebot.ioCWE-79Typebot: Stored XSS via Rating Block Custom Icon Bypasses isUnsafe Sandbox in…
CVE-2026-399666.516.9baptisteArnotypebot.ioCWE-863TypeBot: Async filter() bypasses authorization, allowing IDOR in getLinkedTyp…
CVE-2026-362266.116.8n/an/aCWE-79Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.1…
CVE-2026-53087.516.6MattermostMattermostCWE-400Missing request body size limits on Zoom plugin HTTP endpoints
CVE-2026-410696.516.4strukturaglibheifCWE-125libheif allows Out-of-bounds vector access leading to invalid dereference (DoS)
CVE-2026-46464.316.1MattermostMattermostCWE-1287Insufficient input validation in GitHub plugin API causes denial of service
CVE-2026-75096.416.0helgathevikingKIA SubtitleCWE-79KIA Subtitle <= 4.0.1 - [Improper Neutralization of Input During Web Page Gen…
CVE-2026-34816.116.0burlingtonbytesWP Blockade – Visual Page BuilderCWE-79WP Blockade <= 0.9.14 - Reflected Cross-Site Scripting via 'shortcode' Parameter
CVE-2026-84772.715.9DevolutionsServerCWE-841Improper enforcement of the sealed-entry workflow in the entry sensitive-data…
CVE-2026-72494.315.8shapedpluginLocation Weather – WordPress Weather Forecast, AQI, Temperature and Weather WidgetCWE-862Location Weather <= 3.0.2 - Missing Authorization to Authenticated (Contribut…
CVE-2022-343637.515.8DellUnisphere for PowerMaxCWE-285Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an autho…
CVE-2026-73257.115.7DevolutionsServerCWE-918Improper authorization in the Active Directory browsing feature in Devolution…
CVE-2026-57556.515.5MattermostMattermostCWE-400Denial of service via crafted TIFF file upload
CVE-2026-402956.115.0heartcombodeviseCWE-601Devise: Open Redirect via Unvalidated `request.referrer` in Timeoutable Sessi…
CVE-2026-399645.415.0baptisteArnotypebot.ioCWE-79TypeBot: Stored XSS via javascript: URI in text bubble links — bot author exe…
CVE-2026-399657.714.7baptisteArnotypebot.ioCWE-918TypeBot: SSRF via Open Redirect Bypass in HTTP Request and Code Blocks
CVE-2026-342077.614.7baptisteArnotypebot.ioCWE-20TypeBot: SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP …
CVE-2026-76364.314.4smubSlider by Soliloquy – Responsive Image Slider for WordPressCWE-200Slider by Soliloquy <= 2.8.1 - Authenticated (Subscriber+) Information Disclo…
CVE-2026-425066.114.3golang.org/x/netgolang.org/x/net/htmlCWE-79Invoking incorrect handling of namespaced elements in foreign content in gola…
CVE-2026-51714.314.1DevolutionsServerCWE-284Improper access control in the entry activity log feature in Devolutions Serv…
CVE-2026-92649.313.8TrimbleSketchUpCWE-94Cross-Site Scripting in SketchUp Dynamic Components
CVE-2026-92455.013.6DevolutionsServerCWE-601Improper input validation in the external authentication provider flow in Dev…
CVE-2026-25184.313.6wpxpoFastXCWE-862FastX <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Limited…
CVE-2026-83472.313.3Concrete CMSConcrete CMSCWE-639Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-leve…
CVE-2026-256068.712.9Centralny Instytut Ochrony Pracy - Państwowy Instytut BadawczySTERCWE-89SQL Injection in STER
CVE-2026-86924.313.0registrationformbuilderVedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form BuilderCWE-862Vedrixa Forms <= 1.1.1 - Missing Authorization to Authenticated (Subscriber+)…
CVE-2026-58178.812.9DockerDocker DesktopCWE-829Docker Model Runner container-to-host code execution via unsandboxed trust_re…
CVE-2026-58438.812.9DockerDocker DesktopCWE-829Docker Model Runner container-to-host code execution via MLX-LM model_file im…
CVE-2026-256816.112.7golang.org/x/netgolang.org/x/net/htmlCWE-1021Invoking incorrect handling of character references in DOCTYPE nodes in golan…
CVE-2026-271366.112.7golang.org/x/netgolang.org/x/net/htmlCWE-1021Invoking duplicate attributes can cause XSS in golang.org/x/net/html
CVE-2026-425026.112.7golang.org/x/netgolang.org/x/net/htmlCWE-1021Invoking incorrect handling of HTML elements in foreign content in golang.org…
CVE-2026-91046.412.3dartissDraft ListCWE-79Draft List <= 2.6.3 - Authenticated (Author+) Stored Cross-Site Scripting via…
CVE-2026-92472.412.2DevolutionsServerCWE-778Insufficient logging in the entry export feature in Devolutions Server allows…
CVE-2026-86709.611.8syslink software AGAvantraCWE-613Insecure session handling on metrics web server
CVE-2026-86717.511.8syslink software AGAvantraCWE-532Log Files contain encrypted secrets
CVE-2026-444097.511.8ZTEMU5250CWE-862Information disclosure vulnerability in ZTE MU5250
CVE-2026-92234.311.5DevolutionsServerCWE-284Missing authorization in the vault import feature in Devolutions Server 2026.…
CVE-2026-92244.311.4DevolutionsServerCWE-862Missing authorization in the user profile update feature in Devolutions Serve…
CVE-2026-92464.311.4DevolutionsServerCWE-862Improper access control in the entry documentation and attachment features in…
CVE-2026-64068.811.2DockerDocker DesktopCWE-863Docker Desktop Enhanced Container Isolation bypass via --use-api-socket CLI flag
CVE-2026-256082.310.8Centralny Instytut Ochrony Pracy - Państwowy Instytut BadawczySTERCWE-319Lack of traffic encryption in STER
CVE-2026-92515.49.1DevolutionsServerCWE-862Missing authorization in the entry status management feature in Devolutions S…
CVE-2026-86739.18.8syslink software AGAvantraCWE-523Password re-initialization mechanism sends passwords in plain text
CVE-2026-92493.18.2DevolutionsServerCWE-620Unverified password change in Devolutions Server allows an attacker to change…
CVE-2026-399673.18.2baptisteArnotypebot.ioCWE-639TypeBot: Cross-Typebot Result Data Access via Missing typebotId Filter
CVE-2026-92482.68.2DevolutionsServerCWE-639Authorization bypass in the entry duplication feature in Devolutions Server a…
CVE-2026-36364.38.0MattermostMattermostCWE-200Sanitize team member data returned by API
CVE-2025-264838.26.7DellPowerFlex Manager (Appliance)CWE-601Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect V…
CVE-2026-46355.36.7MattermostMattermostCWE-362Persistent notification timing attack causing server denial of service
CVE-2026-76154.36.3kasparsdWidget ContextCWE-352Widget Context <= 1.3.3 - Cross-Site Request Forgery to Settings Update via '…
CVE-2026-410734.66.0bestpracticalrtCWE-1236RT: Spreadsheet downloads vulnerable to CSV/formula injection in Microsoft Ex…
CVE-2026-40704.35.7pftoolAlfie – Feed PluginCWE-352Alfie <= 1.2.1 - Cross-Site Request Forgery to Feed Deletion via 'delete' Par…
CVE-2026-426265.95.3n/an/aCWE-400HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage co…
CVE-2026-408644.35.2jupyterhubjupyterhubCWE-352JupyterHub: Cross-origin form POSTs bypass XSRF
CVE-2026-34737.14.3MattermostMattermostCWE-639Improper file ownership validation in the Boards API allows unauthorised file…
CVE-2026-83532.14.3Concrete CMSConcrete CMSCWE-79Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name i…
CVE-2026-83815.43.6TeamViewerDEX (On-premises)CWE-862Broken Access Control in TeamViewer DEX Platform (On Premises)
CVE-2026-399696.53.6baptisteArnotypebot.ioCWE-287TypeBot: WhatsApp Webhook Endpoint Missing Signature Verification
CVE-2026-89974.83.6vifmvifmCWE-122Heap Buffer Overflow in vifm
CVE-2026-287355.43.4MattermostMattermostCWE-863GitHub OAuth Scope Validation
CVE-2026-426276.23.0n/an/aCWE-190In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumEl…
CVE-2025-327497.52.6DellPowerFlex Manager (Appliance)CWE-276Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Informa…
CVE-2026-92558.42.0AWSKiro CLICWE-862Tool Execution Without Authorization via Piped Stdin in Kiro CLI
CVE-2026-410747.11.8bestpracticalrtCWE-352RT has broken CSRF protection for authenticated users
CVE-2021-215086.71.8DellVxRailCWE-532Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vul…
CVE-2026-398243.31.6golang.org/x/sysgolang.org/x/sys/windowsCWE-190Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows
CVE-2026-86725.11.2syslink software AGAvantraCWE-1393Default credentials for internal DB
CVE-2025-327465.51.1DellPowerFlex Manager (Appliance)CWE-922Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of…
CVE-2026-83402.31.1Concrete CMSConcrete CMSCWE-352Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveV…
CVE-2025-327515.51.0DellPowerFlex Manager (Appliance)CWE-922Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of…
CVE-2026-256075.70.8Centralny Instytut Ochrony Pracy - Państwowy Instytut BadawczySTERCWE-261Weak password encoding in STER
CVE-2025-327477.80.5DellPowerFlex Manager (Appliance)CWE-266Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege…
CVE-2025-327456.50.3DellPowerFlex Manager (Appliance)CWE-295Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificat…
CVE-2025-463715.50.0DellPowerFlex Manager (Appliance)CWE-327Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or R…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-05-22 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.