AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .8832 99.8 YES
AFFECTED Product Versions Fixed Drupal core 8.9.0 – —
TIMELINE May 20 Reserved by CNA May 22 Added to CISA KEV, due May 27 May 22 Published (CNA: drupal)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
148 CVEs published, led by golang.org/x/crypto (13).
148 CVEs published May 22, 2026: 25 critical, 52 high, 61 medium, 10 low; 1 in the KEV catalog at press time; 5 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 123 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 1070 | 2262 | 1011 | 2564 |
| KEV catalog size | 1671 | |||
38 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 225 | 552 | 67 | 446 | 36 | 0 | 27 | 2 | 0.4 | 7.8 | .0014 | +130 ▲ |
| microsoft | 164 | 539 | 46 | 371 | 111 | 2 | 380 | 27 | 5.0 | 7.8 | .0048 | -14 ▼ |
| apple | 13 | 40 | 0 | 10 | 22 | 1 | 94 | 7 | 17.5 | 6.2 | .0037 | +13 ▲ |
| red hat | 9 | 32 | 5 | 17 | 8 | 2 | 4 | 0 | 0.0 | 7.5 | .0041 | -2 ▼ |
| 16 | 22 | 0 | 13 | 6 | 0 | 74 | 4 | 18.2 | 8.4 | .0035 | +15 ▲ | |
| freebsd | 7 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0020 | +7 ▲ |
| suse | 2 | 2 | 0 | 2 | 0 | 0 | 0 | 0 | 0.0 | 8.2 | .0020 | +2 ▲ |
| android | 0 | 0 | 0 | 0 | 0 | 0 | 15 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 5 | 13 | 3 | 1 | 2 | 0 | 96 | 8 | 61.5 | 8.6 | .1247 | +2 ▲ |
| fortinet | 1 | 6 | 1 | 3 | 0 | 0 | 28 | 3 | 50.0 | 7.9 | .4330 | -2 ▼ |
| ivanti | 2 | 5 | 0 | 1 | 0 | 0 | 33 | 4 | 80.0 | 8.8 | .8056 | +1 ▲ |
| f5 | 2 | 3 | 2 | 0 | 0 | 0 | 7 | 1 | 33.3 | 9.2 | .0996 | +2 ▲ |
| ubiquiti | 2 | 3 | 1 | 2 | 0 | 0 | 4 | 0 | 0.0 | 8.8 | .0068 | +2 ▲ |
| broadcom | 0 | 2 | 0 | 0 | 0 | 0 | 4 | 2 | 100.0 | — | .1990 | 0 |
| palo alto networks | 1 | 1 | 0 | 0 | 0 | 0 | 14 | 1 | 100.0 | — | .3207 | +1 ▲ |
| citrix | 0 | 1 | 0 | 0 | 0 | 0 | 19 | 1 | 100.0 | — | .8447 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 9 | 20 | 4 | 12 | 4 | 0 | 40 | 1 | 5.0 | 7.5 | .0090 | +6 ▲ |
| mozilla | 5 | 5 | 3 | 2 | 0 | 0 | 13 | 0 | 0.0 | 9.6 | .0045 | +5 ▲ |
| docker | 3 | 3 | 0 | 3 | 0 | 0 | 1 | 0 | 0.0 | 8.8 | .0022 | +3 ▲ |
| drupal | 3 | 3 | 1 | 0 | 2 | 0 | 5 | 1 | 33.3 | 5.1 | .0021 | +3 ▲ |
| gitlab | 0 | 2 | 0 | 0 | 0 | 0 | 4 | 2 | 100.0 | — | .4451 | 0 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| wordpress | 0 | 0 | 0 | 0 | 0 | 0 | 5 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| progress | 4 | 4 | 0 | 4 | 0 | 0 | 9 | 0 | 0.0 | 7.5 | .0036 | +4 ▲ |
| adobe | 1 | 4 | 0 | 1 | 0 | 0 | 75 | 3 | 75.0 | 8.6 | .2776 | -2 ▼ |
| solarwinds | 0 | 3 | 1 | 0 | 0 | 0 | 11 | 3 | 100.0 | 9.8 | .8362 | 0 |
| oracle | 0 | 2 | 0 | 2 | 0 | 0 | 40 | 0 | 0.0 | 7.5 | .0066 | 0 |
| zohocorp | 1 | 1 | 0 | 1 | 0 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | +1 ▲ |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| ibm | 0 | 0 | 0 | 0 | 0 | 0 | 7 | 0 | — | — | — | 0 |
| sap | 0 | 0 | 0 | 0 | 0 | 0 | 12 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| siemens | 1 | 1 | 0 | 1 | 0 | 0 | 1 | 0 | 0.0 | 8.7 | .0032 | +1 ▲ |
| d-link | 0 | 1 | 0 | 0 | 0 | 0 | 26 | 1 | 100.0 | — | .8964 | 0 |
| hikvision | 0 | 1 | 0 | 0 | 0 | 0 | 2 | 1 | 100.0 | — | 1.0000 | 0 |
| dahua | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| qnap | 0 | 0 | 0 | 0 | 0 | 0 | 8 | 0 | — | — | — | 0 |
| schneider electric | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| tp-link | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| concrete cms | 44 | 44 | 1 | 9 | 13 | 21 | 0 | 0 | 0.0 | 5.7 | .0015 | +44 ▲ |
| open ises | 37 | 37 | 2 | 14 | 21 | 0 | 0 | 0 | 0.0 | 6.9 | .0021 | +37 ▲ |
| netatalk | 33 | 33 | 1 | 13 | 9 | 10 | 0 | 0 | 0.0 | 6.4 | .0030 | +33 ▲ |
| grafana | 10 | 27 | 2 | 7 | 16 | 2 | 0 | 0 | 0.0 | 6.5 | .0033 | +7 ▲ |
| dell | 12 | 18 | 0 | 6 | 11 | 0 | 2 | 1 | 5.6 | 6.7 | .0019 | +7 ▲ |
| nvidia | 16 | 16 | 7 | 9 | 0 | 0 | 0 | 0 | 0.0 | 8.4 | .0059 | +16 ▲ |
| trend micro | 16 | 16 | 2 | 13 | 1 | 0 | 12 | 1 | 6.3 | 7.8 | .0030 | +16 ▲ |
| givanz | 11 | 15 | 2 | 7 | 6 | 0 | 0 | 0 | 0.0 | 8.3 | .0028 | +7 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-31431 | .9991 | 100.0 | 7.8 |
| CVE-2008-4250 | .9875 | 99.9 | — |
| CVE-2026-41940 | .9793 | 99.9 | 9.3 |
| CVE-2026-39987 | .9658 | 99.9 | — |
| CVE-2026-43284 | .9324 | 99.8 | 8.8 |
| CVE-2026-43500 | .9285 | 99.8 | 7.8 |
| CVE-2024-7399 | .9194 | 99.8 | — |
| CVE-2010-0249 | .9188 | 99.8 | — |
| CVE-2026-20182 | .9152 | 99.8 | — |
| CVE-2025-29635 | .8964 | 99.8 | — |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-43997 | 10.0 | .0098 | |
| CVE-2026-33819 | 10.0 | .0084 | |
| CVE-2026-42826 | 10.0 | .0084 | |
| CVE-2026-20223 | 10.0 | .0083 | |
| CVE-2026-44005 | 10.0 | .0083 | |
| CVE-2026-44006 | 10.0 | .0081 | |
| CVE-2026-35431 | 10.0 | .0051 | |
| CVE-2026-46595 | 10.0 | .0050 | |
| CVE-2026-42822 | 10.0 | .0049 | |
| CVE-2026-33712 | 10.0 | .0035 |
| Vendor | CVEs |
|---|---|
| linux | 295 |
| microsoft | 173 |
| concrete cms | 44 |
| open ises | 37 |
| netatalk | 33 |
| 16 | |
| nvidia | 16 |
| trend micro | 16 |
| apache | 15 |
| apple | 13 |
| Vendor | KEV |
|---|---|
| microsoft | 27 |
| cisco | 8 |
| apple | 7 |
| 4 | |
| ivanti | 4 |
| synacor | 4 |
| adobe | 3 |
| fortinet | 3 |
| smartertools | 3 |
| solarwinds | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 4 |
| PyPI | 1 |
| npm | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4250 | Microsoft | 0 |
| CVE-2009-1537 | Microsoft | 0 |
| CVE-2009-3459 | Adobe | 0 |
| CVE-2010-0249 | Microsoft | 0 |
| CVE-2010-0806 | Microsoft | 0 |
| CVE-2024-1708 | ConnectWise | 0 |
| CVE-2024-57726 | n/a | 0 |
| CVE-2024-57728 | n/a | 0 |
| CVE-2024-7399 | Samsung | 0 |
| CVE-2025-29635 | D-Link | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1647 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1647 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1647 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1647 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1647 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1647 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1647 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1647 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1647 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1647 |
EXPLOIT PUBLISHED — CVE-2026-32253 (LizardByte Sunshine). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-40610 (BentoML). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-41069 (strukturag libheif). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-41071 (strukturag libheif). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-5072 (zephyrproject-rtos Zephyr). Public exploit reference added.
How to read these box scores · glossary
148 CVEs published. 25 box scores, 123 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .8832 99.8 YES
AFFECTED Product Versions Fixed Drupal core 8.9.0 – —
TIMELINE May 20 Reserved by CNA May 22 Added to CISA KEV, due May 27 May 22 Published (CNA: drupal)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P N N H H H 9.2 .0996 95.2 —
AFFECTED Product Versions Fixed NGINX Plus 37.0 – — NGINX Open Source 1.31.0 – —
TIMELINE May 21 Reserved by CNA May 22 Published (CNA: f5)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0157 73.3 —
AFFECTED Product Versions Fixed AudioIgniter Music Player unspecified —
TIMELINE May 15 Reserved by CNA May 22 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0125 67.0 —
AFFECTED Product Versions Fixed UniFi OS Server unspecified —
TIMELINE Mar 17 Reserved by CNA May 22 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0092 57.5 —
AFFECTED Product Versions Fixed Microsoft Planetary Computer Pro (GeoCatalog) - – —
TIMELINE Apr 16 Reserved by CNA May 22 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L L N 6.5 .0087 55.9 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA May 22 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.2 .0085 55.3 —
AFFECTED Product Versions Fixed shell-quote 1.1.0 – —
TIMELINE May 22 Reserved by CNA May 22 Published (CNA: harborist)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0072 50.9 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 22 Reserved by CNA May 22 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N C L L N 5.4 .0069 50.2 —
AFFECTED Product Versions Fixed FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution unspecified —
TIMELINE May 4 Reserved by CNA May 22 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0069 50.1 —
AFFECTED Product Versions Fixed Apache CXF 4.2.0 – —
TIMELINE May 8 Reserved by CNA May 22 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H N N 7.7 .0068 49.6 —
AFFECTED Product Versions Fixed UniFi OS Server unspecified — UDM unspecified — UDM-Pro unspecified — UDM-SE unspecified — UDM-Pro-Max unspecified — UDM-Beast unspecified — EFG unspecified — UDW unspecified — UDR unspecified — UDR7 unspecified — + 21 more
TIMELINE Mar 31 Reserved by CNA May 22 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H N 9.6 .0066 48.6 —
AFFECTED Product Versions Fixed net/http unspecified — net/http/internal/http2 unspecified — golang.org/x/net/idna unspecified —
TIMELINE Apr 7 Reserved by CNA May 22 Published (CNA: Go)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U H H H 7.5 .0064 47.9 —
AFFECTED Product Versions Fixed Apache CXF 4.2.0 – —
TIMELINE May 6 Reserved by CNA May 22 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N H 9.1 .0062 47.1 —
AFFECTED Product Versions Fixed golang.org/x/crypto/ssh unspecified —
TIMELINE Apr 7 Reserved by CNA May 22 Published (CNA: Go)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0060 46.1 —
AFFECTED Product Versions Fixed golang.org/x/crypto/ssh/agent unspecified —
TIMELINE Apr 7 Reserved by CNA May 22 Published (CNA: Go)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H N N 7.7 .0058 45.1 —
AFFECTED Product Versions Fixed Azure Stack HCI - – —
TIMELINE Feb 11 Reserved by CNA May 22 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0058 45.0 —
AFFECTED Product Versions Fixed Microsoft Power Pages - – —
TIMELINE Jan 14 Reserved by CNA May 22 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0057 44.6 —
AFFECTED Product Versions Fixed golang.org/x/crypto/ssh/knownhosts unspecified —
TIMELINE Apr 28 Reserved by CNA May 22 Published (CNA: Go)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0056 44.4 —
AFFECTED Product Versions Fixed Secure Access Client unspecified 22.8R6
TIMELINE May 19 Reserved by CNA May 22 Published (CNA: ivanti)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0055 43.7 —
AFFECTED Product Versions Fixed Microsoft Global Secure Access (GSA) - – —
TIMELINE Jan 14 Reserved by CNA May 22 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0054 43.2 —
AFFECTED Product Versions Fixed Easy Elements for Elementor – Addons & Website Templates unspecified —
TIMELINE May 19 Reserved by CNA May 22 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N H H 8.1 .0053 42.8 —
AFFECTED Product Versions Fixed authentik < 2025.12.5 – —
TIMELINE Apr 9 Reserved by CNA May 22 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0053 42.8 —
AFFECTED Product Versions Fixed Azure Orbital Spatio - – —
TIMELINE Apr 13 Reserved by CNA May 22 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H H 9.1 .0053 42.3 —
AFFECTED Product Versions Fixed golang.org/x/crypto/ssh unspecified —
TIMELINE Apr 7 Reserved by CNA May 22 Published (CNA: Go)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0053 42.3 —
AFFECTED Product Versions Fixed Azure Virtual Network Gateway - – —
TIMELINE Apr 13 Reserved by CNA May 22 Published (CNA: microsoft)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-39835 | 5.3 | 41.0 | golang.org/x/crypto | golang.org/x/crypto/ssh | CWE-476 | Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto… |
| CVE-2026-46595 | 10.0 | 41.0 | golang.org/x/crypto | golang.org/x/crypto/ssh | CWE-863 | Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org… |
| CVE-2026-42827 | 7.5 | 40.9 | Microsoft | Microsoft 365 Copilot | CWE-77 | M365 Copilot Information Disclosure Vulnerability |
| CVE-2026-40597 | 7.6 | 40.7 | mantisbt | mantisbt | CWE-79 | MantisBT has a Content Security Policy bypass via attachments |
| CVE-2026-47280 | 9.8 | 40.4 | Microsoft | Azure Resource Manager | CWE-287 | Azure Resource Manager Elevation of Privilege Vulnerability |
| CVE-2026-46727 | 8.1 | 39.4 | ruby-lang | Ruby | CWE-362 | An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a… |
| CVE-2026-33843 | 9.8 | 39.1 | Microsoft | Microsoft Entra | CWE-288 | Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability |
| CVE-2026-46597 | 7.5 | 39.1 | golang.org/x/crypto | golang.org/x/crypto/ssh | CWE-704 | Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh |
| CVE-2026-39829 | 7.5 | 38.7 | golang.org/x/crypto | golang.org/x/crypto/ssh | CWE-1284 | Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto… |
| CVE-2026-9011 | 7.5 | 38.5 | metaphorcreations | Ditty – Responsive News Tickers, Sliders, and Lists | CWE-862 | Ditty <= 3.1.65 - Missing Authorization to Unauthenticated Sensitive Informat… |
| CVE-2026-40166 | 7.1 | 38.3 | goauthentik | authentik | CWE-200 | authentik: Non-admin user can retrieve confidential OAuth client_secret via /… |
| CVE-2026-40598 | 6.9 | 37.4 | mantisbt | mantisbt | CWE-79 | MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Up… |
| CVE-2026-35430 | 8.8 | 35.7 | Microsoft | Azure Privileged Identity Management (PIM) | CWE-639 | Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability |
| CVE-2026-36228 | 7.3 | 35.6 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacke… |
| CVE-2026-40596 | 7.2 | 35.6 | mantisbt | mantisbt | CWE-79 | MantisBT is vulnerable to XSS and potential account takeover via user font fa… |
| CVE-2026-41090 | 9.3 | 35.2 | Microsoft | Microsoft 365 Copilot for iOS | CWE-77 | Microsoft Copilot Tampering Vulnerability |
| CVE-2026-39831 | 9.1 | 35.2 | golang.org/x/crypto | golang.org/x/crypto/ssh | CWE-862 | Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/… |
| CVE-2026-40607 | 7.5 | 35.1 | mantisbt | mantisbt | CWE-79 | MantisBT is Vulnerable to Stored XSS Through its Saved-Filter Owner Column |
| CVE-2026-39833 | 9.1 | 34.5 | golang.org/x/crypto | golang.org/x/crypto/ssh/agent | CWE-862 | Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent |
| CVE-2026-46598 | 5.3 | 34.6 | golang.org/x/crypto | golang.org/x/crypto/ssh/agent | CWE-129 | Invoking pathological inputs can lead to client panic in golang.org/x/crypto/… |
| CVE-2026-41149 | 5.3 | 33.4 | mermaid-js | mermaid | CWE-94 | Mermaid: Improper sanitization of `classDef` in state diagrams leads to HTML … |
| CVE-2026-3294 | 8.7 | 33.1 | TP-Link Systems Inc. | Archer RE650 v1 | CWE-862 | Authentication Logic Vulnerability on Multiple TP-Link Range Extenders |
| CVE-2026-41076 | 8.1 | 32.5 | bestpractical | rt | CWE-287 | RT: LDAP authentication bypass via empty password |
| CVE-2026-9291 | 7.5 | 31.3 | AWS | Amazon Braket Python SDK | CWE-502 | Insecure Deserialization in Amazon Braket SDK Job Results Processing |
| CVE-2026-39828 | 6.3 | 30.1 | golang.org/x/crypto | golang.org/x/crypto/ssh | CWE-281 | Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh |
| CVE-2026-41147 | 8.7 | 28.1 | nukeviet | nukeviet | CWE-79 | NukeViet CMS: Stored Cross-Site Scripting (XSS) via insufficient server-side … |
| CVE-2026-33712 | 10.0 | 27.8 | baptisteArno | typebot.io | CWE-862 | TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint … |
| CVE-2022-31231 | 7.5 | 27.7 | Dell | ECS | CWE-284 | Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Ide… |
| CVE-2026-41075 | 8.8 | 27.6 | bestpractical | rt | CWE-89 | RT: SQL injection via entry_aggregator parameter in JSON search |
| CVE-2026-5740 | 7.5 | 27.1 | Mattermost | Mattermost | CWE-789 | Unauthenticated WebSocket binary frame causes denial of service in Mattermost… |
| CVE-2026-41148 | 5.3 | 26.8 | mermaid-js | mermaid | CWE-94 | Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injection |
| CVE-2026-25680 | 6.5 | 25.6 | golang.org/x/net | golang.org/x/net/html | CWE-400 | Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html |
| CVE-2026-37470 | 7.3 | 25.3 | n/a | n/a | CWE-1021 | An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary cod… |
| CVE-2026-9047 | 7.6 | 24.7 | Devolutions | Server | CWE-305 | Improper handling of factor key state in the multi-factor authentication mana… |
| CVE-2026-28444 | 6.5 | 24.5 | baptisteArno | typebot.io | CWE-639 | Typebot: IDOR in Result Logs Endpoint Allows Cross-Workspace Data Disclosure |
| CVE-2026-44618 | 5.3 | 23.0 | Apache Software Foundation | Apache CXF | CWE-611 | Apache CXF: XXE vulnerability in WS-Transfer functionality |
| CVE-2026-41071 | 5.1 | 22.8 | strukturag | libheif | CWE-125 | libheif: Heap buffer over-read in SampleAuxInfoReader via crafted HEIF sequen… |
| CVE-2026-42901 | 10.0 | 22.7 | Microsoft | Microsoft Entra | CWE-346 | Microsoft Entra ID Elevation of Privilege Vulnerability |
| CVE-2026-5072 | 6.5 | 22.7 | zephyrproject-rtos | Zephyr | CWE-1335 | ptp: Potential Denial of Service via PTP Interval Shift |
| CVE-2026-32253 | 9.8 | 21.7 | LizardByte | Sunshine | CWE-287 | Sunshine: Authentication bypass via improper client certificate validation |
| CVE-2026-9054 | 9.2 | 21.7 | 9front | 9front | CWE-130 | Invalid IP packets cause a kernel panic |
| CVE-2026-40610 | 5.5 | 21.0 | bentoml | BentoML | CWE-59 | BentoML has Information Disclosure in `bentoml build` via symlink traversal i… |
| CVE-2026-39827 | 6.5 | 20.5 | golang.org/x/crypto | golang.org/x/crypto/ssh | CWE-924 | Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/… |
| CVE-2026-8684 | 5.3 | 20.4 | jetmonsters | MotoPress Hotel Booking | CWE-862 | MotoPress Hotel Booking <= 6.0.1 - Missing Authorization to Unauthenticated A… |
| CVE-2026-39970 | 8.5 | 20.1 | baptisteArno | typebot.io | CWE-79 | TypeBot: Stored Cross-Site Scripting (XSS) via SVG File Upload On Profile Pic… |
| CVE-2026-9053 | 6.9 | 20.1 | 9front | 9front | CWE-434 | Mothra would respect a default value given by a website for HTML file upload … |
| CVE-2026-4834 | 7.5 | 19.7 | weDevs | WP ERP Pro | CWE-89 | WP ERP Pro <= 1.5.1 - Unauthenticated SQL Injection via 'search_key' Parameter |
| CVE-2026-39968 | 7.1 | 19.4 | baptisteArno | typebot.io | CWE-284 | TypeBot: Cross-Workspace Credential Theft via Bot-Engine Preview Endpoint |
| CVE-2026-6864 | 6.1 | 18.4 | manchumahara | CBX 5 Star Rating & Review | CWE-79 | CBX 5 Star Rating & Review <= 1.0.7 - Reflected Cross-Site Scripting via 'pag… |
| CVE-2026-28445 | 8.7 | 17.5 | baptisteArno | typebot.io | CWE-79 | Typebot: Stored XSS via Rating Block Custom Icon Bypasses isUnsafe Sandbox in… |
| CVE-2026-39966 | 6.5 | 17.4 | baptisteArno | typebot.io | CWE-863 | TypeBot: Async filter() bypasses authorization, allowing IDOR in getLinkedTyp… |
| CVE-2026-36226 | 6.1 | 17.4 | n/a | n/a | CWE-79 | Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.1… |
| CVE-2026-5308 | 7.5 | 17.2 | Mattermost | Mattermost | CWE-400 | Missing request body size limits on Zoom plugin HTTP endpoints |
| CVE-2026-41069 | 6.5 | 17.0 | strukturag | libheif | CWE-125 | libheif allows Out-of-bounds vector access leading to invalid dereference (DoS) |
| CVE-2026-4646 | 4.3 | 16.7 | Mattermost | Mattermost | CWE-1287 | Insufficient input validation in GitHub plugin API causes denial of service |
| CVE-2026-7509 | 6.4 | 16.6 | helgatheviking | KIA Subtitle | CWE-79 | KIA Subtitle <= 4.0.1 - [Improper Neutralization of Input During Web Page Gen… |
| CVE-2026-3481 | 6.1 | 16.5 | burlingtonbytes | WP Blockade – Visual Page Builder | CWE-79 | WP Blockade <= 0.9.14 - Reflected Cross-Site Scripting via 'shortcode' Parameter |
| CVE-2026-8477 | 2.7 | 16.5 | Devolutions | Server | CWE-841 | Improper enforcement of the sealed-entry workflow in the entry sensitive-data… |
| CVE-2026-7249 | 4.3 | 16.4 | shapedplugin | Location Weather – WordPress Weather Forecast, AQI, Temperature and Weather Widget | CWE-862 | Location Weather <= 3.0.2 - Missing Authorization to Authenticated (Contribut… |
| CVE-2022-34363 | 7.5 | 16.3 | Dell | Unisphere for PowerMax | CWE-285 | Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an autho… |
| CVE-2026-7325 | 7.1 | 16.3 | Devolutions | Server | CWE-918 | Improper authorization in the Active Directory browsing feature in Devolution… |
| CVE-2026-5755 | 6.5 | 16.1 | Mattermost | Mattermost | CWE-400 | Denial of service via crafted TIFF file upload |
| CVE-2026-40295 | 6.1 | 15.5 | heartcombo | devise | CWE-601 | Devise: Open Redirect via Unvalidated `request.referrer` in Timeoutable Sessi… |
| CVE-2026-39964 | 5.4 | 15.5 | baptisteArno | typebot.io | CWE-79 | TypeBot: Stored XSS via javascript: URI in text bubble links — bot author exe… |
| CVE-2026-39965 | 7.7 | 15.2 | baptisteArno | typebot.io | CWE-918 | TypeBot: SSRF via Open Redirect Bypass in HTTP Request and Code Blocks |
| CVE-2026-34207 | 7.6 | 15.2 | baptisteArno | typebot.io | CWE-20 | TypeBot: SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP … |
| CVE-2026-7636 | 4.3 | 14.9 | smub | Slider by Soliloquy – Responsive Image Slider for WordPress | CWE-200 | Slider by Soliloquy <= 2.8.1 - Authenticated (Subscriber+) Information Disclo… |
| CVE-2026-42506 | 6.1 | 14.8 | golang.org/x/net | golang.org/x/net/html | CWE-79 | Invoking incorrect handling of namespaced elements in foreign content in gola… |
| CVE-2026-5171 | 4.3 | 14.6 | Devolutions | Server | CWE-284 | Improper access control in the entry activity log feature in Devolutions Serv… |
| CVE-2026-9264 | 9.3 | 14.3 | Trimble | SketchUp | CWE-94 | Cross-Site Scripting in SketchUp Dynamic Components |
| CVE-2026-9245 | 5.0 | 14.1 | Devolutions | Server | CWE-601 | Improper input validation in the external authentication provider flow in Dev… |
| CVE-2026-2518 | 4.3 | 14.1 | wpxpo | FastX | CWE-862 | FastX <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Limited… |
| CVE-2026-25606 | 8.7 | 13.4 | Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy | STER | CWE-89 | SQL Injection in STER |
| CVE-2026-8692 | 4.3 | 13.5 | registrationformbuilder | Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder | CWE-862 | Vedrixa Forms <= 1.1.1 - Missing Authorization to Authenticated (Subscriber+)… |
| CVE-2026-5817 | 8.8 | 13.4 | Docker | Docker Desktop | CWE-829 | Docker Model Runner container-to-host code execution via unsandboxed trust_re… |
| CVE-2026-5843 | 8.8 | 13.4 | Docker | Docker Desktop | CWE-829 | Docker Model Runner container-to-host code execution via MLX-LM model_file im… |
| CVE-2026-25681 | 6.1 | 13.2 | golang.org/x/net | golang.org/x/net/html | CWE-1021 | Invoking incorrect handling of character references in DOCTYPE nodes in golan… |
| CVE-2026-27136 | 6.1 | 13.2 | golang.org/x/net | golang.org/x/net/html | CWE-1021 | Invoking duplicate attributes can cause XSS in golang.org/x/net/html |
| CVE-2026-42502 | 6.1 | 13.2 | golang.org/x/net | golang.org/x/net/html | CWE-1021 | Invoking incorrect handling of HTML elements in foreign content in golang.org… |
| CVE-2026-9104 | 6.4 | 12.8 | dartiss | Draft List | CWE-79 | Draft List <= 2.6.3 - Authenticated (Author+) Stored Cross-Site Scripting via… |
| CVE-2026-9247 | 2.4 | 12.7 | Devolutions | Server | CWE-778 | Insufficient logging in the entry export feature in Devolutions Server allows… |
| CVE-2026-8670 | 9.6 | 12.3 | syslink software AG | Avantra | CWE-613 | Insecure session handling on metrics web server |
| CVE-2026-8671 | 7.5 | 12.3 | syslink software AG | Avantra | CWE-532 | Log Files contain encrypted secrets |
| CVE-2026-44409 | 7.5 | 12.3 | ZTE | MU5250 | CWE-862 | Information disclosure vulnerability in ZTE MU5250 |
| CVE-2026-9223 | 4.3 | 11.9 | Devolutions | Server | CWE-284 | Missing authorization in the vault import feature in Devolutions Server 2026.… |
| CVE-2026-9224 | 4.3 | 11.9 | Devolutions | Server | CWE-862 | Missing authorization in the user profile update feature in Devolutions Serve… |
| CVE-2026-9246 | 4.3 | 11.9 | Devolutions | Server | CWE-862 | Improper access control in the entry documentation and attachment features in… |
| CVE-2026-6406 | 8.8 | 11.6 | Docker | Docker Desktop | CWE-863 | Docker Desktop Enhanced Container Isolation bypass via --use-api-socket CLI flag |
| CVE-2026-25608 | 2.3 | 11.3 | Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy | STER | CWE-319 | Lack of traffic encryption in STER |
| CVE-2026-9251 | 5.4 | 9.4 | Devolutions | Server | CWE-862 | Missing authorization in the entry status management feature in Devolutions S… |
| CVE-2026-8673 | 9.1 | 9.2 | syslink software AG | Avantra | CWE-523 | Password re-initialization mechanism sends passwords in plain text |
| CVE-2026-9249 | 3.1 | 8.6 | Devolutions | Server | CWE-620 | Unverified password change in Devolutions Server allows an attacker to change… |
| CVE-2026-39967 | 3.1 | 8.5 | baptisteArno | typebot.io | CWE-639 | TypeBot: Cross-Typebot Result Data Access via Missing typebotId Filter |
| CVE-2026-9248 | 2.6 | 8.5 | Devolutions | Server | CWE-639 | Authorization bypass in the entry duplication feature in Devolutions Server a… |
| CVE-2026-3636 | 4.3 | 8.3 | Mattermost | Mattermost | CWE-200 | Sanitize team member data returned by API |
| CVE-2026-8347 | 2.3 | 7.3 | Concrete CMS | Concrete CMS | CWE-639 | Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-leve… |
| CVE-2025-26483 | 8.2 | 7.0 | Dell | PowerFlex Manager (Appliance) | CWE-601 | Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect V… |
| CVE-2026-4635 | 5.3 | 7.0 | Mattermost | Mattermost | CWE-362 | Persistent notification timing attack causing server denial of service |
| CVE-2026-7615 | 4.3 | 6.6 | kasparsd | Widget Context | CWE-352 | Widget Context <= 1.3.3 - Cross-Site Request Forgery to Settings Update via '… |
| CVE-2026-41073 | 4.6 | 6.3 | bestpractical | rt | CWE-1236 | RT: Spreadsheet downloads vulnerable to CSV/formula injection in Microsoft Ex… |
| CVE-2026-4070 | 4.3 | 6.1 | pftool | Alfie – Feed Plugin | CWE-352 | Alfie <= 1.2.1 - Cross-Site Request Forgery to Feed Deletion via 'delete' Par… |
| CVE-2026-42626 | 5.9 | 5.7 | n/a | n/a | CWE-400 | HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage co… |
| CVE-2026-40864 | 4.3 | 5.6 | jupyterhub | jupyterhub | CWE-352 | JupyterHub: Cross-origin form POSTs bypass XSRF |
| CVE-2026-3473 | 7.1 | 4.7 | Mattermost | Mattermost | CWE-639 | Improper file ownership validation in the Boards API allows unauthorised file… |
| CVE-2026-8353 | 2.1 | 4.7 | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name i… |
| CVE-2026-8381 | 5.4 | 3.9 | TeamViewer | DEX (On-premises) | CWE-862 | Broken Access Control in TeamViewer DEX Platform (On Premises) |
| CVE-2026-39969 | 6.5 | 3.9 | baptisteArno | typebot.io | CWE-287 | TypeBot: WhatsApp Webhook Endpoint Missing Signature Verification |
| CVE-2026-8997 | 4.8 | 3.9 | vifm | vifm | CWE-122 | Heap Buffer Overflow in vifm |
| CVE-2026-28735 | 5.4 | 3.7 | Mattermost | Mattermost | CWE-863 | GitHub OAuth Scope Validation |
| CVE-2026-42627 | 6.2 | 3.2 | n/a | n/a | CWE-190 | In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumEl… |
| CVE-2025-32749 | 7.5 | 2.8 | Dell | PowerFlex Manager (Appliance) | CWE-276 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Informa… |
| CVE-2026-9255 | 8.4 | 2.1 | AWS | Kiro CLI | CWE-862 | Tool Execution Without Authorization via Piped Stdin in Kiro CLI |
| CVE-2026-41074 | 7.1 | 1.9 | bestpractical | rt | CWE-352 | RT has broken CSRF protection for authenticated users |
| CVE-2021-21508 | 6.7 | 1.9 | Dell | VxRail | CWE-532 | Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vul… |
| CVE-2026-39824 | 3.3 | 1.7 | golang.org/x/sys | golang.org/x/sys/windows | CWE-190 | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows |
| CVE-2026-8672 | 5.1 | 1.2 | syslink software AG | Avantra | CWE-1393 | Default credentials for internal DB |
| CVE-2025-32746 | 5.5 | 1.1 | Dell | PowerFlex Manager (Appliance) | CWE-922 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of… |
| CVE-2026-8340 | 2.3 | 1.1 | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveV… |
| CVE-2025-32751 | 5.5 | 1.1 | Dell | PowerFlex Manager (Appliance) | CWE-922 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of… |
| CVE-2026-25607 | 5.7 | 0.8 | Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy | STER | CWE-261 | Weak password encoding in STER |
| CVE-2025-32747 | 7.8 | 0.5 | Dell | PowerFlex Manager (Appliance) | CWE-266 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege… |
| CVE-2025-32745 | 6.5 | 0.3 | Dell | PowerFlex Manager (Appliance) | CWE-295 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Improper Certificat… |
| CVE-2025-46371 | 5.5 | 0.0 | Dell | PowerFlex Manager (Appliance) | CWE-327 | Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) a Use of a Broken or R… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-05-22 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion.