boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Sunday, May 24, 2026 · all times UTC← 2026-05-23 · archive · 2026-05-25 →

Security Box Score — May 24, 2026

64 CVEs published, led by Edimax (20).

64 CVEs published May 24, 2026: 0 critical, 26 high, 16 medium, 22 low; 0 in the KEV catalog at press time; 1 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 39 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published11812393——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

45 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux227553674483801120.47.8.0014+74 ▲
microsoft160530463711112286193.67.8.0047-23 ▼
red hat1062526247200.06.8.0041-9 ▼
apple154511528188715.66.2.0028+15 ▲
google16230176077417.48.8.0034+15 ▲
freebsd770520000.07.8.0020+7 ▲
suse220200000.08.2.0020+2 ▲
ubuntu010001100.02.7.02180
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco512534056866.77.8.1576+5 ▲
fortinet17430028342.99.1.8584-2 ▼
ivanti25230025480.08.8.8056+2 ▲
ubiquiti231200300.08.8.0068+2 ▲
f52220004150.09.2.3901+2 ▲
palo alto networks22110013150.08.6.6281+2 ▲
vmware01010071100.08.1.17420
check point00000010———0
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache922412603314.57.5.0080+6 ▲
mozilla553200900.09.6.0045+5 ▲
docker330300000.08.8.0022+3 ▲
drupal3310204133.35.1.0021+3 ▲
gitlab00000042———0
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
progress440400600.07.5.0036+4 ▲
oracle0312002700.07.5.00880
solarwinds032100103100.09.8.83620
adobe020200192100.08.6.0368-2 ▼
zohocorp110100000.08.4.0170+1 ▲
atlassian000000130———0
ibm00000060———0
sap00000060———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link110100300.08.7.0059+1 ▲
siemens110100000.08.7.0032+1 ▲
tp-link00000010———0
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
concrete cms4444191321000.05.7.0015+44 ▲
open ises3737214210000.06.9.0021+37 ▲
netatalk3333113910000.06.4.0030+33 ▲
grafana102727162200.06.5.0033+6 ▲
edimax2525013012100.07.4.0054+25 ▲
dell121816110215.66.7.0019+7 ▲
nvidia16167900000.08.4.0060+16 ▲
trend micro1616213101216.37.8.0030+16 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-31431.9991100.07.8
CVE-2026-41940.985399.99.3
CVE-2026-0257.939199.87.8
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2026-20182.915299.810.0
CVE-2026-42208.894299.89.3
CVE-2026-9082.883299.89.8
CVE-2024-1708.875699.78.4
CVE-2026-42271.835499.78.7
Highest CVSS
CVECVSSEPSSNote
CVE-2026-2018210.0.9152KEV
CVE-2026-4399710.0.0098
CVE-2026-4282610.0.0084
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
CVE-2026-4659510.0.0050
CVE-2026-4282210.0.0049
CVE-2026-3371210.0.0035
CVE-2026-915210.0.0034
Most disclosures (vendor)
VendorCVEs
linux239
microsoft161
concrete cms44
open ises37
netatalk33
edimax25
google16
nvidia16
trend micro16
apache15
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco8
apple7
google4
ivanti4
fortinet3
smartertools3
solarwinds3
adobe2
berriai2
Most-affected ecosystems
EcosystemAdvisories
Maven4
PyPI1
npm1
Fastest to KEV
CVEVendorDays
CVE-2024-1708ConnectWise0
CVE-2026-31431Linux0
CVE-2026-32202Microsoft0
CVE-2026-34926Trend Micro, Inc.0
CVE-2026-41091Microsoft0
CVE-2026-41940WebPros0
CVE-2026-42208BerriAI0
CVE-2026-42897Microsoft0
CVE-2026-45498Microsoft0
CVE-2026-9082Drupal0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171649
CVE-2021-27102n/a2021-11-171649
CVE-2021-27101n/a2021-11-171649
CVE-2021-27103n/a2021-11-171649
CVE-2021-21017Adobe2021-11-171649
CVE-2021-28550Adobe2021-11-171649
CVE-2021-42013Apache Software Foundation2021-11-171649
CVE-2021-41773Apache Software Foundation2021-11-171649
CVE-2021-30858Apple2021-11-171649
CVE-2021-30860Apple2021-11-171649

Transactions

EXPLOIT PUBLISHED — CVE-2026-4372 (huggingface/transformers). Public exploit reference added.

Yesterday's Results

How to read these box scores · glossary

64 CVEs published. 25 box scores, 39 table rows — nothing truncated.

Totolink A8000RU Web Management cstecgi.cgi setScheduleCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0209   80.2     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 23  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setDiagnosisCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0173   75.9     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 23  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setTracerouteCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0173   75.9     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 23  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setLanguageCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0173   75.9     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 23  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setUpgradeFW os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0173   75.9     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 23  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setDdnsCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0173   75.9     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setGameSpeedCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0173   75.9     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setRemoteCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0173   75.9     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setFirewallType os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0173   75.9     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
NousResearch hermes-agent terminal_tool approval.py detect_dangerous_command os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0166   74.8     —
AFFECTED
  Product       Versions                                    Fixed
  hermes-agent  5157f5427f19488b31c6fdebbacd15d798ce7f63 –  —
TIMELINE
  May 23  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
Edimax EW-7438RPn webs formWizSurvey os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0152   72.6     —
AFFECTED
  Product     Versions  Fixed
  EW-7438RPn  1.0 –     —
TIMELINE
  May 23  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Edimax EW-7438RPn POST Request formHwSet command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0140   70.3     —
AFFECTED
  Product     Versions  Fixed
  EW-7438RPn  1.28a –   —
TIMELINE
  May 23  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
Edimax BR-6675nD POST Request formHwSet command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0117   65.0     —
AFFECTED
  Product    Versions  Fixed
  BR-6675nD  1.12 –    —
TIMELINE
  May 23  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
Edimax EW-7438RPn POST Request formAccep formAccept command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0116   64.7     —
AFFECTED
  Product     Versions  Fixed
  EW-7438RPn  1.12 –    —
TIMELINE
  May 23  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
Edimax EW-7438RPn Setting formConnectionSetting command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0116   64.6     —
AFFECTED
  Product     Versions  Fixed
  EW-7438RPn  1.12 –    —
TIMELINE
  May 23  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
Edimax EW-7438RPn POST Request formEZCHNwlanSetu formEZCHNwlanSetup command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0116   64.6     —
AFFECTED
  Product     Versions  Fixed
  EW-7438RPn  1.12 –    —
TIMELINE
  May 23  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
Edimax BR-6675nD POST Request formWpsStart command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0116   64.6     —
AFFECTED
  Product    Versions  Fixed
  BR-6675nD  1.12 –    —
TIMELINE
  May 23  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Edimax BR-6675nD POST Request formUSBStorage command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0116   64.6     —
AFFECTED
  Product    Versions  Fixed
  BR-6675nD  1.12 –    —
TIMELINE
  May 24  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
Edimax BR-6675nD POST Request formWlanMP command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0116   64.6     —
AFFECTED
  Product    Versions  Fixed
  BR-6675nD  1.12 –    —
TIMELINE
  May 24  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
NousResearch hermes-agent read_file Tool file_tools.py _is_blocked_device path traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   L   L    5.5   .0068   49.4     —
AFFECTED
  Product       Versions    Fixed
  hermes-agent  2026.4.0 –  —
TIMELINE
  May 23  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-22 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
Edimax EW-7438RPn webs formWizSurvey buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0054   43.1     —
AFFECTED
  Product     Versions  Fixed
  EW-7438RPn  1.0 –     —
TIMELINE
  May 23  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Edimax BR-6675nD POST Request formPPTPSetup buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0054   43.1     —
AFFECTED
  Product    Versions  Fixed
  BR-6675nD  1.12 –    —
TIMELINE
  May 23  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
huggingface huggingface/transformers — Arbitrary Remote Code Execution via `_attn_implementation_internal` Config Injection in huggingface/transformers
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   R  U  H  H  H    7.8   .0048   39.2     —
AFFECTED
  Product                   Versions       Fixed
  huggingface/transformers  unspecified –  —
TIMELINE
  Mar 18  Reserved by CNA
  May 24  Public exploit reference published
  May 24  Published (CNA: @huntr_ai)
CWE-502, CWE-1066 · CNA: @huntr_ai · CVSS v3.0 · 2 references · NVD status: Analyzed
GNU GNU SASL — In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0046   37.6     —
AFFECTED
  Product   Versions     Fixed
  GNU SASL  unspecified  —
TIMELINE
  May 24  Reserved by CNA
  May 24  Published (CNA: mitre)
CWE-476 · CNA: mitre · CVSS v3.1 · 5 references · NVD status: Deferred
Besen BS20 EV Charging Station OTA Update Installation improper authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   H   H   H    8.2   .0045   37.5     —
AFFECTED
  Product                   Versions    Fixed
  BS20 EV Charging Station  20260426 –  —
TIMELINE
  May 24  Reserved by CNA
  May 24  Published (CNA: VulDB)
CWE-266, CWE-285 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-93447.436.9EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn webs formWpsStart stack-based overflow
CVE-2026-93467.436.9EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn webs formWirelessTbl buffer overflow
CVE-2026-93487.436.9EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn webs mp stack-based overflow
CVE-2026-93607.436.9EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn POST Request formwlencrypt24g buffer overflow
CVE-2026-93807.436.9EdimaxBR-6675nDCWE-119Edimax BR-6675nD POST Request formL2TPSetup buffer overflow
CVE-2026-93817.436.9EdimaxBR-6675nDCWE-119Edimax BR-6675nD POST Request formPPPoESetup buffer overflow
CVE-2026-93937.436.9H3CMagic B0CWE-119H3C Magic B0 aspForm Edit_BasicSSID_5G buffer overflow
CVE-2026-93997.436.9EdimaxBR-6675nDCWE-119Edimax BR-6675nD POST Request formsetPPPoE buffer overflow
CVE-2026-94017.436.9EdimaxBR-6675nDCWE-119Edimax BR-6675nD POST Request formWanTcpipSetup buffer overflow
CVE-2026-94037.436.9EdimaxBR-6675nDCWE-119Edimax BR-6675nD POST Request formWlSiteSurvey buffer overflow
CVE-2026-93897.436.3TendaF456CWE-119Tenda F456 L7Im frmL7ImForm buffer overflow
CVE-2026-93712.936.2ItzCrazyKnsVaneCWE-287ItzCrazyKns Vane API route.ts missing authentication
CVE-2026-93495.533.8calcomcal.diyCWE-200calcom cal.diy Generic React API bookings-single-view.getServerSideProps.tsx …
CVE-2026-93685.530.8NousResearchhermes-agentCWE-264NousResearch hermes-agent Environment Variable code_execution_tool.py execute…
CVE-2026-93736.328.4n/aJeecgBootCWE-287JeecgBoot OpenAPI Endpoint call improper authentication
CVE-2026-93545.526.1NousResearchhermes-agentCWE-74NousResearch hermes-agent Slack Agent/Mattermost Agent escape output
CVE-2026-93582.124.8n/apostcss-selector-parserCWE-404postcss-selector-parser AST Serialization container.js toString recursion
CVE-2026-93652.924.1n/aEttercapCWE-119Ettercap GG Dissector ec_gg.c FUNC_DECODER heap-based overflow
CVE-2026-93535.522.5NousResearchhermes-agentCWE-74NousResearch hermes-agent Skills Guard Multi-Word Prompt skills_guard.py inje…
CVE-2026-93665.522.5NousResearchhermes-agentCWE-74NousResearch hermes-agent prompt_builder.py _scan_context_content injection
CVE-2026-35158.521.8prefecthqprefecthq/prefectCWE-88Argument Injection in prefecthq/prefect
CVE-2026-93981.321.4BesenBS20 EV Charging StationCWE-287Besen BS20 EV Charging Station BLE/WiFi authentication replay
CVE-2026-93525.520.5NousResearchhermes-agentCWE-200NousResearch hermes-agent Messaging Gateway local.py _make_run_env informatio…
CVE-2026-93572.019.8n/avBulletinCWE-79vBulletin Login cross site scripting
CVE-2026-93505.519.7NousResearchhermes-agentCWE-862NousResearch hermes-agent Batch Runner approval.py check_all_command_guards a…
CVE-2026-93725.519.7ItzCrazyKnsVaneCWE-918ItzCrazyKns Vane Model Provider API route.ts server-side request forgery
CVE-2026-93962.918.4BesenBS20 EV Charging StationCWE-1021Besen BS20 EV Charging Station Firmware Version Check ui layer
CVE-2026-93555.516.6SourceCodesterHospitals Patient Records Management SystemCWE-74SourceCodester Hospitals Patient Records Management System Master.php save_pa…
CVE-2026-93565.516.6SourceCodesterHospitals Patient Records Management SystemCWE-74SourceCodester Hospitals Patient Records Management System manage_history.php…
CVE-2026-93645.516.6projectworldsOnline Art Gallery ShopCWE-74projectworlds Online Art Gallery Shop adminHome.php sql injection
CVE-2026-93835.516.6itsourcecodeElectronic Judging SystemCWE-74itsourcecode Electronic Judging System login.php sql injection
CVE-2026-93762.116.4n/aJPressCWE-266JPress UCenter Article Submission Endpoint doWriteSave improper authorization
CVE-2026-93691.913.4NousResearchhermes-agentCWE-697NousResearch hermes-agent CLI web-dashboard web_server.py _discover_dashboard…
CVE-2026-93702.910.0ulisesbocchiojasypt-spring-bootCWE-759ulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.java getSecret…
CVE-2026-93771.910.0SourceCodesterSUP Online ShoppingCWE-79SourceCodester SUP Online Shopping productedit.php cross site scripting
CVE-2026-93745.39.2yangzongzhuanRuoYi-VueCWE-284yangzongzhuan RuoYi-Vue Common Upload Endpoint upload FileUploadUtils.upload …
CVE-2026-93941.38.9BesenBS20 EV Charging StationCWE-521Besen BS20 EV Charging Station Bluetooth Low Energy weak password
CVE-2026-488323.58.1SPIPSPIPCWE-601action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirec…
CVE-2026-93952.05.2BesenBS20 EV Charging StationCWE-522Besen BS20 EV Charging Station BLE/UDP insufficiently protected credentials

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-05-24 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.