boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Monday, May 25, 2026 · all times UTC← 2026-05-24 · archive · 2026-05-26 →

Security Box Score — May 25, 2026

187 CVEs published, led by Totolink (20).

187 CVEs published May 25, 2026: 5 critical, 72 high, 56 medium, 53 low; 0 in the KEV catalog at press time; 11 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 162 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published13682580——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

48 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux227553674483801120.47.8.0014+64 ▲
microsoft160530463711112286193.67.8.0047-23 ▼
red hat1062526247200.06.8.0041-9 ▼
apple154511528188715.66.2.0028+15 ▲
google16230176077417.48.8.0034+15 ▲
freebsd770520000.07.8.0020+7 ▲
suse220200000.08.2.0020+2 ▲
ubuntu010001100.02.7.02180
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco512534056866.77.8.1576+5 ▲
fortinet17430028342.99.1.8584-2 ▼
ivanti25230025480.08.8.8056+2 ▲
ubiquiti231200300.08.8.0068+2 ▲
f52220004150.09.2.3901+2 ▲
palo alto networks22110013150.08.6.6281+2 ▲
vmware01010071100.08.1.17420
check point00000010———0
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache18314141203313.27.3.0064+15 ▲
mozilla663210900.08.8.0042+6 ▲
docker330300000.08.8.0022+3 ▲
drupal3310204133.35.1.0021+3 ▲
gitlab00000042———0
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
progress440400600.07.5.0036+4 ▲
oracle0312002700.07.5.00880
solarwinds032100103100.09.8.83620
adobe020200192100.08.6.0368-2 ▼
zohocorp110100000.08.4.0170+1 ▲
atlassian000000130———0
ibm00000060———0
sap00000060———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link110100300.08.7.0059+1 ▲
siemens110100000.08.7.0032+1 ▲
tp-link00000010———0
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
concrete cms4444191321000.05.7.0015+44 ▲
edimax4444027017100.07.4.0059+44 ▲
open ises3737214210000.06.9.0021+37 ▲
netatalk3333113910000.06.4.0030+33 ▲
totolink292902405000.08.9.0173+29 ▲
grafana102727162200.06.5.0033+6 ▲
dell121816110215.66.7.0019+7 ▲
nvidia16167900000.08.4.0060+16 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-31431.9991100.07.8
CVE-2026-41940.985399.99.3
CVE-2026-0257.939199.87.8
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2026-20182.915299.810.0
CVE-2026-42208.894299.89.3
CVE-2026-9082.883299.89.8
CVE-2024-1708.875699.78.4
CVE-2026-42271.835499.78.7
Highest CVSS
CVECVSSEPSSNote
CVE-2026-2018210.0.9152KEV
CVE-2026-4399710.0.0098
CVE-2026-4282610.0.0084
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
CVE-2026-4659510.0.0050
CVE-2026-4282210.0.0049
CVE-2026-3371210.0.0035
CVE-2026-915210.0.0034
Most disclosures (vendor)
VendorCVEs
linux229
microsoft161
concrete cms44
edimax44
open ises37
netatalk33
totolink29
apache24
google16
nvidia16
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco8
apple7
google4
ivanti4
fortinet3
smartertools3
solarwinds3
adobe2
berriai2
Most-affected ecosystems
EcosystemAdvisories
Maven10
crates.io2
npm2
PyPI1
Fastest to KEV
CVEVendorDays
CVE-2024-1708ConnectWise0
CVE-2026-31431Linux0
CVE-2026-32202Microsoft0
CVE-2026-34926Trend Micro, Inc.0
CVE-2026-41091Microsoft0
CVE-2026-41940WebPros0
CVE-2026-42208BerriAI0
CVE-2026-42897Microsoft0
CVE-2026-45498Microsoft0
CVE-2026-9082Drupal0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171650
CVE-2021-27102n/a2021-11-171650
CVE-2021-27101n/a2021-11-171650
CVE-2021-27103n/a2021-11-171650
CVE-2021-21017Adobe2021-11-171650
CVE-2021-28550Adobe2021-11-171650
CVE-2021-42013Apache Software Foundation2021-11-171650
CVE-2021-41773Apache Software Foundation2021-11-171650
CVE-2021-30858Apple2021-11-171650
CVE-2021-30860Apple2021-11-171650

Transactions

EXPLOIT PUBLISHED — benoitc hackney: 10 CVEs (CVE-2026-47066, CVE-2026-47067, CVE-2026-47069, CVE-2026-47070, CVE-2026-47071, CVE-2026-47072, CVE-2026-47073, CVE-2026-47075, CVE-2026-47076, CVE-2026-47077). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-2651 (mlflow/mlflow). Public exploit reference added.

Yesterday's Results

How to read these box scores · glossary

187 CVEs published. 25 box scores, 162 table rows — nothing truncated.

Edimax BR-6478AC POST Request formAccept command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .1296   96.0     —
AFFECTED
  Product    Versions  Fixed
  BR-6478AC  1.23 –    —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
Edimax BR-6478AC POST Request formiNICbasic command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .1172   95.7     —
AFFECTED
  Product    Versions  Fixed
  BR-6478AC  1.23 –    —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
Totolink CA750-PoE Setting cstecgi.cgi setNetworkDiag os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .1081   95.5     —
AFFECTED
  Product    Versions    Fixed
  CA750-PoE  6.2c.510 –  —
TIMELINE
  May 25  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .1081   95.5     —
AFFECTED
  Product    Versions    Fixed
  CA750-PoE  6.2c.510 –  —
TIMELINE
  May 25  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi UploadFirmwareFile os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0209   80.2     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setWanCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0209   80.2     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Edimax BR-6675nD POST Request mp command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   L   L   L    2.0   .0208   80.0     —
AFFECTED
  Product    Versions  Fixed
  BR-6675nD  1.12 –    —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setL2tpServerCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0200   79.3     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setQosCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0191   78.2     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCertGenerationCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0191   78.2     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi UploadOpenVpnCert os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0191   78.2     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setOpenVpnCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0191   78.2     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setIpQosRules os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0191   78.2     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setPasswordCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0191   78.2     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setAccessDeviceCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0191   78.2     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setParentalRules os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0191   78.2     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setStaticDhcpRules os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0173   75.9     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setWiFiAdvancedCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0173   75.9     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setMacFilterRules os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0173   75.9     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink A8000RU Web Management cstecgi.cgi setWiFiWpsCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0173   75.9     —
AFFECTED
  Product  Versions               Fixed
  A8000RU  7.1cu.643_b20200521 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
FoundDream miniclawd exec.ts ExecTool.execute os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0138   70.1     —
AFFECTED
  Product    Versions                                    Fixed
  miniclawd  2d65665046e2222eeea76cafc8570ed546a8c125 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
FoundDream miniclawd SkillsLoader skills-loader.ts which command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0138   70.1     —
AFFECTED
  Product    Versions                                    Fixed
  miniclawd  2d65665046e2222eeea76cafc8570ed546a8c125 –  —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
DTStack Taier REST API Runtime.exec os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0136   69.7     —
AFFECTED
  Product  Versions  Fixed
  Taier    1.4.0 –   —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
Edimax EW-7438RPn Content-Type formWlanMP os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0116   64.6     —
AFFECTED
  Product     Versions  Fixed
  EW-7438RPn  1.31 –    —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
Edimax BR-6675nD stainfo command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0116   64.6     —
AFFECTED
  Product    Versions  Fixed
  BR-6675nD  1.12 –    —
TIMELINE
  May 24  Reserved by CNA
  May 25  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-95112.161.9TotolinkCA750-PoECWE-77Totolink CA750-PoE Setting cstecgi.cgi setWebWlanIdx os command injection
CVE-2026-95122.161.9TotolinkCA750-PoECWE-77Totolink CA750-PoE Setting cstecgi.cgi setPasswordCfg os command injection
CVE-2026-95132.161.9TotolinkCA750-PoECWE-77Totolink CA750-PoE Setting cstecgi.cgi NTPSyncWithHost os command injection
CVE-2026-470738.755.5benoitchackneyCWE-400Unbounded memory consumption in WebSocket client in hackney
CVE-2018-253658.753.3PCViewerPCViewerCWE-22PCViewer vt1000 Directory Traversal via GET Request
CVE-2018-253748.753.3SoftnetaMedDream PACS Server PremiumCWE-22Softneta MedDream PACS Server Premium 6.7.1.1 Directory Traversal
CVE-2026-488428.152.7RoundcubeWebmailCWE-89Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authenti…
CVE-2026-470668.752.3benoitchackneyCWE-835Infinite loop in Alt-Svc header parser in hackney
CVE-2026-470678.752.3benoitchackneyCWE-770Atom table exhaustion via unrecognized URL schemes in hackney
CVE-2026-470718.252.3benoitchackneyCWE-400SOCKS5 TLS upgrade ignores caller timeout in hackney
CVE-2026-94597.452.2EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn formConnectionSetting stack-based overflow
CVE-2026-94607.452.2EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn formAccept stack-based overflow
CVE-2026-94617.452.2EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn formRadius stack-based overflow
CVE-2026-452496.152.1Apache Software FoundationApache EChartsCWE-79Apache ECharts: XSS in Lines series tooltip rendering
CVE-2026-86528.551.2NEC Platforms, Ltd.Aterm MR51FNCWE-78An OS Command Injection vulnerability exists in Aterm. If a malicious third p…
CVE-2026-470778.250.5benoitchackneyCWE-400Unbounded body accumulation in HTTP/3 response loop in hackney
CVE-2026-427827.248.5Apache Software FoundationApache SyncopeCWE-653Apache Syncope: Post-auth RCE via Groovy static
CVE-2026-94807.448.2EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn formrefresh stack-based overflow
CVE-2026-453618.145.6Apache Software FoundationApache Airflow Google providerCWE-322Apache Airflow Google provider: SSH host key verification disabled in Compute…
CVE-2026-94427.445.5EdimaxBR-6478ACCWE-119Edimax BR-6478AC POST Request formiNICSiteSurvey buffer overflow
CVE-2026-94437.445.5EdimaxBR-6478ACCWE-119Edimax BR-6478AC POST Request formL2TPSetup buffer overflow
CVE-2026-94627.445.5EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn formWpsProxyEnable stack-based overflow
CVE-2026-94637.445.5EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn formLicence stack-based overflow
CVE-2026-94797.445.5EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn formLogout stack-based overflow
CVE-2026-94817.445.5EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn formStats stack-based overflow
CVE-2026-94827.445.5EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn formSDHCP stack-based overflow
CVE-2026-94287.445.0TendaF1202CWE-119Tenda F1202 PPTPUserSetting fromPPTPUserSetting stack-based overflow
CVE-2026-94297.445.0TendaF1202CWE-119Tenda F1202 WrlExtraSet formWrlExtraSet stack-based overflow
CVE-2026-467455.344.8Apache Software FoundationApache Airflow FAB providerCWE-90Apache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _searc…
CVE-2026-470726.943.1benoitchackneyCWE-93CRLF injection in WebSocket upgrade request in hackney
CVE-2026-470756.839.2benoitchackneyCWE-93CR/LF injection in query parameter in hackney
CVE-2026-52222.339.1RustCargoCWE-647Cargo can be coerced to share credentials between registries
CVE-2026-94257.436.9EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn formWlanMP stack-based overflow
CVE-2026-94267.436.9EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn formHwSet stack-based overflow
CVE-2026-94277.436.9EdimaxEW-7438RPnCWE-119Edimax EW-7438RPn webs formWlSiteSurvey stack-based overflow
CVE-2026-83769.836.7SHAYperlCWE-680Perl versions through 5.43.10 have a heap buffer overflow when compiling regu…
CVE-2026-94307.436.3TendaF1202CWE-119Tenda F1202 GstDhcpSetSerof formGstDhcpSetSer stack-based overflow
CVE-2026-94317.436.3TendaF1202CWE-119Tenda F1202 PptpUserAdd fromPptpUserAdd stack-based overflow
CVE-2026-94672.136.3debugmcpmcp-debuggerCWE-22debugmcp mcp-debugger server.ts handleGetSourceContext path traversal
CVE-2026-427974.936.2Apache Software FoundationApache SyncopeCWE-202Apache Syncope: JexlContextBuilder Information Disclosure
CVE-2026-488473.735.9RoundcubeWebmailCWE-669Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-auth…
CVE-2026-470692.135.2benoitchackneyCWE-93CRLF injection in cookie domain/path options in hackney
CVE-2026-488447.534.2RoundcubeWebmailCWE-670Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure cod…
CVE-2026-438275.934.0Apache Software FoundationApache ShiroCWE-384Apache Shiro: Session fixation: new session is not created after login by def…
CVE-2026-249377.233.6VideoWhisper.comBroadcast Live VideoCWE-94WordPress Broadcast Live Video plugin < 7.1.3 - Remote Code Execution (RCE) v…
CVE-2026-488466.533.4RoundcubeWebmailCWE-669In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote i…
CVE-2026-418636.532.6SpringSpring AICWE-22LLM-influenced filename used unsanitized in Path.resolve before file write in…
CVE-2018-253798.831.8OurenergyCollectric CMUCWE-89Collectric CMU 1.0 SQL Injection via lang Parameter
CVE-2026-452168.831.7StoreAppsSmart ManagerCWE-266WordPress Smart Manager plugin <= 8.85.0 - Privilege Escalation vulnerability
CVE-2026-488487.231.6RoundcubeWebmailCWE-79Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient H…
CVE-2018-253688.731.3NordvpnNordVPNCWE-789Nord VPN 6.14.31 Denial of Service via Password Field
CVE-2026-488456.530.5RoundcubeWebmailCWE-669In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, …
CVE-2026-488378.530.0Unlimited ElementsUnlimited Elements For ElementorCWE-89WordPress Unlimited Elements For Elementor plugin <= 2.0.8 - SQL Injection vu…
CVE-2026-427739.329.9eMagicOneeMagicOne Store ManagerCWE-89WordPress eMagicOne Store Manager plugin <= 1.3.2 - SQL Injection vulnerability
CVE-2026-427749.329.9CrocoblockJetEngineCWE-89WordPress JetEngine plugin <= 3.8.8.1 - SQL Injection vulnerability
CVE-2026-470706.029.9benoitchackneyCWE-601HTTP/3 redirect handler leaks Authorization and Cookie headers to cross-origi…
CVE-2026-445985.129.4Apache Software FoundationApache Shiro Jakarta EE moduleCWE-601Apache Shiro Jakarta EE module: Open redirect and SSRF (requires valid creden…
CVE-2026-401275.329.0OutSystemsLifetimeCWE-639Authorization Bypass Through User-Controlled Key in OutSystems Lifetime
CVE-2026-94642.028.7YunaiVyudao-cloudCWE-918YunaiV yudao-cloud Admin API Endpoint create IotDataSinkHttpConfig server-sid…
CVE-2026-452176.527.8ThemeHighStripe Payment Gateway for WooCommerceCWE-288WordPress Stripe Payment Gateway for WooCommerce plugin <= 5.0.7 - Broken Aut…
CVE-2026-94665.527.8TiandyEasy7 Integrated Management PlatformCWE-640Tiandy Easy7 Integrated Management Platform API Endpoint updateUserPassword p…
CVE-2026-485890.027.8Apache Software FoundationApache ShiroCWE-601Apache Shiro: Jakarta EE open redirect via untrusted Referer in post-login re…
CVE-2018-253718.827.4MoosocialmooSocial Store PluginCWE-89mooSocial Store Plugin 2.6 SQL Injection via product parameter
CVE-2026-26519.027.0mlflowmlflow/mlflowCWE-862Missing Authorization Validation in mlflow/mlflow
CVE-2026-277686.626.5Genetec Inc.Genetec Security CenterCWE-89SQL Injection affecting the Access Manager role.
CVE-2026-94972.126.2changmingxietcc-transactionCWE-20changmingxie tcc-transaction Fastjson AutoType REST API Fastjson.parseObject …
CVE-2018-253648.826.1FyffePHP-Twitter-CloneCWE-89Twitter-Clone 1 SQL Injection via search.php
CVE-2026-94682.126.1dazebcline-mcp-memory-bankCWE-22dazeb cline-mcp-memory-bank index.ts handleInitializeMemoryBank path traversal
CVE-2026-94722.126.1dazebmarkdown-downloaderCWE-22dazeb markdown-downloader index.ts create_subdirectory path traversal
CVE-2026-94732.126.1c-rickjimeng-mcpCWE-22c-rick jimeng-mcp api.ts generateVideo path traversal
CVE-2026-94482.126.0code-projectsEmployee Management SystemCWE-79code-projects Employee Management System applyleave.php cross site scripting
CVE-2026-94382.124.6yashpokharna2555StudentManagementSystemCWE-99yashpokharna2555 StudentManagementSystem courseDel.php resource injection
CVE-2026-488505.924.2PuTTYPuTTYCWE-415PuTTY 0.72 before 0.84 has a double free in RSA KEX.
CVE-2026-94475.524.1SourceCodesterSimple POS and Inventory SystemCWE-74SourceCodester Simple POS and Inventory System search.php sql injection
CVE-2026-94655.524.1TiandyEasy7 Integrated Management PlatformCWE-74Tiandy Easy7 Integrated Management Platform GetDBDataEx.jsp sql injection
CVE-2026-94695.524.1yashpokharna2555StudentManagementSystemCWE-74yashpokharna2555 StudentManagementSystem success.php sql injection
CVE-2026-94705.524.1yashpokharna2555StudentManagementSystemCWE-74yashpokharna2555 StudentManagementSystem student_trans.php confirm_logged_in …
CVE-2026-94745.524.1yashpokharna2555StudentManagementSystemCWE-74yashpokharna2555 StudentManagementSystem studentdel.php confirm_logged_in sql…
CVE-2026-90589.323.1Krajowa Izba RozliczeniowaSzafir SDKCWE-295Improper Certificate Verification in Szafir SDK
CVE-2018-253628.823.0FyffePHP-Twitter-CloneCWE-89Twitter-Clone 1 SQL Injection via follow.php
CVE-2018-253728.822.6MedDreamPACS Server PremiumCWE-89MedDream PACS Server Premium 6.7.1.1 SQL Injection via email
CVE-2026-452097.522.6edward_plainviewMyCryptoCheckoutCWE-862WordPress MyCryptoCheckout plugin <= 2.161 - Broken Access Control vulnerability
CVE-2026-94225.522.5n/aKLiK SocialMediaWebsiteCWE-74KLiK SocialMediaWebsite HTTP POST Request Parameter injection
CVE-2026-245465.321.5Ruben GarciaGamiPressCWE-862WordPress GamiPress plugin <= 7.6.3 - Broken Access Control vulnerability
CVE-2026-94982.121.5Dromaralamp-cloudCWE-791Dromara lamp-cloud Message Template GroovyClassLoader.parseClass special elem…
CVE-2026-52236.521.4Rust ProjectCargoCWE-61Crates in third party registries can override the cached source of other crates
CVE-2026-94215.521.2n/aKLiK SocialMediaWebsiteCWE-284KLiK SocialMediaWebsite File upload.inc.php uniqid unrestricted upload
CVE-2026-454387.520.8WebToffeeSmart Coupons for WooCommerceCWE-862WordPress Smart Coupons for WooCommerce plugin < 2.3.0 - Broken Access Contro…
CVE-2018-253807.120.4ExtroeXtroFormsCWE-89Joomla Component eXtroForms 2.1.5 SQL Injection via filter parameters
CVE-2018-253817.120.4ExtroResponsive PortfolioCWE-89Joomla Responsive Portfolio 1.6.1 SQL Injection via filter parameters
CVE-2026-49156.519.6MattermostMattermostCWE-754Server panic via outgoing webhook responses
CVE-2026-488523.719.3PuTTYPuTTYCWE-617PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.
CVE-2026-438285.919.0Apache Software FoundationApache ShiroCWE-614Apache Shiro: Shiro's native session and rememberMe cookies do not have secur…
CVE-2026-94842.119.0SourceCodesterStudent Grades Management SystemCWE-266SourceCodester Student Grades Management System classroom.php removeStudentFr…
CVE-2026-488437.218.4RoundcubeWebmailCWE-918Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has …
CVE-2026-427636.517.8SePay teamSePay GatewayCWE-862WordPress SePay Gateway plugin <= 1.1.20 - Sensitive Data Exposure vulnerability
CVE-2026-94132.117.7SourceCodesterIndian Invoicing SystemCWE-79SourceCodester Indian Invoicing System category.php cross site scripting
CVE-2026-94152.117.7code-projectsEmployee Management SystemCWE-79code-projects Employee Management System eloginwel.php cross site scripting
CVE-2026-94162.117.7code-projectsEmployee Management SystemCWE-79code-projects Employee Management System myprofile.php cross site scripting
CVE-2026-94172.117.7code-projectsEmployee Management SystemCWE-79code-projects Employee Management System myprofileup.php cross site scripting
CVE-2026-94182.117.7code-projectsEmployee Management SystemCWE-79code-projects Employee Management System changepassemp.php cross site scripting
CVE-2026-94192.117.8code-projectsEmployee Management SystemCWE-79code-projects Employee Management System empproject.php cross site scripting
CVE-2026-94452.117.5SourceCodesterSimple POS and Inventory SystemCWE-284SourceCodester Simple POS and Inventory System File Extension addproduct.php …
CVE-2026-94832.117.5SourceCodesterStudent Grades Management SystemCWE-266SourceCodester Student Grades Management System grades.php improper authoriza…
CVE-2026-77668.317.1KenikKG-5230TAS-IL-3CWE-22Path Traversal in Kenik cameras
CVE-2026-94442.017.1SourceCodesterSimple POS and Inventory SystemCWE-74SourceCodester Simple POS and Inventory System GET Parameter deleteproduct.ph…
CVE-2026-94462.017.1SourceCodesterSimple POS and Inventory SystemCWE-74SourceCodester Simple POS and Inventory System edit_customer.php sql injection
CVE-2026-245865.416.7ThemeansarNewsesCWE-862WordPress Newses theme <= 2.0.0.77 - Broken Access Control vulnerability
CVE-2026-273464.916.6Kings PluginsB2BKingCWE-862WordPress B2BKing plugin < 5.2.10 - Broken Access Control vulnerability
CVE-2026-94712.015.8yashpokharna2555StudentManagementSystemCWE-79yashpokharna2555 StudentManagementSystem student.php cross site scripting
CVE-2026-94852.015.8SourceCodesterStudent Grades Management SystemCWE-79SourceCodester Student Grades Management System students.php cross site scrip…
CVE-2026-94492.115.6code-projectsEmployee Management SystemCWE-74code-projects Employee Management System changepassemp.php sql injection
CVE-2026-94502.115.6code-projectsEmployee Management SystemCWE-74code-projects Employee Management System psubmit.php sql injection
CVE-2026-94512.115.6code-projectsEmployee Management SystemCWE-74code-projects Employee Management System applyleaveprocess.php sql injection
CVE-2026-94202.115.1n/aKLiK SocialMediaWebsiteCWE-74KLiK SocialMediaWebsite HTTP GET Request Parameter injection
CVE-2026-488494.414.7RoundcubeWebmailCWE-79In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitiz…
CVE-2026-245925.313.8Lucian ApostolAuto Affiliate LinksCWE-862WordPress Auto Affiliate Links plugin <= 6.8.8.3 - Broken Access Control vuln…
CVE-2026-273575.313.8Cornel RaiuWP Search AnalyticsCWE-862WordPress WP Search Analytics plugin < 1.5.0 - Broken Access Control vulnerab…
CVE-2026-273985.313.8WP ChillRSVP and Event ManagementCWE-862WordPress RSVP and Event Management plugin <= 2.7.16 - Broken Access Control …
CVE-2026-470766.913.5benoitchackneyCWE-436SSRF allowlist bypass via percent-encoded host in hackney
CVE-2026-488513.112.8PuTTYPuTTYCWE-451PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication fo…
CVE-2026-323895.412.7LinethemesNanoCareCWE-862WordPress NanoCare theme < 1.2.2 - Broken Access Control vulnerability
CVE-2026-427766.310.0WP SunshineSunshine Photo CartCWE-862WordPress Sunshine Photo Cart plugin <= 3.6.7 - Broken Access Control vulnera…
CVE-2026-94122.19.9SourceCodesterIndian Invoicing SystemCWE-266SourceCodester Indian Invoicing System Backend Endpoint access control
CVE-2026-245274.39.8Patterns in the cloudAutoship Cloud for WooCommerce Subscription ProductsCWE-862WordPress Autoship Cloud for WooCommerce Subscription Products plugin <= 2.14…
CVE-2026-245454.39.8Nikki BlightQR RedirectorCWE-862WordPress QR Redirector plugin <= 2.0.3 - Broken Access Control vulnerability
CVE-2026-245824.39.8WPPOOLFlexTableCWE-862WordPress FlexTable plugin <= 3.24.0 - Broken Access Control vulnerability
CVE-2026-90785.49.7MozillaFirefox for iOSCWE-451Firefox iOS RTL Domain Rendering Issue in Link Preview
CVE-2018-253635.39.6FyffePHP-Twitter-CloneCWE-352Twitter-Clone 1 Cross-Site Request Forgery via tweetdel.php
CVE-2026-94092.19.6Sushmi-palInvoice-SystemCWE-266Sushmi-pal Invoice-System User Management user improper authorization
CVE-2026-94102.19.6Sushmi-palInvoice-SystemCWE-266Sushmi-pal Invoice-System Profile Workflow profile improper authorization
CVE-2026-454356.59.4MelapressWP Activity LogCWE-79WordPress WP Activity Log plugin <= 5.6.3 - Cross Site Scripting (XSS) vulner…
CVE-2018-253706.98.8AdmidioAdmidioCWE-352Admidio 3.3.5 Cross-Site Request Forgery via roles_function.php
CVE-2026-94112.18.9SourceCodesterIndian Invoicing SystemCWE-74SourceCodester Indian Invoicing System Invoice Generation IGST_Invoice.php sq…
CVE-2026-94142.08.7SourceCodesterIndian Invoicing SystemCWE-79SourceCodester Indian Invoicing System Invoice Template Render Database-Backe…
CVE-2018-253608.68.5AgatasoftAuto PingMasterCWE-121AgataSoft Auto PingMaster 1.5 Buffer Overflow SEH
CVE-2026-94862.18.3SourceCodesterStudent Grades Management SystemCWE-352SourceCodester Student Grades Management System cross-site request forgery
CVE-2018-253668.67.8globalscapeCuteFTPCWE-120CuteFTP 5.0 XP Buffer Overflow via Site Manager Label Field
CVE-2018-253768.67.8SocuSoft3GP Photo SlideshowCWE-120Socusoft 3GP Photo Slideshow 8.05 Buffer Overflow SEH
CVE-2018-253738.67.8SocuSoftDVD Photo Slideshow ProfessionalCWE-121DVD Photo Slideshow Professional 8.07 Buffer Overflow SEH
CVE-2018-253758.67.8SocuSoftiPod Photo SlideshowCWE-121SocuSoft iPod Photo Slideshow 8.05 Buffer Overflow SEH
CVE-2018-253778.67.8SocuSoftFlash Slideshow Maker ProfessionalCWE-120Flash Slideshow Maker Professional 5.20 Buffer Overflow SEH
CVE-2026-60594.87.4NEC Platforms, Ltd.Aterm WX1800HPCWE-79A cross-site scripting vulnerability exists in Aterm. Arbitrary scripts may b…
CVE-2026-95041.97.2GNULibreDWGCWE-119GNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-bounds
CVE-2026-94906.86.7AcerCare CenterCWE-269Acer Care Center creates a Named Pipe with a weak Security Descriptor
CVE-2025-627456.56.6PickPluginsTeam ShowcaseCWE-79WordPress Team Showcase plugin <= 1.22.28 - Cross Site Scripting (XSS) vulner…
CVE-2018-253696.96.5scanwithVisual PingCWE-120Visual Ping 0.8.0.0 Buffer Overflow Denial of Service
CVE-2018-253676.96.3NASAopenVSPCWE-120NASA openVSP 3.16.1 Denial of Service via Buffer Overflow
CVE-2018-253598.65.3SplinterwareSplinterware System Scheduler ProCWE-276Splinterware System Scheduler Pro 5.12 Privilege Escalation
CVE-2026-95021.94.7GNULibreDWGCWE-119GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section heap-based ove…
CVE-2026-95011.93.9GNULibreDWGCWE-617GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section assertion
CVE-2026-245746.53.6RecorpExport WP Page to Static HTML/CSSCWE-352WordPress Export WP Page to Static HTML/CSS plugin <= 6.0.0 - Cross Site Requ…
CVE-2026-251938.63.3GallagherCommand Centre ServerCWE-532Insertion of Sensitive Information into Log File (CWE-532) in some Command Ce…
CVE-2018-253786.93.3StokedonitNotebook ProCWE-789Notebook Pro 2.0 Denial of Service via Notebook Name Field
CVE-2026-394367.12.9bgermannCformsIICWE-352WordPress CformsII plugin <= 15.1.3 - Cross Site Request Forgery (CSRF) vulne…
CVE-2026-92745.22.4CP PlusWi-Fi Camera CP-E38Q, CP-E48Q, CP-E25Q, CP-E35Q, CP-E45Q, CP-E28Q, CP-E21Q, CP-E31Q, CP-E41Q, CP-E24Q, CP-Z43Q, CP-E34Q, CP-E44Q, CP-T31Q, CP-V48Q, CP-V41Q, CP-Z45QCWE-312Information Exposure Vulnerability in CP-Plus Wi-Fi Camera
CVE-2026-95001.92.4GNULibreDWGCWE-119GNU LibreDWG Dwgread Utility decode.c read_2004_compressed_section heap-based…
CVE-2018-253617.02.2SoroushSoroush IM Desktop AppCWE-290Soroush IM Desktop App 0.17.0 Authentication Bypass via Database Injection
CVE-2026-245544.32.2Convers LabWPSubscriptionCWE-352WordPress WPSubscription plugin <= 1.9.1 - Cross Site Request Forgery (CSRF) …
CVE-2026-245974.32.2WpDevArtOrganization chartCWE-352WordPress Organization chart plugin <= 1.7.5 - Cross Site Request Forgery (CS…
CVE-2026-94898.52.0AcerNitrorSense V3CWE-22NitroSense V3: Local Privilege Escalation (LPE) vulnerability
CVE-2026-95031.91.6GNULibreDWGCWE-404GNU LibreDWG DWG File decode.c dwg_next_entity null pointer dereference

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-05-25 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.