boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, May 26, 2026 · all times UTC← 2026-05-25 · archive · 2026-05-27 →

Security Box Score — May 26, 2026

275 CVEs published, led by IBM (20).

275 CVEs published May 26, 2026: 30 critical, 94 high, 119 medium, 32 low; 1 in the KEV catalog at press time; 20 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 250 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published16432855——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

79 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux230556674484101120.47.8.0014+67 ▲
microsoft160530463711112286193.67.8.0047-23 ▼
red hat1769730257200.07.1.0041-2 ▼
apple225211733188713.56.2.0023+22 ▲
google16230176077417.48.8.0034+15 ▲
freebsd770520000.07.8.0020+7 ▲
suse220200000.08.2.0020+2 ▲
ubuntu010001100.02.7.02180
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco512534056866.77.8.1576+5 ▲
fortinet17430028342.99.1.8584-2 ▼
checkpoint660330300.06.5.0338+6 ▲
ivanti25230025480.08.8.8056+2 ▲
ubiquiti231200300.08.8.0068+2 ▲
f52220004150.09.2.3901+2 ▲
palo alto networks22110013150.08.6.6281+2 ▲
zyxel110010900.06.5.0023+1 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache19324141303313.17.3.0064+16 ▲
mozilla663210900.08.8.0042+6 ▲
docker330300000.08.8.0022+3 ▲
drupal3310204133.35.1.0021+3 ▲
github110100000.07.0.0039+1 ▲
gitlab00000042———0
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ibm202061040600.07.5.0027+20 ▲
progress440400600.07.5.0036+4 ▲
oracle0312002700.07.5.00880
solarwinds032100103100.09.8.83620
zohocorp220110000.07.1.0104+2 ▲
adobe020200192100.08.6.0368-2 ▼
atlassian000000130———0
sap00000060———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
hitachi energy220020000.05.7.0014+2 ▲
d-link110100300.08.7.0059+1 ▲
siemens110100000.08.7.0032+1 ▲
tp-link00000010———0
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
concrete cms4444191321000.05.7.0015+44 ▲
edimax4444027017100.07.4.0059+44 ▲
open ises3737214210000.06.9.0021+37 ▲
totolink343402509000.08.9.0191+34 ▲
netatalk3333113910000.06.4.0030+33 ▲
nvidia333381870000.07.8.0038+33 ▲
grafana102727162200.06.5.0033+6 ▲
joomla! project202118120100.06.9.0024+19 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-31431.9991100.07.8
CVE-2026-41940.985399.99.3
CVE-2026-0257.939199.87.8
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2026-20182.915299.810.0
CVE-2026-42208.894299.89.3
CVE-2026-9082.883299.89.8
CVE-2024-1708.875699.78.4
CVE-2026-42271.835499.78.7
Highest CVSS
CVECVSSEPSSNote
CVE-2026-2018210.0.9152KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4399710.0.0098
CVE-2026-4282610.0.0084
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
CVE-2026-4659510.0.0050
CVE-2026-4282210.0.0049
CVE-2026-3371210.0.0035
Most disclosures (vendor)
VendorCVEs
linux232
microsoft161
concrete cms44
edimax44
open ises37
totolink34
netatalk33
nvidia33
apache25
apple22
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco8
apple7
google4
ivanti4
fortinet3
smartertools3
solarwinds3
adobe2
berriai2
Most-affected ecosystems
EcosystemAdvisories
Maven10
crates.io2
npm2
PyPI1
Fastest to KEV
CVEVendorDays
CVE-2024-1708ConnectWise0
CVE-2026-31431Linux0
CVE-2026-32202Microsoft0
CVE-2026-34926Trend Micro, Inc.0
CVE-2026-41091Microsoft0
CVE-2026-41940WebPros0
CVE-2026-42208BerriAI0
CVE-2026-42897Microsoft0
CVE-2026-45498Microsoft0
CVE-2026-48172LiteSpeed Technologies0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171651
CVE-2021-27102n/a2021-11-171651
CVE-2021-27101n/a2021-11-171651
CVE-2021-27103n/a2021-11-171651
CVE-2021-21017Adobe2021-11-171651
CVE-2021-28550Adobe2021-11-171651
CVE-2021-42013Apache Software Foundation2021-11-171651
CVE-2021-41773Apache Software Foundation2021-11-171651
CVE-2021-30858Apple2021-11-171651
CVE-2021-30860Apple2021-11-171651

Transactions

EXPLOIT PUBLISHED — lepture mistune: 4 CVEs (CVE-2026-44708, CVE-2026-44897, CVE-2026-44898, CVE-2026-44899). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-25104 (MediaArea MediaInfoLib). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-25713 (MediaArea MediaInfoLib). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-40033 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-44214 (rexxars eventsource-encoder). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-44723 (VowpalWabbit vowpal_wabbit). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-44729 (twentyhq twenty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-44788 (adamhathcock sharpcompress). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-44837 (ViewComponent view_component). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-44966 (shepherdwind velocity.js). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-44985 (amir20 dozzle). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-45298 (amir20 dozzle). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-46624 (twentyhq twenty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48687. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48689. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48710 (Kludex starlette). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added.

Yesterday's Results

How to read these box scores · glossary

275 CVEs published. 25 box scores, 250 table rows — nothing truncated.

LiteSpeed cPanel Plugin
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .1891   97.1   YES
AFFECTED
  Product        Versions     Fixed
  cPanel Plugin  2.3 –        —
  WHM Plugin     unspecified  —
TIMELINE
  May 21  Reserved by CNA
  May 26  Added to CISA KEV, due May 29
  May 26  Published (CNA: mitre)
CWE-266 · CNA: mitre · CVSS v4.0 · 4 references · NVD status: Analyzed · KEV due May 29, 2026
Red Hat Red Hat Enterprise Linux 10 — Samba: samba: remote code execution in printing subsystem via unescaped job description
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  C  H  H  H    9.0   .1393   96.2     —
AFFECTED
  Product                                                                Versions     Fixed
  Red Hat Enterprise Linux 10                                            unspecified  0:4.23.5-109.el10_2
  Red Hat Enterprise Linux 10.0 Extended Update Support                  unspecified  0:4.21.3-114.el10_0.1
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:4.10.16-26.el7_9.1
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:4.10.16-26.el7_9.1
  Red Hat Enterprise Linux 8                                             unspecified  0:4.19.4-16.el8_10
  Red Hat Enterprise Linux 8                                             unspecified  0:4.19.4-16.el8_10
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  0:4.13.3-12.el8_4.1
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  0:4.13.3-12.el8_4.1
  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support  unspecified  0:4.15.5-16.el8_6.1
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On  unspecified  0:4.15.5-16.el8_6.1
  + 10 more
TIMELINE
  Mar 19  Reserved by CNA
  May 26  Published (CNA: redhat)
CWE-78 · CNA: redhat · CVSS v3.1 · 15 references · NVD status: Modified
Totolink CA750-PoE Setting cstecgi.cgi setUpgradeUboot os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .1081   95.5     —
AFFECTED
  Product    Versions    Fixed
  CA750-PoE  6.2c.510 –  —
TIMELINE
  May 25  Reserved by CNA
  May 26  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink CA750-PoE Setting cstecgi.cgi setUploadUserData os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .1081   95.5     —
AFFECTED
  Product    Versions    Fixed
  CA750-PoE  6.2c.510 –  —
TIMELINE
  May 25  Reserved by CNA
  May 26  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink CA750-PoE Setting cstecgi.cgi recvUpgradeNewFw os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .1081   95.5     —
AFFECTED
  Product    Versions    Fixed
  CA750-PoE  6.2c.510 –  —
TIMELINE
  May 25  Reserved by CNA
  May 26  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Totolink CA750-PoE Setting cstecgi.cgi setWiFiWpsConfig os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .1081   95.5     —
AFFECTED
  Product    Versions    Fixed
  CA750-PoE  6.2c.510 –  —
TIMELINE
  May 25  Reserved by CNA
  May 26  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
mossdef-org luci-app-https-dns-proxy — luci-app-https-dns-proxy Authenticated Command Injection via setInitAction
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0658   93.3     —
AFFECTED
  Product                   Versions     Fixed
  luci-app-https-dns-proxy  unspecified  —
TIMELINE
  May 13  Reserved by CNA
  May 26  Published (CNA: VulnCheck)
CWE-77 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Deferred
checkpoint Quantum Security Gateway — Identity Awareness Captive Portal - Unauthenticated Local File Inclusion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0475   91.2     —
AFFECTED
  Product                   Versions                                    Fixed
  Quantum Security Gateway  R82.10 with Jumbo Hotfix Take 6 or below –  —
TIMELINE
  May 20  Reserved by CNA
  May 26  Published (CNA: checkpoint)
CWE-98 · CNA: checkpoint · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
checkpoint Quantum Security Gateway — SQL injection issue in UserCheck Portal when DLP Software Blade is active
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  L  L  L    5.6   .0436   90.5     —
AFFECTED
  Product                   Versions                                    Fixed
  Quantum Security Gateway  R82.10 with Jumbo Hotfix Take 6 or below –  —
TIMELINE
  May 20  Reserved by CNA
  May 26  Published (CNA: checkpoint)
CWE-89 · CNA: checkpoint · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
checkpoint Quantum Security Management — Authenticated Administrator Role-Based Access Control Bypass in Compliance
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  L  L  L    4.1   .0410   90.0     —
AFFECTED
  Product                      Versions                                    Fixed
  Quantum Security Management  R82.10 with Jumbo Hotfix Take 6 or below –  —
TIMELINE
  May 20  Reserved by CNA
  May 26  Published (CNA: checkpoint)
CWE-89 · CNA: checkpoint · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
checkpoint Quantum Security Gateway — VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0266   84.5     —
AFFECTED
  Product                   Versions                                    Fixed
  Quantum Security Gateway  R82.10 with Jumbo Hotfix Take 6 or below –  —
TIMELINE
  May 20  Reserved by CNA
  May 26  Published (CNA: checkpoint)
CWE-122 · CNA: checkpoint · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
checkpoint Quantum Security Gateway — HTTP service can incorrectly process malformed HTTP requests
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  L    5.3   .0261   84.2     —
AFFECTED
  Product                   Versions                                    Fixed
  Quantum Security Gateway  R82.10 with Jumbo Hotfix Take 6 or below –  —
TIMELINE
  May 20  Reserved by CNA
  May 26  Published (CNA: checkpoint)
CWE-122 · CNA: checkpoint · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
checkpoint Quantum Security Gateway — VPN service may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0214   80.6     —
AFFECTED
  Product                   Versions                                    Fixed
  Quantum Security Gateway  R82.10 with Jumbo Hotfix Take 6 or below –  —
TIMELINE
  May 20  Reserved by CNA
  May 26  Published (CNA: checkpoint)
CWE-125 · CNA: checkpoint · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
Totolink N300RH Web Management cstecgi.cgi setPasswordCfg os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    8.9   .0213   80.6     —
AFFECTED
  Product  Versions               Fixed
  N300RH   6.1c.1353_B20190305 –  —
TIMELINE
  May 26  Reserved by CNA
  May 26  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Kludex starlette — Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  N    6.5   .0191   78.1     —
AFFECTED
  Product    Versions   Fixed
  starlette  < 1.0.1 –  —
TIMELINE
  May 22  Reserved by CNA
  May 26  Public exploit reference published
  May 26  Published (CNA: GitHub_M)
CWE-444 · CNA: GitHub_M · CVSS v3.1 · 24 references · NVD status: Modified
n/a n/a — FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper ro…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0164   74.6     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  May 22  Reserved by CNA
  May 26  Public exploit reference published
  May 26  Published (CNA: mitre)
CWE-78 · CNA: mitre · CVSS v3.1 · 3 references · NVD status: Modified
amir20 dozzle — Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  N  N    8.6   .0149   72.1     —
AFFECTED
  Product  Versions    Fixed
  dozzle   < 10.5.2 –  —
TIMELINE
  May 11  Reserved by CNA
  May 26  Public exploit reference published
  May 26  Published (CNA: GitHub_M)
CWE-918 · CNA: GitHub_M · CVSS v3.1 · 2 references · NVD status: Analyzed
mikro-orm mikro-orm — MikroORM: SQL injection via runtime-controlled identifiers and JSON-path keys
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  L  L    7.6   .0145   71.3     —
AFFECTED
  Product    Versions                   Fixed
  mikro-orm  >= 7.0.0-rc.0, < 7.0.14 –  —
  knex       < 6.6.14 –                 —
  sql        < 7.0.14 –                 —
TIMELINE
  May 7   Reserved by CNA
  May 26  Published (CNA: GitHub_M)
CWE-89 · CNA: GitHub_M · CVSS v3.1 · 5 references · NVD status: Deferred
n/a n/a — FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik r…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  N    8.1   .0107   62.3     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  May 22  Reserved by CNA
  May 26  Published (CNA: mitre)
CWE-78 · CNA: mitre · CVSS v3.1 · 3 references · NVD status: Analyzed
haojing8312 WorkClaw Blacklist bash.rs is_dangerous os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0105   61.7     —
AFFECTED
  Product   Versions  Fixed
  WorkClaw  0.6.0 –   —
TIMELINE
  May 26  Reserved by CNA
  May 26  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
FreeRDP - Heap-buffer-overflow in gdi_CacheToSurface via rectangle validation bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    8.7   .0104   61.3     —
AFFECTED
  Product  Versions     Fixed
  FreeRDP  unspecified  3.26.0
TIMELINE
  Apr 8   Reserved by CNA
  May 26  Public exploit reference published
  May 26  Published (CNA: VulnCheck)
CWE-122, CWE-787 · CNA: VulnCheck · CVSS v4.0 · 9 references · NVD status: Modified
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities when using when using Web Server Plug-ins
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0085   55.3     —
AFFECTED
  Product                                                                     Versions    Fixed
  Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty  8.5, 9.0 –  —
TIMELINE
  May 14  Reserved by CNA
  May 26  Published (CNA: ibm)
CWE-94 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed
Red Hat Red Hat Container Native Virtualization 4.12 — Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0074   51.9     —
AFFECTED
  Product                                       Versions     Fixed
  Red Hat Container Native Virtualization 4.12  unspecified  1779375376
  Red Hat Container Native Virtualization 4.13  unspecified  1778999881
  Red Hat Container Native Virtualization 4.14  unspecified  1779321599
  Red Hat Container Native Virtualization 4.15  unspecified  1778859977
  Red Hat Container Native Virtualization 4.16  unspecified  1778861274
  Red Hat Container Native Virtualization 4.17  unspecified  1779174925
  Red Hat Container Native Virtualization 4.18  unspecified  1778887155
  Red Hat Container Native Virtualization 4.19  unspecified  1779289071
  Red Hat Container Native Virtualization 4.20  unspecified  1779288737
  Red Hat Container Native Virtualization 4.21  unspecified  1779420069
TIMELINE
  Apr 29  Reserved by CNA
  May 26  Published (CNA: redhat)
CWE-59 · CNA: redhat · CVSS v3.1 · 13 references · NVD status: Awaiting Analysis
Gnutls: gnutls: information disclosure via heap overread in rsa key exchange
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  H    8.2   .0073   51.4     —
AFFECTED
  Product                                                                Versions     Fixed
  gnutls                                                                 unspecified  —
  Red Hat Enterprise Linux 10                                            unspecified  0:3.8.10-4.el10_2
  Red Hat Enterprise Linux 10.0 Extended Update Support                  unspecified  0:3.8.9-9.el10_0.19
  Red Hat Enterprise Linux 8                                             unspecified  0:3.6.16-8.el8_10.6
  Red Hat Enterprise Linux 8                                             unspecified  0:3.6.16-8.el8_10.6
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  0:3.6.14-10.el8_4.1
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  0:4.13-3.el8_4.1
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  0:3.6.14-10.el8_4.1
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  0:4.13-3.el8_4.1
  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support  unspecified  0:3.6.16-5.el8_6.5
  + 24 more
TIMELINE
  Mar 31  Reserved by CNA
  May 26  Published (CNA: redhat)
CWE-126 · CNA: redhat · CVSS v3.1 · 17 references · NVD status: Awaiting Analysis
Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  L    5.3   .0073   51.4     —
AFFECTED
  Product                                                                Versions     Fixed
  gnutls                                                                 unspecified  —
  Red Hat Enterprise Linux 10                                            unspecified  0:3.8.10-4.el10_2
  Red Hat Enterprise Linux 10.0 Extended Update Support                  unspecified  0:3.8.9-9.el10_0.19
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:3.3.29-9.el7_9.2
  Red Hat Enterprise Linux 8                                             unspecified  0:3.6.16-8.el8_10.6
  Red Hat Enterprise Linux 8                                             unspecified  0:3.6.16-8.el8_10.6
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  0:3.6.14-10.el8_4.1
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  0:4.13-3.el8_4.1
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  0:3.6.14-10.el8_4.1
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On  unspecified  0:4.13-3.el8_4.1
  + 23 more
TIMELINE
  Apr 23  Reserved by CNA
  May 26  Published (CNA: redhat)
CWE-193 · CNA: redhat · CVSS v3.1 · 17 references · NVD status: Awaiting Analysis
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-427858.649.6OpenkmOpenKM Community EditionCWE-94OpenKM 6.3.12 Remote Code Execution via Administrative Scripting
CVE-2026-486899.849.5n/an/aCWE-787FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based …
CVE-2026-242129.848.6NVIDIAIsaac LaunchableCWE-319NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive in…
CVE-2026-424258.647.9OpenkmOpenKM Community EditionCWE-89OpenKM 6.3.12 Unrestricted SQL Execution via DatabaseQuery
CVE-2026-36609.845.1IBMEngineering Lifecycle ManagementCWE-863IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Authe…
CVE-2026-95609.444.8OpenVPN IncOpenVPN ConnectCWE-78Privilege escalation via background service of OpenVPN Connect 3.5.1 through …
CVE-2026-486869.844.3n/an/aCWE-120FastNetMon Community Edition through 1.2.9 contains a stack-based buffer over…
CVE-2026-449669.843.3shepherdwindvelocity.jsCWE-1321Velocity.js: Prototype Pollution in #set path assignment
CVE-2026-414017.141.8libyanglibyangCWE-416libyang - Heap Use-After-Free Write in XML Metadata Parsing
CVE-2026-95505.541.7Acrel ElectricalEEMS Enterprise Power Operation and Maintenance Cloud PlatformCWE-22Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platfo…
CVE-2026-403837.540.5Joomla! ProjectJoomla! CMSCWE-22Joomla! Core - [20260509] - LFI in HTMLView layout parameter
CVE-2026-485925.340.5oban-bgoban_webCWE-862Missing authorization check on save-job event handler in oban_web
CVE-2026-72519.340.4EppendorfBioFlo 320CWE-259Eppendorf BioFlo 320 Use of hard-coded password
CVE-2026-88908.839.9code100xcode100xCWE-639code100x Mobile API Authentication Bypass via Header Spoofing
CVE-2026-405646.539.9Apache Software FoundationApache Flink Kubernetes OperatorCWE-552Apache Flink Kubernetes Operator: Server-Side Request Forgery and local file …
CVE-2026-91709.839.8IBMHTTP ServerCWE-94IBM HTTP Server is affected by multiple vulnerabilities
CVE-2026-466249.939.4twentyhqtwentyCWE-78Twenty: SQL Injection via the timeZone field
CVE-2026-447239.938.5VowpalWabbitvowpal_wabbitCWE-78Vowpal Wabbit: Shell injection via crafted PR title in python_checks.yml allo…
CVE-2026-88559.837.7IBMHTTP ServerCWE-94IBM HTTP Server is affected by multiple vulnerabilities
CVE-2026-444499.137.3prolix-ocLumiverseCWE-88Lumiverse: SMB `exists()` basename injection via smbclient `!cmd` escape
CVE-2026-95387.537.1BINGOSArchive::TarCWE-789Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attack…
CVE-2026-80478.736.9CODESYSCODESYS Control RTE (SL)CWE-1284Out-of-bounds Write in CODESYS Control
CVE-2026-403845.936.8Joomla! ProjectJoomla! CMSCWE-22Joomla! Core - [20260510] - Path traversal in com_media webservice endpoint
CVE-2026-457219.036.2xyprotoalgernonCWE-20Algernon: handler.lua discovery walks parent directories above the server root
CVE-2026-424969.135.6BINGOSArchive::TarCWE-59Archive::Tar versions before 3.08 for Perl extract symlinks with attacker con…
CVE-2026-95405.535.4vllm-projectvllmCWE-404vllm-project vllm OpenAI-compatible Serving Path denial of service
CVE-2026-420138.235.0—gnutlsCWE-295Gnutls: gnutls: certificate validation bypass due to oversized subject altern…
CVE-2026-442097.535.1mascibanksCWE-1336Banks: Critical Remote Code Execution (RCE) via Jinja2 SSTI
CVE-2026-396617.534.5MagentechSW CoreCWE-98WordPress SW Core plugin <= 1.7.18 - Local File Inclusion vulnerability
CVE-2026-424977.534.5BINGOSArchive::TarCWE-59Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker cont…
CVE-2026-485935.934.5oban-bgoban_webCWE-400Unbounded range expansion in cron describe causes memory exhaustion in oban_web
CVE-2026-241627.834.4NVIDIAMerlin Transformers4RecCWE-502NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker …
CVE-2026-448377.534.0ViewComponentview_componentCWE-187view_component: System Test Entry Point Path Check Allows Sibling Directory E…
CVE-2026-448438.233.5langchain-ailangchainCWE-502LangChain: Unsafe deserialization of attacker-controlled LangChain objects th…
CVE-2026-95212.932.9frailltbitseryCWE-20fraillt bitsery std_smart_ptr.h loadFromSharedState improper validation of sp…
CVE-2026-448446.332.4GOVCERT-LUeml_parserCWE-674eml_parser: Recursion DoS via nested message/rfc822 attachments
CVE-2026-448959.232.0yoda-digitalmcp-gitlab-serverCWE-306GitLab MCP Server: SSE transport has no authentication and wildcard CORS, exp…
CVE-2026-95175.531.8hemant6488CodeIgniter-StudentManagementSystemCWE-266hemant6488 CodeIgniter-StudentManagementSystem Student Management addStudentV…
CVE-2026-419176.931.5OpenkmOpenKM Community EditionCWE-22OpenKM 6.3.12 Local File Inclusion via Admin Scripting
CVE-2026-86067.031.4GitHubEnterprise ServerCWE-918Server-Side Request Forgery in GitHub Enterprise Server via Advisory Package …
CVE-2026-88507.530.7IBMHTTP ServerCWE-476IBM HTTP Server is affected by multiple vulnerabilities
CVE-2026-444509.930.4prolix-ocLumiverseCWE-88Lumiverse: RCE via MCP stdio argument injection
CVE-2026-81745.729.8ZohocorpZoho Mail wordpress pluginCWE-352Cross-site Request Forgery
CVE-2026-444449.129.7prolix-ocLumiverseCWE-78Lumiverse: Spindle extension install runs untrusted lifecycle scripts before …
CVE-2026-40517.229.5IBMEngineering Lifecycle ManagementCWE-749IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to Serve…
CVE-2026-446689.829.1factionsecurityfactionCWE-306Faction: Unauthenticated Read, Modify, and Delete of Boilerplate Templates
CVE-2026-22649.228.6Google CloudApigee-XCWE-918Server-Side Request Forgery and Credential Exfiltration in Google Cloud Apige…
CVE-2026-94955.528.7n/a@koa/routerCWE-284Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnera…
CVE-2026-88547.528.6IBMHTTP ServerCWE-825IBM HTTP Server is affected by multiple vulnerabilities
CVE-2026-36037.128.1IBMEngineering Lifecycle ManagementCWE-611IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML e…
CVE-2026-420127.128.0—gnutlsCWE-295Gnutls: gnutls: certificate validation bypass due to improper handling of uri…
CVE-2026-400348.527.7gitoxidegitoxideCWE-77gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule
CVE-2026-352238.627.3Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260508] - Improper access check in com_config webservice en…
CVE-2026-80467.227.4CODESYSCODESYS Control RTE (SL)CWE-863Incorrect Authorization in CODESYS Control
CVE-2026-94967.727.1n/apacoteCWE-1333Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable t…
CVE-2026-439828.727.0xyprotoalgernonCWE-22Algernon: Path traversal file write via savein()
CVE-2026-447076.826.9chatwootchatwootCWE-283Chatwoot: Pre-Account Takeover via OAuth on Unconfirmed Accounts
CVE-2026-448366.526.9ViewComponentview_componentCWE-749view_component: Preview Route Can Dispatch Inherited Helper Methods
CVE-2026-96055.526.4GNUlibredwgCWE-119GNU libredwg Dwgbmp Utility bits.c bit_read_RC heap-based overflow
CVE-2026-95182.126.0hemant6488CodeIgniter-StudentManagementSystemCWE-79hemant6488 CodeIgniter-StudentManagementSystem Students Controller view_stude…
CVE-2026-95192.126.0stonith404pingvin-shareCWE-79stonith404 pingvin-share Sign-in Auto-Redirect signIn.tsx getServerSideProps …
CVE-2026-95202.126.0blitz-jsblitzCWE-79blitz-js blitz Sign-in LoginForm.tsx cross site scripting
CVE-2026-95272.126.0itsourcecodeElectronic Judging SystemCWE-79itsourcecode Electronic Judging System judges.php cross site scripting
CVE-2026-481268.225.9xyprotoalgernonCWE-22Algernon: Host header path traversal in --domain mode reads files and runs Lu…
CVE-2026-486836.525.5n/an/aCWE-125FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vul…
CVE-2026-95235.525.3Acrel ElectricalEEMS Enterprise Power Operation and Maintenance Cloud PlatformCWE-74Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platfo…
CVE-2026-467405.324.9RRWOMojolicious::Plugin::StatsdCWE-93Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric inj…
CVE-2026-96035.524.8SourceCodestereDoc Doctor Appointment SystemCWE-862SourceCodester eDoc Doctor Appointment System delete-session.php authorization
CVE-2025-114828.724.4B&R Industrial Automation GmbHPPT30 Operating SystemCWE-770Allocation of Resources Without Limits or Throttling in the OPC-UA Server
CVE-2026-352216.924.4Joomla! ProjectJoomla! CMSCWE-89Joomla! Core - [20260506] - Authenticated blind SQLi in com_finder
CVE-2026-95255.524.1itsourcecodeElectronic Judging SystemCWE-74itsourcecode Electronic Judging System edit_judge.php sql injection
CVE-2026-95265.524.1itsourcecodeElectronic Judging SystemCWE-74itsourcecode Electronic Judging System edit_team.php sql injection
CVE-2026-95285.524.1itsourcecodeElectronic Judging SystemCWE-74itsourcecode Electronic Judging System delete_judge.php sql injection
CVE-2026-95515.524.0DasParking Management System 停车场管理系统CWE-74Das Parking Management System 停车场管理系统 API Endpoint ExportParkingRecords xp_cm…
CVE-2026-95525.524.0DasParking Management System 停车场管理系统CWE-74Das Parking Management System 停车场管理系统 Search API Endpoint sql injection
CVE-2026-447307.223.8OpenCTI-PlatformopenctiCWE-284OpenCTI: Privilege escalation via graphQL API abusable by organization admins…
CVE-2026-448328.723.6grokabilitysnipe-itCWE-281Snipe-IT: Privilege Escalation via API Permissions Assignment
CVE-2026-447886.523.5adamhathcocksharpcompressCWE-22SharpCompress: Directory traversal via directory entries in WriteToDirectory …
CVE-2025-362209.823.1IBMCloud Pak for Data System - CyclopsCWE-89Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops.
CVE-2026-352226.923.1Joomla! ProjectJoomla! CMSCWE-89Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags
CVE-2026-486919.822.9n/an/aCWE-190FastNetMon Community Edition through 1.2.9 contains an integer overflow in th…
CVE-2026-457287.522.3xyprotoalgernonCWE-209Algernon: Single-file mode unconditionally enables debug mode
CVE-2026-450827.622.0karakeep-appkarakeepCWE-918Karakeep has a SSRF Protection Bypass via Redirect Handling
CVE-2026-488968.221.7Joomla! ProjectJoomla! CMSCWE-287Joomla! Core - [20260511] - MFA Authentication Bypass
CVE-2026-439358.121.7e107ince107CWE-20e107: Host Header Injection in e107 password reset enables phishing
CVE-2026-486856.521.5n/an/aCWE-130FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access be…
CVE-2026-489048.221.1Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260514] - Privilege escalation through com_users webservice…
CVE-2026-95805.521.0n/aJeecgBootCWE-266JeecgBoot selectDepart LoginController.selectDepart access control
CVE-2026-95625.520.8sambitrajSTUDENT-MANAGEMENT-SYSTEMCWE-266sambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard access control
CVE-2026-445024.320.6bugsinkbugsinkCWE-918Bugsink: SSRF bypass in `validate_webhook_url`
CVE-2026-486887.520.2n/an/aCWE-125FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds re…
CVE-2026-95662.120.1teableioteableCWE-79teableio teable Sign-up LoginPage.tsx cross site scripting
CVE-2026-447756.920.0KareaditaKavitaCWE-306Kavita: No authentication at /api/Reader/image
CVE-2026-86207.519.9IBMWeb Server Plug-ins for WebSphere Application Server and WebSphere LibertyCWE-444IBM WebSphere Application Server and WebSphere Application Server Liberty are…
CVE-2026-442145.319.6rexxarseventsource-encoderCWE-93eventsource-encoder: SSE event injection via unsanitized event and id fields
CVE-2026-448477.518.81Panel-devMaxKBCWE-287MaxKB: Webhook Trigger Authentication Bypass
CVE-2025-362217.518.5IBMCloud Pak for Data System - CyclopsCWE-1392Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops.
CVE-2026-488988.218.5Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260513] - Privilege escalation through com_users batch task
CVE-2026-486846.517.8n/an/aCWE-125FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in …
CVE-2025-713101.817.9BackdropCMSGDPR cookies module for Backdrop CMSCWE-80The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficien…
CVE-2026-88348.017.3IBMHTTP ServerCWE-122IBM HTTP Server is affected by multiple vulnerabilities
CVE-2026-95445.517.2Shenzhen Sixun SoftwareSixun Shanghui Group Business Management SystemCWE-74Shenzhen Sixun Software Sixun Shanghui Group Business Management System PayCo…
CVE-2026-95735.517.2itsourcecodeStudent Transcript Processing SystemCWE-74itsourcecode Student Transcript Processing System index.php sql injection
CVE-2026-95745.517.2itsourcecodeStudent Transcript Processing SystemCWE-74itsourcecode Student Transcript Processing System trans.php sql injection
CVE-2026-95755.517.2itsourcecodeStudent Transcript Processing SystemCWE-74itsourcecode Student Transcript Processing System index.php sql injection
CVE-2026-447298.717.1twentyhqtwentyCWE-79Twenty: Stored Cross-Site Scripting via Unsanitized File Serving (Missing Con…
CVE-2026-447494.317.1SAP_SESAP GatewayCWE-497Information Disclosure vulnerability in SAP Gateway
CVE-2026-396425.316.8SpabRiceNylaCWE-80WordPress Nyla theme <= 1.7 - Arbitrary Shortcode Execution vulnerability
CVE-2026-95845.516.6code-projectsProject Management SystemCWE-74code-projects Project Management System Login chk.php sql injection
CVE-2026-96065.516.6itsourcecodeCourier Management SystemCWE-74itsourcecode Courier Management System manage_user.php sql injection
CVE-2026-489029.816.3Joomla! ProjectJoomla! CMSCWE-319Joomla! Core - [20260518] - Transport encryption downgrade for password and u…
CVE-2026-88357.316.4IBMHTTP ServerCWE-822IBM HTTP Server is affected by multiple vulnerabilities
CVE-2026-447765.916.1KareaditaKavitaCWE-639Kavita: IDOR in /api/Download/*
CVE-2025-143617.115.8AA-TeamWoocommerce Envato AffiliatesCWE-862WordPress Woocommerce Envato Affiliates plugin <= 1.2.1 - Settings Change vul…
CVE-2026-362394.315.7n/an/aCWE-79PbootCMS v.3.2.11 contains a code injection vulnerability in its site configu…
CVE-2026-95245.315.6xianrendzwEasyReportCWE-74xianrendzw EasyReport REST Endpoint execute sql injection
CVE-2026-245905.315.6VideoWhisper.comPaid Videochat Turnkey SiteCWE-862WordPress Paid Videochat Turnkey Site plugin <= 7.3.23 - Broken Access Contro…
CVE-2026-489017.515.5Joomla! ProjectJoomla! CMSCWE-524Joomla! Core - [20260517] - Incorrect Cache Key Construction for InputFilter …
CVE-2026-95832.115.1SourceCodesterCET Automated Grading System with AI Predictive AnalyticsCWE-200SourceCodester CET Automated Grading System with AI Predictive Analytics SQL …
CVE-2026-486948.114.1n/an/aCWE-77FastNetMon Community Edition through 1.2.9 contains a configuration injection…
CVE-2026-47956.514.0ZyxelGS1200-5v3 firmwareCWE-862A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions t…
CVE-2026-488995.314.1Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260515] - Incorrect Access Control in sample data plugins
CVE-2026-486928.113.9n/an/aCWE-306FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port …
CVE-2026-423356.313.91Panel-devMaxKBCWE-918MaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing Discrepancy
CVE-2026-396555.313.8TeconceThemeMayosis CoreCWE-862WordPress Mayosis Core plugin <= 5.4.7 - Broken Access Control vulnerability
CVE-2026-444519.313.6prolix-ocLumiverseCWE-693Lumiverse: TSX component sandbox escape via DOM ref and string-split identifi…
CVE-2026-447086.113.4lepturemistuneCWE-79Mistune Math Plugin XSS Escape Bypass
CVE-2026-448976.113.4lepturemistuneCWE-79Mistune Heading ID Attribute Injection XSS
CVE-2026-448986.113.4lepturemistuneCWE-79Mistune TOC Anchor Injection XSS
CVE-2026-448996.113.4lepturemistuneCWE-79Mistune Image Directive CSS Injection Vulnerability
CVE-2026-447068.513.2chatwootchatwootCWE-89Chatwoot: SQL Injection in Conversation/Contact Filter API via Custom Attribu…
CVE-2026-251047.813.2MediaAreaMediaInfoLibCWE-191MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability
CVE-2026-257137.813.2MediaAreaMediaInfoLibCWE-122MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability
CVE-2026-488647.813.2Red HatRed Hat Enterprise Linux 10CWE-787Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompre…
CVE-2026-86474.812.6MIKCrypt::ScryptKDFCWE-338Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number …
CVE-2026-96042.112.5n/aJeecgBootCWE-266JeecgBoot AiragModelController access control
CVE-2026-241907.812.4NVIDIAGeForceCWE-862NVIDIA Display Driver for Windows and Linux contains a vulnerability in the k…
CVE-2026-385874.312.5n/an/aCWE-639An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ON…
CVE-2026-464314.312.2xyprotoalgernonCWE-942Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: *
CVE-2026-95682.312.2n/aThingsBoardCWE-74ThingsBoard YAML provision getGatewayDockerComposeFile code injection
CVE-2026-448315.412.1grokabilitysnipe-itCWE-79Snipe-IT: XSS vulnerability in component notes
CVE-2026-246384.312.0Webful CreationsRepairBuddyCWE-862WordPress RepairBuddy plugin <= 4.1121 - Broken Access Control vulnerability
CVE-2026-446678.711.2factionsecurityfactionCWE-79Faction: Stored XSS in Remediation Verification Attachment Filename Preview R…
CVE-2026-446698.711.2factionsecurityfactionCWE-79Faction: Stored XSS in Assessment Attachment Filename Preview Rendering
CVE-2026-488978.211.3Joomla! ProjectJoomla! CMSCWE-287Joomla! Core - [20260512] - MFA Authentication Bypass
CVE-2026-95792.111.0n/aJeecgBootCWE-266JeecgBoot SysUser userEdit user.getUsername access control
CVE-2026-95812.111.0n/aJeecgBootCWE-266JeecgBoot add access control
CVE-2026-442136.510.7open-telemetryopentelemetry-dotnet-contribCWE-295OpenTelemetry.Exporter.Instana bypasses TLS certificate validation when a pro…
CVE-2026-454126.310.71Panel-devMaxKBCWE-918MaxKB: Unauthenticated SSRF via Workflow Template Import
CVE-2026-423375.310.71Panel-devMaxKBCWE-862MaxKB: Broken Access Control in MaxKB OSS URL Fetch API
CVE-2026-241927.810.5NVIDIAGeForceCWE-681NVIDIA Display Driver for Linux contains a vulnerability where an attacker co…
CVE-2026-449035.110.3prometheusprometheusCWE-79Prometheus: Stored XSS via crafted histogram bucket label values in the heatm…
CVE-2026-86768.810.1silabs.comSimplicity SDKCWE-290An attacker is able to downgrade the security of a Bluetooth LE connection by…
CVE-2026-449057.510.1rieblvanetzaCWE-248Vanetza: Remote Denial of Service via Uncaught OER Encoding Exception in Cryp…
CVE-2026-95641.910.0SourceCodesterHospitals Patient Records Management SystemCWE-79SourceCodester/oretnom23 Hospitals Patient Records Management System view_pat…
CVE-2026-448965.39.6lepturemistuneCWE-79Mistune: XSS via unescaped figclass/figwidth in Figure directive
CVE-2026-88569.19.4IBMHTTP ServerCWE-400IBM HTTP Server is affected by multiple vulnerabilities
CVE-2026-241937.89.5NVIDIAGeForceCWE-787NVIDIA Display Driver for Windows and Linux contains a vulnerability where an…
CVE-2026-88527.59.4IBMHTTP ServerCWE-617IBM HTTP Server is affected by multiple vulnerabilities
CVE-2026-464304.39.4xyprotoalgernonCWE-668Algernon: Auto-refresh SSE event server binds to all interfaces by default on…
CVE-2026-424483.59.4magic-wormholemagic-wormholeCWE-22wormhole receive, with --output pointing at an existing directory can be path…
CVE-2026-95422.19.4CodeAstroLeave Management SystemCWE-74CodeAstro Leave Management System add_staff.php sql injection
CVE-2026-449858.79.2amir20dozzleCWE-346Dozzle: Cross-Site WebSocket Hijacking (CSWSH) on exec/attach endpoints bypas…
CVE-2025-361486.19.0IBMFinancial Transaction Manager for SWIFT Services for MultiplatformsCWE-79IBM Financial Transaction Manager for SWIFT Services for Multiplatforms is vu…
CVE-2026-439364.39.0e107ince107CWE-918e107: Server-Side Request Forgery (SSRF) in the remote file fetcher
CVE-2026-254265.38.7Magepeople inc.Taxi Booking Manager for WooCommerceCWE-862WordPress Taxi Booking Manager for WooCommerce plugin <= 2.0.1 - Broken Acces…
CVE-2025-687082.48.6n/an/aCWE-288SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local a…
CVE-2026-241878.88.4NVIDIAGeForceCWE-416NVIDIA Display Driver for Linux contains a vulnerability where an attacker co…
CVE-2026-423365.18.31Panel-devMaxKBCWE-367MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL Fetch
CVE-2025-687112.48.2n/an/aCWE-288AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz)…
CVE-2025-361267.68.0IBMCognos AnalyticsCWE-79IBM Cognos Analytics is affected by Cross-site scripting.
CVE-2026-443145.38.1traccartraccarCWE-863Traccar: Missing edit authorization on device image upload allows read-only u…
CVE-2026-439887.57.9rieblvanetzaCWE-248Vanetza: Remote Denial of Service via Uncaught Exception in ASN.1/OER Parsing
CVE-2026-439818.27.8xyprotoalgernonCWE-362Algernon: Race Condition in handle() shared LState
CVE-2026-259006.97.7Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260501] - XSS in feed modules
CVE-2026-308946.97.7Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260503] - XSS in com_contenthistory
CVE-2025-142905.47.8IBMwebMethods Integration (on prem) -Integration ServerCWE-918IBM webMethods Integration Sever is vulnerable to server-side request forgery
CVE-2026-439346.57.7e107ince107CWE-284e107: Broken Access Control in e107 comment edit allows cross-user comment mo…
CVE-2025-687102.47.5n/an/aCWE-288Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9…
CVE-2026-477284.37.3bugsinkbugsinkCWE-862Bugsink: Project scoping missing in sourcemap and debug-file lookup
CVE-2025-687095.27.2n/an/aCWE-79SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local a…
CVE-2026-259016.97.0Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260502] - XSS in com_associations
CVE-2026-308956.97.0Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260504] - XSS in readmore links
CVE-2025-332216.07.0NVIDIAGeForceCWE-20NVIDIA Display Driver for Windows and Linux contains a vulnerability in the k…
CVE-2026-33144.67.0HitachiHitachi Ops Center AnalyzerCWE-549Missing Password Masking in Hitachi Infrastructure Analytics Advisor, Hitachi…
CVE-2026-472029.36.6KareaditaKavitaCWE-287Kavita: Pre-Auth Account Takeover
CVE-2026-274276.56.6Dylan KuhnGeo MashupCWE-79WordPress Geo Mashup plugin <= 1.13.18 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-84796.96.4Hitachi EnergyRTU500 series CMU firmwareCWE-476IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL…
CVE-2026-95411.96.4n/aSquirrelCWE-119Squirrel Cnut File sqobject.cpp ReadObject heap-based overflow
CVE-2026-242007.06.2NVIDIAVirtual GPU ManagerCWE-416NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, whe…
CVE-2026-74517.86.0Autodesk3ds MaxCWE-787TIF File Parsing Out-of-Bounds Write in Autodesk 3ds Max
CVE-2026-74527.86.0Autodesk3ds MaxCWE-120WRL File Parsing Memory Corruption in Autodesk 3ds Max
CVE-2026-241967.16.1NVIDIAGeForceCWE-125NVIDIA Display Driver for Linux contains a vulnerability where a user could c…
CVE-2025-361455.36.1IBMwatsonx.dataCWE-923Multiple Vulnerabilities in watsonx.data
CVE-2026-486977.45.7n/an/aCWE-295FastNetMon Community Edition through 1.2.9 does not verify TLS certificates o…
CVE-2026-448337.15.7grokabilitysnipe-itCWE-601Snipe-IT: Open redirect vulnerability
CVE-2026-476726.55.6oviva-agepa4all-clientCWE-306epa4all-client: Unauthenticated REST API for Patient Record Writes
CVE-2026-241955.55.6NVIDIAGuest driverCWE-20NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user…
CVE-2026-95721.95.5n/aGPACCWE-401GPAC MP4Box media.c Media_GetSample memory leak
CVE-2026-241976.55.3NVIDIAGeForceCWE-1188NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instanc…
CVE-2026-489006.45.4Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260516] - Incorrect Access Control in com_scheduler
CVE-2026-95822.15.2SourceCodesterCET Automated Grading System with AI Predictive AnalyticsCWE-352SourceCodester CET Automated Grading System with AI Predictive Analytics cros…
CVE-2026-273316.35.0Magepeople inc.WpTravellyCWE-862WordPress WpTravelly plugin <= 2.1.5 - Broken Access Control vulnerability
CVE-2026-241985.64.9NVIDIAGeForceCWE-200NVIDIA GPU Display Driver for Linux contains a vulnerability where an advance…
CVE-2026-74505.54.8Autodesk3ds MaxCWE-476PAR File Parsing NULL Pointer Dereference in Autodesk 3ds Max
CVE-2026-74535.54.8Autodesk3ds MaxCWE-674WRL File Parsing Memory Exhaustion in Autodesk 3ds Max
CVE-2026-245204.34.9bPluginsTiktok FeedCWE-862WordPress Tiktok Feed plugin <= 1.0.24 - Broken Access Control vulnerability
CVE-2026-254444.34.9Magepeople inc.WpBookinglyCWE-862WordPress WpBookingly plugin <= 1.2.9 - Broken Access Control vulnerability
CVE-2026-477153.14.8bugsinkbugsinkCWE-639Bugsink: Issue event views can show an event from another project if its UUID…
CVE-2026-241947.84.6NVIDIAGeForceCWE-281NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode lay…
CVE-2026-449837.34.5servosmallbitvecCWE-122smallbitvec: Safe API Triggered Heap Buffer Overflow via Integer Overflow
CVE-2025-463075.54.4ApplemacOSCWE-284A logic issue was addressed with improved restrictions. This issue is fixed i…
CVE-2026-489036.94.3Joomla! ProjectJoomla! Framework Filter packageCWE-79Joomla! Framework - [20260519] - Inadequate content filtering within the chec…
CVE-2026-489056.94.3Joomla! ProjectJoomla! Framework Filter packageCWE-79Joomla! Framework - [20260520] - Inadequate content filtering within the clea…
CVE-2026-477163.14.1bugsinkbugsinkCWE-639Bugsink: Issue bulk actions can affect another project’s issue if its UUID is…
CVE-2026-251127.84.0Genetec Inc.Genetec RabbitMQCWE-732A high-severity vulnerability in the deployment of Genetec RabbitMQ that allo…
CVE-2026-242015.83.8NVIDIAVirtual GPU ManagerCWE-787NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, whe…
CVE-2026-95291.93.8GNULibreDWGCWE-404GNU LibreDWG Dwggrep Utility dwggrep.c match_BLOCK_HEADER null pointer derefe…
CVE-2026-95301.93.8GNULibreDWGCWE-119GNU LibreDWG Dwgbmp Utility decode.c read_2004_compressed_section out-of-bounds
CVE-2025-432895.53.5ApplemacOSCWE-285A logic issue was addressed with improved validation. This issue is fixed in …
CVE-2026-455748.13.4oviva-agepa4all-clientCWE-295epa4all-client: TLS Certificate Validation Disabled in Production
CVE-2026-241917.83.4NVIDIAGeForceCWE-367NVIDIA Display Driver for Windows contains a vulnerability where an attacker …
CVE-2025-462805.53.3ApplemacOSCWE-125An out-of-bounds read was addressed with improved bounds checking. This issue…
CVE-2025-433067.83.2ApplemacOSCWE-269A logic issue was addressed with improved checks. This issue is fixed in macO…
CVE-2025-434515.53.2ApplemacOSCWE-284A permissions issue was addressed by removing the vulnerable code. This issue…
CVE-2026-466206.53.0e107ince107CWE-285e107: CSRF in comment.php moderation endpoints via token-optional validation …
CVE-2026-74547.83.0Autodesk3ds MaxCWE-120WRL File Parsing Memory Corruption in Autodesk 3ds Max
CVE-2026-444103.82.9ZTEZXUniPOS NDS-LTECWE-1240Function Abusement Vulnerability in ZTE ZXUniPOS NDS-LTE
CVE-2025-432905.52.7ApplemacOSCWE-732A permissions issue was addressed with additional restrictions. This issue is…
CVE-2026-486935.52.6n/an/aCWE-59FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink a…
CVE-2026-447287.82.4babelbabelCWE-94Improper Control of Generation of Code when compiling specifically crafted ma…
CVE-2026-241826.52.5NVIDIAGeForceCWE-667NVIDIA Display Driver for Windows and Linux contains a vulnerability where an…
CVE-2026-486966.22.4n/an/aCWE-120FastNetMon Community Edition through 1.2.9 has a buffer overflow, a different…
CVE-2026-444688.52.3CODESYSCODESYS Development SystemCWE-276Incorrect Default Permissions in CODESYS Development System
CVE-2026-458345.52.3LinuxLinuxCWE-476Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb()
CVE-2026-458355.52.3LinuxLinuxCWE-476Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb()
CVE-2026-458365.52.3LinuxLinuxCWE-476Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb()
CVE-2026-449008.12.1oviva-agepa4all-clientCWE-295epa4all-client: VAU Signature bypass
CVE-2026-455757.41.9oviva-agepa4all-clientCWE-347epa4all-client: Improper Verification of Cryptographic Signature
CVE-2026-444434.81.9prolix-ocLumiverseCWE-362Lumiverse: Sign-up nonce race condition allows unauthorized account registration
CVE-2026-486907.11.8n/an/aCWE-122FastNetMon Community Edition through 1.2.9 contains an integer overflow vulne…
CVE-2026-95671.91.7n/aGPACCWE-404GPAC MP4Box isom_intern.c MergeFragment null pointer dereference
CVE-2025-137555.51.3IBMDb2CWE-532IBM® Db2® is vulnerable to credential exposure in db2diag when executing spec…
CVE-2026-352204.61.3Joomla! ProjectJoomla! CMSCWE-352Joomla! Core - [20260505] - CSRF in user activation endpoint
CVE-2026-444698.51.2CODESYSCODESYS Development SystemCWE-276Incorrect Default Permissions in CODESYS Development System
CVE-2025-462847.01.1ApplemacOSCWE-362A race condition was addressed with additional validation. This issue is fixe…
CVE-2026-73104.41.1Hitachi EnergyMACH HiDrawCWE-122A heap-based buffer overflow vulnerability exists in XML parser functionality…
CVE-2026-241994.70.6NVIDIAGeForceCWE-362NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, …
CVE-2026-454136.90.31Panel-devMaxKBCWE-328MaxKB: Unsalted MD5 Password Hashing
CVE-2026-411644.40.1nuts-foundationnuts-nodeCWE-345nuts-node: JWT type confusion in v1 access token introspection allows VP repl…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-05-26 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.