boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Friday, May 29, 2026 · all times UTC← 2026-05-28 · archive · 2026-05-30 →

Security Box Score — May 29, 2026

248 CVEs published, led by JetBrains (21).

248 CVEs published May 29, 2026: 44 critical, 105 high, 83 medium, 16 low; 0 in the KEV catalog at press time; 17 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 223 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published31474359——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

128 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux6409667961527111120.27.8.0013+477 ▲
microsoft166536463741142286193.57.8.0047-18 ▼
google168175101243567742.38.3.0022+167 ▲
red hat4294836428200.06.6.0040+23 ▲
apple225211733188713.56.2.0023+22 ▲
canonical14140455000.05.5.0009+14 ▲
freebsd770520000.07.8.0020+7 ▲
suse220200000.08.2.0020+2 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco512534056866.77.8.1576+5 ▲
fortinet17430028342.99.1.8584-2 ▼
checkpoint660330300.06.5.0338+6 ▲
ivanti25230025480.08.8.8056+2 ▲
ubiquiti231200300.08.8.0068+2 ▲
f52220004150.09.2.3901+2 ▲
palo alto networks221100132100.08.6.6281+2 ▲
zyxel110010900.06.5.0023+1 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache21344151403312.97.3.0062+12 ▲
gitlab7701604228.64.3.0024+7 ▲
mozilla663210900.08.8.0042+6 ▲
drupal5511304120.05.1.0026+5 ▲
docker330300000.08.8.0022+3 ▲
github221100000.08.1.0347+2 ▲
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ibm49491024150600.07.5.0028+49 ▲
oracle2528915402700.08.1.0027+25 ▲
progress440400600.07.5.0036+4 ▲
veeam331200100.08.6.0051+3 ▲
solarwinds032100103100.09.8.83620
zohocorp220110000.07.1.0104+2 ▲
adobe020200192100.08.6.0368-2 ▼
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology181823103000.05.6.0025+18 ▲
d-link220110300.07.3.0036+2 ▲
hitachi energy220020000.05.7.0014+2 ▲
siemens110100000.08.7.0032+1 ▲
tp-link00000010———0
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
concrete cms4444191321000.05.7.0015+44 ▲
edimax4444027017100.07.4.0059+44 ▲
open ises4444221210000.07.1.0021+44 ▲
helmholz424203930000.07.1.0026+42 ▲
mb connect line424203930000.07.1.0026+42 ▲
totolink343402509000.08.9.0191+34 ▲
netatalk3333113910000.06.4.0030+33 ▲
nvidia333381870000.07.8.0038+33 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-31431.9991100.07.8
CVE-2026-41940.985399.99.3
CVE-2026-0257.939199.87.8
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2026-20182.915299.810.0
CVE-2026-42208.894299.89.3
CVE-2026-9082.883299.89.8
CVE-2026-42271.835499.78.7
CVE-2026-41089.796299.69.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-2018210.0.9152KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4508710.0.1296
CVE-2026-805410.0.0158
CVE-2026-4919910.0.0134
CVE-2026-4399710.0.0098
CVE-2026-4282610.0.0084
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
Most disclosures (vendor)
VendorCVEs
linux642
google168
microsoft166
ibm49
red hat46
concrete cms44
edimax44
open ises44
helmholz42
mb connect line42
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco8
apple7
google4
ivanti4
fortinet3
smartertools3
solarwinds3
adobe2
berriai2
Most-affected ecosystems
EcosystemAdvisories
Maven12
Packagist7
PyPI2
crates.io2
npm2
Fastest to KEV
CVEVendorDays
CVE-2026-31431Linux0
CVE-2026-34926Trend Micro, Inc.0
CVE-2026-41091Microsoft0
CVE-2026-41940WebPros0
CVE-2026-42208BerriAI0
CVE-2026-42897Microsoft0
CVE-2026-45321@tanstack0
CVE-2026-45498Microsoft0
CVE-2026-48027nrwl0
CVE-2026-48172LiteSpeed Technologies0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171654
CVE-2021-27102n/a2021-11-171654
CVE-2021-27101n/a2021-11-171654
CVE-2021-27103n/a2021-11-171654
CVE-2021-21017Adobe2021-11-171654
CVE-2021-28550Adobe2021-11-171654
CVE-2021-42013Apache Software Foundation2021-11-171654
CVE-2021-41773Apache Software Foundation2021-11-171654
CVE-2021-30858Apple2021-11-171654
CVE-2021-30860Apple2021-11-171654

Transactions

EXPLOIT PUBLISHED — WWBN AVideo: 4 CVEs (CVE-2026-45731, CVE-2026-46337, CVE-2026-47694, CVE-2026-47696). Public exploit references added.

EXPLOIT PUBLISHED — FreeRDP: 3 CVEs (CVE-2026-44421, CVE-2026-44422, CVE-2026-45700). Public exploit references added.

EXPLOIT PUBLISHED — yhirose cpp-httplib: 3 CVEs (CVE-2026-45352, CVE-2026-45372, CVE-2026-46527). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-39276. Public exploit reference added.

Yesterday's Results

How to read these box scores · glossary

248 CVEs published. 25 box scores, 223 table rows — nothing truncated.

JetBrains TeamCity — In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .2707   97.9     —
AFFECTED
  Product   Versions     Fixed
  TeamCity  unspecified  —
TIMELINE
  May 29  Reserved by CNA
  May 29  Published (CNA: JetBrains)
CWE-88 · CNA: JetBrains · CVSS v3.1 · 1 reference · NVD status: Analyzed
flippercode WP Maps Pro — WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .2151   97.4     —
AFFECTED
  Product      Versions     Fixed
  WP Maps Pro  unspecified  —
TIMELINE
  May 16  Reserved by CNA
  May 29  Published (CNA: Wordfence)
CWE-306 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
TRENDnet TEW-432BRP formSetRoute command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0501   91.6     —
AFFECTED
  Product     Versions   Fixed
  TEW-432BRP  3.10B20 –  —
TIMELINE
  May 29  Reserved by CNA
  May 29  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Analyzed
TRENDnet TEW-432BRP formWPS command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0501   91.6     —
AFFECTED
  Product     Versions   Fixed
  TEW-432BRP  3.10B20 –  —
TIMELINE
  May 29  Reserved by CNA
  May 29  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Analyzed
FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CLIP_CAPS
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0367   88.8     —
AFFECTED
  Product  Versions    Fixed
  FreeRDP  < 3.26.0 –  —
TIMELINE
  May 6   Reserved by CNA
  May 29  Published (CNA: GitHub_M)
CWE-122, CWE-131 · CNA: GitHub_M · CVSS v3.1 · 7 references · NVD status: Modified
Waterfall WF-500 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0138   70.0     —
AFFECTED
  Product  Versions     Fixed
  WF-500   unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 29  Published (CNA: Nozomi)
CWE-78 · CNA: Nozomi · CVSS v4.0 · 1 reference · NVD status: Analyzed
Waterfall WF-500 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0138   70.0     —
AFFECTED
  Product  Versions     Fixed
  WF-500   unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 29  Published (CNA: Nozomi)
CWE-78 · CNA: Nozomi · CVSS v4.0 · 1 reference · NVD status: Analyzed
Waterfall WF-500 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0138   70.0     —
AFFECTED
  Product  Versions     Fixed
  WF-500   unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 29  Published (CNA: Nozomi)
CWE-78 · CNA: Nozomi · CVSS v4.0 · 1 reference · NVD status: Analyzed
Waterfall WF-500 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0138   70.0     —
AFFECTED
  Product  Versions     Fixed
  WF-500   unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 29  Published (CNA: Nozomi)
CWE-78 · CNA: Nozomi · CVSS v4.0 · 1 reference · NVD status: Analyzed
Waterfall WF-500 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0138   70.0     —
AFFECTED
  Product  Versions     Fixed
  WF-500   unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 29  Published (CNA: Nozomi)
CWE-78 · CNA: Nozomi · CVSS v4.0 · 1 reference · NVD status: Analyzed
Waterfall WF-500 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0138   70.0     —
AFFECTED
  Product  Versions     Fixed
  WF-500   unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 29  Published (CNA: Nozomi)
CWE-78 · CNA: Nozomi · CVSS v4.0 · 1 reference · NVD status: Analyzed
Waterfall WF-500 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0138   70.0     —
AFFECTED
  Product  Versions     Fixed
  WF-500   unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 29  Published (CNA: Nozomi)
CWE-78 · CNA: Nozomi · CVSS v4.0 · 1 reference · NVD status: Analyzed
Acer Predator Connect W6x — Predator Connect W6x: RCE via MQTT
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0134   69.1     —
AFFECTED
  Product               Versions               Fixed
  Predator Connect W6x  W6x_GBL_2.00.000005 –  —
TIMELINE
  May 28  Reserved by CNA
  May 29  Published (CNA: Acer)
CWE-77 · CNA: Acer · CVSS v4.0 · 1 reference · NVD status: Analyzed
Dokploy: Command Injection in /docker-container-logs Endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0092   57.6     —
AFFECTED
  Product  Versions     Fixed
  dokploy  <= 0.26.6 –  —
TIMELINE
  May 12  Reserved by CNA
  May 29  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Deferred
Waterfall WF-500 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0088   56.4     —
AFFECTED
  Product  Versions     Fixed
  WF-500   unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 29  Published (CNA: Nozomi)
CWE-78 · CNA: Nozomi · CVSS v4.0 · 1 reference · NVD status: Analyzed
Waterfall WF-500 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0088   56.4     —
AFFECTED
  Product  Versions     Fixed
  WF-500   unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 29  Published (CNA: Nozomi)
CWE-78 · CNA: Nozomi · CVSS v4.0 · 1 reference · NVD status: Analyzed
Waterfall WF-500 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0088   56.4     —
AFFECTED
  Product  Versions     Fixed
  WF-500   unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 29  Published (CNA: Nozomi)
CWE-78 · CNA: Nozomi · CVSS v4.0 · 1 reference · NVD status: Analyzed
Waterfall WF-500 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   P   H   H   H    8.5   .0088   56.4     —
AFFECTED
  Product  Versions     Fixed
  WF-500   unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  May 29  Published (CNA: Nozomi)
CWE-78 · CNA: Nozomi · CVSS v4.0 · 1 reference · NVD status: Analyzed
Red Hat Red Hat Enterprise Linux 10 — Libsoup: libsoup: http request smuggling via unsigned to signed conversion error
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  L  L  N    4.8   .0087   56.2     —
AFFECTED
  Product                      Versions     Fixed
  Red Hat Enterprise Linux 10  unspecified  —
  Red Hat Enterprise Linux 6   unspecified  —
  Red Hat Enterprise Linux 7   unspecified  —
  Red Hat Enterprise Linux 8   unspecified  —
  Red Hat Enterprise Linux 9   unspecified  —
TIMELINE
  Apr 14  Reserved by CNA
  May 29  Published (CNA: redhat)
CWE-444 · CNA: redhat · CVSS v3.1 · 4 references · NVD status: Awaiting Analysis
Dokploy: Remote Code Execution via destinationPath in Container File Upload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0087   55.9     —
AFFECTED
  Product  Versions     Fixed
  dokploy  <= 0.29.1 –  —
TIMELINE
  May 12  Reserved by CNA
  May 29  Published (CNA: GitHub_M)
CWE-77 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Deferred
SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  L  N    8.5   .0087   55.9     —
AFFECTED
  Product      Versions    Fixed
  SillyTavern  < 1.18.0 –  —
TIMELINE
  May 13  Reserved by CNA
  May 29  Published (CNA: GitHub_M)
CWE-918 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Deferred
TRENDnet TEW-432BRP formWPS stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0085   55.5     —
AFFECTED
  Product     Versions   Fixed
  TEW-432BRP  3.10B20 –  —
TIMELINE
  May 29  Reserved by CNA
  May 29  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Analyzed
Dokploy: Command Injection via incomplete shell escaping in docker logout (registry deletion)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0084   55.1     —
AFFECTED
  Product  Versions     Fixed
  dokploy  <= 0.29.0 –  —
TIMELINE
  May 12  Reserved by CNA
  May 29  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Deferred
TRENDnet TEW-432BRP formSetRoute stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0083   55.0     —
AFFECTED
  Product     Versions   Fixed
  TEW-432BRP  3.10B20 –  —
TIMELINE
  May 29  Reserved by CNA
  May 29  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Analyzed
n/a n/a — The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0078   53.2     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  May 29  Public exploit reference published
  May 29  Published (CNA: mitre)
CWE-22 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-456309.052.6DokploydokployCWE-78Dokploy: Authenticated Remote Code Execution via Command Injection in updateT…
CVE-2026-456299.952.4DokploydokployCWE-78Dokploy: Authenticated Remote Code Execution via Command Injection in /listen…
CVE-2026-493774.350.2JetBrainsTeamCityCWE-526In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default…
CVE-2026-449629.949.9WebProsPleskCWE-643Plesk contains an XPath injection vulnerability in the APS Application Catalo…
CVE-2026-456619.948.8DokploydokployCWE-22Dokploy: Remote Code Execution through Path Traversal
CVE-2026-457007.747.4FreeRDPFreeRDPCWE-787Heap-buffer-overflow write in planar bitmap decoder
CVE-2026-53869.147.2KMWKM-IP521CWE-620KMW CCTV Security Cameras Unverified Password Change
CVE-2026-90519.347.2NISystemLink EnterpriseCWE-306Authentication Bypass Vulnerability in NI SystemLink Enterprise
CVE-2026-100429.247.1zyddnysmanga-image-translatorCWE-502manga-image-translator RCE via Unsafe Pickle Deserialization in Share Model
CVE-2026-95599.945.2—mautic/coreCWE-22A path traversal vulnerability exists in the campaign import feature of Mauti…
CVE-2026-95589.944.6—mautic/coreCWE-1336A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's them…
CVE-2026-446509.144.4SillyTavernSillyTavernCWE-22SillyTavern: Improper Limitation of a Pathname to a Restricted Directory ('Pa…
CVE-2018-253937.144.3NavigatecmsNavigate CMSCWE-22Navigate CMS 2.8.5 Path Traversal via navigate_download.php
CVE-2026-463848.743.5iskorotkovavroCWE-190iskorotkov/avro: Integer Overflow in Avro Decoder
CVE-2026-463858.742.0iskorotkovavroCWE-400iskorotkov/avro: CPU Exhaustion in Avro Decoder
CVE-2018-253888.741.8SitejoHaPe PKHCWE-434HaPe PKH 1.1 Arbitrary File Upload via aksi_foto.php
CVE-2026-4920010.041.7AcerWave 7 routerCWE-532Acer Wave 7 router: Broken Access Control
CVE-2026-101088.741.4hanxixiaomusicCWE-22xiaomusic 0.5.7 Path Traversal via GET /music endpoint
CVE-2026-36559.841.2glboyOTP Login With Phone Number, OTP VerificationCWE-287OTP Login With Phone Number, OTP Verification <= 1.8.60 - Unauthenticated Aut…
CVE-2026-100719.341.0InterinfoDreamMakerCWE-434Interinfo|DreamMaker - Arbitrary File Upload
CVE-2026-444218.840.9FreeRDPFreeRDPCWE-122FreeRDP RDPGFX CacheToSurface heap-buffer-overflow via clamped-rectangle vali…
CVE-2025-412817.540.8WaterfallWF-500CWE-78Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special …
CVE-2026-411595.339.7mermaid-jsmermaidCWE-94Mermaid: Improper sanitization of configuration leads to CSS injection
CVE-2026-456979.838.9verbbformieCWE-94Formie: Pre-authenticated server-side template injection in Hidden fields
CVE-2026-392927.338.7n/an/aCWE-434Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload v…
CVE-2026-457316.938.5WWBNAVideoCWE-22WWBN AVideo: Authenticated Arbitrary File Read in view/update.php
CVE-2026-100728.637.6InterinfoDreamMakerCWE-434Interinfo|DreamMaker - Arbitrary File Upload
CVE-2026-493667.837.6JetBrainsIntelliJ IDEACWE-78In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via…
CVE-2026-463376.937.6WWBNAVideoCWE-22WWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view…
CVE-2026-465797.537.0Red HatRed Hat OpenShift Container Platform 4.12CWE-287Openshift/router: openshift/router: mtls client certificate spoofing via unst…
CVE-2026-485578.736.4spatielaravel-medialibraryCWE-184Spatie Laravel Media Library < 11.23.0 File Upload Restriction Bypass via Fil…
CVE-2026-100658.736.3ShibbyTomatoCWE-119Shibby Tomato tomatodata.cgi get_ups_field stack-based overflow
CVE-2026-100668.736.3ShibbyTomatoCWE-119Shibby Tomato UPS Service tomatoups.cgi sub_9068 stack-based overflow
CVE-2026-100678.736.3ShibbyTomatoCWE-119Shibby Tomato multimon.cgi sub_90F0 stack-based overflow
CVE-2026-100698.736.3ShibbyTomatoCWE-400Shibby Tomato miniupnpd resource consumption
CVE-2025-412688.836.2WaterfallWF-500CWE-23Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Admi…
CVE-2025-412718.736.0WaterfallWF-500CWE-23Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Cons…
CVE-2026-444228.835.6FreeRDPFreeRDPCWE-415FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and typ…
CVE-2026-463769.335.2FreePBXsecurity-reportingCWE-798FreePBX: Unauthenticated Use of Hard-Coded Credentials Vulnerability in FreeP…
CVE-2026-77869.834.3Jinan USR IOT Technology Limited (PUSR)USR-W610 RS232/485 to Wi-Fi/Ethernet ConverterCWE-798Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet …
CVE-2025-127145.333.9rankmathRank Math SEO – AI SEO Tools to Dominate SEO RankingsCWE-862Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.271 - Missing Au…
CVE-2025-412739.333.5WaterfallWF-500CWE-288Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alt…
CVE-2026-100642.132.7TRENDnetTEW-432BRPCWE-119TRENDnet TEW-432BRP formSetPortTr stack-based overflow
CVE-2026-446487.532.2SillyTavernSillyTavernCWE-613SillyTavern: Existing sessions are not invalidated after password change, all…
CVE-2026-456259.931.6getarcaneapparcaneCWE-862Arcane: Missing admin authorization on git repository endpoints allows non-ad…
CVE-2026-100756.931.5InterinfoDreamMakerCWE-36Interinfo|DreamMaker - Path Traversal
CVE-2026-411505.331.2mermaid-jsmermaidCWE-835Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS
CVE-2026-425005.331.2golang.org/x/imagegolang.org/x/image/bmp—Panic when reading out of bound palette index in golang.org/x/image/bmp
CVE-2026-446978.630.7klever-ioklever-goCWE-409Klever-Go MultiDataInterceptor: remote OOM via crafted compressed P2P payload
CVE-2026-832610.030.5Remote Spark (https://www.remotespark.com/)SparkViewCWE-23Remote Spark SparkView Path Traversal in RDP Drive Redirection leading to RCE
CVE-2025-119938.830.5sbthemesWooCommerce Infinite Scroll and Ajax PaginationCWE-502WooCommerce Infinite Scroll and Ajax Pagination <= 1.8 - Authenticated (Subsc…
CVE-2026-404256.930.3DanelecMacGregor Voyage Data Recorder (VDR) G4eCWE-552MacGregor Voyage Data Recorder (VDR) G4e Files or Directories Accessible to E…
CVE-2026-446526.930.2SillyTavernSillyTavernCWE-918SillyTavern: SSRF vulnerability in the CORS proxy middleware
CVE-2026-68248.430.0CP PlusCP-UNR-108F1 HardwareCWE-79CP Plus 8 Ch. Network Video Recorder Cross-site Scripting
CVE-2026-491968.629.7AcerPredator Connect W6xCWE-77Predator Connect W6x: Web Interface Command Injection
CVE-2026-100738.728.0InterinfoDreamMakerCWE-23Interinfo|DreamMaker - Arbitrary File Read
CVE-2026-465997.527.9golang.org/x/imagegolang.org/x/image/tiffCWE-770Excessive resource consumption in PackBits decompression in golang.org/x/imag…
CVE-2026-4563110.027.7DokploydokployCWE-798Dokploy: Pre-Auth Admin Takeover via Hardcoded Authentication Secret
CVE-2026-95098.727.7SupremaBioStar 2 (server)CWE-248Uncaught exception vulnerability in Suprema's BioStar
CVE-2026-100746.927.3InterinfoDreamMakerCWE-23Interinfo|DreamMaker - Arbitrary File Read
CVE-2026-950810.026.6SupremaBioStar 2 (server)CWE-732Incorrect Permission Assignment for Critical Resource vulnerability in Suprem…
CVE-2018-253828.825.8BylancerZechatCWE-89Zechat 1.5 SQL Injection via uname Parameter
CVE-2018-253858.825.8eregistrasi-kejuaraan-silatRegistrasi Pencak SilatCWE-89E-Registrasi Pencak Silat 18.10 SQL Injection via id_partai
CVE-2018-253868.825.8SitejoHaPe PKHCWE-89HaPe PKH 1.1 SQL Injection via id Parameter in admin/media.php
CVE-2018-253898.825.8SitejoHaPe PKHCWE-89HaPe PKH 1.1 SQL Injection via nama_kelompok Parameter
CVE-2018-253908.825.8SitejoHaPe PKHCWE-89HaPe PKH 1.1 SQL Injection via desa Parameter
CVE-2018-253948.825.8KadosKados R10 GreenBeeCWE-89Kados R10 GreenBee SQL Injection via update_release.php
CVE-2018-253958.825.8KadosKados R10 GreenBeeCWE-89Kados R10 GreenBee SQL Injection via update_feature.php
CVE-2018-253988.825.8Open ISESOpen ISES ProjectCWE-89The Open ISES Project 3.30A SQL Injection via main.php
CVE-2018-253998.825.8Open ISESOpen ISES ProjectCWE-89The Open ISES Project 3.30A SQL Injection via nearby.php
CVE-2018-254008.825.8Open ISESOpen ISES ProjectCWE-89The Open ISES Project 3.30A SQL Injection via form_post.php
CVE-2018-254018.825.8Open ISESOpen ISES ProjectCWE-89The Open ISES Project 3.30A SQL Injection via sever_graph.php
CVE-2018-254028.825.8Open ISESOpen ISES ProjectCWE-89The Open ISES Project 3.30A SQL Injection via inc_types_graph.php
CVE-2018-254038.825.8Open ISESOpen ISES ProjectCWE-89The Open ISES Project 3.30A SQL Injection via city_graph.php
CVE-2026-4919710.025.6AcerPredator Connect W6xCWE-287Predator Connect W6x: Improper Authentication
CVE-2026-493678.825.5JetBrainsIntelliJ IDEACWE-862In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via…
CVE-2018-253918.725.6SitejoHaPe PKHCWE-862HaPe PKH 1.1 Missing Authorization Allows Unauthenticated Record Deletion
CVE-2026-465278.725.1yhirosecpp-httplibCWE-476cpp-httplib: Malicious `X-Forwarded-For` Under Trusted-Proxy Configuration Tr…
CVE-2026-453527.525.1yhirosecpp-httplibCWE-20cpp-httplib DoS: Negative chunk-size in chunked Transfer-Encoding
CVE-2026-446516.924.6SillyTavernSillyTavernCWE-79SillyTavern: Reflected XSS vulnerability in the CORS proxy middleware
CVE-2026-477449.924.3shopperlabsshopperCWE-269Shopper: Authorization bypass and RBAC privilege escalation in team settings
CVE-2026-101058.724.1agno-agiagnoCWE-89agno 2.6.5 SQL Injection via ClickHouse delete_by_metadata()
CVE-2026-455788.824.0WWBNAVideoCWE-78WWBN AVideo Live: OS command injection in on_publish.php execAsync via unesca…
CVE-2018-253968.723.5HeatmiserHeatmiser Wifi ThermostatCWE-256Heatmiser Wifi Thermostat 1.7 Credential Disclosure via networkSetup.htm
CVE-2026-472668.723.3verbbformieCWE-639Formie: Unauthenticated front-end submission editing can overwrite existing s…
CVE-2026-471797.722.8getarcaneapparcaneCWE-22Arcane: Authenticated Arbitrary Host File Read via Docker Compose Include Dir…
CVE-2026-62756.422.5statcounterStatCounter – Free Real Time Visitor StatsCWE-79StatCounter <= 2.1.1 - Authenticated (Author+) Stored Cross-Site Scripting vi…
CVE-2026-445185.322.5open-quantum-safeliboqsCWE-20liboqs: XMSS Buffer Overread Bug
CVE-2026-463445.322.5open-quantum-safeliboqsCWE-125liboqs: Heap-buffer-overflow in XMSS verification path via OID-controlled par…
CVE-2026-451497.522.0juliangruberbrace-expansionCWE-400brace-expansion: Large numeric range defeats documented `max` DoS protection
CVE-2026-493727.521.8JetBrainsTeamCityCWE-918In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build…
CVE-2026-453729.921.4yhirosecpp-httplibCWE-93cpp-httplib: HTTP header value percent-decoding in server-side `parse_header`…
CVE-2026-453129.921.3infiniflowragflowCWE-1336RAGFlow: Server-Side Template Injection in Prompt Generator leads to Remote C…
CVE-2026-485019.120.8clicliCWE-863GitHub CLI tokens leak via `gh attestation` commands
CVE-2026-442388.520.8FreePBXsecurity-reportingCWE-89FreePBX: Authenticated SQL Injection via ORDER BY in CDR Reports
CVE-2026-100394.920.7shabtiFrontend Admin by DynamiAppsCWE-89Frontend Admin by DynamiApps <= 3.28.28 - Authenticated (Administrator+) SQL …
CVE-2026-89954.320.3ays-proPoll Maker by AYS – Versus Polls, Anonymous Polls, Image PollsCWE-200Poll Maker by AYS <= 6.3.7 - Authenticated (Subscriber+) Sensitive Informatio…
CVE-2026-465108.220.1kaspernjform-data-objectizerCWE-1321Prototype pollution in form-data-objectizer via bracket-notation form keys
CVE-2026-57688.819.9Fourth FrontierFrontier X Android applicationCWE-306Fourth Frontier Frontier X Mobile Application, Frontier X2 Missing Authentica…
CVE-2026-100686.919.7ShibbyTomatoCWE-918Shibby Tomato SUBSCRIBE Call miniupnpd send server-side request forgery
CVE-2018-253927.119.1TalagasoftMaxOn ERPCWE-89MaxOn ERP Software 8.x-9.x SQL Injection via nomor Parameter
CVE-2026-92436.419.2posimyththemesThe Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerceCWE-79The Plus Addons for Elementor <= 6.4.15 - Authenticated (Contributor+) Stored…
CVE-2026-21285.319.2cloudwaysBreeze CacheCWE-200Breeze Cache <= 2.5.2 - Unauthenticated Exposure of Sensitive Information to …
CVE-2026-442397.619.1FreePBXsecurity-reportingCWE-98FreePBX: Authenticated Local File Inclusion in Dashboard Module
CVE-2018-254048.818.7Open ISESOpen ISES ProjectCWE-89The Open ISES Project 3.30A SQL Injection via add_facnote.php
CVE-2026-442857.717.7labringFastGPTCWE-918FastGPT: SSRF Protection Bypass via `externalFile` in Dataset Preview API
CVE-2026-4920110.017.6AcerWave 7 routerCWE-798Acer Wave 7 router: Hardcoded Cryptographic Key
CVE-2026-493718.217.6JetBrainsTeamCityCWE-79In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was…
CVE-2026-455826.517.5czlonkowskin8n-mcpCWE-201n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-sh…
CVE-2026-94937.117.2BankPro E-Service TechnologyService CenterCWE-639BankPro E-Service Technology|Service Center - Insecure Direct Object Reference
CVE-2026-42909.117.1WPTravelWP Travel ProCWE-862WP Travel Pro <= 10.6.0 - Missing Authorization to Unauthenticated Arbitrary …
CVE-2026-477408.117.1shopperlabsshopperCWE-285Shopper: Authorization bypass in multiple Livewire admin components
CVE-2026-493866.517.1JetBrainsYouTrackCWE-639In JetBrains YouTrack before 2026.1.13570 improper access control allowed enu…
CVE-2026-429656.517.0Red HatRed Hat OpenShift Container Platform 4.2CWE-918Openshift/router: openshift/router: cloud metadata ssrf via fqdn-typed endpoi…
CVE-2026-493796.517.0JetBrainsTeamCityCWE-522In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
CVE-2026-456329.916.9DokploydokployCWE-78Dokploy: Schedule Authorization Bypass Enables Host/Server Command Execution
CVE-2026-356748.716.5OpenClawOpenClawCWE-863OpenClaw < 2026.5.18 - Scope Bypass via Inherited chat.send Route
CVE-2026-101077.016.1jxxghpMoviePilotCWE-918MoviePilot v2 SSRF via /api/v1/system/img/{proxy} Endpoint
CVE-2026-455776.916.0markmhendricksonneotomaCWE-288Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth…
CVE-2026-493707.515.8JetBrainsYouTrackCWE-201In JetBrains YouTrack before 2026.1.13162 information disclosure was possible…
CVE-2026-485555.315.9spatielaravel-medialibraryCWE-918Spatie Laravel Media Library < 11.23.0 SSRF via addMediaFromUrl()
CVE-2026-471258.815.5getarcaneapparcaneCWE-862Arcane: Missing admin authorization on global variables endpoint
CVE-2026-74304.415.3saadiqbalPost Snippets – Custom WordPress Code Snippets CustomizerCWE-79Post Snippets <= 4.0.19 - Authenticated (Administrator+) Stored Cross-Site Sc…
CVE-2026-100567.515.0Network OptixNx Witness VMSCWE-942CORS misconfiguration in Nx Witness VMS allows session token exfiltration via…
CVE-2025-112627.215.1linkwhsprLink Whisper FreeCWE-79Link Whisper Free <= 0.9.0 - Unauthenticated Stored Cross-Site Scripting
CVE-2026-392296.514.9n/an/aCWE-89Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the c…
CVE-2026-329058.714.7OpenClawOpenClawCWE-862OpenClaw < 2026.5.4 - Unauthorized Device-Pairing Bootstrap Code Issuance via…
CVE-2026-442876.314.7labringFastGPTCWE-94FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*\(/ is bypass…
CVE-2026-477415.914.7shopperlabsshopperCWE-362Shopper: Race condition on Discount.usage_limit allows silent over-redemption
CVE-2026-341275.314.8TP-Link Systems Inc.TL-SG108PE v5CWE-79Stored Cross-Site Scripting (XSS) via Configuration File Import on TP-Link's …
CVE-2026-457078.114.3czlonkowskin8n-mcpCWE-284n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials…
CVE-2026-493747.614.1JetBrainsTeamCityCWE-862In JetBrains TeamCity before 2026.1 improper permission checks exposed build …
CVE-2026-456289.613.5DokploydokployCWE-20Dokploy: Command Injection via Unescaped Branch Fields in Deployment Pipeline
CVE-2026-455515.113.5IntermeshgroupofficeCWE-79Group-Office: Authenticated Stored XSS in Administrator Context via Arbitrary…
CVE-2026-485278.713.3haxthewebhaxcms-nodejsCWE-79HaxCMS has a stored Cross-Site Scripting (XSS) bypass in saveNode endpoint
CVE-2026-451512.913.2nanomqnanomqCWE-476NanoMQ: NULL Pointer Dereference
CVE-2026-450439.313.1rustfsrustfsCWE-269RustFS: ImportIam Allows Creation of Backdoor Service Accounts Under Any Pare…
CVE-2026-429298.713.1DanelecMacGregor Voyage Data Recorder (VDR) G4eCWE-798MacGregor Voyage Data Recorder (VDR) G4e Use of Hard-coded Credentials
CVE-2026-429418.713.1DanelecMacGregor Voyage Data Recorder (VDR) G4eCWE-1392MacGregor Voyage Data Recorder (VDR) G4e Use of Default Credentials
CVE-2026-439175.313.0DokploydokployCWE-639Dokploy: Cross-Organization IDOR - Multiple tRPC endpoints missing activeOrga…
CVE-2026-47767.112.8—mautic/coreCWE-89An SQL injection vulnerability exists in Mautic's API contact filtering mecha…
CVE-2026-493756.112.7JetBrainsTeamCityCWE-79In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on …
CVE-2026-477426.512.4shopperlabsshopperCWE-862Shopper: Missing authorization on Product admin Livewire sub-form components
CVE-2026-477456.512.4shopperlabsshopperCWE-862Shopper: Missing per-action authorization on PaymentMethods, Currencies and C…
CVE-2026-493856.512.4JetBrainsYouTrackCWE-862In JetBrains YouTrack before 2026.1.13570 improper access control allowed low…
CVE-2026-493784.312.2JetBrainsTeamCityCWE-862In JetBrains TeamCity before 2026.1 credentials parameters were exposed via p…
CVE-2026-446499.812.0SillyTavernSillyTavernCWE-290SillyTavern: Authentication Bypass via SSO Header Injection
CVE-2026-100705.112.1macrozhengmallCWE-266macrozheng mall Super Admin Password update improper authorization
CVE-2026-493766.511.8JetBrainsTeamCityCWE-863In JetBrains TeamCity before 2026.1 insufficient username validation in the S…
CVE-2026-405101.011.8OpenSCOpenSCCWE-121OpenSC < 0.27.0-rc1 Stack Buffer Overflow via piv_process_history() in card-p…
CVE-2026-491958.711.8AcerPredator Connect W6xCWE-306Predator Connect W6x: unauthenticated Debug Service
CVE-2018-253845.111.7wikidforumWikidforumCWE-79Wikidforum 2.20 Cross-Site Scripting via reply_text Parameter
CVE-2026-98097.611.4—mautic/coreCWE-79A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects comp…
CVE-2026-493814.811.4JetBrainsTeamCityCWE-79In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was pos…
CVE-2026-60758.111.2dglingrenMedia Library AssistantCWE-352Media Library Assistant <= 3.35 - Cross-Site Request Forgery via Bulk Action …
CVE-2026-456266.311.1getarcaneapparcaneCWE-78Arcane: OS Command Injection in Volume Browser ListDirectory via path query p…
CVE-2026-452945.311.1freescout-help-deskfreescoutCWE-203FreeScout: User Account Enumeration via Password Reset Response Differentiation
CVE-2026-491988.310.8AcerPredator Connect W6xCWE-284Predator Connect W6x: MQTT Broker Access Control
CVE-2026-456096.510.7spring-ai-communitymcp-securityCWE-918mcp-security: Unvalidated URL Fetching (SSRF)
CVE-2026-356307.510.6OpenClawOpenClawCWE-862OpenClaw < 2026.5.18 - QQBot Missing Approver Identity Enforcement in Native …
CVE-2026-493685.410.6JetBrainsYouTrackCWE-79In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification …
CVE-2026-493694.310.3JetBrainsYouTrackCWE-863In JetBrains YouTrack before 2026.1.13162 information disclosure was possible…
CVE-2026-91895.310.3scottpatersonContact Form 7 – PayPal & Stripe Add-onCWE-345Contact Form 7 – PayPal & Stripe Add-on <= 2.4.9 - Unauthenticated Payment By…
CVE-2026-442377.69.9FreePBXsecurity-reportingCWE-1390FreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication By…
CVE-2026-98087.19.9—mautic/coreCWE-863An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints…
CVE-2026-456158.29.4mouse07410asn1cCWE-20mouse07410/asn1c: 1-byte Heap Out-of-Bounds Read in `INTEGER_decode_oer` via …
CVE-2026-97146.49.5creaweb2bSimple Divi ShortcodeCWE-79Simple Divi Shortcode <= 1.2 - Authenticated (Contributor+) Stored Cross-Site…
CVE-2026-100782.79.3Red HatRed Hat Quay 3CWE-598Quay/config-tool: quay/config-tool: gitlab oauth client_secret exposed in url…
CVE-2026-456205.39.0WWBNAVideoCWE-204AVideo CVE-2026-43881 incomplete fix - `objects/mention.json.php:17` is an un…
CVE-2026-100524.18.2Red HatRed Hat Quay 3CWE-918Quay/config-tool: quay/config-tool: ssrf via unfiltered ldap and smtp config …
CVE-2026-456278.28.0getarcaneapparcaneCWE-79Arcane: Unauthenticated reflected XSS via SVG color parameter in /api/app-ima…
CVE-2026-333862.38.1OpenSolutionQuickCMSCWE-79XSS in QuickCMS
CVE-2026-101016.37.8Red HatMulticluster Engine for KubernetesCWE-201Assisted-service: assisted-service: infraenv status leaks referenced pull-sec…
CVE-2018-253838.67.7CommentcamarcheFree MP3 CD RipperCWE-121Free MP3 CD Ripper 2.8 Buffer Overflow SEH DEP Bypass
CVE-2026-493846.17.7JetBrainsPyCharmCWE-79In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown …
CVE-2026-493164.17.6Indian MotorcycleScout Bobber + TechCWE-440Indian Scout Bobber 2025 WCM CAN bus-off attack silently bypasses anti-theft …
CVE-2026-100574.87.2ITP TechnologyITS Intelligent SCADA SystemCWE-79ITP Technology|ITS Intelligent SCADA System - Stored Cross-Site Scripting
CVE-2026-100584.87.2ITP TechnologyITS Intelligent SCADA SystemCWE-79ITP Technology|ITS Intelligent SCADA System - Stored Cross-Site Scripting
CVE-2018-253876.97.0SitejoHaPe PKHCWE-352HaPe PKH 1.1 Cross-Site Request Forgery via aksi_user.php
CVE-2026-493244.16.9Indian MotorcycleScout Bobber + TechCWE-307Indian Scout Bobber 2025 WCM brute-force
CVE-2026-98115.46.7—mautic/coreCWE-79A stored Cross-Site Scripting (XSS) vulnerability exists in the project selec…
CVE-2026-329062.36.8OpenClawOpenClawCWE-863OpenClaw < 2026.5.12 - Privilege Escalation in Slack Plugin Approvals via Exe…
CVE-2026-98316.36.7Extreme NetworksExtreme Platform ONECWE-362ExtremeCloud IQ Cross Tenant Data Exposure via Extreme Platform One Authentic…
CVE-2026-456689.36.5TriliumNextTriliumCWE-22Trilium Notes : Note Import to RCE via #docName Path Traversal (Safe Import E…
CVE-2026-493806.16.5JetBrainsTeamCityCWE-601In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was poss…
CVE-2026-429515.96.3DanelecMacGregor Voyage Data Recorder (VDR) G4eCWE-522MacGregor Voyage Data Recorder (VDR) G4e Insufficiently Protected Credentials
CVE-2018-253976.95.5joeyrushPHP-SHOP masterCWE-352PHP-SHOP 1.0 Cross-Site Request Forgery via users.php
CVE-2026-476945.45.6WWBNAVideoCWE-79WWBN AVideo: Stored XSS via unescaped Gallery category description
CVE-2026-493254.15.4Indian MotorcycleScout Bobber + TechCWE-693Indian Scout Bobber 2025 WCM voltage-based shutdown
CVE-2025-140426.45.3themesuiteAutomotive Car Dealership Business WordPress ThemeCWE-79Automotive Car Dealership Business WordPress Theme <= 13.4.1 - Authenticated …
CVE-2026-363246.14.8n/an/aCWE-79SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scri…
CVE-2026-356735.94.9OpenClawOpenClawCWE-863OpenClaw < 2026.4.29 - SSRF Policy Bypass via Browser Debug/Export Routes
CVE-2026-488104.34.9freescout-help-deskfreescoutCWE-285FreeScout: Thread Edit Authorization Bypass via Missing Mailbox Check
CVE-2026-488114.34.9freescout-help-deskfreescoutCWE-862FreeScout: Thread Deletion Bypasses Mailbox Access Revocation
CVE-2026-333844.84.8OpenSolutionQuickCMSCWE-384Session Fixation in QuickCMS
CVE-2026-456605.44.5statamiccmsCWE-918Statamic: Server-Side Request Forgery via Glide
CVE-2026-345072.34.2OpenClawOpenClawCWE-863OpenClaw < 2026.4.29 - Policy Bypass in QQBot Admin Commands via DM-only and …
CVE-2025-412807.54.1WaterfallWF-500CWE-23Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) …
CVE-2026-95576.44.1—mautic/coreCWE-918A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus c…
CVE-2026-405281.04.1OpenSCOpenSCCWE-121OpenSC < 0.27.0 Buffer Overrun in do_key_value() via profile.c
CVE-2026-471237.54.0freescout-help-deskfreescoutCWE-290FreeScout: Agent Impersonation via Missing HMAC Verification on Notification …
CVE-2026-455557.83.8MarcelRoozekransroslyn-codelens-mcpCWE-94Roslyn CodeLens MCP Server: Untrusted Roslyn Analyzer Execution via get_diagn…
CVE-2026-493171.03.8Indian MotorcycleScout Bobber + TechCWE-636Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM …
CVE-2026-493181.03.8Indian MotorcycleScout Bobber + TechCWE-636Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM …
CVE-2026-446115.93.7DanelecMacGregor Voyage Data Recorder (VDR) G4eCWE-916MacGregor Voyage Data Recorder (VDR) G4e Use of Password Hash With Insufficie…
CVE-2026-446988.33.3home-assistantcoreCWE-94Home Assistant: Cross-origin iframe access token exfiltration via WebView JS …
CVE-2026-456196.53.2WWBNAVideoCWE-367AVideo CVE-2026-43884 incomplete fix - `isSSRFSafeURL()` call sites still dis…
CVE-2026-455805.43.2WWBNAVideoCWE-79WWBN AVideo Live: stored XSS via unescaped stream key in modeYoutubeLive.php …
CVE-2026-493827.83.2JetBrainsIntelliJ IDEACWE-1336In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via temp…
CVE-2026-74807.33.2ASUSASUS System Control InterfaceCWE-732An Incorrect Permission Assignment for Critical Resource vulnerability in ASU…
CVE-2026-43872.03.0StrongDMStrongDM Desktop ApplicationCWE-312Unencrypted storage of authentication state in StrongDM Desktop Application s…
CVE-2026-100995.12.4XX-netXX-NetCWE-1286XX-Net V5.16.6 WebSocket Frame Parsing Data Corruption via simple_http_server.py
CVE-2026-68925.12.3Canon Inc.Canon PIXUS iX6800 Series CUPS Printer Driver for macOSCWE-59Improper handling of symbolic links in the installer of CUPS Printer Driver f…
CVE-2025-412787.52.1WaterfallWF-500CWE-125Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF…
CVE-2026-476967.12.0WWBNAVideoCWE-345WWBN AVideo: Authenticated wallet credit bypass in AuthorizeNet processPaymen…
CVE-2026-456133.31.5rizinorgrizinCWE-125Rizin: Heap-buffer-overflow in OMF parser
CVE-2026-456106.51.4WWBNAVideoCWE-306WWBN AVideo plugin/LoginControl/set.json.php: 2FA toggle endpoint has no CSRF…
CVE-2026-493833.31.3JetBrainsIntelliJ IDEACWE-611In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser w…
CVE-2026-493234.11.2Indian MotorcycleScout Bobber + TechCWE-327Indian Scout Bobber 2025 WCM-to-ECM weak authentication
CVE-2026-493224.11.1Indian MotorcycleScout Bobber + TechCWE-294Indian Scout Bobber 2025 Infotainment-to-WCM weak authentication allows recov…
CVE-2026-453243.31.0rizinorgrizinCWE-415Rizin: Double free in cmd_search.c
CVE-2026-446404.50.8nanomqnanomqCWE-843NanoMQ: QUIC Dialer Close Type Confusion
CVE-2026-80707.30.5ASUSArmoury CrateCWE-732Incorrect permission assignment for a critical resource in Armoury Crate allo…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-05-29 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.