boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, June 2, 2026 · all times UTC← 2026-06-01 · archive · 2026-06-03 →

Security Box Score — June 2, 2026

225 CVEs published, led by Dräger (13).

225 CVEs published June 2, 2026: 14 critical, 85 high, 97 medium, 29 low; 1 in the KEV catalog at press time; 25 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 200 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published6015062——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

199 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux19687961727111120.27.8.0013-60 ▼
microsoft1537463751142286193.57.8.0047+1 ▲
google612361115361117752.18.1.0021+61 ▲
red hat599839439200.06.7.0037+5 ▲
apple05211733188713.56.2.00230
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
suse020200000.08.2.00200
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco012534056866.77.8.15760
fortinet07430028342.99.1.85840
ivanti16240025466.78.8.5751+1 ▲
checkpoint060330300.06.5.03380
zyxel230030900.06.5.0017+2 ▲
ubiquiti031200300.08.8.00680
f50220004150.09.2.39010
palo alto networks021100132100.08.6.62810
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache30646262923311.66.8.0053+30 ▲
mozilla4103340900.07.4.0035+4 ▲
gitlab0701604228.64.3.00240
drupal0511304120.05.1.00260
docker140400000.08.8.0022+1 ▲
github021100000.08.1.03470
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ibm5541326150600.07.5.0031+5 ▲
oracle028915402713.68.1.00270
progress591710600.07.5.0036+5 ▲
solarwinds14220010375.08.9.8262+1 ▲
veeam031200100.08.6.00510
adobe020200192100.08.6.03680
zohocorp020110000.07.1.01040
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology01823103000.05.6.00250
d-link240310300.07.4.0054+2 ▲
siemens120110000.07.3.0026+1 ▲
hitachi energy020020000.05.7.00140
tp-link00000010———0
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
edimax051032019100.07.4.00590
concrete cms044191321000.05.7.00150
open ises044221210000.07.1.00210
helmholz04203930000.07.1.00260
mb connect line04203930000.07.1.00260
sourcecodester1537001126000.02.1.0025+15 ▲
nvidia23582070000.07.8.0029+2 ▲
totolink03502609000.08.9.01910

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-0257.939199.87.8
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2026-20182.915299.810.0
CVE-2026-42208.894299.89.3
CVE-2026-9082.883299.89.8
CVE-2026-42271.835499.78.7
CVE-2026-41089.796299.69.8
CVE-2026-42897.712099.48.1
CVE-2026-42945.680599.39.2
Highest CVSS
CVECVSSEPSSNote
CVE-2026-2018210.0.9152KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4508710.0.1296
CVE-2026-805410.0.0158
CVE-2026-4919910.0.0134
CVE-2026-4399710.0.0098
CVE-2026-4282610.0.0084
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
Most disclosures (vendor)
VendorCVEs
linux581
google229
microsoft167
ibm54
apache51
edimax51
red hat47
concrete cms44
open ises44
helmholz42
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco8
apple7
google5
ivanti4
fortinet3
smartertools3
solarwinds3
adobe2
berriai2
Most-affected ecosystems
EcosystemAdvisories
Maven23
Packagist7
PyPI3
crates.io2
npm2
Fastest to KEV
CVEVendorDays
CVE-2025-48595Google0
CVE-2026-34926Trend Micro, Inc.0
CVE-2026-41091Microsoft0
CVE-2026-42208BerriAI0
CVE-2026-42897Microsoft0
CVE-2026-45321@tanstack0
CVE-2026-45498Microsoft0
CVE-2026-48027nrwl0
CVE-2026-48172LiteSpeed Technologies0
CVE-2026-9082Drupal0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171658
CVE-2021-27102n/a2021-11-171658
CVE-2021-27101n/a2021-11-171658
CVE-2021-27103n/a2021-11-171658
CVE-2021-21017Adobe2021-11-171658
CVE-2021-28550Adobe2021-11-171658
CVE-2021-42013Apache Software Foundation2021-11-171658
CVE-2021-41773Apache Software Foundation2021-11-171658
CVE-2021-30858Apple2021-11-171658
CVE-2021-30860Apple2021-11-171658

Transactions

EXPLOIT PUBLISHED — open-telemetry opentelemetry-ebpf-instrumentation: 10 CVEs (CVE-2026-45676, CVE-2026-45678, CVE-2026-45679, CVE-2026-45680, CVE-2026-45681, CVE-2026-45682, CVE-2026-45683, CVE-2026-45684, CVE-2026-45685, CVE-2026-45686). Public exploit references added.

EXPLOIT PUBLISHED — danny-avila LibreChat: 3 CVEs (CVE-2026-32625, CVE-2026-44653, CVE-2026-44654). Public exploit references added.

EXPLOIT PUBLISHED — elixir-tesla tesla: 3 CVEs (CVE-2026-48594, CVE-2026-48595, CVE-2026-48596). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-3198 (mlflow/mlflow). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-3514 (prefecthq/prefect). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-35482 (alfio-event alf.io). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-42073 (Gitlawb openclaude). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-42074 (Gitlawb openclaude). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-49443 (goauthentik authentik). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-49448 (goauthentik authentik). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-5422 (jupyter/jupyter). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-7299 (Appsmith). Public exploit reference added.

DUE DATE PASSED — CVE-2026-0257 (Palo Alto Networks PAN-OS). CISA remediation deadline was June 1, 2026; still in catalog.

Yesterday's Results

How to read these box scores · glossary

225 CVEs published. 25 box scores, 200 table rows — nothing truncated.

Google Android — Android Framework
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   N  U  H  H  H    8.4   .0171   75.6   YES
AFFECTED
  Product  Versions   Fixed
  Android  16-qpr2 –  —
TIMELINE
  May 22  Reserved by CNA
  Jun 2   Added to CISA KEV, due Jun 5
  Jun 2   Published (CNA: google_android)
CWE-190 · CNA: google_android · CVSS v3.1 · 2 references · NVD status: Analyzed · KEV due June 5, 2026
danny-avila LibreChat — LibreChat Exfiltrates Server Secrets via MCP Server URL Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  N    9.6   .0294   86.1     —
AFFECTED
  Product    Versions       Fixed
  LibreChat  < 0.8.4-rc1 –  —
TIMELINE
  Mar 12  Reserved by CNA
  Jun 2   Public exploit reference published
  Jun 2   Published (CNA: GitHub_M)
CWE-200 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Analyzed
ARMember Premium <= 7.3.1 - Unauthenticated SQL Injection via 'order' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0138   70.1     —
AFFECTED
  Product                                                                                               Versions     Fixed
  ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup  unspecified  —
TIMELINE
  Mar 28  Reserved by CNA
  Jun 2   Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
themeum Kirki – Freeform Page Builder, Website Builder & Customizer — Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0128   67.8     —
AFFECTED
  Product                                                      Versions  Fixed
  Kirki – Freeform Page Builder, Website Builder & Customizer  6.0.0 –   —
TIMELINE
  May 9   Reserved by CNA
  Jun 2   Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
elunez eladmin Application Deployment App.java command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0107   62.2     —
AFFECTED
  Product  Versions  Fixed
  eladmin  2.0 –     —
TIMELINE
  Jun 1   Reserved by CNA
  Jun 2   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
maziyarpanahi openmed — OpenMed < 1.5.2 Remote Code Execution via PII Model Loading
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0092   57.4     —
AFFECTED
  Product  Versions     Fixed
  openmed  unspecified  —
TIMELINE
  May 18  Reserved by CNA
  Jun 2   Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
Mozilla Firefox — JIT miscompilation in the JavaScript Engine: JIT component
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  N  N  L    4.3   .0086   55.6     —
AFFECTED
  Product  Versions     Fixed
  Firefox  unspecified  151.0.3
TIMELINE
  Jun 2   Reserved by CNA
  Jun 2   Published (CNA: mozilla)
CWE-843, CWE-733 · CNA: mozilla · CVSS v3.1 · 5 references · NVD status: Modified
n/a n/a — A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmwar…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0072   51.2     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 2   Published (CNA: mitre)
CWE-22 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Modified
jhorowitz Content Visibility for Divi Builder — Content Visibility for Divi Builder <= 4.02 - Authenticated (Contributor+) Remote Code Execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0071   50.7     —
AFFECTED
  Product                              Versions     Fixed
  Content Visibility for Divi Builder  unspecified  —
TIMELINE
  Feb 3   Reserved by CNA
  Jun 2   Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · CVSS v3.1 · 3 references · NVD status: Deferred
Spacelabs Healthcare Sentinel 10.5.x < 11.6.0 Unauthenticated RCE via .NET Remoting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0066   49.0     —
AFFECTED
  Product   Versions  Fixed
  Sentinel  10.5.0 –  —
TIMELINE
  Jan 5   Reserved by CNA
  Jun 2   Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Deferred
AWS Kiro IDE — Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   H   H   H    8.6   .0066   48.9     —
AFFECTED
  Product   Versions     Fixed
  Kiro IDE  unspecified  —
TIMELINE
  Jun 1   Reserved by CNA
  Jun 2   Published (CNA: AMZN)
CWE-732 · CNA: AMZN · CVSS v4.0 · 2 references · NVD status: Analyzed
n/a n/a — A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpo…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0060   46.0     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Mar 4   Reserved by CNA
  Jun 2   Published (CNA: mitre)
CWE-120 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Modified
Go standard library crypto/x509 — Inefficient candidate hostname parsing in crypto/x509
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  N  L  H    6.5   .0059   45.6     —
AFFECTED
  Product      Versions     Fixed
  crypto/x509  unspecified  —
TIMELINE
  Feb 17  Reserved by CNA
  Jun 2   Published (CNA: Go)
CWE-606 · CNA: Go · CVSS v3.1 · 75 references · NVD status: Awaiting Analysis
Gitlawb openclaude — OpenClaude: Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` Input
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0059   45.5     —
AFFECTED
  Product     Versions   Fixed
  openclaude  < 0.5.1 –  —
TIMELINE
  Apr 23  Reserved by CNA
  Jun 2   Public exploit reference published
  Jun 2   Published (CNA: GitHub_M)
CWE-284, CWE-306 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Analyzed
Go standard library mime — Quadratic complexity in WordDecoder.DecodeHeader in mime
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0056   44.1     —
AFFECTED
  Product  Versions     Fixed
  mime     unspecified  —
TIMELINE
  Apr 28  Reserved by CNA
  Jun 2   Published (CNA: Go)
CWE-407 · CNA: Go · CVSS v3.1 · 4 references · NVD status: Awaiting Analysis
Simple SA Wirtualna Uczelnia — Server-Side Template Injection (SSTI) in Wirtualna Uczelnia
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0056   43.9     —
AFFECTED
  Product             Versions     Fixed
  Wirtualna Uczelnia  unspecified  —
TIMELINE
  Mar 31  Reserved by CNA
  Jun 2   Published (CNA: CERT-PL)
CWE-1336 · CNA: CERT-PL · CVSS v4.0 · 2 references · NVD status: Deferred
n/a n/a — A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interfac…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0052   42.0     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Mar 4   Reserved by CNA
  Jun 2   Published (CNA: mitre)
CWE-120 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Modified
SolarWinds Web Help Desk Denial-of-Service Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0052   41.9     —
AFFECTED
  Product        Versions                            Fixed
  Web Help Desk  2026.1 and all previous versions –  —
TIMELINE
  Feb 26  Reserved by CNA
  Jun 2   Published (CNA: SolarWinds)
CWE-770 · CNA: SolarWinds · CVSS v3.1 · 2 references · NVD status: Analyzed
sayan365 student-management-system improper authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0050   40.4     —
AFFECTED
  Product                    Versions  Fixed
  student-management-system  n/a –     —
TIMELINE
  Jun 2   Reserved by CNA
  Jun 2   Published (CNA: VulDB)
CWE-287 · CNA: VulDB · CVSS v4.0 · 12 references · NVD status: Deferred
elixir-tesla tesla — Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirects
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   N   N    8.2   .0049   39.7     —
AFFECTED
  Product  Versions                                    Fixed
  tesla    1.4.0 –                                     —
  tesla    2d937d5813d7cda5cd726f41824985fb655c920f –  —
TIMELINE
  May 22  Reserved by CNA
  Jun 2   Public exploit reference published
  Jun 2   Published (CNA: EEF)
CWE-178 · CNA: EEF · CVSS v4.0 · 4 references · NVD status: Analyzed
prefecthq prefecthq/prefect — Authentication Bypass in prefecthq/prefect
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0048   39.0     —
AFFECTED
  Product            Versions       Fixed
  prefecthq/prefect  unspecified –  —
TIMELINE
  Mar 4   Reserved by CNA
  Jun 2   Public exploit reference published
  Jun 2   Published (CNA: @huntr_ai)
CWE-863 · CNA: @huntr_ai · CVSS v3.0 · 2 references · NVD status: Analyzed
Progress Software Sitefinity — CWE-20: Improper Input Validation in web services in Progress Sitefinity
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  N    8.1   .0047   38.6     —
AFFECTED
  Product     Versions  Fixed
  Sitefinity  14.1.0 –  —
TIMELINE
  Apr 27  Reserved by CNA
  Jun 2   Published (CNA: ProgressSoftware)
CWE-20 · CNA: ProgressSoftware · CVSS v3.1 · 1 reference · NVD status: Analyzed
open-telemetry opentelemetry-ebpf-instrumentation — OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0046   38.1     —
AFFECTED
  Product                             Versions             Fixed
  opentelemetry-ebpf-instrumentation  >= 0.1.0, < 0.9.0 –  —
TIMELINE
  May 13  Reserved by CNA
  Jun 2   Public exploit reference published
  Jun 2   Published (CNA: GitHub_M)
CWE-20, CWE-248, CWE-704 · CNA: GitHub_M · CVSS v3.1 · 2 references · NVD status: Analyzed
elixir-tesla tesla — Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compression
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   H    8.2   .0046   37.6     —
AFFECTED
  Product  Versions                                    Fixed
  tesla    0.6.0 –                                     —
  tesla    5bd90bb5cf0d15e375edc2a66fa322292940fce2 –  —
TIMELINE
  May 22  Reserved by CNA
  Jun 2   Public exploit reference published
  Jun 2   Published (CNA: EEF)
CWE-409 · CNA: EEF · CVSS v4.0 · 4 references · NVD status: Analyzed
Progress Software Sitefinity — CWE-284: Improper Access Control in web services in Progress Sitefinity
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0044   36.7     —
AFFECTED
  Product     Versions     Fixed
  Sitefinity  15.4.8623 –  —
TIMELINE
  Apr 27  Reserved by CNA
  Jun 2   Published (CNA: ProgressSoftware)
CWE-284 · CNA: ProgressSoftware · CVSS v3.1 · 1 reference · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-106228.236.6CollibraCollibra Platform (on-prem)—CVE-2026-10622
CVE-2026-73127.536.5Progress SoftwareSitefinityCWE-522CWE‑522: Insufficiently Protected Credentials in web services in Progress Sit…
CVE-2026-54228.136.2jupyterjupyter/jupyterCWE-23Path Traversal in jupyter/jupyter
CVE-2026-467186.536.1Apache Software FoundationApache CalciteCWE-470Apache Calcite: A user-controled model can load arbitrary classes, leading to…
CVE-2026-106505.535.5warmcatlibwebsocketsCWE-400warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource co…
CVE-2026-50769.834.7armemberARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signupCWE-287ARMember Premium <= 7.3.1 - Insecure Password Reset Mechanism to Unauthentica…
CVE-2026-53858.434.5glpi-projectglpiCWE-79GLPI 11.0.0 - Stored XSS in knowledge base
CVE-2026-422118.134.4remix-runreact-routerCWE-502React Router's vendored turbo-stream v2 allows arbitrary constructor invocati…
CVE-2025-534408.134.3AxiomthemesConfidantCWE-98WordPress Confidant theme <= 1.4 - Local File Inclusion vulnerability
CVE-2025-587058.134.3AxiomthemesCraftiCWE-98WordPress Crafti theme <= 1.12 - Local File Inclusion vulnerability
CVE-2026-494489.833.4goauthentikauthentikCWE-287authentik: SourceStage bypass via empty POST
CVE-2026-106217.533.1CollibraCollibra Platform (SaaS)—CVE-2026-10621
CVE-2026-106175.532.8nextlevelbuilderGoClawCWE-287nextlevelbuilder GoClaw Webhook Verification auth.go resolveAuth missing auth…
CVE-2026-491438.732.0browserstackbrowserstack-runnerCWE-94BrowserStack Runner 0.9.5 Unauthenticated RCE via /_log HTTP Handler
CVE-2026-488628.231.1elixir-mintmintCWE-770Unbounded conn.streams growth in Mint HTTP/2 client via unenforced PUSH_PROMI…
CVE-2026-497548.231.1elixir-mintmintCWE-770HTTP/2 CONTINUATION flood in Mint client via unbounded header-block accumulation
CVE-2026-306497.330.4n/an/aCWE-121Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remot…
CVE-2026-425075.329.7Go standard librarynet/textproto—Arbitrary inputs are included in errors without any escaping in net/textproto
CVE-2026-428499.328.2goauthentikauthentikCWE-79authentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeover
CVE-2026-456867.528.0open-telemetryopentelemetry-ebpf-instrumentationCWE-190OpenTelemetry eBPF Instrumentation: Memcached payload length overflow can cra…
CVE-2026-106912.128.0wonderwhy-erDesktopCommanderMCPCWE-400wonderwhy-er DesktopCommanderMCP start_search search-manager.ts redos
CVE-2026-106118.227.9mispmispCWE-287OTP bypass via plugin-based LDAP authentication in MISP when LDAP mixed authe…
CVE-2026-72018.827.4Progress SoftwareSitefinityCWE-639CWE-639: Authorization Bypass Through User-Controlled Key in web services in …
CVE-2026-485978.227.3elixir-teslateslaCWE-770Atom table exhaustion via untrusted URL scheme in Tesla.Adapter.Mint
CVE-2026-455545.326.8zauberzeugniceguiCWE-248NiceGUI: Unauthenticated log-flood DoS via trailing slash on ESM and per-comp…
CVE-2026-456787.526.7open-telemetryopentelemetry-ebpf-instrumentationCWE-20OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malfor…
CVE-2026-72995.426.6AppsmithAppsmithCWE-79CVE-2026-7299
CVE-2025-587078.126.1AxiomthemesSpinCWE-98WordPress Spin theme <= 1.8 - Local File Inclusion vulnerability
CVE-2025-588978.126.1AxiomthemesFermentioCWE-98WordPress Fermentio theme <= 1.5.0 - Local File Inclusion vulnerability
CVE-2025-688868.126.1androThemesCookiteerCWE-98WordPress Cookiteer theme <= 1.4.8 - Local File Inclusion vulnerability
CVE-2026-395528.125.8Code Supply Co.BlueprintCWE-98WordPress Blueprint theme < 1.1.5 - Local File Inclusion vulnerability
CVE-2026-395538.125.8Select-ThemesWaveRideCWE-98WordPress WaveRide theme <= 1.4 - Local File Inclusion vulnerability
CVE-2026-389679.825.6n/an/aCWE-113CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection v…
CVE-2025-693698.125.0AxiomthemesRacquetCWE-98WordPress Racquet theme <= 1.12.0 - Local File Inclusion vulnerability
CVE-2026-357166.324.5n/an/aCWE-121A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8…
CVE-2026-456807.524.1open-telemetryopentelemetry-ebpf-instrumentationCWE-400OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can…
CVE-2026-73134.924.1Progress SoftwareSitefinityCWE-522CWE‑522: Insufficiently Protected Credentials in web services in Progress Sit…
CVE-2026-414124.923.9alfio-eventalf.ioCWE-22alf.io vulnerable to Arbitrary File Read and Exfil via simpleHttpClient Exten…
CVE-2026-106075.523.5n/aDedeCMSCWE-74DedeCMS flink.php dede_htmlspecialchars sql injection
CVE-2026-106922.123.1johnhuang316code-index-mcpCWE-400johnhuang316 code-index-mcp search_code_advanced is_safe_regex_pattern redos
CVE-2026-395508.122.9Elated-ThemesAperitifCWE-502WordPress Aperitif theme <= 1.6 - PHP Object Injection vulnerability
CVE-2026-395518.122.9Elated-ThemesTöbelCWE-502WordPress Töbel theme <= 1.8.1 - PHP Object Injection vulnerability
CVE-2026-50746.522.9armemberARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signupCWE-89ARMember Premium <= 7.3.1 - Authenticated (Subscriber+) SQL Injection via 'sS…
CVE-2026-106085.522.9n/aDedeCMSCWE-74DedeCMS carbuyaction.php RemoveXSS sql injection
CVE-2026-18717.122.6TP-Link Systems Inc.Tapo C200 v5CWE-121Authenticated Stack-based Buffer Overflow in RTSP Authentication of Tapo C200
CVE-2026-389785.322.6n/an/aCWE-113transmission through 4.1.1 was found to have a clickjacking weakness in the b…
CVE-2026-107017.522.1MozillaFirefoxCWE-119Incorrect boundary conditions in the Graphics: Text component
CVE-2026-497536.322.1elixir-mintmintCWE-444HTTP response smuggling in Mint HTTP/1 client via lenient Content-Length parsing
CVE-2025-580247.522.0UnboundStudioAccordion FAQCWE-98WordPress Accordion FAQ Plugin <= 2.2.1 - Local File Inclusion Vulnerability
CVE-2026-499436.322.1NICBIRDCWE-121CZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buf…
CVE-2026-426849.321.9AhmadWP Job PortalCWE-89WordPress WP Job Portal plugin <= 2.5.1 - SQL Injection vulnerability
CVE-2026-423427.521.9remix-runreact-routerCWE-400React Router vulnerable to DoS via unbounded path expansion in __manifest end…
CVE-2026-494438.821.9goauthentikauthentikCWE-287authentik: `UserSourceConnection.user` and `GroupSourceConnection.group` are …
CVE-2026-340777.521.3remix-runreact-routerCWE-770React Router vulnerable to Denial of Service via reflected user input in sing…
CVE-2025-533458.821.3ThimPressThim CoreCWE-862WordPress Thim Core plugin <= 2.3.3 - Arbitrary Plugin Installation vulnerabi…
CVE-2026-411154.320.7Apache Software FoundationApache KafkaCWE-285Apache Kafka: Improper Authorization in CONSUMER_GROUP_DESCRIBE API
CVE-2026-456815.920.6open-telemetryopentelemetry-ebpf-instrumentationCWE-125OpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffe…
CVE-2026-349075.120.4Simple SAWirtualna UczelniaCWE-79Reflected Cross-Site Scripting (XSS) in Wirtualna Uczelnia
CVE-2024-140368.720.4DrägerCoreCWE-400Dräger Core 1.0.5 Denial of Service via Malformed SDC Message
CVE-2026-354829.120.1alfio-eventalf.ioCWE-863alf.io has an Authenticated RCE via Extension Script Sandbox Escape
CVE-2026-446536.519.4danny-avilaLibreChatCWE-201LibreChat Shared MCP Server View Leaks Decrypted Admin Secrets
CVE-2025-532099.819.4ThemeisleMasteriyo LMS PROCWE-266WordPress Masteriyo LMS PRO plugin <= 2.20.0 - Privilege Escalation Vulnerabi…
CVE-2026-485982.119.2elixir-teslateslaCWE-116CRLF injection in Tesla.Multipart disposition parameters allows multipart par…
CVE-2026-403146.919.0NamelessMCNamelessCWE-862NamelessMC: Reactions on private or blocking profile posts can be read and mo…
CVE-2026-106205.519.0code-projectsStudent Admission SystemCWE-74code-projects Student Admission System index.php sql injection
CVE-2026-401087.118.5glpi-projectglpiCWE-79GLPI Vulnerable to Stored XSS in ITIL Costs
CVE-2026-105495.318.4YandexYandex DatabaseCWE-280Privilege escalation in Yandex Database
CVE-2026-407807.518.4Liquid Web / StellarWPBookItCWE-288WordPress BookIt plugin < 2.5.4.1 - Broken Authentication vulnerability
CVE-2026-486825.918.3n/an/aCWE-125FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in …
CVE-2026-446545.718.0danny-avilaLibreChatCWE-863LibreChat: Shared-agent editor can globally delete owner's file records — bre…
CVE-2026-357176.317.5n/an/aCWE-121A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD…
CVE-2026-37226.417.0arunbasillalAuto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO)CWE-79Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Ti…
CVE-2026-395558.116.7Elated-ThemesAskkaCWE-502WordPress Askka theme <= 1.3.1 - PHP Object Injection vulnerability
CVE-2026-455537.516.7zauberzeugniceguiCWE-200NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured…
CVE-2026-420736.516.7GitlawbopenclaudeCWE-352OpenClaude's MCP OAuth Callback: State Check Bypass via error Param Leads to DoS
CVE-2026-106065.516.6n/aDedeCMSCWE-74DedeCMS Feedback feedback.php TrimMsg sql injection
CVE-2026-426707.516.4Etoile Web Design IncorporatedFive Star Restaurant ReservationsCWE-862WordPress Five Star Restaurant Reservations plugin <= 2.7.14 - Payment Bypass…
CVE-2026-450806.916.0Aiven-OpenklawCWE-200Klaw: Improper Access Control Allows Disclosure of Password Hash
CVE-2026-106612.115.8ahujasidblender-mcpCWE-74ahujasid blender-mcp server.py open injection
CVE-2026-36204.415.6takienWord ReplacerCWE-20Word Replacer <= 0.4 - Authenticated (Administrator+) Stored Cross-Site Scrip…
CVE-2026-31986.515.3mlflowmlflow/mlflowCWE-284Improper Access Control in mlflow/mlflow
CVE-2026-40806.415.2zeshanbEasy CartCWE-79Easy Cart <= 1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting v…
CVE-2026-106242.115.1SourceCodesterHuman Resource ManagementCWE-99SourceCodester Human Resource Management Employee View detailview.php resourc…
CVE-2026-40816.415.0jhdscriptZeM STLCWE-79ZeM STL <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via…
CVE-2021-44796.315.0DrägerAtlan A350CWE-1286Dräger Atlan A350 1.00 <= 1.01 DoS via Medibus Interface
CVE-2026-98448.814.8Roche Diagnosticsnavify Digital PathologyCWE-1392Vulnerability in navify® Digital Pathology
CVE-2026-485962.114.7elixir-teslateslaCWE-113CRLF injection in Tesla.Multipart.add_content_type_param/2 allows HTTP header…
CVE-2026-105672.014.51Panel-devCordysCRMCWE-791Panel-dev CordysCRM ModuleFormController ModuleFormService.java save cross s…
CVE-2026-82937.514.4UnknownReally Simple SecurityCWE-287Really Simple Security < 9.5.10.1 - Authentication Bypass via Two-Factor OTP …
CVE-2019-257236.314.4DrägerPerseus A500CWE-1286Dräger Perseus A500 2.00-2.02 DoS via Medibus Interface
CVE-2026-354475.314.3NamelessMCNamelessCWE-201NamelessMC: Private or blocking profile pages can be bypassed with direct POS…
CVE-2026-443672.714.4Aiven-OpenklawCWE-20Klaw: user lockout due to case sensitivity inconsistency
CVE-2026-350496.514.2wireappwire-iosCWE-20wire-ios has Persistent Remote DoS via Integer Underflow
CVE-2026-354435.314.2NamelessMCNamelessCWE-862NamelessMC: Forum reactions bypass the "view own topics only" restriction
CVE-2026-405715.314.2NamelessMCNamelessCWE-862NamelessMC: Reactions on private or blocking profile posts can be modified wi…
CVE-2026-491206.313.4medplummedplumCWE-918Medplum < 5.1.14 SSRF via FHIR Subscription Endpoint
CVE-2026-105582.113.2SourceCodesterPizzafy Ecommerce SystemCWE-73SourceCodester Pizzafy Ecommerce System index.php file inclusion
CVE-2026-105592.113.2SourceCodesterPizzafy Ecommerce SystemCWE-73SourceCodester Pizzafy Ecommerce System index.php file inclusion
CVE-2026-106622.113.2ahujasidblender-mcpCWE-918ahujasid blender-mcp ZIP File server.py requests.get server-side request forgery
CVE-2026-105832.013.2nextlevelbuilderGoClawCWE-918nextlevelbuilder GoClaw TTS Configuration Endpoint tts_config.go import serve…
CVE-2026-333987.113.0NamelessMCNamelessCWE-285Authenticated users can read hidden forum posts through `/forum/get_quotes`
CVE-2026-89936.513.0Ditec a.s.D.Launcher 2CWE-74Improper URL Handler Processing in D.Launcher 2 enables NTLM Credential Discl…
CVE-2026-305866.112.9n/an/aCWE-79Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote…
CVE-2026-105651.312.8n/aOpen5GSCWE-362Open5GS NGAP Handover gmm-sm.c gmm_state_security_mode race condition
CVE-2026-106902.112.5wonderwhy-erDesktopCommanderMCPCWE-918wonderwhy-er DesktopCommanderMCP read_file filesystem.ts readFileFromUrl serv…
CVE-2026-456796.511.3open-telemetryopentelemetry-ebpf-instrumentationCWE-117OpenTelemetry eBPF Instrumentation: Redis error text is exported in span stat…
CVE-2026-352022.311.4pterodactylpanelCWE-367Pterodactyl has a database resource limit bypass via race condition in Client…
CVE-2026-401816.611.2remix-runreact-routerCWE-601React Router's same-origin redirect with path starting // causes open redirec…
CVE-2026-105291.911.1westboyCicadasCMSCWE-79westboy CicadasCMS Task Scheduling Management ScheduleJobController.java cros…
CVE-2026-491447.110.8browserstackbrowserstack-runnerCWE-22BrowserStack Runner 0.9.5 Path Traversal via _default HTTP Handler
CVE-2026-14516.110.8federicocarrararognoneCWE-79rognone <= 0.6.2 - Reflected Cross-Site Scripting via 'a' Parameter
CVE-2026-24256.110.8den-mediahiWeb Migration SimpleCWE-79hiWeb Migration Simple <= 2.0.0.1 - Reflected Cross-Site Scripting via 'new_d…
CVE-2026-74214.410.9passeumPasseum TicketingCWE-79Passeum Ticketing <= 1.0 - Authenticated (Administrator+) Stored Cross-Site S…
CVE-2026-426547.110.7WP SwingsWallet System for WooCommerceCWE-288WordPress Wallet System for WooCommerce plugin <= 2.7.5 - Broken Authenticati…
CVE-2026-319427.110.5danny-avilaLibreChatCWE-862LibreChat has IDOR in API Keys Management that allows any authenticated user …
CVE-2026-106162.110.5nextlevelbuilderGoClawCWE-862nextlevelbuilder GoClaw Team Task Completion team_tasks_lifecycle.go TeamTask…
CVE-2026-14506.110.3federicocarrararognoneCWE-79rognone <= 0.6.2 - Reflected Cross-Site Scripting via 'mode' Parameter
CVE-2019-257175.310.1DrägerInfinity DeltaCWE-538Dräger Infinity Delta/Kappa Patient Monitors Unauthenticated Log File Disclosure
CVE-2026-426697.510.0EventPrimeEventPrimeCWE-862WordPress EventPrime plugin <= 4.3.2.0 - Broken Access Control vulnerability
CVE-2025-50855.59.9ariyesWP Nano ADCWE-79wp-nano-ad <= 1.31 - Authenticated (Administrator+) Stored Cross-Site Scripti…
CVE-2026-105812.19.9n/aDedeCMSCWE-918DedeCMS download.php base64_decode server-side request forgery
CVE-2026-105682.19.8itsourcecodeFees Management SystemCWE-74itsourcecode Fees Management System manage_payment.php sql injection
CVE-2026-497825.49.6ElementorElementor Website BuilderCWE-862WordPress Elementor Website Builder plugin <= 4.1.0 - Broken Access Control v…
CVE-2026-92344.39.6ntbykJTL-Connector for WooCommerceCWE-862JTL-Connector for WooCommerce <= 2.4.1 - Missing Authorization to Authenticat…
CVE-2026-17848.89.1Red HatRed Hat OpenShift Container Platform 4.13CWE-15Ose-cluster-ingress-operator: remote code execution through haproxy configura…
CVE-2026-419185.99.1SiemensRUGGEDCOM RST2428PCWE-525A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (Al…
CVE-2019-257227.29.0DrägerSC 6002XLCWE-798Dräger SC Monitoring Devices Hard-coded Credentials and DoS
CVE-2026-23826.48.8frankpwFPW Category ThumbnailsCWE-79FPW Category Thumbnails <= 1.9.5 - Authenticated (Subscriber+) Stored Cross-S…
CVE-2026-415696.98.7goauthentikauthentikCWE-601authentik: WS-Federation wreply origin bypass can exfiltrate signed login res…
CVE-2026-332454.78.5remix-runreact-routerCWE-79React Router vulnerable to XSS in unstable RSC redirect handling via javascri…
CVE-2019-257217.18.3DrägerInfinity M300CWE-400Dräger Infinity M300 VG2.3.1 Network-Based Denial of Service
CVE-2025-533025.38.3Anton ShevchukConstructorCWE-862WordPress Constructor theme <= 1.6.5 - Broken Access Control Vulnerability
CVE-2026-322504.38.0NamelessMCNamelessCWE-79NamelessMC has Reflected Cross-Site Scripting (XSS) in id parameter of /index…
CVE-2026-95905.38.0DevolutionsServerCWE-284Improper access control in the permission validation component in Devolutions…
CVE-2026-101004.47.9pattihisSimple Custom Login PageCWE-79Simple Custom Login Page <= 1.0.3 - Authenticated (Admin+) Stored Cross-Site …
CVE-2026-472018.57.7goauthentikauthentikCWE-347authentik: XML Signature Wrapping in SAML Source ACS allows authentication as…
CVE-2026-88856.47.7marcqueraltDeMomentSomTres ShortcodesCWE-79DeMomentSomTres Shortcodes <= 1.1.1 - Authenticated (Contributor+) Stored Cro…
CVE-2026-349937.37.4aio-libsaiohttpCWE-502AIOHTTP Vulnerable to Deserialization of Untrusted Data
CVE-2026-258618.27.4QloAppsQloAppsCWE-916QloApps 1.7.0 Weak Password Hashing via MD5 in Tools.php
CVE-2026-106882.07.3ahujasidblender-mcpCWE-74ahujasid blender-mcp server.py execute_blender_code code injection
CVE-2019-257247.16.9DrägerInfinity M300CWE-400Dräger Infinity M300 VG2.x Network-Based Denial of Service
CVE-2026-106297.46.9VerizonVoLTE—CVE-2026-10629
CVE-2025-527666.56.9PrinteersPrinteers Print & ShipCWE-862WordPress Printeers Print & Ship plugin <= 1.17.0 - Broken Access Control vul…
CVE-2026-456833.86.9open-telemetryopentelemetry-ebpf-instrumentationCWE-127OpenTelemetry eBPF Instrumentation: Java TLS ioctl kprobe allows kernel memor…
CVE-2026-242377.86.8NVIDIANVTabularCWE-502NVIDIA NVTabular contains a vulnerability where an attacker could cause impro…
CVE-2026-456845.36.6open-telemetryopentelemetry-ebpf-instrumentationCWE-126OpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and…
CVE-2026-242217.86.4NVIDIANVTabularCWE-502NVIDIA NVTabular contains a vulnerability where an attacker could cause impro…
CVE-2025-156537.06.4DrägerZeus IECWE-668Dräger Zeus IE Anesthesia Workstation USB Interface Privilege Escalation
CVE-2026-415776.96.4goauthentikauthentikCWE-345authentik: SAML source does not validate Conditions, timing, or audience on a…
CVE-2026-38706.56.2ZyxelVMG4005-B50B firmwareCWE-120A buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel…
CVE-2026-38716.56.2ZyxelVMG4005-B50B firmwareCWE-120A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zy…
CVE-2026-488612.16.1elixir-mintmintCWE-93CRLF injection in HTTP/1 request line via unvalidated method in Mint
CVE-2026-335536.16.1n/an/aCWE-79Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27…
CVE-2026-273515.45.9Sekander BadshaCrew HRMCWE-862WordPress Crew HRM plugin <= 1.2.2 - Broken Access Control vulnerability
CVE-2026-456765.55.6open-telemetryopentelemetry-ebpf-instrumentationCWE-20OpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed E…
CVE-2026-456825.55.5open-telemetryopentelemetry-ebpf-instrumentationCWE-401OpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after …
CVE-2022-49928.85.4DrägerInfinity Acute Care SystemCWE-345Dräger Infinity M540 VG4.1.1 Spoofed Network Message Handling DoS/Tampering
CVE-2026-105106.14.8TECNO Mobilecom.transsion.aiassistantlifestyleCWE-79GeniexWebView XSS in com.transsion.aiassistantlifestyle
CVE-2026-407136.14.6DellThinOS 10CWE-284Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper …
CVE-2026-439655.64.5GleamGleamCWE-22Path Traversal in build/packages/packages.toml Allows Arbitrary Directory Del…
CVE-2026-326854.64.5GleamGleamCWE-22Path Traversal in gleam docs build via documentation.pages Allows Arbitrary F…
CVE-2025-533464.34.6ThimPressThim CoreCWE-862WordPress Thim Core Plugin <= 2.3.3 - Broken Access Control Vulnerability
CVE-2024-422063.14.5HCLiReflectionCWE-1395HCL iReflection Use of Third party vulnerable and outdated components issue w…
CVE-2026-472656.64.4aio-libsaiohttpCWE-346AIOHTTP vulnerable to cross-origin redirect with per-request cookies
CVE-2026-352125.34.3OpenCTI-PlatformopenctiCWE-79OpenCTI has XSS in the rendering of email-message observable body data
CVE-2025-527597.14.1UnboundStudioAccordion FAQCWE-79WordPress Accordion FAQ plugin <= 2.2.1 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-426857.14.1AhmadWP Job PortalCWE-79WordPress WP Job Portal plugin <= 2.5.1 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-332445.44.0remix-runreact-routerCWE-79React Router has stored XSS via unescaped Location header in prerendered redi…
CVE-2026-452895.33.6CloudburstMCProtocolCWE-287CloudburstMC Protocol: Partially missing validation for FULL type authenticat…
CVE-2026-105481.93.5NousResearchhermes-agentCWE-287NousResearch hermes-agent Credential Pool Synchronization credential_pool.py …
CVE-2026-95225.43.4DevolutionsServerCWE-284Improper access control in the PAM account discovery feature in Devolutions S…
CVE-2026-281165.93.2Emilia ProjectsProgress PlannerCWE-79WordPress Progress Planner plugin <= 1.9.0 - Cross Site Scripting (XSS) vulne…
CVE-2026-51915.43.1raja3cTiled Gallery Carousel Without JetPackCWE-79Tiled Gallery Carousel Without JetPack <= 3.1 - Authenticated (Contributor+) …
CVE-2019-257198.83.0DrägerInfinity Acute Care SystemCWE-924Dräger Infinity M540 VG4.1.1 Spoofing and DoS via Network Message Handling
CVE-2026-427955.13.0GleamGleamCWE-59Symlink Following in Hex Package Export Allows Embedding Files Outside Projec…
CVE-2026-84224.33.0mr_matRemove meta boxes per user roleCWE-352Remove meta boxes per user role <= 1.01 - Cross-Site Request Forgery to Setti…
CVE-2026-40714.32.9birdseedappBirdSeedCWE-352BirdSeed <= 2.2.0 - Cross-Site Request Forgery via BirdSeed Token Change
CVE-2026-97224.32.9pcisLaiser TagCWE-352Laiser Tag <= 1.2.5 - Cross-Site Request Forgery to Plugin Settings Update vi…
CVE-2026-97304.32.9jamesmugaRemove NoFollow Commenter URLCWE-352Remove NoFollow Commenter URL <= 1.0 - Cross-Site Request Forgery to Settings…
CVE-2026-95994.32.7russellrTectite FormsCWE-352Tectite Forms <= 1.3 - Cross-Site Request Forgery to Settings Update
CVE-2026-97234.32.7ddd2500Google Plus One BottomCWE-352Google Plus One Bottom <= 0.0.2 - Cross-Site Request Forgery to Plugin Settin…
CVE-2026-97324.32.7planetshakerEmergencyWP – Dead Man's switch & legacy deliveranceCWE-352EmergencyWP <= 1.4.2 - Cross-Site Request Forgery to Plugin Settings Update
CVE-2026-105281.92.4OrthancDICOM ServerCWE-119Orthanc DICOM Server DCMTK FromDcmtkBridge.cpp read stack-based overflow
CVE-2021-44788.32.2DrägerCC-Vision BasicCWE-787Dräger CC-Vision Basic and CC-Vision E-Cal Out-of-Bounds Write via Malicious …
CVE-2026-105661.92.2FoundationAgentsMetaGPTCWE-20FoundationAgents MetaGPT schema.py Message.check_instruct_content deserializa…
CVE-2026-100468.51.9BitdefenderNapoca bare-metal hypervisorCWE-787Out-of-bounds write in Napoca BIOS INT 0x15 E820 memory map handler (VA-13905)
CVE-2026-100478.51.9BitdefenderNapoca bare-metal hypervisorCWE-787Out-of-bounds write in Napoca real-mode hook handler via guest-controlled SS:…
CVE-2026-89368.21.7DockerDocker DesktopCWE-674Unbounded recursion in grpcfuse kernel module allows container to crash Docke…
CVE-2026-406197.81.7Genetec Inc.Genetec Security CenterCWE-532A high security vulnerability affecting Security Center main server installat…
CVE-2026-344605.41.6NamelessMCNamelessCWE-302NamelessMC: OAuth callback `state` is not validated, allowing login CSRF / se…
CVE-2026-107184.61.6—openSeaChestCWE-787Open Seachest/Seachest NVMe Trim (Deallocate) Vulnerability
CVE-2026-80368.41.2NINI-PALCWE-1285Local privilege escalation in NI-PAL
CVE-2021-44808.31.3DrägerProtector SoftwareCWE-732Dräger Protector Software Local Privilege Escalation via Insecure File Permis…
CVE-2021-44818.31.3DrägerProtector SoftwareCWE-732Dräger Protector Software Local Privilege Escalation via Insecure File Permis…
CVE-2026-107171.81.0—openSeaChestCWE-787Open-Seachest/Seachest show SCSI Defect List Vulnerability
CVE-2026-107191.81.0—openSeaChestCWE-787Open Seachest/Seachest NVMe show Format Descriptors Vulnerability
CVE-2026-105848.21.0AWSGraph ExplorerCWE-319HTTPS Fallback to HTTP in Graph Explorer
CVE-2026-407157.80.9DellThinOS 10CWE-284Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper …
CVE-2026-80356.90.8NINI-PALCWE-476NULL pointer dereference in NI-PAL
CVE-2025-643907.40.4SonyPS4CWE-367A privilege escalation vulnerability exists in PlayStation 4 firmware version…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-02 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.