boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Sunday, June 7, 2026 · all times UTC← 2026-06-06 · archive · 2026-06-08 →

Security Box Score — June 7, 2026

23 CVEs published, led by GL.iNet (6).

23 CVEs published June 7, 2026: 0 critical, 1 high, 9 medium, 13 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 0 awaiting enrichment.

Standings

League
MTDYTD2025 same span2025 full
CVEs published16056066——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

260 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux3310008163028811120.27.8.0013-113 ▼
google48866358335255157750.87.8.0023+488 ▲
microsoft7543473791152286193.57.8.0047-5 ▼
red hat191138494610200.07.0.0033+14 ▲
apple05211733188713.56.2.00230
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
suse020200000.08.2.00200
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco214536056857.17.3.0566+2 ▲
fortinet07430028342.99.1.85840
ivanti16240025466.78.8.57510
checkpoint060330300.06.5.03380
zyxel230030900.06.5.0017+2 ▲
ubiquiti031200300.08.8.00680
f50220004150.09.2.39010
palo alto networks021100132100.08.6.6281-1 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache32668262923311.57.2.0052+28 ▲
mozilla4103340900.07.4.00350
gitlab0701604228.64.3.00240
docker250500000.08.8.0021+2 ▲
drupal0511304120.05.1.00260
github021100000.08.1.03470
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ibm5541326150600.07.5.0031+5 ▲
oracle028915402713.68.1.00270
progress591710600.07.5.0036+5 ▲
solarwinds25230010480.08.1.8162+2 ▲
veeam031200100.08.6.00510
adobe020200192100.08.6.03680
zohocorp020110000.07.1.01040
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5 ▲
d-link570313300.06.0.0069+5 ▲
abb440400000.07.3.0024+4 ▲
siemens120110000.07.3.0026+1 ▲
hitachi energy020020000.05.7.00140
tp-link00000010———0
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
edimax051032019100.07.4.00590
concrete cms1451101321000.06.0.0015+1 ▲
sourcecodester2244001430000.02.1.0025+22 ▲
open ises044221210000.07.1.00210
helmholz04203930000.07.1.00260
mb connect line04203930000.07.1.00260
acer2636111960000.08.7.0024+26 ▲
nvidia23582070000.07.8.0029+2 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-0257.939199.87.8
CVE-2026-43500.928599.87.8
CVE-2026-20182.915299.810.0
CVE-2026-9082.883299.89.8
CVE-2026-41089.796299.69.8
CVE-2026-42897.712099.48.1
CVE-2026-42945.680599.39.2
CVE-2026-45498.630899.17.5
CVE-2026-28318.400198.57.5
CVE-2026-44578.388798.58.6
Highest CVSS
CVECVSSEPSSNote
CVE-2026-2018210.0.9152KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4508710.0.1296
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-4399710.0.0098
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
Most disclosures (vendor)
VendorCVEs
google656
linux464
microsoft161
red hat56
ibm54
edimax51
apache49
concrete cms45
open ises44
sourcecodester44
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco8
apple7
google5
ivanti4
solarwinds4
fortinet3
smartertools3
adobe2
berriai2
Most-affected ecosystems
EcosystemAdvisories
Maven24
PyPI10
Packagist7
crates.io2
npm2
Fastest to KEV
CVEVendorDays
CVE-2025-48595Google0
CVE-2026-28318SolarWinds0
CVE-2026-34926Trend Micro, Inc.0
CVE-2026-41091Microsoft0
CVE-2026-42897Microsoft0
CVE-2026-45247Mirasvit0
CVE-2026-45321@tanstack0
CVE-2026-45498Microsoft0
CVE-2026-48027nrwl0
CVE-2026-48172LiteSpeed Technologies0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171663
CVE-2021-27102n/a2021-11-171663
CVE-2021-27101n/a2021-11-171663
CVE-2021-27103n/a2021-11-171663
CVE-2021-21017Adobe2021-11-171663
CVE-2021-28550Adobe2021-11-171663
CVE-2021-42013Apache Software Foundation2021-11-171663
CVE-2021-41773Apache Software Foundation2021-11-171663
CVE-2021-30858Apple2021-11-171663
CVE-2021-30860Apple2021-11-171663

Transactions

DUE DATE PASSED — CVE-2026-45247 (Mirasvit Full Page Cache Warmer for Magento 2). CISA remediation deadline was June 6, 2026; still in catalog.

Yesterday's Results

How to read these box scores · glossary

23 CVEs published. 23 box scores, 0 table rows — nothing truncated.

GL.iNet GL-MT3000 FTP Protocol glc snprintf command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    6.9   .0203   79.5     —
AFFECTED
  Product    Versions  Fixed
  GL-MT3000  4.4.5 –   4.8.1
TIMELINE
  Jun 6   Reserved by CNA
  Jun 7   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
GL.iNet GL-MT3000 SET_USER_PWD glc FUN_0042e200 command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    6.9   .0168   75.1     —
AFFECTED
  Product    Versions  Fixed
  GL-MT3000  4.4.0 –   4.8.1
TIMELINE
  Jun 6   Reserved by CNA
  Jun 7   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
GL.iNet GL-MT3000 Minidlna Service rpc realpath command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   L   L   L    5.1   .0158   73.6     —
AFFECTED
  Product    Versions  Fixed
  GL-MT3000  4.4.0 –   4.7
TIMELINE
  Jun 6   Reserved by CNA
  Jun 7   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
GL.iNet GL-MT3000 Path Normalization dlopen command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    6.9   .0157   73.5     —
AFFECTED
  Product    Versions  Fixed
  GL-MT3000  4.4.5 –   4.7
TIMELINE
  Jun 6   Reserved by CNA
  Jun 7   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
GL.iNet GL-MT3000 LuCI JSON-RPC rpc rpc_sys command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    5.3   .0110   63.2     —
AFFECTED
  Product    Versions  Fixed
  GL-MT3000  4.4.5 –   4.8.1
TIMELINE
  Jun 6   Reserved by CNA
  Jun 7   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
GL.iNet GL-MT3000 MTK Backend iwinfo.so iwinfo_backend command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0107   62.4     —
AFFECTED
  Product    Versions  Fixed
  GL-MT3000  4.4.0 –   4.7
TIMELINE
  Jun 6   Reserved by CNA
  Jun 7   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
FoundationAgents MetaGPT common.py check_cmd_exists command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   L   N   L   L   L    1.3   .0094   58.1     —
AFFECTED
  Product  Versions  Fixed
  MetaGPT  0.8.0 –   —
TIMELINE
  Jun 6   Reserved by CNA
  Jun 7   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
Xcitium Client Security / Comodo Internet Security Remote Denial of Service
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0054   43.1     —
AFFECTED
  Product                        Versions     Fixed
  Comodo Internet Security       unspecified  —
  Xcitium Client Security (XCS)  unspecified  —
TIMELINE
  May 31  Reserved by CNA
  Jun 7   Published (CNA: VulnCheck)
CWE-191 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
erzhongxmu JeeWMS JimuReport test-connection Endpoint testConnection injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0033   25.2     —
AFFECTED
  Product  Versions                                    Fixed
  JeeWMS   141740afb2ba14d441c82a833d0a418d07ca2d69 –  —
TIMELINE
  Jun 6   Reserved by CNA
  Jun 7   Published (CNA: VulDB)
CWE-74, CWE-707 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
jishenghua jshERP addAccountHeadAndDetail Endpoint AccountHeadService.java path traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   L   L    2.1   .0032   24.5     —
AFFECTED
  Product  Versions  Fixed
  jshERP   3.0 –     —
TIMELINE
  Jun 7   Reserved by CNA
  Jun 7   Published (CNA: VulDB)
CWE-22 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
USCiLab Cereal Shared Pointer type confusion
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   L   L   L    2.9   .0031   23.5     —
AFFECTED
  Product  Versions  Fixed
  Cereal   1.3.0 –   —
TIMELINE
  Jun 7   Reserved by CNA
  Jun 7   Published (CNA: VulDB)
CWE-843 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
Boost Serialization improper validation of specified type of input
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   L   L   L    2.9   .0031   23.2     —
AFFECTED
  Product        Versions  Fixed
  Serialization  1.0 –     —
TIMELINE
  Jun 7   Reserved by CNA
  Jun 7   Published (CNA: VulDB)
CWE-20, CWE-1287 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Chengdu Everbrite Network Technology BeikeShop Stripe Plugin StripeController.php callback improper authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0029   21.4     —
AFFECTED
  Product    Versions   Fixed
  BeikeShop  1.6.0.0 –  —
TIMELINE
  Jun 7   Reserved by CNA
  Jun 7   Published (CNA: VulDB)
CWE-266, CWE-285 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
erzhongxmu JeeWMS Boot Actuator Endpoint actuator information disclosure
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    5.5   .0029   21.2     —
AFFECTED
  Product  Versions                                    Fixed
  JeeWMS   141740afb2ba14d441c82a833d0a418d07ca2d69 –  —
TIMELINE
  Jun 6   Reserved by CNA
  Jun 7   Published (CNA: VulDB)
CWE-200, CWE-284 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Chanjet CRM HTTP GET Request jxf_dump_systable.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0026   17.3     —
AFFECTED
  Product  Versions  Fixed
  CRM      1.0 –     —
TIMELINE
  Jun 6   Reserved by CNA
  Jun 7   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
zilliztech deep-searcher collection_router.py CollectionRouter.invoke access control
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   N   L    2.1   .0025   16.4     —
AFFECTED
  Product        Versions  Fixed
  deep-searcher  0.0.1 –   —
TIMELINE
  Jun 7   Reserved by CNA
  Jun 7   Published (CNA: VulDB)
CWE-266, CWE-284 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
jishenghua jshERP platformConfig Add Endpoint PlatformConfigService.java insertPlatformConfig server-side request forgery
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   L   L   L    2.0   .0023   13.8     —
AFFECTED
  Product  Versions  Fixed
  jshERP   3.0 –     —
TIMELINE
  Jun 7   Reserved by CNA
  Jun 7   Published (CNA: VulDB)
CWE-918 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
NousResearch hermes-agent resume Endpoint hermes_state.py resolve_session_by_title authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0022   12.9     —
AFFECTED
  Product       Versions  Fixed
  hermes-agent  0.1 –     —
TIMELINE
  Jun 7   Reserved by CNA
  Jun 7   Published (CNA: VulDB)
CWE-285, CWE-639 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
n/a JeecgBoot — JeecgBoot User List Endpoint SysUserController.java queryPageList information disclosure
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   L   N   L   N   N    1.3   .0022   12.4     —
AFFECTED
  Product    Versions  Fixed
  JeecgBoot  3.9.0 –   —
TIMELINE
  Jun 7   Reserved by CNA
  Jun 7   Published (CNA: VulDB)
CWE-200, CWE-284 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
songquanpeng one-api Redemption Code Top-Up Endpoint redemption.go Redeem logic error
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   L   N   N   L   N    1.3   .0022   12.3     —
AFFECTED
  Product  Versions            Fixed
  one-api  0.6.11-preview.0 –  —
TIMELINE
  Jun 7   Reserved by CNA
  Jun 7   Published (CNA: VulDB)
CWE-840 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
SourceCodester Hospitals Patient Records Management System page room_types cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   P   N   L   N    1.9   .0021   11.6     —
AFFECTED
  Product                                      Versions  Fixed
  Hospitals Patient Records Management System  1.0 –     —
TIMELINE
  Jun 7   Reserved by CNA
  Jun 7   Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Tiobon Employee Self-Service System Login Endpoint BlogSearch.aspx sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0019    8.9     —
AFFECTED
  Product                       Versions  Fixed
  Employee Self-Service System  7.0 –     —
TIMELINE
  Jun 6   Reserved by CNA
  Jun 7   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
SecureAge CatchPulse IOCTL saappctl.sys information disclosure
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   N   N    1.9   .0011    1.2     —
AFFECTED
  Product     Versions  Fixed
  CatchPulse  10.9.0 –  —
TIMELINE
  Jun 6   Reserved by CNA
  Jun 7   Published (CNA: VulDB)
CWE-200, CWE-284 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-07 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.