boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, June 9, 2026 · all times UTC← 2026-06-08 · archive · 2026-06-10 →

Security Box Score — June 9, 2026

719 CVEs published, led by Microsoft (200).

719 CVEs published June 9, 2026: 37 critical, 348 high, 314 medium, 20 low; 3 in the KEV catalog at press time; 12 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 319 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published26097070——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

331 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux9510628466331411120.27.8.0013-115 ▼
microsoft207743555121706286192.67.8.0044+195 ▲
google56273765386267197760.88.1.0023+562 ▲
red hat311258515511200.06.7.0032+26 ▲
apple05211733188713.56.2.00230
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
suse020200000.08.2.00200
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
netgear171700161000.04.3.0024+17 ▲
cisco315546056960.07.5.0694+3 ▲
fortinet29432028333.38.3.0076+2 ▲
ivanti38350025450.08.8.4316+2 ▲
checkpoint2814303112.57.5.0423+2 ▲
vmware3402207125.06.7.0036+3 ▲
zyxel230030900.06.5.0017+2 ▲
ubiquiti031200300.08.8.00680
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache538712333923311.17.2.0053+49 ▲
mozilla5113440900.07.5.0032+1 ▲
gitlab0701604228.64.3.00240
docker250500000.08.8.0021+2 ▲
drupal0511304120.05.1.00260
github021100000.08.1.03470
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
adobe1231254477221921.65.5.0021+123 ▲
ibm5541326150600.07.5.0031+5 ▲
oracle129916402713.48.1.0027+1 ▲
progress591710600.07.5.0036+5 ▲
solarwinds36231010466.77.8.6082+3 ▲
veeam142200100.09.0.0052+1 ▲
zohocorp020110000.07.1.01040
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5 ▲
d-link8100325300.04.2.0055+8 ▲
siemens780440000.07.5.0020+7 ▲
abb440400000.07.3.0024+4 ▲
hitachi energy020020000.05.7.00140
schneider electric110100000.07.1.0023+1 ▲
tp-link00000010———0
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester3557002433000.02.1.0026+35 ▲
spring5354121320000.06.5.0026+53 ▲
edimax051032019100.07.4.00590
concrete cms1451101321000.06.0.0015+1 ▲
open ises044221210000.07.1.00210
helmholz04203930000.07.1.00260
mb connect line04203930000.07.1.00260
totolink338026111000.08.9.0191+3 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-0257.939199.87.8
CVE-2026-43500.928599.87.8
CVE-2026-20182.915299.810.0
CVE-2026-9082.883299.89.8
CVE-2026-50751.837799.79.3
CVE-2026-41089.796299.69.8
CVE-2026-42897.712099.48.1
CVE-2026-42945.680599.39.2
CVE-2026-45498.630899.17.5
CVE-2026-49160.538398.97.5
Highest CVSS
CVECVSSEPSSNote
CVE-2026-2018210.0.9152KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4508710.0.1296
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-4399710.0.0098
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
Most disclosures (vendor)
VendorCVEs
google730
linux526
microsoft361
adobe123
apache70
red hat68
sourcecodester57
ibm54
spring54
edimax51
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco9
apple7
google6
ivanti4
solarwinds4
berriai3
fortinet3
smartertools3
adobe2
Most-affected ecosystems
EcosystemAdvisories
Maven24
Packagist22
PyPI11
npm3
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2025-48595Google0
CVE-2026-11645Google0
CVE-2026-20245Cisco0
CVE-2026-28318SolarWinds0
CVE-2026-34926Trend Micro, Inc.0
CVE-2026-41091Microsoft0
CVE-2026-42897Microsoft0
CVE-2026-45247Mirasvit0
CVE-2026-45321@tanstack0
CVE-2026-45498Microsoft0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171665
CVE-2021-27102n/a2021-11-171665
CVE-2021-27101n/a2021-11-171665
CVE-2021-27103n/a2021-11-171665
CVE-2021-21017Adobe2021-11-171665
CVE-2021-28550Adobe2021-11-171665
CVE-2021-42013Apache Software Foundation2021-11-171665
CVE-2021-41773Apache Software Foundation2021-11-171665
CVE-2021-30858Apple2021-11-171665
CVE-2021-30860Apple2021-11-171665

Transactions

EXPLOIT PUBLISHED — CVE-2025-52292. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-52293. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-55657. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-55658. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-55659. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-10520 (ivanti Sentry). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-44716 (pipecat-ai pipecat). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-46492 (commenthol md-fileserver). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-46518 (openemr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-5067 (zephyrproject-rtos Zephyr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-5068 (zephyrproject-rtos Zephyr). Public exploit reference added.

PATCH SHIPPED — CVE-2026-10520 (ivanti Sentry). Fixed in Sentry R10.5.2.

Yesterday's Results

How to read these box scores · glossary

719 CVEs published. 25 box scores and 375 table rows below; the remaining 319 continue on page 2 — every CVE is listed, nothing truncated.

Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .2532   97.8   YES
AFFECTED
  Product                           Versions   Fixed
  Cisco Catalyst SD-WAN Controller  20.6.4 –   —
  Cisco Catalyst SD-WAN Manager     20.1.12 –  —
TIMELINE
  Oct 8   Reserved by CNA
  Jun 9   Added to CISA KEV, due Jun 23
  Jun 9   Published (CNA: cisco)
CWE-116 · CNA: cisco · CVSS v3.1 · 3 references · NVD status: Analyzed · KEV due June 23, 2026
Google Chromium V8
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0219   81.1   YES
AFFECTED
  Product  Versions          Fixed
  Chrome   149.0.7827.103 –  —
TIMELINE
  Jun 8   Reserved by CNA
  Jun 9   Added to CISA KEV, due Jun 23
  Jun 9   Published (CNA: Chrome)
CWE-125, CWE-787 · CNA: Chrome · CVSS v3.1 · 3 references · NVD status: Analyzed · KEV due June 23, 2026
Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   L   N    6.9   .0111   63.3   YES
AFFECTED
  Product  Versions  Fixed
  EOS      4.36.0 –  —
TIMELINE
  Apr 29  Reserved by CNA
  Jun 9   Added to CISA KEV, due Jun 23
  Jun 9   Published (CNA: Arista)
CWE-1023 · CNA: Arista · CVSS v4.0 · 3 references · NVD status: Analyzed · KEV due June 23, 2026
Microsoft Windows 10 Version 1607 — HTTP.sys Denial of Service Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .5383   98.9     —
AFFECTED
  Product                  Versions        Fixed
  Windows 10 Version 1607  10.0.14393.0 –  —
  Windows 10 Version 1809  10.0.17763.0 –  —
  Windows 10 Version 21H2  10.0.19044.0 –  —
  Windows 10 Version 22H2  10.0.19045.0 –  —
  Windows 11 version 23H2  10.0.22631.0 –  —
  Windows 11 Version 23H2  10.0.22631.0 –  —
  Windows 11 Version 24H2  10.0.26100.0 –  —
  Windows 11 Version 25H2  10.0.26200.0 –  —
  Windows 11 version 26H1  10.0.28000.0 –  —
  Windows Server 2016      10.0.14393.0 –  —
  + 6 more
TIMELINE
  May 27  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-400 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
ivanti Sentry — An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 v…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .5187   98.9     —
AFFECTED
  Product  Versions     Fixed
  Sentry   unspecified  R10.5.2
TIMELINE
  Jun 1   Reserved by CNA
  Jun 9   Published (CNA: ivanti)
CWE-288 · CNA: ivanti · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft SharePoint Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .3522   98.3     —
AFFECTED
  Product                                           Versions  Fixed
  Microsoft SharePoint Enterprise Server 2016       16.0.0 –  —
  Microsoft SharePoint Server 2019                  16.0.0 –  —
  Microsoft SharePoint Server Subscription Edition  16.0.0 –  —
TIMELINE
  May 12  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-502 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Windows 10 Version 1607 — HTTP.sys Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .2275   97.5     —
AFFECTED
  Product                  Versions        Fixed
  Windows 10 Version 1607  10.0.14393.0 –  —
  Windows 10 Version 1809  10.0.17763.0 –  —
  Windows 10 Version 21H2  10.0.19044.0 –  —
  Windows 10 Version 22H2  10.0.19045.0 –  —
  Windows 11 version 23H2  10.0.22631.0 –  —
  Windows 11 Version 23H2  10.0.22631.0 –  —
  Windows 11 Version 24H2  10.0.26100.0 –  —
  Windows 11 Version 25H2  10.0.26200.0 –  —
  Windows 11 version 26H1  10.0.28000.0 –  —
  Windows Server 2012      6.2.9200.0 –    —
  + 10 more
TIMELINE
  May 18  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-190, CWE-122 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Exchange Server Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  N  N    5.0   .2026   97.3     —
AFFECTED
  Product                                              Versions     Fixed
  Microsoft Exchange Server 2016 Cumulative Update 23  15.01.0.0 –  —
  Microsoft Exchange Server 2019 Cumulative Update 14  15.02.0.0 –  —
  Microsoft Exchange Server 2019 Cumulative Update 15  15.02.0.0 –  —
  Microsoft Exchange Server Subscription Edition RTM   15.02.0.0 –  —
TIMELINE
  May 12  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-918 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Windows 11 version 23H2 — Windows Kernel Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .1548   96.5     —
AFFECTED
  Product                                         Versions        Fixed
  Windows 11 version 23H2                         10.0.22631.0 –  —
  Windows 11 Version 23H2                         10.0.22631.0 –  —
  Windows 11 Version 24H2                         10.0.26100.0 –  —
  Windows 11 Version 25H2                         10.0.26200.0 –  —
  Windows 11 version 26H1                         10.0.28000.0 –  —
  Windows Server 2022                             10.0.20348.0 –  —
  Windows Server 2025                             10.0.26100.0 –  —
  Windows Server 2025 (Server Core installation)  10.0.26100.0 –  —
TIMELINE
  May 12  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-416, CWE-122 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Ivanti Endpoint Manager Mobile — An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .1363   96.2     —
AFFECTED
  Product                  Versions     Fixed
  Endpoint Manager Mobile  unspecified  12.9.0.1
TIMELINE
  Jun 3   Reserved by CNA
  Jun 9   Published (CNA: ivanti)
CWE-78 · CNA: ivanti · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
Microsoft Windows 10 Version 1607 — Windows NTLM Spoofing Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0868   94.7     —
AFFECTED
  Product                                            Versions        Fixed
  Windows 10 Version 1607                            10.0.14393.0 –  —
  Windows 11 version 22H2                            10.0.22621.0 –  —
  Windows Server 2012                                6.2.9200.0 –    —
  Windows Server 2012 (Server Core installation)     6.2.9200.0 –    —
  Windows Server 2012 R2                             6.3.9600.0 –    —
  Windows Server 2012 R2 (Server Core installation)  6.3.9600.0 –    —
  Windows Server 2016                                10.0.14393.0 –  —
  Windows Server 2016 (Server Core installation)     10.0.14393.0 –  —
  Windows Server 2022                                10.0.20348.0 –  —
  Windows Server version 2004                        10.0.0 –        —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-200 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Windows 10 Version 1607 — NT OS Kernel Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0695   93.6     —
AFFECTED
  Product                  Versions        Fixed
  Windows 10 Version 1607  10.0.14393.0 –  —
  Windows 10 Version 1809  10.0.17763.0 –  —
  Windows 10 Version 21H2  10.0.19044.0 –  —
  Windows 10 Version 22H2  10.0.19045.0 –  —
  Windows 11 version 23H2  10.0.22631.0 –  —
  Windows 11 Version 23H2  10.0.22631.0 –  —
  Windows 11 Version 24H2  10.0.26100.0 –  —
  Windows 11 Version 25H2  10.0.26200.0 –  —
  Windows 11 version 26H1  10.0.28000.0 –  —
  Windows Server 2012      6.2.9200.0 –    —
  + 10 more
TIMELINE
  Apr 30  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-191, CWE-122 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Windows 10 Version 1607 — Windows BitLocker Security Feature Bypass Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   P   L   N   N  U  H  H  H    6.8   .0501   91.6     —
AFFECTED
  Product                  Versions        Fixed
  Windows 10 Version 1607  10.0.14393.0 –  —
  Windows 10 Version 1809  10.0.17763.0 –  —
  Windows 10 Version 21H2  10.0.19044.0 –  —
  Windows 10 Version 22H2  10.0.19045.0 –  —
  Windows 11 version 23H2  10.0.22631.0 –  —
  Windows 11 Version 23H2  10.0.22631.0 –  —
  Windows 11 Version 24H2  10.0.26100.0 –  —
  Windows 11 Version 25H2  10.0.26200.0 –  —
  Windows 11 version 26H1  10.0.28000.0 –  —
  Windows Server 2012 R2   6.3.9600.0 –    —
  + 8 more
TIMELINE
  Jun 4   Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-306 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Modified
Microsoft Windows 10 Version 1607 — Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0363   88.6     —
AFFECTED
  Product                  Versions        Fixed
  Windows 10 Version 1607  10.0.14393.0 –  —
  Windows 10 Version 1809  10.0.17763.0 –  —
  Windows 10 Version 21H2  10.0.19044.0 –  —
  Windows 10 Version 22H2  10.0.19045.0 –  —
  Windows 11 version 23H2  10.0.22631.0 –  —
  Windows 11 Version 23H2  10.0.22631.0 –  —
  Windows 11 Version 24H2  10.0.26100.0 –  —
  Windows 11 Version 25H2  10.0.26200.0 –  —
  Windows 11 version 26H1  10.0.28000.0 –  —
  Windows Server 2012      6.2.9200.0 –    —
  + 10 more
TIMELINE
  May 12  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-59 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
OpenSSL OpenSSL — Heap Use-After-Free in the PKCS7_verify() Function
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0357   88.5     —
AFFECTED
  Product  Versions  Fixed
  OpenSSL  4.0.0 –   —
TIMELINE
  May 12  Reserved by CNA
  Jun 9   Published (CNA: openssl)
CWE-416 · CNA: openssl · CVSS v3.1 · 25 references · NVD status: Modified
Adobe ColdFusion — ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   A   L   N   R  C  H  H  H    8.8   .0255   83.8     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 20  Reserved by CNA
  Jun 9   Published (CNA: adobe)
CWE-22 · CNA: adobe · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft .NET 10.0 — ASP.NET Core Denial of Service Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0248   83.3     —
AFFECTED
  Product                                    Versions  Fixed
  .NET 10.0                                  10.0.0 –  —
  .NET 8.0                                   8.0.0 –   —
  .NET 9.0                                   9.0.0 –   —
  ASP.NET Core 10.0                          10.0 –    —
  ASP.NET Core 8.0                           8.0 –     —
  ASP.NET Core 9.0                           9.0 –     —
  Microsoft Visual Studio 2026 version 18.6  18.6.0 –  —
TIMELINE
  May 12  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-400 · CNA: microsoft · CVSS v3.1 · 21 references · NVD status: Modified
Veeam Backup and Replication — A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0235   82.4     —
AFFECTED
  Product                 Versions     Fixed
  Backup and Replication  unspecified  —
TIMELINE
  May 8   Reserved by CNA
  Jun 9   Published (CNA: hackerone)
CWE-502 · CNA: hackerone · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
Adobe ColdFusion — ColdFusion | Improper Input Validation (CWE-20)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   A   L   N   N  C  H  H  H    9.6   .0232   82.1     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 20  Reserved by CNA
  Jun 9   Published (CNA: adobe)
CWE-20 · CNA: adobe · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Windows 10 Version 1607 — Winlogon Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0227   81.7     —
AFFECTED
  Product                  Versions        Fixed
  Windows 10 Version 1607  10.0.14393.0 –  —
  Windows 10 Version 1809  10.0.17763.0 –  —
  Windows 10 Version 21H2  10.0.19044.0 –  —
  Windows 10 Version 22H2  10.0.19045.0 –  —
  Windows 11 version 23H2  10.0.22631.0 –  —
  Windows 11 Version 23H2  10.0.22631.0 –  —
  Windows 11 Version 24H2  10.0.26100.0 –  —
  Windows 11 Version 25H2  10.0.26200.0 –  —
  Windows 11 version 26H1  10.0.28000.0 –  —
  Windows Server 2012      6.2.9200.0 –    —
  + 10 more
TIMELINE
  Apr 30  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-59 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Adobe ColdFusion — ColdFusion | Incorrect Authorization (CWE-863)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   A   L   H   N  C  H  H  H    8.4   .0209   80.2     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 20  Reserved by CNA
  Jun 9   Published (CNA: adobe)
CWE-863 · CNA: adobe · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Windows 10 Version 1607 — Windows DWM Core Library Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0200   79.3     —
AFFECTED
  Product                  Versions        Fixed
  Windows 10 Version 1607  10.0.14393.0 –  —
  Windows 10 Version 1809  10.0.17763.0 –  —
  Windows 10 Version 21H2  10.0.19044.0 –  —
  Windows 10 Version 22H2  10.0.19045.0 –  —
  Windows 11 version 23H2  10.0.22631.0 –  —
  Windows 11 Version 23H2  10.0.22631.0 –  —
  Windows 11 Version 24H2  10.0.26100.0 –  —
  Windows 11 Version 25H2  10.0.26200.0 –  —
  Windows 11 version 26H1  10.0.28000.0 –  —
  Windows Server 2012      6.2.9200.0 –    —
  + 10 more
TIMELINE
  Apr 30  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-416 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Graphics Component Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0200   79.3     —
AFFECTED
  Product                  Versions        Fixed
  Windows 10 Version 1607  10.0.14393.0 –  —
  Windows 10 Version 1809  10.0.17763.0 –  —
  Windows 10 Version 21H2  10.0.19044.0 –  —
  Windows 10 Version 22H2  10.0.19045.0 –  —
  Windows 11 version 23H2  10.0.22631.0 –  —
  Windows 11 Version 23H2  10.0.22631.0 –  —
  Windows 11 Version 24H2  10.0.26100.0 –  —
  Windows 11 Version 25H2  10.0.26200.0 –  —
  Windows 11 version 26H1  10.0.28000.0 –  —
  Windows Server 2012      6.2.9200.0 –    —
  + 10 more
TIMELINE
  Apr 30  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-416 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Nuance PowerScribe 360 4.0 — Nuance PowerScribe Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0191   78.2     —
AFFECTED
  Product                               Versions  Fixed
  Nuance PowerScribe 360 4.0            4.0 –     —
  Nuance PowerScribe 360 version 4.0.1  4.0.1 –   —
  Nuance PowerScribe 360 version 4.0.2  4.0.2 –   —
  Nuance PowerScribe 360 version 4.0.3  4.0.3 –   —
  Nuance PowerScribe 360 version 4.0.4  4.0.4 –   —
  Nuance PowerScribe 360 version 4.0.5  4.0.5 –   —
  Nuance PowerScribe 360 version 4.0.6  4.0.6 –   —
  Nuance PowerScribe 360 version 4.0.7  4.0.7 –   —
  Nuance PowerScribe 360 version 4.0.8  4.0.8 –   —
  Nuance PowerScribe 360 version 4.0.9  4.0.9 –   —
  + 12 more
TIMELINE
  Feb 11  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-502 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft SharePoint Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0163   74.4     —
AFFECTED
  Product                                           Versions  Fixed
  Microsoft SharePoint Enterprise Server 2016       16.0.0 –  —
  Microsoft SharePoint Server 2019                  16.0.0 –  —
  Microsoft SharePoint Server Subscription Edition  16.0.0 –  —
TIMELINE
  May 12  Reserved by CNA
  Jun 9   Published (CNA: microsoft)
CWE-22 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-429858.867.3MicrosoftRemote Desktop client for Windows DesktopCWE-416Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-428358.167.3MicrosoftMicrosoft Teams for AndroidCWE-74Microsoft Teams for Android Information Disclosure Vulnerability
CVE-2026-427647.564.9OpenSSLOpenSSLCWE-476NULL Pointer Dereference in QUIC Server Initial Packet Handling
CVE-2026-456488.863.8MicrosoftWindows Server 2022CWE-121Windows Active Directory Domain Services Remote Code Execution Vulnerability
CVE-2026-83658.863.7creativethemeshqBlocksyCWE-502Blocksy <= 2.1.41 - Authenticated (Contributor+) PHP Object Injection via Des…
CVE-2026-448159.863.2MicrosoftWindows 10 Version 1607CWE-121DHCP Client Service Remote Code Execution Vulnerability
CVE-2026-427665.962.0OpenSSLOpenSSLCWE-476Possible NULL Dereference in Password-Based CMS Decryption
CVE-2026-341837.561.7OpenSSLOpenSSLCWE-1325Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler
CVE-2026-115727.461.5n/adegitCWE-78Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are v…
CVE-2026-485737.961.0MicrosoftWindows 10 Version 1607CWE-1329Secure Boot Security Feature Bypass Vulnerability
CVE-2026-485767.961.0MicrosoftWindows 10 Version 1607CWE-1329Secure Boot Security Feature Bypass Vulnerability
CVE-2026-341807.561.0OpenSSLOpenSSLCWE-125Heap Buffer Over-read in ASN.1 Content Parsing
CVE-2026-367238.860.1n/an/aCWE-22An unrestricted file rename vulnerability in the /api/create-user component o…
CVE-2026-472898.858.7MicrosoftWindows 10 Version 1607CWE-122Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-499598.758.4nesquenahermes-webuiCWE-78Hermes WebUI < 0.51.311 RCE via Git Configuration Injection
CVE-2026-485605.458.2MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-502Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-472846.557.6MicrosoftVisual Studio CodeCWE-200Visual Studio Code Information Disclosure Vulnerability
CVE-2026-429036.557.1MicrosoftWindows 10 Version 1607CWE-476Windows Kerberos Denial of Service Vulnerability
CVE-2026-429087.556.1MicrosoftWindows 10 Version 1607CWE-125Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-456397.556.1MicrosoftRemote Desktop client for Windows DesktopCWE-125Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-455048.855.3MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 23CWE-918Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2026-410988.454.8MicrosoftAzure Stack EdgeCWE-79Azure Stack Edge Spoofing Vulnerability
CVE-2026-386159.854.4n/an/aCWE-78DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
CVE-2026-429076.554.4MicrosoftWindows 10 Version 1809CWE-200Windows Shell Information Disclosure Vulnerability
CVE-2026-73838.154.0OpenSSLOpenSSLCWE-787Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion
CVE-2026-429145.353.6MicrosoftWindows 10 Version 1607CWE-125Windows Kerberos Denial of Service Vulnerability
CVE-2026-472876.553.4MicrosoftVisual Studio CodeCWE-23Visual Studio Code Tampering Vulnerability
CVE-2026-409847.552.6SpringMicrometerCWE-400Micrometer HTTP server instrumentations DoS vulnerability
CVE-2026-472819.652.5MicrosoftVisual Studio CodeCWE-862Visual Studio Code Elevation of Privilege Vulnerability
CVE-2026-476439.852.3MicrosoftAzure Stack EdgeCWE-73Azure Stack Edge Remote Code Execution Vulnerability
CVE-2025-713198.751.4image-sizeimage-sizeCWE-835image-size 2.0.2 Denial of Service via Infinite Loop in JXL/HEIF Parser
CVE-2026-90767.550.7OpenSSLOpenSSLCWE-125Out-of-Bounds Read in CMS Password-Based Decryption
CVE-2026-454815.449.9MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-403768.149.2MicrosoftVisual Studio CodeCWE-20Visual Studio Code Elevation of Privilege Vulnerability
CVE-2016-200646.949.2myasuiWP VaultCWE-98WP Vault 0.8.6.6 Local File Inclusion via wpv-image Parameter
CVE-2026-472988.049.2MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-285Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-50679.848.0zephyrproject-rtosZephyrCWE-787Out-of-bounds read/write in HTTP WebSocket upgrade via non-null-terminated Se…
CVE-2017-202488.747.9AppthaApptha Slider GalleryCWE-22WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download
CVE-2017-202508.747.9AppthaMac Photo GalleryCWE-22WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download
CVE-2026-429748.147.9MicrosoftWindows 11 version 23H2CWE-190Windows Performance Monitor Remote Code Execution Vulnerability
CVE-2026-429818.147.9MicrosoftWindows 11 version 23H2CWE-191Windows Performance Monitor Remote Code Execution Vulnerability
CVE-2026-403718.847.5MicrosoftMicrosoft Dynamics 365 (on-premises) version 9.1CWE-280Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability
CVE-2026-454554.347.4MicrosoftMicrosoft 365 Apps for EnterpriseCWE-125Microsoft Excel Information Disclosure Vulnerability
CVE-2026-498186.547.2Apache Software FoundationApache Airflow Samba providerCWE-22Apache Airflow Samba provider: Path traversal in GCSToSambaOperator via GCS o…
CVE-2026-456504.347.0MicrosoftMicrosoft Bing Search for AndroidCWE-451Microsoft Bing Search Spoofing Vulnerability
CVE-2026-409837.546.7SpringMicrometerCWE-400Micrometer gRPC server instrumentation DoS vulnerability
CVE-2026-454457.546.2OpenSSLOpenSSLCWE-325AES-OCB IV Ignored on EVP_Cipher() Path
CVE-2026-476538.846.1MicrosoftWindows 10 Version 1607CWE-416Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-429878.145.5MicrosoftWindows Server 2012CWE-416Windows Deployment Services (WDS) Remote Code Execution
CVE-2026-499556.945.4nesquenahermes-webuiCWE-770Hermes WebUI < 0.51.270 Resource Exhaustion via passkey/options
CVE-2026-427683.745.1OpenSSLOpenSSLCWE-514Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()
CVE-2026-301419.844.7n/an/aCWE-120An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in …
CVE-2025-102639.144.6ArmC1-UltraCWE-362Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neove…
CVE-2026-479308.144.5AdobeColdFusionCWE-20ColdFusion | Improper Input Validation (CWE-20)
CVE-2026-117887.544.1Red HatRed Hat Directory Server 11.7 E4S for RHEL 8CWE-476389-ds-base: 389-ds-base: null pointer dereference in deref control plugin be…
CVE-2017-202519.344.0ThemeisleWoody Code SnippetsCWE-94WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST API
CVE-2026-476345.444.0MicrosoftMicrosoft SharePoint Server 2019CWE-74Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-427675.943.9OpenSSLOpenSSLCWE-476NULL Pointer Dereference in CRMF EncryptedValue Decryption
CVE-2026-456448.043.7MicrosoftMicrosoft Live Share Canvas SDKCWE-79Microsoft Live Share Canvas SDK Elevation of Privilege Vulnerability
CVE-2026-4830310.043.7AdobeAdobe Campaign Classic (ACC)CWE-863Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
CVE-2026-96628.143.6plasmatizemediaRecover Exit For WooCommerceCWE-98Recover Exit For WooCommerce <= 1.0.3 - Unauthenticated Local File Inclusion …
CVE-2026-476547.543.5MicrosoftWindows Server 2016CWE-416Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-485637.543.5MicrosoftWindows 10 Version 1809CWE-416Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-448037.842.0MicrosoftMicrosoft Excel for AndroidCWE-190Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-448127.842.0MicrosoftMicrosoft Excel for AndroidCWE-190Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-331136.141.9MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-455998.141.8MicrosoftWindows 10 Version 1607CWE-416Windows UPnP Device Host Remote Code Execution Vulnerability
CVE-2026-456358.141.8MicrosoftWindows 10 Version 1607CWE-843Windows UPnP Device Host Remote Code Execution Vulnerability
CVE-2026-448228.241.7MicrosoftMicrosoft 365 Apps for EnterpriseCWE-125Microsoft Excel Information Disclosure Vulnerability
CVE-2026-367265.341.3n/an/aCWE-22An arbitrary file deletion vulnerability in the /api/delete-temp-license/{fil…
CVE-2026-417318.141.1SpringSpring for Apache KafkaCWE-502In Spring for Apache Kafka, overly broad trusted-package matching in header m…
CVE-2026-454535.441.2MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-454645.441.2MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-454655.441.2MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-476365.441.2MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-476395.441.2MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-427657.541.1OpenSSLOpenSSLCWE-476NULL Dereference in Certificate Verification with OCSP Checking
CVE-2026-454625.440.8MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-454675.440.8MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-454685.440.8MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-454795.440.8MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-454835.440.8MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft Office Project Server Spoofing Vulnerability
CVE-2026-476375.440.8MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-476385.440.8MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-476405.440.8MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-476415.440.8MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-20Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-485624.640.8MicrosoftMicrosoft SharePoint Enterprise Server 2016CWE-79Microsoft SharePoint Server Spoofing Vulnerability
CVE-2025-522927.540.5n/an/aCWE-121A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP…
CVE-2026-472887.140.5MicrosoftWindows Server 2012CWE-190Windows Kerberos Key Distribution Center (KDC) Remote Code Execution
CVE-2026-335826.539.2Apache Software FoundationApache AnswerCWE-434Apache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory…
CVE-2026-455838.138.9MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 23CWE-94Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2026-429137.538.8MicrosoftRemote Desktop client for Windows DesktopCWE-362Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-427703.738.4OpenSSLOpenSSLCWE-325FFC-DH Peer Validation Uses Attacker-Supplied q
CVE-2025-522937.538.3n/an/aCWE-400A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_t…
CVE-2025-556577.538.3n/an/aCWE-476A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descr…
CVE-2026-448215.538.2MicrosoftMicrosoft 365 Apps for EnterpriseCWE-125Microsoft Office Information Disclosure Vulnerability
CVE-2026-96989.838.1HMBRANDDBICWE-787DBI versions before 1.648 for Perl saved errors in a limited-sized buffer
CVE-2026-429927.538.0MicrosoftWindows 10 Version 1607CWE-122Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-447997.538.0MicrosoftRemote Desktop client for Windows DesktopCWE-122Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-448017.538.0MicrosoftRemote Desktop client for Windows DesktopCWE-416Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-440838.737.9QNAP Systems Inc.QuMagieCWE-639QuMagie
CVE-2026-429715.537.8MicrosoftWindows 10 Version 1607CWE-200Windows Push Notification Information Disclosure Vulnerability
CVE-2026-429725.537.8MicrosoftWindows 10 Version 1607CWE-200Windows Hyper-V Information Disclosure Vulnerability
CVE-2026-479607.437.7AdobeColdFusionCWE-611ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (C…
CVE-2026-448197.837.5MicrosoftMicrosoft 365 Apps for EnterpriseCWE-122Microsoft Office Remote Code Execution Vulnerability
CVE-2026-448247.837.5MicrosoftMicrosoft 365 Apps for EnterpriseCWE-122Microsoft Office Remote Code Execution Vulnerability
CVE-2026-454717.837.5MicrosoftMicrosoft 365 Apps for EnterpriseCWE-822Microsoft Word Remote Code Execution Vulnerability
CVE-2026-454757.837.5MicrosoftMicrosoft 365 Apps for EnterpriseCWE-122Microsoft Office Remote Code Execution Vulnerability
CVE-2026-401289.037.5SAP_SESAP NetWeaver Application Server Java (Web Container)CWE-35Directory Traversal vulnerability in SAP NetWeaver Application Server Java (W…
CVE-2026-50688.837.3zephyrproject-rtosZephyrCWE-787bt: l2cap le coc: remote oob write via seg counter stored in net_buf user_data
CVE-2026-425675.937.3sveltejssvelteCWE-1333Svelte: ReDoS in `<svelte:element>` Tag Validation
CVE-2026-4793810.037.1AdobeAdobe Campaign Classic (ACC)CWE-918Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
CVE-2026-498427.537.1signalwirefreeswitchCWE-400FreeSWITCH: Pre-authentication bandwidth amplification via `mod_verto` speed-…
CVE-2026-485747.836.9MicrosoftWindows 10 Version 1607CWE-122Windows Media Remote Code Execution Vulnerability
CVE-2026-455036.536.9MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 23CWE-285Microsoft Exchange Server Information Disclosure Vulnerability
CVE-2025-628585.136.9QNAP Systems Inc.QTSCWE-121QTS, QuTS hero
CVE-2026-463169.336.6LinuxLinuxCWE-911KVM: arm64: vgic-its: Drop the translation cache reference only for the erase…
CVE-2026-472927.836.4MicrosoftVisual Studio Code - MSSQL ExtensionCWE-829Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability
CVE-2026-429049.636.3MicrosoftWindows 10 Version 21H2CWE-122Windows TCP/IP Elevation of Privilege Vulnerability
CVE-2026-454568.436.3MicrosoftMicrosoft 365 Apps for EnterpriseCWE-843Microsoft Outlook and Word Remote Code Execution Vulnerability
CVE-2026-454588.436.3MicrosoftMicrosoft 365 Apps for EnterpriseCWE-416Microsoft Outlook and Word Remote Code Execution Vulnerability
CVE-2026-276719.836.2SAP_SESAP NetWeaver AS ABAP and ABAP PlatformCWE-121Memory Corruption vulnerability in Application Server ABAP of SAP NetWeaver a…
CVE-2026-454853.336.2MicrosoftMicrosoft 365 Apps for EnterpriseCWE-125Microsoft Office Information Disclosure Vulnerability
CVE-2026-341829.136.1OpenSSLOpenSSLCWE-354CMS AuthEnvelopedData Processing May Accept Forged Messages
CVE-2026-429937.536.0MicrosoftWindows 10 Version 21H2CWE-122Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-467468.735.7SiemensSINEC INSCWE-78A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Upd…
CVE-2026-485657.835.8MicrosoftWindows Narrator BrailleCWE-426Windows Narrator Braille Elevation of Privilege Vulnerability
CVE-2026-347117.535.6AdobeCAI Content CredentialsCWE-190CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)
CVE-2026-456497.135.4MicrosoftMicrosoft Excel for AndroidCWE-284Office for Android Spoofing Vulnerability
CVE-2026-447167.535.0pipecat-aipipecatCWE-22Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File …
CVE-2026-455955.435.0MicrosoftWindows 10 Version 1607CWE-693Windows Mark of the Web Security Feature Bypass Vulnerability
CVE-2026-464918.635.0simplesamlphpsimplesamlphp-module-casserverCWE-22SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ti…
CVE-2026-499576.334.8nesquenahermes-webuiCWE-22Hermes WebUI < 0.51.296 Workspace Boundary Bypass via api/workspace.py
CVE-2026-498477.534.2signalwirefreeswitchCWE-674FreeSWITCH: Stack overflow in bundled cJSON parser via deeply nested JSON
CVE-2026-456555.334.1MicrosoftWindows 10 Version 1607CWE-693Windows BitLocker Security Feature Bypass Vulnerability
CVE-2026-456367.833.9MicrosoftWindows 10 Version 1607CWE-122Windows NTFS Remote Code Execution Vulnerability
CVE-2026-347127.533.6AdobeCAI Content CredentialsCWE-20CAI Content Credentials | Improper Input Validation (CWE-20)
CVE-2026-347137.533.6AdobeCAI Content CredentialsCWE-400CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVE-2026-256886.133.5Apache Software FoundationApache AnswerCWE-87Apache Answer: XSS in AI Answer Rendering
CVE-2026-256996.133.5Apache Software FoundationApache AnswerCWE-359Apache Answer: Authorization Bypass in Timeline API
CVE-2026-429065.533.3MicrosoftWindows 10 Version 21H2CWE-200Windows Shell Information Disclosure Vulnerability
CVE-2026-429705.533.3MicrosoftWindows 10 Version 1607CWE-200Windows Push Notification Information Disclosure Vulnerability
CVE-2026-429735.533.3MicrosoftWindows 10 Version 1607CWE-200Windows Push Notification Information Disclosure Vulnerability
CVE-2026-455945.533.3MicrosoftWindows 10 Version 1607CWE-200Windows Application Identity (AppID) Information Disclosure Vulnerability
CVE-2026-91857.533.1sixstorage6Storage RentalsCWE-6396Storage Rentals <= 2.22.0 - Unauthenticated Insecure Direct Object Reference…
CVE-2026-116185.532.9DTStackTaierCWE-287DTStack Taier Source Connection Test Endpoint LoginInterceptor.java preHandle…
CVE-2026-427695.333.0OpenSSLOpenSSLCWE-295Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate
CVE-2026-418427.532.7SpringSpring FrameworkCWE-400Spring Framework Denial of Service via Versioned Resources in Spring MVC and …
CVE-2026-367797.532.6n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) wa…
CVE-2026-367837.532.6n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) wa…
CVE-2026-367917.532.6n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda O3v3 v1.0.0.5 was discovered to cont…
CVE-2026-367927.532.6n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) wa…
CVE-2026-367937.532.6n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) wa…
CVE-2026-367947.532.6n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) wa…
CVE-2026-367967.532.6n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to cont…
CVE-2026-367977.532.6n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to cont…
CVE-2026-367997.532.6n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to cont…
CVE-2026-425707.532.5sveltejsdevalueCWE-770Svelte devalue: DoS via sparse array deserialization
CVE-2026-429097.532.5MicrosoftRemote Desktop client for Windows DesktopCWE-362Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-92136.932.6NETGEARMR70CWE-20Insufficient input validation in certain NETGEAR routers
CVE-2026-498419.832.3signalwirefreeswitchCWE-122FreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST …
CVE-2026-417298.132.1SpringSpring Data RESTCWE-917Spring Data REST SpEL Injection via Map Key in JSON Patch
CVE-2026-454618.431.8MicrosoftMicrosoft 365 Apps for EnterpriseCWE-416Microsoft Office Remote Code Execution Vulnerability
CVE-2026-429685.531.6MicrosoftWindows 10 Version 1607CWE-125Windows Telephony Server Information Disclosure Vulnerability
CVE-2026-429695.531.6MicrosoftWindows 10 Version 1607CWE-908Windows Push Notification Information Disclosure Vulnerability
CVE-2026-454915.531.6Microsoft.NET 10.0CWE-59.NET Tampering Vulnerability
CVE-2026-485665.531.6MicrosoftWindows 11 Version 24H2CWE-125Windows DWM Core Library Information Disclosure Vulnerability
CVE-2026-454663.331.3MicrosoftMicrosoft 365 Apps for EnterpriseCWE-122Microsoft Word Information Disclosure Vulnerability
CVE-2026-454907.831.1Microsoft.NET 10.0CWE-285.NET SDK Elevation of Privilege Vulnerability
CVE-2026-429155.531.0MicrosoftWindows 10 Version 21H2CWE-131Microsoft Windows VMSwitch Denial of Service Vulnerability
CVE-2026-456065.531.0MicrosoftWindows 10 Version 1607CWE-125Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability
CVE-2026-455006.130.2MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 23CWE-79Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-454464.830.1OpenSSLOpenSSLCWE-325Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes
CVE-2026-506358.729.9LimeSurveyLimeSurveyCWE-640LimeSurvey Password Reset Host Header Injection Discloses Reset Token
CVE-2026-448177.829.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-843Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-448207.829.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-125Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-448237.829.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-197Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-454577.829.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-125Microsoft Word Remote Code Execution Vulnerability
CVE-2026-454697.829.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-191Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-454867.829.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-416Microsoft Word Remote Code Execution Vulnerability
CVE-2026-456437.829.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-822Microsoft Word Remote Code Execution Vulnerability
CVE-2026-456457.829.9MicrosoftMicrosoft 365 Apps for EnterpriseCWE-822Microsoft Office Remote Code Execution Vulnerability
CVE-2026-536738.629.8BuddyPressBuddyPressCWE-639BuddyPress 14.4.0 Private Message IDOR via REST API user_id Parameter
CVE-2026-454593.329.8MicrosoftMicrosoft 365 Apps for EnterpriseCWE-693Microsoft Excel Security Feature Bypass Vulnerability
CVE-2026-367784.929.7n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) wa…
CVE-2026-454604.729.7MicrosoftMicrosoft 365 Apps for EnterpriseCWE-126Microsoft Office Information Disclosure Vulnerability
CVE-2009-100079.129.6ETHERCatalyst::Plugin::AuthenticationCWE-384Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is suscept…
CVE-2026-418435.929.5SpringSpring FrameworkCWE-22Spring Framework Path Traversal via Versioned Static Resources in Spring MVC …
CVE-2026-97507.129.5MongoDBMongoDB ServerCWE-617Metadata name collision on $-prefixed fields causes post-auth server crash
CVE-2026-536747.129.4BuddyPressBuddyPressCWE-943BuddyPress 14.4.0 REGEXP Injection via @Mention Username Resolution
CVE-2026-456029.129.3MicrosoftWindows 10 Version 1607CWE-349Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability
CVE-2026-367279.129.1n/an/aCWE-287An insecure authentication vulnerability in the /api/social-sign-in endpoint …
CVE-2026-454638.429.0MicrosoftMicrosoft 365 Apps for EnterpriseCWE-191Microsoft Office Remote Code Execution Vulnerability
CVE-2026-454728.429.0MicrosoftMicrosoft 365 Apps for EnterpriseCWE-416Microsoft Office Remote Code Execution Vulnerability
CVE-2026-454748.429.1MicrosoftMicrosoft 365 Apps for EnterpriseCWE-416Microsoft Office Remote Code Execution Vulnerability
CVE-2026-416957.529.1SpringSpring Data CommonsCWE-400Denial of Service in Spring Data Commons Property Path Resolution
CVE-2026-417167.529.0SpringSpring Data CommonsCWE-770Spring Data web support unbounded negative-result cache keyed on attacker-sup…
CVE-2026-340316.528.9Apache Software FoundationApache AnswerCWE-434Apache Answer: The custom avatar was not properly validated
CVE-2026-456345.528.9MicrosoftWindows 10 Version 1607CWE-125Windows DHCP Client Information Disclosure Vulnerability
CVE-2026-418507.528.6SpringSpring FrameworkCWE-407Spring Framework Algorithmic Denial of Service via SpEL Expressions
CVE-2026-418517.528.6SpringSpring FrameworkCWE-770Spring Framework Denial of Service via Unbounded Cache in SpEL
CVE-2026-482883.528.7AdobeAdobe Experience ManagerCWE-20Adobe Experience Manager | Improper Input Validation (CWE-20)
CVE-2026-346919.328.5AdobeAdobe Experience Manager Forms JEECWE-79Adobe Experience Manager Forms JEE | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-506368.728.4LimeSurveyLimeSurveyCWE-89LimeSurvey RemoteControl invite_participants/remind_participants SQL Injection
CVE-2026-456077.828.3MicrosoftWindows 10 Version 1607CWE-125Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-30884.928.4NETGEARRBR860CWE-787Unauthenticated users can disrupt router operation
CVE-2026-448055.528.3MicrosoftWindows Server 2019CWE-416Windows Network Controller (NC) Host Agent Denial of Service Vulnerability
CVE-2026-497382.128.2TYPO3TYPO3 CMSCWE-22TYPO3 CMS - Broken Access Control in File Abstraction Layer
CVE-2026-456586.827.9MicrosoftWindows 10 Version 1607CWE-284Windows BitLocker Security Feature Bypass Vulnerability
CVE-2026-476315.428.0MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 23CWE-79Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-485695.527.6MicrosoftVisual Studio CodeCWE-20Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-107319.327.5NemonNemon Trade EnergyCWE-89SQL injection in Nemon products
CVE-2026-463259.827.3LinuxLinux—RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE
CVE-2026-97428.227.2MongoDBMongoDB ServerCWE-1287Authenticate command with specific mechanism parameter can trigger server crash
CVE-2026-417328.127.3SpringSpring for Apache PulsarCWE-502In Spring for Apache Pulsar, overly broad trusted-package matching in header …
CVE-2026-465417.527.1nimiqcore-rs-albatrossCWE-754Nimiq network-libp2p: DHT query poisoning via first-record verification failure
CVE-2026-97408.727.0MongoDBMongoDB ServerCWE-674Unbounded recursion in BSONColumn interleaved-reference causes pre-auth stack…
CVE-2026-454828.427.0MicrosoftMicrosoft Visual Studio Code CoPilot Chat ExtensionCWE-22Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability
CVE-2025-556596.527.1n/an/aCWE-476A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_…
CVE-2026-457717.526.9signalwirefreeswitchCWE-776Freeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion
CVE-2026-425735.326.7sveltejssvelteCWE-79Svelte: XSS via DOM Clobbering of Internal Framework State
CVE-2026-476528.226.6MicrosoftWindows 11 version 23H2CWE-122Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-456045.526.6MicrosoftWindows 11 version 23H2CWE-125Windows Managed Installer Information Disclosure Vulnerability
CVE-2026-404047.826.3MicrosoftWindows 10 Version 1607CWE-122Windows Universal Disk Format File System Driver (UDFS) Elevation of Privileg…
CVE-2026-465457.526.3nimiqcore-rs-albatrossCWE-248nimiq-primitives: Panic DoS in trie chunk processing via ROOT-keyed item
CVE-2026-418415.926.3SpringSpring FrameworkCWE-524Spring Framework Information Disclosure via Static Resource Cache in Spring M…
CVE-2026-456086.826.2MicrosoftWindows 10 Version 1607CWE-125Windows DHCP Client Information Disclosure Vulnerability
CVE-2026-321938.826.0MicrosoftAzure Kubernetes ServiceCWE-22Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability
CVE-2026-340335.425.9Apache Software FoundationApache AnswerCWE-79Apache Answer: HTML Content Injection in Email
CVE-2026-446348.725.6simpleblesimplebleCWE-121Stack buffer overflows in SimpleBLE
CVE-2026-476358.425.7MicrosoftMicrosoft Office LTSC 2024CWE-122Microsoft Outlook and Word Remote Code Execution Vulnerability
CVE-2026-409887.525.5SpringSpring SecurityCWE-400Unbounded DEFLATE Inflation in SAML 2.0 Service Provider
CVE-2026-417215.925.4SpringSpring Data CommonsCWE-400Spring Data Commons Denial of Service via Data Binding
CVE-2026-479127.825.2AdobeAcrobat ReaderCWE-416Acrobat Reader | Use After Free (CWE-416)
CVE-2026-479137.825.2AdobeAcrobat ReaderCWE-416Acrobat Reader | Use After Free (CWE-416)
CVE-2026-479147.825.2AdobeAcrobat ReaderCWE-416Acrobat Reader | Use After Free (CWE-416)
CVE-2026-505117.825.3MicrosoftMicrosoft PC ManagerCWE-59Microsoft PC Manager Elevation of Privilege Vulnerability
CVE-2026-367707.525.2n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda US_W3V1.0BR v1.0.0.3 was discovered …
CVE-2026-367717.525.2n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) wa…
CVE-2026-367847.525.2n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) wa…
CVE-2026-417178.125.2SpringSpring Data MongoDBCWE-917Spring Data MongoDB - SpEL Expression Injection via Annotated Query Parameter…
CVE-2026-428287.824.9MicrosoftWindows 10 Version 1809CWE-126Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-428377.824.9MicrosoftWindows 10 Version 1809CWE-125Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-429167.824.9MicrosoftWindows 10 Version 1607CWE-190NT OS Kernel Elevation of Privilege Vulnerability
CVE-2026-454768.224.7MicrosoftLinux kernel - Microsoft MANA Network DriverCWE-416Microsoft Azure Network Adapter Elevation of Privilege Vulnerability
CVE-2026-240658.124.5Waves Audio Ltd.Waves CentralCWE-367Local Privilege Escalation via Insecure XPC Client Validation in Waves Centra…
CVE-2026-97487.124.6MongoDBMongoDB ServerCWE-617$_internalConvertBucketIndexStats may crash the mongod server when working on…
CVE-2026-04134.324.5NETGEARRBE370CWE-121Buffer overflow vulnerability in certain NETGEAR Nighthawk routers
CVE-2026-262366.624.4QNAP Systems Inc.QuMagieCWE-862QuMagie
CVE-2026-367197.524.4n/an/aCWE-200An information disclosure vulnerability in the /api/v1/user/info endpoint of …
CVE-2026-456567.824.1MicrosoftWindows 10 Version 1607CWE-693UEFI Secure Boot Security Feature Bypass Vulnerability
CVE-2026-456423.924.1MicrosoftWindows 10 Version 1607CWE-20Microsoft Azure Attestation service and Device Health Attestation Service Spo…
CVE-2026-448145.523.9MicrosoftWindows 11 version 26H1CWE-125Windows DWM Core Library Information Disclosure Vulnerability
CVE-2026-418487.523.8SpringSpring FrameworkCWE-1333Spring Framework Denial of Service via AntPathMatcher
CVE-2026-497427.123.4TYPO3TYPO3 CMSCWE-22TYPO3 CMS - Broken Access Control in Media Module
CVE-2026-349056.523.5Apache Software FoundationApache AnswerCWE-200Apache Answer: Unlisted Questions Accessible via Direct API Access
CVE-2026-498409.123.1signalwirefreeswitchCWE-20FreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length…
CVE-2026-338287.823.1MicrosoftWindows 10 Version 1607CWE-501Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability
CVE-2026-456547.922.9MicrosoftWindows 11 Version 24H2CWE-284Secure Boot Security Feature Bypass Vulnerability
CVE-2026-368007.523.0n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to cont…
CVE-2026-368017.523.0n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to cont…
CVE-2026-368027.523.0n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda PW201A v1.0.5 was discovered to cont…
CVE-2026-368037.523.0n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda PW201A v1.0.5 was discovered to cont…
CVE-2026-368057.523.0n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to cont…
CVE-2026-368067.523.1n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c…
CVE-2026-368077.523.1n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c…
CVE-2026-368087.523.1n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c…
CVE-2026-368097.523.1n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c…
CVE-2026-368107.523.1n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c…
CVE-2026-368117.523.1n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c…
CVE-2026-368137.523.0n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c…
CVE-2026-368157.523.1n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c…
CVE-2026-368167.523.1n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c…
CVE-2026-368177.523.0n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to c…
CVE-2026-368187.523.1n/an/aCWE-120Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to co…
CVE-2026-368197.523.1n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to co…
CVE-2026-368207.523.1n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to co…
CVE-2026-368217.523.1n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to co…
CVE-2026-368227.523.1n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to co…
CVE-2026-368237.523.1n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to co…
CVE-2026-455016.122.9MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 23CWE-918Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-456417.822.8MicrosoftWindows 10 Version 21H2CWE-843Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-479157.822.7AdobeAcrobat ReaderCWE-416Acrobat Reader | Use After Free (CWE-416)
CVE-2026-479177.822.7AdobeAcrobat ReaderCWE-416Acrobat Reader | Use After Free (CWE-416)
CVE-2026-97437.122.7MongoDBMongoDB serverCWE-476Aggregation sub-pipeline null dereference may allow DoS via crafted getMore
CVE-2026-417287.522.6SpringSpring Data RESTCWE-284Spring Data REST JSON Patch bypasses Jackson read-only property protection on…
CVE-2026-455887.922.4MicrosoftWindows 10 Version 1607CWE-693Secure Boot Security Feature Bypass Vulnerability
CVE-2026-476567.922.4MicrosoftWindows 10 Version 1607CWE-693Windows Boot Manager Security Feature Bypass Vulnerability
CVE-2026-485687.922.4MicrosoftWindows 10 Version 1607CWE-693Secure Boot Security Feature Bypass Vulnerability
CVE-2026-485707.922.4MicrosoftWindows 10 Version 1607CWE-693Secure Boot Security Feature Bypass Vulnerability
CVE-2026-485757.922.4MicrosoftWindows 10 Version 1607CWE-693Secure Boot Security Feature Bypass Vulnerability
CVE-2026-417115.922.3SpringSpring Data CommonsCWE-400Potential Denial of Service through crafted Sort Parameters
CVE-2026-351885.022.2OpenSSLOpenSSLCWE-415Double-free When Checking OCSP Stapled Response
CVE-2026-367986.522.1n/an/aCWE-121Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to cont…
CVE-2026-464116.522.1halfgaarFlashMQCWE-248FlashMQ: Client can trigger uncaught exception on FlashMQ 1.26.1 and older
CVE-2026-410077.521.9SpringSpring HATEOASCWE-770Spring HATEOAS heap exhaustion through unbounded internal caching
CVE-2026-346938.021.8AdobeAdobe Experience Manager Forms JEECWE-79Adobe Experience Manager Forms JEE | Cross-site Scripting (Reflected XSS) (CW…
CVE-2026-404097.821.8MicrosoftWindows 10 Version 1607CWE-197Windows Universal Disk Format File System Driver (UDFS) Elevation of Privileg…
CVE-2026-97537.221.8MongoDBMongoDB ServerCWE-787Server crash via malformed binary diff passed to $_internalApplyOplogUpdate.
CVE-2026-479187.821.7AdobeAcrobat ReaderCWE-416Acrobat Reader | Use After Free (CWE-416)
CVE-2026-479197.821.7AdobeAcrobat ReaderCWE-416Acrobat Reader | Use After Free (CWE-416)
CVE-2026-445055.321.8nimiqcore-rs-albatrossCWE-755Nimiq network-libp2p: Untrusted peer can wedge DHT
CVE-2025-556586.521.6n/an/aCWE-1077GPAC MP4Box v2.4 was discovered to contain a floating point exception in the …
CVE-2026-417266.521.6SpringSpring for Apache KafkaCWE-770In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled…
CVE-2017-202498.821.4appthaApptha Slider GalleryCWE-89WordPress Plugin Apptha Slider Gallery 1.0 SQL Injection
CVE-2026-473475.321.4TYPO3TYPO3 CMSCWE-601TYPO3 CMS - Open Redirect in Core Utilities
CVE-2026-479245.521.2AdobeAcrobat ReaderCWE-416Acrobat Reader | Use After Free (CWE-416)
CVE-2026-258605.321.3frankverbekeOpenClinic GACWE-79OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler
CVE-2026-410927.821.1MicrosoftWindows 10 Version 1607CWE-284Microsoft Kinect Elevation of Privilege Vulnerability
CVE-2026-428297.821.1MicrosoftWindows 11 Version 24H2CWE-284Windows Administrator Protection Secure Feature Bypass Vulnerability
CVE-2026-429027.821.1MicrosoftMicrosoft PowerToysCWE-285Microsoft PowerToys Elevation of Privilege Vulnerability
CVE-2026-465435.321.1nimiqcore-rs-albatrossCWE-617nimiq-blockchain: Genesis batch set request
CVE-2026-117904.921.1Red HatRed Hat Directory Server 11CWE-400389-ds-base: 389-ds-base: pbkdf2 password storage plugin unbounded iteration …
CVE-2026-499488.620.9mem0aimem0CWE-862Mem0 0.2.8 Missing Authorization via POST /configure Endpoint
CVE-2026-367246.520.9n/an/aCWE-400An uncaught exception in the /application/job/update/{id} endpoint of Fastapi…
CVE-2026-04194.420.9NETGEARJR6150CWE-20Insufficient input validation vulnerability in NETGEAR JR6150
CVE-2026-418559.820.8SpringSpring FrameworkCWE-502Spring Framework Unsafe Deserialization via Jackson JMS Converters
CVE-2026-429107.820.6MicrosoftWindows 11 Version 24H2CWE-787Windows Hotpatch Monitoring Service Elevation of Privilege Vulnerability
CVE-2026-429837.820.6MicrosoftWindows 10 Version 1809CWE-416Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-455927.820.6MicrosoftWindows 10 Version 1607CWE-190Windows Internet (wininet.dll) Elevation of Privilege Vulnerability
CVE-2026-455937.820.6MicrosoftWindows 10 Version 1809CWE-416Windows SDK Elevation of Privilege Vulnerability
CVE-2026-456007.820.6MicrosoftWindows 11 Version 24H2CWE-843Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2026-456057.820.6MicrosoftWindows 10 Version 1607CWE-416Windows Bluetooth Service Elevation of Privilege Vulnerability
CVE-2026-456377.820.6MicrosoftWindows 10 Version 1809CWE-416Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-456387.820.6MicrosoftWindows 10 Version 1607CWE-122Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerab…
CVE-2026-116205.520.5TOTOLINKEX200CWE-266TOTOLINK EX200 vsftpd vsftpd.conf least privilege violation
CVE-2026-498435.320.3signalwirefreeswitchCWE-287FreeSWITCH: Pre-authentication session eviction via attacker-chosen `sessid` …
CVE-2026-117896.520.1Red HatRed Hat Directory Server 11CWE-191389-ds-base: 389-ds-base: smd5 password storage plugin salt length integer un…
CVE-2026-479395.420.1AdobeAdobe Experience ManagerCWE-79Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-479415.420.1AdobeAdobe Experience ManagerCWE-79Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-479425.420.1AdobeAdobe Experience ManagerCWE-79Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-479435.420.1AdobeAdobe Experience ManagerCWE-79Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-479455.420.1AdobeAdobe Experience ManagerCWE-79Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-479485.420.1AdobeAdobe Experience ManagerCWE-79Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-479705.420.1AdobeAdobe Experience ManagerCWE-79Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-117934.920.1Red HatRed Hat Directory Server 11CWE-121389-ds-base: 389-ds-base: stack buffer overflow in checkprefix() algorithm id…
CVE-2026-482917.820.0AdobeFormat PluginsCWE-122Format Plugins | Heap-based Buffer Overflow (CWE-122)
CVE-2026-482927.820.0AdobeFormat PluginsCWE-122Format Plugins | Heap-based Buffer Overflow (CWE-122)
CVE-2026-479235.520.0AdobeAcrobat ReaderCWE-125Acrobat Reader | Out-of-bounds Read (CWE-125)
CVE-2026-417105.919.9SpringSpring RetryCWE-770Cache Exhaustion in Stateful Retries leads to Denial of Service
CVE-2026-64458.719.8EverpureFlashArrayCWE-939A flaw exists in FlashArray Purity where insufficient filtering of certain da…
CVE-2026-64448.619.8EverpureFlashArrayCWE-639A flaw exists in the FlashArray Purity management interface where an authenti…
CVE-2026-494757.519.7signalwirefreeswitchCWE-20FreeSWITCH: Out-of-bounds memory access in core STUN attribute parsing
CVE-2026-04114.219.7NETGEARRBE970CWE-200A Sensitive Information Disclosure Vulnerability in NETGEAR Orbi Satellites
CVE-2026-410067.519.6SpringSpring HATEOASCWE-284Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson config…
CVE-2026-479117.819.4AdobeAcrobat ReaderCWE-787Acrobat Reader | Out-of-bounds Write (CWE-787)
CVE-2026-74869.819.3Netcad Software Inc.E-İmarCWE-89SQLi in Netcad's E-İmar
CVE-2026-80259.819.3MOSK Information Technologies Ltd.CBS PlatformCWE-89SQLi in MOSK Informatics' CBS Platform
CVE-2026-116168.819.4stiofansislandEvents Calendar for GeoDirectoryCWE-269Events Calendar for GeoDirectory <= 2.3.28 - Authenticated (Subscriber+) Priv…
CVE-2026-411087.019.2MicrosoftWindows 10 Version 1607CWE-122Windows DNS Client Elevation of Privilege Vulnerability
CVE-2026-84995.319.1helpfulcrowdHelpfulcrowd Product ReviewsCWE-843Helpfulcrowd Product Reviews <= 1.2.9 - Inccorect Authorization via Type Jugg…
CVE-2026-499567.119.0nesquenahermes-webuiCWE-862Hermes WebUI < 0.51.269 Profile Isolation Bypass via sessions search
CVE-2016-200628.818.7Ollie ArmstrongSimply PollCWE-89Simply Poll 1.4.1 Plugin for WordPress SQL Injection
CVE-2016-200658.818.7EvWillProduct Catalog 8CWE-89Product Catalog 8 1.2 Plugin WordPress SQL Injection
CVE-2017-202448.818.7Wow-CompanyWow FormsCWE-89Wow Forms WordPress Plugin 2.1 SQL Injection
CVE-2017-202458.818.7Wow-CompanyWow Viral SignupsCWE-89Wow Viral Signups 2.1 WordPress Plugin SQL Injection
CVE-2017-202468.818.7MissilesiloKittyCatfishCWE-89KittyCatfish 2.2 Plugin for WordPress SQL Injection
CVE-2026-92798.718.7logseqlogseqCWE-78Shell command injection in Logseq
CVE-2026-97467.118.6MongoDBMongoDB ServerCWE-617Server crashes in case of the use of exchange
CVE-2026-97477.118.6MongoDBMongoDB ServerCWE-617Crafted cross-shard merge aggregation crashes MongoDB Server
CVE-2026-97497.118.6MongoDBMongoDB ServerCWE-617Using MaxKey() may crash the server
CVE-2026-97527.118.6MongoDBMongoDB ServerCWE-476GeometryCollection with strict-winding polygon causes server crash during 2ds…
CVE-2026-92125.618.6NETGEARLBR1020CWE-20Insufficient authentication and input validation in certain NETGEAR products
CVE-2026-473485.118.5TYPO3TYPO3 CMSCWE-79TYPO3 CMS - Cross-Site Scripting in Indexed Search
CVE-2026-367219.818.5n/an/aCWE-347A lack of cryptographic signature verification in the validateAccessToken fun…
CVE-2026-485787.918.4MicrosoftWindows 10 Version 1607CWE-284Secure Boot Security Feature Bypass Vulnerability
CVE-2026-448027.818.3MicrosoftWindows 10 Version 1809CWE-416Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-448047.818.3MicrosoftWindows 11 version 26H1CWE-416Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-448077.818.3MicrosoftWindows 11 version 26H1CWE-416Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-448087.818.3MicrosoftWindows 11 version 26H1CWE-122Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-448097.818.3MicrosoftWindows 11 Version 24H2CWE-416Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2026-448117.818.3MicrosoftWindows 11 version 26H1CWE-122Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-448137.818.3MicrosoftWindows 11 version 26H1CWE-416Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-485837.818.3MicrosoftWindows 10 Version 1607CWE-416Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-418405.918.4SpringSpring FrameworkCWE-401Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks…

Results continue: ranks 401–719.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-09 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.