boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Thursday, June 11, 2026 · all times UTC← 2026-06-10 · archive · 2026-06-12 →

Security Box Score — June 11, 2026

194 CVEs published, led by Google (27).

194 CVEs published June 11, 2026: 20 critical, 96 high, 71 medium, 7 low; 1 in the KEV catalog at press time; 7 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 169 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published30537514——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

343 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux9510628466331411120.27.8.0013-116 ▼
google59076566406272217760.88.1.0023+590 ▲
microsoft207743555121706286192.67.8.0044+195 ▲
red hat391338546011200.06.5.0031+34 ▲
apple146612142288710.65.7.0019-1 ▼
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
debian220020100.06.5.0023+2 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
netgear171700161000.04.3.0024+17 ▲
cisco315546056960.07.5.0694+3 ▲
palo alto networks911127113218.25.9.0022+8 ▲
ivanti49450025555.68.8.5187+3 ▲
checkpoint3915303111.17.5.0410+3 ▲
fortinet29432028333.38.3.0076+2 ▲
vmware3402207125.06.7.0036+3 ▲
zyxel230030900.06.5.0017+2 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache569012363923311.17.2.0053+52 ▲
gitlab1118041224211.14.8.0024+11 ▲
mozilla5113440900.07.5.0032+1 ▲
docker250500000.08.8.0021+2 ▲
drupal0511304120.05.1.00260
github021100000.08.1.03470
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
adobe1231254477221921.65.5.0021+123 ▲
ibm10591328180600.07.5.0028+10 ▲
oracle129916402713.48.1.0027+1 ▲
progress591710600.07.5.0036+5 ▲
solarwinds36231010466.77.8.6082+3 ▲
veeam142200100.09.0.0052+1 ▲
zohocorp020110000.07.1.01040
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5 ▲
d-link8100325300.04.2.0055+8 ▲
siemens780440000.07.5.0020+7 ▲
abb550410000.07.2.0018+5 ▲
dahua330111000.06.9.0036+3 ▲
hitachi energy020020000.05.7.00140
schneider electric110100000.07.1.0023+1 ▲
tp-link00000010———0
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring6869227391000.06.5.0023+68 ▲
sourcecodester3557002433000.02.1.0026+35 ▲
edimax051032019100.07.4.00590
concrete cms2461111321000.06.2.0015+2 ▲
open ises044221210000.07.1.00210
helmholz04203930000.07.1.00260
mb connect line04203930000.07.1.00260
totolink338026111000.08.9.0191+3 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9991100.010.0
CVE-2026-0257.939199.87.8
CVE-2026-20182.915299.810.0
CVE-2026-9082.883299.89.8
CVE-2026-50751.837799.79.3
CVE-2026-42897.712099.48.1
CVE-2026-42945.680599.39.2
CVE-2026-45498.630899.17.5
CVE-2026-49160.538398.97.5
CVE-2026-10523.518798.99.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9991KEV
CVE-2026-2018210.0.9152KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4508710.0.1296
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-4399710.0.0098
CVE-2026-2022310.0.0083
Most disclosures (vendor)
VendorCVEs
google758
linux525
microsoft236
adobe123
red hat76
apache73
spring69
ibm59
sourcecodester57
edimax51
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco9
apple7
google6
ivanti5
solarwinds4
berriai3
fortinet3
smartertools3
adobe2
Most-affected ecosystems
EcosystemAdvisories
Maven24
Packagist22
PyPI11
npm3
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2025-48595Google0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-20245Cisco0
CVE-2026-28318SolarWinds0
CVE-2026-34926Trend Micro, Inc.0
CVE-2026-41091Microsoft0
CVE-2026-42897Microsoft0
CVE-2026-45247Mirasvit0
CVE-2026-45321@tanstack0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171667
CVE-2021-27102n/a2021-11-171667
CVE-2021-27101n/a2021-11-171667
CVE-2021-27103n/a2021-11-171667
CVE-2021-21017Adobe2021-11-171667
CVE-2021-28550Adobe2021-11-171667
CVE-2021-42013Apache Software Foundation2021-11-171667
CVE-2021-41773Apache Software Foundation2021-11-171667
CVE-2021-30858Apple2021-11-171667
CVE-2021-30860Apple2021-11-171667

Transactions

EXPLOIT PUBLISHED — axios: 9 CVEs (CVE-2026-44486, CVE-2026-44487, CVE-2026-44488, CVE-2026-44489, CVE-2026-44490, CVE-2026-44492, CVE-2026-44494, CVE-2026-44495, CVE-2026-44496). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-11816 (keras-team/keras). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-11945 (DALIBO PostgreSQL Anonymizer). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-44705 (raszi node-tmp). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-49982 (raszi node-tmp). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-5497 (vllm-project/vllm). Public exploit reference added.

DUE DATE PASSED — CVE-2026-45321 (@tanstack arktype-adapter). CISA remediation deadline was June 10, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-48027 (nrwl nx-console). CISA remediation deadline was June 10, 2026; still in catalog.

Yesterday's Results

How to read these box scores · glossary

194 CVEs published. 25 box scores, 169 table rows — nothing truncated.

Ivanti Sentry
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS    %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .9991   100.0   YES
AFFECTED
  Product  Versions     Fixed
  Sentry   unspecified  R10.5.2
TIMELINE
  Jun 1   Reserved by CNA
  Jun 9   Patch available
  Jun 9   Public exploit reference published
  Jun 11  Added to CISA KEV, due Jun 14
  Jun 11  Published (CNA: ivanti)
CWE-78 · CNA: ivanti · CVSS v3.1 · 3 references · NVD status: Analyzed · KEV due June 14, 2026
davidanderson UpdraftPlus: WP Backup & Migration Plugin — UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0358   88.5     —
AFFECTED
  Product                                    Versions     Fixed
  UpdraftPlus: WP Backup & Migration Plugin  unspecified  —
TIMELINE
  Jun 3   Reserved by CNA
  Jun 11  Published (CNA: Wordfence)
CWE-347 · CNA: Wordfence · CVSS v3.1 · 4 references · NVD status: Deferred
MariaDB server has unsafe parameter handling in `wsrep_notify_cmd`
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0158   73.6     —
AFFECTED
  Product  Versions                Fixed
  server   >= 10.6.1, < 10.6.27 –  —
TIMELINE
  May 28  Reserved by CNA
  Jun 11  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v3.1 · 15 references · NVD status: Modified
Beardev JoomSport — WordPress JoomSport plugin <= 5.7.7 - SQL Injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  N  L    9.3   .0132   68.7     —
AFFECTED
  Product    Versions  Fixed
  JoomSport  n/a –     5.7.8
TIMELINE
  Apr 29  Reserved by CNA
  Jun 11  Published (CNA: Patchstack)
CWE-89 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0103   60.9     —
AFFECTED
  Product  Versions                          Fixed
  netty    >= 4.2.0.Final, < 4.2.15.Final –  —
TIMELINE
  May 5   Reserved by CNA
  Jun 11  Published (CNA: GitHub_M)
CWE-284, CWE-697 · CNA: GitHub_M · CVSS v3.1 · 22 references · NVD status: Modified
Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  C  H  H  N    8.7   .0102   60.7     —
AFFECTED
  Product  Versions              Fixed
  axios    >= 1.0.0, < 1.16.0 –  —
TIMELINE
  May 6   Reserved by CNA
  Jun 11  Public exploit reference published
  Jun 11  Published (CNA: GitHub_M)
CWE-441, CWE-1321 · CNA: GitHub_M · CVSS v3.1 · 51 references · NVD status: Modified
lingdojo kana-dojo — KanaDojo < 0.1.18 Command Injection via patchNotesData.json in release.yml
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   P   H   H   N    8.5   .0091   57.3     —
AFFECTED
  Product    Versions     Fixed
  kana-dojo  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 11  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  N  N    8.6   .0087   56.1     —
AFFECTED
  Product  Versions              Fixed
  axios    >= 1.0.0, < 1.16.0 –  —
TIMELINE
  May 6   Reserved by CNA
  Jun 11  Public exploit reference published
  Jun 11  Published (CNA: GitHub_M)
CWE-918 · CNA: GitHub_M · CVSS v3.1 · 45 references · NVD status: Modified
Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  L  H    7.7   .0084   55.0     —
AFFECTED
  Product  Versions              Fixed
  axios    >= 1.0.0, < 1.15.2 –  —
TIMELINE
  May 6   Reserved by CNA
  Jun 11  Public exploit reference published
  Jun 11  Published (CNA: GitHub_M)
CWE-94, CWE-1321 · CNA: GitHub_M · CVSS v3.1 · 50 references · NVD status: Analyzed
Red Hat Red Hat Directory Server 11.5 E4S for RHEL 8 — 389-ds-base: 389-ds-base: integer overflow in sasl packet length bypasses size limit leading to heap buffer overflow
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  L  L  H    7.6   .0080   53.7     —
AFFECTED
  Product                                                                Versions     Fixed
  Red Hat Directory Server 11.5 E4S for RHEL 8                           unspecified  8060020260702180044.0ca98e7e
  Red Hat Directory Server 11.7 E4S for RHEL 8                           unspecified  8080020260702180836.f969626e
  Red Hat Directory Server 11.9 for RHEL 8                               unspecified  8100020260702145313.37ed7c03
  Red Hat Directory Server 12.2 E4S for RHEL 9                           unspecified  9020020260703060155.1674d574
  Red Hat Directory Server 12.4 E4S for RHEL 9                           unspecified  9040020260703055735.1674d574
  Red Hat Enterprise Linux 10                                            unspecified  0:3.2.0-8.el10_2
  Red Hat Enterprise Linux 10.0 Extended Update Support                  unspecified  0:3.0.6-19.el10_0
  Red Hat Enterprise Linux 7 Extended Lifecycle Support                  unspecified  0:1.3.11.1-13.el7_9
  Red Hat Enterprise Linux 8                                             unspecified  8100020260626120929.25e700aa
  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support  unspecified  8040020260629123121.96015a92
  + 13 more
TIMELINE
  Jun 9   Reserved by CNA
  Jun 11  Published (CNA: redhat)
CWE-190 · CNA: redhat · CVSS v3.1 · 20 references · NVD status: Awaiting Analysis
Axios: Allocation of Resources Without Limits or Throttling in axios
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0067   49.2     —
AFFECTED
  Product  Versions              Fixed
  axios    >= 1.7.0, < 1.16.0 –  —
TIMELINE
  May 6   Reserved by CNA
  Jun 11  Public exploit reference published
  Jun 11  Published (CNA: GitHub_M)
CWE-770 · CNA: GitHub_M · CVSS v3.1 · 51 references · NVD status: Modified
Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0067   49.2     —
AFFECTED
  Product  Versions              Fixed
  axios    >= 1.0.0, < 1.16.0 –  —
TIMELINE
  May 6   Reserved by CNA
  Jun 11  Public exploit reference published
  Jun 11  Published (CNA: GitHub_M)
CWE-400, CWE-1333 · CNA: GitHub_M · CVSS v3.1 · 41 references · NVD status: Modified
Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   N   N    8.2   .0066   49.0     —
AFFECTED
  Product  Versions              Fixed
  axios    >= 1.0.0, < 1.16.0 –  —
TIMELINE
  May 6   Reserved by CNA
  Jun 11  Public exploit reference published
  Jun 11  Published (CNA: GitHub_M)
CWE-201 · CNA: GitHub_M · CVSS v4.0 · 51 references · NVD status: Modified
Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0066   48.8     —
AFFECTED
  Product  Versions              Fixed
  axios    >= 1.0.0, < 1.16.0 –  —
TIMELINE
  May 6   Reserved by CNA
  Jun 11  Public exploit reference published
  Jun 11  Published (CNA: GitHub_M)
CWE-200 · CNA: GitHub_M · CVSS v3.1 · 45 references · NVD status: Modified
MacWarrior clipbucket-v5 — ClipBucket: Remote Play URL Command Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0060   46.2     —
AFFECTED
  Product        Versions          Fixed
  clipbucket-v5  < 5.5.3 - #140 –  —
TIMELINE
  Apr 30  Reserved by CNA
  Jun 11  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Deferred
keras-team keras-team/keras — Path Traversal in keras-team/keras
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  N    8.1   .0056   44.3     —
AFFECTED
  Product           Versions       Fixed
  keras-team/keras  unspecified –  —
TIMELINE
  Jun 9   Reserved by CNA
  Jun 11  Public exploit reference published
  Jun 11  Published (CNA: @huntr_ai)
CWE-22 · CNA: @huntr_ai · CVSS v3.1 · 6 references · NVD status: Modified
CyberArk Software, a Palo Alto Networks Company PAM Self-Hosted, Privilege Cloud — Idira Privileged Session Manager for SSH (PSMP): Arbitrary Command Execution via Improper Neutralization of Special Elements used in an OS Command
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   L    8.7   .0055   43.6     —
AFFECTED
  Product                           Versions  Fixed
  PAM Self-Hosted, Privilege Cloud  14.0 –    14.0.6
TIMELINE
  May 8   Reserved by CNA
  Jun 11  Published (CNA: palo_alto)
CWE-78 · CNA: palo_alto · CVSS v4.0 · 4 references · NVD status: Analyzed
CyberArk Software, a Palo Alto Networks Company Privileged Session Manager, Vault — Idira Privileged Session Manager (PSM): Potential Code Execution due to an Incomplete Input Validation
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0054   43.2     —
AFFECTED
  Product                            Versions  Fixed
  Privileged Session Manager, Vault  14.0 –    14.0.5
TIMELINE
  May 8   Reserved by CNA
  Jun 11  Published (CNA: palo_alto)
CWE-22 · CNA: palo_alto · CVSS v4.0 · 4 references · NVD status: Analyzed
nesquena hermes-webui — Hermes WebUI < 0.51.358 Unauthenticated Password Takeover via /api/settings
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   L    9.2   .0054   43.2     —
AFFECTED
  Product       Versions     Fixed
  hermes-webui  unspecified  —
TIMELINE
  Jun 2   Reserved by CNA
  Jun 11  Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Deferred
vllm-project vllm-project/vllm — Unbounded Frame Count in video/jpeg Base64 Data URL Processing Leads to OOM DoS in vllm-project/vllm
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0054   42.8     —
AFFECTED
  Product            Versions       Fixed
  vllm-project/vllm  unspecified –  —
TIMELINE
  Apr 3   Reserved by CNA
  Jun 11  Public exploit reference published
  Jun 11  Published (CNA: @huntr_ai)
CWE-400, CWE-770 · CNA: @huntr_ai · CVSS v3.1 · 5 references · NVD status: Modified
Hippoo Hippoo Mobile App for WooCommerce — WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0051   41.4     —
AFFECTED
  Product                            Versions  Fixed
  Hippoo Mobile App for WooCommerce  n/a –     1.9.5
TIMELINE
  May 27  Reserved by CNA
  Jun 11  Published (CNA: Patchstack)
CWE-266 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
CyberArk Software, a Palo Alto Networks Company Conjur Cloud (Edge Finding only) — Idira Secrets Manager SaaS Edge: Authentication Bypass of an internal validation mechanism
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   N    9.1   .0050   40.7     —
AFFECTED
  Product                           Versions  Fixed
  Conjur Cloud (Edge Finding only)  1.0 –     1.8
TIMELINE
  May 8   Reserved by CNA
  Jun 11  Published (CNA: palo_alto)
CWE-284 · CNA: palo_alto · CVSS v4.0 · 1 reference · NVD status: Analyzed
raszi node-tmp — tmp: Type-confusion bypass of _assertPath in tmp@0.2.6 allows path traversal via non-string prefix/postfix/template
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  L    8.2   .0050   40.3     —
AFFECTED
  Product   Versions  Fixed
  node-tmp  0.2.6 –   —
TIMELINE
  Jun 2   Reserved by CNA
  Jun 11  Public exploit reference published
  Jun 11  Published (CNA: GitHub_M)
CWE-20, CWE-22 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Analyzed
lingdojo kana-dojo — KanaDojo < 0.1.18 Sandbox Escape RCE via messages.cjs
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   P   H   H   N    8.5   .0049   39.7     —
AFFECTED
  Product    Versions     Fixed
  kana-dojo  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 11  Published (CNA: VulnCheck)
CWE-693 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Deferred
TP-Link Systems Inc. Tapo C110 v2 — Authenticated Format String Injection on TP-Link Tapo C110
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   L   N   N   H   H    7.0   .0046   38.1     —
AFFECTED
  Product       Versions     Fixed
  Tapo C110 v2  unspecified  —
TIMELINE
  Apr 13  Reserved by CNA
  Jun 11  Published (CNA: TPLink)
CWE-134 · CNA: TPLink · CVSS v4.0 · 4 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-442507.537.9nettynettyCWE-400Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays
CVE-2026-448907.537.9nettynettyCWE-400Netty has Unbounded Direct Memory Consumption in its RedisDecoder
CVE-2026-115619.837.2Soagen Informatics Technologies Software and Consulting Inc.ApinizerCWE-917SSTI in Soagen Informatics' Apinizer
CVE-2026-33298.737.1SonatypeNexus Repository ManagerCWE-307Nexus Repository Manager - Improper Restriction of Excessive Authentication A…
CVE-2026-447057.736.0raszinode-tmpCWE-22tmp: Path Traversal via unsanitized prefix/postfix enables directory escape
CVE-2026-416999.835.7SpringSpring for GraphQLCWE-502Unsafe Deserialization in Spring GraphQL
CVE-2026-538067.734.6OpenClawOpenClawCWE-367OpenClaw < 2026.5.12 - Shell Option Parsing Bypass in Exec Revalidation
CVE-2026-538107.734.7OpenClawOpenClawCWE-829OpenClaw < 2026.5.18 - Arbitrary Code Execution via Unscanned Marketplace Run…
CVE-2026-394949.331.8WBW PluginsProduct Filter by WBWCWE-89WordPress Product Filter by WBW plugin <= 3.1.2 - SQL Injection vulnerability
CVE-2026-409998.631.1SpringSpring Web ServicesCWE-918Spring WS SSRF via unvalidated WS-Addressing reply destinations
CVE-2026-537778.630.6PerryTSperryCWE-22Perry < 0.5.1159 Path Traversal via ArtifactReady WebSocket
CVE-2026-465198.830.3Flux159mcp-server-kubernetesCWE-863mcp-server-kubernetes Affected By Tool Access Control Bypass: Presentation-La…
CVE-2026-72507.529.7GitLabGitLabCWE-770Allocation of Resources Without Limits or Throttling in GitLab
CVE-2026-409975.329.2SpringSpring Web ServicesCWE-209SOAP security faults leak Spring Security account state
CVE-2026-450609.829.1MacWarriorclipbucket-v5CWE-89ClipBucket: Blind SQL Injection in progress_video.php
CVE-2026-451788.428.8CyberArk Software, a Palo Alto Networks CompanyConjur EnterpriseCWE-284Idira Secrets Manager Self-Hosted: Improper Access Control in Internal Cluste…
CVE-2026-78529.828.4Limatek System Inc.LimRAD NACCWE-434Unrestricted File Upload in Limatek's LimRAD NAC
CVE-2026-409988.227.8SpringSpring Web ServicesCWE-611Jaxp13 XPath XXE via StreamSource and SAXSource
CVE-2026-418567.527.8SpringSpring for GraphQLCWE-284Spring GraphQL Annotation Detection Vulnerability
CVE-2026-78708.826.8IBMiCWE-427IBM i is Affected by Privilege Escalation []
CVE-2026-538168.626.8OpenClawOpenClawCWE-862OpenClaw < 2026.5.18 - Exec Lifecycle Event Forgery via Paired Node
CVE-2026-118399.925.9Başarsoft Information Technologies Inc.RotabanCWE-434Arbitrary File Upload in Basarsoft's Rotaban
CVE-2026-385819.825.2n/an/aCWE-89SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0…
CVE-2026-471729.524.6duck-organizationquest-botCWE-829Quest Bot: Untrusted pull request code can be built and deployed by privilege…
CVE-2026-471718.824.6duck-organizationquest-botCWE-116Quest Bot: Reminder messages allow stored mass mentions through `@everyone` a…
CVE-2026-537815.324.7steipetesummarizeCWE-770Summarize < 0.17.0 Disk Exhaustion via Uncapped Media Download
CVE-2026-15006.524.4GitLabGitLabCWE-770Allocation of Resources Without Limits or Throttling in GitLab
CVE-2026-471749.523.3duck-organizationduck-siteCWE-829Duck Site: Untrusted pull request code can trigger privileged production depl…
CVE-2026-539018.723.3cerebratecerebrateCWE-20Cerebrate before v1.37 allows mass assignment of record identifiers during ob…
CVE-2026-538077.723.3OpenClawOpenClawCWE-863OpenClaw < 2026.5.6 - Authorization Bypass in Telegram Interactive Callbacks …
CVE-2026-464898.123.2SolidInvoiceSolidInvoiceCWE-79SolidInvoice: Unrestricted file upload with no MIME validation allows stored …
CVE-2026-538178.723.0OpenClawOpenClawCWE-290OpenClaw < 2026.5.22 - Control UI Locality Spoofing in Device Pairing
CVE-2026-444908.223.0axiosaxiosCWE-1321Axios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in ax…
CVE-2026-538117.723.0OpenClawOpenClawCWE-290OpenClaw < 2026.5.7 - Privilege Escalation via Mutable Display Names in Matri…
CVE-2026-454188.822.8MacWarriorclipbucket-v5CWE-89ClipBucket: Blind SQL Injection in subtitle_edit.php
CVE-2026-471898.322.7duck-organizationquest-botCWE-639Quest Bot: AutoMod removal can delete rules from another guild by global rule ID
CVE-2026-528596.922.3vimvimCWE-125Vim: Out-of-bounds Read in Terminal Screen Snapshot
CVE-2026-119864.922.1Red HatRed Hat build of Keycloak 26.6CWE-425Keycloak-rest-admin-ui-ext: authorization bypass vulnerability in the admin-u…
CVE-2026-538198.721.8OpenClawOpenClawCWE-426OpenClaw < 2026.5.27 - Arbitrary Homebrew Executable Execution via Workspace …
CVE-2026-120078.820.6GoogleChromeCWE-416Use after free in Core in Google Chrome on Windows prior to 149.0.7827.115 al…
CVE-2026-538148.720.0OpenClawOpenClawCWE-266OpenClaw < 2026.5.20 - Privilege Escalation via Hook-Triggered CLI MCP Tool A…
CVE-2026-120108.319.0GoogleChromeCWE-122Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.1…
CVE-2023-339997.119.0WPVibesWP Mail LogCWE-79WordPress WP Mail Log plugin <= 1.0.2 - Reflected Cross Site Scripting (XSS) …
CVE-2025-463157.518.7ApplemacOSCWE-284A permissions issue was addressed with additional restrictions. This issue is…
CVE-2026-472506.118.3Flux159mcp-server-kubernetesCWE-88mcp-server-kubernetes: kubectl-generic flag injection enables Kubernetes bear…
CVE-2026-471736.317.6duck-organizationquest-botCWE-116Quest Bot: Ticket reason allows mass-mention injection
CVE-2026-537826.317.4steipetesummarizeCWE-918Summarize < 0.17.0 SSRF via podcast:transcript URL fetch
CVE-2026-118505.017.5Red HatRed Hat Hardened ImagesCWE-191Krb5: krb5: integer underflow in berval2tl_data() leads to heap out-of-bounds…
CVE-2026-536618.817.2malach-itboruta-serverCWE-614boruta-server sent sensitive session cookies without the Secure attribute
CVE-2026-458026.017.3SetasignFPDICWE-400FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service
CVE-2026-85898.716.8GitLabGitLabCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…
CVE-2026-120198.316.5GoogleChromeCWE-787Heap buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior t…
CVE-2026-499496.016.5steipeteCodexBarCWE-522CodexBar < 0.33.0 Credential Leakage via HTTP Redirect
CVE-2026-63384.916.4KongKong Enterprise GatewayCWE-444HTTP request smuggling in Kong Enteprise Gateway
CVE-2026-471818.716.2PenguinModPenguinMod-BackendApiCWE-20PenguinMod-BackendApi: NoSQL Injection in Password Reset Endpoint Allows Acco…
CVE-2026-471765.716.2duck-organizationquest-botCWE-200Quest Bot: Logging module can disclose private-channel message contents to a …
CVE-2026-471775.716.2duck-organizationquest-botCWE-200Quest Bot: Ticket transcripts can disclose private ticket contents to a lower…
CVE-2026-471627.316.1vimvimCWE-74Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted direct…
CVE-2026-100878.716.0GitLabGitLabCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…
CVE-2026-77878.115.9IBMLangflow OSSCWE-639Unauthenticated Session History Access via Public Flow Execution
CVE-2026-119457.515.7DALIBOPostgreSQL AnonymizerCWE-89PostgreSQL Anonymizer: SQL injection in the rules import functions
CVE-2026-92046.515.7GitLabGitLabCWE-918Server-Side Request Forgery (SSRF) in GitLab
CVE-2026-538124.915.7OpenClawOpenClawCWE-918OpenClaw < 2026.5.18 - Private-Network Navigation Bypass via Browser Act Inte…
CVE-2026-120088.315.6GoogleChromeCWE-416Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115…
CVE-2026-120098.315.6GoogleChromeCWE-20Insufficient validation of untrusted input in Accessibility in Google Chrome …
CVE-2026-120118.315.6GoogleChromeCWE-416Use after free in WebMIDI in Google Chrome on Windows prior to 149.0.7827.115…
CVE-2026-539125.115.1cerebratecerebrateCWE-200Cerebrate self-registration password hash exposure via inbox and audit log views
CVE-2026-471697.514.6duck-organizationquest-botCWE-266Quest Bot: Manage Server users can configure AutoRole to grant Administrator …
CVE-2026-84067.114.6OS4EDopenSIS-ClassicCWE-639openSIS Classic 9.3 - Insecure Direct Object Reference in Sent Mail
CVE-2026-120266.514.4GoogleChromeCWE-125Out of bounds read in Video in Google Chrome on ChromeOS prior to 149.0.7827.…
CVE-2023-402005.314.3Essential PluginWP Logo Showcase Responsive Slider and CarouselCWE-639WordPress WP Logo Showcase Responsive Slider and Carousel plugin <= 3.6 - Bro…
CVE-2026-444895.314.3axiosaxiosCWE-113Axios: Proxy-Authorization Header Injection via Prototype Pollution — Incompl…
CVE-2026-35533.114.3GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2026-471752.314.1duck-organizationquest-botCWE-116Quest Bot: Moderation reason fields allow bot-powered `@everyone` / `@here` p…
CVE-2026-471882.314.1duck-organizationquest-botCWE-116Quest Bot: Unban and unwarn reason fields still allow bot-powered mass mentions.
CVE-2026-466977.514.1stefanbohacekfediverse-embeds-wordpress-pluginCWE-918Fediverse Embeds: Unauthenticated SSRF / open proxy via REST media-proxy endp…
CVE-2022-458135.413.5BeRocketAdvanced AJAX Product FiltersCWE-862WordPress Advanced AJAX Product Filters plugin <= 1.6.3.3 - Broken Access Con…
CVE-2025-463085.313.6AppleiOS and iPadOSCWE-284An authorization issue was addressed with improved state management. This iss…
CVE-2026-120168.313.5GoogleChromeCWE-20Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827…
CVE-2026-120238.313.5GoogleChromeCWE-416Use after free in GPU in Google Chrome on Mac prior to 149.0.7827.115 allowed…
CVE-2026-120288.313.5GoogleChromeCWE-416Use after free in GPU in Google Chrome on Android prior to 149.0.7827.115 all…
CVE-2026-409948.213.5SpringSpring Web ServicesCWE-1188Wss4jSecurityInterceptor disables WS-I BSP validation by default
CVE-2026-466985.313.5stefanbohacekfediverse-embeds-wordpress-pluginCWE-918Fediverse Embeds: Public-nonce SSRF via ftf_get_site_info AJAX action
CVE-2026-537026.513.3Red HatRed Hat Enterprise Linux 10CWE-787Gstreamer1-plugins-bad-free: gstreamer: stack buffer overflow in h.265 buffer…
CVE-2026-120155.313.2GoogleChromeCWE-416Use after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a…
CVE-2026-120255.313.2GoogleChromeCWE-20Insufficient validation of untrusted input in Network in Google Chrome prior …
CVE-2026-120128.112.9GoogleChromeCWE-416Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an…
CVE-2026-409856.413.0SpringSpring Web FlowCWE-917Data Binding Vulnerability in Spring Web Flow with Unified EL Parser
CVE-2026-120279.612.8GoogleChromeCWE-250Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827…
CVE-2026-120208.812.8GoogleChromeCWE-416Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 al…
CVE-2026-528607.512.8vimvimCWE-94Vim: Arbitrary Code Execution via Python Omni-Completion
CVE-2026-96489.112.7Haskell Programming Languagecrypton-certificate—CVE-2026-9648
CVE-2026-410003.712.7SpringSpring Web ServicesCWE-294WSS4J validation does not use configured replay cache
CVE-2026-107334.312.3GitLabGitLabCWE-1021Improper Restriction of Rendered UI Layers or Frames in GitLab
CVE-2026-537235.812.2guzzleguzzle-servicesCWE-20guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injec…
CVE-2026-471637.211.7duck-organizationquest-botCWE-862Quest Bot: Unprivileged users can create and remove AutoMod rules.
CVE-2026-538157.111.7OpenClawOpenClawCWE-862OpenClaw < 2026.5.19 - Channel Allowlist Bypass in Message Read Actions
CVE-2026-96944.311.2GitLabGitLabCWE-153Improper Neutralization of Substitution Characters in GitLab
CVE-2026-409877.111.1SpringSpring IntegrationCWE-22Remote-file synchronizer in Spring Integration writes server-supplied filenam…
CVE-2026-471707.710.9garlic-signagegarlic-hubCWE-918Garlic-Hub: SSRF vulnerability in uploadFromUrl endpoint
CVE-2026-120173.110.9GoogleChromeCWE-20Inappropriate implementation in Extensions in Google Chrome prior to 149.0.78…
CVE-2026-47649.410.7Google CloudDialogflow CXCWE-862Privilege Escalation in Dialogflow CX via Playbook Import
CVE-2026-539116.310.7cerebratecerebrateCWE-639Cerebrate primary key mass assignment in CRUD edit operations allows authenti…
CVE-2026-537016.510.6Red HatRed Hat Enterprise Linux 10CWE-787Gstreamer1-plugins-bad-free: gstreamer: out-of-bounds write in h.266/vvc pps …
CVE-2026-84648.310.3Neuron SoftGolem OEE MESCWE-22Path traversal in Neuron Soft Golem OEE MES
CVE-2026-409864.810.0SpringSpring Web FlowCWE-79Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML
CVE-2026-528587.39.9vimvimCWE-94Vim: Arbitrary Code Execution via Python Omni-Completion
CVE-2026-472386.59.8MacWarriorclipbucket-v5CWE-639ClipBucket: IDOR in videos subtitle editor
CVE-2026-489985.39.6guzzlepsr7CWE-918guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
CVE-2026-500058.39.4BrickcomCubeCWE-1392Brickcom Cameras Use of Default Credentials
CVE-2026-466228.19.4SolidInvoiceSolidInvoiceCWE-312SolidInvoice: API tokens stored as plaintext in the database allowing full cr…
CVE-2026-471576.59.1subzeroidaiograpiCWE-918aiograpi: Unsafe signup challenge path handling
CVE-2026-538086.09.1OpenClawOpenClawCWE-863OpenClaw < 2026.5.6 - Approval Policy Bypass in Skill Workshop Apply Flow
CVE-2026-120298.38.8GoogleChromeCWE-416Use after free in Video in Google Chrome on Windows prior to 149.0.7827.115 a…
CVE-2026-120308.38.8GoogleChromeCWE-122Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.11…
CVE-2026-120318.38.8GoogleChromeCWE-693Inappropriate implementation in Views in Google Chrome on Windows prior to 14…
CVE-2026-119566.38.8TwiNgatusCWE-614TwiN gatus OIDC Session Cookie oidc.go setSessionCookie missing secure attribute
CVE-2026-492145.38.6guzzlepsr7CWE-20guzzlehttp/psr7 has CRLF Injection via URI Host Component
CVE-2026-417008.18.5SpringSpring for GraphQLCWE-346Cross-Site WebSocket Hijacking in Spring for GraphQL
CVE-2026-120335.38.5GoogleChromeCWE-125Out of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 a…
CVE-2026-28274.78.4100pluginsOpen User Map PROCWE-79Open User Map PRO <= 1.4.31 - Unauthenticated Stored Cross-Site Scripting via…
CVE-2026-120358.88.3GoogleChromeCWE-416Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 a…
CVE-2026-62695.48.3GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2023-329594.38.0Sparkle WPMetroStoreCWE-862WordPress MetroStore theme <= 1.3.2 - Broken Access Control
CVE-2026-62774.37.7GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2026-120348.37.6GoogleChromeCWE-20Insufficient validation of untrusted input in Linux Toolkit Theming in Google…
CVE-2022-424795.47.2TemplateHouseSoledadCWE-862WordPress Soledad premium theme <= 8.2.5 - Broken Access Control vulnerability
CVE-2023-259695.47.1ThemeHunkContact Form & Lead Form Elementor BuilderCWE-862WordPress Contact Form & Lead Form Elementor Builder plugin <= 1.8.4 - Broken…
CVE-2026-120148.36.9GoogleChromeCWE-416Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an at…
CVE-2026-494824.36.4MacWarriorclipbucket-v5CWE-155ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subt…
CVE-2026-120228.36.0GoogleChromeCWE-362Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed…
CVE-2026-451738.45.5CyberArk Software, a Palo Alto Networks CompanyIdentity Browser ExtensionsCWE-346Idira Identity Browser Extension: Unauthorized Application Interaction via Or…
CVE-2026-120188.85.3GoogleChromeCWE-269Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149…
CVE-2026-120246.55.1GoogleChromeCWE-346Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7…
CVE-2026-69763.75.1GitLabGitLabCWE-639Authorization Bypass Through User-Controlled Key in GitLab
CVE-2026-502458.35.0BrickcomCubeCWE-306Brickcom Cameras Missing Authentication for Critical Function
CVE-2026-120323.14.9GoogleChromeCWE-346Inappropriate implementation in Passwords in Google Chrome on Android prior t…
CVE-2025-432785.54.5ApplemacOSCWE-61This issue was addressed with improved handling of symlinks. This issue is fi…
CVE-2026-40966.14.3IBMDevOps PlanCWE-644A vulnerability has been identified in IBM DevOps Plan that allows a Host Hea…
CVE-2026-409955.44.3SpringSpring Web ServicesCWE-287X.509 authentication bypasses Spring Security account checks
CVE-2022-446304.63.9YITHYITH WooCommerce Product Slider CarouselCWE-352WordPress YITH WooCommerce Product Slider Carousel plugin <= 1.16.0 - Cross-S…
CVE-2026-426537.13.7iova.mihaiSliceWPCWE-79WordPress SliceWP plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnerability
CVE-2025-242685.53.6ApplemacOSCWE-22A parsing issue in the handling of directory paths was addressed with improve…
CVE-2025-462935.53.6ApplemacOSCWE-59This issue was addressed with improved handling of symlinks. This issue is fi…
CVE-2026-33415.43.4IBMLangflow DesktopCWE-918IBM Langflow Desktop 1.0.0 - 1.9.2 DNS Rebinding Bypasses SSRF Protection All…
CVE-2026-471675.13.2vimvimCWE-94Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-de…
CVE-2026-410059.02.9Cloud FoundryUAACWE-347UAA accepts SAML Encrypted Assertions authentication bypass
CVE-2025-463135.52.8ApplemacOSCWE-532A logging issue was addressed with improved data redaction. This issue is fix…
CVE-2026-409964.82.8SpringSpring Web ServicesCWE-327Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default
CVE-2026-451758.52.7CyberArk Software, a Palo Alto Networks CompanyIdira Endpoint Privilege ManagerCWE-295Idira Endpoint Privilege Manager Agent: Security Control and Cryptographic Va…
CVE-2025-242848.82.6ApplemacOSCWE-693This issue was addressed with improved checks to prevent unauthorized actions…
CVE-2026-534235.92.6membraneframeworkmembrane_mp4_pluginCWE-770Unauthenticated denial-of-service via BEAM atom table exhaustion in membrane_…
CVE-2025-304315.52.6ApplemacOSCWE-693The issue was addressed with improved checks. This issue is fixed in macOS Se…
CVE-2026-451748.52.5CyberArk Software, a Palo Alto Networks CompanyIdira Endpoint Privilege ManagerCWE-404Idira Endpoint Privilege Manager Linux Agent: Potential bypass of Agent Daemo…
CVE-2026-451768.92.4CyberArk Software, a Palo Alto Networks CompanyIdira Endpoint Privilege ManagerCWE-269Idira Endpoint Privilege Manager Agent: Local Privilege Escalation via Intern…
CVE-2026-108477.82.3checkpointIdentity AgentCWE-427Local Privilege Escalation vulnerability in Check Point Identity Agent Full f…
CVE-2026-409925.02.3SpringSpring BootCWE-295Mail Auto-Configuration Does Not Enable SSL Hostname Verification
CVE-2025-304595.52.2ApplemacOSCWE-359A privacy issue was addressed by removing the vulnerable code. This issue is …
CVE-2025-241655.52.1ApplemacOSCWE-284A permissions issue was addressed with additional restrictions. This issue is…
CVE-2025-70645.61.8ABBFreelanceCWE-305Freelance Security Lock – Access to Windows OS
CVE-2025-312727.81.7ApplemacOSCWE-269The issue was addressed with improved checks. This issue is fixed in macOS Se…
CVE-2026-538137.31.7OpenClawOpenClawCWE-427OpenClaw < 2026.4.25 - Arbitrary Artifact Loading via Fake Package Root Resol…
CVE-2022-471504.31.6weDevsWooCommerce Conversion TrackingCWE-352WordPress WooCommerce Conversion Tracking plugin <= 2.0.10 - Cross-Site Reque…
CVE-2025-433395.51.5ApplemacOSCWE-284An access issue was addressed with additional sandbox restrictions. This issu…
CVE-2024-321104.30.9Magepeople inc.WpEventlyCWE-352WordPress Event Manager and Tickets Selling Plugin for WooCommerce plugin <= …
CVE-2026-538186.90.8OpenClawOpenClawCWE-862OpenClaw < 2026.4.24 - Owner-Only Tool Policy Bypass via MCP Loopback
CVE-2026-410015.30.7SpringSpring BootCWE-377Predictable Temp Directory in Artemis Auto-configuration
CVE-2024-456364.40.7IBMSecurity QRadar EDRCWE-522IBM Security QRadar EDR Software has a vulnerability where user credentials m…
CVE-2026-538094.80.6OpenClawOpenClawCWE-863OpenClaw < 2026.4.25 - Provider Alias Confusion in Embedded Runner Policy

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-11 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.