boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Sunday, June 14, 2026 · all times UTC← 2026-06-13 · archive · 2026-06-15 →

Security Box Score — June 14, 2026

17 CVEs published, led by GL.iNet (2).

17 CVEs published June 14, 2026: 1 critical, 10 high, 4 medium, 2 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 0 awaiting enrichment.

Standings

League
MTDYTD2025 same span2025 full
CVEs published33727833——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

349 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux9510628466331411120.27.8.0013-118 ▼
google59176667406272217760.88.1.0023+591 ▲
microsoft207743555121706286192.67.8.0044+69 ▲
red hat441388576211200.06.7.0030+39 ▲
apple146612142288710.65.7.0019-1 ▼
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
debian220020100.06.5.0023+2 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
netgear171700161000.04.3.0024+17 ▲
cisco315546056960.07.5.0694+2 ▲
palo alto networks911127113218.25.9.0022+7 ▲
ivanti49450025555.68.8.5187+3 ▲
checkpoint3915303111.17.5.0410+3 ▲
fortinet29432028333.38.3.0076+1 ▲
ubiquiti584400300.08.9.0052+5 ▲
vmware3402207125.06.7.0036+3 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache6710115404323311.07.3.0052+63 ▲
gitlab1118041224211.14.8.0024+11 ▲
mozilla5113440900.07.5.0032+1 ▲
docker250500000.08.8.0021+2 ▲
drupal0511304120.05.1.00260
github021100000.08.1.03470
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
adobe1241264487221921.65.5.0021+124 ▲
ibm11601329180600.07.5.0028+11 ▲
oracle2301016402726.78.1.0027+2 ▲
progress591710600.07.5.0036+5 ▲
solarwinds36231010466.77.8.6082+3 ▲
veeam142200100.09.0.0052+1 ▲
zohocorp020110000.07.1.01040
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5 ▲
d-link9110425300.05.5.0058+9 ▲
siemens780440000.07.5.0020+6 ▲
abb550410000.07.2.0018+5 ▲
dahua330111000.06.9.0036+3 ▲
hitachi energy020020000.05.7.00140
moxa110100000.07.0.0007+1 ▲
schneider electric110100000.07.1.0023+1 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring6869227391000.06.5.0023+68 ▲
sourcecodester3658002434000.02.1.0026+36 ▲
edimax051032019100.07.4.00590
concrete cms2461111321000.06.2.0015+2 ▲
open ises044221210000.07.1.00210
helmholz04203930000.07.1.00260
mb connect line04203930000.07.1.00260
openclaw3440024124000.07.4.0022+34 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9991100.010.0
CVE-2026-35273.954799.99.8
CVE-2026-9082.883299.89.8
CVE-2026-50751.837799.79.3
CVE-2026-45498.630899.17.5
CVE-2026-49160.538398.97.5
CVE-2026-10523.518798.99.8
CVE-2026-28318.400198.57.5
CVE-2026-53435.376698.48.8
CVE-2026-46442.363498.49.4
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9991KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4508710.0.1296
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-2022310.0.0083
CVE-2026-4714010.0.0082
CVE-2026-4720810.0.0076
Most disclosures (vendor)
VendorCVEs
google759
linux521
microsoft234
adobe124
apache84
red hat81
spring69
ibm60
sourcecodester58
edimax51
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco9
apple7
google6
ivanti5
solarwinds4
berriai3
fortinet3
smartertools3
adobe2
Most-affected ecosystems
EcosystemAdvisories
Maven35
Packagist22
PyPI11
npm4
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2025-48595Google0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-20245Cisco0
CVE-2026-28318SolarWinds0
CVE-2026-34926Trend Micro, Inc.0
CVE-2026-35273Oracle Corporation0
CVE-2026-41091Microsoft0
CVE-2026-45247Mirasvit0
CVE-2026-45321@tanstack0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171670
CVE-2021-27102n/a2021-11-171670
CVE-2021-27101n/a2021-11-171670
CVE-2021-27103n/a2021-11-171670
CVE-2021-21017Adobe2021-11-171670
CVE-2021-28550Adobe2021-11-171670
CVE-2021-42013Apache Software Foundation2021-11-171670
CVE-2021-41773Apache Software Foundation2021-11-171670
CVE-2021-30858Apple2021-11-171670
CVE-2021-30860Apple2021-11-171670

Transactions

EXPLOIT PUBLISHED — CVE-2026-12188 (Grit42 Grit). Public exploit reference added.

Yesterday's Results

How to read these box scores · glossary

17 CVEs published. 17 box scores, 0 table rows — nothing truncated.

Ruijie EG105G-P JSON-RPC Diagnose Endpoint diagnose nslookup command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    7.3   .0238   82.6     —
AFFECTED
  Product   Versions  Fixed
  EG105G-P  2.340 –   —
TIMELINE
  Jun 14  Reserved by CNA
  Jun 14  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
GL.iNet GL-MT3000 Tor Proxy Service Configuration tor replace_country command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0197   78.8     —
AFFECTED
  Product    Versions  Fixed
  GL-MT3000  4.4.0 –   4.7
TIMELINE
  Jun 14  Reserved by CNA
  Jun 14  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
GL.iNet GL-MT3000 Online Firmware Upgrade one_click_upgrade command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0194   78.6     —
AFFECTED
  Product    Versions  Fixed
  GL-MT3000  4.4.0 –   4.7
TIMELINE
  Jun 14  Reserved by CNA
  Jun 14  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
RURBAN GD — GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0135   69.4     —
AFFECTED
  Product  Versions     Fixed
  GD       unspecified  —
TIMELINE
  Jun 7   Reserved by CNA
  Jun 14  Published (CNA: CPANSec)
CWE-73, CWE-78 · CNA: CPANSec · CVSS v3.1 · 4 references · NVD status: Deferred
SHLOMIF Config::IniFiles — Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   R  C  H  H  H    8.6   .0107   62.2     —
AFFECTED
  Product           Versions     Fixed
  Config::IniFiles  unspecified  —
TIMELINE
  Jun 7   Reserved by CNA
  Jun 14  Published (CNA: CPANSec)
CWE-73, CWE-78 · CNA: CPANSec · CVSS v3.1 · 4 references · NVD status: Deferred
debevv nanoMODBUS — nanoMODBUS Off-by-One Buffer Overflow in recv_msg_header() via Crafted MBAP Length Field
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   H    7.8   .0054   43.0     —
AFFECTED
  Product     Versions     Fixed
  nanoMODBUS  unspecified  —
TIMELINE
  Jun 13  Reserved by CNA
  Jun 14  Published (CNA: TuranSec)
CWE-193, CWE-787 · CNA: TuranSec · CVSS v4.0 · 4 references · NVD status: Deferred
LiamBindle MQTT-C — MQTT-C Heap Out-of-Bounds Read and Integer Underflow in mqtt_unpack_publish_response()
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   H    7.8   .0041   33.6     —
AFFECTED
  Product  Versions     Fixed
  MQTT-C   unspecified  —
TIMELINE
  Jun 13  Reserved by CNA
  Jun 14  Published (CNA: TuranSec)
CWE-125, CWE-191 · CNA: TuranSec · CVSS v4.0 · 4 references · NVD status: Deferred
driftregion iso14229 — iso14229 Integer Underflow and Out-of-Bounds Read in Handle_0x27_SecurityAccess()
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   H    7.8   .0041   33.6     —
AFFECTED
  Product   Versions     Fixed
  iso14229  unspecified  —
TIMELINE
  Jun 13  Reserved by CNA
  Jun 14  Published (CNA: TuranSec)
CWE-125, CWE-191 · CNA: TuranSec · CVSS v4.0 · 4 references · NVD status: Deferred
Linux-PAM pam_userdb Observable Timing Discrepancy in Plaintext Password Comparison
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   N   H   N   N    6.9   .0033   25.6     —
AFFECTED
  Product    Versions     Fixed
  Linux-PAM  unspecified  —
TIMELINE
  Jun 13  Reserved by CNA
  Jun 14  Published (CNA: TuranSec)
CWE-208 · CNA: TuranSec · CVSS v4.0 · 4 references · NVD status: Deferred
GALAYOU Y4 Web Server buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   N   N   H   H   H    7.4   .0032   23.8     —
AFFECTED
  Product  Versions  Fixed
  Y4       1.0.0 –   —
TIMELINE
  Jun 14  Reserved by CNA
  Jun 14  Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
OpenStack Ironic — In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  N  N    6.8   .0029   21.0     —
AFFECTED
  Product  Versions  Fixed
  Ironic   17.0.0 –  —
TIMELINE
  Jun 14  Reserved by CNA
  Jun 14  Published (CNA: mitre)
CWE-212 · CNA: mitre · CVSS v3.1 · 3 references · NVD status: Deferred
Grit42 Grit GritEntityController grit_entity_controller.rb sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0020    9.4     —
AFFECTED
  Product  Versions  Fixed
  Grit     0.1 –     —
TIMELINE
  Jun 14  Public exploit reference published
  Jun 14  Reserved by CNA
  Jun 14  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Unknown Iptanus File Upload — Iptanus File Upload < 5.1.7 - File Overwrite via Race Condition
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   R  U  N  H  L    5.4   .0016    5.2     —
AFFECTED
  Product              Versions     Fixed
  Iptanus File Upload  unspecified  —
TIMELINE
  Jan 26  Reserved by CNA
  Jun 14  Published (CNA: WPScan)
CWE-362 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Deferred
VS Revo RevoUninstaller IOCTL RevoDetector.sys IOCtl_Handler heap-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   H   H   H    7.1   .0014    3.7     —
AFFECTED
  Product          Versions  Fixed
  RevoUninstaller  2.5.* –   2.7.0
TIMELINE
  Jun 14  Reserved by CNA
  Jun 14  Published (CNA: VulDB)
CWE-119, CWE-122 · CNA: VulDB · CVSS v4.0 · 10 references · NVD status: Deferred
Comma AI Openpilot Pickle modeld.py pickle.loads deserialization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   H   H   H    7.1   .0014    3.3     —
AFFECTED
  Product    Versions  Fixed
  Openpilot  0.11 –    —
TIMELINE
  Jun 14  Reserved by CNA
  Jun 14  Published (CNA: VulDB)
CWE-20, CWE-502 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
Genspark AI Workspace App ai.mainfunc.genspark improper authorization in handler for custom url scheme
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    4.8   .0010    1.2     —
AFFECTED
  Product           Versions  Fixed
  AI Workspace App  2.8.4 –   —
TIMELINE
  Jun 14  Reserved by CNA
  Jun 14  Published (CNA: VulDB)
CWE-285, CWE-939 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Moovit Bus & Public Transit App com.tranzmate improper authorization in handler for custom url scheme
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    1.9   .0010    1.2     —
AFFECTED
  Product                   Versions  Fixed
  Bus & Public Transit App  1.18 –    —
TIMELINE
  Jun 14  Reserved by CNA
  Jun 14  Published (CNA: VulDB)
CWE-285, CWE-939 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-14 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.