boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, June 16, 2026 · all times UTC← 2026-06-15 · archive · 2026-06-17 →

Security Box Score — June 16, 2026 — page 2

Edition of June 16, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–546 of 546
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-223128.613.8RadiflowiSAP Smart CollectorCWE-798Use of Hard-coded Credentials Vulnerability in Radiflow iSAP Smart Collector
CVE-2026-487756.813.8langchain-ailanggraphCWE-502LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading
CVE-2026-106394.813.9zephyrprojectzephyrCWE-416Use-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet i…
CVE-2026-01518.813.7GoogleAndroidCWE-190In IntfGraphCreate of intfgraph.c, there is a possible out of bounds write du…
CVE-2026-01548.813.7GoogleAndroidCWE-120In Modem, there is a possible way to trigger a modem crash during a SIP REFER…
CVE-2026-01608.813.7GoogleAndroidCWE-120In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, th…
CVE-2026-01618.813.7GoogleAndroidCWE-190In numberOfReportBlocks of RtpSession.cpp, there is a possible out of bounds …
CVE-2026-01628.813.7GoogleAndroidCWE-843In ParsePayloads of AudioSdpParser.cpp, there is a possible memory corruption…
CVE-2026-01648.813.7GoogleAndroidCWE-120In Modem, there is a possible out of bounds write due to a missing bounds che…
CVE-2026-467706.113.7Oracle CorporationOracle Application Development Framework (ADF)CWE-284Vulnerability in the Oracle Application Development Framework (ADF) product o…
CVE-2026-527127.613.4tnomiAttendance ManagerCWE-89WordPress Attendance Manager plugin <= 0.6.2 - SQL Injection vulnerability
CVE-2026-100936.413.3deepakkiteSecure Client Portal and Private File Sharing Plugin – User Private FilesCWE-79File Sharing & Download Manager <= 2.1.6 - Authenticated (Subscriber+) Stored…
CVE-2026-91875.313.3zealopensourceAbandoned Contact Form 7CWE-862Abandoned Contact Form 7 <= 2.2 - Missing Authorization to Unauthenticated Ar…
CVE-2026-123256.513.1MozillaFirefoxCWE-400Denial-of-service in the Graphics: ImageLib component
CVE-2026-538578.613.0OpenClawOpenClawCWE-290OpenClaw < 2026.5.3 - Mutable Display Name Binding in Zalo allowFrom Policy
CVE-2025-680457.513.0ArrayticsWP Event SOlutionCWE-862WordPress WP Event SOlution plugin <= 4.1.12 - Broken Access Control vulnerab…
CVE-2026-527117.513.0kilbotWooCommerce POSCWE-862WordPress WooCommerce POS plugin <= 1.8.14 - Broken Access Control vulnerability
CVE-2026-445876.112.7carrierwaveuploadercarrierwaveCWE-79CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metachar…
CVE-2026-538406.012.7OpenClawOpenClawCWE-522OpenClaw < 2026.5.12 - Custom Header Leakage via MCP Streamable HTTP Cross-Or…
CVE-2026-476847.712.5Sync-inserverCWE-918Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regE…
CVE-2026-123034.312.5MozillaFirefoxCWE-125Information disclosure due to incorrect boundary conditions in the Graphics: …
CVE-2026-395988.012.5Kodezen LLCAcademy LMS ProCWE-434WordPress Academy LMS Pro plugin < 3.5.2 - Arbitrary File Upload vulnerability
CVE-2026-487808.212.1foremforemCWE-287Forem vulnerable to bypass of email address domain restrictions
CVE-2026-487769.111.9langchain-ailangchain-aiCWE-22LangGraph SDK has unsafe URL path construction
CVE-2026-490738.511.4wpWaxDirectorist BookingCWE-89WordPress Directorist Booking plugin <= 3.0.3 - SQL Injection vulnerability
CVE-2026-467869.611.3Oracle CorporationOracle WebCenter ContentCWE-352Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-01567.511.2GoogleAndroidCWE-476In checkSsrcCollisionOnRcv of RtpSession.cpp, there is a possible memory safe…
CVE-2026-123196.511.0MozillaFirefoxCWE-400Denial-of-service in the Audio/Video: Playback component
CVE-2026-538446.011.1OpenClawOpenClawCWE-862OpenClaw < 2026.4.29 - Session Visibility Check Bypass in Shared Memory Search
CVE-2026-538596.011.1OpenClawOpenClawCWE-918OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot Inconsistency
CVE-2026-487819.910.9gitroomhqpostiz-appCWE-302Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery
CVE-2026-123247.310.9MozillaFirefoxCWE-703Incorrect boundary conditions in the Graphics: CanvasWebGL component
CVE-2026-17645.610.9Red HatRed Hat Enterprise Linux 10CWE-125Localsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer ove…
CVE-2025-712618.610.8SUSEHarvesterCWE-295Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS
CVE-2026-123225.410.7MozillaFirefoxCWE-1021Clickjacking issue in the Widget: Gtk component
CVE-2026-479647.810.5AdobeDNG SDKCWE-122DNG SDK | Heap-based Buffer Overflow (CWE-122)
CVE-2026-538522.310.6OpenClawOpenClawCWE-636OpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairing
CVE-2026-395775.510.4Elated-ThemesPlayroomCWE-502WordPress Playroom theme <= 1.4.1 - PHP Object Injection vulnerability
CVE-2026-107804.310.3mohammadtanzilurrahmanStatic BlockCWE-639Static Block <= 2.2 - Insecure Direct Object Reference to Authenticated (Cont…
CVE-2026-477497.810.1leejetstable-diffusion.cppCWE-122stable-diffusion.cpp: Heap buffer overflow in SHORT_BINUNICODE parsing for Py…
CVE-2026-352728.49.8Oracle CorporationPeopleSoft Enterprise PT PeopleToolsCWE-269Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle P…
CVE-2026-01414.39.8GoogleAndroidCWE-120In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to …
CVE-2024-304765.49.6DellPowerStoreCWE-79PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerS…
CVE-2026-541917.19.5Pods FrameworkPodsCWE-79WordPress Pods plugin <= 3.3.8 - Cross Site Scripting (XSS) vulnerability
CVE-2026-541987.19.5David LingrenMedia LIbrary AssistantCWE-79WordPress Media LIbrary Assistant plugin <= 3.35 - Reflected Cross Site Scrip…
CVE-2026-467859.39.4Oracle CorporationOracle WebCenter ContentCWE-352Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-408096.59.3Rara ThemesMetro MagazineCWE-862WordPress Metro Magazine theme <= 1.4.1 - Broken Access Control vulnerability
CVE-2026-241557.89.0NVIDIANeMo FrameworkCWE-94NVIDIA NeMo Framework for all platforms contains a code injection vulnerabili…
CVE-2026-538516.38.8OpenClawOpenClawCWE-862OpenClaw < 2026.5.12 - Slack Reaction Event Notification Bypass
CVE-2026-123049.18.6MozillaFirefoxCWE-346Same-origin policy bypass in the Networking: Cookies component
CVE-2026-26045.68.6GNOMEEvolution Data ServerCWE-73Evolution-data-server: evolution data server: arbitrary file deletion via inc…
CVE-2026-352888.28.4Oracle CorporationPeopleSoft Enterprise PT PeopleToolsCWE-269Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle P…
CVE-2026-538412.18.4OpenClawOpenClawCWE-83OpenClaw < 2026.5.12 - Cross-Site Scripting via Unsafe Markdown Links in Expo…
CVE-2026-488697.18.2KriesiEnfoldCWE-79WordPress Enfold theme <= 7.1.4 - Reflected Cross Site Scripting (XSS) vulner…
CVE-2026-123114.78.1MozillaFirefoxCWE-200Information disclosure, sandbox escape in the Security: Process Sandboxing co…
CVE-2026-538452.38.0OpenClawOpenClawCWE-693OpenClaw < 2026.5.6 - Skill-Command Dispatch Hook Bypass via Before-Tool-Call…
CVE-2026-538482.38.0OpenClawOpenClawCWE-184OpenClaw < 2026.5.26 - Exec Allowlist Bypass via Transparent Command Wrappers
CVE-2026-01286.57.8GoogleAndroidCWE-190In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read d…
CVE-2026-477477.87.6leejetstable-diffusion.cppCWE-122stable-diffusion.cpp has a Heap-based Buffer Overflow
CVE-2026-477507.87.6leejetstable-diffusion.cppCWE-787stable-diffusion.cpp: Heap buffer overflow in GLOBAL opcode parsing for PyTor…
CVE-2025-691517.17.5ThemeGoodsGrand Car RentalCWE-79WordPress Grand Car Rental theme <= 3.7 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-468696.57.6Oracle CorporationMySQL ShellCWE-352Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: D…
CVE-2026-123204.37.4MozillaFirefoxCWE-200Information disclosure in the Password Manager component
CVE-2026-01404.37.3GoogleAndroidCWE-125In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an …
CVE-2026-538475.37.2OpenClawOpenClawCWE-266OpenClaw < 2026.5.6 - Privilege Escalation via Active Memory Write Scope
CVE-2026-395487.17.0SneeitMagOneCWE-79WordPress MagOne theme <= 9.0 - Reflected Cross Site Scripting (XSS) vulnerab…
CVE-2026-123134.77.1MozillaFirefoxCWE-269Information disclosure, sandbox escape in the Security: Process Sandboxing co…
CVE-2026-01303.56.8GoogleAndroidCWE-122In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to …
CVE-2026-420898.66.7yeomanenvironmentCWE-829yeoman-environment Vulnerable to Arbitrary Package Installation without User …
CVE-2026-468948.06.6Oracle CorporationOracle iSupplier PortalCWE-352Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Sui…
CVE-2026-527145.96.6SEO SquirrlySEO Plugin by Squirrly SEOCWE-862WordPress SEO Plugin by Squirrly SEO plugin <= 12.4.16 - Broken Access Contro…
CVE-2026-01655.76.5GoogleAndroidCWE-120In several functions of the RTCP packet decoder, there is a possible out-of-b…
CVE-2026-538602.36.6OpenClawOpenClawCWE-807OpenClaw < 2026.5.7 - Sender Policy Bypass via Mutable Conversation Identifie…
CVE-2025-116948.76.5Rockwell AutomationCompactLogix 5370CWE-354Rockwell Automation CompactLogix 5370 Controllers – Multiple Vulnerabilities
CVE-2026-487834.86.5gitroomhqpostiz-appCWE-345Postiz has an unauthenticated billing-enforcement bypass via /public/modify-s…
CVE-2026-538636.06.4OpenClawOpenClawCWE-639OpenClaw < 2026.4.25 - Unvalidated Group ID Acceptance in Tool Group Policy
CVE-2026-01554.36.3GoogleAndroidCWE-120In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a m…
CVE-2026-01574.36.3GoogleAndroidCWE-120In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missin…
CVE-2026-468658.26.3Oracle CorporationOracle Enterprise Manager Base PlatformCWE-284Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-123235.46.3MozillaFirefoxCWE-1021Spoofing issue in the DOM: Core & HTML component
CVE-2026-01293.56.3GoogleAndroidCWE-120In RtcpByePacket::decodeByePacket, there is a possible due to a missing bound…
CVE-2026-468776.06.1Oracle CorporationOracle VM VirtualBoxCWE-269Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-479275.55.9AdobeDNG SDKCWE-125DNG SDK | Out-of-bounds Read (CWE-125)
CVE-2026-479345.55.9AdobeDNG SDKCWE-125DNG SDK | Out-of-bounds Read (CWE-125)
CVE-2026-479635.55.9AdobeDNG SDKCWE-125DNG SDK | Out-of-bounds Read (CWE-125)
CVE-2026-106356.35.7zephyrprojectzephyrCWE-416Dangling memory-domain pointer (use-after-free) in Xtensa MMU page-table code…
CVE-2026-123305.45.8MozillaFirefoxCWE-119Incorrect boundary conditions in the Internationalization component
CVE-2026-477485.55.7leejetstable-diffusion.cppCWE-125stable-diffusion.cpp: Out-of-bounds reads in PyTorch checkpoint pickle opcode…
CVE-2026-468153.25.6Oracle CorporationOracle VM VirtualBoxCWE-200Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-468163.25.6Oracle CorporationOracle VM VirtualBoxCWE-200Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-469773.25.6Oracle CorporationOracle VM VirtualBoxCWE-200Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-242287.85.5NVIDIANeMo FrameworkCWE-502NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker ma…
CVE-2026-467878.05.4Oracle CorporationOracle WebCenter ContentCWE-352Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle…
CVE-2026-468256.05.2Oracle CorporationOracle VM VirtualBoxCWE-284Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-123215.45.2MozillaFirefoxCWE-670JIT miscompilation in the JavaScript: WebAssembly component
CVE-2026-17666.15.2Red HatRed Hat Enterprise Linux 10CWE-805Localsearch: tracker-miners: gnome localsearch mp3 extractor: denial of servi…
CVE-2026-469557.55.0Oracle CorporationOracle Human ResourcesCWE-79Vulnerability in the Oracle Human Resources product of Oracle E-Business Suit…
CVE-2026-469147.14.8Oracle CorporationOracle SolarisCWE-269Vulnerability in the Oracle Solaris product of Oracle Systems (component: Fil…
CVE-2026-420146.64.4—gnutlsCWE-825Gnutls: gnutls: use-after-free in gnutls_pkcs11_token_set_pin
CVE-2026-467686.04.4Oracle CorporationOracle VM VirtualBoxCWE-284Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-124255.74.3PowerSchoolEmployee Access CenterCWE-79Reflected / DOM cross-site scripting (XSS) in PowerSchool ERP / Employee Acce…
CVE-2026-352757.54.2Oracle CorporationOracle VM VirtualBoxCWE-284Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-120035.34.2Python Software FoundationCPythonCWE-427CPython >3.11 Insecure Input Validation resulting in privilege escalation
CVE-2026-394377.13.7WPFactoryMin Max Step Quantity Limits Manager for WooCommerceCWE-79WordPress Min Max Step Quantity Limits Manager for WooCommerce plugin <= 5.2.…
CVE-2026-468487.93.7Oracle CorporationWebLogic ServerCWE-284Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com…
CVE-2026-469139.33.6Oracle CorporationJD Edwards EnterpriseOne ToolsCWE-284Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa…
CVE-2026-469747.53.6Oracle CorporationOracle VM VirtualBoxCWE-284Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-84844.83.6FuseSourcejansiCWE-122Heap buffer overflow in Jansi
CVE-2026-17655.63.5Red HatRed Hat Enterprise Linux 10CWE-125Localsearch: tracker-miners: gnome localsearch mp3 extractor: denial of servi…
CVE-2026-467714.13.2Oracle CorporationOracle Application Development Framework (ADF)CWE-284Vulnerability in the Oracle Application Development Framework (ADF) product o…
CVE-2026-538427.03.0OpenClawOpenClawCWE-426OpenClaw < 2026.5.2 - Arbitrary Python Runtime Execution via CLOUDSDK_PYTHON …
CVE-2026-467724.72.9Oracle CorporationOracle Application Development Framework (ADF)CWE-284Vulnerability in the Oracle Application Development Framework (ADF) product o…
CVE-2026-43675.52.7Red HatRed Hat Hardened ImagesCWE-125Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing
CVE-2026-468743.22.8Oracle CorporationOracle VM VirtualBoxCWE-200Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-538587.02.4OpenClawOpenClawCWE-426OpenClaw < 2026.5.2 - Arbitrary Runtime Dependency Loading via STATE_DIRECTOR…
CVE-2026-538657.22.3OpenClawOpenClawCWE-426OpenClaw < 2026.5.2 - Arbitrary Command Execution via Workspace-Derived Servi…
CVE-2026-469268.82.0Oracle CorporationSiebel CRM Cloud ApplicationsCWE-284Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-468887.82.0Oracle CorporationSiebel CRM DeploymentCWE-284Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp…
CVE-2026-538467.01.9OpenClawOpenClawCWE-426OpenClaw < 2026.4.29 - Arbitrary Package Manager Execution via Workspace .env…
CVE-2025-102626.31.8NokiaSR LinuxCWE-134An unsanitized format validation vulnerability in Nokia SR Linux
CVE-2026-468737.51.6Oracle CorporationOracle VM VirtualBoxCWE-269Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2025-99126.31.4NokiaNokia SR LinuxCWE-269A local privilege escalation vulnerability in Nokia SR Linux
CVE-2026-01357.81.1GoogleAndroidCWE-125In Modem, there is a possible out of bounds read due to a missing bounds chec…
CVE-2026-539004.30.9MozillaFirefox for iOSCWE-345Cookie injection was possible when opening a PDF link
CVE-2024-224516.70.9DellPeripheral ManagerCWE-427Dell Peripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncontrolle…
CVE-2024-224477.80.8DellPeripheral ManagerCWE-427Dell Peripheral Manager, versions prior to 1.7.3, contain an uncontrolled sea…
CVE-2024-395757.40.8DellDell EMC VxRail ApplianceCWE-256update_disk_psu_baseline.sh requires password in plain text
CVE-2026-538996.50.8MozillaFirefox for iOSCWE-345Cross-origin cookies could be leaked when opening a PDF link
CVE-2026-538565.70.7OpenClawOpenClawCWE-732OpenClaw 2026.4.23 < 2026.4.24 - Insecure File Permissions in Config Recovery…
CVE-2026-538506.80.6OpenClawOpenClawCWE-862OpenClaw < 2026.4.25 - Control Scope Enforcement Bypass in Focus Command
CVE-2026-502555.40.5Sony CorporationOptical Disc Archive Software for WindowsCWE-276Incorrect default permissions issue exists in Optical Disc Archive Software f…
CVE-2026-538622.30.4OpenClawOpenClawCWE-266OpenClaw < 2026.5.12 - Bootstrap Token Replay via Pending Pairing Scope Widening
CVE-2024-384877.00.2DellEMC VxRail ApplianceCWE-269api-gateway container running with root privilege would allow an attacker to …
CVE-2026-01377.80.1GoogleAndroidCWE-416In edgetpu_sync_fence_group_shutdown() of edgetpu-dmabuf.c, there is a possib…
CVE-2026-01387.80.1GoogleAndroidCWE-120In lwis_io_buffer_write of lwis_io_buffer.c, there is a possible out of bound…
CVE-2026-01437.80.1GoogleAndroidCWE-416In lwis_device_external_event_emit of lwis_event.c, there is a possible memor…
CVE-2026-01317.30.1GoogleAndroidCWE-125In RtpPacket::decodePacket, there is a possible out of bounds access due to a…
CVE-2026-01343.30.1GoogleAndroidCWE-1188In PostWipeData of recovery_ui.cpp, there is a possible data persistence issu…
CVE-2026-01527.80.1GoogleAndroidCWE-119In OSMMapPMRGeneric of pmr_os.c, there is a possible way to leverage a system…
CVE-2026-01423.30.0GoogleAndroidCWE-20In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read d…
CVE-2026-01537.80.0GoogleAndroidCWE-787In Write of msg_to_host_buffer.cc, there is a possible out of bounds write du…
CVE-2026-01453.30.0GoogleAndroidCWE-862In keymint, there is a possible Permission Bypass due to a logic error in the…
CVE-2026-01337.80.0GoogleAndroidCWE-862In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign maliciou…
CVE-2026-01507.80.0GoogleAndroidCWE-190In ExecuteGraph command handler of EdgeTPU firmware, there is a possible out …
CVE-2026-01257.00.0GoogleAndroidCWE-416In multiple functions of vpu_ioctl.c, there is a possible use after free due …
CVE-2026-01583.30.0GoogleAndroidCWE-862In Camera, there is a possible unauthorized way to access photos due to a mis…