AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P N N H H H 9.2 .0402 89.7 —
AFFECTED Product Versions Fixed NGINX Open Source 1.13.10 – — NGINX Plus 37.0 – —
TIMELINE Jun 2 Reserved by CNA Jun 17 Published (CNA: f5)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
396 CVEs published, led by Google (50).
396 CVEs published June 17, 2026: 90 critical, 196 high, 101 medium, 9 low; 0 in the KEV catalog at press time; 7 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 371 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 4717 | 9154 | 1072 | 2564 |
| KEV catalog size | 1671 | |||
424 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 97 | 1065 | 84 | 664 | 312 | 1 | 27 | 3 | 0.3 | 7.8 | .0013 | -118 ▼ |
| 680 | 854 | 80 | 449 | 293 | 29 | 74 | 6 | 0.7 | 8.1 | .0023 | +680 ▲ | |
| microsoft | 208 | 753 | 55 | 513 | 170 | 6 | 380 | 27 | 3.6 | 7.8 | .0045 | +69 ▲ |
| red hat | 65 | 129 | 8 | 57 | 58 | 6 | 4 | 0 | 0.0 | 7.0 | .0028 | +61 ▲ |
| apple | 14 | 61 | 0 | 16 | 36 | 2 | 94 | 7 | 11.5 | 5.7 | .0023 | +1 ▲ |
| canonical | 0 | 14 | 0 | 4 | 5 | 5 | 0 | 0 | 0.0 | 5.5 | .0009 | 0 |
| freebsd | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0020 | 0 |
| suse | 2 | 4 | 0 | 4 | 0 | 0 | 0 | 0 | 0.0 | 8.6 | .0021 | +2 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 9 | 22 | 4 | 3 | 8 | 0 | 96 | 10 | 45.5 | 6.8 | .0257 | +8 ▲ |
| netgear | 17 | 17 | 0 | 0 | 16 | 1 | 8 | 0 | 0.0 | 4.3 | .0024 | +17 ▲ |
| palo alto networks | 9 | 11 | 0 | 1 | 7 | 1 | 14 | 2 | 18.2 | 4.8 | .0022 | +8 ▲ |
| f5 | 6 | 9 | 4 | 3 | 1 | 0 | 7 | 1 | 11.1 | 8.9 | .0221 | +5 ▲ |
| ivanti | 4 | 9 | 2 | 3 | 0 | 0 | 33 | 5 | 55.6 | 8.8 | .5187 | +3 ▲ |
| checkpoint | 3 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | +3 ▲ |
| ubiquiti | 5 | 8 | 4 | 4 | 0 | 0 | 4 | 0 | 0.0 | 8.9 | .0052 | +5 ▲ |
| fortinet | 2 | 8 | 1 | 3 | 2 | 0 | 28 | 3 | 37.5 | 7.3 | .0066 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 74 | 106 | 18 | 41 | 44 | 2 | 40 | 1 | 0.9 | 7.3 | .0050 | +70 ▲ |
| mozilla | 49 | 55 | 11 | 18 | 26 | 0 | 13 | 0 | 0.0 | 7.3 | .0026 | +45 ▲ |
| gitlab | 11 | 20 | 0 | 4 | 12 | 2 | 4 | 2 | 10.0 | 4.8 | .0024 | +11 ▲ |
| docker | 2 | 5 | 0 | 5 | 0 | 0 | 1 | 0 | 0.0 | 8.8 | .0021 | +2 ▲ |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 5 | 1 | 20.0 | 5.1 | .0026 | 0 |
| github | 0 | 2 | 1 | 1 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0347 | 0 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 243 | 270 | 131 | 116 | 18 | 4 | 40 | 2 | 0.7 | 8.8 | .0040 | +243 ▲ |
| adobe | 129 | 133 | 4 | 49 | 75 | 2 | 75 | 3 | 2.3 | 5.5 | .0021 | +129 ▲ |
| ibm | 11 | 60 | 13 | 29 | 18 | 0 | 7 | 0 | 0.0 | 7.5 | .0028 | +11 ▲ |
| progress | 5 | 9 | 1 | 7 | 1 | 0 | 9 | 0 | 0.0 | 7.5 | .0036 | +5 ▲ |
| solarwinds | 3 | 6 | 1 | 2 | 1 | 0 | 11 | 4 | 66.7 | 7.5 | .3995 | +3 ▲ |
| veeam | 1 | 4 | 2 | 2 | 0 | 0 | 4 | 0 | 0.0 | 9.0 | .0046 | +1 ▲ |
| zohocorp | 0 | 2 | 0 | 1 | 1 | 0 | 0 | 0 | 0.0 | 7.1 | .0104 | 0 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 5 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +5 ▲ |
| d-link | 9 | 12 | 0 | 4 | 2 | 5 | 26 | 1 | 8.3 | 5.5 | .0058 | +9 ▲ |
| siemens | 7 | 8 | 0 | 4 | 4 | 0 | 1 | 0 | 0.0 | 7.5 | .0020 | +6 ▲ |
| rockwell automation | 7 | 7 | 1 | 5 | 1 | 0 | 0 | 0 | 0.0 | 8.7 | .0030 | +7 ▲ |
| abb | 5 | 5 | 0 | 4 | 1 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | +5 ▲ |
| moxa | 5 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | +5 ▲ |
| dahua | 3 | 3 | 0 | 1 | 1 | 1 | 2 | 0 | 0.0 | 6.9 | .0036 | +3 ▲ |
| hitachi energy | 0 | 2 | 0 | 0 | 2 | 0 | 0 | 0 | 0.0 | 5.7 | .0014 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| spring | 71 | 72 | 2 | 30 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0023 | +71 ▲ |
| openclaw | 61 | 67 | 0 | 35 | 22 | 10 | 0 | 0 | 0.0 | 7.0 | .0021 | +61 ▲ |
| sourcecodester | 37 | 59 | 0 | 0 | 25 | 34 | 0 | 0 | 0.0 | 2.1 | .0026 | +37 ▲ |
| themerex | 58 | 58 | 5 | 53 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0043 | +58 ▲ |
| edimax | 0 | 51 | 0 | 32 | 0 | 19 | 1 | 0 | 0.0 | 7.4 | .0059 | 0 |
| concrete cms | 2 | 46 | 1 | 11 | 13 | 21 | 0 | 0 | 0.0 | 6.2 | .0015 | +2 ▲ |
| dell | 26 | 44 | 0 | 20 | 23 | 0 | 2 | 1 | 2.3 | 6.7 | .0016 | +26 ▲ |
| open ises | 0 | 44 | 2 | 21 | 21 | 0 | 0 | 0 | 0.0 | 7.1 | .0021 | 0 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-10520 | .9990 | 100.0 | 10.0 |
| CVE-2008-4250 | .9875 | 99.9 | — |
| CVE-2026-35273 | .9547 | 99.9 | 9.8 |
| CVE-2026-0257 | .9391 | 99.8 | — |
| CVE-2010-0249 | .9188 | 99.8 | — |
| CVE-2026-9082 | .8832 | 99.8 | 9.8 |
| CVE-2009-3459 | .8658 | 99.7 | — |
| CVE-2025-34291 | .8384 | 99.7 | — |
| CVE-2026-42271 | .8301 | 99.6 | — |
| CVE-2026-50751 | .8255 | 99.6 | 9.3 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-10520 | 10.0 | .9990 | KEV |
| CVE-2026-48907 | 10.0 | .6883 | KEV |
| CVE-2026-48172 | 10.0 | .1891 | KEV |
| CVE-2026-49777 | 10.0 | .0166 | |
| CVE-2026-8054 | 10.0 | .0158 | |
| CVE-2026-45087 | 10.0 | .0147 | |
| CVE-2026-49199 | 10.0 | .0134 | |
| CVE-2026-11429 | 10.0 | .0115 | |
| CVE-2026-20223 | 10.0 | .0083 | |
| CVE-2026-47140 | 10.0 | .0082 |
| Vendor | CVEs |
|---|---|
| 848 | |
| linux | 523 |
| oracle | 268 |
| microsoft | 235 |
| adobe | 130 |
| red hat | 101 |
| apache | 91 |
| spring | 72 |
| openclaw | 67 |
| ibm | 60 |
| Vendor | KEV |
|---|---|
| microsoft | 27 |
| cisco | 10 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| synacor | 4 |
| adobe | 3 |
| fortinet | 3 |
| linux | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 42 |
| Packagist | 22 |
| PyPI | 11 |
| npm | 4 |
| crates.io | 2 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4250 | Microsoft | 0 |
| CVE-2009-1537 | Microsoft | 0 |
| CVE-2009-3459 | Adobe | 0 |
| CVE-2010-0249 | Microsoft | 0 |
| CVE-2010-0806 | Microsoft | 0 |
| CVE-2022-0492 | Linux | 0 |
| CVE-2024-21182 | Oracle | 0 |
| CVE-2025-34291 | Langflow | 0 |
| CVE-2025-48595 | 0 | |
| CVE-2026-0257 | Palo Alto Networks | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1673 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1673 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1673 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1673 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1673 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1673 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1673 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1673 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1673 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1673 |
EXPLOIT PUBLISHED — CVE-2026-10641 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10850 (Plane). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47103 (fgmacedo python-statemachine). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47774 (envoyproxy envoy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48988 (markdown-it). Public exploit reference added.
How to read these box scores · glossary
396 CVEs published. 25 box scores, 371 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P N N H H H 9.2 .0402 89.7 —
AFFECTED Product Versions Fixed NGINX Open Source 1.13.10 – — NGINX Plus 37.0 – —
TIMELINE Jun 2 Reserved by CNA Jun 17 Published (CNA: f5)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N N H H H 9.2 .0368 88.8 —
AFFECTED Product Versions Fixed NGINX Open Source 1.31.0 – —
TIMELINE Jun 2 Reserved by CNA Jun 17 Published (CNA: f5)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.2 .0203 79.5 —
AFFECTED Product Versions Fixed libssh2 unspecified 7acf3dfda80c91c3a8c9f2372546301d4a1a7a8
TIMELINE Jun 16 Reserved by CNA Jun 17 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0179 76.5 —
AFFECTED Product Versions Fixed RadiX AX6600 WiFi 6 Tri-Band Gaming Router firmware versions prior to v781521 – —
TIMELINE Jun 10 Reserved by CNA Jun 17 Published (CNA: jpcert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0117 65.0 —
AFFECTED Product Versions Fixed python-statemachine 3.0.0 – —
TIMELINE May 18 Reserved by CNA Jun 17 Public exploit reference published Jun 17 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0097 59.0 —
AFFECTED Product Versions Fixed envoy < 1.35.11 – —
TIMELINE May 19 Reserved by CNA Jun 17 Public exploit reference published Jun 17 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N N N H 8.2 .0092 57.5 —
AFFECTED Product Versions Fixed libssh2 unspecified 17626857d20b3c9a1addfa45979dadcee1cd84a4
TIMELINE Jun 16 Reserved by CNA Jun 17 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0087 56.1 —
AFFECTED Product Versions Fixed GEN3C unspecified —
TIMELINE Jun 10 Reserved by CNA Jun 17 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0079 53.4 —
AFFECTED Product Versions Fixed undici unspecified 6.26.0
TIMELINE Jun 12 Reserved by CNA Jun 17 Published (CNA: openjs)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0076 52.4 —
AFFECTED Product Versions Fixed picklescan unspecified 0.0.33
TIMELINE Jun 8 Reserved by CNA Jun 17 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0075 52.1 —
AFFECTED Product Versions Fixed Cisco Identity Services Engine Software 3.1.0 – — Cisco ISE Passive Identity Connector 3.2.0 – —
TIMELINE Oct 8 Reserved by CNA Jun 17 Published (CNA: cisco)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U L H H 7.1 .0075 52.0 —
AFFECTED Product Versions Fixed e107 < 2.3.6 – —
TIMELINE May 26 Reserved by CNA Jun 17 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0070 50.3 —
AFFECTED Product Versions Fixed WP Activity Log n/a – 5.6.4
TIMELINE Jun 16 Reserved by CNA Jun 17 Published (CNA: Patchstack)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N N L N L 6.3 .0068 49.8 —
AFFECTED Product Versions Fixed NGINX Open Source 1.13.10 – — NGINX Plus 37.0 – —
TIMELINE Jun 2 Reserved by CNA Jun 17 Published (CNA: f5)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0063 47.6 —
AFFECTED Product Versions Fixed Splunk AI Toolkit 5.7 – —
TIMELINE Oct 8 Reserved by CNA Jun 17 Published (CNA: cisco)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0063 47.3 —
AFFECTED Product Versions Fixed Apache Airflow SFTP provider unspecified —
TIMELINE Jun 4 Reserved by CNA Jun 17 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0062 47.2 —
AFFECTED Product Versions Fixed picklescan unspecified 0.0.33
TIMELINE Jun 8 Reserved by CNA Jun 17 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0062 47.2 —
AFFECTED Product Versions Fixed picklescan unspecified 1.0.4
TIMELINE Mar 3 Reserved by CNA Jun 17 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0062 47.2 —
AFFECTED Product Versions Fixed picklescan unspecified 0.0.33
TIMELINE Jun 8 Reserved by CNA Jun 17 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0062 47.2 —
AFFECTED Product Versions Fixed Pimcore CMS/DXP unspecified fffa7f6396329e88610db70a8652529bbc734892
TIMELINE Jun 5 Reserved by CNA Jun 17 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0061 46.7 —
AFFECTED Product Versions Fixed Chrome 149.0.7827.155 – —
TIMELINE Jun 16 Reserved by CNA Jun 17 Published (CNA: Chrome)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0060 46.2 —
AFFECTED Product Versions Fixed ThingsBoard prior to v4.3.1.2 – —
TIMELINE Jun 10 Reserved by CNA Jun 17 Published (CNA: jpcert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0059 45.7 —
AFFECTED Product Versions Fixed hermes-agent unspecified 0.16.0
TIMELINE Jun 10 Reserved by CNA Jun 17 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H N 9.1 .0058 45.1 —
AFFECTED Product Versions Fixed hermes-webui unspecified 0.51.409
TIMELINE Jun 16 Reserved by CNA Jun 17 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H N 8.6 .0057 44.5 —
AFFECTED Product Versions Fixed NGINX Gateway Fabric 2.5.0 – —
TIMELINE Jun 4 Reserved by CNA Jun 17 Published (CNA: f5)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-8383 | 5.3 | 44.3 | Unknown | LearnPress | CWE-862 | LearnPress < 4.3.7 - Unauthenticated Sensitive User Information Disclosure vi… |
| CVE-2026-49767 | 9.8 | 43.5 | Tomdever | wpForo Forum | CWE-288 | WordPress wpForo Forum plugin <= 3.1.0 - Broken Authentication vulnerability |
| CVE-2026-40783 | 9.9 | 43.2 | Creative Themes | Blocksy Companion Pro | CWE-94 | WordPress Blocksy Companion Pro plugin <= 2.1.37 - Remote Code Execution (RCE… |
| CVE-2026-27400 | 8.6 | 43.1 | Ovatheme | BookPro | CWE-22 | WordPress BookPro plugin <= 1.1.0 - Arbitrary File Deletion vulnerability |
| CVE-2025-60205 | 9.8 | 42.3 | ThemeREX | ThemeREX Addons | CWE-502 | WordPress ThemeREX Addons plugin <= 2.36.1.1 - PHP Object Injection vulnerabi… |
| CVE-2026-53874 | 9.3 | 41.9 | picklescan | picklescan | CWE-502 | picklescan - Arbitrary Code Execution via Obfuscated eval Call |
| CVE-2026-12115 | 6.6 | 42.0 | wpcalc | Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress | CWE-502 | Counter Box <= 2.0.13 - Authenticated (Administrator+) PHP Object Injection v… |
| CVE-2026-42380 | 9.8 | 41.4 | jwsthemes | AI Lab | CWE-502 | WordPress AI Lab theme < 5.4.2 - PHP Object Injection vulnerability |
| CVE-2026-53872 | 8.7 | 41.3 | picklescan | picklescan | CWE-22 | picklescan - Arbitrary File Read via Unsafe Pickle Deserialization |
| CVE-2026-20190 | 7.5 | 41.0 | Cisco | Cisco Identity Services Engine Software | CWE-285 | Cisco Identity Services Engine Information Disclosure Vulnerability |
| CVE-2026-49268 | 8.8 | 40.4 | Apache Software Foundation | Apache Shiro | CWE-90 | Apache Shiro: LDAP DN Injection in DefaultLdapRealm |
| CVE-2026-52707 | 8.1 | 40.4 | Mikado-Themes | Kastell | CWE-35 | WordPress Kastell theme <= 2.0 - Local File Inclusion vulnerability |
| CVE-2026-50107 | 8.6 | 40.3 | F5 | NGINX Gateway Fabric | CWE-74 | NGINX Gateway Fabric vulnerability |
| CVE-2025-69130 | 8.8 | 39.7 | Themovation | Entrepreneur - Booking for Small Businesses WordPress Theme | CWE-502 | WordPress Entrepreneur - Booking for Small Businesses WordPress Theme theme <… |
| CVE-2025-71325 | 9.3 | 39.3 | picklescan | picklescan | CWE-391 | picklescan - Detection Bypass via STACK_GLOBAL Opcode Parsing Logic Flaw |
| CVE-2024-52488 | 9.9 | 38.9 | Zidithemes | Grip | CWE-434 | WordPress Grip theme <= 1.0.9 - Arbitrary Plugin Activation/Deactivation to R… |
| CVE-2026-36418 | 9.1 | 38.9 | n/a | n/a | CWE-94 | JimuReport versions 2.3.4 and below are vulnerable to remote code execution d… |
| CVE-2026-9690 | 7.5 | 38.7 | Joomunited | WP Media folder Addon | CWE-22 | WordPress WP Media folder Addon plugin <= 4.0.1 - Arbitrary File Download vul… |
| CVE-2026-22334 | 7.5 | 38.7 | WPos | Woocommerce Book Price | CWE-22 | WordPress Woocommerce Book Price plugin <= 1.3 - Arbitrary File Download vuln… |
| CVE-2026-52706 | 9.8 | 38.6 | Jetimpex Inc. | JetEngine | CWE-502 | WordPress JetEngine plugin <= 3.8.10 - PHP Object Injection vulnerability |
| CVE-2026-22327 | 9.9 | 38.6 | Zozothemes | Restaurt | CWE-434 | WordPress Restaurt theme <= 1.0.4 - Arbitrary File Upload vulnerability |
| CVE-2026-53873 | 9.3 | 38.2 | picklescan | picklescan | CWE-184 | picklescan - Arbitrary Code Execution via profile.run() Blocklist Bypass |
| CVE-2025-69128 | 8.6 | 38.2 | EMV | JobCareer | CWE-22 | WordPress JobCareer theme <= 7.3 - Arbitrary File Deletion vulnerability |
| CVE-2026-9697 | 7.4 | 38.2 | undici | undici | CWE-295 | undici vulnerable to TLS certificate validation bypass via dropped requestTls… |
| CVE-2025-59872 | 9.8 | 37.8 | HCL Software | ZIE | CWE-434 | HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, |
| CVE-2025-69179 | 9.8 | 37.6 | Theme passion | Support Ticket Management System | CWE-266 | WordPress Support Ticket Management System plugin <= 1.9 - Privilege Escalati… |
| CVE-2026-54803 | 9.8 | 37.6 | Cozy Vision Technologies Pvt. Ltd. | SMS Alert Order Notifications | CWE-863 | WordPress SMS Alert Order Notifications plugin <= 3.9.4 - Privilege Escalatio… |
| CVE-2025-60223 | 7.7 | 37.6 | QuantumCloud | WPBot Pro Wordpress Chatbot | CWE-22 | WordPress WPBot Pro Wordpress Chatbot plugin <= 13.6.5 - Arbitrary File Delet… |
| CVE-2026-39589 | 9.9 | 37.5 | A WP Life | Webenvo | CWE-434 | WordPress Webenvo theme <= 0.0.6 - Arbitrary File Upload vulnerability |
| CVE-2025-60218 | 9.9 | 37.3 | WPLocker | PT Luxa Addons | CWE-434 | WordPress PT Luxa Addons Plugin <= 1.2.2 - Arbitrary File Upload Vulnerability |
| CVE-2026-54387 | 9.3 | 36.7 | tinyproxy | tinyproxy | CWE-444 | Tinyproxy - HTTP Request Smuggling via CL/TE Desynchronization |
| CVE-2026-54388 | 9.3 | 36.7 | tinyproxy | tinyproxy | CWE-444 | Tinyproxy - HTTP Request Smuggling via Duplicate Content-Length Headers |
| CVE-2026-54807 | 9.8 | 36.6 | ThemeGrill | Registration Form for WooCommerce | CWE-266 | WordPress Registration Form for WooCommerce plugin <= 1.0.9 - Privilege Escal… |
| CVE-2026-24611 | 9.1 | 36.6 | WPMet | MetForm Pro | CWE-862 | WordPress MetForm Pro plugin <= 3.9.1 - Broken Access Control vulnerability |
| CVE-2026-41280 | 4.9 | 36.6 | Apache Software Foundation | Apache DolphinScheduler | CWE-863 | Apache DolphinScheduler: Incorrect Authorization vulnerability allows users w… |
| CVE-2025-69106 | 8.1 | 36.4 | ThemeREX | Imba | CWE-98 | WordPress Imba theme <= 1.5.0 - Local File Inclusion vulnerability |
| CVE-2025-69110 | 8.1 | 36.4 | ThemeREX | AirSupply | CWE-98 | WordPress AirSupply theme <= 2.0.0 - Local File Inclusion vulnerability |
| CVE-2025-69117 | 8.1 | 36.4 | ThemeREX | Ingenioso | CWE-98 | WordPress Ingenioso theme <= 1.14.0 - Local File Inclusion vulnerability |
| CVE-2025-69120 | 8.1 | 36.4 | ThemeREX | Dazzle | CWE-98 | WordPress Dazzle theme <= 1.0.0 - Local File Inclusion vulnerability |
| CVE-2025-69148 | 8.1 | 36.4 | ThemeREX | Quirky | CWE-98 | WordPress Quirky theme <= 1.23 - Local File Inclusion vulnerability |
| CVE-2025-69157 | 8.1 | 36.4 | ThemeREX | Gamic | CWE-98 | WordPress Gamic theme <= 1.15 - Local File Inclusion vulnerability |
| CVE-2025-69166 | 8.1 | 36.4 | ThemeREX | Gunslinger | CWE-98 | WordPress Gunslinger theme <= 1.7 - Local File Inclusion vulnerability |
| CVE-2025-69172 | 8.1 | 36.4 | ThemeREX | Resurs | CWE-98 | WordPress Resurs theme <= 1.3 - Local File Inclusion vulnerability |
| CVE-2025-69173 | 8.1 | 36.4 | ThemeREX | Tipsy | CWE-98 | WordPress Tipsy theme <= 1.1 - Local File Inclusion vulnerability |
| CVE-2026-25446 | 9.9 | 36.3 | WishList Products, LLC. | WishList Member X | CWE-434 | WordPress WishList Member X plugin <= 3.29.0 - Arbitrary File Upload vulnerab… |
| CVE-2026-40746 | 9.9 | 36.3 | themagnifico52 | Restaurant Zone | CWE-434 | WordPress Restaurant Zone theme <= 0.7.8 - Arbitrary File Upload vulnerability |
| CVE-2026-40747 | 9.9 | 36.3 | themagnifico52 | Ecommerce Zone | CWE-434 | WordPress Ecommerce Zone theme <= 0.9.7 - Arbitrary File Upload vulnerability |
| CVE-2026-40748 | 9.9 | 36.3 | themagnifico52 | Kids Gift Shop | CWE-434 | WordPress Kids Gift Shop theme <= 0.5.4 - Arbitrary File Upload vulnerability |
| CVE-2026-40749 | 9.9 | 36.3 | themagnifico52 | Charity Zone | CWE-434 | WordPress Charity Zone theme <= 1.1.1 - Arbitrary File Upload vulnerability |
| CVE-2026-53875 | 7.1 | 36.4 | picklescan | picklescan | CWE-95 | picklescan - Scanning Bypass via Dynamic Eval in scan_pytorch |
| CVE-2026-47340 | 6.5 | 36.3 | Apache Software Foundation | Apache DolphinScheduler | CWE-200 | Apache DolphinScheduler: An incorrect authorization vulnerability allows auth… |
| CVE-2025-69129 | 10.0 | 36.2 | Extendons | WordPress & WooCommerce Scraper Plugin, Import Data from Any Site | CWE-434 | WordPress WordPress & WooCommerce Scraper Plugin, Import Data from Any Site p… |
| CVE-2024-32729 | 7.5 | 36.0 | QuantumCloud | Conversational Forms for ChatBot | CWE-22 | WordPress ChatBot Conversational Forms plugin <= 1.1.8 - Arbitrary File Downl… |
| CVE-2025-60229 | 9.8 | 35.7 | Themeton | Lagom | CWE-502 | WordPress Lagom theme <= 2.0 - PHP Object Injection vulnerability |
| CVE-2025-60230 | 9.8 | 35.7 | Themeton | The Barber Shop | CWE-502 | WordPress The Barber Shop theme <= 1.9 - PHP Object Injection vulnerability |
| CVE-2026-12447 | 8.8 | 35.7 | Chrome | CWE-122 | Heap buffer overflow in WebRTC in Google Chrome prior to 149.0.7827.155 allow… | |
| CVE-2026-12466 | 8.8 | 35.7 | Chrome | CWE-122 | Heap buffer overflow in WebRTC in Google Chrome on Windows prior to 149.0.782… | |
| CVE-2026-9675 | 7.5 | 35.7 | undici | undici | CWE-400 | undici WebSocket client vulnerable to denial of service via cumulative fragme… |
| CVE-2025-58953 | 8.1 | 35.5 | ThemeREX | Joly | CWE-98 | WordPress Joly theme <= 1.22.0 - Local File Inclusion vulnerability |
| CVE-2025-58954 | 8.1 | 35.5 | ThemeREX | HomeRoofer | CWE-98 | WordPress HomeRoofer theme <= 2.11.0 - Local File Inclusion vulnerability |
| CVE-2026-39537 | 8.1 | 35.5 | Mikado-Themes | Mikado Core | CWE-98 | WordPress Mikado Core plugin <= 1.6 - Local File Inclusion vulnerability |
| CVE-2026-40731 | 8.1 | 35.5 | Mikado-Themes | ChapterOne | CWE-98 | WordPress ChapterOne theme <= 1.7 - Local File Inclusion vulnerability |
| CVE-2026-10839 | 5.1 | 35.2 | Password Manager | Password Manager | CWE-601 | Open redirection vulnerability in Password Manager |
| CVE-2026-54417 | 8.7 | 35.0 | rxi | microtar | CWE-190 | Integer Overflow in rxi/microtar mtar_next() Causes Infinite Loop DoS |
| CVE-2026-40724 | 6.5 | 34.5 | Client Portal Ltd. | Client Portal (Pro) | CWE-22 | WordPress Client Portal (Pro) plugin <= 5.6.2 - Arbitrary File Download vulne… |
| CVE-2026-40721 | 7.5 | 33.4 | BdThemes | Element Pack Pro | CWE-98 | WordPress Element Pack Pro plugin <= 9.0.6 - Local File Inclusion vulnerability |
| CVE-2026-55738 | 8.7 | 33.2 | rxi | microtar | CWE-121 | Stack Buffer Overflow in rxi/microtar raw_to_header() via non-null-terminated… |
| CVE-2026-48989 | 8.9 | 33.0 | CursorTouch | Windows-MCP | CWE-306 | Windows-MCP: HTTP transports expose unauthenticated PowerShell control with w… |
| CVE-2025-59554 | 9.3 | 33.0 | Advanced Ads GmbH | Advanced Ads – Tracking | CWE-89 | WordPress Advanced Ads – Tracking plugin < 3.0.7 - SQL Injection vulnerability |
| CVE-2026-12165 | 8.8 | 33.0 | contest-gallery | Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe | CWE-269 | Contest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via … |
| CVE-2026-12442 | 8.8 | 32.9 | Chrome | CWE-416 | Use after free in Passwords in Google Chrome on Android prior to 149.0.7827.1… | |
| CVE-2026-39445 | 8.1 | 32.8 | PressLayouts | Alukas | CWE-502 | WordPress Alukas theme < 3.0.0 - PHP Object Injection vulnerability |
| CVE-2026-39545 | 8.1 | 32.8 | Select-Themes | Zermatt | CWE-502 | WordPress Zermatt theme <= 1.6.1 - PHP Object Injection vulnerability |
| CVE-2026-39573 | 8.1 | 32.8 | Select-Themes | Mildhill | CWE-502 | WordPress Mildhill theme <= 1.5 - PHP Object Injection vulnerability |
| CVE-2026-39576 | 8.1 | 32.8 | Elated-Themes | SingleMalt | CWE-502 | WordPress SingleMalt theme <= 1.5 - PHP Object Injection vulnerability |
| CVE-2026-40735 | 8.1 | 32.8 | Edge-Themes | Reina | CWE-502 | WordPress Reina theme <= 2.1 - PHP Object Injection vulnerability |
| CVE-2026-27868 | 6.9 | 32.7 | Teldat | Regesta Smart HD-PLC - TLDPH16D2 | CWE-201 | PUBLICATION OF SENSITIVE INFORMATION ON REGESTA SMART HD-PLC OF TELDAT |
| CVE-2026-27869 | 6.9 | 32.7 | Teldat | Regesta Smart HD-PLC - TLDPH16D2 | CWE-770 | WEB SERVICE (HTTP) DENIAL OF SERVICE VIA SLOW HEADERS ON REGESTA SMART HD-PLC… |
| CVE-2025-26240 | 8.4 | 32.5 | n/a | n/a | CWE-120 | In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution… |
| CVE-2026-32966 | 9.8 | 32.4 | Apache Software Foundation | Apache DolphinScheduler | CWE-863 | Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to … |
| CVE-2025-69138 | 8.8 | 32.2 | Jthemes | Genemy | CWE-266 | WordPress Genemy theme <= 1.6.6 - Privilege Escalation vulnerability |
| CVE-2026-55743 | 9.4 | 32.2 | tinyhumansai | OpenHuman | CWE-78 | OpenHuman desktop agent shell tool sandbox bypass leads to arbitrary command … |
| CVE-2025-69111 | 9.8 | 32.0 | ThemeREX | Reisen | CWE-502 | WordPress Reisen theme <= 1.4.1 - PHP Object Injection vulnerability |
| CVE-2025-69127 | 9.8 | 32.0 | ThemeREX | Plumbing | CWE-502 | WordPress Plumbing theme <= 1.6 - PHP Object Injection vulnerability |
| CVE-2026-45357 | 7.5 | 31.9 | harttle | liquidjs | CWE-400 | LiquidJS: Memory and render limit bypass via unbounded width padding in `date… |
| CVE-2026-45617 | 7.5 | 31.9 | harttle | liquidjs | CWE-1333 | LiquidJS: ReDoS via Quadratic Backtracking in `strip_html` Filter Regex |
| CVE-2025-71322 | 8.7 | 31.7 | PickleScan | PickleScan | CWE-693 | PickleScan - Unsafe Globals Check Bypass via pty.spawn Function |
| CVE-2025-66391 | 8.8 | 31.6 | n/a | n/a | CWE-284 | In Citrix Cloud through 2025-11-10, an account with read-only access can trig… |
| CVE-2026-55202 | 8.8 | 31.4 | tinyproxy | tinyproxy | CWE-290 | Tinyproxy - Stathost Detection Bypass via Host Header Manipulation |
| CVE-2026-10094 | 9.8 | 31.3 | Dassault Systèmes | SOLIDWORKS Visualize | CWE-22 | Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS D… |
| CVE-2026-48988 | 5.3 | 31.2 | markdown-it | markdown-it | CWE-400 | markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt strin… |
| CVE-2025-59563 | 8.8 | 31.0 | SONAAR MUSIC | Sonaar | CWE-266 | WordPress Sonaar theme <= 4.27.4 - Privilege Escalation vulnerability |
| CVE-2026-54805 | 8.8 | 31.0 | sbouey | Falang multilanguage | CWE-266 | WordPress Falang multilanguage plugin <= 1.4.2 - Privilege Escalation vulnera… |
| CVE-2026-40725 | 9.8 | 30.8 | Barn2 Media Ltd | WooCommerce Product Filters | CWE-502 | WordPress WooCommerce Product Filters plugin < 2.0.6 - PHP Object Injection v… |
| CVE-2026-49075 | 9.8 | 30.8 | Jetimpex Inc. | JetEngine | CWE-502 | WordPress JetEngine plugin <= 3.8.9.1 - PHP Object Injection vulnerability |
| CVE-2026-49107 | 9.8 | 30.8 | Thrive Themes | Thrive Apprentice | CWE-502 | WordPress Thrive Apprentice plugin < 10.8.10.2 - PHP Object Injection vulnera… |
| CVE-2026-22340 | 9.3 | 30.5 | Jobster Marketplace | WPJobster | CWE-89 | WordPress WPJobster theme <= 6.3.5 - SQL Injection vulnerability |
| CVE-2026-39596 | 9.3 | 30.5 | Creative Themes | Blocksy Companion Pro | CWE-89 | WordPress Blocksy Companion Pro plugin < 2.1.29 - SQL Injection vulnerability |
| CVE-2026-48875 | 9.3 | 30.5 | Jetimpex Inc. | JetSmartFilters | CWE-89 | WordPress JetSmartFilters plugin <= 3.8.1 - SQL Injection vulnerability |
| CVE-2026-49076 | 9.3 | 30.5 | Jetimpex Inc. | JetEngine | CWE-89 | WordPress JetEngine plugin <= 3.8.9.1 - SQL Injection vulnerability |
| CVE-2026-54802 | 7.5 | 30.3 | Cozy Vision Technologies Pvt. Ltd. | SMS Alert Order Notifications | CWE-862 | WordPress SMS Alert Order Notifications plugin <= 3.9.3 - Broken Authenticati… |
| CVE-2026-48818 | 7.5 | 30.0 | Kludex | starlette | CWE-918 | Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Win… |
| CVE-2026-53871 | 8.6 | 29.8 | nesquena | hermes-webui | CWE-565 | Hermes WebUI < 0.51.368 - Profile-Scoped Authorization Bypass via Forged herm… |
| CVE-2026-8050 | 7.5 | 29.8 | SignalRGB | SignalRGB kernel driver | — | CVE-2026-8050 |
| CVE-2026-22325 | 8.1 | 29.5 | AxiomThemes | Promo | CWE-98 | WordPress Promo theme <= 1.3.0 - Local File Inclusion vulnerability |
| CVE-2026-22330 | 8.1 | 29.5 | Themeum | Right Way | CWE-98 | WordPress Right Way theme <= 4.0 - Local File Inclusion vulnerability |
| CVE-2026-22331 | 8.1 | 29.5 | ThemeREX | AutoParts | CWE-98 | WordPress AutoParts theme <= 1.5.8 - Local File Inclusion vulnerability |
| CVE-2026-9678 | 5.9 | 29.3 | undici | undici | CWE-524 | undici vulnerable to cross-user information disclosure via shared cache white… |
| CVE-2026-55706 | 8.3 | 28.7 | OpenBSD | OpenBSD | CWE-1284 | sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows auth… |
| CVE-2026-35065 | 8.8 | 28.6 | Dell | PowerFlex | CWE-306 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Missing Aut… |
| CVE-2026-54415 | 8.6 | 28.0 | Azuriom | Azuriom CMS | CWE-269 | Broken Access Control in Azuriom CMS Server Routes Allows Account Takeover |
| CVE-2025-69115 | 8.1 | 28.0 | ThemeREX | LuxMed | Medicine & Healthcare Doctor WordPress Theme | CWE-98 | WordPress LuxMed | Medicine & Healthcare Doctor WordPress Theme theme <= 1.2.… |
| CVE-2025-69123 | 8.1 | 28.0 | ThemeREX | Snow Club | CWE-98 | WordPress Snow Club theme <= 1.1 - Local File Inclusion vulnerability |
| CVE-2025-69126 | 8.1 | 28.0 | ThemeREX | Fortius | CWE-98 | WordPress Fortius theme <= 2.3.0 - Local File Inclusion vulnerability |
| CVE-2025-69144 | 8.1 | 28.0 | ThemeREX | Preservation | CWE-98 | WordPress Preservation theme <= 1.10 - Local File Inclusion vulnerability |
| CVE-2025-69145 | 8.1 | 28.0 | ThemeREX | Gat | CWE-98 | WordPress Gat theme <= 1.16 - Local File Inclusion vulnerability |
| CVE-2025-69158 | 8.1 | 28.0 | ThemeREX | Granola | CWE-98 | WordPress Granola theme <= 1.13 - Local File Inclusion vulnerability |
| CVE-2025-69161 | 8.1 | 28.0 | ThemeREX | Snowy | CWE-98 | WordPress Snowy theme <= 1.13 - Local File Inclusion vulnerability |
| CVE-2025-69164 | 8.1 | 28.0 | ThemeREX | Skyward | CWE-98 | WordPress Skyward theme <= 1.10 - Local File Inclusion vulnerability |
| CVE-2025-69170 | 8.1 | 28.0 | ThemeREX | Eventicity | CWE-98 | WordPress Eventicity theme <= 1.5 - Local File Inclusion vulnerability |
| CVE-2025-69171 | 8.1 | 28.0 | ThemeREX | Orpheus | CWE-98 | WordPress Orpheus theme <= 1.3 - Local File Inclusion vulnerability |
| CVE-2025-69174 | 8.1 | 28.0 | ThemeREX | Etude | CWE-98 | WordPress Etude theme <= 1.6 - Local File Inclusion vulnerability |
| CVE-2025-69175 | 8.1 | 28.0 | ThemeREX | Line Agency | CWE-98 | WordPress Line Agency theme <= 1.3.1 - Local File Inclusion vulnerability |
| CVE-2026-22335 | 8.5 | 27.9 | WC Lovers. | WooCommerce Frontend Manager – Ultimate | CWE-89 | WordPress WooCommerce Frontend Manager – Ultimate plugin < 6.7.7 - SQL Inject… |
| CVE-2026-49079 | 9.3 | 27.8 | Jetimpex Inc. | JetSearch | CWE-89 | WordPress JetSearch plugin <= 3.5.17 - SQL Injection vulnerability |
| CVE-2026-6734 | 8.8 | 27.7 | undici | undici | CWE-346 | undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse |
| CVE-2026-49133 | 7.1 | 27.4 | typemill | typemill | CWE-22 | Typemill < 2.24.0 Path Traversal via ControllerApiImage::getPagemedia() |
| CVE-2025-69135 | 8.5 | 27.4 | CurlyThemes | Events Schedule - WordPress Events Calendar Plugin | CWE-89 | WordPress Events Schedule - WordPress Events Calendar Plugin plugin <= 2.7.2 … |
| CVE-2026-52716 | 6.5 | 27.2 | purethemes | WorkScout-Core | CWE-22 | WordPress WorkScout-Core plugin <= 1.7.11 - Arbitrary File Deletion vulnerabi… |
| CVE-2026-50196 | 7.5 | 27.0 | SteeltoeOSS | Steeltoe.Discovery.Eureka | CWE-20 | Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire re… |
| CVE-2025-58952 | 8.1 | 26.9 | ThemeREX | Neuronet | CWE-98 | WordPress Neuronet theme < 1.14.0 - Local File Inclusion vulnerability |
| CVE-2026-22326 | 8.1 | 26.9 | AxiomThemes | Reprizo | CWE-98 | WordPress Reprizo theme <= 1.0.8 - Local File Inclusion vulnerability |
| CVE-2026-22338 | 8.1 | 26.9 | ThemeREX | EcoBlue | CWE-98 | WordPress EcoBlue theme <= 1.15 - Local File Inclusion vulnerability |
| CVE-2026-39523 | 8.1 | 26.9 | Elated-Themes | Solene Core | CWE-98 | WordPress Solene Core plugin <= 2.3.2 - Local File Inclusion vulnerability |
| CVE-2026-39558 | 8.1 | 26.9 | Elated-Themes | Malmö | CWE-98 | WordPress Malmö theme <= 2.2 - Local File Inclusion vulnerability |
| CVE-2026-39559 | 8.1 | 26.9 | codesupplyco | Uppercase | CWE-98 | WordPress Uppercase theme < 1.2.2 - Local File Inclusion vulnerability |
| CVE-2026-39582 | 8.1 | 26.9 | xtemos | Hitek | CWE-98 | WordPress Hitek theme < 1.8.3 - Local File Inclusion vulnerability |
| CVE-2026-39590 | 8.1 | 26.9 | ThemeMove | Atomlab | CWE-98 | WordPress Atomlab theme <= 2.4.5 - Local File Inclusion vulnerability |
| CVE-2026-32967 | 9.1 | 26.8 | Apache Software Foundation | Apache DolphinScheduler | CWE-863 | Apache DolphinScheduler: The `/v2` experimental interface lacks permission ch… |
| CVE-2026-48967 | 8.5 | 26.2 | Dylan Kuhn | Geo Mashup | CWE-89 | WordPress Geo Mashup plugin <= 1.13.19 - SQL Injection vulnerability |
| CVE-2026-54185 | 8.5 | 26.2 | THEMECO | Cornerstone | CWE-89 | WordPress Cornerstone plugin < 7.8.8 - SQL Injection vulnerability |
| CVE-2026-12439 | 8.8 | 26.0 | Chrome | CWE-416 | Use after free in Digital Credentials in Google Chrome prior to 149.0.7827.15… | |
| CVE-2026-54814 | 8.1 | 25.7 | StylemixThemes | Motors | CWE-98 | WordPress Motors plugin <= 1.4.109 - Local File Inclusion vulnerability |
| CVE-2026-54193 | 7.7 | 25.7 | ThemeFusion | Fusion Builder | CWE-22 | WordPress Fusion Builder plugin <= 3.15.4 - Arbitrary File Deletion vulnerabi… |
| CVE-2026-54816 | 7.5 | 25.7 | Monetizemore | Advanced Ads | CWE-94 | WordPress Advanced Ads plugin <= 2.0.21 - Remote Code Execution (RCE) vulnera… |
| CVE-2026-12199 | 7.5 | 25.5 | nltk | nltk/nltk | CWE-306 | Unauthenticated Denial of Service in nltk.app.wordnet_app |
| CVE-2026-25439 | 8.1 | 25.1 | fs-code | Booknetic | CWE-288 | WordPress Booknetic plugin <= 4.8.5 - Account Takeover vulnerability |
| CVE-2026-12360 | 7.5 | 25.1 | Crocoblock | JetEngine | CWE-89 | JetEngine <= 3.8.10.1 - Unauthenticated SQL Injection via Listing Grid Load M… |
| CVE-2026-49058 | 9.8 | 25.0 | LoginPress | LoginPress Pro | CWE-266 | WordPress LoginPress Pro plugin <= 6.2.2 - Privilege Escalation vulnerability |
| CVE-2026-27041 | 9.9 | 24.8 | Studio Keren Aga LTD. | Unlimited Elements for Elementor (Premium) | CWE-434 | WordPress Unlimited Elements for Elementor (Premium) plugin <= 2.0.6 - Arbitr… |
| CVE-2026-44645 | 6.5 | 24.6 | harttle | liquidjs | CWE-400 | LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body |
| CVE-2026-42629 | 8.8 | 24.4 | Powerpackelements | PowerPack Pro for Elementor | CWE-288 | WordPress PowerPack Pro for Elementor plugin < v2.13.0 - Broken Authenticatio… |
| CVE-2026-10837 | 5.1 | 24.3 | Password Manager | Password Manager | CWE-601 | Open redirection vulnerability in Password Manager |
| CVE-2025-60231 | 9.8 | 24.2 | EMV | The Hospital | CWE-502 | WordPress The Hospital theme <= 1.8.1 - PHP Object Injection vulnerability |
| CVE-2025-60236 | 9.8 | 24.2 | EMV | Creatify | CWE-502 | WordPress Creatify theme <= 1.5 - PHP Object Injection vulnerability |
| CVE-2026-42357 | 6.5 | 24.0 | Apache Software Foundation | Apache DolphinScheduler | CWE-863 | Apache DolphinScheduler: Incorrect Authorization vulnerability allows users t… |
| CVE-2026-49072 | 6.5 | 23.6 | OPMC | WooCommerce Anti-Fraud | CWE-862 | WordPress WooCommerce Anti-Fraud plugin <= 7.2.6 - Broken Access Control vuln… |
| CVE-2026-54808 | 9.3 | 23.5 | WP Travel | WP Travel Gutenberg Blocks | CWE-89 | WordPress WP Travel Gutenberg Blocks plugin <= 3.9.4 - SQL Injection vulnerab… |
| CVE-2026-39442 | 8.1 | 23.5 | PressLayouts | PressMart | CWE-502 | WordPress PressMart theme <= 1.2.26 - PHP Object Injection vulnerability |
| CVE-2026-39556 | 8.1 | 23.5 | Elated-Themes | Konsept | CWE-502 | WordPress Konsept theme <= 1.9 - PHP Object Injection vulnerability |
| CVE-2026-39560 | 8.1 | 23.5 | Select-Themes | Hiroshi | CWE-502 | WordPress Hiroshi theme <= 1.5.1 - PHP Object Injection vulnerability |
| CVE-2026-40733 | 8.1 | 23.5 | Mikado-Themes | ShiftUp | CWE-502 | WordPress ShiftUp theme <= 1.3 - PHP Object Injection vulnerability |
| CVE-2026-40738 | 8.1 | 23.5 | Edge-Themes | Eldon | CWE-502 | WordPress Eldon theme <= 1.4.1 - PHP Object Injection vulnerability |
| CVE-2026-40752 | 8.1 | 23.5 | Select-Themes | Manufaktur Solutions | CWE-502 | WordPress Manufaktur Solutions theme <= 1.1.1 - PHP Object Injection vulnerab… |
| CVE-2026-40753 | 8.1 | 23.5 | Mikado-Themes | EasyMeals | CWE-502 | WordPress EasyMeals theme <= 1.5.1 - PHP Object Injection vulnerability |
| CVE-2026-10836 | 5.1 | 23.5 | Password Manager | Password Manager | CWE-644 | Improper neutralization of HTTP headers in Password Manager |
| CVE-2026-49071 | 6.5 | 23.2 | OPMC | WooCommerce Dropshipping | CWE-288 | WordPress WooCommerce Dropshipping plugin <= 5.2.4 - Broken Authentication vu… |
| CVE-2026-49108 | 9.8 | 23.1 | park_of_ideas | Moderno | CWE-502 | WordPress Moderno theme < 1.43 - PHP Object Injection vulnerability |
| CVE-2025-49403 | 7.5 | 23.1 | AA-Team | Premium Age Verification / Restriction for WordPress | CWE-98 | WordPress Premium Age Verification / Restriction for WordPress Plugin <= 3.0.… |
| CVE-2026-55201 | 7.4 | 23.1 | Hackplayers | evil-winrm | CWE-22 | Evil-WinRM - Path Traversal in download_dir() Function |
| CVE-2026-45436 | 6.5 | 23.1 | Rain-Task Ltd. | WPBakery Page Builder | CWE-862 | WordPress WPBakery Page Builder plugin <= 8.7.2 - Broken Access Control vulne… |
| CVE-2026-34888 | 7.5 | 22.9 | Bricksforge | Bricksforge | CWE-201 | WordPress Bricksforge plugin <= 3.1.8.4 - Sensitive Data Exposure vulnerability |
| CVE-2026-12530 | 8.4 | 22.8 | AWS | bedrock-agentcore | CWE-88 | Improper neutralization of argument delimiters in AWS Bedrock AgentCore Pytho… |
| CVE-2026-12441 | 8.8 | 22.8 | Chrome | CWE-416 | Use after free in File Input in Google Chrome on Linux prior to 149.0.7827.15… | |
| CVE-2026-12437 | 8.3 | 22.5 | Chrome | CWE-416 | Use after free in WebShare in Google Chrome on Windows prior to 149.0.7827.15… | |
| CVE-2026-48814 | 9.1 | 22.4 | Jovancoding | Network-AI | CWE-306 | Network-AI: Empty default secret still authorizes all requests (Incomplete fi… |
| CVE-2026-30803 | 8.8 | 22.3 | RTI | Connext Micro | CWE-191 | Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Co… |
| CVE-2024-35690 | 6.5 | 22.0 | MarketingFire | Widget Options | CWE-201 | WordPress Widget Options plugin <= 4.0.1 - Subscriber+ User Meta Data Exposur… |
| CVE-2024-32949 | 8.3 | 21.9 | Prince | Integrate Google Drive | CWE-862 | WordPress Integrate Google Drive plugin <= 1.3.8 - Broken Access Control vuln… |
| CVE-2026-27870 | 4.8 | 21.9 | Teldat | Regesta Smart HD-PLC - TLDPH16D2 | CWE-79 | CROSS-SITE SCRIPTING (XSS) VIA MALICIOUS FILE UPLOAD ON REGESTA SMART HD-PLC … |
| CVE-2026-32682 | 7.1 | 21.8 | F5 | NGINX Gateway Fabric | CWE-129 | NGINX Gateway Fabric vulnerability |
| CVE-2026-54445 | 6.9 | 21.8 | vantage6 | vantage6 | CWE-204 | Vantage6: Set admin user and password from environment or configuration |
| CVE-2026-49081 | 8.2 | 21.6 | ThemeGrill | User Registration Stripe | CWE-862 | WordPress User Registration Stripe plugin <= 1.3.12 - Broken Access Control v… |
| CVE-2026-50202 | 5.9 | 21.5 | SteeltoeOSS | Steeltoe.Security.Authentication.CloudFoundryBase | CWE-668 | Steeltoe's static JWKS cache shared across schemes and never invalidated |
| CVE-2026-54186 | 9.3 | 21.5 | eyecix | JobSearch | CWE-89 | WordPress JobSearch plugin <= 3.2.9 - SQL Injection vulnerability |
| CVE-2026-39546 | 7.6 | 21.4 | Techspawn | MultiLoca | CWE-266 | WordPress MultiLoca plugin <= 4.2.15 - Privilege Escalation vulnerability |
| CVE-2026-40768 | 7.3 | 21.4 | Dimitri Grassi | Salon booking system | CWE-639 | WordPress Salon booking system plugin <= 10.30.24 - Insecure Direct Object Re… |
| CVE-2026-52705 | 9.0 | 21.1 | BDthemes | SigmaForms Pro – AI Generated Forms | CWE-434 | WordPress SigmaForms Pro – AI Generated Forms plugin <= 1.4.5 - Arbitrary Fil… |
| CVE-2026-54533 | 6.9 | 21.1 | vantage6 | vantage6 | CWE-284 | vantage6 node has an Improper Access Control issue |
| CVE-2026-12529 | 6.9 | 21.0 | SourceCodester | CET Automated Grading System with AI Predictive Analytics | CWE-266 | SourceCodester CET Automated Grading System with AI Predictive Analytics Stud… |
| CVE-2026-22332 | 9.3 | 20.9 | Themeum | Tutor LMS Pro | CWE-89 | WordPress Tutor LMS Pro plugin <= 3.9.6 - SQL Injection vulnerability |
| CVE-2026-49084 | 9.3 | 20.9 | Jetimpex Inc. | JetEngine | CWE-89 | WordPress JetEngine plugin < 3.8.9.1 - SQL Injection vulnerability |
| CVE-2026-54187 | 9.3 | 20.9 | Jetimpex Inc. | JetEngine | CWE-89 | WordPress JetEngine plugin <= 3.8.10.1 - SQL Injection vulnerability |
| CVE-2026-54811 | 9.3 | 20.9 | Tips and Tricks HQ | WP eMember | CWE-89 | WordPress WP eMember plugin < v10.9.4 - SQL Injection vulnerability |
| CVE-2026-54812 | 9.3 | 20.9 | StylemixThemes | Motors | CWE-89 | WordPress Motors plugin <= 1.4.109 - SQL Injection vulnerability |
| CVE-2026-10641 | 7.1 | 20.8 | zephyrproject | zephyr | CWE-787 | Out-of-bounds write in Bluetooth HFP Hands-Free CIND indicator parsing (cind_… |
| CVE-2026-54818 | 8.5 | 20.4 | VeronaLabs | Slimstat Analytics | CWE-89 | WordPress Slimstat Analytics plugin <= 5.4.11 - SQL Injection vulnerability |
| CVE-2024-27928 | 5.9 | 20.4 | vantage6 | vantage6 | CWE-308 | Vantage6: 2FA can be circumvented with hacked email access |
| CVE-2024-24769 | 2.1 | 20.3 | vantage6 | vantage6 | CWE-400 | Vantage6: No limit on emails sent for password/MFA reset |
| CVE-2026-54804 | 7.6 | 19.8 | melhorenvio | Melhor Envio | CWE-288 | WordPress Melhor Envio plugin <= 2.16.3 - Broken Authentication vulnerability |
| CVE-2026-27410 | 6.5 | 19.9 | VeronaLabs | Slimstat Analytics | CWE-502 | WordPress Slimstat Analytics plugin < 5.4.0 - Deserialization of untrusted da… |
| CVE-2026-11857 | 8.4 | 19.7 | Quanos Solutions GmbH | SCHEMA ST4 | CWE-502 | Insecure .NET Remoting deserialization in Quanos SCHEMA ST4 Client Update Ser… |
| CVE-2026-55197 | 7.1 | 19.7 | nesquena | hermes-webui | CWE-639 | Hermes WebUI < 0.51.443 - Broken Access Control in /api/session Endpoint |
| CVE-2026-55198 | 7.1 | 19.7 | nesquena | hermes-webui | CWE-639 | Hermes WebUI < 0.51.443 - Cross-Profile Session Data Exfiltration via Session… |
| CVE-2026-48764 | 8.2 | 19.6 | baptisteArno | typebot.io | CWE-918 | TypeBot has SSRF in HTTP request and script fetch flows via DNS rebinding bypass |
| CVE-2026-12462 | 7.5 | 19.4 | Chrome | CWE-416 | Use after free in Media in Google Chrome prior to 149.0.7827.155 allowed a re… | |
| CVE-2026-44646 | 5.3 | 19.4 | harttle | liquidjs | CWE-693 | LiquidJS: `{% render %}` tag silently bypasses per-render `ownPropertyOnly:tr… |
| CVE-2026-10741 | 5.9 | 19.3 | Sonatype | Nexus Repository Manager | CWE-863 | Nexus Repository Manager - Incorrect Authorization allows credential disclosu… |
| CVE-2026-10696 | 7.5 | 19.1 | Devolutions | UniGetUI | CWE-706 | Use of an incorrectly resolved name or reference in the pinget backend in Dev… |
| CVE-2024-37210 | 6.5 | 19.2 | ali2woo | AliNext | CWE-862 | WordPress AliExpress Dropshipping with AliNext Lite plugin <= 3.3.5 - Broken … |
| CVE-2026-48768 | 9.3 | 19.1 | baptisteArno | typebot.io | CWE-22 | TypeBot: Unauthenticated arbitrary s3 object write in generate-upload-url via… |
| CVE-2026-48979 | 7.5 | 18.9 | php-standard-library | php-standard-library | CWE-444 | PHP Standard Library: HTTP/2 server-side missing content-length validation en… |
| CVE-2026-22343 | 8.6 | 18.0 | PremiumPress Limited. | WordPress Dating Theme | CWE-862 | WordPress WordPress Dating Theme theme <= 11.2.0 - Broken Access Control vuln… |
| CVE-2026-8607 | 6.4 | 18.0 | saadiqbal | Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred | CWE-79 | myCred – Points Management System For Gamification, Ranks, Badges, and Loyalt… |
| CVE-2026-24575 | 4.3 | 17.8 | WishList Member | WishList Member X | CWE-862 | WordPress WishList Member X plugin <= 3.29.0 - Broken Access Control vulnerab… |
| CVE-2026-48820 | 6.3 | 17.7 | cakephp | cakephp | CWE-22 | CakePHP: View::element() is missing a path containment check |
| CVE-2026-9679 | 5.9 | 17.6 | undici | undici | CWE-93 | undici vulnerable to HTTP header injection via Set-Cookie percent-decoding |
| CVE-2026-12452 | 8.8 | 17.5 | Chrome | CWE-416 | Use after free in Downloads in Google Chrome on Android prior to 149.0.7827.1… | |
| CVE-2026-8494 | 6.4 | 17.4 | mbis | Permalink Manager Lite | CWE-79 | Permalink Manager Lite <= 2.5.3.3 - Authenticated (Contributor+) Stored Cross… |
| CVE-2026-11975 | 6.2 | 17.5 | simplcommerce | SimplCommerce | CWE-79 | Stored Cross-Site Scripting (XSS) in SimplCommerce News Module Admin Interface |
| CVE-2026-12448 | 8.8 | 17.3 | Chrome | CWE-269 | Inappropriate implementation in WebView in Google Chrome on Android prior to … | |
| CVE-2026-30799 | 6.1 | 17.3 | RTI | Connext Professional | CWE-306 | Missing Authentication for Critical Function vulnerability in RTI Connext Pro… |
| CVE-2026-54184 | 8.2 | 17.1 | Alberto Hornero | Clean Login | CWE-639 | WordPress Clean Login plugin <= 1.15 - Insecure Direct Object References (IDO… |
| CVE-2026-54817 | 6.5 | 17.0 | FluxBuilder | MStore API | CWE-288 | WordPress MStore API plugin <= 4.18.4 - Broken Authentication vulnerability |
| CVE-2026-20220 | 6.3 | 17.0 | Cisco | Cisco Crosswork Network Change Automation | CWE-74 | Cisco Crosswork Network Controller Remote Code Execution Vulnerability |
| CVE-2026-12440 | 9.6 | 16.8 | Chrome | CWE-416 | Use after free in DigitalCredentials in Google Chrome on Windows prior to 149… | |
| CVE-2026-7300 | 8.8 | 16.8 | RTI | Connext Professional | CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulner… |
| CVE-2026-12568 | 6.5 | 16.8 | Black Lantern Security | BBOT | CWE-22 | Arbitrary File Write in postman_download module |
| CVE-2026-40756 | 8.1 | 16.6 | Mikado-Themes | Zoya | CWE-502 | WordPress Zoya theme <= 1.4 - PHP Object Injection vulnerability |
| CVE-2026-40757 | 8.1 | 16.6 | Mikado-Themes | Château | CWE-502 | WordPress Château theme <= 1.2.1 - PHP Object Injection vulnerability |
| CVE-2026-30802 | 8.8 | 16.5 | RTI | Connext Micro | CWE-125 | Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows… |
| CVE-2024-33909 | 5.3 | 16.6 | Avirtum | iPages Flipbook | CWE-862 | WordPress iPages Flipbook plugin <= 1.5.1 - Broken Access Control vulnerability |
| CVE-2026-40726 | 8.2 | 15.9 | ThemeGrill | User Registration Stripe | CWE-862 | WordPress User Registration Stripe plugin <= 1.3.14 - Broken Access Control v… |
| CVE-2026-22328 | 7.1 | 15.9 | VamTam | Auto Repair | CWE-79 | WordPress Auto Repair theme <= 22.6 - Reflected Cross Site Scripting (XSS) vu… |
| CVE-2026-24610 | 4.3 | 15.8 | WPMet | MetForm Pro | CWE-862 | WordPress MetForm Pro plugin <= 3.9.1 - Broken Access Control vulnerability |
| CVE-2026-40723 | 4.3 | 15.8 | Bricks | Bricks Builder | CWE-862 | WordPress Bricks Builder theme <= 2.1.4 - Broken Access Control vulnerability |
| CVE-2026-12465 | 8.3 | 15.7 | Chrome | CWE-20 | Object lifecycle issue in Metrics in Google Chrome prior to 149.0.7827.155 al… | |
| CVE-2026-12461 | 6.5 | 15.6 | Chrome | CWE-125 | Out of bounds read in WebRTC in Google Chrome on Windows prior to 149.0.7827.… | |
| CVE-2024-49269 | 7.1 | 15.5 | Mythemes | my flatonica | CWE-79 | WordPress my flatonica theme <= 0.0.8 - Reflected Cross Site Scripting (XSS) … |
| CVE-2026-54386 | 5.1 | 15.3 | marimo-team | marimo | CWE-79 | marimo < 0.23.9 XSS via file Query Parameter in assets.py |
| CVE-2026-12491 | 4.8 | 15.3 | vllm-project | vLLM | CWE-115 | Vllm: vllm: image exif rotation & png trns transparency not normalized, causi… |
| CVE-2026-50194 | 8.2 | 15.1 | SteeltoeOSS | Steeltoe.Management.Endpoint | CWE-288 | Steeltoe vulnerable to management-port isolation bypass via spoofed Host header |
| CVE-2026-52696 | 7.5 | 15.1 | Jetimpex Inc. | JetBlog | CWE-1258 | WordPress JetBlog plugin <= 2.4.8 - Sensitive Data Exposure vulnerability |
| CVE-2026-11525 | 3.7 | 15.2 | undici | undici | CWE-183 | undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive s… |
| CVE-2026-54810 | 7.5 | 14.9 | Nexi Payments | Nexi XPay | CWE-862 | WordPress Nexi XPay plugin <= 8.3.1 - Broken Access Control vulnerability |
| CVE-2026-54196 | 6.8 | 14.9 | Jetmonsters | JetFormBuilder | CWE-266 | WordPress JetFormBuilder plugin <= 3.6.1 - Privilege Escalation vulnerability |
| CVE-2026-54809 | 9.3 | 14.6 | VillaTheme | GIFT4U | CWE-89 | WordPress GIFT4U plugin <= 1.0.10 - SQL Injection vulnerability |
| CVE-2026-50201 | 6.5 | 14.2 | SteeltoeOSS | Steeltoe.Management.Endpoint | CWE-269 | Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission |
| CVE-2025-59560 | 7.1 | 14.1 | SONAAR MUSIC | Sonaar | CWE-79 | WordPress Sonaar theme <= 4.27.4 - Cross Site Scripting (XSS) vulnerability |
| CVE-2025-68524 | 7.1 | 14.1 | ThemeGoods | Avante | CWE-79 | WordPress Avante theme < 3.0.5 - Reflected Cross Site Scripting (XSS) vulnera… |
| CVE-2026-22339 | 7.1 | 14.1 | Jobster Marketplace | WPJobster | CWE-79 | WordPress WPJobster theme <= 6.3.5 - Reflected Cross Site Scripting (XSS) vul… |
| CVE-2026-40765 | 7.1 | 14.1 | collectchat | collectchat | CWE-79 | WordPress collectchat plugin <= 2.4.9 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-41557 | 7.1 | 14.1 | PressLayouts | Kapee | CWE-79 | WordPress Kapee theme < 1.7.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-42385 | 7.1 | 14.1 | Cozmoslabs | Profile Builder Pro | CWE-79 | WordPress Profile Builder Pro plugin <= 3.15.0 - Cross Site Scripting (XSS) v… |
| CVE-2026-54815 | 9.3 | 14.0 | Cargo RD | Cargo Shipping Location for WooCommerce | CWE-89 | WordPress Cargo Shipping Location for WooCommerce plugin <= 5.6 - SQL Injecti… |
| CVE-2026-54819 | 9.3 | 14.0 | Webilia Inc. | Listdom | CWE-89 | WordPress Listdom plugin <= 5.4.0 - SQL Injection vulnerability |
| CVE-2026-35069 | 8.0 | 14.0 | Dell | PowerFlex | CWE-89 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper N… |
| CVE-2026-32804 | 8.1 | 13.9 | Dell | PowerFlex | CWE-287 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper A… |
| CVE-2025-15657 | 5.3 | 13.8 | Mojoomla | School Management | CWE-639 | WordPress School Management plugin <= 93.1.0 - Insecure Direct Object Referen… |
| CVE-2026-12455 | 7.5 | 13.7 | Chrome | CWE-416 | Use after free in Tab Strip in Google Chrome prior to 149.0.7827.155 allowed … | |
| CVE-2026-12528 | 5.4 | 13.6 | Red Hat | Red Hat Directory Server 11 | CWE-787 | 389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt() |
| CVE-2026-12515 | 4.3 | 13.1 | Red Hat | Red Hat Satellite 6.16 for RHEL 8 | CWE-862 | Katello: missing repository authorization in content_uploads exposes cross-pr… |
| CVE-2026-12464 | 8.3 | 13.1 | Chrome | CWE-416 | Use after free in Browser in Google Chrome prior to 149.0.7827.155 allowed a … | |
| CVE-2026-12467 | 8.3 | 13.1 | Chrome | CWE-416 | Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed… | |
| CVE-2026-54192 | 7.1 | 12.9 | Ays Pro | Popup box | CWE-79 | WordPress Popup box plugin <= 6.2.9 - Reflected Cross Site Scripting (XSS) vu… |
| CVE-2026-6733 | 3.7 | 12.8 | undici | undici | CWE-367 | undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse |
| CVE-2026-0092 | 10.0 | 12.5 | Android | CWE-862 | In Package Manager, there is a possible device lock controller bypass due to … | |
| CVE-2026-55748 | 6.0 | 12.5 | OpenStack | Horizon | CWE-78 | OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downlo… |
| CVE-2026-20265 | 4.3 | 12.4 | Splunk | Splunk AI Toolkit | CWE-1188 | Insecure Default Domain Allowlist in Splunk AI Toolkit |
| CVE-2026-8089 | 7.1 | 12.2 | Unknown | weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce | CWE-79 | weMail < 2.1.3 - Reflected Cross-Site Scripting |
| CVE-2026-52698 | 7.4 | 12.0 | Syed Balkhi | PushEngage – Web Push Notifications, eCommerce Automation & Chat Widget | CWE-201 | WordPress PushEngage – Web Push Notifications, eCommerce Automation & Chat Wi… |
| CVE-2026-22283 | 7.5 | 11.9 | Dell | PowerFlex | CWE-829 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Inclusion … |
| CVE-2026-48817 | 5.3 | 11.9 | Kludex | starlette | CWE-470 | Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via … |
| CVE-2026-2675 | 6.0 | 11.8 | RTI | Connext Professional | CWE-306 | Missing Authentication for Critical Function vulnerability in RTI Connext Pro… |
| CVE-2026-49502 | 8.1 | 11.4 | Dell | PowerFlex | CWE-287 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper A… |
| CVE-2026-35162 | 6.5 | 11.5 | Dell | PowerFlex | CWE-284 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper A… |
| CVE-2026-39595 | 4.7 | 11.5 | BoldGrid | W3 Total Cache | CWE-862 | WordPress W3 Total Cache plugin <= 2.9.1 - Broken Access Control vulnerability |
| CVE-2026-12565 | 5.3 | 11.3 | Black Lantern Security | BBOT | CWE-22 | Path Traversal (Zip-Slip) in unarchive module |
| CVE-2024-31435 | 4.3 | 11.3 | Inisev | Social Media & Share Icons | CWE-862 | WordPress Social Media Share Buttons & Social Sharing Icons plugin <= 2.8.6 -… |
| CVE-2024-37496 | 4.3 | 11.3 | Rara Themes | Metro Magazine | CWE-862 | WordPress Metro Magazine theme <= 1.3.7 - Broken Access Control on Notice Dis… |
| CVE-2026-12438 | 8.3 | 11.2 | Chrome | CWE-693 | Inappropriate implementation in WebView in Google Chrome on Android prior to … | |
| CVE-2026-54813 | 8.5 | 10.8 | Brainstorm Force | SureDash | CWE-89 | WordPress SureDash plugin <= 1.8.0 - SQL Injection vulnerability |
| CVE-2025-62340 | 5.3 | 10.7 | HCL Software | iControl | CWE-613 | HCL iControl was affected by Inadequate Session Timeout vulnerability |
| CVE-2026-44644 | 6.1 | 10.6 | harttle | liquidjs | CWE-79 | LiquidJS's strip_html filter bypass via newline characters in HTML tags enabl… |
| CVE-2026-48759 | 7.1 | 10.5 | baptisteArno | typebot.io | CWE-639 | TypeBot: Cross-Workspace Theme Template IDOR (Modification and Deletion) |
| CVE-2026-20178 | 4.3 | 10.5 | Cisco | Cisco Webex App | CWE-601 | A vulnerability in the browser-based version of Cisco Webex App could have al… |
| CVE-2026-3894 | 9.2 | 10.2 | RTI | Connext Professional | CWE-125 | Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries)… |
| CVE-2026-54195 | 7.1 | 9.9 | Jetmonsters | JetFormBuilder | CWE-79 | WordPress JetFormBuilder plugin <= 3.6.0.1 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-9591 | 6.9 | 9.8 | simplcommerce | SimplCommerce | CWE-352 | Cross-Site Request Forgery (CSRF) in SimplCommerce News Module |
| CVE-2026-12446 | 4.3 | 9.5 | Chrome | CWE-863 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.782… | |
| CVE-2026-35068 | 5.7 | 9.2 | Dell | PowerFlex | CWE-89 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper N… |
| CVE-2024-24709 | 4.3 | 9.2 | Shareaholic | Shareaholic | CWE-862 | WordPress Shareaholic plugin <= 9.7.11 - Broken Access Control vulnerability |
| CVE-2025-48571 | 4.3 | 9.1 | Android | CWE-693 | In multiple functions of btm_sec.cc, there is a possible way for an attacker … | |
| CVE-2026-12458 | 3.1 | 9.0 | Chrome | CWE-451 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.782… | |
| CVE-2026-2467 | 9.2 | 8.9 | RTI | Connext Professional | CWE-122 | Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Li… |
| CVE-2026-40722 | 5.5 | 8.7 | Yoast BV | Yoast SEO Premium | CWE-862 | WordPress Yoast SEO Premium plugin <= 26.6 - Broken Access Control vulnerability |
| CVE-2026-22329 | 7.1 | 8.5 | Themeum | Skillate | CWE-79 | WordPress Skillate theme <= 1.2.10 - Reflected Cross Site Scripting (XSS) vul… |
| CVE-2026-49778 | 7.1 | 8.6 | WPFunnels | WPFunnels Pro | CWE-79 | WordPress WPFunnels Pro plugin <= 2.9.4 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-12469 | 4.3 | 8.5 | Chrome | CWE-457 | Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.155 … | |
| CVE-2026-50200 | 7.5 | 8.4 | SteeltoeOSS | Steeltoe.Management.Endpoint | CWE-200 | Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords |
| CVE-2026-22342 | 8.8 | 8.3 | PremiumPress Limited. | WordPress Dating Theme | CWE-352 | WordPress WordPress Dating Theme theme <= 11.2.0 - Cross Site Request Forgery… |
| CVE-2026-48117 | 6.8 | 8.3 | fduflyer | DroneAware-Node-Releases | CWE-287 | DroneAware's Improper Account Activation in Registration and SSO Flows Leads … |
| CVE-2026-12450 | 6.5 | 8.3 | Chrome | CWE-269 | Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.15… | |
| CVE-2026-35066 | 7.1 | 8.2 | Dell | PowerFlex | CWE-284 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper A… |
| CVE-2026-12459 | 6.1 | 8.0 | Chrome | CWE-79 | Inappropriate implementation in Serial in Google Chrome prior to 149.0.7827.1… | |
| CVE-2025-69140 | 7.1 | 7.9 | SeventhQueen | SweetDate Core | CWE-79 | WordPress SweetDate Core plugin < 1.1.5 - Reflected Cross Site Scripting (XSS… |
| CVE-2026-2674 | 4.8 | 7.9 | RTI | Connext Professional | CWE-787 | Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Servi… |
| CVE-2026-12453 | 4.2 | 7.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in Input in Google Chrome prior to… | |
| CVE-2025-69189 | 7.3 | 7.6 | EMV | JobBank | CWE-862 | WordPress JobBank plugin <= 1.2.3 - Broken Access Control vulnerability |
| CVE-2026-12451 | 8.3 | 7.5 | Chrome | CWE-416 | Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.155… | |
| CVE-2026-39597 | 7.1 | 7.3 | WPZOOM | WPZOOM Addons for Elementor | CWE-79 | WordPress WPZOOM Addons for Elementor plugin <= 1.3.4 - Reflected Cross Site … |
| CVE-2026-40720 | 7.1 | 7.3 | Royal Elementor Addons | Royal Elementor Addons Pro | CWE-79 | WordPress Royal Elementor Addons Pro plugin < 1.7.1041 - Cross Site Scripting… |
| CVE-2026-49074 | 7.1 | 7.3 | Jetimpex Inc. | JetEngine | CWE-79 | WordPress JetEngine plugin <= 3.8.9.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-12566 | 3.1 | 6.4 | Black Lantern Security | BBOT | CWE-918 | SSRF via unvalidated WWW-Authenticate realm in docker_pull module |
| CVE-2026-0082 | 10.0 | 6.2 | Android | CWE-453 | In tryStartActivity of NfcDispatcher.java, there is a possible automatic spec… | |
| CVE-2026-10850 | 6.9 | 6.2 | Plane | Plane | CWE-79 | Plane 1.3.1 - Stored XSS in intake issue description_html |
| CVE-2025-15641 | 6.8 | 6.0 | Netskope | Netskope Client | CWE-782 | Netskope Client Exposed IOCTL with Insufficient Access Controls |
| CVE-2026-48990 | 5.3 | 6.0 | authlib | joserfc | CWE-400 | joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limit… |
| CVE-2026-12445 | 7.5 | 5.5 | Chrome | CWE-416 | Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed… | |
| CVE-2026-0063 | 10.0 | 5.2 | Android | CWE-269 | In setAllowedCarriers of PhoneInterfaceManager.java, there is a possible way … | |
| CVE-2026-0071 | 10.0 | 5.2 | Android | CWE-862 | In SettingsLib, there is a possible missing permission check due to a logic e… | |
| CVE-2024-33685 | 4.3 | 5.2 | Jegstudio | Startupzy | CWE-862 | WordPress Startupzy theme <= 1.1.1 - Broken Access Control vulnerability |
| CVE-2026-12460 | 4.2 | 5.0 | Chrome | CWE-284 | Insufficient policy enforcement in File System Access in Google Chrome prior … | |
| CVE-2026-5667 | 7.2 | 4.8 | Mitsubishi Electric Corporation | Room Air Conditioners (for Japan) MSZ-BKR2223-W | CWE-798 | Information Disclosure, Information Tampering, or Denial-of-Service (DoS) Vul… |
| CVE-2026-35067 | 8.0 | 4.7 | Dell | PowerFlex | CWE-284 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper A… |
| CVE-2026-0081 | 10.0 | 4.5 | Android | CWE-862 | In NFC, there is a possible way to spoof an NFC event due to a missing permis… | |
| CVE-2026-28576 | 10.0 | 4.5 | Android | Android | CWE-89 | In Contacts Provider, there is a possible way to access the contacts database… |
| CVE-2026-12454 | 8.3 | 4.4 | Chrome | CWE-362 | Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.155 allowed… | |
| CVE-2025-31013 | 7.1 | 4.4 | Themify | Themify Folo | CWE-79 | WordPress Themify Folo theme <= 1.9.6 - Reflected Cross Site Scripting (XSS) … |
| CVE-2026-9570 | 7.1 | 4.4 | Unknown | Taskbuilder | CWE-79 | Taskbuilder < 5.0.8 - Reflected XSS via Shortcode |
| CVE-2025-32748 | 6.1 | 4.4 | Dell | PowerFlex rack | CWE-601 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header… |
| CVE-2026-12468 | 8.3 | 4.1 | Chrome | CWE-362 | Race in Updater in Google Chrome on Mac prior to 149.0.7827.155 allowed a rem… | |
| CVE-2025-15642 | 6.8 | 4.2 | Netskope | Netskope Client | CWE-276 | Netskope Client Service Insufficient Access Controls |
| CVE-2026-12444 | 5.5 | 4.1 | Chrome | CWE-125 | Out of bounds read in Chromoting in Google Chrome on Windows prior to 149.0.7… | |
| CVE-2026-54188 | 7.1 | 4.0 | Jetimpex Inc. | JetEngine | CWE-79 | WordPress JetEngine plugin <= 3.8.10 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-54189 | 7.1 | 4.0 | Jetimpex Inc. | JetEngine | CWE-79 | WordPress JetEngine plugin <= 3.8.10 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-7850 | 5.9 | 3.8 | Unknown | WP Magnific Popup | — | WP Magnific Popup <= 1.0 - Author+ Stored XSS via href Attribute |
| CVE-2026-12456 | 4.2 | 3.6 | Chrome | CWE-20 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.78… | |
| CVE-2026-12457 | 4.2 | 3.5 | Chrome | CWE-693 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.78… | |
| CVE-2026-48591 | 4.8 | 3.3 | pragdave | earmark | CWE-83 | Stored XSS via unescaped HTML attribute values in earmark |
| CVE-2026-12463 | 4.7 | 3.3 | Chrome | CWE-79 | Inappropriate implementation in Views in Google Chrome on Linux prior to 149.… | |
| CVE-2026-48821 | 5.8 | 3.0 | shaarli | Shaarli | CWE-79 | Shaarli: DOM-based Cross-Site Scripting (XSS) in Thumbnail Synchronizer |
| CVE-2026-48991 | 5.5 | 2.8 | XianYuLauncher | XianYuLauncher | CWE-287 | XianYuLauncher: Legacy Microsoft account OAuth sign-in flow lacks PKCE and st… |
| CVE-2024-35648 | 4.3 | 2.8 | Andy Moyle | Emergency Password Reset | CWE-352 | WordPress Emergency Password Reset plugin <= 8.0 - Cross Site Request Forgery… |
| CVE-2026-11858 | 8.4 | 2.7 | Quanos Solutions GmbH | SCHEMA ST4 | CWE-862 | Missing authorization in Quanos SCHEMA ST4 Client Update Service allows arbit… |
| CVE-2026-28575 | 10.0 | 2.6 | Android | CWE-400 | In PackageInstaller.Session#transfer of frameworks/base/services/core/java/co… | |
| CVE-2026-39199 | 2.9 | 2.6 | Snes9X team | Snes9X | CWE-787 | snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted… |
| CVE-2024-47477 | 6.5 | 2.5 | Dell | PowerFlex Manager | CWE-295 | Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certif… |
| CVE-2026-0068 | 10.0 | 2.5 | Android | CWE-362 | In createSessionInternal of PackageInstallerService.java, there is a possible… | |
| CVE-2026-28615 | 10.0 | 2.5 | Android | CWE-862 | In Telecomm, there is a possible way to initiate an unauthorized phone call d… | |
| CVE-2026-0064 | 10.0 | 2.4 | Android | CWE-400 | In multiple places, there is a possible persistent denial of service due to r… | |
| CVE-2026-0083 | 10.0 | 2.2 | Android | CWE-362 | In Nfc::eventCallback() of Nfc.h, there is a possible use after free due to a… | |
| CVE-2026-48822 | 5.8 | 2.2 | shaarli | Shaarli | CWE-79 | Shaarli has Stored Cross-Site Scripting (XSS) via Markdown Reference Links |
| CVE-2024-34810 | 4.3 | 1.9 | Extend Themes | Skyline WP | CWE-352 | WordPress Skyline WP theme <= 1.0.10 - Cross Site Request Forgery (CSRF) vuln… |
| CVE-2026-1288 | 5.5 | 1.8 | Autodesk | Revit | CWE-476 | RFA File Parsing Vulnerability in Autodesk Revit |
| CVE-2026-28587 | 10.0 | 1.8 | Android | CWE-862 | In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve… | |
| CVE-2026-48823 | 4.8 | 1.8 | shaarli | Shaarli | CWE-79 | Shaarli has Stored Cross-Site Scripting (XSS) via Tags Search |
| CVE-2026-8049 | 5.3 | 1.6 | SignalRGB | SignalRGB kernel driver | — | CVE-2026-8049 |
| CVE-2026-12449 | 7.8 | 1.4 | Chrome | CWE-416 | Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.… | |
| CVE-2026-53870 | 6.8 | 1.4 | NousResearch | hermes-agent | CWE-276 | Hermes Agent < 0.16.0 - Sensitive File Permission Vulnerability in Store Files |
| CVE-2026-20246 | 6.0 | 1.2 | Cisco | Cisco Umbrella Insights Virtual Appliance | CWE-269 | Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability |
| CVE-2026-40641 | 4.8 | 1.0 | Dell | PowerFlex | CWE-327 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Use of a B… |
| CVE-2026-32652 | 7.8 | 0.9 | Dell | AIOps | CWE-1392 | Dell AIOps Collector versions prior to 1.18.3 contain a "Use of Default Crede… |
| CVE-2025-48640 | 8.0 | 0.7 | Android | CWE-862 | In multiple locations, there is a possible 3rd party passkey entry pairing ap… | |
| CVE-2026-12567 | 2.2 | 0.6 | Black Lantern Security | BBOT | CWE-59 | Symlink-following arbitrary write via github_workflows module |
| CVE-2025-48643 | 7.8 | 0.3 | Android | CWE-20 | In multiple locations there is a possible provisioning bypass due to improper… | |
| CVE-2026-0019 | 7.8 | 0.2 | Android | CWE-269 | In SettingsLib, there is a possible way to disable system components due to a… | |
| CVE-2025-48617 | 7.8 | 0.1 | Android | CWE-862 | In overrideConfig of CarrierConfigLoader.java, there is a possible way to byp… | |
| CVE-2026-50267 | 4.7 | 0.0 | SteeltoeOSS | Steeltoe.Configuration.Abstractions | CWE-312 | Steeltoe: TLS private keys written to /tmp with default permissions, never de… |
| CVE-2026-0057 | 3.3 | 0.0 | Android | CWE-862 | In Contacts Provider, there is a possible way to access an incoming call's ph… | |
| CVE-2026-50268 | 1.9 | 0.0 | SteeltoeOSS | Steeltoe.Configuration.Encryption | CWE-256 | Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-06-17 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion.