boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Thursday, June 18, 2026 · all times UTC← 2026-06-17 · archive · 2026-06-19 →

Security Box Score — June 18, 2026

151 CVEs published, led by mcdope (7).

151 CVEs published June 18, 2026: 27 critical, 59 high, 62 medium, 3 low; 1 in the KEV catalog at press time; 5 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 126 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published48659326——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

432 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux9610638466431411120.27.8.0013-119 ▼
google68485983454293297760.78.1.0023+684 ▲
microsoft212748565161706286192.57.8.0044+69 ▲
red hat671618677511200.06.6.0028+61 ▲
apple146612142288710.65.7.0019-1 ▼
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
suse350410000.08.5.0022+3 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco92165100561047.67.2.0438+8 ▲
netgear171700161000.04.3.0024+17 ▲
palo alto networks911127113218.25.9.0022+7 ▲
ivanti49450025555.68.8.5187+3 ▲
checkpoint3915303111.17.5.0410+3 ▲
fortinet29432028333.38.3.0076+1 ▲
f56843104112.58.9.0225+5 ▲
ubiquiti584400300.08.9.0052+5 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache7410818414623310.97.3.0050+70 ▲
mozilla49551118260900.07.3.0026+45 ▲
gitlab1118041224211.14.8.0024+11 ▲
docker470520000.08.2.0016+4 ▲
drupal0511304120.05.1.00260
github021100000.08.1.03470
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2422701321161842720.78.8.0040+242 ▲
adobe1291314507521921.55.5.0021+129 ▲
ibm11601329180600.07.5.0028+11 ▲
progress591710600.07.5.0036+5 ▲
solarwinds36231010466.77.8.6082+3 ▲
veeam142200100.09.0.0052+1 ▲
zohocorp020110000.07.1.01040
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5 ▲
d-link9110425300.05.5.0058+9 ▲
siemens780440000.07.5.0020+6 ▲
rockwell automation771510000.08.7.0030+7 ▲
abb550410000.07.2.0018+5 ▲
moxa550320000.07.0.0029+5 ▲
dahua330111000.06.9.0036+3 ▲
hitachi energy020020000.05.7.00140
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7172230391000.06.5.0023+71 ▲
openclaw61670352210000.07.0.0021+61 ▲
sourcecodester3759002534000.02.1.0026+37 ▲
themerex585855300000.08.1.0043+58 ▲
edimax051032019100.07.4.00590
concrete cms2461111321000.06.2.0015+2 ▲
dell2644120230212.36.7.0016+26 ▲
open ises044221210000.07.1.00210

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9991100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-9082.883299.89.8
CVE-2026-50751.837799.79.3
CVE-2026-48907.781099.510.0
CVE-2026-45498.630899.17.5
CVE-2026-49160.538398.97.5
CVE-2026-10523.518798.99.8
CVE-2026-28318.400198.57.5
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9991KEV
CVE-2026-4890710.0.7810KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4508710.0.1296
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-4925710.0.0093
CVE-2026-2022310.0.0083
Most disclosures (vendor)
VendorCVEs
google852
linux520
oracle267
microsoft234
adobe129
red hat103
apache91
spring72
openclaw67
ibm60
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco10
apple7
google6
ivanti5
solarwinds4
berriai3
fortinet3
smartertools3
adobe2
Most-affected ecosystems
EcosystemAdvisories
Maven42
Packagist22
PyPI11
npm4
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2025-48595Google0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-28318SolarWinds0
CVE-2026-34926Trend Micro, Inc.0
CVE-2026-35273Oracle Corporation0
CVE-2026-41091Microsoft0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171674
CVE-2021-27102n/a2021-11-171674
CVE-2021-27101n/a2021-11-171674
CVE-2021-27103n/a2021-11-171674
CVE-2021-21017Adobe2021-11-171674
CVE-2021-28550Adobe2021-11-171674
CVE-2021-42013Apache Software Foundation2021-11-171674
CVE-2021-41773Apache Software Foundation2021-11-171674
CVE-2021-30858Apple2021-11-171674
CVE-2021-30860Apple2021-11-171674

Transactions

EXPLOIT PUBLISHED — CVE-2026-43994 (coturn). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-44663 (AcademySoftwareFoundation openexr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-45696 (AcademySoftwareFoundation openexr). Public exploit reference added.

Yesterday's Results

How to read these box scores · glossary

151 CVEs published. 25 box scores, 126 table rows — nothing truncated.

Splunk Splunk Enterprise — Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .9694   99.9   YES
AFFECTED
  Product            Versions  Fixed
  Splunk Enterprise  10.2 –    —
TIMELINE
  Oct 8   Reserved by CNA
  Jun 18  Added to CISA KEV, due Jun 21
  Jun 18  Published (CNA: cisco)
CWE-306 · CNA: cisco · CVSS v3.1 · 3 references · NVD status: Analyzed · KEV due June 21, 2026
n/a n/a — InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0231   82.0     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 18  Published (CNA: mitre)
CWE-77 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Analyzed
n/a n/a — InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0231   82.0     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 18  Published (CNA: mitre)
CWE-77 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Analyzed
n/a n/a — InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0231   82.0     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 18  Published (CNA: mitre)
CWE-77 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Analyzed
n/a n/a — InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0231   82.0     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 18  Published (CNA: mitre)
CWE-77 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Analyzed
FFmpeg FFmpeg — Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0157   73.5     —
AFFECTED
  Product  Versions     Fixed
  FFmpeg   unspecified  —
TIMELINE
  May 13  Reserved by CNA
  Jun 18  Published (CNA: JFROG)
CWE-787 · CNA: JFROG · CVSS v3.1 · 5 references · NVD status: Awaiting Analysis
Microsoft Microsoft 365 Copilot — M365 Copilot Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0108   62.7     —
AFFECTED
  Product                Versions  Fixed
  Microsoft 365 Copilot  - –       —
TIMELINE
  Jun 11  Reserved by CNA
  Jun 18  Published (CNA: microsoft)
CWE-306 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0107   62.4     —
AFFECTED
  Product                         Versions    Fixed
  org.geoserver.extension:gs-db2  < 2.27.0 –  —
TIMELINE
  Feb 26  Reserved by CNA
  Jun 18  Published (CNA: GitHub_M)
CWE-74, CWE-502 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Analyzed
Microsoft Cost Management Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0103   61.0     —
AFFECTED
  Product                    Versions  Fixed
  Microsoft Cost Management  - –       —
TIMELINE
  May 19  Reserved by CNA
  Jun 18  Published (CNA: microsoft)
CWE-200 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
LMS LMS — OS Command Injection in LMS
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   L   N   H   H   H    8.6   .0095   58.5     —
AFFECTED
  Product  Versions     Fixed
  LMS      unspecified  —
TIMELINE
  Apr 13  Reserved by CNA
  Jun 18  Published (CNA: CERT-PL)
CWE-78 · CNA: CERT-PL · CVSS v4.0 · 3 references · NVD status: Deferred
startreedata mcp-pinot — mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0093   57.9     —
AFFECTED
  Product    Versions   Fixed
  mcp-pinot  < 3.1.0 –  —
TIMELINE
  May 28  Reserved by CNA
  Jun 18  Published (CNA: GitHub_M)
CWE-306 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Deferred
pgadmin.org pgAdmin 4 — pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.5   .0092   57.6     —
AFFECTED
  Product    Versions  Fixed
  pgAdmin 4  6.9 –     —
TIMELINE
  Jun 11  Reserved by CNA
  Jun 18  Published (CNA: PostgreSQL)
CWE-306, CWE-502 · CNA: PostgreSQL · CVSS v4.0 · 2 references · NVD status: Analyzed
PraisonAI - Arbitrary File Read and Write via Path Traversal in MultiAgentMonitor
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0092   57.4     —
AFFECTED
  Product    Versions     Fixed
  PraisonAI  unspecified  1.5.115
TIMELINE
  Jun 18  Reserved by CNA
  Jun 18  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Deferred
AVer PTC cameras Files or Directories Accessible to External Parties
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0083   54.9     —
AFFECTED
  Product  Versions     Fixed
  PTC500S  unspecified  —
  PTC115   unspecified  —
  PTC500+  unspecified  —
  PTC115+  unspecified  —
TIMELINE
  May 7   Reserved by CNA
  Jun 18  Published (CNA: icscert)
CWE-552 · CNA: icscert · CVSS v4.0 · 2 references · NVD status: Awaiting Analysis
Microsoft Microsoft Dynamics 365 — Dynamics 365 Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0078   53.1     —
AFFECTED
  Product                 Versions  Fixed
  Microsoft Dynamics 365  - –       —
TIMELINE
  May 19  Reserved by CNA
  Jun 18  Published (CNA: microsoft)
CWE-284 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Government Accountability Office Electronic Protest Docketing System (EPDS) — U.S. GAO EPDS and CBCA EDS unauthenticated password change
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0077   52.9     —
AFFECTED
  Product                                     Versions     Fixed
  Electronic Protest Docketing System (EPDS)  unspecified  2026-02-22
  Electronic Docketing System (EDS)           unspecified  2026-03-19
TIMELINE
  Jun 11  Reserved by CNA
  Jun 18  Published (CNA: cisa-cg)
CWE-306 · CNA: cisa-cg · CVSS v4.0 · 4 references · NVD status: Awaiting Analysis
Microsoft Azure AI Bot Service — Azure Bot Service Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0077   52.7     —
AFFECTED
  Product               Versions  Fixed
  Azure AI Bot Service  - –       —
TIMELINE
  Mar 10  Reserved by CNA
  Jun 18  Published (CNA: microsoft)
CWE-287 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
PraisonAI - Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   N    8.6   .0074   51.9     —
AFFECTED
  Product    Versions     Fixed
  PraisonAI  unspecified  1.5.128
TIMELINE
  Jun 18  Reserved by CNA
  Jun 18  Published (CNA: VulnCheck)
CWE-942 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
Government Accountability Office Electronic Protest Docketing System (EPDS) — U.S. GAO EPDS and CBCA EDS client-based privilege escalation
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0072   51.3     —
AFFECTED
  Product                                     Versions     Fixed
  Electronic Protest Docketing System (EPDS)  unspecified  2026-02-22
  Electronic Docketing System (EDS)           unspecified  2026-03-19
TIMELINE
  Jun 11  Reserved by CNA
  Jun 18  Published (CNA: cisa-cg)
CWE-602 · CNA: cisa-cg · CVSS v4.0 · 4 references · NVD status: Awaiting Analysis
pgadmin.org pgAdmin 4 — pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templates
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0071   50.7     —
AFFECTED
  Product    Versions  Fixed
  pgAdmin 4  1.0 –     —
TIMELINE
  Jun 11  Reserved by CNA
  Jun 18  Published (CNA: PostgreSQL)
CWE-89, CWE-116 · CNA: PostgreSQL · CVSS v4.0 · 3 references · NVD status: Analyzed
PraisonAI - Arbitrary Shell Command Execution via Hardcoded Approval Mode Override
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0071   50.6     —
AFFECTED
  Product    Versions     Fixed
  PraisonAI  unspecified  4.5.128
TIMELINE
  Jun 18  Reserved by CNA
  Jun 18  Published (CNA: VulnCheck)
CWE-863 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
CometD has acknowledgement extension out of memory
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0068   49.8     —
AFFECTED
  Product  Versions              Fixed
  cometd   >= 5.0.0, < 5.0.23 –  —
TIMELINE
  Jun 25  Reserved by CNA
  Jun 18  Published (CNA: GitHub_M)
CWE-400 · CNA: GitHub_M · CVSS v3.1 · 6 references · NVD status: Deferred
Coturn: Stack buffer overflow in decode_oauth_token_gcm()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0067   49.4     —
AFFECTED
  Product  Versions    Fixed
  coturn   < 4.10.0 –  —
TIMELINE
  May 4   Reserved by CNA
  Jun 18  Public exploit reference published
  Jun 18  Published (CNA: GitHub_M)
CWE-120 · CNA: GitHub_M · CVSS v3.1 · 2 references · NVD status: Analyzed
pgadmin.org pgAdmin 4 — pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   P   H   H   H    9.4   .0066   48.7     —
AFFECTED
  Product    Versions  Fixed
  pgAdmin 4  9.13 –    —
TIMELINE
  Jun 11  Reserved by CNA
  Jun 18  Published (CNA: PostgreSQL)
CWE-77, CWE-89 · CNA: PostgreSQL · CVSS v4.0 · 2 references · NVD status: Analyzed
libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   L   N   H    8.3   .0065   48.3     —
AFFECTED
  Product  Versions     Fixed
  libssh2  unspecified  2dae3024897e1898d389835151f4e9606227721d
TIMELINE
  Jun 18  Reserved by CNA
  Jun 18  Published (CNA: VulnCheck)
CWE-125 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-542238.647.4UBB SystemsUBB.threadsCWE-22Remote Code Execution via arbitrary file read and write in UBB.threads
CVE-2025-524657.246.8geoserverorg.geoserver.web:gs-web-appCWE-73GeoServer has an arbitrary file write vulnerability in its Master Password Du…
CVE-2026-543909.346.2JTL SoftwareJTL ShopCWE-1336JTL Shop < 5.7.2 Server-Side Template Injection via Smarty Renderer
CVE-2026-91585.246.1Eclipse FoundationEclipse 4diacCWE-416In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE co…
CVE-2026-489377.544.7nodejsnodeCWE-400A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data …
CVE-2026-492488.344.6theonedevonedevCWE-61OneDev: RCE through absolute-path symlink following allows low-privileged use…
CVE-2026-98608.844.1vanyukovOffload, AI & Optimize with Cloudflare ImagesCWE-434Offload, AI & Optimize with Cloudflare Images <= 1.10.2 - Authenticated (Auth…
CVE-2026-560226.943.8WebminWebminCWE-308Webmin MFA bypass
CVE-2026-80249.343.7ibaibaPDACWE-502Deserialization vulnerability in ibaPDA and ibaDatCoordinator
CVE-2026-81008.643.5Progress ChefChef360CWE-23Impact A security issue has been identified in Chef 360 that could allow unau…
CVE-2025-323928.742.5Significant-GravitasAutoGPTCWE-400AutoGPT has a DoS vulnerability in LoopVideoBlock
CVE-2026-552056.942.0nesquenahermes-webuiCWE-770Hermes WebUI < 0.51.468 - Resource Exhaustion via Unauthenticated OAuth Flow …
CVE-2026-540177.741.9open-webuiopen-webuiCWE-22Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path t…
CVE-2026-446888.440.9Eclipse FoundationEclipse TheiaCWE-829In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed worksp…
CVE-2026-465808.440.9Eclipse FoundationEclipse TheiaCWE-829In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompt…
CVE-2026-541056.940.8Government Accountability OfficeElectronic Protest Docketing System (EPDS)CWE-639U.S. GAO EPDS and CBCA EDS user information disclosure
CVE-2026-560996.940.6openbsdsrcCWE-125OpenBSD mpls_do_error Kernel Stack Memory Disclosure via MPLS Input
CVE-2026-560209.240.2WebminWebminCWE-290Webmin HTTP header authentication bypass
CVE-2026-541065.140.0Government Accountability OfficeElectronic Protest Docketing System (EPDS)CWE-940U.S. GAO EPDS and CBCA EDS network access control bypass
CVE-2026-107364.939.9themeumTutor LMS – eLearning and online course solutionCWE-89Tutor LMS <= 3.9.11 - Authenticated (Administrator+) SQL Injection via 'data'…
CVE-2026-552048.739.5haproxyhaproxyCWE-476HAProxy - NULL Pointer Dereference in hpack_dht_insert Function
CVE-2026-478469.839.4Bitnamibitnami/cassandraCWE-798Bitnami Cassandra container images are affected by a retained default superus…
CVE-2026-560216.939.0WebminWebminCWE-185Webmin information disclosure via regex pattern
CVE-2026-119825.138.9Gravgrav-plugin-apiCWE-79Stored XSS via missing XSS safety check in Admin2 Pages API partial validation
CVE-2026-113604.938.9algolplusAdvanced Order Export For WooCommerceCWE-89Advanced Order Export For WooCommerce <= 4.0.10 - Authenticated (Shop Manager…
CVE-2025-581758.238.7geoserverorg.geoserver.web:gs-web-appCWE-20GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML E…
CVE-2026-492529.938.6deepstreamIOdeepstream.ioCWE-1321deepstream is vulnerable to prototype pollution
CVE-2026-387187.537.7n/an/aCWE-120InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlie…
CVE-2026-560777.136.9PraisonAIPraisonAICWE-668PraisonAI - Information Disclosure via Shared MultiAgentLedger State
CVE-2026-544199.336.7claudiopizzilloPIAF-HMSCWE-89PIAF-HMS multiple unauthenticated SQL injection vulnerabilities via mysql_query
CVE-2025-324228.735.4Significant-GravitasAutoGPTCWE-400AutoGPT has a DoS vulnerability in FileStoreBlock with StepThroughItemsBlock
CVE-2025-324248.735.4Significant-GravitasAutoGPTCWE-400AutoGPT has a DoS vulnerability in ScreenshotWebPageBlock
CVE-2025-324378.735.4Significant-GravitasAutoGPTCWE-400AutoGPT has a DoS vulnerability in MediaDurationBlock
CVE-2026-501417.135.4woodpecker-ciwoodpeckerCWE-290Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent imperson…
CVE-2026-120505.335.3pgadmin.orgpgAdmin 4CWE-89pgAdmin 4: SQL injection in named restore point endpoint
CVE-2026-487168.734.9HKUDSnanobotCWE-22nanobot: Path traversal via unsanitized WhatsApp document fileName enables ar…
CVE-2026-96925.334.7HAYAJOMojolicious::Sessions::StorableCWE-338Mojolicious::Sessions::Storable versions through 0.05 for Perl generate sessi…
CVE-2026-456968.334.5AcademySoftwareFoundationopenexrCWE-122OpenEXR HTJ2K decoder heap buffer over-read in ht_undo_impl() (DoS)
CVE-2026-449426.534.4SUSElibzyppCWE-24libzypp .repo files can have an optional path which can lead to path traversa…
CVE-2026-446918.433.7Eclipse FoundationEclipse TheiaCWE-829In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspa…
CVE-2025-105609.331.6Silver Leaf Technologies, Inc.Worksnaps.net WorksnapsCWE-798Hardcoded cloud credentials in Worksnaps client application binaries expose p…
CVE-2026-492056.531.2thorstenphpMyFAQCWE-862phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-2442…
CVE-2025-324367.130.9Significant-GravitasAutoGPTCWE-400AutoGPT has a DoS vulnerability in AddAudioToVideoBlock
CVE-2026-124078.830.3oleksandrzE2Pdf – Export Pdf Tool for WordPressCWE-862E2Pdf <= 1.32.26 - Missing Authorization to Authenticated (Custom+) Arbitrary…
CVE-2026-560128.528.4David LingrenMedia LIbrary AssistantCWE-89WordPress Media LIbrary Assistant plugin <= 3.35 - SQL Injection vulnerability
CVE-2026-120495.328.2pgadmin.orgpgAdmin 4CWE-601pgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated …
CVE-2026-424888.128.0XenXenCWE-119x86: mismatched mapcache metadata
CVE-2026-120935.327.8wpinsider-1Simple MembershipCWE-862Simple Membership <= 4.7.5 - Missing Authorization to Unauthenticated Arbitra…
CVE-2026-528667.127.3Apollo PharmacyBlood Glucose Monitoring System (Model No. APG-01 BT)CWE-862Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT Missing Authorization
CVE-2026-552039.027.3haproxyhaproxyCWE-190HAProxy - Integer Overflow in FCGI Demux Record Length Field
CVE-2026-117764.927.110webForm Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form BuilderCWE-89Form Maker by 10Web <= 1.15.43 - Authenticated (Adminsitrator+) SQL Injection…
CVE-2026-117774.927.110webForm Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form BuilderCWE-89Form Maker by 10Web <= 1.15.43 - Authenticated (Administrator+) SQL Injection…
CVE-2026-121205.325.5firepluginsFireBox Popups – Increase Sales and Grow Your Email ListCWE-200FireBox Popups <= 3.1.7 - Unauthenticated Sensitive Information Exposure in '…
CVE-2026-466997.625.4conda-forgeconda-smithyCWE-284conda-smithy vulnerable to misrouted repository invitation by conda-forge-web…
CVE-2026-113574.324.5stellarwpKadence Blocks — Page Builder Toolkit for Gutenberg EditorCWE-200Kadence Blocks <= 3.7.5 - Authenticated (Contributor+) Sensitive Information …
CVE-2026-552378.824.1Significant-GravitasAutoGPTCWE-87AutoGPT SignUp Page has DOM-Based XSS and Open Redirect
CVE-2026-88117.124.1SEPPmail AGSecure Email GatewayCWE-22Path traversal in PDF generation module
CVE-2026-404572.124.0LMSLMSCWE-79Reflected XSS in LMS
CVE-2026-486178.223.8nodejsnodeCWE-284A flaw in Node.js Permission Model enforcement allows Bypass via `process.rep…
CVE-2026-478475.323.4Bitnamibitnami/mariadb-galeraCWE-798Bitnami MariaDB Galera container images and Helm chart are affected by a hard…
CVE-2026-225516.723.4Eclipse FoundationEclipse TheiaCWE-201In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown imag…
CVE-2026-100295.323.2eventkoiEvent Koi Lite – Events Calendar, Event Management, RSVP, and TicketsCWE-862Event Koi Lite <= 1.3.13.1 - Missing Authorization to Unauthenticated Sensiti…
CVE-2026-226744.823.0hashgraphguardianCWE-79Hashgraph Guardian Stored XSS via branding companyName field
CVE-2026-542228.622.6UBB SystemsUBB.threadsCWE-89Blind SQL Injection in UBB.threads
CVE-2026-542195.121.3UBB SystemsUBB.threadsCWE-79Stored XSS in UBB.threads
CVE-2026-542215.121.2UBB SystemsUBB.threadsCWE-79Reflected XSS in UBB.threads
CVE-2026-113957.220.9mariovalneyCF7 to WebhookCWE-918CF7 to Webhook <= 5.0.0 - Unauthenticated Server-Side Request Forgery via CF7…
CVE-2026-557409.320.1Nur-Alam39bus-ticketCWE-89SQL Injection in Nur-Alam39 bus-ticket bus_info.php via busid parameter
CVE-2026-121114.319.6codepeopleAppointment Booking CalendarCWE-200Appointment Booking Calendar <= 1.4.01 - Authenticated (Contributor+) Sensiti…
CVE-2026-542247.119.0UBB SystemsUBB.threadsCWE-405Denial of Service in UBB.threads
CVE-2026-121022.719.0stiofansislandUsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WPCWE-639UsersWP <= 1.2.63 - Insecure Direct Object Reference to Authenticated (Editor…
CVE-2026-86682.318.8Progress ChefChef360CWE-523Hardcoded credentials in embedded content
CVE-2026-120489.318.5pgadmin.orgpgAdmin 4CWE-79pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through…
CVE-2026-113584.417.9themeisleOrbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & MoreCWE-79Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fon…
CVE-2026-106234.316.4pressprimerPressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment PluginCWE-639PressPrimer Quiz <= 2.3.0 - Insecure Direct Object Reference to Authenticated…
CVE-2026-125276.015.2Shenzhen Liandian Communication Technology LTDV380 IP Camera / AppFHE1_V1.0.6.0CWE-306A broken authorization boundary in the RTSP media delivery pipeline of Shenzh…
CVE-2026-100234.315.2dokanincDokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, EtsyCWE-639Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.3 - Ins…
CVE-2026-439155.414.8coturncoturnCWE-79Coturn: Stored Cross-Site Scripting (XSS) in web-admin interface via TURN use…
CVE-2026-91994.314.6equalizedigitalEqualize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 complianceCWE-862Equalize Digital Accessibility Checker <= 1.42.1 - Missing Authorization to A…
CVE-2026-117844.313.4optimoleOptimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image OptimizationCWE-352Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Op…
CVE-2026-494549.113.1szTheoryrelyraCWE-287Relyra SAML SignatureValue not cryptographically verified -> authentication b…
CVE-2026-120474.812.4pgadmin.orgpgAdmin 4CWE-79pgAdmin 4: HTML injection in cloud verify_credentials / deploy endpoints via …
CVE-2026-404558.611.8LMSLMSCWE-89SQL Injection in LMS
CVE-2026-98156.511.7UnknownMagicForm—MagicForm <= 0.1.3 - Unauthenticated Arbitrary File Upload to RCE
CVE-2026-117915.011.4Red HatRed Hat Directory Server 11CWE-416389-ds-base: 389-ds-base: use-after-free in schema reload via attr_syntax_swa…
CVE-2026-446637.111.3AcademySoftwareFoundationopenexrCWE-190OpenEXR: Integer overflow in the HTJ2K decoder leads to heap-buffer-overflow
CVE-2026-121376.111.2phppoetSysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu ManagerCWE-79SysBasics Customize My Account for WooCommerce <= 4.3.6 - Reflected Cross-Sit…
CVE-2026-500347.110.9Apollo PharmacyBlood Glucose Monitoring System (Model No. APG-01 BT)CWE-319Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT Cleartext Transmiss…
CVE-2026-114026.410.5bpluginsServices Section Block – Showcase Service Details in Grid or ColumnsCWE-79Services Section Block <= 1.4.4 - Authenticated (Contributor+) Stored Cross-S…
CVE-2026-424906.59.8XenXenCWE-667domctl lock open to abuse
CVE-2026-20216.49.7contridSlideshow Gallery LITECWE-79Slideshow Gallery LITE <= 1.8.5 - Authenticated (Contributor+) Stored Cross-S…
CVE-2026-258658.59.6YandexPunto SwitcherCWE-428Punto Switcher 4.5.0.583 Unquoted Search Path via WinExec
CVE-2026-120986.49.3blubrryPowerPress Podcasting plugin by BlubrryCWE-79PowerPress Podcasting plugin by Blubrry <= 11.16.8 - Authenticated (Author+) …
CVE-2026-121366.48.4phppoetSysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu ManagerCWE-79SysBasics Customize My Account for WooCommerce <= 4.3.6 - Authenticated (Cont…
CVE-2026-542208.68.3UBB SystemsUBB.threadsCWE-352Cross-Site Request Forgery in UBB.threads
CVE-2026-117189.38.1GoogleMCP Toolbox for Databases (googleapis/mcp-toolbox)CWE-287An authentication bypass vulnerability exists in the generic opaque token val…
CVE-2026-123908.48.1AzeoTechDAQFactoryCWE-843Access of resource using incompatible type ('type confusion') in AzeoTech DAQ…
CVE-2026-80396.47.7dijitulFancy TestimonialsCWE-79Fancy Testimonials <= 1.0 - Authenticated (Author+) Stored Cross-Site Scripting
CVE-2026-117179.37.2GoogleMCP Toolbox for Databases (googleapis/mcp-toolbox)CWE-287An authentication bypass vulnerability exists in the generic opaque token val…
CVE-2026-560246.57.1Saad IqbalWP EasyPayCWE-352WordPress WP EasyPay plugin <= 4.5.0 - Cross Site Request Forgery (CSRF) vuln…
CVE-2026-489806.37.1mcdopepam_usbCWE-454pam_usb: getenv() used in PAM context allows environment variable injection i…
CVE-2026-557467.06.6CotontiCotontiCWE-79Cotonti stored XSS via PFS folder title
CVE-2026-478336.96.1Cloud Foundry Foundationbpm-releaseCWE-59setupBpmLogs follows symlink for bpm.log open and chown — container-to-host p…
CVE-2026-560746.86.0PraisonAIPraisonAICWE-863PraisonAI - Tool Approval Cache Bypass via Coarse-Grained Caching
CVE-2026-489855.55.7mcdopepam_usbCWE-476pam_usb: NULL Dereference Crash in pusb_is_loginctl_local when loginctl Retur…
CVE-2026-125057.85.0Red HatRed Hat Enterprise Linux 10CWE-250Cifs-utils: local privilege escalation via forged cifs.spnego key description…
CVE-2026-489816.74.8mcdopepam_usbCWE-611pam_usb: xmlReadFile flags=0 permits XXE network entity fetching in conf.c
CVE-2026-557429.44.5CotontiCotontiCWE-352Cotonti CSRF in admin.rights.php allows privilege escalation
CVE-2026-553926.74.5nilfs-devnilfs-utilsCWE-1284NILFS utilities - Undefined Behavior and Out-of-Memory via Unvalidated s_log_…
CVE-2026-557418.74.2CotontiCotontiCWE-352Cotonti CSRF in admin.config.php allows unauthorized configuration changes
CVE-2026-557448.64.3CotontiCotontiCWE-352Cotonti CSRF in PFS allows forced arbitrary file upload
CVE-2026-120395.74.3DockerDocker SandboxesCWE-923Docker Sandboxes network egress allowlist bypass via unfiltered DNS resolution
CVE-2026-489844.74.2mcdopepam_usbCWE-14pam_usb: xfree() does not call explicit_bzero — sensitive cryptographic mater…
CVE-2026-117198.64.0GoogleMCP Toolbox for Databases (googleapis/mcp-toolbox)CWE-862An authenticated authorization bypass vulnerability exists in MCP Toolbox for…
CVE-2026-489864.73.6mcdopepam_usbCWE-835pam_usb: Infinite loop DoS in process-tree walk when parent process exits dur…
CVE-2026-125395.73.5DockerDocker SandboxesCWE-665Docker Sandboxes ICMP egress restriction bypass after daemon restart
CVE-2026-2857310.03.4GoogleAndroidCWE-862In AndroidManifest.xml, there is a possible persistent denial of service due …
CVE-2026-560075.93.4OceanWPOcean Product SharingCWE-79WordPress Ocean Product Sharing plugin <= 2.2.2 - Cross Site Scripting (XSS) …
CVE-2026-506435.13.4rui3148ccCWE-125Out‑of‑Bounds Read in 8cc
CVE-2026-560095.93.2BricksableBricksable for Bricks BuilderCWE-79WordPress Bricksable for Bricks Builder plugin <= 1.6.83 - Cross Site Scripti…
CVE-2026-489825.81.9mcdopepam_usbCWE-362pam_usb: Missing O_EXCL on pad temp file creation allows concurrent update race
CVE-2026-489835.81.2mcdopepam_usbCWE-367pam_usb: TOCTOU race condition in pad directory creation allows symlink subst…
CVE-2026-119587.31.0ANSSIDFIR-ORCCWE-427Local privilege escalation in ANSSI’s DFIR-ORC
CVE-2026-557455.30.8CotontiCotontiCWE-352Cotonti CSRF in PFS folder edit allows unauthorized folder modification
CVE-2026-424877.90.7XenXenCWE-362x86 HVM I/O port list traversal
CVE-2026-424895.30.1XenXenCWE-667domctl lock open to abuse

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-18 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.