boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Friday, June 19, 2026 · all times UTC← 2026-06-18 · archive · 2026-06-20 →

Security Box Score — June 19, 2026

194 CVEs published, led by Apache Software Foundation (12).

194 CVEs published June 19, 2026: 20 critical, 115 high, 51 medium, 8 low; 0 in the KEV catalog at press time; 61 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 169 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published50599520——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

439 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux9910668466731411120.27.8.0013-118 ▼
google68485983454293297760.78.1.0023+684 ▲
microsoft220756585201726286192.57.8.0045+76 ▲
red hat751698727811200.06.7.0029+69 ▲
apple146612142288710.65.7.0019-1 ▼
canonical1150465000.05.5.0009+1 ▲
freebsd070520000.07.8.00200
suse461410000.08.6.0029+4 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco92165100561047.67.2.0438+8 ▲
netgear171700161000.04.3.0024+17 ▲
palo alto networks911127113218.25.9.0022+7 ▲
ivanti49450025555.68.8.5187+3 ▲
checkpoint3915303111.17.5.0410+3 ▲
fortinet29432028333.38.3.0076+1 ▲
f56843104112.58.9.0225+5 ▲
ubiquiti584400300.08.9.0052+5 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache8612018425273310.86.8.0050+82 ▲
mozilla49551118260900.07.3.0026+44 ▲
gitlab1118041224211.14.8.0024+11 ▲
docker470520000.08.2.0016+4 ▲
drupal0511304120.05.1.00260
github021100000.08.1.03470
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2422701321161842720.78.8.0040+242 ▲
adobe1291314507521921.55.5.0021+129 ▲
ibm11601329180600.07.5.0028+11 ▲
progress591710600.07.5.0036+5 ▲
solarwinds36231010466.77.8.6082+3 ▲
veeam142200100.09.0.0052+1 ▲
zohocorp020110000.07.1.01040
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5 ▲
d-link9110425300.05.5.0058+9 ▲
siemens780440000.07.5.0020+6 ▲
rockwell automation771510000.08.7.0030+7 ▲
abb550410000.07.2.0018+5 ▲
moxa550320000.07.0.0029+5 ▲
dahua330111000.06.9.0036+3 ▲
mitsubishi electric330300000.08.7.0064+3 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7172230391000.06.5.0023+71 ▲
openclaw61670352210000.07.0.0021+61 ▲
sourcecodester3759002534000.02.1.0026+37 ▲
themerex585855300000.08.1.0043+58 ▲
edimax051032019100.07.4.00590
concrete cms2461111321000.06.2.0015+2 ▲
dell2745121230212.26.7.0015+27 ▲
open ises044221210000.07.1.00210

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9991100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-9082.883299.89.8
CVE-2026-50751.837799.79.3
CVE-2026-48907.781099.510.0
CVE-2026-49160.538398.97.5
CVE-2026-10523.518798.99.8
CVE-2026-28318.400198.57.5
CVE-2026-53435.376698.48.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9991KEV
CVE-2026-4890710.0.7810KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4508710.0.1296
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-4925710.0.0093
CVE-2026-4548010.0.0090
Most disclosures (vendor)
VendorCVEs
google836
linux523
oracle267
microsoft238
adobe129
red hat107
apache103
spring72
openclaw67
ibm60
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco10
apple7
google6
ivanti5
solarwinds4
berriai3
fortinet3
smartertools3
adobe2
Most-affected ecosystems
EcosystemAdvisories
Maven42
Packagist22
PyPI11
npm4
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2025-48595Google0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-28318SolarWinds0
CVE-2026-34926Trend Micro, Inc.0
CVE-2026-35273Oracle Corporation0
CVE-2026-45247Mirasvit0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171675
CVE-2021-27102n/a2021-11-171675
CVE-2021-27101n/a2021-11-171675
CVE-2021-27103n/a2021-11-171675
CVE-2021-21017Adobe2021-11-171675
CVE-2021-28550Adobe2021-11-171675
CVE-2021-42013Apache Software Foundation2021-11-171675
CVE-2021-41773Apache Software Foundation2021-11-171675
CVE-2021-30858Apple2021-11-171675
CVE-2021-30860Apple2021-11-171675

Transactions

EXPLOIT PUBLISHED — sysown proxysql: 3 CVEs (CVE-2026-48772, CVE-2026-48773, CVE-2026-48774). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2025-62821. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-49293 (sunnyadn js-toml). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-49295 (strukturag libde265). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-49346 (strukturag libde265). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-50559 (quarkusio quarkus). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-51843. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-51844. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-51845. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-51846. Public exploit reference added.

DUE DATE PASSED — CVE-2026-54420 (LiteSpeed Technologies cPanel Plugin). CISA remediation deadline was June 18, 2026; still in catalog.

Yesterday's Results

How to read these box scores · glossary

194 CVEs published. 25 box scores, 169 table rows — nothing truncated.

themefusion Avada (Fusion) Builder — Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion via Form Entry Value
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0267   84.6     —
AFFECTED
  Product                 Versions     Fixed
  Avada (Fusion) Builder  unspecified  —
TIMELINE
  May 15  Reserved by CNA
  Jun 19  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
SIMA GmbH Bondix Server — Authenticated OS Command Injection in Bondix
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0132   68.6     —
AFFECTED
  Product        Versions     Fixed
  Bondix Server  unspecified  1.25.7.6
TIMELINE
  Jun 12  Reserved by CNA
  Jun 19  Published (CNA: NCSC.ch)
CWE-78 · CNA: NCSC.ch · CVSS v4.0 · 2 references · NVD status: Deferred
SUSE Rancher — Command injection through unsanitized YAML parameter in Rancher
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    9.4   .0131   68.5     —
AFFECTED
  Product  Versions  Fixed
  Rancher  2.14.0 –  —
TIMELINE
  May 8   Reserved by CNA
  Jun 19  Published (CNA: suse)
CWE-95 · CNA: suse · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
microsoft kiota-typescript — @microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    5.5   .0118   65.3     —
AFFECTED
  Product           Versions                                    Fixed
  kiota-typescript  >= 1.0.0-preview.97, < 1.0.0-preview.102 –  —
TIMELINE
  May 29  Reserved by CNA
  Jun 19  Published (CNA: GitHub_M)
CWE-178, CWE-200 · CNA: GitHub_M · CVSS v4.0 · 2 references · NVD status: Deferred
n/a n/a — Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize c…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  H    9.1   .0105   61.7     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Oct 23  Reserved by CNA
  Jun 19  Public exploit reference published
  Jun 19  Published (CNA: mitre)
CWE-125 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Analyzed
pontedilana php-weasyprint — PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0095   58.6     —
AFFECTED
  Product         Versions   Fixed
  php-weasyprint  < 2.6.0 –  —
TIMELINE
  May 28  Reserved by CNA
  Jun 19  Published (CNA: GitHub_M)
CWE-502 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Deferred
BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0094   58.3     —
AFFECTED
  Product         Versions     Fixed
  BetterDocs Pro  unspecified  —
TIMELINE
  Apr 30  Reserved by CNA
  Jun 19  Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · CVSS v3.1 · 3 references · NVD status: Deferred
Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0092   57.6     —
AFFECTED
  Product              Versions  Fixed
  GitHub Copilot Chat  1.0.0 –   —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 19  Published (CNA: microsoft)
CWE-1188 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Azure Synapse Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0091   57.4     —
AFFECTED
  Product        Versions  Fixed
  Azure Synapse  - –       —
TIMELINE
  May 21  Reserved by CNA
  Jun 19  Published (CNA: microsoft)
CWE-250 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Azure Active Directory — Azure Active Directory Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0090   57.0     —
AFFECTED
  Product                 Versions  Fixed
  Azure Active Directory  - –       —
TIMELINE
  May 12  Reserved by CNA
  Jun 19  Published (CNA: microsoft)
CWE-287 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Wdmtech vBizz — Joomla! Component vBizz 1.0.7 Remote Code Execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0089   56.7     —
AFFECTED
  Product  Versions  Fixed
  vBizz    1.0.7 –   —
TIMELINE
  Jun 19  Reserved by CNA
  Jun 19  Published (CNA: VulnCheck)
CWE-434 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Analyzed
n/a n/a — In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer o…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0084   55.2     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 8   Reserved by CNA
  Jun 19  Public exploit reference published
  Jun 19  Published (CNA: mitre)
CWE-121 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Analyzed
byrongamatos slopsmith — Slopsmith has path traversal in archive extractors that allows arbitrary file write → potential RCE
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    7.6   .0083   54.9     —
AFFECTED
  Product    Versions           Fixed
  slopsmith  < 0.2.9-alpha.5 –  —
TIMELINE
  May 28  Reserved by CNA
  Jun 19  Published (CNA: GitHub_M)
CWE-22, CWE-23, CWE-36 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Deferred
NI grpc-device — Untrusted pointer dereference in NI grpc-device sideband streaming API
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   N    9.3   .0080   53.9     —
AFFECTED
  Product           Versions     Fixed
  grpc-device       unspecified  —
  InstrumentStudio  unspecified  —
TIMELINE
  May 20  Reserved by CNA
  Jun 19  Published (CNA: NI)
CWE-822 · CNA: NI · CVSS v4.0 · 2 references · NVD status: Analyzed
Microsoft 365 Copilot's Business Chat Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0076   52.4     —
AFFECTED
  Product                Versions  Fixed
  Microsoft 365 Copilot  - –       —
TIMELINE
  May 19  Reserved by CNA
  Jun 19  Published (CNA: microsoft)
CWE-601 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Copilot Tampering Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  N    7.5   .0071   50.7     —
AFFECTED
  Product                Versions  Fixed
  Microsoft 365 Copilot  - –       —
TIMELINE
  Apr 30  Reserved by CNA
  Jun 19  Published (CNA: microsoft)
CWE-77 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
flipped-aurora gin-vue-admin — gin-vue-admin vulnerable to RCE
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0069   50.0     —
AFFECTED
  Product        Versions   Fixed
  gin-vue-admin  = 2.9.1 –  —
TIMELINE
  May 22  Reserved by CNA
  Jun 19  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v4.0 · 1 reference · NVD status: Deferred
Microsoft Exchange Online Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  N    9.6   .0069   50.0     —
AFFECTED
  Product                    Versions  Fixed
  Microsoft Exchange Online  - –       —
TIMELINE
  May 21  Reserved by CNA
  Jun 19  Published (CNA: microsoft)
CWE-862 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Apache APISIX: Session replay issue in hmac-auth
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   N    6.3   .0069   50.0     —
AFFECTED
  Product        Versions  Fixed
  Apache APISIX  3.11.0 –  —
TIMELINE
  May 19  Reserved by CNA
  Jun 19  Published (CNA: apache)
CWE-294 · CNA: apache · CVSS v4.0 · 2 references · NVD status: Analyzed
Apache APISIX: Identity Injection via forward-auth Plugin Missing Header Cleanup
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   N   N   N    5.8   .0068   49.5     —
AFFECTED
  Product        Versions  Fixed
  Apache APISIX  2.12.0 –  —
TIMELINE
  Apr 8   Reserved by CNA
  Jun 19  Published (CNA: apache)
CWE-20 · CNA: apache · CVSS v4.0 · 2 references · NVD status: Analyzed
quarkusio quarkus — Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0067   49.1     —
AFFECTED
  Product  Versions               Fixed
  quarkus  >= 3.36.0, < 3.36.3 –  —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 19  Public exploit reference published
  Jun 19  Published (CNA: GitHub_M)
CWE-287, CWE-863, CWE-551 · CNA: GitHub_M · CVSS v3.1 · 12 references · NVD status: Modified
error311 FileRise — FileRise shared-folder upload path traversal allows arbitrary file write and admin takeover
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0066   49.0     —
AFFECTED
  Product   Versions     Fixed
  FileRise  unspecified  —
TIMELINE
  Jun 13  Reserved by CNA
  Jun 19  Published (CNA: TuranSec)
CWE-22, CWE-434 · CNA: TuranSec · CVSS v4.0 · 3 references · NVD status: Deferred
Apache APISIX: Cas-auth Host header influence on CAS service URL
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   A   N   N   N    2.1   .0065   48.2     —
AFFECTED
  Product        Versions  Fixed
  Apache APISIX  3.0.0 –   —
TIMELINE
  May 26  Reserved by CNA
  Jun 19  Published (CNA: apache)
CWE-601 · CNA: apache · CVSS v4.0 · 2 references · NVD status: Analyzed
sunnyadn js-toml — CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0064   48.1     —
AFFECTED
  Product  Versions   Fixed
  js-toml  < 1.1.1 –  —
TIMELINE
  May 28  Reserved by CNA
  Jun 19  Public exploit reference published
  Jun 19  Published (CNA: GitHub_M)
CWE-400, CWE-407, CWE-1333 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Analyzed
strablengineering STRABL – A checkout solution — STRABL <= 4.5 - Unauthenticated Arbitrary Webhook Creation via REST API Endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0064   48.1     —
AFFECTED
  Product                       Versions     Fixed
  STRABL – A checkout solution  unspecified  —
TIMELINE
  Mar 6   Reserved by CNA
  Jun 19  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 14 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-449152.148.1Apache Software FoundationApache APISIXCWE-601Apache APISIX: Cas-auth plugin open redirect via unsanitized cookie value
CVE-2026-88058.747.8Mitsubishi Electric CorporationMitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIPCWE-190Denial-of-service (DoS) vulnerability in MELSEC iQ-F Series EtherNet/IP module
CVE-2026-88068.747.8Mitsubishi Electric CorporationMitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IPCWE-440Denial-of-service (DoS) vulnerability in MELSEC iQ-F Series FX5-ENET/IP Ether…
CVE-2026-399997.047.7Apache Software FoundationApache APISIXCWE-290Apache APISIX: JWT Algorithm Confusion allows authentication bypass
CVE-2026-493455.347.7sourcentismercatorCWE-918Mercator CVE Configuration Vulnerable to Server-Side Request Forgery (SSRF)
CVE-2019-257628.747.5JoomboostJoomProjectCWE-359Joomla! Component JoomProject 1.1.3.2 Information Disclosure
CVE-2026-561428.847.2JetBrainsHubCWE-915In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.14…
CVE-2026-115519.847.0wpmudevBranda – White Label & Branding, Free Login Page CustomizerCWE-640Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unaut…
CVE-2026-502429.846.5JetBrainsHubCWE-306In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.14…
CVE-2026-75474.945.5teamwsaWoosa – Marktplaats for WooCommerceCWE-22Woosa <= 2.0.5 - Authenticated (Administrator+) Arbitrary File Read via 'log_…
CVE-2026-100345.345.0legalwebWP DSGVO Tools (GDPR)CWE-862WP DSGVO Tools (GDPR) <= 3.1.39 - Missing Authorization to Unauthenticated Se…
CVE-2026-492312.344.8Apache Software FoundationApache APISIXCWE-290Apache APISIX: Identity spoofing issue in APISIX opa plugin
CVE-2026-560819.344.8Cap-gocapgoCWE-640Cap-go - Account Lockout via 2FA Misconfiguration on Unverified Email
CVE-2026-493578.844.3dtwangline-desktop-mcpCWE-306Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authent…
CVE-2026-518439.843.8n/an/aCWE-121Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the …
CVE-2026-518449.843.8n/an/aCWE-121Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the …
CVE-2026-518459.843.8n/an/aCWE-121Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the …
CVE-2026-560806.943.1Cap-gocapgoCWE-287Cap-go - Authentication Logic Flaw in Enforce Password Policy
CVE-2026-498725.342.2Apache Software FoundationApache APISIXCWE-287Apache APISIX: Improper authentication in cas-auth plugin
CVE-2026-322085.442.0MicrosoftMicrosoft Edge (Chromium-based)CWE-79Microsoft Entra ID Spoofing Vulnerability
CVE-2026-561419.841.9JetBrainsHubCWE-338In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.14…
CVE-2026-561385.341.2ail-projectail-frameworkCWE-22Authenticated Path Traversal in AIL framework /objects/item/diff Allows Readi…
CVE-2026-126445.540.9n/ats-deepmergeCWE-248Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught …
CVE-2019-257606.940.8JoomtechEasy ShopCWE-98Joomla! Component Easy Shop 1.2.3 Local File Inclusion
CVE-2026-119896.540.3bitpressadminBit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email AutomationCWE-918Bit integrations <= 2.8.7 - Unauthenticated Server-Side Request Forgery via F…
CVE-2017-202548.840.0GegabyteUser BenchCWE-89Joomla! Component User Bench 1.0 SQL Injection via userid
CVE-2017-202578.840.0JoomplaceQuiz DeluxeCWE-89Joomla! Component Quiz Deluxe 3.7.4 SQL Injection
CVE-2017-202588.840.0ExtroRPCCWE-89Joomla! Component RPC Responsive Portfolio 1.6.1 SQL Injection
CVE-2017-202598.840.0JoomlashackOSDownloadsCWE-89Joomla OSDownloads 1.7.4 SQL Injection via item view
CVE-2017-202668.840.0JoomshaperSP Movie DatabaseCWE-89Joomla SP Movie Database 1.3 SQL Injection via searchword
CVE-2019-257518.840.0CmsjunkieClassifiedsManagerCWE-89Joomla J-ClassifiedsManager 3.0.5 SQL Injection
CVE-2019-257568.840.0WdmtechvAccountCWE-89Joomla! Component vAccount 2.0.2 SQL Injection via vaccount-dashboard
CVE-2023-543578.739.9ArtioJoomla! com_booking componentCWE-203Joomla com_booking 2.4.9 Information Disclosure via Account Enumeration
CVE-2026-481388.739.8NIgrpc-deviceCWE-125Out-of-bounds read vulnerability in the NI grpc-device streaming API
CVE-2026-481398.739.8NIgrpc-deviceCWE-476NULL pointer dereference vulnerability in NI grpc-device data moniker service
CVE-2026-492918.139.8doobidoomcp-memory-serviceCWE-862mcp-memory-service: OAuth read-only clients can write and delete memories thr…
CVE-2026-440462.338.9Apache Software FoundationApache APISIXCWE-348Apache APISIX: wolf-rbac plugin Identity Spoofing
CVE-2026-473395.338.7Apache Software FoundationApache APISIXCWE-863Apache APISIX: authz-casdoor incorrect session sharing
CVE-2026-487739.838.3sysownproxysqlCWE-787ProxySQL pre-auth heap overflow in MySQL and PostgreSQL first-packet handling
CVE-2025-77378.637.9HitachiHitachi Virtual Storage Platform E990, E1090, E1090HCWE-770DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform
CVE-2026-115767.537.9Eclipse FoundationEclipse ThreadX - NetX DuoCWE-459The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors erro…
CVE-2026-492877.437.7statamiccmsCWE-470Statamic CMS vulnerable to unsafe method invocation via collection sorting al…
CVE-2026-67985.337.52download2Download Connector for 2DL Hosted CheckoutCWE-8622Download Connector for 2DL Hosted Checkout <= 0.1.5 - Missing Authorization …
CVE-2019-257508.837.4CmsjunkieMultipleHotelReservationCWE-89Joomla J-MultipleHotelReservation 6.0.7 SQL Injection
CVE-2019-257528.837.4CmsjunkieJ-BusinessDirectoryCWE-89Joomla! Component J-BusinessDirectory 4.9.7 SQL Injection
CVE-2019-257538.837.4WdmtechVMapCWE-89Joomla! Component VMap 1.9.6 SQL Injection via loadmarker
CVE-2019-257548.837.4WdmtechvRestaurantCWE-89Joomla vRestaurant 1.9.4 SQL Injection via menu-listing-layout
CVE-2019-257558.837.4WdmtechvReviewCWE-89Joomla vReview 1.9.11 SQL Injection via editReview
CVE-2026-539158.837.4JetBrainsGoLandCWE-73In JetBrains GoLand before 2026.1.3 remote code execution was possible via un…
CVE-2026-472032.937.4autheliaautheliaCWE-178Authelia Missing Username Canonicalization in Basic Auth (LDAP)
CVE-2026-562117.137.3Red HatRed Hat Enterprise Linux AI 3.3 for RHEL 9CWE-787Libaom: libaom: remote code execution via svc layer context handling with att…
CVE-2017-202647.137.3PulseextensionsSponsor WallCWE-89Joomla! Component Sponsor Wall 8.0 SQL Injection
CVE-2026-481407.136.9NIgrpc-deviceCWE-704Unchecked enum cast vulnerability in NI grpc-device in BeginSidebandStream
CVE-2026-481296.536.9kestra-iokestraCWE-22Kestra task inputFiles accepts traversal filenames for worker file writes
CVE-2026-90134.336.6rocklobsterincBogoCWE-862Bogo <= 3.9.1 - Missing Authorization to Authenticated (Subscriber+) Sensitiv…
CVE-2026-91429.336.0NIgrpc-deviceCWE-306Insecure Default Credentials vulnerability in NI grpc-device when TLS configu…
CVE-2017-202728.835.8FabobaUltimate Property ListingCWE-89Joomla Ultimate Property Listing 1.0.2 SQL Injection via sf_selectuser_id
CVE-2017-202768.835.8SimbunchSIMGenealogyCWE-89Joomla! Component SIMGenealogy 2.1.5 SQL Injection
CVE-2026-493408.135.4sentrizgonicCWE-22gonic has arbitrary file write in createPlaylist: any authenticated user can …
CVE-2026-493596.535.0pontedilanaphp-weasyprintCWE-918PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment…
CVE-2026-562087.634.9Red HatRed Hat Enterprise Linux 10.0 Extended Update SupportCWE-122Libaom: libaom: heap buffer overflow in av1 encoder first-pass stats buffer v…
CVE-2026-481416.034.7NIgrpc-deviceCWE-401Memory leak in NI grpc-device BeginSidebandStream
CVE-2026-487941.334.3autheliaautheliaCWE-178Authelia has an Edge Case Access Control Rule Mismatch
CVE-2017-202538.834.1GegabyteMy ProjectsCWE-89Joomla! Component My Projects 2.0 SQL Injection
CVE-2017-202558.834.1JoombookingJB VisaCWE-89Joomla! Component JB Visa 1.0 SQL Injection via visatype
CVE-2017-202568.834.1JoomplaceSurvey Force DeluxeCWE-89Joomla Survey Force Deluxe 3.2.4 SQL Injection via invite Parameter
CVE-2017-202608.834.1WeborangePrice AlertCWE-89Joomla! Component Price Alert 3.0.2 SQL Injection
CVE-2017-202618.834.1WeborangeBargain Product VM3CWE-89Joomla! Component Bargain Product VM3 1.0 SQL Injection
CVE-2017-202628.834.1WebkulAjax QuizCWE-89Joomla! Component Ajax Quiz 1.8 SQL Injection
CVE-2017-202638.834.1FocalpointxFocalPoint Pro / FreeCWE-89Joomla! FocalPoint Pro Free 1.2.3 SQL Injection via location
CVE-2017-202678.834.1JoomlathatCalendar PlannerCWE-89Joomla! Component Calendar Planner 1.0.1 SQL Injection
CVE-2026-278786.533.9GrafanaEnterprise Traces (GET)CWE-400Tempo TraceQL query with exemplar hint could result in unbounded memory usage
CVE-2026-560797.133.7CapgoCapgoCWE-200Capgo - Cross-Tenant Authorization Bypass via PostgREST Webhook Access
CVE-2026-493425.333.2lsegalyardCWE-22YARD static cache reads raw traversal paths before router sanitization
CVE-2017-202528.832.9nextgeneditorNextGen EditorCWE-89Joomla NextGen Editor 2.1.0 SQL Injection via plname Parameter
CVE-2026-493397.131.6sentrizgonicCWE-22Path traversal in getPlaylist/deletePlaylist bypasses ownership check: any au…
CVE-2026-81186.531.3wproyalRoyal Addons for Elementor – Addons and Templates Kit for ElementorCWE-73Royal Addons for Elementor – Addons and Templates Kit for Elementor 1.7.1058 …
CVE-2026-126204.631.3MicrochipGridTime 3000CWE-200Access Token Exposure in URL Parameters in GridTime™ 3000 GNSS Time Server
CVE-2026-493447.130.9sourcentismercatorCWE-359Mercator has a Personal Identifiable Information Leak from Query Executor fea…
CVE-2026-560828.729.9Cap-gocapgoCWE-284Capgo - Unauthenticated Cross-Tenant Billing Log Tampering via public.record_…
CVE-2026-107794.329.8techlabpro1Classified Listing – AI-Powered Classified ads & Business DirectoryCWE-862Classified Listing <= 5.4.2 - Missing Authorization to Authenticated (Subscri…
CVE-2026-480897.129.1l3montree-devdevguardCWE-285DevGuard has improper authorization on public assets
CVE-2019-257488.828.9CmsjunkieJHotelReservationCWE-89Joomla JHotelReservation 6.0.7 SQL Injection via search-hotels
CVE-2026-40268.727.7FlexeraFlexNet Manager SuiteCWE-284FlexNet Manager Suite Privilege Escalation Vulnerability
CVE-2026-40277.127.7FlexeraFlexNet Manager SuiteCWE-284FlexNet Manager Suite Attachment File Disclosure
CVE-2026-498712.127.7Apache Software FoundationApache APISIXCWE-352Apache APISIX: cas-auth login CSRF / session injection issue
CVE-2026-121576.427.5wpdevteamBetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with ChatbotCWE-79BetterDocs <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scriptin…
CVE-2026-43286.426.8addonspressAdvanced ImportCWE-918Advanced Import: One-Click Demo Import for WordPress <= 1.4.6 - Authenticated…
CVE-2026-122385.326.8wpgmapsWP Go Maps – Google Map, OpenStreetMap, Leaflet MapCWE-862WP Go Maps <= 10.1.01 - Unauthenticated Arbitrary Record Creation
CVE-2026-98226.526.5UnknownWP Hotel Booking—WP Hotel Booking < 2.3.1 - Subscriber+ Missing Authorization in Multiple AJAX…
CVE-2026-492957.126.2strukturaglibde265CWE-787libde265 has an out-of-bounds write in process_reference_picture_set via pred…
CVE-2026-493467.126.2strukturaglibde265CWE-190libde265 has a heap buffer overflow in de265_image_get_buffer via SPS dimensi…
CVE-2026-124304.425.9creativethemeshqBlocksy CompanionCWE-79Blocksy Companion <= 2.1.45 - Authenticated (Editor+) Stored Cross-Site Scrip…
CVE-2017-202688.825.4ZcontentZap Calendar LiteCWE-89Joomla! Component Zap Calendar Lite 4.3.4 SQL Injection
CVE-2017-202698.825.4TerrywcarterKissGalleryCWE-89Joomla! Component KissGallery 1.0.0 SQL Injection
CVE-2017-202708.825.4RaindropsinfotechTwitch TvCWE-89Joomla! Component Twitch Tv 1.1 SQL Injection
CVE-2026-18566.425.5creaviCreavi Appointment Booking CalendarCWE-79Appointment Booking Calendar <= 1.4.4 - Authenticated (Author+) Stored Cross-…
CVE-2026-562097.125.1Red HatRed Hat Enterprise Linux AI 3.3 for RHEL 9CWE-787Libaom: libaom: arbitrary address write via svc layer context oob and cyclic …
CVE-2017-202818.825.0JoomlaboatExtra SearchCWE-89Joomla! Component Extra Search 2.2.8 SQL Injection
CVE-2017-202828.825.0Soft-PhpjCart for OpenCartCWE-89Joomla! Component jCart for OpenCart 2.0 SQL Injection
CVE-2026-493374.325.0strukturaglibde265CWE-770libde265 has an unbounded memory leak via orphaned slice headers in `read_sli…
CVE-2026-127266.324.9Red HatRed Hat Ansible Automation Platform 2CWE-918Awx: automation-controller: awx: github webhook second-order ssrf via unvalid…
CVE-2026-117525.923.8LY CorporationArmeria—A vulnerability has been identified in armeria-xds versions 1.38.0 through 1.…
CVE-2026-82965.623.8Octopus DeployOctopus ServerCWE-79In affected versions of Octopus Server with certain access levels it was poss…
CVE-2017-202778.823.2JoomboostJoomla JoomRecipeCWE-89Joomla JoomRecipe 1.0.4 Component Blind SQL Injection via search_author
CVE-2026-91436.322.1NIgrpc-deviceCWE-681Incorrect Conversion between Numeric Types in NI grpc-device due to missing r…
CVE-2026-107205.121.9CanonicalMicrocephCWE-23MicroCeph path traversal issue in the remote-import API
CVE-2017-202657.121.8PulseextensionsFlip WallCWE-89Joomla! Component Flip Wall 8.0 SQL Injection
CVE-2026-492306.321.6Apache Software FoundationApache APISIXCWE-354Apache APISIX: Authentication bypass in jwe-decrypt
CVE-2017-202718.821.3NordmographStreetGuessr GameCWE-89Joomla StreetGuessr Game 1.1.8 SQL Injection via catid
CVE-2017-202738.821.3JoomlashowroomEvent Registration Pro CalendarCWE-89Joomla Event Registration Pro Calendar 4.1.3 SQL Injection
CVE-2017-202748.821.3King-productsLMS King ProfessionalCWE-89Joomla LMS King Professional 3.2.4.0 SQL Injection via learningpath
CVE-2017-202788.821.3JoomboostJoomRecipeCWE-89Joomla JoomRecipe 1.0.3 SQL Injection via category parameter
CVE-2017-202798.821.3ExtensionsJoomla PayageCWE-89Joomla Payage 2.05 SQL Injection via aid Parameter
CVE-2017-202808.821.3MyportfolioMyportfolioCWE-89Joomla Component Myportfolio 3.0.2 SQL Injection via pid Parameter
CVE-2026-562107.120.8Red HatRed Hat Enterprise Linux AI 3.3 for RHEL 9CWE-125Libaom: libaom: heap-buffer-overflow read via missing bounds check in ctrl_se…
CVE-2017-202758.820.7HenryschorradtBridgeCWE-89Joomla! Component PHP-Bridge 1.2.3 SQL Injection via id Parameter
CVE-2026-493387.120.8sentrizgonicCWE-285Subsonic API: any authenticated user can delete or read any other user's play…
CVE-2026-440875.320.1Apache Software FoundationApache APISIXCWE-345Apache APISIX: Openid-connect plugin Identity Header Spoofing
CVE-2026-487747.519.2sysownproxysqlCWE-20ProxySQL MCP run_sql_readonly executes side-effecting MySQL multi-statements …
CVE-2026-560739.318.6Cap-gocapgoCWE-345Cap-go - OTP Bypass via Response Manipulation in Email Verification
CVE-2026-492884.318.7statamiccmsCWE-200Statamic CMS missing authorization on Control Panel fieldtype endpoints allow…
CVE-2019-257497.117.8CmsjunkieJ-CruisePortalCWE-89Joomla J-CruisePortal 6.0.4 SQL Injection via cruises
CVE-2019-257577.117.8WdmtechvWishlistCWE-89Joomla vWishlist 1.0.1 SQL Injection via vproductid Parameter
CVE-2019-257597.117.8WdmtechvBizzCWE-89Joomla! Component vBizz 1.0.7 SQL Injection
CVE-2019-257617.117.8JoomboostJoomCRMCWE-89Joomla! Component JoomCRM 1.1.1 SQL Injection via deal_id
CVE-2026-119415.616.2CloudflareQuicheCWE-416Use-after-free in connection ID iterator and FFI functions
CVE-2026-127066.515.5Red HatRed Hat Enterprise Linux AI (RHEL AI) 3CWE-416Ffmpeg: ffmpeg: heap use-after-free read in rasc decoder decode_move()
CVE-2026-126215.313.7MicrochipGridTime 3000CWE-79Cross-Site Scripting (XSS) Vulnerability in Password Reset Redirect in GridTi…
CVE-2026-126195.113.7MicrochipGridTime 3000CWE-79GridTime™ 3000 GNSS Time Server CSRF to XSS
CVE-2022-509718.512.9MalwarebytesMalwarebytesCWE-428Malwarebytes 4.5 Unquoted Service Path Privilege Escalation
CVE-2026-492608.213.0pontedilanaphp-weasyprintCWE-78PhpWeasyPrint: shell command injection via configurable WeasyPrint binary pat…
CVE-2026-4877210.011.3sysownproxysqlCWE-348ProxySQL: PROXY-Protocol-v1 UNKNOWN parses spoofed source IP, bypassing mysql…
CVE-2026-126225.310.7MicrochipGridTime 3000CWE-601Open Redirect Vulnerability in Password Reset Submission in GridTime™ 3000 GN…
CVE-2026-487157.710.2radvd-projectradvdumpCWE-121radvdump's Route Information Option Parser has a Stack Buffer Overflow
CVE-2026-492716.59.7strukturaglibheifCWE-125libheif: Wrapped icef compressed-unit range check causes out-of-bounds read i…
CVE-2016-200948.59.4AnydeskAnyDeskCWE-428AnyDesk 2.5.0 Unquoted Service Path Elevation of Privilege
CVE-2026-117754.38.7adamsilversteinUser Admin SimplifierCWE-352User Admin Simplifier <= 3.0.0 - Cross-Site Request Forgery
CVE-2025-713268.57.8AvastAVAST AntivirusCWE-428AVAST Antivirus 25.11 Unquoted Service Path Privilege Escalation
CVE-2026-561314.97.8libexpat projectlibexpatCWE-416libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_Resu…
CVE-2016-200878.57.0NetworkdlsFortitude HTTPCWE-428Fortitude HTTP 1.0.4.0 Unquoted Service Path Elevation of Privilege
CVE-2016-200888.57.0ComodoChromodo BrowserCWE-428Comodo Chromodo Browser 52.15.25.664 Unquoted Service Path Privilege Escalation
CVE-2016-200898.57.0IperiusremoteIperius RemoteCWE-428Iperius Remote 1.7.0 Unquoted Service Path Elevation of Privilege
CVE-2016-200908.57.0ComodoDragon BrowserCWE-428Comodo Dragon Browser 52.15.25.663 Privilege Escalation via Unquoted Service …
CVE-2016-200928.57.0NetdriveNetDriveCWE-428NetDrive 2.6.12 Unquoted Service Path Elevation of Privilege
CVE-2016-200938.57.0WisecleanerWise Care 365CWE-428Wise Care 365 4.27 and Wise Disk Cleaner 9.29 Unquoted Service Path Privilege…
CVE-2019-257478.57.0Network-Inventory-AdvisorNetwork Inventory AdvisorCWE-428Network Inventory Advisor 5.0.26.0 Unquoted Service Path Privilege Escalation
CVE-2020-372548.57.0WondersharePDFelementCWE-428Wondershare PDFelement 5.2.9 Privilege Escalation via Unquoted Service Path
CVE-2023-543538.57.0PersonifyincChromacamCWE-428Chromacam 4.0.3.0 Unquoted Service Path Privilege Escalation
CVE-2016-200958.56.8Matrix42Matrix42 Remote Control HostCWE-428Matrix42 Remote Control Host 3.20.0031 Unquoted Path Privilege Escalation
CVE-2020-372508.56.8Weird-SolutionsTFTP BroadbandCWE-428TFTP Broadband 4.3.0.1465 Unquoted Service Path Privilege Escalation
CVE-2020-372518.56.8RealRealTimes Desktop ServiceCWE-428RealTimes Desktop Service 18.1.4 Unquoted Service Path Privilege Escalation
CVE-2020-372528.56.8RealtekRealtek Audio ServiceCWE-428Realtek Audio Service 1.0.0.55 Unquoted Service Path Privilege Escalation
CVE-2026-31957.46.6—qemuCWE-122Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb (incomplet…
CVE-2016-200858.56.2RealtekRealtek High Definition Audio DriverCWE-428Realtek High Definition Audio Driver 6.0.1.6730 Privilege Escalation
CVE-2016-200868.56.2VembuVembu StoreGridCWE-428Vembu StoreGrid 4.0 Unquoted Service Path Privilege Escalation
CVE-2016-200918.55.8BinisoftWindows Firewall ControlCWE-428Windows Firewall Control 4.8.6.0 Unquoted Service Path Privilege Escalation
CVE-2021-479858.55.8BrotherSAPSprintCWE-428Brother SAPSprint 7.60 Unquoted Service Path Privilege Escalation
CVE-2026-341927.75.5Imagination TechnologiesGraphics DDKCWE-416GPU DDK - _MMU_AllocLevel error recovery paths leave dangling page table entries
CVE-2026-411567.75.5Imagination TechnologiesGraphics DDKCWE-416GPU DDK - kernel<->fw CCB contains SYNC_PRIMITIVE_BLOCK firmware address with…
CVE-2020-372538.55.0WinstepWinstepCWE-428Winstep 18.06.0096 Unquoted Service Path Privilege Escalation
CVE-2026-217686.35.0HCLSoftwareVerse for AndroidCWE-20HCL Verse for Android is susceptible to an injection vulnerability
CVE-2026-493583.04.4pontedilanaphp-weasyprintCWE-73PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $t…
CVE-2026-31965.53.8—qemuCWE-190Qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation
CVE-2026-464617.83.3DellServer Hardware ManagerCWE-284Dell Server Hardware Manager, versions prior to 3.2.2, contains an Improper A…
CVE-2026-529087.82.7LinuxLinux—RDMA: During rereg_mr ensure that REREG_ACCESS is compatible
CVE-2026-529097.82.0LinuxLinux—ip6_vti: set netns_immutable on the fallback device.
CVE-2026-561326.91.3libexpat projectlibexpatCWE-821In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog i…
CVE-2026-529107.81.1LinuxLinuxCWE-125bpf: Free reuseport cBPF prog after RCU grace period.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-19 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.