boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Sunday, June 21, 2026 · all times UTC← 2026-06-20 · archive · 2026-06-22 →

Security Box Score — June 21, 2026

73 CVEs published, led by BerriAI (10).

73 CVEs published June 21, 2026: 3 critical, 21 high, 23 medium, 26 low; 0 in the KEV catalog at press time; 14 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 48 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published51749635——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

441 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux10010678466831411120.27.8.0013-125 ▼
google68485983454293297760.78.1.0023+668 ▲
microsoft220756585201726286192.57.8.0045+72 ▲
red hat751698727811200.06.7.0029+65 ▲
apple146612142288710.65.7.0019-1 ▼
canonical1150465000.05.5.0009+1 ▲
freebsd070520000.07.8.0020-7 ▼
suse461410000.08.6.0029+2 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco92165100561047.67.2.0438+4 ▲
netgear171700161000.04.3.0024+17 ▲
palo alto networks911127113218.25.9.0022+7 ▲
ivanti49450025555.68.8.5187+3 ▲
checkpoint3915303111.17.5.0410+3 ▲
fortinet29432028333.38.3.0076+1 ▲
f56843104112.58.9.0225+5 ▲
ubiquiti584400300.08.9.0052+5 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache8612018425273310.86.8.0050+80 ▲
mozilla49551118260900.07.3.0026+44 ▲
gitlab1118041224211.14.8.0024+11 ▲
docker470520000.08.2.0016+4 ▲
drupal0511304120.05.1.0026-2 ▼
github021100000.08.1.03470
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2422701321161842720.78.8.0040+242 ▲
adobe1291314507521921.55.5.0021+129 ▲
ibm11601329180600.07.5.0028+11 ▲
progress591710600.07.5.0036+1 ▲
solarwinds36231010466.77.8.6082+3 ▲
veeam142200100.09.0.0052+1 ▲
zohocorp020110000.07.1.0104-1 ▼
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5 ▲
d-link9110425300.05.5.0058+9 ▲
siemens780440000.07.5.0020+6 ▲
rockwell automation771510000.08.7.0030+7 ▲
abb550410000.07.2.0018+5 ▲
moxa550320000.07.0.0029+5 ▲
dahua330111000.06.9.0036+3 ▲
mitsubishi electric330300000.08.7.0064+3 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7172230391000.06.5.0023+71 ▲
openclaw61670352210000.07.0.0021+61 ▲
sourcecodester3759002534000.02.1.0026+37 ▲
themerex585855300000.08.1.0043+58 ▲
edimax556033023100.07.4.0070+5 ▲
concrete cms2461111321000.06.2.0015-39 ▼
dell2745121230212.26.7.0015+25 ▲
open ises044221210000.07.1.0021-37 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9991100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-50751.837799.79.3
CVE-2026-48907.781099.510.0
CVE-2026-49160.538398.97.5
CVE-2026-10523.518798.99.8
CVE-2026-28318.400198.57.5
CVE-2026-53435.376698.48.8
CVE-2026-46442.363498.49.4
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9991KEV
CVE-2026-4890710.0.7810KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4508710.0.1296
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4919910.0.0134
CVE-2026-1142910.0.0115
CVE-2026-4925710.0.0093
CVE-2026-4548010.0.0090
Most disclosures (vendor)
VendorCVEs
google836
linux516
oracle267
microsoft226
adobe129
red hat107
apache98
spring72
openclaw67
ibm60
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco10
apple7
google6
ivanti5
solarwinds4
berriai3
fortinet3
smartertools3
adobe2
Most-affected ecosystems
EcosystemAdvisories
Maven39
Packagist22
PyPI10
npm3
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2025-48595Google0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-28318SolarWinds0
CVE-2026-35273Oracle Corporation0
CVE-2026-45247Mirasvit0
CVE-2026-45321@tanstack0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171677
CVE-2021-27102n/a2021-11-171677
CVE-2021-27101n/a2021-11-171677
CVE-2021-27103n/a2021-11-171677
CVE-2021-21017Adobe2021-11-171677
CVE-2021-28550Adobe2021-11-171677
CVE-2021-42013Apache Software Foundation2021-11-171677
CVE-2021-41773Apache Software Foundation2021-11-171677
CVE-2021-30858Apple2021-11-171677
CVE-2021-30860Apple2021-11-171677

Transactions

EXPLOIT PUBLISHED — picklescan: 3 CVEs (CVE-2025-71348, CVE-2025-71357, CVE-2025-71378). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-12822 (langflow-ai langflow). Public exploit reference added.

Yesterday's Results

How to read these box scores · glossary

73 CVEs published. 25 box scores, 48 table rows — nothing truncated.

Crawl4AI - Authentication Bypass via Hardcoded JWT Signing Key
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0264   84.4     —
AFFECTED
  Product   Versions     Fixed
  Crawl4AI  unspecified  0.8.7
TIMELINE
  Jun 20  Reserved by CNA
  Jun 21  Published (CNA: VulnCheck)
CWE-798 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Analyzed
Edimax BR-6478AC V2 POST Request setWAN command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0199   79.1     —
AFFECTED
  Product       Versions  Fixed
  BR-6478AC V2  1.23 –    —
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Edimax BR-6478AC V2 POST Request stainfo command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0199   79.1     —
AFFECTED
  Product       Versions  Fixed
  BR-6478AC V2  1.23 –    —
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Edimax BR-6478AC V2 POST Request wiz_5in1_redirect command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0199   79.1     —
AFFECTED
  Product       Versions  Fixed
  BR-6478AC V2  1.23 –    —
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Edimax BR-6478AC V2 POST Request mp command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0199   79.1     —
AFFECTED
  Product       Versions  Fixed
  BR-6478AC V2  1.23 –    —
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Comfast CF-WR631AX V3 API Endpoint mbox-config system os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0199   79.1     —
AFFECTED
  Product        Versions   Fixed
  CF-WR631AX V3  2.7.0.0 –  —
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
coollabsio coolify Image Name os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0199   79.1     —
AFFECTED
  Product  Versions  Fixed
  coolify  4.0.0 –   —
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0102   60.7     —
AFFECTED
  Product  Versions  Fixed
  litellm  1.59.0 –  —
TIMELINE
  Jun 20  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-287, CWE-303 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Modified
craftcms cms — Craft CMS - Remote Code Execution via Missing Config Sanitization in FieldsController
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0089   56.5     —
AFFECTED
  Product  Versions  Fixed
  cms      5.5.0 –   5.9.14
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
Edimax BR-6478AC V2 POST Request formWlSiteSurvey buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0080   54.0     —
AFFECTED
  Product       Versions  Fixed
  BR-6478AC V2  1.23 –    —
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
BerriAI litellm SSO Debug Flow ui_sso.py json.dumps missing authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0080   53.6     —
AFFECTED
  Product  Versions  Fixed
  litellm  1.82.0 –  —
TIMELINE
  Jun 20  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-287, CWE-306 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Analyzed
picklescan - Remote Code Execution via timeit.timeit() Detection Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   P   H   H   N    7.6   .0071   50.7     —
AFFECTED
  Product     Versions     Fixed
  picklescan  unspecified  0.0.25
TIMELINE
  Jun 20  Reserved by CNA
  Jun 21  Published (CNA: VulnCheck)
CWE-184 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
SiYuan - Remote Code Execution via Malicious Bazaar Package Metadata and README
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   H   H   H    9.4   .0070   50.4     —
AFFECTED
  Product  Versions     Fixed
  SiYuan   unspecified  3.6.1
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulnCheck)
CWE-79 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
SiYuan - Remote Code Execution via Malicious Bazaar Package Metadata and README
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   H   H   H    9.4   .0070   50.4     —
AFFECTED
  Product  Versions     Fixed
  SiYuan   unspecified  3.6.1
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulnCheck)
CWE-79 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
Capgo - Denial of Service via Unauthenticated OPTIONS Request to /build/upload Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    6.9   .0068   49.8     —
AFFECTED
  Product  Versions     Fixed
  Capgo    unspecified  12.128.2
TIMELINE
  Jun 20  Reserved by CNA
  Jun 21  Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
Linux Linux — ksmbd: scope conn->binding slowpath to bound sessions only
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0066   48.9     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    f5a544e3bab78142207e0242d22442db85ba1eff –  —
  Linux    5.15 –                                      5.15.209
TIMELINE
  Jun 9   Reserved by CNA
  Jun 21  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 7 references · NVD status: Analyzed
BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid session expiration
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0057   44.6     —
AFFECTED
  Product  Versions  Fixed
  litellm  1.82.0 –  —
TIMELINE
  Jun 20  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-613 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Analyzed
BerriAI litellm Admin Key key_management_endpoints.py improper authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   L   L    2.1   .0057   44.5     —
AFFECTED
  Product  Versions  Fixed
  litellm  1.63.0 –  —
TIMELINE
  Jun 20  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-266, CWE-285 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Analyzed
picklescan - Arbitrary Code Execution via torch.utils._config_module.load_config Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   P   H   H   N    7.6   .0055   43.7     —
AFFECTED
  Product     Versions     Fixed
  picklescan  unspecified  0.0.28
TIMELINE
  Jun 20  Reserved by CNA
  Jun 21  Public exploit reference published
  Jun 21  Published (CNA: VulnCheck)
CWE-502 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Analyzed
kortix-ai suna Auth Endpoint page.tsx router.push cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   L   N    2.1   .0050   40.4     —
AFFECTED
  Product  Versions  Fixed
  suna     0.8.0 –   0.8.39
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Deferred
FlowiseAI Flowise S3 Document Loader S3.ts path traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0049   40.1     —
AFFECTED
  Product  Versions  Fixed
  Flowise  3.1.0 –   —
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-22 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
craftcms cms — Craft CMS - Authenticated Path Traversal in assets/icon Extension Parameter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   N   N    7.1   .0049   40.1     —
AFFECTED
  Product  Versions     Fixed
  cms      4.0.0-RC1 –  4.17.7
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Deferred
picklescan - Remote Code Execution via Undetected cProfile.runctx in Pickle Files
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   P   H   H   N    7.6   .0048   39.2     —
AFFECTED
  Product     Versions     Fixed
  picklescan  unspecified  0.0.30
TIMELINE
  Jun 20  Reserved by CNA
  Jun 21  Public exploit reference published
  Jun 21  Published (CNA: VulnCheck)
CWE-502 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Analyzed
OFFIS DCMTK ofxml.cc parseFile heap-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   L   L   L    2.1   .0047   38.4     —
AFFECTED
  Product  Versions  Fixed
  DCMTK    3.0 –     —
TIMELINE
  Jun 21  Reserved by CNA
  Jun 21  Published (CNA: VulDB)
CWE-119, CWE-122 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Deferred
Capgo - Privilege Escalation via Broken Row Level Security in org_users
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   N   H   H    7.0   .0044   36.7     —
AFFECTED
  Product  Versions     Fixed
  Capgo    unspecified  12.128.2
TIMELINE
  Jun 19  Reserved by CNA
  Jun 21  Published (CNA: VulnCheck)
CWE-266 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-563968.736.6phpMyFAQphpMyFAQCWE-862phpMyFAQ - Privilege Escalation via Missing Authorization in editUser() and u…
CVE-2026-562428.736.4CapgoCapgoCWE-200Capgo - Unauthenticated API Key Validity Oracle and User Identity Disclosure …
CVE-2026-127711.335.7BerriAIlitellmCWE-266BerriAI litellm M2M JWT user_api_key_auth.py improper authorization
CVE-2026-127992.135.3BerriAIlitellmCWE-266BerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_vi…
CVE-2026-562538.735.0CapgoCapgoCWE-284Capgo - Unauthenticated Organization Member Email Disclosure via get_org_memb…
CVE-2026-563676.334.5ImageMagickImageMagickCWE-125ImageMagick - Heap Out-of-Bounds Read in PSB RLE Decoding
CVE-2026-127755.533.9MontodelHouse-Rental-ManagementCWE-74Montodel House-Rental-Management login.php sql injection
CVE-2026-563166.933.7Cap-gocapgoCWE-203Cap-go - Job Existence Oracle via Unauthenticated OPTIONS /build/upload/:jobId/*
CVE-2026-127872.133.7zhilink 智互联(深圳)科技有限公司ADP Application Developer Platform 应用开发者平台CWE-20zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 testConnecti…
CVE-2026-127722.132.8BerriAIlitellmCWE-613BerriAI litellm PROXY_ADMIN database API Key Generator login_utils.py authent…
CVE-2026-127742.132.8BerriAIlitellmCWE-918BerriAI litellm MCP Server Connection Testing rest_endpoints.py _execute_with…
CVE-2026-127882.132.8zhilink 智互联(深圳)科技有限公司ADP Application Developer Platform 应用开发者平台CWE-610zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 XML Parser i…
CVE-2026-127972.132.8BerriAIlitellmCWE-285BerriAI litellm Completions banned_keywords.py async_pre_call_hook authorization
CVE-2026-127982.132.8BerriAIlitellmCWE-918BerriAI litellm MCP OpenAPI Spec Loader openapi_to_mcp_generator.py load_open…
CVE-2025-713577.632.0picklescanpicklescanCWE-502picklescan - Arbitrary Code Execution via Undetected idlelib.pyshell.Modified…
CVE-2026-563786.331.7ImageMagickImageMagickCWE-125ImageMagick - Heap Out-of-Bounds Read in PCD Decoder
CVE-2026-562297.130.3CapgoCapgoCWE-639Capgo - Cross-App Build Job Access via app_id/job_id Mismatch in /build/statu…
CVE-2026-563855.328.6craftcmscmsCWE-639Craft CMS - Authorization Bypass in assets/preview-file Endpoint
CVE-2026-128132.127.3n/aactivepiecesCWE-918activepieces File URL file.ts handleUrlFile server-side request forgery
CVE-2026-562397.227.2CapgoCapgoCWE-269Capgo - Privilege Escalation via SECURITY DEFINER Function apply_usage_overage
CVE-2026-127892.025.5ILIASLearning Management SystemCWE-74ILIAS Learning Management System Learning Progress Tracking class.ilTrQuery.p…
CVE-2026-563845.325.4craftcmscmsCWE-862Craft CMS - Missing Authorization in assets/preview-thumb Endpoint
CVE-2026-128122.025.4RadwareCyber ControllerCWE-74Radware Cyber Controller HTML Report Generation HTML injection
CVE-2026-563934.624.2craftcmscmsCWE-79Craft CMS - Multiple Stored Cross-Site Scripting in Settings Names and Field …
CVE-2026-127762.123.8MontodelHouse-Rental-ManagementCWE-74Montodel House-Rental-Management index.php houses sql injection
CVE-2026-563834.623.0craftcmscmsCWE-79Craft CMS - Stored XSS in Table Field via Row Heading Column Type
CVE-2026-128221.919.5langflow-ailangflowCWE-74langflow-ai langflow Bundle URL Loader code injection
CVE-2026-128042.117.4n/alemonldap-ngCWE-601lemonldap-ng SAML Common Domain Cookie Endpoint CDC.pm redirect
CVE-2026-563814.616.3craftcmscmsCWE-79Craft CMS - Stored XSS via User Group Name in User Permissions Page
CVE-2026-564125.98.1libexpat projectlibexpatCWE-416libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection …
CVE-2026-562366.87.9capgocliCWE-59Capgo CLI - Arbitrary File Overwrite via Symlink-Following in Local Credentia…
CVE-2026-127787.15.6AOMEIPartition AssistantCWE-266AOMEI Partition Assistant Kernel Driver ampa10.sys access control
CVE-2026-127797.15.6AOMEIDynamic Disk ManagerCWE-266AOMEI Dynamic Disk Manager Kernel Driver ddmdrv.sys access control
CVE-2026-127807.15.6AOMEIBackupperCWE-266AOMEI Backupper Kernel Driver amwrtdrv.sys access control
CVE-2026-127847.15.6IM-MagicPartition ResizerCWE-266IM-Magic Partition Resizer Kernel Driver MDA_NTDRV.sys access control
CVE-2026-127867.15.6EzbsystemsUltraISO Premium EditionCWE-266Ezbsystems UltraISO Premium Edition Kernel Driver bootpt64.sys access control
CVE-2026-127817.15.4EaseUSPartition MasterCWE-266EaseUS Partition Master Kernel Driver epmntdrv.sys access control
CVE-2026-127827.15.4EaseUSPartition MasterCWE-266EaseUS Partition Master Kernel Driver EUEDKEPM.sys access control
CVE-2026-128231.95.4BrowserbaseSkillsCWE-266Browserbase Skills Autobrowse Trace Artifact default permission
CVE-2026-564036.93.6libexpat projectlibexpatCWE-190libexpat before 2.8.2 has an integer overflow in storeAtts.
CVE-2026-564046.93.6libexpat projectlibexpatCWE-190libexpat before 2.8.2 has an integer overflow in addBinding.
CVE-2026-564056.93.6libexpat projectlibexpatCWE-190libexpat before 2.8.2 has an integer overflow in getAttributeId.
CVE-2026-564086.93.6libexpat projectlibexpatCWE-190libexpat before 2.8.2 has an integer overflow in copyString.
CVE-2026-564066.93.5libexpat projectlibexpatCWE-190libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it l…
CVE-2026-564076.93.5libexpat projectlibexpatCWE-190libexpat before 2.8.2 has an integer overflow in doProlog that is related to …
CVE-2026-564106.93.5libexpat projectlibexpatCWE-190xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
CVE-2026-564116.93.5libexpat projectlibexpatCWE-190xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via …
CVE-2026-564096.53.1libexpat projectlibexpatCWE-190xmlwf in libexpat before 2.8.2 has an integer overflow for the output filenam…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-21 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.