AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0118 65.2 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Nov 28 Reserved by CNA Jun 22 Public exploit reference published Jun 22 Published (CNA: mitre)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
220 CVEs published, led by IBM (21).
220 CVEs published June 22, 2026: 21 critical, 80 high, 105 medium, 14 low; 0 in the KEV catalog at press time; 22 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 195 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 5394 | 9855 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
448 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 100 | 1067 | 84 | 668 | 314 | 1 | 11 | 2 | 0.2 | 7.8 | .0013 | -125 ▼ |
| 684 | 859 | 83 | 454 | 293 | 29 | 77 | 6 | 0.7 | 8.1 | .0023 | +668 ▲ | |
| microsoft | 220 | 756 | 58 | 520 | 172 | 6 | 286 | 19 | 2.5 | 7.8 | .0045 | +60 ▲ |
| red hat | 79 | 173 | 8 | 74 | 80 | 11 | 2 | 0 | 0.0 | 6.7 | .0029 | +69 ▲ |
| apple | 14 | 66 | 1 | 21 | 42 | 2 | 88 | 7 | 10.6 | 5.7 | .0019 | -1 ▼ |
| canonical | 2 | 16 | 1 | 4 | 6 | 5 | 0 | 0 | 0.0 | 5.5 | .0010 | +2 ▲ |
| freebsd | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0020 | -7 ▼ |
| suse | 4 | 6 | 1 | 4 | 1 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | +2 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 9 | 21 | 6 | 5 | 10 | 0 | 56 | 10 | 47.6 | 7.2 | .0438 | +4 ▲ |
| netgear | 17 | 17 | 0 | 0 | 16 | 1 | 0 | 0 | 0.0 | 4.3 | .0024 | +17 ▲ |
| palo alto networks | 9 | 11 | 1 | 2 | 7 | 1 | 13 | 2 | 18.2 | 5.9 | .0022 | +7 ▲ |
| ivanti | 4 | 9 | 4 | 5 | 0 | 0 | 25 | 5 | 55.6 | 8.8 | .5187 | +2 ▲ |
| checkpoint | 3 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | +3 ▲ |
| fortinet | 2 | 9 | 4 | 3 | 2 | 0 | 28 | 3 | 33.3 | 8.3 | .0076 | +1 ▲ |
| f5 | 6 | 8 | 4 | 3 | 1 | 0 | 4 | 1 | 12.5 | 8.9 | .0225 | +4 ▲ |
| ubiquiti | 5 | 8 | 4 | 4 | 0 | 0 | 3 | 0 | 0.0 | 8.9 | .0052 | +3 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 92 | 126 | 18 | 44 | 55 | 8 | 33 | 1 | 0.8 | 6.5 | .0051 | +83 ▲ |
| mozilla | 49 | 55 | 11 | 18 | 26 | 0 | 9 | 0 | 0.0 | 7.3 | .0026 | +44 ▲ |
| gitlab | 11 | 18 | 0 | 4 | 12 | 2 | 4 | 2 | 11.1 | 4.8 | .0024 | +11 ▲ |
| docker | 4 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.2 | .0016 | +1 ▲ |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 4 | 1 | 20.0 | 5.1 | .0026 | -3 ▼ |
| github | 0 | 2 | 1 | 1 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0347 | 0 |
| wordpress | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 242 | 270 | 132 | 116 | 18 | 4 | 27 | 2 | 0.7 | 8.8 | .0040 | +242 ▲ |
| adobe | 129 | 131 | 4 | 50 | 75 | 2 | 19 | 2 | 1.5 | 5.5 | .0021 | +129 ▲ |
| ibm | 32 | 81 | 19 | 35 | 27 | 0 | 6 | 0 | 0.0 | 7.5 | .0031 | +32 ▲ |
| progress | 5 | 9 | 1 | 7 | 1 | 0 | 6 | 0 | 0.0 | 7.5 | .0036 | +1 ▲ |
| solarwinds | 3 | 6 | 2 | 3 | 1 | 0 | 10 | 4 | 66.7 | 7.8 | .6082 | +3 ▲ |
| veeam | 1 | 4 | 2 | 2 | 0 | 0 | 1 | 0 | 0.0 | 9.0 | .0052 | +1 ▲ |
| zohocorp | 0 | 2 | 0 | 1 | 1 | 0 | 0 | 0 | 0.0 | 7.1 | .0104 | -1 ▼ |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 5 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +5 ▲ |
| d-link | 9 | 11 | 0 | 4 | 2 | 5 | 3 | 0 | 0.0 | 5.5 | .0058 | +9 ▲ |
| siemens | 7 | 8 | 0 | 4 | 4 | 0 | 0 | 0 | 0.0 | 7.5 | .0020 | +6 ▲ |
| rockwell automation | 7 | 7 | 1 | 5 | 1 | 0 | 0 | 0 | 0.0 | 8.7 | .0030 | +7 ▲ |
| abb | 5 | 5 | 0 | 4 | 1 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | +5 ▲ |
| moxa | 5 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | +5 ▲ |
| dahua | 3 | 3 | 0 | 1 | 1 | 1 | 0 | 0 | 0.0 | 6.9 | .0036 | +3 ▲ |
| mitsubishi electric | 3 | 3 | 0 | 3 | 0 | 0 | 0 | 0 | 0.0 | 8.7 | .0064 | +3 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| spring | 71 | 72 | 2 | 30 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0023 | +71 ▲ |
| openclaw | 61 | 67 | 0 | 35 | 22 | 10 | 0 | 0 | 0.0 | 7.0 | .0021 | +61 ▲ |
| sourcecodester | 37 | 59 | 0 | 0 | 25 | 34 | 0 | 0 | 0.0 | 2.1 | .0026 | +37 ▲ |
| themerex | 58 | 58 | 5 | 53 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0043 | +58 ▲ |
| edimax | 5 | 56 | 0 | 33 | 0 | 23 | 1 | 0 | 0.0 | 7.4 | .0070 | +5 ▲ |
| dell | 31 | 49 | 1 | 24 | 24 | 0 | 2 | 1 | 2.0 | 7.0 | .0017 | +19 ▲ |
| concrete cms | 2 | 46 | 1 | 11 | 13 | 21 | 0 | 0 | 0.0 | 6.2 | .0015 | -42 ▼ |
| open ises | 0 | 44 | 2 | 21 | 21 | 0 | 0 | 0 | 0.0 | 7.1 | .0021 | -37 ▼ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-10520 | .9991 | 100.0 | 10.0 |
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-35273 | .9547 | 99.9 | 9.8 |
| CVE-2026-50751 | .8377 | 99.7 | 9.3 |
| CVE-2026-48907 | .7810 | 99.5 | 10.0 |
| CVE-2026-49160 | .5383 | 98.9 | 7.5 |
| CVE-2026-10523 | .5187 | 98.9 | 9.8 |
| CVE-2026-28318 | .4001 | 98.5 | 7.5 |
| CVE-2026-53435 | .3766 | 98.4 | 8.8 |
| CVE-2026-46442 | .3634 | 98.4 | 9.4 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-10520 | 10.0 | .9991 | KEV |
| CVE-2026-48907 | 10.0 | .7810 | KEV |
| CVE-2026-48172 | 10.0 | .1891 | KEV |
| CVE-2026-45087 | 10.0 | .1296 | |
| CVE-2026-49777 | 10.0 | .0166 | |
| CVE-2026-8054 | 10.0 | .0158 | |
| CVE-2026-49199 | 10.0 | .0134 | |
| CVE-2026-11429 | 10.0 | .0115 | |
| CVE-2026-49257 | 10.0 | .0093 | |
| CVE-2026-10561 | 10.0 | .0091 |
| Vendor | CVEs |
|---|---|
| 836 | |
| linux | 514 |
| oracle | 267 |
| microsoft | 226 |
| adobe | 129 |
| red hat | 111 |
| apache | 104 |
| ibm | 81 |
| spring | 72 |
| openclaw | 67 |
| Vendor | KEV |
|---|---|
| microsoft | 19 |
| cisco | 10 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| berriai | 3 |
| fortinet | 3 |
| smartertools | 3 |
| adobe | 2 |
| Ecosystem | Advisories |
|---|---|
| Maven | 43 |
| Packagist | 22 |
| PyPI | 10 |
| npm | 3 |
| crates.io | 2 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2025-48595 | 0 | |
| CVE-2026-10520 | ivanti | 0 |
| CVE-2026-11645 | 0 | |
| CVE-2026-20245 | Cisco | 0 |
| CVE-2026-20253 | Splunk | 0 |
| CVE-2026-20262 | Cisco | 0 |
| CVE-2026-28318 | SolarWinds | 0 |
| CVE-2026-35273 | Oracle Corporation | 0 |
| CVE-2026-45247 | Mirasvit | 0 |
| CVE-2026-45321 | @tanstack | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1678 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1678 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1678 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1678 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1678 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1678 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1678 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1678 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1678 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1678 |
EXPLOIT PUBLISHED — vllm-project vllm: 4 CVEs (CVE-2026-41523, CVE-2026-54232, CVE-2026-54235, CVE-2026-54236). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2025-66389. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10645 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10651 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-12549 (Red Hat Enterprise Linux 10). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-41479 (authlib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44311 (fabricjs fabric.js). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48931 (nodejs node). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-50146 (withastro astro). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-53550 (nodeca js-yaml). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-53571 (vitejs vite). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-53655 (isaacs node-tar). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54293 (nltk). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54298 (withastro astro). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55599 (phpseclib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55602 (chimurai http-proxy-middleware). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55603 (chimurai http-proxy-middleware). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56268 (Flowise). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-6653 (GNOME libxml2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-6858 (Unknown Transbank Webpay). Public exploit reference added.
DUE DATE PASSED — CVE-2026-20253 (Splunk Enterprise). CISA remediation deadline was June 21, 2026; still in catalog.
How to read these box scores · glossary
220 CVEs published. 25 box scores, 195 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0118 65.2 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Nov 28 Reserved by CNA Jun 22 Public exploit reference published Jun 22 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N H 9.1 .0115 64.5 —
AFFECTED Product Versions Fixed vllm >= 0.3.0, < 0.22.0 – —
TIMELINE May 22 Reserved by CNA Jun 22 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L N N 5.3 .0093 57.8 —
AFFECTED Product Versions Fixed vllm < 0.23.1rc0 – —
TIMELINE Jun 12 Reserved by CNA Jun 22 Public exploit reference published Jun 22 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0091 57.4 —
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE Jun 1 Reserved by CNA Jun 22 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N R U H H H 7.5 .0088 56.4 —
AFFECTED Product Versions Fixed vllm < 0.22.0 – —
TIMELINE Apr 20 Reserved by CNA Jun 22 Public exploit reference published Jun 22 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0072 51.1 —
AFFECTED Product Versions Fixed WebSphere Application Server 8.5 – —
TIMELINE May 20 Reserved by CNA Jun 22 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C H H H 9.6 .0070 50.4 —
AFFECTED Product Versions Fixed Fusion 2703.1.11 – —
TIMELINE Jun 3 Reserved by CNA Jun 22 Published (CNA: autodesk)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N H N H H N 8.7 .0069 50.0 —
AFFECTED Product Versions Fixed misp unspecified —
TIMELINE Jun 22 Reserved by CNA Jun 22 Published (CNA: CIRCL)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV A L N N N H H H 8.7 .0066 49.0 —
AFFECTED Product Versions Fixed Archer MR200 v07 unspecified — Archer MR200 v8 unspecified — Archer MR402 v1 unspecified — Archer VR2100 v1 unspecified — Archer C20 v5 unspecified — Archer C20 v6 unspecified — TL-MR6400 v7 unspecified —
TIMELINE Jun 9 Reserved by CNA Jun 22 Published (CNA: TPLink)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P H N H H H 7.5 .0066 48.8 —
AFFECTED Product Versions Fixed Apache NiFi 1.12.0 – —
TIMELINE May 8 Reserved by CNA Jun 22 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P H P N N N 5.2 .0065 48.2 —
AFFECTED Product Versions Fixed Apache NiFi 1.2.0 – —
TIMELINE May 8 Reserved by CNA Jun 22 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0064 47.8 —
AFFECTED Product Versions Fixed Capgo unspecified 12.128.2
TIMELINE Jun 20 Reserved by CNA Jun 22 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N P H H N 7.6 .0064 47.8 —
AFFECTED Product Versions Fixed picklescan unspecified 0.0.30
TIMELINE Jun 20 Reserved by CNA Jun 22 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0063 47.5 —
AFFECTED Product Versions Fixed Storage Protect Client 8.1.0.0 – — Storage Protect Snapshot For Windows 8.1.0.0 – —
TIMELINE Jun 18 Reserved by CNA Jun 22 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N H H 8.1 .0063 47.3 —
AFFECTED Product Versions Fixed PMI v8xx 0.0.0 – — PASvisu 0.0.0 – —
TIMELINE Oct 13 Reserved by CNA Jun 22 Published (CNA: CERTVDE)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L N 6.9 .0062 46.9 —
AFFECTED Product Versions Fixed Central Dogma unspecified 0.84.0
TIMELINE Jun 9 Reserved by CNA Jun 22 Published (CNA: LY-Corporation)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H N 9.3 .0062 46.8 —
AFFECTED Product Versions Fixed misp unspecified —
TIMELINE Jun 22 Reserved by CNA Jun 22 Published (CNA: CIRCL)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0060 46.2 —
AFFECTED Product Versions Fixed nltk < 3.10.0-rc1 – —
TIMELINE Jun 12 Reserved by CNA Jun 22 Public exploit reference published Jun 22 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 9.4 .0060 46.2 —
AFFECTED Product Versions Fixed misp unspecified —
TIMELINE Jun 22 Reserved by CNA Jun 22 Published (CNA: CIRCL)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.5 .0059 45.7 —
AFFECTED Product Versions Fixed litellm < 1.84.0 – —
TIMELINE May 30 Reserved by CNA Jun 22 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0059 45.5 —
AFFECTED Product Versions Fixed WebSphere Application Server 9.0.0 – — WebSphere Application Server - Liberty 17.0.0.3 – —
TIMELINE May 14 Reserved by CNA Jun 22 Published (CNA: ibm)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0059 45.4 —
AFFECTED Product Versions Fixed webp_server_go unspecified —
TIMELINE Jun 10 Reserved by CNA Jun 22 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N N N H 8.2 .0058 45.2 —
AFFECTED Product Versions Fixed angular >= 22.0.0-next.0 < 22.0.1 – —
TIMELINE Jun 12 Reserved by CNA Jun 22 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N N H L L 7.0 .0058 45.0 —
AFFECTED Product Versions Fixed libxml2 2.9.11 – —
TIMELINE Apr 20 Reserved by CNA Jun 22 Public exploit reference published Jun 22 Published (CNA: canonical)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H N N 8.2 .0058 44.9 —
AFFECTED Product Versions Fixed vite >= 8.0.0, < 8.0.16 – —
TIMELINE Jun 9 Reserved by CNA Jun 22 Public exploit reference published Jun 22 Published (CNA: GitHub_M)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-56450 | 5.1 | 44.9 | ail project | ail framework | CWE-307 | AIL Framework - Missing Rate Limiting Enables Brute-Force Attacks Against Two… |
| CVE-2026-7167 | 6.9 | 44.6 | Gaudire | Assassin game | CWE-200 | Multiple vulnerabilities in the Assassin game by Gaudire |
| CVE-2026-11373 | 9.1 | 44.5 | JASEI | Net::Statsite::Client | CWE-93 | Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections |
| CVE-2026-9320 | 7.5 | 44.3 | IBM | WebSphere Application Server | CWE-400 | IBM WebSphere Application Server and WebSphere Application Server Liberty are… |
| CVE-2026-54232 | 8.8 | 44.2 | vllm-project | vllm | CWE-427 | vLLM: Dependency Confusion Vulnerability in vLLM Dockerfile |
| CVE-2025-66336 | 8.1 | 44.1 | Apache Software Foundation | Apache Doris MCP Server | CWE-89 | Apache Doris MCP Server: SQL injection leading the authentication bypass |
| CVE-2026-9071 | 7.5 | 43.5 | IBM | WebSphere Application Server | CWE-400 | IBM WebSphere Application Server and WebSphere Application Server Liberty are… |
| CVE-2026-7166 | 9.2 | 43.2 | Gaudire | Assassin game | CWE-200 | Multiple vulnerabilities in the Assassin game by Gaudire |
| CVE-2026-12725 | 5.9 | 42.3 | Red Hat | Red Hat Enterprise Linux 10 | CWE-122 | Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupporte… |
| CVE-2025-71339 | 7.6 | 42.0 | Picklescan | Picklescan | CWE-502 | Picklescan - Arbitrary Code Execution via numpy.f2py.crackfortran._eval_lengt… |
| CVE-2026-56424 | 7.1 | 42.0 | misp | misp | CWE-639 | Broken access control in MISP core allows cross-organization unauthorized mod… |
| CVE-2026-44911 | 2.3 | 41.6 | Apache Software Foundation | Apache NiFi | CWE-863 | Apache NiFi: Incorrect Authorization for Configuration Verification Requests |
| CVE-2026-8934 | 6.9 | 41.2 | Google Cloud | Cloud Console UIs | CWE-862 | Cross-Project Information Leakage in Google App Engine UI |
| CVE-2026-48109 | 8.2 | 41.1 | MessagePack-CSharp | MessagePack-CSharp | CWE-20 | MessagePack-CSharp: LZ4 decompression may fail with AccessViolationException … |
| CVE-2025-62198 | 5.4 | 40.8 | Apache Software Foundation | Apache Atlas | CWE-80 | Apache Atlas: Stored XSS in Create Entity page |
| CVE-2026-50178 | 8.7 | 40.7 | angular | angular | CWE-79 | Angular: Remote Code Execution via JSDoc Hover Command Injection in VS Code A… |
| CVE-2026-7664 | 9.8 | 40.4 | IBM | Langflow OSS | CWE-287 | Unauthenticated Flow Execution via Webhook Endpoint in Langflow OSS |
| CVE-2026-54281 | 8.7 | 40.4 | nestjs | nest | CWE-863 | Nest: Middleware Bypass on Fastify via Trailing Slash |
| CVE-2026-47240 | 5.8 | 39.9 | ruby | net-imap | CWE-77 | Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument |
| CVE-2026-53923 | 5.3 | 39.5 | vllm-project | vllm | CWE-200 | vLLM GGUF Kernels: int64_t to int truncation of tensor dimensions causes GPU … |
| CVE-2026-56348 | 5.3 | 39.4 | n8n | n8n | CWE-918 | n8n - Credential Exfiltration via Allowed HTTP Request Domains Bypass in Dyna… |
| CVE-2026-54283 | 7.5 | 39.3 | Kludex | starlette | CWE-770 | Starlette: request.form() limits silently ignored for application/x-www-form-… |
| CVE-2026-7165 | 9.4 | 39.3 | Gaudire | Assassin game | CWE-20 | Multiple vulnerabilities in the Assassin game by Gaudire |
| CVE-2026-56266 | 9.2 | 39.0 | Crawl4AI | Crawl4AI | CWE-918 | Crawl4AI - Server-Side Request Forgery via Direct Crawl Endpoints |
| CVE-2026-10852 | 7.5 | 38.8 | IBM | WebSphere Application Server | CWE-476 | Websphere Application Server is Affected By a Denial of Service |
| CVE-2026-48506 | 7.5 | 38.7 | MessagePack-CSharp | MessagePack-CSharp | CWE-674 | MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maxi… |
| CVE-2026-56423 | 9.4 | 38.5 | misp | misp | CWE-862 | MISP Core: Broken access control allows instance-wide unauthorized deletion o… |
| CVE-2026-10845 | 7.3 | 38.3 | IBM | WebSphere Application Server | CWE-287 | IBM WebSphere Application Server is affected by an authentication bypass vuln… |
| CVE-2026-56324 | 8.8 | 38.2 | Capgo | Capgo | CWE-770 | Capgo - Rate Limit Bypass via User-Controlled device_id Parameter |
| CVE-2026-56425 | 9.3 | 38.0 | misp | misp | CWE-384 | MISP AAD authentication plugin - Improper OAuth State Handling, Missing Sessi… |
| CVE-2026-45034 | 9.2 | 38.0 | PHPOffice | PhpSpreadsheet | CWE-502 | PhpSpreadsheet: File::prohibitWrappers bypass |
| CVE-2026-48712 | 7.5 | 37.9 | protobufjs | protobuf.js | CWE-674 | protobufjs: Denial of service through unbounded Any expansion during JSON con… |
| CVE-2026-53539 | 7.5 | 37.9 | Kludex | python-multipart | CWE-400 | Python-Multipart: Quadratic-time querystring parsing with semicolon separator… |
| CVE-2026-56321 | 6.9 | 37.6 | Capgo | Capgo | CWE-306 | Capgo - Missing Authentication Middleware on GET /private/role_bindings Endpoint |
| CVE-2026-55388 | 8.1 | 37.5 | piscinajs | piscina | CWE-94 | piscina: Prototype Pollution Gadget → RCE via inherited options.filename |
| CVE-2026-12581 | 7.7 | 37.5 | Digiwin | EasyFlow .NET | CWE-384 | Digiwin|EasyFlow .NET - Session Fixation |
| CVE-2026-54235 | 6.9 | 37.2 | vllm-project | vllm | CWE-1287 | vLLM: temperature=NaN and temperature=Infinity bypass validation and propagat… |
| CVE-2026-12888 | 2.0 | 36.7 | Thinkst Applied Research | Canarytokens | CWE-74 | HTML injection in the Canarytoken Google Chat notification |
| CVE-2026-42129 | 7.7 | 36.7 | Grafana | Grafana OSS | CWE-22 | Path traversal in the Loki data source plugin |
| CVE-2026-11942 | 4.8 | 36.5 | Akaunting | Akaunting | CWE-79 | Akaunting 3.1.21 - Stored XSS in delete confirmation modal |
| CVE-2026-11943 | 4.8 | 36.5 | Akaunting | Akaunting | CWE-79 | Akaunting 3.1.21 - Authenticated stored XSS in document timeline |
| CVE-2026-11994 | 4.8 | 36.5 | Akaunting | Akaunting | CWE-79 | Akaunting 3.1.21 - Authenticated stored XSS in report description rendering |
| CVE-2026-44271 | 8.8 | 36.4 | Dell | Wyse Management Suite (WMS) | CWE-89 | Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Impr… |
| CVE-2026-44272 | 8.8 | 36.4 | Dell | Wyse Management Suite (WMS) | CWE-89 | Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Impr… |
| CVE-2026-44727 | 9.3 | 36.3 | jupyter-server | jupyter_server | CWE-79 | Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler`… |
| CVE-2026-56448 | 8.3 | 36.2 | ail project | ail framework | CWE-22 | Authenticated Path Traversal in AIL Framework Investigation Downloads Allows … |
| CVE-2026-48502 | 8.2 | 36.3 | MessagePack-CSharp | MessagePack-CSharp | CWE-125 | MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or cr… |
| CVE-2026-39904 | 7.1 | 36.1 | gophish | gophish | CWE-770 | Gophish 0.12.1 Denial of Service via Office Document Upload |
| CVE-2026-54286 | 5.9 | 35.9 | honojs | hono | CWE-22 | Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) |
| CVE-2026-42127 | 7.5 | 35.8 | Grafana | Grafana Enterprise | CWE-400 | Pre-authentication denial of service in the public dashboard query endpoint |
| CVE-2025-71358 | 7.6 | 35.7 | picklescan | picklescan | CWE-502 | picklescan - Remote Code Execution via idlelib.autocomplete.AutoComplete.get_… |
| CVE-2026-53632 | 5.5 | 35.4 | vitejs | launch-editor | CWE-73 | NTLMv2 hash disclosure via UNC path handling on Windows |
| CVE-2026-56314 | 7.1 | 35.3 | Capgo | Capgo | CWE-672 | Capgo - Deleted Bundle Selection via Missing Deletion Filter in /updates Endp… |
| CVE-2026-50170 | 8.2 | 35.2 | angular | angular | CWE-524 | Angular: Information Leak via Default Caching of Credentialed Requests in Htt… |
| CVE-2026-54233 | 6.5 | 34.9 | vllm-project | vllm | CWE-409 | vLLM: OOM Denial of Service via Audio Decompression Bomb |
| CVE-2024-54178 | 6.5 | 34.8 | IBM | Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data | CWE-770 | Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Wareh… |
| CVE-2026-8157 | 8.8 | 34.5 | Unknown | Vitepos | CWE-269 | Vitepos < 3.4.2 - Outlet Manager+ Privilege Escalation |
| CVE-2026-56104 | 8.8 | 34.4 | Chainlit | chainlit | CWE-862 | Chainlit < 2.10.1 Session Hijacking via WebSocket Session Restoration |
| CVE-2026-48509 | 6.3 | 34.4 | MessagePack-CSharp | MessagePack-CSharp | CWE-1188 | MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to Truste… |
| CVE-2026-56698 | 5.3 | 34.1 | Nuxt | Nuxt | CWE-79 | Nuxt - Cross-Site Scripting via navigateTo open Option |
| CVE-2026-50556 | 8.6 | 34.0 | angular | angular | CWE-79 | Angular: Missing `<noscript>` Raw-Text Serialization Escaping leads to Cross-… |
| CVE-2026-12549 | 4.8 | 33.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-805 | Libsoup: incomplete fix for cve-2026-2443: range suffix overflow in libsoup s… |
| CVE-2026-8858 | 8.8 | 33.8 | IBM | WebSphere Application Server | CWE-94 | WebSphere Application Server Remote Code Execution |
| CVE-2026-48510 | 6.3 | 33.4 | MessagePack-CSharp | MessagePack-CSharp | CWE-409 | MessagePack-CSharp: LZ4 decompression allocates from unbounded declared outpu… |
| CVE-2026-48511 | 6.3 | 33.4 | MessagePack-CSharp | MessagePack-CSharp | CWE-407 | MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion w… |
| CVE-2026-48512 | 6.3 | 33.4 | MessagePack-CSharp | MessagePack-CSharp | CWE-674 | MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth… |
| CVE-2026-48513 | 6.3 | 33.4 | MessagePack-CSharp | MessagePack-CSharp | CWE-674 | MessagePack-CSharp: DynamicUnionResolver generated deserializers miss depth e… |
| CVE-2026-48514 | 6.3 | 33.4 | MessagePack-CSharp | MessagePack-CSharp | CWE-770 | MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte… |
| CVE-2026-48515 | 6.3 | 33.4 | MessagePack-CSharp | MessagePack-CSharp | CWE-770 | MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecke… |
| CVE-2026-48516 | 6.3 | 33.4 | MessagePack-CSharp | MessagePack-CSharp | CWE-407 | MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant com… |
| CVE-2026-54269 | 5.3 | 33.1 | protobufjs | protobuf.js | CWE-674 | protobufjs: Schema-derived names can shadow runtime-significant properties |
| CVE-2026-54270 | 5.3 | 33.1 | protobufjs | protobuf.js | CWE-770 | protobufjs: Memory amplification from preserved unknown fields in binary decode |
| CVE-2026-52725 | 5.3 | 32.6 | angular | angular | CWE-79 | Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site… |
| CVE-2026-54278 | 6.6 | 32.5 | aio-libs | aiohttp | CWE-409 | AIOHTTP: Unread Compressed Request Bodies Bypass client_max_size During Cleanup |
| CVE-2026-56268 | 5.3 | 31.9 | Flowise | Flowise | CWE-863 | Flowise - Cross-Workspace Information Disclosure via chatflows/apikey Endpoint |
| CVE-2026-54264 | 8.3 | 31.8 | angular | angular | CWE-200 | Angular: Sensitive Header Leakage on Cross-Origin Redirects in Angular Servic… |
| CVE-2026-53550 | 5.3 | 31.4 | nodeca | js-yaml | CWE-407 | js-yaml: Quadratic-complexity DoS in merge key handling via repeated aliases |
| CVE-2026-9006 | 9.1 | 31.3 | IBM | WebSphere Application Server | CWE-918 | IBM WebSphere Application Server is affected by server-side request forgery |
| CVE-2026-12479 | 6.1 | 31.1 | keras-team | keras-team/keras | CWE-22 | Path Traversal in keras-team/keras |
| CVE-2026-12862 | 5.1 | 30.9 | pretix | Venueless | CWE-148 | XLSX formula injection in exports |
| CVE-2026-56221 | 7.1 | 30.7 | Cap-go | capgo | CWE-89 | Cap-go - SQL Injection in Cloudflare Analytics Engine Queries via cloudflare.ts |
| CVE-2026-56255 | 5.3 | 30.1 | Capgo | Capgo | CWE-770 | Capgo - Denial of Service via Unlimited Demo App Creation |
| CVE-2026-56280 | 7.1 | 29.9 | Cap-go | capgo | CWE-862 | Cap-go - Privilege Inversion in Build Log Stream via SSE Disconnect |
| CVE-2026-54911 | 6.5 | 29.9 | ultrajson | ultrajson | CWE-20 | UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson… |
| CVE-2026-7253 | 6.0 | 29.9 | IBM | Sterling B2B Integrator | CWE-89 | IBM Sterling File Gateway SQL Injection |
| CVE-2026-55602 | 6.9 | 29.7 | chimurai | http-proxy-middleware | CWE-20 | http-proxy-middleware `router` host+path substring matching allows Host-heade… |
| CVE-2026-56311 | 6.9 | 29.1 | Capgo | Capgo | CWE-285 | Capgo - Unauthenticated Cross-Tenant Disclosure via get_current_plan_max_org RPC |
| CVE-2026-56326 | 5.3 | 28.8 | Nuxt | Nuxt | CWE-601 | Nuxt - Server-Side Open Redirect via Path-Normalization Bypass in navigateTo |
| CVE-2026-46417 | 8.8 | 28.7 | angular | angular | CWE-918 | Angular: SSRF via Hostname Hijacking in @angular/platform-server |
| CVE-2026-12863 | 5.1 | 27.7 | pretix | Venueless | CWE-601 | Open redirect |
| CVE-2026-28381 | 8.1 | 27.6 | Grafana | Snowflake Datasource | CWE-284 | Local File Read/Write to Potential Privilege Escalation via Snowflake GET/PUT |
| CVE-2026-48517 | 6.3 | 27.3 | MessagePack-CSharp | MessagePack-CSharp | CWE-470 | MessagePack-CSharp: Typeless deserialization type restrictions do not recurse… |
| CVE-2026-48166 | 5.3 | 27.0 | filamentphp | filament | CWE-208 | Filament: Timing-based user enumeration on login page |
| CVE-2026-56306 | 5.3 | 27.0 | Capgo | Capgo | CWE-20 | Capgo - Subkey Enforcement Bypass via x-limited-key-id Header Parsing |
| CVE-2026-48931 | 3.7 | 27.0 | nodejs | node | CWE-367 | A flaw in Node.js HTTP Agent can cause a client to accept as valid a response… |
| CVE-2026-50557 | 5.3 | 26.9 | angular | angular | CWE-79 | Angular: Template and Attribute Namespace Sanitization Bypass (XSS) |
| CVE-2026-54265 | 5.3 | 26.9 | angular | angular | CWE-79 | Angular: Two-Way Property Binding Sanitization Bypass (XSS) |
| CVE-2026-54285 | 5.3 | 26.9 | open-telemetry | opentelemetry-js | CWE-770 | opentelemetry-js: Unbounded memory allocation in W3C Baggage propagation |
| CVE-2025-2669 | 6.5 | 26.8 | IBM | Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data | CWE-295 | Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Wareh… |
| CVE-2026-48500 | 6.5 | 26.8 | filamentphp | filament | CWE-862 | Filament: Unauthenticated temporary file upload on auth pages |
| CVE-2026-53540 | 3.7 | 26.7 | Kludex | python-multipart | CWE-1284 | Python-Multipart: Negative Content-Length in parse_form buffers the entire bo… |
| CVE-2026-56697 | 5.3 | 26.1 | Nuxt | Nuxt | CWE-601 | Nuxt - Open Redirect via Protocol-Relative Paths in reloadNuxtApp |
| CVE-2026-9162 | 4.3 | 25.9 | Mattermost | Mattermost | CWE-613 | Global session revocation does not invalidate active WebSocket connections |
| CVE-2026-54299 | 7.5 | 25.6 | withastro | astro | CWE-20 | Astro: Host-header full-read SSRF in core prerendered error-page fetch (prere… |
| CVE-2025-4994 | 8.7 | 25.5 | SafeLine | SafeLine SL6/SL6+ | CWE-305 | Authentication Bypass for SafeLine SL6 and SL6+ |
| CVE-2026-54290 | 7.1 | 25.1 | honojs | hono | CWE-942 | Hono: CORS Middleware reflects any Origin with credentials when `origin` defa… |
| CVE-2026-54665 | 6.3 | 25.0 | Apache Software Foundation | Apache NiFi | CWE-346 | Apache NiFi: Missing Validation for Proxy Host Headers |
| CVE-2026-54277 | 6.6 | 24.4 | aio-libs | aiohttp | CWE-770 | AIOHTTP: C HTTP Parser Bypasses max_line_size for Fragmented Lines |
| CVE-2026-8074 | 3.8 | 24.0 | Mattermost | Mattermost | CWE-863 | Improper Permission Check Allows User Manager to Deactivate Bot Accounts |
| CVE-2026-8823 | 3.8 | 24.0 | Mattermost | Mattermost | CWE-863 | User Manager can demote bot accounts to guest without bot-management permission |
| CVE-2026-54267 | 8.6 | 23.8 | angular | angular | CWE-79 | Angular Client Hydration DOM Clobbering & Response-Cache Poisoning |
| CVE-2026-56357 | 6.3 | 23.5 | n8n | n8n | CWE-290 | n8n - Webhook Forgery via Missing HMAC-SHA256 Signature Verification in GitHu… |
| CVE-2026-54300 | 5.3 | 23.4 | withastro | astro | CWE-918 | @astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config |
| CVE-2026-54287 | 5.3 | 23.2 | honojs | hono | CWE-116 | Hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value,… |
| CVE-2026-54276 | 6.3 | 22.7 | aio-libs | aiohttp | CWE-601 | AIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Ch… |
| CVE-2026-54274 | 6.6 | 22.5 | aio-libs | aiohttp | CWE-770 | AIOHTTP: Incomplete websocket frame payloads bypass memory limits |
| CVE-2026-54271 | 8.2 | 22.3 | protobufjs | protobufjs-cli | CWE-94 | protobufjs-cli: Code injection in pbjs static output from crafted JSON descri… |
| CVE-2026-50269 | 2.7 | 22.2 | aio-libs | aiohttp | CWE-93 | AIOHTTP: CRLF injection in multipart headers |
| CVE-2026-48067 | 6.5 | 21.9 | filamentphp | filament | CWE-639 | Filament: Inconsistent scope enforcement for AttachAction and AssociateAction… |
| CVE-2026-6673 | 6.4 | 21.9 | Mattermost | Mattermost | CWE-306 | Mattermost Jira plugin had unauthenticated {{/ac/installed}} lifecycle callba… |
| CVE-2026-10651 | 6.5 | 21.9 | zephyrproject | zephyr | CWE-20 | Out-of-bounds read in Bluetooth Classic SDP attribute parsing (`bt_sdp_parse_… |
| CVE-2026-48505 | 7.4 | 21.6 | filamentphp | filament | CWE-362 | Filament: Multi-factor authentication (app) recovery codes can still be used … |
| CVE-2026-6858 | 7.1 | 21.2 | Unknown | Transbank Webpay | CWE-79 | Transbank Webpay < 1.14.0 - Unauthenticated Stored XSS |
| CVE-2026-53537 | 5.3 | 21.1 | Kludex | python-multipart | CWE-20 | Python-Multipart: Content-Disposition parameter smuggling via RFC 2231/5987 e… |
| CVE-2026-5139 | 5.4 | 20.7 | Mattermost | Mattermost | CWE-862 | GitLab Plugin Allows Non-Admin Users to Modify Default Instance Configuration |
| CVE-2026-55603 | 7.5 | 20.5 | chimurai | http-proxy-middleware | CWE-93 | http-proxy-middleware: multipart/form-data field injection via unescaped CRLF… |
| CVE-2026-10601 | 4.3 | 20.5 | Grafana | Grafana OSS | CWE-22 | Path traversal in the Tempo and Loki data source plugins |
| CVE-2026-54100 | 8.3 | 20.4 | Red Hat | Red Hat OpenShift for Windows Containers 10.22 | CWE-295 | Windows-machine-config-operator: windows-machine-config-operator: ssh host ke… |
| CVE-2026-55409 | 7.6 | 20.4 | filamentphp | filament | CWE-79 | Filament: Disabled RichEditor field state can be used for XSS |
| CVE-2026-10658 | 7.1 | 20.1 | zephyrproject | zephyr | CWE-787 | Out-of-bounds access in Bluetooth ISO receive (`bt_iso_recv`) due to missing … |
| CVE-2026-54280 | 1.7 | 20.1 | aio-libs | aiohttp | CWE-404 | AIOHTTP: Payload Response Resources Are Not Closed After Mid-Body Disconnect |
| CVE-2026-12580 | 5.1 | 19.9 | Digiwin | EasyFlow .NET | CWE-79 | Digiwin|EasyFlow .NET - Stored Cross-Site Scripting |
| CVE-2026-8918 | 7.1 | 19.9 | ASUS | Armoury Crate | CWE-183 | A permissive list of allowed inputs in ASUS Armoury Crate allows a local admi… |
| CVE-2026-54273 | 6.6 | 19.8 | aio-libs | aiohttp | CWE-770 | AIOHTTP: HTTP/1 Pipelined Requests Queue Without Limit |
| CVE-2026-54279 | 1.3 | 19.8 | aio-libs | aiohttp | CWE-665 | AIOHTTP: Host-Only Cookies Become Domain Cookies After CookieJar Persistence |
| CVE-2026-54282 | 5.3 | 19.1 | Kludex | starlette | CWE-706 | Starlette: Unvalidated request path concatenated into authority poisons reque… |
| CVE-2026-44311 | 6.1 | 19.0 | fabricjs | fabric.js | CWE-79 | Fabric.js: Improper escaping in fabric.Gradient colorStops leads to XSS in SV… |
| CVE-2026-44889 | 6.1 | 18.5 | Pylons | webob | CWE-601 | WebOb: Location header normalization during redirect leads to open redirect |
| CVE-2026-50146 | 6.1 | 18.5 | withastro | astro | CWE-80 | Astro: Reflected XSS via unescaped slot name |
| CVE-2026-50555 | 8.6 | 18.3 | angular | angular | CWE-79 | Angular: Improper Neutralization of Input During Web Page Generation ('Cross-… |
| CVE-2026-54275 | 2.7 | 18.0 | aio-libs | aiohttp | CWE-297 | AIOHTTP: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections |
| CVE-2026-9610 | 5.3 | 17.3 | IBM | Datacap | CWE-425 | Multiple Vulnerabilities in IBM Datacap |
| CVE-2026-41479 | 5.4 | 17.0 | authlib | authlib | CWE-601 | Authlib OAuth 2.0 authorization endpoint open redirects to attacker-controlle… |
| CVE-2026-50171 | 8.2 | 16.8 | angular | angular | CWE-400 | Angular: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo) |
| CVE-2026-53538 | 3.7 | 16.8 | Kludex | python-multipart | CWE-436 | Python-Multipart: Semicolon treated as querystring field separator enables pa… |
| CVE-2024-51454 | 6.1 | 16.4 | IBM | Engineering Workflow Management | CWE-644 | IBM Engineering Lifecycle Management - Engineering Workflow Management is imp… |
| CVE-2026-4110 | 6.1 | 16.4 | Unknown | ultimate-woocommerce-auction-pro | — | Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_auctions_bi… |
| CVE-2026-4259 | 7.1 | 16.3 | Unknown | ultimate-woocommerce-auction-pro | CWE-79 | Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_manage_auct… |
| CVE-2026-9029 | 5.4 | 16.2 | Grafana | Grafana OSS | CWE-79 | Stored XSS in the Geomap panel tile-layer attribution |
| CVE-2023-33854 | 5.3 | 16.1 | IBM | Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data | CWE-294 | Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Wareh… |
| CVE-2026-47155 | 6.5 | 16.0 | vllm-project | vllm | CWE-345 | vLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned c… |
| CVE-2026-48167 | 6.4 | 15.7 | filamentphp | filament | CWE-79 | Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS |
| CVE-2026-49241 | 8.7 | 15.1 | angular | angular | CWE-79 | Angular: Multiple Remote Code Execution Vulnerabilities in Angular Language S… |
| CVE-2026-6062 | 6.4 | 14.8 | Mattermost | Mattermost | CWE-639 | IDOR in Jira plugin subscription edit endpoint |
| CVE-2026-47241 | 2.1 | 14.7 | ruby | net-imap | CWE-162 | Net::IMAP: Denial of Service via incomplete raw argument validation |
| CVE-2026-50168 | 8.8 | 14.5 | angular | angular | CWE-346 | Angular: URL Parser Differential in @angular/platform-server leading to SSRF … |
| CVE-2026-8059 | 6.1 | 14.3 | IBM | Datacap | CWE-79 | Multiple Vulnerabilities in IBM Datacap |
| CVE-2025-33128 | 5.4 | 13.7 | IBM | Engineering Workflow Management | CWE-79 | IBM Engineering Lifecycle Management - Engineering Workflow Management is imp… |
| CVE-2026-11372 | 5.4 | 13.7 | IBM | TRIRIGA Application Platform | CWE-79 | IBM TRIRIGA Cross-Site Scripting Vulnerability |
| CVE-2026-11746 | 9.4 | 13.4 | LY Corporation | Central Dogma | CWE-798 | A vulnerability has been identified in centraldogma-server versions prior to … |
| CVE-2026-54298 | 6.1 | 13.3 | withastro | astro | CWE-79 | Astro: XSS via Unescaped Attribute Names in Spread Props |
| CVE-2026-50169 | 5.7 | 13.3 | angular | angular | CWE-200 | Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities |
| CVE-2026-11745 | 8.8 | 12.2 | LY Corporation | Central Dogma | CWE-322 | A vulnerability has been identified in centraldogma-server-mirror-git version… |
| CVE-2026-55599 | 5.8 | 11.4 | phpseclib | phpseclib | CWE-918 | phpseclib: X.509 certificate validation sends attacker-controlled outbound re… |
| CVE-2023-45795 | 7.8 | 11.0 | Pilz | PMI v8xx | CWE-79 | Pilz: XSS vulnerability in Pilz PASvisu and PMI v8xx |
| CVE-2026-55443 | 5.5 | 11.1 | langchain-ai | langchain | CWE-22 | LangChain: Path traversal and sandbox escape in LangChain file-search middlew… |
| CVE-2026-50184 | 5.7 | 10.8 | angular | angular | CWE-200 | Angular: Request Credential & Cache Policy Stripping in Angular Service Worker |
| CVE-2026-10530 | 5.3 | 10.3 | Unknown | Pie Register | — | Pie Register < 3.8.4.10 - Unauthenticated Email Verification Bypass via Predi… |
| CVE-2026-41047 | 6.9 | 9.7 | presire | qSnapper | CWE-306 | Information leak via “diff” methods in qSnapper |
| CVE-2026-8636 | 7.5 | 9.6 | IBM | Datacap | CWE-316 | Multiple Vulnerabilities in IBM Datacap |
| CVE-2026-41046 | 7.3 | 8.1 | presire | qSnapper | CWE-23 | path traversal via `config` parameter in qSnapper |
| CVE-2026-41049 | 8.4 | 7.9 | presire | qSnapper | CWE-863 | Caching of Authentication allows Authentication Bypass between users in qSnapper |
| CVE-2026-41048 | 8.4 | 7.4 | presire | qSnapper | CWE-863 | Caching of Authentication allows Authentication Bypass in qSnapper |
| CVE-2026-6645 | 7.3 | 7.4 | PaperCut | Print Deploy | CWE-427 | Insecure Search Path Vulnerability in PaperCut Print Deploy Client for Windows |
| CVE-2026-54289 | 4.8 | 7.4 | honojs | hono | CWE-348 | Hono: Lambda@Edge adapter keeps only the last value of a repeated request hea… |
| CVE-2026-12602 | 8.8 | 6.9 | Aruba | ArubaSign | CWE-276 | Incorrect permissions in ArubaSign by Aruba |
| CVE-2026-44274 | 7.8 | 6.9 | Dell | Wyse Management Suite (WMS) | CWE-59 | Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Impr… |
| CVE-2026-49461 | 6.9 | 6.9 | py-pdf | pypdf | CWE-400 | pypdf: Possible large memory usage for form XObjects during text extraction |
| CVE-2026-54530 | 6.9 | 6.9 | py-pdf | pypdf | CWE-835 | pypdf: Possible infinite loop when retrieving fonts for layout-mode text extr… |
| CVE-2026-54531 | 6.9 | 6.9 | py-pdf | pypdf | CWE-835 | pypdf: Possible infinite loop when processing outlines/bookmarks in writer |
| CVE-2026-49460 | 5.1 | 6.0 | py-pdf | pypdf | CWE-407 | pypdf: Inefficient decoding of FlateDecode PNG predictor streams |
| CVE-2026-7859 | 5.3 | 5.6 | Unknown | Motors | CWE-862 | Motors Car Dealership & Classified Listings < 1.4.110 - Unauthenticated Post-… |
| CVE-2026-41045 | 7.0 | 5.3 | presire | qSnapper | CWE-367 | Weak polkit authentication check in qSnapper |
| CVE-2026-54651 | 6.9 | 5.2 | py-pdf | pypdf | CWE-835 | pypdf: Possible infinite loop when processing threads/articles in writer |
| CVE-2026-10645 | 5.5 | 5.1 | zephyrproject | zephyr | CWE-125 | Out-of-bounds read in Zephyr ext2 directory entry traversal from a crafted fi… |
| CVE-2026-53655 | 6.9 | 5.0 | isaacs | node-tar | CWE-436 | node-tar applies PAX size override to intermediary GNU long-name/long-link he… |
| CVE-2026-44273 | 4.4 | 4.6 | Dell | Wyse Management Suite (WMS) | CWE-1392 | Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use o… |
| CVE-2026-53663 | 3.1 | 4.2 | remix-run | react-router | CWE-352 | React Router: `handleDocumentRequest` CSRF check covers `POST` only; PUT/PATC… |
| CVE-2026-54288 | 6.5 | 4.2 | honojs | hono | CWE-345 | Hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Co… |
| CVE-2026-12249 | 9.0 | 3.8 | — | adsys | CWE-348 | Canonical ADSys Trust Store Poisoning via Plaintext HTTP Certificate Auto-Enr… |
| CVE-2026-56109 | 7.0 | 3.4 | alsa-project | alsa-lib | CWE-415 | ALSA Library < 1.2.16.1 Double-Free via parse_def() in conf.c |
| CVE-2026-47242 | 5.8 | 2.9 | ruby | net-imap | CWE-77 | Net::IMAP: Command Injection via ID command argument |
| CVE-2026-54266 | 8.8 | 2.6 | angular | angular | CWE-328 | Angular: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cros… |
| CVE-2026-49356 | 3.6 | 2.5 | babel | babel | CWE-22 | Babel: Arbitrary File Read via sourceMappingURL Comment in @babel/core |
| CVE-2026-54099 | 8.8 | 1.4 | Red Hat | Red Hat OpenShift for Windows Containers 10.22 | CWE-269 | Windows-machine-config-operator: windows-machine-config-operator: wicd csr ex… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-06-22 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.