boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, June 23, 2026 · all times UTC← 2026-06-22 · archive · 2026-06-24 →

Security Box Score — June 23, 2026

257 CVEs published, led by nocodb (29).

257 CVEs published June 23, 2026: 28 critical, 98 high, 117 medium, 11 low; 3 in the KEV catalog at press time; 57 with a public exploit reference; 3 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 232 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published565110112——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

468 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux10010678466831411120.27.8.0013-127 ▼
google68485983454293297760.78.1.0023+668 ▲
microsoft220756585201726286192.57.8.0045+60 ▲
red hat911859758912200.06.5.0029+81 ▲
apple146612142288710.65.7.0019-1 ▼
canonical2161465000.05.5.0010+2 ▲
freebsd070520000.07.8.0020-7 ▼
suse461410000.08.6.0029+2 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco92165100561047.67.2.0438+4 ▲
netgear171700161000.04.3.0024+17 ▲
palo alto networks911127113218.25.9.0022+7 ▲
ubiquiti81174003327.39.9.0083+6 ▲
ivanti49450025555.68.8.5187+2 ▲
checkpoint3915303111.17.5.0410+3 ▲
fortinet29432028333.38.3.0076+1 ▲
f56843104112.58.9.0225+4 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache9212618445583310.86.5.0051+83 ▲
mozilla49551118260900.07.3.0026+44 ▲
gitlab1118041224211.14.8.0024+11 ▲
docker470520000.08.2.0016+1 ▲
drupal0511304120.05.1.0026-3 ▼
github021100000.08.1.03470
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2422701321161842720.78.8.0040+242 ▲
adobe1321344517721921.55.5.0021+132 ▲
ibm32811935270600.07.5.0031+32 ▲
progress591710600.07.5.0036+1 ▲
solarwinds36231010466.77.8.6082+3 ▲
veeam142200100.09.0.0052+1 ▲
zohocorp131110000.08.4.01700
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5 ▲
d-link9110425300.05.5.0058+8 ▲
siemens780440000.07.5.0020+6 ▲
rockwell automation771510000.08.7.0030+7 ▲
abb660420000.07.2.0018+6 ▲
moxa550320000.07.0.0029+5 ▲
dahua330111000.06.9.0036+3 ▲
mitsubishi electric330300000.08.7.0064+3 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7273231391000.06.5.0024+72 ▲
openclaw61670352210000.07.0.0021+61 ▲
sourcecodester3759002534000.02.1.0026+36 ▲
themerex585855300000.08.1.0043+58 ▲
edimax556033023100.07.4.00700
dell3149124240212.07.0.0017+19 ▲
concrete cms2461111321000.06.2.0015-42 ▼
open ises044221210000.07.1.0021-37 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9991100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-34910.874799.710.0
CVE-2026-34908.851999.710.0
CVE-2026-50751.837799.79.3
CVE-2026-48907.781099.510.0
CVE-2026-34909.639099.210.0
CVE-2026-49160.538398.97.5
CVE-2026-10523.518798.99.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9991KEV
CVE-2026-3491010.0.8747KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.7810KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4508710.0.1296
CVE-2026-5375310.0.0290
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
Most disclosures (vendor)
VendorCVEs
google836
linux514
oracle267
microsoft226
adobe132
red hat123
apache104
ibm81
spring73
openclaw67
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco10
apple7
google6
ivanti5
solarwinds4
berriai3
fortinet3
smartertools3
ubiquiti3
Most-affected ecosystems
EcosystemAdvisories
Maven43
Packagist22
PyPI10
npm3
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2025-48595Google0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-28318SolarWinds0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
CVE-2026-34910Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171679
CVE-2021-27102n/a2021-11-171679
CVE-2021-27101n/a2021-11-171679
CVE-2021-27103n/a2021-11-171679
CVE-2021-21017Adobe2021-11-171679
CVE-2021-28550Adobe2021-11-171679
CVE-2021-42013Apache Software Foundation2021-11-171679
CVE-2021-41773Apache Software Foundation2021-11-171679
CVE-2021-30858Apple2021-11-171679
CVE-2021-30860Apple2021-11-171679

Transactions

EXPLOIT PUBLISHED — open-webui: 14 CVEs (CVE-2026-54006, CVE-2026-54007, CVE-2026-54008, CVE-2026-54009, CVE-2026-54010, CVE-2026-54011, CVE-2026-54012, CVE-2026-54013, CVE-2026-54014, CVE-2026-54015, CVE-2026-54016, CVE-2026-54018, CVE-2026-54019, CVE-2026-54022). Public exploit references added.

EXPLOIT PUBLISHED — langflow-ai langflow: 8 CVEs (CVE-2026-33760, CVE-2026-42867, CVE-2026-48519, CVE-2026-48520, CVE-2026-55423, CVE-2026-55446, CVE-2026-55447, CVE-2026-55450). Public exploit references added.

EXPLOIT PUBLISHED — caddyserver caddy: 5 CVEs (CVE-2026-45135, CVE-2026-45692, CVE-2026-52844, CVE-2026-52845, CVE-2026-52846). Public exploit references added.

EXPLOIT PUBLISHED — denoland deno: 5 CVEs (CVE-2026-44726, CVE-2026-49401, CVE-2026-49402, CVE-2026-49406, CVE-2026-49411). Public exploit references added.

EXPLOIT PUBLISHED — traefik: 5 CVEs (CVE-2026-48020, CVE-2026-48491, CVE-2026-53622, CVE-2026-54761, CVE-2026-54762). Public exploit references added.

EXPLOIT PUBLISHED — Flowise: 3 CVEs (CVE-2025-71337, CVE-2026-56274, CVE-2026-56275). Public exploit references added.

EXPLOIT PUBLISHED — Ubiquiti Inc UniFi OS Server: 3 CVEs (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2025-55639. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-4983 (Eclipse Foundation Eclipse Open VSX). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-50023 (yt-dlp). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-50193 (FasterXML jackson-databind). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-50221 (OpenStack Swift). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54317 (home-assistant core). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54318 (home-assistant core). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54512 (FasterXML jackson-databind). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-55249 (rtk-ai rtk). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-55653 (Red Hat Enterprise Linux 10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-55654 (Red Hat Enterprise Linux 10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56968 (GNU SASL). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-57053 (GNU libidn). Public exploit reference added.

DUE DATE PASSED — CVE-2026-42271 (BerriAI LiteLLM). CISA remediation deadline was June 22, 2026; still in catalog.

Yesterday's Results

How to read these box scores · glossary

257 CVEs published. 25 box scores, 232 table rows — nothing truncated.

Ubiquiti UniFi OS
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .8747   99.7   YES
AFFECTED
  Product          Versions     Fixed
  UniFi OS Server  unspecified  —
  UDM              unspecified  —
  UDM-Pro          unspecified  —
  UDM-SE           unspecified  —
  UDM-Pro-Max      unspecified  —
  UDM-Beast        unspecified  —
  EFG              unspecified  —
  UDW              unspecified  —
  UDR              unspecified  —
  UDR7             unspecified  —
  + 21 more
TIMELINE
  Mar 31  Reserved by CNA
  Jun 23  Public exploit reference published
  Jun 23  Added to CISA KEV, due Jun 26
  Jun 23  Published (CNA: hackerone)
CWE-20 · CNA: hackerone · CVSS v3.1 · 3 references · NVD status: Analyzed · KEV due June 26, 2026
Ubiquiti UniFi OS
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .8519   99.7   YES
AFFECTED
  Product          Versions     Fixed
  UniFi OS Server  unspecified  —
  UDM              unspecified  —
  UDM-Pro          unspecified  —
  UDM-SE           unspecified  —
  UDM-Pro-Max      unspecified  —
  UDM-Beast        unspecified  —
  EFG              unspecified  —
  UDW              unspecified  —
  UDR              unspecified  —
  UDR7             unspecified  —
  + 21 more
TIMELINE
  Mar 31  Reserved by CNA
  Jun 23  Public exploit reference published
  Jun 23  Added to CISA KEV, due Jun 26
  Jun 23  Published (CNA: hackerone)
CWE-284 · CNA: hackerone · CVSS v3.1 · 3 references · NVD status: Analyzed · KEV due June 26, 2026
Ubiquiti UniFi OS
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .6390   99.2   YES
AFFECTED
  Product          Versions     Fixed
  UniFi OS Server  unspecified  —
  Express          unspecified  —
  UDM              unspecified  —
  UDM-Pro          unspecified  —
  UDM-SE           unspecified  —
  UDM-Pro-Max      unspecified  —
  UDM-Beast        unspecified  —
  EFG              unspecified  —
  UDW              unspecified  —
  UDR              unspecified  —
  + 22 more
TIMELINE
  Mar 31  Reserved by CNA
  Jun 23  Public exploit reference published
  Jun 23  Added to CISA KEV, due Jun 26
  Jun 23  Published (CNA: hackerone)
CWE-22 · CNA: hackerone · CVSS v3.1 · 3 references · NVD status: Analyzed · KEV due June 26, 2026
Flowise - Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccess
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0752   94.0     —
AFFECTED
  Product             Versions     Fixed
  Flowise             unspecified  3.1.2
  Flowise Components  unspecified  3.1.2
TIMELINE
  Jun 20  Reserved by CNA
  Jun 23  Public exploit reference published
  Jun 23  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Analyzed
unclecode crawl4ai — Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0290   85.9     —
AFFECTED
  Product   Versions   Fixed
  crawl4ai  < 0.8.7 –  —
TIMELINE
  Jun 10  Reserved by CNA
  Jun 23  Published (CNA: GitHub_M)
CWE-94, CWE-913 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Analyzed
zohocorp manageengine_adselfservice_plus — Account Takeover via Predictable SSO Ticket Generation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  C  H  H  H    9.0   .0252   83.6     —
AFFECTED
  Product                             Versions     Fixed
  manageengine_adselfservice_plus     unspecified  —
  manageengine_recovery_manager_plus  unspecified  —
  manageengine_m365_manager_plus      unspecified  —
  manageengine_adaudit_plus           unspecified  —
TIMELINE
  Jun 5   Reserved by CNA
  Jun 23  Published (CNA: Zohocorp)
CWE-287, CWE-330, CWE-340 · CNA: Zohocorp · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
FOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    9.4   .0191   78.1     —
AFFECTED
  Product      Versions   Fixed
  FOSSBilling  < 0.8.0 –  —
TIMELINE
  Feb 27  Reserved by CNA
  Jun 23  Published (CNA: GitHub_M)
CWE-1336 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Deferred
LobeHub: Unauthenticated SSRF in `/webapi/proxy`
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  L  H    9.0   .0183   77.2     —
AFFECTED
  Product  Versions    Fixed
  lobehub  < 2.1.57 –  —
TIMELINE
  Jun 11  Reserved by CNA
  Jun 23  Published (CNA: GitHub_M)
CWE-918 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Deferred
unclecode crawl4ai — Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0158   73.6     —
AFFECTED
  Product   Versions   Fixed
  crawl4ai  < 0.8.9 –  —
TIMELINE
  Jun 10  Reserved by CNA
  Jun 23  Published (CNA: GitHub_M)
CWE-918 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Analyzed
NetComm NF20MESH < R6B032 Authenticated RCE via OS Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0127   67.5     —
AFFECTED
  Product   Versions     Fixed
  NF20MESH  unspecified  —
TIMELINE
  Mar 31  Reserved by CNA
  Jun 23  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
langflow-ai langflow — Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  N  H    9.3   .0119   65.6     —
AFFECTED
  Product   Versions   Fixed
  langflow  < 1.9.1 –  —
TIMELINE
  Jun 16  Reserved by CNA
  Jun 23  Public exploit reference published
  Jun 23  Published (CNA: GitHub_M)
CWE-200, CWE-306, CWE-400 · CNA: GitHub_M · CVSS v3.1 · 2 references · NVD status: Analyzed
picklescan - Remote Code Execution via Unblocked Standard Library Modules
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0115   64.3     —
AFFECTED
  Product     Versions     Fixed
  picklescan  unspecified  1.0.4
TIMELINE
  Jun 20  Reserved by CNA
  Jun 23  Published (CNA: VulnCheck)
CWE-184 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
elixir-plug plug — Plug: quadratic-time decoding of nested query/body parameters enables denial of service
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0095   58.5     —
AFFECTED
  Product  Versions                                    Fixed
  plug     1.15.0 –                                    —
  plug     712b875d3442c765d8d37e546ffd5ad9f8afcc55 –  c317d08fdcf96e17931f7419275b2b8c4bf3e951
TIMELINE
  Jun 16  Reserved by CNA
  Jun 23  Published (CNA: EEF)
CWE-407 · CNA: EEF · CVSS v4.0 · 8 references · NVD status: Deferred
Crawl4AI - Arbitrary File Write via output_path Symlink and TOCTOU
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   N   H   H   H    9.2   .0091   57.3     —
AFFECTED
  Product   Versions     Fixed
  Crawl4AI  unspecified  0.8.8
TIMELINE
  Jun 19  Reserved by CNA
  Jun 23  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Analyzed
FasterXML jackson-databind — jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0089   56.7     —
AFFECTED
  Product           Versions               Fixed
  jackson-databind  >= 2.10.0, < 2.18.8 –  —
TIMELINE
  Jun 15  Reserved by CNA
  Jun 23  Published (CNA: GitHub_M)
CWE-184 · CNA: GitHub_M · CVSS v3.1 · 29 references · NVD status: Modified
ImageMagick - Command Injection via SVG Decoder
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   N   H   H   H    9.2   .0088   56.5     —
AFFECTED
  Product      Versions     Fixed
  ImageMagick  unspecified  7.1.2-15
  ImageMagick  unspecified  6.9.13-40
TIMELINE
  Jun 21  Reserved by CNA
  Jun 23  Published (CNA: VulnCheck)
CWE-116, CWE-78 · CNA: VulnCheck · CVSS v4.0 · 6 references · NVD status: Modified
FasterXML jackson-databind — jackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows arbitrary class instantiation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0087   56.2     —
AFFECTED
  Product           Versions               Fixed
  jackson-databind  >= 2.10.0, < 2.18.8 –  —
TIMELINE
  Jun 15  Reserved by CNA
  Jun 23  Public exploit reference published
  Jun 23  Published (CNA: GitHub_M)
CWE-184, CWE-502 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Analyzed
n/a expr-eval — All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attac…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0087   55.9     —
AFFECTED
  Product                    Versions     Fixed
  expr-eval                  unspecified  —
  org.webjars.npm:expr-eval  unspecified  —
TIMELINE
  Jun 22  Reserved by CNA
  Jun 23  Published (CNA: snyk)
CWE-94 · CNA: snyk · CVSS v4.0 · 4 references · NVD status: Deferred
NetComm NF20MESH < R6B032 Hardcoded AES Key Authentication Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0081   54.0     —
AFFECTED
  Product   Versions     Fixed
  NF20MESH  unspecified  —
TIMELINE
  Mar 31  Reserved by CNA
  Jun 23  Published (CNA: VulnCheck)
CWE-321 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
langflow-ai langflow — Langflow: Unauthenticated RCE in Shareable Playgrounds
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  H  H    9.6   .0078   53.3     —
AFFECTED
  Product   Versions   Fixed
  langflow  < 1.9.2 –  —
TIMELINE
  May 21  Reserved by CNA
  Jun 23  Public exploit reference published
  Jun 23  Published (CNA: GitHub_M)
CWE-94 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Analyzed
Traefik - Denial of Service via HTTP/2 Request Handling
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0077   53.0     —
AFFECTED
  Product  Versions       Fixed
  Traefik  unspecified    2.10.5
  Traefik  3.0.0-beta1 –  3.0.0-beta4
TIMELINE
  Jun 22  Reserved by CNA
  Jun 23  Published (CNA: VulnCheck)
CWE-400, CWE-770 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Analyzed
Traefik StripPrefix Route-Level Auth Bypass via Path Normalization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   N    7.8   .0076   52.4     —
AFFECTED
  Product  Versions                  Fixed
  traefik  >= 3.7.0-ea.1, < 3.7.3 –  —
TIMELINE
  May 20  Reserved by CNA
  Jun 23  Public exploit reference published
  Jun 23  Published (CNA: GitHub_M)
CWE-288, CWE-22 · CNA: GitHub_M · CVSS v4.0 · 7 references · NVD status: Modified
Python Software Foundation CPython — tarfile extraction filter bypass allows escaping the destination directory
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   N    7.8   .0075   52.2     —
AFFECTED
  Product  Versions     Fixed
  CPython  unspecified  —
TIMELINE
  Jun 10  Reserved by CNA
  Jun 23  Published (CNA: PSF)
CWE-22, CWE-59 · CNA: PSF · CVSS v4.0 · 10 references · NVD status: Awaiting Analysis
Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persi…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0075   52.0     —
AFFECTED
  Product              Versions  Fixed
  Spring Statemachine  4.0.0 –   —
TIMELINE
  Apr 22  Reserved by CNA
  Jun 23  Published (CNA: vmware)
CWE-502 · CNA: vmware · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
n/a n/a — An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0072   51.2     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 23  Published (CNA: mitre)
CWE-502 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2025-610187.549.7n/an/aCWE-89An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v…
CVE-2025-610207.549.7n/an/aCWE-89An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource …
CVE-2025-610237.549.7n/an/aCWE-89An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 …
CVE-2025-610287.549.7n/an/aCWE-89An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.1…
CVE-2026-451358.149.4caddyservercaddyCWE-20Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PH…
CVE-2026-500239.649.0yt-dlpyt-dlpCWE-641yt-dlp: Dangerous file type creation via insufficient filename sanitization (…
CVE-2026-554479.648.9langflow-ailangflowCWE-61Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
CVE-2026-349168.848.4Revive AdserverRevive AdserverCWE-94A missing validation of user input when saving delivery limitations in Revive…
CVE-2026-528447.547.0caddyservercaddyCWE-22Caddy: Windows `file_server` path authorization bypass via encoded backslash
CVE-2026-501936.346.8FasterXMLjackson-databindCWE-400jackson-databind: Deeply nested JsonNode throws StackOverflowError for toStri…
CVE-2025-713417.646.7picklescanpicklescanCWE-502picklescan - Remote Code Execution via Undetected profile.Profile.runctx
CVE-2026-130078.746.5tenableTenable Identity ExposureCWE-306Insecure Public Caching on REST API Endpoints in Tenable Identity Exposure
CVE-2026-526736.546.0n/an/aCWE-89SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remote atta…
CVE-2026-449598.845.3ReviveAdserverCWE-94A missing validation of user input exists when saving delivery limitations in…
CVE-2025-713827.145.3ArtifexSoftwaremupdfCWE-674MuPDF < 1.27.0-rc1 Stack Exhaustion DoS via EPUB CSS Rendering
CVE-2026-554467.545.1langflow-ailangflowCWE-400Langflow: Unauthenticated DoS through multipart form boundary file upload
CVE-2026-117725.143.8DRIMODRIMO CMSCWE-79Reflected XSS in DRIMO CMS
CVE-2026-552498.843.6rtk-airtkCWE-78@rtk-ai/rtk-rewrite: OpenClaw Rewrite Plugin Command Injection via execSync T…
CVE-2026-105218.643.6MB connect linembCONNECT24CWE-425Authenticated unintended access to critical program parameters
CVE-2026-543098.843.3n8n-ion8nCWE-306n8n: n8n MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control S…
CVE-2026-543146.343.3n8n-ion8nCWE-409n8n: Denial of Service via ZIP decompression in webhook workflow
CVE-2026-543106.543.2n8n-ion8nCWE-89n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes
CVE-2025-713707.643.2picklescanpicklescanCWE-502picklescan - Remote Code Execution via torch.jit.unsupported_tensor_ops.execW…
CVE-2026-545889.643.2poweradminpoweradminCWE-20Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, …
CVE-2026-494656.043.0n8n-ion8nCWE-22n8n: Git Node Clone and Push Operations Bypass File Sandbox
CVE-2026-447919.442.8n8n-ion8nCWE-1321n8n: XML Node Prototype Pollution Patch Bypass
CVE-2026-118079.642.5Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8CWE-862Eda-server: websocket missing authorization allows credential theft via activ…
CVE-2026-447909.442.4n8n-ion8nCWE-88n8n: Arbitrary File Read via Git Node
CVE-2026-447899.442.4n8n-ion8nCWE-1321n8n: HTTP Request Node Pagination Prototype Pollution to RCE
CVE-2026-97339.141.9HAYAJOMojolicious::Plugin::Web::Auth::OAuth2CWE-338Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an…
CVE-2026-562228.641.8CapgoCapgoCWE-639Capgo - Cross-Organization App Takeover via Mismatched org_id and app_id in /…
CVE-2025-556396.541.2n/an/aCWE-476GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the …
CVE-2026-2760410.041.1FOSSBillingFOSSBillingCWE-200FOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Ac…
CVE-2025-610197.540.4n/an/aCWE-89An issue in the sqlo_key_part_best component of openlink virtuoso-opensource …
CVE-2025-610217.540.4n/an/aCWE-89An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensou…
CVE-2025-610227.540.4n/an/aCWE-89An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v…
CVE-2025-610247.540.4n/an/aCWE-89An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7…
CVE-2025-610257.540.4n/an/aCWE-89An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.1…
CVE-2025-610277.540.4n/an/aCWE-89An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 …
CVE-2025-610297.540.4n/an/aCWE-89An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 …
CVE-2026-337608.840.2langflow-ailangflowCWE-639Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpo…
CVE-2026-562488.739.8Cap-gocapgoCWE-400Capgo - Unauthenticated Denial-of-Service via audit_logs RLS Policy
CVE-2026-428676.538.3langflow-ailangflowCWE-22Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint
CVE-2026-543166.038.3anthropicsclaude-codeCWE-183Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domai…
CVE-2026-505749.638.2yt-dlpyt-dlpCWE-74yt-dlp: Arbitrary code execution via manifest downloads with aria2c
CVE-2026-563228.737.8CapgoCapgoCWE-200Capgo - Information Disclosure via Unauthenticated /updates defaultChannel Pa…
CVE-2026-543246.537.6daytonaiodaytonaCWE-639Daytona: Cross-tenant data leak in notification WebSocket gateway via unverif…
CVE-2026-561158.737.4garybowersbootimusCWE-862Bootimus 0.1.70 Broken Access Control via JWTMiddleware Authorization Bypass
CVE-2026-545165.337.1FasterXMLjackson-databindCWE-915jackson-databind: Renamed @JsonIgnore'd setters can deserialize via private f…
CVE-2026-119728.236.8Python Software FoundationCPythonCWE-252tarfile opened in streaming mode mishandles EOF
CVE-2026-494028.136.8denolanddenoCWE-78Deno: Command Injection via spawnSync & spawn on Windows
CVE-2026-473765.136.7nocodbnocodbCWE-79NocoDB: Reflected Cross-Site Scripting via Password Reset Token
CVE-2026-563716.936.4ImageMagickImageMagickCWE-401ImageMagick - Memory Leak in TXT File Processing via Texture Attribute
CVE-2026-485206.136.2langflow-ailangflowCWE-73Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read
CVE-2026-473855.336.2nocodbnocodbCWE-22NocoDB: Path Traversal via SQLite Source Filename
CVE-2026-547625.936.0traefiktraefikCWE-636Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolut…
CVE-2026-537547.535.9unclecodecrawl4aiCWE-918Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT6…
CVE-2026-536629.635.7immich-appimmichCWE-79immich: One-click account takeover via XSS in login page continue redirect
CVE-2025-713657.635.7picklescanpicklescanCWE-502picklescan - Arbitrary Code Execution via numpy.f2py.crackfortran.myeval Dete…
CVE-2025-713767.635.7picklescanpicklescanCWE-502picklescan - Arbitrary Code Execution via Undetected idlelib.autocomplete.Aut…
CVE-2026-81638.835.6UnknownInfility Global—Infility Global < 2.15.19 - Subscriber+ SQL Injection via order Parameter
CVE-2026-473816.935.6nocodbnocodbCWE-290NocoDB: Cross-Workspace Integration Use in Connection Test
CVE-2026-542579.335.4electronelectronCWE-120Electron: Buffer performs incorrect byte length calculations resulting in hea…
CVE-2026-473796.935.4nocodbnocodbCWE-200NocoDB: Plaintext Password Comparison in Shared Views
CVE-2025-713378.734.9FlowiseFlowiseCWE-620Flowise - Unverified Email Change via Account Profile Endpoint
CVE-2026-567858.434.9FlatPressFlatPressCWE-79FlatPress - Stored Cross-Site Scripting via Unescaped Comment and Contact For…
CVE-2026-473845.334.8nocodbnocodbCWE-89NocoDB: SQL Injection via Column Title in Bulk GroupBy
CVE-2026-540108.334.7open-webuiopen-webuiCWE-284Open WebUI: Forged chat-file link allows cross-user file read and deletion
CVE-2026-567626.934.5HonoHonoCWE-20Hono - Missing Cookie Name Validation in setCookie()
CVE-2026-556543.734.3Red HatRed Hat Enterprise Linux 10CWE-125Openssh: heap out-of-bounds read in red hat enterprise linux versions of open…
CVE-2026-562258.734.0CapgoCapgoCWE-269Capgo - Authorization Bypass in API Key Management via App-Limited Keys
CVE-2026-449610.034.0ReviveAdserverCWE-287The XML‑RPC API addUser method has a validation bypass introduced in the fix …
CVE-2026-465516.533.9nocodbnocodbCWE-770NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Servi…
CVE-2026-83797.533.5UnknownFrontend File Manager Plugin—Frontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Download
CVE-2026-472796.933.4nocodbnocodbCWE-284NocoDB: Hidden LTAR Column Exposure in Public Shared-View Relation Endpoints
CVE-2026-473786.933.4nocodbnocodbCWE-639NocoDB: Hidden Column Exposure in Public Shared View Endpoints
CVE-2026-539316.933.4nocodbnocodbCWE-441NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint
CVE-2026-539266.333.4nocodbnocodbCWE-613NocoDB: OAuth Tokens Persist Through Security Events
CVE-2026-473775.133.4nocodbnocodbCWE-601NocoDB: Open Redirect via Hash Fragment in hashRedirect Plugin
CVE-2026-465532.133.4nocodbnocodbCWE-770NocoDB: Attachment Size Limit Bypass via Upload-by-URL
CVE-2026-566957.133.0HKUDSOpenHarnessCWE-862OpenHarness - Cross-Session Disclosure via /resume and /summary Commands
CVE-2026-562346.932.9CapgoCapgoCWE-307Capgo - Password Spraying via Public-Key Accessible Credential Validation End…
CVE-2026-129695.332.8Red HatRed Hat Enterprise Linux 10CWE-125Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes …
CVE-2026-543217.032.7daytonaiodaytonaCWE-613Daytona: Public sandbox previews remain accessible for up to one hour after b…
CVE-2026-473878.432.5nocodbnocodbCWE-79NocoDB: Stored Cross-Site Scripting via Form View Redirect URL
CVE-2026-473837.432.5nocodbnocodbCWE-79NocoDB: Stored Cross-Site Scripting via Row Comments
CVE-2026-543127.232.4n8n-ion8nCWE-1321n8n: Microsoft SQL Node Prototype Pollution
CVE-2026-567017.132.4GravGravCWE-611Grav - XML External Entity Injection via SVG Upload
CVE-2026-539295.132.5nocodbnocodbCWE-79NocoDB: Stored Cross-Site Scripting via Secure Attachment
CVE-2026-536227.832.3traefiktraefikCWE-288Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and …
CVE-2026-118206.532.3Red HatRed Hat Enterprise Linux 10CWE-532Community.general: community.general nexmo — api credentials exposed in get u…
CVE-2026-78426.831.9UnknownInfility Global—Infility Global < 2.15.20 - Editor+ SQL Injection via orderby Parameter
CVE-2026-543116.031.9n8n-ion8nCWE-488n8n: Merge Node SQL Mode Prototype Pollution
CVE-2026-449560.031.7ReviveAdserverCWE-79Low‑privileged users could use their Full Name as a vector for a stored XSS a…
CVE-2026-449600.031.7ReviveAdserverCWE-79A stored XSS can be exploited by leveraging the usernames as an attack vector…
CVE-2026-349148.331.6ReviveAdserverCWE-89A missing sanitisation of user input in the zone-include.php script of Revive…
CVE-2026-539275.131.6nocodbnocodbCWE-918NocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL
CVE-2026-539305.131.6nocodbnocodbCWE-918NocoDB: Server-Side Request Forgery via Base Migration URL
CVE-2026-447928.931.5n8n-ion8nCWE-89n8n: Source Control Pull SQL Injection
CVE-2026-235137.131.5FOSSBillingFOSSBillingCWE-863FOSSBilling: Broken Authorization in Client Transaction and Order Listings
CVE-2026-562438.631.4CapgoCapgoCWE-288Capgo - Hashed API Key Enforcement Bypass via PostgREST/RLS Plane
CVE-2026-543078.531.3n8n-ion8nCWE-863n8n: Credential Exfiltration via Permission Bypass
CVE-2026-540187.731.3open-webuiopen-webuiCWE-918Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects
CVE-2026-540196.531.3open-webuiopen-webuiCWE-862Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode
CVE-2026-494447.131.3n8n-ion8nCWE-20n8n: Python sandbox escape
CVE-2026-545175.331.2FasterXMLjackson-databindCWE-863jackson-databind: @JsonView bypass for setterless creator properties
CVE-2026-543047.131.0n8n-ion8nCWE-200n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host
CVE-2026-540096.531.0open-webuiopen-webuiCWE-639Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field
CVE-2026-349174.330.7ReviveAdserverCWE-287Low‑privileged session IDs generated for the web admin console could be reuse…
CVE-2026-564027.130.3nanocoainanoclawCWE-862NanoClaw < 2.1.17 - Privilege Escalation via Unverified Approval Response Han…
CVE-2026-473756.030.3nocodbnocodbCWE-89NocoDB: Postgres SQL Injection in Formula `ARRAYSORT`
CVE-2026-476936.930.2poweradminpoweradminCWE-1236Poweradmin: CSV Injection in log export endpoints allows formula execution in…
CVE-2026-106096.830.2Red HatLogging Subsystem for Red Hat OpenShiftCWE-862Openshift/cluster-logging-operator: cluster logging operator creates and forw…
CVE-2026-543058.930.1n8n-ion8nCWE-200n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
CVE-2026-566965.329.7HKUDSOpenHarnessCWE-862OpenHarness - Prompt Injection via /issue and /pr_comments Slash Commands
CVE-2026-547616.029.5traefiktraefikCWE-284Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute o…
CVE-2026-545145.329.4FasterXMLjackson-databindCWE-918jackson-databind: InetSocketAddress deserialization triggers eager DNS resolu…
CVE-2026-557365.929.3ash-projectashCWE-915Private action arguments can be set by user input in Ash
CVE-2026-107118.829.2AKIN Software Computer Import Export Industry and Trade Ltd.CafePlusCWE-306RCE in Akınsoft's CafePlus
CVE-2025-621807.129.1PegasystemsPega InfinityCWE-639Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an autho…
CVE-2025-641055.129.1FOSSBillingFOSSBillingCWE-639FOSSBilling: IDOR Vulnerability in Support Ticket Creation
CVE-2026-567848.629.0openremoteopenremoteCWE-639OpenRemote < 1.25.0 IDOR via Bulk Alarm Deletion Endpoint
CVE-2026-540144.328.7open-webuiopen-webuiCWE-22Open WebUI: Sibling-Prefix Path Traversal via /cache/{path} in open-webui/ope…
CVE-2026-545186.528.1FasterXMLjackson-databindCWE-863jackson-databind: @JsonView bypass for unwrapped creator parameters in jackso…
CVE-2026-543208.427.8daytonaiodaytonaCWE-287Daytona: Cross-tenant organization takeover via invitation acceptance with an…
CVE-2026-473825.327.7nocodbnocodbCWE-918NocoDB: Server-Side Request Forgery via Database Connection Host
CVE-2026-457328.327.6n8n-ion8nCWE-639n8n: Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints
CVE-2026-46106.427.5metagaussProfileGrid – User Profiles, Groups and CommunitiesCWE-79ProfileGrid <= 5.9.9.2 - Authenticated (Subscriber+) Stored Cross-Site Script…
CVE-2026-540225.327.3open-webuiopen-webuiCWE-706Open WebUI: Any authenticated user can read other users' private notes via So…
CVE-2026-545155.327.1FasterXMLjackson-databindCWE-915jackson-databind: Case-insensitive deserialization bypasses per-property @Jso…
CVE-2026-562635.326.9Crawl4AICrawl4AICWE-79Crawl4AI - Stored Cross-Site Scripting in Monitor Dashboard
CVE-2026-543136.526.8n8n-ion8nCWE-89n8n: NoSQL Injection in MongoDB Node Find And Replace Operation
CVE-2026-449585.426.4ReviveAdserverCWE-284An access control bypass allows an advertiser‑level user to activate or deact…
CVE-2026-540115.426.0open-webuiopen-webuiCWE-79Open WebUI: Stored XSS in Mermaid Markdown Preview
CVE-2026-484917.825.1traefiktraefikCWE-288Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-front…
CVE-2026-540088.524.9open-webuiopen-webuiCWE-918Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url`
CVE-2026-540127.124.7open-webuiopen-webuiCWE-284Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
CVE-2026-563766.324.2ImageMagickImageMagickCWE-416ImageMagick - Heap Use-After-Free in Meta Coder
CVE-2026-500197.424.1yt-dlpyt-dlpCWE-200yt-dlp: File Downloader cookie leak with curl
CVE-2026-562756.023.6FlowiseFlowiseCWE-918Flowise - Server-Side Request Forgery via Execute Flow Base URL
CVE-2026-555174.323.7denolanddenoCWE-248Deno: Denial of service via non-ASCII bytes in WebSocket response headers
CVE-2026-473806.323.5nocodbnocodbCWE-208NocoDB: User Enumeration via Sign-In Timing
CVE-2026-539286.323.5nocodbnocodbCWE-613NocoDB: Refresh Tokens Persist Through Password Recovery
CVE-2026-465542.323.5nocodbnocodbCWE-613NocoDB: Stale Auth Cache After API Token Deletion
CVE-2026-465525.823.4nocodbnocodbCWE-285NocoDB: Shared-base link access can invite arbitrary users as persistent base…
CVE-2026-49835.423.1Eclipse FoundationEclipse Open VSXCWE-79Open VSX Registry does not sanitize SVG files uploaded as extension icons pri…
CVE-2026-440899.423.0TotolinkEX1200LCWE-121Buffer Overflow in Totolink EX1200L router
CVE-2026-543177.622.9home-assistantcoreCWE-200Home Assistant: Konnected alarm-panel switch state and zone topology disclose…
CVE-2026-484935.522.6grokabilitysnipe-itCWE-863Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assi…
CVE-2026-543227.722.5daytonaiodaytonaCWE-639Daytona: Cross-org IDOR in organization role update/delete — any org owner ca…
CVE-2026-540164.322.4open-webuiopen-webuiCWE-639Open WebUI: Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Kno…
CVE-2026-540137.622.1open-webuiopen-webuiCWE-79Open WebUI: Stored XSS to Account Takeover via Model Profile Images in Open W…
CVE-2026-543086.321.9n8n-ion8nCWE-290n8n: Missing Token Validation on Microsoft Agent 365 Trigger Node
CVE-2026-540064.321.9open-webuiopen-webuiCWE-639Open WebUI: Calendar event re-parenting allows writing events into another us…
CVE-2026-566945.321.4nanocoainanoclawCWE-863NanoClaw < 2.1.0 - Privilege Escalation via Forged Channel Approval Callback
CVE-2026-465484.321.3nocodbnocodbCWE-918NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discor…
CVE-2026-528458.121.1caddyservercaddyCWE-287Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`
CVE-2026-556536.520.9Red HatRed Hat Enterprise Linux 10CWE-415Openssh: double free in red hat enterprise linux versions of openssh dh-gex c…
CVE-2026-561167.120.7NetworkConfigurationdhcpcdCWE-401dhcpcd Memory Leak DoS via IPv6 Router Advertisement Handling
CVE-2026-569685.320.5GNUGNU SASLCWE-908GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_…
CVE-2026-540216.320.2open-webuiopen-webuiCWE-863Open WebUI: Authenticated users can target arbitrary configured Ollama backen…
CVE-2026-543066.319.9n8n-ion8nCWE-1321n8n: Prototype Pollution enables confused-deputy execution via public webhooks
CVE-2026-128914.319.0Red HatRed Hat Enterprise Linux 10CWE-125Gstreamer1-plugins-bad: gstreamer1-plugins-bad: global buffer overflow (oob r…
CVE-2026-473882.318.8nocodbnocodbCWE-639NocoDB: Missing Ownership Check in MCP Attachment Read
CVE-2026-349124.318.6ReviveAdserverCWE-284A missing access control check when linking banners or campaigns to a zone th…
CVE-2026-349134.318.6ReviveAdserverCWE-284A missing access control check when linking trackers to campaigns through the…
CVE-2026-449574.318.6ReviveAdserverCWE-284A missing access control check when invoking various modify methods in the XM…
CVE-2026-118338.218.6Yokogawa Electric CorporationFAST/TOOLSCWE-319Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web…
CVE-2026-540156.418.6open-webuiopen-webuiCWE-284Open WebUI: Prompt history IDOR: unbound history_id allows cross-prompt read …
CVE-2026-561136.018.5NetworkConfigurationdhcpcdCWE-416dhcpcd Heap Use-After-Free in dhcp6_deprecateaddrs via DHCPv6 RENEW
CVE-2026-561146.018.5NetworkConfigurationdhcpcdCWE-787dhcpcd Stack Out-of-Bounds Write in dhcp6_makemessage()
CVE-2026-81727.118.5UnknownSimple Basic Contact Form—Simple Basic Contact Form <= 20250114 - Reflected XSS
CVE-2026-465476.117.9nocodbnocodbCWE-79NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL
CVE-2020-97115.517.4AdobeAcrobat ReaderCWE-125Acrobat Reader | Out-of-bounds Read (CWE-125)
CVE-2020-97135.517.4AdobeAcrobat ReaderCWE-125Acrobat Reader | Out-of-bounds Read (CWE-125)
CVE-2026-349156.117.3ReviveAdserverCWE-79A missing sanitisation of user input in the zone-include.php script of Revive…
CVE-2020-96957.817.3AdobeAcrobat ReaderCWE-787Acrobat Reader | Out-of-bounds Write (CWE-787)
CVE-2026-473866.316.8nocodbnocodbCWE-362NocoDB: OAuth Authorization Code Race Condition
CVE-2026-108576.116.4AKIN Software Computer Import Export Industry and Trade Ltd.e-CommerceCWE-79Reflected XSS in Akinsoft's e-Commerce
CVE-2026-58187.215.5CaliptraCore Runtime FirmwareCWE-253MCU Firmware Update Authentication Bypass on Caliptra Core
CVE-2026-543194.215.2daytonaiodaytonaCWE-22Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into…
CVE-2026-121634.815.1FortraFile Integrity Monitoring (FIM)CWE-79Stored XSS in Fortra File Integrity Monitoring (FIM)
CVE-2026-465492.015.0nocodbnocodbCWE-863NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
CVE-2026-543017.014.6n8n-ion8nCWE-79n8n: Same-Origin XSS in Respond to Webhook Node
CVE-2026-494407.414.5denolanddenoCWE-325Deno: Miller-Rabin Primality Test Allows Zero Rounds
CVE-2026-447269.114.1denolanddenoCWE-319Deno: TLS retry copies stale upgrade hook, risking plaintext traffic
CVE-2026-540077.113.8open-webuiopen-webuiCWE-346Open WebUI: Cross-origin postMessage confirmation bypass via action:submit
CVE-2026-543027.013.7n8n-ion8nCWE-79n8n: Stored XSS in Chat Trigger Node
CVE-2026-543036.813.7n8n-ion8nCWE-79n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhoo…
CVE-2026-557664.813.5guzzlepsr7CWE-93guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
CVE-2026-83785.413.1UnknownFrontend File Manager Plugin—Frontend File Manager Plugin <= 23.6 - Subscriber+ Stored Cross-Site Scriptin…
CVE-2026-554236.112.5langflow-ailangflowCWE-613Langflow: Logout button does not clear session
CVE-2026-121127.811.8Red HatRed Hat Satellite 6.18CWE-287Foreman-mcp-server: mcp server: active session hijacking via insecure session…
CVE-2026-557675.811.3guzzleguzzleCWE-346Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzle
CVE-2026-90736.210.8Red HatRed Hat Satellite 6.18CWE-532Foreman-mcp-server: mcp server: insecure sensitive http header sanitization
CVE-2026-494018.49.4denolanddenoCWE-41Deno Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
CVE-2026-64585.19.4CaliptraCore Runtime FirmwareCWE-325AES-256-GCM Authentication Tag Does Not Cover First Ciphertext Blocks When AA…
CVE-2026-545557.89.3rtk-airtkCWE-863rtk: Permission-gate bypass in rtk rewrite auto-allow via unsplit shell separ…
CVE-2026-129588.58.8Amazon Web ServicesLanguage Servers for AWSCWE-61Arbitrary file write in Language Servers for AWS
CVE-2026-528464.28.5caddyservercaddyCWE-116Caddy: stripHTML template function bypass
CVE-2026-543235.98.1daytonaiodaytonaCWE-295Daytona: Git credential leak via git clone with TLS verification disabled
CVE-2026-494065.57.1denolanddenoCWE-22Deno: BYONM module resolution allows `package.json` main path traversal to by…
CVE-2026-568157.46.7rasta-mousepwnliftCWE-61pwnlift before d7a9544, in a privileged deployment, contains a symlink follow…
CVE-2026-543262.56.7earendil-workspiCWE-79Pi: Potential XSS in HTML session exports via Markdown URL sanitization bypass
CVE-2026-129578.56.5Amazon Web ServicesLanguage Servers for AWSCWE-732Arbitrary Code Execution in Language Servers for AWS
CVE-2026-543187.16.3home-assistantcoreCWE-926Home Assistant: Exported BroadcastReceiver allows local apps to spoof device …
CVE-2026-456923.86.1caddyservercaddyCWE-187Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Nor…
CVE-2026-566926.86.0nanocoainanoclawCWE-59NanoClaw < 2.1.17 - Arbitrary File Read via Symlink Following in forwardAttac…
CVE-2026-566936.85.9nanocoainanoclawCWE-602NanoClaw < 2.1.17 - Privilege Escalation via Unauthorized create_agent System…
CVE-2026-543254.45.9earendil-workspiCWE-829Pi loads project-local extensions without approval
CVE-2026-543287.35.8earendil-workspiCWE-379Pi: Predictable temporary extension install paths allow local privilege escal…
CVE-2026-118195.55.5Red HatRed Hat Enterprise Linux 10CWE-532Community.general: community.general keyring_info — os keyring passphrase ret…
CVE-2026-465505.45.2nocodbnocodbCWE-614NocoDB: Refresh Token Cookie Set Without `Secure` and `SameSite` Flags
CVE-2026-494116.55.1denolanddenoCWE-284Deno Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny…
CVE-2025-156193.55.1HCLSoftwareConnectionsCWE-284HCL Connections is vulnerable to broken access control
CVE-2026-563016.84.3NuxtNuxtCWE-276Nuxt - Arbitrary File Read via World-Connectable vite-node IPC Socket on Linux
CVE-2026-570532.54.3GNUlibidnCWE-1284GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memor…
CVE-2026-555685.94.2guzzleguzzleCWE-311Guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
CVE-2026-121644.44.0FortraFile Integrity Monitoring (FIM)CWE-266Privilege Escalation in Fortra File Integrity Monitoring (FIM)
CVE-2026-502215.33.9OpenStackSwiftCWE-918In OpenStack Swift before 2.37.2, proxy-server does not strip internal update…
CVE-2026-570622.93.8GnuPGGnuPGCWE-1284CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 m…
CVE-2026-498595.23.6denolanddenoCWE-693Deno: `fetch()` API sandbox bypass via missing DNS resolution check
CVE-2026-498605.23.6denolanddenoCWE-918Deno: WebSocket API sandbox bypass via missing post-DNS check
CVE-2026-499835.23.5denolanddenoCWE-863Deno: process.loadEnvFile() bypasses env permission checks and mutates proces…
CVE-2026-561175.73.2NetworkConfigurationdhcpcdCWE-416dhcpcd Heap Use-After-Free via Control Socket Handling
CVE-2026-08644.12.5Python Software FoundationCPythonCWE-74Configuration Injection via Carriage Return (\r) in write() method
CVE-2026-128924.41.9Red HatRed Hat Enterprise Linux 10CWE-125Gstreamer1-plugins-bad: gstreamer1-plugins-bad: 1-byte heap out-of-bounds rea…
CVE-2025-131624.11.8ABBControl Builder ACWE-427Advant Master Online Builder DLL vulnerability
CVE-2026-75748.71.7AnthropicClaude Desktop CoworkCWE-353Anthropic Claude Desktop Cowork VM Image Contents Not Validated Before Use
CVE-2026-457926.91.4rtk-airtkCWE-345RTK improperly trusts project-local filter configuration, allowing silent tam…
CVE-2026-543272.20.6earendil-workspiCWE-367Pi: Race condition in auth.json writes could expose stored credentials
CVE-2026-556556.10.4Red HatRed Hat Enterprise Linux 10CWE-923Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-23 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.