AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0793 94.3 —
AFFECTED Product Versions Fixed gogs < 0.14.3 – —
TIMELINE Jun 8 Reserved by CNA Jun 24 Published (CNA: GitHub_M)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
520 CVEs published, led by Linux (219).
520 CVEs published June 24, 2026: 56 critical, 226 high, 227 medium, 10 low; 0 in the KEV catalog at press time; 16 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 120 on continuation pages.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 6171 | 10632 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
481 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 319 | 1286 | 104 | 767 | 414 | 1 | 11 | 2 | 0.2 | 7.8 | .0014 | +92 ▲ |
| 704 | 879 | 85 | 466 | 299 | 29 | 77 | 6 | 0.7 | 8.1 | .0023 | +688 ▲ | |
| microsoft | 220 | 756 | 58 | 520 | 172 | 6 | 286 | 19 | 2.5 | 7.8 | .0045 | +60 ▲ |
| red hat | 93 | 187 | 9 | 76 | 90 | 12 | 2 | 0 | 0.0 | 6.5 | .0029 | +83 ▲ |
| apple | 14 | 66 | 1 | 21 | 42 | 2 | 88 | 7 | 10.6 | 5.7 | .0019 | -1 ▼ |
| canonical | 2 | 16 | 1 | 4 | 6 | 5 | 0 | 0 | 0.0 | 5.5 | .0010 | +2 ▲ |
| freebsd | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0020 | -7 ▼ |
| suse | 4 | 6 | 1 | 4 | 1 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | +2 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 9 | 21 | 6 | 5 | 10 | 0 | 56 | 10 | 47.6 | 7.2 | .0438 | +4 ▲ |
| netgear | 17 | 17 | 0 | 0 | 16 | 1 | 0 | 0 | 0.0 | 4.3 | .0024 | +17 ▲ |
| palo alto networks | 9 | 11 | 1 | 2 | 7 | 1 | 13 | 2 | 18.2 | 5.9 | .0022 | +7 ▲ |
| ubiquiti | 8 | 11 | 7 | 4 | 0 | 0 | 3 | 3 | 27.3 | 9.9 | .0083 | +6 ▲ |
| ivanti | 4 | 9 | 4 | 5 | 0 | 0 | 25 | 5 | 55.6 | 8.8 | .5187 | +2 ▲ |
| checkpoint | 3 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | +3 ▲ |
| fortinet | 2 | 9 | 4 | 3 | 2 | 0 | 28 | 3 | 33.3 | 8.3 | .0076 | +1 ▲ |
| f5 | 6 | 8 | 4 | 3 | 1 | 0 | 4 | 1 | 12.5 | 8.9 | .0225 | +4 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 92 | 126 | 18 | 44 | 55 | 8 | 33 | 1 | 0.8 | 6.5 | .0051 | +83 ▲ |
| mozilla | 49 | 55 | 11 | 18 | 26 | 0 | 9 | 0 | 0.0 | 7.3 | .0026 | +44 ▲ |
| gitlab | 11 | 18 | 0 | 4 | 12 | 2 | 4 | 2 | 11.1 | 4.8 | .0024 | +11 ▲ |
| docker | 4 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.2 | .0016 | +1 ▲ |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 4 | 1 | 20.0 | 5.1 | .0026 | -3 ▼ |
| github | 0 | 2 | 1 | 1 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0347 | 0 |
| wordpress | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 242 | 270 | 132 | 116 | 18 | 4 | 27 | 2 | 0.7 | 8.8 | .0040 | +242 ▲ |
| adobe | 132 | 134 | 4 | 51 | 77 | 2 | 19 | 2 | 1.5 | 5.5 | .0021 | +132 ▲ |
| ibm | 32 | 81 | 19 | 35 | 27 | 0 | 6 | 0 | 0.0 | 7.5 | .0031 | +32 ▲ |
| progress | 5 | 9 | 1 | 7 | 1 | 0 | 6 | 0 | 0.0 | 7.5 | .0036 | +1 ▲ |
| solarwinds | 3 | 6 | 2 | 3 | 1 | 0 | 10 | 4 | 66.7 | 7.8 | .6082 | +3 ▲ |
| veeam | 1 | 4 | 2 | 2 | 0 | 0 | 1 | 0 | 0.0 | 9.0 | .0052 | +1 ▲ |
| zohocorp | 1 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 5 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +5 ▲ |
| d-link | 9 | 11 | 0 | 4 | 2 | 5 | 3 | 0 | 0.0 | 5.5 | .0058 | +8 ▲ |
| siemens | 7 | 8 | 0 | 4 | 4 | 0 | 0 | 0 | 0.0 | 7.5 | .0020 | +6 ▲ |
| rockwell automation | 7 | 7 | 1 | 5 | 1 | 0 | 0 | 0 | 0.0 | 8.7 | .0030 | +7 ▲ |
| abb | 6 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | +6 ▲ |
| moxa | 5 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | +5 ▲ |
| dahua | 3 | 3 | 0 | 1 | 1 | 1 | 0 | 0 | 0.0 | 6.9 | .0036 | +3 ▲ |
| mitsubishi electric | 3 | 3 | 0 | 3 | 0 | 0 | 0 | 0 | 0.0 | 8.7 | .0064 | +3 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| spring | 72 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | +72 ▲ |
| openclaw | 61 | 67 | 0 | 35 | 22 | 10 | 0 | 0 | 0.0 | 7.0 | .0021 | +61 ▲ |
| sourcecodester | 37 | 59 | 0 | 0 | 25 | 34 | 0 | 0 | 0.0 | 2.1 | .0026 | +33 ▲ |
| themerex | 58 | 58 | 5 | 53 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0043 | +58 ▲ |
| edimax | 5 | 56 | 0 | 33 | 0 | 23 | 1 | 0 | 0.0 | 7.4 | .0070 | -20 ▼ |
| jenkins project | 36 | 49 | 0 | 9 | 39 | 1 | 3 | 0 | 0.0 | 4.8 | .0025 | +36 ▲ |
| dell | 31 | 49 | 1 | 24 | 24 | 0 | 2 | 1 | 2.0 | 7.0 | .0017 | +19 ▲ |
| capgo | 46 | 46 | 2 | 22 | 21 | 1 | 0 | 0 | 0.0 | 7.0 | .0039 | +46 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-10520 | .9991 | 100.0 | 10.0 |
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-35273 | .9547 | 99.9 | 9.8 |
| CVE-2026-34910 | .8747 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-50751 | .8377 | 99.7 | 9.3 |
| CVE-2026-48907 | .7810 | 99.5 | 10.0 |
| CVE-2026-34909 | .6390 | 99.2 | 10.0 |
| CVE-2026-49160 | .5383 | 98.9 | 7.5 |
| CVE-2026-10523 | .5187 | 98.9 | 9.8 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-10520 | 10.0 | .9991 | KEV |
| CVE-2026-34910 | 10.0 | .8747 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-48907 | 10.0 | .7810 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-48172 | 10.0 | .1891 | KEV |
| CVE-2026-45087 | 10.0 | .1296 | |
| CVE-2026-53753 | 10.0 | .0290 | |
| CVE-2026-49777 | 10.0 | .0166 | |
| CVE-2026-8054 | 10.0 | .0158 |
| Vendor | CVEs |
|---|---|
| 856 | |
| linux | 733 |
| oracle | 267 |
| microsoft | 226 |
| adobe | 132 |
| red hat | 125 |
| apache | 95 |
| ibm | 81 |
| spring | 72 |
| openclaw | 67 |
| Vendor | KEV |
|---|---|
| microsoft | 19 |
| cisco | 10 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| berriai | 3 |
| fortinet | 3 |
| smartertools | 3 |
| ubiquiti | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 37 |
| Packagist | 22 |
| PyPI | 10 |
| npm | 3 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2025-48595 | 0 | |
| CVE-2026-10520 | ivanti | 0 |
| CVE-2026-11645 | 0 | |
| CVE-2026-20245 | Cisco | 0 |
| CVE-2026-20253 | Splunk | 0 |
| CVE-2026-20262 | Cisco | 0 |
| CVE-2026-28318 | SolarWinds | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE-2026-34909 | Ubiquiti Inc | 0 |
| CVE-2026-34910 | Ubiquiti Inc | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1680 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1680 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1680 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1680 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1680 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1680 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1680 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1680 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1680 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1680 |
EXPLOIT PUBLISHED — appsmithorg appsmith: 3 CVEs (CVE-2026-49979, CVE-2026-50189, CVE-2026-55454). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2025-60466. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-60467. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-60468. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-60471. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-60473. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-60474. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-71332 (Flowise). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10642 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-11998 (Google AngularJS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-53765 (ChromeDevTools chrome-devtools-mcp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-53766 (ChromeDevTools chrome-devtools-mcp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54297 (lostisland faraday). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54904 (ruby-concurrency concurrent-ruby). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56270 (Flowise). Public exploit reference added.
DUE DATE PASSED — CVE-2026-11645 (Google Chrome). CISA remediation deadline was June 23, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-20245 (Cisco Catalyst SD-WAN Controller). CISA remediation deadline was June 23, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-7473 (Arista Networks EOS). CISA remediation deadline was June 23, 2026; still in catalog.
How to read these box scores · glossary
520 CVEs published. 25 box scores and 375 table rows below; the remaining 120 continue on page 2 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0793 94.3 —
AFFECTED Product Versions Fixed gogs < 0.14.3 – —
TIMELINE Jun 8 Reserved by CNA Jun 24 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0549 92.2 —
AFFECTED Product Versions Fixed NetVault Backup 14.0.0.19 – —
TIMELINE May 27 Reserved by CNA Jun 24 Published (CNA: zdi)
AV AC PR UI S C I A CVSS EPSS %ile KEV L L L N U H N N 5.5 .0295 86.1 —
AFFECTED Product Versions Fixed motioneye < 0.44.0 – —
TIMELINE Mar 11 Reserved by CNA Jun 24 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0270 84.8 —
AFFECTED Product Versions Fixed GV-I/O Box 4E V2.09 – V2.12
TIMELINE Jun 17 Reserved by CNA Jun 24 Published (CNA: GV)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0270 84.8 —
AFFECTED Product Versions Fixed GV-I/O Box 4E V2.09 – V2.12
TIMELINE Jun 22 Reserved by CNA Jun 24 Published (CNA: GV)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0270 84.8 —
AFFECTED Product Versions Fixed GV-I/O Box 4E V2.09 – V2.12
TIMELINE Jun 22 Reserved by CNA Jun 24 Published (CNA: GV)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0270 84.8 —
AFFECTED Product Versions Fixed GV-I/O Box 4E V2.09 – V2.12
TIMELINE Jun 22 Reserved by CNA Jun 24 Published (CNA: GV)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0239 82.6 —
AFFECTED Product Versions Fixed siyuan < 3.7.0 – —
TIMELINE Jun 11 Reserved by CNA Jun 24 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0223 81.4 —
AFFECTED Product Versions Fixed Unizon 2.7.262.002 – —
TIMELINE May 27 Reserved by CNA Jun 24 Published (CNA: zdi)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0223 81.4 —
AFFECTED Product Versions Fixed Unizon 2.7.262.002 – —
TIMELINE May 27 Reserved by CNA Jun 24 Published (CNA: zdi)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0205 79.7 —
AFFECTED Product Versions Fixed Flowise unspecified 3.1.0
TIMELINE Jun 20 Reserved by CNA Jun 24 Public exploit reference published Jun 24 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0189 77.9 —
AFFECTED Product Versions Fixed Unraid 1161ec120 – —
TIMELINE May 27 Reserved by CNA Jun 24 Published (CNA: zdi)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0189 77.9 —
AFFECTED Product Versions Fixed Unraid 1161ec120 – —
TIMELINE May 27 Reserved by CNA Jun 24 Published (CNA: zdi)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0185 77.5 —
AFFECTED Product Versions Fixed Unizon 2.7.262.002 – —
TIMELINE May 27 Reserved by CNA Jun 24 Published (CNA: zdi)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0169 75.3 —
AFFECTED Product Versions Fixed cacti < 1.2.31 – —
TIMELINE Apr 9 Reserved by CNA Jun 24 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U N H H 6.5 .0151 72.5 —
AFFECTED Product Versions Fixed Unizon 2.7.262.002 – —
TIMELINE May 27 Reserved by CNA Jun 24 Published (CNA: zdi)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U N H H 6.5 .0151 72.5 —
AFFECTED Product Versions Fixed Unizon 2.7.262.002 – —
TIMELINE May 27 Reserved by CNA Jun 24 Published (CNA: zdi)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L N N 5.5 .0149 72.1 —
AFFECTED Product Versions Fixed gogs < 0.14.3 – —
TIMELINE Jun 8 Reserved by CNA Jun 24 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0140 70.3 —
AFFECTED Product Versions Fixed warp >= 0.2023.03.21.08.02.stable_00, < 0.2026.05.13.09.15.stable_01 – —
TIMELINE May 22 Reserved by CNA Jun 24 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0137 69.9 —
AFFECTED Product Versions Fixed feast unspecified —
TIMELINE Jun 18 Reserved by CNA Jun 24 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L R U H H H 8.0 .0132 68.7 —
AFFECTED Product Versions Fixed warp >= 0.2025.08.06.08.12.stable_00, < 0.2026.05.13.09.15.stable_01 – —
TIMELINE May 22 Reserved by CNA Jun 24 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0129 68.0 —
AFFECTED Product Versions Fixed InsightConnect RPM Plugin unspecified 1.0.2
TIMELINE May 15 Reserved by CNA Jun 24 Published (CNA: rapid7)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0111 63.3 —
AFFECTED Product Versions Fixed gogs < 0.14.3 – —
TIMELINE Jun 8 Reserved by CNA Jun 24 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0095 58.4 —
AFFECTED Product Versions Fixed NetVault Backup 14.0.0.19 – —
TIMELINE Apr 30 Reserved by CNA Jun 24 Published (CNA: zdi)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0095 58.4 —
AFFECTED Product Versions Fixed NetVault Backup 14.0.0.19 – —
TIMELINE May 27 Reserved by CNA Jun 24 Published (CNA: zdi)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-9782 | 8.8 | 58.4 | Quest | NetVault Backup | CWE-89 | Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vul… |
| CVE-2026-9783 | 8.8 | 58.4 | Quest | NetVault Backup | CWE-89 | Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution … |
| CVE-2026-9784 | 8.8 | 58.4 | Quest | NetVault Backup | CWE-89 | Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vul… |
| CVE-2026-9785 | 8.8 | 58.4 | Quest | NetVault Backup | CWE-89 | Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vul… |
| CVE-2026-9786 | 8.8 | 58.4 | Quest | NetVault Backup | CWE-89 | Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulne… |
| CVE-2026-7569 | 8.8 | 58.1 | Quest | NetVault Backup | CWE-79 | Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass V… |
| CVE-2026-9780 | 8.8 | 58.1 | Quest | NetVault Backup | CWE-79 | Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass V… |
| CVE-2026-48731 | 7.8 | 56.5 | warpdotdev | warp | CWE-78 | Warp: Linux external editor command injection |
| CVE-2026-25119 | 7.7 | 55.8 | gogs | gogs | CWE-290 | Gogs: Authentication Bypass via Unvalidated Reverse Proxy Headers |
| CVE-2026-12242 | 8.8 | 55.6 | adegans | AdRotate Banner Manager | CWE-94 | AdRotate Banner Manager <= 5.17.7 - Authenticated (Contributor+) PHP Code Inj… |
| CVE-2026-39948 | 9.3 | 55.3 | Cacti | cacti | CWE-89 | Cacti has SQL Injection via rfilter parameter in RLIKE clauses |
| CVE-2026-57296 | 8.8 | 54.9 | Jenkins Project | Jenkins External Workspace Manager Plugin | CWE-22 | Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject p… |
| CVE-2026-12417 | 9.8 | 54.5 | pravel | SignUp & SignIn | CWE-640 | SignUp & SignIn <= 1.0.0 - Unauthenticated Privilege Escalation via Weak Pass… |
| CVE-2025-60474 | 7.5 | 54.1 | n/a | n/a | CWE-121 | A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c)… |
| CVE-2026-50551 | 9.9 | 53.0 | siyuan-note | siyuan | CWE-79 | SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content |
| CVE-2026-56262 | 6.9 | 52.4 | Crawl4AI | Crawl4AI | CWE-306 | Crawl4AI - Unauthenticated Access to Monitor Endpoints via Docker API Server |
| CVE-2026-49980 | 9.8 | 52.0 | rclone | rclone | CWE-306 | Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inli… |
| CVE-2026-54699 | 7.7 | 51.9 | warpdotdev | warp | CWE-78 | Warp: OS command injection when opening terminal links from WSL |
| CVE-2026-52999 | 9.1 | 51.7 | Linux | Linux | CWE-125 | netfilter: nfnetlink_osf: fix out-of-bounds read on option matching |
| CVE-2026-53043 | 9.1 | 51.7 | Linux | Linux | CWE-787 | ocfs2/dlm: validate qr_numregions in dlm_match_regions() |
| CVE-2025-60467 | 7.5 | 51.4 | n/a | n/a | CWE-416 | A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter… |
| CVE-2026-7761 | 8.8 | 51.3 | ultimatemember | Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin | CWE-862 | Ultimate Member <= 2.11.4 - Authenticated (Contributor+) Account Takeover via… |
| CVE-2026-53046 | 9.8 | 51.0 | Linux | Linux | CWE-416 | ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine |
| CVE-2026-52922 | 7.5 | 51.0 | Linux | Linux | CWE-476 | batman-adv: dat: handle forward allocation error |
| CVE-2026-52929 | 7.5 | 51.0 | Linux | Linux | CWE-476 | sctp: stream: fully roll back denied add-stream state |
| CVE-2026-52954 | 7.5 | 51.0 | Linux | Linux | CWE-617 | libceph: handle rbtree insertion error in decode_choose_args() |
| CVE-2026-52957 | 7.5 | 51.0 | Linux | Linux | CWE-476 | libceph: Fix potential null-ptr-deref in decode_choose_args() |
| CVE-2026-53003 | 7.5 | 51.0 | Linux | Linux | — | pppoe: drop PFC frames |
| CVE-2026-1840 | 8.7 | 50.8 | Hubbell | Aclara Metrum Cellular Web Interface | CWE-306 | Missing authentication for critical function in Hubbell Aclara Metrum Cellula… |
| CVE-2026-13164 | 8.8 | 50.8 | Mailerup | Mailerup | CWE-306 | Unauthenticated self-registration in MailerUp allows access to stored email data |
| CVE-2026-53069 | 7.5 | 50.4 | Linux | Linux | CWE-476 | net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master |
| CVE-2026-39938 | 9.8 | 50.1 | Cacti | cacti | CWE-22 | Cacti: Unauthenticated RCE on Graph Image |
| CVE-2026-52974 | 7.5 | 49.8 | Linux | Linux | CWE-401 | net: tls: fix strparser anchor skb leak on offload RX setup failure |
| CVE-2026-53087 | 7.5 | 49.8 | Linux | Linux | CWE-401 | net: bcmgenet: fix leaking free_bds |
| CVE-2026-45677 | 8.7 | 49.7 | RocketChat | Rocket.Chat | CWE-862 | Rocket.Chat: Lack of SAML Signature Check During Logout Could Lead To DoS |
| CVE-2026-9779 | 7.2 | 49.6 | ATEN | Unizon | CWE-347 | ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Sig… |
| CVE-2026-8705 | 7.5 | 49.5 | clearsale | ClearSale Total | CWE-89 | ClearSale Total <= 3.4.2 - Unauthenticated SQL Injection |
| CVE-2026-52816 | 5.4 | 49.5 | gogs | gogs | CWE-80 | Gogs: Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary dat… |
| CVE-2026-57281 | 7.5 | 49.4 | Jenkins Project | Jenkins Script Security Plugin | CWE-93 | Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject… |
| CVE-2026-39893 | 9.8 | 49.4 | Cacti | cacti | CWE-89 | Cacti: Pre-authentication SQL injection via rfilter RLIKE clause in graph_vie… |
| CVE-2026-12416 | 9.8 | 49.3 | pravel | Invoice Generator | CWE-640 | Invoice Generator <= 1.0.0 - Unauthenticated Account Takeover via Weak Passwo… |
| CVE-2026-54904 | 8.2 | 49.3 | ruby-concurrency | concurrent-ruby | CWE-835 | concurrent-ruby: `AtomicReference#update` livelocks when the stored value is … |
| CVE-2026-4297 | 8.8 | 49.3 | newscred | Welcome Software Publishing | CWE-862 | Welcome Software Publishing <= 0.0.31 - Authenticated (Subscriber+) Arbitrary… |
| CVE-2026-48793 | 8.8 | 49.0 | jellyfin | jellyfin | CWE-88 | Jellyfin: Potential FFmpeg argument injection via unescaped subtitle file path |
| CVE-2026-44017 | 7.5 | 48.7 | docling-project | docling | CWE-22 | Docling: Unsafe Zip Extraction in EasyOCR Model Download |
| CVE-2026-56111 | 8.3 | 48.2 | MarlinFirmware | Marlin | CWE-129 | Marlin Firmware 2.1.2.7 Out-of-Bounds Write via M421 G-code Handler |
| CVE-2026-53010 | 9.8 | 47.5 | Linux | Linux | CWE-416 | ksmbd: fix use-after-free in smb2_open during durable reconnect |
| CVE-2026-53055 | 9.8 | 47.5 | Linux | Linux | CWE-416 | crypto: hisilicon/sec2 - prevent req used-after-free for sec |
| CVE-2026-49851 | 8.7 | 47.4 | lepture | mistune | CWE-400 | Mistune: Potential DoS via quadratic-time parsing in parse_link_text |
| CVE-2026-57301 | 8.8 | 47.3 | Jenkins Project | Jenkins OWASP ZAP Plugin | CWE-610 | Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the J… |
| CVE-2026-55488 | 7.7 | 47.2 | motioneye-project | motioneye | CWE-22 | motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary F… |
| CVE-2026-52946 | 7.5 | 47.1 | Linux | Linux | CWE-667 | fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling |
| CVE-2026-55570 | 9.0 | 46.9 | siyuan-note | siyuan | CWE-79 | SiYuan: Stored XSS results to Electron RCE in SiYuan marketplace via unescape… |
| CVE-2026-9178 | 7.5 | 46.6 | hancock11 | WP Forms Connector | CWE-862 | WP Forms Connector <= 1.8 - Missing Authorization to Unauthenticated Informat… |
| CVE-2026-52932 | 7.5 | 46.5 | Linux | Linux | — | xfrm: ipcomp: Free destination pages on acomp errors |
| CVE-2026-52983 | 7.5 | 46.5 | Linux | Linux | — | net: airoha: fix BQL imbalance in TX path |
| CVE-2026-53026 | 7.5 | 46.5 | Linux | Linux | — | NFSD: fix nfs4_file access extra count in nfsd4_add_rdaccess_to_wrdeleg |
| CVE-2026-55454 | 9.9 | 46.2 | appsmithorg | appsmith | CWE-749 | Appsmith: Caddy admin API exposed without authentication |
| CVE-2026-44020 | 7.5 | 46.1 | docling-project | docling | CWE-776 | Docling: Unsafe XML Entity Expansion in USPTO Patent Backend |
| CVE-2025-71361 | 7.6 | 46.0 | picklescan | picklescan | CWE-95 | picklescan - Remote Code Execution via Undetected idlelib.calltip.Calltip.fet… |
| CVE-2026-12485 | 10.0 | 46.0 | GeoVision Inc. | GV-I/O Box 4E | CWE-121 | GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET … |
| CVE-2026-12846 | 10.0 | 46.0 | GeoVision Inc. | GV-I/O Box 4E | CWE-121 | GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET … |
| CVE-2026-12847 | 10.0 | 46.0 | GeoVision Inc. | GV-I/O Box 4E | CWE-121 | GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET … |
| CVE-2026-12848 | 10.0 | 46.0 | GeoVision Inc. | GV-I/O Box 4E | CWE-121 | GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET … |
| CVE-2026-44016 | 8.2 | 45.7 | docling-project | docling | CWE-94 | Docling: Unsafe Playwright-based HTML Rendering |
| CVE-2026-2050 | 7.8 | 45.6 | GIMP | GIMP | CWE-122 | GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulner… |
| CVE-2026-39955 | 9.8 | 45.3 | Cacti | cacti | CWE-89 | Cacti has Pre-Authentication SQL Injection via unanchored FILTER_VALIDATE_REG… |
| CVE-2026-54069 | 9.2 | 45.0 | siyuan-note | siyuan | CWE-346 | SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Orig… |
| CVE-2026-53049 | 9.8 | 44.6 | Linux | Linux | CWE-667 | gfs2: add some missing log locking |
| CVE-2026-52801 | 8.1 | 44.5 | gogs | gogs | CWE-20 | Gogs: Ability to import local repositories via Mirror Settings |
| CVE-2026-23879 | 8.0 | 44.4 | miurahr | py7zr | CWE-59 | py7zr: Arbitrary File Write Vulnerability |
| CVE-2026-52802 | 5.4 | 43.8 | gogs | gogs | CWE-601 | Gogs: Open Redirect via redirect_to in Gogs |
| CVE-2026-52986 | 9.8 | 43.6 | Linux | Linux | CWE-476 | netfilter: nf_conntrack_sip: don't use simple_strtoul |
| CVE-2026-49247 | 8.8 | 43.4 | jellyfin | jellyfin | CWE-22 | Jellyfin: Potential Authenticated path traversal in /ClientLog/Document |
| CVE-2026-47110 | 7.1 | 43.4 | ueberdosis | tiptap-php | CWE-241 | Tiptap for PHP < 2.1.1 DoS via Malformed href Attribute |
| CVE-2026-10043 | 7.8 | 43.4 | MosaicML | Composer | CWE-502 | MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vul… |
| CVE-2026-52814 | 5.5 | 43.4 | gogs | gogs | CWE-400 | Gogs: Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake St… |
| CVE-2026-52920 | 8.3 | 43.2 | Linux | Linux | — | netfilter: xt_policy: fix strict mode inbound policy matching |
| CVE-2026-9612 | 5.3 | 43.1 | yapacdev | WhatsOrder – Instant Checkout for WooCommerce | CWE-200 | WhatsOrder <= 1.0.1 - Unauthenticated Sensitive Information Exposure via Pred… |
| CVE-2026-54067 | 9.9 | 43.0 | siyuan-note | siyuan | CWE-79 | SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet() |
| CVE-2026-10749 | 7.2 | 43.0 | Unknown | Post Duplicator | — | Post Duplicator < 3.0.15 - Contributor+ PHP Object Injection via customMetaData |
| CVE-2026-52958 | 9.1 | 42.8 | Linux | Linux | CWE-125 | libceph: Fix potential out-of-bounds access in osdmap_decode() |
| CVE-2026-52982 | 9.8 | 42.8 | Linux | Linux | CWE-416 | net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() |
| CVE-2026-33235 | 7.7 | 42.6 | Significant-Gravitas | AutoGPT | CWE-400 | AutoGPT: Denial of Service (DoS) via Resource Exhaustion in text templating f… |
| CVE-2026-52981 | 7.5 | 42.5 | Linux | Linux | CWE-401 | neigh: let neigh_xmit take skb ownership |
| CVE-2026-52797 | 8.5 | 42.4 | gogs | gogs | CWE-22 | Gogs: Overwriting critical files results in a denial of service |
| CVE-2026-50699 | 4.6 | 42.4 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Stored XSS in Auto Repeat dashboard schedule re… |
| CVE-2026-45689 | 9.1 | 42.2 | RocketChat | Rocket.Chat | CWE-943 | Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arb… |
| CVE-2026-56237 | 9.3 | 41.7 | Capgo | Capgo | CWE-287 | Capgo - Unauthenticated API Key Generation via Client-Side Parameter Manipula… |
| CVE-2025-71332 | 8.5 | 41.6 | Flowise | Flowise | CWE-89 | Flowise - SQL Injection in importChatflows API via chatflow.id Parameter |
| CVE-2026-53045 | 9.8 | 41.4 | Linux | Linux | — | memory: tegra124-emc: Fix dll_change check |
| CVE-2026-52914 | 9.8 | 41.3 | Linux | Linux | CWE-787 | batman-adv: fix fragment reassembly length accounting |
| CVE-2026-57280 | 8.8 | 41.4 | Jenkins Project | Jenkins Script Security Plugin | CWE-693 | Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not interc… |
| CVE-2026-13163 | 5.3 | 41.2 | Mailerup | Mailerup | CWE-601 | Lack of input validation in Mailerup input parameter leads to Open Redirect |
| CVE-2026-54158 | 9.9 | 41.1 | siyuan-note | siyuan | CWE-79 | SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML() |
| CVE-2026-9179 | 7.5 | 40.8 | hancock11 | WP Forms Connector | CWE-89 | WP Forms Connector <= 1.8 - Unauthenticated SQL Injection via 'order' Parameter |
| CVE-2026-11998 | 7.6 | 40.6 | AngularJS | CWE-791 | AngularJS XSS via SCE resource URL sanitization bypass | |
| CVE-2026-52998 | 7.5 | 40.6 | Linux | Linux | CWE-476 | netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check |
| CVE-2026-52804 | 5.5 | 40.5 | gogs | gogs | CWE-193 | Gogs: Privilege Escalation via Collaboration Access Mode Validation |
| CVE-2026-50189 | 8.9 | 40.1 | appsmithorg | appsmith | CWE-183 | Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor… |
| CVE-2026-13150 | 6.9 | 40.1 | Pentestify | Pentestify | CWE-918 | SSRF in Pentestify PDF generation endpoint via Host header |
| CVE-2026-45688 | 9.1 | 40.1 | RocketChat | Rocket.Chat | CWE-943 | Rocket.Chat: Pre-Auth NoSQL Injection in CAS Login Handler leading to Arbitra… |
| CVE-2026-56338 | 6.9 | 40.0 | Capgo | Capgo | CWE-703 | Capgo - Denial of Service in 2FA Email Verification via /auth/v1/otp Endpoint |
| CVE-2026-52960 | 7.5 | 39.8 | Linux | Linux | — | ceph: put folios not suitable for writeback |
| CVE-2026-9175 | 5.3 | 39.8 | ajitdas | Devs Accounting – Simple Accounting and Invoicing Solution | CWE-862 | Devs Accounting <= 1.2.0 - Missing Authorization to Unauthenticated Sensitive… |
| CVE-2026-54297 | 7.5 | 39.7 | lostisland | faraday | CWE-674 | Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustio… |
| CVE-2026-52807 | 4.8 | 39.4 | gogs | gogs | CWE-79 | Gogs: DOM-based XSS via Milestone Name on New Issue Page |
| CVE-2026-52808 | 7.1 | 39.1 | gogs | gogs | CWE-269 | Gogs: Write-level collaborators can mutate admin-only repository settings via… |
| CVE-2026-52811 | 9.0 | 38.9 | gogs | gogs | CWE-22 | Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym |
| CVE-2026-55762 | 8.1 | 38.9 | RocketChat | Rocket.Chat | CWE-862 | Rocket.Chat: Any Authenticated User Can Permanently Deregister Workspace from… |
| CVE-2026-56232 | 8.7 | 38.5 | Capgo | Capgo | CWE-863 | Capgo - Subkey Scope Bypass in middlewareKey via x-limited-key-id Header |
| CVE-2026-52794 | 7.5 | 38.4 | getsentry | sentry | CWE-1333 | Sentry: Inefficient Regular Expression Complexity in sentry |
| CVE-2026-50129 | 7.5 | 37.9 | mastodon | mastodon | CWE-248 | Mastodon: Persistent anonymous DoS via unhandled NoMethodError in MATH_TRANSF… |
| CVE-2026-56368 | 6.3 | 37.9 | ImageMagick | ImageMagick | CWE-401 | ImageMagick - Memory Leak in Raw Pixel Data Coders |
| CVE-2026-56245 | 8.8 | 37.8 | Cap-go | capgo | CWE-269 | Supabase Capgo - Unauthenticated Cross-Tenant Build-Time Accounting Poisoning… |
| CVE-2026-50701 | 5.1 | 37.4 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Reflected DOM XSS in dashboard-view breadcrumb … |
| CVE-2025-71354 | 7.6 | 37.1 | picklescan | picklescan | CWE-502 | picklescan - Remote Code Execution via idlelib.debugobj.ObjectTreeItem.SetText |
| CVE-2026-33543 | 9.3 | 37.0 | FOSSBilling | FOSSBilling | CWE-288 | FOSSBilling: Authentication bypass allows unauthenticated administrator creation |
| CVE-2026-53943 | 9.6 | 36.9 | TryGhost | Ghost | CWE-524 | Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header |
| CVE-2026-54759 | 8.7 | 36.7 | siyuan-note | siyuan | CWE-79 | SiYuan: Lute HTML sanitizer allows `<iframe>` tags in Bazaar package README, … |
| CVE-2026-48704 | 8.8 | 36.6 | warpdotdev | warp | CWE-20 | Warp Markdown notebook links may open executable local files |
| CVE-2026-48720 | 8.8 | 36.6 | warpdotdev | warp | CWE-20 | Warp: SSH remote output can lead to local file overwrite and persistence |
| CVE-2025-64719 | 4.9 | 36.5 | gogs | gogs | CWE-20 | Gogs: Denial of Service in repository/wiki file listing web pages |
| CVE-2026-8690 | 5.3 | 36.3 | rentmy | RentMy Real-Time Rental Management Plugin | CWE-862 | RentMy Real-Time Rental Management Plugin <= 4.0.4.1 - Missing Authorization … |
| CVE-2026-56337 | 6.9 | 36.2 | Capgo | Capgo | CWE-200 | Capgo - Information Disclosure via Unauthenticated RPC Function exist_app_v2 |
| CVE-2026-11614 | 6.4 | 36.0 | xpro | Xpro Addons — 140+ Widgets for Elementor | CWE-79 | Xpro Addons <= 1.7.2 - Authenticated (Author+) Stored Cross-Site Scripting vi… |
| CVE-2026-10735 | 7.5 | 36.0 | Unknown | smart-post-show-pro | — | ShapedPlugin Multiple Pro Plugins - Backdoor via Compromised Vendor Update Se… |
| CVE-2026-50698 | 4.6 | 36.0 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Stored XSS in Audit Trail template rendering |
| CVE-2026-50700 | 4.6 | 36.0 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Stored XSS in frappe.get_avatar image rendering |
| CVE-2026-50704 | 4.6 | 36.0 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Reflected/Stored XSS in File View breadcrumbs r… |
| CVE-2026-50705 | 4.6 | 36.0 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Stored XSS in Form Dashboard headline rendering |
| CVE-2026-50710 | 4.6 | 36.0 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Stored XSS via eval in Number Card filters_config |
| CVE-2026-50711 | 4.6 | 36.0 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Stored XSS in Number Card filter fields rendering |
| CVE-2026-52798 | 8.9 | 35.5 | gogs | gogs | CWE-79 | Gogs: Stored XSS in `.ipynb` Preview |
| CVE-2026-10745 | 7.9 | 35.4 | upKeeper Solutions | upKeeper Instant Privilege Access | CWE-117 | Improper output neutralization for logs vulnerability in upKeeper Solutions u… |
| CVE-2026-52810 | 7.1 | 35.4 | gogs | gogs | CWE-284 | Gogs: Write to readonly repositories using receive-pack + service=git-upload-… |
| CVE-2026-52799 | 7.5 | 35.0 | gogs | gogs | CWE-639 | Gogs: Missing Authorization in Attachment Download |
| CVE-2026-47267 | 8.3 | 34.7 | gogs | gogs | CWE-918 | Gogs: SSRF in webhook deliveries |
| CVE-2026-9643 | 7.2 | 34.6 | joomunited | WP Meta SEO | CWE-79 | WP Meta SEO <= 4.5.18 - Unauthenticated Stored Cross-Site Scripting via REQUE… |
| CVE-2026-9619 | 4.3 | 34.6 | berfect | Reviews and Rating – Docplanner | CWE-862 | Reviews and Rating <= 1.1.4 - Missing Authorization to Authenticated (Subscri… |
| CVE-2026-31978 | 6.5 | 34.5 | motioneye-project | motioneye | CWE-22 | motionEye: Arbitrary File Read via Path Traversal in Picture/Movie Preview En… |
| CVE-2026-56256 | 7.1 | 34.2 | Capgo | Capgo | CWE-602 | Capgo - Two-Factor Authentication Bypass via Organization Management API |
| CVE-2026-49278 | 6.7 | 34.2 | RocketChat | Rocket.Chat | CWE-285 | Rocket.Chat: Livechat Visitor Profile Disclosure Leaks Bearer Token and Enabl… |
| CVE-2026-52918 | 8.8 | 34.0 | Linux | Linux | — | Bluetooth: serialize accept_q access |
| CVE-2026-52934 | 8.8 | 34.0 | Linux | Linux | — | batman-adv: tvlv: reject oversized TVLV packets |
| CVE-2026-55666 | 9.3 | 33.4 | RocketChat | Rocket.Chat | CWE-287 | Rocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple … |
| CVE-2026-46348 | 8.7 | 33.4 | mastodon | mastodon | CWE-918 | Mastodon: SSRF Bypass via IPv6 Unspecified Address (::) |
| CVE-2026-10092 | 7.2 | 33.4 | nicashmu | Cincopa video and media plug-in | CWE-79 | Cincopa video and media plug-in <= 1.163 - Unauthenticated Stored Cross-Site … |
| CVE-2026-50703 | 4.8 | 33.4 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Stored XSS in Desktop Icon label rendering |
| CVE-2026-50708 | 4.8 | 33.4 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Stored XSS in Multi Select Dialog result rendering |
| CVE-2026-50709 | 4.8 | 33.4 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Stored XSS in Notifications Events color rendering |
| CVE-2026-50712 | 4.8 | 33.4 | Frappe | Frappe Framework | CWE-79 | Frappe Framework 17.0.0-dev - Stored XSS in Tree View node label rendering |
| CVE-2026-55611 | 0.0 | 33.4 | Mintplex-Labs | anything-llm | CWE-639 | AnythingLLM: embed-parsed-file cleanup deletes any parsed file by ID without … |
| CVE-2026-54686 | 4.3 | 33.3 | warpdotdev | warp | CWE-78 | Warp: DCS lifecycle hook spoofing can alter terminal session metadata |
| CVE-2026-7617 | 5.3 | 33.1 | secufor | Secufor_OAuth | CWE-862 | Secufor_OAuth <= 1.0.7 - Missing Authorization to Unauthenticated Account Log… |
| CVE-2026-12094 | 5.3 | 33.1 | iamranit | Advanced Contact Form 7 – Compact DB | CWE-862 | Advanced Contact Form 7 <= 1.0.0 - Missing Authorization to Unauthenticated A… |
| CVE-2026-56223 | 9.3 | 33.1 | Capgo | Capgo | CWE-287 | Capgo - Account Takeover via Cross-Domain SSO Email Assertion in provision-user |
| CVE-2026-52931 | 9.8 | 32.7 | Linux | Linux | — | batman-adv: tp_meter: avoid use of uninit sender vars |
| CVE-2026-53088 | 9.8 | 32.7 | Linux | Linux | CWE-193 | net: bcmgenet: fix off-by-one in bcmgenet_put_txcb |
| CVE-2026-52945 | 7.5 | 32.7 | Linux | Linux | — | Revert "wireguard: device: enable threaded NAPI" |
| CVE-2026-39951 | 8.8 | 32.5 | Cacti | cacti | CWE-89 | Cacti: Stored SQL Injection via graph_name_regexp in Reports feature |
| CVE-2026-12095 | 7.2 | 32.5 | bytuncay | Kargo Takip | CWE-918 | Kargo Takip <= 1.2 - Unauthenticated Server-Side Request Forgery via 'api_url… |
| CVE-2026-53006 | 9.8 | 32.3 | Linux | Linux | CWE-416 | ipv6: fix possible UAF in icmpv6_rcv() |
| CVE-2026-47389 | 8.6 | 32.2 | mastodon | mastodon | CWE-184 | Mastodon: SSRF protection bypass on older Ruby versions |
| CVE-2026-8688 | 4.3 | 32.2 | krishaweb | Advance Nav Menu Manager | CWE-862 | Advance Nav Menu Manager <= 1.3 - Missing Authorization to Authenticated (Sub… |
| CVE-2026-9616 | 4.3 | 32.2 | verenigingvanregistrars | Generate Security.txt | CWE-862 | Generate Security.txt <= 1.0.12 - Missing Authorization to Authenticated (Sub… |
| CVE-2026-52967 | 8.1 | 32.1 | Linux | Linux | CWE-125 | smb/client: fix possible infinite loop and oob read in symlink_data() |
| CVE-2026-8617 | 5.3 | 31.9 | ailchev | SearchPlus | CWE-862 | SearchPlus <= 1.7.1 - Missing Authorization to Unauthenticated Settings Modif… |
| CVE-2026-9172 | 5.3 | 31.8 | ajitdas | Devs Accounting – Simple Accounting and Invoicing Solution | CWE-862 | Devs Accounting <= 1.2.0 - Missing Authorization to Unauthenticated Account D… |
| CVE-2026-55455 | 5.3 | 31.6 | appsmithorg | appsmith | CWE-918 | Appsmith: SSRF in REST API / GraphQL datasource plugins via insufficient host… |
| CVE-2026-39899 | 6.9 | 31.4 | Cacti | cacti | CWE-22 | Cacti: Path Traversal via filename parameter in package_import.php |
| CVE-2026-52805 | 8.7 | 31.1 | gogs | gogs | CWE-918 | Gogs: Migration Redirect Bypass Leads to Internal Repository Theft |
| CVE-2026-13031 | 8.8 | 31.0 | Chrome | CWE-416 | Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a re… | |
| CVE-2026-13033 | 8.8 | 31.0 | Chrome | CWE-125 | Out of bounds read and write in Blink>InterestGroups in Google Chrome prior t… | |
| CVE-2026-13036 | 8.8 | 31.0 | Chrome | CWE-416 | Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a re… | |
| CVE-2026-13038 | 8.8 | 31.0 | Chrome | CWE-416 | Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.19… | |
| CVE-2026-56052 | 7.6 | 31.0 | FunnelKit | Funnel Builder by FunnelKit | CWE-89 | WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.5 - SQL Injection vuln… |
| CVE-2026-12100 | 7.2 | 31.1 | abhisheksaha11 | URL Preview | CWE-918 | URL Preview <= 1.0 - Unauthenticated Server-Side Request Forgery via 'url' Pa… |
| CVE-2026-52955 | 9.8 | 30.8 | Linux | Linux | CWE-125 | libceph: Fix potential out-of-bounds access in crush_decode() |
| CVE-2026-48725 | 8.1 | 30.5 | warpdotdev | warp | CWE-276 | Warp may allow terminal output to access the local clipboard through OSC 52 |
| CVE-2026-54068 | 5.9 | 30.4 | siyuan-note | siyuan | CWE-306 | SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /a… |
| CVE-2026-56351 | 5.3 | 30.3 | n8n | n8n | CWE-89 | n8n - SQL Injection in MySQL, PostgreSQL, and Microsoft SQL Nodes |
| CVE-2026-9709 | 7.7 | 29.8 | Unknown | Cornerstone | — | Themeco Cornerstone < 7.8.9 (Premium, bundled with X Theme) - Subscriber+ Arb… |
| CVE-2026-9710 | 7.7 | 29.8 | Unknown | Cornerstone | — | Themeco Cornerstone < 7.8.8 (Premium, bundled with X Theme) - Subscriber+ Arb… |
| CVE-2026-49246 | 1.7 | 29.7 | jellyfin | jellyfin | CWE-22 | Jellyfin: Potential MKV attachment filename path traversal to RCE |
| CVE-2026-49979 | 5.1 | 29.5 | appsmithorg | appsmith | CWE-918 | Appsmith: SSRF via `POST /api/v1/admin/send-test-email` — JavaMail Bypasses W… |
| CVE-2026-52993 | 9.8 | 29.4 | Linux | Linux | CWE-415 | tipc: fix double-free in tipc_buf_append() |
| CVE-2026-27708 | 7.1 | 29.1 | FOSSBilling | FOSSBilling | CWE-284 | FOSSBilling: IDOR in Servicecustom Client API allows cross-client data access |
| CVE-2026-9183 | 4.3 | 28.8 | 24liveblog | 24liveblog – live blog tool | CWE-200 | 24liveblog <= 2.2 - Authenticated (Contributor+) Exposure of Sensitive Inform… |
| CVE-2026-10091 | 7.2 | 28.7 | cgarvey | Email JavaScript Cloak | CWE-79 | Email JavaScript Cloak <= 1.03 - Unauthenticated Stored Cross-Site Scripting |
| CVE-2026-12760 | 7.1 | 28.7 | TP-Link Systems Inc. | Tapo C200 v3 | CWE-770 | Denial-of-Service Vulnerability via Malformed IPv4 Fragmentation Handling in … |
| CVE-2026-52956 | 7.5 | 28.6 | Linux | Linux | CWE-125 | libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() |
| CVE-2026-57303 | 7.1 | 28.5 | Jenkins Project | Jenkins Assembla Plugin | CWE-918 | Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to … |
| CVE-2026-53949 | 5.3 | 28.5 | TryGhost | Ghost | CWE-200 | Ghost Content API filter bypass reveals private fields |
| CVE-2026-54639 | 8.8 | 28.3 | style-dictionary | style-dictionary | CWE-1321 | Style Dictionary - Prototype Pollution in convertTokenData utility function |
| CVE-2026-52989 | 9.8 | 28.3 | Linux | Linux | CWE-390 | nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers |
| CVE-2026-9620 | 6.4 | 28.2 | joomunited | WP Latest Posts | CWE-79 | WP Latest Posts <= 5.0.11 - Authenticated (Author+) Stored Cross-Site Scripti… |
| CVE-2026-53002 | 9.8 | 28.1 | Linux | Linux | CWE-787 | netfilter: conntrack: remove sprintf usage |
| CVE-2026-9184 | 4.3 | 28.0 | 24liveblog | 24liveblog – live blog tool | CWE-862 | 24liveblog <= 2.2 - Missing Authorization to Authenticated (Author+) Settings… |
| CVE-2026-13035 | 8.8 | 28.0 | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 a… | |
| CVE-2026-53950 | 7.5 | 27.8 | TryGhost | Ghost | CWE-79 | @tryghost/activitypub: XSS in Ghost's ActivityPub client |
| CVE-2026-35025 | 8.6 | 27.5 | ProFTPD Project | ProFTPD | CWE-59 | ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR |
| CVE-2026-56302 | 6.9 | 27.4 | Capgo | Capgo | CWE-284 | Capgo - Unsecured Supabase Images Bucket via Missing Row Level Security |
| CVE-2026-53070 | 7.5 | 27.1 | Linux | Linux | — | sctp: disable BH before calling udp_tunnel_xmit_skb() |
| CVE-2026-53947 | 5.3 | 27.0 | TryGhost | Ghost | CWE-204 | Ghost: Member existence leak via magic link sign-in response |
| CVE-2026-48789 | 4.3 | 26.7 | Mintplex-Labs | anything-llm | CWE-22 | AnythingLLM: Windows path containment bypass in document folder route |
| CVE-2026-45687 | 8.5 | 26.7 | RocketChat | Rocket.Chat | CWE-915 | Rocket.Chat: Authenticated Arbitrary Data Export Theft via Mass Assignment in… |
| CVE-2026-57284 | 4.3 | 26.3 | Jenkins Project | Jenkins Pipeline: Groovy Plugin | CWE-470 | Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restr… |
| CVE-2026-12488 | 6.2 | 25.9 | GeoVision Inc. | GeoVision | CWE-121 | GeoVision GV-VMS V20 GV-Cloud memory corruption vulnerability |
| CVE-2026-49220 | 5.7 | 25.8 | jellyfin | jellyfin | CWE-79 | Jellyfin: Potential XSS in user management |
| CVE-2026-52924 | 9.8 | 25.5 | Linux | Linux | CWE-416 | sctp: purge outqueue on stale COOKIE-ECHO handling |
| CVE-2026-8865 | 6.4 | 25.5 | paradigmatools | Avalon23 Products Filter for WooCommerce | CWE-79 | Avalon23 Products Filter for WooCommerce <= 1.1.6 - Authenticated (Contributo… |
| CVE-2026-11370 | 6.4 | 25.4 | joomunited | WP Meta SEO | CWE-918 | WP Meta SEO <= 4.5.18 - Authenticated (Contributor+) Server-Side Request Forg… |
| CVE-2026-53944 | 5.8 | 25.2 | TryGhost | Ghost | CWE-184 | Ghost: Private IP filtering bypass to make server-side requests to internal s… |
| CVE-2026-57288 | 3.7 | 25.2 | Jenkins Project | Jenkins Active Directory Plugin | CWE-90 | Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user n… |
| CVE-2026-56244 | 7.1 | 25.2 | Capgo | Capgo | CWE-200 | Capgo - Webhook Signing Secret Disclosure via Non-Admin API Key |
| CVE-2026-8614 | 4.3 | 24.8 | assistioai | Assistio | CWE-862 | Assistio <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Plug… |
| CVE-2026-55759 | 7.4 | 24.6 | RocketChat | Rocket.Chat | CWE-287 | Rocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and … |
| CVE-2026-8896 | 6.4 | 24.3 | mirsoftware | MIR blocks and shortcodes | CWE-79 | MIR blocks and shortcodes <= 1.0.0 - Authenticated (Contributor+) Stored Cros… |
| CVE-2026-13028 | 9.6 | 24.2 | Chrome | CWE-416 | Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 a… | |
| CVE-2026-13032 | 9.6 | 24.2 | Chrome | CWE-416 | Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 a… | |
| CVE-2026-13026 | 8.8 | 24.2 | Chrome | CWE-416 | Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.… | |
| CVE-2026-13027 | 8.8 | 24.2 | Chrome | CWE-416 | Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed… | |
| CVE-2026-53072 | 8.8 | 24.0 | Linux | Linux | CWE-667 | Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER |
| CVE-2026-3652 | 7.2 | 24.0 | n/a | ARforms | CWE-79 | ARForms <= 7.1.3 - Unauthenticated Stored Cross-Site Scripting via 'value' Pa… |
| CVE-2026-45757 | 2.3 | 23.5 | RocketChat | Rocket.Chat | CWE-613 | Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking exis… |
| CVE-2026-49277 | 2.3 | 23.5 | RocketChat | Rocket.Chat | CWE-613 | Rocket.Chat: OAuth access and refresh tokens remain valid after account deact… |
| CVE-2026-56257 | 7.1 | 23.5 | Capgo | Capgo | CWE-284 | Capgo - Authorization Bypass in App Ownership Transfer via Direct PostgREST U… |
| CVE-2026-56231 | 7.2 | 22.9 | Capgo | Capgo | CWE-285 | Capgo - Broken Object Level Authorization in Build Job Control via jobId Para… |
| CVE-2026-11877 | 6.3 | 22.6 | OpenText | Access Manager | CWE-648 | Missing Authorization Vulnerability in OpenText Access Manager |
| CVE-2026-56310 | 5.3 | 22.5 | Cap-go | capgo | CWE-285 | Cap-go - Authorization Bypass in Organization Members Endpoint via API Key Sc… |
| CVE-2026-53086 | 9.8 | 22.4 | Linux | Linux | CWE-362 | net: bcmgenet: fix racing timeout handler |
| CVE-2026-13025 | 8.3 | 22.3 | Chrome | CWE-20 | Race in DevTools in Google Chrome prior to 149.0.7827.197 allowed a remote at… | |
| CVE-2026-54070 | 7.1 | 22.0 | siyuan-note | siyuan | CWE-79 | SiYuan: Stored XSS in Bazaar marketplace via package README event handlers |
| CVE-2026-13140 | 1.1 | 21.5 | Thinkst Applied Research | Canarytokens | CWE-79 | Stored Cross-Site Scripting in Canarytokens.org |
| CVE-2026-56761 | 5.3 | 21.3 | hono | hono | CWE-79 | hono - HTML Injection via Improper JSX Attribute Name Handling in SSR |
| CVE-2026-13023 | 5.3 | 20.7 | Chrome | CWE-457 | Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a r… | |
| CVE-2026-13030 | 5.3 | 20.7 | Chrome | CWE-457 | Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 … | |
| CVE-2026-8622 | 6.1 | 20.5 | pixelwelt | Image Sizes on Demand | CWE-79 | Image Sizes on Demand <= 1.3 - Reflected Cross-Site Scripting via PHP_SELF Se… |
| CVE-2026-8628 | 6.1 | 20.5 | owencutajar | EntreDroppers | CWE-79 | EntreDroppers <= 1.1.2 - Reflected Cross-Site Scripting via PHP_SELF Parameter |
| CVE-2026-52796 | 3.5 | 20.4 | gogs | gogs | CWE-1336 | Gogs: DoS in rendering issue index pattern |
| CVE-2026-52795 | 4.3 | 20.0 | gogs | gogs | CWE-863 | Gogs: Authorization Bypass in Watch API allows any user to monitor private re… |
| CVE-2026-57285 | 4.3 | 20.0 | Jenkins Project | Jenkins GitHub Branch Source Plugin | CWE-862 | A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v… |
| CVE-2026-57286 | 4.3 | 20.0 | Jenkins Project | Jenkins Git Parameter Plugin | CWE-862 | A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_… |
| CVE-2026-57300 | 4.3 | 20.0 | Jenkins Project | Jenkins MCP Server Plugin | CWE-862 | A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe … |
| CVE-2026-57302 | 4.3 | 20.0 | Jenkins Project | Jenkins FitNesse Plugin | CWE-256 | Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job … |
| CVE-2026-10753 | 2.7 | 20.1 | Unknown | Site Kit by Google | — | Site Kit by Google < 1.176.0 - Editor+ Email Reporting Settings Update |
| CVE-2026-12986 | 7.3 | 19.3 | Payara | Payara Server | CWE-352 | A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.… |
| CVE-2026-57293 | 4.3 | 18.7 | Jenkins Project | Jenkins Gitee Plugin | CWE-862 | An incorrect permission check in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ a… |
| CVE-2026-39897 | 5.3 | 17.7 | Cacti | cacti | CWE-79 | Cacti has a Reflected XSS Vulnerability via html_auth_footer |
| CVE-2026-39900 | 5.3 | 17.7 | Cacti | cacti | CWE-79 | Cacti: Reflected XSS via tab parameter in auth_profile.php JavaScript context |
| CVE-2026-55583 | 7.6 | 17.4 | twentyhq | twenty | CWE-639 | Twenty: Cross-workspace IDOR in AgentTurnResolver |
| CVE-2026-6292 | 4.3 | 17.5 | manuelpadillac | MP Customize Login Page | CWE-352 | MP Customize Login Page <= 1.0 - Cross-Site Request Forgery to Settings Update |
| CVE-2026-53071 | 8.8 | 17.3 | Linux | Linux | CWE-667 | Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp |
| CVE-2026-57294 | 5.4 | 16.7 | Jenkins Project | Jenkins EC2 Fleet Plugin | CWE-862 | A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81… |
| CVE-2026-57304 | 5.4 | 16.7 | Jenkins Project | Jenkins Assembla Plugin | CWE-862 | A missing permission check in Jenkins Assembla Plugin 1.4 and earlier allows … |
| CVE-2026-57290 | 4.3 | 16.5 | Jenkins Project | Jenkins Priority Sorter Plugin | CWE-352 | A cross-site request forgery (CSRF) vulnerability in Jenkins Priority Sorter … |
| CVE-2026-57282 | 5.0 | 16.5 | Jenkins Project | Jenkins Git client Plugin | CWE-78 | Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the wor… |
| CVE-2026-48703 | 7.8 | 16.4 | warpdotdev | warp | CWE-78 | Warp: Command Injection via Warp code search tool arguments |
| CVE-2026-54906 | 2.1 | 16.4 | ruby-concurrency | concurrent-ruby | CWE-414 | concurrent-ruby: ReadWriteLock allows wrong-thread write release and stray re… |
| CVE-2026-57297 | 4.3 | 16.1 | Jenkins Project | Jenkins Contrast Continuous Application Security Plugin | CWE-862 | A missing permission check in Jenkins Contrast Continuous Application Securit… |
| CVE-2026-57299 | 4.3 | 16.1 | Jenkins Project | Jenkins Contrast Continuous Application Security Plugin | CWE-862 | Missing permission checks in Jenkins Contrast Continuous Application Security… |
| CVE-2026-52800 | 8.8 | 15.9 | gogs | gogs | CWE-352 | Gogs: CSRF Leading to Organization Owner Takeover |
| CVE-2026-13029 | 7.5 | 15.6 | Chrome | CWE-416 | Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197… | |
| CVE-2026-56358 | 5.1 | 15.2 | n8n | n8n | CWE-79 | n8n - Stored Cross-Site Scripting in Form Trigger Node |
| CVE-2026-10642 | 4.6 | 15.2 | zephyrproject | zephyr | CWE-835 | Unbounded TX busy-loop DoS in Zephyr PL011 UART driver under CTS hardware flo… |
| CVE-2026-52943 | 7.8 | 14.6 | Linux | Linux | CWE-416 | net: skbuff: fix missing zerocopy reference in pskb_carve helpers |
| CVE-2026-57283 | 4.3 | 14.4 | Jenkins Project | Jenkins Pipeline: Groovy Plugin | CWE-352 | A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy… |
| CVE-2026-52812 | 7.1 | 14.4 | gogs | gogs | CWE-345 | Gogs: LFS dedupe path leaks private repo content across tenants |
| CVE-2026-57291 | 5.4 | 13.6 | Jenkins Project | Jenkins Gitee Plugin | CWE-862 | Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and e… |
| CVE-2026-10531 | 5.4 | 13.1 | Unknown | AI Share & Summarize | — | AI Share & Summarize < 2.0.4 - Contributor+ Stored XSS via title_style Shortc… |
| CVE-2026-53948 | 5.4 | 13.1 | TryGhost | Ghost | CWE-434 | Ghost: File Upload Content-Type Spoofing |
| CVE-2026-13024 | 4.2 | 12.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in Navigation in Google Chrome pri… | |
| CVE-2026-46423 | 9.3 | 12.5 | RocketChat | Rocket.Chat | CWE-347 | Rocket.Chat: SAML signature validation skipped when IdP certificate field is … |
| CVE-2026-48721 | 8.6 | 12.5 | warpdotdev | warp | CWE-180 | Warp: Env-var prefixes can lead to denylisted command autoexecution |
| CVE-2026-11878 | 8.2 | 12.4 | OpenText | Access Manager | CWE-79 | Reflected Cross-Site Scripting vulnerability in OpenText Access Manager |
| CVE-2026-9539 | 6.5 | 12.5 | freedesktop.org | libslirp | CWE-125 | libslirp TCP URG OOB Read Information Leak |
| CVE-2026-57295 | 5.4 | 12.4 | Jenkins Project | Jenkins EC2 Fleet Plugin | CWE-352 | A cross-site request forgery (CSRF) vulnerability in Jenkins EC2 Fleet Plugin… |
| CVE-2026-57305 | 5.4 | 12.4 | Jenkins Project | Jenkins Assembla Plugin | CWE-352 | A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Plugin … |
| CVE-2026-53945 | 4.0 | 11.6 | TryGhost | Ghost | CWE-367 | Ghost: Server-side request forgery via DNS rebinding in external request hand… |
| CVE-2026-12537 | 10.0 | 11.3 | Google Cloud | Gemini CLI | CWE-78 | Unauthenticated Remote Code Execution in Gemini CLI CI/CD Workflows |
| CVE-2026-57307 | 4.2 | 10.8 | Jenkins Project | Jenkins Zowe zDevOps Plugin | CWE-862 | A missing permission check in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_4… |
| CVE-2026-44022 | 5.5 | 10.7 | docling-project | docling | CWE-22 | Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands |
| CVE-2026-53946 | 5.4 | 10.7 | TryGhost | Ghost | CWE-918 | Ghost: Mobiledoc image-size fetch SSRF |
| CVE-2026-13034 | 4.7 | 10.2 | Chrome | CWE-346 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.782… | |
| CVE-2026-13021 | 4.3 | 10.2 | Chrome | CWE-346 | Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrom… | |
| CVE-2026-52809 | 6.8 | 10.0 | gogs | gogs | CWE-324 | Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_P… |
| CVE-2026-13022 | 6.5 | 9.3 | Chrome | CWE-346 | Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827… | |
| CVE-2026-52969 | 7.8 | 9.2 | Linux | Linux | CWE-129 | KVM: Reject wrapped offset in kvm_reset_dirty_gfn() |
| CVE-2026-46349 | 5.3 | 9.2 | mastodon | mastodon | CWE-347 | Mastodon: LD-Signature Bypass via JSON-LD Named-Graph Restructuring |
| CVE-2026-57287 | 4.3 | 9.2 | Jenkins Project | Jenkins Job Configuration History Plugin | CWE-312 | Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier doe… |
| CVE-2026-53090 | 7.8 | 9.0 | Linux | Linux | CWE-253 | bpf: Fix ld_{abs,ind} failure path analysis in subprogs |
| CVE-2026-52912 | 7.8 | 9.0 | Linux | Linux | CWE-416 | netfilter: nf_queue: hold bridge skb->dev while queued |
| CVE-2026-10552 | 4.3 | 8.8 | jotis | Blue Captcha | CWE-352 | Blue Captcha <= 2.0.1 - Cross-Site Request Forgery via 'blcap_action' Parameter |
| CVE-2026-12681 | 8.9 | 8.8 | go-attestation | CWE-1285 | Improper Validation of Specified Index, Position, or Offset in Input vulnerab… | |
| CVE-2026-9724 | 4.3 | 8.7 | motordesk | MotorDesk | CWE-352 | MotorDesk <= 1.1.2 - Cross-Site Request Forgery to Settings Update |
| CVE-2026-11997 | 4.3 | 8.7 | seo_tools | Bulk SEO Image | CWE-352 | Bulk SEO Image <= 1.1 - Cross-Site Request Forgery to Settings Update |
| CVE-2025-60473 | 5.5 | 8.4 | n/a | n/a | CWE-476 | A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter… |
| CVE-2026-53033 | 7.8 | 8.2 | Linux | Linux | CWE-416 | bpf, sockmap: Take state lock for af_unix iter |
| CVE-2026-53130 | 7.8 | 8.2 | Linux | Linux | CWE-191 | fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START |
| CVE-2026-52972 | 5.5 | 8.0 | Linux | Linux | CWE-190 | crypto: af_alg - Cap AEAD AD length to 0x80000000 |
| CVE-2026-47733 | 4.4 | 8.0 | RocketChat | Rocket.Chat | CWE-79 | Rocket.Chat: Missing URL protocol sanitization in ImageElement allows javascr… |
| CVE-2026-57306 | 4.2 | 8.0 | Jenkins Project | Jenkins Zowe zDevOps Plugin | CWE-352 | A cross-site request forgery (CSRF) vulnerability in Jenkins Zowe zDevOps Plu… |
| CVE-2025-60471 | 5.5 | 7.9 | n/a | n/a | CWE-416 | A use-after-free in the gf_filter_pid_reconfigure_task_discard function (/fil… |
| CVE-2026-11968 | 5.5 | 7.8 | TortoiseGit team | TortoiseGit | CWE-88 | Improper Neutralization of Argument Delimiters in a Command ('Argument Inject… |
| CVE-2026-52961 | 5.5 | 7.8 | Linux | Linux | CWE-617 | ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size |
| CVE-2026-50128 | 5.3 | 7.9 | mastodon | mastodon | CWE-354 | Mastodon: Spoofing of attribution domains |
| CVE-2026-53081 | 7.8 | 7.6 | Linux | Linux | CWE-386 | bpf: Enforce regsafe base id consistency for BPF_ADD_CONST scalars |
| CVE-2026-53092 | 7.8 | 7.6 | Linux | Linux | CWE-393 | bpf: Fix linked reg delta tracking when src_reg == dst_reg |
| CVE-2026-52951 | 7.8 | 7.3 | Linux | Linux | CWE-416 | drm/xe/dma-buf: handle empty bo and UAF races |
| CVE-2026-52952 | 8.8 | 7.3 | Linux | Linux | CWE-617 | iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset |
| CVE-2026-53091 | 8.4 | 7.3 | Linux | Linux | CWE-131 | net: pull headers in qdisc_pkt_len_segs_init() |
| CVE-2026-8905 | 6.1 | 7.3 | osiris8 | Osiris Signature Banner | CWE-352 | Osiris Signature Banner <= 0.5 - Cross-Site Request Forgery to Stored Cross-S… |
| CVE-2026-56370 | 4.8 | 7.2 | ImageMagick | ImageMagick | CWE-125 | ImageMagick - Out-of-bounds Access in ConnectedComponentsImage via connected-… |
| CVE-2026-53075 | 8.8 | 7.1 | Linux | Linux | — | ppp: require CAP_NET_ADMIN in target netns for unattached ioctls |
| CVE-2026-52935 | 7.8 | 7.1 | Linux | Linux | CWE-787 | xfrm: espintcp: do not reuse an in-progress partial send |
| CVE-2026-52962 | 7.8 | 7.1 | Linux | Linux | CWE-787 | ceph: fix a buffer leak in __ceph_setxattr() |
| CVE-2026-52987 | 7.8 | 7.1 | Linux | Linux | CWE-1341 | drm/amdgpu: avoid double drm_exec_fini() in userq validate |
| CVE-2026-52992 | 7.8 | 7.1 | Linux | Linux | CWE-787 | fs/adfs: validate nzones in adfs_validate_bblk() |
| CVE-2026-53077 | 7.8 | 7.1 | Linux | Linux | — | net/rds: Restrict use of RDS/IB to the initial network namespace |
| CVE-2026-53096 | 7.8 | 7.1 | Linux | Linux | CWE-476 | bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path |
| CVE-2026-52968 | 7.1 | 7.1 | Linux | Linux | CWE-125 | KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic |
| CVE-2026-48028 | 6.5 | 7.1 | mastodon | mastodon | CWE-354 | Mastodon: Removal of integrity-protected JSON entries from signed activities |
| CVE-2026-53047 | 5.5 | 7.1 | Linux | Linux | — | efi/capsule-loader: fix incorrect sizeof in phys array reallocation |
| CVE-2026-53053 | 8.8 | 7.0 | Linux | Linux | — | iommu/amd: Fix clone_alias() to use the original device's devid |
| CVE-2026-53031 | 7.8 | 7.0 | Linux | Linux | — | bpf: Validate node_id in arena_alloc_pages() |
| CVE-2026-53078 | 7.8 | 7.0 | Linux | Linux | CWE-125 | bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops |
| CVE-2026-53085 | 7.8 | 7.1 | Linux | Linux | CWE-416 | bpf: fix mm lifecycle in open-coded task_vma iterator |
| CVE-2026-53094 | 7.8 | 7.0 | Linux | Linux | — | bpf: Fix stale offload->prog pointer after constant blinding |
| CVE-2026-53110 | 7.8 | 7.0 | Linux | Linux | — | s390/bpf: Zero-extend bpf prog return values and kfunc arguments |
| CVE-2026-53115 | 7.8 | 7.0 | Linux | Linux | CWE-416 | bus: fsl-mc: use generic driver_override infrastructure |
| CVE-2026-53117 | 7.8 | 7.0 | Linux | Linux | CWE-416 | s390/cio: use generic driver_override infrastructure |
| CVE-2026-53119 | 7.8 | 7.0 | Linux | Linux | CWE-416 | platform/wmi: use generic driver_override infrastructure |
| CVE-2026-53120 | 7.8 | 7.0 | Linux | Linux | CWE-416 | PCI: use generic driver_override infrastructure |
| CVE-2026-13006 | 7.0 | 7.0 | QOS.CH Sarl | Logback-core | CWE-20 | Incomplete protection against CVE-2025-11226 |
| CVE-2026-53057 | 8.8 | 6.8 | Linux | Linux | — | iommu/riscv: Add IOTINVAL after updating DDT/PDT entries |
| CVE-2026-53067 | 7.8 | 6.8 | Linux | Linux | CWE-415 | PCI: endpoint: pci-ep-msi: Fix error unwind and prevent double alloc |
| CVE-2026-53109 | 7.8 | 6.8 | Linux | Linux | CWE-416 | powerpc/pgtable-frag: Fix bad page state in pte_frag_destroy |
| CVE-2026-53118 | 7.8 | 6.8 | Linux | Linux | CWE-416 | vdpa: use generic driver_override infrastructure |
| CVE-2026-53012 | 5.5 | 6.7 | Linux | Linux | CWE-476 | nexthop: fix IPv6 route referencing IPv4 nexthop |
| CVE-2026-52944 | 5.5 | 6.6 | Linux | Linux | — | ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET… |
| CVE-2026-52996 | 5.5 | 6.6 | Linux | Linux | CWE-401 | ksmbd: fix durable fd leak on ClientGUID mismatch in durable v2 open |
| CVE-2026-42450 | 8.4 | 6.6 | AcademySoftwareFoundation | OpenColorIO | CWE-120 | OpenColorIO vulnerable to stack buffer overflow via unbounded `sscanf %s` in … |
| CVE-2026-52947 | 7.8 | 6.5 | Linux | Linux | CWE-416 | net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove |
| CVE-2026-53011 | 7.8 | 6.5 | Linux | Linux | CWE-416 | net/sched: taprio: fix use-after-free in advance_sched() on schedule switch |
| CVE-2026-53112 | 7.8 | 6.5 | Linux | Linux | CWE-416 | wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prep… |
| CVE-2026-53097 | 7.8 | 6.5 | Linux | Linux | CWE-416 | wifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work() |
| CVE-2026-53098 | 7.8 | 6.5 | Linux | Linux | CWE-416 | wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work() |
| CVE-2025-60468 | 5.5 | 6.4 | n/a | n/a | CWE-122 | GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88… |
| CVE-2026-52966 | 5.5 | 6.4 | Linux | Linux | — | drm: Replace old pointer to new idr |
| CVE-2026-52953 | 7.1 | 6.3 | Linux | Linux | CWE-125 | iommu/vt-d: Fix oops due to out of scope access |
| CVE-2026-52971 | 7.8 | 6.3 | Linux | Linux | CWE-416 | net: ena: PHC: Fix potential use-after-free in get_timestamp |
| CVE-2026-52917 | 7.1 | 6.1 | Linux | Linux | CWE-125 | sctp: diag: reject stale associations in dump_one path |
| CVE-2026-53041 | 7.1 | 6.1 | Linux | Linux | CWE-787 | ocfs2: fix listxattr handling when the buffer is full |
| CVE-2026-53068 | 7.1 | 6.1 | Linux | Linux | CWE-190 | drm/komeda: fix integer overflow in AFBC framebuffer size check |
| CVE-2026-53076 | 7.1 | 6.0 | Linux | Linux | CWE-125 | bpf: Fix OOB in pcpu_init_value |
| CVE-2026-53024 | 7.8 | 5.9 | Linux | Linux | CWE-416 | greybus: raw: fix use-after-free if write is called after disconnect |
| CVE-2026-53025 | 7.8 | 5.9 | Linux | Linux | CWE-416 | greybus: raw: fix use-after-free on cdev close |
| CVE-2026-53089 | 7.8 | 5.9 | Linux | Linux | CWE-416 | bpf: Fix use-after-free in offloaded map/prog info fill |
| CVE-2026-53116 | 7.8 | 5.9 | Linux | Linux | CWE-416 | s390/ap: use generic driver_override infrastructure |
| CVE-2026-53044 | 7.1 | 5.8 | Linux | Linux | CWE-125 | soc/tegra: cbb: Fix incorrect ARRAY_SIZE in fabric lookup tables |
| CVE-2026-53040 | 7.1 | 5.6 | Linux | Linux | CWE-416 | ocfs2: validate bg_bits during freefrag scan |
| CVE-2026-52913 | 5.5 | 5.6 | Linux | Linux | CWE-476 | batman-adv: v: stop OGMv2 on disabled interface |
| CVE-2026-52916 | 5.5 | 5.6 | Linux | Linux | — | batman-adv: frag: disallow unicast fragment in fragment |
| CVE-2026-52921 | 5.5 | 5.6 | Linux | Linux | CWE-835 | netfilter: ipset: stop hash:* range iteration at end |
| CVE-2026-52925 | 5.5 | 5.6 | Linux | Linux | CWE-476 | vrf: Fix a potential NPD when removing a port from a VRF |
| CVE-2026-52926 | 5.5 | 5.6 | Linux | Linux | — | batman-adv: clear current gateway during teardown |
| CVE-2026-52936 | 5.5 | 5.5 | Linux | Linux | — | crypto: jitterentropy - replace long-held spinlock with mutex |
| CVE-2026-52939 | 5.5 | 5.6 | Linux | Linux | CWE-476 | net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion |
| CVE-2026-52941 | 5.5 | 5.6 | Linux | Linux | CWE-476 | net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint |
| CVE-2026-52963 | 5.5 | 5.6 | Linux | Linux | — | ALSA: usb-audio: Bound MIDI endpoint descriptor scans |
| CVE-2026-52964 | 5.5 | 5.5 | Linux | Linux | — | ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans |
| CVE-2026-52970 | 5.5 | 5.6 | Linux | Linux | — | netfilter: nft_ct: fix missing expect put in obj eval |
| CVE-2026-52980 | 5.5 | 5.5 | Linux | Linux | CWE-476 | sched/fair: Clear rel_deadline when initializing forked entities |
| CVE-2026-52985 | 5.5 | 5.6 | Linux | Linux | CWE-908 | netdevsim: zero initialize struct iphdr in dummy sk_buff |
Results continue: ranks 401–520.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-06-24 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.