boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Wednesday, June 24, 2026 · all times UTC← 2026-06-23 · archive · 2026-06-25 →

Security Box Score — June 24, 2026

520 CVEs published, led by Linux (219).

520 CVEs published June 24, 2026: 56 critical, 226 high, 227 medium, 10 low; 0 in the KEV catalog at press time; 16 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 120 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published617110632——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

481 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux319128610476741411120.27.8.0014+92 ▲
google70487985466299297760.78.1.0023+688 ▲
microsoft220756585201726286192.57.8.0045+60 ▲
red hat931879769012200.06.5.0029+83 ▲
apple146612142288710.65.7.0019-1 ▼
canonical2161465000.05.5.0010+2 ▲
freebsd070520000.07.8.0020-7 ▼
suse461410000.08.6.0029+2 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco92165100561047.67.2.0438+4 ▲
netgear171700161000.04.3.0024+17 ▲
palo alto networks911127113218.25.9.0022+7 ▲
ubiquiti81174003327.39.9.0083+6 ▲
ivanti49450025555.68.8.5187+2 ▲
checkpoint3915303111.17.5.0410+3 ▲
fortinet29432028333.38.3.0076+1 ▲
f56843104112.58.9.0225+4 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache9212618445583310.86.5.0051+83 ▲
mozilla49551118260900.07.3.0026+44 ▲
gitlab1118041224211.14.8.0024+11 ▲
docker470520000.08.2.0016+1 ▲
drupal0511304120.05.1.0026-3 ▼
github021100000.08.1.03470
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2422701321161842720.78.8.0040+242 ▲
adobe1321344517721921.55.5.0021+132 ▲
ibm32811935270600.07.5.0031+32 ▲
progress591710600.07.5.0036+1 ▲
solarwinds36231010466.77.8.6082+3 ▲
veeam142200100.09.0.0052+1 ▲
zohocorp131110000.08.4.01700
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5 ▲
d-link9110425300.05.5.0058+8 ▲
siemens780440000.07.5.0020+6 ▲
rockwell automation771510000.08.7.0030+7 ▲
abb660420000.07.2.0018+6 ▲
moxa550320000.07.0.0029+5 ▲
dahua330111000.06.9.0036+3 ▲
mitsubishi electric330300000.08.7.0064+3 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7273231391000.06.5.0024+72 ▲
openclaw61670352210000.07.0.0021+61 ▲
sourcecodester3759002534000.02.1.0026+33 ▲
themerex585855300000.08.1.0043+58 ▲
edimax556033023100.07.4.0070-20 ▼
jenkins project364909391300.04.8.0025+36 ▲
dell3149124240212.07.0.0017+19 ▲
capgo4646222211000.07.0.0039+46 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9991100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-34910.874799.710.0
CVE-2026-34908.851999.710.0
CVE-2026-50751.837799.79.3
CVE-2026-48907.781099.510.0
CVE-2026-34909.639099.210.0
CVE-2026-49160.538398.97.5
CVE-2026-10523.518798.99.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9991KEV
CVE-2026-3491010.0.8747KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.7810KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-4817210.0.1891KEV
CVE-2026-4508710.0.1296
CVE-2026-5375310.0.0290
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
Most disclosures (vendor)
VendorCVEs
google856
linux733
oracle267
microsoft226
adobe132
red hat125
apache95
ibm81
spring72
openclaw67
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco10
apple7
google6
ivanti5
solarwinds4
berriai3
fortinet3
smartertools3
ubiquiti3
Most-affected ecosystems
EcosystemAdvisories
Maven37
Packagist22
PyPI10
npm3
Fastest to KEV
CVEVendorDays
CVE-2025-48595Google0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-28318SolarWinds0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
CVE-2026-34910Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171680
CVE-2021-27102n/a2021-11-171680
CVE-2021-27101n/a2021-11-171680
CVE-2021-27103n/a2021-11-171680
CVE-2021-21017Adobe2021-11-171680
CVE-2021-28550Adobe2021-11-171680
CVE-2021-42013Apache Software Foundation2021-11-171680
CVE-2021-41773Apache Software Foundation2021-11-171680
CVE-2021-30858Apple2021-11-171680
CVE-2021-30860Apple2021-11-171680

Transactions

EXPLOIT PUBLISHED — appsmithorg appsmith: 3 CVEs (CVE-2026-49979, CVE-2026-50189, CVE-2026-55454). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2025-60466. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-60467. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-60468. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-60471. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-60473. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-60474. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-71332 (Flowise). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-10642 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-11998 (Google AngularJS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-53765 (ChromeDevTools chrome-devtools-mcp). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-53766 (ChromeDevTools chrome-devtools-mcp). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54297 (lostisland faraday). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54904 (ruby-concurrency concurrent-ruby). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56270 (Flowise). Public exploit reference added.

DUE DATE PASSED — CVE-2026-11645 (Google Chrome). CISA remediation deadline was June 23, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-20245 (Cisco Catalyst SD-WAN Controller). CISA remediation deadline was June 23, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-7473 (Arista Networks EOS). CISA remediation deadline was June 23, 2026; still in catalog.

Yesterday's Results

How to read these box scores · glossary

520 CVEs published. 25 box scores and 375 table rows below; the remaining 120 continue on page 2 — every CVE is listed, nothing truncated.

Gogs: RCE via git rebase --exec argument injection in pull request merge
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0793   94.3     —
AFFECTED
  Product  Versions    Fixed
  gogs     < 0.14.3 –  —
TIMELINE
  Jun 8   Reserved by CNA
  Jun 24  Published (CNA: GitHub_M)
CWE-77 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Deferred
Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0549   92.2     —
AFFECTED
  Product          Versions     Fixed
  NetVault Backup  14.0.0.19 –  —
TIMELINE
  May 27  Reserved by CNA
  Jun 24  Published (CNA: zdi)
CWE-78 · CNA: zdi · CVSS v3.0 · 2 references · NVD status: Analyzed
motioneye-project motioneye — motionEye: World-Readable Configuration File Exposes Admin Password Hash
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  N  N    5.5   .0295   86.1     —
AFFECTED
  Product    Versions    Fixed
  motioneye  < 0.44.0 –  —
TIMELINE
  Mar 11  Reserved by CNA
  Jun 24  Published (CNA: GitHub_M)
CWE-200, CWE-522, CWE-732 · CNA: GitHub_M · CVSS v3.1 · 2 references · NVD status: Deferred
GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0270   84.8     —
AFFECTED
  Product        Versions  Fixed
  GV-I/O Box 4E  V2.09 –   V2.12
TIMELINE
  Jun 17  Reserved by CNA
  Jun 24  Published (CNA: GV)
CWE-78 · CNA: GV · CVSS v3.1 · 2 references · NVD status: Deferred
GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0270   84.8     —
AFFECTED
  Product        Versions  Fixed
  GV-I/O Box 4E  V2.09 –   V2.12
TIMELINE
  Jun 22  Reserved by CNA
  Jun 24  Published (CNA: GV)
CWE-78 · CNA: GV · CVSS v3.1 · 2 references · NVD status: Deferred
GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0270   84.8     —
AFFECTED
  Product        Versions  Fixed
  GV-I/O Box 4E  V2.09 –   V2.12
TIMELINE
  Jun 22  Reserved by CNA
  Jun 24  Published (CNA: GV)
CWE-78 · CNA: GV · CVSS v3.1 · 2 references · NVD status: Deferred
GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0270   84.8     —
AFFECTED
  Product        Versions  Fixed
  GV-I/O Box 4E  V2.09 –   V2.12
TIMELINE
  Jun 22  Reserved by CNA
  Jun 24  Published (CNA: GV)
CWE-78 · CNA: GV · CVSS v3.1 · 2 references · NVD status: Deferred
siyuan-note siyuan — SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0239   82.6     —
AFFECTED
  Product  Versions   Fixed
  siyuan   < 3.7.0 –  —
TIMELINE
  Jun 11  Reserved by CNA
  Jun 24  Published (CNA: GitHub_M)
CWE-22, CWE-23, CWE-1188 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Deferred
ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0223   81.4     —
AFFECTED
  Product  Versions       Fixed
  Unizon   2.7.262.002 –  —
TIMELINE
  May 27  Reserved by CNA
  Jun 24  Published (CNA: zdi)
CWE-22 · CNA: zdi · CVSS v3.0 · 2 references · NVD status: Analyzed
ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0223   81.4     —
AFFECTED
  Product  Versions       Fixed
  Unizon   2.7.262.002 –  —
TIMELINE
  May 27  Reserved by CNA
  Jun 24  Published (CNA: zdi)
CWE-22 · CNA: zdi · CVSS v3.0 · 2 references · NVD status: Analyzed
Flowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0205   79.7     —
AFFECTED
  Product  Versions     Fixed
  Flowise  unspecified  3.1.0
TIMELINE
  Jun 20  Reserved by CNA
  Jun 24  Public exploit reference published
  Jun 24  Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Analyzed
Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0189   77.9     —
AFFECTED
  Product  Versions     Fixed
  Unraid   1161ec120 –  —
TIMELINE
  May 27  Reserved by CNA
  Jun 24  Published (CNA: zdi)
CWE-78 · CNA: zdi · CVSS v3.0 · 1 reference · NVD status: Analyzed
Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0189   77.9     —
AFFECTED
  Product  Versions     Fixed
  Unraid   1161ec120 –  —
TIMELINE
  May 27  Reserved by CNA
  Jun 24  Published (CNA: zdi)
CWE-78 · CNA: zdi · CVSS v3.0 · 1 reference · NVD status: Analyzed
ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0185   77.5     —
AFFECTED
  Product  Versions       Fixed
  Unizon   2.7.262.002 –  —
TIMELINE
  May 27  Reserved by CNA
  Jun 24  Published (CNA: zdi)
CWE-22 · CNA: zdi · CVSS v3.0 · 2 references · NVD status: Analyzed
Cacti: Command Injection via escape_command() no-op in RRDtool execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0169   75.3     —
AFFECTED
  Product  Versions    Fixed
  cacti    < 1.2.31 –  —
TIMELINE
  Apr 9   Reserved by CNA
  Jun 24  Published (CNA: GitHub_M)
CWE-78, CWE-88 · CNA: GitHub_M · CVSS v4.0 · 2 references · NVD status: Analyzed
ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  N  H  H    6.5   .0151   72.5     —
AFFECTED
  Product  Versions       Fixed
  Unizon   2.7.262.002 –  —
TIMELINE
  May 27  Reserved by CNA
  Jun 24  Published (CNA: zdi)
CWE-22 · CNA: zdi · CVSS v3.1 · 2 references · NVD status: Analyzed
ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  N  H  H    6.5   .0151   72.5     —
AFFECTED
  Product  Versions       Fixed
  Unizon   2.7.262.002 –  —
TIMELINE
  May 27  Reserved by CNA
  Jun 24  Published (CNA: zdi)
CWE-22 · CNA: zdi · CVSS v3.1 · 2 references · NVD status: Analyzed
Gogs: Unauthenticated Organization Teams Information Disclosure via API
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    5.5   .0149   72.1     —
AFFECTED
  Product  Versions    Fixed
  gogs     < 0.14.3 –  —
TIMELINE
  Jun 8   Reserved by CNA
  Jun 24  Published (CNA: GitHub_M)
CWE-200 · CNA: GitHub_M · CVSS v4.0 · 1 reference · NVD status: Deferred
warpdotdev warp — Warp: Remote SSH cwd can lead to unauthorized remote command execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0140   70.3     —
AFFECTED
  Product  Versions                                                           Fixed
  warp     >= 0.2023.03.21.08.02.stable_00, < 0.2026.05.13.09.15.stable_01 –  —
TIMELINE
  May 22  Reserved by CNA
  Jun 24  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v3.1 · 2 references · NVD status: Deferred
feast-dev feast — Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0137   69.9     —
AFFECTED
  Product  Versions     Fixed
  feast    unspecified  —
TIMELINE
  Jun 18  Reserved by CNA
  Jun 24  Published (CNA: VulnCheck)
CWE-502 · CNA: VulnCheck · CVSS v4.0 · 7 references · NVD status: Deferred
warpdotdev warp — Warp branch selector command injection via Git branch names
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   R  U  H  H  H    8.0   .0132   68.7     —
AFFECTED
  Product  Versions                                                           Fixed
  warp     >= 0.2025.08.06.08.12.stable_00, < 0.2026.05.13.09.15.stable_01 –  —
TIMELINE
  May 22  Reserved by CNA
  Jun 24  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v3.1 · 2 references · NVD status: Deferred
Rapid7 InsightConnect RPM Plugin — OS Command Injection in Rapid7 InsightConnect RPM Plugin
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0129   68.0     —
AFFECTED
  Product                    Versions     Fixed
  InsightConnect RPM Plugin  unspecified  1.0.2
TIMELINE
  May 15  Reserved by CNA
  Jun 24  Published (CNA: rapid7)
CWE-78 · CNA: rapid7 · CVSS v3.1 · 1 reference · NVD status: Analyzed
Gogs: Path Traversal in organization name results in RCE through Git hooks
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0111   63.3     —
AFFECTED
  Product  Versions    Fixed
  gogs     < 0.14.3 –  —
TIMELINE
  Jun 8   Reserved by CNA
  Jun 24  Published (CNA: GitHub_M)
CWE-23 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Deferred
Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0095   58.4     —
AFFECTED
  Product          Versions     Fixed
  NetVault Backup  14.0.0.19 –  —
TIMELINE
  Apr 30  Reserved by CNA
  Jun 24  Published (CNA: zdi)
CWE-89 · CNA: zdi · CVSS v3.0 · 2 references · NVD status: Analyzed
Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0095   58.4     —
AFFECTED
  Product          Versions     Fixed
  NetVault Backup  14.0.0.19 –  —
TIMELINE
  May 27  Reserved by CNA
  Jun 24  Published (CNA: zdi)
CWE-89 · CNA: zdi · CVSS v3.0 · 2 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-97828.858.4QuestNetVault BackupCWE-89Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vul…
CVE-2026-97838.858.4QuestNetVault BackupCWE-89Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution …
CVE-2026-97848.858.4QuestNetVault BackupCWE-89Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vul…
CVE-2026-97858.858.4QuestNetVault BackupCWE-89Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vul…
CVE-2026-97868.858.4QuestNetVault BackupCWE-89Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulne…
CVE-2026-75698.858.1QuestNetVault BackupCWE-79Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass V…
CVE-2026-97808.858.1QuestNetVault BackupCWE-79Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass V…
CVE-2026-487317.856.5warpdotdevwarpCWE-78Warp: Linux external editor command injection
CVE-2026-251197.755.8gogsgogsCWE-290Gogs: Authentication Bypass via Unvalidated Reverse Proxy Headers
CVE-2026-122428.855.6adegansAdRotate Banner ManagerCWE-94AdRotate Banner Manager <= 5.17.7 - Authenticated (Contributor+) PHP Code Inj…
CVE-2026-399489.355.3CacticactiCWE-89Cacti has SQL Injection via rfilter parameter in RLIKE clauses
CVE-2026-572968.854.9Jenkins ProjectJenkins External Workspace Manager PluginCWE-22Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject p…
CVE-2026-124179.854.5pravelSignUp & SignInCWE-640SignUp & SignIn <= 1.0.0 - Unauthenticated Privilege Escalation via Weak Pass…
CVE-2025-604747.554.1n/an/aCWE-121A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c)…
CVE-2026-505519.953.0siyuan-notesiyuanCWE-79SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content
CVE-2026-562626.952.4Crawl4AICrawl4AICWE-306Crawl4AI - Unauthenticated Access to Monitor Endpoints via Docker API Server
CVE-2026-499809.852.0rclonercloneCWE-306Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inli…
CVE-2026-546997.751.9warpdotdevwarpCWE-78Warp: OS command injection when opening terminal links from WSL
CVE-2026-529999.151.7LinuxLinuxCWE-125netfilter: nfnetlink_osf: fix out-of-bounds read on option matching
CVE-2026-530439.151.7LinuxLinuxCWE-787ocfs2/dlm: validate qr_numregions in dlm_match_regions()
CVE-2025-604677.551.4n/an/aCWE-416A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter…
CVE-2026-77618.851.3ultimatememberUltimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership PluginCWE-862Ultimate Member <= 2.11.4 - Authenticated (Contributor+) Account Takeover via…
CVE-2026-530469.851.0LinuxLinuxCWE-416ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine
CVE-2026-529227.551.0LinuxLinuxCWE-476batman-adv: dat: handle forward allocation error
CVE-2026-529297.551.0LinuxLinuxCWE-476sctp: stream: fully roll back denied add-stream state
CVE-2026-529547.551.0LinuxLinuxCWE-617libceph: handle rbtree insertion error in decode_choose_args()
CVE-2026-529577.551.0LinuxLinuxCWE-476libceph: Fix potential null-ptr-deref in decode_choose_args()
CVE-2026-530037.551.0LinuxLinux—pppoe: drop PFC frames
CVE-2026-18408.750.8HubbellAclara Metrum Cellular Web InterfaceCWE-306Missing authentication for critical function in Hubbell Aclara Metrum Cellula…
CVE-2026-131648.850.8MailerupMailerupCWE-306Unauthenticated self-registration in MailerUp allows access to stored email data
CVE-2026-530697.550.4LinuxLinuxCWE-476net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master
CVE-2026-399389.850.1CacticactiCWE-22Cacti: Unauthenticated RCE on Graph Image
CVE-2026-529747.549.8LinuxLinuxCWE-401net: tls: fix strparser anchor skb leak on offload RX setup failure
CVE-2026-530877.549.8LinuxLinuxCWE-401net: bcmgenet: fix leaking free_bds
CVE-2026-456778.749.7RocketChatRocket.ChatCWE-862Rocket.Chat: Lack of SAML Signature Check During Logout Could Lead To DoS
CVE-2026-97797.249.6ATENUnizonCWE-347ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Sig…
CVE-2026-87057.549.5clearsaleClearSale TotalCWE-89ClearSale Total <= 3.4.2 - Unauthenticated SQL Injection
CVE-2026-528165.449.5gogsgogsCWE-80Gogs: Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary dat…
CVE-2026-572817.549.4Jenkins ProjectJenkins Script Security PluginCWE-93Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject…
CVE-2026-398939.849.4CacticactiCWE-89Cacti: Pre-authentication SQL injection via rfilter RLIKE clause in graph_vie…
CVE-2026-124169.849.3pravelInvoice GeneratorCWE-640Invoice Generator <= 1.0.0 - Unauthenticated Account Takeover via Weak Passwo…
CVE-2026-549048.249.3ruby-concurrencyconcurrent-rubyCWE-835concurrent-ruby: `AtomicReference#update` livelocks when the stored value is …
CVE-2026-42978.849.3newscredWelcome Software PublishingCWE-862Welcome Software Publishing <= 0.0.31 - Authenticated (Subscriber+) Arbitrary…
CVE-2026-487938.849.0jellyfinjellyfinCWE-88Jellyfin: Potential FFmpeg argument injection via unescaped subtitle file path
CVE-2026-440177.548.7docling-projectdoclingCWE-22Docling: Unsafe Zip Extraction in EasyOCR Model Download
CVE-2026-561118.348.2MarlinFirmwareMarlinCWE-129Marlin Firmware 2.1.2.7 Out-of-Bounds Write via M421 G-code Handler
CVE-2026-530109.847.5LinuxLinuxCWE-416ksmbd: fix use-after-free in smb2_open during durable reconnect
CVE-2026-530559.847.5LinuxLinuxCWE-416crypto: hisilicon/sec2 - prevent req used-after-free for sec
CVE-2026-498518.747.4lepturemistuneCWE-400Mistune: Potential DoS via quadratic-time parsing in parse_link_text
CVE-2026-573018.847.3Jenkins ProjectJenkins OWASP ZAP PluginCWE-610Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the J…
CVE-2026-554887.747.2motioneye-projectmotioneyeCWE-22motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary F…
CVE-2026-529467.547.1LinuxLinuxCWE-667fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
CVE-2026-555709.046.9siyuan-notesiyuanCWE-79SiYuan: Stored XSS results to Electron RCE in SiYuan marketplace via unescape…
CVE-2026-91787.546.6hancock11WP Forms ConnectorCWE-862WP Forms Connector <= 1.8 - Missing Authorization to Unauthenticated Informat…
CVE-2026-529327.546.5LinuxLinux—xfrm: ipcomp: Free destination pages on acomp errors
CVE-2026-529837.546.5LinuxLinux—net: airoha: fix BQL imbalance in TX path
CVE-2026-530267.546.5LinuxLinux—NFSD: fix nfs4_file access extra count in nfsd4_add_rdaccess_to_wrdeleg
CVE-2026-554549.946.2appsmithorgappsmithCWE-749Appsmith: Caddy admin API exposed without authentication
CVE-2026-440207.546.1docling-projectdoclingCWE-776Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
CVE-2025-713617.646.0picklescanpicklescanCWE-95picklescan - Remote Code Execution via Undetected idlelib.calltip.Calltip.fet…
CVE-2026-1248510.046.0GeoVision Inc.GV-I/O Box 4ECWE-121GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET …
CVE-2026-1284610.046.0GeoVision Inc.GV-I/O Box 4ECWE-121GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET …
CVE-2026-1284710.046.0GeoVision Inc.GV-I/O Box 4ECWE-121GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET …
CVE-2026-1284810.046.0GeoVision Inc.GV-I/O Box 4ECWE-121GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET …
CVE-2026-440168.245.7docling-projectdoclingCWE-94Docling: Unsafe Playwright-based HTML Rendering
CVE-2026-20507.845.6GIMPGIMPCWE-122GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulner…
CVE-2026-399559.845.3CacticactiCWE-89Cacti has Pre-Authentication SQL Injection via unanchored FILTER_VALIDATE_REG…
CVE-2026-540699.245.0siyuan-notesiyuanCWE-346SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Orig…
CVE-2026-530499.844.6LinuxLinuxCWE-667gfs2: add some missing log locking
CVE-2026-528018.144.5gogsgogsCWE-20Gogs: Ability to import local repositories via Mirror Settings
CVE-2026-238798.044.4miurahrpy7zrCWE-59py7zr: Arbitrary File Write Vulnerability
CVE-2026-528025.443.8gogsgogsCWE-601Gogs: Open Redirect via redirect_to in Gogs
CVE-2026-529869.843.6LinuxLinuxCWE-476netfilter: nf_conntrack_sip: don't use simple_strtoul
CVE-2026-492478.843.4jellyfinjellyfinCWE-22Jellyfin: Potential Authenticated path traversal in /ClientLog/Document
CVE-2026-471107.143.4ueberdosistiptap-phpCWE-241Tiptap for PHP < 2.1.1 DoS via Malformed href Attribute
CVE-2026-100437.843.4MosaicMLComposerCWE-502MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vul…
CVE-2026-528145.543.4gogsgogsCWE-400Gogs: Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake St…
CVE-2026-529208.343.2LinuxLinux—netfilter: xt_policy: fix strict mode inbound policy matching
CVE-2026-96125.343.1yapacdevWhatsOrder – Instant Checkout for WooCommerceCWE-200WhatsOrder <= 1.0.1 - Unauthenticated Sensitive Information Exposure via Pred…
CVE-2026-540679.943.0siyuan-notesiyuanCWE-79SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
CVE-2026-107497.243.0UnknownPost Duplicator—Post Duplicator < 3.0.15 - Contributor+ PHP Object Injection via customMetaData
CVE-2026-529589.142.8LinuxLinuxCWE-125libceph: Fix potential out-of-bounds access in osdmap_decode()
CVE-2026-529829.842.8LinuxLinuxCWE-416net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()
CVE-2026-332357.742.6Significant-GravitasAutoGPTCWE-400AutoGPT: Denial of Service (DoS) via Resource Exhaustion in text templating f…
CVE-2026-529817.542.5LinuxLinuxCWE-401neigh: let neigh_xmit take skb ownership
CVE-2026-527978.542.4gogsgogsCWE-22Gogs: Overwriting critical files results in a denial of service
CVE-2026-506994.642.4FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Stored XSS in Auto Repeat dashboard schedule re…
CVE-2026-456899.142.2RocketChatRocket.ChatCWE-943Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arb…
CVE-2026-562379.341.7CapgoCapgoCWE-287Capgo - Unauthenticated API Key Generation via Client-Side Parameter Manipula…
CVE-2025-713328.541.6FlowiseFlowiseCWE-89Flowise - SQL Injection in importChatflows API via chatflow.id Parameter
CVE-2026-530459.841.4LinuxLinux—memory: tegra124-emc: Fix dll_change check
CVE-2026-529149.841.3LinuxLinuxCWE-787batman-adv: fix fragment reassembly length accounting
CVE-2026-572808.841.4Jenkins ProjectJenkins Script Security PluginCWE-693Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not interc…
CVE-2026-131635.341.2MailerupMailerupCWE-601Lack of input validation in Mailerup input parameter leads to Open Redirect
CVE-2026-541589.941.1siyuan-notesiyuanCWE-79SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
CVE-2026-91797.540.8hancock11WP Forms ConnectorCWE-89WP Forms Connector <= 1.8 - Unauthenticated SQL Injection via 'order' Parameter
CVE-2026-119987.640.6GoogleAngularJSCWE-791AngularJS XSS via SCE resource URL sanitization bypass
CVE-2026-529987.540.6LinuxLinuxCWE-476netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check
CVE-2026-528045.540.5gogsgogsCWE-193Gogs: Privilege Escalation via Collaboration Access Mode Validation
CVE-2026-501898.940.1appsmithorgappsmithCWE-183Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor…
CVE-2026-131506.940.1PentestifyPentestifyCWE-918SSRF in Pentestify PDF generation endpoint via Host header
CVE-2026-456889.140.1RocketChatRocket.ChatCWE-943Rocket.Chat: Pre-Auth NoSQL Injection in CAS Login Handler leading to Arbitra…
CVE-2026-563386.940.0CapgoCapgoCWE-703Capgo - Denial of Service in 2FA Email Verification via /auth/v1/otp Endpoint
CVE-2026-529607.539.8LinuxLinux—ceph: put folios not suitable for writeback
CVE-2026-91755.339.8ajitdasDevs Accounting – Simple Accounting and Invoicing SolutionCWE-862Devs Accounting <= 1.2.0 - Missing Authorization to Unauthenticated Sensitive…
CVE-2026-542977.539.7lostislandfaradayCWE-674Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustio…
CVE-2026-528074.839.4gogsgogsCWE-79Gogs: DOM-based XSS via Milestone Name on New Issue Page
CVE-2026-528087.139.1gogsgogsCWE-269Gogs: Write-level collaborators can mutate admin-only repository settings via…
CVE-2026-528119.038.9gogsgogsCWE-22Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym
CVE-2026-557628.138.9RocketChatRocket.ChatCWE-862Rocket.Chat: Any Authenticated User Can Permanently Deregister Workspace from…
CVE-2026-562328.738.5CapgoCapgoCWE-863Capgo - Subkey Scope Bypass in middlewareKey via x-limited-key-id Header
CVE-2026-527947.538.4getsentrysentryCWE-1333Sentry: Inefficient Regular Expression Complexity in sentry
CVE-2026-501297.537.9mastodonmastodonCWE-248Mastodon: Persistent anonymous DoS via unhandled NoMethodError in MATH_TRANSF…
CVE-2026-563686.337.9ImageMagickImageMagickCWE-401ImageMagick - Memory Leak in Raw Pixel Data Coders
CVE-2026-562458.837.8Cap-gocapgoCWE-269Supabase Capgo - Unauthenticated Cross-Tenant Build-Time Accounting Poisoning…
CVE-2026-507015.137.4FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Reflected DOM XSS in dashboard-view breadcrumb …
CVE-2025-713547.637.1picklescanpicklescanCWE-502picklescan - Remote Code Execution via idlelib.debugobj.ObjectTreeItem.SetText
CVE-2026-335439.337.0FOSSBillingFOSSBillingCWE-288FOSSBilling: Authentication bypass allows unauthenticated administrator creation
CVE-2026-539439.636.9TryGhostGhostCWE-524Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header
CVE-2026-547598.736.7siyuan-notesiyuanCWE-79SiYuan: Lute HTML sanitizer allows `<iframe>` tags in Bazaar package README, …
CVE-2026-487048.836.6warpdotdevwarpCWE-20Warp Markdown notebook links may open executable local files
CVE-2026-487208.836.6warpdotdevwarpCWE-20Warp: SSH remote output can lead to local file overwrite and persistence
CVE-2025-647194.936.5gogsgogsCWE-20Gogs: Denial of Service in repository/wiki file listing web pages
CVE-2026-86905.336.3rentmyRentMy Real-Time Rental Management PluginCWE-862RentMy Real-Time Rental Management Plugin <= 4.0.4.1 - Missing Authorization …
CVE-2026-563376.936.2CapgoCapgoCWE-200Capgo - Information Disclosure via Unauthenticated RPC Function exist_app_v2
CVE-2026-116146.436.0xproXpro Addons — 140+ Widgets for ElementorCWE-79Xpro Addons <= 1.7.2 - Authenticated (Author+) Stored Cross-Site Scripting vi…
CVE-2026-107357.536.0Unknownsmart-post-show-pro—ShapedPlugin Multiple Pro Plugins - Backdoor via Compromised Vendor Update Se…
CVE-2026-506984.636.0FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Stored XSS in Audit Trail template rendering
CVE-2026-507004.636.0FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Stored XSS in frappe.get_avatar image rendering
CVE-2026-507044.636.0FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Reflected/Stored XSS in File View breadcrumbs r…
CVE-2026-507054.636.0FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Stored XSS in Form Dashboard headline rendering
CVE-2026-507104.636.0FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Stored XSS via eval in Number Card filters_config
CVE-2026-507114.636.0FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Stored XSS in Number Card filter fields rendering
CVE-2026-527988.935.5gogsgogsCWE-79Gogs: Stored XSS in `.ipynb` Preview
CVE-2026-107457.935.4upKeeper SolutionsupKeeper Instant Privilege AccessCWE-117Improper output neutralization for logs vulnerability in upKeeper Solutions u…
CVE-2026-528107.135.4gogsgogsCWE-284Gogs: Write to readonly repositories using receive-pack + service=git-upload-…
CVE-2026-527997.535.0gogsgogsCWE-639Gogs: Missing Authorization in Attachment Download
CVE-2026-472678.334.7gogsgogsCWE-918Gogs: SSRF in webhook deliveries
CVE-2026-96437.234.6joomunitedWP Meta SEOCWE-79WP Meta SEO <= 4.5.18 - Unauthenticated Stored Cross-Site Scripting via REQUE…
CVE-2026-96194.334.6berfectReviews and Rating – DocplannerCWE-862Reviews and Rating <= 1.1.4 - Missing Authorization to Authenticated (Subscri…
CVE-2026-319786.534.5motioneye-projectmotioneyeCWE-22motionEye: Arbitrary File Read via Path Traversal in Picture/Movie Preview En…
CVE-2026-562567.134.2CapgoCapgoCWE-602Capgo - Two-Factor Authentication Bypass via Organization Management API
CVE-2026-492786.734.2RocketChatRocket.ChatCWE-285Rocket.Chat: Livechat Visitor Profile Disclosure Leaks Bearer Token and Enabl…
CVE-2026-529188.834.0LinuxLinux—Bluetooth: serialize accept_q access
CVE-2026-529348.834.0LinuxLinux—batman-adv: tvlv: reject oversized TVLV packets
CVE-2026-556669.333.4RocketChatRocket.ChatCWE-287Rocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple …
CVE-2026-463488.733.4mastodonmastodonCWE-918Mastodon: SSRF Bypass via IPv6 Unspecified Address (::)
CVE-2026-100927.233.4nicashmuCincopa video and media plug-inCWE-79Cincopa video and media plug-in <= 1.163 - Unauthenticated Stored Cross-Site …
CVE-2026-507034.833.4FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Stored XSS in Desktop Icon label rendering
CVE-2026-507084.833.4FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Stored XSS in Multi Select Dialog result rendering
CVE-2026-507094.833.4FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Stored XSS in Notifications Events color rendering
CVE-2026-507124.833.4FrappeFrappe FrameworkCWE-79Frappe Framework 17.0.0-dev - Stored XSS in Tree View node label rendering
CVE-2026-556110.033.4Mintplex-Labsanything-llmCWE-639AnythingLLM: embed-parsed-file cleanup deletes any parsed file by ID without …
CVE-2026-546864.333.3warpdotdevwarpCWE-78Warp: DCS lifecycle hook spoofing can alter terminal session metadata
CVE-2026-76175.333.1secuforSecufor_OAuthCWE-862Secufor_OAuth <= 1.0.7 - Missing Authorization to Unauthenticated Account Log…
CVE-2026-120945.333.1iamranitAdvanced Contact Form 7 – Compact DBCWE-862Advanced Contact Form 7 <= 1.0.0 - Missing Authorization to Unauthenticated A…
CVE-2026-562239.333.1CapgoCapgoCWE-287Capgo - Account Takeover via Cross-Domain SSO Email Assertion in provision-user
CVE-2026-529319.832.7LinuxLinux—batman-adv: tp_meter: avoid use of uninit sender vars
CVE-2026-530889.832.7LinuxLinuxCWE-193net: bcmgenet: fix off-by-one in bcmgenet_put_txcb
CVE-2026-529457.532.7LinuxLinux—Revert "wireguard: device: enable threaded NAPI"
CVE-2026-399518.832.5CacticactiCWE-89Cacti: Stored SQL Injection via graph_name_regexp in Reports feature
CVE-2026-120957.232.5bytuncayKargo TakipCWE-918Kargo Takip <= 1.2 - Unauthenticated Server-Side Request Forgery via 'api_url…
CVE-2026-530069.832.3LinuxLinuxCWE-416ipv6: fix possible UAF in icmpv6_rcv()
CVE-2026-473898.632.2mastodonmastodonCWE-184Mastodon: SSRF protection bypass on older Ruby versions
CVE-2026-86884.332.2krishawebAdvance Nav Menu ManagerCWE-862Advance Nav Menu Manager <= 1.3 - Missing Authorization to Authenticated (Sub…
CVE-2026-96164.332.2verenigingvanregistrarsGenerate Security.txtCWE-862Generate Security.txt <= 1.0.12 - Missing Authorization to Authenticated (Sub…
CVE-2026-529678.132.1LinuxLinuxCWE-125smb/client: fix possible infinite loop and oob read in symlink_data()
CVE-2026-86175.331.9ailchevSearchPlusCWE-862SearchPlus <= 1.7.1 - Missing Authorization to Unauthenticated Settings Modif…
CVE-2026-91725.331.8ajitdasDevs Accounting – Simple Accounting and Invoicing SolutionCWE-862Devs Accounting <= 1.2.0 - Missing Authorization to Unauthenticated Account D…
CVE-2026-554555.331.6appsmithorgappsmithCWE-918Appsmith: SSRF in REST API / GraphQL datasource plugins via insufficient host…
CVE-2026-398996.931.4CacticactiCWE-22Cacti: Path Traversal via filename parameter in package_import.php
CVE-2026-528058.731.1gogsgogsCWE-918Gogs: Migration Redirect Bypass Leads to Internal Repository Theft
CVE-2026-130318.831.0GoogleChromeCWE-416Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a re…
CVE-2026-130338.831.0GoogleChromeCWE-125Out of bounds read and write in Blink>InterestGroups in Google Chrome prior t…
CVE-2026-130368.831.0GoogleChromeCWE-416Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a re…
CVE-2026-130388.831.0GoogleChromeCWE-416Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.19…
CVE-2026-560527.631.0FunnelKitFunnel Builder by FunnelKitCWE-89WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.5 - SQL Injection vuln…
CVE-2026-121007.231.1abhisheksaha11URL PreviewCWE-918URL Preview <= 1.0 - Unauthenticated Server-Side Request Forgery via 'url' Pa…
CVE-2026-529559.830.8LinuxLinuxCWE-125libceph: Fix potential out-of-bounds access in crush_decode()
CVE-2026-487258.130.5warpdotdevwarpCWE-276Warp may allow terminal output to access the local clipboard through OSC 52
CVE-2026-540685.930.4siyuan-notesiyuanCWE-306SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /a…
CVE-2026-563515.330.3n8nn8nCWE-89n8n - SQL Injection in MySQL, PostgreSQL, and Microsoft SQL Nodes
CVE-2026-97097.729.8UnknownCornerstone—Themeco Cornerstone < 7.8.9 (Premium, bundled with X Theme) - Subscriber+ Arb…
CVE-2026-97107.729.8UnknownCornerstone—Themeco Cornerstone < 7.8.8 (Premium, bundled with X Theme) - Subscriber+ Arb…
CVE-2026-492461.729.7jellyfinjellyfinCWE-22Jellyfin: Potential MKV attachment filename path traversal to RCE
CVE-2026-499795.129.5appsmithorgappsmithCWE-918Appsmith: SSRF via `POST /api/v1/admin/send-test-email` — JavaMail Bypasses W…
CVE-2026-529939.829.4LinuxLinuxCWE-415tipc: fix double-free in tipc_buf_append()
CVE-2026-277087.129.1FOSSBillingFOSSBillingCWE-284FOSSBilling: IDOR in Servicecustom Client API allows cross-client data access
CVE-2026-91834.328.824liveblog24liveblog – live blog toolCWE-20024liveblog <= 2.2 - Authenticated (Contributor+) Exposure of Sensitive Inform…
CVE-2026-100917.228.7cgarveyEmail JavaScript CloakCWE-79Email JavaScript Cloak <= 1.03 - Unauthenticated Stored Cross-Site Scripting
CVE-2026-127607.128.7TP-Link Systems Inc.Tapo C200 v3CWE-770Denial-of-Service Vulnerability via Malformed IPv4 Fragmentation Handling in …
CVE-2026-529567.528.6LinuxLinuxCWE-125libceph: Fix potential out-of-bounds access in __ceph_x_decrypt()
CVE-2026-573037.128.5Jenkins ProjectJenkins Assembla PluginCWE-918Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to …
CVE-2026-539495.328.5TryGhostGhostCWE-200Ghost Content API filter bypass reveals private fields
CVE-2026-546398.828.3style-dictionarystyle-dictionaryCWE-1321Style Dictionary - Prototype Pollution in convertTokenData utility function
CVE-2026-529899.828.3LinuxLinuxCWE-390nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers
CVE-2026-96206.428.2joomunitedWP Latest PostsCWE-79WP Latest Posts <= 5.0.11 - Authenticated (Author+) Stored Cross-Site Scripti…
CVE-2026-530029.828.1LinuxLinuxCWE-787netfilter: conntrack: remove sprintf usage
CVE-2026-91844.328.024liveblog24liveblog – live blog toolCWE-86224liveblog <= 2.2 - Missing Authorization to Authenticated (Author+) Settings…
CVE-2026-130358.828.0GoogleChromeCWE-416Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 a…
CVE-2026-539507.527.8TryGhostGhostCWE-79@tryghost/activitypub: XSS in Ghost's ActivityPub client
CVE-2026-350258.627.5ProFTPD ProjectProFTPDCWE-59ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR
CVE-2026-563026.927.4CapgoCapgoCWE-284Capgo - Unsecured Supabase Images Bucket via Missing Row Level Security
CVE-2026-530707.527.1LinuxLinux—sctp: disable BH before calling udp_tunnel_xmit_skb()
CVE-2026-539475.327.0TryGhostGhostCWE-204Ghost: Member existence leak via magic link sign-in response
CVE-2026-487894.326.7Mintplex-Labsanything-llmCWE-22AnythingLLM: Windows path containment bypass in document folder route
CVE-2026-456878.526.7RocketChatRocket.ChatCWE-915Rocket.Chat: Authenticated Arbitrary Data Export Theft via Mass Assignment in…
CVE-2026-572844.326.3Jenkins ProjectJenkins Pipeline: Groovy PluginCWE-470Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restr…
CVE-2026-124886.225.9GeoVision Inc.GeoVisionCWE-121GeoVision GV-VMS V20 GV-Cloud memory corruption vulnerability
CVE-2026-492205.725.8jellyfinjellyfinCWE-79Jellyfin: Potential XSS in user management
CVE-2026-529249.825.5LinuxLinuxCWE-416sctp: purge outqueue on stale COOKIE-ECHO handling
CVE-2026-88656.425.5paradigmatoolsAvalon23 Products Filter for WooCommerceCWE-79Avalon23 Products Filter for WooCommerce <= 1.1.6 - Authenticated (Contributo…
CVE-2026-113706.425.4joomunitedWP Meta SEOCWE-918WP Meta SEO <= 4.5.18 - Authenticated (Contributor+) Server-Side Request Forg…
CVE-2026-539445.825.2TryGhostGhostCWE-184Ghost: Private IP filtering bypass to make server-side requests to internal s…
CVE-2026-572883.725.2Jenkins ProjectJenkins Active Directory PluginCWE-90Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user n…
CVE-2026-562447.125.2CapgoCapgoCWE-200Capgo - Webhook Signing Secret Disclosure via Non-Admin API Key
CVE-2026-86144.324.8assistioaiAssistioCWE-862Assistio <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Plug…
CVE-2026-557597.424.6RocketChatRocket.ChatCWE-287Rocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and …
CVE-2026-88966.424.3mirsoftwareMIR blocks and shortcodesCWE-79MIR blocks and shortcodes <= 1.0.0 - Authenticated (Contributor+) Stored Cros…
CVE-2026-130289.624.2GoogleChromeCWE-416Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 a…
CVE-2026-130329.624.2GoogleChromeCWE-416Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 a…
CVE-2026-130268.824.2GoogleChromeCWE-416Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.…
CVE-2026-130278.824.2GoogleChromeCWE-416Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed…
CVE-2026-530728.824.0LinuxLinuxCWE-667Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER
CVE-2026-36527.224.0n/aARformsCWE-79ARForms <= 7.1.3 - Unauthenticated Stored Cross-Site Scripting via 'value' Pa…
CVE-2026-457572.323.5RocketChatRocket.ChatCWE-613Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking exis…
CVE-2026-492772.323.5RocketChatRocket.ChatCWE-613Rocket.Chat: OAuth access and refresh tokens remain valid after account deact…
CVE-2026-562577.123.5CapgoCapgoCWE-284Capgo - Authorization Bypass in App Ownership Transfer via Direct PostgREST U…
CVE-2026-562317.222.9CapgoCapgoCWE-285Capgo - Broken Object Level Authorization in Build Job Control via jobId Para…
CVE-2026-118776.322.6OpenTextAccess ManagerCWE-648Missing Authorization Vulnerability in OpenText Access Manager
CVE-2026-563105.322.5Cap-gocapgoCWE-285Cap-go - Authorization Bypass in Organization Members Endpoint via API Key Sc…
CVE-2026-530869.822.4LinuxLinuxCWE-362net: bcmgenet: fix racing timeout handler
CVE-2026-130258.322.3GoogleChromeCWE-20Race in DevTools in Google Chrome prior to 149.0.7827.197 allowed a remote at…
CVE-2026-540707.122.0siyuan-notesiyuanCWE-79SiYuan: Stored XSS in Bazaar marketplace via package README event handlers
CVE-2026-131401.121.5Thinkst Applied ResearchCanarytokensCWE-79Stored Cross-Site Scripting in Canarytokens.org
CVE-2026-567615.321.3honohonoCWE-79hono - HTML Injection via Improper JSX Attribute Name Handling in SSR
CVE-2026-130235.320.7GoogleChromeCWE-457Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a r…
CVE-2026-130305.320.7GoogleChromeCWE-457Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 …
CVE-2026-86226.120.5pixelweltImage Sizes on DemandCWE-79Image Sizes on Demand <= 1.3 - Reflected Cross-Site Scripting via PHP_SELF Se…
CVE-2026-86286.120.5owencutajarEntreDroppersCWE-79EntreDroppers <= 1.1.2 - Reflected Cross-Site Scripting via PHP_SELF Parameter
CVE-2026-527963.520.4gogsgogsCWE-1336Gogs: DoS in rendering issue index pattern
CVE-2026-527954.320.0gogsgogsCWE-863Gogs: Authorization Bypass in Watch API allows any user to monitor private re…
CVE-2026-572854.320.0Jenkins ProjectJenkins GitHub Branch Source PluginCWE-862A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v…
CVE-2026-572864.320.0Jenkins ProjectJenkins Git Parameter PluginCWE-862A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_…
CVE-2026-573004.320.0Jenkins ProjectJenkins MCP Server PluginCWE-862A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe …
CVE-2026-573024.320.0Jenkins ProjectJenkins FitNesse PluginCWE-256Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job …
CVE-2026-107532.720.1UnknownSite Kit by Google—Site Kit by Google < 1.176.0 - Editor+ Email Reporting Settings Update
CVE-2026-129867.319.3PayaraPayara ServerCWE-352A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.…
CVE-2026-572934.318.7Jenkins ProjectJenkins Gitee PluginCWE-862An incorrect permission check in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ a…
CVE-2026-398975.317.7CacticactiCWE-79Cacti has a Reflected XSS Vulnerability via html_auth_footer
CVE-2026-399005.317.7CacticactiCWE-79Cacti: Reflected XSS via tab parameter in auth_profile.php JavaScript context
CVE-2026-555837.617.4twentyhqtwentyCWE-639Twenty: Cross-workspace IDOR in AgentTurnResolver
CVE-2026-62924.317.5manuelpadillacMP Customize Login PageCWE-352MP Customize Login Page <= 1.0 - Cross-Site Request Forgery to Settings Update
CVE-2026-530718.817.3LinuxLinuxCWE-667Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp
CVE-2026-572945.416.7Jenkins ProjectJenkins EC2 Fleet PluginCWE-862A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81…
CVE-2026-573045.416.7Jenkins ProjectJenkins Assembla PluginCWE-862A missing permission check in Jenkins Assembla Plugin 1.4 and earlier allows …
CVE-2026-572904.316.5Jenkins ProjectJenkins Priority Sorter PluginCWE-352A cross-site request forgery (CSRF) vulnerability in Jenkins Priority Sorter …
CVE-2026-572825.016.5Jenkins ProjectJenkins Git client PluginCWE-78Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the wor…
CVE-2026-487037.816.4warpdotdevwarpCWE-78Warp: Command Injection via Warp code search tool arguments
CVE-2026-549062.116.4ruby-concurrencyconcurrent-rubyCWE-414concurrent-ruby: ReadWriteLock allows wrong-thread write release and stray re…
CVE-2026-572974.316.1Jenkins ProjectJenkins Contrast Continuous Application Security PluginCWE-862A missing permission check in Jenkins Contrast Continuous Application Securit…
CVE-2026-572994.316.1Jenkins ProjectJenkins Contrast Continuous Application Security PluginCWE-862Missing permission checks in Jenkins Contrast Continuous Application Security…
CVE-2026-528008.815.9gogsgogsCWE-352Gogs: CSRF Leading to Organization Owner Takeover
CVE-2026-130297.515.6GoogleChromeCWE-416Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197…
CVE-2026-563585.115.2n8nn8nCWE-79n8n - Stored Cross-Site Scripting in Form Trigger Node
CVE-2026-106424.615.2zephyrprojectzephyrCWE-835Unbounded TX busy-loop DoS in Zephyr PL011 UART driver under CTS hardware flo…
CVE-2026-529437.814.6LinuxLinuxCWE-416net: skbuff: fix missing zerocopy reference in pskb_carve helpers
CVE-2026-572834.314.4Jenkins ProjectJenkins Pipeline: Groovy PluginCWE-352A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy…
CVE-2026-528127.114.4gogsgogsCWE-345Gogs: LFS dedupe path leaks private repo content across tenants
CVE-2026-572915.413.6Jenkins ProjectJenkins Gitee PluginCWE-862Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and e…
CVE-2026-105315.413.1UnknownAI Share & Summarize—AI Share & Summarize < 2.0.4 - Contributor+ Stored XSS via title_style Shortc…
CVE-2026-539485.413.1TryGhostGhostCWE-434Ghost: File Upload Content-Type Spoofing
CVE-2026-130244.212.9GoogleChromeCWE-20Insufficient validation of untrusted input in Navigation in Google Chrome pri…
CVE-2026-464239.312.5RocketChatRocket.ChatCWE-347Rocket.Chat: SAML signature validation skipped when IdP certificate field is …
CVE-2026-487218.612.5warpdotdevwarpCWE-180Warp: Env-var prefixes can lead to denylisted command autoexecution
CVE-2026-118788.212.4OpenTextAccess ManagerCWE-79Reflected Cross-Site Scripting vulnerability in OpenText Access Manager
CVE-2026-95396.512.5freedesktop.orglibslirpCWE-125libslirp TCP URG OOB Read Information Leak
CVE-2026-572955.412.4Jenkins ProjectJenkins EC2 Fleet PluginCWE-352A cross-site request forgery (CSRF) vulnerability in Jenkins EC2 Fleet Plugin…
CVE-2026-573055.412.4Jenkins ProjectJenkins Assembla PluginCWE-352A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Plugin …
CVE-2026-539454.011.6TryGhostGhostCWE-367Ghost: Server-side request forgery via DNS rebinding in external request hand…
CVE-2026-1253710.011.3Google CloudGemini CLICWE-78Unauthenticated Remote Code Execution in Gemini CLI CI/CD Workflows
CVE-2026-573074.210.8Jenkins ProjectJenkins Zowe zDevOps PluginCWE-862A missing permission check in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_4…
CVE-2026-440225.510.7docling-projectdoclingCWE-22Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands
CVE-2026-539465.410.7TryGhostGhostCWE-918Ghost: Mobiledoc image-size fetch SSRF
CVE-2026-130344.710.2GoogleChromeCWE-346Inappropriate implementation in Passwords in Google Chrome prior to 149.0.782…
CVE-2026-130214.310.2GoogleChromeCWE-346Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrom…
CVE-2026-528096.810.0gogsgogsCWE-324Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_P…
CVE-2026-130226.59.3GoogleChromeCWE-346Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827…
CVE-2026-529697.89.2LinuxLinuxCWE-129KVM: Reject wrapped offset in kvm_reset_dirty_gfn()
CVE-2026-463495.39.2mastodonmastodonCWE-347Mastodon: LD-Signature Bypass via JSON-LD Named-Graph Restructuring
CVE-2026-572874.39.2Jenkins ProjectJenkins Job Configuration History PluginCWE-312Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier doe…
CVE-2026-530907.89.0LinuxLinuxCWE-253bpf: Fix ld_{abs,ind} failure path analysis in subprogs
CVE-2026-529127.89.0LinuxLinuxCWE-416netfilter: nf_queue: hold bridge skb->dev while queued
CVE-2026-105524.38.8jotisBlue CaptchaCWE-352Blue Captcha <= 2.0.1 - Cross-Site Request Forgery via 'blcap_action' Parameter
CVE-2026-126818.98.8Googlego-attestationCWE-1285Improper Validation of Specified Index, Position, or Offset in Input vulnerab…
CVE-2026-97244.38.7motordeskMotorDeskCWE-352MotorDesk <= 1.1.2 - Cross-Site Request Forgery to Settings Update
CVE-2026-119974.38.7seo_toolsBulk SEO ImageCWE-352Bulk SEO Image <= 1.1 - Cross-Site Request Forgery to Settings Update
CVE-2025-604735.58.4n/an/aCWE-476A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter…
CVE-2026-530337.88.2LinuxLinuxCWE-416bpf, sockmap: Take state lock for af_unix iter
CVE-2026-531307.88.2LinuxLinuxCWE-191fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START
CVE-2026-529725.58.0LinuxLinuxCWE-190crypto: af_alg - Cap AEAD AD length to 0x80000000
CVE-2026-477334.48.0RocketChatRocket.ChatCWE-79Rocket.Chat: Missing URL protocol sanitization in ImageElement allows javascr…
CVE-2026-573064.28.0Jenkins ProjectJenkins Zowe zDevOps PluginCWE-352A cross-site request forgery (CSRF) vulnerability in Jenkins Zowe zDevOps Plu…
CVE-2025-604715.57.9n/an/aCWE-416A use-after-free in the gf_filter_pid_reconfigure_task_discard function (/fil…
CVE-2026-119685.57.8TortoiseGit teamTortoiseGitCWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Inject…
CVE-2026-529615.57.8LinuxLinuxCWE-617ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size
CVE-2026-501285.37.9mastodonmastodonCWE-354Mastodon: Spoofing of attribution domains
CVE-2026-530817.87.6LinuxLinuxCWE-386bpf: Enforce regsafe base id consistency for BPF_ADD_CONST scalars
CVE-2026-530927.87.6LinuxLinuxCWE-393bpf: Fix linked reg delta tracking when src_reg == dst_reg
CVE-2026-529517.87.3LinuxLinuxCWE-416drm/xe/dma-buf: handle empty bo and UAF races
CVE-2026-529528.87.3LinuxLinuxCWE-617iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset
CVE-2026-530918.47.3LinuxLinuxCWE-131net: pull headers in qdisc_pkt_len_segs_init()
CVE-2026-89056.17.3osiris8Osiris Signature BannerCWE-352Osiris Signature Banner <= 0.5 - Cross-Site Request Forgery to Stored Cross-S…
CVE-2026-563704.87.2ImageMagickImageMagickCWE-125ImageMagick - Out-of-bounds Access in ConnectedComponentsImage via connected-…
CVE-2026-530758.87.1LinuxLinux—ppp: require CAP_NET_ADMIN in target netns for unattached ioctls
CVE-2026-529357.87.1LinuxLinuxCWE-787xfrm: espintcp: do not reuse an in-progress partial send
CVE-2026-529627.87.1LinuxLinuxCWE-787ceph: fix a buffer leak in __ceph_setxattr()
CVE-2026-529877.87.1LinuxLinuxCWE-1341drm/amdgpu: avoid double drm_exec_fini() in userq validate
CVE-2026-529927.87.1LinuxLinuxCWE-787fs/adfs: validate nzones in adfs_validate_bblk()
CVE-2026-530777.87.1LinuxLinux—net/rds: Restrict use of RDS/IB to the initial network namespace
CVE-2026-530967.87.1LinuxLinuxCWE-476bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path
CVE-2026-529687.17.1LinuxLinuxCWE-125KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic
CVE-2026-480286.57.1mastodonmastodonCWE-354Mastodon: Removal of integrity-protected JSON entries from signed activities
CVE-2026-530475.57.1LinuxLinux—efi/capsule-loader: fix incorrect sizeof in phys array reallocation
CVE-2026-530538.87.0LinuxLinux—iommu/amd: Fix clone_alias() to use the original device's devid
CVE-2026-530317.87.0LinuxLinux—bpf: Validate node_id in arena_alloc_pages()
CVE-2026-530787.87.0LinuxLinuxCWE-125bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops
CVE-2026-530857.87.1LinuxLinuxCWE-416bpf: fix mm lifecycle in open-coded task_vma iterator
CVE-2026-530947.87.0LinuxLinux—bpf: Fix stale offload->prog pointer after constant blinding
CVE-2026-531107.87.0LinuxLinux—s390/bpf: Zero-extend bpf prog return values and kfunc arguments
CVE-2026-531157.87.0LinuxLinuxCWE-416bus: fsl-mc: use generic driver_override infrastructure
CVE-2026-531177.87.0LinuxLinuxCWE-416s390/cio: use generic driver_override infrastructure
CVE-2026-531197.87.0LinuxLinuxCWE-416platform/wmi: use generic driver_override infrastructure
CVE-2026-531207.87.0LinuxLinuxCWE-416PCI: use generic driver_override infrastructure
CVE-2026-130067.07.0QOS.CH SarlLogback-coreCWE-20Incomplete protection against CVE-2025-11226
CVE-2026-530578.86.8LinuxLinux—iommu/riscv: Add IOTINVAL after updating DDT/PDT entries
CVE-2026-530677.86.8LinuxLinuxCWE-415PCI: endpoint: pci-ep-msi: Fix error unwind and prevent double alloc
CVE-2026-531097.86.8LinuxLinuxCWE-416powerpc/pgtable-frag: Fix bad page state in pte_frag_destroy
CVE-2026-531187.86.8LinuxLinuxCWE-416vdpa: use generic driver_override infrastructure
CVE-2026-530125.56.7LinuxLinuxCWE-476nexthop: fix IPv6 route referencing IPv4 nexthop
CVE-2026-529445.56.6LinuxLinux—ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET…
CVE-2026-529965.56.6LinuxLinuxCWE-401ksmbd: fix durable fd leak on ClientGUID mismatch in durable v2 open
CVE-2026-424508.46.6AcademySoftwareFoundationOpenColorIOCWE-120OpenColorIO vulnerable to stack buffer overflow via unbounded `sscanf %s` in …
CVE-2026-529477.86.5LinuxLinuxCWE-416net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove
CVE-2026-530117.86.5LinuxLinuxCWE-416net/sched: taprio: fix use-after-free in advance_sched() on schedule switch
CVE-2026-531127.86.5LinuxLinuxCWE-416wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prep…
CVE-2026-530977.86.5LinuxLinuxCWE-416wifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work()
CVE-2026-530987.86.5LinuxLinuxCWE-416wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work()
CVE-2025-604685.56.4n/an/aCWE-122GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88…
CVE-2026-529665.56.4LinuxLinux—drm: Replace old pointer to new idr
CVE-2026-529537.16.3LinuxLinuxCWE-125iommu/vt-d: Fix oops due to out of scope access
CVE-2026-529717.86.3LinuxLinuxCWE-416net: ena: PHC: Fix potential use-after-free in get_timestamp
CVE-2026-529177.16.1LinuxLinuxCWE-125sctp: diag: reject stale associations in dump_one path
CVE-2026-530417.16.1LinuxLinuxCWE-787ocfs2: fix listxattr handling when the buffer is full
CVE-2026-530687.16.1LinuxLinuxCWE-190drm/komeda: fix integer overflow in AFBC framebuffer size check
CVE-2026-530767.16.0LinuxLinuxCWE-125bpf: Fix OOB in pcpu_init_value
CVE-2026-530247.85.9LinuxLinuxCWE-416greybus: raw: fix use-after-free if write is called after disconnect
CVE-2026-530257.85.9LinuxLinuxCWE-416greybus: raw: fix use-after-free on cdev close
CVE-2026-530897.85.9LinuxLinuxCWE-416bpf: Fix use-after-free in offloaded map/prog info fill
CVE-2026-531167.85.9LinuxLinuxCWE-416s390/ap: use generic driver_override infrastructure
CVE-2026-530447.15.8LinuxLinuxCWE-125soc/tegra: cbb: Fix incorrect ARRAY_SIZE in fabric lookup tables
CVE-2026-530407.15.6LinuxLinuxCWE-416ocfs2: validate bg_bits during freefrag scan
CVE-2026-529135.55.6LinuxLinuxCWE-476batman-adv: v: stop OGMv2 on disabled interface
CVE-2026-529165.55.6LinuxLinux—batman-adv: frag: disallow unicast fragment in fragment
CVE-2026-529215.55.6LinuxLinuxCWE-835netfilter: ipset: stop hash:* range iteration at end
CVE-2026-529255.55.6LinuxLinuxCWE-476vrf: Fix a potential NPD when removing a port from a VRF
CVE-2026-529265.55.6LinuxLinux—batman-adv: clear current gateway during teardown
CVE-2026-529365.55.5LinuxLinux—crypto: jitterentropy - replace long-held spinlock with mutex
CVE-2026-529395.55.6LinuxLinuxCWE-476net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion
CVE-2026-529415.55.6LinuxLinuxCWE-476net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint
CVE-2026-529635.55.6LinuxLinux—ALSA: usb-audio: Bound MIDI endpoint descriptor scans
CVE-2026-529645.55.5LinuxLinux—ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans
CVE-2026-529705.55.6LinuxLinux—netfilter: nft_ct: fix missing expect put in obj eval
CVE-2026-529805.55.5LinuxLinuxCWE-476sched/fair: Clear rel_deadline when initializing forked entities
CVE-2026-529855.55.6LinuxLinuxCWE-908netdevsim: zero initialize struct iphdr in dummy sk_buff

Results continue: ranks 401–520.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-24 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.