boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Thursday, June 25, 2026 · all times UTC← 2026-06-24 · archive · 2026-06-26 →

Security Box Score — June 25, 2026

468 CVEs published, led by Linux (146).

468 CVEs published June 25, 2026: 42 critical, 219 high, 172 medium, 35 low; 2 in the KEV catalog at press time; 48 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 68 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published663911100——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

492 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux465143211884546811120.17.8.0014+238 ▲
google70788285468300297760.78.1.0023+691 ▲
microsoft220756585201726286192.57.8.0045+60 ▲
red hat1062009829712200.06.5.0029+96 ▲
apple156712143288710.45.5.00200
canonical2161465000.05.5.0010+2 ▲
freebsd070520000.07.8.0020-7 ▼
suse461410000.08.6.0029+2 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco102266100561150.07.3.0566+5 ▲
netgear171700161000.04.3.0024+17 ▲
palo alto networks911127113218.25.9.0022+7 ▲
ubiquiti81174003327.39.9.0083+6 ▲
ivanti49450025555.68.8.5187+2 ▲
checkpoint3915303111.17.5.0410+3 ▲
fortinet29432028333.38.3.0076+1 ▲
f56843104112.58.9.0225+4 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache99133204557103310.86.5.0050+81 ▲
mozilla49551118260900.07.3.0026+43 ▲
gitlab243105215426.54.4.0029+24 ▲
docker470520000.08.2.0016+1 ▲
drupal0511304120.05.1.0026-3 ▼
github021100000.08.1.03470
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2422701321161842720.78.8.0040+242 ▲
adobe1321344517721921.55.5.0021+132 ▲
ibm32811935270600.07.5.0031+32 ▲
progress591710600.07.5.0036+1 ▲
solarwinds36231010466.77.8.6082+3 ▲
veeam142200100.09.0.0052+1 ▲
zohocorp131110000.08.4.01700
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5 ▲
d-link9110425300.05.5.0058+8 ▲
siemens780440000.07.5.0020+6 ▲
rockwell automation771510000.08.7.0030+7 ▲
abb660420000.07.2.0018+6 ▲
schneider electric660420000.07.8.0042+6 ▲
moxa550320000.07.0.0029+5 ▲
dahua330111000.06.9.0036+3 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7273231391000.06.5.0024+71 ▲
openclaw61670352210000.07.0.0021+61 ▲
sourcecodester3759002534000.02.1.0026+21 ▲
themerex585855300000.08.1.0043+58 ▲
edimax556033023100.07.4.0070-39 ▼
dell3755229240211.87.2.0017+25 ▲
jenkins project364909391300.04.8.0025+36 ▲
capgo4646222211000.07.0.0039+46 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9991100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-20230.882099.88.6
CVE-2026-34910.874799.710.0
CVE-2026-34908.851999.710.0
CVE-2026-50751.837799.79.3
CVE-2026-48907.781099.510.0
CVE-2026-34909.639099.210.0
CVE-2026-49160.538398.97.5
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9991KEV
CVE-2026-3491010.0.8747KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.7810KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-4508710.0.1296
CVE-2026-5375310.0.0290
CVE-2026-4977710.0.0166
CVE-2026-805410.0.0158
CVE-2026-4919910.0.0134
Most disclosures (vendor)
VendorCVEs
linux876
google859
oracle267
microsoft226
adobe132
red hat131
apache101
spring72
openclaw67
ibm61
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco11
apple7
google6
ivanti5
solarwinds4
berriai3
fortinet3
smartertools3
ubiquiti3
Most-affected ecosystems
EcosystemAdvisories
Maven39
Packagist22
PyPI10
npm4
Fastest to KEV
CVEVendorDays
CVE-2025-48595Google0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-28318SolarWinds0
CVE-2026-34908Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171681
CVE-2021-27102n/a2021-11-171681
CVE-2021-27101n/a2021-11-171681
CVE-2021-27103n/a2021-11-171681
CVE-2021-21017Adobe2021-11-171681
CVE-2021-28550Adobe2021-11-171681
CVE-2021-42013Apache Software Foundation2021-11-171681
CVE-2021-41773Apache Software Foundation2021-11-171681
CVE-2021-30858Apple2021-11-171681
CVE-2021-30860Apple2021-11-171681

Transactions

EXPLOIT PUBLISHED — pnpm: 13 CVEs (CVE-2026-48995, CVE-2026-50014, CVE-2026-50015, CVE-2026-50016, CVE-2026-50017, CVE-2026-50021, CVE-2026-50573, CVE-2026-55180, CVE-2026-55487, CVE-2026-55697, CVE-2026-55698, CVE-2026-55699, CVE-2026-55700). Public exploit references added.

EXPLOIT PUBLISHED — danny-avila LibreChat: 9 CVEs (CVE-2026-54024, CVE-2026-54025, CVE-2026-54027, CVE-2026-54029, CVE-2026-54030, CVE-2026-54033, CVE-2026-54036, CVE-2026-54037, CVE-2026-54040). Public exploit references added.

EXPLOIT PUBLISHED — Flowise: 8 CVEs (CVE-2025-71324, CVE-2025-71327, CVE-2025-71328, CVE-2025-71333, CVE-2025-71334, CVE-2025-71335, CVE-2025-71336, CVE-2025-71338). Public exploit references added.

EXPLOIT PUBLISHED — cacti: 4 CVEs (CVE-2026-40080, CVE-2026-40082, CVE-2026-40083, CVE-2026-40084). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2025-60464. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-60465. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-13351 (zephyrproject-rtos Zephyr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-47770 (jqlang jq). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-49839 (jqlang jq). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54917 (seaweedfs). Public exploit reference added.

Yesterday's Results

How to read these box scores · glossary

468 CVEs published. 25 box scores and 375 table rows below; the remaining 68 continue on page 2 — every CVE is listed, nothing truncated.

Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  N  H  N    8.6   .8820   99.8   YES
AFFECTED
  Product                               Versions  Fixed
  Cisco Unified Communications Manager  14 –      —
TIMELINE
  Oct 8   Reserved by CNA
  Jun 25  Added to CISA KEV, due Jun 28
  Jun 25  Published (CNA: cisco)
CWE-918 · CNA: cisco · CVSS v3.1 · 3 references · NVD status: Analyzed · KEV due June 28, 2026
PTC Windchill PDMLink — Remote Code Execution (RCE) vulnerability in Windchill PDMlink
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .4059   98.5   YES
AFFECTED
  Product            Versions     Fixed
  Windchill PDMLink  unspecified  —
  FlexPLM            unspecified  —
TIMELINE
  Jun 18  Reserved by CNA
  Jun 25  Added to CISA KEV, due Jun 28
  Jun 25  Published (CNA: PTC)
CWE-20, CWE-502 · CNA: PTC · CVSS v4.0 · 2 references · NVD status: Analyzed · KEV due June 28, 2026
Flowise - Arbitrary File Access via Missing Chat Flow ID Validation
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0436   90.5     —
AFFECTED
  Product  Versions     Fixed
  Flowise  unspecified  3.0.6
TIMELINE
  Jun 20  Reserved by CNA
  Jun 25  Public exploit reference published
  Jun 25  Published (CNA: VulnCheck)
CWE-73 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Analyzed
vanhauser-thc thc-hydra — Hydra - Stack Buffer Overflow in NTLM Authentication Handler
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   H   H   H    8.6   .0244   83.0     —
AFFECTED
  Product    Versions     Fixed
  thc-hydra  unspecified  9cc84c20e75f5fef6bb1790bb9ada2afad2204e2
TIMELINE
  Jun 22  Reserved by CNA
  Jun 25  Published (CNA: VulnCheck)
CWE-121 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
Schneider Electric PowerLogic™ P7 — CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exis…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0173   75.8     —
AFFECTED
  Product         Versions                             Fixed
  PowerLogic™ P7  Version V02.003.001.000 and prior –  —
TIMELINE
  May 27  Reserved by CNA
  Jun 25  Published (CNA: schneider)
CWE-78 · CNA: schneider · CVSS v4.0 · 1 reference · NVD status: Analyzed
Rapid7 InsightConnect Sed Plugin — OS Command Injection in Rapid7 InsightConnect Sed Plugin via expression parameter.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0160   73.8     —
AFFECTED
  Product                    Versions     Fixed
  InsightConnect Sed Plugin  unspecified  2.0.5
TIMELINE
  May 21  Reserved by CNA
  Jun 25  Published (CNA: rapid7)
CWE-78 · CNA: rapid7 · CVSS v3.1 · 1 reference · NVD status: Analyzed
Flowise - Arbitrary File Read via chatId Parameter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0157   73.5     —
AFFECTED
  Product  Versions     Fixed
  Flowise  unspecified  3.0.6
TIMELINE
  Jun 8   Reserved by CNA
  Jun 25  Public exploit reference published
  Jun 25  Published (CNA: VulnCheck)
CWE-73 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Modified
YMC YMC Filter — WordPress Filter & Grids plugin <= 3.11.5 - SQL Injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  N  L    9.3   .0134   69.2     —
AFFECTED
  Product     Versions  Fixed
  YMC Filter  n/a –     3.11.6
TIMELINE
  Jun 16  Reserved by CNA
  Jun 25  Published (CNA: Patchstack)
CWE-89 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
Rapid7 InsightConnect Tcpdump Plugin — OS Command Injection in Rapid7 InsightConnect Tcpdump Plugin
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0129   68.0     —
AFFECTED
  Product                        Versions     Fixed
  InsightConnect Tcpdump Plugin  unspecified  2.0.0
TIMELINE
  May 15  Reserved by CNA
  Jun 25  Published (CNA: rapid7)
CWE-78 · CNA: rapid7 · CVSS v3.1 · 1 reference · NVD status: Analyzed
Rapid7 InsightConnect SQLmap Plugin — OS Command Injection in Rapid7 InsightConnect SQLmap Plugin
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0129   68.0     —
AFFECTED
  Product                       Versions     Fixed
  InsightConnect SQLmap Plugin  unspecified  2.0.1
TIMELINE
  May 15  Reserved by CNA
  Jun 25  Published (CNA: rapid7)
CWE-78 · CNA: rapid7 · CVSS v3.1 · 1 reference · NVD status: Analyzed
Rapid7 InsightConnect Finger Plugin — OS Command Injection in Rapid7 InsightConnect Finger Plugin
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0129   68.0     —
AFFECTED
  Product                       Versions     Fixed
  InsightConnect Finger Plugin  unspecified  1.0.3
TIMELINE
  May 15  Reserved by CNA
  Jun 25  Published (CNA: rapid7)
CWE-78 · CNA: rapid7 · CVSS v3.1 · 1 reference · NVD status: Analyzed
Rapid7 InsightConnect AWK Plugin — OS Command Injection in Rapid7 InsightConnect AWK Plugin
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0120   65.7     —
AFFECTED
  Product                    Versions     Fixed
  InsightConnect AWK Plugin  unspecified  1.2.2
TIMELINE
  May 14  Reserved by CNA
  Jun 25  Published (CNA: rapid7)
CWE-78 · CNA: rapid7 · CVSS v3.1 · 1 reference · NVD status: Analyzed
Rapid7 InsightConnect Ping Plugin — OS Command Injection in Rapid7 InsightConnect Ping Plugin
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0120   65.7     —
AFFECTED
  Product                     Versions     Fixed
  InsightConnect Ping Plugin  unspecified  1.0.4
TIMELINE
  May 15  Reserved by CNA
  Jun 25  Published (CNA: rapid7)
CWE-78 · CNA: rapid7 · CVSS v3.1 · 1 reference · NVD status: Analyzed
Rapid7 InsightConnect TR Plugin — OS Command Injection in Rapid7 InsightConnect Translate Plugin
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0120   65.7     —
AFFECTED
  Product                   Versions     Fixed
  InsightConnect TR Plugin  unspecified  2.0.3
TIMELINE
  May 15  Reserved by CNA
  Jun 25  Published (CNA: rapid7)
CWE-78 · CNA: rapid7 · CVSS v3.1 · 1 reference · NVD status: Analyzed
Rapid7 InsightConnect Traceroute Plugin — OS Command Injection in Rapid7 InsightConnect Traceroute Plugin
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0120   65.7     —
AFFECTED
  Product                           Versions     Fixed
  InsightConnect Traceroute Plugin  unspecified  1.0.3
TIMELINE
  May 15  Reserved by CNA
  Jun 25  Published (CNA: rapid7)
CWE-78 · CNA: rapid7 · CVSS v3.1 · 1 reference · NVD status: Analyzed
Flowise - Unsandboxed Remote Code Execution via Custom MCP
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0115   64.4     —
AFFECTED
  Product  Versions     Fixed
  Flowise  unspecified  3.0.6
TIMELINE
  Jun 20  Reserved by CNA
  Jun 25  Public exploit reference published
  Jun 25  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Analyzed
Cursor Desktop sandbox escape via agent-controlled working directory
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0101   60.5     —
AFFECTED
  Product  Versions  Fixed
  cursor   < 3.0 –   —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 25  Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · CVSS v4.0 · 1 reference · NVD status: Analyzed
Cursor Desktop sandbox escape via symlink and failed path canonicalization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0101   60.5     —
AFFECTED
  Product  Versions  Fixed
  cursor   < 3.0 –   —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 25  Published (CNA: GitHub_M)
CWE-59 · CNA: GitHub_M · CVSS v4.0 · 1 reference · NVD status: Analyzed
Flowise - Arbitrary File Write to Remote Code Execution via document-store API
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0094   58.3     —
AFFECTED
  Product  Versions     Fixed
  Flowise  unspecified  —
TIMELINE
  Jun 20  Reserved by CNA
  Jun 25  Public exploit reference published
  Jun 25  Published (CNA: VulnCheck)
CWE-73 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Analyzed
Flowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0090   57.0     —
AFFECTED
  Product  Versions     Fixed
  Flowise  unspecified  —
TIMELINE
  Jun 20  Reserved by CNA
  Jun 25  Public exploit reference published
  Jun 25  Published (CNA: VulnCheck)
CWE-73 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Analyzed
FOSSBilling: Unauthenticated update patcher endpoint allows remote maintenance execution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   L   L    6.9   .0090   57.0     —
AFFECTED
  Product      Versions             Fixed
  FOSSBilling  >= 0.5.4, < 0.8.0 –  —
TIMELINE
  May 4   Reserved by CNA
  Jun 25  Published (CNA: GitHub_M)
CWE-306 · CNA: GitHub_M · CVSS v4.0 · 2 references · NVD status: Deferred
danpros htmly — HTMLy CMS 3.1.1 Path Traversal via oldfile Parameter in Autosave
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   H   H    7.2   .0090   57.0     —
AFFECTED
  Product  Versions     Fixed
  htmly    unspecified  —
TIMELINE
  May 11  Reserved by CNA
  Jun 25  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0087   56.1     —
AFFECTED
  Product                Versions     Fixed
  Wyse Management Suite  unspecified  —
TIMELINE
  May 31  Reserved by CNA
  Jun 25  Published (CNA: dell)
CWE-22 · CNA: dell · CVSS v3.1 · 1 reference · NVD status: Analyzed
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Neutralization o…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0082   54.5     —
AFFECTED
  Product                         Versions     Fixed
  Display and Peripheral Manager  unspecified  —
TIMELINE
  May 17  Reserved by CNA
  Jun 25  Published (CNA: dell)
CWE-78 · CNA: dell · CVSS v3.1 · 1 reference · NVD status: Analyzed
MarketingFire Widget Options — WordPress Widget Options plugin <= 4.2.3 - Remote Code Execution (RCE) vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0079   53.5     —
AFFECTED
  Product         Versions  Fixed
  Widget Options  n/a –     4.2.4
TIMELINE
  Jun 16  Reserved by CNA
  Jun 25  Published (CNA: Patchstack)
CWE-94 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-90867.353.2Red HatRed Hat build of Keycloak 26.4CWE-79Keycloak: keycloak: cross-site scripting (xss) via case-insensitive uri valid…
CVE-2026-90834.953.2Red HatRed Hat build of Keycloak 26.4CWE-22Keycloak: keycloak: information disclosure through arbitrary filesystem path …
CVE-2026-540889.352.6filebrowserfilebrowserCWE-78File Browser: Command Injection via Authentication Hook Shell Substitution (P…
CVE-2026-531769.851.6LinuxLinuxCWE-191IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN
CVE-2026-531997.551.0LinuxLinux—hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf
CVE-2026-567688.750.8haiwenseahubCWE-862Seahub < 13.0.23 - Authentication Bypass in ShareLinkZipTaskView GET Method
CVE-2026-567869.350.8tomojitakasuRTKLIBCWE-787RTKLIB 2.4.3 - Out-of-bounds Write in decode_type1033 via Crafted RTCM3 Message
CVE-2026-501768.750.8EVokeEVoke CSMSCWE-307EVoke Systems EVoke CSMS Improper Restriction of Excessive Authentication Att…
CVE-2026-531837.549.8LinuxLinux—mptcp: allow subflow rcv wnd to shrink
CVE-2026-531847.549.8LinuxLinux—udp: clear skb->dev before running a sockmap verdict
CVE-2025-713279.349.4FlowiseFlowiseCWE-306Flowise - Authentication Bypass via Unprotected Registration Endpoint
CVE-2026-560918.249.2Apache Software FoundationApache ShiroCWE-289Apache Shiro: Authentication bypass in Guice-Web integration
CVE-2026-407029.348.2EVokeEVoke CSMSCWE-306EVoke Systems EVoke CSMS Missing Authentication for Critical Function
CVE-2026-564458.847.9pydicompynetdicom LibraryCWE-22pydicom pynetdicom Library Path Traversal
CVE-2026-575207.147.8bitwardenserverCWE-862Bitwarden Server < 2026.5.0 Privilege Escalation via Bulk User Remove Endpoint
CVE-2026-98008.147.6Red HatRed Hat build of Keycloak 26.4CWE-1025Keycloak-policy-enforcer: keycloak policy enforcer: authorization bypass via …
CVE-2026-531988.847.5LinuxLinuxCWE-416ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL
CVE-2026-386377.547.4n/an/aCWE-400An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f…
CVE-2026-386407.547.4n/an/aCWE-400A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc c…
CVE-2026-532297.547.4LinuxLinuxCWE-401net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure
CVE-2026-532357.547.4LinuxLinux—net: add pskb_may_pull() to skb_gro_receive_list()
CVE-2026-120537.547.3GitLabGitLabCWE-532Insertion of Sensitive Information into Log File in GitLab
CVE-2026-554777.246.8MHSanaei3x-uiCWE-73Authenticated Arbitrary File Write via Database Import and Xray Log Path Mani…
CVE-2026-540899.146.6filebrowserfilebrowserCWE-287File Browser: Authentication Bypass via Proxy Auth Header Forgery
CVE-2026-466017.546.5golang.org/x/imagegolang.org/x/image/webp—Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image
CVE-2026-466027.546.5golang.org/x/imagegolang.org/x/image/tiff—Lack of limit on tile sizes in x/image/tiff in golang.org/x/image
CVE-2026-567678.745.9getmaxunmaxunCWE-862Maxun < 0.0.42 - Cross-Tenant IDOR in Storage and Webhook API Handlers
CVE-2026-567708.745.2schwehrlibaisCWE-129libais 0.15 - Out-of-bounds Vector Access in VdmStream::AddLine via Invalid S…
CVE-2026-560498.545.2Post SnippetsPost SnippetsCWE-94WordPress Post Snippets plugin <= 4.0.19 - Remote Code Execution (RCE) vulner…
CVE-2026-532408.844.3LinuxLinuxCWE-416xfrm: iptfs: fix use-after-free on first_skb in __input_process_payload
CVE-2026-567876.944.3tomojitakasuRTKLIBCWE-193RTKLIB 2.4.3 - Off-by-One Out-of-Bounds Read in decode_ssr3 via RTCM3 SSR Mes…
CVE-2026-561228.743.7rickknowlesWinstone Servlet ContainerCWE-22Winstone Servlet Engine 0.9.10 Path Traversal via HTTP Request Paths
CVE-2026-561239.243.4socatsocatCWE-122socat 1.8.0.0 - 1.8.1.1 Heap Buffer Overflow via SOCKS5 Reply Parser
CVE-2026-540926.543.4filebrowserfilebrowserCWE-400File Browser: DoS Vulnerability on Public Login API
CVE-2026-374537.543.0n/an/aCWE-200Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.120…
CVE-2026-374527.542.7n/an/aCWE-200Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.120…
CVE-2026-532488.842.3LinuxLinuxCWE-416net: airoha: Fix use-after-free in metadata dst teardown
CVE-2026-500168.842.3pnpmpnpmCWE-23pnpm: Transitive dependency alias path traversal allows project path override…
CVE-2026-532178.642.1LinuxLinux—net: mvpp2: sync RX data at the hardware packet offset
CVE-2026-5770010.041.9Daan.devOMGF ProCWE-434WordPress OMGF Pro plugin <= 5.2.6 - Arbitrary File Upload vulnerability
CVE-2026-560538.841.7EventPrimeEventPrimeCWE-502WordPress EventPrime plugin <= 4.3.4.1 - PHP Object Injection vulnerability
CVE-2026-532249.141.6LinuxLinuxCWE-125sctp: validate embedded INIT chunk and address list lengths in cookie
CVE-2026-540917.541.5filebrowserfilebrowserCWE-863File Browser: Incorrect access control in public directory shares via rule pa…
CVE-2026-60946.341.5wolfSSLwolfSSLCWE-125Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 En…
CVE-2026-532219.841.4LinuxLinux—ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()
CVE-2026-532289.841.4LinuxLinux—ipv6: sit: reload inner IPv6 header after GSO offloads
CVE-2026-531869.141.4LinuxLinux—RDMA/srp: bound SRP_RSP sense copy by the received length
CVE-2026-532259.141.4LinuxLinuxCWE-908sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
CVE-2026-540376.541.3danny-avilaLibreChatCWE-770LibreChat: Incomplete Fix for CVE-2025-7105 — /api/convos/duplicate Lacks Rat…
CVE-2026-53058.840.8UnknownEmail Address Encoder—Email Address Encoder (Free < 1.0.25, Premium < 0.3.12) - Unauthenticated Sto…
CVE-2026-66798.840.8wolfSSLwolfSSLCWE-787DTLS 1.3 ACK serialization heap buffer overflow via integer truncation
CVE-2026-129377.540.8themeficTourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress PluginCWE-89Tourfic <= 2.22.7 - Unauthenticated SQL Injection via 'post_id' Parameter
CVE-2026-554395.540.8halo-devhaloCWE-22Halo: Path Traversal in Backup Download Leads to Arbitrary File Read
CVE-2026-540947.540.7filebrowserfilebrowserCWE-22File Browser: Symlink following lets scoped users read, overwrite, and share …
CVE-2026-532159.840.7LinuxLinux—net: mvpp2: refill RX buffers before XDP or skb use
CVE-2026-532169.840.7LinuxLinux—net: mvpp2: limit XDP frame size to the RX buffer
CVE-2026-400837.240.6CacticactiCWE-89Cacti: SQL Injection in managers.php
CVE-2026-545735.340.4outlineoutlineCWE-863Authorization Bypass in API Key/OAuth Scopes via Path Parsing Discrepancy
CVE-2026-75312.340.4wolfSSLwolfSSLCWE-416Use-after-free in PQC hybrid key-share handling
CVE-2026-556678.240.2filebrowserfilebrowserCWE-22File Browser: Out-of-scope file deletion by a Create-only scoped user via sym…
CVE-2026-228798.139.9vtkvtkCWE-129vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnera…
CVE-2026-90997.739.9Red HatRed Hat build of Keycloak 26.4CWE-639Keycloak: group-admin escalation to realm-admin
CVE-2026-531657.539.8LinuxLinuxCWE-476iomap: avoid potential null folio->mapping deref during error reporting
CVE-2026-532447.539.8LinuxLinux—VFS: fix possible failure to unlock in nfsd4_create_file()
CVE-2026-133517.539.6zephyrproject-rtosZephyrCWE-772net: Maliciously fragmented IPv6 packets can prevent receiving/processing fut…
CVE-2026-531807.539.6LinuxLinuxCWE-667timers/migration: Fix livelock in tmigr_handle_remote_up()
CVE-2026-400846.539.6CacticactiCWE-22Cacti: Arbitrary File Read via Path Traversal in Report `format_file` Parameter
CVE-2026-4675210.039.3Apache Software FoundationApache KvrocksCWE-122Apache Kvrocks: Stack buffer overflow in Lua bit.tohex()
CVE-2026-567745.339.0kanboardkanboardCWE-639Kanboard - Cross-User Deletion of Persistent Login Sessions via Unvalidated S…
CVE-2025-713288.738.8FlowiseFlowiseCWE-620Flowise - Unverified Password Change via Account Settings
CVE-2026-22385.338.7GitLabGitLabCWE-862Missing Authorization in GitLab
CVE-2026-560547.738.5AhmadJS Help DeskCWE-22WordPress JS Help Desk plugin <= 3.1.1 - Arbitrary File Deletion vulnerability
CVE-2026-532479.838.3LinuxLinuxCWE-416net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown
CVE-2026-548458.138.4PluginUs.NetMDTFCWE-98WordPress MDTF plugin <= 1.3.8 - Local File Inclusion vulnerability
CVE-2026-97056.538.2Red HatRed Hat build of Keycloak 26.4CWE-613Keycloak: keycloak: attacker can re-enable and take over disabled clients via…
CVE-2026-120777.538.1wedevsDokan ProCWE-89Dokan Pro <= 5.0.4 - Unauthenticated SQL Injection via 'latitude' and 'longit…
CVE-2026-97168.737.9Schneider ElectricPowerLogic™ P7CWE-476CWE-476 NULL Pointer Dereference vulnerability exists that could cause a deni…
CVE-2026-574341.737.9sparklemotionnokogiriCWE-476Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper c…
CVE-2026-574351.737.9sparklemotionnokogiriCWE-416Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogi…
CVE-2026-531519.837.7LinuxLinux—rxrpc: Fix the ACK parser to extract the SACK table for parsing
CVE-2026-575222.337.5bitwardenserverCWE-74Bitwarden Server < 2026.5.0 JSON Injection via Webhook Templates
CVE-2026-91536.537.4Rapid7InsightConnect Sed PluginCWE-22Arbitrary File Read in Rapid7 InsightConnect Sed Plugin
CVE-2026-105122.337.3wolfSSLwolfSSLCWE-682X25519 x86_64 assembly final reduction leaves non-canonical field element
CVE-2026-540977.237.2filebrowserfilebrowserCWE-639File Browser: Cross-user unauthorized share-link deletion via unbounded prefi…
CVE-2026-556996.537.2pnpmpnpmCWE-22pnpm: reserved bin name deletes PNPM_HOME during global remove
CVE-2026-575872.937.1tenableNessusCWE-89SQL Injection in Nessus via Reverse DNS Lookup
CVE-2026-540246.536.8danny-avilaLibreChatCWE-770LibreChat: Incomplete Fix for CVE-2024-11171 — Conversation Import Multer Ins…
CVE-2026-132255.336.7pretixpretixCWE-80Stored XSS in ticket confirmation page
CVE-2026-559588.336.7wolfSSLwolfSSLCWE-787Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage
CVE-2026-544486.936.7aquasecuritytrivyCWE-770Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser
CVE-2026-489446.536.7getk2.orgK2 extension for JoomlaCWE-22Joomla Extension - getk2.org - Exposure of sensitive files via attachment cop…
CVE-2026-532469.836.6LinuxLinuxCWE-787sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing
CVE-2026-550927.036.6aquasecuritytrivyCWE-22Trivy: Path traversal via a crafted vulnerability database or other downloade…
CVE-2026-540908.736.2filebrowserfilebrowserCWE-77File Browser: Command Allowlist Bypass via Shell Metacharacter Injection
CVE-2026-500176.936.2pnpmpnpmCWE-200pnpm binds unscoped user-level npm auth credentials to a repository-selected …
CVE-2026-45267.136.1Silicon LabsEmberZNetCWE-125Global ZCL command parser missing minimum-length validation in EmberZNet v9.0.2
CVE-2026-471457.136.1Silicon LabsEmberZNetCWE-617Color Control hue/saturation assertion abort in EmberZNet v9.0.2
CVE-2026-471467.136.1Silicon LabsEmberZNetCWE-617Color Control color-temperature assertion abort in EmberZNet v9.0.2
CVE-2026-471487.136.1Silicon LabsEmberZNetCWE-125Groups GetGroupMembership count/list-length mismatch in EmberZNet v9.0.2
CVE-2026-471497.136.1Silicon LabsEmberZNetCWE-125Door Lock GetUserType invalid table index in EmberZNet v9.0.2
CVE-2026-471527.136.1Silicon LabsEmberZNetCWE-369Level Control Move divide-by-zero in EmberZNet v9.0.2
CVE-2026-471537.136.1Silicon LabsEmberZNetCWE-369Level Control Step With On/Off divide-by-zero in EmberZNet v9.0.2
CVE-2026-471547.136.1Silicon LabsEmberZNetCWE-125Simple Metering GetProfileResponse interval-bounds bug in EmberZNet v9.0.2
CVE-2025-713407.635.7picklescanpicklescanCWE-502picklescan - Remote Code Execution via idlelib.pyshell.ModifiedInterpreter.ru…
CVE-2026-575215.335.6bitwardenserverCWE-862Bitwarden Server < 2026.5.0 Broken Access Control via PreviewInvoiceController
CVE-2026-500157.335.4pnpmpnpmCWE-22pnpm: Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)
CVE-2026-97186.935.3Schneider ElectricPowerLogic™ P7CWE-617CWE-617 Reachable Assertion vulnerability exists that could allow an authenti…
CVE-2026-129936.535.3Red HatRed Hat build of Apicurio Registry 3CWE-776Apicurio/apicurio-registry: apicurio-registry: xml entity-expansion denial of…
CVE-2026-572356.335.3sparklemotionnokogiriCWE-125Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
CVE-2026-531319.435.2LinuxLinux—netfilter: require Ethernet MAC header before using eth_hdr()
CVE-2026-575328.835.1pretixpretixCWE-80Malicious HTML content contained in the layout specification of a PDF ticket …
CVE-2026-107126.135.2GitLabGitLabCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…
CVE-2026-575342.135.1pretixpretix-pagesCWE-80Stored XSS in pretix-pages
CVE-2026-133142.035.1pretixpretix-digitalCWE-80Stored XSS in pretix-digital
CVE-2026-446226.935.0EVokeEVoke CSMSCWE-522EVoke Systems EVoke CSMS Insufficiently Protected Credentials
CVE-2026-567897.135.0tomojitakasuRTKLIBCWE-122RTKLIB 2.4.3 - Heap Buffer Overflow and Stack Read via Oversized RINEX Epoch …
CVE-2026-544796.934.7EVokeEVoke CSMSCWE-613EVoke Systems EVoke CSMS Insufficient Session Expiration
CVE-2026-557007.134.5pnpmpnpmCWE-22pnpm: stage download writes outside destination via manifest version traversal
CVE-2026-548417.534.3AppsbdViteposCWE-201WordPress Vitepos plugin <= 3.4.2 - Sensitive Data Exposure vulnerability
CVE-2026-92229.234.0Shenzhen i365-Tech Co. Ltd.Setracker2 Parental Control App (Android) package com.tgelec.setrackerCWE-836Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of pa…
CVE-2026-129758.533.9Red HatRed Hat build of Apicurio Registry 3CWE-611Apicurio/apicurio-registry: apicurio-registry: unhardened saxparser in conten…
CVE-2026-91546.533.8Rapid7InsightConnect Sed PluginCWE-22Arbitrary File Write in Rapid7 InsightConnect Sed Plugin
CVE-2026-96508.733.5Schneider ElectricEasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & ControllerCWE-522CWE-522 Insufficiently Protected Credentials vulnerability that could cause u…
CVE-2026-471477.133.3Silicon LabsEmberZNetCWE-125OTA server raw parser missing per-field bounds validation in EmberZNet v9.0.2
CVE-2026-574361.733.1sparklemotionnokogiriCWE-416Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid…
CVE-2026-574371.733.1sparklemotionnokogiriCWE-416Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathCo…
CVE-2026-466087.432.9nicolargoglancesCWE-183Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildc…
CVE-2026-548439.332.9PluginUs.NetMDTFCWE-89WordPress MDTF plugin <= 1.3.7 - SQL Injection vulnerability
CVE-2026-548499.332.9PremmercePremmerce Wishlist for WooCommerceCWE-89WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.11 - SQL Injection…
CVE-2026-25086.532.8GravityMoreGravity BookingsCWE-89Gravity Forms Booking <= 2.7.1 - Authenticated (Subscriber+) Time-Based SQL I…
CVE-2026-532328.832.7LinuxLinux—net: phy: clean the sfp upstream if phy probing fails
CVE-2026-128447.532.6DROLSKYList::SomeUtils::XSCWE-122List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow…
CVE-2026-542266.432.5Apache Software FoundationApache KvrocksCWE-190Apache Kvrocks: RESTORE IntSet Integer Overflow Leads to Remote DoS
CVE-2026-64325.332.5Silicon LabsSiSDKCWE-130Improper bounds validation in EmberZNet SDK
CVE-2026-554139.432.5ToolJetToolJetCWE-94ToolJet - Marketplace Plugin Poisoning Enables Instance-Wide Remote Code Exec…
CVE-2026-532537.132.4LinuxLinuxCWE-125Bluetooth: bnep: reject short frames before parsing
CVE-2026-575352.132.5pretixpretixCWE-80Content injected to PDF rendering contexts could, in many places, include HTM…
CVE-2026-92208.732.2Shenzhen i365-Tech Co. Ltd.Setracker2 Parental Control App (Android) package com.tgelec.setrackerCWE-321Setracker2 Children's Smartwatch Ecosystem Use of hard-coded cryptographic key
CVE-2026-57964.331.7GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2026-124738.331.6Open Health Imaging Foundation (OHIF)DICOM Web Viewer FrameworkCWE-918OHIF Viewers DICOM Server-Side request forgery
CVE-2026-411209.831.4DellWyse Management SuiteCWE-349Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Accepta…
CVE-2026-423875.931.3PowerDNSRecursorCWE-20Insufficient input validation in ZoneToCache
CVE-2026-423885.931.3PowerDNSRecursorCWE-20Missing input validation for catalog zones
CVE-2026-549177.831.2seaweedfsseaweedfsCWE-22SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bu…
CVE-2026-60922.131.1wolfSSLwolfSSLCWE-757Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_M…
CVE-2026-540368.131.1danny-avilaLibreChatCWE-306LibreChat: 2FA Re-enrollment Allows Full Account 2FA Takeover Without OTP Ver…
CVE-2025-713358.630.7FlowiseFlowiseCWE-613Flowise - Session Invalidation Failure After Password Change
CVE-2026-471507.130.7Silicon LabsEmberZNetCWE-787IAS Zone enroll invalid table index and write in EmberZNet 9.0.2
CVE-2026-471517.130.7Silicon LabsEmberZNetCWE-787Door Lock ClearWeekdaySchedule invalid table index and write in EmberZNet v9.0.2
CVE-2026-120796.530.7wedevsDokan ProCWE-89Dokan Pro <= 5.0.4 - Authenticated (Subscriber+) SQL Injection via 'orderby' …
CVE-2026-66811.030.3wolfSSLwolfSSLCWE-120PKCS#7 decode ignores caller output buffer size, writing past buffer bounds
CVE-2026-576196.529.7ElementorElementor Website BuilderCWE-862WordPress Elementor Website Builder plugin <= 4.1.3 - Sensitive Data Exposure…
CVE-2026-532609.829.5LinuxLinuxCWE-416tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req().
CVE-2026-567696.329.5hcengineeringplatformCWE-918Huly Platform - Server-Side Request Forgery via /import Endpoint
CVE-2026-551806.529.3pnpmpnpmCWE-200pnpm: Repository config can expand victim environment secrets into registry r…
CVE-2026-127552.729.2DevolutionsServerCWE-1284Improper input validation in the PAM AD discovery endpoints in Devolutions Se…
CVE-2026-415669.429.1Apache Software FoundationApache KvrocksCWE-280Apache Kvrocks: Improper permission for the APPLYBATCH command
CVE-2026-16064.328.9GitLabGitLabCWE-94Improper Control of Generation of Code ('Code Injection') in GitLab
CVE-2026-133118.728.7ljharbshell-quoteCWE-407shell-quote parse() is quadratic in token count, enabling denial of service
CVE-2026-466077.828.7nicolargoglancesCWE-502Glances: Insecure Pickle Deserialization in Version Cache Leads to Arbitrary …
CVE-2026-117036.028.5wolfSSLwolfSSLCWE-287Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption
CVE-2026-97027.528.4UnknownInPost PL—InPost PL < 1.9.1 - Unauthenticated WooCommerce Order Parcel-Locker Hijacking
CVE-2026-548228.528.4SALESmanagoSALESmanago & LeadooCWE-89WordPress SALESmanago & Leadoo plugin <= 3.11.2 - SQL Injection vulnerability
CVE-2026-548388.528.4Rymera Web CoWC Vendors MarketplaceCWE-89WordPress WC Vendors Marketplace plugin <= 2.6.8 - SQL Injection vulnerability
CVE-2026-540336.527.8danny-avilaLibreChatCWE-918LibreChat: SSRF via User-Provided Custom Endpoint baseURL — no private IP val…
CVE-2026-567716.327.7samuelclayNewsBlurCWE-918NewsBlur < 14.5.0 - Server-Side Request Forgery via add_url Endpoint
CVE-2026-548428.127.6Royal PluginsRoyal MCPCWE-862WordPress Royal MCP plugin <= 1.4.25 - Broken Access Control vulnerability
CVE-2026-92198.327.5Shenzhen i365-Tech Co. Ltd.Setracker2 Parental Control App (Android) package com.tgelec.setrackerCWE-340Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers …
CVE-2026-100865.427.5GitLabGitLabCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…
CVE-2026-548287.527.2StylemixThemesMotorsCWE-862WordPress Motors plugin <= 1.4.109 - Broken Access Control vulnerability
CVE-2026-548307.527.2Etoile Web Design IncorporatedFive Star Restaurant ReservationsCWE-862WordPress Five Star Restaurant Reservations plugin <= 2.7.19 - Broken Access …
CVE-2026-548447.527.2CheckViewCheckView Automated TestingCWE-862WordPress CheckView Automated Testing plugin <= 2.1.0 - Broken Access Control…
CVE-2026-532688.226.9LinuxLinuxCWE-125netfilter: conntrack_irc: fix possible out-of-bounds read
CVE-2026-420054.326.9PowerDNSAuthoritativeCWE-400Insufficient input validation of internal web server
CVE-2026-374547.526.8n/an/aCWE-200Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.120…
CVE-2026-572361.726.6sparklemotionnokogiriCWE-416Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` ra…
CVE-2026-574296.526.5eLightUpSlim SEOCWE-862WordPress Slim SEO plugin <= 4.6.2 - Broken Access Control vulnerability
CVE-2026-526905.926.4PowerDNSRecursorCWE-290Spoofed answers can mark an authoritative non-EDNS capable
CVE-2026-132837.526.2GoogleChromeCWE-416Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.20…
CVE-2026-59524.325.9GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2026-560136.525.6myCredLicense Manager for WooCommerceCWE-639WordPress License Manager for WooCommerce plugin <= 3.0.15 - Insecure Direct …
CVE-2026-560506.525.6ThemeislePPOM for WooCommerceCWE-284WordPress PPOM for WooCommerce plugin <= 33.0.18 - Broken Access Control vuln…
CVE-2026-108336.425.5wpdevteamGutenberg Essential Blocks – Page Builder for Gutenberg Blocks & PatternsCWE-79Gutenberg Essential Blocks - Page Builder for Gutenberg Blocks & Patterns <= …
CVE-2026-132226.325.4pretixpretix-oppwaCWE-841Insufficient validation of payment status in pretix-oppwa
CVE-2026-132236.325.4pretixpretix-computopCWE-841Insufficient validation of payment status in pretix-computop
CVE-2026-575366.325.4pretixpretix-mollieCWE-841Insufficient validation of payment status in pretix-mollie
CVE-2026-567725.325.4samuelclayNewsBlurCWE-639NewsBlur < 14.5.0 - Insecure Direct Object Reference in Social Interactions E…
CVE-2026-489455.325.3getk2.orgK2 extension for JoomlaCWE-434Joomla Extension - getk2.org - Privileged RCE vulnerability in K2 extension f…
CVE-2026-575881.825.3tenableNessusCWE-89SQL Injection in Nessus via Malicious Scan Result File Import
CVE-2026-64501.025.3wolfSSLwolfSSLCWE-295CRL critical extension bypass in ParseCRL_Extensions
CVE-2026-66781.025.3wolfSSLwolfSSLCWE-191Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info
CVE-2026-467515.524.9Apache Software FoundationApache Kvrocks—Apache Kvrocks: Does not remove the unsafe loadstring function from its Lua s…
CVE-2026-09343.824.9GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2026-122448.724.8NLnet LabsNSDCWE-122Heap overflow and crash with crafted SVCB RR
CVE-2026-540276.524.7danny-avilaLibreChatCWE-862LibreChat: Image Upload Route Bypasses Agent Permission Check — Incomplete Fi…
CVE-2026-548297.524.2Jacob N. BreetveltWP Photo Album PlusCWE-89WordPress WP Photo Album Plus plugin <= 9.1.13.005 - SQL Injection vulnerability
CVE-2026-400825.424.2CacticactiCWE-384Cacti: Session Fixation via missing session_regenerate_id() after login
CVE-2026-122458.724.1NLnet LabsNSDCWE-416Denial of DNS over TLS service by any DoT client
CVE-2026-554128.324.1ToolJetToolJetCWE-918ToolJet Cloud - SSRF to Azure Cloud Infrastructure Compromise
CVE-2026-548488.323.9Saad IqbalAPIExperts Square for WooCommerceCWE-201WordPress APIExperts Square for WooCommerce plugin <= 4.7.3 - Sensitive Data …
CVE-2026-129927.424.0Red HatRed Hat build of Apicurio Registry 3CWE-918Apicurio/apicurio-registry: apicurio-registry: ssrf via wsdl4j import derefer…
CVE-2026-500147.324.0pnpmpnpmCWE-88pnpm: Git Fetch Argument Injection via Lockfile resolution.commit
CVE-2026-400125.324.0PowerDNSRecursorCWE-524Information about ECS zero scoped answers might leak to clients that use a sp…
CVE-2026-531759.823.5LinuxLinuxCWE-416inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush
CVE-2026-273667.523.4MainWPMainWP ChildCWE-862WordPress MainWP Child plugin <= 6.1.1 - Broken Access Control vulnerability
CVE-2026-531788.123.2LinuxLinuxCWE-191staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction
CVE-2026-288985.323.2Appleswift-nio-http2CWE-116swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header val…
CVE-2026-567907.023.0canboatcanboatCWE-193CANBoat - Off-by-One Global Buffer Overflow in searchForPgn()
CVE-2026-130836.922.4Red HatPen Drive Powered by Red Hat LightspeedCWE-79Pen-drive: pen-drive: stored xss via unescaped cluster data in html report
CVE-2026-489436.522.4getk2.orgK2 extension for JoomlaCWE-915Joomla Extension - getk2.org - Authenticated user property mass-assignment in…
CVE-2026-118008.122.0Red HatRed Hat build of Keycloak 26.6CWE-347Org.keycloak:keycloak-services: keycloak: authentication bypass via jwt algor…
CVE-2026-122467.222.0NLnet LabsNSDCWE-20Out of bounds stack write with crafted APL RR
CVE-2026-113795.322.0GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2026-493196.921.9Alps Electric Co., Ltd.Remote Keyless Entry System (RKES) R53R0CWE-294Alps Electric Co., Ltd. R53R0 Remote Keyless Entry System (RKES) Replay Attack
CVE-2026-423895.321.9PowerDNSRecursorCWE-20Reject more queries with invalid header values
CVE-2026-561302.021.9Apache Software FoundationApache ShiroCWE-294Apache Shiro: Remember-me cookie isn't checked for expiry on the server
CVE-2026-123406.321.8wolfSSLwolfSSLCWE-125Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computa…
CVE-2026-556988.821.7pnpmpnpmCWE-345pnpm: Project env lockfile can short-circuit package-manager resolution and e…
CVE-2026-402115.321.6PowerDNSDNSdistCWE-770Denial of service via crafted DoH3 queries
CVE-2026-86624.321.5Rapid7InsightConnect Compression PluginCWE-22Path Traversal in Rapid7 InsightConnect Compression Plugin
CVE-2026-575332.121.5pretixpretixCWE-80Malicious HTML content could be injected into the page pretix shows when redi…
CVE-2026-53095.421.4GitLabGitLabCWE-639Authorization Bypass Through User-Controlled Key in GitLab
CVE-2026-567795.321.41Panel-devMaxKBCWE-918MaxKB < 2.10.0 - Server-Side Request Forgery via downloadCallbackUrl and down…
CVE-2026-97994.621.3Red HatRed Hat build of Keycloak 26.4CWE-639Keycloak: keycloak: unauthorized access to resources via uma permission ticke…
CVE-2026-63252.021.4wolfSSLwolfSSLCWE-787Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms…
CVE-2026-402095.321.0PowerDNSDNSdistCWE-772Denial of service via IXFR queries
CVE-2026-31763.120.9GitLabGitLabCWE-862Missing Authorization in GitLab
CVE-2026-75325.720.8wolfSSLwolfSSLCWE-295iPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefined
CVE-2026-560235.420.7Knit PayUPI QR Code Payment Gateway for WooCommerceCWE-862WordPress UPI QR Code Payment Gateway for WooCommerce plugin <= 1.6.2 - Broke…
CVE-2020-372565.120.6GravGravCWE-79Grav - Cross-Site Scripting in Admin Plugin Page Editor
CVE-2026-548217.420.3Bootstrapped VenturesVisual Link PreviewCWE-201WordPress Visual Link Preview plugin <= 2.3.1 - Sensitive Data Exposure vulne…
CVE-2026-489466.320.3getk2.orgK2 extension for JoomlaCWE-434Joomla Extension - getk2.org - Privileged RCE vulnerability in K2 extension f…
CVE-2026-489403.420.3getk2.orgK2 extension for JoomlaCWE-79Joomla Extension - getk2.org - Stored-XSS in K2 extension for Joomla < 2.26
CVE-2026-108246.519.3UnknownMasteriyo LMS—Masteriyo LMS < 2.2.1 - Unauthenticated Course Progress Disclosure and Deletion
CVE-2026-540296.519.1danny-avilaLibreChatCWE-862LibreChat: IDOR in Message Deletion — Incomplete Fix for CVE-2024-41703 Leave…
CVE-2026-133502.318.8pretixVenuelessCWE-639Permissions where checked incorrectly during room creation, allowing attacker…
CVE-2026-531478.118.4LinuxLinuxCWE-125thunderbolt: Validate XDomain request packet size before type cast
CVE-2026-532548.118.4LinuxLinuxCWE-125Bluetooth: RFCOMM: validate skb length in MCC handlers
CVE-2026-489416.518.1getk2.orgK2 extension for JoomlaCWE-862Joomla Extension - getk2.org - Unauthenticated folder delete in K2 extension …
CVE-2026-409417.118.0CacticactiCWE-347Cacti: Package Import Signature Validation Bypass Allows Self-Signed Packages
CVE-2026-100978.317.5wolfSSLwolfSSLCWE-697ML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break…
CVE-2026-132818.317.5GoogleChromeCWE-472Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a r…
CVE-2026-531966.817.5LinuxLinuxCWE-787USB: serial: io_ti: fix heap overflow in get_manuf_info()
CVE-2026-402104.817.5PowerDNSDNSdistCWE-126Out-of-bounds read in SetMacAddrAction
CVE-2026-92218.717.1Shenzhen i365-Tech Co. Ltd.Setracker2 Parental Control App (Android) package com.tgelec.setrackerCWE-327Setracker2 Children's Smartwatch Ecosystem Use of a Broken or Risky Cryptogra…
CVE-2026-540407.117.1danny-avilaLibreChatCWE-306LibreChat: 2FA Backup Code Regeneration Without OTP Verification Allows 2FA B…
CVE-2026-400806.117.0CacticactiCWE-601Cacti: Open Redirect via HTTP_REFERER substring check in auth_login_redirect
CVE-2026-75115.916.8wolfSSLwolfSSLCWE-347PKCS7_verify signer confusion allows forged signatures to be accepted
CVE-2026-489426.116.4getk2.orgK2 extension for JoomlaCWE-79Joomla Extension - getk2.org - Stored-XSS in K2 extension for Joomla < 2.26
CVE-2026-28158.416.2Silicon LabsSiSDKCWE-339Incorrect use of the PUF key for user key generation in EFR32xG27 results in …
CVE-2026-560057.116.3MelapressWP Activity LogCWE-79WordPress WP Activity Log plugin <= 5.6.3.1 - Cross Site Scripting (XSS) vuln…
CVE-2026-560067.116.3H5PH5PCWE-79WordPress H5P plugin <= 1.17.6 - Reflected Cross Site Scripting (XSS) vulnera…
CVE-2026-560147.116.3AvertaMaster SliderCWE-79WordPress Master Slider plugin <= 3.11.2 - Cross Site Scripting (XSS) vulnera…
CVE-2026-560427.116.3AlgolplusAdvanced Order Export For WooCommerceCWE-79WordPress Advanced Order Export For WooCommerce plugin <= 4.0.9 - Cross Site …
CVE-2026-560517.116.3TablePressTablePressCWE-79WordPress TablePress plugin <= 3.3.1 - Reflected Cross Site Scripting (XSS) v…
CVE-2026-560717.116.3WPMU DEVForminatorCWE-79WordPress Forminator plugin <= 1.53.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-126353.116.0GitLabGitLabCWE-350Reliance on Reverse DNS Resolution for a Security-Critical Action in GitLab
CVE-2026-532568.015.9LinuxLinuxCWE-416Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()
CVE-2026-62916.015.2wolfSSLwolfSSLCWE-208Bleichenbacher padding oracle in PKCS#7 KTRI RSA PKCS#1 v1.5 decryption
CVE-2026-531467.115.1LinuxLinux—thunderbolt: Limit XDomain response copy to actual frame size
CVE-2026-532647.815.0LinuxLinuxCWE-416net/sched: act_api: use RCU with deferred freeing for action lifecycle
CVE-2026-540255.414.6danny-avilaLibreChatCWE-79LibreChat: Stored XSS via unescaped image alt text in markdown artifact preview
CVE-2026-133186.414.4Red HatRed Hat OpenShift Virtualization 4CWE-918Virt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalid…
CVE-2026-559626.014.2wolfSSLwolfSSLCWE-287TLS 1.3 post-handshake authentication: server accepts Finished without client…
CVE-2026-113108.714.1wolfSSLwolfSSLCWE-295X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermed…
CVE-2026-119998.214.1wolfSSLwolfSSLCWE-295X.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert()
CVE-2026-559608.214.1wolfSSLwolfSSLCWE-295Un-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing…
CVE-2026-532758.813.8LinuxLinuxCWE-416ipv6: mcast: Fix use-after-free when processing MLD queries
CVE-2026-558955.713.1vimvimCWE-78Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename
CVE-2026-371497.711.9n/an/aCWE-89GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was disco…
CVE-2026-63296.011.4wolfSSLwolfSSLCWE-347PKCS#12 MAC verification uses attacker-controlled comparison length
CVE-2026-466067.811.4nicolargoglancesCWE-78Glances: Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vm…
CVE-2026-574537.310.8vimvimCWE-77Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction
CVE-2026-423905.310.4PowerDNSRecursorCWE-20ZONEMD validation can be bypassed
CVE-2026-402083.710.3PowerDNSDNSdistCWE-705Denial of service via DoH3 queries
CVE-2026-67316.010.3wolfSSLwolfSSLCWE-295X.509 name constraint bypass via Subject CN treated as a DNS name
CVE-2026-531377.89.9LinuxLinuxCWE-787drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size
CVE-2026-531947.89.7LinuxLinuxCWE-787USB: serial: kl5kusb105: fix bulk-out buffer overflow
CVE-2026-554116.89.6ToolJetToolJetCWE-639ToolJet: Cross-tenant credential decryption (IDOR) in POST /api/data-sources/…
CVE-2026-105926.39.6wolfSSLwolfSSLCWE-295Wildcard DNS SAN bypasses CA name-constraint checks
CVE-2025-604647.89.6n/an/aCWE-416A use-after-free in the gf_sei_load_from_state_internal function (/filters/se…
CVE-2026-572342.69.6sparklemotionnokogiriCWE-178Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, byp…
CVE-2026-60916.09.2wolfSSLwolfSSLCWE-295Partial-chain verification accepts untrusted intermediate as trust anchor
CVE-2026-540936.89.0filebrowserfilebrowserCWE-22File Browser: Path traversal in download-as-zip/tar via Windows-style backsla…
CVE-2026-532037.18.9LinuxLinuxCWE-787accel/ivpu: Add buffer overflow check in MS get_info_ioctl
CVE-2026-556978.88.7pnpmpnpmCWE-78pnpm: Repository-controlled configDependencies can select a pacquet native in…
CVE-2026-531957.88.7LinuxLinuxCWE-787USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()
CVE-2026-100986.38.6wolfSSLwolfSSLCWE-295OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status
CVE-2026-559646.38.6wolfSSLwolfSSLCWE-295Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA (temp…
CVE-2026-63312.18.7wolfSSLwolfSSLCWE-347HMAC zero-length tag forgery in EVP_DigestVerifyFinal
CVE-2026-129218.48.3AzeoTechDAQFactoryCWE-416Use after free in AzeoTech DAQFactory
CVE-2025-604656.18.3n/an/aCWE-416A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter…
CVE-2026-531487.88.2LinuxLinuxCWE-787thunderbolt: Clamp XDomain response data copy to allocation size
CVE-2026-531327.18.2LinuxLinuxCWE-401vsock/virtio: fix potential unbounded skb queue
CVE-2026-539257.87.9nicolargoglancesCWE-22Glances: Arbitrary file write and command execution via `secure_popen` redire…
CVE-2026-540968.47.8filebrowserfilebrowserCWE-863File Browser: Improper Access Control Occurs via Pre-Created Public Share for…
CVE-2026-83304.47.8GitLabGitLabCWE-532Insertion of Sensitive Information into Log File in GitLab
CVE-2026-559672.07.8wolfSSLwolfSSLCWE-323AES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enab…
CVE-2026-554878.87.7pnpmpnpmCWE-346pnpm: manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
CVE-2026-500218.17.7pnpmpnpmCWE-354pnpm: Integrity Check Bypass via Missing Lockfile Integrity Field
CVE-2021-479867.77.5parse-communityparse-serverCWE-494Parse Server - Unreviewed Code Execution via Malicious Version Tags
CVE-2026-532347.87.4LinuxLinuxCWE-416net: ibm: emac: Fix use-after-free during device removal
CVE-2026-45226.77.4HYPRPasswordlessCWE-306Missing authentication for critical function vulnerability in HYPR Passwordle…
CVE-2021-479877.77.3parse-communityparse-serverCWE-494Parse Server - Arbitrary Code Execution via Malicious Version Tags
CVE-2026-531337.87.1LinuxLinuxCWE-681RDMA/umem: Fix truncation for block sizes >= 4G
CVE-2026-531827.87.1LinuxLinux—wifi: nl80211: reject oversized EMA RNR lists
CVE-2026-532097.87.1LinuxLinuxCWE-787Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend
CVE-2026-532657.87.1LinuxLinux—dm cache policy smq: check allocation under invalidate lock
CVE-2026-531595.57.1LinuxLinux—misc: fastrpc: fix DMA address corruption due to find_vma misuse
CVE-2026-531708.87.0LinuxLinuxCWE-908accel/ethosu: reject DMA commands with uninitialized length
CVE-2026-531718.87.0LinuxLinux—accel/ethosu: fix arithmetic issues in dma_length()
CVE-2026-128978.47.0Horner AutomationCscapeCWE-125Out-of-bounds read in Horner Automation Cscape
CVE-2026-531917.87.0LinuxLinux—io_uring/net: inherit IORING_CQE_F_BUF_MORE across bundle recv retries
CVE-2026-531937.87.0LinuxLinuxCWE-416ALSA: timer: Forcibly close timer instances at closing
CVE-2026-532017.87.0LinuxLinux—Revert "drm/xe: Skip exec queue schedule toggle if queue is idle during suspend"
CVE-2026-532337.87.0LinuxLinuxCWE-415netdev: fix double-free in netdev_nl_bind_rx_doit()
CVE-2026-531888.86.8LinuxLinux—RDMA/core: Validate the passed in fops for ib_get_ucaps()
CVE-2026-531627.86.8LinuxLinux—memcg: use round-robin victim selection in refill_stock
CVE-2026-567884.86.7tomojitakasuRTKLIBCWE-125RTKLIB 2.4.3 - Out-of-bounds Read via Negative Array Index in getcodepri
CVE-2026-532745.56.7LinuxLinux—net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS
CVE-2026-531607.86.5LinuxLinuxCWE-416misc: fastrpc: fix use-after-free race in fastrpc_map_create
CVE-2026-531617.86.5LinuxLinuxCWE-416misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context
CVE-2026-532397.86.5LinuxLinuxCWE-416xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()
CVE-2026-489954.86.5pnpmpnpmCWE-353pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile
CVE-2026-531567.86.5LinuxLinuxCWE-416nvmem: core: fix use-after-free bugs in error paths
CVE-2026-531927.86.5LinuxLinuxCWE-416ALSA: timer: Fix UAF at snd_timer_user_params()
CVE-2026-532727.86.5LinuxLinuxCWE-416erofs: fix use-after-free on sbi->sync_decompress
CVE-2026-558925.56.5vimvimCWE-787Vim: Out-of-bounds Write in Spell File Prefix Dump
CVE-2026-574525.56.5vimvimCWE-125Vim: Out-of-bounds Read with libsodium-encrypted Files
CVE-2026-575897.86.4OpenBSDOpenBSDCWE-416sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing loca…
CVE-2026-574546.86.3vimvimCWE-125Vim: Out-of-bounds Read with Text Properties
CVE-2026-63306.36.3wolfSSLwolfSSLCWE-327ML-KEM ARM64 NEON ciphertext comparison only compares half of the input
CVE-2026-540309.36.2danny-avilaLibreChatCWE-346LibreChat: Missing Resource Parameter Validation in MCP OAuth Flow
CVE-2026-505738.16.2pnpmpnpmCWE-345pnpm: Unsafe default behavior breaks integrity check
CVE-2026-532597.86.3LinuxLinuxCWE-416ipv6: anycast: insert aca into global hash under idev->lock
CVE-2026-532237.16.1LinuxLinux—net: guard timestamp cmsgs to real error queue skbs
CVE-2026-542505.86.1k3s-iok3sCWE-22K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression
CVE-2026-532308.76.0LinuxLinuxCWE-125net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list
CVE-2026-531797.16.0LinuxLinuxCWE-125staging: rtl8723bs: fix buffer over-read in rtw_update_protection
CVE-2026-532057.16.0LinuxLinuxCWE-787accel/ivpu: Add bounds checks for firmware log indices
CVE-2026-466115.36.0nicolargoglancesCWE-346Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding …
CVE-2026-532008.85.9LinuxLinux—KVM: arm64: nv: Fix handling of XN[0] when !FEAT_XNX
CVE-2026-531727.85.9LinuxLinuxCWE-125accel/ethosu: fix IFM region index out-of-bounds in command stream parser
CVE-2026-531737.85.9LinuxLinuxCWE-787accel/ethosu: fix OOB write in ethosu_gem_cmdstream_copy_and_validate()
CVE-2026-531747.85.9LinuxLinux—ovl: keep err zero after successful ovl_cache_get()
CVE-2026-532767.85.9LinuxLinuxCWE-416Bluetooth: ISO: Fix a use-after-free of the hci_conn pointer
CVE-2026-561296.85.9Dynabook Inc.Generic IO & Memory Access driverCWE-782Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and…
CVE-2026-531877.15.8LinuxLinuxCWE-787RDMA/core: Validate cpu_id against nr_cpu_ids in DMAH alloc
CVE-2026-531355.55.6LinuxLinuxCWE-476drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs
CVE-2026-531405.55.5LinuxLinuxCWE-401drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups
CVE-2026-531425.55.5LinuxLinuxCWE-908drm/xe/display: fix oops in suspend/shutdown without display
CVE-2026-531445.55.5LinuxLinuxCWE-476drm/amdkfd: fix NULL dereference in get_queue_ids()
CVE-2026-531505.55.6LinuxLinuxCWE-191thunderbolt: Reject zero-length property entries in validator
CVE-2026-531525.55.5LinuxLinuxCWE-476mmc: dw_mmc-rockchip: Add missing private data for very old controllers
CVE-2026-531545.55.5LinuxLinuxCWE-772mm/hugetlb: restore reservation on error in hugetlb folio copy paths
CVE-2026-531685.55.6LinuxLinux—fuse: reject fuse_notify() pagecache ops on directories
CVE-2026-531775.55.6LinuxLinuxCWE-476bnxt_en: Fix NULL pointer dereference
CVE-2026-531905.55.5LinuxLinux—drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait()
CVE-2026-532105.55.5LinuxLinuxCWE-401tee: shm: fix shm leak in register_shm_helper()
CVE-2026-532145.55.5LinuxLinuxCWE-476ipv6: Fix a potential NPD in cleanup_prefix_route()
CVE-2026-532195.55.6LinuxLinux—netfilter: x_tables: avoid leaking percpu counter pointers
CVE-2026-532205.55.5LinuxLinuxCWE-476netfilter: revalidate bridge ports
CVE-2026-532375.55.5LinuxLinuxCWE-476gpio: mvebu: fix NULL pointer dereference in suspend/resume
CVE-2026-532385.55.6LinuxLinux—netlabel: validate unlabeled address and mask attribute lengths
CVE-2026-532415.55.5LinuxLinux—ALSA: seq: dummy: fix UMP event stack overread
CVE-2026-532515.55.5LinuxLinuxCWE-772Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync
CVE-2026-532615.55.5LinuxLinuxCWE-401devlink: Release nested relation on devlink free
CVE-2026-532635.55.6LinuxLinuxCWE-1936lowpan: fix off-by-one in multicast context address compression
CVE-2026-532695.55.6LinuxLinux—netfilter: synproxy: add mutex to guard hook reference counting
CVE-2026-532715.55.5LinuxLinuxCWE-476ksmbd: fix NULL-deref of opinfo->conn in oplock/lease break notifiers
CVE-2026-574516.15.5vimvimCWE-125Vim: Out-of-bounds Read in Text Property Count
CVE-2026-531415.55.4LinuxLinux—drm/v3d: Fix global performance monitor reference counting
CVE-2026-531645.55.4LinuxLinux—iommu/dma: Do not try to iommu_map a 0 length region in swiotlb
CVE-2026-532115.55.4LinuxLinuxCWE-401netfilter: nft_meta_bridge: fix stale stack leak via IIFHWADDR register
CVE-2026-532585.55.4LinuxLinuxCWE-401wifi: fix leak if split 6 GHz scanning fails

Results continue: ranks 401–468.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-25 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.