AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C N H N 8.6 .8820 99.8 YES
AFFECTED Product Versions Fixed Cisco Unified Communications Manager 14 – —
TIMELINE Oct 8 Reserved by CNA Jun 25 Added to CISA KEV, due Jun 28 Jun 25 Published (CNA: cisco)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
468 CVEs published, led by Linux (146).
468 CVEs published June 25, 2026: 42 critical, 219 high, 172 medium, 35 low; 2 in the KEV catalog at press time; 48 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 68 on continuation pages.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 6639 | 11100 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
492 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 465 | 1432 | 118 | 845 | 468 | 1 | 11 | 2 | 0.1 | 7.8 | .0014 | +238 ▲ |
| 707 | 882 | 85 | 468 | 300 | 29 | 77 | 6 | 0.7 | 8.1 | .0023 | +691 ▲ | |
| microsoft | 220 | 756 | 58 | 520 | 172 | 6 | 286 | 19 | 2.5 | 7.8 | .0045 | +60 ▲ |
| red hat | 106 | 200 | 9 | 82 | 97 | 12 | 2 | 0 | 0.0 | 6.5 | .0029 | +96 ▲ |
| apple | 15 | 67 | 1 | 21 | 43 | 2 | 88 | 7 | 10.4 | 5.5 | .0020 | 0 |
| canonical | 2 | 16 | 1 | 4 | 6 | 5 | 0 | 0 | 0.0 | 5.5 | .0010 | +2 ▲ |
| freebsd | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0020 | -7 ▼ |
| suse | 4 | 6 | 1 | 4 | 1 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | +2 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 10 | 22 | 6 | 6 | 10 | 0 | 56 | 11 | 50.0 | 7.3 | .0566 | +5 ▲ |
| netgear | 17 | 17 | 0 | 0 | 16 | 1 | 0 | 0 | 0.0 | 4.3 | .0024 | +17 ▲ |
| palo alto networks | 9 | 11 | 1 | 2 | 7 | 1 | 13 | 2 | 18.2 | 5.9 | .0022 | +7 ▲ |
| ubiquiti | 8 | 11 | 7 | 4 | 0 | 0 | 3 | 3 | 27.3 | 9.9 | .0083 | +6 ▲ |
| ivanti | 4 | 9 | 4 | 5 | 0 | 0 | 25 | 5 | 55.6 | 8.8 | .5187 | +2 ▲ |
| checkpoint | 3 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | +3 ▲ |
| fortinet | 2 | 9 | 4 | 3 | 2 | 0 | 28 | 3 | 33.3 | 8.3 | .0076 | +1 ▲ |
| f5 | 6 | 8 | 4 | 3 | 1 | 0 | 4 | 1 | 12.5 | 8.9 | .0225 | +4 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 99 | 133 | 20 | 45 | 57 | 10 | 33 | 1 | 0.8 | 6.5 | .0050 | +81 ▲ |
| mozilla | 49 | 55 | 11 | 18 | 26 | 0 | 9 | 0 | 0.0 | 7.3 | .0026 | +43 ▲ |
| gitlab | 24 | 31 | 0 | 5 | 21 | 5 | 4 | 2 | 6.5 | 4.4 | .0029 | +24 ▲ |
| docker | 4 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.2 | .0016 | +1 ▲ |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 4 | 1 | 20.0 | 5.1 | .0026 | -3 ▼ |
| github | 0 | 2 | 1 | 1 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0347 | 0 |
| wordpress | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 242 | 270 | 132 | 116 | 18 | 4 | 27 | 2 | 0.7 | 8.8 | .0040 | +242 ▲ |
| adobe | 132 | 134 | 4 | 51 | 77 | 2 | 19 | 2 | 1.5 | 5.5 | .0021 | +132 ▲ |
| ibm | 32 | 81 | 19 | 35 | 27 | 0 | 6 | 0 | 0.0 | 7.5 | .0031 | +32 ▲ |
| progress | 5 | 9 | 1 | 7 | 1 | 0 | 6 | 0 | 0.0 | 7.5 | .0036 | +1 ▲ |
| solarwinds | 3 | 6 | 2 | 3 | 1 | 0 | 10 | 4 | 66.7 | 7.8 | .6082 | +3 ▲ |
| veeam | 1 | 4 | 2 | 2 | 0 | 0 | 1 | 0 | 0.0 | 9.0 | .0052 | +1 ▲ |
| zohocorp | 1 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 5 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +5 ▲ |
| d-link | 9 | 11 | 0 | 4 | 2 | 5 | 3 | 0 | 0.0 | 5.5 | .0058 | +8 ▲ |
| siemens | 7 | 8 | 0 | 4 | 4 | 0 | 0 | 0 | 0.0 | 7.5 | .0020 | +6 ▲ |
| rockwell automation | 7 | 7 | 1 | 5 | 1 | 0 | 0 | 0 | 0.0 | 8.7 | .0030 | +7 ▲ |
| abb | 6 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | +6 ▲ |
| schneider electric | 6 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0042 | +6 ▲ |
| moxa | 5 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | +5 ▲ |
| dahua | 3 | 3 | 0 | 1 | 1 | 1 | 0 | 0 | 0.0 | 6.9 | .0036 | +3 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| spring | 72 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | +71 ▲ |
| openclaw | 61 | 67 | 0 | 35 | 22 | 10 | 0 | 0 | 0.0 | 7.0 | .0021 | +61 ▲ |
| sourcecodester | 37 | 59 | 0 | 0 | 25 | 34 | 0 | 0 | 0.0 | 2.1 | .0026 | +21 ▲ |
| themerex | 58 | 58 | 5 | 53 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0043 | +58 ▲ |
| edimax | 5 | 56 | 0 | 33 | 0 | 23 | 1 | 0 | 0.0 | 7.4 | .0070 | -39 ▼ |
| dell | 37 | 55 | 2 | 29 | 24 | 0 | 2 | 1 | 1.8 | 7.2 | .0017 | +25 ▲ |
| jenkins project | 36 | 49 | 0 | 9 | 39 | 1 | 3 | 0 | 0.0 | 4.8 | .0025 | +36 ▲ |
| capgo | 46 | 46 | 2 | 22 | 21 | 1 | 0 | 0 | 0.0 | 7.0 | .0039 | +46 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-10520 | .9991 | 100.0 | 10.0 |
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-35273 | .9547 | 99.9 | 9.8 |
| CVE-2026-20230 | .8820 | 99.8 | 8.6 |
| CVE-2026-34910 | .8747 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-50751 | .8377 | 99.7 | 9.3 |
| CVE-2026-48907 | .7810 | 99.5 | 10.0 |
| CVE-2026-34909 | .6390 | 99.2 | 10.0 |
| CVE-2026-49160 | .5383 | 98.9 | 7.5 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-10520 | 10.0 | .9991 | KEV |
| CVE-2026-34910 | 10.0 | .8747 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-48907 | 10.0 | .7810 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-45087 | 10.0 | .1296 | |
| CVE-2026-53753 | 10.0 | .0290 | |
| CVE-2026-49777 | 10.0 | .0166 | |
| CVE-2026-8054 | 10.0 | .0158 | |
| CVE-2026-49199 | 10.0 | .0134 |
| Vendor | CVEs |
|---|---|
| linux | 876 |
| 859 | |
| oracle | 267 |
| microsoft | 226 |
| adobe | 132 |
| red hat | 131 |
| apache | 101 |
| spring | 72 |
| openclaw | 67 |
| ibm | 61 |
| Vendor | KEV |
|---|---|
| microsoft | 19 |
| cisco | 11 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| berriai | 3 |
| fortinet | 3 |
| smartertools | 3 |
| ubiquiti | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 39 |
| Packagist | 22 |
| PyPI | 10 |
| npm | 4 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2025-48595 | 0 | |
| CVE-2026-10520 | ivanti | 0 |
| CVE-2026-11645 | 0 | |
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-20245 | Cisco | 0 |
| CVE-2026-20253 | Splunk | 0 |
| CVE-2026-20262 | Cisco | 0 |
| CVE-2026-28318 | SolarWinds | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1681 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1681 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1681 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1681 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1681 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1681 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1681 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1681 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1681 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1681 |
EXPLOIT PUBLISHED — pnpm: 13 CVEs (CVE-2026-48995, CVE-2026-50014, CVE-2026-50015, CVE-2026-50016, CVE-2026-50017, CVE-2026-50021, CVE-2026-50573, CVE-2026-55180, CVE-2026-55487, CVE-2026-55697, CVE-2026-55698, CVE-2026-55699, CVE-2026-55700). Public exploit references added.
EXPLOIT PUBLISHED — danny-avila LibreChat: 9 CVEs (CVE-2026-54024, CVE-2026-54025, CVE-2026-54027, CVE-2026-54029, CVE-2026-54030, CVE-2026-54033, CVE-2026-54036, CVE-2026-54037, CVE-2026-54040). Public exploit references added.
EXPLOIT PUBLISHED — Flowise: 8 CVEs (CVE-2025-71324, CVE-2025-71327, CVE-2025-71328, CVE-2025-71333, CVE-2025-71334, CVE-2025-71335, CVE-2025-71336, CVE-2025-71338). Public exploit references added.
EXPLOIT PUBLISHED — cacti: 4 CVEs (CVE-2026-40080, CVE-2026-40082, CVE-2026-40083, CVE-2026-40084). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2025-60464. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-60465. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-13351 (zephyrproject-rtos Zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47770 (jqlang jq). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-49839 (jqlang jq). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54917 (seaweedfs). Public exploit reference added.
How to read these box scores · glossary
468 CVEs published. 25 box scores and 375 table rows below; the remaining 68 continue on page 2 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C N H N 8.6 .8820 99.8 YES
AFFECTED Product Versions Fixed Cisco Unified Communications Manager 14 – —
TIMELINE Oct 8 Reserved by CNA Jun 25 Added to CISA KEV, due Jun 28 Jun 25 Published (CNA: cisco)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .4059 98.5 YES
AFFECTED Product Versions Fixed Windchill PDMLink unspecified — FlexPLM unspecified —
TIMELINE Jun 18 Reserved by CNA Jun 25 Added to CISA KEV, due Jun 28 Jun 25 Published (CNA: PTC)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0436 90.5 —
AFFECTED Product Versions Fixed Flowise unspecified 3.0.6
TIMELINE Jun 20 Reserved by CNA Jun 25 Public exploit reference published Jun 25 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N A H H H 8.6 .0244 83.0 —
AFFECTED Product Versions Fixed thc-hydra unspecified 9cc84c20e75f5fef6bb1790bb9ada2afad2204e2
TIMELINE Jun 22 Reserved by CNA Jun 25 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0173 75.8 —
AFFECTED Product Versions Fixed PowerLogic™ P7 Version V02.003.001.000 and prior – —
TIMELINE May 27 Reserved by CNA Jun 25 Published (CNA: schneider)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0160 73.8 —
AFFECTED Product Versions Fixed InsightConnect Sed Plugin unspecified 2.0.5
TIMELINE May 21 Reserved by CNA Jun 25 Published (CNA: rapid7)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0157 73.5 —
AFFECTED Product Versions Fixed Flowise unspecified 3.0.6
TIMELINE Jun 8 Reserved by CNA Jun 25 Public exploit reference published Jun 25 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H N L 9.3 .0134 69.2 —
AFFECTED Product Versions Fixed YMC Filter n/a – 3.11.6
TIMELINE Jun 16 Reserved by CNA Jun 25 Published (CNA: Patchstack)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0129 68.0 —
AFFECTED Product Versions Fixed InsightConnect Tcpdump Plugin unspecified 2.0.0
TIMELINE May 15 Reserved by CNA Jun 25 Published (CNA: rapid7)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0129 68.0 —
AFFECTED Product Versions Fixed InsightConnect SQLmap Plugin unspecified 2.0.1
TIMELINE May 15 Reserved by CNA Jun 25 Published (CNA: rapid7)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0129 68.0 —
AFFECTED Product Versions Fixed InsightConnect Finger Plugin unspecified 1.0.3
TIMELINE May 15 Reserved by CNA Jun 25 Published (CNA: rapid7)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0120 65.7 —
AFFECTED Product Versions Fixed InsightConnect AWK Plugin unspecified 1.2.2
TIMELINE May 14 Reserved by CNA Jun 25 Published (CNA: rapid7)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0120 65.7 —
AFFECTED Product Versions Fixed InsightConnect Ping Plugin unspecified 1.0.4
TIMELINE May 15 Reserved by CNA Jun 25 Published (CNA: rapid7)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0120 65.7 —
AFFECTED Product Versions Fixed InsightConnect TR Plugin unspecified 2.0.3
TIMELINE May 15 Reserved by CNA Jun 25 Published (CNA: rapid7)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0120 65.7 —
AFFECTED Product Versions Fixed InsightConnect Traceroute Plugin unspecified 1.0.3
TIMELINE May 15 Reserved by CNA Jun 25 Published (CNA: rapid7)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0115 64.4 —
AFFECTED Product Versions Fixed Flowise unspecified 3.0.6
TIMELINE Jun 20 Reserved by CNA Jun 25 Public exploit reference published Jun 25 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0101 60.5 —
AFFECTED Product Versions Fixed cursor < 3.0 – —
TIMELINE Jun 4 Reserved by CNA Jun 25 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0101 60.5 —
AFFECTED Product Versions Fixed cursor < 3.0 – —
TIMELINE Jun 4 Reserved by CNA Jun 25 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0094 58.3 —
AFFECTED Product Versions Fixed Flowise unspecified —
TIMELINE Jun 20 Reserved by CNA Jun 25 Public exploit reference published Jun 25 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0090 57.0 —
AFFECTED Product Versions Fixed Flowise unspecified —
TIMELINE Jun 20 Reserved by CNA Jun 25 Public exploit reference published Jun 25 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N L L 6.9 .0090 57.0 —
AFFECTED Product Versions Fixed FOSSBilling >= 0.5.4, < 0.8.0 – —
TIMELINE May 4 Reserved by CNA Jun 25 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N N H H 7.2 .0090 57.0 —
AFFECTED Product Versions Fixed htmly unspecified —
TIMELINE May 11 Reserved by CNA Jun 25 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0087 56.1 —
AFFECTED Product Versions Fixed Wyse Management Suite unspecified —
TIMELINE May 31 Reserved by CNA Jun 25 Published (CNA: dell)
AV AC PR UI S C I A CVSS EPSS %ile KEV L L L N U H H H 7.8 .0082 54.5 —
AFFECTED Product Versions Fixed Display and Peripheral Manager unspecified —
TIMELINE May 17 Reserved by CNA Jun 25 Published (CNA: dell)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0079 53.5 —
AFFECTED Product Versions Fixed Widget Options n/a – 4.2.4
TIMELINE Jun 16 Reserved by CNA Jun 25 Published (CNA: Patchstack)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-9086 | 7.3 | 53.2 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-79 | Keycloak: keycloak: cross-site scripting (xss) via case-insensitive uri valid… |
| CVE-2026-9083 | 4.9 | 53.2 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-22 | Keycloak: keycloak: information disclosure through arbitrary filesystem path … |
| CVE-2026-54088 | 9.3 | 52.6 | filebrowser | filebrowser | CWE-78 | File Browser: Command Injection via Authentication Hook Shell Substitution (P… |
| CVE-2026-53176 | 9.8 | 51.6 | Linux | Linux | CWE-191 | IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN |
| CVE-2026-53199 | 7.5 | 51.0 | Linux | Linux | — | hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf |
| CVE-2026-56768 | 8.7 | 50.8 | haiwen | seahub | CWE-862 | Seahub < 13.0.23 - Authentication Bypass in ShareLinkZipTaskView GET Method |
| CVE-2026-56786 | 9.3 | 50.8 | tomojitakasu | RTKLIB | CWE-787 | RTKLIB 2.4.3 - Out-of-bounds Write in decode_type1033 via Crafted RTCM3 Message |
| CVE-2026-50176 | 8.7 | 50.8 | EVoke | EVoke CSMS | CWE-307 | EVoke Systems EVoke CSMS Improper Restriction of Excessive Authentication Att… |
| CVE-2026-53183 | 7.5 | 49.8 | Linux | Linux | — | mptcp: allow subflow rcv wnd to shrink |
| CVE-2026-53184 | 7.5 | 49.8 | Linux | Linux | — | udp: clear skb->dev before running a sockmap verdict |
| CVE-2025-71327 | 9.3 | 49.4 | Flowise | Flowise | CWE-306 | Flowise - Authentication Bypass via Unprotected Registration Endpoint |
| CVE-2026-56091 | 8.2 | 49.2 | Apache Software Foundation | Apache Shiro | CWE-289 | Apache Shiro: Authentication bypass in Guice-Web integration |
| CVE-2026-40702 | 9.3 | 48.2 | EVoke | EVoke CSMS | CWE-306 | EVoke Systems EVoke CSMS Missing Authentication for Critical Function |
| CVE-2026-56445 | 8.8 | 47.9 | pydicom | pynetdicom Library | CWE-22 | pydicom pynetdicom Library Path Traversal |
| CVE-2026-57520 | 7.1 | 47.8 | bitwarden | server | CWE-862 | Bitwarden Server < 2026.5.0 Privilege Escalation via Bulk User Remove Endpoint |
| CVE-2026-9800 | 8.1 | 47.6 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-1025 | Keycloak-policy-enforcer: keycloak policy enforcer: authorization bypass via … |
| CVE-2026-53198 | 8.8 | 47.5 | Linux | Linux | CWE-416 | ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL |
| CVE-2026-38637 | 7.5 | 47.4 | n/a | n/a | CWE-400 | An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f… |
| CVE-2026-38640 | 7.5 | 47.4 | n/a | n/a | CWE-400 | A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc c… |
| CVE-2026-53229 | 7.5 | 47.4 | Linux | Linux | CWE-401 | net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure |
| CVE-2026-53235 | 7.5 | 47.4 | Linux | Linux | — | net: add pskb_may_pull() to skb_gro_receive_list() |
| CVE-2026-12053 | 7.5 | 47.3 | GitLab | GitLab | CWE-532 | Insertion of Sensitive Information into Log File in GitLab |
| CVE-2026-55477 | 7.2 | 46.8 | MHSanaei | 3x-ui | CWE-73 | Authenticated Arbitrary File Write via Database Import and Xray Log Path Mani… |
| CVE-2026-54089 | 9.1 | 46.6 | filebrowser | filebrowser | CWE-287 | File Browser: Authentication Bypass via Proxy Auth Header Forgery |
| CVE-2026-46601 | 7.5 | 46.5 | golang.org/x/image | golang.org/x/image/webp | — | Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image |
| CVE-2026-46602 | 7.5 | 46.5 | golang.org/x/image | golang.org/x/image/tiff | — | Lack of limit on tile sizes in x/image/tiff in golang.org/x/image |
| CVE-2026-56767 | 8.7 | 45.9 | getmaxun | maxun | CWE-862 | Maxun < 0.0.42 - Cross-Tenant IDOR in Storage and Webhook API Handlers |
| CVE-2026-56770 | 8.7 | 45.2 | schwehr | libais | CWE-129 | libais 0.15 - Out-of-bounds Vector Access in VdmStream::AddLine via Invalid S… |
| CVE-2026-56049 | 8.5 | 45.2 | Post Snippets | Post Snippets | CWE-94 | WordPress Post Snippets plugin <= 4.0.19 - Remote Code Execution (RCE) vulner… |
| CVE-2026-53240 | 8.8 | 44.3 | Linux | Linux | CWE-416 | xfrm: iptfs: fix use-after-free on first_skb in __input_process_payload |
| CVE-2026-56787 | 6.9 | 44.3 | tomojitakasu | RTKLIB | CWE-193 | RTKLIB 2.4.3 - Off-by-One Out-of-Bounds Read in decode_ssr3 via RTCM3 SSR Mes… |
| CVE-2026-56122 | 8.7 | 43.7 | rickknowles | Winstone Servlet Container | CWE-22 | Winstone Servlet Engine 0.9.10 Path Traversal via HTTP Request Paths |
| CVE-2026-56123 | 9.2 | 43.4 | socat | socat | CWE-122 | socat 1.8.0.0 - 1.8.1.1 Heap Buffer Overflow via SOCKS5 Reply Parser |
| CVE-2026-54092 | 6.5 | 43.4 | filebrowser | filebrowser | CWE-400 | File Browser: DoS Vulnerability on Public Login API |
| CVE-2026-37453 | 7.5 | 43.0 | n/a | n/a | CWE-200 | Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.120… |
| CVE-2026-37452 | 7.5 | 42.7 | n/a | n/a | CWE-200 | Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.120… |
| CVE-2026-53248 | 8.8 | 42.3 | Linux | Linux | CWE-416 | net: airoha: Fix use-after-free in metadata dst teardown |
| CVE-2026-50016 | 8.8 | 42.3 | pnpm | pnpm | CWE-23 | pnpm: Transitive dependency alias path traversal allows project path override… |
| CVE-2026-53217 | 8.6 | 42.1 | Linux | Linux | — | net: mvpp2: sync RX data at the hardware packet offset |
| CVE-2026-57700 | 10.0 | 41.9 | Daan.dev | OMGF Pro | CWE-434 | WordPress OMGF Pro plugin <= 5.2.6 - Arbitrary File Upload vulnerability |
| CVE-2026-56053 | 8.8 | 41.7 | EventPrime | EventPrime | CWE-502 | WordPress EventPrime plugin <= 4.3.4.1 - PHP Object Injection vulnerability |
| CVE-2026-53224 | 9.1 | 41.6 | Linux | Linux | CWE-125 | sctp: validate embedded INIT chunk and address list lengths in cookie |
| CVE-2026-54091 | 7.5 | 41.5 | filebrowser | filebrowser | CWE-863 | File Browser: Incorrect access control in public directory shares via rule pa… |
| CVE-2026-6094 | 6.3 | 41.5 | wolfSSL | wolfSSL | CWE-125 | Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 En… |
| CVE-2026-53221 | 9.8 | 41.4 | Linux | Linux | — | ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() |
| CVE-2026-53228 | 9.8 | 41.4 | Linux | Linux | — | ipv6: sit: reload inner IPv6 header after GSO offloads |
| CVE-2026-53186 | 9.1 | 41.4 | Linux | Linux | — | RDMA/srp: bound SRP_RSP sense copy by the received length |
| CVE-2026-53225 | 9.1 | 41.4 | Linux | Linux | CWE-908 | sctp: fix uninit-value in __sctp_rcv_asconf_lookup() |
| CVE-2026-54037 | 6.5 | 41.3 | danny-avila | LibreChat | CWE-770 | LibreChat: Incomplete Fix for CVE-2025-7105 — /api/convos/duplicate Lacks Rat… |
| CVE-2026-5305 | 8.8 | 40.8 | Unknown | Email Address Encoder | — | Email Address Encoder (Free < 1.0.25, Premium < 0.3.12) - Unauthenticated Sto… |
| CVE-2026-6679 | 8.8 | 40.8 | wolfSSL | wolfSSL | CWE-787 | DTLS 1.3 ACK serialization heap buffer overflow via integer truncation |
| CVE-2026-12937 | 7.5 | 40.8 | themefic | Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin | CWE-89 | Tourfic <= 2.22.7 - Unauthenticated SQL Injection via 'post_id' Parameter |
| CVE-2026-55439 | 5.5 | 40.8 | halo-dev | halo | CWE-22 | Halo: Path Traversal in Backup Download Leads to Arbitrary File Read |
| CVE-2026-54094 | 7.5 | 40.7 | filebrowser | filebrowser | CWE-22 | File Browser: Symlink following lets scoped users read, overwrite, and share … |
| CVE-2026-53215 | 9.8 | 40.7 | Linux | Linux | — | net: mvpp2: refill RX buffers before XDP or skb use |
| CVE-2026-53216 | 9.8 | 40.7 | Linux | Linux | — | net: mvpp2: limit XDP frame size to the RX buffer |
| CVE-2026-40083 | 7.2 | 40.6 | Cacti | cacti | CWE-89 | Cacti: SQL Injection in managers.php |
| CVE-2026-54573 | 5.3 | 40.4 | outline | outline | CWE-863 | Authorization Bypass in API Key/OAuth Scopes via Path Parsing Discrepancy |
| CVE-2026-7531 | 2.3 | 40.4 | wolfSSL | wolfSSL | CWE-416 | Use-after-free in PQC hybrid key-share handling |
| CVE-2026-55667 | 8.2 | 40.2 | filebrowser | filebrowser | CWE-22 | File Browser: Out-of-scope file deletion by a Create-only scoped user via sym… |
| CVE-2026-22879 | 8.1 | 39.9 | vtk | vtk | CWE-129 | vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnera… |
| CVE-2026-9099 | 7.7 | 39.9 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-639 | Keycloak: group-admin escalation to realm-admin |
| CVE-2026-53165 | 7.5 | 39.8 | Linux | Linux | CWE-476 | iomap: avoid potential null folio->mapping deref during error reporting |
| CVE-2026-53244 | 7.5 | 39.8 | Linux | Linux | — | VFS: fix possible failure to unlock in nfsd4_create_file() |
| CVE-2026-13351 | 7.5 | 39.6 | zephyrproject-rtos | Zephyr | CWE-772 | net: Maliciously fragmented IPv6 packets can prevent receiving/processing fut… |
| CVE-2026-53180 | 7.5 | 39.6 | Linux | Linux | CWE-667 | timers/migration: Fix livelock in tmigr_handle_remote_up() |
| CVE-2026-40084 | 6.5 | 39.6 | Cacti | cacti | CWE-22 | Cacti: Arbitrary File Read via Path Traversal in Report `format_file` Parameter |
| CVE-2026-46752 | 10.0 | 39.3 | Apache Software Foundation | Apache Kvrocks | CWE-122 | Apache Kvrocks: Stack buffer overflow in Lua bit.tohex() |
| CVE-2026-56774 | 5.3 | 39.0 | kanboard | kanboard | CWE-639 | Kanboard - Cross-User Deletion of Persistent Login Sessions via Unvalidated S… |
| CVE-2025-71328 | 8.7 | 38.8 | Flowise | Flowise | CWE-620 | Flowise - Unverified Password Change via Account Settings |
| CVE-2026-2238 | 5.3 | 38.7 | GitLab | GitLab | CWE-862 | Missing Authorization in GitLab |
| CVE-2026-56054 | 7.7 | 38.5 | Ahmad | JS Help Desk | CWE-22 | WordPress JS Help Desk plugin <= 3.1.1 - Arbitrary File Deletion vulnerability |
| CVE-2026-53247 | 9.8 | 38.3 | Linux | Linux | CWE-416 | net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown |
| CVE-2026-54845 | 8.1 | 38.4 | PluginUs.Net | MDTF | CWE-98 | WordPress MDTF plugin <= 1.3.8 - Local File Inclusion vulnerability |
| CVE-2026-9705 | 6.5 | 38.2 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-613 | Keycloak: keycloak: attacker can re-enable and take over disabled clients via… |
| CVE-2026-12077 | 7.5 | 38.1 | wedevs | Dokan Pro | CWE-89 | Dokan Pro <= 5.0.4 - Unauthenticated SQL Injection via 'latitude' and 'longit… |
| CVE-2026-9716 | 8.7 | 37.9 | Schneider Electric | PowerLogic™ P7 | CWE-476 | CWE-476 NULL Pointer Dereference vulnerability exists that could cause a deni… |
| CVE-2026-57434 | 1.7 | 37.9 | sparklemotion | nokogiri | CWE-476 | Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper c… |
| CVE-2026-57435 | 1.7 | 37.9 | sparklemotion | nokogiri | CWE-416 | Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogi… |
| CVE-2026-53151 | 9.8 | 37.7 | Linux | Linux | — | rxrpc: Fix the ACK parser to extract the SACK table for parsing |
| CVE-2026-57522 | 2.3 | 37.5 | bitwarden | server | CWE-74 | Bitwarden Server < 2026.5.0 JSON Injection via Webhook Templates |
| CVE-2026-9153 | 6.5 | 37.4 | Rapid7 | InsightConnect Sed Plugin | CWE-22 | Arbitrary File Read in Rapid7 InsightConnect Sed Plugin |
| CVE-2026-10512 | 2.3 | 37.3 | wolfSSL | wolfSSL | CWE-682 | X25519 x86_64 assembly final reduction leaves non-canonical field element |
| CVE-2026-54097 | 7.2 | 37.2 | filebrowser | filebrowser | CWE-639 | File Browser: Cross-user unauthorized share-link deletion via unbounded prefi… |
| CVE-2026-55699 | 6.5 | 37.2 | pnpm | pnpm | CWE-22 | pnpm: reserved bin name deletes PNPM_HOME during global remove |
| CVE-2026-57587 | 2.9 | 37.1 | tenable | Nessus | CWE-89 | SQL Injection in Nessus via Reverse DNS Lookup |
| CVE-2026-54024 | 6.5 | 36.8 | danny-avila | LibreChat | CWE-770 | LibreChat: Incomplete Fix for CVE-2024-11171 — Conversation Import Multer Ins… |
| CVE-2026-13225 | 5.3 | 36.7 | pretix | pretix | CWE-80 | Stored XSS in ticket confirmation page |
| CVE-2026-55958 | 8.3 | 36.7 | wolfSSL | wolfSSL | CWE-787 | Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage |
| CVE-2026-54448 | 6.9 | 36.7 | aquasecurity | trivy | CWE-770 | Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser |
| CVE-2026-48944 | 6.5 | 36.7 | getk2.org | K2 extension for Joomla | CWE-22 | Joomla Extension - getk2.org - Exposure of sensitive files via attachment cop… |
| CVE-2026-53246 | 9.8 | 36.6 | Linux | Linux | CWE-787 | sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing |
| CVE-2026-55092 | 7.0 | 36.6 | aquasecurity | trivy | CWE-22 | Trivy: Path traversal via a crafted vulnerability database or other downloade… |
| CVE-2026-54090 | 8.7 | 36.2 | filebrowser | filebrowser | CWE-77 | File Browser: Command Allowlist Bypass via Shell Metacharacter Injection |
| CVE-2026-50017 | 6.9 | 36.2 | pnpm | pnpm | CWE-200 | pnpm binds unscoped user-level npm auth credentials to a repository-selected … |
| CVE-2026-4526 | 7.1 | 36.1 | Silicon Labs | EmberZNet | CWE-125 | Global ZCL command parser missing minimum-length validation in EmberZNet v9.0.2 |
| CVE-2026-47145 | 7.1 | 36.1 | Silicon Labs | EmberZNet | CWE-617 | Color Control hue/saturation assertion abort in EmberZNet v9.0.2 |
| CVE-2026-47146 | 7.1 | 36.1 | Silicon Labs | EmberZNet | CWE-617 | Color Control color-temperature assertion abort in EmberZNet v9.0.2 |
| CVE-2026-47148 | 7.1 | 36.1 | Silicon Labs | EmberZNet | CWE-125 | Groups GetGroupMembership count/list-length mismatch in EmberZNet v9.0.2 |
| CVE-2026-47149 | 7.1 | 36.1 | Silicon Labs | EmberZNet | CWE-125 | Door Lock GetUserType invalid table index in EmberZNet v9.0.2 |
| CVE-2026-47152 | 7.1 | 36.1 | Silicon Labs | EmberZNet | CWE-369 | Level Control Move divide-by-zero in EmberZNet v9.0.2 |
| CVE-2026-47153 | 7.1 | 36.1 | Silicon Labs | EmberZNet | CWE-369 | Level Control Step With On/Off divide-by-zero in EmberZNet v9.0.2 |
| CVE-2026-47154 | 7.1 | 36.1 | Silicon Labs | EmberZNet | CWE-125 | Simple Metering GetProfileResponse interval-bounds bug in EmberZNet v9.0.2 |
| CVE-2025-71340 | 7.6 | 35.7 | picklescan | picklescan | CWE-502 | picklescan - Remote Code Execution via idlelib.pyshell.ModifiedInterpreter.ru… |
| CVE-2026-57521 | 5.3 | 35.6 | bitwarden | server | CWE-862 | Bitwarden Server < 2026.5.0 Broken Access Control via PreviewInvoiceController |
| CVE-2026-50015 | 7.3 | 35.4 | pnpm | pnpm | CWE-22 | pnpm: Arbitrary File Write/Delete via Malicious Patch File (Path Traversal) |
| CVE-2026-9718 | 6.9 | 35.3 | Schneider Electric | PowerLogic™ P7 | CWE-617 | CWE-617 Reachable Assertion vulnerability exists that could allow an authenti… |
| CVE-2026-12993 | 6.5 | 35.3 | Red Hat | Red Hat build of Apicurio Registry 3 | CWE-776 | Apicurio/apicurio-registry: apicurio-registry: xml entity-expansion denial of… |
| CVE-2026-57235 | 6.3 | 35.3 | sparklemotion | nokogiri | CWE-125 | Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]` |
| CVE-2026-53131 | 9.4 | 35.2 | Linux | Linux | — | netfilter: require Ethernet MAC header before using eth_hdr() |
| CVE-2026-57532 | 8.8 | 35.1 | pretix | pretix | CWE-80 | Malicious HTML content contained in the layout specification of a PDF ticket … |
| CVE-2026-10712 | 6.1 | 35.2 | GitLab | GitLab | CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scri… |
| CVE-2026-57534 | 2.1 | 35.1 | pretix | pretix-pages | CWE-80 | Stored XSS in pretix-pages |
| CVE-2026-13314 | 2.0 | 35.1 | pretix | pretix-digital | CWE-80 | Stored XSS in pretix-digital |
| CVE-2026-44622 | 6.9 | 35.0 | EVoke | EVoke CSMS | CWE-522 | EVoke Systems EVoke CSMS Insufficiently Protected Credentials |
| CVE-2026-56789 | 7.1 | 35.0 | tomojitakasu | RTKLIB | CWE-122 | RTKLIB 2.4.3 - Heap Buffer Overflow and Stack Read via Oversized RINEX Epoch … |
| CVE-2026-54479 | 6.9 | 34.7 | EVoke | EVoke CSMS | CWE-613 | EVoke Systems EVoke CSMS Insufficient Session Expiration |
| CVE-2026-55700 | 7.1 | 34.5 | pnpm | pnpm | CWE-22 | pnpm: stage download writes outside destination via manifest version traversal |
| CVE-2026-54841 | 7.5 | 34.3 | Appsbd | Vitepos | CWE-201 | WordPress Vitepos plugin <= 3.4.2 - Sensitive Data Exposure vulnerability |
| CVE-2026-9222 | 9.2 | 34.0 | Shenzhen i365-Tech Co. Ltd. | Setracker2 Parental Control App (Android) package com.tgelec.setracker | CWE-836 | Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of pa… |
| CVE-2026-12975 | 8.5 | 33.9 | Red Hat | Red Hat build of Apicurio Registry 3 | CWE-611 | Apicurio/apicurio-registry: apicurio-registry: unhardened saxparser in conten… |
| CVE-2026-9154 | 6.5 | 33.8 | Rapid7 | InsightConnect Sed Plugin | CWE-22 | Arbitrary File Write in Rapid7 InsightConnect Sed Plugin |
| CVE-2026-9650 | 8.7 | 33.5 | Schneider Electric | EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller | CWE-522 | CWE-522 Insufficiently Protected Credentials vulnerability that could cause u… |
| CVE-2026-47147 | 7.1 | 33.3 | Silicon Labs | EmberZNet | CWE-125 | OTA server raw parser missing per-field bounds validation in EmberZNet v9.0.2 |
| CVE-2026-57436 | 1.7 | 33.1 | sparklemotion | nokogiri | CWE-416 | Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid… |
| CVE-2026-57437 | 1.7 | 33.1 | sparklemotion | nokogiri | CWE-416 | Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathCo… |
| CVE-2026-46608 | 7.4 | 32.9 | nicolargo | glances | CWE-183 | Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildc… |
| CVE-2026-54843 | 9.3 | 32.9 | PluginUs.Net | MDTF | CWE-89 | WordPress MDTF plugin <= 1.3.7 - SQL Injection vulnerability |
| CVE-2026-54849 | 9.3 | 32.9 | Premmerce | Premmerce Wishlist for WooCommerce | CWE-89 | WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.11 - SQL Injection… |
| CVE-2026-2508 | 6.5 | 32.8 | GravityMore | Gravity Bookings | CWE-89 | Gravity Forms Booking <= 2.7.1 - Authenticated (Subscriber+) Time-Based SQL I… |
| CVE-2026-53232 | 8.8 | 32.7 | Linux | Linux | — | net: phy: clean the sfp upstream if phy probing fails |
| CVE-2026-12844 | 7.5 | 32.6 | DROLSKY | List::SomeUtils::XS | CWE-122 | List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow… |
| CVE-2026-54226 | 6.4 | 32.5 | Apache Software Foundation | Apache Kvrocks | CWE-190 | Apache Kvrocks: RESTORE IntSet Integer Overflow Leads to Remote DoS |
| CVE-2026-6432 | 5.3 | 32.5 | Silicon Labs | SiSDK | CWE-130 | Improper bounds validation in EmberZNet SDK |
| CVE-2026-55413 | 9.4 | 32.5 | ToolJet | ToolJet | CWE-94 | ToolJet - Marketplace Plugin Poisoning Enables Instance-Wide Remote Code Exec… |
| CVE-2026-53253 | 7.1 | 32.4 | Linux | Linux | CWE-125 | Bluetooth: bnep: reject short frames before parsing |
| CVE-2026-57535 | 2.1 | 32.5 | pretix | pretix | CWE-80 | Content injected to PDF rendering contexts could, in many places, include HTM… |
| CVE-2026-9220 | 8.7 | 32.2 | Shenzhen i365-Tech Co. Ltd. | Setracker2 Parental Control App (Android) package com.tgelec.setracker | CWE-321 | Setracker2 Children's Smartwatch Ecosystem Use of hard-coded cryptographic key |
| CVE-2026-5796 | 4.3 | 31.7 | GitLab | GitLab | CWE-863 | Incorrect Authorization in GitLab |
| CVE-2026-12473 | 8.3 | 31.6 | Open Health Imaging Foundation (OHIF) | DICOM Web Viewer Framework | CWE-918 | OHIF Viewers DICOM Server-Side request forgery |
| CVE-2026-41120 | 9.8 | 31.4 | Dell | Wyse Management Suite | CWE-349 | Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Accepta… |
| CVE-2026-42387 | 5.9 | 31.3 | PowerDNS | Recursor | CWE-20 | Insufficient input validation in ZoneToCache |
| CVE-2026-42388 | 5.9 | 31.3 | PowerDNS | Recursor | CWE-20 | Missing input validation for catalog zones |
| CVE-2026-54917 | 7.8 | 31.2 | seaweedfs | seaweedfs | CWE-22 | SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bu… |
| CVE-2026-6092 | 2.1 | 31.1 | wolfSSL | wolfSSL | CWE-757 | Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_M… |
| CVE-2026-54036 | 8.1 | 31.1 | danny-avila | LibreChat | CWE-306 | LibreChat: 2FA Re-enrollment Allows Full Account 2FA Takeover Without OTP Ver… |
| CVE-2025-71335 | 8.6 | 30.7 | Flowise | Flowise | CWE-613 | Flowise - Session Invalidation Failure After Password Change |
| CVE-2026-47150 | 7.1 | 30.7 | Silicon Labs | EmberZNet | CWE-787 | IAS Zone enroll invalid table index and write in EmberZNet 9.0.2 |
| CVE-2026-47151 | 7.1 | 30.7 | Silicon Labs | EmberZNet | CWE-787 | Door Lock ClearWeekdaySchedule invalid table index and write in EmberZNet v9.0.2 |
| CVE-2026-12079 | 6.5 | 30.7 | wedevs | Dokan Pro | CWE-89 | Dokan Pro <= 5.0.4 - Authenticated (Subscriber+) SQL Injection via 'orderby' … |
| CVE-2026-6681 | 1.0 | 30.3 | wolfSSL | wolfSSL | CWE-120 | PKCS#7 decode ignores caller output buffer size, writing past buffer bounds |
| CVE-2026-57619 | 6.5 | 29.7 | Elementor | Elementor Website Builder | CWE-862 | WordPress Elementor Website Builder plugin <= 4.1.3 - Sensitive Data Exposure… |
| CVE-2026-53260 | 9.8 | 29.5 | Linux | Linux | CWE-416 | tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). |
| CVE-2026-56769 | 6.3 | 29.5 | hcengineering | platform | CWE-918 | Huly Platform - Server-Side Request Forgery via /import Endpoint |
| CVE-2026-55180 | 6.5 | 29.3 | pnpm | pnpm | CWE-200 | pnpm: Repository config can expand victim environment secrets into registry r… |
| CVE-2026-12755 | 2.7 | 29.2 | Devolutions | Server | CWE-1284 | Improper input validation in the PAM AD discovery endpoints in Devolutions Se… |
| CVE-2026-41566 | 9.4 | 29.1 | Apache Software Foundation | Apache Kvrocks | CWE-280 | Apache Kvrocks: Improper permission for the APPLYBATCH command |
| CVE-2026-1606 | 4.3 | 28.9 | GitLab | GitLab | CWE-94 | Improper Control of Generation of Code ('Code Injection') in GitLab |
| CVE-2026-13311 | 8.7 | 28.7 | ljharb | shell-quote | CWE-407 | shell-quote parse() is quadratic in token count, enabling denial of service |
| CVE-2026-46607 | 7.8 | 28.7 | nicolargo | glances | CWE-502 | Glances: Insecure Pickle Deserialization in Version Cache Leads to Arbitrary … |
| CVE-2026-11703 | 6.0 | 28.5 | wolfSSL | wolfSSL | CWE-287 | Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption |
| CVE-2026-9702 | 7.5 | 28.4 | Unknown | InPost PL | — | InPost PL < 1.9.1 - Unauthenticated WooCommerce Order Parcel-Locker Hijacking |
| CVE-2026-54822 | 8.5 | 28.4 | SALESmanago | SALESmanago & Leadoo | CWE-89 | WordPress SALESmanago & Leadoo plugin <= 3.11.2 - SQL Injection vulnerability |
| CVE-2026-54838 | 8.5 | 28.4 | Rymera Web Co | WC Vendors Marketplace | CWE-89 | WordPress WC Vendors Marketplace plugin <= 2.6.8 - SQL Injection vulnerability |
| CVE-2026-54033 | 6.5 | 27.8 | danny-avila | LibreChat | CWE-918 | LibreChat: SSRF via User-Provided Custom Endpoint baseURL — no private IP val… |
| CVE-2026-56771 | 6.3 | 27.7 | samuelclay | NewsBlur | CWE-918 | NewsBlur < 14.5.0 - Server-Side Request Forgery via add_url Endpoint |
| CVE-2026-54842 | 8.1 | 27.6 | Royal Plugins | Royal MCP | CWE-862 | WordPress Royal MCP plugin <= 1.4.25 - Broken Access Control vulnerability |
| CVE-2026-9219 | 8.3 | 27.5 | Shenzhen i365-Tech Co. Ltd. | Setracker2 Parental Control App (Android) package com.tgelec.setracker | CWE-340 | Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers … |
| CVE-2026-10086 | 5.4 | 27.5 | GitLab | GitLab | CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scri… |
| CVE-2026-54828 | 7.5 | 27.2 | StylemixThemes | Motors | CWE-862 | WordPress Motors plugin <= 1.4.109 - Broken Access Control vulnerability |
| CVE-2026-54830 | 7.5 | 27.2 | Etoile Web Design Incorporated | Five Star Restaurant Reservations | CWE-862 | WordPress Five Star Restaurant Reservations plugin <= 2.7.19 - Broken Access … |
| CVE-2026-54844 | 7.5 | 27.2 | CheckView | CheckView Automated Testing | CWE-862 | WordPress CheckView Automated Testing plugin <= 2.1.0 - Broken Access Control… |
| CVE-2026-53268 | 8.2 | 26.9 | Linux | Linux | CWE-125 | netfilter: conntrack_irc: fix possible out-of-bounds read |
| CVE-2026-42005 | 4.3 | 26.9 | PowerDNS | Authoritative | CWE-400 | Insufficient input validation of internal web server |
| CVE-2026-37454 | 7.5 | 26.8 | n/a | n/a | CWE-200 | Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.120… |
| CVE-2026-57236 | 1.7 | 26.6 | sparklemotion | nokogiri | CWE-416 | Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` ra… |
| CVE-2026-57429 | 6.5 | 26.5 | eLightUp | Slim SEO | CWE-862 | WordPress Slim SEO plugin <= 4.6.2 - Broken Access Control vulnerability |
| CVE-2026-52690 | 5.9 | 26.4 | PowerDNS | Recursor | CWE-290 | Spoofed answers can mark an authoritative non-EDNS capable |
| CVE-2026-13283 | 7.5 | 26.2 | Chrome | CWE-416 | Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.20… | |
| CVE-2026-5952 | 4.3 | 25.9 | GitLab | GitLab | CWE-863 | Incorrect Authorization in GitLab |
| CVE-2026-56013 | 6.5 | 25.6 | myCred | License Manager for WooCommerce | CWE-639 | WordPress License Manager for WooCommerce plugin <= 3.0.15 - Insecure Direct … |
| CVE-2026-56050 | 6.5 | 25.6 | Themeisle | PPOM for WooCommerce | CWE-284 | WordPress PPOM for WooCommerce plugin <= 33.0.18 - Broken Access Control vuln… |
| CVE-2026-10833 | 6.4 | 25.5 | wpdevteam | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns | CWE-79 | Gutenberg Essential Blocks - Page Builder for Gutenberg Blocks & Patterns <= … |
| CVE-2026-13222 | 6.3 | 25.4 | pretix | pretix-oppwa | CWE-841 | Insufficient validation of payment status in pretix-oppwa |
| CVE-2026-13223 | 6.3 | 25.4 | pretix | pretix-computop | CWE-841 | Insufficient validation of payment status in pretix-computop |
| CVE-2026-57536 | 6.3 | 25.4 | pretix | pretix-mollie | CWE-841 | Insufficient validation of payment status in pretix-mollie |
| CVE-2026-56772 | 5.3 | 25.4 | samuelclay | NewsBlur | CWE-639 | NewsBlur < 14.5.0 - Insecure Direct Object Reference in Social Interactions E… |
| CVE-2026-48945 | 5.3 | 25.3 | getk2.org | K2 extension for Joomla | CWE-434 | Joomla Extension - getk2.org - Privileged RCE vulnerability in K2 extension f… |
| CVE-2026-57588 | 1.8 | 25.3 | tenable | Nessus | CWE-89 | SQL Injection in Nessus via Malicious Scan Result File Import |
| CVE-2026-6450 | 1.0 | 25.3 | wolfSSL | wolfSSL | CWE-295 | CRL critical extension bypass in ParseCRL_Extensions |
| CVE-2026-6678 | 1.0 | 25.3 | wolfSSL | wolfSSL | CWE-191 | Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info |
| CVE-2026-46751 | 5.5 | 24.9 | Apache Software Foundation | Apache Kvrocks | — | Apache Kvrocks: Does not remove the unsafe loadstring function from its Lua s… |
| CVE-2026-0934 | 3.8 | 24.9 | GitLab | GitLab | CWE-863 | Incorrect Authorization in GitLab |
| CVE-2026-12244 | 8.7 | 24.8 | NLnet Labs | NSD | CWE-122 | Heap overflow and crash with crafted SVCB RR |
| CVE-2026-54027 | 6.5 | 24.7 | danny-avila | LibreChat | CWE-862 | LibreChat: Image Upload Route Bypasses Agent Permission Check — Incomplete Fi… |
| CVE-2026-54829 | 7.5 | 24.2 | Jacob N. Breetvelt | WP Photo Album Plus | CWE-89 | WordPress WP Photo Album Plus plugin <= 9.1.13.005 - SQL Injection vulnerability |
| CVE-2026-40082 | 5.4 | 24.2 | Cacti | cacti | CWE-384 | Cacti: Session Fixation via missing session_regenerate_id() after login |
| CVE-2026-12245 | 8.7 | 24.1 | NLnet Labs | NSD | CWE-416 | Denial of DNS over TLS service by any DoT client |
| CVE-2026-55412 | 8.3 | 24.1 | ToolJet | ToolJet | CWE-918 | ToolJet Cloud - SSRF to Azure Cloud Infrastructure Compromise |
| CVE-2026-54848 | 8.3 | 23.9 | Saad Iqbal | APIExperts Square for WooCommerce | CWE-201 | WordPress APIExperts Square for WooCommerce plugin <= 4.7.3 - Sensitive Data … |
| CVE-2026-12992 | 7.4 | 24.0 | Red Hat | Red Hat build of Apicurio Registry 3 | CWE-918 | Apicurio/apicurio-registry: apicurio-registry: ssrf via wsdl4j import derefer… |
| CVE-2026-50014 | 7.3 | 24.0 | pnpm | pnpm | CWE-88 | pnpm: Git Fetch Argument Injection via Lockfile resolution.commit |
| CVE-2026-40012 | 5.3 | 24.0 | PowerDNS | Recursor | CWE-524 | Information about ECS zero scoped answers might leak to clients that use a sp… |
| CVE-2026-53175 | 9.8 | 23.5 | Linux | Linux | CWE-416 | inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush |
| CVE-2026-27366 | 7.5 | 23.4 | MainWP | MainWP Child | CWE-862 | WordPress MainWP Child plugin <= 6.1.1 - Broken Access Control vulnerability |
| CVE-2026-53178 | 8.1 | 23.2 | Linux | Linux | CWE-191 | staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction |
| CVE-2026-28898 | 5.3 | 23.2 | Apple | swift-nio-http2 | CWE-116 | swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header val… |
| CVE-2026-56790 | 7.0 | 23.0 | canboat | canboat | CWE-193 | CANBoat - Off-by-One Global Buffer Overflow in searchForPgn() |
| CVE-2026-13083 | 6.9 | 22.4 | Red Hat | Pen Drive Powered by Red Hat Lightspeed | CWE-79 | Pen-drive: pen-drive: stored xss via unescaped cluster data in html report |
| CVE-2026-48943 | 6.5 | 22.4 | getk2.org | K2 extension for Joomla | CWE-915 | Joomla Extension - getk2.org - Authenticated user property mass-assignment in… |
| CVE-2026-11800 | 8.1 | 22.0 | Red Hat | Red Hat build of Keycloak 26.6 | CWE-347 | Org.keycloak:keycloak-services: keycloak: authentication bypass via jwt algor… |
| CVE-2026-12246 | 7.2 | 22.0 | NLnet Labs | NSD | CWE-20 | Out of bounds stack write with crafted APL RR |
| CVE-2026-11379 | 5.3 | 22.0 | GitLab | GitLab | CWE-863 | Incorrect Authorization in GitLab |
| CVE-2026-49319 | 6.9 | 21.9 | Alps Electric Co., Ltd. | Remote Keyless Entry System (RKES) R53R0 | CWE-294 | Alps Electric Co., Ltd. R53R0 Remote Keyless Entry System (RKES) Replay Attack |
| CVE-2026-42389 | 5.3 | 21.9 | PowerDNS | Recursor | CWE-20 | Reject more queries with invalid header values |
| CVE-2026-56130 | 2.0 | 21.9 | Apache Software Foundation | Apache Shiro | CWE-294 | Apache Shiro: Remember-me cookie isn't checked for expiry on the server |
| CVE-2026-12340 | 6.3 | 21.8 | wolfSSL | wolfSSL | CWE-125 | Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computa… |
| CVE-2026-55698 | 8.8 | 21.7 | pnpm | pnpm | CWE-345 | pnpm: Project env lockfile can short-circuit package-manager resolution and e… |
| CVE-2026-40211 | 5.3 | 21.6 | PowerDNS | DNSdist | CWE-770 | Denial of service via crafted DoH3 queries |
| CVE-2026-8662 | 4.3 | 21.5 | Rapid7 | InsightConnect Compression Plugin | CWE-22 | Path Traversal in Rapid7 InsightConnect Compression Plugin |
| CVE-2026-57533 | 2.1 | 21.5 | pretix | pretix | CWE-80 | Malicious HTML content could be injected into the page pretix shows when redi… |
| CVE-2026-5309 | 5.4 | 21.4 | GitLab | GitLab | CWE-639 | Authorization Bypass Through User-Controlled Key in GitLab |
| CVE-2026-56779 | 5.3 | 21.4 | 1Panel-dev | MaxKB | CWE-918 | MaxKB < 2.10.0 - Server-Side Request Forgery via downloadCallbackUrl and down… |
| CVE-2026-9799 | 4.6 | 21.3 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-639 | Keycloak: keycloak: unauthorized access to resources via uma permission ticke… |
| CVE-2026-6325 | 2.0 | 21.4 | wolfSSL | wolfSSL | CWE-787 | Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms… |
| CVE-2026-40209 | 5.3 | 21.0 | PowerDNS | DNSdist | CWE-772 | Denial of service via IXFR queries |
| CVE-2026-3176 | 3.1 | 20.9 | GitLab | GitLab | CWE-862 | Missing Authorization in GitLab |
| CVE-2026-7532 | 5.7 | 20.8 | wolfSSL | wolfSSL | CWE-295 | iPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefined |
| CVE-2026-56023 | 5.4 | 20.7 | Knit Pay | UPI QR Code Payment Gateway for WooCommerce | CWE-862 | WordPress UPI QR Code Payment Gateway for WooCommerce plugin <= 1.6.2 - Broke… |
| CVE-2020-37256 | 5.1 | 20.6 | Grav | Grav | CWE-79 | Grav - Cross-Site Scripting in Admin Plugin Page Editor |
| CVE-2026-54821 | 7.4 | 20.3 | Bootstrapped Ventures | Visual Link Preview | CWE-201 | WordPress Visual Link Preview plugin <= 2.3.1 - Sensitive Data Exposure vulne… |
| CVE-2026-48946 | 6.3 | 20.3 | getk2.org | K2 extension for Joomla | CWE-434 | Joomla Extension - getk2.org - Privileged RCE vulnerability in K2 extension f… |
| CVE-2026-48940 | 3.4 | 20.3 | getk2.org | K2 extension for Joomla | CWE-79 | Joomla Extension - getk2.org - Stored-XSS in K2 extension for Joomla < 2.26 |
| CVE-2026-10824 | 6.5 | 19.3 | Unknown | Masteriyo LMS | — | Masteriyo LMS < 2.2.1 - Unauthenticated Course Progress Disclosure and Deletion |
| CVE-2026-54029 | 6.5 | 19.1 | danny-avila | LibreChat | CWE-862 | LibreChat: IDOR in Message Deletion — Incomplete Fix for CVE-2024-41703 Leave… |
| CVE-2026-13350 | 2.3 | 18.8 | pretix | Venueless | CWE-639 | Permissions where checked incorrectly during room creation, allowing attacker… |
| CVE-2026-53147 | 8.1 | 18.4 | Linux | Linux | CWE-125 | thunderbolt: Validate XDomain request packet size before type cast |
| CVE-2026-53254 | 8.1 | 18.4 | Linux | Linux | CWE-125 | Bluetooth: RFCOMM: validate skb length in MCC handlers |
| CVE-2026-48941 | 6.5 | 18.1 | getk2.org | K2 extension for Joomla | CWE-862 | Joomla Extension - getk2.org - Unauthenticated folder delete in K2 extension … |
| CVE-2026-40941 | 7.1 | 18.0 | Cacti | cacti | CWE-347 | Cacti: Package Import Signature Validation Bypass Allows Self-Signed Packages |
| CVE-2026-10097 | 8.3 | 17.5 | wolfSSL | wolfSSL | CWE-697 | ML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break… |
| CVE-2026-13281 | 8.3 | 17.5 | Chrome | CWE-472 | Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a r… | |
| CVE-2026-53196 | 6.8 | 17.5 | Linux | Linux | CWE-787 | USB: serial: io_ti: fix heap overflow in get_manuf_info() |
| CVE-2026-40210 | 4.8 | 17.5 | PowerDNS | DNSdist | CWE-126 | Out-of-bounds read in SetMacAddrAction |
| CVE-2026-9221 | 8.7 | 17.1 | Shenzhen i365-Tech Co. Ltd. | Setracker2 Parental Control App (Android) package com.tgelec.setracker | CWE-327 | Setracker2 Children's Smartwatch Ecosystem Use of a Broken or Risky Cryptogra… |
| CVE-2026-54040 | 7.1 | 17.1 | danny-avila | LibreChat | CWE-306 | LibreChat: 2FA Backup Code Regeneration Without OTP Verification Allows 2FA B… |
| CVE-2026-40080 | 6.1 | 17.0 | Cacti | cacti | CWE-601 | Cacti: Open Redirect via HTTP_REFERER substring check in auth_login_redirect |
| CVE-2026-7511 | 5.9 | 16.8 | wolfSSL | wolfSSL | CWE-347 | PKCS7_verify signer confusion allows forged signatures to be accepted |
| CVE-2026-48942 | 6.1 | 16.4 | getk2.org | K2 extension for Joomla | CWE-79 | Joomla Extension - getk2.org - Stored-XSS in K2 extension for Joomla < 2.26 |
| CVE-2026-2815 | 8.4 | 16.2 | Silicon Labs | SiSDK | CWE-339 | Incorrect use of the PUF key for user key generation in EFR32xG27 results in … |
| CVE-2026-56005 | 7.1 | 16.3 | Melapress | WP Activity Log | CWE-79 | WordPress WP Activity Log plugin <= 5.6.3.1 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-56006 | 7.1 | 16.3 | H5P | H5P | CWE-79 | WordPress H5P plugin <= 1.17.6 - Reflected Cross Site Scripting (XSS) vulnera… |
| CVE-2026-56014 | 7.1 | 16.3 | Averta | Master Slider | CWE-79 | WordPress Master Slider plugin <= 3.11.2 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-56042 | 7.1 | 16.3 | Algolplus | Advanced Order Export For WooCommerce | CWE-79 | WordPress Advanced Order Export For WooCommerce plugin <= 4.0.9 - Cross Site … |
| CVE-2026-56051 | 7.1 | 16.3 | TablePress | TablePress | CWE-79 | WordPress TablePress plugin <= 3.3.1 - Reflected Cross Site Scripting (XSS) v… |
| CVE-2026-56071 | 7.1 | 16.3 | WPMU DEV | Forminator | CWE-79 | WordPress Forminator plugin <= 1.53.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-12635 | 3.1 | 16.0 | GitLab | GitLab | CWE-350 | Reliance on Reverse DNS Resolution for a Security-Critical Action in GitLab |
| CVE-2026-53256 | 8.0 | 15.9 | Linux | Linux | CWE-416 | Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() |
| CVE-2026-6291 | 6.0 | 15.2 | wolfSSL | wolfSSL | CWE-208 | Bleichenbacher padding oracle in PKCS#7 KTRI RSA PKCS#1 v1.5 decryption |
| CVE-2026-53146 | 7.1 | 15.1 | Linux | Linux | — | thunderbolt: Limit XDomain response copy to actual frame size |
| CVE-2026-53264 | 7.8 | 15.0 | Linux | Linux | CWE-416 | net/sched: act_api: use RCU with deferred freeing for action lifecycle |
| CVE-2026-54025 | 5.4 | 14.6 | danny-avila | LibreChat | CWE-79 | LibreChat: Stored XSS via unescaped image alt text in markdown artifact preview |
| CVE-2026-13318 | 6.4 | 14.4 | Red Hat | Red Hat OpenShift Virtualization 4 | CWE-918 | Virt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalid… |
| CVE-2026-55962 | 6.0 | 14.2 | wolfSSL | wolfSSL | CWE-287 | TLS 1.3 post-handshake authentication: server accepts Finished without client… |
| CVE-2026-11310 | 8.7 | 14.1 | wolfSSL | wolfSSL | CWE-295 | X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermed… |
| CVE-2026-11999 | 8.2 | 14.1 | wolfSSL | wolfSSL | CWE-295 | X.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert() |
| CVE-2026-55960 | 8.2 | 14.1 | wolfSSL | wolfSSL | CWE-295 | Un-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing… |
| CVE-2026-53275 | 8.8 | 13.8 | Linux | Linux | CWE-416 | ipv6: mcast: Fix use-after-free when processing MLD queries |
| CVE-2026-55895 | 5.7 | 13.1 | vim | vim | CWE-78 | Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename |
| CVE-2026-37149 | 7.7 | 11.9 | n/a | n/a | CWE-89 | GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was disco… |
| CVE-2026-6329 | 6.0 | 11.4 | wolfSSL | wolfSSL | CWE-347 | PKCS#12 MAC verification uses attacker-controlled comparison length |
| CVE-2026-46606 | 7.8 | 11.4 | nicolargo | glances | CWE-78 | Glances: Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vm… |
| CVE-2026-57453 | 7.3 | 10.8 | vim | vim | CWE-77 | Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction |
| CVE-2026-42390 | 5.3 | 10.4 | PowerDNS | Recursor | CWE-20 | ZONEMD validation can be bypassed |
| CVE-2026-40208 | 3.7 | 10.3 | PowerDNS | DNSdist | CWE-705 | Denial of service via DoH3 queries |
| CVE-2026-6731 | 6.0 | 10.3 | wolfSSL | wolfSSL | CWE-295 | X.509 name constraint bypass via Subject CN treated as a DNS name |
| CVE-2026-53137 | 7.8 | 9.9 | Linux | Linux | CWE-787 | drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size |
| CVE-2026-53194 | 7.8 | 9.7 | Linux | Linux | CWE-787 | USB: serial: kl5kusb105: fix bulk-out buffer overflow |
| CVE-2026-55411 | 6.8 | 9.6 | ToolJet | ToolJet | CWE-639 | ToolJet: Cross-tenant credential decryption (IDOR) in POST /api/data-sources/… |
| CVE-2026-10592 | 6.3 | 9.6 | wolfSSL | wolfSSL | CWE-295 | Wildcard DNS SAN bypasses CA name-constraint checks |
| CVE-2025-60464 | 7.8 | 9.6 | n/a | n/a | CWE-416 | A use-after-free in the gf_sei_load_from_state_internal function (/filters/se… |
| CVE-2026-57234 | 2.6 | 9.6 | sparklemotion | nokogiri | CWE-178 | Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, byp… |
| CVE-2026-6091 | 6.0 | 9.2 | wolfSSL | wolfSSL | CWE-295 | Partial-chain verification accepts untrusted intermediate as trust anchor |
| CVE-2026-54093 | 6.8 | 9.0 | filebrowser | filebrowser | CWE-22 | File Browser: Path traversal in download-as-zip/tar via Windows-style backsla… |
| CVE-2026-53203 | 7.1 | 8.9 | Linux | Linux | CWE-787 | accel/ivpu: Add buffer overflow check in MS get_info_ioctl |
| CVE-2026-55697 | 8.8 | 8.7 | pnpm | pnpm | CWE-78 | pnpm: Repository-controlled configDependencies can select a pacquet native in… |
| CVE-2026-53195 | 7.8 | 8.7 | Linux | Linux | CWE-787 | USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() |
| CVE-2026-10098 | 6.3 | 8.6 | wolfSSL | wolfSSL | CWE-295 | OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status |
| CVE-2026-55964 | 6.3 | 8.6 | wolfSSL | wolfSSL | CWE-295 | Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA (temp… |
| CVE-2026-6331 | 2.1 | 8.7 | wolfSSL | wolfSSL | CWE-347 | HMAC zero-length tag forgery in EVP_DigestVerifyFinal |
| CVE-2026-12921 | 8.4 | 8.3 | AzeoTech | DAQFactory | CWE-416 | Use after free in AzeoTech DAQFactory |
| CVE-2025-60465 | 6.1 | 8.3 | n/a | n/a | CWE-416 | A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter… |
| CVE-2026-53148 | 7.8 | 8.2 | Linux | Linux | CWE-787 | thunderbolt: Clamp XDomain response data copy to allocation size |
| CVE-2026-53132 | 7.1 | 8.2 | Linux | Linux | CWE-401 | vsock/virtio: fix potential unbounded skb queue |
| CVE-2026-53925 | 7.8 | 7.9 | nicolargo | glances | CWE-22 | Glances: Arbitrary file write and command execution via `secure_popen` redire… |
| CVE-2026-54096 | 8.4 | 7.8 | filebrowser | filebrowser | CWE-863 | File Browser: Improper Access Control Occurs via Pre-Created Public Share for… |
| CVE-2026-8330 | 4.4 | 7.8 | GitLab | GitLab | CWE-532 | Insertion of Sensitive Information into Log File in GitLab |
| CVE-2026-55967 | 2.0 | 7.8 | wolfSSL | wolfSSL | CWE-323 | AES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enab… |
| CVE-2026-55487 | 8.8 | 7.7 | pnpm | pnpm | CWE-346 | pnpm: manifest identity spoof satisfies allowBuilds and runs attacker lifecycle |
| CVE-2026-50021 | 8.1 | 7.7 | pnpm | pnpm | CWE-354 | pnpm: Integrity Check Bypass via Missing Lockfile Integrity Field |
| CVE-2021-47986 | 7.7 | 7.5 | parse-community | parse-server | CWE-494 | Parse Server - Unreviewed Code Execution via Malicious Version Tags |
| CVE-2026-53234 | 7.8 | 7.4 | Linux | Linux | CWE-416 | net: ibm: emac: Fix use-after-free during device removal |
| CVE-2026-4522 | 6.7 | 7.4 | HYPR | Passwordless | CWE-306 | Missing authentication for critical function vulnerability in HYPR Passwordle… |
| CVE-2021-47987 | 7.7 | 7.3 | parse-community | parse-server | CWE-494 | Parse Server - Arbitrary Code Execution via Malicious Version Tags |
| CVE-2026-53133 | 7.8 | 7.1 | Linux | Linux | CWE-681 | RDMA/umem: Fix truncation for block sizes >= 4G |
| CVE-2026-53182 | 7.8 | 7.1 | Linux | Linux | — | wifi: nl80211: reject oversized EMA RNR lists |
| CVE-2026-53209 | 7.8 | 7.1 | Linux | Linux | CWE-787 | Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend |
| CVE-2026-53265 | 7.8 | 7.1 | Linux | Linux | — | dm cache policy smq: check allocation under invalidate lock |
| CVE-2026-53159 | 5.5 | 7.1 | Linux | Linux | — | misc: fastrpc: fix DMA address corruption due to find_vma misuse |
| CVE-2026-53170 | 8.8 | 7.0 | Linux | Linux | CWE-908 | accel/ethosu: reject DMA commands with uninitialized length |
| CVE-2026-53171 | 8.8 | 7.0 | Linux | Linux | — | accel/ethosu: fix arithmetic issues in dma_length() |
| CVE-2026-12897 | 8.4 | 7.0 | Horner Automation | Cscape | CWE-125 | Out-of-bounds read in Horner Automation Cscape |
| CVE-2026-53191 | 7.8 | 7.0 | Linux | Linux | — | io_uring/net: inherit IORING_CQE_F_BUF_MORE across bundle recv retries |
| CVE-2026-53193 | 7.8 | 7.0 | Linux | Linux | CWE-416 | ALSA: timer: Forcibly close timer instances at closing |
| CVE-2026-53201 | 7.8 | 7.0 | Linux | Linux | — | Revert "drm/xe: Skip exec queue schedule toggle if queue is idle during suspend" |
| CVE-2026-53233 | 7.8 | 7.0 | Linux | Linux | CWE-415 | netdev: fix double-free in netdev_nl_bind_rx_doit() |
| CVE-2026-53188 | 8.8 | 6.8 | Linux | Linux | — | RDMA/core: Validate the passed in fops for ib_get_ucaps() |
| CVE-2026-53162 | 7.8 | 6.8 | Linux | Linux | — | memcg: use round-robin victim selection in refill_stock |
| CVE-2026-56788 | 4.8 | 6.7 | tomojitakasu | RTKLIB | CWE-125 | RTKLIB 2.4.3 - Out-of-bounds Read via Negative Array Index in getcodepri |
| CVE-2026-53274 | 5.5 | 6.7 | Linux | Linux | — | net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS |
| CVE-2026-53160 | 7.8 | 6.5 | Linux | Linux | CWE-416 | misc: fastrpc: fix use-after-free race in fastrpc_map_create |
| CVE-2026-53161 | 7.8 | 6.5 | Linux | Linux | CWE-416 | misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context |
| CVE-2026-53239 | 7.8 | 6.5 | Linux | Linux | CWE-416 | xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() |
| CVE-2026-48995 | 4.8 | 6.5 | pnpm | pnpm | CWE-353 | pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile |
| CVE-2026-53156 | 7.8 | 6.5 | Linux | Linux | CWE-416 | nvmem: core: fix use-after-free bugs in error paths |
| CVE-2026-53192 | 7.8 | 6.5 | Linux | Linux | CWE-416 | ALSA: timer: Fix UAF at snd_timer_user_params() |
| CVE-2026-53272 | 7.8 | 6.5 | Linux | Linux | CWE-416 | erofs: fix use-after-free on sbi->sync_decompress |
| CVE-2026-55892 | 5.5 | 6.5 | vim | vim | CWE-787 | Vim: Out-of-bounds Write in Spell File Prefix Dump |
| CVE-2026-57452 | 5.5 | 6.5 | vim | vim | CWE-125 | Vim: Out-of-bounds Read with libsodium-encrypted Files |
| CVE-2026-57589 | 7.8 | 6.4 | OpenBSD | OpenBSD | CWE-416 | sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing loca… |
| CVE-2026-57454 | 6.8 | 6.3 | vim | vim | CWE-125 | Vim: Out-of-bounds Read with Text Properties |
| CVE-2026-6330 | 6.3 | 6.3 | wolfSSL | wolfSSL | CWE-327 | ML-KEM ARM64 NEON ciphertext comparison only compares half of the input |
| CVE-2026-54030 | 9.3 | 6.2 | danny-avila | LibreChat | CWE-346 | LibreChat: Missing Resource Parameter Validation in MCP OAuth Flow |
| CVE-2026-50573 | 8.1 | 6.2 | pnpm | pnpm | CWE-345 | pnpm: Unsafe default behavior breaks integrity check |
| CVE-2026-53259 | 7.8 | 6.3 | Linux | Linux | CWE-416 | ipv6: anycast: insert aca into global hash under idev->lock |
| CVE-2026-53223 | 7.1 | 6.1 | Linux | Linux | — | net: guard timestamp cmsgs to real error queue skbs |
| CVE-2026-54250 | 5.8 | 6.1 | k3s-io | k3s | CWE-22 | K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression |
| CVE-2026-53230 | 8.7 | 6.0 | Linux | Linux | CWE-125 | net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list |
| CVE-2026-53179 | 7.1 | 6.0 | Linux | Linux | CWE-125 | staging: rtl8723bs: fix buffer over-read in rtw_update_protection |
| CVE-2026-53205 | 7.1 | 6.0 | Linux | Linux | CWE-787 | accel/ivpu: Add bounds checks for firmware log indices |
| CVE-2026-46611 | 5.3 | 6.0 | nicolargo | glances | CWE-346 | Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding … |
| CVE-2026-53200 | 8.8 | 5.9 | Linux | Linux | — | KVM: arm64: nv: Fix handling of XN[0] when !FEAT_XNX |
| CVE-2026-53172 | 7.8 | 5.9 | Linux | Linux | CWE-125 | accel/ethosu: fix IFM region index out-of-bounds in command stream parser |
| CVE-2026-53173 | 7.8 | 5.9 | Linux | Linux | CWE-787 | accel/ethosu: fix OOB write in ethosu_gem_cmdstream_copy_and_validate() |
| CVE-2026-53174 | 7.8 | 5.9 | Linux | Linux | — | ovl: keep err zero after successful ovl_cache_get() |
| CVE-2026-53276 | 7.8 | 5.9 | Linux | Linux | CWE-416 | Bluetooth: ISO: Fix a use-after-free of the hci_conn pointer |
| CVE-2026-56129 | 6.8 | 5.9 | Dynabook Inc. | Generic IO & Memory Access driver | CWE-782 | Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and… |
| CVE-2026-53187 | 7.1 | 5.8 | Linux | Linux | CWE-787 | RDMA/core: Validate cpu_id against nr_cpu_ids in DMAH alloc |
| CVE-2026-53135 | 5.5 | 5.6 | Linux | Linux | CWE-476 | drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs |
| CVE-2026-53140 | 5.5 | 5.5 | Linux | Linux | CWE-401 | drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups |
| CVE-2026-53142 | 5.5 | 5.5 | Linux | Linux | CWE-908 | drm/xe/display: fix oops in suspend/shutdown without display |
| CVE-2026-53144 | 5.5 | 5.5 | Linux | Linux | CWE-476 | drm/amdkfd: fix NULL dereference in get_queue_ids() |
| CVE-2026-53150 | 5.5 | 5.6 | Linux | Linux | CWE-191 | thunderbolt: Reject zero-length property entries in validator |
| CVE-2026-53152 | 5.5 | 5.5 | Linux | Linux | CWE-476 | mmc: dw_mmc-rockchip: Add missing private data for very old controllers |
| CVE-2026-53154 | 5.5 | 5.5 | Linux | Linux | CWE-772 | mm/hugetlb: restore reservation on error in hugetlb folio copy paths |
| CVE-2026-53168 | 5.5 | 5.6 | Linux | Linux | — | fuse: reject fuse_notify() pagecache ops on directories |
| CVE-2026-53177 | 5.5 | 5.6 | Linux | Linux | CWE-476 | bnxt_en: Fix NULL pointer dereference |
| CVE-2026-53190 | 5.5 | 5.5 | Linux | Linux | — | drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() |
| CVE-2026-53210 | 5.5 | 5.5 | Linux | Linux | CWE-401 | tee: shm: fix shm leak in register_shm_helper() |
| CVE-2026-53214 | 5.5 | 5.5 | Linux | Linux | CWE-476 | ipv6: Fix a potential NPD in cleanup_prefix_route() |
| CVE-2026-53219 | 5.5 | 5.6 | Linux | Linux | — | netfilter: x_tables: avoid leaking percpu counter pointers |
| CVE-2026-53220 | 5.5 | 5.5 | Linux | Linux | CWE-476 | netfilter: revalidate bridge ports |
| CVE-2026-53237 | 5.5 | 5.5 | Linux | Linux | CWE-476 | gpio: mvebu: fix NULL pointer dereference in suspend/resume |
| CVE-2026-53238 | 5.5 | 5.6 | Linux | Linux | — | netlabel: validate unlabeled address and mask attribute lengths |
| CVE-2026-53241 | 5.5 | 5.5 | Linux | Linux | — | ALSA: seq: dummy: fix UMP event stack overread |
| CVE-2026-53251 | 5.5 | 5.5 | Linux | Linux | CWE-772 | Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync |
| CVE-2026-53261 | 5.5 | 5.5 | Linux | Linux | CWE-401 | devlink: Release nested relation on devlink free |
| CVE-2026-53263 | 5.5 | 5.6 | Linux | Linux | CWE-193 | 6lowpan: fix off-by-one in multicast context address compression |
| CVE-2026-53269 | 5.5 | 5.6 | Linux | Linux | — | netfilter: synproxy: add mutex to guard hook reference counting |
| CVE-2026-53271 | 5.5 | 5.5 | Linux | Linux | CWE-476 | ksmbd: fix NULL-deref of opinfo->conn in oplock/lease break notifiers |
| CVE-2026-57451 | 6.1 | 5.5 | vim | vim | CWE-125 | Vim: Out-of-bounds Read in Text Property Count |
| CVE-2026-53141 | 5.5 | 5.4 | Linux | Linux | — | drm/v3d: Fix global performance monitor reference counting |
| CVE-2026-53164 | 5.5 | 5.4 | Linux | Linux | — | iommu/dma: Do not try to iommu_map a 0 length region in swiotlb |
| CVE-2026-53211 | 5.5 | 5.4 | Linux | Linux | CWE-401 | netfilter: nft_meta_bridge: fix stale stack leak via IIFHWADDR register |
| CVE-2026-53258 | 5.5 | 5.4 | Linux | Linux | CWE-401 | wifi: fix leak if split 6 GHz scanning fails |
Results continue: ranks 401–468.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-06-25 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.