boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Friday, June 26, 2026 · all times UTC← 2026-06-25 · archive · 2026-06-27 →

Security Box Score — June 26, 2026

353 CVEs published, led by Linux (47).

353 CVEs published June 26, 2026: 47 critical, 147 high, 152 medium, 7 low; 0 in the KEV catalog at press time; 39 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 328 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published699211453——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

508 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux512147911985450511120.17.8.0014+282 ▲
google70788285468300297760.78.1.0023+691 ▲
microsoft220756585201726286192.57.8.0045+60 ▲
red hat1082029829813200.06.5.0029+91 ▲
apple156712143288710.45.5.0020-7 ▼
canonical6202585000.05.5.0011+6 ▲
freebsd290630000.07.8.0019-5 ▼
suse461410000.08.6.0029+2 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco102266100561150.07.3.0566+5 ▲
netgear171700161000.04.3.0024+17 ▲
palo alto networks911127113218.25.9.0022+7 ▲
ubiquiti81174003327.39.9.0083+6 ▲
ivanti49450025555.68.8.5187+2 ▲
checkpoint3915303111.17.5.0410-3 ▼
fortinet29432028333.38.3.0076+1 ▲
f56843104112.58.9.0225+4 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache104138224758103310.76.8.0050+85 ▲
mozilla49551118260900.07.3.0026+43 ▲
gitlab243105215426.54.4.0029+24 ▲
docker470520000.08.2.0016+1 ▲
drupal0511304120.05.1.0026-3 ▼
github131110000.07.0.00390
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2422701321161842720.78.8.0040+242 ▲
adobe1321344517721921.55.5.0021+132 ▲
ibm32811935270600.07.5.0031+12 ▲
progress591710600.07.5.0036+1 ▲
solarwinds36231010466.77.8.6082+3 ▲
veeam142200100.09.0.0052+1 ▲
zohocorp131110000.08.4.0170-1 ▼
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5 ▲
d-link9110425300.05.5.0058+8 ▲
siemens780440000.07.5.0020+6 ▲
rockwell automation771510000.08.7.0030+7 ▲
abb660420000.07.2.0018+6 ▲
schneider electric660420000.07.8.0042+6 ▲
moxa550320000.07.0.0029+5 ▲
dahua330111000.06.9.0036+3 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7273231391000.06.5.0024+71 ▲
openclaw61670352210000.07.0.0021+61 ▲
sourcecodester3759002534000.02.1.0026+17 ▲
themerex585855300000.08.1.0043+58 ▲
dell3856230240211.87.3.0017+26 ▲
edimax556033023100.07.4.0070-39 ▼
jenkins project364909391300.04.8.0025+36 ▲
capgo4646222211000.07.0.0039+46 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9991100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-20230.882099.88.6
CVE-2026-34910.874799.710.0
CVE-2026-34908.851999.710.0
CVE-2026-50751.837799.79.3
CVE-2026-48907.781099.510.0
CVE-2026-34909.639099.210.0
CVE-2026-49160.538398.97.5
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9991KEV
CVE-2026-3491010.0.8747KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.7810KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-5357610.0.0330
CVE-2026-5375310.0.0290
CVE-2026-4977710.0.0166
CVE-2026-4919910.0.0134
CVE-2026-4986910.0.0116
Most disclosures (vendor)
VendorCVEs
google858
linux648
oracle267
microsoft220
adobe132
red hat128
apache106
spring72
openclaw67
themerex58
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco11
apple7
google6
ivanti5
solarwinds4
berriai3
fortinet3
smartertools3
ubiquiti3
Most-affected ecosystems
EcosystemAdvisories
Maven41
Packagist22
PyPI9
npm5
Fastest to KEV
CVEVendorDays
CVE-2025-48595Google0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-28318SolarWinds0
CVE-2026-34908Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171682
CVE-2021-27102n/a2021-11-171682
CVE-2021-27101n/a2021-11-171682
CVE-2021-27103n/a2021-11-171682
CVE-2021-21017Adobe2021-11-171682
CVE-2021-28550Adobe2021-11-171682
CVE-2021-42013Apache Software Foundation2021-11-171682
CVE-2021-41773Apache Software Foundation2021-11-171682
CVE-2021-30858Apple2021-11-171682
CVE-2021-30860Apple2021-11-171682

Transactions

EXPLOIT PUBLISHED — envoyproxy envoy: 11 CVEs (CVE-2026-47204, CVE-2026-47205, CVE-2026-47207, CVE-2026-47220, CVE-2026-47221, CVE-2026-47775, CVE-2026-47778, CVE-2026-48042, CVE-2026-48044, CVE-2026-48090, CVE-2026-48743). Public exploit references added.

EXPLOIT PUBLISHED — budibase: 7 CVEs (CVE-2026-50132, CVE-2026-50136, CVE-2026-50137, CVE-2026-54350, CVE-2026-54351, CVE-2026-54352, CVE-2026-54353). Public exploit references added.

EXPLOIT PUBLISHED — kestra-io kestra: 6 CVEs (CVE-2026-45807, CVE-2026-49869, CVE-2026-49984, CVE-2026-53576, CVE-2026-53577, CVE-2026-55069). Public exploit references added.

EXPLOIT PUBLISHED — notepad-plus-plus: 5 CVEs (CVE-2026-48770, CVE-2026-48778, CVE-2026-48800, CVE-2026-52884, CVE-2026-52885). Public exploit references added.

EXPLOIT PUBLISHED — Canonical lxd: 4 CVEs (CVE-2026-9639, CVE-2026-9640, CVE-2026-12411, CVE-2026-28385). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-50765. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-50766. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-50767. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-55686 (podman-container-tools podman). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56876 (max-mapper extract-zip). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-57920 (Peplink InControl). Public exploit reference added.

Yesterday's Results

How to read these box scores · glossary

353 CVEs published. 25 box scores, 328 table rows — nothing truncated.

Revive Adserver — Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offse…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0494   91.5     —
AFFECTED
  Product   Versions     Fixed
  Adserver  unspecified  —
TIMELINE
  Jun 6   Reserved by CNA
  Jun 26  Published (CNA: hackerone)
CWE-94 · CNA: hackerone · CVSS v3.0 · 2 references · NVD status: Analyzed
nodejs node — A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a mu…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0371   88.9     —
AFFECTED
  Product  Versions   Fixed
  node     22.22.3 –  —
TIMELINE
  May 26  Reserved by CNA
  Jun 26  Published (CNA: hackerone)
CWE-190, CWE-770 · CNA: hackerone · CVSS v3.1 · 17 references · NVD status: Modified
kestra-io kestra — Kestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0330   87.6     —
AFFECTED
  Product  Versions    Fixed
  kestra   < 1.0.45 –  —
TIMELINE
  Jun 9   Reserved by CNA
  Jun 26  Public exploit reference published
  Jun 26  Published (CNA: GitHub_M)
CWE-94, CWE-288 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Analyzed
nodejs node — A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wi…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0323   87.3     —
AFFECTED
  Product  Versions   Fixed
  node     22.22.3 –  —
TIMELINE
  May 22  Reserved by CNA
  Jun 26  Published (CNA: hackerone)
CWE-176, CWE-289 · CNA: hackerone · CVSS v3.1 · 17 references · NVD status: Modified
Shenzhen Cudy Technology Co., Ltd. LT300 3.0 — Cudy LT300 3.0 OS Command Injection via NTP Configuration
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0242   82.9     —
AFFECTED
  Product    Versions     Fixed
  LT300 3.0  unspecified  —
TIMELINE
  Mar 16  Reserved by CNA
  Jun 26  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
Unknown YMC Filter — YMC Smart Filter < 3.11.3 - Unauthenticated Private/Draft Post Disclosure
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0152   72.7     —
AFFECTED
  Product     Versions     Fixed
  YMC Filter  unspecified  —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 26  Published (CNA: WPScan)
CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Deferred
GeoVision Inc. GV-LPCLPC2011/2211 — GV-LPC2011/LPC2211 - unauthorized directory traversal vulnerability (get_fcont.cgi)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0145   71.3     —
AFFECTED
  Product             Versions  Fixed
  GV-LPCLPC2011/2211  1.12 –    1.13
TIMELINE
  Jun 26  Reserved by CNA
  Jun 26  Published (CNA: GV)
CWE-22 · CNA: GV · CVSS v3.1 · 1 reference · NVD status: Deferred
Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  C  H  H  H    8.0   .0135   69.3     —
AFFECTED
  Product                    Versions     Fixed
  Container Storage Modules  unspecified  —
TIMELINE
  Apr 15  Reserved by CNA
  Jun 26  Published (CNA: dell)
CWE-78 · CNA: dell · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
nrwl nx — Nx: `nx graph` dev server permissive CORS policy
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   R  U  H  L  N    5.9   .0120   65.9     —
AFFECTED
  Product  Versions               Fixed
  nx       >= 17.0.4, < 22.7.2 –  —
TIMELINE
  Jun 15  Reserved by CNA
  Jun 26  Published (CNA: GitHub_M)
CWE-749, CWE-942 · CNA: GitHub_M · CVSS v3.1 · 2 references · NVD status: Deferred
kestra-io kestra — Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0116   64.7     —
AFFECTED
  Product  Versions    Fixed
  kestra   < 1.0.45 –  —
TIMELINE
  Jun 1   Reserved by CNA
  Jun 26  Public exploit reference published
  Jun 26  Published (CNA: GitHub_M)
CWE-78, CWE-184, CWE-287, CWE-918 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Analyzed
GeoVision Inc. GV-LPCLPC2011/2211 — GV-LPC2011/LPC2211 - unauthorized buffer overflow vulnerability (thttpd)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0095   58.7     —
AFFECTED
  Product             Versions  Fixed
  GV-LPCLPC2011/2211  1.12 –    1.13
TIMELINE
  Jun 26  Reserved by CNA
  Jun 26  Published (CNA: GV)
CWE-121 · CNA: GV · CVSS v3.1 · 1 reference · NVD status: Deferred
GeoVision Inc. GV-LPCLPC2011/2211 — GV-LPC2011/LPC2211 - unauthorized buffer overflow via AuthMode/AuthValue path (ssvr)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0095   58.4     —
AFFECTED
  Product             Versions  Fixed
  GV-LPCLPC2011/2211  1.12 –    1.13
TIMELINE
  Jun 26  Reserved by CNA
  Jun 26  Published (CNA: GV)
CWE-121 · CNA: GV · CVSS v3.1 · 1 reference · NVD status: Deferred
GeoVision Inc. GV-LPCLPC2011/2211 — GV-LPC2011/LPC2211 - unauthorized buffer overflow via RTSP Digest username (ssvr)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0095   58.4     —
AFFECTED
  Product             Versions  Fixed
  GV-LPCLPC2011/2211  1.12 –    1.13
TIMELINE
  Jun 26  Reserved by CNA
  Jun 26  Published (CNA: GV)
CWE-121 · CNA: GV · CVSS v3.1 · 1 reference · NVD status: Deferred
Edgewall *Genshi* Genshi — Server side template inject (SSTI) in Edgewall Genshi Template Engine
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0093   57.8     —
AFFECTED
  Product  Versions     Fixed
  Genshi   unspecified  —
TIMELINE
  Jan 7   Reserved by CNA
  Jun 26  Published (CNA: certcc)
CNA: certcc · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
Linux Linux — ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0076   52.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    ea2034416b54700e30371f2ad6517cbb94674083 –  —
  Linux    2.6.37 –                                    5.10.258
TIMELINE
  Jun 9   Reserved by CNA
  Jun 26  Published (CNA: Linux)
CWE-193 · CNA: Linux · CVSS v3.1 · 8 references · NVD status: Analyzed
Ollama AI Ollama — There exists an unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0073   51.7     —
AFFECTED
  Product  Versions   Fixed
  Ollama   v0.13.5 –  —
TIMELINE
  Apr 7   Reserved by CNA
  Jun 26  Published (CNA: certcc)
CWE-125 · CNA: certcc · CVSS v3.1 · 3 references · NVD status: Analyzed
GeoVision Inc. GV-LPCLPC2011/2211 — GV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability in packet parsing
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0073   51.3     —
AFFECTED
  Product             Versions  Fixed
  GV-LPCLPC2011/2211  1.12 –    1.13
TIMELINE
  Jun 26  Reserved by CNA
  Jun 26  Published (CNA: GV)
CWE-476 · CNA: GV · CVSS v3.1 · 1 reference · NVD status: Deferred
dragonflydb dragonfly — Dragonfly: RESTORE operations may crash the server
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0071   50.7     —
AFFECTED
  Product    Versions    Fixed
  dragonfly  < 1.39.0 –  —
TIMELINE
  Jun 12  Reserved by CNA
  Jun 26  Published (CNA: GitHub_M)
CWE-125 · CNA: GitHub_M · CVSS v3.1 · 2 references · NVD status: Deferred
jdx mise — mise: Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  H  H    9.6   .0069   49.8     —
AFFECTED
  Product  Versions       Fixed
  mise     < 2026.3.10 –  —
TIMELINE
  Mar 23  Reserved by CNA
  Jun 26  Published (CNA: GitHub_M)
CWE-94 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Deferred
Pagekit CMS 1.0.18 Privilege Escalation via UserApiController
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0069   49.8     —
AFFECTED
  Product  Versions     Fixed
  pagekit  unspecified  —
TIMELINE
  Jun 24  Reserved by CNA
  Jun 26  Published (CNA: VulnCheck)
CWE-862 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
zaproxy zap-extensions — ZAP ViewState Add-on Insecure Deserialization via JSFViewState.decode()
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    8.7   .0068   49.7     —
AFFECTED
  Product         Versions     Fixed
  zap-extensions  unspecified  —
TIMELINE
  Jun 24  Reserved by CNA
  Jun 26  Published (CNA: VulnCheck)
CWE-502 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Awaiting Analysis
Daktronics Controller Firmware Path Traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0068   49.6     —
AFFECTED
  Product       Versions     Fixed
  VFC-DMP-5000  unspecified  —
  DMP-5000      unspecified  —
  DMP-8000      unspecified  —
TIMELINE
  Mar 30  Reserved by CNA
  Jun 26  Published (CNA: icscert)
CWE-22 · CNA: icscert · CVSS v4.0 · 2 references · NVD status: Analyzed
envoyproxy envoy — Envoy: Segmentation fault when using %REQUESTED_SERVER_NAME% in log format
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0066   49.0     —
AFFECTED
  Product  Versions               Fixed
  envoy    >= 1.38.0, < 1.38.3 –  —
TIMELINE
  May 18  Reserved by CNA
  Jun 26  Public exploit reference published
  Jun 26  Published (CNA: GitHub_M)
CWE-476 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Modified
GeoVision Inc. GV-LPCLPC2011/2211 — GV-LPC2011/LPC2211 - unauthorized stack-based buffer overflow vulnerability (vlsvr)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0065   48.3     —
AFFECTED
  Product             Versions  Fixed
  GV-LPCLPC2011/2211  1.12 –    1.13
TIMELINE
  Jun 26  Reserved by CNA
  Jun 26  Published (CNA: GV)
CWE-121 · CNA: GV · CVSS v3.1 · 1 reference · NVD status: Deferred
nodejs node — A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could l…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0064   47.9     —
AFFECTED
  Product  Versions   Fixed
  node     22.22.3 –  —
TIMELINE
  May 22  Reserved by CNA
  Jun 26  Published (CNA: hackerone)
CWE-400 · CNA: hackerone · CVSS v3.1 · 1 reference · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-559758.647.5H.VIEWHV-500S6 IP CameraCWE-78H.VIEW HV-500S6 IP Camera OS Command Injection
CVE-2026-96407.247.6CanonicalLXDCWE-863LXD Snapshot Import Privilege Escalation Vulnerability
CVE-2026-386397.547.4n/an/aCWE-20An issue in the parse_month function (/time/strptime.rs) of relibc commit ab6…
CVE-2026-386417.547.4n/an/aCWE-404An issue in the DSO::mmap_and_copy function of relibc commit 61f42d allows at…
CVE-2026-487787.847.0notepad-plus-plusnotepad-plus-plusCWE-78Notepad++: Arbitrary Code Execution via config.xml commandLineInterpreter
CVE-2026-487067.546.5envoyproxyenvoyCWE-120Envoy Heap Buffer Overflow in TcpStatsdSink
CVE-2026-532847.546.5LinuxLinuxCWE-476btrfs: only release the dirty pages io tree after successful writes
CVE-2026-300417.545.8n/an/aCWE-400An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3…
CVE-2026-573158.545.2Creative ThemesBlocksy Companion ProCWE-94WordPress Blocksy Companion Pro plugin <= 2.1.45 - Remote Code Execution (RCE…
CVE-2026-480905.945.0envoyproxyenvoyCWE-416Envoy HTTP: OAuth2 filter late async token completion after stream teardown (…
CVE-2026-319289.344.5DaktronicsVFC-DMP-5000CWE-798Daktronics Controller Firmware Use of Hard-coded Credentials
CVE-2026-458077.744.4kestra-iokestraCWE-22Kestra: Path traversal via URL-encoded "%2E%2E" in execution and namespace fi…
CVE-2026-499847.744.4kestra-iokestraCWE-22Kestra: Path traversal in `LocalStorage` allows any authenticated user to rea…
CVE-2026-560329.844.3BuddyBossBuddyboss PlatformCWE-502WordPress Buddyboss Platform plugin <= 3.0.4 - PHP Object Injection vulnerabi…
CVE-2026-560579.844.3Uncanny OwlUncanny Automator ProCWE-502WordPress Uncanny Automator Pro plugin <= 7.3.0.6 - PHP Object Injection vuln…
CVE-2026-480427.543.9envoyproxyenvoyCWE-1124Envoy: Stack overflow in destructor of highly nested JSON
CVE-2026-364787.543.5n/an/aCWE-400An issue in Technitium DNS Server v.14.3 and before allows a remote attacker …
CVE-2026-578767.543.5GeoVision Inc.GV-LPCLPC2011/2211CWE-787GV-LPC2011/LPC2211 - unauthorized out-of-bounds writing vulnerability (onvif.…
CVE-2026-96396.543.4CanonicalLXDCWE-476Authenticated Denial of Service via Malicious Backup Tarball in LXD
CVE-2026-578747.543.3GeoVision Inc.GV-LPCLPC2011/2211CWE-120GV-LPC2011/LPC2211 - unauthorized buffer overflow vulnerability (IEEE8021x_up…
CVE-2026-543509.842.9BudibasebudibaseCWE-89Budibase: Anonymous NoSQL operator injection via published-app query templates
CVE-2025-550179.142.8Apache Software FoundationApache IoTDBCWE-22Apache IoTDB: Path Traversal Vulnerability
CVE-2025-641529.142.8Apache Software FoundationApache IoTDBCWE-22Apache IoTDB: Path Traversal Vulnerability
CVE-2026-567738.742.8teableioteableCWE-862Teable - Missing Authorization in v2 REST API
CVE-2026-546369.942.4dokkudokkuCWE-78Dokku: OS Command Injection via app.json managed Cron
CVE-2026-454068.842.4dokkudokkuCWE-95Dokku: Host RCE via Maliciously Named OpenResty Include Files Injected Throug…
CVE-2026-579157.342.2Apache Software FoundationApache KerbyCWE-304Apache Kerby: Kerberos Pre-Authentication Bypass
CVE-2026-560289.842.1themewantEasy Elements for Elementor &#8211; Addons &amp; Website TemplatesCWE-266WordPress Easy Elements for Elementor – Addons & Website Templates plugin <= …
CVE-2026-560558.841.7InspiryThemesRealHomesCWE-502WordPress RealHomes theme <= 4.5.3 - PHP Object Injection vulnerability
CVE-2026-116257.541.1DAVIDOBytes::Random::SecureCWE-335Bytes::Random::Secure versions through 0.29 for Perl share internal state acr…
CVE-2026-117027.541.1DAVIDOBytes::Random::Secure::TinyCWE-335Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal st…
CVE-2026-576589.140.5TemplatespareTemplateSpareCWE-434WordPress TemplateSpare plugin <= 4.2.0 - Arbitrary File Upload vulnerability
CVE-2026-133727.240.5DevolutionsRemote Desktop ManagerCWE-706Incorrect link resolution by display name in the custom PowerShell VPN editor…
CVE-2026-543529.640.1BudibasebudibaseCWE-22Budibase: Arbitrary file read by workspace-builder via PWA-zip symlink upload
CVE-2026-463869.939.9opfopenprojectCWE-502OpenProject: Pre-authentication RCE in openproject/openproject Docker image v…
CVE-2026-480447.539.6envoyproxyenvoyCWE-409Envoy Zstd Decompressor: Ratio Check at Wrong Loop Depth lead to memory explo…
CVE-2026-507394.339.6ReviveAdserverCWE-284A bypass for CVE‑2026‑34913 exists with proper ownership validation that had …
CVE-2026-560309.839.4paytiumsupportPaytiumCWE-266WordPress Paytium plugin <= 5.0.2 - Privilege Escalation vulnerability
CVE-2026-560339.839.4Dokan Multivendor PluginDokan ProCWE-266WordPress Dokan Pro plugin <= 5.0.4 - Privilege Escalation vulnerability
CVE-2026-560589.939.2ThemeCatcherQuformCWE-434WordPress Quform plugin <= 2.23.0 - Arbitrary File Upload vulnerability
CVE-2026-560599.939.2PhysCodeTravel BookingCWE-434WordPress Travel Booking theme <= 2.2.5 - Arbitrary File Upload vulnerability
CVE-2026-83806.538.7UnknownFrontend File Manager Plugin—Frontend File Manager Plugin <= 23.6 - Author+ Arbitrary Post Deletion
CVE-2026-132266.538.7trainingbusinessprosGroundhogg — CRM, Newsletters, and Marketing AutomationCWE-89Groundhogg <= 4.5.4 - Authenticated (Custom+) SQL Injection via 'after' Param…
CVE-2026-560665.838.3ShortPixelShortPixel Adaptive ImagesCWE-22WordPress ShortPixel Adaptive Images plugin <= 3.11.4 - Arbitrary File Deleti…
CVE-2026-300406.538.2n/an/aCWE-122A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 al…
CVE-2026-543519.638.0BudibasebudibaseCWE-915Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automatio…
CVE-2026-96996.837.8MattermostMattermostCWE-532Mattermost Agents plugin logs unsanitized OpenAI API keys on authentication e…
CVE-2026-454058.837.7dokkudokkuCWE-59Dokku: Arbitrary File Write via Tar Symlink Traversal in git:from-archive and…
CVE-2026-527829.937.5opfopenprojectCWE-639OpenProject: IDOR through /projects/<A>/settings/project_storages/<A_ps_id> v…
CVE-2026-472062.337.3dragonflydbdragonflyCWE-116Dragonfly: RESP Protocol Injection via Lua redis.error_reply() in EvalSerializer
CVE-2026-472047.537.1envoyproxyenvoyCWE-476Envoy: grpc_stats filter segfault on Connect protocol requests to direct_resp…
CVE-2026-472217.536.8envoyproxyenvoyCWE-476Envoy: Null pointer deref in internal redirects
CVE-2026-335608.436.8DaktronicsVFC-DMP-5000CWE-434Daktronics Controller Firmware Unrestricted Upload of File with Dangerous Type
CVE-2026-472076.536.8envoyproxyenvoyCWE-416Envoy crashes if multiple unexpected ext_proc responses are packed into one g…
CVE-2026-494867.536.6Apache Software FoundationApache Airflow FTP providerCWE-319Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel …
CVE-2026-535776.536.2kestra-iokestraCWE-863Kestra: Cross-Execution File Read via Preview Endpoint (IDOR)
CVE-2026-560318.136.1Uncanny OwlUncanny AutomatorCWE-502WordPress Uncanny Automator plugin <= 7.3.1.2 - PHP Object Injection vulnerab…
CVE-2026-579146.536.1Apache Software FoundationApache KerbyCWE-400Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures
CVE-2026-578778.635.9GeoVision Inc.GV-LPCLPC2011/2211CWE-134GV-LPC2011/LPC2211 - unauthorized format string vulnerability (vlsvr)
CVE-2026-556777.535.7labstackechoCWE-22Echo: Encoded slash (%2F) bypasses route-level protection and exposes static …
CVE-2025-680637.535.5StylemixThemesSplash - Sport Club WordPress Theme for Basketball, Football, HockeyCWE-98WordPress Splash - Sport Club WordPress theme for Basketball, Football, Hocke…
CVE-2025-680647.535.5EverthemessGoya CoreCWE-98WordPress Goya Core plugin < 1.0.9.4 - Local File Inclusion vulnerability
CVE-2026-576477.535.5bPluginsPanorama Viewer – 360 Degree Image + Video ViewerCWE-98WordPress Panorama Viewer – 360 Degree Image + Video Viewer plugin <= 1.6.1 -…
CVE-2026-471937.535.5opfopenprojectCWE-200OpenProject: Journal diff endpoint bypasses object, journal, and field visibi…
CVE-2026-560297.535.3corvuspayCorvusPay WooCommerce Payment GatewayCWE-288WordPress CorvusPay WooCommerce Payment Gateway plugin <= 2.7.4 - Broken Auth…
CVE-2026-560697.535.2Site Building with ToolsetToolset FormsCWE-639WordPress Toolset Forms plugin <= 2.6.24 - Insecure Direct Object References …
CVE-2026-486157.534.8nodejsnodeCWE-359A flaw in Node.js proxy tunnel error handling could expose proxy credentials …
CVE-2026-454089.034.6dokkudokkuCWE-78Dokku: OS Command Injection via App Name in Git Pre-Receive Hook
CVE-2026-560088.834.5ThemeFusionFusion BuilderCWE-266WordPress Fusion Builder plugin <= 3.15.4 - Privilege Escalation vulnerability
CVE-2026-560108.834.5Tyche Softwares.Abandoned Cart Pro for WooCommerceCWE-266WordPress Abandoned Cart Pro for WooCommerce plugin <= 10.4.0 - Privilege Esc…
CVE-2026-560388.834.5FrisbiiFrisbii PayCWE-862WordPress Frisbii Pay plugin <= 1.8.2 - Privilege Escalation vulnerability
CVE-2026-548247.534.3Ads WPQuadsAds by WPQuadsCWE-497WordPress Ads by WPQuads plugin <= 3.0.3 - Sensitive Data Exposure vulnerability
CVE-2026-548347.534.3fpuenteonlineObject Cache 4 everyoneCWE-201WordPress Object Cache 4 everyone plugin <= 2.3.2 - Sensitive Data Exposure v…
CVE-2026-560607.534.3tychesoftwaresPrint Invoice & Delivery Notes for WooCommerceCWE-497WordPress Print Invoice & Delivery Notes for WooCommerce plugin <= 7.1.1 - Se…
CVE-2026-579127.534.3Johnson & JohnsonCampus RecruitingCWE-602Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data …
CVE-2026-579137.534.3Johnson & JohnsonAudit Tracking Management SystemCWE-602Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 a…
CVE-2026-499918.634.3rustfsrustfsCWE-22RustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injec…
CVE-2026-501378.234.3BudibasebudibaseCWE-862Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets…
CVE-2026-08287.533.7SafeticaEndpoint Client—Kernel driver vulnerability in Safetica Endpoint Client
CVE-2026-573217.133.7icc0rzH5PCWE-22WordPress H5P plugin <= 1.17.7 - Arbitrary File Deletion vulnerability
CVE-2025-119199.633.6Wolfram Research Inc.Cloud—Unprotected temporary directories in Wolfram Cloud may result in privilege es…
CVE-2026-484977.533.4envoyproxyenvoyCWE-480Envoy: Abnormal process termination in DNS UDP filter
CVE-2026-548209.332.9Crocoblock. Jetimpex Inc.JetBookingCWE-89WordPress JetBooking plugin <= 4.0.4.1 - SQL Injection vulnerability
CVE-2026-548259.332.9wpDataTableswpDataTablesCWE-89WordPress wpDataTables plugin <= 7.4 - SQL Injection vulnerability
CVE-2026-548279.332.9contempoincReal Estate 7CWE-89WordPress Real Estate 7 theme <= 3.5.9 - SQL Injection vulnerability
CVE-2026-548319.332.9PaoloGeoDirectoryCWE-89WordPress GeoDirectory plugin <= 2.8.162 - SQL Injection vulnerability
CVE-2026-560349.332.9Online Web TutorLibrary Management SystemCWE-89WordPress Library Management System plugin <= 3.5.7 - SQL Injection vulnerabi…
CVE-2026-560369.332.9codemstory워드프레스 결제 심플페이CWE-89WordPress 워드프레스 결제 심플페이 plugin <= 5.5.6 - SQL Injection vulnerability
CVE-2026-560629.332.9oooorgleQuotes llamaCWE-89WordPress Quotes llama plugin <= 3.1.5 - SQL Injection vulnerability
CVE-2026-560679.332.9Crocoblock. Jetimpex Inc.JetSmartFiltersCWE-89WordPress JetSmartFilters plugin <= 3.8.3 - SQL Injection vulnerability
CVE-2026-560689.332.9Crocoblock. Jetimpex Inc.JetEngineCWE-89WordPress JetEngine plugin <= 3.8.10.2 - SQL Injection vulnerability
CVE-2026-560709.332.9ThemeHunkAdvance Product SearchCWE-89WordPress Advance Product Search plugin <= 1.4.4 - SQL Injection vulnerability
CVE-2026-205310.032.2WSO2WSO2 API ManagerCWE-918Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API Man…
CVE-2026-548377.532.2Syed BalkhiIntranet &amp; Private Site &#8211; All-In-One IntranetCWE-862WordPress Intranet & Private Site – All-In-One Intranet plugin <= 1.8.1 - Bro…
CVE-2026-548397.532.2kingaddonsTrinity Backup &#8211; Backup, Migrate, Restore, Clone &amp; Schedule BackupsCWE-639WordPress Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups…
CVE-2026-548467.532.2akosglysSyncee Premium Dropshipping &amp; WholesaleCWE-862WordPress Syncee Premium Dropshipping & Wholesale plugin <= 1.0.27 - Broken A…
CVE-2026-548477.532.2DesignStylish Cost CalculatorCWE-862WordPress Stylish Cost Calculator plugin <= 8.3.9 - Broken Access Control vul…
CVE-2026-447366.532.1opfopenprojectCWE-200OpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Pr…
CVE-2026-568768.631.9max-mapperextract-zipCWE-22extract-zip unvalidated symlink path traversal
CVE-2026-527809.631.8opfopenprojectCWE-20OpenProject: Cache store poisoning leads to Remote Code Execution (RCE)
CVE-2026-564148.631.6H.VIEWHV-500S6 IP CameraCWE-434H.VIEW HV-500S6 IP Camera Unrestricted Upload of File with Dangerous Type
CVE-2025-102685.331.6UnknownPrintcart Web to Print Product Designer for WooCommerce—Printcart Web to Print Product Designer for WooCommerce <= 2.4.8 - Unauthenti…
CVE-2026-579402.131.6danprosHTMLyCWE-918HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in th…
CVE-2026-472055.931.5envoyproxyenvoyCWE-416Envoy: ext_authz Use-After-Free during Stream Teardown with Per-Route Overrides
CVE-2026-576287.631.0WP All ImportWP All ImportCWE-89WordPress WP All Import plugin <= 4.0.1 - SQL Injection vulnerability
CVE-2026-576317.631.0Ays ProPopup boxCWE-89WordPress Popup box plugin <= 6.0.1 - SQL Injection vulnerability
CVE-2026-507405.431.0ReviveAdserverCWE-79A missing sanitisation vulnerability of user input in the zone-include.php sc…
CVE-2025-323945.330.9Significant-GravitasAutoGPTCWE-405AutoGPT: There is a DoS vulnerability in AITextSummarizerBlock
CVE-2025-324235.330.9Significant-GravitasAutoGPTCWE-770AutoGPT: There is a DoS vulnerability in ExtractTextInformationBlock
CVE-2026-507456.130.7ReviveAdserverCWE-79A missing sanitisation vulnerability exists with user input in the stats-vide…
CVE-2026-560358.630.5Cory MarshBitFire SecurityCWE-1284WordPress BitFire Security plugin <= 5.0.3 - Multiple Vulnerabilities vulnera…
CVE-2026-527859.930.5opfopenprojectCWE-89OpenProject: SQL injection in timestamps functionality
CVE-2026-579207.730.5PeplinkInControlCWE-551Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolo…
CVE-2026-556865.330.1podman-container-toolspodmanCWE-61Podman: WORKDIR symlink traversal vulnerability
CVE-2026-472147.130.1docling-projectdoclingCWE-73Docling: Unsafe URI and Path Handling in HTML Backend
CVE-2026-566638.530.0Significant-GravitasAutoGPTCWE-918AutoGPT: SSRF-to-RCE Chain in `SendWebRequestBlock` via IP validation bypass …
CVE-2026-573166.529.8RoxnorGetGenieCWE-497WordPress GetGenie plugin <= 4.4.2 - Sensitive Data Exposure vulnerability
CVE-2026-573186.529.8Gemini LabsSite ReviewsCWE-201WordPress Site Reviews plugin <= 8.0.11 - Sensitive Data Exposure vulnerability
CVE-2026-295095.329.9wummelpatoolCWE-22Patool < 4.0.5 Path Traversal via safe_extract() Function
CVE-2026-447356.529.7opfopenprojectCWE-863OpenProject: Shares API Information Disclosure
CVE-2026-108357.729.2UnknownSALESmanago & Leadoo—SALESmanago & Leadoo < 3.11.3 - Subscriber+ SQL Injection
CVE-2026-117795.329.1PayloadCMSPayloadCMSCWE-307PayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlo…
CVE-2026-533228.828.8LinuxLinuxCWE-415vfio/pci: Clean up DMABUFs before disabling function
CVE-2026-560648.528.4ThemeficTourficCWE-89WordPress Tourfic plugin <= 2.22.5 - SQL Injection vulnerability
CVE-2026-576368.528.4TomdeverwpForo ForumCWE-89WordPress wpForo Forum plugin <= 3.0.9 - SQL Injection vulnerability
CVE-2026-576428.528.4bestwebsoftGalleryCWE-89WordPress Gallery plugin <= 4.7.8 - SQL Injection vulnerability
CVE-2026-576438.528.4AF themesWP Post AuthorCWE-89WordPress WP Post Author plugin <= 3.9.1 - SQL Injection vulnerability
CVE-2026-576448.528.4jetmonstersRestaurant Menu by MotoPressCWE-89WordPress Restaurant Menu by MotoPress plugin <= 2.4.10 - SQL Injection vulne…
CVE-2026-576538.528.4wpjobportalWP Job PortalCWE-89WordPress WP Job Portal plugin <= 2.5.2 - SQL Injection vulnerability
CVE-2026-576628.528.4Wasiliy StreckerContest GalleryCWE-89WordPress Contest Gallery plugin <= 30.0.0 - SQL Injection vulnerability
CVE-2026-576638.528.4Igor BenicRecipe Maker For Your Food Blog from Zip RecipesCWE-89WordPress Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.2.7 - …
CVE-2026-576678.528.4Adrian TobeyGroundhoggCWE-89WordPress Groundhogg plugin <= 4.5 - SQL Injection vulnerability
CVE-2026-578737.527.3GeoVision Inc.GV-LPCLPC2011/2211CWE-476GV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability (IEE…
CVE-2026-576458.127.2Tribulant SoftwareNewslettersCWE-862WordPress Newsletters plugin <= 4.13 - Broken Access Control vulnerability
CVE-2026-548327.527.2JegstudioGutenverse CompanionCWE-862WordPress Gutenverse Companion plugin <= 2.5.0 - Broken Access Control vulner…
CVE-2026-548357.527.2RustauriusFive Star Restaurant MenuCWE-862WordPress Five Star Restaurant Menu plugin <= 2.5.2 - Broken Access Control v…
CVE-2026-560257.527.2PaymobPaymob for WooCommerceCWE-862WordPress Paymob for WooCommerce plugin <= 4.1.2 - Broken Access Control vuln…
CVE-2026-560617.527.2WP SwingsSubscriptions for WooCommerceCWE-862WordPress Subscriptions for WooCommerce plugin <= 1.9.5 - Broken Access Contr…
CVE-2026-466047.526.7golang.org/x/imagegolang.org/x/image/tiffCWE-787Panic decoding image with out-of-bounds strip offset in x/image/tiff in golan…
CVE-2026-507425.426.8ReviveAdserverCWE-79A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `m…
CVE-2026-551897.726.5rustfsrustfsCWE-862RustFS: FTP frontend skips IAM authorization on object reads
CVE-2026-579269.826.2JetBrainsYouTrackCWE-1321In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerabl…
CVE-2026-539149.825.7JetBrainsKotlinCWE-502In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe dese…
CVE-2026-560486.525.6tychesoftwaresPayment Gateway Based Fees and Discounts for WooCommerceCWE-639WordPress Payment Gateway Based Fees and Discounts for WooCommerce plugin <= …
CVE-2026-573246.525.6VillaThemeGIFT4UCWE-862WordPress GIFT4U plugin <= 1.0.10 - Broken Access Control vulnerability
CVE-2025-646375.325.3Opal_WPAuros CoreCWE-80WordPress Auros Core plugin <= 5.3.1 - Content Injection vulnerability
CVE-2026-576335.325.3WCBoostWCBoost &#8211; Products CompareCWE-497WordPress WCBoost &#8211; Products Compare plugin <= 1.1.0 - Sensitive Data E…
CVE-2026-447346.524.9opfopenprojectCWE-862OpenProject: Improper Access Control on OpenProject through the POST request …
CVE-2026-489309.824.7nodejsnodeCWE-284A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can …
CVE-2026-548337.424.6Dev KabirEnable CORSCWE-321WordPress Enable CORS plugin <= 2.0.3 - Backdoor vulnerability
CVE-2026-560279.924.1PluggablBooster for WooCommerceCWE-434WordPress Booster for WooCommerce plugin <= 8.0.1 - Arbitrary File Upload vul…
CVE-2026-573235.823.4bPluginsFlash & HTML5 VideoCWE-862WordPress Flash & HTML5 Video plugin <= 2.11.0 - Broken Access Control vulner…
CVE-2025-661235.323.4About EnvatoBookProCWE-639WordPress BookPro plugin <= 1.1.0 - Insecure Direct Object References (IDOR) …
CVE-2026-576305.323.4Creative ThemesBlocksy Companion ProCWE-639WordPress Blocksy Companion Pro plugin <= 2.1.46 - Insecure Direct Object Ref…
CVE-2026-576525.323.4JoomSkyJS Help DeskCWE-639WordPress JS Help Desk plugin <= 3.1.0 - Insecure Direct Object References (I…
CVE-2026-576655.323.4GravityKitGravityViewCWE-639WordPress GravityView plugin <= 3.0.0 - Insecure Direct Object References (ID…
CVE-2026-572317.523.3podman-container-toolspodmanCWE-200Podman: Malformed Image can trick podman run into leaking host environment va…
CVE-2026-527795.423.4opfopenprojectCWE-639OpenProject: Cross-project authorization bypass allows deleting public Calend…
CVE-2026-548267.623.1PSM PluginsSupportCandyCWE-639WordPress SupportCandy plugin <= 3.4.6 - Insecure Direct Object References (I…
CVE-2026-507656.123.2n/an/aCWE-79A stored cross-site scripting (XSS) vulnerability in the patron restriction t…
CVE-2025-79587.123.0TrellixTrellix Network Security NX, EX, FX, AX, and CMSCWE-94A Code Injection vulnerability existed in Trellix Network Security CM and NX.…
CVE-2026-446965.722.2opfopenprojectCWE-79OpenProject: Stored CSS injection via Sanitize::Config::RELAXED[:css] enables…
CVE-2026-560638.322.1bPluginsMailChimp BlockCWE-862WordPress MailChimp Block plugin <= 1.1.15 - Broken Access Control vulnerability
CVE-2026-548407.322.1Tribulant SoftwareNewslettersCWE-862WordPress Newsletters plugin <= 4.13 - Broken Access Control vulnerability
CVE-2026-18696.522.1wpeverestUser Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login BuilderCWE-862User Registration & Membership <= 5.2.0 - Missing Authorization to Unauthenti…
CVE-2026-579217.522.0JetBrainsYouTrackCWE-862In JetBrains YouTrack before 2026.2.16593 improper access control allowed rea…
CVE-2026-576546.522.0wp.insiderAffiliates ManagerCWE-862WordPress Affiliates Manager plugin <= 2.9.49 - Broken Access Control vulnera…
CVE-2026-487437.521.8envoyproxyenvoyCWE-444Envoy: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonze…
CVE-2026-551888.221.7rustfsrustfsCWE-200RustFS: ListRemoteTargetHandler authorization bypass leaks replication target…
CVE-2026-576644.321.4VillaThemeBopo – WooCommerce Product Bundle BuilderCWE-497WordPress Bopo – WooCommerce Product Bundle Builder plugin <= 1.1.6 - Sensiti…
CVE-2025-646365.321.4rhewlifDonation ThermometerCWE-862WordPress Donation Thermometer plugin <= 2.2.7 - Broken Access Control vulner…
CVE-2026-245475.321.4SiteGroundSiteGround Email MarketingCWE-862WordPress SiteGround Email Marketing plugin <= 1.7.5 - Broken Access Control …
CVE-2026-576605.321.4magepeopleteamBooking and Rental ManagerCWE-862WordPress Booking and Rental Manager plugin <= 2.7.1 - Broken Access Control …
CVE-2026-447314.321.3opfopenprojectCWE-639OpenProject: Improper Access Control on OpenProject through /projects/[projec…
CVE-2026-493554.321.3opfopenprojectCWE-200OpenProject: Private work package data disclosure through single meeting agen…
CVE-2026-507444.321.2ReviveAdserverCWE-284A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver …
CVE-2026-134265.421.0Mattermostgithub.com/mattermost/mattermost/server/publicCWE-22Client4 fails to validate path parameters
CVE-2026-501365.321.0BudibasebudibaseCWE-306Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary wr…
CVE-2026-124119.620.8CanonicallxdCWE-639Broken Access Control in Canonical LXD DevLXD API
CVE-2025-630415.420.7Code AmpForget About Shortcode ButtonsCWE-862WordPress Forget About Shortcode Buttons plugin <= 2.1.3 - Broken Access Cont…
CVE-2026-576325.420.7OmnisendEmail Marketing for WooCommerce by OmnisendCWE-862WordPress Email Marketing for WooCommerce by Omnisend plugin <= 1.19.0 - Brok…
CVE-2026-576615.420.7NexcessWPCompleteCWE-862WordPress WPComplete plugin <= 2.9.5.5 - Broken Access Control vulnerability
CVE-2026-447335.920.0opfopenprojectCWE-620OpenProject: Business Logic Error on OpenProject through PATCH request to /ap…
CVE-2026-283855.019.7CanonicallxdCWE-918SSRF via image import from URL allows internal network probing by authenticat…
CVE-2026-507665.419.6n/an/aCWE-79A stored cross-site scripting (XSS) vulnerability in the OPAC item detail pag…
CVE-2026-507675.419.6n/an/aCWE-79A stored cross-site scripting (XSS) vulnerability in the item type administra…
CVE-2026-447324.319.5opfopenprojectCWE-639OpenProject: IDOR on OpenProject through /api/v3/documents/{id} via PATCH par…
CVE-2026-579245.319.1JetBrainsYouTrackCWE-276In JetBrains YouTrack before 2026.2.16593 default role configuration exposed …
CVE-2026-579255.319.1JetBrainsYouTrackCWE-862In JetBrains YouTrack before 2026.2.16593 improper access control allowed rea…
CVE-2026-34723.518.8MattermostMattermostCWE-693Markdown image rendering bypass in AI bot tool result posts in Mattermost
CVE-2025-630794.318.7bdthemesLive Copy Paste for ElementorCWE-862WordPress Live Copy Paste for Elementor plugin <= 1.5.3 - Broken Access Contr…
CVE-2026-558384.318.7rustfsrustfsCWE-862RustFS: Missing admin authorization on /rustfs/admin/v3/metrics allows any au…
CVE-2026-576224.318.7ArrayticsWPCafeCWE-862WordPress WPCafe plugin <= 3.0.14 - Broken Access Control vulnerability
CVE-2026-576494.318.7studiowombatShoppable Images LiteCWE-862WordPress Shoppable Images Lite plugin <= 1.3 - Broken Access Control vulnera…
CVE-2026-579237.518.1JetBrainsYouTrackCWE-862In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app c…
CVE-2026-527016.518.1ThemegrillUser RegistrationCWE-862WordPress User Registration plugin <= 5.2.2 - Broken Access Control vulnerabi…
CVE-2026-489344.317.0nodejsnodeCWE-295A flaw in Node.js TLS host verification can cause an attacker to bypass certi…
CVE-2025-630784.316.6jetmonstersRestaurant Menu by MotoPressCWE-862WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Broken Access Contr…
CVE-2026-574304.316.6SEOPress FreeSEOPress PROCWE-862WordPress SEOPress PRO plugin <= 9.1.1 - Broken Access Control vulnerability
CVE-2026-576344.316.6WP Folio TeamPPWPCWE-639WordPress PPWP plugin <= 1.9.19 - Insecure Direct Object References (IDOR) vu…
CVE-2026-576404.316.6StylemixMasterStudy LMSCWE-862WordPress MasterStudy LMS plugin <= 3.7.30 - Broken Access Control vulnerability
CVE-2026-576484.316.6Nelio SoftwareNelio ContentCWE-862WordPress Nelio Content plugin <= 4.3.4 - Broken Access Control vulnerability
CVE-2026-560117.116.3chrisvrichardsonMapPress Maps for WordPressCWE-79WordPress MapPress Maps for WordPress plugin <= 2.97.3 - Cross Site Scripting…
CVE-2026-560397.116.3WordPress.comQuick Interest SliderCWE-79WordPress Quick Interest Slider plugin <= 3.1.6 - Reflected Cross Site Script…
CVE-2026-560407.116.3WordPress.comGutenverse FormCWE-79WordPress Gutenverse Form plugin <= 2.4.7 - Cross Site Scripting (XSS) vulner…
CVE-2026-560417.116.3dFactoryResponsive LightboxCWE-79WordPress Responsive Lightbox plugin <= 2.7.6 - Cross Site Scripting (XSS) vu…
CVE-2026-560437.116.3CusRevCustomer Reviews for WooCommerceCWE-79WordPress Customer Reviews for WooCommerce plugin <= 5.110.1 - Cross Site Scr…
CVE-2026-560447.116.3AdenionBlog2SocialCWE-79WordPress Blog2Social plugin <= 8.9.2 - Cross Site Scripting (XSS) vulnerability
CVE-2026-560457.116.3ValvePressAutomaticCWE-79WordPress Automatic plugin < 3.135.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-560477.116.3Perfmatters, Powered Kinsta + GeneratePress Docs Changelog Feature requests Legal Affiliate ContactperfmattersCWE-79WordPress perfmatters plugin <= 2.6.3 - Reflected Cross Site Scripting (XSS) …
CVE-2026-560727.116.3XtemosWoodMartCWE-79WordPress WoodMart theme <= 8.5.3 - Cross Site Scripting (XSS) vulnerability
CVE-2026-573127.116.2wpeverestEverest FormsCWE-79WordPress Everest Forms plugin <= 3.4.8 - Reflected Cross Site Scripting (XSS…
CVE-2026-573147.116.3SureCartSureCartCWE-79WordPress SureCart plugin <= 4.3.2 - Reflected Cross Site Scripting (XSS) vul…
CVE-2026-573177.116.3NSquaredSimply Schedule AppointmentsCWE-79WordPress Simply Schedule Appointments plugin <= 1.6.12.2 - Cross Site Script…
CVE-2026-573197.116.3RealMag777FOXCWE-79WordPress FOX plugin <= 1.4.8 - Cross Site Scripting (XSS) vulnerability
CVE-2026-573227.116.3weDevsweMailCWE-79WordPress weMail plugin <= 2.1.2 - Reflected Cross Site Scripting (XSS) vulne…
CVE-2026-573257.116.3JellywpNanoMagCWE-79WordPress NanoMag theme <= 1.8 - Cross Site Scripting (XSS) vulnerability
CVE-2026-527816.416.2opfopenprojectCWE-79OpenProject: Stored XSS on openproject.example.com through /api/v3/projects/{…
CVE-2026-568235.416.1Significant-GravitasAutoGPTCWE-284AutoGPT: IDOR in Webhook Ping Endpoint Allows Enumeration and Cross-User Ping…
CVE-2026-86614.815.5Rapid7InsightConnect Markdown PluginCWE-79Server-Side Cross-Site Scripting and SSRF in Rapid7 InsightConnect Markdown t…
CVE-2026-550698.715.3kestra-iokestraCWE-916Kestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force Attack
CVE-2026-134344.915.4Red HatRed Hat OpenShift Virtualization 4CWE-20Virt-controller-rhel9: kubevirt: kubevirt: multus default-network annotation …
CVE-2026-527848.814.9opfopenprojectCWE-352OpenProject: CSRF on TARGET through /users/:id via POST parameter "user[admin]"
CVE-2026-576565.914.9peregrinethemesHester CoreCWE-79WordPress Hester Core plugin <= 1.1.8 - Cross Site Scripting (XSS) vulnerability
CVE-2026-579225.314.6JetBrainsYouTrackCWE-862In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the…
CVE-2026-560266.413.6Chris Carlevatoutm.codesCWE-918WordPress utm.codes plugin <= 1.9.0 - Server Side Request Forgery (SSRF) vuln…
CVE-2026-576465.413.6Majestic SupportMajestic SupportCWE-639WordPress Majestic Support plugin <= 1.1.7 - Insecure Direct Object Reference…
CVE-2026-574735.813.4ReolinkHome HubCWE-1391A vulnerability exists in the netclient and factory services of Reolink Home …
CVE-2026-66585.413.2jupyterjupyter/jupyterCWE-79Cross-site Scripting (XSS) in jupyter/nbconvert
CVE-2025-680746.512.9GhozyLabImage CarouselCWE-79WordPress Image Carousel plugin <= 1.0.0.41 - Cross Site Scripting (XSS) vuln…
CVE-2025-680756.512.9KerryBNE TestimonialsCWE-79WordPress BNE Testimonials plugin <= 2.0.8 - Cross Site Scripting (XSS) vulne…
CVE-2026-560466.512.9CridioStudioListingProCWE-79WordPress ListingPro theme <= 2.9.11 - Cross Site Scripting (XSS) vulnerability
CVE-2026-573136.512.9SureCartSureCartCWE-79WordPress SureCart plugin <= 4.2.2 - Cross Site Scripting (XSS) vulnerability
CVE-2026-574316.512.9Mervin PraisonFeatured ImageCWE-79WordPress Featured Image plugin <= 2.1 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-576176.512.9SeedProd LLC.SeedProd ProCWE-79WordPress SeedProd Pro plugin < 6.19.5 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-576186.512.9ThemeisleNeve PROCWE-79WordPress Neve PRO theme <= 3.1.2 - Cross Site Scripting (XSS) vulnerability
CVE-2026-576206.512.9Tim StriflerExclusive Addons ElementorCWE-79WordPress Exclusive Addons Elementor plugin <= 2.7.9.8 - Cross Site Scripting…
CVE-2026-576296.512.9StatCounterStatCounterCWE-79WordPress StatCounter plugin <= 2.1.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-576386.512.9WPManageNinja LLCFluent BookingCWE-79WordPress Fluent Booking plugin <= 2.1.0 - Cross Site Scripting (XSS) vulnera…
CVE-2026-576506.512.9BlockArtMagazine BlocksCWE-79WordPress Magazine Blocks plugin <= 1.8.3 - Cross Site Scripting (XSS) vulner…
CVE-2026-576516.512.9nKGhost KitCWE-79WordPress Ghost Kit plugin <= 3.6.0 - Cross Site Scripting (XSS) vulnerability
CVE-2026-477756.812.2envoyproxyenvoyCWE-209Envoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie Decryption
CVE-2026-476924.312.1envoyproxyenvoyCWE-130Envoy: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB…
CVE-2026-489285.411.8nodejsnodeCWE-284A inconsistency in Node.js hostname matching can cause a trust-policy bypass …
CVE-2026-543537.111.4BudibasebudibaseCWE-367Budibase: Potential SSRF DNS rebinding bypass in outbound fetch validation
CVE-2026-477784.411.4envoyproxyenvoyCWE-158Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate …
CVE-2026-488007.810.9notepad-plus-plusnotepad-plus-plusCWE-78Notepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injection
CVE-2026-528847.810.8notepad-plus-plusnotepad-plus-plusCWE-42Notepad++: CVE-2026-48800 Bypass
CVE-2026-485296.010.4githubgithub-mcp-serverCWE-284GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user G…
CVE-2025-680528.89.8Eagle-ThemesEagle BookingCWE-352WordPress Eagle Booking plugin <= 1.3.4.3 - Cross Site Request Forgery (CSRF)…
CVE-2026-576598.89.8Stranger StudiosPaid Memberships Pro - Add Member From AdminCWE-352WordPress Paid Memberships Pro - Add Member From Admin plugin <= 0.7.2 - Cros…
CVE-2026-527838.29.7opfopenprojectCWE-313OpenProject: Information Disclosure (cleartext storage of data) on localhost …
CVE-2026-579187.19.2sahlberglibnfsCWE-191libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVE…
CVE-2026-501327.38.9BudibasebudibaseCWE-284Budibase: Chat Identity Link Hijacking via Missing Consent & CSRF — Account I…
CVE-2026-576274.98.4ThemeumKirkiCWE-918WordPress Kirki plugin <= 6.0.11 - Server Side Request Forgery (SSRF) vulnera…
CVE-2026-489353.38.1nodejsnodeCWE-276A flaw in Node.js Permission API can cause a file metadata to be modified eve…
CVE-2026-554418.68.0jdxmiseCWE-78mise: Arbitrary command execution via task-include files in an untrusted, con…
CVE-2026-369085.58.0n/an/aCWE-121A stack overflow in the AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity compon…
CVE-2026-452577.87.1FreeBSDFreeBSDCWE-123Arbitrary file overwrite via the KTLS receive path
CVE-2026-532947.87.1LinuxLinuxCWE-415mailbox: mailbox-test: don't free the reused channel
CVE-2026-532967.87.1LinuxLinuxCWE-416mailbox: mailbox-test: free channels on probe error
CVE-2026-576416.56.9ContempoincReal Estate 7CWE-352WordPress Real Estate 7 theme <= 3.5.9 - Cross Site Request Forgery (CSRF) vu…
CVE-2026-545575.56.9jdxmiseCWE-22mise HTTP backend uses raw version path for install symlink destination
CVE-2026-533205.56.7LinuxLinux—nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty()
CVE-2026-532867.86.3LinuxLinuxCWE-415idpf: fix double free and use-after-free in aux device error paths
CVE-2026-532907.86.3LinuxLinuxCWE-416drm/xe/eustall: Fix drm_dev_put called before stream disable in close
CVE-2026-533007.86.3LinuxLinuxCWE-416net: enetc: fix NTMP DMA use-after-free issue
CVE-2026-576558.26.1Jay VersluisChild Theme WizardCWE-352WordPress Child theme Wizard plugin <= 1.4 - Cross Site Request Forgery (CSRF…
CVE-2026-533037.16.1LinuxLinuxCWE-125f2fs: protect extension_list reading with sb_lock in f2fs_sbi_show()
CVE-2026-576356.56.1FunnelKitFunnelKit Payment Gateway for Stripe WooCommerceCWE-352WordPress FunnelKit Payment Gateway for Stripe WooCommerce plugin <= 1.14.0.3…
CVE-2026-369075.55.7n/an/aCWE-121A stack overflow in the AP4_StsdAtom::AP4_StsdAtom component of axiomatic-sys…
CVE-2026-217347.75.5Imagination TechnologiesGraphics DDKCWE-823GPU DDK - libusc OOB write at TreeRemove during WebGPU shader compilation
CVE-2026-532795.55.6LinuxLinux—drm/gma500/oaktrail_lvds: fix hang on init failure
CVE-2026-532875.55.6LinuxLinux—audit: fix incorrect inheritable capability in CAPSET records
CVE-2026-532885.55.6LinuxLinuxCWE-674arm64: Reserve an extra page for early kernel mapping
CVE-2026-532895.55.6LinuxLinuxCWE-476ice: fix NULL pointer dereference in ice_reset_all_vfs()
CVE-2026-532915.55.6LinuxLinuxCWE-476ALSA: hda/conexant: Fix missing error check for jack detection
CVE-2026-532955.55.6LinuxLinux—mailbox: add sanity check for channel array
CVE-2026-532985.55.6LinuxLinuxCWE-476net: airoha: Move ndesc initialization at end of airoha_qdma_init_rx_queue()
CVE-2026-533145.55.6LinuxLinux—padata: Put CPU offline callback in ONLINE section to allow failure
CVE-2026-533175.55.5LinuxLinux—wifi: mt76: mt7921: Place upper limit on station AID
CVE-2026-533185.55.5LinuxLinuxCWE-476wifi: mt76: mt7925: prevent NULL pointer dereference in mt7925_tx_check_aggr()
CVE-2026-440187.15.5docling-projectdoclingCWE-409Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
CVE-2026-532825.55.4LinuxLinux—x86/kexec: Push kjump return address even for non-kjump kexec
CVE-2026-532835.55.4LinuxLinuxCWE-476iommu/amd: Bounds-check devid in __rlookup_amd_iommu()
CVE-2026-532995.55.4LinuxLinuxCWE-476net: airoha: Move ndesc initialization at end of airoha_qdma_init_tx()
CVE-2026-533015.55.4LinuxLinuxCWE-476reset: amlogic: t7: Fix null reset ops
CVE-2026-533025.55.4LinuxLinuxCWE-476crypto: eip93 - fix hmac setkey algo selection
CVE-2026-533055.55.4LinuxLinuxCWE-476usb: typec: ps883x: Fix Oops at unbind
CVE-2026-533075.55.4LinuxLinuxCWE-476pinctrl: pinconf-generic: Fully validate 'pinmux' property
CVE-2026-533105.55.4LinuxLinux—soc/tegra: cbb: Fix cross-fabric target timeout lookup
CVE-2026-533115.55.4LinuxLinuxCWE-908fuse: fix uninit-value in fuse_dentry_revalidate()
CVE-2026-533125.55.4LinuxLinuxCWE-835iommu/riscv: Remove overflows on the invalidation path
CVE-2026-533215.55.4LinuxLinux—io_uring/napi: cap busy_poll_to 10 msec
CVE-2026-554486.35.2jdxmiseCWE-78mise: Local credential_command executes untrusted config
CVE-2023-205725.64.7AMDAMD Athlon™ 3000 Series Mobile Processors with Radeon™ GraphicsCWE-208An observable timing discrepancy in the ASP could allow a privileged attacker…
CVE-2026-385714.64.7n/an/aCWE-312Cleartext storage and exposure of WPA2 credentials, and missing authenticatio…
CVE-2023-205401.84.7AMDAMD Ryzen™ 3000 Series Desktop ProcessorsCWE-208An observable timing discrepancy in the ASP could allow a privileged attacker…
CVE-2026-467107.54.5notepad-plus-plusnotepad-plus-plusCWE-426Notepad++: Privilege Escalation in the Installer via Uncontrolled Executable …
CVE-2026-87978.54.3NEC CorporationExpressUpdate Agent for WindowsCWE-782An access control deficiency vulnerability exists in ExpressUpdate Agent for …
CVE-2026-451957.83.9Imagination TechnologiesGraphics DDKCWE-280GPU DDK - rgxfw_set_mips_fault_address(&psInit->sFaultPhysAddr) is untrusted
CVE-2026-532785.53.8LinuxLinuxCWE-476arm_mpam: Check whether the config array is allocated before destroying it
CVE-2026-532805.53.8LinuxLinuxCWE-476iommu: Fix NULL group->domain dereference in pci_dev_reset_iommu_done()
CVE-2026-532855.53.8LinuxLinuxCWE-617drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTIO…
CVE-2026-532925.53.8LinuxLinuxCWE-617net: phonet: do not BUG_ON() in pn_socket_autobind() on failed bind
CVE-2026-533085.53.8LinuxLinuxCWE-401power: supply: max77705: Free allocated workqueue and fix removal order
CVE-2026-533135.53.8LinuxLinuxCWE-476drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths
CVE-2026-533155.53.8LinuxLinuxCWE-476drm/amd/ras: Fix NULL deref in ras_core_get_utc_second_timestamp()
CVE-2026-533165.53.8LinuxLinuxCWE-476drm/amd/ras: Fix NULL deref in ras_core_ras_interrupt_detected()
CVE-2026-533195.53.8LinuxLinuxCWE-617blk-wbt: remove WARN_ON_ONCE from wbt_init_enable_default()
CVE-2026-487705.03.7notepad-plus-plusnotepad-plus-plusCWE-125Notepad++ WM_COPYDATA COPYDATA_FULL_CMDLINE local DoS crash
CVE-2026-576374.33.7tychesoftwaresAbandoned Cart Lite for WooCommerceCWE-352WordPress Abandoned Cart Lite for WooCommerce plugin <= 6.8.0 - Cross Site Re…
CVE-2026-576574.33.7Noor AlamGmail SMTPCWE-352WordPress Gmail SMTP plugin <= 1.2.3.19 - Cross Site Request Forgery (CSRF) v…
CVE-2026-43396.53.5MattermostMattermostCWE-918SSRF via unvalidated attachment URLs in Mattermost Agents plugin MCP server
CVE-2026-489363.33.2nodejsnodeCWE-284A flaw in Node.js Permission API can cause a local server to be started (via …
CVE-2026-133223.83.1Red HatRed Hat OpenShift Virtualization 4CWE-770Kubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in v…
CVE-2026-533045.53.1LinuxLinuxCWE-667scsi: sg: Resolve soft lockup issue when opening /dev/sgX
CVE-2026-532818.82.8LinuxLinuxCWE-476iommu/vt-d: Avoid NULL pointer dereference or refcount corruption
CVE-2026-528857.52.5notepad-plus-plusnotepad-plus-plusCWE-367Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memory
CVE-2026-454075.52.4dokkudokkuCWE-522Dokku: Git Credentials in .netrc Stored World-Readable Due to Premature touch
CVE-2026-532935.52.4LinuxLinuxCWE-667drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG
CVE-2026-533235.52.3LinuxLinuxCWE-667net: dsa: remove redundant netdev_lock_ops() from conduit ethtool ops
CVE-2026-533065.52.3LinuxLinuxCWE-193tty: hvc_iucv: fix off-by-one in number of supported devices
CVE-2026-452565.52.2FreeBSDFreeBSDCWE-269Missing permission check in thr_kill2(2)
CVE-2026-532975.52.1LinuxLinuxCWE-476net: mana: Guard mana_remove against double invocation
CVE-2026-533245.51.7LinuxLinuxCWE-476net: mana: Use pci_name() for debugfs directory naming
CVE-2024-235817.80.5HCLSoftwareTraveler for Microsoft OutlookCWE-347HCL Traveler for Microsoft Outlook (HTMO) is susceptible to an application mo…
CVE-2026-390315.50.5n/an/aCWE-321Lansweeper lsrunase 2.0 and lsencrypt 2.0 use RC4 encryption with a hardcoded…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-26 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.