boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Monday, June 29, 2026 · all times UTC← 2026-06-28 · archive · 2026-06-30 →

Security Box Score — June 29, 2026

232 CVEs published, led by Apple (37).

232 CVEs published June 29, 2026: 11 critical, 76 high, 101 medium, 44 low; 1 in the KEV catalog at press time; 6 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 207 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published730111762——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

528 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux513148011985450611120.17.8.0014-127 ▼
google70888386468300297760.78.1.0023+540 ▲
microsoft220756585201726286192.57.8.0045+54 ▲
red hat11520998410313200.06.5.0029+73 ▲
apple521042287228876.76.5.0032+30 ▲
canonical6202585000.05.5.0011-8 ▼
freebsd91601240000.07.8.0016+2 ▲
suse682510000.08.7.0039+4 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco102266100561150.07.3.0566+5 ▲
netgear171700161000.04.3.0024+17 ▲
palo alto networks911127113218.25.9.0022+7 ▲
ubiquiti81174003327.39.9.0083+6 ▲
ivanti49450025555.68.8.5187+2 ▲
checkpoint3915303111.17.5.0410-3 ▼
fortinet29432028333.38.3.0076+1 ▲
f56843104112.58.9.0225+4 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache111145244961103310.77.0.0052+90 ▲
mozilla49551118260900.07.3.0026+43 ▲
gitlab243105215426.54.4.0029+17 ▲
docker470520000.08.2.0016+1 ▲
drupal0511304120.05.1.0026-5 ▼
github131110000.07.0.0039-1 ▼
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2422701321161842720.78.8.0040+217 ▲
adobe1321344517721921.55.5.0021+132 ▲
ibm32811935270600.07.5.0031-17 ▼
progress591710600.07.5.0036+1 ▲
solarwinds36231010466.77.8.6082+3 ▲
veeam142200100.09.0.0052-2 ▼
zohocorp131110000.08.4.0170-1 ▼
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025-13 ▼
d-link10120525300.05.8.0058+8 ▲
siemens780440000.07.5.0020+6 ▲
rockwell automation771510000.08.7.0030+7 ▲
abb660420000.07.2.0018+6 ▲
schneider electric660420000.07.8.0042+6 ▲
moxa550320000.07.0.0029+5 ▲
dahua330111000.06.9.0036+3 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7273231391000.06.5.0024+71 ▲
sourcecodester4971003635000.05.5.0027+29 ▲
openclaw61670352210000.07.0.0021+55 ▲
edimax1465039026100.07.4.0080-30 ▼
themerex585855300000.08.1.0043+58 ▲
dell3856230240211.87.3.0017+26 ▲
itsourcecode4353001835000.02.1.0027+33 ▲
jenkins project364909391300.04.8.0025+23 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9991100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-20230.882099.88.6
CVE-2026-34910.874799.710.0
CVE-2026-34908.851999.710.0
CVE-2026-50751.837799.79.3
CVE-2026-48907.781099.510.0
CVE-2026-34909.639099.210.0
CVE-2026-49160.538398.97.5
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9991KEV
CVE-2026-3491010.0.8747KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.7810KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-5357610.0.0330
CVE-2026-5375310.0.0290
CVE-2026-4977710.0.0166
CVE-2026-4986910.0.0116
CVE-2026-1142910.0.0115
Most disclosures (vendor)
VendorCVEs
google708
linux513
oracle242
microsoft220
adobe132
red hat115
apache111
spring72
openclaw61
themerex58
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco11
apple7
google6
ivanti5
solarwinds4
berriai3
fortinet3
smartertools3
ubiquiti3
Most-affected ecosystems
EcosystemAdvisories
Maven39
Packagist15
PyPI9
npm5
Fastest to KEV
CVEVendorDays
CVE-2025-48595Google0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-28318SolarWinds0
CVE-2026-34908Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171685
CVE-2021-27102n/a2021-11-171685
CVE-2021-27101n/a2021-11-171685
CVE-2021-27103n/a2021-11-171685
CVE-2021-21017Adobe2021-11-171685
CVE-2021-28550Adobe2021-11-171685
CVE-2021-42013Apache Software Foundation2021-11-171685
CVE-2021-41773Apache Software Foundation2021-11-171685
CVE-2021-30858Apple2021-11-171685
CVE-2021-30860Apple2021-11-171685

Transactions

EXPLOIT PUBLISHED — zephyrproject zephyr: 4 CVEs (CVE-2026-7656, CVE-2026-8023, CVE-2026-10647, CVE-2026-10648). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-36848. Public exploit reference added.

DUE DATE PASSED — CVE-2026-12569 (PTC Windchill PDMLink). CISA remediation deadline was June 28, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-20230 (Cisco Unified Communications Manager). CISA remediation deadline was June 28, 2026; still in catalog.

Yesterday's Results

How to read these box scores · glossary

232 CVEs published. 25 box scores, 207 table rows — nothing truncated.

SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.5   .1238   95.9   YES
AFFECTED
  Product     Versions  Fixed
  SimpleHelp  5.5.0 –   —
TIMELINE
  May 21  Reserved by CNA
  Jun 12  Public exploit reference published
  Jun 29  Added to CISA KEV, due Jul 2
  Jun 29  Published (CNA: VulnCheck)
CWE-347 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Analyzed · KEV due July 2, 2026
D-Link DCS-935L POST Parameter setconf.cgi sub_400E40 os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0554   92.2     —
AFFECTED
  Product   Versions   Fixed
  DCS-935L  1.10.01 –  —
TIMELINE
  Jun 28  Reserved by CNA
  Jun 29  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Analyzed
Apache Tomcat: XSS in number guess example
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  L  N    6.1   .0409   89.9     —
AFFECTED
  Product        Versions     Fixed
  Apache Tomcat  11.0.0-M1 –  —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 29  Published (CNA: apache)
CWE-80 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Analyzed
gorse-io gorse — Gorse - Unauthenticated Database Dump and Restore via /api/dump and /api/restore Endpoints
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0356   88.4     —
AFFECTED
  Product  Versions     Fixed
  gorse    unspecified  0.5.10
TIMELINE
  Jun 23  Reserved by CNA
  Jun 29  Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  L    7.3   .0286   85.7     —
AFFECTED
  Product        Versions     Fixed
  Apache Tomcat  11.0.0-M1 –  —
TIMELINE
  Jun 17  Reserved by CNA
  Jun 29  Published (CNA: apache)
CWE-304 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Analyzed
openwrt luci-proto-openvpn — luci-proto-openvpn - Command Injection via cl_meta Parameter in generateKey
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0271   84.8     —
AFFECTED
  Product             Versions     Fixed
  luci-proto-openvpn  unspecified  e4ff45ecbc6ad212951815c8c99b2749fbd7de6b
TIMELINE
  Jun 26  Reserved by CNA
  Jun 29  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Deferred
openwrt luci-app-tailscale-community — luci-app-tailscale-community - Command Injection via tailscale.do_login RPC
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   H   H   H    7.7   .0228   81.8     —
AFFECTED
  Product                       Versions     Fixed
  luci-app-tailscale-community  unspecified  —
TIMELINE
  Jun 26  Reserved by CNA
  Jun 29  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
Wavlink WL-NU516U1-A POST Parameter wireless.cgi sub_401D68 command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0218   81.0     —
AFFECTED
  Product       Versions         Fixed
  WL-NU516U1-A  M16U1_V240425 –  —
TIMELINE
  Jun 28  Reserved by CNA
  Jun 29  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 10 references · NVD status: Deferred
Edimax EW-7478APC POST Request formAccept os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0199   79.1     —
AFFECTED
  Product     Versions  Fixed
  EW-7478APC  1.04 –    —
TIMELINE
  Jun 28  Reserved by CNA
  Jun 29  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Edimax EW-7478APC POST Request formiNICbasic os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0199   79.1     —
AFFECTED
  Product     Versions  Fixed
  EW-7478APC  1.04 –    —
TIMELINE
  Jun 28  Reserved by CNA
  Jun 29  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Edimax EW-7478APC POST Request formStaDrvSetup os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0199   79.1     —
AFFECTED
  Product     Versions  Fixed
  EW-7478APC  1.04 –    —
TIMELINE
  Jun 28  Reserved by CNA
  Jun 29  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
coollabsio coolify — Coolify: Authenticated Remote Code Execution via Command Injection in Destination Network Management
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0194   78.6     —
AFFECTED
  Product  Versions            Fixed
  coolify  < 4.0.0-beta.471 –  —
TIMELINE
  Mar 30  Reserved by CNA
  Jun 29  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Deferred
Apache Tomcat: Security constraints for default servlet ignored method
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  N    6.5   .0153   72.8     —
AFFECTED
  Product        Versions     Fixed
  Apache Tomcat  11.0.0-M1 –  —
TIMELINE
  Jun 17  Reserved by CNA
  Jun 29  Published (CNA: apache)
CWE-285 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Analyzed
Apple iOS and iPadOS — This issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0121   66.2     —
AFFECTED
  Product         Versions     Fixed
  iOS and iPadOS  unspecified  —
  macOS           unspecified  —
  tvOS            unspecified  —
  visionOS        unspecified  —
  watchOS         unspecified  —
TIMELINE
  Apr 7   Reserved by CNA
  Jun 29  Published (CNA: apple)
CWE-20 · CNA: apple · CVSS v3.1 · 8 references · NVD status: Modified
TP-Link Systems Inc. TL-WR841N v14 — Authenticated Stack-Based Buffer Overflow in TP-Link TL-WR841N Web Interface
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   H   N   N   N   H    6.8   .0112   63.6     —
AFFECTED
  Product        Versions     Fixed
  TL-WR841N v14  unspecified  —
TIMELINE
  May 20  Reserved by CNA
  Jun 29  Published (CNA: TPLink)
CWE-787, CWE-121 · CNA: TPLink · CVSS v4.0 · 3 references · NVD status: Analyzed
joomshaper.com Helix3 extension for Joomla — Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  N    7.5   .0099   59.9     —
AFFECTED
  Product                      Versions     Fixed
  Helix3 extension for Joomla  1.0-3.1.1 –  —
TIMELINE
  May 27  Reserved by CNA
  Jun 29  Published (CNA: Joomla)
CWE-284 · CNA: Joomla · CVSS v3.1 · 1 reference · NVD status: Analyzed
coollabsio coolify — Coolify: Authenticated Host RCE
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0098   59.5     —
AFFECTED
  Product  Versions            Fixed
  coolify  < 4.0.0-beta.470 –  —
TIMELINE
  Mar 30  Reserved by CNA
  Jun 29  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Deferred
FrontAccounting < 2.4.20 Path Traversal RCE via attachment upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0098   59.5     —
AFFECTED
  Product          Versions     Fixed
  FrontAccounting  unspecified  701fea6848da4a02fb83d30f07a9c0473d6b7e33
TIMELINE
  Apr 13  Reserved by CNA
  Jun 29  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
n/a n/a — Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0093   57.8     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 29  Public exploit reference published
  Jun 29  Published (CNA: mitre)
CWE-22 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Analyzed
Apple Safari — The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18.7.10 a…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  L  L    7.1   .0091   57.3     —
AFFECTED
  Product         Versions     Fixed
  Safari          unspecified  —
  iOS and iPadOS  unspecified  —
  macOS           unspecified  —
  tvOS            unspecified  —
  visionOS        unspecified  —
  watchOS         unspecified  —
TIMELINE
  May 1   Reserved by CNA
  Jun 29  Published (CNA: apple)
CWE-20 · CNA: apple · CVSS v3.1 · 7 references · NVD status: Modified
Apple Safari — A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2,…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0089   56.7     —
AFFECTED
  Product         Versions     Fixed
  Safari          unspecified  —
  iOS and iPadOS  unspecified  —
  macOS           unspecified  —
  tvOS            unspecified  —
  visionOS        unspecified  —
  watchOS         unspecified  —
TIMELINE
  May 1   Reserved by CNA
  Jun 29  Published (CNA: apple)
CWE-416 · CNA: apple · CVSS v3.1 · 6 references · NVD status: Modified
zephyrproject zephyr — Path traversal in Zephyr HTTP server static-filesystem resource handler allows unauthenticated remote arbitrary file read
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0087   56.1     —
AFFECTED
  Product  Versions  Fixed
  zephyr   4.0.0 –   —
TIMELINE
  May 5   Reserved by CNA
  Jun 29  Public exploit reference published
  Jun 29  Published (CNA: zephyr)
CWE-22, CWE-23 · CNA: zephyr · CVSS v3.1 · 2 references · NVD status: Modified
Tenda JD12L WifiBasicSet formWifiBasicSet stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0085   55.5     —
AFFECTED
  Product  Versions       Fixed
  JD12L    16.03.53.23 –  —
TIMELINE
  Jun 28  Reserved by CNA
  Jun 29  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Tenda JD12L addressNat fromAddressNat stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0085   55.5     —
AFFECTED
  Product  Versions       Fixed
  JD12L    16.03.53.23 –  —
TIMELINE
  Jun 28  Reserved by CNA
  Jun 29  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Tenda JD12L NatStaticSetting fromNatStaticSetting stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0085   55.5     —
AFFECTED
  Product  Versions       Fixed
  JD12L    16.03.53.23 –  —
TIMELINE
  Jun 28  Reserved by CNA
  Jun 29  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-135397.455.5WavlinkWL-NU516U1-ACWE-119Wavlink WL-NU516U1-A POST Parameter wireless.cgi sub_407504 stack-based overflow
CVE-2026-135627.454.0EdimaxEW-7478APCCWE-119Edimax EW-7478APC POST Request formiNICSiteSurvey buffer overflow
CVE-2026-135637.454.0EdimaxEW-7478APCCWE-119Edimax EW-7478APC POST Request formL2TPSetup stack-based overflow
CVE-2026-135647.454.0EdimaxEW-7478APCCWE-119Edimax EW-7478APC POST Request formPPPoESetup stack-based overflow
CVE-2026-135807.454.0EdimaxEW-7478APCCWE-119Edimax EW-7478APC POST Request formQoS buffer overflow
CVE-2026-135827.454.0EdimaxEW-7478APCCWE-119Edimax EW-7478APC POST Request formUSBAccount buffer overflow
CVE-2026-135837.454.0EdimaxEW-7478APCCWE-119Edimax EW-7478APC POST Request formUSBFolder buffer overflow
CVE-2026-131658.650.7Krajowa Izba RozliczeniowaSzafirHostCWE-434Remote Code Execution in SzafirHost
CVE-2026-534272.350.0leandrocpmdexCWE-79Cross-site scripting in MDEx via unescaped highlight_lines_class code-fence a…
CVE-2026-437076.549.9AppleSafariCWE-119A memory corruption issue was addressed with improved memory handling. This i…
CVE-2026-437456.549.6AppleSafariCWE-787An out-of-bounds write issue was addressed with improved input validation. Th…
CVE-2026-137637.949.5AWSAWS Application Load BalancerCWE-444HTTP/2 Stream Parser Confusion Body-Inspection Bypass in AWS Application Load…
CVE-2026-376379.149.0n/an/aCWE-94An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute ar…
CVE-2026-437206.548.8AppleSafariCWE-416A use-after-free issue was addressed with improved memory management. This is…
CVE-2026-135872.948.8seladbPcapPlusPlusCWE-119seladb PcapPlusPlus LightPcapNg light_pcapng.c parse_by_block_type heap-based…
CVE-2026-135465.548.6FeehiCMSCWE-287Feehi CMS REST API Endpoint articles missing authentication
CVE-2026-135285.548.3YunaiVruoyi-vue-proCWE-22YunaiV/zhijiantianya ruoyi-vue-pro AppFileController File Upload Endpoint Fil…
CVE-2026-135925.547.8liftoff-srCIPsterCWE-119liftoff-sr CIPster EtherNet IP Message append out-of-bounds write
CVE-2026-561248.747.8shimosyanphpUploaderCWE-359phpUploader < 2.0.2 Unauthenticated Database Exposure via index model
CVE-2026-137627.947.3AWSAmazon CloudFrontCWE-444HTTP/2 Stream Parser Confusion Body-Inspection Bypass in Amazon CloudFront wi…
CVE-2026-534047.347.2Apache Software FoundationApache TomcatCWE-670Apache Tomcat: Bad ornext processing in RewriteValve
CVE-2026-560187.546.5GTERMARSJavaScript::Minifier::XSCWE-400JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every c…
CVE-2026-257078.846.0SUSElibzyppCWE-23Handcrafted repo metadata may cause arbitrary local files to be overwritten b…
CVE-2026-437166.546.0AppleSafariCWE-119The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-135432.945.4n/aDocumensoCWE-287Documenso Google OAuth Login handle-oauth-callback-url.ts improper authentica…
CVE-2026-135882.945.3seladbPcapPlusPlusCWE-119seladb PcapPlusPlus TLS Hello SSLHandshake.cpp getHandshakeVersion heap-based…
CVE-2026-135892.945.3seladbPcapPlusPlusCWE-119seladb PcapPlusPlus Telnet Subnegotiation Packet TelnetLayer.cpp getSubComman…
CVE-2026-135902.945.3seladbPcapPlusPlusCWE-119seladb PcapPlusPlus Modbus Protocol ModbusLayer.h getLength heap-based overflow
CVE-2026-552769.144.3Apache Software FoundationApache TomcatCWE-670Apache Tomcat: Logged effective web.xml is incomplete
CVE-2026-556077.743.6anthropicsclaude-codeCWE-22Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxe…
CVE-2026-437017.143.6AppleSafariCWE-284The issue was addressed with improved checks. This issue is fixed in Safari 2…
CVE-2026-128568.843.5Red HatRed Hat OpenShift Dev Spaces 3.29CWE-88Vscode-java: vscode: command injection vulnerability in the javadoc hover pro…
CVE-2026-573319.943.4videowhisperPaid Videochat Turnkey SiteCWE-22WordPress Paid Videochat Turnkey Site plugin <= 7.4.8 - Arbitrary File Deleti…
CVE-2026-534349.143.2Apache Software FoundationApache TomcatCWE-390Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Conn…
CVE-2026-126166.943.0Eclipse FoundationEclipse CSI - PIACWE-117The /v1/upload/sbom endpoint extracts the iss claim from the attacker-supplie…
CVE-2026-137498.842.9SnowflakeSnowflake CLICWE-94Snowflake CLI Arbitrary Code Execution via Snowpark Annotation Processor Temp…
CVE-2026-548895.142.9leandrocpmdexCWE-79Unsanitized URL schemes in MDEx Quill Delta output allow javascript: injectio…
CVE-2026-117209.342.6GoogleMCP Toolbox for Databases (googleapis/mcp-toolbox)CWE-22Path Traversal in googleapis/mcp-toolbox HTTP Tool URL Builder
CVE-2026-437136.542.4AppleSafariCWE-284A permissions issue was addressed with additional restrictions. This issue is…
CVE-2026-135715.541.2SourceCodesterSimple Food Ordering SystemCWE-840SourceCodester Simple Food Ordering System cart.php logic error
CVE-2026-135492.141.3CodeAstroComplaint Management SystemCWE-285CodeAstro Complaint Management System Report Endpoint Report.php deletereport…
CVE-2026-135222.141.2InvestintechSlimPDFReaderCWE-119Investintech SlimPDFReader PDF File SlimPDFReader.exe TeighaDo+0x25cde0 out-o…
CVE-2026-437058.840.9AppleSafariCWE-843A type confusion issue was addressed with improved checks. This issue is fixe…
CVE-2026-135535.540.2itsourcecodeOnline Hotel Management SystemCWE-284itsourcecode Online Hotel Management System controller.php add unrestricted u…
CVE-2026-512217.539.8n/an/aCWE-284A buffer overflow in the Get_Attribute_List function of EIPStackGroup OpENer …
CVE-2026-560177.539.8GTERMARSJavaScript::Minifier::XSCWE-125JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL poin…
CVE-2026-135335.539.4agentejoCockpit CMSCWE-425agentejo Cockpit CMS htaccess config.yaml YAMLLoad file access
CVE-2026-562857.739.3zedeusnitterCWE-918Nitter - Server-Side Request Forgery in /video Media Proxy Endpoint
CVE-2026-437036.539.2AppleiOS and iPadOSCWE-125The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-437326.539.3AppleSafariCWE-22A path handling issue was addressed with improved validation. This issue is f…
CVE-2026-512197.539.0n/an/aCWE-122A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages f…
CVE-2026-405237.238.8FrontAccountingFrontAccountingCWE-89FrontAccounting < 2.4.20 SQL Injection via reporting/rep710.php
CVE-2026-405247.238.8FrontAccountingFrontAccountingCWE-89FrontAccounting < 2.4.20 SQL Injection via get_gl_transactions()
CVE-2026-135475.538.7Hanwange-Face General Management PlatformCWE-284Hanwang e-Face General Management Platform upload.do unrestricted upload
CVE-2026-135685.538.7SourceCodesterInventory Management SystemCWE-266SourceCodester Inventory Management System User Registration Endpoint users_h…
CVE-2026-135542.138.6itsourcecodeOnline Hotel Management SystemCWE-79itsourcecode Online Hotel Management System POST Request controller.php add c…
CVE-2026-135562.138.6itsourcecodeOnline Hotel Management SystemCWE-79itsourcecode Online Hotel Management System POST Request controller.php edit …
CVE-2026-135572.138.6itsourcecodeOnline Hotel Management SystemCWE-79itsourcecode Online Hotel Management System POST Request controller.php add c…
CVE-2026-135672.138.6code-projectsOnline Music SiteCWE-79code-projects Online Music Site POST Request Feedback.php cross site scripting
CVE-2026-436766.538.5AppleSafariCWE-125An out-of-bounds access issue was addressed with improved bounds checking. Th…
CVE-2026-137448.838.2SnowflakeSnowflake CLICWE-89Snowflake CLI SQL Injection Through Improper Neutralization of User-Controlle…
CVE-2026-567837.137.8parseablehqparseableCWE-522Parseable < 2.9.2 - Cleartext Credential Exposure in Notification Target API
CVE-2026-567807.737.5modoboamodoboaCWE-639Modoboa < 2.9.0 - Insecure Direct Object Reference in Account Password Change…
CVE-2026-135362.137.1n/aGotoHTTPCWE-79GotoHTTP reg.12x cross site scripting
CVE-2026-134376.536.3DevolutionsPowerShell UniversalCWE-201Insertion of sensitive information into sent data in the AI Agent job API in …
CVE-2026-579535.336.3its-a-featureMythicCWE-863Mythic < 3.4.0.60 - Unauthorized Automation Workflow Modification via eventin…
CVE-2026-437066.536.2AppleiOS and iPadOSCWE-415A double free issue was addressed with improved memory management. This issue…
CVE-2026-437216.536.2AppleSafariCWE-732This issue was addressed through improved state management. This issue is fix…
CVE-2026-559556.536.2Apache Software FoundationApache TomcatCWE-287Apache Tomcat: EncryptInterceptor not protected against replay attacks
CVE-2026-579572.336.1papermarkpapermarkCWE-942Papermark 0.22.0 - CORS Misconfiguration in Viewer Upload Endpoint
CVE-2026-579517.135.9its-a-featureMythicCWE-863Mythic < 3.4.0.60 - Broken Permission Filter in payload_build_step Table
CVE-2026-129127.335.8Red HatRed Hat Enterprise Linux 10CWE-122Libtiff: libtiff: heap-based buffer overflow via crafted pixarlog-compressed …
CVE-2026-135215.535.7SourceCodesterClass and Exam Timetabling SystemCWE-74SourceCodester Class and Exam Timetabling System preview5.php sql injection
CVE-2026-135265.535.7SourceCodesterClass and Exam Timetabling SystemCWE-74SourceCodester Class and Exam Timetabling System edit_class.php sql injection
CVE-2026-135275.535.7SourceCodesterClass and Exam Timetabling SystemCWE-74SourceCodester Class and Exam Timetabling System preview4.php sql injection
CVE-2026-135505.535.7itsourcecodeBaptism Information Management SystemCWE-74itsourcecode Baptism Information Management System delbaptism.php sql injection
CVE-2026-135515.535.7itsourcecodeBaptism Information Management SystemCWE-74itsourcecode Baptism Information Management System editBaptism.php sql injection
CVE-2026-135525.535.7itsourcecodeOnline Hotel Management SystemCWE-74itsourcecode Online Hotel Management System controller.php edit sql injection
CVE-2026-135555.535.7itsourcecodeOnline Hotel Management SystemCWE-74itsourcecode Online Hotel Management System controller.php add sql injection
CVE-2026-135595.535.7code-projectsReal State ServicesCWE-74code-projects Real State Services single-list_sale.php add sql injection
CVE-2026-135655.535.7SourceCodesterClass and Exam Timetabling SystemCWE-74SourceCodester Class and Exam Timetabling System edit_class1.php sql injection
CVE-2026-135665.535.7SourceCodesterClass and Exam Timetabling SystemCWE-74SourceCodester Class and Exam Timetabling System preview3.php sql injection
CVE-2026-579608.335.6HiEventsDevHi.EventsCWE-359Hi.Events 1.9.0 - Unauthenticated Attendee PII Exposure via Check-in List sho…
CVE-2026-437126.535.4AppleSafariCWE-125The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-579466.335.4iv-orgInvidiousCWE-862Invidious - Private Playlist Disclosure via Unauthenticated RSS Feed Endpoint
CVE-2026-135242.935.1CherryHQcherry-studioCWE-266CherryHQ cherry-studio MCP OAuth Local Callback Server callback.ts improper a…
CVE-2026-410529.435.1SUSERancherCWE-305Rancher Privilege Escalation from Project Owner to Host
CVE-2026-579508.634.0Yunairuoyi-vue-proCWE-863ruoyi-vue-pro - Incorrect Permission Namespace in ErpSaleOrderController
CVE-2026-437186.534.0AppleSafariCWE-121A stack overflow was addressed with improved input validation. This issue is …
CVE-2026-512187.533.7n/an/aCWE-122A heap buffer overflow in the TS7Worker::PerformFunctionWrite() function (/co…
CVE-2026-573467.133.7EpiphytEmbed PrivacyCWE-22WordPress Embed Privacy plugin <= 1.12.3 - Arbitrary File Deletion vulnerability
CVE-2026-437318.833.4AppleSafariCWE-416A use-after-free issue was addressed with improved memory management. This is…
CVE-2026-579497.133.0Yunairuoyi-vue-proCWE-862ruoyi-vue-pro - Missing Authorization in CRM Follow-up Record GET Endpoint
CVE-2026-437406.532.7AppleSafariCWE-119The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-137583.732.7MIKCryptXCWE-208CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in…
CVE-2026-567816.932.5teableioteableCWE-639Teable - Unauthenticated Hidden Field Disclosure via Projection Parameter Ove…
CVE-2026-436996.532.1AppleSafariCWE-416A use-after-free issue was addressed with improved memory management. This is…
CVE-2026-437346.532.1AppleSafariCWE-416A use-after-free issue was addressed with improved memory management. This is…
CVE-2026-437426.532.1AppleSafariCWE-416A use-after-free issue was addressed with improved memory management. This is…
CVE-2026-418967.531.7coollabsiocoolifyCWE-287Coolify: Unauthenticated Deployment Trigger via Webhook HMAC Bypass with Null…
CVE-2026-289796.531.7AppleSafariCWE-125An out-of-bounds access issue was addressed with improved bounds checking. Th…
CVE-2026-437045.331.7AppleSafariCWE-416A use-after-free issue was addressed with improved memory management. This is…
CVE-2026-136767.531.2fast-urifast-uriCWE-436fast-uri vulnerable to host confusion via failed IDN canonicalization
CVE-2026-574989.630.8coollabsiocoolifyCWE-639Coolify Cross-Team IDOR: Livewire Components Accept Unscoped server_id and de…
CVE-2025-73866.830.4HitachiHitachi Virtual Storage Platform 5100, 5200, 5500, 5600, 5100H, 5200H, 5500H, 5600H, VX8CWE-522Information exposure vulnerability in Hitachi Storage Navigator
CVE-2026-437084.330.1AppleSafariCWE-20The issue was addressed with improved input validation. This issue is fixed i…
CVE-2026-135402.130.2n/aGitBucketCWE-918GitBucket RepositoryCreationService.scala Git.cloneRepository.setURI server-s…
CVE-2026-135442.130.2FeehiCMSCWE-266Feehi CMS API users access control
CVE-2026-437096.529.7AppleSafariCWE-416A use-after-free issue was addressed with improved memory management. This is…
CVE-2026-437176.529.7AppleSafariCWE-416A use-after-free issue was addressed with improved memory management. This is…
CVE-2026-398726.529.5AppleSafariCWE-119The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-436636.529.5AppleSafariCWE-119The issue was addressed with improved memory handling. This issue is fixed in…
CVE-2026-135292.929.4n/aYzmCMSCWE-74YzmCMS index.php sql injection
CVE-2026-437266.528.5AppleSafariCWE-416A use-after-free issue was addressed with improved memory management. This is…
CVE-2026-579566.127.9SigNozsignozCWE-639SigNoz < 0.133.0 - Cross-Organization Insecure Direct Object Reference in Ale…
CVE-2026-100837.527.8UnknownAPCu Manager—APCu Manager < 4.5.0 - Unauthenticated Stored XSS via Cache Key Pollution
CVE-2025-29028.327.6HitachiHitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090HCWE-862Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtua…
CVE-2026-437276.527.6AppleSafariCWE-416A use-after-free issue was addressed with improved memory management. This is…
CVE-2026-135692.027.5weng-xianhuEyouCMSCWE-74weng-xianhu EyouCMS API index.php sql injection
CVE-2026-135582.027.4CodeAstroComplaint Management SystemCWE-79CodeAstro Complaint Management System Report addreport cross site scripting
CVE-2026-419926.927.2GNUgzipCWE-126Global Buffer Overflow in GNU gzip
CVE-2026-345927.726.5coollabsiocoolifyCWE-639Coolify: Cross-Team IDOR via Unscoped Server and Project Lookups Exposes SSH …
CVE-2026-579436.026.3LibrePhotoslibrephotosCWE-639LibrePhotos < 1.0.0 - Insecure Direct Object Reference in SetPhotosShared End…
CVE-2026-573327.126.3WP SwingsWallet System for WooCommerceCWE-862WordPress Wallet System for WooCommerce plugin <= 2.7.6 - Broken Access Contr…
CVE-2026-135202.125.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System Appointment appointmentapproval.php s…
CVE-2026-135252.125.7CodeAstroHuman Resource Management SystemCWE-74CodeAstro Human Resource Management System Update_Earn_Leave Endpoint Employe…
CVE-2026-135302.125.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System Appointment appointmentdetail.php sql…
CVE-2026-135312.125.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System department.php sql injection
CVE-2026-135322.125.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System departmentDoctor.php sql injection
CVE-2026-135352.125.7CodeAstroHuman Resource Management SystemCWE-74CodeAstro Human Resource Management System View Endpoint Employee_model.php G…
CVE-2026-135412.125.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System doctorchangepassword.php sql injection
CVE-2026-135422.125.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System doctorprofile.php sql injection
CVE-2026-135482.125.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System doctortimings.php sql injection
CVE-2026-135722.125.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System insertbillingrecord.php sql injection
CVE-2026-135782.125.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System patientdetail.php sql injection
CVE-2026-135792.125.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System patientchangepassword.php sql injection
CVE-2026-573346.525.6weDevsWP User FrontendCWE-862WordPress WP User Frontend plugin <= 4.3.7 - Broken Access Control vulnerability
CVE-2026-573396.525.6Strategy11 TeamBusiness DirectoryCWE-862WordPress Business Directory plugin <= 6.4.23 - Broken Access Control vulnera…
CVE-2026-573406.525.6shohei.tanakaJapanized For WooCommerceCWE-862WordPress Japanized For WooCommerce plugin <= 2.9.12 - Broken Access Control …
CVE-2026-573416.525.6ColissimoColissimo Officiel : Méthodes de livraison pour WooCommerceCWE-639WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin …
CVE-2026-135702.025.4SourceCodesterInventory Management SystemCWE-79SourceCodester Inventory Management System User Registration Endpoint users_h…
CVE-2026-76566.825.2zephyrprojectzephyrCWE-290Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA accep…
CVE-2026-437466.525.3AppleSafariCWE-416A use-after-free issue was addressed with improved memory management. This is…
CVE-2026-579476.325.1pinpoint-apmpinpointCWE-918Pinpoint - Server-Side Request Forgery via Alarm Webhook Registration
CVE-2026-137528.025.0SnowflakeSnowflake CLICWE-89Snowflake CLI SQL Injection Through Improper Neutralization of Parameters in …
CVE-2026-437247.824.8AppleiOS and iPadOSCWE-20The issue was addressed with improved input sanitization. This issue is fixed…
CVE-2026-579455.324.8photoprismphotoprismCWE-639PhotoPrism - Unauthorized User Profile Modification via PUT /api/v1/users/{ui…
CVE-2026-135341.324.9CherryHQcherry-studioCWE-285CherryHQ cherry-studio CherryIN Preload API MemoryService.ts sha256 authoriza…
CVE-2026-579558.324.6SigNozsignozCWE-89SigNoz 0.130.1 - SQL Injection in Alert History Endpoints via Rule ID Parameter
CVE-2026-135911.323.9DeepMystMystiCWE-266DeepMyst Mysti Contact Tracking ChannelBridge.ts _isTrackedConversation impro…
CVE-2026-564574.322.1HCLSoftwareHCL DevOps Deploy / HCL LaunchCWE-532HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive inf…
CVE-2026-573356.521.9Ads WPQuadsAds by WPQuadsCWE-862WordPress Ads by WPQuads plugin <= 3.0.3 - Broken Access Control vulnerability
CVE-2026-576764.321.3Matteo MannaSimple User AvatarCWE-639WordPress Simple User Avatar plugin <= 4.9 - Insecure Direct Object Reference…
CVE-2026-135936.521.2GTERMARSCSS::Minifier::XSCWE-401CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the e…
CVE-2026-579526.020.8its-a-featureMythicCWE-862Mythic < 3.4.0.60 - Unauthorized C2 Profile Configuration Access via Unverifi…
CVE-2026-579585.120.5inovectormixpostCWE-79Mixpost 2.6.0 - Reflected XSS via OAuth Callback Error Parameter
CVE-2026-579545.320.0yahooelideCWE-862Elide 7.1.17 - Permission Bypass in Sort Expression Validation
CVE-2026-579426.919.9LibreTranslateLibreTranslateCWE-348LibreTranslate - IP Spoofing via X-Forwarded-For Header
CVE-2026-92676.918.6Eclipse FoundationEclipse tinydtlsCWE-125Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221 conta…
CVE-2026-437225.517.5AppleiOS and iPadOSCWE-20The issue was addressed with improved input sanitization. This issue is fixed…
CVE-2026-573276.317.3mainwpMainWPCWE-862WordPress MainWP plugin <= 6.1.1 - Broken Access Control vulnerability
CVE-2026-558447.517.1home-assistantcoreCWE-319Home Assistant: iOS Companion App ignores internal SSID allowlist for connect…
CVE-2026-579598.216.9HiEventsDevHi.EventsCWE-367Hi.Events 1.9.0 - Promo Code Max-Usage Bypass via Asynchronous Job Race Condi…
CVE-2026-573266.116.4Strategy11 TeamBusiness DirectoryCWE-79WordPress Business Directory plugin <= 6.4.22 - Cross Site Scripting (XSS) vu…
CVE-2026-573207.116.3RealMag777BEARCWE-79WordPress BEAR plugin <= 1.1.8 - Cross Site Scripting (XSS) vulnerability
CVE-2026-573337.116.3Spencer HawsLink Whisper FreeCWE-79WordPress Link Whisper Free plugin <= 0.9.4 - Reflected Cross Site Scripting …
CVE-2026-573367.116.3AstoundifyJobifyCWE-79WordPress Jobify theme <= 4.3.2 - Cross Site Scripting (XSS) vulnerability
CVE-2026-573377.116.3PluginOpsLanding Page BuilderCWE-79WordPress Landing Page Builder plugin <= 1.5.3.5 - Cross Site Scripting (XSS)…
CVE-2026-573387.116.3Repute InfoSystemsARFormsCWE-79WordPress ARForms plugin <= 7.1.2 - Reflected Cross Site Scripting (XSS) vuln…
CVE-2026-579976.316.0strapistrapiCWE-327Strapi users-permissions - JWT Algorithm Confusion via Missing Algorithm Conf…
CVE-2026-310166.514.8n/an/aCWE-352Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 a…
CVE-2026-548886.914.5leandrocpmdexCWE-674Uncontrolled recursion over deeply nested Markdown crashes the BEAM in mdex
CVE-2026-405227.113.9FrontAccountingFrontAccountingCWE-89FrontAccounting < 2.4.20 SQL Injection via rep601.php
CVE-2026-437358.113.6AppleSafariCWE-352The issue was addressed with improved checks. This issue is fixed in Safari 2…
CVE-2026-135372.113.6CodeAstroHuman Resource Management SystemCWE-352CodeAstro Human Resource Management System cross-site request forgery
CVE-2026-573286.512.9Strategy11 TeamBusiness DirectoryCWE-79WordPress Business Directory plugin <= 6.4.22 - Cross Site Scripting (XSS) vu…
CVE-2026-573296.512.9WOOCOMMERCE DESIGNER PROWooCommerce Designer ProCWE-79WordPress WooCommerce Designer Pro plugin <= 1.9.34 - Cross Site Scripting (X…
CVE-2026-573306.512.9StylemixMasterStudy LMSCWE-79WordPress MasterStudy LMS plugin <= 3.7.27 - Cross Site Scripting (XSS) vulne…
CVE-2026-137465.412.0SnowflakeSnowflake CLICWE-89Snowflake CLI SQL Injection Through Improper Neutralization of Local CLI Para…
CVE-2026-137519.610.3SnowflakeSnowflake CLICWE-829Snowflake CLI Server-Side Request Forgery via Arbitrary URL Fetch in !source/…
CVE-2026-579487.610.0pinpoint-apmpinpointCWE-614Pinpoint - Insecure Session Cookie Attributes in pinpointJwt
CVE-2026-106475.39.9zephyrprojectzephyrCWE-667Deadlock denial of service in USB CDC-NCM device class on TX enqueue failure
CVE-2026-437006.58.4AppleSafariCWE-346A cross-origin issue was addressed with improved tracking of security origins…
CVE-2026-534286.98.1leandrocpmdexCWE-789Unbounded memory allocation in highlight_lines range expansion in mdex
CVE-2026-137486.38.1SnowflakeSnowflake CLICWE-22Snowflake CLI Arbitrary Local File Read and Exfiltration Through Improper Fil…
CVE-2026-534268.27.6leandrocpmdexCWE-770Atom-table exhaustion denial-of-service via JSON parse_document in MDEx
CVE-2026-534296.97.6leandrocpmdexCWE-401Unbounded native memory leak in mdex escaped-tag rendering enables unauthenti…
CVE-2026-136016.57.5Red HatRed Hat Enterprise Linux 7 Extended Lifecycle SupportCWE-693Yelp: yelp-xsl: overly permissive content security policy in yelp allows host…
CVE-2026-579197.87.2n/an/aCWE-276PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a…
CVE-2026-135231.95.3n/aGPACCWE-404GPAC ISOBMFF base_encoding.c data amplification
CVE-2026-464064.44.7anthropicsclaude-codeCWE-59Claude Code: Insecure Temporary File in /copy Command Enables Response Disclo…
CVE-2026-543698.44.7acl projectaclCWE-59acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions
CVE-2026-106485.54.6zephyrprojectzephyrCWE-476NULL-pointer dereference in MCUmgr serial/console SMP transport on buffer-poo…
CVE-2026-135955.34.6Red HatRed Hat Hardened ImagesCWE-416Util-linux: util-linux: heap use-after-free in libblkid nested partition probing
CVE-2026-137505.54.5SnowflakeSnowflake CLICWE-532Snowflake CLI Sensitive Credential Exposure Through Debug Logging
CVE-2026-137576.24.2Red HatRed Hat Enterprise Linux 10CWE-674P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing
CVE-2026-96764.33.8UnknownF4 Post Tree—f4 Post Tree < 2.0.5 - Subscriber+ Arbitrary Post Parent/Menu Order Modification
CVE-2026-543718.42.9attr projectattrCWE-59attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr
CVE-2025-08243.72.8HitachiHitachi Virtual Storage Platform One Block 23, 24, 26, 28CWE-347lack of validation for firmware update in Hitachi Virtual Storage
CVE-2026-533255.52.5LinuxLinuxCWE-476agp/amd64: Fix broken error propagation in agp_amd64_probe()
CVE-2026-579664.42.5Red HatRed Hat Enterprise Linux 10CWE-22Spice-vdagent: path traversal in file transfer via unsanitized filename
CVE-2026-220787.32.2OPPOO+ ConnectCWE-266O+ Connect's lack of authentication for IPC channels led to a local privilege…
CVE-2026-419912.01.8GNUgzipCWE-377Predictable Temporary File in GNU gzip
CVE-2026-137425.91.7Honeywell TechnologiesIQ MultiAccessCWE-367Lack of signature verification before execution of downloaded content
CVE-2026-579655.11.6Red HatRed Hat Enterprise Linux 10CWE-190Spice-vdagent: integer overflow in udscs_write() leading to heap buffer overflow
CVE-2026-437434.71.2AppleiOS and iPadOSCWE-362A race condition was addressed with improved state handling. This issue is fi…
CVE-2026-543707.20.4acl projectaclCWE-367acl < 2.4.0 TOCTOU Symlink Traversal via getfacl/setfacl/chacl

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-29 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.