boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, June 30, 2026 · all times UTC← 2026-06-29 · archive · 2026-07-01 →

Security Box Score — June 30, 2026

641 CVEs published, led by Google (382).

641 CVEs published June 30, 2026: 97 critical, 200 high, 327 medium, 17 low; 0 in the KEV catalog at press time; 16 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 241 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published794212403——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

537 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux513148011985450611120.17.8.0014-128 ▼
google10901265133568527377760.57.5.0024+922 ▲
microsoft221757585211726286192.57.8.0045+55 ▲
red hat128222109110813200.06.5.0030+86 ▲
apple521042287228876.76.5.0032+30 ▲
canonical6202585000.05.5.0011-8 ▼
freebsd91601240000.07.8.0016+2 ▲
suse11133730000.08.6.0039+9 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco102266100561150.07.3.0566+5 ▲
netgear171700161000.04.3.0024+17 ▲
palo alto networks911127113218.25.9.0022+7 ▲
ubiquiti81174003327.39.9.0083+6 ▲
ivanti49450025555.68.8.5187+2 ▲
checkpoint3915303111.17.5.0410-3 ▼
fortinet29432028333.38.3.0076+1 ▲
f56843104112.58.9.0225+4 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache121155245763103310.67.2.0053+100 ▲
mozilla50561218260900.07.3.0026+44 ▲
gitlab243105215426.54.4.0029+17 ▲
docker470520000.08.2.0016+1 ▲
github461140000.06.2.0037+2 ▲
drupal0511304120.05.1.0026-5 ▼
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle2422701321161842720.78.8.0040+217 ▲
adobe14214411537821921.45.8.0021+142 ▲
ibm751243642460600.07.5.0034+26 ▲
progress591710600.07.5.0036+1 ▲
solarwinds47232010457.17.5.4001+4 ▲
veeam142200100.09.0.0052-2 ▼
zohocorp131110000.08.4.0170-1 ▼
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025-13 ▼
d-link10120525300.05.8.0058+8 ▲
siemens890450000.06.9.0021+7 ▲
rockwell automation771510000.08.7.0030+7 ▲
abb660420000.07.2.0018+6 ▲
schneider electric660420000.07.8.0042+6 ▲
moxa550320000.07.0.0029+5 ▲
dahua330111000.06.9.0036+3 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring7273231391000.06.5.0024+71 ▲
sourcecodester4971003635000.05.5.0027+29 ▲
openclaw61670352210000.07.0.0021+55 ▲
edimax1465039026100.07.4.0080-33 ▼
capgo6161231271000.07.1.0039+61 ▲
themerex585855300000.08.1.0043+58 ▲
dell3856230240211.87.3.0017+26 ▲
itsourcecode4353001835000.02.1.0027+33 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9991100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-20230.882099.88.6
CVE-2026-34910.874799.710.0
CVE-2026-34908.851999.710.0
CVE-2026-50751.837799.79.3
CVE-2026-48907.781099.510.0
CVE-2026-34909.639099.210.0
CVE-2026-49160.538398.97.5
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9991KEV
CVE-2026-3491010.0.8747KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.7810KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-1377310.0.0610
CVE-2026-5641510.0.0436
CVE-2026-5641310.0.0419
CVE-2026-5357610.0.0330
CVE-2026-5375310.0.0290
Most disclosures (vendor)
VendorCVEs
google1090
linux513
oracle242
microsoft221
adobe142
red hat128
apache121
ibm75
spring72
capgo61
Most KEV additions (YTD)
VendorKEV
microsoft19
cisco11
apple7
google6
ivanti5
solarwinds4
berriai3
fortinet3
smartertools3
ubiquiti3
Most-affected ecosystems
EcosystemAdvisories
Maven49
Packagist15
PyPI9
npm6
Fastest to KEV
CVEVendorDays
CVE-2025-48595Google0
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-28318SolarWinds0
CVE-2026-34908Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171686
CVE-2021-27102n/a2021-11-171686
CVE-2021-27101n/a2021-11-171686
CVE-2021-27103n/a2021-11-171686
CVE-2021-21017Adobe2021-11-171686
CVE-2021-28550Adobe2021-11-171686
CVE-2021-42013Apache Software Foundation2021-11-171686
CVE-2021-41773Apache Software Foundation2021-11-171686
CVE-2021-30858Apple2021-11-171686
CVE-2021-30860Apple2021-11-171686

Transactions

EXPLOIT PUBLISHED — GNOME GLib: 6 CVEs (CVE-2026-58010, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015, CVE-2026-58016). Public exploit references added.

EXPLOIT PUBLISHED — zephyrproject zephyr: 5 CVEs (CVE-2026-9263, CVE-2026-10652, CVE-2026-10653, CVE-2026-10654, CVE-2026-10655). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-4629 (Red Hat build of Keycloak 26.4). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54672 (electron-userland electron-builder). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56364 (ImageMagick). Public exploit reference added.

DUE DATE PASSED — CVE-2026-20262 (Cisco Catalyst SD-WAN Manager). CISA remediation deadline was June 29, 2026; still in catalog.

Yesterday's Results

How to read these box scores · glossary

641 CVEs published. 25 box scores and 375 table rows below; the remaining 241 continue on page 2 — every CVE is listed, nothing truncated.

NetScaler ADC — Insufficient input validation leading to memory overread
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   L   H    8.8   .1565   96.6     —
AFFECTED
  Product  Versions  Fixed
  ADC      14.1 –    —
  Gateway  14.1 –    —
TIMELINE
  May 13  Reserved by CNA
  Jun 30  Published (CNA: NetScaler)
CWE-125 · CNA: NetScaler · CVSS v4.0 · 1 reference · NVD status: Analyzed
conductor-oss conductor — Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0914   94.9     —
AFFECTED
  Product    Versions   Fixed
  conductor  3.21.21 –  —
TIMELINE
  Jun 29  Reserved by CNA
  Jun 30  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Deferred
IBM WebSphere eXtreme Scale is affected by server side request forgery when ORB is used as Transport Protocol
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0610   92.9     —
AFFECTED
  Product                  Versions   Fixed
  WebSphere Extreme Scale  8.6.1.0 –  —
TIMELINE
  Jun 29  Reserved by CNA
  Jun 30  Published (CNA: ibm)
CWE-918 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed
Stonefly Storage Concentrator — OS Command Injection in StoneFly Storage Concentrator
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0436   90.5     —
AFFECTED
  Product                               Versions     Fixed
  Storage Concentrator                  unspecified  8.0.4.29
  Storage Concentrator Virtual Machine  unspecified  8.0.4.29
TIMELINE
  Jun 22  Reserved by CNA
  Jun 30  Published (CNA: icscert)
CWE-78 · CNA: icscert · CVSS v4.0 · 3 references · NVD status: Deferred
StoneFly Storage Concentrator — OS Command Injection in StoneFly Storage Concentrator
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0419   90.2     —
AFFECTED
  Product                               Versions     Fixed
  Storage Concentrator                  unspecified  8.0.4.29
  Storage Concentrator Virtual Machine  unspecified  8.0.4.29
TIMELINE
  Jun 22  Reserved by CNA
  Jun 30  Published (CNA: icscert)
CWE-78 · CNA: icscert · CVSS v4.0 · 3 references · NVD status: Deferred
Adobe ColdFusion — ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  L  N    9.3   .0295   86.1     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 30  Published (CNA: adobe)
CWE-22 · CNA: adobe · CVSS v3.1 · 1 reference · NVD status: Analyzed
Grav - Multiple Remote Code Execution Vulnerabilities via Unsafe Unserialize and Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0253   83.7     —
AFFECTED
  Product  Versions     Fixed
  Grav     unspecified  2.0.0-beta.2
TIMELINE
  Jun 22  Reserved by CNA
  Jun 30  Published (CNA: VulnCheck)
CWE-78, CWE-502 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
AVTECH Security Corporation DGM3103SCT — DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which ma…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0248   83.3     —
AFFECTED
  Product     Versions                              Fixed
  DGM3103SCT  firmware version 3.2.5.4 and prior –  —
TIMELINE
  Jun 23  Reserved by CNA
  Jun 30  Published (CNA: jpcert)
CWE-78 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Deferred
Adobe ColdFusion — ColdFusion | Improper Input Validation (CWE-20)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0142   70.8     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 30  Published (CNA: adobe)
CWE-20 · CNA: adobe · CVSS v3.1 · 1 reference · NVD status: Analyzed
neuml txtai — txtai - Unauthenticated Remote Code Execution via Unsafe Reflection in API /reindex function Parameter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0135   69.4     —
AFFECTED
  Product  Versions     Fixed
  txtai    unspecified  11b32da720f03276199ebc5583c15fc5d1ccafd3
TIMELINE
  Jun 30  Reserved by CNA
  Jun 30  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
Adobe ColdFusion — ColdFusion | Improper Input Validation (CWE-20)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0129   68.1     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 30  Published (CNA: adobe)
CWE-20 · CNA: adobe · CVSS v3.1 · 1 reference · NVD status: Analyzed
Adobe ColdFusion — ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0126   67.3     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 30  Published (CNA: adobe)
CWE-434 · CNA: adobe · CVSS v3.1 · 1 reference · NVD status: Analyzed
Adobe ColdFusion — ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0126   67.3     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 30  Published (CNA: adobe)
CWE-434 · CNA: adobe · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0124   66.8     —
AFFECTED
  Product      Versions                       Fixed
  OpenAPI.NET  >= 2.0.0-preview11, < 2.7.5 –  —
TIMELINE
  May 30  Reserved by CNA
  Jun 30  Published (CNA: GitHub_M)
CWE-674 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
coollabsio coolify — Coolify: Authenticated RCE via command injection in CA certificate management feature
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0117   65.1     —
AFFECTED
  Product  Versions            Fixed
  coolify  < 4.0.0-beta.464 –  —
TIMELINE
  Feb 25  Reserved by CNA
  Jun 30  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Deferred
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0117   64.9     —
AFFECTED
  Product                       Versions     Fixed
  Adobe Campaign Classic (ACC)  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 30  Published (CNA: adobe)
CWE-863 · CNA: adobe · CVSS v3.1 · 1 reference · NVD status: Analyzed
SeaweedFS < 4.34 - Cross-Bucket Object Deletion via DeleteObjects Request-Body Keys
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   H   H    7.2   .0112   63.6     —
AFFECTED
  Product    Versions     Fixed
  seaweedfs  unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jun 30  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 6 references · NVD status: Deferred
Gotcha Gotcha Games Inc. RPG MAKER MV — RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If …
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   N   A   H   H   H    8.4   .0109   62.7     —
AFFECTED
  Product       Versions              Fixed
  RPG MAKER MV  1.6.3 and earlier –   —
  RPG MAKER MZ  1.10.0 and earlier –  —
TIMELINE
  Jun 19  Reserved by CNA
  Jun 30  Published (CNA: jpcert)
CWE-78 · CNA: jpcert · CVSS v4.0 · 3 references · NVD status: Deferred
NetScaler ADC — Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   L   H    8.8   .0104   61.4     —
AFFECTED
  Product  Versions  Fixed
  ADC      14.1 –    —
  Gateway  14.1 –    —
TIMELINE
  May 13  Reserved by CNA
  Jun 30  Published (CNA: NetScaler)
CWE-119 · CNA: NetScaler · CVSS v4.0 · 1 reference · NVD status: Analyzed
Adobe ColdFusion — ColdFusion | Improper Input Validation (CWE-20)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  H  N    9.3   .0103   61.0     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 30  Published (CNA: adobe)
CWE-20 · CNA: adobe · CVSS v3.1 · 1 reference · NVD status: Analyzed
hiyouga LlamaFactory — LLaMA-Factory 0.9.5 Remote Code Execution via WebUI Model Path
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0090   57.1     —
AFFECTED
  Product       Versions     Fixed
  LlamaFactory  unspecified  —
TIMELINE
  Jun 29  Reserved by CNA
  Jun 30  Published (CNA: VulnCheck)
CWE-94, CWE-829 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Analyzed
IBM® Db2® is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0086   55.7     —
AFFECTED
  Product  Versions  Fixed
  Db2      11.5.0 –  —
TIMELINE
  May 29  Reserved by CNA
  Jun 30  Published (CNA: ibm)
CWE-94 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed
OpenBMB ChatDev - Unauthenticated Path Traversal in Upload Handler Allows Arbitrary File Write and Delete
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   H   H    8.8   .0085   55.5     —
AFFECTED
  Product  Versions     Fixed
  ChatDev  unspecified  4fd4da603801766b14ad8788649cfc1ad21f99a6
TIMELINE
  Jun 29  Reserved by CNA
  Jun 30  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
picklescan - Arbitrary Code Execution via Undetected doctest.debug_script
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   P   H   H   N    7.6   .0084   55.1     —
AFFECTED
  Product     Versions     Fixed
  picklescan  unspecified  0.0.30
TIMELINE
  Jun 20  Reserved by CNA
  Jun 30  Published (CNA: VulnCheck)
CWE-502 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
Adobe ColdFusion — ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  N  N    8.6   .0083   54.8     —
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jun 30  Published (CNA: adobe)
CWE-918 · CNA: adobe · CVSS v3.1 · 1 reference · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-113676.553.6andraswebPixMagix – WordPress Image EditorCWE-22PixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' P…
CVE-2026-494327.553.3Apache Software FoundationApache ActiveMQCWE-20Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative c…
CVE-2026-115957.553.2IBMWebSphere Application ServerCWE-22IBM WebSphere Application Server is affected by a Path Traversal vulnerability
CVE-2026-507347.551.8Apache Software FoundationApache ActiveMQ ClientCWE-789Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authenticat…
CVE-2026-539167.551.8Apache Software FoundationApache ActiveMQCWE-789Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header…
CVE-2026-539177.551.8Apache Software FoundationApache ActiveMQCWE-789Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ…
CVE-2026-583709.251.1woodpecker-ciwoodpeckerCWE-290Woodpecker < 3.15.0 - GitLab Approval Gate Bypass via Spoofable Commit Author…
CVE-2026-584466.950.5presentonpresentonCWE-306Presenton < 0.8.8-beta - Authentication Bypass of Session Auth via Unprotecte…
CVE-2026-78719.850.2IBMLangflow OSSCWE-502Insecure Deserialization in Redis Cache Backend
CVE-2026-507507.549.9Apache Software FoundationApache ActiveMQ BrokerCWE-400Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authenticat…
CVE-2026-527606.149.6Apache Software FoundationApache ActiveMQCWE-79Apache ActiveMQ, Apache ActiveMQ Web Console: Stored XSS via Unescaped values…
CVE-2026-536918.649.2RedeightRedeight CMSCWE-434Remote Code Execution in Redeight CMS
CVE-2026-500039.349.0OFFIS DICOMDCMTK ToolkitCWE-22OFFIS DCMTK Toolkit Path Traversal
CVE-2026-355058.748.2OFFIS DICOMDCMTK ToolkitCWE-401OFFIS DCMTK Toolkit Missing Release of Memory after Effective Lifetime
CVE-2026-502548.748.2OFFIS DICOMDCMTK ToolkitCWE-401OFFIS DCMTK Toolkit Missing Release of Memory after Effective Lifetime
CVE-2026-78039.848.0IBMLangflow OSSCWE-20Flow Validation Bypass via Empty Component Type Field
CVE-2025-713637.647.8picklescanpicklescanCWE-502picklescan - Arbitrary Code Execution via Undetected cProfile.run in Pickle D…
CVE-2025-713747.647.8picklescanpicklescanCWE-502picklescan - Arbitrary Code Execution via Undetected profile.Profile.run
CVE-2025-713527.647.8picklescanpicklescanCWE-693picklescan - Remote Code Execution via Undetected trace.Trace.runctx in Pickl…
CVE-2026-583696.947.8woodpecker-ciwoodpeckerCWE-476Woodpecker < 3.15.0 - Unauthenticated NULL Pointer Dereference in /api/orgs/l…
CVE-2026-446288.747.8OFFIS DICOMDCMTK ToolkitCWE-843OFFIS DCMTK Toolkit Type Confusion
CVE-2026-583758.747.6jeecgbootjimureportCWE-306JimuReport 2.5.0 - Unauthenticated Report Export via /jmreport/auto/export
CVE-2026-86558.847.5NetScalerADCCWE-119Multiple Memory overflow vulnerabilities leading to unpredictable or erroneou…
CVE-2026-141629.347.5AdvantechHospital Quering ManagementCWE-306Advantech|Hospital Quering Management - Missing Authentication
CVE-2026-494347.547.5Apache Software FoundationApache ActiveMQ BrokerCWE-20Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: LdapNetworkConn…
CVE-2026-521957.547.4n/an/aCWE-120Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo…
CVE-2026-521967.547.4n/an/aCWE-120Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo…
CVE-2026-562338.747.3CapgoCapgoCWE-22Capgo - SSRF and Privilege Escalation via Path Traversal in Builder Upload Proxy
CVE-2026-122408.047.2qlstudioExport User DataCWE-502Export User Data <= 2.2.6 - Authenticated (Subscriber+) PHP Object Injection …
CVE-2026-483146.547.0AdobeColdFusionCWE-22ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Pa…
CVE-2025-713497.646.7picklescanpicklescanCWE-502picklescan - Arbitrary Code Execution via Undetected trace.Trace.run in Pickl…
CVE-2026-132078.746.4FrangoteamFUXA SCADA/HMICWE-290Frangoteam FUXA SCADA/HMI Authentication Bypass by Spoofing
CVE-2026-581687.745.9HKUDSDeepTutorCWE-862DeepTutor < 1.4.10 - Insecure Default Grants Unrestricted MCP Tool Access to …
CVE-2026-521977.545.2n/an/aCWE-400An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker …
CVE-2026-108167.145.0NetScalerADCCWE-610Arbitrary File Read (Unauthenticated)
CVE-2025-713557.644.9PicklescanPicklescanCWE-184Picklescan - Arbitrary Code Execution via Unsafe Numpy Function Detection Bypass
CVE-2026-521937.544.5n/an/aCWE-120Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo…
CVE-2026-521987.544.5n/an/aCWE-120Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo…
CVE-2026-581729.344.3ThreeMammalsOcelotCWE-288Ocelot - IP Allow/Block List Bypass for WebSocket Upgrade Requests
CVE-2026-1013410.044.3IBMLangflow OSSCWE-94Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows
CVE-2026-350986.944.3KTM Systeme-BOKCWE-307Improper Restriction of Excessive Authentication Attempts in KTM System e-BOK
CVE-2026-544757.544.2Apache Software FoundationApache ActiveMQ BrokerCWE-862Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Temporary desti…
CVE-2025-536485.444.1Apache Software FoundationApache GravitinoCWE-89Apache Gravitino: SQL misconfiguration can access or truncate files
CVE-2026-108176.944.1NetScalerADCCWE-125Insufficient input validation leading to memory overread
CVE-2026-134748.743.8NetScalerADCCWE-401Denial of service via malformed HTTP/2 requests
CVE-2026-581707.243.8HKUDSVibe-TradingCWE-22Vibe-Trading < 0.1.10 - Path Traversal in Proposal Identifier Allows Forging …
CVE-2026-137669.843.5EXODISTDBIx::QuickORMCWE-89DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unqu…
CVE-2026-141618.743.5AdvantechHospital Queuing ManagementCWE-200Advantech|Hospital Queuing Management - Sensitive Data Exposure
CVE-2026-557219.243.3StoneFlyStorage ConcentratorCWE-89SQL Injection in StoneFly Storage Concentrator
CVE-2026-137598.843.3IBMWebSphere Extreme ScaleCWE-502IBM WebSphere eXtreme Scale is affected by Insecure Deserilization
CVE-2026-580169.143.3GNOMEGLibCWE-191Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new…
CVE-2026-483078.843.2AdobeColdFusionCWE-79ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)
CVE-2025-713717.643.2picklescanpicklescanCWE-502picklescan - Remote Code Execution via code.InteractiveInterpreter Detection …
CVE-2026-128199.343.2deltawwDVP-12SECWE-306DVP-12SE Missing Authentication and Unauthorized Write access Vulnerability
CVE-2026-97119.843.0EventONEventON (Pro) - WordPress Virtual Event Calendar PluginCWE-89EventON - WordPress Virtual Event Calendar Plugin <= 5.0.11 - Unauthenticated…
CVE-2026-562867.042.9CapgoCapgoCWE-306Capgo - Account Deletion Without Password Confirmation
CVE-2026-120769.342.5RaythaRaythaCWE-89SQL Injection in Raytha CMS
CVE-2026-78739.942.4IBMLangflow OSSCWE-94Code Injection Vulnerability in Code Validation Endpoint
CVE-2026-120739.842.3metagaussProfileGrid – User Profiles, Groups and CommunitiesCWE-639ProfileGrid - User Profiles, Groups and Communities <= 5.9.9.5 - Unauthentica…
CVE-2026-562789.342.3FlowiseFlowiseCWE-798Flowise - Session Hijacking via Weak Default Express Session Secret
CVE-2026-410538.842.1SUSERancherCWE-303Over-inclusive team membership expansion in GitHub App authentication provide…
CVE-2026-141049.842.0GoogleChromeCWE-20Insufficient validation of untrusted input in WebAppInstalls in Google Chrome…
CVE-2026-138708.842.0GoogleChromeCWE-416Use after free in WebView in Google Chrome on Android prior to 150.0.7871.47 …
CVE-2026-65569.141.9@fastify/express@fastify/expressCWE-285@fastify/express vulnerable to middleware bypass via non-string mount paths i…
CVE-2026-76639.841.8IBMLangflow OSSCWE-863Unauthenticated Cross-User MCP Resource Access and Tool Execution via Streama…
CVE-2026-580157.541.5GNOMEGLibCWE-22Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_…
CVE-2026-498778.141.4Apache Software FoundationApache ActiveMQCWE-285Apache ActiveMQ: Authenticated web users retain admin access by default in th…
CVE-2026-536909.341.3RedeightRedeight CMSCWE-89SQL Injection in Redeight CMS
CVE-2026-137729.941.1IBMWebSphere Extreme ScaleCWE-470IBM WebSphere eXtreme Scale's OQL is affected by remote code execution
CVE-2026-458226.640.9SamVerschuerendecode-uri-componentCWE-400decode-uri-component through 0.4.1 is vulnerable to denial of service. The de…
CVE-2026-115898.840.8UnknownWP Support Plus Responsive Ticket System—WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Stored XS…
CVE-2026-139678.840.2GoogleChromeCWE-843Heap buffer overflow in V8 in Google Chrome prior to 150.0.7871.47 allowed a …
CVE-2026-528688.840.0OFFIS DICOMDCMTK ToolkitCWE-22OFFIS DCMTK Toolkit Path Traversal
CVE-2026-137947.539.8GoogleChromeCWE-20Insufficient validation of untrusted input in WebAppInstalls in Google Chrome…
CVE-2026-562649.239.8Crawl4AICrawl4AICWE-94Crawl4AI - Arbitrary JavaScript Execution via /execute_js Endpoint
CVE-2026-141647.539.8Red HatRed Hat Enterprise Linux 10CWE-415Libarchive: double-free vulnerability in rar5 decompression logic via danglin…
CVE-2026-570807.539.8SANKONet::BitTorrentCWE-400Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustio…
CVE-2026-570817.539.8SANKONet::BitTorrentCWE-400Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustio…
CVE-2026-575857.539.8msgpackmsgpack-pythonCWE-416MessagePack: Out-of-bounds read/crash on Unpacker reuse after caught error
CVE-2026-46296.539.6Red HatRed Hat build of Keycloak 26.4CWE-266Keycloak: keycloak: privilege escalation through hardcoded role mapper injection
CVE-2026-105609.139.5IBMLangflow OSSCWE-287Unauthenticated Access to Private Flow Build Events and Cancellation in Langf…
CVE-2026-552236.339.3swaldmanc3p0CWE-502c3p0 exposes a deserialization "sink" via JDBC DataSource bean properties
CVE-2026-118067.538.7IBMWebSphere Application Server - LibertyCWE-444IBM WebSphere Application Server Liberty is affected by a an arbitrary file r…
CVE-2026-562308.738.5CapgoCapgoCWE-639Capgo - Broken Object Level Authorization via x-limited-key-id Header
CVE-2026-84029.838.4Eksagate Electronic Engineering and Computer Industry Trade Inc.SYSGUARD 6001CWE-89SQLi in Exagate's SYSGUARD 6001
CVE-2026-581767.138.1dromaraRuoYi-Vue-PlusCWE-862RuoYi-Vue-Plus - Missing Authorization on Workflow Task Management Endpoints
CVE-2026-563008.737.8CapgoCapgoCWE-200Capgo - Unauthenticated API Key Validity and Permission Oracle via RPC Functions
CVE-2026-105625.937.8TP-Link Systems Inc.Archer AX20 V2.0CWE-601Unauthenticated Open Redirect Vulnerability on TP-Link Archer AX20 Web Interface
CVE-2026-141219.837.6GoogleChromeCWE-416Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47…
CVE-2026-563995.337.5open-webuiopen-webuiCWE-918Open WebUI - Server-Side Request Forgery via Location Redirect in /api/v1/ret…
CVE-2026-581746.037.3nesquenahermes-webuiCWE-732Hermes WebUI < 0.51.521 - Cross-Profile Authorization Bypass via Unset Sessio…
CVE-2026-562198.737.1CapgoCapgoCWE-287Capgo - Unauthenticated RBAC Bindings and Email Disclosure via get_org_user_a…
CVE-2026-581736.037.0HKUDSVibe-TradingCWE-22Vibe-Trading < 0.1.10 - Path Traversal via Persistent Memory Type
CVE-2026-115908.636.9UnknownWP Support Plus Responsive Ticket System—WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated SQL Injec…
CVE-2026-69535.136.7Intermark ITWebControl CMSCWE-79Multiple vulnerabilities in Intermark IT's WebControl CMS
CVE-2026-562478.736.6CapgoCapgoCWE-266Capgo - Privilege Escalation via Cross-Scope RBAC Role Assignment
CVE-2026-579958.736.6phpMyFAQphpMyFAQCWE-269phpMyFAQ - Privilege Escalation via Missing Self-Rights Constraint in GroupCo…
CVE-2026-449485.336.2SUSERancherCWE-23Path Traversal in Rancher Fleet ImageScan GitRepo Path Handler
CVE-2026-69545.136.2Intermark ITWebControl CMSCWE-79Multiple vulnerabilities in Intermark IT's WebControl CMS
CVE-2025-713507.635.7picklescanpicklescanCWE-502picklescan - Undetected Remote Code Execution via torch.utils.collect_env.run
CVE-2025-363194.335.7IBMwatsonx.data intelligenceCWE-770Vulnerabilities found in Watson Data Intelligence
CVE-2026-142419.835.6MozillaFirefoxCWE-787Memory safety bugs fixed in Firefox 152.0.4
CVE-2026-128189.335.4deltawwDVP-12SECWE-770DVP-12SE Exposure of Sensitive Information Vulnerability
CVE-2026-107637.035.4Hitachi EnergyPROMOD VCWE-1428PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerabi…
CVE-2026-548996.335.4ohler55ojCWE-416Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle
CVE-2026-549006.335.4ohler55ojCWE-190Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
CVE-2026-549016.335.4ohler55ojCWE-416Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking
CVE-2026-549026.335.4ohler55ojCWE-416Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback
CVE-2026-549036.335.4ohler55ojCWE-190Oj: Integer Overflow in Oj.load 2GB String Handling
CVE-2026-137878.134.9GoogleChromeCWE-416Use after free in Chromoting in Google Chrome on Windows prior to 150.0.7871.…
CVE-2026-350976.934.9KTM Systeme-BOKCWE-521Weak Password Requirements in KTM System e-BOK
CVE-2026-119066.534.8IBMDb2CWE-1284IBM® Db2® federated server is vulnerable to a denial of service due to improp…
CVE-2026-534325.634.7fzffzfCWE-190Integer Overflow in fzf
CVE-2026-106538.134.6zephyrprojectzephyrCWE-415Non-atomic `net_buf` reference counts cause double-free / free-list corruptio…
CVE-2026-581697.734.5HKUDSVibe-TradingCWE-346Vibe-Trading < 0.1.10 - Loopback Trust and Missing Host Validation Enable DNS…
CVE-2026-115419.834.5IBMCICS Transaction Gateway for MultiplatformsCWE-444Inconsistent Interpretation of HTTP Requests in CICS Transaction Gateway for …
CVE-2026-123495.334.4octagonwebstudioPremium Addons for KingComposerCWE-862Premium Addons for KingComposer <= 1.1.1 - Missing Authorization to Unauthent…
CVE-2026-106527.434.3zephyrprojectzephyrCWE-125Out-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated…
CVE-2026-581677.134.3ccfosnightingaleCWE-862Nightingale < 9.0.0-beta.2 - Datasource Credential Disclosure to Low-Privileg…
CVE-2026-91326.034.3GitHubEnterprise ServerCWE-862Missing authorization vulnerability in GitHub Enterprise Server allowed discl…
CVE-2026-137868.834.1GoogleChromeCWE-416Use after free in Ozone in Google Chrome prior to 150.0.7871.47 allowed a rem…
CVE-2026-137888.834.1GoogleChromeCWE-416Use after free in Fullscreen in Google Chrome on Android prior to 150.0.7871.…
CVE-2026-138158.834.1GoogleChromeCWE-416Use after free in Blink in Google Chrome prior to 150.0.7871.47 allowed a rem…
CVE-2026-138858.834.1GoogleChromeCWE-416Use after free in Skia in Google Chrome on Android prior to 150.0.7871.47 all…
CVE-2026-138988.834.1GoogleChromeCWE-416Use after free in Cast Receiver in Google Chrome prior to 150.0.7871.47 allow…
CVE-2026-138998.834.1GoogleChromeCWE-416Use after free in HTML in Google Chrome prior to 150.0.7871.47 allowed a remo…
CVE-2026-139658.834.1GoogleChromeCWE-416Use after free in Oilpan in Google Chrome prior to 150.0.7871.47 allowed a re…
CVE-2026-140068.834.1GoogleChromeCWE-416Use after free in Navigation in Google Chrome prior to 150.0.7871.47 allowed …
CVE-2026-140678.834.1GoogleChromeCWE-416Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.…
CVE-2026-140868.834.1GoogleChromeCWE-602Insufficient policy enforcement in HID in Google Chrome prior to 150.0.7871.4…
CVE-2026-141498.834.1GoogleChromeCWE-416Use after free in Audio in Google Chrome on Linux prior to 150.0.7871.47 allo…
CVE-2025-363215.733.6IBMwatsonx.data intelligenceCWE-80Vulnerabilities found in Watson Data Intelligence
CVE-2026-134499.133.5IBMBusiness Automation Manager Open EditionsCWE-611XXE attack in IBM Business Automation Manager Open Editions
CVE-2026-105137.233.4pfefferleWebmentionCWE-79Webmention <= 5.8.0 - Unauthenticated Stored Cross-Site Scripting via MF2 'ph…
CVE-2026-123886.533.4Red HatRed Hat Build of KeycloakCWE-266Keycloak-broker: keycloak: privilege escalation to realm administrator via im…
CVE-2026-570795.333.2SANKONet::BitTorrentCWE-22Net::BitTorrent versions before 2.1.0 for Perl write files outside the downlo…
CVE-2026-584487.133.0YunaiVyudao-cloudCWE-862yudao-cloud < 2026.06 - BPM Module Broken Access Control via process-instance…
CVE-2026-115469.832.8IBMWebSphere Application Server - LibertyCWE-918IBM WebSphere Application Server Liberty is affected by a server-side request…
CVE-2026-580138.232.6GNOMEGLibCWE-126Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"
CVE-2026-95764.932.6UnknownFluent Booking—Fluent Booking < 2.1.2 - Calendar Manager+ Sensitive Information Disclosure v…
CVE-2026-279556.632.4coollabsiocoolifyCWE-78Coolify: Command Injection via Single-Quote Breakout in `executeInDocker()`
CVE-2026-563656.332.3ImageMagickImageMagickCWE-401ImageMagick - Memory Leak in PNG Encoder via MNG Image Writing
CVE-2026-449497.032.2SUSERancherCWE-306Unauthenticated namespace creation and RBAC injection via rancher-webhook Fle…
CVE-2026-137798.132.1GoogleChromeCWE-416Use after free in Chromoting in Google Chrome on ChromeOS prior to 150.0.7871…
CVE-2026-580108.231.8GNOMEGLibCWE-126Glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()
CVE-2026-580128.231.8GNOMEGLibCWE-126Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append()…
CVE-2026-584477.131.7iv-orgInvidiousCWE-639Invidious - Cross-User Playlist Video Deletion via Missing Ownership Check
CVE-2026-449476.931.6SUSERancherCWE-281Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in Rancher
CVE-2026-449469.531.5SUSERancherCWE-294SAML Authentication Replay in Rancher
CVE-2026-139257.531.4GoogleChromeCWE-20Inappropriate implementation in Downloads in Google Chrome on Windows prior t…
CVE-2026-283225.631.4SolarWindsDatabase Performance AnalyzerCWE-20SolarWinds Database Performance Analyzer Stored Cross-Site Scripting Vulnerab…
CVE-2026-125604.431.4wpqodeEditorial Rating – Product Review & Rating SystemCWE-79Editorial Rating <= 4.0.5 - Authenticated (Administrator+) Stored Cross-Site …
CVE-2026-142094.331.4Red HatRed Hat build of Keycloak 26.4CWE-639Keycloak-admin-ui: keycloak-admin-ui:admin ui extension brute-force-user endp…
CVE-2026-117089.331.2IBMWebSphere Application ServerCWE-79IBM WebSphere Application Server is affected by a cross-site scripting vulner…
CVE-2026-117129.331.2IBMWebSphere Application ServerCWE-79IBM WebSphere Application Server is affected by a cross-site scripting vulner…
CVE-2026-141118.131.1GoogleChromeCWE-416Use after free in WebProtect in Google Chrome prior to 150.0.7871.47 allowed …
CVE-2026-138058.831.0GoogleChromeCWE-416Use after free in GFX in Google Chrome on Mac prior to 150.0.7871.47 allowed …
CVE-2026-138118.831.0GoogleChromeCWE-416Use after free in IME in Google Chrome prior to 150.0.7871.47 allowed a remot…
CVE-2026-138218.831.0GoogleChromeCWE-416Use after free in Canvas in Google Chrome prior to 150.0.7871.47 allowed a re…
CVE-2026-138458.831.0GoogleChromeCWE-416Use after free in DOM in Google Chrome prior to 150.0.7871.47 allowed a remot…
CVE-2026-138488.831.0GoogleChromeCWE-416Use after free in Forms in Google Chrome prior to 150.0.7871.47 allowed a rem…
CVE-2026-138888.831.0GoogleChromeCWE-416Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed …
CVE-2026-140918.831.0GoogleChromeCWE-416Use after free in DevTools in Google Chrome prior to 150.0.7871.47 allowed a …
CVE-2026-141078.831.0GoogleChromeCWE-416Use after free in Scheduling in Google Chrome prior to 150.0.7871.47 allowed …
CVE-2026-546963.730.9rubyjsonCWE-122Ruby JSON: JSON generator heap buffer overflow when streaming to an IO
CVE-2026-106555.930.7zephyrprojectzephyrCWE-416Use-after-free race in SNTP async client when closing the socket while the so…
CVE-2026-120856.530.7IBMUCD - IBM UrbanCode DeployCWE-201IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptable to an Insertion…
CVE-2026-563506.030.7n8nn8nCWE-285n8n - SSO Enforcement Bypass via API
CVE-2026-534335.730.5fzffzfCWE-407Denial of Service in fzf
CVE-2026-580117.530.3GNOMEGLibCWE-125Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid …
CVE-2026-125788.430.3deltawwDTMSoftCWE-502DTMSoft - Deserialization of Untrusted Data Vulnerability
CVE-2026-137989.630.0GoogleChromeCWE-122Heap buffer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 al…
CVE-2026-140878.830.0GoogleChromeCWE-787Heap buffer overflow in WebNN in Google Chrome on Windows prior to 150.0.7871…
CVE-2026-572046.929.4py-pdfpypdfCWE-400pypdf: Missing stream length values ignore defined limits
CVE-2026-141785.929.3openGauss-serveropenGauss-server-7.0.0-RC2CWE-416openGauss存在非法内存访问导致DoS漏洞
CVE-2025-363284.329.4IBMwatsonx.data intelligenceCWE-209Error Message Containing Sensitive Information found in Watson Data Intelligence
CVE-2026-117149.829.2IBMWebSphere Application Server - LibertyCWE-918IBM WebSphere Application Server Liberty is affected by an authorization bypa…
CVE-2026-131497.729.1juliangruberbrace-expansionCWE-400brace-expansion through 5.0.6 is vulnerable to denial of service. The expand(…
CVE-2026-91064.829.1GitHubEnterprise ServerCWE-451UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauth…
CVE-2026-583778.629.0jeecgbootJeecgBootCWE-862JeecgBoot 3.9.2 - Missing Authorization on OpenAPI Credential Management Endp…
CVE-2026-562497.229.0CapgoCapgoCWE-285Capgo - Unauthorized Channel Overwrite and Ownership Takeover via POST /chann…
CVE-2026-138027.528.9GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a rem…
CVE-2026-140647.528.9GoogleChromeCWE-416Use after free in PageInfo in Google Chrome on Android prior to 150.0.7871.47…
CVE-2026-278835.028.8coollabsiocoolifyCWE-639Coolify: IDOR in Deployment API - Cross-Team Deployment Information Disclosure
CVE-2025-363276.528.6IBMwatsonx.data intelligenceCWE-602Vulnerabilities found in Watson Data Intelligence
CVE-2026-583767.228.6DolibarrdolibarrCWE-89Dolibarr - SQL Injection via sqlfilters Parameter in Multiple REST API List E…
CVE-2026-563186.928.5CapgoCapgoCWE-200Capgo - Information Disclosure via /private/validate_password_compliance Endp…
CVE-2026-563276.928.5CapgoCapgoCWE-203Capgo - Unauthenticated Organization Existence Oracle via public.invite_user_…
CVE-2026-139687.528.3GoogleChromeCWE-20Insufficient validation of untrusted input in DevTools in Google Chrome prior…
CVE-2026-140746.528.1GoogleChromeCWE-1300Side-channel information leakage in WebAuthentication in Google Chrome on iOS…
CVE-2026-141088.828.0GoogleChromeCWE-416Use after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a re…
CVE-2026-101409.627.6IBMLangflow OSSCWE-639Cross-Tenant API Key Reuse and Billing Fraud in Langflow Voice Mode Subsystem
CVE-2026-563287.127.5CapgoCapgoCWE-670Capgo - Integrity Issue in Release Routing via Multiple Public Channels
CVE-2026-137769.827.4GoogleChromeCWE-843Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remo…
CVE-2026-139196.527.4GoogleChromeCWE-602Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0…
CVE-2026-139216.527.4GoogleChromeCWE-20Insufficient validation of untrusted input in DeviceBoundSessionCredentials i…
CVE-2026-139246.527.4GoogleChromeCWE-20Insufficient validation of untrusted input in WebView in Google Chrome on And…
CVE-2026-139266.527.4GoogleChromeCWE-20Insufficient validation of untrusted input in Network in Google Chrome prior …
CVE-2026-139306.527.4GoogleChromeCWE-602Insufficient policy enforcement in Actor in Google Chrome prior to 150.0.7871…
CVE-2026-140076.527.4GoogleChromeCWE-602Insufficient policy enforcement in PermissionsPolicy in Google Chrome prior t…
CVE-2026-140236.527.4GoogleChromeCWE-20Insufficient validation of untrusted input in SanitizerAPI in Google Chrome p…
CVE-2026-140336.527.4GoogleChromeCWE-602Insufficient policy enforcement in Media in Google Chrome on Windows prior to…
CVE-2026-140656.527.4GoogleChromeCWE-20Insufficient validation of untrusted input in PageInfo in Google Chrome prior…
CVE-2026-137918.127.3GoogleChromeCWE-20Insufficient validation of untrusted input in Downloads in Google Chrome prio…
CVE-2026-139236.527.2GoogleChromeCWE-457Uninitialized Use in GPU in Google Chrome on Android prior to 150.0.7871.47 a…
CVE-2026-139436.527.2GoogleChromeCWE-457Uninitialized Use in CSS in Google Chrome on Android prior to 150.0.7871.47 a…
CVE-2026-137899.627.0GoogleChromeCWE-416Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remot…
CVE-2026-137929.627.0GoogleChromeCWE-416Use after free in Touchbar in Google Chrome on Mac prior to 150.0.7871.47 all…
CVE-2026-138439.627.1GoogleChromeCWE-20Insufficient validation of untrusted input in Chrome for iOS in Google Chrome…
CVE-2026-138469.627.0GoogleChromeCWE-416Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed …
CVE-2026-138699.627.1GoogleChromeCWE-416Use after free in Device in Google Chrome on Windows prior to 150.0.7871.47 a…
CVE-2026-139019.627.1GoogleChromeCWE-20Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.787…
CVE-2026-139099.627.0GoogleChromeCWE-693Insufficient policy enforcement in DevTools in Google Chrome prior to 150.0.7…
CVE-2026-139209.627.1GoogleChromeCWE-20Insufficient validation of untrusted input in Media in Google Chrome on Windo…
CVE-2026-139349.627.0GoogleChromeCWE-20Insufficient validation of untrusted input in Dawn in Google Chrome on Androi…
CVE-2026-140179.627.0GoogleChromeCWE-693Inappropriate implementation in Navigation in Google Chrome prior to 150.0.78…
CVE-2026-140379.627.1GoogleChromeCWE-693Insufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.4…
CVE-2026-140439.627.1GoogleChromeCWE-416Use after free in GetUserMedia in Google Chrome prior to 150.0.7871.47 allowe…
CVE-2026-140449.627.1GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a rem…
CVE-2026-140559.627.1GoogleChromeCWE-20Insufficient validation of untrusted input in Device Trust in Google Chrome o…
CVE-2026-141069.627.1GoogleChromeCWE-20Insufficient validation of untrusted input in Text in Google Chrome on Androi…
CVE-2026-141099.627.1GoogleChromeCWE-20Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.…
CVE-2026-141209.627.1GoogleChromeCWE-20Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871…
CVE-2026-141529.627.0GoogleChromeCWE-787Out of bounds read and write in ANGLE in Google Chrome prior to 150.0.7871.47…
CVE-2026-138178.827.1GoogleChromeCWE-20Insufficient validation of untrusted input in Glic in Google Chrome prior to …
CVE-2026-138358.827.0GoogleChromeCWE-122Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 a…
CVE-2026-139038.827.0GoogleChromeCWE-602Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.…
CVE-2026-139158.827.0GoogleChromeCWE-416Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.…
CVE-2026-139188.827.1GoogleChromeCWE-416Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.…
CVE-2026-139288.827.1GoogleChromeCWE-20Insufficient validation of untrusted input in Enterprise in Google Chrome pri…
CVE-2026-139388.827.0GoogleChromeCWE-472Integer overflow in Fonts in Google Chrome prior to 150.0.7871.47 allowed a r…
CVE-2026-140058.827.1GoogleChromeCWE-416Use after free in Omnibox in Google Chrome on Android prior to 150.0.7871.47 …
CVE-2026-140098.827.0GoogleChromeCWE-20Inappropriate implementation in Passwords in Google Chrome prior to 150.0.787…
CVE-2026-140248.827.1GoogleChromeCWE-416Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allo…
CVE-2026-140258.827.0GoogleChromeCWE-416Use after free in Views in Google Chrome on Mac prior to 150.0.7871.47 allowe…
CVE-2026-140278.827.0GoogleChromeCWE-416Use after free in SignIn in Google Chrome prior to 150.0.7871.47 allowed a re…
CVE-2026-140368.827.1GoogleChromeCWE-602Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.…
CVE-2026-140418.827.0GoogleChromeCWE-602Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.787…
CVE-2026-140788.827.0GoogleChromeCWE-20Insufficient validation of untrusted input in WebRTC in Google Chrome prior t…
CVE-2026-141028.827.1GoogleChromeCWE-416Use after free in Passwords in Google Chrome prior to 150.0.7871.47 allowed a…
CVE-2026-140908.127.1GoogleChromeCWE-125Insufficient validation of untrusted input in CameraCapture in Google Chrome …
CVE-2026-581712.326.9HKUDSVibe-TradingCWE-22Vibe-Trading < 0.1.10 - Path Traversal via Swarm Run Identifier
CVE-2026-563316.926.8CapgoCapgoCWE-209Capgo - Improper Error Handling in Accept Invitation Endpoint via Invalid Mag…
CVE-2026-583735.326.6cvat-aicvatCWE-862CVAT < 2.69.0 - Missing Authorization on Quality Reports parent_id Filter Lea…
CVE-2026-581658.726.5openzitizitiCWE-862OpenZiti - Privilege Escalation to Admin via Unauthorized Enrollment Creation
CVE-2025-248166.526.5NokiaMantaRay NMCWE-284An Improper Access Control vulnerability in Nokia MantaRay NM
CVE-2026-105648.226.2IBMLangflow OSSCWE-918SSRF Vulnerability in Langflow OSS Legacy Components Bypasses Protection
CVE-2026-138317.526.2GoogleChromeCWE-416Out of bounds read and write in GPU in Google Chrome prior to 150.0.7871.47 a…
CVE-2026-138557.526.2GoogleChromeCWE-416Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allo…
CVE-2026-545026.326.2ohler55ojCWE-121Oj: Stack Buffer Overflow in Oj.dump via Large Indent
CVE-2026-115946.126.1IBMWebSphere Application ServerCWE-79IBM WebSphere Application Server is affected by multiple cross-site scripting…
CVE-2026-121144.425.9wpmartTeam Members – Multi Language Supported Team PluginCWE-79Team Members <= 8.7 - Authenticated (Administrator+) Stored Cross-Site Script…
CVE-2026-138839.625.8GoogleChromeCWE-843Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a rem…
CVE-2026-138258.825.8GoogleChromeCWE-457Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.47 allowed a r…
CVE-2026-583712.325.6seaweedfsseaweedfsCWE-79SeaweedFS < 4.30 - Cross-Origin Information Disclosure via Unvalidated JSONP …
CVE-2026-141019.625.6GoogleChromeCWE-269Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 1…
CVE-2026-138978.825.6GoogleChromeCWE-284Insufficient policy enforcement in Chromecast in Google Chrome prior to 150.0…
CVE-2026-138038.325.5GoogleChromeCWE-843Type Confusion in Chrome Tabs in Google Chrome prior to 150.0.7871.47 allowed…
CVE-2026-141518.325.5GoogleChromeCWE-669Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 al…
CVE-2026-580148.625.2GNOMEGLibCWE-193Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_l…
CVE-2026-138068.125.2GoogleChromeCWE-20Insufficient validation of untrusted input in Accessibility in Google Chrome …
CVE-2025-363596.525.2IBMDevOps AutomationCWE-613IBM DevOps Loop is susceptible to an Insufficient Session Expiration vulnerab…
CVE-2026-140389.325.0GoogleChromeCWE-20Insufficient validation of untrusted input in New Tab Page in Google Chrome p…
CVE-2026-92638.125.0zephyrprojectzephyrCWE-125Out-of-bounds read in Bluetooth Controller ISOAL framed RX reassembly leaks a…
CVE-2026-138198.125.0GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 al…
CVE-2026-140118.125.0GoogleChromeCWE-125Out of bounds read in SurfaceCapture in Google Chrome prior to 150.0.7871.47 …
CVE-2026-500405.125.0StoneFlyStorage ConcentratorCWE-79Cross-site Scripting in StoneFly Storage Concentrator
CVE-2026-567775.324.9n8nn8nCWE-184n8n - AST Validator Bypass in Python Code Node
CVE-2026-568095.124.9Ricoh Company, Ltd.Multiple laser printers and MFPs which implement Ricoh Web Image MonitorCWE-79Multiple laser printers and MFPs (multifunction printers) which implement Ric…
CVE-2026-140328.124.8GoogleChromeCWE-416Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 al…
CVE-2026-138298.324.7GoogleChromeCWE-20Insufficient validation of untrusted input in Settings in Google Chrome on Wi…
CVE-2026-138348.324.7GoogleChromeCWE-20Insufficient validation of untrusted input in ANGLE in Google Chrome prior to…
CVE-2026-563335.324.4CapgoCapgoCWE-20Capgo - Server-Side Validation Bypass via Direct Browser-Side Organization Se…
CVE-2026-139586.524.3GoogleChromeCWE-457Uninitialized Use in Codecs in Google Chrome on Windows prior to 150.0.7871.4…
CVE-2026-140086.524.3GoogleChromeCWE-457Uninitialized Use in WebXR in Google Chrome on Android prior to 150.0.7871.47…
CVE-2026-140106.524.3GoogleChromeCWE-457Uninitialized Use in Codecs in Google Chrome on Windows prior to 150.0.7871.4…
CVE-2026-140516.524.3GoogleChromeCWE-457Uninitialized Use in GamepadAPI in Google Chrome prior to 150.0.7871.47 allow…
CVE-2026-140706.524.3GoogleChromeCWE-457Integer overflow in WebNN in Google Chrome prior to 150.0.7871.47 allowed a r…
CVE-2026-140886.524.3GoogleChromeCWE-457Uninitialized Use in Canvas in Google Chrome on Android prior to 150.0.7871.4…
CVE-2026-141256.524.3GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a …
CVE-2026-141486.524.3GoogleChromeCWE-843Type Confusion in CSS in Google Chrome prior to 150.0.7871.47 allowed a remot…
CVE-2026-137998.124.2GoogleChromeCWE-416Use after free in QUIC in Google Chrome prior to 150.0.7871.47 allowed a remo…
CVE-2026-105856.324.3GitHubEnterprise ServerCWE-79Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed…
CVE-2026-1378210.024.2GoogleChromeCWE-416Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a r…
CVE-2026-137759.824.2GoogleChromeCWE-416Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remot…
CVE-2026-137809.624.2GoogleChromeCWE-20Insufficient validation of untrusted input in ANGLE in Google Chrome prior to…
CVE-2026-137819.624.2GoogleChromeCWE-20Insufficient validation of untrusted input in Skia in Google Chrome prior to …
CVE-2026-137859.624.2GoogleChromeCWE-416Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 al…
CVE-2026-137969.624.2GoogleChromeCWE-472Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowe…
CVE-2026-137979.624.2GoogleChromeCWE-20Insufficient validation of untrusted input in Chromecast in Google Chrome pri…
CVE-2026-140569.624.0GoogleChromeCWE-20Insufficient validation of untrusted input in Media in Google Chrome prior to…
CVE-2026-140939.624.2GoogleChromeCWE-416Use after free in Cast in Google Chrome prior to 150.0.7871.47 allowed a remo…
CVE-2026-140959.624.2GoogleChromeCWE-20Insufficient policy enforcement in Browser in Google Chrome prior to 150.0.78…
CVE-2026-140979.624.2GoogleChromeCWE-693Inappropriate implementation in WebAppInstalls in Google Chrome on Mac prior …
CVE-2026-137778.824.2GoogleChromeCWE-20Insufficient validation of untrusted input in iOSWeb in Google Chrome on iOS …
CVE-2026-137838.824.2GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a rem…
CVE-2026-137848.824.2GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a rem…
CVE-2026-140848.824.0GoogleChromeCWE-20Insufficient validation of untrusted input in Chromoting in Google Chrome pri…
CVE-2026-140998.824.2GoogleChromeCWE-416Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.…
CVE-2026-81417.224.0Connekt MediaAjax Load More - FiltersCWE-79Ajax Load More - Filters <= 3.4.1 - Unauthenticated Stored Cross-Site Scripti…
CVE-2026-481926.824.0SiemensMendix Studio Pro 10.11CWE-94A vulnerability has been identified in Mendix Studio Pro 10.11 (All versions)…
CVE-2026-137906.524.0GoogleChromeCWE-1300Side-channel information leakage in Scroll in Google Chrome prior to 150.0.78…
CVE-2026-138106.524.0GoogleChromeCWE-200Inappropriate implementation in Input in Google Chrome on Linux prior to 150.…
CVE-2026-138166.524.0GoogleChromeCWE-20Insufficient validation of untrusted input in File Input in Google Chrome on …
CVE-2026-138476.524.0GoogleChromeCWE-20Insufficient validation of untrusted input in Chrome for iOS in Google Chrome…
CVE-2026-139066.524.0GoogleChromeCWE-125Out of bounds read in Codecs in Google Chrome prior to 150.0.7871.47 allowed …
CVE-2026-139106.524.0GoogleChromeCWE-693Insufficient policy enforcement in WebXR in Google Chrome on Android prior to…
CVE-2026-139226.524.0GoogleChromeCWE-1300Side-channel information leakage in Paint in Google Chrome prior to 150.0.787…
CVE-2026-139356.524.0GoogleChromeCWE-1300Side-channel information leakage in ComputePressure in Google Chrome prior to…
CVE-2026-140046.524.0GoogleChromeCWE-200Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 a…
CVE-2026-140216.524.0GoogleChromeCWE-20Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to…
CVE-2026-140226.524.0GoogleChromeCWE-20Insufficient validation of untrusted input in Network in Google Chrome prior …
CVE-2026-140506.524.0GoogleChromeCWE-693Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.…
CVE-2026-140596.524.0GoogleChromeCWE-693Insufficient policy enforcement in Related-Website-Sets in Google Chrome prio…
CVE-2026-140856.524.0GoogleChromeCWE-1300Side-channel information leakage in CSS in Google Chrome prior to 150.0.7871.…
CVE-2026-141036.524.0GoogleChromeCWE-416Use after free in SSL in Google Chrome on ChromeOS prior to 150.0.7871.47 all…
CVE-2026-141466.524.0GoogleChromeCWE-200Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 a…
CVE-2026-138896.523.6GoogleChromeCWE-20Side-channel information leakage in WebAuthentication in Google Chrome on iOS…
CVE-2026-101298.523.6IBMLangflow OSSCWE-918SSRF via HTTP Redirect Following in Langflow API Request Component
CVE-2026-563207.123.5CapgoCapgoCWE-285Capgo - Org/App Scope Mismatch in Device Creation Endpoint
CVE-2026-138077.523.3GoogleChromeCWE-416Use after free in Import in Google Chrome on iOS prior to 150.0.7871.47 allow…
CVE-2026-138519.123.2GoogleChromeCWE-20Insufficient validation of untrusted input in WebAppInstalls in Google Chrome…
CVE-2026-138529.123.2GoogleChromeCWE-20Insufficient validation of untrusted input in WebAppInstalls in Google Chrome…
CVE-2026-139475.322.9GoogleChromeCWE-457Uninitialized Use in XR in Google Chrome prior to 150.0.7871.47 allowed a rem…
CVE-2026-139505.322.9GoogleChromeCWE-457Uninitialized Use in GPU in Google Chrome prior to 150.0.7871.47 allowed a re…
CVE-2026-138336.522.8GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 all…
CVE-2026-138539.622.6GoogleChromeCWE-416Use after free in Journeys in Google Chrome prior to 150.0.7871.47 allowed a …
CVE-2026-138549.622.6GoogleChromeCWE-416Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allo…
CVE-2026-138599.622.6GoogleChromeCWE-693Inappropriate implementation in ANGLE in Google Chrome prior to 150.0.7871.47…
CVE-2026-138619.622.6GoogleChromeCWE-416Use after free in Core in Google Chrome prior to 150.0.7871.47 allowed a remo…
CVE-2026-138789.622.6GoogleChromeCWE-416Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 al…
CVE-2026-138809.622.6GoogleChromeCWE-416Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed …
CVE-2026-141139.622.6GoogleChromeCWE-416Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 …
CVE-2026-139326.522.7GoogleChromeCWE-284Inappropriate implementation in Sharing in Google Chrome on Android prior to …
CVE-2026-139366.522.7GoogleChromeCWE-284Inappropriate implementation in Passwords in Google Chrome on Android prior t…
CVE-2026-139376.522.7GoogleChromeCWE-284Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.…
CVE-2026-139496.522.7GoogleChromeCWE-284Insufficient policy enforcement in Payments in Google Chrome on Android prior…
CVE-2026-139546.522.7GoogleChromeCWE-284Insufficient policy enforcement in XML in Google Chrome on Android prior to 1…
CVE-2026-140196.522.7GoogleChromeCWE-522Inappropriate implementation in Passwords in Google Chrome prior to 150.0.787…
CVE-2026-141556.522.7GoogleChromeCWE-284Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to…
CVE-2026-138018.322.4GoogleChromeCWE-472Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowe…
CVE-2026-138048.322.4GoogleChromeCWE-416Use after free in Chromecast in Google Chrome prior to 150.0.7871.47 allowed …
CVE-2026-138238.322.4GoogleChromeCWE-416Use after free in Glic in Google Chrome prior to 150.0.7871.47 allowed a remo…
CVE-2026-138328.322.4GoogleChromeCWE-416Use after free in Headless in Google Chrome prior to 150.0.7871.47 allowed a …
CVE-2026-138418.322.4GoogleChromeCWE-472Integer overflow in Skia in Google Chrome prior to 150.0.7871.47 allowed a re…
CVE-2026-139518.322.4GoogleChromeCWE-693Insufficient policy enforcement in USB in Google Chrome prior to 150.0.7871.4…
CVE-2026-138147.522.4GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a rem…
CVE-2026-137748.122.4GoogleChromeCWE-416Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed …
CVE-2025-363726.522.3IBMDb2CWE-538IBM® Db2® could disclose sensitive information to an authenticated user from …
CVE-2026-139646.522.3GoogleChromeCWE-284Insufficient policy enforcement in WebView in Google Chrome on Android prior …
CVE-2026-141186.522.4GoogleChromeCWE-290Insufficient data validation in DevTools in Google Chrome prior to 150.0.7871…
CVE-2026-138138.322.3GoogleChromeCWE-20Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri…
CVE-2026-138247.522.3GoogleChromeCWE-20Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0…
CVE-2026-138567.522.3GoogleChromeCWE-20Insufficient validation of untrusted input in Speech in Google Chrome on Andr…
CVE-2026-138917.522.3GoogleChromeCWE-20Insufficient validation of untrusted input in Extensions in Google Chrome pri…
CVE-2026-141157.522.3GoogleChromeCWE-20Insufficient validation of untrusted input in Cast in Google Chrome prior to …
CVE-2026-139115.322.2GoogleChromeCWE-20Insufficient policy enforcement in Spellcheck in Google Chrome prior to 150.0…
CVE-2026-563696.322.0ImageMagickImageMagickCWE-323ImageMagick - Information Disclosure via AES-CTR Nonce Reuse in PasskeyEnciph…
CVE-2026-140344.322.1GoogleChromeCWE-284Inappropriate implementation in WebXR in Google Chrome on Android prior to 15…
CVE-2026-138666.521.7GoogleChromeCWE-20Inappropriate implementation in Input in Google Chrome on Android prior to 15…
CVE-2026-138716.521.7GoogleChromeCWE-602Insufficient policy enforcement in GuestView in Google Chrome prior to 150.0.…
CVE-2026-139006.521.7GoogleChromeCWE-20Inappropriate implementation in Chromecast in Google Chrome prior to 150.0.78…
CVE-2026-139626.521.7GoogleChromeCWE-20Insufficient data validation in PDF in Google Chrome prior to 150.0.7871.47 a…
CVE-2026-140544.321.5GoogleChromeCWE-602Insufficient policy enforcement in Network in Google Chrome prior to 150.0.78…
CVE-2026-140664.321.5GoogleChromeCWE-20Insufficient validation of untrusted input in Chrome for iOS in Google Chrome…
CVE-2026-138508.821.4GoogleChromeCWE-20Insufficient validation of untrusted input in Chrome for iOS in Google Chrome…
CVE-2026-583747.121.4w1.fihostapdCWE-193In hostapd before 2.12, a missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.1…
CVE-2026-138096.521.4GoogleChromeCWE-1300Side-channel information leakage in Safe Browsing in Google Chrome on iOS pri…
CVE-2026-138736.521.4GoogleChromeCWE-125Out of bounds read in Layout in Google Chrome prior to 150.0.7871.47 allowed …
CVE-2026-140696.521.4GoogleChromeCWE-472Integer overflow in WebNN in Google Chrome prior to 150.0.7871.47 allowed a r…
CVE-2026-140716.521.4GoogleChromeCWE-1300Side-channel information leakage in WebAudio in Google Chrome prior to 150.0.…
CVE-2026-140966.521.4GoogleChromeCWE-200Inappropriate implementation in Input in Google Chrome on Android prior to 15…
CVE-2026-140986.521.4GoogleChromeCWE-200Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 a…
CVE-2026-141006.521.4GoogleChromeCWE-20Insufficient data validation in NetworkCache in Google Chrome prior to 150.0.…
CVE-2026-138586.521.3GoogleChromeCWE-125Out of bounds read in FFmpeg in Google Chrome prior to 150.0.7871.47 allowed …

Results continue: ranks 401–641.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-30 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.