AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H L H 8.8 .1565 96.6 —
AFFECTED Product Versions Fixed ADC 14.1 – — Gateway 14.1 – —
TIMELINE May 13 Reserved by CNA Jun 30 Published (CNA: NetScaler)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
641 CVEs published, led by Google (382).
641 CVEs published June 30, 2026: 97 critical, 200 high, 327 medium, 17 low; 0 in the KEV catalog at press time; 16 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 241 on continuation pages.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 7942 | 12403 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
537 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 513 | 1480 | 119 | 854 | 506 | 1 | 11 | 2 | 0.1 | 7.8 | .0014 | -128 ▼ |
| 1090 | 1265 | 133 | 568 | 527 | 37 | 77 | 6 | 0.5 | 7.5 | .0024 | +922 ▲ | |
| microsoft | 221 | 757 | 58 | 521 | 172 | 6 | 286 | 19 | 2.5 | 7.8 | .0045 | +55 ▲ |
| red hat | 128 | 222 | 10 | 91 | 108 | 13 | 2 | 0 | 0.0 | 6.5 | .0030 | +86 ▲ |
| apple | 52 | 104 | 2 | 28 | 72 | 2 | 88 | 7 | 6.7 | 6.5 | .0032 | +30 ▲ |
| canonical | 6 | 20 | 2 | 5 | 8 | 5 | 0 | 0 | 0.0 | 5.5 | .0011 | -8 ▼ |
| freebsd | 9 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0016 | +2 ▲ |
| suse | 11 | 13 | 3 | 7 | 3 | 0 | 0 | 0 | 0.0 | 8.6 | .0039 | +9 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 10 | 22 | 6 | 6 | 10 | 0 | 56 | 11 | 50.0 | 7.3 | .0566 | +5 ▲ |
| netgear | 17 | 17 | 0 | 0 | 16 | 1 | 0 | 0 | 0.0 | 4.3 | .0024 | +17 ▲ |
| palo alto networks | 9 | 11 | 1 | 2 | 7 | 1 | 13 | 2 | 18.2 | 5.9 | .0022 | +7 ▲ |
| ubiquiti | 8 | 11 | 7 | 4 | 0 | 0 | 3 | 3 | 27.3 | 9.9 | .0083 | +6 ▲ |
| ivanti | 4 | 9 | 4 | 5 | 0 | 0 | 25 | 5 | 55.6 | 8.8 | .5187 | +2 ▲ |
| checkpoint | 3 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | -3 ▼ |
| fortinet | 2 | 9 | 4 | 3 | 2 | 0 | 28 | 3 | 33.3 | 8.3 | .0076 | +1 ▲ |
| f5 | 6 | 8 | 4 | 3 | 1 | 0 | 4 | 1 | 12.5 | 8.9 | .0225 | +4 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 121 | 155 | 24 | 57 | 63 | 10 | 33 | 1 | 0.6 | 7.2 | .0053 | +100 ▲ |
| mozilla | 50 | 56 | 12 | 18 | 26 | 0 | 9 | 0 | 0.0 | 7.3 | .0026 | +44 ▲ |
| gitlab | 24 | 31 | 0 | 5 | 21 | 5 | 4 | 2 | 6.5 | 4.4 | .0029 | +17 ▲ |
| docker | 4 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.2 | .0016 | +1 ▲ |
| github | 4 | 6 | 1 | 1 | 4 | 0 | 0 | 0 | 0.0 | 6.2 | .0037 | +2 ▲ |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 4 | 1 | 20.0 | 5.1 | .0026 | -5 ▼ |
| wordpress | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 242 | 270 | 132 | 116 | 18 | 4 | 27 | 2 | 0.7 | 8.8 | .0040 | +217 ▲ |
| adobe | 142 | 144 | 11 | 53 | 78 | 2 | 19 | 2 | 1.4 | 5.8 | .0021 | +142 ▲ |
| ibm | 75 | 124 | 36 | 42 | 46 | 0 | 6 | 0 | 0.0 | 7.5 | .0034 | +26 ▲ |
| progress | 5 | 9 | 1 | 7 | 1 | 0 | 6 | 0 | 0.0 | 7.5 | .0036 | +1 ▲ |
| solarwinds | 4 | 7 | 2 | 3 | 2 | 0 | 10 | 4 | 57.1 | 7.5 | .4001 | +4 ▲ |
| veeam | 1 | 4 | 2 | 2 | 0 | 0 | 1 | 0 | 0.0 | 9.0 | .0052 | -2 ▼ |
| zohocorp | 1 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | -1 ▼ |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 5 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -13 ▼ |
| d-link | 10 | 12 | 0 | 5 | 2 | 5 | 3 | 0 | 0.0 | 5.8 | .0058 | +8 ▲ |
| siemens | 8 | 9 | 0 | 4 | 5 | 0 | 0 | 0 | 0.0 | 6.9 | .0021 | +7 ▲ |
| rockwell automation | 7 | 7 | 1 | 5 | 1 | 0 | 0 | 0 | 0.0 | 8.7 | .0030 | +7 ▲ |
| abb | 6 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | +6 ▲ |
| schneider electric | 6 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0042 | +6 ▲ |
| moxa | 5 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | +5 ▲ |
| dahua | 3 | 3 | 0 | 1 | 1 | 1 | 0 | 0 | 0.0 | 6.9 | .0036 | +3 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| spring | 72 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | +71 ▲ |
| sourcecodester | 49 | 71 | 0 | 0 | 36 | 35 | 0 | 0 | 0.0 | 5.5 | .0027 | +29 ▲ |
| openclaw | 61 | 67 | 0 | 35 | 22 | 10 | 0 | 0 | 0.0 | 7.0 | .0021 | +55 ▲ |
| edimax | 14 | 65 | 0 | 39 | 0 | 26 | 1 | 0 | 0.0 | 7.4 | .0080 | -33 ▼ |
| capgo | 61 | 61 | 2 | 31 | 27 | 1 | 0 | 0 | 0.0 | 7.1 | .0039 | +61 ▲ |
| themerex | 58 | 58 | 5 | 53 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0043 | +58 ▲ |
| dell | 38 | 56 | 2 | 30 | 24 | 0 | 2 | 1 | 1.8 | 7.3 | .0017 | +26 ▲ |
| itsourcecode | 43 | 53 | 0 | 0 | 18 | 35 | 0 | 0 | 0.0 | 2.1 | .0027 | +33 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-10520 | .9991 | 100.0 | 10.0 |
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-35273 | .9547 | 99.9 | 9.8 |
| CVE-2026-20230 | .8820 | 99.8 | 8.6 |
| CVE-2026-34910 | .8747 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-50751 | .8377 | 99.7 | 9.3 |
| CVE-2026-48907 | .7810 | 99.5 | 10.0 |
| CVE-2026-34909 | .6390 | 99.2 | 10.0 |
| CVE-2026-49160 | .5383 | 98.9 | 7.5 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-10520 | 10.0 | .9991 | KEV |
| CVE-2026-34910 | 10.0 | .8747 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-48907 | 10.0 | .7810 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-13773 | 10.0 | .0610 | |
| CVE-2026-56415 | 10.0 | .0436 | |
| CVE-2026-56413 | 10.0 | .0419 | |
| CVE-2026-53576 | 10.0 | .0330 | |
| CVE-2026-53753 | 10.0 | .0290 |
| Vendor | CVEs |
|---|---|
| 1090 | |
| linux | 513 |
| oracle | 242 |
| microsoft | 221 |
| adobe | 142 |
| red hat | 128 |
| apache | 121 |
| ibm | 75 |
| spring | 72 |
| capgo | 61 |
| Vendor | KEV |
|---|---|
| microsoft | 19 |
| cisco | 11 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| berriai | 3 |
| fortinet | 3 |
| smartertools | 3 |
| ubiquiti | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 49 |
| Packagist | 15 |
| PyPI | 9 |
| npm | 6 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2025-48595 | 0 | |
| CVE-2026-10520 | ivanti | 0 |
| CVE-2026-11645 | 0 | |
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-20245 | Cisco | 0 |
| CVE-2026-20253 | Splunk | 0 |
| CVE-2026-20262 | Cisco | 0 |
| CVE-2026-28318 | SolarWinds | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1686 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1686 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1686 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1686 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1686 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1686 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1686 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1686 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1686 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1686 |
EXPLOIT PUBLISHED — GNOME GLib: 6 CVEs (CVE-2026-58010, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015, CVE-2026-58016). Public exploit references added.
EXPLOIT PUBLISHED — zephyrproject zephyr: 5 CVEs (CVE-2026-9263, CVE-2026-10652, CVE-2026-10653, CVE-2026-10654, CVE-2026-10655). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2026-4629 (Red Hat build of Keycloak 26.4). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54672 (electron-userland electron-builder). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56364 (ImageMagick). Public exploit reference added.
DUE DATE PASSED — CVE-2026-20262 (Cisco Catalyst SD-WAN Manager). CISA remediation deadline was June 29, 2026; still in catalog.
How to read these box scores · glossary
641 CVEs published. 25 box scores and 375 table rows below; the remaining 241 continue on page 2 — every CVE is listed, nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H L H 8.8 .1565 96.6 —
AFFECTED Product Versions Fixed ADC 14.1 – — Gateway 14.1 – —
TIMELINE May 13 Reserved by CNA Jun 30 Published (CNA: NetScaler)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0914 94.9 —
AFFECTED Product Versions Fixed conductor 3.21.21 – —
TIMELINE Jun 29 Reserved by CNA Jun 30 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0610 92.9 —
AFFECTED Product Versions Fixed WebSphere Extreme Scale 8.6.1.0 – —
TIMELINE Jun 29 Reserved by CNA Jun 30 Published (CNA: ibm)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0436 90.5 —
AFFECTED Product Versions Fixed Storage Concentrator unspecified 8.0.4.29 Storage Concentrator Virtual Machine unspecified 8.0.4.29
TIMELINE Jun 22 Reserved by CNA Jun 30 Published (CNA: icscert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0419 90.2 —
AFFECTED Product Versions Fixed Storage Concentrator unspecified 8.0.4.29 Storage Concentrator Virtual Machine unspecified 8.0.4.29
TIMELINE Jun 22 Reserved by CNA Jun 30 Published (CNA: icscert)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H L N 9.3 .0295 86.1 —
AFFECTED Product Versions Fixed ColdFusion unspecified —
TIMELINE May 21 Reserved by CNA Jun 30 Published (CNA: adobe)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0253 83.7 —
AFFECTED Product Versions Fixed Grav unspecified 2.0.0-beta.2
TIMELINE Jun 22 Reserved by CNA Jun 30 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0248 83.3 —
AFFECTED Product Versions Fixed DGM3103SCT firmware version 3.2.5.4 and prior – —
TIMELINE Jun 23 Reserved by CNA Jun 30 Published (CNA: jpcert)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0142 70.8 —
AFFECTED Product Versions Fixed ColdFusion unspecified —
TIMELINE May 21 Reserved by CNA Jun 30 Published (CNA: adobe)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0135 69.4 —
AFFECTED Product Versions Fixed txtai unspecified 11b32da720f03276199ebc5583c15fc5d1ccafd3
TIMELINE Jun 30 Reserved by CNA Jun 30 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0129 68.1 —
AFFECTED Product Versions Fixed ColdFusion unspecified —
TIMELINE May 21 Reserved by CNA Jun 30 Published (CNA: adobe)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0126 67.3 —
AFFECTED Product Versions Fixed ColdFusion unspecified —
TIMELINE May 21 Reserved by CNA Jun 30 Published (CNA: adobe)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0126 67.3 —
AFFECTED Product Versions Fixed ColdFusion unspecified —
TIMELINE May 21 Reserved by CNA Jun 30 Published (CNA: adobe)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0124 66.8 —
AFFECTED Product Versions Fixed OpenAPI.NET >= 2.0.0-preview11, < 2.7.5 – —
TIMELINE May 30 Reserved by CNA Jun 30 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0117 65.1 —
AFFECTED Product Versions Fixed coolify < 4.0.0-beta.464 – —
TIMELINE Feb 25 Reserved by CNA Jun 30 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0117 64.9 —
AFFECTED Product Versions Fixed Adobe Campaign Classic (ACC) unspecified —
TIMELINE May 21 Reserved by CNA Jun 30 Published (CNA: adobe)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N N H H 7.2 .0112 63.6 —
AFFECTED Product Versions Fixed seaweedfs unspecified —
TIMELINE Jun 30 Reserved by CNA Jun 30 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N N A H H H 8.4 .0109 62.7 —
AFFECTED Product Versions Fixed RPG MAKER MV 1.6.3 and earlier – — RPG MAKER MZ 1.10.0 and earlier – —
TIMELINE Jun 19 Reserved by CNA Jun 30 Published (CNA: jpcert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H L H 8.8 .0104 61.4 —
AFFECTED Product Versions Fixed ADC 14.1 – — Gateway 14.1 – —
TIMELINE May 13 Reserved by CNA Jun 30 Published (CNA: NetScaler)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C H H N 9.3 .0103 61.0 —
AFFECTED Product Versions Fixed ColdFusion unspecified —
TIMELINE May 21 Reserved by CNA Jun 30 Published (CNA: adobe)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0090 57.1 —
AFFECTED Product Versions Fixed LlamaFactory unspecified —
TIMELINE Jun 29 Reserved by CNA Jun 30 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0086 55.7 —
AFFECTED Product Versions Fixed Db2 11.5.0 – —
TIMELINE May 29 Reserved by CNA Jun 30 Published (CNA: ibm)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N H H 8.8 .0085 55.5 —
AFFECTED Product Versions Fixed ChatDev unspecified 4fd4da603801766b14ad8788649cfc1ad21f99a6
TIMELINE Jun 29 Reserved by CNA Jun 30 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N P H H N 7.6 .0084 55.1 —
AFFECTED Product Versions Fixed picklescan unspecified 0.0.30
TIMELINE Jun 20 Reserved by CNA Jun 30 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H N N 8.6 .0083 54.8 —
AFFECTED Product Versions Fixed ColdFusion unspecified —
TIMELINE May 21 Reserved by CNA Jun 30 Published (CNA: adobe)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-11367 | 6.5 | 53.6 | andrasweb | PixMagix – WordPress Image Editor | CWE-22 | PixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' P… |
| CVE-2026-49432 | 7.5 | 53.3 | Apache Software Foundation | Apache ActiveMQ | CWE-20 | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative c… |
| CVE-2026-11595 | 7.5 | 53.2 | IBM | WebSphere Application Server | CWE-22 | IBM WebSphere Application Server is affected by a Path Traversal vulnerability |
| CVE-2026-50734 | 7.5 | 51.8 | Apache Software Foundation | Apache ActiveMQ Client | CWE-789 | Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authenticat… |
| CVE-2026-53916 | 7.5 | 51.8 | Apache Software Foundation | Apache ActiveMQ | CWE-789 | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header… |
| CVE-2026-53917 | 7.5 | 51.8 | Apache Software Foundation | Apache ActiveMQ | CWE-789 | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ… |
| CVE-2026-58370 | 9.2 | 51.1 | woodpecker-ci | woodpecker | CWE-290 | Woodpecker < 3.15.0 - GitLab Approval Gate Bypass via Spoofable Commit Author… |
| CVE-2026-58446 | 6.9 | 50.5 | presenton | presenton | CWE-306 | Presenton < 0.8.8-beta - Authentication Bypass of Session Auth via Unprotecte… |
| CVE-2026-7871 | 9.8 | 50.2 | IBM | Langflow OSS | CWE-502 | Insecure Deserialization in Redis Cache Backend |
| CVE-2026-50750 | 7.5 | 49.9 | Apache Software Foundation | Apache ActiveMQ Broker | CWE-400 | Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authenticat… |
| CVE-2026-52760 | 6.1 | 49.6 | Apache Software Foundation | Apache ActiveMQ | CWE-79 | Apache ActiveMQ, Apache ActiveMQ Web Console: Stored XSS via Unescaped values… |
| CVE-2026-53691 | 8.6 | 49.2 | Redeight | Redeight CMS | CWE-434 | Remote Code Execution in Redeight CMS |
| CVE-2026-50003 | 9.3 | 49.0 | OFFIS DICOM | DCMTK Toolkit | CWE-22 | OFFIS DCMTK Toolkit Path Traversal |
| CVE-2026-35505 | 8.7 | 48.2 | OFFIS DICOM | DCMTK Toolkit | CWE-401 | OFFIS DCMTK Toolkit Missing Release of Memory after Effective Lifetime |
| CVE-2026-50254 | 8.7 | 48.2 | OFFIS DICOM | DCMTK Toolkit | CWE-401 | OFFIS DCMTK Toolkit Missing Release of Memory after Effective Lifetime |
| CVE-2026-7803 | 9.8 | 48.0 | IBM | Langflow OSS | CWE-20 | Flow Validation Bypass via Empty Component Type Field |
| CVE-2025-71363 | 7.6 | 47.8 | picklescan | picklescan | CWE-502 | picklescan - Arbitrary Code Execution via Undetected cProfile.run in Pickle D… |
| CVE-2025-71374 | 7.6 | 47.8 | picklescan | picklescan | CWE-502 | picklescan - Arbitrary Code Execution via Undetected profile.Profile.run |
| CVE-2025-71352 | 7.6 | 47.8 | picklescan | picklescan | CWE-693 | picklescan - Remote Code Execution via Undetected trace.Trace.runctx in Pickl… |
| CVE-2026-58369 | 6.9 | 47.8 | woodpecker-ci | woodpecker | CWE-476 | Woodpecker < 3.15.0 - Unauthenticated NULL Pointer Dereference in /api/orgs/l… |
| CVE-2026-44628 | 8.7 | 47.8 | OFFIS DICOM | DCMTK Toolkit | CWE-843 | OFFIS DCMTK Toolkit Type Confusion |
| CVE-2026-58375 | 8.7 | 47.6 | jeecgboot | jimureport | CWE-306 | JimuReport 2.5.0 - Unauthenticated Report Export via /jmreport/auto/export |
| CVE-2026-8655 | 8.8 | 47.5 | NetScaler | ADC | CWE-119 | Multiple Memory overflow vulnerabilities leading to unpredictable or erroneou… |
| CVE-2026-14162 | 9.3 | 47.5 | Advantech | Hospital Quering Management | CWE-306 | Advantech|Hospital Quering Management - Missing Authentication |
| CVE-2026-49434 | 7.5 | 47.5 | Apache Software Foundation | Apache ActiveMQ Broker | CWE-20 | Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: LdapNetworkConn… |
| CVE-2026-52195 | 7.5 | 47.4 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo… |
| CVE-2026-52196 | 7.5 | 47.4 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo… |
| CVE-2026-56233 | 8.7 | 47.3 | Capgo | Capgo | CWE-22 | Capgo - SSRF and Privilege Escalation via Path Traversal in Builder Upload Proxy |
| CVE-2026-12240 | 8.0 | 47.2 | qlstudio | Export User Data | CWE-502 | Export User Data <= 2.2.6 - Authenticated (Subscriber+) PHP Object Injection … |
| CVE-2026-48314 | 6.5 | 47.0 | Adobe | ColdFusion | CWE-22 | ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Pa… |
| CVE-2025-71349 | 7.6 | 46.7 | picklescan | picklescan | CWE-502 | picklescan - Arbitrary Code Execution via Undetected trace.Trace.run in Pickl… |
| CVE-2026-13207 | 8.7 | 46.4 | Frangoteam | FUXA SCADA/HMI | CWE-290 | Frangoteam FUXA SCADA/HMI Authentication Bypass by Spoofing |
| CVE-2026-58168 | 7.7 | 45.9 | HKUDS | DeepTutor | CWE-862 | DeepTutor < 1.4.10 - Insecure Default Grants Unrestricted MCP Tool Access to … |
| CVE-2026-52197 | 7.5 | 45.2 | n/a | n/a | CWE-400 | An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker … |
| CVE-2026-10816 | 7.1 | 45.0 | NetScaler | ADC | CWE-610 | Arbitrary File Read (Unauthenticated) |
| CVE-2025-71355 | 7.6 | 44.9 | Picklescan | Picklescan | CWE-184 | Picklescan - Arbitrary Code Execution via Unsafe Numpy Function Detection Bypass |
| CVE-2026-52193 | 7.5 | 44.5 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo… |
| CVE-2026-52198 | 7.5 | 44.5 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo… |
| CVE-2026-58172 | 9.3 | 44.3 | ThreeMammals | Ocelot | CWE-288 | Ocelot - IP Allow/Block List Bypass for WebSocket Upgrade Requests |
| CVE-2026-10134 | 10.0 | 44.3 | IBM | Langflow OSS | CWE-94 | Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows |
| CVE-2026-35098 | 6.9 | 44.3 | KTM System | e-BOK | CWE-307 | Improper Restriction of Excessive Authentication Attempts in KTM System e-BOK |
| CVE-2026-54475 | 7.5 | 44.2 | Apache Software Foundation | Apache ActiveMQ Broker | CWE-862 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Temporary desti… |
| CVE-2025-53648 | 5.4 | 44.1 | Apache Software Foundation | Apache Gravitino | CWE-89 | Apache Gravitino: SQL misconfiguration can access or truncate files |
| CVE-2026-10817 | 6.9 | 44.1 | NetScaler | ADC | CWE-125 | Insufficient input validation leading to memory overread |
| CVE-2026-13474 | 8.7 | 43.8 | NetScaler | ADC | CWE-401 | Denial of service via malformed HTTP/2 requests |
| CVE-2026-58170 | 7.2 | 43.8 | HKUDS | Vibe-Trading | CWE-22 | Vibe-Trading < 0.1.10 - Path Traversal in Proposal Identifier Allows Forging … |
| CVE-2026-13766 | 9.8 | 43.5 | EXODIST | DBIx::QuickORM | CWE-89 | DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unqu… |
| CVE-2026-14161 | 8.7 | 43.5 | Advantech | Hospital Queuing Management | CWE-200 | Advantech|Hospital Queuing Management - Sensitive Data Exposure |
| CVE-2026-55721 | 9.2 | 43.3 | StoneFly | Storage Concentrator | CWE-89 | SQL Injection in StoneFly Storage Concentrator |
| CVE-2026-13759 | 8.8 | 43.3 | IBM | WebSphere Extreme Scale | CWE-502 | IBM WebSphere eXtreme Scale is affected by Insecure Deserilization |
| CVE-2026-58016 | 9.1 | 43.3 | GNOME | GLib | CWE-191 | Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new… |
| CVE-2026-48307 | 8.8 | 43.2 | Adobe | ColdFusion | CWE-79 | ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79) |
| CVE-2025-71371 | 7.6 | 43.2 | picklescan | picklescan | CWE-502 | picklescan - Remote Code Execution via code.InteractiveInterpreter Detection … |
| CVE-2026-12819 | 9.3 | 43.2 | deltaww | DVP-12SE | CWE-306 | DVP-12SE Missing Authentication and Unauthorized Write access Vulnerability |
| CVE-2026-9711 | 9.8 | 43.0 | EventON | EventON (Pro) - WordPress Virtual Event Calendar Plugin | CWE-89 | EventON - WordPress Virtual Event Calendar Plugin <= 5.0.11 - Unauthenticated… |
| CVE-2026-56286 | 7.0 | 42.9 | Capgo | Capgo | CWE-306 | Capgo - Account Deletion Without Password Confirmation |
| CVE-2026-12076 | 9.3 | 42.5 | Raytha | Raytha | CWE-89 | SQL Injection in Raytha CMS |
| CVE-2026-7873 | 9.9 | 42.4 | IBM | Langflow OSS | CWE-94 | Code Injection Vulnerability in Code Validation Endpoint |
| CVE-2026-12073 | 9.8 | 42.3 | metagauss | ProfileGrid – User Profiles, Groups and Communities | CWE-639 | ProfileGrid - User Profiles, Groups and Communities <= 5.9.9.5 - Unauthentica… |
| CVE-2026-56278 | 9.3 | 42.3 | Flowise | Flowise | CWE-798 | Flowise - Session Hijacking via Weak Default Express Session Secret |
| CVE-2026-41053 | 8.8 | 42.1 | SUSE | Rancher | CWE-303 | Over-inclusive team membership expansion in GitHub App authentication provide… |
| CVE-2026-14104 | 9.8 | 42.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome… | |
| CVE-2026-13870 | 8.8 | 42.0 | Chrome | CWE-416 | Use after free in WebView in Google Chrome on Android prior to 150.0.7871.47 … | |
| CVE-2026-6556 | 9.1 | 41.9 | @fastify/express | @fastify/express | CWE-285 | @fastify/express vulnerable to middleware bypass via non-string mount paths i… |
| CVE-2026-7663 | 9.8 | 41.8 | IBM | Langflow OSS | CWE-863 | Unauthenticated Cross-User MCP Resource Access and Tool Execution via Streama… |
| CVE-2026-58015 | 7.5 | 41.5 | GNOME | GLib | CWE-22 | Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_… |
| CVE-2026-49877 | 8.1 | 41.4 | Apache Software Foundation | Apache ActiveMQ | CWE-285 | Apache ActiveMQ: Authenticated web users retain admin access by default in th… |
| CVE-2026-53690 | 9.3 | 41.3 | Redeight | Redeight CMS | CWE-89 | SQL Injection in Redeight CMS |
| CVE-2026-13772 | 9.9 | 41.1 | IBM | WebSphere Extreme Scale | CWE-470 | IBM WebSphere eXtreme Scale's OQL is affected by remote code execution |
| CVE-2026-45822 | 6.6 | 40.9 | SamVerschueren | decode-uri-component | CWE-400 | decode-uri-component through 0.4.1 is vulnerable to denial of service. The de… |
| CVE-2026-11589 | 8.8 | 40.8 | Unknown | WP Support Plus Responsive Ticket System | — | WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Stored XS… |
| CVE-2026-13967 | 8.8 | 40.2 | Chrome | CWE-843 | Heap buffer overflow in V8 in Google Chrome prior to 150.0.7871.47 allowed a … | |
| CVE-2026-52868 | 8.8 | 40.0 | OFFIS DICOM | DCMTK Toolkit | CWE-22 | OFFIS DCMTK Toolkit Path Traversal |
| CVE-2026-13794 | 7.5 | 39.8 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome… | |
| CVE-2026-56264 | 9.2 | 39.8 | Crawl4AI | Crawl4AI | CWE-94 | Crawl4AI - Arbitrary JavaScript Execution via /execute_js Endpoint |
| CVE-2026-14164 | 7.5 | 39.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-415 | Libarchive: double-free vulnerability in rar5 decompression logic via danglin… |
| CVE-2026-57080 | 7.5 | 39.8 | SANKO | Net::BitTorrent | CWE-400 | Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustio… |
| CVE-2026-57081 | 7.5 | 39.8 | SANKO | Net::BitTorrent | CWE-400 | Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustio… |
| CVE-2026-57585 | 7.5 | 39.8 | msgpack | msgpack-python | CWE-416 | MessagePack: Out-of-bounds read/crash on Unpacker reuse after caught error |
| CVE-2026-4629 | 6.5 | 39.6 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-266 | Keycloak: keycloak: privilege escalation through hardcoded role mapper injection |
| CVE-2026-10560 | 9.1 | 39.5 | IBM | Langflow OSS | CWE-287 | Unauthenticated Access to Private Flow Build Events and Cancellation in Langf… |
| CVE-2026-55223 | 6.3 | 39.3 | swaldman | c3p0 | CWE-502 | c3p0 exposes a deserialization "sink" via JDBC DataSource bean properties |
| CVE-2026-11806 | 7.5 | 38.7 | IBM | WebSphere Application Server - Liberty | CWE-444 | IBM WebSphere Application Server Liberty is affected by a an arbitrary file r… |
| CVE-2026-56230 | 8.7 | 38.5 | Capgo | Capgo | CWE-639 | Capgo - Broken Object Level Authorization via x-limited-key-id Header |
| CVE-2026-8402 | 9.8 | 38.4 | Eksagate Electronic Engineering and Computer Industry Trade Inc. | SYSGUARD 6001 | CWE-89 | SQLi in Exagate's SYSGUARD 6001 |
| CVE-2026-58176 | 7.1 | 38.1 | dromara | RuoYi-Vue-Plus | CWE-862 | RuoYi-Vue-Plus - Missing Authorization on Workflow Task Management Endpoints |
| CVE-2026-56300 | 8.7 | 37.8 | Capgo | Capgo | CWE-200 | Capgo - Unauthenticated API Key Validity and Permission Oracle via RPC Functions |
| CVE-2026-10562 | 5.9 | 37.8 | TP-Link Systems Inc. | Archer AX20 V2.0 | CWE-601 | Unauthenticated Open Redirect Vulnerability on TP-Link Archer AX20 Web Interface |
| CVE-2026-14121 | 9.8 | 37.6 | Chrome | CWE-416 | Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47… | |
| CVE-2026-56399 | 5.3 | 37.5 | open-webui | open-webui | CWE-918 | Open WebUI - Server-Side Request Forgery via Location Redirect in /api/v1/ret… |
| CVE-2026-58174 | 6.0 | 37.3 | nesquena | hermes-webui | CWE-732 | Hermes WebUI < 0.51.521 - Cross-Profile Authorization Bypass via Unset Sessio… |
| CVE-2026-56219 | 8.7 | 37.1 | Capgo | Capgo | CWE-287 | Capgo - Unauthenticated RBAC Bindings and Email Disclosure via get_org_user_a… |
| CVE-2026-58173 | 6.0 | 37.0 | HKUDS | Vibe-Trading | CWE-22 | Vibe-Trading < 0.1.10 - Path Traversal via Persistent Memory Type |
| CVE-2026-11590 | 8.6 | 36.9 | Unknown | WP Support Plus Responsive Ticket System | — | WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated SQL Injec… |
| CVE-2026-6953 | 5.1 | 36.7 | Intermark IT | WebControl CMS | CWE-79 | Multiple vulnerabilities in Intermark IT's WebControl CMS |
| CVE-2026-56247 | 8.7 | 36.6 | Capgo | Capgo | CWE-266 | Capgo - Privilege Escalation via Cross-Scope RBAC Role Assignment |
| CVE-2026-57995 | 8.7 | 36.6 | phpMyFAQ | phpMyFAQ | CWE-269 | phpMyFAQ - Privilege Escalation via Missing Self-Rights Constraint in GroupCo… |
| CVE-2026-44948 | 5.3 | 36.2 | SUSE | Rancher | CWE-23 | Path Traversal in Rancher Fleet ImageScan GitRepo Path Handler |
| CVE-2026-6954 | 5.1 | 36.2 | Intermark IT | WebControl CMS | CWE-79 | Multiple vulnerabilities in Intermark IT's WebControl CMS |
| CVE-2025-71350 | 7.6 | 35.7 | picklescan | picklescan | CWE-502 | picklescan - Undetected Remote Code Execution via torch.utils.collect_env.run |
| CVE-2025-36319 | 4.3 | 35.7 | IBM | watsonx.data intelligence | CWE-770 | Vulnerabilities found in Watson Data Intelligence |
| CVE-2026-14241 | 9.8 | 35.6 | Mozilla | Firefox | CWE-787 | Memory safety bugs fixed in Firefox 152.0.4 |
| CVE-2026-12818 | 9.3 | 35.4 | deltaww | DVP-12SE | CWE-770 | DVP-12SE Exposure of Sensitive Information Vulnerability |
| CVE-2026-10763 | 7.0 | 35.4 | Hitachi Energy | PROMOD V | CWE-1428 | PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerabi… |
| CVE-2026-54899 | 6.3 | 35.4 | ohler55 | oj | CWE-416 | Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle |
| CVE-2026-54900 | 6.3 | 35.4 | ohler55 | oj | CWE-190 | Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling |
| CVE-2026-54901 | 6.3 | 35.4 | ohler55 | oj | CWE-416 | Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking |
| CVE-2026-54902 | 6.3 | 35.4 | ohler55 | oj | CWE-416 | Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback |
| CVE-2026-54903 | 6.3 | 35.4 | ohler55 | oj | CWE-190 | Oj: Integer Overflow in Oj.load 2GB String Handling |
| CVE-2026-13787 | 8.1 | 34.9 | Chrome | CWE-416 | Use after free in Chromoting in Google Chrome on Windows prior to 150.0.7871.… | |
| CVE-2026-35097 | 6.9 | 34.9 | KTM System | e-BOK | CWE-521 | Weak Password Requirements in KTM System e-BOK |
| CVE-2026-11906 | 6.5 | 34.8 | IBM | Db2 | CWE-1284 | IBM® Db2® federated server is vulnerable to a denial of service due to improp… |
| CVE-2026-53432 | 5.6 | 34.7 | fzf | fzf | CWE-190 | Integer Overflow in fzf |
| CVE-2026-10653 | 8.1 | 34.6 | zephyrproject | zephyr | CWE-415 | Non-atomic `net_buf` reference counts cause double-free / free-list corruptio… |
| CVE-2026-58169 | 7.7 | 34.5 | HKUDS | Vibe-Trading | CWE-346 | Vibe-Trading < 0.1.10 - Loopback Trust and Missing Host Validation Enable DNS… |
| CVE-2026-11541 | 9.8 | 34.5 | IBM | CICS Transaction Gateway for Multiplatforms | CWE-444 | Inconsistent Interpretation of HTTP Requests in CICS Transaction Gateway for … |
| CVE-2026-12349 | 5.3 | 34.4 | octagonwebstudio | Premium Addons for KingComposer | CWE-862 | Premium Addons for KingComposer <= 1.1.1 - Missing Authorization to Unauthent… |
| CVE-2026-10652 | 7.4 | 34.3 | zephyrproject | zephyr | CWE-125 | Out-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated… |
| CVE-2026-58167 | 7.1 | 34.3 | ccfos | nightingale | CWE-862 | Nightingale < 9.0.0-beta.2 - Datasource Credential Disclosure to Low-Privileg… |
| CVE-2026-9132 | 6.0 | 34.3 | GitHub | Enterprise Server | CWE-862 | Missing authorization vulnerability in GitHub Enterprise Server allowed discl… |
| CVE-2026-13786 | 8.8 | 34.1 | Chrome | CWE-416 | Use after free in Ozone in Google Chrome prior to 150.0.7871.47 allowed a rem… | |
| CVE-2026-13788 | 8.8 | 34.1 | Chrome | CWE-416 | Use after free in Fullscreen in Google Chrome on Android prior to 150.0.7871.… | |
| CVE-2026-13815 | 8.8 | 34.1 | Chrome | CWE-416 | Use after free in Blink in Google Chrome prior to 150.0.7871.47 allowed a rem… | |
| CVE-2026-13885 | 8.8 | 34.1 | Chrome | CWE-416 | Use after free in Skia in Google Chrome on Android prior to 150.0.7871.47 all… | |
| CVE-2026-13898 | 8.8 | 34.1 | Chrome | CWE-416 | Use after free in Cast Receiver in Google Chrome prior to 150.0.7871.47 allow… | |
| CVE-2026-13899 | 8.8 | 34.1 | Chrome | CWE-416 | Use after free in HTML in Google Chrome prior to 150.0.7871.47 allowed a remo… | |
| CVE-2026-13965 | 8.8 | 34.1 | Chrome | CWE-416 | Use after free in Oilpan in Google Chrome prior to 150.0.7871.47 allowed a re… | |
| CVE-2026-14006 | 8.8 | 34.1 | Chrome | CWE-416 | Use after free in Navigation in Google Chrome prior to 150.0.7871.47 allowed … | |
| CVE-2026-14067 | 8.8 | 34.1 | Chrome | CWE-416 | Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.… | |
| CVE-2026-14086 | 8.8 | 34.1 | Chrome | CWE-602 | Insufficient policy enforcement in HID in Google Chrome prior to 150.0.7871.4… | |
| CVE-2026-14149 | 8.8 | 34.1 | Chrome | CWE-416 | Use after free in Audio in Google Chrome on Linux prior to 150.0.7871.47 allo… | |
| CVE-2025-36321 | 5.7 | 33.6 | IBM | watsonx.data intelligence | CWE-80 | Vulnerabilities found in Watson Data Intelligence |
| CVE-2026-13449 | 9.1 | 33.5 | IBM | Business Automation Manager Open Editions | CWE-611 | XXE attack in IBM Business Automation Manager Open Editions |
| CVE-2026-10513 | 7.2 | 33.4 | pfefferle | Webmention | CWE-79 | Webmention <= 5.8.0 - Unauthenticated Stored Cross-Site Scripting via MF2 'ph… |
| CVE-2026-12388 | 6.5 | 33.4 | Red Hat | Red Hat Build of Keycloak | CWE-266 | Keycloak-broker: keycloak: privilege escalation to realm administrator via im… |
| CVE-2026-57079 | 5.3 | 33.2 | SANKO | Net::BitTorrent | CWE-22 | Net::BitTorrent versions before 2.1.0 for Perl write files outside the downlo… |
| CVE-2026-58448 | 7.1 | 33.0 | YunaiV | yudao-cloud | CWE-862 | yudao-cloud < 2026.06 - BPM Module Broken Access Control via process-instance… |
| CVE-2026-11546 | 9.8 | 32.8 | IBM | WebSphere Application Server - Liberty | CWE-918 | IBM WebSphere Application Server Liberty is affected by a server-side request… |
| CVE-2026-58013 | 8.2 | 32.6 | GNOME | GLib | CWE-126 | Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" |
| CVE-2026-9576 | 4.9 | 32.6 | Unknown | Fluent Booking | — | Fluent Booking < 2.1.2 - Calendar Manager+ Sensitive Information Disclosure v… |
| CVE-2026-27955 | 6.6 | 32.4 | coollabsio | coolify | CWE-78 | Coolify: Command Injection via Single-Quote Breakout in `executeInDocker()` |
| CVE-2026-56365 | 6.3 | 32.3 | ImageMagick | ImageMagick | CWE-401 | ImageMagick - Memory Leak in PNG Encoder via MNG Image Writing |
| CVE-2026-44949 | 7.0 | 32.2 | SUSE | Rancher | CWE-306 | Unauthenticated namespace creation and RBAC injection via rancher-webhook Fle… |
| CVE-2026-13779 | 8.1 | 32.1 | Chrome | CWE-416 | Use after free in Chromoting in Google Chrome on ChromeOS prior to 150.0.7871… | |
| CVE-2026-58010 | 8.2 | 31.8 | GNOME | GLib | CWE-126 | Glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() |
| CVE-2026-58012 | 8.2 | 31.8 | GNOME | GLib | CWE-126 | Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append()… |
| CVE-2026-58447 | 7.1 | 31.7 | iv-org | Invidious | CWE-639 | Invidious - Cross-User Playlist Video Deletion via Missing Ownership Check |
| CVE-2026-44947 | 6.9 | 31.6 | SUSE | Rancher | CWE-281 | Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in Rancher |
| CVE-2026-44946 | 9.5 | 31.5 | SUSE | Rancher | CWE-294 | SAML Authentication Replay in Rancher |
| CVE-2026-13925 | 7.5 | 31.4 | Chrome | CWE-20 | Inappropriate implementation in Downloads in Google Chrome on Windows prior t… | |
| CVE-2026-28322 | 5.6 | 31.4 | SolarWinds | Database Performance Analyzer | CWE-20 | SolarWinds Database Performance Analyzer Stored Cross-Site Scripting Vulnerab… |
| CVE-2026-12560 | 4.4 | 31.4 | wpqode | Editorial Rating – Product Review & Rating System | CWE-79 | Editorial Rating <= 4.0.5 - Authenticated (Administrator+) Stored Cross-Site … |
| CVE-2026-14209 | 4.3 | 31.4 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-639 | Keycloak-admin-ui: keycloak-admin-ui:admin ui extension brute-force-user endp… |
| CVE-2026-11708 | 9.3 | 31.2 | IBM | WebSphere Application Server | CWE-79 | IBM WebSphere Application Server is affected by a cross-site scripting vulner… |
| CVE-2026-11712 | 9.3 | 31.2 | IBM | WebSphere Application Server | CWE-79 | IBM WebSphere Application Server is affected by a cross-site scripting vulner… |
| CVE-2026-14111 | 8.1 | 31.1 | Chrome | CWE-416 | Use after free in WebProtect in Google Chrome prior to 150.0.7871.47 allowed … | |
| CVE-2026-13805 | 8.8 | 31.0 | Chrome | CWE-416 | Use after free in GFX in Google Chrome on Mac prior to 150.0.7871.47 allowed … | |
| CVE-2026-13811 | 8.8 | 31.0 | Chrome | CWE-416 | Use after free in IME in Google Chrome prior to 150.0.7871.47 allowed a remot… | |
| CVE-2026-13821 | 8.8 | 31.0 | Chrome | CWE-416 | Use after free in Canvas in Google Chrome prior to 150.0.7871.47 allowed a re… | |
| CVE-2026-13845 | 8.8 | 31.0 | Chrome | CWE-416 | Use after free in DOM in Google Chrome prior to 150.0.7871.47 allowed a remot… | |
| CVE-2026-13848 | 8.8 | 31.0 | Chrome | CWE-416 | Use after free in Forms in Google Chrome prior to 150.0.7871.47 allowed a rem… | |
| CVE-2026-13888 | 8.8 | 31.0 | Chrome | CWE-416 | Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed … | |
| CVE-2026-14091 | 8.8 | 31.0 | Chrome | CWE-416 | Use after free in DevTools in Google Chrome prior to 150.0.7871.47 allowed a … | |
| CVE-2026-14107 | 8.8 | 31.0 | Chrome | CWE-416 | Use after free in Scheduling in Google Chrome prior to 150.0.7871.47 allowed … | |
| CVE-2026-54696 | 3.7 | 30.9 | ruby | json | CWE-122 | Ruby JSON: JSON generator heap buffer overflow when streaming to an IO |
| CVE-2026-10655 | 5.9 | 30.7 | zephyrproject | zephyr | CWE-416 | Use-after-free race in SNTP async client when closing the socket while the so… |
| CVE-2026-12085 | 6.5 | 30.7 | IBM | UCD - IBM UrbanCode Deploy | CWE-201 | IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptable to an Insertion… |
| CVE-2026-56350 | 6.0 | 30.7 | n8n | n8n | CWE-285 | n8n - SSO Enforcement Bypass via API |
| CVE-2026-53433 | 5.7 | 30.5 | fzf | fzf | CWE-407 | Denial of Service in fzf |
| CVE-2026-58011 | 7.5 | 30.3 | GNOME | GLib | CWE-125 | Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid … |
| CVE-2026-12578 | 8.4 | 30.3 | deltaww | DTMSoft | CWE-502 | DTMSoft - Deserialization of Untrusted Data Vulnerability |
| CVE-2026-13798 | 9.6 | 30.0 | Chrome | CWE-122 | Heap buffer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 al… | |
| CVE-2026-14087 | 8.8 | 30.0 | Chrome | CWE-787 | Heap buffer overflow in WebNN in Google Chrome on Windows prior to 150.0.7871… | |
| CVE-2026-57204 | 6.9 | 29.4 | py-pdf | pypdf | CWE-400 | pypdf: Missing stream length values ignore defined limits |
| CVE-2026-14178 | 5.9 | 29.3 | openGauss-server | openGauss-server-7.0.0-RC2 | CWE-416 | openGauss存在非法内存访问导致DoS漏洞 |
| CVE-2025-36328 | 4.3 | 29.4 | IBM | watsonx.data intelligence | CWE-209 | Error Message Containing Sensitive Information found in Watson Data Intelligence |
| CVE-2026-11714 | 9.8 | 29.2 | IBM | WebSphere Application Server - Liberty | CWE-918 | IBM WebSphere Application Server Liberty is affected by an authorization bypa… |
| CVE-2026-13149 | 7.7 | 29.1 | juliangruber | brace-expansion | CWE-400 | brace-expansion through 5.0.6 is vulnerable to denial of service. The expand(… |
| CVE-2026-9106 | 4.8 | 29.1 | GitHub | Enterprise Server | CWE-451 | UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauth… |
| CVE-2026-58377 | 8.6 | 29.0 | jeecgboot | JeecgBoot | CWE-862 | JeecgBoot 3.9.2 - Missing Authorization on OpenAPI Credential Management Endp… |
| CVE-2026-56249 | 7.2 | 29.0 | Capgo | Capgo | CWE-285 | Capgo - Unauthorized Channel Overwrite and Ownership Takeover via POST /chann… |
| CVE-2026-13802 | 7.5 | 28.9 | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a rem… | |
| CVE-2026-14064 | 7.5 | 28.9 | Chrome | CWE-416 | Use after free in PageInfo in Google Chrome on Android prior to 150.0.7871.47… | |
| CVE-2026-27883 | 5.0 | 28.8 | coollabsio | coolify | CWE-639 | Coolify: IDOR in Deployment API - Cross-Team Deployment Information Disclosure |
| CVE-2025-36327 | 6.5 | 28.6 | IBM | watsonx.data intelligence | CWE-602 | Vulnerabilities found in Watson Data Intelligence |
| CVE-2026-58376 | 7.2 | 28.6 | Dolibarr | dolibarr | CWE-89 | Dolibarr - SQL Injection via sqlfilters Parameter in Multiple REST API List E… |
| CVE-2026-56318 | 6.9 | 28.5 | Capgo | Capgo | CWE-200 | Capgo - Information Disclosure via /private/validate_password_compliance Endp… |
| CVE-2026-56327 | 6.9 | 28.5 | Capgo | Capgo | CWE-203 | Capgo - Unauthenticated Organization Existence Oracle via public.invite_user_… |
| CVE-2026-13968 | 7.5 | 28.3 | Chrome | CWE-20 | Insufficient validation of untrusted input in DevTools in Google Chrome prior… | |
| CVE-2026-14074 | 6.5 | 28.1 | Chrome | CWE-1300 | Side-channel information leakage in WebAuthentication in Google Chrome on iOS… | |
| CVE-2026-14108 | 8.8 | 28.0 | Chrome | CWE-416 | Use after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a re… | |
| CVE-2026-10140 | 9.6 | 27.6 | IBM | Langflow OSS | CWE-639 | Cross-Tenant API Key Reuse and Billing Fraud in Langflow Voice Mode Subsystem |
| CVE-2026-56328 | 7.1 | 27.5 | Capgo | Capgo | CWE-670 | Capgo - Integrity Issue in Release Routing via Multiple Public Channels |
| CVE-2026-13776 | 9.8 | 27.4 | Chrome | CWE-843 | Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remo… | |
| CVE-2026-13919 | 6.5 | 27.4 | Chrome | CWE-602 | Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0… | |
| CVE-2026-13921 | 6.5 | 27.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in DeviceBoundSessionCredentials i… | |
| CVE-2026-13924 | 6.5 | 27.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebView in Google Chrome on And… | |
| CVE-2026-13926 | 6.5 | 27.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in Network in Google Chrome prior … | |
| CVE-2026-13930 | 6.5 | 27.4 | Chrome | CWE-602 | Insufficient policy enforcement in Actor in Google Chrome prior to 150.0.7871… | |
| CVE-2026-14007 | 6.5 | 27.4 | Chrome | CWE-602 | Insufficient policy enforcement in PermissionsPolicy in Google Chrome prior t… | |
| CVE-2026-14023 | 6.5 | 27.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in SanitizerAPI in Google Chrome p… | |
| CVE-2026-14033 | 6.5 | 27.4 | Chrome | CWE-602 | Insufficient policy enforcement in Media in Google Chrome on Windows prior to… | |
| CVE-2026-14065 | 6.5 | 27.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in PageInfo in Google Chrome prior… | |
| CVE-2026-13791 | 8.1 | 27.3 | Chrome | CWE-20 | Insufficient validation of untrusted input in Downloads in Google Chrome prio… | |
| CVE-2026-13923 | 6.5 | 27.2 | Chrome | CWE-457 | Uninitialized Use in GPU in Google Chrome on Android prior to 150.0.7871.47 a… | |
| CVE-2026-13943 | 6.5 | 27.2 | Chrome | CWE-457 | Uninitialized Use in CSS in Google Chrome on Android prior to 150.0.7871.47 a… | |
| CVE-2026-13789 | 9.6 | 27.0 | Chrome | CWE-416 | Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remot… | |
| CVE-2026-13792 | 9.6 | 27.0 | Chrome | CWE-416 | Use after free in Touchbar in Google Chrome on Mac prior to 150.0.7871.47 all… | |
| CVE-2026-13843 | 9.6 | 27.1 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome… | |
| CVE-2026-13846 | 9.6 | 27.0 | Chrome | CWE-416 | Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed … | |
| CVE-2026-13869 | 9.6 | 27.1 | Chrome | CWE-416 | Use after free in Device in Google Chrome on Windows prior to 150.0.7871.47 a… | |
| CVE-2026-13901 | 9.6 | 27.1 | Chrome | CWE-20 | Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.787… | |
| CVE-2026-13909 | 9.6 | 27.0 | Chrome | CWE-693 | Insufficient policy enforcement in DevTools in Google Chrome prior to 150.0.7… | |
| CVE-2026-13920 | 9.6 | 27.1 | Chrome | CWE-20 | Insufficient validation of untrusted input in Media in Google Chrome on Windo… | |
| CVE-2026-13934 | 9.6 | 27.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Dawn in Google Chrome on Androi… | |
| CVE-2026-14017 | 9.6 | 27.0 | Chrome | CWE-693 | Inappropriate implementation in Navigation in Google Chrome prior to 150.0.78… | |
| CVE-2026-14037 | 9.6 | 27.1 | Chrome | CWE-693 | Insufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.4… | |
| CVE-2026-14043 | 9.6 | 27.1 | Chrome | CWE-416 | Use after free in GetUserMedia in Google Chrome prior to 150.0.7871.47 allowe… | |
| CVE-2026-14044 | 9.6 | 27.1 | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a rem… | |
| CVE-2026-14055 | 9.6 | 27.1 | Chrome | CWE-20 | Insufficient validation of untrusted input in Device Trust in Google Chrome o… | |
| CVE-2026-14106 | 9.6 | 27.1 | Chrome | CWE-20 | Insufficient validation of untrusted input in Text in Google Chrome on Androi… | |
| CVE-2026-14109 | 9.6 | 27.1 | Chrome | CWE-20 | Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.… | |
| CVE-2026-14120 | 9.6 | 27.1 | Chrome | CWE-20 | Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871… | |
| CVE-2026-14152 | 9.6 | 27.0 | Chrome | CWE-787 | Out of bounds read and write in ANGLE in Google Chrome prior to 150.0.7871.47… | |
| CVE-2026-13817 | 8.8 | 27.1 | Chrome | CWE-20 | Insufficient validation of untrusted input in Glic in Google Chrome prior to … | |
| CVE-2026-13835 | 8.8 | 27.0 | Chrome | CWE-122 | Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-13903 | 8.8 | 27.0 | Chrome | CWE-602 | Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.… | |
| CVE-2026-13915 | 8.8 | 27.0 | Chrome | CWE-416 | Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.… | |
| CVE-2026-13918 | 8.8 | 27.1 | Chrome | CWE-416 | Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.… | |
| CVE-2026-13928 | 8.8 | 27.1 | Chrome | CWE-20 | Insufficient validation of untrusted input in Enterprise in Google Chrome pri… | |
| CVE-2026-13938 | 8.8 | 27.0 | Chrome | CWE-472 | Integer overflow in Fonts in Google Chrome prior to 150.0.7871.47 allowed a r… | |
| CVE-2026-14005 | 8.8 | 27.1 | Chrome | CWE-416 | Use after free in Omnibox in Google Chrome on Android prior to 150.0.7871.47 … | |
| CVE-2026-14009 | 8.8 | 27.0 | Chrome | CWE-20 | Inappropriate implementation in Passwords in Google Chrome prior to 150.0.787… | |
| CVE-2026-14024 | 8.8 | 27.1 | Chrome | CWE-416 | Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allo… | |
| CVE-2026-14025 | 8.8 | 27.0 | Chrome | CWE-416 | Use after free in Views in Google Chrome on Mac prior to 150.0.7871.47 allowe… | |
| CVE-2026-14027 | 8.8 | 27.0 | Chrome | CWE-416 | Use after free in SignIn in Google Chrome prior to 150.0.7871.47 allowed a re… | |
| CVE-2026-14036 | 8.8 | 27.1 | Chrome | CWE-602 | Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.… | |
| CVE-2026-14041 | 8.8 | 27.0 | Chrome | CWE-602 | Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.787… | |
| CVE-2026-14078 | 8.8 | 27.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebRTC in Google Chrome prior t… | |
| CVE-2026-14102 | 8.8 | 27.1 | Chrome | CWE-416 | Use after free in Passwords in Google Chrome prior to 150.0.7871.47 allowed a… | |
| CVE-2026-14090 | 8.1 | 27.1 | Chrome | CWE-125 | Insufficient validation of untrusted input in CameraCapture in Google Chrome … | |
| CVE-2026-58171 | 2.3 | 26.9 | HKUDS | Vibe-Trading | CWE-22 | Vibe-Trading < 0.1.10 - Path Traversal via Swarm Run Identifier |
| CVE-2026-56331 | 6.9 | 26.8 | Capgo | Capgo | CWE-209 | Capgo - Improper Error Handling in Accept Invitation Endpoint via Invalid Mag… |
| CVE-2026-58373 | 5.3 | 26.6 | cvat-ai | cvat | CWE-862 | CVAT < 2.69.0 - Missing Authorization on Quality Reports parent_id Filter Lea… |
| CVE-2026-58165 | 8.7 | 26.5 | openziti | ziti | CWE-862 | OpenZiti - Privilege Escalation to Admin via Unauthorized Enrollment Creation |
| CVE-2025-24816 | 6.5 | 26.5 | Nokia | MantaRay NM | CWE-284 | An Improper Access Control vulnerability in Nokia MantaRay NM |
| CVE-2026-10564 | 8.2 | 26.2 | IBM | Langflow OSS | CWE-918 | SSRF Vulnerability in Langflow OSS Legacy Components Bypasses Protection |
| CVE-2026-13831 | 7.5 | 26.2 | Chrome | CWE-416 | Out of bounds read and write in GPU in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-13855 | 7.5 | 26.2 | Chrome | CWE-416 | Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allo… | |
| CVE-2026-54502 | 6.3 | 26.2 | ohler55 | oj | CWE-121 | Oj: Stack Buffer Overflow in Oj.dump via Large Indent |
| CVE-2026-11594 | 6.1 | 26.1 | IBM | WebSphere Application Server | CWE-79 | IBM WebSphere Application Server is affected by multiple cross-site scripting… |
| CVE-2026-12114 | 4.4 | 25.9 | wpmart | Team Members – Multi Language Supported Team Plugin | CWE-79 | Team Members <= 8.7 - Authenticated (Administrator+) Stored Cross-Site Script… |
| CVE-2026-13883 | 9.6 | 25.8 | Chrome | CWE-843 | Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a rem… | |
| CVE-2026-13825 | 8.8 | 25.8 | Chrome | CWE-457 | Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.47 allowed a r… | |
| CVE-2026-58371 | 2.3 | 25.6 | seaweedfs | seaweedfs | CWE-79 | SeaweedFS < 4.30 - Cross-Origin Information Disclosure via Unvalidated JSONP … |
| CVE-2026-14101 | 9.6 | 25.6 | Chrome | CWE-269 | Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 1… | |
| CVE-2026-13897 | 8.8 | 25.6 | Chrome | CWE-284 | Insufficient policy enforcement in Chromecast in Google Chrome prior to 150.0… | |
| CVE-2026-13803 | 8.3 | 25.5 | Chrome | CWE-843 | Type Confusion in Chrome Tabs in Google Chrome prior to 150.0.7871.47 allowed… | |
| CVE-2026-14151 | 8.3 | 25.5 | Chrome | CWE-669 | Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 al… | |
| CVE-2026-58014 | 8.6 | 25.2 | GNOME | GLib | CWE-193 | Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_l… |
| CVE-2026-13806 | 8.1 | 25.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in Accessibility in Google Chrome … | |
| CVE-2025-36359 | 6.5 | 25.2 | IBM | DevOps Automation | CWE-613 | IBM DevOps Loop is susceptible to an Insufficient Session Expiration vulnerab… |
| CVE-2026-14038 | 9.3 | 25.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in New Tab Page in Google Chrome p… | |
| CVE-2026-9263 | 8.1 | 25.0 | zephyrproject | zephyr | CWE-125 | Out-of-bounds read in Bluetooth Controller ISOAL framed RX reassembly leaks a… |
| CVE-2026-13819 | 8.1 | 25.0 | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 al… | |
| CVE-2026-14011 | 8.1 | 25.0 | Chrome | CWE-125 | Out of bounds read in SurfaceCapture in Google Chrome prior to 150.0.7871.47 … | |
| CVE-2026-50040 | 5.1 | 25.0 | StoneFly | Storage Concentrator | CWE-79 | Cross-site Scripting in StoneFly Storage Concentrator |
| CVE-2026-56777 | 5.3 | 24.9 | n8n | n8n | CWE-184 | n8n - AST Validator Bypass in Python Code Node |
| CVE-2026-56809 | 5.1 | 24.9 | Ricoh Company, Ltd. | Multiple laser printers and MFPs which implement Ricoh Web Image Monitor | CWE-79 | Multiple laser printers and MFPs (multifunction printers) which implement Ric… |
| CVE-2026-14032 | 8.1 | 24.8 | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 al… | |
| CVE-2026-13829 | 8.3 | 24.7 | Chrome | CWE-20 | Insufficient validation of untrusted input in Settings in Google Chrome on Wi… | |
| CVE-2026-13834 | 8.3 | 24.7 | Chrome | CWE-20 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to… | |
| CVE-2026-56333 | 5.3 | 24.4 | Capgo | Capgo | CWE-20 | Capgo - Server-Side Validation Bypass via Direct Browser-Side Organization Se… |
| CVE-2026-13958 | 6.5 | 24.3 | Chrome | CWE-457 | Uninitialized Use in Codecs in Google Chrome on Windows prior to 150.0.7871.4… | |
| CVE-2026-14008 | 6.5 | 24.3 | Chrome | CWE-457 | Uninitialized Use in WebXR in Google Chrome on Android prior to 150.0.7871.47… | |
| CVE-2026-14010 | 6.5 | 24.3 | Chrome | CWE-457 | Uninitialized Use in Codecs in Google Chrome on Windows prior to 150.0.7871.4… | |
| CVE-2026-14051 | 6.5 | 24.3 | Chrome | CWE-457 | Uninitialized Use in GamepadAPI in Google Chrome prior to 150.0.7871.47 allow… | |
| CVE-2026-14070 | 6.5 | 24.3 | Chrome | CWE-457 | Integer overflow in WebNN in Google Chrome prior to 150.0.7871.47 allowed a r… | |
| CVE-2026-14088 | 6.5 | 24.3 | Chrome | CWE-457 | Uninitialized Use in Canvas in Google Chrome on Android prior to 150.0.7871.4… | |
| CVE-2026-14125 | 6.5 | 24.3 | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a … | |
| CVE-2026-14148 | 6.5 | 24.3 | Chrome | CWE-843 | Type Confusion in CSS in Google Chrome prior to 150.0.7871.47 allowed a remot… | |
| CVE-2026-13799 | 8.1 | 24.2 | Chrome | CWE-416 | Use after free in QUIC in Google Chrome prior to 150.0.7871.47 allowed a remo… | |
| CVE-2026-10585 | 6.3 | 24.3 | GitHub | Enterprise Server | CWE-79 | Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed… |
| CVE-2026-13782 | 10.0 | 24.2 | Chrome | CWE-416 | Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a r… | |
| CVE-2026-13775 | 9.8 | 24.2 | Chrome | CWE-416 | Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remot… | |
| CVE-2026-13780 | 9.6 | 24.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to… | |
| CVE-2026-13781 | 9.6 | 24.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in Skia in Google Chrome prior to … | |
| CVE-2026-13785 | 9.6 | 24.2 | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 al… | |
| CVE-2026-13796 | 9.6 | 24.2 | Chrome | CWE-472 | Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowe… | |
| CVE-2026-13797 | 9.6 | 24.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chromecast in Google Chrome pri… | |
| CVE-2026-14056 | 9.6 | 24.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Media in Google Chrome prior to… | |
| CVE-2026-14093 | 9.6 | 24.2 | Chrome | CWE-416 | Use after free in Cast in Google Chrome prior to 150.0.7871.47 allowed a remo… | |
| CVE-2026-14095 | 9.6 | 24.2 | Chrome | CWE-20 | Insufficient policy enforcement in Browser in Google Chrome prior to 150.0.78… | |
| CVE-2026-14097 | 9.6 | 24.2 | Chrome | CWE-693 | Inappropriate implementation in WebAppInstalls in Google Chrome on Mac prior … | |
| CVE-2026-13777 | 8.8 | 24.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in iOSWeb in Google Chrome on iOS … | |
| CVE-2026-13783 | 8.8 | 24.2 | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a rem… | |
| CVE-2026-13784 | 8.8 | 24.2 | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a rem… | |
| CVE-2026-14084 | 8.8 | 24.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chromoting in Google Chrome pri… | |
| CVE-2026-14099 | 8.8 | 24.2 | Chrome | CWE-416 | Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.… | |
| CVE-2026-8141 | 7.2 | 24.0 | Connekt Media | Ajax Load More - Filters | CWE-79 | Ajax Load More - Filters <= 3.4.1 - Unauthenticated Stored Cross-Site Scripti… |
| CVE-2026-48192 | 6.8 | 24.0 | Siemens | Mendix Studio Pro 10.11 | CWE-94 | A vulnerability has been identified in Mendix Studio Pro 10.11 (All versions)… |
| CVE-2026-13790 | 6.5 | 24.0 | Chrome | CWE-1300 | Side-channel information leakage in Scroll in Google Chrome prior to 150.0.78… | |
| CVE-2026-13810 | 6.5 | 24.0 | Chrome | CWE-200 | Inappropriate implementation in Input in Google Chrome on Linux prior to 150.… | |
| CVE-2026-13816 | 6.5 | 24.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in File Input in Google Chrome on … | |
| CVE-2026-13847 | 6.5 | 24.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome… | |
| CVE-2026-13906 | 6.5 | 24.0 | Chrome | CWE-125 | Out of bounds read in Codecs in Google Chrome prior to 150.0.7871.47 allowed … | |
| CVE-2026-13910 | 6.5 | 24.0 | Chrome | CWE-693 | Insufficient policy enforcement in WebXR in Google Chrome on Android prior to… | |
| CVE-2026-13922 | 6.5 | 24.0 | Chrome | CWE-1300 | Side-channel information leakage in Paint in Google Chrome prior to 150.0.787… | |
| CVE-2026-13935 | 6.5 | 24.0 | Chrome | CWE-1300 | Side-channel information leakage in ComputePressure in Google Chrome prior to… | |
| CVE-2026-14004 | 6.5 | 24.0 | Chrome | CWE-200 | Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-14021 | 6.5 | 24.0 | Chrome | CWE-20 | Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to… | |
| CVE-2026-14022 | 6.5 | 24.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Network in Google Chrome prior … | |
| CVE-2026-14050 | 6.5 | 24.0 | Chrome | CWE-693 | Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.… | |
| CVE-2026-14059 | 6.5 | 24.0 | Chrome | CWE-693 | Insufficient policy enforcement in Related-Website-Sets in Google Chrome prio… | |
| CVE-2026-14085 | 6.5 | 24.0 | Chrome | CWE-1300 | Side-channel information leakage in CSS in Google Chrome prior to 150.0.7871.… | |
| CVE-2026-14103 | 6.5 | 24.0 | Chrome | CWE-416 | Use after free in SSL in Google Chrome on ChromeOS prior to 150.0.7871.47 all… | |
| CVE-2026-14146 | 6.5 | 24.0 | Chrome | CWE-200 | Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-13889 | 6.5 | 23.6 | Chrome | CWE-20 | Side-channel information leakage in WebAuthentication in Google Chrome on iOS… | |
| CVE-2026-10129 | 8.5 | 23.6 | IBM | Langflow OSS | CWE-918 | SSRF via HTTP Redirect Following in Langflow API Request Component |
| CVE-2026-56320 | 7.1 | 23.5 | Capgo | Capgo | CWE-285 | Capgo - Org/App Scope Mismatch in Device Creation Endpoint |
| CVE-2026-13807 | 7.5 | 23.3 | Chrome | CWE-416 | Use after free in Import in Google Chrome on iOS prior to 150.0.7871.47 allow… | |
| CVE-2026-13851 | 9.1 | 23.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome… | |
| CVE-2026-13852 | 9.1 | 23.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome… | |
| CVE-2026-13947 | 5.3 | 22.9 | Chrome | CWE-457 | Uninitialized Use in XR in Google Chrome prior to 150.0.7871.47 allowed a rem… | |
| CVE-2026-13950 | 5.3 | 22.9 | Chrome | CWE-457 | Uninitialized Use in GPU in Google Chrome prior to 150.0.7871.47 allowed a re… | |
| CVE-2026-13833 | 6.5 | 22.8 | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 all… | |
| CVE-2026-13853 | 9.6 | 22.6 | Chrome | CWE-416 | Use after free in Journeys in Google Chrome prior to 150.0.7871.47 allowed a … | |
| CVE-2026-13854 | 9.6 | 22.6 | Chrome | CWE-416 | Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allo… | |
| CVE-2026-13859 | 9.6 | 22.6 | Chrome | CWE-693 | Inappropriate implementation in ANGLE in Google Chrome prior to 150.0.7871.47… | |
| CVE-2026-13861 | 9.6 | 22.6 | Chrome | CWE-416 | Use after free in Core in Google Chrome prior to 150.0.7871.47 allowed a remo… | |
| CVE-2026-13878 | 9.6 | 22.6 | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 al… | |
| CVE-2026-13880 | 9.6 | 22.6 | Chrome | CWE-416 | Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed … | |
| CVE-2026-14113 | 9.6 | 22.6 | Chrome | CWE-416 | Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 … | |
| CVE-2026-13932 | 6.5 | 22.7 | Chrome | CWE-284 | Inappropriate implementation in Sharing in Google Chrome on Android prior to … | |
| CVE-2026-13936 | 6.5 | 22.7 | Chrome | CWE-284 | Inappropriate implementation in Passwords in Google Chrome on Android prior t… | |
| CVE-2026-13937 | 6.5 | 22.7 | Chrome | CWE-284 | Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.… | |
| CVE-2026-13949 | 6.5 | 22.7 | Chrome | CWE-284 | Insufficient policy enforcement in Payments in Google Chrome on Android prior… | |
| CVE-2026-13954 | 6.5 | 22.7 | Chrome | CWE-284 | Insufficient policy enforcement in XML in Google Chrome on Android prior to 1… | |
| CVE-2026-14019 | 6.5 | 22.7 | Chrome | CWE-522 | Inappropriate implementation in Passwords in Google Chrome prior to 150.0.787… | |
| CVE-2026-14155 | 6.5 | 22.7 | Chrome | CWE-284 | Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to… | |
| CVE-2026-13801 | 8.3 | 22.4 | Chrome | CWE-472 | Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowe… | |
| CVE-2026-13804 | 8.3 | 22.4 | Chrome | CWE-416 | Use after free in Chromecast in Google Chrome prior to 150.0.7871.47 allowed … | |
| CVE-2026-13823 | 8.3 | 22.4 | Chrome | CWE-416 | Use after free in Glic in Google Chrome prior to 150.0.7871.47 allowed a remo… | |
| CVE-2026-13832 | 8.3 | 22.4 | Chrome | CWE-416 | Use after free in Headless in Google Chrome prior to 150.0.7871.47 allowed a … | |
| CVE-2026-13841 | 8.3 | 22.4 | Chrome | CWE-472 | Integer overflow in Skia in Google Chrome prior to 150.0.7871.47 allowed a re… | |
| CVE-2026-13951 | 8.3 | 22.4 | Chrome | CWE-693 | Insufficient policy enforcement in USB in Google Chrome prior to 150.0.7871.4… | |
| CVE-2026-13814 | 7.5 | 22.4 | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a rem… | |
| CVE-2026-13774 | 8.1 | 22.4 | Chrome | CWE-416 | Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed … | |
| CVE-2025-36372 | 6.5 | 22.3 | IBM | Db2 | CWE-538 | IBM® Db2® could disclose sensitive information to an authenticated user from … |
| CVE-2026-13964 | 6.5 | 22.3 | Chrome | CWE-284 | Insufficient policy enforcement in WebView in Google Chrome on Android prior … | |
| CVE-2026-14118 | 6.5 | 22.4 | Chrome | CWE-290 | Insufficient data validation in DevTools in Google Chrome prior to 150.0.7871… | |
| CVE-2026-13813 | 8.3 | 22.3 | Chrome | CWE-20 | Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri… | |
| CVE-2026-13824 | 7.5 | 22.3 | Chrome | CWE-20 | Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0… | |
| CVE-2026-13856 | 7.5 | 22.3 | Chrome | CWE-20 | Insufficient validation of untrusted input in Speech in Google Chrome on Andr… | |
| CVE-2026-13891 | 7.5 | 22.3 | Chrome | CWE-20 | Insufficient validation of untrusted input in Extensions in Google Chrome pri… | |
| CVE-2026-14115 | 7.5 | 22.3 | Chrome | CWE-20 | Insufficient validation of untrusted input in Cast in Google Chrome prior to … | |
| CVE-2026-13911 | 5.3 | 22.2 | Chrome | CWE-20 | Insufficient policy enforcement in Spellcheck in Google Chrome prior to 150.0… | |
| CVE-2026-56369 | 6.3 | 22.0 | ImageMagick | ImageMagick | CWE-323 | ImageMagick - Information Disclosure via AES-CTR Nonce Reuse in PasskeyEnciph… |
| CVE-2026-14034 | 4.3 | 22.1 | Chrome | CWE-284 | Inappropriate implementation in WebXR in Google Chrome on Android prior to 15… | |
| CVE-2026-13866 | 6.5 | 21.7 | Chrome | CWE-20 | Inappropriate implementation in Input in Google Chrome on Android prior to 15… | |
| CVE-2026-13871 | 6.5 | 21.7 | Chrome | CWE-602 | Insufficient policy enforcement in GuestView in Google Chrome prior to 150.0.… | |
| CVE-2026-13900 | 6.5 | 21.7 | Chrome | CWE-20 | Inappropriate implementation in Chromecast in Google Chrome prior to 150.0.78… | |
| CVE-2026-13962 | 6.5 | 21.7 | Chrome | CWE-20 | Insufficient data validation in PDF in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-14054 | 4.3 | 21.5 | Chrome | CWE-602 | Insufficient policy enforcement in Network in Google Chrome prior to 150.0.78… | |
| CVE-2026-14066 | 4.3 | 21.5 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome… | |
| CVE-2026-13850 | 8.8 | 21.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome… | |
| CVE-2026-58374 | 7.1 | 21.4 | w1.fi | hostapd | CWE-193 | In hostapd before 2.12, a missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.1… |
| CVE-2026-13809 | 6.5 | 21.4 | Chrome | CWE-1300 | Side-channel information leakage in Safe Browsing in Google Chrome on iOS pri… | |
| CVE-2026-13873 | 6.5 | 21.4 | Chrome | CWE-125 | Out of bounds read in Layout in Google Chrome prior to 150.0.7871.47 allowed … | |
| CVE-2026-14069 | 6.5 | 21.4 | Chrome | CWE-472 | Integer overflow in WebNN in Google Chrome prior to 150.0.7871.47 allowed a r… | |
| CVE-2026-14071 | 6.5 | 21.4 | Chrome | CWE-1300 | Side-channel information leakage in WebAudio in Google Chrome prior to 150.0.… | |
| CVE-2026-14096 | 6.5 | 21.4 | Chrome | CWE-200 | Inappropriate implementation in Input in Google Chrome on Android prior to 15… | |
| CVE-2026-14098 | 6.5 | 21.4 | Chrome | CWE-200 | Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-14100 | 6.5 | 21.4 | Chrome | CWE-20 | Insufficient data validation in NetworkCache in Google Chrome prior to 150.0.… | |
| CVE-2026-13858 | 6.5 | 21.3 | Chrome | CWE-125 | Out of bounds read in FFmpeg in Google Chrome prior to 150.0.7871.47 allowed … |
Results continue: ranks 401–641.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-06-30 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.