AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.2 .0486 91.3 —
AFFECTED Product Versions Fixed dockwatch unspecified —
TIMELINE Jun 30 Reserved by CNA Jul 2 Published (CNA: VulnCheck)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
265 CVEs published, led by Ubiquiti Inc (25).
265 CVEs published July 2, 2026: 32 critical, 149 high, 78 medium, 6 low; 0 in the KEV catalog at press time; 4 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 240 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 630 | 13013 | 1187 | 2564 |
| KEV catalog size | 1671 | |||
566 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 33 | 1515 | 120 | 862 | 528 | 1 | 27 | 3 | 0.2 | 7.5 | .0013 | +31 ▲ |
| 52 | 1316 | 148 | 586 | 542 | 37 | 74 | 6 | 0.5 | 7.8 | .0023 | -9 ▼ | |
| microsoft | 7 | 773 | 60 | 526 | 172 | 6 | 380 | 28 | 3.6 | 7.8 | .0046 | +6 ▲ |
| red hat | 9 | 201 | 11 | 83 | 99 | 8 | 4 | 0 | 0.0 | 6.6 | .0026 | +4 ▲ |
| apple | 0 | 99 | 1 | 23 | 66 | 2 | 94 | 7 | 7.1 | 6.5 | .0031 | 0 |
| canonical | 0 | 20 | 2 | 5 | 8 | 5 | 0 | 0 | 0.0 | 5.5 | .0011 | 0 |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0015 | 0 |
| suse | 2 | 15 | 4 | 8 | 3 | 0 | 0 | 0 | 0.0 | 8.8 | .0036 | +2 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ubiquiti | 25 | 36 | 14 | 21 | 1 | 0 | 4 | 3 | 8.3 | 8.8 | .0036 | +25 ▲ |
| cisco | 8 | 31 | 4 | 12 | 8 | 0 | 96 | 11 | 35.5 | 7.5 | .0056 | +8 ▲ |
| netgear | 0 | 17 | 0 | 0 | 16 | 1 | 8 | 0 | 0.0 | 4.3 | .0024 | 0 |
| palo alto networks | 0 | 11 | 0 | 1 | 7 | 1 | 14 | 2 | 18.2 | 4.8 | .0022 | 0 |
| checkpoint | 0 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | 0 |
| f5 | 0 | 9 | 4 | 3 | 1 | 0 | 7 | 1 | 11.1 | 8.9 | .0221 | 0 |
| ivanti | 0 | 9 | 2 | 3 | 0 | 0 | 33 | 5 | 55.6 | 8.8 | .5187 | -1 ▼ |
| fortinet | 0 | 8 | 1 | 3 | 2 | 0 | 28 | 3 | 37.5 | 7.3 | .0066 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 2 | 155 | 24 | 59 | 61 | 10 | 40 | 1 | 0.6 | 7.3 | .0048 | -28 ▼ |
| mozilla | 2 | 58 | 12 | 18 | 28 | 0 | 13 | 0 | 0.0 | 7.3 | .0025 | -2 ▼ |
| gitlab | 0 | 33 | 0 | 5 | 21 | 5 | 4 | 2 | 6.1 | 4.4 | .0022 | 0 |
| github | 1 | 7 | 1 | 1 | 5 | 0 | 0 | 0 | 0.0 | 6.0 | .0026 | +1 ▲ |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 1 | 0 | 0.0 | 8.2 | .0016 | -1 ▼ |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 5 | 1 | 20.0 | 5.1 | .0026 | 0 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 270 | 131 | 116 | 18 | 4 | 40 | 2 | 0.7 | 8.8 | .0040 | -1 ▼ |
| adobe | 0 | 146 | 11 | 52 | 78 | 2 | 75 | 3 | 2.1 | 5.5 | .0021 | 0 |
| ibm | 0 | 124 | 36 | 42 | 46 | 0 | 7 | 0 | 0.0 | 7.5 | .0025 | -5 ▼ |
| progress | 2 | 11 | 1 | 9 | 1 | 0 | 9 | 0 | 0.0 | 7.5 | .0035 | -3 ▼ |
| solarwinds | 0 | 7 | 1 | 2 | 2 | 0 | 11 | 4 | 57.1 | 7.5 | .0835 | -1 ▼ |
| veeam | 0 | 4 | 2 | 2 | 0 | 0 | 4 | 0 | 0.0 | 9.0 | .0046 | 0 |
| zohocorp | 0 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 0 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | 0 |
| d-link | 0 | 13 | 0 | 5 | 2 | 5 | 26 | 1 | 7.7 | 5.8 | .0059 | -2 ▼ |
| siemens | 0 | 9 | 0 | 4 | 5 | 0 | 1 | 0 | 0.0 | 6.9 | .0019 | -1 ▼ |
| rockwell automation | 0 | 7 | 1 | 5 | 1 | 0 | 0 | 0 | 0.0 | 8.7 | .0030 | 0 |
| abb | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | 0 |
| schneider electric | 0 | 6 | 0 | 4 | 2 | 0 | 1 | 0 | 0.0 | 7.8 | .0024 | 0 |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | 0 |
| dahua | 0 | 3 | 0 | 1 | 1 | 1 | 2 | 0 | 0.0 | 6.9 | .0036 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| spring | 0 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | -2 ▼ |
| sourcecodester | 0 | 71 | 0 | 0 | 36 | 35 | 0 | 0 | 0.0 | 5.5 | .0026 | -15 ▼ |
| openclaw | 0 | 67 | 0 | 35 | 22 | 10 | 0 | 0 | 0.0 | 7.0 | .0021 | 0 |
| edimax | 0 | 65 | 0 | 39 | 0 | 26 | 1 | 0 | 0.0 | 7.4 | .0059 | 0 |
| capgo | 0 | 61 | 2 | 31 | 27 | 1 | 0 | 0 | 0.0 | 7.1 | .0031 | 0 |
| themerex | 2 | 60 | 5 | 54 | 1 | 0 | 0 | 0 | 0.0 | 8.1 | .0043 | +2 ▲ |
| dell | 1 | 57 | 1 | 31 | 24 | 0 | 2 | 1 | 1.8 | 7.3 | .0015 | -1 ▼ |
| nvidia | 17 | 56 | 11 | 38 | 7 | 0 | 0 | 0 | 0.0 | 7.8 | .0019 | +15 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-10520 | .9990 | 100.0 | 10.0 |
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-35273 | .9547 | 99.9 | 9.8 |
| CVE-2026-34910 | .8696 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-20230 | .8321 | 99.7 | 8.6 |
| CVE-2026-42271 | .8301 | 99.6 | — |
| CVE-2026-50751 | .8255 | 99.6 | 9.3 |
| CVE-2026-48907 | .6883 | 99.3 | 10.0 |
| CVE-2026-34909 | .6390 | 99.2 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-10520 | 10.0 | .9990 | KEV |
| CVE-2026-34910 | 10.0 | .8696 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-48907 | 10.0 | .6883 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-50160 | 10.0 | .1775 | |
| CVE-2026-48276 | 10.0 | .0505 | |
| CVE-2026-13773 | 10.0 | .0341 | |
| CVE-2026-56413 | 10.0 | .0316 | |
| CVE-2026-56415 | 10.0 | .0315 |
| Vendor | CVEs |
|---|---|
| 1081 | |
| linux | 545 |
| oracle | 242 |
| microsoft | 227 |
| adobe | 142 |
| red hat | 132 |
| apache | 93 |
| ibm | 70 |
| spring | 70 |
| capgo | 61 |
| Vendor | KEV |
|---|---|
| microsoft | 28 |
| cisco | 11 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| synacor | 4 |
| adobe | 3 |
| fortinet | 3 |
| linux | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 40 |
| Packagist | 15 |
| PyPI | 8 |
| npm | 6 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2025-67038 | Lantronix | 0 |
| CVE-2026-10520 | ivanti | 0 |
| CVE-2026-11645 | 0 | |
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-20245 | Cisco | 0 |
| CVE-2026-20253 | Splunk | 0 |
| CVE-2026-20262 | Cisco | 0 |
| CVE-2026-28318 | SolarWinds | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1688 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1688 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1688 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1688 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1688 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1688 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1688 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1688 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1688 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1688 |
EXPLOIT PUBLISHED — CVE-2026-38971. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-38972. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44941 (SUSE libzypp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-8147 (mlflow/mlflow). Public exploit reference added.
How to read these box scores · glossary
265 CVEs published. 25 box scores, 240 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.2 .0486 91.3 —
AFFECTED Product Versions Fixed dockwatch unspecified —
TIMELINE Jun 30 Reserved by CNA Jul 2 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0250 83.5 —
AFFECTED Product Versions Fixed UniFi Connect Application unspecified —
TIMELINE Jun 6 Reserved by CNA Jul 2 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0154 72.9 —
AFFECTED Product Versions Fixed WP Database Backup – Unlimited Database & Files Backup by Backup for WP unspecified —
TIMELINE May 28 Reserved by CNA Jul 2 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0131 68.3 —
AFFECTED Product Versions Fixed UniFi OS Server unspecified — Dream Machines unspecified — Enterprise Fortress Gateway unspecified — Dream Wall unspecified — Dream Routers unspecified — Express 7 unspecified — Cloud Keys unspecified — Network Video Recorders unspecified — Enterprise Video Recorders unspecified — Cloud Gateways unspecified — + 2 more
TIMELINE Jun 13 Reserved by CNA Jul 2 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0121 65.9 —
AFFECTED Product Versions Fixed UniFi Access Application unspecified —
TIMELINE Jun 6 Reserved by CNA Jul 2 Published (CNA: hackerone)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P N N H H H 9.2 .0101 60.4 —
AFFECTED Product Versions Fixed Fireware OS 2025.1 – 12.0 Fireware OS 12.0 – —
TIMELINE Jun 25 Reserved by CNA Jul 2 Published (CNA: WatchGuard)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0086 55.7 —
AFFECTED Product Versions Fixed KSOA 9.0 – —
TIMELINE Jan 11 Reserved by CNA Jul 2 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0072 51.2 —
AFFECTED Product Versions Fixed Divi Form Builder unspecified —
TIMELINE Apr 4 Reserved by CNA Jul 2 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0071 50.7 —
AFFECTED Product Versions Fixed Red Sea Cloud eHR unspecified —
TIMELINE Jul 2 Reserved by CNA Jul 2 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0068 49.5 —
AFFECTED Product Versions Fixed Blocksy Companion Pro n/a – 2.1.47
TIMELINE Jun 25 Reserved by CNA Jul 2 Published (CNA: Patchstack)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0065 48.5 —
AFFECTED Product Versions Fixed Microsoft Entra Provisioning Service - – —
TIMELINE Jun 23 Reserved by CNA Jul 2 Published (CNA: microsoft)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0065 48.4 —
AFFECTED Product Versions Fixed Fireware OS 2025.1 – — Fireware OS 12.0 – —
TIMELINE Jun 23 Reserved by CNA Jul 2 Published (CNA: WatchGuard)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N H H 8.1 .0065 48.4 —
AFFECTED Product Versions Fixed TinyPNG – JPEG, PNG & WebP image compression unspecified —
TIMELINE Apr 28 Reserved by CNA Jul 2 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0065 48.3 —
AFFECTED Product Versions Fixed Microsoft Exchange Online - – —
TIMELINE Jun 16 Reserved by CNA Jul 2 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0064 48.0 —
AFFECTED Product Versions Fixed Perfmatters unspecified —
TIMELINE Jun 24 Reserved by CNA Jul 2 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0062 47.1 —
AFFECTED Product Versions Fixed Fireware OS 2025.1 – — Fireware OS 12.0 – —
TIMELINE Jun 23 Reserved by CNA Jul 2 Published (CNA: WatchGuard)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H N N 8.6 .0062 47.1 —
AFFECTED Product Versions Fixed UniFi OS Server unspecified — Dream Machines unspecified — Enterprise Fortress Gateway unspecified — Dream Wall unspecified — Dream Routers unspecified — Express 7 unspecified — Cloud Keys unspecified — Network Video Recorders unspecified — Enterprise Video Recorders unspecified — Cloud Gateways unspecified — + 2 more
TIMELINE Jun 13 Reserved by CNA Jul 2 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0061 46.5 —
AFFECTED Product Versions Fixed Azure Open AI - – —
TIMELINE May 12 Reserved by CNA Jul 2 Published (CNA: microsoft)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0061 46.4 —
AFFECTED Product Versions Fixed Fireware OS 2025.1 – — Fireware OS 12.0 – —
TIMELINE Jun 23 Reserved by CNA Jul 2 Published (CNA: WatchGuard)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0060 46.0 —
AFFECTED Product Versions Fixed libreswan 4.6 – 5.3.1
TIMELINE Jun 16 Reserved by CNA Jul 2 Published (CNA: libreswan)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0060 46.0 —
AFFECTED Product Versions Fixed Fireware OS 2025.1 – — Fireware OS 12.1 – —
TIMELINE Jun 25 Reserved by CNA Jul 2 Published (CNA: WatchGuard)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0060 46.0 —
AFFECTED Product Versions Fixed Fireware OS 2025.1 – — Fireware OS 12.1 – —
TIMELINE Jun 25 Reserved by CNA Jul 2 Published (CNA: WatchGuard)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H L 9.5 .0058 45.3 —
AFFECTED Product Versions Fixed Gardyn Home Firmware unspecified — Gardyn Studio Firmware unspecified — Gardyn Cloud API unspecified —
TIMELINE Jun 29 Reserved by CNA Jul 2 Published (CNA: icscert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0056 44.4 —
AFFECTED Product Versions Fixed Landry Office Automation (OA) unspecified —
TIMELINE Jun 8 Reserved by CNA Jul 2 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0056 43.9 —
AFFECTED Product Versions Fixed wakaama unspecified —
TIMELINE Jun 30 Reserved by CNA Jul 2 Published (CNA: VulnCheck)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-52830 | 9.4 | 43.4 | leshchenko1979 | fast-mcp-telegram | CWE-22 | fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram ses… |
| CVE-2026-41106 | 9.3 | 42.6 | Microsoft | Microsoft 365 Copilot | CWE-601 | Microsoft 365 Copilot Elevation of Privilege Vulnerability |
| CVE-2026-55115 | 9.9 | 42.1 | Ubiquiti Inc | UniFi Protect Application | CWE-918 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-44941 | 8.8 | 42.0 | SUSE | libzypp | CWE-23 | libzypp path traversal via "keyhint" in repomd.xml |
| CVE-2026-54400 | 9.1 | 41.9 | Ubiquiti Inc | UniFi Access Application | CWE-284 | A malicious actor with access to the network and high privileges could exploi… |
| CVE-2026-38971 | 9.1 | 41.3 | n/a | n/a | CWE-125 | ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issu… |
| CVE-2026-58466 | 9.3 | 41.1 | EstrellaXD | Auto_Bangumi | CWE-1392 | AutoBangumi < 3.2.8 - Hard-coded Default Credentials via add_default_user() |
| CVE-2026-13084 | 8.7 | 40.7 | WatchGuard | Fireware OS | CWE-476 | Null Pointer Dereference in WatchGuard Fireware OS iked Process |
| CVE-2026-50747 | 9.9 | 40.1 | Ubiquiti Inc | UniFi Talk Application | CWE-89 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-58652 | 7.7 | 39.6 | openwrt | luci-app-travelmate | CWE-78 | luci-app-travelmate - Arbitrary Command Execution via UCI Script Parameter |
| CVE-2026-55952 | 8.2 | 39.6 | Erlang | OTP | CWE-1284 | TLS 1.3 server denial of service via malformed ClientHello pre-shared key ext… |
| CVE-2026-59094 | 8.7 | 38.9 | pathwaycom | pathway | CWE-407 | Pathway - Unauthenticated Denial of Service via Exponential Glob Pattern Matc… |
| CVE-2026-52187 | 7.5 | 37.7 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo… |
| CVE-2026-52189 | 7.5 | 37.7 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo… |
| CVE-2026-52191 | 7.5 | 37.7 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo… |
| CVE-2026-38970 | 7.5 | 37.6 | n/a | n/a | CWE-674 | pdfcpu through v0.11.1 contains an uncontrolled-recursion denial-of-service i… |
| CVE-2026-55116 | 9.8 | 34.7 | Ubiquiti Inc | Dream Machines | CWE-284 | A malicious actor with access to the network and under certain network config… |
| CVE-2026-44935 | 9.9 | 34.5 | SUSE | Rancher | CWE-1287 | Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated… |
| CVE-2026-52192 | 7.5 | 34.3 | n/a | n/a | CWE-400 | An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker … |
| CVE-2026-13369 | 7.5 | 34.2 | SaturdayDrive | Ninja Forms - File Uploads | CWE-22 | Ninja Forms - File Uploads <= 3.3.29 - Unauthenticated Arbitrary File Read vi… |
| CVE-2026-58467 | 8.2 | 34.1 | cockpit-hq | cockpit | CWE-22 | Cockpit CMS 2.14.0 - Path Traversal Local File Inclusion via index.php |
| CVE-2026-55726 | 6.9 | 32.7 | Gardyn | Gardyn Home Firmware | CWE-497 | Gardyn IoT Hub Exposure of Sensitive System Information to an Unauthorized Co… |
| CVE-2026-59093 | 8.7 | 32.2 | weaviate | weaviate | CWE-266 | Weaviate < 1.38.0 - Privilege Escalation via Unchecked Permissions in RBAC Ro… |
| CVE-2025-69133 | 7.5 | 32.1 | GoodLayers | Tourmaster | CWE-98 | WordPress Tourmaster plugin <= 5.4.5 - Local File Inclusion vulnerability |
| CVE-2026-50721 | 5.9 | 32.0 | The Libreswan Project | libreswan | CWE-347 | IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentic… |
| CVE-2026-27436 | 9.1 | 31.9 | Rustaurius | Five Star Business Profile and Schema | CWE-94 | WordPress Five Star Business Profile and Schema plugin <= 2.3.19 - Arbitrary … |
| CVE-2026-55117 | 8.6 | 31.5 | Ubiquiti Inc | UniFi Access Application | CWE-22 | A malicious actor with access to the network could exploit a Path Traversal v… |
| CVE-2026-33592 | 7.5 | 31.5 | open62541 project / o6 Automation GmbH | open62541 | CWE-770 | FindServers Memory Exhaustion in open62541 |
| CVE-2026-11946 | 7.5 | 31.4 | open62541 project / o6 Automation GmbH | open62541 | CWE-770 | GetEndpoints Memory Exhaustion in open62541 |
| CVE-2026-12657 | 5.3 | 31.4 | latepoint | LatePoint – Calendar Booking Plugin for Appointments and Events | CWE-639 | LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbi… |
| CVE-2026-38968 | 9.8 | 31.2 | n/a | n/a | CWE-341 | ntopng through 6.6 is vulnerable to Predictable Session Identifier which can … |
| CVE-2026-55950 | 8.7 | 31.2 | Erlang | OTP | CWE-367 | DTLS listener crash via race condition in dtls_packet_demux causes denial of … |
| CVE-2026-54406 | 8.7 | 31.0 | Ubiquiti Inc | UniFi Network Application | CWE-22 | A malicious actor with access to the network and high privileges could exploi… |
| CVE-2026-59092 | 7.0 | 31.0 | juicedata | juicefs | CWE-489 | JuiceFS - Authentication Bypass via pprof and metrics Endpoints |
| CVE-2026-8147 | 8.1 | 30.9 | mlflow | mlflow/mlflow | CWE-284 | Authorization Bypass in mlflow/mlflow |
| CVE-2026-56004 | 10.0 | 30.8 | openSUSE | buildservice | CWE-78 | obs-service-tar_scm: command injection via mercurial handler |
| CVE-2026-57347 | 6.5 | 30.4 | jetmonsters | Hotel Booking Lite | CWE-201 | WordPress Hotel Booking Lite plugin <= 6.0.3 - Sensitive Data Exposure vulner… |
| CVE-2026-26145 | 9.8 | 29.1 | Microsoft | Azure Synapse | CWE-284 | Microsoft Azure Synapse Elevation of Privilege Vulnerability |
| CVE-2026-59099 | 9.3 | 28.8 | apereo | cas | CWE-323 | Apereo CAS 7.3.0 < 8.0.0-RC6 - AES-GCM Nonce Reuse Information Disclosure |
| CVE-2026-27419 | 9.9 | 28.4 | Zozothemes | Zegen | CWE-434 | WordPress Zegen theme <= 1.1.9 - Arbitrary File Upload vulnerability |
| CVE-2026-13371 | 6.9 | 28.3 | WatchGuard | Fireware OS | CWE-502 | WatchGuard Firebox Management Web UI Denial of Service via Unsafe Deserializa… |
| CVE-2026-9563 | 7.5 | 27.7 | Eclipse Foundation | Eclipse Parsson | CWE-400 | In Eclipse Parsson published Maven Central artifacts before version 1.1.8, th… |
| CVE-2026-50722 | 5.9 | 27.8 | The Libreswan Project | libreswan | CWE-347 | IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authenticatio… |
| CVE-2026-12472 | 5.3 | 27.7 | themeum | Kirki – Freeform Page Builder, Website Builder & Customizer | CWE-862 | Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Arbitrary Email Co… |
| CVE-2025-69132 | 6.5 | 27.7 | Zozothemes | Corpkit | CWE-201 | WordPress Corpkit theme <= 1.0.5 - Sensitive Data Exposure vulnerability |
| CVE-2026-5821 | 8.1 | 27.5 | elemntor | Image Optimizer – Optimize Images and Convert to WebP or AVIF | CWE-73 | Image Optimizer <= 1.7.4 - Authenticated (Author+) Arbitrary File Deletion vi… |
| CVE-2026-59097 | 6.9 | 27.5 | taiga | taiga-back | CWE-862 | Taiga < 6.10.2 - Unauthorized Due-Date Creation via API Viewsets |
| CVE-2026-49779 | 6.5 | 27.4 | Addify | Tax Exempt for WooCommerce | CWE-35 | WordPress Tax Exempt for WooCommerce plugin < 1.9.5 - Path Traversal vulnerab… |
| CVE-2026-57669 | 6.5 | 27.2 | Vsourz Digital | Advanced Contact form 7 DB | CWE-862 | WordPress Advanced Contact form 7 DB plugin <= 2.0.9 - Broken Access Control … |
| CVE-2026-54405 | 7.5 | 27.0 | Ubiquiti Inc | UniFi Network Application | CWE-20 | A malicious actor with access to the network could exploit an Improper Input … |
| CVE-2026-55111 | 7.5 | 26.6 | Ubiquiti Inc | UniFi Protect Floodlight | CWE-22 | A malicious actor with access to the network could exploit a Path Traversal v… |
| CVE-2026-4767 | 9.8 | 26.3 | TR7 Cyber Defense Inc. | WAF-ASP | CWE-306 | Improper Access Control in TR7's WAF-ASP |
| CVE-2026-14249 | 7.5 | 26.3 | emarket-design | Request a Quote – Quote Forms for Any WordPress Site | CWE-74 | Request a Quote Form Plugin <= 2.5.5 - Unauthenticated Code Injection via 'pa… |
| CVE-2026-13459 | 5.3 | 26.3 | jetmonsters | JetFormBuilder — Dynamic Blocks Form Builder | CWE-862 | JetFormBuilder <= 3.6.3 - Missing Authorization to Unauthenticated Sensitive … |
| CVE-2026-54886 | 5.3 | 26.1 | Erlang | OTP | CWE-400 | SSH SFTP server denial of service via extended channel data infinite loop |
| CVE-2026-57621 | 9.8 | 25.6 | Arraytics | Booktics | CWE-502 | WordPress Booktics plugin <= 1.0.21 - PHP Object Injection vulnerability |
| CVE-2026-57677 | 9.8 | 25.6 | Novalnet | Novalnet Payment Gateway for WooCommerce | CWE-502 | WordPress Novalnet Payment Gateway for WooCommerce plugin <= 12.10.3 - PHP Ob… |
| CVE-2026-57623 | 9.0 | 25.2 | BoldGrid | W3 Total Cache | CWE-1284 | WordPress W3 Total Cache plugin <= 2.9.4 - Arbitrary Code Execution vulnerabi… |
| CVE-2026-59101 | 6.9 | 25.0 | EstrellaXD | Auto_Bangumi | CWE-918 | AutoBangumi < 3.2.8 - SSRF via /api/v1/setup/test-downloader |
| CVE-2026-14029 | 6.5 | 24.7 | trainingbusinesspros | Groundhogg — CRM, Newsletters, and Marketing Automation | CWE-89 | Groundhogg <= 4.5.8 - Authenticated (Custom+) SQL Injection via 'select' Para… |
| CVE-2026-11896 | 5.3 | 24.1 | joedolson | My Calendar – Accessible Event Manager | CWE-639 | My Calendar <= 3.7.14 - Insecure Direct Object Reference to Unauthenticated S… |
| CVE-2026-54407 | 8.6 | 23.8 | Ubiquiti Inc | UniFi Protect Application | CWE-284 | A malicious actor with access to the network could exploit an Improper Access… |
| CVE-2026-9145 | 6.5 | 23.5 | crmperks | Database for Contact Form 7, WPforms, Elementor forms | CWE-22 | Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthentica… |
| CVE-2026-58578 | 7.1 | 23.2 | lobehub | lobehub | CWE-1333 | LobeChat < 2.2.10-canary.15 - Regular Expression Denial of Service in GitHub … |
| CVE-2026-54408 | 9.8 | 23.1 | Ubiquiti Inc | UniFi Protect Application | CWE-284 | A malicious actor with access to the network could exploit an Improper Access… |
| CVE-2026-56037 | 8.8 | 22.6 | Themify | Themify Popup | CWE-502 | WordPress Themify Popup plugin <= 1.4.3 - PHP Object Injection vulnerability |
| CVE-2026-57353 | 6.5 | 22.6 | LinkWhisper | Link Whisper Premium | CWE-862 | WordPress Link Whisper Premium plugin <= 2.9.0 - Broken Access Control vulner… |
| CVE-2026-57355 | 6.5 | 22.6 | RadiusTheme | Classified Listing | CWE-862 | WordPress Classified Listing plugin <= 5.4.2 - Broken Access Control vulnerab… |
| CVE-2026-9188 | 5.3 | 22.3 | wappointment | Appointment Bookings for Zoom GoogleMeet and more – Wappointment | CWE-639 | Appointment Bookings for Zoom GoogleMeet and more – Wappointment <= 2.7.6 - U… |
| CVE-2026-42382 | 8.1 | 22.0 | Elated-Themes | Audrey | CWE-98 | WordPress Audrey theme <= 1.5 - Local File Inclusion vulnerability |
| CVE-2026-57268 | 8.3 | 21.9 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57273 | 8.3 | 21.9 | GeoVision Inc. | GeoWebPlayer | CWE-120 | GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe… |
| CVE-2026-57274 | 8.3 | 21.9 | GeoVision Inc. | GeoWebPlayer | CWE-120 | GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe… |
| CVE-2026-57275 | 8.3 | 21.9 | GeoVision Inc. | GeoWebPlayer | CWE-120 | GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe… |
| CVE-2026-57276 | 8.3 | 21.9 | GeoVision Inc. | GeoWebPlayer | CWE-120 | GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe… |
| CVE-2025-69134 | 7.5 | 21.7 | Merkulove | OpenAI Chatbot for WordPress – Helper | CWE-862 | WordPress OpenAI Chatbot for WordPress – Helper plugin <= 1.1.4 - Arbitrary C… |
| CVE-2026-57277 | 8.3 | 21.3 | GeoVision Inc. | GeoWebPlayer | CWE-120 | GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe… |
| CVE-2026-57278 | 8.3 | 21.3 | GeoVision Inc. | GeoWebPlayer | CWE-120 | GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe… |
| CVE-2026-12122 | 5.3 | 21.1 | themeum | Kirki – Freeform Page Builder, Website Builder & Customizer | CWE-862 | Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Sensitive Informat… |
| CVE-2026-57752 | 8.5 | 20.7 | iNET | iNET Webkit | CWE-89 | WordPress iNET Webkit plugin 1.2.4 - SQL Injection vulnerability |
| CVE-2026-54404 | 8.8 | 20.5 | Ubiquiti Inc | UniFi OS Server | CWE-89 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-56841 | 8.8 | 20.5 | Ubiquiti Inc | UniFi Protect Application | CWE-89 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-27060 | 8.8 | 20.5 | Repute Infosystems | ARMember Premium | CWE-502 | WordPress ARMember Premium plugin < 7.6 - PHP Object Injection vulnerability |
| CVE-2026-27414 | 8.8 | 20.5 | Fuelthemes | Werkstatt | CWE-502 | WordPress Werkstatt theme <= 4.8.3 - PHP Object Injection vulnerability |
| CVE-2026-13357 | 4.9 | 20.5 | propertyhive | Houzez Property Feed | CWE-89 | Houzez Property Feed <= 2.5.46 - Authenticated (Administrator+) SQL Injection… |
| CVE-2026-57748 | 7.5 | 20.0 | Shopify Help Center | Shopify | CWE-98 | WordPress Shopify plugin <= 1.0.0 - Local File Inclusion vulnerability |
| CVE-2025-58902 | 8.1 | 19.9 | AncoraThemes | Lighthouse | CWE-98 | WordPress Lighthouse theme <= 1.2.12 - Local File Inclusion vulnerability |
| CVE-2026-27412 | 8.1 | 19.9 | StylemixThemes | Pearl - Corporate Business | CWE-98 | WordPress Pearl - Corporate Business theme <= 3.4.10 - Local File Inclusion v… |
| CVE-2026-8441 | 7.5 | 19.7 | https://wpreviewslider.com/ | WP Review Slider Pro | CWE-89 | WP Review Slider Pro <= 12.7.2 - Unauthenticated SQL Injection via 'notinstri… |
| CVE-2026-13722 | 8.6 | 19.6 | WatchGuard | Fireware OS | CWE-347 | WatchGuard Firebox Firmware Image Validation Bypass in WatchGuard Fireware OS |
| CVE-2026-54409 | 8.1 | 19.7 | Ubiquiti Inc | UniFi Protect Application | CWE-665 | A malicious actor with access to the network and under certain conditions cou… |
| CVE-2026-11592 | 4.3 | 19.7 | icegram | Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress | CWE-862 | Email Subscribers & Newsletters <= 5.9.27 - Missing Authorization to Authenti… |
| CVE-2026-54477 | 5.1 | 19.4 | Gardyn | Gardyn Home Firmware | CWE-644 | Gardyn IoT Hub Improper Neutralization of HTTP Headers for Scripting Syntax |
| CVE-2025-69094 | 8.5 | 19.2 | ThemeMove | Unicamp | CWE-89 | WordPress Unicamp theme <= 2.2.2 - SQL Injection vulnerability |
| CVE-2026-57749 | 7.5 | 19.3 | ThemeBoy | SportsPress Pro | CWE-98 | WordPress SportsPress Pro plugin <= 2.7.29 - Local File Inclusion vulnerability |
| CVE-2026-14449 | 6.4 | 19.2 | u5CMS | u5CMS | CWE-79 | POST-based reflected XSS via the thanks parameter in form components |
| CVE-2026-8247 | 7.7 | 19.1 | WatchGuard | Fireware OS | CWE-787 | WatchGuard Firebox admd Out of Bounds Write Vulnerability |
| CVE-2026-10104 | 4.4 | 18.4 | nikhilgadhiya | Product Video Gallery for Woocommerce | CWE-79 | Product Video Gallery for Woocommerce <= 1.5.1.8 - Authenticated (Shop Manage… |
| CVE-2026-5348 | 5.3 | 18.1 | kodezen | Academy LMS – WordPress LMS Plugin for Complete eLearning Solution | CWE-639 | Academy LMS <= 3.8.1 - Unauthenticated Insecure Direct Object Reference to Pr… |
| CVE-2026-53422 | 2.3 | 18.2 | Erlang | OTP | CWE-204 | SFTP REALPATH path-existence oracle allowing filesystem enumeration outside c… |
| CVE-2026-57625 | 9.6 | 18.0 | ASE | Admin and Site Enhancements (ASE) Pro | CWE-79 | WordPress Admin and Site Enhancements (ASE) Pro plugin <= 8.8.5 - Cross Site … |
| CVE-2026-55114 | 8.8 | 17.9 | Ubiquiti Inc | UniFi Network Application | CWE-284 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-53357 | 8.0 | 17.6 | Linux | Linux | CWE-416 | Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() |
| CVE-2026-39448 | 7.5 | 17.4 | CoderPress | NOWPayments for WooCommerce | CWE-862 | WordPress NOWPayments for WooCommerce plugin <= 1.4.0 - Broken Access Control… |
| CVE-2026-57685 | 4.3 | 17.2 | drfuri | Martfury - WooCommerce Marketplace WordPress Theme | CWE-862 | WordPress Martfury - WooCommerce Marketplace WordPress theme theme <= 3.2.8 -… |
| CVE-2026-57272 | 8.3 | 17.0 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-50281 | 7.1 | 17.1 | craftcms | cms | CWE-915 | Craft CMS: Mass assignment via id in newAttributes during bulk duplicate over… |
| CVE-2026-57680 | 6.5 | 17.0 | Themeum | Kirki | CWE-639 | WordPress Kirki plugin <= 6.0.11 - Insecure Direct Object References (IDOR) v… |
| CVE-2026-9272 | 8.7 | 16.9 | Progress Software | Flowmon ADS | CWE-89 | Possibility of unintended database operations when querying data related to d… |
| CVE-2026-57269 | 8.3 | 16.1 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-59096 | 8.2 | 16.2 | dapr | dapr | CWE-346 | Dapr - OIDC Discovery Issuer and JWKS URI Injection via Unvalidated X-Forward… |
| CVE-2026-27433 | 6.5 | 16.1 | StylemixThemes | Motors | CWE-862 | WordPress Motors theme <= 5.6.80 - Broken Access Control vulnerability |
| CVE-2026-54887 | 6.3 | 15.8 | Erlang | OTP | CWE-1394 | DTLS server cookie bypass during startup window due to empty initial cookie s… |
| CVE-2026-57271 | 8.3 | 15.5 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57679 | 9.3 | 15.4 | Ahmadgb | GeekyBot | CWE-89 | WordPress GeekyBot plugin <= 1.2.5 - SQL Injection vulnerability |
| CVE-2026-57683 | 9.3 | 15.4 | Epsiloncool | WP Fast Total Search | CWE-89 | WordPress WP Fast Total Search plugin <= 1.80.280 - SQL Injection vulnerability |
| CVE-2026-10077 | 6.8 | 15.4 | Unknown | yootheme | — | YOOtheme Pro < 5.0.35 - Author+ Stored XSS via UIkit Data Attributes |
| CVE-2026-54401 | 8.8 | 15.2 | Ubiquiti Inc | UniFi OS Server | CWE-918 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-59098 | 7.1 | 15.2 | lobehub | lobehub | CWE-639 | LobeChat 2.2.9 - Cross-User Document Disclosure via Unscoped RAG Semantic Search |
| CVE-2026-13125 | 8.8 | 15.0 | GeoVision Inc. | GeoWebPlayer | CWE-306 | GeoVision GeoWebPlayer 1.1.1.0 Websocket Server function vulnerability |
| CVE-2026-52188 | 6.5 | 15.0 | n/a | n/a | CWE-119 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo… |
| CVE-2025-71385 | 5.1 | 15.0 | netdata | netdata | CWE-79 | Netdata < 2.3.1 - Reflected Cross-Site Scripting via love Parameter in ilove.… |
| CVE-2026-11600 | 4.3 | 14.8 | envothemes | Envo's Templates & Widgets for Elementor and WooCommerce | CWE-862 | Envo's Templates & Widgets for Elementor and WooCommerce <= 1.4.26 - Missing … |
| CVE-2026-59095 | 8.3 | 14.8 | lobehub | lobehub | CWE-918 | LobeChat < 2.2.10-canary.18 - SSRF via importFromUrl and fetchImageFromUrl |
| CVE-2026-57688 | 8.2 | 14.6 | Gurmehub | POS Entegratör | CWE-862 | WordPress POS Entegratör plugin <= 3.7.103 - Broken Access Control vulnerability |
| CVE-2026-57746 | 7.1 | 14.7 | ThemeREX | Booked | CWE-862 | WordPress Booked plugin <= 3.0.0 - Broken Access Control vulnerability |
| CVE-2026-13704 | 6.4 | 14.4 | stellarwp | GiveWP – Donation Plugin and Fundraising Platform | CWE-79 | GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting v… |
| CVE-2026-12134 | 4.3 | 14.4 | beardev | JoomSport – for Sports: Team & League, Football, Hockey & more | CWE-862 | JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arb… |
| CVE-2026-14336 | 8.2 | 13.8 | Eclipse Foundation | Eclipse CSI - PIA | CWE-918 | PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix chec… |
| CVE-2026-57267 | 8.3 | 13.5 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57270 | 8.3 | 13.5 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57681 | 6.4 | 13.2 | Paolo | GeoDirectory | CWE-918 | WordPress GeoDirectory plugin <= 2.8.161 - Server Side Request Forgery (SSRF)… |
| CVE-2026-55113 | 7.5 | 13.2 | Ubiquiti Inc | UniFi Talk Application | CWE-918 | A malicious actor with access to the network could exploit a Server-Side Requ… |
| CVE-2026-57689 | 4.3 | 13.1 | Fuelthemes | Werkstatt | CWE-862 | WordPress Werkstatt theme <= 4.7.2 - Broken Access Control vulnerability |
| CVE-2026-57730 | 4.3 | 13.1 | UX-themes | Flatsome | CWE-862 | WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability |
| CVE-2026-13131 | 8.3 | 12.9 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-13132 | 8.3 | 12.9 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57264 | 8.3 | 12.9 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57265 | 8.3 | 12.9 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57266 | 8.3 | 12.9 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-55119 | 8.1 | 13.0 | Ubiquiti Inc | UniFi Talk Application | CWE-284 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-57342 | 6.5 | 12.6 | ShortPixel | ShortPixel Adaptive Images | CWE-79 | WordPress ShortPixel Adaptive Images plugin <= 3.11.3 - Cross Site Scripting … |
| CVE-2026-57354 | 6.5 | 12.6 | Crocoblock. Jetimpex Inc. | JetReviews | CWE-79 | WordPress JetReviews plugin <= 3.0.0.1 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-57687 | 8.5 | 12.1 | Hiroaki Miyashita | Custom Field Template | CWE-89 | WordPress Custom Field Template plugin <= 2.7.8 - SQL Injection vulnerability |
| CVE-2026-57756 | 8.5 | 12.1 | 友人a丶 | nicen-localize-image | CWE-89 | WordPress nicen-localize-image plugin <= 1.4.9 - SQL Injection vulnerability |
| CVE-2026-57765 | 8.5 | 12.1 | Levelfourdevelopment | WP EasyCart | CWE-89 | WordPress WP EasyCart plugin <= 5.9.0 - SQL Injection vulnerability |
| CVE-2026-56842 | 7.5 | 12.0 | Ubiquiti Inc | UniFi Network Application | CWE-863 | A malicious actor with access to the network and under certain conditions cou… |
| CVE-2026-10089 | 6.4 | 11.7 | figureone | Insert Pages | CWE-79 | Insert Pages <= 3.11.4 - Authenticated (Author+) Stored Cross-Site Scripting … |
| CVE-2026-57731 | 6.5 | 11.5 | UX-themes | Flatsome | CWE-862 | WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability |
| CVE-2026-12166 | 5.5 | 11.3 | Little Orbit | GameFirst Anti-Cheat | — | CVE-2026-12166 |
| CVE-2025-66076 | 5.3 | 11.2 | dylan ngo | Woostify Sites Library | CWE-862 | WordPress Woostify Sites Library plugin <= 1.6.2 - Broken Access Control vuln… |
| CVE-2026-8699 | 7.0 | 11.1 | TP-Link Systems Inc. | Archer C5 v6.8 | CWE-79 | Stored Cross-Site Scripting (XSS) in TP-Link Archer C5 Web Management Interface |
| CVE-2026-50282 | 4.9 | 11.1 | craftcms | cms | CWE-862 | Craft CMS: Unauthorized Deletion of Destination Folders During Forced Moves |
| CVE-2026-55118 | 8.3 | 10.7 | Ubiquiti Inc | UniFi Network Application | CWE-284 | A malicious actor with access to the network,low privileges and under certain… |
| CVE-2026-57352 | 4.8 | 10.7 | VillaTheme | ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce | CWE-1390 | WordPress ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce p… |
| CVE-2026-57753 | 5.3 | 10.3 | Nathanbarry | Kit (formerly ConvertKit) for WooCommerce | CWE-497 | WordPress Kit (formerly ConvertKit) for WooCommerce plugin <= 2.1.5 - Sensiti… |
| CVE-2026-59102 | 2.1 | 10.0 | forgejo | forgejo | CWE-79 | Forgejo < 15.0.3 - Stored XSS via Actions Run Full Name Rendering |
| CVE-2026-55112 | 8.8 | 10.0 | Ubiquiti Inc | Dream Machines | CWE-284 | A malicious actor with access to the network and low privileges and under cer… |
| CVE-2026-57348 | 7.2 | 9.8 | Cozmoslabs | Paid Member Subscriptions | CWE-918 | WordPress Paid Member Subscriptions plugin <= 3.0.4 - Server Side Request For… |
| CVE-2026-53358 | 8.8 | 9.6 | Linux | Linux | CWE-667 | Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() |
| CVE-2026-13252 | 6.4 | 9.6 | themeisle | RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator | CWE-79 | RSS Aggregator by Feedzy <= 5.2.1 - Authenticated (Contributor+) Stored Cross… |
| CVE-2026-11781 | 2.7 | 8.9 | Unknown | Adminify | — | Adminify < 4.2.10 - Contributor+ Sensitive Information Disclosure via Global … |
| CVE-2026-27426 | 7.1 | 8.5 | Themesuite | Automotive Car Dealership Business | CWE-79 | WordPress Automotive Car Dealership Business theme <= 13.3.3 - Reflected Cros… |
| CVE-2026-27430 | 7.1 | 8.5 | tranmautritam | TheFox | CWE-79 | WordPress TheFox theme <= 3.9.76 - Reflected Cross Site Scripting (XSS) vulne… |
| CVE-2026-57343 | 7.1 | 8.5 | Contempoinc | Real Estate 7 | CWE-79 | WordPress Real Estate 7 theme <= 3.5.9 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-57344 | 7.1 | 8.5 | RadiusTheme | Classified Listing | CWE-79 | WordPress Classified Listing plugin <= 5.4.2 - Cross Site Scripting (XSS) vul… |
| CVE-2026-57345 | 7.1 | 8.5 | Webraketen | Internal Links Manager | CWE-79 | WordPress Internal Links Manager plugin <= 3.0.3 - Cross Site Scripting (XSS)… |
| CVE-2026-57349 | 7.1 | 8.5 | etruel | WPeMatico RSS Feed Fetcher | CWE-79 | WordPress WPeMatico RSS Feed Fetcher plugin <= 2.8.17 - Cross Site Scripting … |
| CVE-2026-57350 | 7.1 | 8.5 | Andy Fragen | WP Debugging | CWE-79 | WordPress WP Debugging plugin <= 2.12.2 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-57351 | 7.1 | 8.5 | Haktan Suren | HandL UTM Grabber | CWE-79 | WordPress HandL UTM Grabber plugin <= 2.9.2 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-57356 | 7.1 | 8.5 | Moreconvert Team | MC Woocommerce Wishlist | CWE-79 | WordPress MC Woocommerce Wishlist plugin <= 1.9.19 - Cross Site Scripting (XS… |
| CVE-2026-57357 | 7.1 | 8.5 | Search Atlas Group | Search Atlas SEO | CWE-79 | WordPress Search Atlas SEO plugin <= 2.6.6 - Reflected Cross Site Scripting (… |
| CVE-2026-57358 | 7.1 | 8.5 | SysBasics | Customize My Account for WooCommerce | CWE-79 | WordPress Customize My Account for WooCommerce plugin <= 4.3.9 - Reflected Cr… |
| CVE-2026-57359 | 7.1 | 8.5 | ReviewX | ReviewX | CWE-79 | WordPress ReviewX plugin <= 2.3.10 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57360 | 7.1 | 8.5 | impleCode | eCommerce Product Catalog | CWE-79 | WordPress eCommerce Product Catalog plugin <= 3.5.4 - Cross Site Scripting (X… |
| CVE-2026-57361 | 7.1 | 8.5 | Ays Pro | Survey Maker | CWE-79 | WordPress Survey Maker plugin <= 5.2.2.5 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-57362 | 7.1 | 8.5 | QuantumCloud | ChatBot | CWE-79 | WordPress ChatBot plugin <= 8.3.2 - Reflected Cross Site Scripting (XSS) vuln… |
| CVE-2026-57366 | 7.1 | 8.5 | Greg Winiarski | WPAdverts | CWE-79 | WordPress WPAdverts plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57426 | 7.1 | 8.5 | Chill Media Labs S.R.L. | Modula - PRO | CWE-79 | WordPress Modula - PRO plugin <= 2.10.8 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-57670 | 7.1 | 8.5 | Codepeople | Google Maps CP | CWE-79 | WordPress Google Maps CP plugin <= 1.2.5 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-57671 | 7.1 | 8.5 | Perfmatters | perfmatters | CWE-79 | WordPress perfmatters plugin <= 2.6.4 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57672 | 7.1 | 8.5 | Melograno Venture Studio | wpDataTables | CWE-79 | WordPress wpDataTables plugin <= 6.5.1.1 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-57673 | 7.1 | 8.5 | Optimole | Optimole | CWE-79 | WordPress Optimole plugin <= 4.2.7 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57674 | 7.1 | 8.5 | Arraytics | Timetics | CWE-79 | WordPress Timetics plugin <= 1.0.58 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57675 | 7.1 | 8.5 | Jacob N. Breetvelt | WP Photo Album Plus | CWE-79 | WordPress WP Photo Album Plus plugin <= 9.2.02.004 - Cross Site Scripting (XS… |
| CVE-2026-57682 | 7.1 | 8.5 | QuantumCloud | Simple Link Directory | CWE-79 | WordPress Simple Link Directory plugin <= 15.0.5 - Cross Site Scripting (XSS)… |
| CVE-2026-57686 | 7.1 | 8.5 | WPXPO | WowAddons | CWE-79 | WordPress WowAddons plugin <= 1.6.14 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-8079 | 8.7 | 8.1 | Progress Software | Flowmon | CWE-863 | Unintended limited set of actions with elevated privileges may be performed d… |
| CVE-2026-58579 | 5.1 | 8.1 | infiniflow | ragflow | CWE-79 | RAGFlow < 0.26.3 - Stored Cross-Site Scripting via Agent Pipeline Node Name |
| CVE-2026-38972 | 7.8 | 8.0 | n/a | n/a | CWE-427 | Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerabili… |
| CVE-2026-59100 | 2.3 | 7.9 | lobehub | lobehub | CWE-639 | LobeChat 2.2.9 - Broken Object Level Authorization via Chat-Group Agent Opera… |
| CVE-2026-57750 | 5.3 | 7.7 | Keksdieb | ez Form Calculator Premium | CWE-862 | WordPress ez Form Calculator Premium plugin <= 2.14.1.2 - Broken Access Contr… |
| CVE-2026-57760 | 5.3 | 7.7 | Sendcloud | Sendcloud Shipping | CWE-862 | WordPress Sendcloud Shipping plugin <= 1.0.29 - Broken Access Control vulnera… |
| CVE-2025-69152 | 7.1 | 7.3 | ThemeGoods | Artale | Wedding Photography WordPress | CWE-79 | WordPress Artale | Wedding Photography WordPress theme <= 2.2.2 - Cross Site … |
| CVE-2025-69153 | 7.1 | 7.3 | designthemes | Trendy Travel | CWE-79 | WordPress Trendy Travel theme <= 6.7 - Reflected Cross Site Scripting (XSS) v… |
| CVE-2025-69154 | 7.1 | 7.3 | designthemes | SpaLab | Beauty Salon WordPress Theme | CWE-79 | WordPress SpaLab | Beauty Salon WordPress Theme theme <= 6.7 - Cross Site Scr… |
| CVE-2025-69155 | 7.1 | 7.3 | Designthemes | Fitness Zone WordPress Theme | CWE-79 | WordPress Fitness Zone WordPress Theme theme <= 5.7 - Cross Site Scripting (X… |
| CVE-2025-69156 | 7.1 | 7.3 | Design themes | Kids Zone - Children WordPress Theme | CWE-79 | WordPress Kids Zone - Children WordPress Theme theme <= 5.4 - Cross Site Scri… |
| CVE-2026-27402 | 7.1 | 7.3 | Designthemes | Kids Life | Children School WordPress | CWE-79 | WordPress Kids Life | Children School WordPress theme <= 5.2 - Cross Site Scr… |
| CVE-2026-27404 | 7.1 | 7.3 | Designthemes | LMS | CWE-79 | WordPress LMS theme <= 9.7 - Reflected Cross Site Scripting (XSS) vulnerability |
| CVE-2026-27408 | 7.1 | 7.3 | imithemes | NativeChurch | CWE-79 | WordPress NativeChurch theme <= 4.8.8.2 - Reflected Cross Site Scripting (XSS… |
| CVE-2026-27425 | 7.1 | 7.3 | Themesuite | Automotive Listings | CWE-79 | WordPress Automotive Listings plugin <= 18.6 - Reflected Cross Site Scripting… |
| CVE-2026-12167 | 7.8 | 6.8 | Little Orbit | GameFirst Anti-Cheat | — | CVE-2026-12167 |
| CVE-2026-13373 | 4.8 | 6.7 | WatchGuard | Fireware OS | CWE-79 | WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpa… |
| CVE-2026-13374 | 4.8 | 6.7 | WatchGuard | Fireware OS | CWE-79 | WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Connect… |
| CVE-2026-13375 | 4.8 | 6.7 | WatchGuard | Fireware OS | CWE-79 | WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotas… |
| CVE-2026-13376 | 4.8 | 6.7 | WatchGuard | Fireware OS | CWE-79 | WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlo… |
| CVE-2026-13377 | 4.8 | 6.7 | WatchGuard | Fireware OS | CWE-79 | WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in SIP Pro… |
| CVE-2026-11578 | 2.7 | 6.6 | Unknown | Fluent Forms | — | Fluent Forms < 6.2.5 - Form Manager+ Cross-Form Submission Entry Deletion via… |
| CVE-2026-57684 | 6.5 | 6.3 | tranmautritam | TheFox | CWE-79 | WordPress TheFox theme <= 3.9.70 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-11965 | 6.5 | 6.2 | Unknown | User Registration & Membership | — | User Registration & Membership < 5.2.0 - Unauthenticated Paid Membership Bypass |
| CVE-2026-12168 | 7.8 | 6.0 | Little Orbit | GameFirst Anti-Cheat | — | CVE-2026-12168 |
| CVE-2026-58653 | 5.3 | 5.5 | PraisonAI | PraisonAI | CWE-639 | PraisonAI - Authorization Bypass via Unvalidated project_id in Issue Create/U… |
| CVE-2026-58580 | 6.0 | 5.1 | lobehub | lobehub | CWE-639 | LobeChat 2.2.9 - Broken Object-Level Authorization in Message Sub-Resource Wr… |
| CVE-2026-57678 | 7.1 | 4.8 | ThemePunch | Slider Revolution | CWE-79 | WordPress Slider Revolution plugin 7.0.0-7.0.16 - Cross Site Scripting (XSS) … |
| CVE-2026-55110 | 6.1 | 4.5 | Ubiquiti Inc | UniFi OS Server | CWE-942 | A malicious actor who lures an authenticated user to a malicious page could e… |
| CVE-2026-13728 | 5.9 | 4.5 | WatchGuard | Fireware OS | CWE-798 | WatchGuard Firebox Hardcoded Fallback Encryption Key in Access Portal Resourc… |
| CVE-2026-8482 | 4.3 | 4.2 | Stormshield | Stormshield Network Security | CWE-532 | Information leak in NSRPC client history |
| CVE-2026-57762 | 5.9 | 4.2 | Andrew Fiebert | Simple URLs | CWE-79 | WordPress Simple URLs plugin <= 151 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57759 | 8.8 | 4.0 | Metagauss | ProfileGrid | CWE-352 | WordPress ProfileGrid plugin <= 5.9.9.7 - CSRF to Account Takeover vulnerability |
| CVE-2026-57766 | 8.8 | 4.0 | XplodedThemes | WPIDE – File Manager & Code Editor | CWE-352 | WordPress WPIDE – File Manager & Code Editor plugin <= 3.5.6 - Cross Site Req… |
| CVE-2026-13079 | 7.3 | 3.9 | WatchGuard | Mobile VPN with SSL Client | CWE-732 | WatchGuard Mobile VPN with SSL Windows Client Local Privilege Escalation |
| CVE-2026-57751 | 8.1 | 3.8 | Heateor Support | Heateor Social Login | CWE-352 | WordPress Heateor Social Login plugin <= 1.1.39 - Cross Site Request Forgery … |
| CVE-2026-58460 | 7.0 | 3.7 | ajith-ab | react-native-receive-sharing-intent | CWE-22 | react-native-receive-sharing-intent Path Traversal via _display_name |
| CVE-2026-57754 | 6.5 | 3.4 | Livemesh | Livemesh Addons for WPBakery Page Builder | CWE-79 | WordPress Livemesh Addons for WPBakery Page Builder plugin <= 3.9.4 - Cross S… |
| CVE-2026-57755 | 6.5 | 3.4 | Misbah WP | Mosaic Gallery – Advanced Gallery | CWE-79 | WordPress Mosaic Gallery – Advanced Gallery plugin <= 1.2.0 - Cross Sit… |
| CVE-2026-57763 | 6.5 | 3.4 | Gordon Böhme | Structured Content | CWE-79 | WordPress Structured Content plugin <= 1.7.0 - Cross Site Scripting (XSS) vul… |
| CVE-2026-57764 | 6.5 | 3.4 | Surbma | Surbma | Yoast SEO Breadcrumb Shortcode | CWE-79 | WordPress Surbma | Yoast SEO Breadcrumb Shortcode plugin <= 1.2 - Cross Site … |
| CVE-2026-54891 | 6.3 | 3.4 | Erlang | OTP | CWE-924 | Plaintext APPLICATION_DATA injected during TLS handshake delivered to client … |
| CVE-2026-4772 | 5.4 | 3.3 | TR7 Cyber Defense Inc. | WAF-ASP | CWE-79 | Stored XSS in TR7's WAF-ASP |
| CVE-2026-4770 | 4.6 | 3.3 | TR7 Cyber Defense Inc. | WAF-ASP | CWE-79 | DOM-Based XSS in TR7's WAF-ASP |
| CVE-2026-54431 | 5.1 | 2.9 | OpenIDC | liboauth2 | CWE-358 | Improper Data Validation in liboauth2 |
| CVE-2026-57747 | 6.5 | 2.5 | ThemeREX | Booked | CWE-352 | WordPress Booked plugin <= 3.0.0 - Cross Site Request Forgery (CSRF) vulnerab… |
| CVE-2026-54430 | 5.1 | 2.3 | OpenIDC | liboauth2 | CWE-918 | Server-Site Request Forgery in liboauth2 |
| CVE-2026-58381 | 6.1 | 2.0 | Red Hat | Red Hat Enterprise Linux 6 | CWE-415 | Gimp: gimp: double-free in read_layer_block() |
| CVE-2026-57757 | 7.1 | 1.8 | ploudapp | pCloud WP Backup | CWE-352 | WordPress pCloud WP Backup plugin <= 2.0.2 - Cross Site Request Forgery (CSRF… |
| CVE-2026-13743 | 3.3 | 1.9 | CubeSpace | CW0057 Reaction Wheel | CWE-347 | Improper verification of cryptographic signature in CubeSpace CW0057 Reaction… |
| CVE-2026-57690 | 4.3 | 1.2 | Fuelthemes | Werkstatt | CWE-352 | WordPress Werkstatt theme <= 4.7.2 - Cross Site Request Forgery (CSRF) vulner… |
| CVE-2026-57758 | 7.1 | 0.7 | BeRocket | Permalink Manager for WooCommerce | CWE-352 | WordPress Permalink Manager for WooCommerce plugin <= 1.0.8.2 - CSRF to Store… |
| CVE-2026-57761 | 7.1 | 0.7 | BlueAstralThemes | SEOWP | CWE-352 | WordPress SEOWP theme <= 3.12.2 - CSRF to Stored XSS vulnerability |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-02 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion.