boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Thursday, July 2, 2026 · all times UTC← 2026-07-01 · archive · 2026-07-03 →

Security Box Score — July 2, 2026

265 CVEs published, led by Ubiquiti Inc (25).

265 CVEs published July 2, 2026: 32 critical, 149 high, 78 medium, 6 low; 0 in the KEV catalog at press time; 4 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 240 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published63013033——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

568 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux33151312086253011120.17.5.0014+32 ▲
google521317148590542377760.57.8.0024-9 ▼
microsoft7764605261726286202.67.8.0046+6 ▲
red hat9231119211513200.06.5.0030+4 ▲
apple01042287228876.76.5.00320
canonical0202585000.05.5.00110
freebsd01601240000.07.8.00160
suse2154830000.08.8.0042+2 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ubiquiti2536142110338.38.8.0049+25 ▲
cisco830614100561136.77.5.0057+8 ▲
netgear01700161000.04.3.00240
palo alto networks011127113218.25.9.00220
checkpoint0915303111.17.5.04100
fortinet09432028333.38.3.00760
ivanti09450025555.68.8.5187-1 ▼
f50843104112.58.9.02250
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache2157245963103310.67.2.0053-28 ▼
mozilla2581218280900.07.3.0026-2 ▼
gitlab03105215426.54.4.00290
github171150000.06.0.0039+1 ▲
docker070520000.08.2.0016-1 ▼
drupal0511304120.05.1.00260
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle02701321161842720.78.8.00400
adobe014411537821921.45.8.00210
ibm01243642460600.07.5.0034-5 ▼
progress2111910600.07.5.0036-3 ▼
solarwinds07232010457.17.5.4001-1 ▼
veeam042200100.09.0.00520
zohocorp031110000.08.4.01700
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology02325133000.05.6.00250
d-link0120525300.05.8.0058-2 ▼
siemens090450000.06.9.0021-1 ▼
rockwell automation071510000.08.7.00300
abb060420000.07.2.00180
schneider electric060420000.07.8.00420
moxa050320000.07.0.00290
dahua030111000.06.9.00360
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
spring073231391000.06.5.0024-2 ▼
sourcecodester071003635000.05.5.0027-15 ▼
openclaw0670352210000.07.0.00210
edimax065039026100.07.4.00800
capgo061231271000.07.1.00390
themerex26055410000.08.1.0043+2 ▲
dell157231240211.87.4.0017-1 ▼
nvidia1756113870000.07.8.0038+15 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9991100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-20230.882099.88.6
CVE-2026-34910.874799.710.0
CVE-2026-34908.851999.710.0
CVE-2026-50751.837799.79.3
CVE-2026-48907.781099.510.0
CVE-2026-45659.760899.58.8
CVE-2026-34909.639099.210.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9991KEV
CVE-2026-3491010.0.8747KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.7810KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-1377310.0.0610
CVE-2026-5641510.0.0436
CVE-2026-5641310.0.0419
CVE-2026-5357610.0.0330
CVE-2026-5375310.0.0290
Most disclosures (vendor)
VendorCVEs
google1081
linux545
oracle242
microsoft227
adobe142
red hat132
apache93
ibm70
spring70
capgo61
Most KEV additions (YTD)
VendorKEV
microsoft20
cisco11
apple7
google6
ivanti5
solarwinds4
berriai3
fortinet3
smartertools3
ubiquiti3
Most-affected ecosystems
EcosystemAdvisories
Maven40
Packagist15
PyPI8
npm6
Fastest to KEV
CVEVendorDays
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-28318SolarWinds0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171688
CVE-2021-27102n/a2021-11-171688
CVE-2021-27101n/a2021-11-171688
CVE-2021-27103n/a2021-11-171688
CVE-2021-21017Adobe2021-11-171688
CVE-2021-28550Adobe2021-11-171688
CVE-2021-42013Apache Software Foundation2021-11-171688
CVE-2021-41773Apache Software Foundation2021-11-171688
CVE-2021-30858Apple2021-11-171688
CVE-2021-30860Apple2021-11-171688

Transactions

EXPLOIT PUBLISHED — CVE-2026-38971. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-38972. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-44941 (SUSE libzypp). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-8147 (mlflow/mlflow). Public exploit reference added.

Yesterday's Results

How to read these box scores · glossary

265 CVEs published. 25 box scores, 240 table rows — nothing truncated.

Notifiarr dockwatch — Dockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0804   94.3     —
AFFECTED
  Product    Versions     Fixed
  dockwatch  unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 2   Published (CNA: VulnCheck)
CWE-78, CWE-698 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
databasebackup WP Database Backup – Unlimited Database & Files Backup by Backup for WP — WP Database Backup <= 7.11 - Authenticated (Administrator+) OS Command Injection via 'wp_db_exclude_table' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0265   84.5     —
AFFECTED
  Product                                                                  Versions     Fixed
  WP Database Backup – Unlimited Database & Files Backup by Backup for WP  unspecified  —
TIMELINE
  May 28  Reserved by CNA
  Jul 2   Published (CNA: Wordfence)
CWE-77 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
Ubiquiti Inc UniFi OS Server — A malicious actor with access to the network and low privileges could exploit an Improper Input Validation …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0176   76.2     —
AFFECTED
  Product                      Versions     Fixed
  UniFi OS Server              unspecified  —
  Dream Machines               unspecified  —
  Enterprise Fortress Gateway  unspecified  —
  Dream Wall                   unspecified  —
  Dream Routers                unspecified  —
  Express 7                    unspecified  —
  Cloud Keys                   unspecified  —
  Network Video Recorders      unspecified  —
  Enterprise Video Recorders   unspecified  —
  Cloud Gateways               unspecified  —
  + 2 more
TIMELINE
  Jun 13  Reserved by CNA
  Jul 2   Published (CNA: hackerone)
CWE-77, CWE-20 · CNA: hackerone · CVSS v3.1 · 1 reference · NVD status: Analyzed
Ubiquiti Inc UniFi Connect Application — A malicious actor with access to the network could exploit an Improper Access Control vulnerability found i…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0169   75.3     —
AFFECTED
  Product                    Versions     Fixed
  UniFi Connect Application  unspecified  —
TIMELINE
  Jun 6   Reserved by CNA
  Jul 2   Published (CNA: hackerone)
CWE-284 · CNA: hackerone · CVSS v3.1 · 1 reference · NVD status: Analyzed
Ubiquiti Inc UniFi Access Application — A malicious actor with access to the network and low privileges could exploit an Improper Input Validation …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0163   74.3     —
AFFECTED
  Product                   Versions     Fixed
  UniFi Access Application  unspecified  —
TIMELINE
  Jun 6   Reserved by CNA
  Jul 2   Published (CNA: hackerone)
CWE-20 · CNA: hackerone · CVSS v3.1 · 1 reference · NVD status: Analyzed
Yonyou KSOA 9.0 Unauthenticated File Upload RCE via ImageUpload Servlet
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0152   72.6     —
AFFECTED
  Product  Versions  Fixed
  KSOA     9.0 –     —
TIMELINE
  Jan 11  Reserved by CNA
  Jul 2   Published (CNA: VulnCheck)
CWE-434 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Deferred
Guangzhou Red Sea Cloud Computing Co., Ltd. Red Sea Cloud eHR — Redsea Cloud eHR Unauthenticated File Upload RCE via PtFjk.mob
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0128   67.8     —
AFFECTED
  Product            Versions     Fixed
  Red Sea Cloud eHR  unspecified  —
TIMELINE
  Jul 2   Reserved by CNA
  Jul 2   Published (CNA: VulnCheck)
CWE-434 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
TinyPNG <= 3.6.13 - Authenticated (Author+) Arbitrary File Deletion via 'convert.path' in 'tiny_compress_images' Post Meta
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  H    8.1   .0103   61.2     —
AFFECTED
  Product                                       Versions     Fixed
  TinyPNG – JPEG, PNG & WebP image compression  unspecified  —
TIMELINE
  Apr 28  Reserved by CNA
  Jul 2   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
WatchGuard Firebox Race Condition and Use-After-Free in Mobile VPN with IKEv2 LDAP Authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   N   H   H   H    9.2   .0101   60.5     —
AFFECTED
  Product      Versions  Fixed
  Fireware OS  2025.1 –  12.0
  Fireware OS  12.0 –    —
TIMELINE
  Jun 25  Reserved by CNA
  Jul 2   Published (CNA: WatchGuard)
CWE-416 · CNA: WatchGuard · CVSS v4.0 · 2 references · NVD status: Analyzed
Perfmatters <= 2.6.4 - Unauthenticated Arbitrary File Read via 's' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0094   58.3     —
AFFECTED
  Product      Versions     Fixed
  Perfmatters  unspecified  —
TIMELINE
  Jun 24  Reserved by CNA
  Jul 2   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 3 references · NVD status: Deferred
eclipse-wakaama wakaama — Eclipse Wakaama CoAP Block1 Handler Unbounded Memory Allocation DoS
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0092   57.6     —
AFFECTED
  Product  Versions     Fixed
  wakaama  unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 2   Published (CNA: VulnCheck)
CWE-770 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
Divi Form Builder <= 5.1.8 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via 'acceptFileTypes' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0092   57.6     —
AFFECTED
  Product            Versions     Fixed
  Divi Form Builder  unspecified  —
TIMELINE
  Apr 4   Reserved by CNA
  Jul 2   Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
Shenzhen Landray Software Co., Ltd. Landry Office Automation (OA) — Landray OA Unauthenticated HQL Injection via wechatLoginHelper.do
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0090   56.8     —
AFFECTED
  Product                        Versions     Fixed
  Landry Office Automation (OA)  unspecified  —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 2   Published (CNA: VulnCheck)
CWE-564 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
Creative Themes Blocksy Companion Pro — WordPress Blocksy Companion Pro plugin <= 2.1.46 - Remote Code Execution (RCE) vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0086   55.7     —
AFFECTED
  Product                Versions  Fixed
  Blocksy Companion Pro  n/a –     2.1.47
TIMELINE
  Jun 25  Reserved by CNA
  Jul 2   Published (CNA: Patchstack)
CWE-94 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
EstrellaXD Auto_Bangumi — AutoBangumi < 3.2.8 - Hard-coded Default Credentials via add_default_user()
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0080   54.0     —
AFFECTED
  Product       Versions     Fixed
  Auto_Bangumi  unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 2   Published (CNA: VulnCheck)
CWE-1392 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
openwrt luci-app-travelmate — luci-app-travelmate - Arbitrary Command Execution via UCI Script Parameter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   L   N   H   H   H    7.7   .0080   53.9     —
AFFECTED
  Product              Versions    Fixed
  luci-app-travelmate  2.4.5-r3 –  —
  travelmate           2.4.5-r3 –  —
TIMELINE
  Jul 1   Reserved by CNA
  Jul 2   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 7 references · NVD status: Deferred
pathwaycom pathway — Pathway - Unauthenticated Denial of Service via Exponential Glob Pattern Matching in Document Store
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0079   53.6     —
AFFECTED
  Product  Versions     Fixed
  pathway  unspecified  d09722eef03fd94bba701836eb4c7fbfa3d3b88e
TIMELINE
  Jul 2   Reserved by CNA
  Jul 2   Published (CNA: VulnCheck)
CWE-407 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
Microsoft Azure Open AI — Azure OpenAI Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0078   53.1     —
AFFECTED
  Product        Versions  Fixed
  Azure Open AI  - –       —
TIMELINE
  May 12  Reserved by CNA
  Jul 2   Published (CNA: microsoft)
CWE-918 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Exchange Online Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0078   53.1     —
AFFECTED
  Product                    Versions  Fixed
  Microsoft Exchange Online  - –       —
TIMELINE
  Jun 16  Reserved by CNA
  Jul 2   Published (CNA: microsoft)
CWE-863 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0078   53.1     —
AFFECTED
  Product                               Versions  Fixed
  Microsoft Entra Provisioning Service  - –       —
TIMELINE
  Jun 23  Reserved by CNA
  Jul 2   Published (CNA: microsoft)
CWE-918 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Ubiquiti Inc UniFi OS Server — A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  N  N    8.6   .0077   53.0     —
AFFECTED
  Product                      Versions     Fixed
  UniFi OS Server              unspecified  —
  Dream Machines               unspecified  —
  Enterprise Fortress Gateway  unspecified  —
  Dream Wall                   unspecified  —
  Dream Routers                unspecified  —
  Express 7                    unspecified  —
  Cloud Keys                   unspecified  —
  Network Video Recorders      unspecified  —
  Enterprise Video Recorders   unspecified  —
  Cloud Gateways               unspecified  —
  + 2 more
TIMELINE
  Jun 13  Reserved by CNA
  Jul 2   Published (CNA: hackerone)
CWE-22 · CNA: hackerone · CVSS v3.1 · 1 reference · NVD status: Analyzed
WatchGuard Firebox ikestubd Out of Bounds Write Vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0072   51.3     —
AFFECTED
  Product      Versions  Fixed
  Fireware OS  2025.1 –  —
  Fireware OS  12.1 –    —
TIMELINE
  Jun 25  Reserved by CNA
  Jul 2   Published (CNA: WatchGuard)
CWE-787 · CNA: WatchGuard · CVSS v4.0 · 2 references · NVD status: Modified
WatchGuard Firebox wgagent Out of Bounds Write Vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0072   51.3     —
AFFECTED
  Product      Versions  Fixed
  Fireware OS  2025.1 –  —
  Fireware OS  12.1 –    —
TIMELINE
  Jun 25  Reserved by CNA
  Jul 2   Published (CNA: WatchGuard)
CWE-787 · CNA: WatchGuard · CVSS v4.0 · 2 references · NVD status: Modified
Microsoft 365 Copilot Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  H  N    9.3   .0072   51.0     —
AFFECTED
  Product                Versions  Fixed
  Microsoft 365 Copilot  - –       —
TIMELINE
  Apr 16  Reserved by CNA
  Jul 2   Published (CNA: microsoft)
CWE-601 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Weaviate < 1.38.0 - Privilege Escalation via Unchecked Permissions in RBAC Role Assignment
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0071   50.8     —
AFFECTED
  Product   Versions     Fixed
  weaviate  unspecified  —
TIMELINE
  Jul 2   Reserved by CNA
  Jul 2   Published (CNA: VulnCheck)
CWE-266 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-261459.850.3MicrosoftAzure SynapseCWE-284Microsoft Azure Synapse Elevation of Privilege Vulnerability
CVE-2026-559508.749.8ErlangOTPCWE-367DTLS listener crash via race condition in dtls_packet_demux causes denial of …
CVE-2026-389719.149.6n/an/aCWE-125ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issu…
CVE-2026-126575.349.2latepointLatePoint – Calendar Booking Plugin for Appointments and EventsCWE-639LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbi…
CVE-2026-274369.149.0RustauriusFive Star Business Profile and SchemaCWE-94WordPress Five Star Business Profile and Schema plugin <= 2.3.19 - Arbitrary …
CVE-2026-5600410.048.9openSUSEbuildserviceCWE-78obs-service-tar_scm: command injection via mercurial handler
CVE-2026-58218.148.9elemntorImage Optimizer – Optimize Images and Convert to WebP or AVIFCWE-73Image Optimizer <= 1.7.4 - Authenticated (Author+) Arbitrary File Deletion vi…
CVE-2026-130508.648.4WatchGuardFireware OSCWE-787WatchGuard Firebox networkd Out of Bounds Write Vulnerability
CVE-2026-137689.548.4GardynGardyn Home FirmwareCWE-798Gardyn IoT Hub Use of Hard-coded Credentials
CVE-2026-528309.448.3leshchenko1979fast-mcp-telegramCWE-22fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram ses…
CVE-2026-130538.648.0WatchGuardFireware OSCWE-787WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI Comman…
CVE-2026-95637.547.4Eclipse FoundationEclipse ParssonCWE-400In Eclipse Parsson published Maven Central artifacts before version 1.1.8, th…
CVE-2026-389707.547.4n/an/aCWE-674pdfcpu through v0.11.1 contains an uncontrolled-recursion denial-of-service i…
CVE-2026-521877.547.4n/an/aCWE-120Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo…
CVE-2026-521897.547.4n/an/aCWE-120Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo…
CVE-2026-521917.547.4n/an/aCWE-120Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo…
CVE-2026-47679.846.3TR7 Cyber ​​Defense Inc.WAF-ASPCWE-306Improper Access Control in TR7's WAF-ASP
CVE-2026-130548.646.3WatchGuardFireware OSCWE-22WatchGuard Firebox Arbitrary File Write via Path Traversal in Management Web UI
CVE-2026-124725.346.1themeumKirki – Freeform Page Builder, Website Builder & CustomizerCWE-862Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Arbitrary Email Co…
CVE-2026-133697.546.0SaturdayDriveNinja Forms - File UploadsCWE-22Ninja Forms - File Uploads <= 3.3.29 - Unauthenticated Arbitrary File Read vi…
CVE-2026-124137.546.0The Libreswan ProjectlibreswanCWE-193IKEv2 Denial of Service via malformed fragmentation
CVE-2026-544068.745.4Ubiquiti IncUniFi Network ApplicationCWE-22A malicious actor with access to the network and high privileges could exploi…
CVE-2026-521927.545.2n/an/aCWE-400An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker …
CVE-2026-134595.345.0jetmonstersJetFormBuilder — Dynamic Blocks Form BuilderCWE-862JetFormBuilder <= 3.6.3 - Missing Authorization to Unauthenticated Sensitive …
CVE-2026-544089.844.4Ubiquiti IncUniFi Protect ApplicationCWE-284A malicious actor with access to the network could exploit an Improper Access…
CVE-2026-576219.844.3ArrayticsBookticsCWE-502WordPress Booktics plugin <= 1.0.21 - PHP Object Injection vulnerability
CVE-2026-576779.844.3NovalnetNovalnet Payment Gateway for WooCommerceCWE-502WordPress Novalnet Payment Gateway for WooCommerce plugin <= 12.10.3 - PHP Ob…
CVE-2026-142497.544.2emarket-designRequest a Quote – Quote Forms for Any WordPress SiteCWE-74Request a Quote Form Plugin <= 2.5.5 - Unauthenticated Code Injection via 'pa…
CVE-2026-551178.644.1Ubiquiti IncUniFi Access ApplicationCWE-22A malicious actor with access to the network could exploit a Path Traversal v…
CVE-2026-389689.843.7n/an/aCWE-341ntopng through 6.6 is vulnerable to Predictable Session Identifier which can …
CVE-2026-140296.543.6trainingbusinessprosGroundhogg — CRM, Newsletters, and Marketing AutomationCWE-89Groundhogg <= 4.5.8 - Authenticated (Custom+) SQL Injection via 'select' Para…
CVE-2026-590999.343.4apereocasCWE-323Apereo CAS 7.3.0 < 8.0.0-RC6 - AES-GCM Nonce Reuse Information Disclosure
CVE-2026-81478.143.4mlflowmlflow/mlflowCWE-284Authorization Bypass in mlflow/mlflow
CVE-2026-585787.143.4lobehublobehubCWE-1333LobeChat < 2.2.10-canary.15 - Regular Expression Denial of Service in GitHub …
CVE-2026-118965.343.2joedolsonMy Calendar – Accessible Event ManagerCWE-639My Calendar <= 3.7.14 - Insecure Direct Object Reference to Unauthenticated S…
CVE-2026-590976.942.9taigataiga-backCWE-862Taiga < 6.10.2 - Unauthorized Due-Date Creation via API Viewsets
CVE-2026-449418.842.6SUSElibzyppCWE-23libzypp path traversal via "keyhint" in repomd.xml
CVE-2026-576239.042.1BoldGridW3 Total CacheCWE-1284WordPress W3 Total Cache plugin <= 2.9.4 - Arbitrary Code Execution vulnerabi…
CVE-2026-544009.142.1Ubiquiti IncUniFi Access ApplicationCWE-284A malicious actor with access to the network and high privileges could exploi…
CVE-2026-119467.542.1open62541 project / o6 Automation GmbHopen62541CWE-770GetEndpoints Memory Exhaustion in open62541
CVE-2026-335927.542.1open62541 project / o6 Automation GmbHopen62541CWE-770FindServers Memory Exhaustion in open62541
CVE-2026-584678.241.9cockpit-hqcockpitCWE-22Cockpit CMS 2.14.0 - Path Traversal Local File Inclusion via index.php
CVE-2026-544057.542.0Ubiquiti IncUniFi Network ApplicationCWE-20A malicious actor with access to the network could exploit an Improper Input …
CVE-2026-270608.841.7Repute InfosystemsARMember PremiumCWE-502WordPress ARMember Premium plugin < 7.6 - PHP Object Injection vulnerability
CVE-2026-274148.841.7FuelthemesWerkstattCWE-502WordPress Werkstatt theme <= 4.8.3 - PHP Object Injection vulnerability
CVE-2026-560378.841.7ThemifyThemify PopupCWE-502WordPress Themify Popup plugin <= 1.4.3 - PHP Object Injection vulnerability
CVE-2026-91885.341.6wappointmentAppointment Bookings for Zoom GoogleMeet and more – WappointmentCWE-639Appointment Bookings for Zoom GoogleMeet and more – Wappointment <= 2.7.6 - U…
CVE-2026-591016.940.8EstrellaXDAuto_BangumiCWE-918AutoBangumi < 3.2.8 - SSRF via /api/v1/setup/test-downloader
CVE-2026-551117.540.7Ubiquiti IncUniFi Protect FloodlightCWE-22A malicious actor with access to the network could exploit a Path Traversal v…
CVE-2026-130848.740.5WatchGuardFireware OSCWE-476Null Pointer Dereference in WatchGuard Fireware OS iked Process
CVE-2026-121225.340.2themeumKirki – Freeform Page Builder, Website Builder & CustomizerCWE-862Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Sensitive Informat…
CVE-2026-507479.940.1Ubiquiti IncUniFi Talk ApplicationCWE-89A malicious actor with access to the network and low privileges could exploit…
CVE-2026-544048.840.1Ubiquiti IncUniFi OS ServerCWE-89A malicious actor with access to the network and low privileges could exploit…
CVE-2026-568418.840.1Ubiquiti IncUniFi Protect ApplicationCWE-89A malicious actor with access to the network and low privileges could exploit…
CVE-2026-449359.939.9SUSERancherCWE-1287Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated…
CVE-2026-133574.939.4propertyhiveHouzez Property FeedCWE-89Houzez Property Feed <= 2.5.46 - Authenticated (Administrator+) SQL Injection…
CVE-2026-559528.239.3ErlangOTPCWE-1284TLS 1.3 server denial of service via malformed ClientHello pre-shared key ext…
CVE-2026-274199.939.2ZozothemesZegenCWE-434WordPress Zegen theme <= 1.1.9 - Arbitrary File Upload vulnerability
CVE-2026-115924.338.7icegramEmail Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPressCWE-862Email Subscribers & Newsletters <= 5.9.27 - Missing Authorization to Authenti…
CVE-2026-551159.938.4Ubiquiti IncUniFi Protect ApplicationCWE-918A malicious actor with access to the network and low privileges could exploit…
CVE-2026-551148.838.4Ubiquiti IncUniFi Network ApplicationCWE-284A malicious actor with access to the network and low privileges could exploit…
CVE-2026-557266.938.5GardynGardyn Home FirmwareCWE-497Gardyn IoT Hub Exposure of Sensitive System Information to an Unauthorized Co…
CVE-2025-589028.138.4AncoraThemesLighthouseCWE-98WordPress Lighthouse theme <= 1.2.12 - Local File Inclusion vulnerability
CVE-2026-274128.138.4StylemixThemesPearl - Corporate BusinessCWE-98WordPress Pearl - Corporate Business theme <= 3.4.10 - Local File Inclusion v…
CVE-2026-423828.138.4Elated-ThemesAudreyCWE-98WordPress Audrey theme <= 1.5 - Local File Inclusion vulnerability
CVE-2026-84417.538.1https://wpreviewslider.com/WP Review Slider ProCWE-89WP Review Slider Pro <= 12.7.2 - Unauthenticated SQL Injection via 'notinstri…
CVE-2026-53485.337.5kodezenAcademy LMS – WordPress LMS Plugin for Complete eLearning SolutionCWE-639Academy LMS <= 3.8.1 - Unauthenticated Insecure Direct Object Reference to Pr…
CVE-2026-544078.637.4Ubiquiti IncUniFi Protect ApplicationCWE-284A malicious actor with access to the network could exploit an Improper Access…
CVE-2026-572688.337.3GeoVision Inc.GeoWebPlayerCWE-129GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
CVE-2026-576259.637.2ASEAdmin and Site Enhancements (ASE) ProCWE-79WordPress Admin and Site Enhancements (ASE) Pro plugin <= 8.8.5 - Cross Site …
CVE-2026-497796.536.7AddifyTax Exempt for WooCommerceCWE-35WordPress Tax Exempt for WooCommerce plugin < 1.9.5 - Path Traversal vulnerab…
CVE-2026-544098.136.4Ubiquiti IncUniFi Protect ApplicationCWE-665A malicious actor with access to the network and under certain conditions cou…
CVE-2026-144496.436.2u5CMSu5CMSCWE-79POST-based reflected XSS via the thanks parameter in form components
CVE-2026-544018.835.6Ubiquiti IncUniFi OS ServerCWE-918A malicious actor with access to the network and low privileges could exploit…
CVE-2026-100776.835.7Unknownyootheme—YOOtheme Pro < 5.0.35 - Author+ Stored XSS via UIkit Data Attributes
CVE-2026-92728.735.6Progress SoftwareFlowmon ADSCWE-89Possibility of unintended database operations when querying data related to d…
CVE-2025-713855.135.6netdatanetdataCWE-79Netdata < 2.3.1 - Reflected Cross-Site Scripting via love Parameter in ilove.…
CVE-2025-691337.535.5GoodLayersTourmasterCWE-98WordPress Tourmaster plugin <= 5.4.5 - Local File Inclusion vulnerability
CVE-2026-577487.535.5Shopify Help CenterShopifyCWE-98WordPress Shopify plugin <= 1.0.0 - Local File Inclusion vulnerability
CVE-2026-577497.535.5ThemeBoySportsPress ProCWE-98WordPress SportsPress Pro plugin <= 2.7.29 - Local File Inclusion vulnerability
CVE-2026-502817.135.5craftcmscmsCWE-915Craft CMS: Mass assignment via id in newAttributes during bulk duplicate over…
CVE-2026-91456.535.4crmperksDatabase for Contact Form 7, WPforms, Elementor formsCWE-22Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthentica…
CVE-2025-691347.535.2MerkuloveOpenAI Chatbot for WordPress – HelperCWE-862WordPress OpenAI Chatbot for WordPress – Helper plugin <= 1.1.4 - Arbitrary C…
CVE-2026-590987.134.3lobehublobehubCWE-639LobeChat 2.2.9 - Cross-User Document Disclosure via Unscoped RAG Semantic Search
CVE-2026-551169.834.0Ubiquiti IncDream MachinesCWE-284A malicious actor with access to the network and under certain network config…
CVE-2026-137046.433.6stellarwpGiveWP – Donation Plugin and Fundraising PlatformCWE-79GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting v…
CVE-2026-121344.333.2beardevJoomSport – for Sports: Team & League, Football, Hockey & moreCWE-862JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arb…
CVE-2026-590958.333.0lobehublobehubCWE-918LobeChat < 2.2.10-canary.18 - SSRF via importFromUrl and fetchImageFromUrl
CVE-2026-572738.333.0GeoVision Inc.GeoWebPlayerCWE-120GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe…
CVE-2026-572748.333.0GeoVision Inc.GeoWebPlayerCWE-120GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe…
CVE-2026-572758.333.0GeoVision Inc.GeoWebPlayerCWE-120GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe…
CVE-2026-572768.333.0GeoVision Inc.GeoWebPlayerCWE-120GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe…
CVE-2026-572778.333.0GeoVision Inc.GeoWebPlayerCWE-120GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe…
CVE-2026-572788.333.0GeoVision Inc.GeoWebPlayerCWE-120GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe…
CVE-2026-576799.332.9AhmadgbGeekyBotCWE-89WordPress GeekyBot plugin <= 1.2.5 - SQL Injection vulnerability
CVE-2026-576839.332.9EpsiloncoolWP Fast Total SearchCWE-89WordPress WP Fast Total Search plugin <= 1.80.280 - SQL Injection vulnerability
CVE-2026-572728.332.2GeoVision Inc.GeoWebPlayerCWE-129GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
CVE-2026-576888.231.9GurmehubPOS EntegratörCWE-862WordPress POS Entegratör plugin <= 3.7.103 - Broken Access Control vulnerability
CVE-2026-116004.331.5envothemesEnvo's Templates & Widgets for Elementor and WooCommerceCWE-862Envo's Templates & Widgets for Elementor and WooCommerce <= 1.4.26 - Missing …
CVE-2026-551198.131.3Ubiquiti IncUniFi Talk ApplicationCWE-284A malicious actor with access to the network and low privileges could exploit…
CVE-2026-507215.931.4The Libreswan ProjectlibreswanCWE-347IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentic…
CVE-2026-131258.830.8GeoVision Inc.GeoWebPlayerCWE-306GeoVision GeoWebPlayer 1.1.1.0 Websocket Server function vulnerability
CVE-2026-590927.030.4juicedatajuicefsCWE-489JuiceFS - Authentication Bypass via pprof and metrics Endpoints
CVE-2026-131318.329.8GeoVision Inc.GeoWebPlayerCWE-129GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
CVE-2026-131328.329.8GeoVision Inc.GeoWebPlayerCWE-129GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
CVE-2026-572648.329.8GeoVision Inc.GeoWebPlayerCWE-129GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
CVE-2026-572658.329.8GeoVision Inc.GeoWebPlayerCWE-129GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
CVE-2026-572668.329.8GeoVision Inc.GeoWebPlayerCWE-129GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
CVE-2026-572678.329.8GeoVision Inc.GeoWebPlayerCWE-129GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
CVE-2026-572698.329.8GeoVision Inc.GeoWebPlayerCWE-129GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
CVE-2026-572708.329.8GeoVision Inc.GeoWebPlayerCWE-129GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
CVE-2026-572718.329.8GeoVision Inc.GeoWebPlayerCWE-129GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
CVE-2025-691326.529.8ZozothemesCorpkitCWE-201WordPress Corpkit theme <= 1.0.5 - Sensitive Data Exposure vulnerability
CVE-2026-573476.529.8jetmonstersHotel Booking LiteCWE-201WordPress Hotel Booking Lite plugin <= 6.0.3 - Sensitive Data Exposure vulner…
CVE-2026-551137.529.7Ubiquiti IncUniFi Talk ApplicationCWE-918A malicious actor with access to the network could exploit a Server-Side Requ…
CVE-2026-551188.329.3Ubiquiti IncUniFi Network ApplicationCWE-284A malicious actor with access to the network,low privileges and under certain…
CVE-2026-568427.528.9Ubiquiti IncUniFi Network ApplicationCWE-863A malicious actor with access to the network and under certain conditions cou…
CVE-2025-690948.528.4ThemeMoveUnicampCWE-89WordPress Unicamp theme <= 2.2.2 - SQL Injection vulnerability
CVE-2026-576878.528.4Hiroaki MiyashitaCustom Field TemplateCWE-89WordPress Custom Field Template plugin <= 2.7.8 - SQL Injection vulnerability
CVE-2026-577528.528.4iNETiNET WebkitCWE-89WordPress iNET Webkit plugin 1.2.4 - SQL Injection vulnerability
CVE-2026-577568.528.4友人a丶nicen-localize-imageCWE-89WordPress nicen-localize-image plugin <= 1.4.9 - SQL Injection vulnerability
CVE-2026-577658.528.4LevelfourdevelopmentWP EasyCartCWE-89WordPress WP EasyCart plugin <= 5.9.0 - SQL Injection vulnerability
CVE-2026-100896.428.4figureoneInsert PagesCWE-79Insert Pages <= 3.11.4 - Authenticated (Author+) Stored Cross-Site Scripting …
CVE-2026-551128.828.3Ubiquiti IncDream MachinesCWE-284A malicious actor with access to the network and low privileges and under cer…
CVE-2026-521886.527.9n/an/aCWE-119Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo…
CVE-2026-133716.927.7WatchGuardFireware OSCWE-502WatchGuard Firebox Management Web UI Denial of Service via Unsafe Deserializa…
CVE-2026-502824.927.7craftcmscmsCWE-862Craft CMS: Unauthorized Deletion of Destination Folders During Forced Moves
CVE-2026-132526.427.5themeisleRSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds AggregatorCWE-79RSS Aggregator by Feedzy <= 5.2.1 - Authenticated (Contributor+) Stored Cross…
CVE-2026-591022.127.2forgejoforgejoCWE-79Forgejo < 15.0.3 - Stored XSS via Actions Run Full Name Rendering
CVE-2026-394487.527.2CoderPressNOWPayments for WooCommerceCWE-862WordPress NOWPayments for WooCommerce plugin <= 1.4.0 - Broken Access Control…
CVE-2026-507225.927.2The Libreswan ProjectlibreswanCWE-347IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authenticatio…
CVE-2026-576696.526.5Vsourz DigitalAdvanced Contact form 7 DBCWE-862WordPress Advanced Contact form 7 DB plugin <= 2.0.9 - Broken Access Control …
CVE-2026-577316.526.5UX-themesFlatsomeCWE-862WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability
CVE-2026-590968.226.1daprdaprCWE-346Dapr - OIDC Discovery Issuer and JWKS URI Injection via Unvalidated X-Forward…
CVE-2026-101044.425.9nikhilgadhiyaProduct Video Gallery for WoocommerceCWE-79Product Video Gallery for Woocommerce <= 1.5.1.8 - Authenticated (Shop Manage…
CVE-2026-274336.525.6StylemixThemesMotorsCWE-862WordPress Motors theme <= 5.6.80 - Broken Access Control vulnerability
CVE-2026-576806.525.6ThemeumKirkiCWE-639WordPress Kirki plugin <= 6.0.11 - Insecure Direct Object References (IDOR) v…
CVE-2026-548865.325.4ErlangOTPCWE-400SSH SFTP server denial of service via extended channel data infinite loop
CVE-2026-577535.325.3NathanbarryKit (formerly ConvertKit) for WooCommerceCWE-497WordPress Kit (formerly ConvertKit) for WooCommerce plugin <= 2.1.5 - Sensiti…
CVE-2026-544775.125.0GardynGardyn Home FirmwareCWE-644Gardyn IoT Hub Improper Neutralization of HTTP Headers for Scripting Syntax
CVE-2026-80798.724.6Progress SoftwareFlowmonCWE-863Unintended limited set of actions with elevated privileges may be performed d…
CVE-2026-143368.224.3Eclipse FoundationEclipse CSI - PIACWE-918PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix chec…
CVE-2026-533588.824.0LinuxLinuxCWE-667Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen()
CVE-2026-117812.723.7UnknownAdminify—Adminify < 4.2.10 - Contributor+ Sensitive Information Disclosure via Global …
CVE-2026-573536.521.9LinkWhisperLink Whisper PremiumCWE-862WordPress Link Whisper Premium plugin <= 2.9.0 - Broken Access Control vulner…
CVE-2026-573556.521.9RadiusThemeClassified ListingCWE-862WordPress Classified Listing plugin <= 5.4.2 - Broken Access Control vulnerab…
CVE-2026-585795.121.8infiniflowragflowCWE-79RAGFlow < 0.26.3 - Stored Cross-Site Scripting via Agent Pipeline Node Name
CVE-2025-660765.321.4dylan ngoWoostify Sites LibraryCWE-862WordPress Woostify Sites Library plugin <= 1.6.2 - Broken Access Control vuln…
CVE-2026-577505.321.4Keksdiebez Form Calculator PremiumCWE-862WordPress ez Form Calculator Premium plugin <= 2.14.1.2 - Broken Access Contr…
CVE-2026-577605.321.4SendcloudSendcloud ShippingCWE-862WordPress Sendcloud Shipping plugin <= 1.0.29 - Broken Access Control vulnera…
CVE-2026-591002.321.0lobehublobehubCWE-639LobeChat 2.2.9 - Broken Object Level Authorization via Chat-Group Agent Opera…
CVE-2026-577467.120.9ThemeREXBookedCWE-862WordPress Booked plugin <= 3.0.0 - Broken Access Control vulnerability
CVE-2026-115782.720.1UnknownFluent Forms—Fluent Forms < 6.2.5 - Form Manager+ Cross-Form Submission Entry Deletion via…
CVE-2026-86997.019.8TP-Link Systems Inc.Archer C5 v6.8CWE-79Stored Cross-Site Scripting (XSS) in TP-Link Archer C5 Web Management Interface
CVE-2026-119656.519.3UnknownUser Registration & Membership—User Registration & Membership < 5.2.0 - Unauthenticated Paid Membership Bypass
CVE-2026-137228.619.0WatchGuardFireware OSCWE-347WatchGuard Firebox Firmware Image Validation Bypass in WatchGuard Fireware OS
CVE-2026-533578.019.0LinuxLinuxCWE-416Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()
CVE-2026-551106.118.8Ubiquiti IncUniFi OS ServerCWE-942A malicious actor who lures an authenticated user to a malicious page could e…
CVE-2026-133734.818.7WatchGuardFireware OSCWE-79WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpa…
CVE-2026-133744.818.7WatchGuardFireware OSCWE-79WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Connect…
CVE-2026-133754.818.7WatchGuardFireware OSCWE-79WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotas…
CVE-2026-133764.818.7WatchGuardFireware OSCWE-79WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlo…
CVE-2026-133774.818.7WatchGuardFireware OSCWE-79WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in SIP Pro…
CVE-2026-576894.318.7FuelthemesWerkstattCWE-862WordPress Werkstatt theme <= 4.7.2 - Broken Access Control vulnerability
CVE-2026-577304.318.7UX-themesFlatsomeCWE-862WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability
CVE-2026-82477.718.5WatchGuardFireware OSCWE-787WatchGuard Firebox admd Out of Bounds Write Vulnerability
CVE-2026-573487.218.1CozmoslabsPaid Member SubscriptionsCWE-918WordPress Paid Member Subscriptions plugin <= 3.0.4 - Server Side Request For…
CVE-2026-586535.317.9PraisonAIPraisonAICWE-639PraisonAI - Authorization Bypass via Unvalidated project_id in Issue Create/U…
CVE-2026-534222.317.6ErlangOTPCWE-204SFTP REALPATH path-existence oracle allowing filesystem enumeration outside c…
CVE-2026-573524.817.3VillaThemeALD – Dropshipping and Fulfillment for AliExpress and WooCommerceCWE-1390WordPress ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce p…
CVE-2026-576854.316.6drfuriMartfury - WooCommerce Marketplace WordPress ThemeCWE-862WordPress Martfury - WooCommerce Marketplace WordPress theme theme <= 3.2.8 -…
CVE-2025-691527.116.2ThemeGoodsArtale | Wedding Photography WordPressCWE-79WordPress Artale | Wedding Photography WordPress theme <= 2.2.2 - Cross Site …
CVE-2025-691537.116.2designthemesTrendy TravelCWE-79WordPress Trendy Travel theme <= 6.7 - Reflected Cross Site Scripting (XSS) v…
CVE-2025-691547.116.2designthemesSpaLab | Beauty Salon WordPress ThemeCWE-79WordPress SpaLab | Beauty Salon WordPress Theme theme <= 6.7 - Cross Site Scr…
CVE-2025-691557.116.2DesignthemesFitness Zone WordPress ThemeCWE-79WordPress Fitness Zone WordPress Theme theme <= 5.7 - Cross Site Scripting (X…
CVE-2025-691567.116.3Design themesKids Zone - Children WordPress ThemeCWE-79WordPress Kids Zone - Children WordPress Theme theme <= 5.4 - Cross Site Scri…
CVE-2026-274027.116.3DesignthemesKids Life | Children School WordPressCWE-79WordPress Kids Life | Children School WordPress theme <= 5.2 - Cross Site Scr…
CVE-2026-274047.116.3DesignthemesLMSCWE-79WordPress LMS theme <= 9.7 - Reflected Cross Site Scripting (XSS) vulnerability
CVE-2026-274087.116.3imithemesNativeChurchCWE-79WordPress NativeChurch theme <= 4.8.8.2 - Reflected Cross Site Scripting (XSS…
CVE-2026-274257.116.2ThemesuiteAutomotive ListingsCWE-79WordPress Automotive Listings plugin <= 18.6 - Reflected Cross Site Scripting…
CVE-2026-274267.116.2ThemesuiteAutomotive Car Dealership BusinessCWE-79WordPress Automotive Car Dealership Business theme <= 13.3.3 - Reflected Cros…
CVE-2026-274307.116.3tranmautritamTheFoxCWE-79WordPress TheFox theme <= 3.9.76 - Reflected Cross Site Scripting (XSS) vulne…
CVE-2026-573437.116.3ContempoincReal Estate 7CWE-79WordPress Real Estate 7 theme <= 3.5.9 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-573447.116.3RadiusThemeClassified ListingCWE-79WordPress Classified Listing plugin <= 5.4.2 - Cross Site Scripting (XSS) vul…
CVE-2026-573457.116.3WebraketenInternal Links ManagerCWE-79WordPress Internal Links Manager plugin <= 3.0.3 - Cross Site Scripting (XSS)…
CVE-2026-573497.116.3etruelWPeMatico RSS Feed FetcherCWE-79WordPress WPeMatico RSS Feed Fetcher plugin <= 2.8.17 - Cross Site Scripting …
CVE-2026-573507.116.3Andy FragenWP DebuggingCWE-79WordPress WP Debugging plugin <= 2.12.2 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-573517.116.3Haktan SurenHandL UTM GrabberCWE-79WordPress HandL UTM Grabber plugin <= 2.9.2 - Cross Site Scripting (XSS) vuln…
CVE-2026-573567.116.3Moreconvert TeamMC Woocommerce WishlistCWE-79WordPress MC Woocommerce Wishlist plugin <= 1.9.19 - Cross Site Scripting (XS…
CVE-2026-573577.116.3Search Atlas GroupSearch Atlas SEOCWE-79WordPress Search Atlas SEO plugin <= 2.6.6 - Reflected Cross Site Scripting (…
CVE-2026-573587.116.3SysBasicsCustomize My Account for WooCommerceCWE-79WordPress Customize My Account for WooCommerce plugin <= 4.3.9 - Reflected Cr…
CVE-2026-573597.116.3ReviewXReviewXCWE-79WordPress ReviewX plugin <= 2.3.10 - Cross Site Scripting (XSS) vulnerability
CVE-2026-573607.116.3impleCodeeCommerce Product CatalogCWE-79WordPress eCommerce Product Catalog plugin <= 3.5.4 - Cross Site Scripting (X…
CVE-2026-573617.116.3Ays ProSurvey MakerCWE-79WordPress Survey Maker plugin <= 5.2.2.5 - Cross Site Scripting (XSS) vulnera…
CVE-2026-573627.116.3QuantumCloudChatBotCWE-79WordPress ChatBot plugin <= 8.3.2 - Reflected Cross Site Scripting (XSS) vuln…
CVE-2026-573667.116.3Greg WiniarskiWPAdvertsCWE-79WordPress WPAdverts plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-574267.116.2Chill Media Labs S.R.L.Modula - PROCWE-79WordPress Modula - PRO plugin <= 2.10.8 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-576707.116.3CodepeopleGoogle Maps CPCWE-79WordPress Google Maps CP plugin <= 1.2.5 - Cross Site Scripting (XSS) vulnera…
CVE-2026-576717.116.3PerfmattersperfmattersCWE-79WordPress perfmatters plugin <= 2.6.4 - Cross Site Scripting (XSS) vulnerability
CVE-2026-576727.116.3Melograno Venture StudiowpDataTablesCWE-79WordPress wpDataTables plugin <= 6.5.1.1 - Cross Site Scripting (XSS) vulnera…
CVE-2026-576737.116.3OptimoleOptimoleCWE-79WordPress Optimole plugin <= 4.2.7 - Cross Site Scripting (XSS) vulnerability
CVE-2026-576747.116.3ArrayticsTimeticsCWE-79WordPress Timetics plugin <= 1.0.58 - Cross Site Scripting (XSS) vulnerability
CVE-2026-576757.116.3Jacob N. BreetveltWP Photo Album PlusCWE-79WordPress WP Photo Album Plus plugin <= 9.2.02.004 - Cross Site Scripting (XS…
CVE-2026-576787.116.3ThemePunchSlider RevolutionCWE-79WordPress Slider Revolution plugin 7.0.0-7.0.16 - Cross Site Scripting (XSS) …
CVE-2026-576827.116.2QuantumCloudSimple Link DirectoryCWE-79WordPress Simple Link Directory plugin <= 15.0.5 - Cross Site Scripting (XSS)…
CVE-2026-576867.116.3WPXPOWowAddonsCWE-79WordPress WowAddons plugin <= 1.6.14 - Cross Site Scripting (XSS) vulnerability
CVE-2026-585806.016.1lobehublobehubCWE-639LobeChat 2.2.9 - Broken Object-Level Authorization in Message Sub-Resource Wr…
CVE-2026-548876.315.2ErlangOTPCWE-1394DTLS server cookie bypass during startup window due to empty initial cookie s…
CVE-2026-577625.914.9Andrew FiebertSimple URLsCWE-79WordPress Simple URLs plugin <= 151 - Cross Site Scripting (XSS) vulnerability
CVE-2026-576816.413.6PaoloGeoDirectoryCWE-918WordPress GeoDirectory plugin <= 2.8.161 - Server Side Request Forgery (SSRF)…
CVE-2026-137285.913.7WatchGuardFireware OSCWE-798WatchGuard Firebox Hardcoded Fallback Encryption Key in Access Portal Resourc…
CVE-2026-84824.313.4StormshieldStormshield Network SecurityCWE-532Information leak in NSRPC client history
CVE-2026-47725.413.1TR7 Cyber ​​Defense Inc.WAF-ASPCWE-79Stored XSS in TR7's WAF-ASP
CVE-2026-47704.613.1TR7 Cyber ​​Defense Inc.WAF-ASPCWE-79DOM-Based XSS in TR7's WAF-ASP
CVE-2026-573426.512.9ShortPixelShortPixel Adaptive ImagesCWE-79WordPress ShortPixel Adaptive Images plugin <= 3.11.3 - Cross Site Scripting …
CVE-2026-573546.512.9Crocoblock. Jetimpex Inc.JetReviewsCWE-79WordPress JetReviews plugin <= 3.0.0.1 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-576846.512.9tranmautritamTheFoxCWE-79WordPress TheFox theme <= 3.9.70 - Cross Site Scripting (XSS) vulnerability
CVE-2026-577546.512.9LivemeshLivemesh Addons for WPBakery Page BuilderCWE-79WordPress Livemesh Addons for WPBakery Page Builder plugin <= 3.9.4 - Cross S…
CVE-2026-577556.512.9Misbah WPMosaic Gallery &#8211; Advanced GalleryCWE-79WordPress Mosaic Gallery &#8211; Advanced Gallery plugin <= 1.2.0 - Cross Sit…
CVE-2026-577636.512.9Gordon BöhmeStructured ContentCWE-79WordPress Structured Content plugin <= 1.7.0 - Cross Site Scripting (XSS) vul…
CVE-2026-577646.512.9SurbmaSurbma | Yoast SEO Breadcrumb ShortcodeCWE-79WordPress Surbma | Yoast SEO Breadcrumb Shortcode plugin <= 1.2 - Cross Site …
CVE-2026-577598.89.8MetagaussProfileGridCWE-352WordPress ProfileGrid plugin <= 5.9.9.7 - CSRF to Account Takeover vulnerability
CVE-2026-577668.89.8XplodedThemesWPIDE – File Manager & Code EditorCWE-352WordPress WPIDE – File Manager & Code Editor plugin <= 3.5.6 - Cross Site Req…
CVE-2026-577518.18.6Heateor SupportHeateor Social LoginCWE-352WordPress Heateor Social Login plugin <= 1.1.39 - Cross Site Request Forgery …
CVE-2026-389727.88.6n/an/aCWE-427Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerabili…
CVE-2026-584607.08.5ajith-abreact-native-receive-sharing-intentCWE-22react-native-receive-sharing-intent Path Traversal via _display_name
CVE-2026-544315.17.3OpenIDCliboauth2CWE-358Improper Data Validation in liboauth2
CVE-2026-577476.56.9ThemeREXBookedCWE-352WordPress Booked plugin <= 3.0.0 - Cross Site Request Forgery (CSRF) vulnerab…
CVE-2026-121687.86.8Little OrbitGameFirst Anti-Cheat—CVE-2026-12168
CVE-2026-544305.16.3OpenIDCliboauth2CWE-918Server-Site Request Forgery in liboauth2
CVE-2026-137433.35.6CubeSpaceCW0057 Reaction WheelCWE-347Improper verification of cryptographic signature in CubeSpace CW0057 Reaction…
CVE-2026-577577.15.1ploudapppCloud WP BackupCWE-352WordPress pCloud WP Backup plugin <= 2.0.2 - Cross Site Request Forgery (CSRF…
CVE-2026-121665.54.6Little OrbitGameFirst Anti-Cheat—CVE-2026-12166
CVE-2026-121677.84.2Little OrbitGameFirst Anti-Cheat—CVE-2026-12167
CVE-2026-576904.33.7FuelthemesWerkstattCWE-352WordPress Werkstatt theme <= 4.7.2 - Cross Site Request Forgery (CSRF) vulner…
CVE-2026-130797.33.6WatchGuardMobile VPN with SSL ClientCWE-732WatchGuard Mobile VPN with SSL Windows Client Local Privilege Escalation
CVE-2026-548916.33.2ErlangOTPCWE-924Plaintext APPLICATION_DATA injected during TLS handshake delivered to client …
CVE-2026-577587.12.7BeRocketPermalink Manager for WooCommerceCWE-352WordPress Permalink Manager for WooCommerce plugin <= 1.0.8.2 - CSRF to Store…
CVE-2026-577617.12.7BlueAstralThemesSEOWPCWE-352WordPress SEOWP theme <= 3.12.2 - CSRF to Stored XSS vulnerability
CVE-2026-583816.11.9Red HatRed Hat Enterprise Linux 6CWE-415Gimp: gimp: double-free in read_layer_block()

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-02 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.