AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.2 .0804 94.3 —
AFFECTED Product Versions Fixed dockwatch unspecified —
TIMELINE Jun 30 Reserved by CNA Jul 2 Published (CNA: VulnCheck)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
265 CVEs published, led by Ubiquiti Inc (25).
265 CVEs published July 2, 2026: 32 critical, 149 high, 78 medium, 6 low; 0 in the KEV catalog at press time; 4 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 240 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 630 | 13033 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
568 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 33 | 1513 | 120 | 862 | 530 | 1 | 11 | 2 | 0.1 | 7.5 | .0014 | +32 ▲ |
| 52 | 1317 | 148 | 590 | 542 | 37 | 77 | 6 | 0.5 | 7.8 | .0024 | -9 ▼ | |
| microsoft | 7 | 764 | 60 | 526 | 172 | 6 | 286 | 20 | 2.6 | 7.8 | .0046 | +6 ▲ |
| red hat | 9 | 231 | 11 | 92 | 115 | 13 | 2 | 0 | 0.0 | 6.5 | .0030 | +4 ▲ |
| apple | 0 | 104 | 2 | 28 | 72 | 2 | 88 | 7 | 6.7 | 6.5 | .0032 | 0 |
| canonical | 0 | 20 | 2 | 5 | 8 | 5 | 0 | 0 | 0.0 | 5.5 | .0011 | 0 |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| suse | 2 | 15 | 4 | 8 | 3 | 0 | 0 | 0 | 0.0 | 8.8 | .0042 | +2 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ubiquiti | 25 | 36 | 14 | 21 | 1 | 0 | 3 | 3 | 8.3 | 8.8 | .0049 | +25 ▲ |
| cisco | 8 | 30 | 6 | 14 | 10 | 0 | 56 | 11 | 36.7 | 7.5 | .0057 | +8 ▲ |
| netgear | 0 | 17 | 0 | 0 | 16 | 1 | 0 | 0 | 0.0 | 4.3 | .0024 | 0 |
| palo alto networks | 0 | 11 | 1 | 2 | 7 | 1 | 13 | 2 | 18.2 | 5.9 | .0022 | 0 |
| checkpoint | 0 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | 0 |
| fortinet | 0 | 9 | 4 | 3 | 2 | 0 | 28 | 3 | 33.3 | 8.3 | .0076 | 0 |
| ivanti | 0 | 9 | 4 | 5 | 0 | 0 | 25 | 5 | 55.6 | 8.8 | .5187 | -1 ▼ |
| f5 | 0 | 8 | 4 | 3 | 1 | 0 | 4 | 1 | 12.5 | 8.9 | .0225 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 2 | 157 | 24 | 59 | 63 | 10 | 33 | 1 | 0.6 | 7.2 | .0053 | -28 ▼ |
| mozilla | 2 | 58 | 12 | 18 | 28 | 0 | 9 | 0 | 0.0 | 7.3 | .0026 | -2 ▼ |
| gitlab | 0 | 31 | 0 | 5 | 21 | 5 | 4 | 2 | 6.5 | 4.4 | .0029 | 0 |
| github | 1 | 7 | 1 | 1 | 5 | 0 | 0 | 0 | 0.0 | 6.0 | .0039 | +1 ▲ |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.2 | .0016 | -1 ▼ |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 4 | 1 | 20.0 | 5.1 | .0026 | 0 |
| wordpress | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 270 | 132 | 116 | 18 | 4 | 27 | 2 | 0.7 | 8.8 | .0040 | 0 |
| adobe | 0 | 144 | 11 | 53 | 78 | 2 | 19 | 2 | 1.4 | 5.8 | .0021 | 0 |
| ibm | 0 | 124 | 36 | 42 | 46 | 0 | 6 | 0 | 0.0 | 7.5 | .0034 | -5 ▼ |
| progress | 2 | 11 | 1 | 9 | 1 | 0 | 6 | 0 | 0.0 | 7.5 | .0036 | -3 ▼ |
| solarwinds | 0 | 7 | 2 | 3 | 2 | 0 | 10 | 4 | 57.1 | 7.5 | .4001 | -1 ▼ |
| veeam | 0 | 4 | 2 | 2 | 0 | 0 | 1 | 0 | 0.0 | 9.0 | .0052 | 0 |
| zohocorp | 0 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 0 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | 0 |
| d-link | 0 | 12 | 0 | 5 | 2 | 5 | 3 | 0 | 0.0 | 5.8 | .0058 | -2 ▼ |
| siemens | 0 | 9 | 0 | 4 | 5 | 0 | 0 | 0 | 0.0 | 6.9 | .0021 | -1 ▼ |
| rockwell automation | 0 | 7 | 1 | 5 | 1 | 0 | 0 | 0 | 0.0 | 8.7 | .0030 | 0 |
| abb | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | 0 |
| schneider electric | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0042 | 0 |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | 0 |
| dahua | 0 | 3 | 0 | 1 | 1 | 1 | 0 | 0 | 0.0 | 6.9 | .0036 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| spring | 0 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | -2 ▼ |
| sourcecodester | 0 | 71 | 0 | 0 | 36 | 35 | 0 | 0 | 0.0 | 5.5 | .0027 | -15 ▼ |
| openclaw | 0 | 67 | 0 | 35 | 22 | 10 | 0 | 0 | 0.0 | 7.0 | .0021 | 0 |
| edimax | 0 | 65 | 0 | 39 | 0 | 26 | 1 | 0 | 0.0 | 7.4 | .0080 | 0 |
| capgo | 0 | 61 | 2 | 31 | 27 | 1 | 0 | 0 | 0.0 | 7.1 | .0039 | 0 |
| themerex | 2 | 60 | 5 | 54 | 1 | 0 | 0 | 0 | 0.0 | 8.1 | .0043 | +2 ▲ |
| dell | 1 | 57 | 2 | 31 | 24 | 0 | 2 | 1 | 1.8 | 7.4 | .0017 | -1 ▼ |
| nvidia | 17 | 56 | 11 | 38 | 7 | 0 | 0 | 0 | 0.0 | 7.8 | .0038 | +15 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-10520 | .9991 | 100.0 | 10.0 |
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-35273 | .9547 | 99.9 | 9.8 |
| CVE-2026-20230 | .8820 | 99.8 | 8.6 |
| CVE-2026-34910 | .8747 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-50751 | .8377 | 99.7 | 9.3 |
| CVE-2026-48907 | .7810 | 99.5 | 10.0 |
| CVE-2026-45659 | .7608 | 99.5 | 8.8 |
| CVE-2026-34909 | .6390 | 99.2 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-10520 | 10.0 | .9991 | KEV |
| CVE-2026-34910 | 10.0 | .8747 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-48907 | 10.0 | .7810 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-13773 | 10.0 | .0610 | |
| CVE-2026-56415 | 10.0 | .0436 | |
| CVE-2026-56413 | 10.0 | .0419 | |
| CVE-2026-53576 | 10.0 | .0330 | |
| CVE-2026-53753 | 10.0 | .0290 |
| Vendor | CVEs |
|---|---|
| 1081 | |
| linux | 545 |
| oracle | 242 |
| microsoft | 227 |
| adobe | 142 |
| red hat | 132 |
| apache | 93 |
| ibm | 70 |
| spring | 70 |
| capgo | 61 |
| Vendor | KEV |
|---|---|
| microsoft | 20 |
| cisco | 11 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| berriai | 3 |
| fortinet | 3 |
| smartertools | 3 |
| ubiquiti | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 40 |
| Packagist | 15 |
| PyPI | 8 |
| npm | 6 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-10520 | ivanti | 0 |
| CVE-2026-11645 | 0 | |
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-20245 | Cisco | 0 |
| CVE-2026-20253 | Splunk | 0 |
| CVE-2026-20262 | Cisco | 0 |
| CVE-2026-28318 | SolarWinds | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE-2026-34909 | Ubiquiti Inc | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1688 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1688 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1688 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1688 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1688 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1688 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1688 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1688 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1688 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1688 |
EXPLOIT PUBLISHED — CVE-2026-38971. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-38972. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44941 (SUSE libzypp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-8147 (mlflow/mlflow). Public exploit reference added.
How to read these box scores · glossary
265 CVEs published. 25 box scores, 240 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.2 .0804 94.3 —
AFFECTED Product Versions Fixed dockwatch unspecified —
TIMELINE Jun 30 Reserved by CNA Jul 2 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0265 84.5 —
AFFECTED Product Versions Fixed WP Database Backup – Unlimited Database & Files Backup by Backup for WP unspecified —
TIMELINE May 28 Reserved by CNA Jul 2 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0176 76.2 —
AFFECTED Product Versions Fixed UniFi OS Server unspecified — Dream Machines unspecified — Enterprise Fortress Gateway unspecified — Dream Wall unspecified — Dream Routers unspecified — Express 7 unspecified — Cloud Keys unspecified — Network Video Recorders unspecified — Enterprise Video Recorders unspecified — Cloud Gateways unspecified — + 2 more
TIMELINE Jun 13 Reserved by CNA Jul 2 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0169 75.3 —
AFFECTED Product Versions Fixed UniFi Connect Application unspecified —
TIMELINE Jun 6 Reserved by CNA Jul 2 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0163 74.3 —
AFFECTED Product Versions Fixed UniFi Access Application unspecified —
TIMELINE Jun 6 Reserved by CNA Jul 2 Published (CNA: hackerone)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0152 72.6 —
AFFECTED Product Versions Fixed KSOA 9.0 – —
TIMELINE Jan 11 Reserved by CNA Jul 2 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0128 67.8 —
AFFECTED Product Versions Fixed Red Sea Cloud eHR unspecified —
TIMELINE Jul 2 Reserved by CNA Jul 2 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N H H 8.1 .0103 61.2 —
AFFECTED Product Versions Fixed TinyPNG – JPEG, PNG & WebP image compression unspecified —
TIMELINE Apr 28 Reserved by CNA Jul 2 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P N N H H H 9.2 .0101 60.5 —
AFFECTED Product Versions Fixed Fireware OS 2025.1 – 12.0 Fireware OS 12.0 – —
TIMELINE Jun 25 Reserved by CNA Jul 2 Published (CNA: WatchGuard)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0094 58.3 —
AFFECTED Product Versions Fixed Perfmatters unspecified —
TIMELINE Jun 24 Reserved by CNA Jul 2 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0092 57.6 —
AFFECTED Product Versions Fixed wakaama unspecified —
TIMELINE Jun 30 Reserved by CNA Jul 2 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0092 57.6 —
AFFECTED Product Versions Fixed Divi Form Builder unspecified —
TIMELINE Apr 4 Reserved by CNA Jul 2 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0090 56.8 —
AFFECTED Product Versions Fixed Landry Office Automation (OA) unspecified —
TIMELINE Jun 8 Reserved by CNA Jul 2 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0086 55.7 —
AFFECTED Product Versions Fixed Blocksy Companion Pro n/a – 2.1.47
TIMELINE Jun 25 Reserved by CNA Jul 2 Published (CNA: Patchstack)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0080 54.0 —
AFFECTED Product Versions Fixed Auto_Bangumi unspecified —
TIMELINE Jun 30 Reserved by CNA Jul 2 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P L N H H H 7.7 .0080 53.9 —
AFFECTED Product Versions Fixed luci-app-travelmate 2.4.5-r3 – — travelmate 2.4.5-r3 – —
TIMELINE Jul 1 Reserved by CNA Jul 2 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0079 53.6 —
AFFECTED Product Versions Fixed pathway unspecified d09722eef03fd94bba701836eb4c7fbfa3d3b88e
TIMELINE Jul 2 Reserved by CNA Jul 2 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0078 53.1 —
AFFECTED Product Versions Fixed Azure Open AI - – —
TIMELINE May 12 Reserved by CNA Jul 2 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0078 53.1 —
AFFECTED Product Versions Fixed Microsoft Exchange Online - – —
TIMELINE Jun 16 Reserved by CNA Jul 2 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0078 53.1 —
AFFECTED Product Versions Fixed Microsoft Entra Provisioning Service - – —
TIMELINE Jun 23 Reserved by CNA Jul 2 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H N N 8.6 .0077 53.0 —
AFFECTED Product Versions Fixed UniFi OS Server unspecified — Dream Machines unspecified — Enterprise Fortress Gateway unspecified — Dream Wall unspecified — Dream Routers unspecified — Express 7 unspecified — Cloud Keys unspecified — Network Video Recorders unspecified — Enterprise Video Recorders unspecified — Cloud Gateways unspecified — + 2 more
TIMELINE Jun 13 Reserved by CNA Jul 2 Published (CNA: hackerone)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0072 51.3 —
AFFECTED Product Versions Fixed Fireware OS 2025.1 – — Fireware OS 12.1 – —
TIMELINE Jun 25 Reserved by CNA Jul 2 Published (CNA: WatchGuard)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0072 51.3 —
AFFECTED Product Versions Fixed Fireware OS 2025.1 – — Fireware OS 12.1 – —
TIMELINE Jun 25 Reserved by CNA Jul 2 Published (CNA: WatchGuard)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C H H N 9.3 .0072 51.0 —
AFFECTED Product Versions Fixed Microsoft 365 Copilot - – —
TIMELINE Apr 16 Reserved by CNA Jul 2 Published (CNA: microsoft)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0071 50.8 —
AFFECTED Product Versions Fixed weaviate unspecified —
TIMELINE Jul 2 Reserved by CNA Jul 2 Published (CNA: VulnCheck)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-26145 | 9.8 | 50.3 | Microsoft | Azure Synapse | CWE-284 | Microsoft Azure Synapse Elevation of Privilege Vulnerability |
| CVE-2026-55950 | 8.7 | 49.8 | Erlang | OTP | CWE-367 | DTLS listener crash via race condition in dtls_packet_demux causes denial of … |
| CVE-2026-38971 | 9.1 | 49.6 | n/a | n/a | CWE-125 | ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issu… |
| CVE-2026-12657 | 5.3 | 49.2 | latepoint | LatePoint – Calendar Booking Plugin for Appointments and Events | CWE-639 | LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbi… |
| CVE-2026-27436 | 9.1 | 49.0 | Rustaurius | Five Star Business Profile and Schema | CWE-94 | WordPress Five Star Business Profile and Schema plugin <= 2.3.19 - Arbitrary … |
| CVE-2026-56004 | 10.0 | 48.9 | openSUSE | buildservice | CWE-78 | obs-service-tar_scm: command injection via mercurial handler |
| CVE-2026-5821 | 8.1 | 48.9 | elemntor | Image Optimizer – Optimize Images and Convert to WebP or AVIF | CWE-73 | Image Optimizer <= 1.7.4 - Authenticated (Author+) Arbitrary File Deletion vi… |
| CVE-2026-13050 | 8.6 | 48.4 | WatchGuard | Fireware OS | CWE-787 | WatchGuard Firebox networkd Out of Bounds Write Vulnerability |
| CVE-2026-13768 | 9.5 | 48.4 | Gardyn | Gardyn Home Firmware | CWE-798 | Gardyn IoT Hub Use of Hard-coded Credentials |
| CVE-2026-52830 | 9.4 | 48.3 | leshchenko1979 | fast-mcp-telegram | CWE-22 | fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram ses… |
| CVE-2026-13053 | 8.6 | 48.0 | WatchGuard | Fireware OS | CWE-787 | WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI Comman… |
| CVE-2026-9563 | 7.5 | 47.4 | Eclipse Foundation | Eclipse Parsson | CWE-400 | In Eclipse Parsson published Maven Central artifacts before version 1.1.8, th… |
| CVE-2026-38970 | 7.5 | 47.4 | n/a | n/a | CWE-674 | pdfcpu through v0.11.1 contains an uncontrolled-recursion denial-of-service i… |
| CVE-2026-52187 | 7.5 | 47.4 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo… |
| CVE-2026-52189 | 7.5 | 47.4 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo… |
| CVE-2026-52191 | 7.5 | 47.4 | n/a | n/a | CWE-120 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo… |
| CVE-2026-4767 | 9.8 | 46.3 | TR7 Cyber Defense Inc. | WAF-ASP | CWE-306 | Improper Access Control in TR7's WAF-ASP |
| CVE-2026-13054 | 8.6 | 46.3 | WatchGuard | Fireware OS | CWE-22 | WatchGuard Firebox Arbitrary File Write via Path Traversal in Management Web UI |
| CVE-2026-12472 | 5.3 | 46.1 | themeum | Kirki – Freeform Page Builder, Website Builder & Customizer | CWE-862 | Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Arbitrary Email Co… |
| CVE-2026-13369 | 7.5 | 46.0 | SaturdayDrive | Ninja Forms - File Uploads | CWE-22 | Ninja Forms - File Uploads <= 3.3.29 - Unauthenticated Arbitrary File Read vi… |
| CVE-2026-12413 | 7.5 | 46.0 | The Libreswan Project | libreswan | CWE-193 | IKEv2 Denial of Service via malformed fragmentation |
| CVE-2026-54406 | 8.7 | 45.4 | Ubiquiti Inc | UniFi Network Application | CWE-22 | A malicious actor with access to the network and high privileges could exploi… |
| CVE-2026-52192 | 7.5 | 45.2 | n/a | n/a | CWE-400 | An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker … |
| CVE-2026-13459 | 5.3 | 45.0 | jetmonsters | JetFormBuilder — Dynamic Blocks Form Builder | CWE-862 | JetFormBuilder <= 3.6.3 - Missing Authorization to Unauthenticated Sensitive … |
| CVE-2026-54408 | 9.8 | 44.4 | Ubiquiti Inc | UniFi Protect Application | CWE-284 | A malicious actor with access to the network could exploit an Improper Access… |
| CVE-2026-57621 | 9.8 | 44.3 | Arraytics | Booktics | CWE-502 | WordPress Booktics plugin <= 1.0.21 - PHP Object Injection vulnerability |
| CVE-2026-57677 | 9.8 | 44.3 | Novalnet | Novalnet Payment Gateway for WooCommerce | CWE-502 | WordPress Novalnet Payment Gateway for WooCommerce plugin <= 12.10.3 - PHP Ob… |
| CVE-2026-14249 | 7.5 | 44.2 | emarket-design | Request a Quote – Quote Forms for Any WordPress Site | CWE-74 | Request a Quote Form Plugin <= 2.5.5 - Unauthenticated Code Injection via 'pa… |
| CVE-2026-55117 | 8.6 | 44.1 | Ubiquiti Inc | UniFi Access Application | CWE-22 | A malicious actor with access to the network could exploit a Path Traversal v… |
| CVE-2026-38968 | 9.8 | 43.7 | n/a | n/a | CWE-341 | ntopng through 6.6 is vulnerable to Predictable Session Identifier which can … |
| CVE-2026-14029 | 6.5 | 43.6 | trainingbusinesspros | Groundhogg — CRM, Newsletters, and Marketing Automation | CWE-89 | Groundhogg <= 4.5.8 - Authenticated (Custom+) SQL Injection via 'select' Para… |
| CVE-2026-59099 | 9.3 | 43.4 | apereo | cas | CWE-323 | Apereo CAS 7.3.0 < 8.0.0-RC6 - AES-GCM Nonce Reuse Information Disclosure |
| CVE-2026-8147 | 8.1 | 43.4 | mlflow | mlflow/mlflow | CWE-284 | Authorization Bypass in mlflow/mlflow |
| CVE-2026-58578 | 7.1 | 43.4 | lobehub | lobehub | CWE-1333 | LobeChat < 2.2.10-canary.15 - Regular Expression Denial of Service in GitHub … |
| CVE-2026-11896 | 5.3 | 43.2 | joedolson | My Calendar – Accessible Event Manager | CWE-639 | My Calendar <= 3.7.14 - Insecure Direct Object Reference to Unauthenticated S… |
| CVE-2026-59097 | 6.9 | 42.9 | taiga | taiga-back | CWE-862 | Taiga < 6.10.2 - Unauthorized Due-Date Creation via API Viewsets |
| CVE-2026-44941 | 8.8 | 42.6 | SUSE | libzypp | CWE-23 | libzypp path traversal via "keyhint" in repomd.xml |
| CVE-2026-57623 | 9.0 | 42.1 | BoldGrid | W3 Total Cache | CWE-1284 | WordPress W3 Total Cache plugin <= 2.9.4 - Arbitrary Code Execution vulnerabi… |
| CVE-2026-54400 | 9.1 | 42.1 | Ubiquiti Inc | UniFi Access Application | CWE-284 | A malicious actor with access to the network and high privileges could exploi… |
| CVE-2026-11946 | 7.5 | 42.1 | open62541 project / o6 Automation GmbH | open62541 | CWE-770 | GetEndpoints Memory Exhaustion in open62541 |
| CVE-2026-33592 | 7.5 | 42.1 | open62541 project / o6 Automation GmbH | open62541 | CWE-770 | FindServers Memory Exhaustion in open62541 |
| CVE-2026-58467 | 8.2 | 41.9 | cockpit-hq | cockpit | CWE-22 | Cockpit CMS 2.14.0 - Path Traversal Local File Inclusion via index.php |
| CVE-2026-54405 | 7.5 | 42.0 | Ubiquiti Inc | UniFi Network Application | CWE-20 | A malicious actor with access to the network could exploit an Improper Input … |
| CVE-2026-27060 | 8.8 | 41.7 | Repute Infosystems | ARMember Premium | CWE-502 | WordPress ARMember Premium plugin < 7.6 - PHP Object Injection vulnerability |
| CVE-2026-27414 | 8.8 | 41.7 | Fuelthemes | Werkstatt | CWE-502 | WordPress Werkstatt theme <= 4.8.3 - PHP Object Injection vulnerability |
| CVE-2026-56037 | 8.8 | 41.7 | Themify | Themify Popup | CWE-502 | WordPress Themify Popup plugin <= 1.4.3 - PHP Object Injection vulnerability |
| CVE-2026-9188 | 5.3 | 41.6 | wappointment | Appointment Bookings for Zoom GoogleMeet and more – Wappointment | CWE-639 | Appointment Bookings for Zoom GoogleMeet and more – Wappointment <= 2.7.6 - U… |
| CVE-2026-59101 | 6.9 | 40.8 | EstrellaXD | Auto_Bangumi | CWE-918 | AutoBangumi < 3.2.8 - SSRF via /api/v1/setup/test-downloader |
| CVE-2026-55111 | 7.5 | 40.7 | Ubiquiti Inc | UniFi Protect Floodlight | CWE-22 | A malicious actor with access to the network could exploit a Path Traversal v… |
| CVE-2026-13084 | 8.7 | 40.5 | WatchGuard | Fireware OS | CWE-476 | Null Pointer Dereference in WatchGuard Fireware OS iked Process |
| CVE-2026-12122 | 5.3 | 40.2 | themeum | Kirki – Freeform Page Builder, Website Builder & Customizer | CWE-862 | Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Sensitive Informat… |
| CVE-2026-50747 | 9.9 | 40.1 | Ubiquiti Inc | UniFi Talk Application | CWE-89 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-54404 | 8.8 | 40.1 | Ubiquiti Inc | UniFi OS Server | CWE-89 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-56841 | 8.8 | 40.1 | Ubiquiti Inc | UniFi Protect Application | CWE-89 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-44935 | 9.9 | 39.9 | SUSE | Rancher | CWE-1287 | Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated… |
| CVE-2026-13357 | 4.9 | 39.4 | propertyhive | Houzez Property Feed | CWE-89 | Houzez Property Feed <= 2.5.46 - Authenticated (Administrator+) SQL Injection… |
| CVE-2026-55952 | 8.2 | 39.3 | Erlang | OTP | CWE-1284 | TLS 1.3 server denial of service via malformed ClientHello pre-shared key ext… |
| CVE-2026-27419 | 9.9 | 39.2 | Zozothemes | Zegen | CWE-434 | WordPress Zegen theme <= 1.1.9 - Arbitrary File Upload vulnerability |
| CVE-2026-11592 | 4.3 | 38.7 | icegram | Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress | CWE-862 | Email Subscribers & Newsletters <= 5.9.27 - Missing Authorization to Authenti… |
| CVE-2026-55115 | 9.9 | 38.4 | Ubiquiti Inc | UniFi Protect Application | CWE-918 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-55114 | 8.8 | 38.4 | Ubiquiti Inc | UniFi Network Application | CWE-284 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-55726 | 6.9 | 38.5 | Gardyn | Gardyn Home Firmware | CWE-497 | Gardyn IoT Hub Exposure of Sensitive System Information to an Unauthorized Co… |
| CVE-2025-58902 | 8.1 | 38.4 | AncoraThemes | Lighthouse | CWE-98 | WordPress Lighthouse theme <= 1.2.12 - Local File Inclusion vulnerability |
| CVE-2026-27412 | 8.1 | 38.4 | StylemixThemes | Pearl - Corporate Business | CWE-98 | WordPress Pearl - Corporate Business theme <= 3.4.10 - Local File Inclusion v… |
| CVE-2026-42382 | 8.1 | 38.4 | Elated-Themes | Audrey | CWE-98 | WordPress Audrey theme <= 1.5 - Local File Inclusion vulnerability |
| CVE-2026-8441 | 7.5 | 38.1 | https://wpreviewslider.com/ | WP Review Slider Pro | CWE-89 | WP Review Slider Pro <= 12.7.2 - Unauthenticated SQL Injection via 'notinstri… |
| CVE-2026-5348 | 5.3 | 37.5 | kodezen | Academy LMS – WordPress LMS Plugin for Complete eLearning Solution | CWE-639 | Academy LMS <= 3.8.1 - Unauthenticated Insecure Direct Object Reference to Pr… |
| CVE-2026-54407 | 8.6 | 37.4 | Ubiquiti Inc | UniFi Protect Application | CWE-284 | A malicious actor with access to the network could exploit an Improper Access… |
| CVE-2026-57268 | 8.3 | 37.3 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57625 | 9.6 | 37.2 | ASE | Admin and Site Enhancements (ASE) Pro | CWE-79 | WordPress Admin and Site Enhancements (ASE) Pro plugin <= 8.8.5 - Cross Site … |
| CVE-2026-49779 | 6.5 | 36.7 | Addify | Tax Exempt for WooCommerce | CWE-35 | WordPress Tax Exempt for WooCommerce plugin < 1.9.5 - Path Traversal vulnerab… |
| CVE-2026-54409 | 8.1 | 36.4 | Ubiquiti Inc | UniFi Protect Application | CWE-665 | A malicious actor with access to the network and under certain conditions cou… |
| CVE-2026-14449 | 6.4 | 36.2 | u5CMS | u5CMS | CWE-79 | POST-based reflected XSS via the thanks parameter in form components |
| CVE-2026-54401 | 8.8 | 35.6 | Ubiquiti Inc | UniFi OS Server | CWE-918 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-10077 | 6.8 | 35.7 | Unknown | yootheme | — | YOOtheme Pro < 5.0.35 - Author+ Stored XSS via UIkit Data Attributes |
| CVE-2026-9272 | 8.7 | 35.6 | Progress Software | Flowmon ADS | CWE-89 | Possibility of unintended database operations when querying data related to d… |
| CVE-2025-71385 | 5.1 | 35.6 | netdata | netdata | CWE-79 | Netdata < 2.3.1 - Reflected Cross-Site Scripting via love Parameter in ilove.… |
| CVE-2025-69133 | 7.5 | 35.5 | GoodLayers | Tourmaster | CWE-98 | WordPress Tourmaster plugin <= 5.4.5 - Local File Inclusion vulnerability |
| CVE-2026-57748 | 7.5 | 35.5 | Shopify Help Center | Shopify | CWE-98 | WordPress Shopify plugin <= 1.0.0 - Local File Inclusion vulnerability |
| CVE-2026-57749 | 7.5 | 35.5 | ThemeBoy | SportsPress Pro | CWE-98 | WordPress SportsPress Pro plugin <= 2.7.29 - Local File Inclusion vulnerability |
| CVE-2026-50281 | 7.1 | 35.5 | craftcms | cms | CWE-915 | Craft CMS: Mass assignment via id in newAttributes during bulk duplicate over… |
| CVE-2026-9145 | 6.5 | 35.4 | crmperks | Database for Contact Form 7, WPforms, Elementor forms | CWE-22 | Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthentica… |
| CVE-2025-69134 | 7.5 | 35.2 | Merkulove | OpenAI Chatbot for WordPress – Helper | CWE-862 | WordPress OpenAI Chatbot for WordPress – Helper plugin <= 1.1.4 - Arbitrary C… |
| CVE-2026-59098 | 7.1 | 34.3 | lobehub | lobehub | CWE-639 | LobeChat 2.2.9 - Cross-User Document Disclosure via Unscoped RAG Semantic Search |
| CVE-2026-55116 | 9.8 | 34.0 | Ubiquiti Inc | Dream Machines | CWE-284 | A malicious actor with access to the network and under certain network config… |
| CVE-2026-13704 | 6.4 | 33.6 | stellarwp | GiveWP – Donation Plugin and Fundraising Platform | CWE-79 | GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting v… |
| CVE-2026-12134 | 4.3 | 33.2 | beardev | JoomSport – for Sports: Team & League, Football, Hockey & more | CWE-862 | JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arb… |
| CVE-2026-59095 | 8.3 | 33.0 | lobehub | lobehub | CWE-918 | LobeChat < 2.2.10-canary.18 - SSRF via importFromUrl and fetchImageFromUrl |
| CVE-2026-57273 | 8.3 | 33.0 | GeoVision Inc. | GeoWebPlayer | CWE-120 | GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe… |
| CVE-2026-57274 | 8.3 | 33.0 | GeoVision Inc. | GeoWebPlayer | CWE-120 | GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe… |
| CVE-2026-57275 | 8.3 | 33.0 | GeoVision Inc. | GeoWebPlayer | CWE-120 | GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe… |
| CVE-2026-57276 | 8.3 | 33.0 | GeoVision Inc. | GeoWebPlayer | CWE-120 | GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe… |
| CVE-2026-57277 | 8.3 | 33.0 | GeoVision Inc. | GeoWebPlayer | CWE-120 | GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe… |
| CVE-2026-57278 | 8.3 | 33.0 | GeoVision Inc. | GeoWebPlayer | CWE-120 | GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffe… |
| CVE-2026-57679 | 9.3 | 32.9 | Ahmadgb | GeekyBot | CWE-89 | WordPress GeekyBot plugin <= 1.2.5 - SQL Injection vulnerability |
| CVE-2026-57683 | 9.3 | 32.9 | Epsiloncool | WP Fast Total Search | CWE-89 | WordPress WP Fast Total Search plugin <= 1.80.280 - SQL Injection vulnerability |
| CVE-2026-57272 | 8.3 | 32.2 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57688 | 8.2 | 31.9 | Gurmehub | POS Entegratör | CWE-862 | WordPress POS Entegratör plugin <= 3.7.103 - Broken Access Control vulnerability |
| CVE-2026-11600 | 4.3 | 31.5 | envothemes | Envo's Templates & Widgets for Elementor and WooCommerce | CWE-862 | Envo's Templates & Widgets for Elementor and WooCommerce <= 1.4.26 - Missing … |
| CVE-2026-55119 | 8.1 | 31.3 | Ubiquiti Inc | UniFi Talk Application | CWE-284 | A malicious actor with access to the network and low privileges could exploit… |
| CVE-2026-50721 | 5.9 | 31.4 | The Libreswan Project | libreswan | CWE-347 | IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentic… |
| CVE-2026-13125 | 8.8 | 30.8 | GeoVision Inc. | GeoWebPlayer | CWE-306 | GeoVision GeoWebPlayer 1.1.1.0 Websocket Server function vulnerability |
| CVE-2026-59092 | 7.0 | 30.4 | juicedata | juicefs | CWE-489 | JuiceFS - Authentication Bypass via pprof and metrics Endpoints |
| CVE-2026-13131 | 8.3 | 29.8 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-13132 | 8.3 | 29.8 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57264 | 8.3 | 29.8 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57265 | 8.3 | 29.8 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57266 | 8.3 | 29.8 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57267 | 8.3 | 29.8 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57269 | 8.3 | 29.8 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57270 | 8.3 | 29.8 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2026-57271 | 8.3 | 29.8 | GeoVision Inc. | GeoWebPlayer | CWE-129 | GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability |
| CVE-2025-69132 | 6.5 | 29.8 | Zozothemes | Corpkit | CWE-201 | WordPress Corpkit theme <= 1.0.5 - Sensitive Data Exposure vulnerability |
| CVE-2026-57347 | 6.5 | 29.8 | jetmonsters | Hotel Booking Lite | CWE-201 | WordPress Hotel Booking Lite plugin <= 6.0.3 - Sensitive Data Exposure vulner… |
| CVE-2026-55113 | 7.5 | 29.7 | Ubiquiti Inc | UniFi Talk Application | CWE-918 | A malicious actor with access to the network could exploit a Server-Side Requ… |
| CVE-2026-55118 | 8.3 | 29.3 | Ubiquiti Inc | UniFi Network Application | CWE-284 | A malicious actor with access to the network,low privileges and under certain… |
| CVE-2026-56842 | 7.5 | 28.9 | Ubiquiti Inc | UniFi Network Application | CWE-863 | A malicious actor with access to the network and under certain conditions cou… |
| CVE-2025-69094 | 8.5 | 28.4 | ThemeMove | Unicamp | CWE-89 | WordPress Unicamp theme <= 2.2.2 - SQL Injection vulnerability |
| CVE-2026-57687 | 8.5 | 28.4 | Hiroaki Miyashita | Custom Field Template | CWE-89 | WordPress Custom Field Template plugin <= 2.7.8 - SQL Injection vulnerability |
| CVE-2026-57752 | 8.5 | 28.4 | iNET | iNET Webkit | CWE-89 | WordPress iNET Webkit plugin 1.2.4 - SQL Injection vulnerability |
| CVE-2026-57756 | 8.5 | 28.4 | 友人a丶 | nicen-localize-image | CWE-89 | WordPress nicen-localize-image plugin <= 1.4.9 - SQL Injection vulnerability |
| CVE-2026-57765 | 8.5 | 28.4 | Levelfourdevelopment | WP EasyCart | CWE-89 | WordPress WP EasyCart plugin <= 5.9.0 - SQL Injection vulnerability |
| CVE-2026-10089 | 6.4 | 28.4 | figureone | Insert Pages | CWE-79 | Insert Pages <= 3.11.4 - Authenticated (Author+) Stored Cross-Site Scripting … |
| CVE-2026-55112 | 8.8 | 28.3 | Ubiquiti Inc | Dream Machines | CWE-284 | A malicious actor with access to the network and low privileges and under cer… |
| CVE-2026-52188 | 6.5 | 27.9 | n/a | n/a | CWE-119 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allo… |
| CVE-2026-13371 | 6.9 | 27.7 | WatchGuard | Fireware OS | CWE-502 | WatchGuard Firebox Management Web UI Denial of Service via Unsafe Deserializa… |
| CVE-2026-50282 | 4.9 | 27.7 | craftcms | cms | CWE-862 | Craft CMS: Unauthorized Deletion of Destination Folders During Forced Moves |
| CVE-2026-13252 | 6.4 | 27.5 | themeisle | RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator | CWE-79 | RSS Aggregator by Feedzy <= 5.2.1 - Authenticated (Contributor+) Stored Cross… |
| CVE-2026-59102 | 2.1 | 27.2 | forgejo | forgejo | CWE-79 | Forgejo < 15.0.3 - Stored XSS via Actions Run Full Name Rendering |
| CVE-2026-39448 | 7.5 | 27.2 | CoderPress | NOWPayments for WooCommerce | CWE-862 | WordPress NOWPayments for WooCommerce plugin <= 1.4.0 - Broken Access Control… |
| CVE-2026-50722 | 5.9 | 27.2 | The Libreswan Project | libreswan | CWE-347 | IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authenticatio… |
| CVE-2026-57669 | 6.5 | 26.5 | Vsourz Digital | Advanced Contact form 7 DB | CWE-862 | WordPress Advanced Contact form 7 DB plugin <= 2.0.9 - Broken Access Control … |
| CVE-2026-57731 | 6.5 | 26.5 | UX-themes | Flatsome | CWE-862 | WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability |
| CVE-2026-59096 | 8.2 | 26.1 | dapr | dapr | CWE-346 | Dapr - OIDC Discovery Issuer and JWKS URI Injection via Unvalidated X-Forward… |
| CVE-2026-10104 | 4.4 | 25.9 | nikhilgadhiya | Product Video Gallery for Woocommerce | CWE-79 | Product Video Gallery for Woocommerce <= 1.5.1.8 - Authenticated (Shop Manage… |
| CVE-2026-27433 | 6.5 | 25.6 | StylemixThemes | Motors | CWE-862 | WordPress Motors theme <= 5.6.80 - Broken Access Control vulnerability |
| CVE-2026-57680 | 6.5 | 25.6 | Themeum | Kirki | CWE-639 | WordPress Kirki plugin <= 6.0.11 - Insecure Direct Object References (IDOR) v… |
| CVE-2026-54886 | 5.3 | 25.4 | Erlang | OTP | CWE-400 | SSH SFTP server denial of service via extended channel data infinite loop |
| CVE-2026-57753 | 5.3 | 25.3 | Nathanbarry | Kit (formerly ConvertKit) for WooCommerce | CWE-497 | WordPress Kit (formerly ConvertKit) for WooCommerce plugin <= 2.1.5 - Sensiti… |
| CVE-2026-54477 | 5.1 | 25.0 | Gardyn | Gardyn Home Firmware | CWE-644 | Gardyn IoT Hub Improper Neutralization of HTTP Headers for Scripting Syntax |
| CVE-2026-8079 | 8.7 | 24.6 | Progress Software | Flowmon | CWE-863 | Unintended limited set of actions with elevated privileges may be performed d… |
| CVE-2026-14336 | 8.2 | 24.3 | Eclipse Foundation | Eclipse CSI - PIA | CWE-918 | PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix chec… |
| CVE-2026-53358 | 8.8 | 24.0 | Linux | Linux | CWE-667 | Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() |
| CVE-2026-11781 | 2.7 | 23.7 | Unknown | Adminify | — | Adminify < 4.2.10 - Contributor+ Sensitive Information Disclosure via Global … |
| CVE-2026-57353 | 6.5 | 21.9 | LinkWhisper | Link Whisper Premium | CWE-862 | WordPress Link Whisper Premium plugin <= 2.9.0 - Broken Access Control vulner… |
| CVE-2026-57355 | 6.5 | 21.9 | RadiusTheme | Classified Listing | CWE-862 | WordPress Classified Listing plugin <= 5.4.2 - Broken Access Control vulnerab… |
| CVE-2026-58579 | 5.1 | 21.8 | infiniflow | ragflow | CWE-79 | RAGFlow < 0.26.3 - Stored Cross-Site Scripting via Agent Pipeline Node Name |
| CVE-2025-66076 | 5.3 | 21.4 | dylan ngo | Woostify Sites Library | CWE-862 | WordPress Woostify Sites Library plugin <= 1.6.2 - Broken Access Control vuln… |
| CVE-2026-57750 | 5.3 | 21.4 | Keksdieb | ez Form Calculator Premium | CWE-862 | WordPress ez Form Calculator Premium plugin <= 2.14.1.2 - Broken Access Contr… |
| CVE-2026-57760 | 5.3 | 21.4 | Sendcloud | Sendcloud Shipping | CWE-862 | WordPress Sendcloud Shipping plugin <= 1.0.29 - Broken Access Control vulnera… |
| CVE-2026-59100 | 2.3 | 21.0 | lobehub | lobehub | CWE-639 | LobeChat 2.2.9 - Broken Object Level Authorization via Chat-Group Agent Opera… |
| CVE-2026-57746 | 7.1 | 20.9 | ThemeREX | Booked | CWE-862 | WordPress Booked plugin <= 3.0.0 - Broken Access Control vulnerability |
| CVE-2026-11578 | 2.7 | 20.1 | Unknown | Fluent Forms | — | Fluent Forms < 6.2.5 - Form Manager+ Cross-Form Submission Entry Deletion via… |
| CVE-2026-8699 | 7.0 | 19.8 | TP-Link Systems Inc. | Archer C5 v6.8 | CWE-79 | Stored Cross-Site Scripting (XSS) in TP-Link Archer C5 Web Management Interface |
| CVE-2026-11965 | 6.5 | 19.3 | Unknown | User Registration & Membership | — | User Registration & Membership < 5.2.0 - Unauthenticated Paid Membership Bypass |
| CVE-2026-13722 | 8.6 | 19.0 | WatchGuard | Fireware OS | CWE-347 | WatchGuard Firebox Firmware Image Validation Bypass in WatchGuard Fireware OS |
| CVE-2026-53357 | 8.0 | 19.0 | Linux | Linux | CWE-416 | Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() |
| CVE-2026-55110 | 6.1 | 18.8 | Ubiquiti Inc | UniFi OS Server | CWE-942 | A malicious actor who lures an authenticated user to a malicious page could e… |
| CVE-2026-13373 | 4.8 | 18.7 | WatchGuard | Fireware OS | CWE-79 | WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpa… |
| CVE-2026-13374 | 4.8 | 18.7 | WatchGuard | Fireware OS | CWE-79 | WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Connect… |
| CVE-2026-13375 | 4.8 | 18.7 | WatchGuard | Fireware OS | CWE-79 | WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotas… |
| CVE-2026-13376 | 4.8 | 18.7 | WatchGuard | Fireware OS | CWE-79 | WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlo… |
| CVE-2026-13377 | 4.8 | 18.7 | WatchGuard | Fireware OS | CWE-79 | WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in SIP Pro… |
| CVE-2026-57689 | 4.3 | 18.7 | Fuelthemes | Werkstatt | CWE-862 | WordPress Werkstatt theme <= 4.7.2 - Broken Access Control vulnerability |
| CVE-2026-57730 | 4.3 | 18.7 | UX-themes | Flatsome | CWE-862 | WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability |
| CVE-2026-8247 | 7.7 | 18.5 | WatchGuard | Fireware OS | CWE-787 | WatchGuard Firebox admd Out of Bounds Write Vulnerability |
| CVE-2026-57348 | 7.2 | 18.1 | Cozmoslabs | Paid Member Subscriptions | CWE-918 | WordPress Paid Member Subscriptions plugin <= 3.0.4 - Server Side Request For… |
| CVE-2026-58653 | 5.3 | 17.9 | PraisonAI | PraisonAI | CWE-639 | PraisonAI - Authorization Bypass via Unvalidated project_id in Issue Create/U… |
| CVE-2026-53422 | 2.3 | 17.6 | Erlang | OTP | CWE-204 | SFTP REALPATH path-existence oracle allowing filesystem enumeration outside c… |
| CVE-2026-57352 | 4.8 | 17.3 | VillaTheme | ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce | CWE-1390 | WordPress ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce p… |
| CVE-2026-57685 | 4.3 | 16.6 | drfuri | Martfury - WooCommerce Marketplace WordPress Theme | CWE-862 | WordPress Martfury - WooCommerce Marketplace WordPress theme theme <= 3.2.8 -… |
| CVE-2025-69152 | 7.1 | 16.2 | ThemeGoods | Artale | Wedding Photography WordPress | CWE-79 | WordPress Artale | Wedding Photography WordPress theme <= 2.2.2 - Cross Site … |
| CVE-2025-69153 | 7.1 | 16.2 | designthemes | Trendy Travel | CWE-79 | WordPress Trendy Travel theme <= 6.7 - Reflected Cross Site Scripting (XSS) v… |
| CVE-2025-69154 | 7.1 | 16.2 | designthemes | SpaLab | Beauty Salon WordPress Theme | CWE-79 | WordPress SpaLab | Beauty Salon WordPress Theme theme <= 6.7 - Cross Site Scr… |
| CVE-2025-69155 | 7.1 | 16.2 | Designthemes | Fitness Zone WordPress Theme | CWE-79 | WordPress Fitness Zone WordPress Theme theme <= 5.7 - Cross Site Scripting (X… |
| CVE-2025-69156 | 7.1 | 16.3 | Design themes | Kids Zone - Children WordPress Theme | CWE-79 | WordPress Kids Zone - Children WordPress Theme theme <= 5.4 - Cross Site Scri… |
| CVE-2026-27402 | 7.1 | 16.3 | Designthemes | Kids Life | Children School WordPress | CWE-79 | WordPress Kids Life | Children School WordPress theme <= 5.2 - Cross Site Scr… |
| CVE-2026-27404 | 7.1 | 16.3 | Designthemes | LMS | CWE-79 | WordPress LMS theme <= 9.7 - Reflected Cross Site Scripting (XSS) vulnerability |
| CVE-2026-27408 | 7.1 | 16.3 | imithemes | NativeChurch | CWE-79 | WordPress NativeChurch theme <= 4.8.8.2 - Reflected Cross Site Scripting (XSS… |
| CVE-2026-27425 | 7.1 | 16.2 | Themesuite | Automotive Listings | CWE-79 | WordPress Automotive Listings plugin <= 18.6 - Reflected Cross Site Scripting… |
| CVE-2026-27426 | 7.1 | 16.2 | Themesuite | Automotive Car Dealership Business | CWE-79 | WordPress Automotive Car Dealership Business theme <= 13.3.3 - Reflected Cros… |
| CVE-2026-27430 | 7.1 | 16.3 | tranmautritam | TheFox | CWE-79 | WordPress TheFox theme <= 3.9.76 - Reflected Cross Site Scripting (XSS) vulne… |
| CVE-2026-57343 | 7.1 | 16.3 | Contempoinc | Real Estate 7 | CWE-79 | WordPress Real Estate 7 theme <= 3.5.9 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-57344 | 7.1 | 16.3 | RadiusTheme | Classified Listing | CWE-79 | WordPress Classified Listing plugin <= 5.4.2 - Cross Site Scripting (XSS) vul… |
| CVE-2026-57345 | 7.1 | 16.3 | Webraketen | Internal Links Manager | CWE-79 | WordPress Internal Links Manager plugin <= 3.0.3 - Cross Site Scripting (XSS)… |
| CVE-2026-57349 | 7.1 | 16.3 | etruel | WPeMatico RSS Feed Fetcher | CWE-79 | WordPress WPeMatico RSS Feed Fetcher plugin <= 2.8.17 - Cross Site Scripting … |
| CVE-2026-57350 | 7.1 | 16.3 | Andy Fragen | WP Debugging | CWE-79 | WordPress WP Debugging plugin <= 2.12.2 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-57351 | 7.1 | 16.3 | Haktan Suren | HandL UTM Grabber | CWE-79 | WordPress HandL UTM Grabber plugin <= 2.9.2 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-57356 | 7.1 | 16.3 | Moreconvert Team | MC Woocommerce Wishlist | CWE-79 | WordPress MC Woocommerce Wishlist plugin <= 1.9.19 - Cross Site Scripting (XS… |
| CVE-2026-57357 | 7.1 | 16.3 | Search Atlas Group | Search Atlas SEO | CWE-79 | WordPress Search Atlas SEO plugin <= 2.6.6 - Reflected Cross Site Scripting (… |
| CVE-2026-57358 | 7.1 | 16.3 | SysBasics | Customize My Account for WooCommerce | CWE-79 | WordPress Customize My Account for WooCommerce plugin <= 4.3.9 - Reflected Cr… |
| CVE-2026-57359 | 7.1 | 16.3 | ReviewX | ReviewX | CWE-79 | WordPress ReviewX plugin <= 2.3.10 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57360 | 7.1 | 16.3 | impleCode | eCommerce Product Catalog | CWE-79 | WordPress eCommerce Product Catalog plugin <= 3.5.4 - Cross Site Scripting (X… |
| CVE-2026-57361 | 7.1 | 16.3 | Ays Pro | Survey Maker | CWE-79 | WordPress Survey Maker plugin <= 5.2.2.5 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-57362 | 7.1 | 16.3 | QuantumCloud | ChatBot | CWE-79 | WordPress ChatBot plugin <= 8.3.2 - Reflected Cross Site Scripting (XSS) vuln… |
| CVE-2026-57366 | 7.1 | 16.3 | Greg Winiarski | WPAdverts | CWE-79 | WordPress WPAdverts plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57426 | 7.1 | 16.2 | Chill Media Labs S.R.L. | Modula - PRO | CWE-79 | WordPress Modula - PRO plugin <= 2.10.8 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-57670 | 7.1 | 16.3 | Codepeople | Google Maps CP | CWE-79 | WordPress Google Maps CP plugin <= 1.2.5 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-57671 | 7.1 | 16.3 | Perfmatters | perfmatters | CWE-79 | WordPress perfmatters plugin <= 2.6.4 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57672 | 7.1 | 16.3 | Melograno Venture Studio | wpDataTables | CWE-79 | WordPress wpDataTables plugin <= 6.5.1.1 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-57673 | 7.1 | 16.3 | Optimole | Optimole | CWE-79 | WordPress Optimole plugin <= 4.2.7 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57674 | 7.1 | 16.3 | Arraytics | Timetics | CWE-79 | WordPress Timetics plugin <= 1.0.58 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57675 | 7.1 | 16.3 | Jacob N. Breetvelt | WP Photo Album Plus | CWE-79 | WordPress WP Photo Album Plus plugin <= 9.2.02.004 - Cross Site Scripting (XS… |
| CVE-2026-57678 | 7.1 | 16.3 | ThemePunch | Slider Revolution | CWE-79 | WordPress Slider Revolution plugin 7.0.0-7.0.16 - Cross Site Scripting (XSS) … |
| CVE-2026-57682 | 7.1 | 16.2 | QuantumCloud | Simple Link Directory | CWE-79 | WordPress Simple Link Directory plugin <= 15.0.5 - Cross Site Scripting (XSS)… |
| CVE-2026-57686 | 7.1 | 16.3 | WPXPO | WowAddons | CWE-79 | WordPress WowAddons plugin <= 1.6.14 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-58580 | 6.0 | 16.1 | lobehub | lobehub | CWE-639 | LobeChat 2.2.9 - Broken Object-Level Authorization in Message Sub-Resource Wr… |
| CVE-2026-54887 | 6.3 | 15.2 | Erlang | OTP | CWE-1394 | DTLS server cookie bypass during startup window due to empty initial cookie s… |
| CVE-2026-57762 | 5.9 | 14.9 | Andrew Fiebert | Simple URLs | CWE-79 | WordPress Simple URLs plugin <= 151 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57681 | 6.4 | 13.6 | Paolo | GeoDirectory | CWE-918 | WordPress GeoDirectory plugin <= 2.8.161 - Server Side Request Forgery (SSRF)… |
| CVE-2026-13728 | 5.9 | 13.7 | WatchGuard | Fireware OS | CWE-798 | WatchGuard Firebox Hardcoded Fallback Encryption Key in Access Portal Resourc… |
| CVE-2026-8482 | 4.3 | 13.4 | Stormshield | Stormshield Network Security | CWE-532 | Information leak in NSRPC client history |
| CVE-2026-4772 | 5.4 | 13.1 | TR7 Cyber Defense Inc. | WAF-ASP | CWE-79 | Stored XSS in TR7's WAF-ASP |
| CVE-2026-4770 | 4.6 | 13.1 | TR7 Cyber Defense Inc. | WAF-ASP | CWE-79 | DOM-Based XSS in TR7's WAF-ASP |
| CVE-2026-57342 | 6.5 | 12.9 | ShortPixel | ShortPixel Adaptive Images | CWE-79 | WordPress ShortPixel Adaptive Images plugin <= 3.11.3 - Cross Site Scripting … |
| CVE-2026-57354 | 6.5 | 12.9 | Crocoblock. Jetimpex Inc. | JetReviews | CWE-79 | WordPress JetReviews plugin <= 3.0.0.1 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-57684 | 6.5 | 12.9 | tranmautritam | TheFox | CWE-79 | WordPress TheFox theme <= 3.9.70 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-57754 | 6.5 | 12.9 | Livemesh | Livemesh Addons for WPBakery Page Builder | CWE-79 | WordPress Livemesh Addons for WPBakery Page Builder plugin <= 3.9.4 - Cross S… |
| CVE-2026-57755 | 6.5 | 12.9 | Misbah WP | Mosaic Gallery – Advanced Gallery | CWE-79 | WordPress Mosaic Gallery – Advanced Gallery plugin <= 1.2.0 - Cross Sit… |
| CVE-2026-57763 | 6.5 | 12.9 | Gordon Böhme | Structured Content | CWE-79 | WordPress Structured Content plugin <= 1.7.0 - Cross Site Scripting (XSS) vul… |
| CVE-2026-57764 | 6.5 | 12.9 | Surbma | Surbma | Yoast SEO Breadcrumb Shortcode | CWE-79 | WordPress Surbma | Yoast SEO Breadcrumb Shortcode plugin <= 1.2 - Cross Site … |
| CVE-2026-57759 | 8.8 | 9.8 | Metagauss | ProfileGrid | CWE-352 | WordPress ProfileGrid plugin <= 5.9.9.7 - CSRF to Account Takeover vulnerability |
| CVE-2026-57766 | 8.8 | 9.8 | XplodedThemes | WPIDE – File Manager & Code Editor | CWE-352 | WordPress WPIDE – File Manager & Code Editor plugin <= 3.5.6 - Cross Site Req… |
| CVE-2026-57751 | 8.1 | 8.6 | Heateor Support | Heateor Social Login | CWE-352 | WordPress Heateor Social Login plugin <= 1.1.39 - Cross Site Request Forgery … |
| CVE-2026-38972 | 7.8 | 8.6 | n/a | n/a | CWE-427 | Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerabili… |
| CVE-2026-58460 | 7.0 | 8.5 | ajith-ab | react-native-receive-sharing-intent | CWE-22 | react-native-receive-sharing-intent Path Traversal via _display_name |
| CVE-2026-54431 | 5.1 | 7.3 | OpenIDC | liboauth2 | CWE-358 | Improper Data Validation in liboauth2 |
| CVE-2026-57747 | 6.5 | 6.9 | ThemeREX | Booked | CWE-352 | WordPress Booked plugin <= 3.0.0 - Cross Site Request Forgery (CSRF) vulnerab… |
| CVE-2026-12168 | 7.8 | 6.8 | Little Orbit | GameFirst Anti-Cheat | — | CVE-2026-12168 |
| CVE-2026-54430 | 5.1 | 6.3 | OpenIDC | liboauth2 | CWE-918 | Server-Site Request Forgery in liboauth2 |
| CVE-2026-13743 | 3.3 | 5.6 | CubeSpace | CW0057 Reaction Wheel | CWE-347 | Improper verification of cryptographic signature in CubeSpace CW0057 Reaction… |
| CVE-2026-57757 | 7.1 | 5.1 | ploudapp | pCloud WP Backup | CWE-352 | WordPress pCloud WP Backup plugin <= 2.0.2 - Cross Site Request Forgery (CSRF… |
| CVE-2026-12166 | 5.5 | 4.6 | Little Orbit | GameFirst Anti-Cheat | — | CVE-2026-12166 |
| CVE-2026-12167 | 7.8 | 4.2 | Little Orbit | GameFirst Anti-Cheat | — | CVE-2026-12167 |
| CVE-2026-57690 | 4.3 | 3.7 | Fuelthemes | Werkstatt | CWE-352 | WordPress Werkstatt theme <= 4.7.2 - Cross Site Request Forgery (CSRF) vulner… |
| CVE-2026-13079 | 7.3 | 3.6 | WatchGuard | Mobile VPN with SSL Client | CWE-732 | WatchGuard Mobile VPN with SSL Windows Client Local Privilege Escalation |
| CVE-2026-54891 | 6.3 | 3.2 | Erlang | OTP | CWE-924 | Plaintext APPLICATION_DATA injected during TLS handshake delivered to client … |
| CVE-2026-57758 | 7.1 | 2.7 | BeRocket | Permalink Manager for WooCommerce | CWE-352 | WordPress Permalink Manager for WooCommerce plugin <= 1.0.8.2 - CSRF to Store… |
| CVE-2026-57761 | 7.1 | 2.7 | BlueAstralThemes | SEOWP | CWE-352 | WordPress SEOWP theme <= 3.12.2 - CSRF to Stored XSS vulnerability |
| CVE-2026-58381 | 6.1 | 1.9 | Red Hat | Red Hat Enterprise Linux 6 | CWE-415 | Gimp: gimp: double-free in read_layer_block() |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-02 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.