boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Friday, July 3, 2026 · all times UTC← 2026-07-02 · archive · 2026-07-04 →

Security Box Score — July 3, 2026

180 CVEs published, led by Microsoft (43).

180 CVEs published July 3, 2026: 25 critical, 77 high, 70 medium, 8 low; 0 in the KEV catalog at press time; 19 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 155 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published81013213——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

571 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux33151312086253011120.17.5.00140
google521317148590542377760.57.8.0024-9 ▼
microsoft50807615521886286202.57.8.0046+49 ▲
red hat15237129311814200.06.5.0030+10 ▲
apple01042287228876.76.5.00320
canonical0202585000.05.5.00110
freebsd01601240000.07.8.00160
suse2154830000.08.8.0042+2 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ubiquiti2536142110338.38.8.0049+25 ▲
cisco830614100561136.77.5.0057+6 ▲
netgear01700161000.04.3.00240
palo alto networks011127113218.25.9.00220
checkpoint0915303111.17.5.04100
fortinet09432028333.38.3.00760
ivanti09450025555.68.8.5187-1 ▼
f50843104112.58.9.02250
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache5160246164103310.67.3.0053-26 ▼
mozilla2581218280900.07.3.0026-2 ▼
gitlab03105215426.54.4.00290
github171150000.06.0.0039+1 ▲
docker070520000.08.2.0016-1 ▼
drupal0511304120.05.1.00260
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle02701321161842720.78.8.00400
adobe014411537821921.45.8.00210
ibm01243642460600.07.5.0034-5 ▼
progress2111910600.07.5.0036-3 ▼
solarwinds07232010457.17.5.4001-1 ▼
veeam042200100.09.0.00520
zohocorp031110000.08.4.01700
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology02325133000.05.6.0025-5 ▼
d-link0120525300.05.8.0058-2 ▼
siemens090450000.06.9.0021-1 ▼
rockwell automation071510000.08.7.00300
abb060420000.07.2.0018-4 ▼
schneider electric060420000.07.8.00420
moxa050320000.07.0.00290
dahua030111000.06.9.00360
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell2076234382211.36.7.0018+18 ▲
sourcecodester273003637000.02.9.0027-16 ▼
spring073231391000.06.5.0024-2 ▼
openclaw0670352210000.07.0.00210
edimax065039026100.07.4.00800
capgo061231271000.07.1.00390
themerex26055410000.08.1.0043+2 ▲
nvidia1756113870000.07.8.0038+15 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9991100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-20230.882099.88.6
CVE-2026-34910.874799.710.0
CVE-2026-34908.851999.710.0
CVE-2026-50751.837799.79.3
CVE-2026-48907.781099.510.0
CVE-2026-45659.760899.58.8
CVE-2026-34909.639099.210.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9991KEV
CVE-2026-3491010.0.8747KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.7810KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-1377310.0.0610
CVE-2026-5641510.0.0436
CVE-2026-5641310.0.0419
CVE-2026-5357610.0.0330
CVE-2026-5375310.0.0290
Most disclosures (vendor)
VendorCVEs
google1081
linux513
microsoft270
oracle242
adobe142
red hat138
apache95
ibm70
spring70
capgo61
Most KEV additions (YTD)
VendorKEV
microsoft20
cisco11
apple7
google6
ivanti5
solarwinds4
berriai3
fortinet3
smartertools3
ubiquiti3
Most-affected ecosystems
EcosystemAdvisories
Maven39
Packagist15
npm6
NuGet3
PyPI1
Fastest to KEV
CVEVendorDays
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-28318SolarWinds0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171689
CVE-2021-27102n/a2021-11-171689
CVE-2021-27101n/a2021-11-171689
CVE-2021-27103n/a2021-11-171689
CVE-2021-21017Adobe2021-11-171689
CVE-2021-28550Adobe2021-11-171689
CVE-2021-42013Apache Software Foundation2021-11-171689
CVE-2021-41773Apache Software Foundation2021-11-171689
CVE-2021-30858Apple2021-11-171689
CVE-2021-30860Apple2021-11-171689

Transactions

EXPLOIT PUBLISHED — curl: 18 CVEs (CVE-2026-8286, CVE-2026-8458, CVE-2026-8924, CVE-2026-8925, CVE-2026-8926, CVE-2026-8927, CVE-2026-8932, CVE-2026-9079, CVE-2026-9080, CVE-2026-9545, CVE-2026-9546, CVE-2026-9547, CVE-2026-10536, CVE-2026-11352, CVE-2026-11564, CVE-2026-11586, CVE-2026-11856, CVE-2026-12064). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-12481 (keras-team/keras). Public exploit reference added.

DUE DATE PASSED — CVE-2026-48558 (SimpleHelp). CISA remediation deadline was July 2, 2026; still in catalog.

Yesterday's Results

How to read these box scores · glossary

180 CVEs published. 25 box scores, 155 table rows — nothing truncated.

Gitea Docker image trusts spoofable reverse-proxy headers by default
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0276   85.1     —
AFFECTED
  Product                       Versions     Fixed
  Gitea Open Source Git Server  unspecified  —
TIMELINE
  Mar 3   Reserved by CNA
  Jul 3   Published (CNA: Gitea)
CWE-284 · CNA: Gitea · CVSS v3.1 · 4 references · NVD status: Deferred
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0200   79.2     —
AFFECTED
  Product                   Versions     Fixed
  PowerProtect Data Domain  unspecified  —
TIMELINE
  Jun 1   Reserved by CNA
  Jul 3   Published (CNA: dell)
CWE-78 · CNA: dell · CVSS v3.1 · 1 reference · NVD status: Analyzed
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0200   79.2     —
AFFECTED
  Product                   Versions     Fixed
  PowerProtect Data Domain  unspecified  —
TIMELINE
  Jun 9   Reserved by CNA
  Jul 3   Published (CNA: dell)
CWE-78 · CNA: dell · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   R  C  H  H  H    8.3   .0199   79.1     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 3   Published (CNA: microsoft)
CWE-843 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  N  H  H    6.5   .0177   76.4     —
AFFECTED
  Product                   Versions     Fixed
  PowerProtect Data Domain  unspecified  —
TIMELINE
  Feb 13  Reserved by CNA
  Jul 3   Published (CNA: dell)
CWE-78 · CNA: dell · CVSS v3.1 · 1 reference · NVD status: Analyzed
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0171   75.6     —
AFFECTED
  Product                   Versions     Fixed
  PowerProtect Data Domain  unspecified  —
TIMELINE
  Jun 1   Reserved by CNA
  Jul 3   Published (CNA: dell)
CWE-78 · CNA: dell · CVSS v3.1 · 1 reference · NVD status: Analyzed
Gitea Composer package source links use insufficient permission checks
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  L  N    8.2   .0139   70.3     —
AFFECTED
  Product                       Versions     Fixed
  Gitea Open Source Git Server  unspecified  —
TIMELINE
  Mar 3   Reserved by CNA
  Jul 3   Published (CNA: Gitea)
CWE-862 · CNA: Gitea · CVSS v3.0 · 4 references · NVD status: Deferred
Printcart Web to Print Product Designer for WooCommerce <= 2.5.2 - Unauthenticated Arbitrary File Deletion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0117   64.9     —
AFFECTED
  Product                                                  Versions     Fixed
  Printcart Web to Print Product Designer for WooCommerce  unspecified  —
TIMELINE
  May 27  Reserved by CNA
  Jul 3   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
curl curl — SASL double-free
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0108   62.5     —
AFFECTED
  Product  Versions  Fixed
  curl     8.20.0 –  —
TIMELINE
  May 19  Reserved by CNA
  Jul 3   Public exploit reference published
  Jul 3   Published (CNA: curl)
CWE-415 · CNA: curl · CVSS v3.1 · 3 references · NVD status: Analyzed
curl curl — stale proxy password leak
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0106   62.1     —
AFFECTED
  Product  Versions  Fixed
  curl     8.20.0 –  —
TIMELINE
  May 20  Reserved by CNA
  Jul 3   Public exploit reference published
  Jul 3   Published (CNA: curl)
CWE-522 · CNA: curl · CVSS v3.1 · 3 references · NVD status: Analyzed
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  N  N    7.4   .0104   61.3     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 26  Reserved by CNA
  Jul 3   Published (CNA: microsoft)
CWE-59 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
curl curl — QUIC zero-length UDP datagrams busy-loop
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0101   60.5     —
AFFECTED
  Product  Versions  Fixed
  curl     8.20.0 –  —
TIMELINE
  Jun 5   Reserved by CNA
  Jul 3   Public exploit reference published
  Jul 3   Published (CNA: curl)
CWE-835 · CNA: curl · CVSS v3.1 · 3 references · NVD status: Analyzed
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   R  C  H  N  N    6.1   .0099   59.9     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 3   Published (CNA: microsoft)
CWE-672 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Hplip: incomplete fix for cve-2026-8631
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0093   57.8     —
AFFECTED
  Product                      Versions     Fixed
  HPLIP                        unspecified  —
  Red Hat Enterprise Linux 10  unspecified  0:3.23.12-10.el10_2.5
  Red Hat Enterprise Linux 8   unspecified  0:3.18.4-14.el8_10
  Red Hat Enterprise Linux 9   unspecified  0:3.21.2-6.el9_8.5
  Red Hat Enterprise Linux 6   unspecified  —
  Red Hat Enterprise Linux 7   unspecified  —
TIMELINE
  Jul 3   Reserved by CNA
  Jul 3   Published (CNA: redhat)
CWE-190 · CNA: redhat · CVSS v3.1 · 5 references · NVD status: Awaiting Analysis
Microsoft Edge (Chromium-based) Spoofing Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  N  N    6.5   .0092   57.6     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 22  Reserved by CNA
  Jul 3   Published (CNA: microsoft)
CWE-200 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
curl curl — HTTP/2 stream-dependency tree UAF
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0089   56.7     —
AFFECTED
  Product  Versions  Fixed
  curl     8.20.0 –  —
TIMELINE
  Jun 1   Reserved by CNA
  Jul 3   Public exploit reference published
  Jul 3   Published (CNA: curl)
CWE-416 · CNA: curl · CVSS v3.1 · 3 references · NVD status: Analyzed
Microsoft Edge (Chromium-based) Spoofing Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  N  H  N    7.4   .0088   56.3     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 26  Reserved by CNA
  Jul 3   Published (CNA: microsoft)
CWE-918 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Edge (Chromium-based) Spoofing Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  N  H  N    6.5   .0088   56.3     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  May 12  Reserved by CNA
  Jul 3   Published (CNA: microsoft)
CWE-749 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Modified
Microsoft Edge for Android Security Feature Bypass Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  N  H  N    6.5   .0088   56.3     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jul 1   Reserved by CNA
  Jul 3   Published (CNA: microsoft)
CWE-284 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Edge (Chromium-based) Spoofing Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  N  N    6.5   .0087   56.2     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 26  Reserved by CNA
  Jul 3   Published (CNA: microsoft)
CWE-918 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
curl curl — WS Auto-PONG memory exhaustion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0086   55.8     —
AFFECTED
  Product  Versions  Fixed
  curl     8.20.0 –  —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 3   Public exploit reference published
  Jul 3   Published (CNA: curl)
CWE-770 · CNA: curl · CVSS v3.1 · 3 references · NVD status: Analyzed
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0082   54.5     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 22  Reserved by CNA
  Jul 3   Published (CNA: microsoft)
CWE-122 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0082   54.5     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 26  Reserved by CNA
  Jul 3   Published (CNA: microsoft)
CWE-190 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0082   54.5     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 26  Reserved by CNA
  Jul 3   Published (CNA: microsoft)
CWE-416 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Apache Lucene.Net: Unauthenticated arbitrary file read on the Lucene.Net.Replicator replication server
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   N   N    8.9   .0081   54.1     —
AFFECTED
  Product            Versions           Fixed
  Apache Lucene.Net  4.8.0-beta00005 –  —
TIMELINE
  May 20  Reserved by CNA
  Jul 3   Published (CNA: apache)
CWE-22 · CNA: apache · CVSS v4.0 · 2 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-579887.152.5MicrosoftMicrosoft Edge (Chromium-based)CWE-23Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-478978.951.2Apache Software FoundationApache Lucene.NetCWE-22Apache Lucene.Net: Arbitrary file write from malicious server to Lucene.Net.R…
CVE-2026-579858.851.1MicrosoftMicrosoft Edge (Chromium-based)CWE-20Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-124819.851.1keras-teamkeras-team/kerasCWE-502Deserialization of Untrusted Data in keras-team/keras
CVE-2026-49677.550.6Unisoc (Shanghai) Technologies Co., Ltd.SC7731E/SC9832E/SC9863A/T310/T610/T618/T7200/T7225/T7250/T7255/T7280/T7300/T8100/T9100/T8200/T8300—In IMS, there is a possible out of bounds read due to a missing bounds check.…
CVE-2026-585974.350.5MicrosoftMicrosoft Edge (Chromium-based)CWE-357Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-143527.549.4webandprintAR for WooCommerceCWE-22AR for WooCommerce <= 8.40 - Unauthenticated Path Traversal to Arbitrary File…
CVE-2026-262929.848.5GiteaGitea Open Source Git ServerCWE-284Gitea LFS mirror synchronization bypasses migration HTTP transport restrictions
CVE-2026-95467.548.5curlcurl—sending old referer
CVE-2026-5798310.048.3MicrosoftMicrosoft Edge (Chromium-based)CWE-285Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2026-592346.947.9RoskusProspero Flow CRMCWE-639Authorization Bypass Through User-Controlled Key in Prospero Flow CRM calenda…
CVE-2026-277809.847.8GiteaGitea Open Source Git ServerCWE-863Gitea pre-receive hook can miss branch-protection checks after scanner errors
CVE-2026-560159.147.6TPODERNet::IP::LPMCWE-125Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read v…
CVE-2026-263077.547.4GiteaGitea Open Source Git ServerCWE-400Gitea git grep search lacks a timeout
CVE-2026-498136.747.2DellPowerProtect Data DomainCWE-78Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-544836.747.2DellPowerProtect Data DomainCWE-78Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release …
CVE-2026-584229.847.1GiteaGitea Open Source Git ServerCWE-284Improper authorization on OAuth sign-in callback silently re-enables administ…
CVE-2026-464644.947.0DellPowerProtect Data DomainCWE-59Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-143277.546.8webandprintAR for WordPressCWE-22AR for WordPress <= 8.40 - Unauthenticated Arbitrary File Read via 'file' Par…
CVE-2026-115649.146.5curlcurlCWE-295Native CA trust persist
CVE-2026-582858.346.4MicrosoftMicrosoft Edge (Chromium-based)CWE-843Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-582878.346.4MicrosoftMicrosoft Edge (Chromium-based)CWE-416Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-582888.346.4MicrosoftMicrosoft Edge (Chromium-based)CWE-416Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-579757.546.4MicrosoftMicrosoft Edge (Chromium-based)CWE-843Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-579847.546.4MicrosoftMicrosoft Edge (Chromium-based)CWE-416Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-579867.546.4MicrosoftMicrosoft Edge (Chromium-based)CWE-416Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-579927.546.4MicrosoftMicrosoft Edge (Chromium-based)CWE-416Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-582767.546.4MicrosoftMicrosoft Edge (Chromium-based)CWE-416Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-582937.546.4MicrosoftMicrosoft Edge (Chromium-based)CWE-73Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-582947.546.4MicrosoftMicrosoft Edge (Chromium-based)CWE-416Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-118569.846.2curlcurlCWE-294cross-origin Digest auth state leak
CVE-2026-277797.545.2GiteaGitea Open Source Git ServerCWE-284Gitea forwarded-proto handling allows public URL spoofing
CVE-2026-584217.545.2GiteaGitea Open Source Git ServerCWE-284Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
CVE-2026-579777.144.9MicrosoftMicrosoft Edge (Chromium-based)CWE-79Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-207069.144.3GiteaGitea Open Source Git ServerCWE-284Gitea repository archive downloads bypass token scope checks
CVE-2026-257189.144.2GiteaGitea Open Source Git ServerCWE-59Gitea template repository generation mishandles symlinked paths
CVE-2026-582848.344.2MicrosoftMicrosoft Edge (Chromium-based)CWE-285Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-113985.344.1latepointLatePoint – Calendar Booking Plugin for Appointments and EventsCWE-862LatePoint <= 5.6.1 - Missing Authorization to Unauthenticated Arbitrary Custo…
CVE-2026-89249.144.1curlcurl—trailing dot domain super cookie
CVE-2026-91805.343.9jetmonstersMotoPress Appointment BookingCWE-639MotoPress Appointment Booking <= 2.4.4 - Unauthenticated Insecure Direct Obje…
CVE-2026-286998.143.6GiteaGitea Open Source Git ServerCWE-284Gitea Basic Auth bypasses OAuth2 access token scopes
CVE-2026-84586.543.2curlcurl—wrong reuse for different services
CVE-2026-582967.143.1MicrosoftMicrosoft Edge (Chromium-based)CWE-359Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2026-582977.143.1MicrosoftMicrosoft Edge (Chromium-based)CWE-359Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2026-584237.742.8GiteaGitea Open Source Git ServerCWE-287LFS authentication bypass via malformed SSH sub-verb allows unauthorized read…
CVE-2026-130407.242.3webawaysNEX-Forms – Ultimate Forms Plugin for WordPressCWE-79NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via 'real_va…
CVE-2026-277758.842.0GiteaGitea Open Source Git ServerCWE-863Gitea pre-receive hook permission cache allows full repository write access
CVE-2026-225479.141.9GiteaGitea Open Source Git ServerCWE-20Gitea repository creation accepts invalid field values
CVE-2026-146204.741.9webpack-dev-serverwebpack-dev-serverCWE-352webpack-dev-server vulnerable to cross-site request forgery via internal deve…
CVE-2026-146315.341.6webpack-dev-serverwebpack-dev-serverCWE-20webpack-dev-server vulnerable to denial of service via a malformed Host or Or…
CVE-2026-584197.541.1GiteaGitea Open Source Git ServerCWE-200Notification API leaks private issue metadata after access revocation
CVE-2026-91487.241.0advancedcodingComments – wpDiscuzCWE-79Comments <= 7.6.56 - Unauthenticated Stored Cross-Site Scripting via 'Website…
CVE-2026-582958.340.9MicrosoftMicrosoft Edge (Chromium-based)CWE-843Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2026-262329.140.2GiteaGitea Open Source Git ServerCWE-294Gitea OAuth2 authorization codes lack expiry and reuse enforcement
CVE-2026-262479.140.2GiteaGitea Open Source Git ServerCWE-284Gitea OAuth2 PKCE S256 challenges are not enforced during token exchange
CVE-2026-90807.340.2curlcurlCWE-416UAF after pause in socket callback
CVE-2026-92304.340.0expresstechQuiz and Survey Master (QSM) – Easy Quiz and Survey MakerCWE-862Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticat…
CVE-2026-582927.539.4MicrosoftMicrosoft Edge (Chromium-based)CWE-20Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-129204.939.4wplegalpagesCookie Banner for GDPR / CCPA – WPLP Cookie ConsentCWE-89Cookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Administrator+) SQL I…
CVE-2026-244517.539.3GiteaGitea Open Source Git ServerCWE-200Gitea fork synchronization can expose private parent repository data
CVE-2026-250387.539.3GiteaGitea Open Source Git ServerCWE-200Gitea private organization labels are visible to unauthorized users
CVE-2026-257127.539.3GiteaGitea Open Source Git ServerCWE-284Gitea organization permission APIs expose private visibility information
CVE-2026-207797.139.3GiteaGitea Open Source Git ServerCWE-294Gitea TOTP single-use enforcement defect allows OTP replay
CVE-2026-43219.838.4Raera - Ankara Web Design and Digital Advertising AgencyDestekzCWE-89SQLi in Raera's Destekz
CVE-2026-478984.038.4Apache Software FoundationApache Lucene.NetCWE-611Apache Lucene.Net: XXE vulnerability in Lucene.Net.Analysis.Common PatternParser
CVE-2026-582997.538.3MicrosoftMicrosoft Edge (Chromium-based)CWE-367Microsoft Edge for Android Remote Code Execution Vulnerability
CVE-2026-228749.638.1GiteaGitea Open Source Git ServerCWE-918Gitea webhook and migration allow-list filtering permits SSRF
CVE-2026-119004.337.5spacetimeAd Inserter – Ad Manager & AdSense AdsCWE-639Ad Inserter <= 2.8.16 - Insecure Direct Object Reference to Authenticated (Co…
CVE-2026-246907.537.3GiteaGitea Open Source Git ServerCWE-284Gitea pull-request branch updates use insufficient permission checks
CVE-2026-276577.537.3GiteaGitea Open Source Git ServerCWE-639Gitea email settings allow changing another user's primary email address
CVE-2026-276607.537.3GiteaGitea Open Source Git ServerCWE-284Gitea draft releases use insufficient permission checks
CVE-2026-287055.337.3GiteaGitea Open Source Git ServerCWE-22Gitea repository dumps write release assets using unsafe path names
CVE-2026-287448.137.1GiteaGitea Open Source Git ServerCWE-863Gitea Git smart HTTP bypasses repository token scopes for bearer tokens
CVE-2026-133417.436.9KongHQmcp-konnectCWE-20Prompt Injection and Credential Exposure via Untrusted Analytics Data in Kong…
CVE-2026-583005.536.9MicrosoftMicrosoft Edge (Chromium-based)CWE-36Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2026-51374.336.9romethemeRTMKitCWE-98RTMKit <= 2.0.7 - Authenticated (Contributor+) Limited Local File Inclusion v…
CVE-2026-582836.936.6MicrosoftMicrosoft Edge (Chromium-based)CWE-843Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-89279.136.4curlcurlCWE-294env-set cross-proxy Digest auth state leak
CVE-2026-585225.536.1MicrosoftMicrosoft Edge (Chromium-based)CWE-23Microsoft Edge for Android Information Disclosure Vulnerability
CVE-2026-582907.535.7MicrosoftMicrosoft Edge (Chromium-based)CWE-843Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-287378.735.6GiteaGitea Open Source Git ServerCWE-79Gitea 3D file viewer allows stored XSS through glTF extensionsRequired
CVE-2026-146115.335.6DeepMystMystiCWE-200DeepMyst Mysti Per-Project Auto-Memory MemoryManager.ts initProjectMemory exp…
CVE-2026-225558.135.3GiteaGitea Open Source Git ServerCWE-284Gitea organization forks can expose organization secrets without create permi…
CVE-2026-582826.934.7MicrosoftMicrosoft Edge (Chromium-based)CWE-284Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-582866.934.7MicrosoftMicrosoft Edge (Chromium-based)CWE-284Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-84896.434.6ultimatememberUltimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership PluginCWE-79Ultimate Member <= 2.11.4 - Authenticated (Subscriber+) Stored Cross-Site Scr…
CVE-2026-117785.434.7villathemeCURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.xCWE-94CURCY <= 2.2.14 - Unauthenticated Arbitrary Shortcode Execution via 'exchange…
CVE-2026-584186.534.3GiteaGitea Open Source Git ServerCWE-918SSRF via HTTP Redirect in Repository Migration
CVE-2026-582986.134.1MicrosoftMicrosoft Edge (Chromium-based)CWE-79Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-585246.134.1MicrosoftMicrosoft Edge (Chromium-based)CWE-79Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-95457.533.6curlcurl—exposing HTTP/3 early data
CVE-2026-83516.433.6romethemeRTMKitCWE-79RTMKit <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…
CVE-2026-464655.533.6DellPowerProtect Data DomainCWE-134Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-582785.432.8MicrosoftMicrosoft Edge (Chromium-based)CWE-918Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-146092.932.9SourceCodesterCET Automated Grading System with AI Predictive AnalyticsCWE-384SourceCodester CET Automated Grading System with AI Predictive Analytics sess…
CVE-2026-100558.532.8Eclipse FoundationEclipse TheiaCWE-200In Eclipse Theia since version 1.26.0, the backend /services/request-service …
CVE-2026-146042.132.7Open Asset Import LibraryAssimpCWE-119Open Asset Import Library Assimp PLY Model PlyLoader.cpp ExportToBlob double …
CVE-2026-89327.532.5curlcurl—incomplete mTLS config matching in conn reuse
CVE-2026-209095.331.8GiteaGitea Open Source Git ServerCWE-284Gitea tracked-time list endpoint has insufficient permission checks
CVE-2026-257825.331.8GiteaGitea Open Source Git ServerCWE-639Gitea tracked-time deletion can target entries from another issue
CVE-2026-113975.531.3vjinfotechWP Import Export LiteCWE-918WP Import Export Lite <= 3.9.30 - Authenticated (Administrator+) Server-Side …
CVE-2026-89269.130.4curlcurlCWE-522password leak with netrc and user in URL
CVE-2026-96266.430.2parorreyJSON API UserCWE-79JSON API User <= 4.1.0 - Authenticated (Subscriber+) Stored Cross-Site Script…
CVE-2026-146082.130.1SourceCodesterCET Automated Grading System with AI Predictive AnalyticsCWE-285SourceCodester CET Automated Grading System with AI Predictive Analytics POST…
CVE-2026-146171.330.1NousResearchhermes-agentCWE-178NousResearch hermes-agent Streaming Reasoning Tag Filter stream_consumer.py G…
CVE-2026-584248.929.7GiteaGitea Open Source Git ServerCWE-285Permanent Fork PR Workflow Approval Gate Bypass
CVE-2026-277614.329.4GiteaGitea Open Source Git ServerCWE-863Gitea repository feeds bypass API token scope enforcement
CVE-2026-454885.928.9MicrosoftMicrosoft Edge (Chromium-based)CWE-451Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-97566.428.4edge22GenerateBlocksCWE-79GenerateBlocks <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-127294.328.0wedevsweDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI ChatbotCWE-862weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= …
CVE-2026-125575.327.9SaturdayDriveNinja Forms - File UploadsCWE-862Ninja Forms - File Uploads <= 3.3.29 - Missing Authorization to Unauthenticat…
CVE-2026-262318.527.7GiteaGitea Open Source Git ServerCWE-863Gitea maintainer-edit permissions allow unauthorized commits to readable repo…
CVE-2026-88926.427.5creativemindssolutionsCM Business Directory – Optimise and showcase local businessCWE-79CM Business Directory <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Si…
CVE-2026-257796.126.9GiteaGitea Open Source Git ServerCWE-601Gitea redirect handling permits open redirects through backslash paths
CVE-2026-257144.326.7GiteaGitea Open Source Git ServerCWE-862Gitea user organization API bypasses public-only token filtering
CVE-2026-277834.326.7GiteaGitea Open Source Git ServerCWE-862Gitea issue-template APIs bypass repository unit authorization
CVE-2026-120647.526.3curlcurlCWE-295proto-default skips SSH verification
CVE-2026-464636.525.6DellPowerProtect Data DomainCWE-190Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-127316.425.5wedevsweDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI ChatbotCWE-79weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= …
CVE-2026-127346.425.5wedevsweDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI ChatbotCWE-79weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= …
CVE-2026-146134.925.3Red HatRed Hat build of Keycloak 26.6CWE-284Keycloak-services: keycloak-services: keycloak: fgap v2 role groups endpoint …
CVE-2026-95477.424.8curlcurl—SSH improper host validation
CVE-2026-287407.124.5GiteaGitea Open Source Git ServerCWE-639Gitea LFS object reuse bypasses Code-unit authorization
CVE-2026-146152.723.8Red HatRed Hat build of Keycloak 26.4CWE-1220Keycloak-services: keycloak: fgap v2 parent group children endpoint bypasses …
CVE-2026-146145.423.7Red HatRed Hat build of Keycloak 26.4CWE-639Keycloak-services: keycloak-services: fgap v2 client scope assignment bypass …
CVE-2026-82868.123.1curlcurlCWE-295wrong STARTTLS connection reuse
CVE-2026-584269.622.1GiteaGitea Open Source Git ServerCWE-347Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository …
CVE-2026-48046.420.2themegrillZakraCWE-79Zakra <= 4.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via…
CVE-2026-143555.319.8phpphpCWE-122ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD
CVE-2026-411234.316.6DellPowerProtect Data DomainCWE-284Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release …
CVE-2026-43226.116.4Raera - Ankara Web Design and Digital Advertising AgencyDestekzCWE-79XSS in Raera's Destekz
CVE-2026-583797.313.9Red HatRed Hat Enterprise Linux 9CWE-122Gimp: gimp: heap buffer overflow in read_channel_data()
CVE-2026-146124.213.1Red HatRed Hat Enterprise Linux 10CWE-787Freeipa: ipa: idm: freeipa: off-by-one buffer overflows in ipa-otpd oauth2.c …
CVE-2026-100548.812.2Eclipse FoundationEclipse TheiaCWE-306In affected versions of Eclipse Theia (1.8.1 and later), the browser backend …
CVE-2026-144598.810.8TUBITAK BILGEM Software Technologies Research Institutepardus-softwareCWE-88Argument Injection in TUBITAK BILGEM's pardus-software
CVE-2026-351595.310.5DellInspiron 15 3520CWE-305Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakne…
CVE-2026-146057.19.5n/aRT-ThreadCWE-119RT-Thread ls1c CAN ls1c_can.h recvmsg stack-based overflow
CVE-2026-146067.19.5n/aRT-ThreadCWE-119RT-Thread SWM341 CAN SWM341.h CAN_Receive stack-based overflow
CVE-2026-559454.28.2MicrosoftMicrosoft Edge (Chromium-based)CWE-362Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-442694.46.8DellPowerProtect Data DomainCWE-59Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release …
CVE-2026-464684.46.8DellPowerProtect Data DomainCWE-59Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-146101.96.8Open Asset Import LibraryAssimpCWE-119Open Asset Import Library Assimp CSM File CSMLoader.cpp InternReadFile heap-b…
CVE-2026-467304.26.7DellPowerProtect Data DomainCWE-863Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-411244.46.3DellPowerProtect Data DomainCWE-22Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release …
CVE-2026-146075.46.1n/aRT-ThreadCWE-119RT-Thread lwp_syscall.c sys_getaddrinfo memory corruption
CVE-2026-144608.85.7TUBITAK BILGEM Software Technologies Research Institutepardus-softwareCWE-862Missing Authorization in TUBITAK BILGEM's pardus-software
CVE-2026-129606.05.3ASUSRouter appCWE-926An Improper Export of Android Application Components vulnerability in ASUS Ro…
CVE-2026-89218.54.9ASUSASUS Business ManagerCWE-73External Control of File Name or Path vulnerability in ASUS Business Manager …
CVE-2026-464662.74.6DellPowerProtect Data DomainCWE-348Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-442684.44.1DellPowerProtect Data DomainCWE-732Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release …
CVE-2022-49898.53.7ASUSAI Suite 3CWE-1284** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in …
CVE-2026-560853.33.3DellPowerProtect Data DomainCWE-908Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2022-49907.32.9ASUSAI Suite 3CWE-1284** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in …
CVE-2026-464675.81.6DellPowerProtect Data DomainCWE-532Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-88046.71.2PerforcePuppet CoreCWE-312Cleartext Storage of Sensitive Information for Puppet Resource API

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-03 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.