AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N L L 5.5 .0046 38.4 —
AFFECTED Product Versions Fixed chatgpt-on-wechat CowAgent 2.1.0 – 2.1.1
TIMELINE Jul 4 Reserved by CNA Jul 5 Published (CNA: VulDB)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
86 CVEs published, led by SourceCodester (20).
86 CVEs published July 5, 2026: 1 critical, 6 high, 44 medium, 35 low; 0 in the KEV catalog at press time; 7 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 61 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 965 | 13348 | 1249 | 2564 |
| KEV catalog size | 1671 | |||
572 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 37 | 1519 | 120 | 866 | 528 | 1 | 27 | 3 | 0.2 | 7.5 | .0013 | +3 ▲ |
| 52 | 1316 | 148 | 586 | 542 | 37 | 74 | 6 | 0.5 | 7.8 | .0023 | -436 ▼ | |
| microsoft | 50 | 816 | 61 | 552 | 188 | 6 | 380 | 28 | 3.4 | 7.8 | .0045 | +43 ▲ |
| red hat | 16 | 208 | 12 | 84 | 103 | 9 | 4 | 0 | 0.0 | 6.5 | .0026 | -3 ▼ |
| apple | 0 | 99 | 1 | 23 | 66 | 2 | 94 | 7 | 7.1 | 6.5 | .0031 | 0 |
| canonical | 0 | 20 | 2 | 5 | 8 | 5 | 0 | 0 | 0.0 | 5.5 | .0011 | 0 |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0015 | 0 |
| suse | 2 | 15 | 4 | 8 | 3 | 0 | 0 | 0 | 0.0 | 8.8 | .0036 | +2 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ubiquiti | 25 | 36 | 14 | 21 | 1 | 0 | 4 | 3 | 8.3 | 8.8 | .0036 | +25 ▲ |
| cisco | 8 | 31 | 4 | 12 | 8 | 0 | 96 | 11 | 35.5 | 7.5 | .0056 | +6 ▲ |
| netgear | 0 | 17 | 0 | 0 | 16 | 1 | 8 | 0 | 0.0 | 4.3 | .0024 | 0 |
| palo alto networks | 0 | 11 | 0 | 1 | 7 | 1 | 14 | 2 | 18.2 | 4.8 | .0022 | 0 |
| checkpoint | 0 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | 0 |
| f5 | 0 | 9 | 4 | 3 | 1 | 0 | 7 | 1 | 11.1 | 8.9 | .0221 | 0 |
| ivanti | 0 | 9 | 2 | 3 | 0 | 0 | 33 | 5 | 55.6 | 8.8 | .5187 | -1 ▼ |
| fortinet | 0 | 8 | 1 | 3 | 2 | 0 | 28 | 3 | 37.5 | 7.3 | .0066 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 5 | 158 | 24 | 61 | 62 | 10 | 40 | 1 | 0.6 | 7.3 | .0048 | -27 ▼ |
| mozilla | 2 | 58 | 12 | 18 | 28 | 0 | 13 | 0 | 0.0 | 7.3 | .0025 | -2 ▼ |
| gitlab | 0 | 33 | 0 | 5 | 21 | 5 | 4 | 2 | 6.1 | 4.4 | .0022 | 0 |
| github | 1 | 7 | 1 | 1 | 5 | 0 | 0 | 0 | 0.0 | 6.0 | .0026 | +1 ▲ |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 1 | 0 | 0.0 | 8.2 | .0016 | -2 ▼ |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 5 | 1 | 20.0 | 5.1 | .0026 | 0 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 270 | 131 | 116 | 18 | 4 | 40 | 2 | 0.7 | 8.8 | .0040 | -1 ▼ |
| adobe | 0 | 146 | 11 | 52 | 78 | 2 | 75 | 3 | 2.1 | 5.5 | .0021 | 0 |
| ibm | 0 | 124 | 36 | 42 | 46 | 0 | 7 | 0 | 0.0 | 7.5 | .0025 | -5 ▼ |
| progress | 2 | 11 | 1 | 9 | 1 | 0 | 9 | 0 | 0.0 | 7.5 | .0035 | -3 ▼ |
| solarwinds | 0 | 7 | 1 | 2 | 2 | 0 | 11 | 4 | 57.1 | 7.5 | .0835 | -2 ▼ |
| veeam | 0 | 4 | 2 | 2 | 0 | 0 | 4 | 0 | 0.0 | 9.0 | .0046 | 0 |
| zohocorp | 0 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 0 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -5 ▼ |
| d-link | 0 | 13 | 0 | 5 | 2 | 5 | 26 | 1 | 7.7 | 5.8 | .0059 | -5 ▼ |
| siemens | 0 | 9 | 0 | 4 | 5 | 0 | 1 | 0 | 0.0 | 6.9 | .0019 | -1 ▼ |
| rockwell automation | 0 | 7 | 1 | 5 | 1 | 0 | 0 | 0 | 0.0 | 8.7 | .0030 | 0 |
| abb | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -4 ▼ |
| schneider electric | 0 | 6 | 0 | 4 | 2 | 0 | 1 | 0 | 0.0 | 7.8 | .0024 | 0 |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | 0 |
| dahua | 0 | 3 | 0 | 1 | 1 | 1 | 2 | 0 | 0.0 | 6.9 | .0036 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 27 | 98 | 0 | 0 | 52 | 46 | 0 | 0 | 0.0 | 5.5 | .0026 | +6 ▲ |
| dell | 20 | 76 | 1 | 34 | 38 | 2 | 2 | 1 | 1.3 | 6.7 | .0016 | +17 ▲ |
| spring | 0 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | -2 ▼ |
| openclaw | 0 | 67 | 0 | 35 | 22 | 10 | 0 | 0 | 0.0 | 7.0 | .0021 | 0 |
| edimax | 0 | 65 | 0 | 39 | 0 | 26 | 1 | 0 | 0.0 | 7.4 | .0059 | 0 |
| itsourcecode | 10 | 63 | 0 | 0 | 19 | 44 | 0 | 0 | 0.0 | 2.1 | .0020 | -9 ▼ |
| capgo | 0 | 61 | 2 | 31 | 27 | 1 | 0 | 0 | 0.0 | 7.1 | .0031 | 0 |
| themerex | 2 | 60 | 5 | 54 | 1 | 0 | 0 | 0 | 0.0 | 8.1 | .0043 | +2 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-10520 | .9990 | 100.0 | 10.0 |
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-35273 | .9547 | 99.9 | 9.8 |
| CVE-2026-34910 | .8696 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-20230 | .8321 | 99.7 | 8.6 |
| CVE-2026-42271 | .8301 | 99.6 | — |
| CVE-2026-50751 | .8255 | 99.6 | 9.3 |
| CVE-2026-48907 | .6883 | 99.3 | 10.0 |
| CVE-2026-34909 | .6390 | 99.2 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-10520 | 10.0 | .9990 | KEV |
| CVE-2026-34910 | 10.0 | .8696 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-48907 | 10.0 | .6883 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-50160 | 10.0 | .1775 | |
| CVE-2026-48276 | 10.0 | .0505 | |
| CVE-2026-13773 | 10.0 | .0341 | |
| CVE-2026-56413 | 10.0 | .0316 | |
| CVE-2026-56415 | 10.0 | .0315 |
| Vendor | CVEs |
|---|---|
| 654 | |
| linux | 517 |
| microsoft | 264 |
| oracle | 242 |
| adobe | 142 |
| red hat | 125 |
| apache | 94 |
| ibm | 70 |
| spring | 70 |
| capgo | 61 |
| Vendor | KEV |
|---|---|
| microsoft | 28 |
| cisco | 11 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| synacor | 4 |
| adobe | 3 |
| fortinet | 3 |
| linux | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 38 |
| Packagist | 15 |
| npm | 6 |
| NuGet | 3 |
| PyPI | 3 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2025-67038 | Lantronix | 0 |
| CVE-2026-10520 | ivanti | 0 |
| CVE-2026-11645 | 0 | |
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-20245 | Cisco | 0 |
| CVE-2026-20253 | Splunk | 0 |
| CVE-2026-20262 | Cisco | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE-2026-34909 | Ubiquiti Inc | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1691 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1691 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1691 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1691 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1691 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1691 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1691 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1691 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1691 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1691 |
EXPLOIT PUBLISHED — CVE-2026-10656 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10657 (zephyrproject zephyr). Public exploit reference added.
DUE DATE PASSED — CVE-2026-45659 (Microsoft SharePoint Enterprise Server 2016). CISA remediation deadline was July 4, 2026; still in catalog.
How to read these box scores · glossary
86 CVEs published. 25 box scores, 61 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N L L 5.5 .0046 38.4 —
AFFECTED Product Versions Fixed chatgpt-on-wechat CowAgent 2.1.0 – 2.1.1
TIMELINE Jul 4 Reserved by CNA Jul 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 7.4 .0045 37.4 —
AFFECTED Product Versions Fixed HiPER 1250GW 3.2.7-210907-180535 – —
TIMELINE Jul 4 Reserved by CNA Jul 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H N N 7.1 .0037 30.5 —
AFFECTED Product Versions Fixed ail-framework unspecified —
TIMELINE Jul 5 Reserved by CNA Jul 5 Published (CNA: CIRCL)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 9.2 .0035 28.1 —
AFFECTED Product Versions Fixed cve-search v4.0 – —
TIMELINE Jul 5 Reserved by CNA Jul 5 Published (CNA: CIRCL)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L N N 2.1 .0033 26.3 —
AFFECTED Product Versions Fixed hermes-agent 2026.5.29.2 – —
TIMELINE Jul 5 Reserved by CNA Jul 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N L N 5.5 .0033 26.2 —
AFFECTED Product Versions Fixed BettaFish 1.2.0 – —
TIMELINE Jul 4 Reserved by CNA Jul 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0032 25.4 —
AFFECTED Product Versions Fixed Hotel and Tourism Reservation 1.0 – —
TIMELINE Jul 4 Reserved by CNA Jul 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0032 25.1 —
AFFECTED Product Versions Fixed TidGi-Desktop 0.1 – —
TIMELINE Jul 4 Reserved by CNA Jul 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0032 25.1 —
AFFECTED Product Versions Fixed stumasy 327d1b0f2915ba79d7ef8ebb74553e987609d9be – —
TIMELINE Jul 4 Reserved by CNA Jul 5 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0032 24.3 —
AFFECTED Product Versions Fixed Crypt::DSA unspecified —
TIMELINE Jul 3 Reserved by CNA Jul 5 Published (CNA: CPANSec)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0031 23.6 —
AFFECTED Product Versions Fixed stumasy 327d1b0f2915ba79d7ef8ebb74553e987609d9be – —
TIMELINE Jul 4 Reserved by CNA Jul 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0029 22.0 —
AFFECTED Product Versions Fixed Multi-Vendor Online Grocery Management System 1.0 – —
TIMELINE Jul 4 Reserved by CNA Jul 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0029 22.0 —
AFFECTED Product Versions Fixed Onlne Examination & Learning Management System 1.0 – —
TIMELINE Jul 4 Reserved by CNA Jul 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0029 22.0 —
AFFECTED Product Versions Fixed Onlne Examination & Learning Management System 1.0 – —
TIMELINE Jul 5 Reserved by CNA Jul 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N P N L N 2.1 .0029 21.3 —
AFFECTED Product Versions Fixed bluebox 4.5.0 – —
TIMELINE Jul 4 Reserved by CNA Jul 5 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N L 5.3 .0029 21.1 —
AFFECTED Product Versions Fixed zephyr 1.10.0 – —
TIMELINE Jun 2 Reserved by CNA Jul 5 Public exploit reference published Jul 5 Published (CNA: zephyr)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0028 21.0 —
AFFECTED Product Versions Fixed Class and Exam Timetabling System 1.0 – —
TIMELINE Jul 4 Reserved by CNA Jul 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0028 21.0 —
AFFECTED Product Versions Fixed Class and Exam Timetabling System 1.0 – —
TIMELINE Jul 4 Reserved by CNA Jul 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0028 21.0 —
AFFECTED Product Versions Fixed Class and Exam Timetabling System 1.0 – —
TIMELINE Jul 4 Reserved by CNA Jul 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0028 21.0 —
AFFECTED Product Versions Fixed RG-UAC 1.0-R1.8.2.p5 – —
TIMELINE Jul 4 Reserved by CNA Jul 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0028 21.0 —
AFFECTED Product Versions Fixed Class and Exam Timetabling System 1.0 – —
TIMELINE Jul 5 Reserved by CNA Jul 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0028 21.0 —
AFFECTED Product Versions Fixed Class and Exam Timetabling System 1.0 – —
TIMELINE Jul 5 Reserved by CNA Jul 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0028 21.0 —
AFFECTED Product Versions Fixed Class and Exam Timetabling System 1.0 – —
TIMELINE Jul 5 Reserved by CNA Jul 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0028 20.6 —
AFFECTED Product Versions Fixed Online Hotel Management System 1.0 – —
TIMELINE Jul 4 Reserved by CNA Jul 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 6.9 .0027 19.1 —
AFFECTED Product Versions Fixed Real State Services 1.0 – —
TIMELINE Jul 4 Reserved by CNA Jul 5 Published (CNA: VulDB)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-14700 | 5.5 | 19.1 | code-projects | Internship Management System | CWE-74 | code-projects Internship Management System Employer Login Endpoint login.php … |
| CVE-2026-14705 | 5.5 | 19.1 | code-projects | Online Examination | CWE-74 | code-projects Online Examination head.php sql injection |
| CVE-2026-14713 | 5.5 | 19.1 | SourceCodester | Pizzafy E-Commerce System | CWE-74 | SourceCodester Pizzafy E-Commerce System ajax.php confirm_order sql injection |
| CVE-2026-14735 | 5.5 | 19.1 | code-projects | Smart Parking System | CWE-74 | code-projects Smart Parking System parkings.php sql injection |
| CVE-2026-14746 | 5.5 | 19.1 | code-projects | Real State Services | CWE-74 | code-projects Real State Services addprojectrent.php sql injection |
| CVE-2026-14750 | 5.5 | 19.1 | mjperpinosa | stumasy | CWE-74 | mjperpinosa stumasy accessing_dictionary_authorization.php accessing_dictiona… |
| CVE-2026-14754 | 5.5 | 19.1 | code-projects | Hotel and Tourism Reservation | CWE-74 | code-projects Hotel and Tourism Reservation add_room.php sql injection |
| CVE-2026-14755 | 5.5 | 19.1 | code-projects | Hotel and Tourism Reservation | CWE-74 | code-projects Hotel and Tourism Reservation Reservations Management reservati… |
| CVE-2026-14756 | 5.5 | 19.1 | code-projects | Hotel and Tourism Reservation | CWE-74 | code-projects Hotel and Tourism Reservation Tour Management add_tour.php sql … |
| CVE-2026-14763 | 5.5 | 19.1 | code-projects | Hotel and Tourism Reservation | CWE-74 | code-projects Hotel and Tourism Reservation Tour Reservations tour_reserves.p… |
| CVE-2026-14764 | 5.5 | 19.1 | code-projects | Hotel and Tourism Reservation | CWE-74 | code-projects Hotel and Tourism Reservation Event Management add_event.php sq… |
| CVE-2026-14768 | 5.5 | 19.1 | code-projects | Real State Services | CWE-74 | code-projects Real State Services builderHome.php sql injection |
| CVE-2026-14769 | 5.5 | 19.1 | code-projects | Real State Services | CWE-74 | code-projects Real State Services pay.php sql injection |
| CVE-2026-14695 | 5.5 | 18.3 | SourceCodester | Multi-Vendor Online Grocery Management System | CWE-74 | SourceCodester Multi-Vendor Online Grocery Management System Registration Use… |
| CVE-2026-14743 | 5.5 | 18.3 | code-projects | Real State Services | CWE-74 | code-projects Real State Services normalHomeSale.php sql injection |
| CVE-2026-14744 | 5.5 | 18.3 | code-projects | Real State Services | CWE-74 | code-projects Real State Services normalHomeRent.php sql injection |
| CVE-2026-14745 | 5.5 | 18.3 | code-projects | Real State Services | CWE-74 | code-projects Real State Services single-list_rent.php sql injection |
| CVE-2026-14737 | 5.5 | 17.8 | Hanwang | e-Face General Management Platform | CWE-74 | Hanwang e-Face General Management Platform querySysAuthStr.do sql injection |
| CVE-2026-10656 | 4.6 | 17.2 | zephyrproject | zephyr | CWE-476 | NULL-pointer dereference DoS in MAX32 USB device controller transfer-completi… |
| CVE-2026-14716 | 2.1 | 16.1 | nextlevelbuilder | GoClaw | CWE-285 | nextlevelbuilder GoClaw WebSocket RPC router.go MethodRouter.Handle authoriza… |
| CVE-2026-14691 | 2.1 | 15.6 | SourceCodester | Multi-Vendor Online Grocery Management System | CWE-74 | SourceCodester Multi-Vendor Online Grocery Management System Setting SystemSe… |
| CVE-2026-14693 | 2.1 | 14.6 | SourceCodester | Multi-Vendor Online Grocery Management System | CWE-266 | SourceCodester Multi-Vendor Online Grocery Management System Master.php cance… |
| CVE-2026-14748 | 2.1 | 14.3 | AIAnytime | Awesome-MCP-Server | CWE-918 | AIAnytime Awesome-MCP-Server mcp-wiki/wiki-summary server.py server-side requ… |
| CVE-2026-14738 | 2.9 | 12.3 | exo-explore | exo | CWE-327 | exo-explore exo Vision Feature Cache vision.py _image_cache_key weak hash |
| CVE-2026-14698 | 2.1 | 12.0 | SourceCodester | Syllabus-Aligned Learning Management and Examination System | CWE-284 | SourceCodester Syllabus-Aligned Learning Management and Examination System up… |
| CVE-2026-14725 | 2.1 | 12.0 | SourceCodester | Online Boat Reservation System | CWE-613 | SourceCodester Online Boat Reservation System session expiration |
| CVE-2026-14775 | 2.1 | 12.0 | SourceCodester | Onlne Examination & Learning Management System | CWE-284 | SourceCodester Onlne Examination & Learning Management System process_lesson.… |
| CVE-2026-14776 | 2.1 | 12.0 | SourceCodester | Onlne Examination & Learning Management System | CWE-284 | SourceCodester Onlne Examination & Learning Management System Filename Extens… |
| CVE-2026-14777 | 2.1 | 12.0 | SourceCodester | Onlne Examination & Learning Management System | CWE-284 | SourceCodester Onlne Examination & Learning Management System announcements.p… |
| CVE-2026-14692 | 2.1 | 10.8 | SourceCodester | Multi-Vendor Online Grocery Management System | CWE-74 | SourceCodester Multi-Vendor Online Grocery Management System POST Parameter M… |
| CVE-2026-14703 | 2.1 | 10.8 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System patientorder.php sql injection |
| CVE-2026-14706 | 2.1 | 10.8 | code-projects | Online Examination | CWE-74 | code-projects Online Examination Quiz Creation Feature update.php sql injection |
| CVE-2026-14717 | 2.1 | 10.8 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System patientlogin.php sql injection |
| CVE-2026-14730 | 2.1 | 10.8 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System patientprofile.php sql injection |
| CVE-2026-14731 | 2.1 | 10.8 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System patientreport.php sql injection |
| CVE-2026-14751 | 2.1 | 10.8 | mjperpinosa | stumasy | CWE-74 | mjperpinosa stumasy search_scratch_data.php search_scratch_data sql injection |
| CVE-2026-14766 | 2.1 | 10.8 | CodeAstro | Apartment Visitor Management System | CWE-74 | CodeAstro Apartment Visitor Management System POST Parameter search-result.ph… |
| CVE-2026-14767 | 2.1 | 10.8 | CodeAstro | Ecommerce Website | CWE-74 | CodeAstro Ecommerce Website POST Parameter confirm.php sql injection |
| CVE-2026-14773 | 2.1 | 10.8 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System payment.php sql injection |
| CVE-2026-14774 | 2.1 | 10.8 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System paymentdischarge.php sql injection |
| CVE-2026-14752 | 2.0 | 10.6 | mjperpinosa | stumasy | CWE-79 | mjperpinosa stumasy add_into_dictionary.php add_definition cross site scripting |
| CVE-2026-14689 | 2.1 | 10.3 | CodeAstro | Apartment Visitor Management System | CWE-74 | CodeAstro Apartment Visitor Management System add-apartment.php sql injection |
| CVE-2026-14694 | 2.1 | 10.2 | SourceCodester | Multi-Vendor Online Grocery Management System | CWE-74 | SourceCodester Multi-Vendor Online Grocery Management System POST Parameter M… |
| CVE-2026-14701 | 2.1 | 10.2 | code-projects | Internship Management System | CWE-74 | code-projects Internship Management System Password Change Endpoint change_pa… |
| CVE-2026-59511 | 5.3 | 9.6 | Tim Strifler | Exclusive Addons Elementor | CWE-201 | WordPress Exclusive Addons Elementor plugin <= 2.7.9.9 - Sensitive Data Expos… |
| CVE-2026-59519 | 5.3 | 9.6 | Softaculous | FormLayer | CWE-201 | WordPress FormLayer plugin <= 1.0.6 - Sensitive Data Exposure vulnerability |
| CVE-2026-14759 | 1.9 | 9.0 | radareorg | radare2 | CWE-119 | radareorg radare2 RBinJava Line Number Table class.c r_bin_java_inner_classes… |
| CVE-2026-14781 | 4.8 | 7.6 | Red Hat | Red Hat Build of Keycloak | CWE-1288 | Keycloak-services: keycloak-services: oidc email_verified claim incorrectly a… |
| CVE-2026-14757 | 1.9 | 7.3 | radareorg | radare2 | CWE-189 | radareorg radare2 cmd_anal.inc core_anal_bytes integer overflow |
| CVE-2026-14760 | 1.9 | 6.4 | radareorg | radare2 | CWE-119 | radareorg radare2 regprofile disasm.c r_core_seek_arch_bits use after free |
| CVE-2026-14758 | 1.9 | 5.9 | radareorg | radare2 | CWE-189 | radareorg radare2 hexpairs cmd_anal.inc.c cmd_anal_opcode integer overflow |
| CVE-2026-14761 | 1.9 | 5.9 | radareorg | radare2 | CWE-189 | radareorg radare2 str.c r_str_append integer overflow |
| CVE-2026-14742 | 1.3 | 5.7 | langchain-ai | langgraph | CWE-327 | langchain-ai langgraph Task Result Cache _cache.py _freeze weak hash |
| CVE-2026-14699 | 4.8 | 3.8 | zcaceres | markdownify-mcp | CWE-59 | zcaceres markdownify-mcp Markdownify.ts assertPathAllowed symlink |
| CVE-2026-14723 | 4.8 | 2.5 | AD-Security | AD_Miner | CWE-20 | AD-Security AD_Miner Cache analyse_cache.py request_a deserialization |
| CVE-2026-14702 | 1.1 | 1.5 | zcaceres | markdownify-mcp | CWE-310 | zcaceres markdownify-mcp webpage-to-markdown Markdownify.ts saveToTempFile ra… |
| CVE-2026-12250 | 7.9 | 1.3 | TUBITAK BILGEM Software Technologies Research Institute | Pardus Domain Joiner | CWE-214 | Sensitive Data Exposure in TUBITAK BILGEM's Pardus Domain Joiner |
| CVE-2026-9085 | 8.8 | 1.0 | TUBITAK BILGEM Software Technologies Research Institute | Pardus-Parental-Control | CWE-284 | DNS Hijacking in TUBITAK BILGEM's Pardus-Parental-Control |
| CVE-2026-6509 | 7.8 | 1.0 | TUBITAK BILGEM Software Technologies Research Institute | Pardus Update | CWE-862 | Privilege Escalation in TUBITAK BILGEM's Pardus Update |
| CVE-2026-59520 | 4.3 | 1.0 | properfraction | CrawlWP SEO | CWE-352 | WordPress CrawlWP SEO plugin <= 3.0.16 - Cross Site Request Forgery (CSRF) vu… |
| CVE-2026-12386 | 3.9 | 0.8 | TUBITAK BILGEM Software Technologies Research Institute | Pardus Pen | CWE-170 | Buffer Overflow in TUBITAK BILGEM's Pardus Pen |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-05 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion.