boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Sunday, July 5, 2026 · all times UTC← 2026-07-04 · archive · 2026-07-06 →

Security Box Score — July 5, 2026

86 CVEs published, led by SourceCodester (20).

86 CVEs published July 5, 2026: 1 critical, 6 high, 44 medium, 35 low; 0 in the KEV catalog at press time; 8 with a public exploit reference; 0 awaiting enrichment. 25 rendered as box scores below; the remaining 61 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published96513368——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

574 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux37151712086653011120.17.5.0014+4 ▲
google521317148590542377760.57.8.0024-436 ▼
microsoft50807615521886286202.57.8.0046+43 ▲
red hat16238129311914200.06.5.0030-3 ▼
apple01042287228876.76.5.00320
canonical0202585000.05.5.00110
freebsd01601240000.07.8.00160
suse2154830000.08.8.0042+2 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ubiquiti2536142110338.38.8.0049+25 ▲
cisco830614100561136.77.5.0057+6 ▲
netgear01700161000.04.3.00240
palo alto networks011127113218.25.9.00220
checkpoint0915303111.17.5.04100
fortinet09432028333.38.3.00760
ivanti09450025555.68.8.5187-1 ▼
f50843104112.58.9.02250
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache5160246164103310.67.3.0053-27 ▼
mozilla2581218280900.07.3.0026-2 ▼
gitlab03105215426.54.4.00290
github171150000.06.0.0039+1 ▲
docker070520000.08.2.0016-2 ▼
drupal0511304120.05.1.00260
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle02701321161842720.78.8.00400
adobe014411537821921.45.8.00210
ibm01243642460600.07.5.0034-5 ▼
progress2111910600.07.5.0036-3 ▼
solarwinds07232010457.17.5.4001-2 ▼
veeam042200100.09.0.00520
zohocorp031110000.08.4.01700
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology02325133000.05.6.0025-5 ▼
d-link0120525300.05.8.0058-5 ▼
siemens090450000.06.9.0021-1 ▼
rockwell automation071510000.08.7.00300
abb060420000.07.2.0018-4 ▼
schneider electric060420000.07.8.00420
moxa050320000.07.0.00290
dahua030111000.06.9.00360
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester2798005246000.05.5.0029+6 ▲
dell2076234382211.36.7.0018+17 ▲
spring073231391000.06.5.0024-2 ▼
openclaw0670352210000.07.0.00210
edimax065039026100.07.4.00800
itsourcecode1063001944000.02.1.0033-9 ▼
capgo061231271000.07.1.00390
themerex26055410000.08.1.0043+2 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9991100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-20230.882099.88.6
CVE-2026-34910.874799.710.0
CVE-2026-34908.851999.710.0
CVE-2026-50751.837799.79.3
CVE-2026-48907.781099.510.0
CVE-2026-45659.760899.58.8
CVE-2026-34909.639099.210.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9991KEV
CVE-2026-3491010.0.8747KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.7810KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-1377310.0.0610
CVE-2026-5641510.0.0436
CVE-2026-5641310.0.0419
CVE-2026-5357610.0.0330
CVE-2026-5375310.0.0290
Most disclosures (vendor)
VendorCVEs
google654
linux517
microsoft264
oracle242
adobe142
red hat125
apache94
ibm70
spring70
capgo61
Most KEV additions (YTD)
VendorKEV
microsoft20
cisco11
apple7
google6
ivanti5
solarwinds4
berriai3
fortinet3
smartertools3
ubiquiti3
Most-affected ecosystems
EcosystemAdvisories
Maven38
Packagist15
npm6
NuGet3
PyPI3
Fastest to KEV
CVEVendorDays
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
CVE-2026-34910Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171691
CVE-2021-27102n/a2021-11-171691
CVE-2021-27101n/a2021-11-171691
CVE-2021-27103n/a2021-11-171691
CVE-2021-21017Adobe2021-11-171691
CVE-2021-28550Adobe2021-11-171691
CVE-2021-42013Apache Software Foundation2021-11-171691
CVE-2021-41773Apache Software Foundation2021-11-171691
CVE-2021-30858Apple2021-11-171691
CVE-2021-30860Apple2021-11-171691

Transactions

EXPLOIT PUBLISHED — CVE-2026-10656 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-10657 (zephyrproject zephyr). Public exploit reference added.

DUE DATE PASSED — CVE-2026-45659 (Microsoft SharePoint Enterprise Server 2016). CISA remediation deadline was July 4, 2026; still in catalog.

Yesterday's Results

How to read these box scores · glossary

86 CVEs published. 25 box scores, 61 table rows — nothing truncated.

UTT HiPER 1250GW Web Endpoint ConfigWirelessBase_5g stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0079   53.5     —
AFFECTED
  Product       Versions               Fixed
  HiPER 1250GW  3.2.7-210907-180535 –  —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
zhayujie chatgpt-on-wechat CowAgent wx Endpoint common.py verify_server missing authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   L   L    5.5   .0078   53.3     —
AFFECTED
  Product                     Versions  Fixed
  chatgpt-on-wechat CowAgent  2.1.0 –   2.1.1
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-287, CWE-306 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
cve-search cve-search — Unauthenticated arbitrary MongoDB collection read in cve-search
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    9.2   .0054   43.1     —
AFFECTED
  Product     Versions  Fixed
  cve-search  v4.0 –    —
TIMELINE
  Jul 5   Reserved by CNA
  Jul 5   Published (CNA: CIRCL)
CWE-20 · CNA: CIRCL · CVSS v4.0 · 2 references · NVD status: Deferred
tiddly-gittly TidGi-Desktop Git Repository Import loadWikiTiddlersWithSubWikis.ts code injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0054   43.1     —
AFFECTED
  Product        Versions  Fixed
  TidGi-Desktop  0.1 –     —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-94 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
mjperpinosa stumasy calculate.php eval code injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0054   43.1     —
AFFECTED
  Product  Versions                                    Fixed
  stumasy  327d1b0f2915ba79d7ef8ebb74553e987609d9be –  —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-94 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
666ghj BettaFish InsightEngine search-result Deduplication agent.py _deduplicate_results partial string comparison
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   L   N    5.5   .0053   42.3     —
AFFECTED
  Product    Versions  Fixed
  BettaFish  1.2.0 –   —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-187, CWE-697 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
mjperpinosa stumasy Note Handler/Assignment notes authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0052   41.8     —
AFFECTED
  Product  Versions                                    Fixed
  stumasy  327d1b0f2915ba79d7ef8ebb74553e987609d9be –  —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-285, CWE-639 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
ail-project ail-framework — Authenticated Path Traversal in AIL Framework PDF Object Handling Enables Potential Arbitrary File Read
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   N   N    7.1   .0051   41.2     —
AFFECTED
  Product        Versions     Fixed
  ail-framework  unspecified  —
TIMELINE
  Jul 5   Reserved by CNA
  Jul 5   Published (CNA: CIRCL)
CWE-22 · CNA: CIRCL · CVSS v4.0 · 1 reference · NVD status: Deferred
TIMLEGGE Crypt::DSA — Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0051   41.1     —
AFFECTED
  Product     Versions     Fixed
  Crypt::DSA  unspecified  —
TIMELINE
  Jul 3   Reserved by CNA
  Jul 5   Published (CNA: CPANSec)
CWE-330 · CNA: CPANSec · CVSS v3.1 · 4 references · NVD status: Deferred
SourceCodester Multi-Vendor Online Grocery Management System Users.php save_users improper authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0050   40.2     —
AFFECTED
  Product                                        Versions  Fixed
  Multi-Vendor Online Grocery Management System  1.0 –     —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-266, CWE-285 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
SourceCodester Onlne Examination & Learning Management System Registration Endpoint register.php privileges management
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0050   40.2     —
AFFECTED
  Product                                         Versions  Fixed
  Onlne Examination & Learning Management System  1.0 –     —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-266, CWE-269 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
SourceCodester Onlne Examination & Learning Management System Enrollment Management ajax_enroll.php improper authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0050   40.2     —
AFFECTED
  Product                                         Versions  Fixed
  Onlne Examination & Learning Management System  1.0 –     —
TIMELINE
  Jul 5   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-266, CWE-285 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
stephen-kruger bluebox cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   L   N    2.1   .0049   39.6     —
AFFECTED
  Product  Versions  Fixed
  bluebox  4.5.0 –   —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
NousResearch hermes-agent skills_tool.py skill_view path traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   N   N    2.1   .0048   39.1     —
AFFECTED
  Product       Versions       Fixed
  hermes-agent  2026.5.29.2 –  —
TIMELINE
  Jul 5   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-22 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Deferred
Ruijie RG-UAC user_auth_commit.php unrestricted upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0047   38.7     —
AFFECTED
  Product  Versions         Fixed
  RG-UAC   1.0-R1.8.2.p5 –  —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-284, CWE-434 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
code-projects Real State Services addprojectsale.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    6.9   .0043   35.7     —
AFFECTED
  Product              Versions  Fixed
  Real State Services  1.0 –     —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
itsourcecode Online Hotel Management System login.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0043   35.7     —
AFFECTED
  Product                         Versions  Fixed
  Online Hotel Management System  1.0 –     —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
SourceCodester Multi-Vendor Online Grocery Management System Registration Users.php save_client sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0043   35.7     —
AFFECTED
  Product                                        Versions  Fixed
  Multi-Vendor Online Grocery Management System  1.0 –     —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
code-projects Internship Management System Employer Login Endpoint login.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0043   35.7     —
AFFECTED
  Product                       Versions  Fixed
  Internship Management System  1.0 –     —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
code-projects Online Examination head.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0043   35.7     —
AFFECTED
  Product             Versions  Fixed
  Online Examination  1.0 –     —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
SourceCodester Pizzafy E-Commerce System ajax.php confirm_order sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0043   35.7     —
AFFECTED
  Product                    Versions  Fixed
  Pizzafy E-Commerce System  1.0 –     —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
SourceCodester Class and Exam Timetabling System edit_exam.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0043   35.7     —
AFFECTED
  Product                            Versions  Fixed
  Class and Exam Timetabling System  1.0 –     —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
SourceCodester Class and Exam Timetabling System edit_coursea.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0043   35.7     —
AFFECTED
  Product                            Versions  Fixed
  Class and Exam Timetabling System  1.0 –     —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
SourceCodester Class and Exam Timetabling System edit_product.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0043   35.7     —
AFFECTED
  Product                            Versions  Fixed
  Class and Exam Timetabling System  1.0 –     —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
code-projects Smart Parking System parkings.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0043   35.7     —
AFFECTED
  Product               Versions  Fixed
  Smart Parking System  1.0 –     —
TIMELINE
  Jul 4   Reserved by CNA
  Jul 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-147435.535.7code-projectsReal State ServicesCWE-74code-projects Real State Services normalHomeSale.php sql injection
CVE-2026-147445.535.7code-projectsReal State ServicesCWE-74code-projects Real State Services normalHomeRent.php sql injection
CVE-2026-147455.535.7code-projectsReal State ServicesCWE-74code-projects Real State Services single-list_rent.php sql injection
CVE-2026-147465.535.7code-projectsReal State ServicesCWE-74code-projects Real State Services addprojectrent.php sql injection
CVE-2026-147505.535.7mjperpinosastumasyCWE-74mjperpinosa stumasy accessing_dictionary_authorization.php accessing_dictiona…
CVE-2026-147545.535.7code-projectsHotel and Tourism ReservationCWE-74code-projects Hotel and Tourism Reservation add_room.php sql injection
CVE-2026-147555.535.7code-projectsHotel and Tourism ReservationCWE-74code-projects Hotel and Tourism Reservation Reservations Management reservati…
CVE-2026-147565.535.7code-projectsHotel and Tourism ReservationCWE-74code-projects Hotel and Tourism Reservation Tour Management add_tour.php sql …
CVE-2026-147625.535.7code-projectsHotel and Tourism ReservationCWE-74code-projects Hotel and Tourism Reservation Room Management rooms.php sql inj…
CVE-2026-147635.535.7code-projectsHotel and Tourism ReservationCWE-74code-projects Hotel and Tourism Reservation Tour Reservations tour_reserves.p…
CVE-2026-147645.535.7code-projectsHotel and Tourism ReservationCWE-89code-projects Hotel and Tourism Reservation Event Management add_event.php sq…
CVE-2026-147685.535.7code-projectsReal State ServicesCWE-74code-projects Real State Services builderHome.php sql injection
CVE-2026-147695.535.7code-projectsReal State ServicesCWE-74code-projects Real State Services pay.php sql injection
CVE-2026-147705.535.7SourceCodesterClass and Exam Timetabling SystemCWE-74SourceCodester Class and Exam Timetabling System edit_room.php sql injection
CVE-2026-147715.535.7SourceCodesterClass and Exam Timetabling SystemCWE-74SourceCodester Class and Exam Timetabling System edit_exam1.php sql injection
CVE-2026-147725.535.7SourceCodesterClass and Exam Timetabling SystemCWE-74SourceCodester Class and Exam Timetabling System edit_course1.php sql injection
CVE-2026-146912.134.1SourceCodesterMulti-Vendor Online Grocery Management SystemCWE-74SourceCodester Multi-Vendor Online Grocery Management System Setting SystemSe…
CVE-2026-147375.533.9Hanwange-Face General Management PlatformCWE-74Hanwang e-Face General Management Platform querySysAuthStr.do sql injection
CVE-2026-106575.333.2zephyrprojectzephyrCWE-125Out-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past stri…
CVE-2026-146932.133.0SourceCodesterMulti-Vendor Online Grocery Management SystemCWE-266SourceCodester Multi-Vendor Online Grocery Management System Master.php cance…
CVE-2026-147162.132.6nextlevelbuilderGoClawCWE-285nextlevelbuilder GoClaw WebSocket RPC router.go MethodRouter.Handle authoriza…
CVE-2026-147482.130.2AIAnytimeAwesome-MCP-ServerCWE-918AIAnytime Awesome-MCP-Server mcp-wiki/wiki-summary server.py server-side requ…
CVE-2026-146982.129.3SourceCodesterSyllabus-Aligned Learning Management and Examination SystemCWE-284SourceCodester Syllabus-Aligned Learning Management and Examination System up…
CVE-2026-147252.129.3SourceCodesterOnline Boat Reservation SystemCWE-613SourceCodester Online Boat Reservation System session expiration
CVE-2026-147752.129.3SourceCodesterOnlne Examination & Learning Management SystemCWE-284SourceCodester Onlne Examination & Learning Management System process_lesson.…
CVE-2026-147762.129.3SourceCodesterOnlne Examination & Learning Management SystemCWE-284SourceCodester Onlne Examination & Learning Management System Filename Extens…
CVE-2026-147772.129.3SourceCodesterOnlne Examination & Learning Management SystemCWE-284SourceCodester Onlne Examination & Learning Management System announcements.p…
CVE-2026-147522.027.4mjperpinosastumasyCWE-79mjperpinosa stumasy add_into_dictionary.php add_definition cross site scripting
CVE-2026-146892.125.7CodeAstroApartment Visitor Management SystemCWE-74CodeAstro Apartment Visitor Management System add-apartment.php sql injection
CVE-2026-146922.125.7SourceCodesterMulti-Vendor Online Grocery Management SystemCWE-74SourceCodester Multi-Vendor Online Grocery Management System POST Parameter M…
CVE-2026-146942.125.7SourceCodesterMulti-Vendor Online Grocery Management SystemCWE-74SourceCodester Multi-Vendor Online Grocery Management System POST Parameter M…
CVE-2026-147012.125.7code-projectsInternship Management SystemCWE-74code-projects Internship Management System Password Change Endpoint change_pa…
CVE-2026-147032.125.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System patientorder.php sql injection
CVE-2026-147062.125.7code-projectsOnline ExaminationCWE-74code-projects Online Examination Quiz Creation Feature update.php sql injection
CVE-2026-147172.125.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System patientlogin.php sql injection
CVE-2026-147302.125.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System patientprofile.php sql injection
CVE-2026-147312.125.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System patientreport.php sql injection
CVE-2026-147512.125.7mjperpinosastumasyCWE-74mjperpinosa stumasy search_scratch_data.php search_scratch_data sql injection
CVE-2026-147662.125.7CodeAstroApartment Visitor Management SystemCWE-74CodeAstro Apartment Visitor Management System POST Parameter search-result.ph…
CVE-2026-147672.125.7CodeAstroEcommerce WebsiteCWE-74CodeAstro Ecommerce Website POST Parameter confirm.php sql injection
CVE-2026-147732.125.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System payment.php sql injection
CVE-2026-147742.125.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System paymentdischarge.php sql injection
CVE-2026-595115.325.3Tim StriflerExclusive Addons ElementorCWE-201WordPress Exclusive Addons Elementor plugin <= 2.7.9.9 - Sensitive Data Expos…
CVE-2026-595195.325.3SoftaculousFormLayerCWE-201WordPress FormLayer plugin <= 1.0.6 - Sensitive Data Exposure vulnerability
CVE-2026-147234.824.6AD-SecurityAD_MinerCWE-20AD-Security AD_Miner Cache analyse_cache.py request_a deserialization
CVE-2026-147382.923.1exo-exploreexoCWE-327exo-explore exo Vision Feature Cache vision.py _image_cache_key weak hash
CVE-2026-106564.620.0zephyrprojectzephyrCWE-476NULL-pointer dereference DoS in MAX32 USB device controller transfer-completi…
CVE-2026-147814.819.8Red HatRed Hat Build of KeycloakCWE-1288Keycloak-services: keycloak-services: oidc email_verified claim incorrectly a…
CVE-2026-147421.313.9langchain-ailanggraphCWE-327langchain-ai langgraph Task Result Cache _cache.py _freeze weak hash
CVE-2026-147591.912.5radareorgradare2CWE-119radareorg radare2 RBinJava Line Number Table class.c r_bin_java_inner_classes…
CVE-2026-147571.910.8radareorgradare2CWE-189radareorg radare2 cmd_anal.inc core_anal_bytes integer overflow
CVE-2026-147601.99.7radareorgradare2CWE-119radareorg radare2 regprofile disasm.c r_core_seek_arch_bits use after free
CVE-2026-147581.98.6radareorgradare2CWE-189radareorg radare2 hexpairs cmd_anal.inc.c cmd_anal_opcode integer overflow
CVE-2026-147611.98.6radareorgradare2CWE-189radareorg radare2 str.c r_str_append integer overflow
CVE-2026-146994.86.8zcaceresmarkdownify-mcpCWE-59zcaceres markdownify-mcp Markdownify.ts assertPathAllowed symlink
CVE-2026-122507.94.6TUBITAK BILGEM Software Technologies Research InstitutePardus Domain JoinerCWE-214Sensitive Data Exposure in TUBITAK BILGEM's Pardus Domain Joiner
CVE-2026-90858.83.9TUBITAK BILGEM Software Technologies Research InstitutePardus-Parental-ControlCWE-284DNS Hijacking in TUBITAK BILGEM's Pardus-Parental-Control
CVE-2026-65097.83.9TUBITAK BILGEM Software Technologies Research InstitutePardus UpdateCWE-862Privilege Escalation in TUBITAK BILGEM's Pardus Update
CVE-2026-147021.13.9zcaceresmarkdownify-mcpCWE-310zcaceres markdownify-mcp webpage-to-markdown Markdownify.ts saveToTempFile ra…
CVE-2026-595204.33.7properfractionCrawlWP SEOCWE-352WordPress CrawlWP SEO plugin <= 3.0.16 - Cross Site Request Forgery (CSRF) vu…
CVE-2026-123863.93.1TUBITAK BILGEM Software Technologies Research InstitutePardus PenCWE-170Buffer Overflow in TUBITAK BILGEM's Pardus Pen

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-05 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.