AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L L L 7.3 .1392 96.2 —
AFFECTED Product Versions Fixed Apache OpenNLP :: Core :: ML :: LibSVM 3.0.0-M1 – —
TIMELINE May 2 Reserved by CNA Jul 6 Published (CNA: apache)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
196 CVEs published, led by Apache Software Foundation (39).
196 CVEs published July 6, 2026: 30 critical, 80 high, 60 medium, 26 low; 0 in the KEV catalog at press time; 20 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 171 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 1161 | 13564 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
589 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 37 | 1517 | 120 | 866 | 530 | 1 | 11 | 2 | 0.1 | 7.5 | .0014 | +4 ▲ |
| 52 | 1317 | 148 | 590 | 542 | 37 | 77 | 6 | 0.5 | 7.8 | .0024 | -436 ▼ | |
| microsoft | 50 | 807 | 61 | 552 | 188 | 6 | 286 | 20 | 2.5 | 7.8 | .0046 | +43 ▲ |
| red hat | 19 | 241 | 12 | 95 | 120 | 14 | 2 | 0 | 0.0 | 6.5 | .0030 | 0 |
| apple | 0 | 104 | 2 | 28 | 72 | 2 | 88 | 7 | 6.7 | 6.5 | .0032 | 0 |
| canonical | 0 | 20 | 2 | 5 | 8 | 5 | 0 | 0 | 0.0 | 5.5 | .0011 | 0 |
| suse | 5 | 18 | 4 | 10 | 4 | 0 | 0 | 0 | 0.0 | 8.6 | .0041 | +5 ▲ |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ubiquiti | 25 | 36 | 14 | 21 | 1 | 0 | 3 | 3 | 8.3 | 8.8 | .0049 | +25 ▲ |
| cisco | 8 | 30 | 6 | 14 | 10 | 0 | 56 | 11 | 36.7 | 7.5 | .0057 | +6 ▲ |
| netgear | 0 | 17 | 0 | 0 | 16 | 1 | 0 | 0 | 0.0 | 4.3 | .0024 | 0 |
| palo alto networks | 0 | 11 | 1 | 2 | 7 | 1 | 13 | 2 | 18.2 | 5.9 | .0022 | 0 |
| checkpoint | 0 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | 0 |
| fortinet | 0 | 9 | 4 | 3 | 2 | 0 | 28 | 3 | 33.3 | 8.3 | .0076 | 0 |
| ivanti | 0 | 9 | 4 | 5 | 0 | 0 | 25 | 5 | 55.6 | 8.8 | .5187 | -1 ▼ |
| f5 | 0 | 8 | 4 | 3 | 1 | 0 | 4 | 1 | 12.5 | 8.9 | .0225 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 44 | 199 | 36 | 79 | 72 | 11 | 33 | 1 | 0.5 | 7.3 | .0057 | +12 ▲ |
| mozilla | 3 | 59 | 12 | 18 | 29 | 0 | 9 | 0 | 0.0 | 7.3 | .0025 | -1 ▼ |
| gitlab | 0 | 31 | 0 | 5 | 21 | 5 | 4 | 2 | 6.5 | 4.4 | .0029 | 0 |
| github | 1 | 7 | 1 | 1 | 5 | 0 | 0 | 0 | 0.0 | 6.0 | .0039 | +1 ▲ |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.2 | .0016 | -2 ▼ |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 4 | 1 | 20.0 | 5.1 | .0026 | 0 |
| wordpress | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 270 | 132 | 116 | 18 | 4 | 27 | 2 | 0.7 | 8.8 | .0040 | 0 |
| adobe | 2 | 146 | 12 | 53 | 79 | 2 | 19 | 2 | 1.4 | 5.8 | .0021 | +2 ▲ |
| ibm | 0 | 124 | 36 | 42 | 46 | 0 | 6 | 0 | 0.0 | 7.5 | .0034 | -5 ▼ |
| progress | 2 | 11 | 1 | 9 | 1 | 0 | 6 | 0 | 0.0 | 7.5 | .0036 | -3 ▼ |
| solarwinds | 0 | 7 | 2 | 3 | 2 | 0 | 10 | 4 | 57.1 | 7.5 | .4001 | -2 ▼ |
| veeam | 0 | 4 | 2 | 2 | 0 | 0 | 1 | 0 | 0.0 | 9.0 | .0052 | 0 |
| zohocorp | 0 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 0 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -5 ▼ |
| d-link | 0 | 12 | 0 | 5 | 2 | 5 | 3 | 0 | 0.0 | 5.8 | .0058 | -5 ▼ |
| siemens | 0 | 9 | 0 | 4 | 5 | 0 | 0 | 0 | 0.0 | 6.9 | .0021 | -1 ▼ |
| rockwell automation | 0 | 7 | 1 | 5 | 1 | 0 | 0 | 0 | 0.0 | 8.7 | .0030 | 0 |
| abb | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -4 ▼ |
| schneider electric | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0042 | 0 |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | 0 |
| dahua | 0 | 3 | 0 | 1 | 1 | 1 | 0 | 0 | 0.0 | 6.9 | .0036 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 27 | 98 | 0 | 0 | 52 | 46 | 0 | 0 | 0.0 | 5.5 | .0029 | +6 ▲ |
| dell | 20 | 76 | 2 | 34 | 38 | 2 | 2 | 1 | 1.3 | 6.7 | .0018 | +17 ▲ |
| spring | 0 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | -2 ▼ |
| openclaw | 0 | 67 | 0 | 35 | 22 | 10 | 0 | 0 | 0.0 | 7.0 | .0021 | 0 |
| edimax | 0 | 65 | 0 | 39 | 0 | 26 | 1 | 0 | 0.0 | 7.4 | .0080 | 0 |
| itsourcecode | 10 | 63 | 0 | 0 | 19 | 44 | 0 | 0 | 0.0 | 2.1 | .0033 | -9 ▼ |
| capgo | 0 | 61 | 2 | 31 | 27 | 1 | 0 | 0 | 0.0 | 7.1 | .0039 | 0 |
| themerex | 2 | 60 | 5 | 54 | 1 | 0 | 0 | 0 | 0.0 | 8.1 | .0043 | +2 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-10520 | .9991 | 100.0 | 10.0 |
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-35273 | .9547 | 99.9 | 9.8 |
| CVE-2026-20230 | .8820 | 99.8 | 8.6 |
| CVE-2026-34910 | .8747 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-50751 | .8377 | 99.7 | 9.3 |
| CVE-2026-48907 | .7810 | 99.5 | 10.0 |
| CVE-2026-45659 | .7608 | 99.5 | 8.8 |
| CVE-2026-34909 | .6390 | 99.2 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-10520 | 10.0 | .9991 | KEV |
| CVE-2026-34910 | 10.0 | .8747 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-48907 | 10.0 | .7810 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-13773 | 10.0 | .0610 | |
| CVE-2026-56415 | 10.0 | .0436 | |
| CVE-2026-56413 | 10.0 | .0419 | |
| CVE-2026-53576 | 10.0 | .0330 | |
| CVE-2026-53753 | 10.0 | .0290 |
| Vendor | CVEs |
|---|---|
| 654 | |
| linux | 517 |
| microsoft | 264 |
| oracle | 242 |
| adobe | 144 |
| apache | 133 |
| red hat | 128 |
| ibm | 70 |
| spring | 70 |
| capgo | 61 |
| Vendor | KEV |
|---|---|
| microsoft | 20 |
| cisco | 11 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| berriai | 3 |
| fortinet | 3 |
| smartertools | 3 |
| ubiquiti | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 68 |
| Packagist | 15 |
| npm | 6 |
| NuGet | 3 |
| PyPI | 3 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-10520 | ivanti | 0 |
| CVE-2026-11645 | 0 | |
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-20245 | Cisco | 0 |
| CVE-2026-20253 | Splunk | 0 |
| CVE-2026-20262 | Cisco | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE-2026-34909 | Ubiquiti Inc | 0 |
| CVE-2026-34910 | Ubiquiti Inc | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1692 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1692 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1692 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1692 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1692 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1692 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1692 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1692 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1692 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1692 |
EXPLOIT PUBLISHED — python-pillow Pillow: 5 CVEs (CVE-2026-54059, CVE-2026-54060, CVE-2026-55379, CVE-2026-55380, CVE-2026-55798). Public exploit references added.
EXPLOIT PUBLISHED — pnpm: 3 CVEs (CVE-2026-59194, CVE-2026-59195, CVE-2026-59196). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2026-41516 (OP-TEE optee_os). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-44936 (SUSE Rancher). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-49297 (Apache Software Foundation Apache Airflow Google provider). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54234 (vllm-project vllm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-57571 (unclecode crawl4ai). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58203 (pydantic-settings). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58380 (Red Hat Enterprise Linux 9). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-59089 (Red Hat Enterprise Linux 6). Public exploit reference added.
How to read these box scores · glossary
196 CVEs published. 25 box scores, 171 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L L L 7.3 .1392 96.2 —
AFFECTED Product Versions Fixed Apache OpenNLP :: Core :: ML :: LibSVM 3.0.0-M1 – —
TIMELINE May 2 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0280 85.4 —
AFFECTED Product Versions Fixed coolify < 4.0.0-beta.471 – —
TIMELINE Mar 30 Reserved by CNA Jul 6 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0254 83.7 —
AFFECTED Product Versions Fixed coolify < 4.0.0-beta.469 – —
TIMELINE Mar 25 Reserved by CNA Jul 6 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0243 83.0 —
AFFECTED Product Versions Fixed Apache Camel 4.15.0 – —
TIMELINE Apr 8 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0211 80.4 —
AFFECTED Product Versions Fixed create-react-app 5.0.0 – —
TIMELINE Jul 5 Reserved by CNA Jul 6 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H H H 9.1 .0140 70.4 —
AFFECTED Product Versions Fixed FileOrganizer unspecified — Advanced File Manager unspecified — File Manager Pro unspecified — File Manager unspecified —
TIMELINE Apr 15 Reserved by CNA Jul 6 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H N 10.0 .0112 63.8 —
AFFECTED Product Versions Fixed ColdFusion unspecified —
TIMELINE May 21 Reserved by CNA Jul 6 Published (CNA: adobe)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0109 62.9 —
AFFECTED Product Versions Fixed ArcGIS Server unspecified —
TIMELINE May 21 Reserved by CNA Jul 6 Published (CNA: Esri)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0109 62.7 —
AFFECTED Product Versions Fixed Apache Camel Keycloak 4.15.0 – —
TIMELINE Jun 11 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N H H 8.1 .0099 60.0 —
AFFECTED Product Versions Fixed Apache Airflow Google provider unspecified —
TIMELINE May 28 Reserved by CNA Jul 6 Public exploit reference published Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H H H 8.1 .0098 59.6 —
AFFECTED Product Versions Fixed Apache Camel 4.0.0 – —
TIMELINE May 4 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0094 58.2 —
AFFECTED Product Versions Fixed crawl4ai < 0.9.0 – —
TIMELINE Jun 24 Reserved by CNA Jul 6 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0093 57.8 —
AFFECTED Product Versions Fixed Apache Camel 4.18.0 – —
TIMELINE May 4 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H H H 8.1 .0089 56.5 —
AFFECTED Product Versions Fixed Apache Camel 4.0.0 – —
TIMELINE Apr 15 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0086 55.7 —
AFFECTED Product Versions Fixed Apache Camel Vertx Websocket 4.0.0 – —
TIMELINE May 16 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0086 55.7 —
AFFECTED Product Versions Fixed Apache Camel Atmosphere Websocket 4.0.0 – —
TIMELINE Jun 18 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0084 55.1 —
AFFECTED Product Versions Fixed Apache Camel 4.18.0 – —
TIMELINE May 15 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0083 54.7 —
AFFECTED Product Versions Fixed Apache Camel 4.0.0 – —
TIMELINE May 14 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C H H H 9.6 .0081 54.1 —
AFFECTED Product Versions Fixed crawl4ai < 0.9.0 – —
TIMELINE Jun 24 Reserved by CNA Jul 6 Public exploit reference published Jul 6 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0079 53.5 —
AFFECTED Product Versions Fixed Apache Camel 4.0.0 – —
TIMELINE May 14 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0078 53.3 —
AFFECTED Product Versions Fixed coolify < 4.0.0-beta.471 – —
TIMELINE Mar 25 Reserved by CNA Jul 6 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0076 52.7 —
AFFECTED Product Versions Fixed firmware US_AC6V2.0RTL_V15.03.06.51_multi_T – — firmware US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 – — firmware US_AC10V1.0re_V15.03.06.46_multi_TDE01 – — firmware US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE – — firmware US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD – —
TIMELINE Jun 5 Reserved by CNA Jul 6 Published (CNA: certcc)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.2 .0075 52.2 —
AFFECTED Product Versions Fixed Remote Support unspecified — Privileged Remote Access unspecified —
TIMELINE Apr 9 Reserved by CNA Jul 6 Published (CNA: BT)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0074 51.8 —
AFFECTED Product Versions Fixed Apache IoTDB 1.3.3 – —
TIMELINE Jan 20 Reserved by CNA Jul 6 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0074 51.8 —
AFFECTED Product Versions Fixed Apache Camel AWS2 SNS 4.0.0 – —
TIMELINE Jun 19 Reserved by CNA Jul 6 Published (CNA: apache)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-48204 | 9.8 | 51.5 | Apache Software Foundation | Apache Camel | CWE-20 | Apache Camel: Camel-MongoDB-GridFS: The gridfs.* control headers used non-Cam… |
| CVE-2026-11962 | 8.8 | 51.5 | Unknown | FileOrganizer | — | FileOrganizer < 1.2.0 - Authenticated Arbitrary File Upload via elFinder File… |
| CVE-2026-46587 | 7.3 | 50.1 | Apache Software Foundation | Apache Camel | CWE-20 | Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFil… |
| CVE-2026-46588 | 7.3 | 50.1 | Apache Software Foundation | Apache Camel | CWE-20 | Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilte… |
| CVE-2026-49042 | 7.3 | 50.1 | Apache Software Foundation | Apache Camel | CWE-20 | Apache Camel: langchain4j-tools: filter tool argument headers against declare… |
| CVE-2026-24014 | 9.8 | 50.0 | Apache Software Foundation | Apache IoTDB | CWE-284 | Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allo… |
| CVE-2026-46455 | 9.8 | 50.0 | Apache Software Foundation | Apache Camel | CWE-613 | Apache Camel: Camel-Keycloak: The access-token validity window is not verifie… |
| CVE-2026-14808 | 9.3 | 50.0 | PROG MIS | Prog Management System | CWE-497 | PROG MIS|Prog Management System - Exposure of Sensitive Information |
| CVE-2026-49086 | 6.5 | 49.7 | Apache Software Foundation | Apache Camel Dapr | CWE-20 | Apache Camel Dapr: Pub/Sub consumer copied the inbound CloudEvent's pub/sub-n… |
| CVE-2026-49097 | 6.5 | 49.4 | Apache Software Foundation | Apache Camel | CWE-20 | Apache Camel: Camel-IRC: The irc.sendTo (and other irc.*) Exchange header con… |
| CVE-2026-42527 | 8.1 | 49.1 | Apache Software Foundation | Apache Camel | CWE-502 | Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.**… |
| CVE-2026-5268 | 9.1 | 49.0 | CIENA | 6500 S-Series | CWE-288 | SFTP Server Authentication Weakness |
| CVE-2026-55514 | 7.1 | 49.0 | vllm-project | vllm | CWE-617 | vLLM denial of service via prompt embeds on M-RoPE models |
| CVE-2026-46457 | 7.5 | 48.8 | Apache Software Foundation | Apache Camel | CWE-20 | Apache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Ex… |
| CVE-2026-43866 | 7.3 | 48.5 | Apache Software Foundation | Apache Camel | CWE-502 | Apache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via Default… |
| CVE-2026-42153 | 8.8 | 48.4 | coollabsio | coolify | CWE-78 | Coolify: PostgreSQL Healthcheck Command Injection Allows Root Code Execution … |
| CVE-2026-42204 | 8.8 | 48.4 | coollabsio | coolify | CWE-78 | Coolify: Authenticated RCE via SHELL_SAFE_COMMAND_PATTERN regression → host root |
| CVE-2026-40140 | 8.7 | 48.3 | BeyondTrust | Remote Support | CWE-400 | High-Severity Pre-Authentication Vulnerability in BeyondTrust Remote Support … |
| CVE-2026-24013 | 9.1 | 47.7 | Apache Software Foundation | Apache IoTDB | CWE-290 | Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC |
| CVE-2026-14807 | 9.3 | 47.5 | PROG MIS | ERP App | CWE-798 | PROG MIS|ERP App - Use of Hard-coded Credentials |
| CVE-2026-46585 | 7.5 | 47.5 | Apache Software Foundation | Apache Camel Lucene | CWE-20 | Apache Camel Lucene: The query control headers used non-Camel-prefixed names … |
| CVE-2026-14792 | 6.9 | 47.4 | n/a | Formbricks | CWE-266 | Formbricks Survey actions.ts access control |
| CVE-2026-46592 | 7.5 | 47.3 | Apache Software Foundation | Apache Camel | CWE-20 | Apache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-… |
| CVE-2026-55994 | 7.5 | 47.3 | Apache Software Foundation | Apache Camel Iggy | CWE-20 | Apache Camel Iggy: The inbound consumer maps externally-supplied Iggy message… |
| CVE-2026-54234 | 7.5 | 46.8 | vllm-project | vllm | CWE-20 | vLLM: Remote DoS in vLLM via Invalid Recovered Token Reinjection |
| CVE-2025-53827 | 9.1 | 46.8 | owncloud | ownCloud Core | CWE-749 | ownCloud Core: Updater has an exposed dangerous method or function |
| CVE-2026-13708 | 7.5 | 46.5 | TONYC | Imager::File::JPEG | CWE-401 | Imager::File::JPEG versions before 1.003 for Perl leak heap memory when readi… |
| CVE-2026-38976 | 7.5 | 46.5 | n/a | n/a | CWE-476 | mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/v… |
| CVE-2026-49098 | 5.3 | 46.4 | Apache Software Foundation | Apache Camel | CWE-20 | Apache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Excha… |
| CVE-2026-48203 | 9.1 | 46.0 | Apache Software Foundation | Apache Camel | CWE-20 | Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefi… |
| CVE-2026-48205 | 9.1 | 46.0 | Apache Software Foundation | Apache Camel DNS | CWE-20 | Apache Camel DNS: The dns.* and term Exchange header constants used non-Camel… |
| CVE-2026-55574 | 8.7 | 45.2 | vllm-project | vllm | CWE-1333 | vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar… |
| CVE-2026-14471 | 8.6 | 45.2 | AWS | MCP Gateway & Registry | CWE-89 | Authenticated SQL injection in the metrics-service retention policy subsystem… |
| CVE-2026-48614 | 9.9 | 45.1 | WebPros | Plesk | CWE-94 | An improper authorization vulnerability in the Plesk XML API allows an authen… |
| CVE-2026-49365 | 5.3 | 44.8 | Apache Software Foundation | Apache Camel | CWE-209 | Apache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted t… |
| CVE-2026-56139 | 5.3 | 44.8 | Apache Software Foundation | Apache Camel Undertow | CWE-209 | Apache Camel Undertow: The muteException consumer option defaulted to false, … |
| CVE-2026-14809 | 8.7 | 44.3 | PROG MIS | Prog Management System | CWE-89 | PROG MIS|Prog Management System - SQL Injection |
| CVE-2026-46584 | 3.7 | 44.2 | Apache Software Foundation | Apache Camel Mail | CWE-20 | Apache Camel Mail: The mail producer applied attacker-supplied message header… |
| CVE-2026-4249 | 8.6 | 43.9 | WSO2 | WSO2 Universal Gateway | CWE-707 | Denial of Service via Malicious JSON Payloads in Throttling Events in Multipl… |
| CVE-2026-46453 | 5.3 | 43.6 | Apache Software Foundation | Apache Camel | CWE-639 | Apache Camel: Camel-Elasticsearch-Rest-Client: Exchange header constants with… |
| CVE-2026-48206 | 5.3 | 43.6 | Apache Software Foundation | Apache Camel JIRA | CWE-20 | Apache Camel JIRA: A set of non-Camel-prefixed Exchange header constants bypa… |
| CVE-2026-46591 | 8.2 | 43.5 | Apache Software Foundation | Apache Camel | CWE-943 | Apache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProper… |
| CVE-2026-9165 | 7.7 | 43.4 | Red Hat | Red Hat Advanced Cluster Security 4.9 | CWE-400 | Stackrox: stackrox: unbounded graphql query depth allows authenticated denial… |
| CVE-2026-58226 | 8.7 | 43.4 | elixir-mint | hpax | CWE-407 | Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpax |
| CVE-2026-9182 | 9.8 | 43.3 | Esri | ArcGIS Server | CWE-434 | Unvalidated File Upload vulnerability in ArcGIS Server. |
| CVE-2026-53647 | 6.9 | 43.2 | FOSSBilling | FOSSBilling | CWE-200 | FOSSBilling vulnerable to unauthenticated API key configuration disclosure vi… |
| CVE-2026-41899 | 6.5 | 42.9 | coollabsio | coolify | CWE-306 | Coolify unauthenticated feedback endpoint allows Discord webhook abuse |
| CVE-2026-40141 | 8.5 | 42.4 | BeyondTrust | Remote Support | CWE-943 | High-Severity Vulnerability In Web Application Component of BeyondTrust Remot… |
| CVE-2026-14803 | 6.5 | 42.4 | SRI | Mojo::JSON | CWE-674 | Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounde… |
| CVE-2026-56810 | 8.7 | 42.0 | elixir-mint | mint | CWE-770 | mint buffers an entire chunked response chunk in memory in Mint.HTTP1.decode_… |
| CVE-2026-49099 | 5.3 | 41.8 | Apache Software Foundation | Apache Camel Salesforce | CWE-74 | Apache Camel Salesforce: Non-Camel-prefixed Exchange header constants bypass … |
| CVE-2026-55646 | 6.5 | 41.8 | vllm-project | vllm | CWE-400 | vLLM speech-to-text endpoints allocate full upload before enforcing the audio… |
| CVE-2025-53829 | 8.0 | 41.2 | owncloud | ownCloud 10 | CWE-23 | ownCloud 10 is vulnerable to Relative Path Traversal |
| CVE-2026-11855 | 8.8 | 40.8 | Unknown | Simple Membership | — | Simple Membership < 4.7.5 - Unauthenticated Stored XSS via Stripe Webhook API… |
| CVE-2026-55727 | 7.5 | 40.5 | Genetec Inc. | Genetec Security Center | CWE-287 | A flaw in the authentication mechanism for video stream requests in Genetec S… |
| CVE-2024-6228 | 7.5 | 39.5 | Unknown | Notifications for Forms & WordPress Actions | — | WANotifier < 2.6 - Subscriber+ LFI |
| CVE-2026-58403 | 5.9 | 38.9 | gohugoio | hugo | CWE-59 | Hugo symlink confinement bypass in os.ReadFile |
| CVE-2026-12083 | 8.1 | 38.4 | Unknown | Admin and Site Enhancements (ASE) | — | Admin and Site Enhancements < 8.8.4 - Unauthenticated Administrator-Role Rest… |
| CVE-2025-53830 | 9.1 | 38.0 | owncloud | Anti-Virus for ownCloud | CWE-918 | Anti-Virus for ownCloud 10 is vulnerable to Server-Side Request Forgery (SSRF) |
| CVE-2026-43925 | 6.9 | 38.0 | FOSSBilling | FOSSBilling | CWE-915 | FOSSBilling: Mass assignment of group_id in guest client registration allows … |
| CVE-2026-40138 | 9.2 | 37.8 | BeyondTrust | Remote Support | CWE-287 | Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and P… |
| CVE-2026-13753 | 7.5 | 37.8 | HP Inc. | HP 2800 Printer Series | — | CVE-2026-13753 |
| CVE-2026-59712 | 8.6 | 37.1 | Leantime | Leantime | CWE-639 | Leantime - JSON-RPC API Broken Access Control via users.getUser |
| CVE-2026-57573 | 8.6 | 36.9 | unclecode | crawl4ai | CWE-918 | Crawl4AI unauthenticated SSRF in Docker streaming crawl endpoint |
| CVE-2026-14468 | 7.7 | 36.7 | HashiCorp | Terraform Enterprise | CWE-22 | Path traversal allows arbitrary file read in Terraform Enterprise container |
| CVE-2026-53641 | 4.8 | 36.7 | FOSSBilling | FOSSBilling | CWE-79 | FOSSBilling has stored XSS in client email views via unescaped content in Jav… |
| CVE-2026-7185 | 6.0 | 36.2 | T-Systems | Archivo | CWE-22 | Unauthorized access to files in T-Systems products |
| CVE-2026-10830 | 8.8 | 35.7 | Unknown | AllCoach | — | AllCoach < 1.0.2 - Unauthenticated Account Takeover |
| CVE-2026-14536 | 8.8 | 35.5 | Devolutions | Server | CWE-863 | Improper enforcement of a mandatory multi-factor authentication policy in Dev… |
| CVE-2026-43921 | 8.9 | 35.1 | FOSSBilling | FOSSBilling | CWE-94 | FOSSBilling vulnerable to arbitrary PHP code injection via unescaped config s… |
| CVE-2026-44937 | 8.3 | 35.1 | SUSE | Rancher | CWE-918 | SUSE Rancher Fleet had an Unauthenticated Webhook: Regex Injection via Unsani… |
| CVE-2026-43928 | 2.3 | 35.1 | FOSSBilling | FOSSBilling | CWE-754 | FOSSBilling: Payment amount not validated in PayPalEmail adapter allows invoi… |
| CVE-2026-55379 | 7.5 | 34.9 | python-pillow | Pillow | CWE-789 | Pillow BdfFontFile`: `Image.new()` called without `_decompression_bomb_check(… |
| CVE-2026-42331 | 7.7 | 34.6 | FOSSBilling | FOSSBilling | CWE-306 | FOSSBilling missing authorization in guest Invoice API endpoints |
| CVE-2026-54060 | 7.5 | 34.6 | python-pillow | Pillow | CWE-789 | Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bo… |
| CVE-2026-55380 | 7.5 | 34.6 | python-pillow | Pillow | CWE-789 | Pillow GdImageFile decompression bomb protection bypass |
| CVE-2026-11766 | 8.0 | 34.1 | Unknown | Ultimate Member | — | Ultimate Member < 2.12.0 - Subscriber+ Stored XSS via Custom Textarea Profile… |
| CVE-2026-50135 | 6.9 | 33.9 | gohugoio | hugo | CWE-59 | Hugo: Symlink confinement bypass in resources.Get |
| CVE-2026-54059 | 7.5 | 33.8 | python-pillow | Pillow | CWE-789 | Pillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_de… |
| CVE-2026-53648 | 5.1 | 33.8 | FOSSBilling | FOSSBilling | CWE-73 | FOSSBilling: Downloadable product files can be overwritten through filename c… |
| CVE-2026-59195 | 8.2 | 33.0 | pnpm | pnpm | CWE-22 | pnpm: Path traversal in configDependencies env lockfile allows symlink creati… |
| CVE-2026-59194 | 7.1 | 33.0 | pnpm | pnpm | CWE-22 | pnpm: patch-remove could delete project-selected files outside the patches di… |
| CVE-2026-59196 | 7.1 | 33.0 | pnpm | pnpm | CWE-22 | pnpm: hoisted install imports lockfile alias outside node_modules |
| CVE-2026-14784 | 5.3 | 32.7 | vxcontrol | PentAGI | CWE-264 | vxcontrol PentAGI Docker API client.go sandbox |
| CVE-2026-50134 | 6.3 | 32.4 | gohugoio | hugo | CWE-918 | Hugo: security.http.urls allow-list bypass via HTTP redirects |
| CVE-2025-53828 | 8.5 | 32.1 | owncloud | SharePoint | CWE-918 | SharePoint for ownCloud 10 is vulnerable to Server-Side Request Forgery (SSRF) |
| CVE-2026-53644 | 8.6 | 31.7 | FOSSBilling | FOSSBilling | CWE-639 | FOSSBilling's missing order-state validation allows clients to read and reset… |
| CVE-2026-14793 | 5.3 | 31.4 | Craft | CMS | CWE-285 | Craft CMS reorder-sets Endpoint GlobalsController.php actionReorderSets autho… |
| CVE-2026-14794 | 5.3 | 31.3 | Craft | CMS | CWE-266 | Craft CMS Charts Endpoint ChartsController.php actionGetNewUsersData improper… |
| CVE-2026-32718 | 6.5 | 30.3 | coollabsio | coolify | CWE-863 | Coolify read-scoped API tokens can perform state-changing validation operations |
| CVE-2026-34050 | 6.5 | 30.3 | coollabsio | coolify | CWE-862 | Coolify Settings/Updates Livewire component missing instance administrator au… |
| CVE-2026-14898 | 6.5 | 30.1 | OpenAI | Codex desktop app for macOS | CWE-200 | The OpenAI Codex desktop app for macOS rendered remote images from Markdown i… |
| CVE-2026-12686 | 9.3 | 29.9 | Adiss | Biloop | CWE-639 | Incorrect authorisation in Adiss’s Biloop |
| CVE-2026-53645 | 8.5 | 29.9 | FOSSBilling | FOSSBilling | CWE-269 | FOSSBilling's missing self-edit prevention in staff permission management all… |
| CVE-2026-33734 | 6.9 | 29.5 | FOSSBilling | FOSSBilling | CWE-89 | FOSSBilling has improper SQL neutralization in `Massmailer` recipient filters |
| CVE-2026-58404 | 4.6 | 29.4 | gohugoio | hugo | CWE-918 | Hugo security.http.urls deny rules bypassed by alternate IPv4 encodings |
| CVE-2026-43918 | 8.7 | 29.1 | FOSSBilling | FOSSBilling | CWE-613 | Suspended or inactive FOSSBilling accounts can retain or regain access throug… |
| CVE-2026-53643 | 8.7 | 27.7 | FOSSBilling | FOSSBilling | CWE-200 | FOSSBilling allows low-privileged staff accounts to perform unauthorized acti… |
| CVE-2026-53642 | 5.3 | 27.7 | FOSSBilling | FOSSBilling | CWE-863 | FOSSBilling: Unverified clients can access client-area pages when email confi… |
| CVE-2026-53640 | 2.3 | 27.7 | FOSSBilling | FOSSBilling | CWE-200 | FOSSBilling missing authorization checks on read-only admin API endpoints exp… |
| CVE-2026-44936 | 5.0 | 27.3 | SUSE | Rancher | CWE-918 | Rancher Fleet SSRF in Bundle Reader via Unvalidated Helm Repository URL in fl… |
| CVE-2026-14791 | 2.0 | 27.4 | crater-invoice-inc | crater | CWE-79 | crater-invoice-inc crater Invoice Note InvoicesRequest.php getFormattedString… |
| CVE-2026-34167 | 5.0 | 26.7 | coollabsio | coolify | CWE-639 | Coolify: Cross-tenant activity log disclosure via unlocked Livewire property … |
| CVE-2026-59710 | 5.3 | 26.2 | showdown | showdown | CWE-79 | showdown - Stored XSS via Unescaped Table Header ID Attribute Injection |
| CVE-2026-14795 | 2.1 | 25.7 | CodeAstro | Apartment Visitor Management System | CWE-74 | CodeAstro Apartment Visitor Management System action-visitor.php sql injection |
| CVE-2026-14796 | 2.1 | 25.7 | CodeAstro | Apartment Visitor Management System | CWE-74 | CodeAstro Apartment Visitor Management System report.php sql injection |
| CVE-2026-14797 | 2.1 | 25.7 | CodeAstro | Apartment Visitor Management System | CWE-74 | CodeAstro Apartment Visitor Management System edit-apartment.php sql injection |
| CVE-2026-14798 | 2.1 | 25.7 | CodeAstro | Apartment Visitor Management System | CWE-74 | CodeAstro Apartment Visitor Management System visitor-entry.php sql injection |
| CVE-2026-14799 | 2.1 | 25.7 | CodeAstro | Ecommerce Website | CWE-74 | CodeAstro Ecommerce Website my_account.php sql injection |
| CVE-2026-12154 | 6.4 | 25.5 | widgetpack | Reviews Widgets for Google, TripAdvisor, Yelp & Recommendations | CWE-79 | Reviews Widgets for Google, Yelp & TripAdvisor <= 2.7.3 - Authenticated (Cont… |
| CVE-2026-43927 | 6.9 | 25.4 | FOSSBilling | FOSSBilling | CWE-367 | FOSSBilling has race condition in cart checkout that bypasses promo code usag… |
| CVE-2026-59711 | 5.3 | 25.0 | showdown | showdown | CWE-79 | showdown - Cross-Site Scripting via Unescaped Metadata Title in completeHTMLD… |
| CVE-2026-50133 | 5.1 | 25.0 | gohugoio | hugo | CWE-79 | Hugo: XSS via text/html content files |
| CVE-2026-53646 | 7.7 | 23.5 | FOSSBilling | FOSSBilling | CWE-640 | FOSSBilling: Client password reset token reuse allows persistent account take… |
| CVE-2026-13698 | 6.0 | 23.5 | OpenVPN | OpenVPN | CWE-401 | A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 a… |
| CVE-2026-34049 | 3.3 | 23.2 | coollabsio | coolify | CWE-78 | Coolify: Command Injection via unsanitized MongoDB collection names in databa… |
| CVE-2026-1433 | 4.8 | 22.6 | NT-ware | uniFLOW ULM (Universal Login Manager) Standalone | CWE-522 | uniFLOW Universal Login Manager (ULM) Standalone Improper Protection of Sensi… |
| CVE-2026-58402 | 5.1 | 22.0 | gohugoio | hugo | CWE-79 | Hugo default code block renderer XSS via unescaped code-fence language |
| CVE-2026-59089 | 5.5 | 21.6 | — | gimp | CWE-190 | Gimp: gimp: denial of service via integer overflow in playstation tim loader |
| CVE-2026-13122 | 5.9 | 21.3 | Openvpn | OpenVPN | CWE-617 | OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remo… |
| CVE-2026-54764 | 6.9 | 20.0 | traefik | traefik | CWE-345 | ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwar… |
| CVE-2025-53831 | 8.2 | 19.5 | owncloud | DrawIO for ownCloud | CWE-79 | DrawIO for ownCloud 10 is vulnerable to Stored XSS |
| CVE-2026-54765 | 6.3 | 19.5 | traefik | traefik | CWE-284 | Traefik: Gateway HTTPRoute backendRef filters can leak backend context across… |
| CVE-2026-42341 | 9.2 | 19.1 | FOSSBilling | FOSSBilling | CWE-306 | FOSSBilling has an unauthenticated payment bypass via IPN callback forgery |
| CVE-2026-38979 | 5.4 | 18.8 | n/a | n/a | CWE-1021 | ajenti through v2.2.13 has a clickjacking weakness in the browser-facing logi… |
| CVE-2026-58380 | 7.8 | 17.0 | Red Hat | Red Hat Enterprise Linux 9 | CWE-193 | Gimp: gimp: stack buffer overflow in pnmscanner_gettoken() |
| CVE-2025-8591 | 6.1 | 16.4 | WSO2 | WSO2 Identity Server | CWE-79 | Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products En… |
| CVE-2026-54291 | 8.2 | 14.4 | pgjdbc | pgjdbc | CWE-636 | Silent channel-binding authentication downgrade via unsupported certificate a… |
| CVE-2026-59713 | 8.6 | 14.1 | Leantime | Leantime | CWE-352 | Leantime - OIDC Login CSRF via Unconditional State Verification Stub |
| CVE-2026-48267 | 5.5 | 14.1 | Adobe | DNG SDK | CWE-476 | DNG SDK | NULL Pointer Dereference (CWE-476) |
| CVE-2026-14800 | 2.1 | 13.6 | imhamzaazam | ecommerceFlask | CWE-352 | imhamzaazam ecommerceFlask cross-site request forgery |
| CVE-2026-6900 | 9.1 | 12.6 | B&R Industrial Automation GmbH | APROL | CWE-295 | Improper Certificate Validation |
| CVE-2026-14789 | 1.9 | 12.5 | radareorg | radare2 | CWE-119 | radareorg radare2 Memory64ListStream mdmp.c stack-based overflow |
| CVE-2026-13356 | 6.3 | 12.2 | Mozilla | Firefox for iOS | CWE-451 | Interrupted navigation could allow address bar origin spoofing in Firefox for… |
| CVE-2026-54763 | 7.8 | 10.7 | traefik | traefik | CWE-178 | Traefik: headerField underscore-variant identity spoofing in BasicAuth / Dige… |
| CVE-2026-14787 | 1.9 | 10.4 | radareorg | radare2 | CWE-189 | radareorg radare2 pb Print cmd_print.inc cmd_print integer overflow |
| CVE-2026-54893 | 2.1 | 10.2 | swoosh | swoosh | CWE-116 | Email-derived URL path injection in the Swoosh Microsoft Graph adapter |
| CVE-2026-14788 | 1.9 | 9.7 | radareorg | radare2 | CWE-119 | radareorg radare2 cfile.c r_core_bin_load use after free |
| CVE-2026-59152 | 5.0 | 9.6 | langchain-ai | langsmith-sdk | CWE-22 | Arbitrary server-side file read in LangSmith SDK TracingMiddleware |
| CVE-2026-53763 | 3.8 | 9.1 | OP-TEE | optee_os | CWE-190 | OP-TEE has AES-GCM 32-bit integer overflow in length counters that breaks aut… |
| CVE-2026-14786 | 1.9 | 8.6 | radareorg | radare2 | CWE-189 | radareorg radare2 str.c r_str_word_get0set integer overflow |
| CVE-2026-58203 | 5.3 | 8.0 | pydantic | pydantic-settings | CWE-22 | NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling lo… |
| CVE-2026-55798 | 4.5 | 7.4 | python-pillow | Pillow | CWE-78 | Pillow: WindowsViewer.get_command() OS command injection via unescaped shell … |
| CVE-2026-44362 | 5.5 | 7.4 | OP-TEE | optee_os | CWE-285 | OP-TEE's subkey rollback protection can be bypassed with older subkey versions |
| CVE-2026-13705 | 7.1 | 6.9 | TONYC | Imager | CWE-125 | Imager versions before 1.032 for Perl have a heap out-of-bounds read in the b… |
| CVE-2025-15668 | 1.9 | 6.7 | n/a | GPAC | CWE-119 | GPAC MP4Box box_code_base.c sgpd_del_entry heap-based overflow |
| CVE-2026-38973 | 4.4 | 5.8 | n/a | n/a | CWE-125 | mrubyc through release3.4.1 was found to contain an out-of-bounds read in bui… |
| CVE-2026-6901 | 8.4 | 5.5 | B&R Industrial Automation GmbH | APROL | CWE-426 | Untrusted Search Path |
| CVE-2024-56141 | 5.0 | 5.3 | Bixilon | Minosoft | CWE-329 | Minosoft has IV equal to key |
| CVE-2026-14801 | 4.8 | 5.3 | n/a | GPAC | CWE-369 | GPAC TeXML File load_text.c txtin_probe_duration divide by zero |
| CVE-2025-15667 | 1.9 | 5.3 | n/a | GPAC | CWE-119 | GPAC MP4Box avc_ext.c gf_isom_nalu_sample_rewrite double free |
| CVE-2026-14790 | 1.9 | 5.3 | n/a | GPAC | CWE-404 | GPAC Media File write_nhml.c nhmldump_send_frame null pointer dereference |
| CVE-2026-42148 | 3.8 | 5.1 | coollabsio | coolify | CWE-78 | Coolify: Command Injection via Unescaped Version String in Docker Build |
| CVE-2026-40257 | 5.5 | 4.7 | OP-TEE | optee_os | CWE-787 | OP-TEE has SHA-3 accelerated finalize heap overflow |
| CVE-2026-44934 | 7.0 | 4.6 | SUSE | Rancher | CWE-215 | Exposed tokens in SUSE Rancher AI Agent logs |
| CVE-2026-42546 | 3.8 | 4.5 | OP-TEE | optee_os | CWE-770 | OP-TEE has missing OPTEE_MSG_ATTR_TYPE_MASK in cleanup_shm_refs() leaks mobj … |
| CVE-2026-41434 | 3.3 | 4.5 | OP-TEE | optee_os | CWE-121 | OP-TEE has unbounded recursion in sanitize_client_object() |
| CVE-2026-41516 | 3.3 | 3.4 | OP-TEE | optee_os | CWE-208 | OP-TEE: Hisilicon HPRE PKCS#1 v1.5 Decryption Padding Oracle |
| CVE-2026-41514 | 3.3 | 3.1 | OP-TEE | optee_os | CWE-208 | OP-TEE: RSA-OAEP padding oracle in Hisilicon HPRE driver enables plaintext re… |
| CVE-2026-41515 | 3.3 | 3.1 | OP-TEE | optee_os | CWE-208 | OP-TEE: RSA-OAEP padding oracle in NXP CAAM driver enables plaintext recovery |
| CVE-2026-25268 | 8.8 | 1.1 | Qualcomm, Inc. | Snapdragon | CWE-121 | Stack-based Buffer Overflow in WLAN Host |
| CVE-2026-21379 | 7.8 | 1.1 | Qualcomm, Inc. | Snapdragon | CWE-126 | Buffer Over-read in Windows Compute |
| CVE-2026-21383 | 7.1 | 1.0 | Qualcomm, Inc. | Snapdragon | CWE-323 | Reusing a Nonce, Key Pair in Encryption in HLOS |
| CVE-2025-59615 | 7.8 | 0.4 | Qualcomm, Inc. | Snapdragon | CWE-416 | Use After Free in Computer Vision |
| CVE-2025-59616 | 7.8 | 0.4 | Qualcomm, Inc. | Snapdragon | CWE-416 | Use After Free in Computer Vision |
| CVE-2025-59617 | 7.3 | 0.4 | Qualcomm, Inc. | Snapdragon | CWE-416 | Use After Free in Computer Vision |
| CVE-2026-21368 | 5.3 | 0.2 | Qualcomm, Inc. | Snapdragon | CWE-787 | Out-of-bounds Write in Camera Driver |
| CVE-2026-21369 | 5.3 | 0.2 | Qualcomm, Inc. | Snapdragon | CWE-787 | Out-of-bounds Write in Camera Driver |
| CVE-2026-21370 | 5.3 | 0.2 | Qualcomm, Inc. | Snapdragon | CWE-787 | Out-of-bounds Write in Camera Driver |
| CVE-2026-21384 | 5.3 | 0.2 | Qualcomm, Inc. | Snapdragon | CWE-787 | Out-of-bounds Write in Camera Driver |
| CVE-2026-25271 | 7.0 | 0.1 | Qualcomm, Inc. | Snapdragon | CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition in DSP Service |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-06 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.