AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .4239 98.6 YES
AFFECTED Product Versions Fixed ColdFusion unspecified —
TIMELINE May 21 Reserved by CNA Jul 7 Added to CISA KEV, due Jul 10 Jul 7 Published (CNA: adobe)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
170 CVEs published, led by coollabsio (21).
170 CVEs published July 7, 2026: 25 critical, 70 high, 64 medium, 11 low; 4 in the KEV catalog at press time; 7 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 145 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 1331 | 13734 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
600 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 37 | 1517 | 120 | 866 | 530 | 1 | 11 | 2 | 0.1 | 7.5 | .0014 | +4 ▲ |
| 52 | 1317 | 148 | 590 | 542 | 37 | 77 | 6 | 0.5 | 7.8 | .0024 | -436 ▼ | |
| microsoft | 50 | 807 | 61 | 552 | 188 | 6 | 286 | 20 | 2.5 | 7.8 | .0046 | +43 ▲ |
| red hat | 27 | 249 | 12 | 99 | 123 | 15 | 2 | 0 | 0.0 | 6.5 | .0030 | +8 ▲ |
| apple | 0 | 104 | 2 | 28 | 72 | 2 | 88 | 7 | 6.7 | 6.5 | .0032 | 0 |
| canonical | 0 | 20 | 2 | 5 | 8 | 5 | 0 | 0 | 0.0 | 5.5 | .0011 | 0 |
| suse | 6 | 19 | 4 | 11 | 4 | 0 | 0 | 0 | 0.0 | 8.6 | .0042 | +6 ▲ |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ubiquiti | 25 | 36 | 14 | 21 | 1 | 0 | 3 | 3 | 8.3 | 8.8 | .0049 | +25 ▲ |
| cisco | 8 | 30 | 6 | 14 | 10 | 0 | 56 | 11 | 36.7 | 7.5 | .0057 | +6 ▲ |
| netgear | 0 | 17 | 0 | 0 | 16 | 1 | 0 | 0 | 0.0 | 4.3 | .0024 | 0 |
| palo alto networks | 0 | 11 | 1 | 2 | 7 | 1 | 13 | 2 | 18.2 | 5.9 | .0022 | 0 |
| checkpoint | 0 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | 0 |
| fortinet | 0 | 9 | 4 | 3 | 2 | 0 | 28 | 3 | 33.3 | 8.3 | .0076 | 0 |
| ivanti | 0 | 9 | 4 | 5 | 0 | 0 | 25 | 5 | 55.6 | 8.8 | .5187 | -1 ▼ |
| f5 | 0 | 8 | 4 | 3 | 1 | 0 | 4 | 1 | 12.5 | 8.9 | .0225 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 50 | 205 | 37 | 79 | 77 | 11 | 33 | 1 | 0.5 | 7.3 | .0057 | +18 ▲ |
| mozilla | 3 | 59 | 12 | 18 | 29 | 0 | 9 | 0 | 0.0 | 7.3 | .0025 | -1 ▼ |
| gitlab | 0 | 31 | 0 | 5 | 21 | 5 | 4 | 2 | 6.5 | 4.4 | .0029 | 0 |
| github | 1 | 7 | 1 | 1 | 5 | 0 | 0 | 0 | 0.0 | 6.0 | .0039 | +1 ▲ |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.2 | .0016 | -2 ▼ |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 4 | 1 | 20.0 | 5.1 | .0026 | 0 |
| wordpress | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 270 | 132 | 116 | 18 | 4 | 27 | 2 | 0.7 | 8.8 | .0040 | 0 |
| adobe | 3 | 147 | 13 | 53 | 79 | 2 | 19 | 3 | 2.0 | 6.1 | .0021 | +3 ▲ |
| ibm | 0 | 124 | 36 | 42 | 46 | 0 | 6 | 0 | 0.0 | 7.5 | .0034 | -5 ▼ |
| progress | 2 | 11 | 1 | 9 | 1 | 0 | 6 | 0 | 0.0 | 7.5 | .0036 | -3 ▼ |
| solarwinds | 0 | 7 | 2 | 3 | 2 | 0 | 10 | 4 | 57.1 | 7.5 | .4001 | -2 ▼ |
| veeam | 0 | 4 | 2 | 2 | 0 | 0 | 1 | 0 | 0.0 | 9.0 | .0052 | 0 |
| zohocorp | 0 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 0 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -5 ▼ |
| d-link | 0 | 12 | 0 | 5 | 2 | 5 | 3 | 0 | 0.0 | 5.8 | .0058 | -5 ▼ |
| siemens | 0 | 9 | 0 | 4 | 5 | 0 | 0 | 0 | 0.0 | 6.9 | .0021 | -1 ▼ |
| rockwell automation | 0 | 7 | 1 | 5 | 1 | 0 | 0 | 0 | 0.0 | 8.7 | .0030 | 0 |
| abb | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -4 ▼ |
| schneider electric | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0042 | 0 |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | 0 |
| dahua | 0 | 3 | 0 | 1 | 1 | 1 | 0 | 0 | 0.0 | 6.9 | .0036 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 27 | 98 | 0 | 0 | 52 | 46 | 0 | 0 | 0.0 | 5.5 | .0029 | +5 ▲ |
| dell | 23 | 79 | 4 | 35 | 38 | 2 | 2 | 1 | 1.3 | 6.7 | .0019 | +20 ▲ |
| spring | 0 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | -2 ▼ |
| openclaw | 0 | 67 | 0 | 35 | 22 | 10 | 0 | 0 | 0.0 | 7.0 | .0021 | 0 |
| edimax | 0 | 65 | 0 | 39 | 0 | 26 | 1 | 0 | 0.0 | 7.4 | .0080 | 0 |
| itsourcecode | 10 | 63 | 0 | 0 | 19 | 44 | 0 | 0 | 0.0 | 2.1 | .0033 | -9 ▼ |
| capgo | 0 | 61 | 2 | 31 | 27 | 1 | 0 | 0 | 0.0 | 7.1 | .0039 | 0 |
| themerex | 2 | 60 | 5 | 54 | 1 | 0 | 0 | 0 | 0.0 | 8.1 | .0043 | +2 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-10520 | .9991 | 100.0 | 10.0 |
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-35273 | .9547 | 99.9 | 9.8 |
| CVE-2026-20230 | .8820 | 99.8 | 8.6 |
| CVE-2026-34910 | .8747 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-50751 | .8377 | 99.7 | 9.3 |
| CVE-2026-48907 | .7810 | 99.5 | 10.0 |
| CVE-2026-45659 | .7608 | 99.5 | 8.8 |
| CVE-2026-34909 | .6390 | 99.2 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-10520 | 10.0 | .9991 | KEV |
| CVE-2026-34910 | 10.0 | .8747 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-48907 | 10.0 | .7810 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-48282 | 10.0 | .4239 | KEV |
| CVE-2026-56290 | 10.0 | .3038 | KEV |
| CVE-2026-48908 | 10.0 | .1482 | KEV |
| CVE-2026-13773 | 10.0 | .0610 | |
| CVE-2026-56415 | 10.0 | .0436 |
| Vendor | CVEs |
|---|---|
| 654 | |
| linux | 517 |
| microsoft | 264 |
| oracle | 242 |
| adobe | 145 |
| apache | 139 |
| red hat | 136 |
| ibm | 70 |
| spring | 70 |
| capgo | 61 |
| Vendor | KEV |
|---|---|
| microsoft | 20 |
| cisco | 11 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| fortinet | 3 |
| smartertools | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 68 |
| Packagist | 15 |
| npm | 7 |
| PyPI | 6 |
| NuGet | 3 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-10520 | ivanti | 0 |
| CVE-2026-11645 | 0 | |
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-20245 | Cisco | 0 |
| CVE-2026-20253 | Splunk | 0 |
| CVE-2026-20262 | Cisco | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE-2026-34909 | Ubiquiti Inc | 0 |
| CVE-2026-34910 | Ubiquiti Inc | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1693 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1693 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1693 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1693 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1693 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1693 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1693 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1693 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1693 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1693 |
EXPLOIT PUBLISHED — CVE-2026-10659 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-49471 (oraios serena). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55255 (langflow-ai langflow). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55490 (openwrt). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56290 (JoomlaCK.fr Page Builder CK extension for Joomla). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56812 (phoenixframework phoenix). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58384 (Red Hat Enterprise Linux 9). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58583 (FluxInk Color Management Driver). Public exploit reference added.
How to read these box scores · glossary
170 CVEs published. 25 box scores, 145 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .4239 98.6 YES
AFFECTED Product Versions Fixed ColdFusion unspecified —
TIMELINE May 21 Reserved by CNA Jul 7 Added to CISA KEV, due Jul 10 Jul 7 Published (CNA: adobe)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .3038 98.1 YES
AFFECTED Product Versions Fixed JoomlaCK.fr Page Builder CK extension for Joomla 1.0-3.6.0 – —
TIMELINE Jun 20 Reserved by CNA Jul 7 Public exploit reference published Jul 7 Added to CISA KEV, due Jul 10 Jul 7 Published (CNA: Joomla)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .1482 96.4 YES
AFFECTED Product Versions Fixed SP Page Builder extension for Joomla 1.0.0-6.6.1 – —
TIMELINE May 26 Reserved by CNA Jul 7 Added to CISA KEV, due Jul 10 Jul 7 Published (CNA: Joomla)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N C H H L 8.4 .0089 56.5 YES
AFFECTED Product Versions Fixed langflow < 1.9.1 – —
TIMELINE Jun 16 Reserved by CNA Jul 7 Public exploit reference published Jul 7 Added to CISA KEV, due Jul 10 Jul 7 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0264 84.4 —
AFFECTED Product Versions Fixed coder < 2.29.7 – —
TIMELINE May 6 Reserved by CNA Jul 7 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.2 .0204 79.7 —
AFFECTED Product Versions Fixed 9router unspecified 0.4.44
TIMELINE Jul 7 Reserved by CNA Jul 7 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0197 78.9 —
AFFECTED Product Versions Fixed PowerProtect Data Domain unspecified —
TIMELINE Jun 9 Reserved by CNA Jul 7 Published (CNA: dell)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0165 74.7 —
AFFECTED Product Versions Fixed Apache Airflow unspecified —
TIMELINE Mar 18 Reserved by CNA Jul 7 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0139 70.3 —
AFFECTED Product Versions Fixed WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell unspecified —
TIMELINE Jul 1 Reserved by CNA Jul 7 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0123 66.5 —
AFFECTED Product Versions Fixed Vtiger CRM unspecified —
TIMELINE Jan 14 Reserved by CNA Jul 7 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U H H H 7.5 .0102 60.9 —
AFFECTED Product Versions Fixed AMP for WP – Accelerated Mobile Pages unspecified —
TIMELINE Apr 10 Reserved by CNA Jul 7 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0100 60.1 —
AFFECTED Product Versions Fixed Vtiger CRM unspecified 8.4.0
TIMELINE Jan 14 Reserved by CNA Jul 7 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0089 56.7 —
AFFECTED Product Versions Fixed coolify < 4.0.0-beta.474 – —
TIMELINE Apr 25 Reserved by CNA Jul 7 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0080 54.0 —
AFFECTED Product Versions Fixed mem0 unspecified —
TIMELINE Jul 6 Reserved by CNA Jul 7 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0080 53.7 —
AFFECTED Product Versions Fixed coolify < 4.0.0-beta.471 – —
TIMELINE Mar 25 Reserved by CNA Jul 7 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0080 53.7 —
AFFECTED Product Versions Fixed dataease < 2.10.24 – —
TIMELINE Jun 16 Reserved by CNA Jul 7 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0078 53.3 —
AFFECTED Product Versions Fixed coolify < 4.0.0-beta.466 – —
TIMELINE Mar 25 Reserved by CNA Jul 7 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0078 53.3 —
AFFECTED Product Versions Fixed coolify < 4.0.0-beta.471 – —
TIMELINE Mar 25 Reserved by CNA Jul 7 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0078 53.3 —
AFFECTED Product Versions Fixed coolify < 4.0.0-beta.471 – —
TIMELINE Apr 24 Reserved by CNA Jul 7 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N N N L 6.3 .0078 53.1 —
AFFECTED Product Versions Fixed phoenix 1.2.0-rc.0 – — phoenix 1.2.0-rc.0 – — phoenix 2270aaf21bd02c6a6a1022820564efb605a97655 – 7f7b971c1ea0994e3fbd1c11ddb05e780bd38ad8
TIMELINE Jun 23 Reserved by CNA Jul 7 Public exploit reference published Jul 7 Published (CNA: EEF)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0077 53.0 —
AFFECTED Product Versions Fixed Module::Load unspecified —
TIMELINE Jul 5 Reserved by CNA Jul 7 Published (CNA: CPANSec)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0076 52.4 —
AFFECTED Product Versions Fixed phoenix 0.11.0 – — phoenix 14a297e88023cb280a577962a49a0bbdeef9f4eb – c498ba8cf49f6accbbd0c643a5340b58db891218
TIMELINE Jun 23 Reserved by CNA Jul 7 Published (CNA: EEF)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0071 50.8 —
AFFECTED Product Versions Fixed coolify < 4.0.0-beta.471 – —
TIMELINE Mar 25 Reserved by CNA Jul 7 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0068 49.7 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA Jul 7 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV A L N N U N N H 6.5 .0068 49.7 —
AFFECTED Product Versions Fixed openwrt < 25.12.5 – —
TIMELINE Jun 16 Reserved by CNA Jul 7 Public exploit reference published Jul 7 Published (CNA: GitHub_M)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-14476 | 8.0 | 49.2 | Red Hat | Red Hat Enterprise Linux 10 | CWE-23 | Sssd: sssd: gpo cache path traversal via unsanitized gpcfilesyspath allows ke… |
| CVE-2026-48828 | 6.5 | 49.0 | Apache Software Foundation | Apache Airflow | CWE-200 | Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact… |
| CVE-2026-48892 | 6.5 | 49.0 | Apache Software Foundation | Apache Airflow | CWE-200 | Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypa… |
| CVE-2026-49487 | 6.5 | 49.0 | Apache Software Foundation | Apache Airflow | CWE-200 | Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs |
| CVE-2026-34158 | 8.8 | 48.4 | coollabsio | coolify | CWE-78 | Coolify: Command injection via single-quote breakout in Docker Compose custom… |
| CVE-2026-34058 | 8.8 | 48.4 | coollabsio | coolify | CWE-78 | Coolify: OS Command Injection via Unmanaged Container Operations - Remote Cod… |
| CVE-2026-34152 | 8.8 | 48.4 | coollabsio | coolify | CWE-78 | Coolify: Command Injection via Newline in Pre/Post Deployment Commands (Hered… |
| CVE-2026-53729 | 8.7 | 48.0 | dataease | dataease | CWE-639 | DataEase ExportCenter IDOR allows cross-user export task access |
| CVE-2026-37271 | 9.8 | 48.0 | n/a | n/a | CWE-287 | Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Imp… |
| CVE-2026-48891 | 4.3 | 47.7 | Apache Software Foundation | Apache Airflow | CWE-200 | Apache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identi… |
| CVE-2026-53481 | 9.8 | 47.5 | Dell | PowerProtect Data Domain | CWE-22 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release … |
| CVE-2026-14895 | 7.5 | 47.4 | BAKERSCOT | String::Util | CWE-1333 | String::Util versions before 1.36 for Perl are susceptible to a regular expre… |
| CVE-2026-34035 | 8.8 | 47.4 | coollabsio | coolify | CWE-78 | Coolify: Host RCE via Log Drain secret/env command injection |
| CVE-2026-34057 | 8.8 | 47.4 | coollabsio | coolify | CWE-78 | Coolify: Authenticated Remote Code Execution via Command Injection in Databas… |
| CVE-2026-11610 | 8.8 | 47.3 | 389ds | 389-ds-base | CWE-122 | 389-ds-base: 389-ds-base: heap buffer overflow in sasl_io_recv() via padded s… |
| CVE-2026-53483 | 9.8 | 47.3 | Dell | PowerProtect Data Domain | CWE-287 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release … |
| CVE-2026-55077 | 7.2 | 46.7 | coder | coder | CWE-285 | Coder: User-admin role can reset owner account password |
| CVE-2026-55079 | 6.5 | 46.5 | coder | coder | CWE-789 | Coder's unbounded memory allocation in provisioner file upload allows authent… |
| CVE-2026-55078 | 6.5 | 46.1 | coder | coder | CWE-409 | Coder: Zip upload decompression lacks aggregate size limit, enabling denial o… |
| CVE-2026-57867 | 8.8 | 46.0 | MicroRealEstate | MicroRealEstate | CWE-288 | MicroRealEstate allows adversaries to bypass authentication due to a lack of … |
| CVE-2026-53751 | 8.7 | 45.9 | dataease | dataease | CWE-94 | DataEase: H2 JDBC URL Filter Bypass Leads to Remote Code Execution (RCE) |
| CVE-2026-51937 | 7.5 | 45.8 | n/a | n/a | CWE-306 | An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive infor… |
| CVE-2026-59708 | 8.7 | 45.7 | ghostfolio | ghostfolio | CWE-862 | Ghostfolio - Unauthorized Portfolio Data Exposure via Public Endpoint |
| CVE-2026-14904 | 7.1 | 44.6 | AWS | res | CWE-59 | RES Auth.GetUserPrivateKey Arbitrary File Read |
| CVE-2026-14474 | 8.8 | 44.5 | Red Hat | Red Hat Enterprise Linux 10 | CWE-1188 | Sssd: sssd: sudo ldap provider searches entire directory tree for sudorole ob… |
| CVE-2026-55434 | 6.5 | 43.6 | coder | coder | CWE-770 | Coder vulnerable to denial of service via unbounded request body in AI Bridge… |
| CVE-2026-12375 | 9.8 | 43.3 | Unknown | uncanny-automator-pro | — | Uncanny Automator Pro 7.3.0.5 - Backdoor via Compromised Vendor Update Server |
| CVE-2026-57871 | 7.1 | 43.0 | MicroRealEstate | MicroRealEstate | CWE-23 | Relative path traversal vulnerability in MicroRealEstate file upload function… |
| CVE-2026-54607 | 7.7 | 42.0 | labring | FastGPT | CWE-918 | FastGPT: SSRF in HTTP-tool OpenAPI schema importer via SwaggerParser $ref (by… |
| CVE-2026-13696 | 8.8 | 41.7 | HAVELSAN Inc. | Liman MYS | CWE-90 | LDAP Injection in HAVELSAN's Liman MYS |
| CVE-2026-58473 | 9.3 | 41.2 | topoteretes | cognee | CWE-306 | Cognee < 1.2.0 Unauthorized LLM Configuration Overwrite via /api/v1/settings |
| CVE-2026-50529 | 8.7 | 40.3 | dataease | dataease | CWE-863 | DataEase: Link Token Leakage Prior to Share Password/Ticket Validation |
| CVE-2026-14940 | 5.3 | 39.7 | Red Hat | Red Hat Directory Server 11 | CWE-122 | 389-ds-base: 389-ds-base: heap-buffer-overflow in dn normalization via quoted… |
| CVE-2026-59707 | 9.2 | 39.3 | LocalAI | LocalAI | CWE-918 | LocalAI - Server-Side Request Forgery via POST /models/apply |
| CVE-2026-55418 | 8.6 | 39.3 | labring | FastGPT | CWE-639 | FastGPT: S3 presign/read handlers do not bind the object key to the caller's … |
| CVE-2026-14380 | 8.8 | 39.2 | HMBRAND | DBI | CWE-95 | DBI versions before 1.650 for Perl are vulnerable to code injection via calle… |
| CVE-2026-55075 | 7.4 | 39.2 | coder | coder | CWE-287 | Coder vulnerable to OIDC account takeover via email-based user matching and e… |
| CVE-2026-55076 | 7.4 | 39.2 | coder | coder | CWE-287 | Coder's OIDC email_verified type coercion bypass enables account takeover via… |
| CVE-2026-55647 | 5.1 | 38.4 | dataease | dataease | CWE-79 | DataEase: authenticated stored XSS in the dashboard text components |
| CVE-2026-55427 | 8.3 | 38.3 | coder | coder | CWE-74 | Coder vulnerable to SSH config injection via unsanitized server-supplied valu… |
| CVE-2026-48958 | 6.4 | 37.9 | Joomla! Project | Joomla! CMS | CWE-284 | Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice… |
| CVE-2026-44877 | 6.5 | 37.9 | Hewlett Packard Enterprise (HPE) | HPE Networking Instant On | CWE-200 | Unauthenticated Remote Disclosure of Cryptographic Secrets |
| CVE-2026-55631 | 7.2 | 37.8 | dataease | dataease | CWE-22 | DataEase: Path Traversal Leading to Arbitrary File Deletion via Font Management |
| CVE-2026-57172 | 8.3 | 37.0 | dataease | dataease | CWE-321 | DataEase: Hardcoded JWT Signing Secret in ShareLink |
| CVE-2026-42147 | 4.9 | 36.8 | coollabsio | coolify | CWE-918 | Coolify: SSRF via S3 Storage Endpoint in testConnection() |
| CVE-2026-59706 | 9.2 | 36.6 | mem0 | mem0 | CWE-306 | mem0 - Unauthenticated Config API Exposure and SSRF via ollama_base_url |
| CVE-2026-44938 | 8.8 | 36.6 | SUSE | Rancher | CWE-522 | Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent |
| CVE-2026-34037 | 9.9 | 36.5 | coollabsio | coolify | CWE-639 | Cross-Tenant Resource Cloning via Broken Object-Level Authorization in cloneTo() |
| CVE-2026-49229 | 8.3 | 36.5 | actualbudget | actual | CWE-613 | Actual: Disabled OpenID users keep access through existing session tokens |
| CVE-2026-53877 | 6.3 | 36.2 | djangoproject | Django | CWE-805 | Heap buffer over-read in GDALRaster |
| CVE-2026-13019 | 9.8 | 35.9 | Esri | Portal for ArcGIS | CWE-640 | Missing Authentication |
| CVE-2026-45796 | 6.5 | 35.6 | coder | coder | CWE-918 | Coder vulnerable to unauthenticated SSRF via Azure Instance Identity Endpoint |
| CVE-2026-48588 | 2.3 | 35.5 | djangoproject | Django | CWE-524 | Potential exposure of private data via cached Set-Cookie response |
| CVE-2026-50007 | 7.2 | 35.4 | actualbudget | actual | CWE-862 | Actual: Shared users can perform owner-only file management actions |
| CVE-2026-48948 | 6.4 | 35.1 | Joomla! Project | Joomla! CMS | CWE-284 | Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download |
| CVE-2026-48957 | 6.4 | 35.1 | Joomla! Project | Joomla! CMS | CWE-284 | Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservic… |
| CVE-2026-4375 | 9.0 | 34.8 | Unknown | DoLeads Integrator | — | DoLeads Integrator <= 1.2.2 & wp2epub <= 0.65 - Unauthenticated RCE |
| CVE-2026-55417 | 6.9 | 34.9 | chevereto | chevereto | CWE-862 | Chevereto private profile setting leaks username on /json endpoint |
| CVE-2026-5730 | 7.5 | 34.5 | Idvlabs Software and Consulting Services Inc. | Ontime | CWE-639 | IDOR in Idvlabs' Ontime |
| CVE-2026-5799 | 7.5 | 34.5 | Idvlabs Software and Consulting Services Inc. | Ontime | CWE-639 | IDOR in Idvlabs' Ontime |
| CVE-2026-12948 | 4.8 | 34.5 | Digi International | Digi PortServer TS | CWE-79 | Stored Cross-Site Scripting (XSS) |
| CVE-2026-50530 | 7.1 | 34.1 | dataease | dataease | CWE-639 | DataEase: Token with Overly Broad Privileges in Share Mode: Access to Unshare… |
| CVE-2026-14739 | 9.8 | 34.1 | HMBRAND | DBI | CWE-787 | DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL s… |
| CVE-2026-55635 | 8.7 | 34.0 | dataease | dataease | CWE-89 | DataEase: Authenticated SQL Injection in Chart Quota Filters |
| CVE-2025-12799 | 6.5 | 33.6 | Red Hat | Red Hat JBoss Enterprise Application Platform 8.1.7.GA | CWE-79 | Jastow: jastow cross-site scripting attack due to unsanitized uri |
| CVE-2026-55428 | 8.2 | 33.3 | coder | coder | CWE-285 | Coder: Route hijacking through lack of validation of agent-supplied AllowedIP… |
| CVE-2026-54601 | 6.3 | 33.3 | labring | FastGPT | CWE-915 | FastGPT: reTrainingCollection allows server-owned datasetId override causing … |
| CVE-2026-7017 | 7.1 | 33.1 | HAARG | HTTP::Tiny | CWE-522 | HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross… |
| CVE-2026-34044 | 7.7 | 33.0 | coollabsio | coolify | CWE-639 | Coolify: Cross-team IDOR in logs component (resource lookup not team-scoped) |
| CVE-2026-12352 | 5.9 | 32.9 | Digi International | PortServer TS 1/2/4 | CWE-863 | Incorrect Authorization |
| CVE-2026-49296 | 6.5 | 32.7 | Apache Software Foundation | Apache Airflow | CWE-639 | Apache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET… |
| CVE-2026-42145 | 3.1 | 32.3 | coollabsio | coolify | CWE-434 | Coolify: File Upload Without Type or Size Validation in Database Backup Restore |
| CVE-2026-12277 | 8.7 | 31.9 | Unknown | Frontend File Manager Plugin | — | Frontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Deletio… |
| CVE-2026-14740 | 9.1 | 31.5 | HMBRAND | DBI | CWE-125 | DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse wh… |
| CVE-2026-27790 | 2.7 | 31.3 | Gallagher | T-20 Readers | CWE-248 | Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and a… |
| CVE-2026-27844 | 2.7 | 31.3 | Gallagher | Controller 7000 and 6000 | CWE-248 | Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagn… |
| CVE-2026-49471 | 8.3 | 30.0 | oraios | serena | CWE-306 | Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding →… |
| CVE-2026-59704 | 7.1 | 29.5 | Cap | Cap | CWE-862 | Cap - Missing Access Control in Video AI Metadata Endpoint |
| CVE-2026-53730 | 8.7 | 29.1 | dataease | dataease | CWE-862 | DataEase: Unauthorized Access to Engine Database via previewSql Endpoint |
| CVE-2026-54602 | 7.1 | 29.1 | labring | FastGPT | CWE-639 | FastGPT: Cross-team LLM request/response disclosure (IDOR) via /api/core/ai/r… |
| CVE-2026-57868 | 7.1 | 29.1 | MicroRealEstate | MicroRealEstate | CWE-639 | MicroRealEstate is affected by broken object-level access controls in PDF gen… |
| CVE-2026-57869 | 7.1 | 29.1 | MicroRealEstate | MicroRealEstate | CWE-639 | Broken object-level access controls and the use of a deterministic pattern du… |
| CVE-2026-57870 | 5.3 | 29.1 | MicroRealEstate | MicroRealEstate | CWE-639 | Broken object-level access control on the Template API in MicroRealEstate all… |
| CVE-2026-34149 | 3.3 | 28.4 | coollabsio | coolify | CWE-78 | Coolify: Authenticated Host-Level RCE via Unescaped Database Credentials in B… |
| CVE-2026-58469 | 8.7 | 27.7 | gnuwget | wget | CWE-125 | GNU Wget 1.25.0 Heap Buffer Underread via Metalink URL Parsing |
| CVE-2026-11340 | 8.3 | 27.6 | HAVELSAN Inc. | Liman MYS | CWE-862 | Authorization Bypass in HAVELSAN's Open Source Project Liman MYS |
| CVE-2026-48955 | 6.4 | 27.1 | Joomla! Project | Joomla! CMS | CWE-284 | Joomla! Core - [20260709] - Incorrect Access Control in com_workflow |
| CVE-2026-46700 | 4.3 | 26.7 | actualbudget | actual | CWE-285 | Actual: Missing authorization on GET /secret/:name allows non-admin OpenID us… |
| CVE-2026-53935 | 6.9 | 26.5 | cilium | cilium | CWE-863 | CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traff… |
| CVE-2026-58468 | 5.1 | 26.1 | nocobase | nocobase | CWE-918 | NocoBase 2.1.20 Server-Side Request Forgery via serverRequest wrapper |
| CVE-2026-59709 | 5.3 | 26.0 | Ghostfolio | Ghostfolio | CWE-862 | Ghostfolio - Unauthorized Portfolio Holding Tag Modification via Missing Perm… |
| CVE-2026-8377 | 8.2 | 26.0 | Armiya Information Technologies Ltd. Co. | Access Control System (GKS) | CWE-862 | Improper Authorization in Armiya Technologies' Access Control System |
| CVE-2026-48947 | 6.4 | 25.5 | Joomla! Project | Joomla! CMS | CWE-284 | Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice … |
| CVE-2026-53878 | 5.3 | 25.0 | djangoproject | Django | CWE-144 | Header injection possibility since DomainNameValidator accepted newlines in i… |
| CVE-2026-58384 | 7.8 | 24.6 | Red Hat | Red Hat Enterprise Linux 9 | CWE-190 | Gimp: gimp: integer overflow in read_rle_channel() |
| CVE-2026-11328 | 6.4 | 24.3 | timstrifler | Exclusive Addons for Elementor | CWE-79 | Exclusive Addons for Elementor <= 2.7.9.8 - Authenticated (Contributor+) Stor… |
| CVE-2026-46354 | 9.1 | 24.0 | coder | coder | CWE-347 | Coder: PKCS#7 signature bypass in Azure instance identity allows unauthentica… |
| CVE-2026-55435 | 5.4 | 23.7 | coder | coder | CWE-863 | Suspended Coder users retain access to AI Bridge LLM proxy endpoints |
| CVE-2026-42201 | 3.3 | 23.2 | coollabsio | coolify | CWE-78 | Coolify: OS Command Injection via Database Credential Fields in Docker Compos… |
| CVE-2026-42172 | 3.1 | 21.9 | coollabsio | coolify | CWE-613 | Coolify: Sanctum API Tokens Have No Expiration — Leaked Tokens Grant Permanen… |
| CVE-2026-50179 | 4.2 | 20.5 | actualbudget | actual | CWE-1236 | Actual: CSV Formula Injection in Transaction Export via Imported Payee/Notes … |
| CVE-2026-55592 | 3.9 | 20.4 | lissy93 | dashy | CWE-79 | Dashy: XSS in workspace url parameter |
| CVE-2026-50811 | 6.5 | 19.7 | n/a | n/a | CWE-125 | An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions be… |
| CVE-2026-48956 | 6.4 | 19.3 | Joomla! Project | Joomla! CMS | CWE-284 | Joomla! Core - [20260710] - Incorrect Access Control in com_modules |
| CVE-2026-34170 | 4.3 | 18.7 | coollabsio | coolify | CWE-918 | Coolify: Server-Side Request Forgery via attacker-controlled GitHub App API URL |
| CVE-2026-13020 | 9.8 | 18.0 | Esri | Portal for ArcGIS | CWE-640 | Weak Password Recovery Mechanism in Portal for ArcGIS |
| CVE-2026-59153 | 2.1 | 17.9 | ankitects | anki | CWE-346 | Anki's local HTTP server does not sufficiently validate requests |
| CVE-2026-11348 | 8.1 | 16.5 | HAVELSAN Inc. | Liman MYS | CWE-347 | Authentication Bypass in HAVELSAN's Open Source Project Liman MYS |
| CVE-2026-7380 | 6.1 | 16.4 | Armiya Information Technologies Ltd. Co. | Access Control System (GKS) | CWE-80 | HTML Injection in Armiya Technologies' Access Control System |
| CVE-2026-8306 | 6.1 | 16.4 | Armiya Information Technologies Ltd. Co. | Access Control System (GKS) | CWE-79 | Stored XSS in Armiya Technologies' Access Control System |
| CVE-2026-58470 | 6.9 | 15.7 | gnuwget | wget | CWE-190 | GNU Wget 1.25.0 Integer Overflow via Content-Range Header Parsing |
| CVE-2026-26053 | 5.3 | 15.7 | Gallagher | Command Centre Server | CWE-266 | An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Cent… |
| CVE-2026-55408 | 8.4 | 15.6 | koodo-reader | koodo-reader | CWE-94 | Koodo Reader: Remote code execution via malicious epub file |
| CVE-2026-10834 | 4.6 | 15.5 | Unknown | WP Travel Engine | — | WP Travel Engine < 6.8.1 - Subscriber+ Arbitrary Media File Move via user_pro… |
| CVE-2026-48949 | 5.9 | 15.4 | Joomla! Project | Joomla! CMS | CWE-79 | Joomla! Core - [20260703] - XSS in MFA method management |
| CVE-2026-48950 | 5.9 | 15.4 | Joomla! Project | Joomla! CMS | CWE-79 | Joomla! Core - [20260704] - XSS in com_templates |
| CVE-2026-48951 | 5.9 | 15.4 | Joomla! Project | Joomla! CMS | CWE-79 | Joomla! Core - [20260705] - XSS in various modalreturn layouts |
| CVE-2026-48952 | 5.9 | 15.4 | Joomla! Project | Joomla! CMS | CWE-79 | Joomla! Core - [20260706] - XSS in com_installer |
| CVE-2026-48953 | 5.9 | 15.4 | Joomla! Project | Joomla! CMS | CWE-79 | Joomla! Core - [20260707] - XSS in the generic image output layout |
| CVE-2026-48954 | 5.9 | 15.4 | Joomla! Project | Joomla! CMS | CWE-79 | Joomla! Core - [20260708] - XSS through language overrides |
| CVE-2026-36162 | 5.4 | 14.2 | n/a | n/a | CWE-79 | An authenticated stored cross-site scripting (XSS) vulnerability in the Uploa… |
| CVE-2026-36163 | 5.4 | 14.2 | n/a | n/a | CWE-79 | An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2… |
| CVE-2026-14935 | 3.7 | 13.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-670 | Gstreamer: gstreamer: webrtcbin accepts remote sdp without a=fingerprint due … |
| CVE-2026-28378 | 2.7 | 13.2 | Grafana | Grafana Enterprise | CWE-284 | Cross-Organization Public Dashboard Deletion via Missing Org Isolation |
| CVE-2026-8309 | 5.4 | 13.1 | Armiya Information Technologies Ltd. Co. | Access Control System (GKS) | CWE-79 | Reflected XSS in Armiya Technologies' Access Control System |
| CVE-2026-58266 | 6.5 | 12.4 | ankitects | anki | CWE-346 | Anki: User scripts in iframes have access to the internal Anki API |
| CVE-2026-58471 | 6.0 | 12.4 | gnuwget | wget | CWE-122 | GNU Wget 1.25.0 Heap Buffer Overflow via convert_fname() in url.c |
| CVE-2026-58472 | 6.0 | 12.4 | gnuwget | wget | CWE-190 | GNU Wget 1.25.0 Heap Buffer Overflow via HTML Attribute Encoding |
| CVE-2026-34171 | 8.0 | 10.0 | coollabsio | coolify | CWE-352 | Coolify: Account takeover via CSRF-able GET endpoint that resets password to … |
| CVE-2026-34198 | 5.3 | 9.9 | coollabsio | coolify | CWE-346 | Coolify: Password reset link poisoning via X-Forwarded-Host header spoofing |
| CVE-2026-46672 | 4.6 | 8.3 | actualbudget | actual | CWE-1236 | Actual: CSV Formula Injection in `@actual-app/cli` `--format csv` Output via … |
| CVE-2026-42958 | 8.4 | 8.1 | Labcenter | Proteus | CWE-416 | Use After Free in Labcenter Proteus |
| CVE-2026-42953 | 8.4 | 8.0 | Labcenter | Proteus | CWE-787 | Out-of-bounds write in Labcenter Proteus |
| CVE-2026-49033 | 8.4 | 8.0 | Labcenter | Proteus | CWE-121 | Stack-Based Buffer Overflow in Labcenter Proteus |
| CVE-2026-54698 | 6.0 | 6.6 | hasura | graphql-engine | CWE-863 | Hasura: Row-level authorization bypass on table computed fields |
| CVE-2026-50810 | 5.5 | 6.5 | n/a | n/a | CWE-476 | A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/… |
| CVE-2026-57851 | 8.5 | 6.1 | Micro-Star International (MSI) | KernCoreLib64.sys | CWE-782 | MSI KernCoreLib64.sys Privilege Escalation via IOCTL Handlers |
| CVE-2026-13199 | 5.1 | 5.7 | Raspberry Pi | Raspberry Pi 5 and Compute Module 5 | CWE-331 | Insufficient Entropy in Raspberry Pi 5 and Compute Module 5 |
| CVE-2026-53511 | 8.5 | 4.5 | kovidgoyal | calibre | CWE-94 | calibre: Arbitrary Code Execution in Template Formatter via Book Metadata |
| CVE-2026-58315 | 5.1 | 4.3 | SEIKO EPSON CORPORATION | Web Config | CWE-352 | Cross-site request forgery vulnerability exists in SEIKO EPSON Web Config. If… |
| CVE-2026-58583 | 8.4 | 4.0 | FluxInk | Color Management Driver | CWE-269 | FluxInk Color Management Driver local privilege escalation |
| CVE-2026-10659 | 4.7 | 3.1 | zephyrproject | zephyr | CWE-476 | NULL pointer dereference in Zephyr Dhara FTL disk driver on flash read error … |
| CVE-2026-14867 | 6.8 | 3.0 | arcinfo | PcVue | CWE-256 | Insecure password storage in User directory |
| CVE-2026-14969 | 4.4 | 1.2 | Red Hat | Red Hat Directory Server 11 | CWE-329 | 389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc at… |
| CVE-2026-14868 | 8.4 | 0.0 | arcinfo | PcVue | CWE-326 | Weak encryption mechanism for User directory |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-07 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.