boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, July 7, 2026 · all times UTC← 2026-07-06 · archive · 2026-07-08 →

Security Box Score — July 7, 2026

170 CVEs published, led by coollabsio (21).

170 CVEs published July 7, 2026: 25 critical, 70 high, 64 medium, 11 low; 4 in the KEV catalog at press time; 7 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 145 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published133113734——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

600 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux37151712086653011120.17.5.0014+4 ▲
google521317148590542377760.57.8.0024-436 ▼
microsoft50807615521886286202.57.8.0046+43 ▲
red hat27249129912315200.06.5.0030+8 ▲
apple01042287228876.76.5.00320
canonical0202585000.05.5.00110
suse61941140000.08.6.0042+6 ▲
freebsd01601240000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ubiquiti2536142110338.38.8.0049+25 ▲
cisco830614100561136.77.5.0057+6 ▲
netgear01700161000.04.3.00240
palo alto networks011127113218.25.9.00220
checkpoint0915303111.17.5.04100
fortinet09432028333.38.3.00760
ivanti09450025555.68.8.5187-1 ▼
f50843104112.58.9.02250
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache50205377977113310.57.3.0057+18 ▲
mozilla3591218290900.07.3.0025-1 ▼
gitlab03105215426.54.4.00290
github171150000.06.0.0039+1 ▲
docker070520000.08.2.0016-2 ▼
drupal0511304120.05.1.00260
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle02701321161842720.78.8.00400
adobe314713537921932.06.1.0021+3 ▲
ibm01243642460600.07.5.0034-5 ▼
progress2111910600.07.5.0036-3 ▼
solarwinds07232010457.17.5.4001-2 ▼
veeam042200100.09.0.00520
zohocorp031110000.08.4.01700
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology02325133000.05.6.0025-5 ▼
d-link0120525300.05.8.0058-5 ▼
siemens090450000.06.9.0021-1 ▼
rockwell automation071510000.08.7.00300
abb060420000.07.2.0018-4 ▼
schneider electric060420000.07.8.00420
moxa050320000.07.0.00290
dahua030111000.06.9.00360
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester2798005246000.05.5.0029+5 ▲
dell2379435382211.36.7.0019+20 ▲
spring073231391000.06.5.0024-2 ▼
openclaw0670352210000.07.0.00210
edimax065039026100.07.4.00800
itsourcecode1063001944000.02.1.0033-9 ▼
capgo061231271000.07.1.00390
themerex26055410000.08.1.0043+2 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9991100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-20230.882099.88.6
CVE-2026-34910.874799.710.0
CVE-2026-34908.851999.710.0
CVE-2026-50751.837799.79.3
CVE-2026-48907.781099.510.0
CVE-2026-45659.760899.58.8
CVE-2026-34909.639099.210.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9991KEV
CVE-2026-3491010.0.8747KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.7810KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-4828210.0.4239KEV
CVE-2026-5629010.0.3038KEV
CVE-2026-4890810.0.1482KEV
CVE-2026-1377310.0.0610
CVE-2026-5641510.0.0436
Most disclosures (vendor)
VendorCVEs
google654
linux517
microsoft264
oracle242
adobe145
apache139
red hat136
ibm70
spring70
capgo61
Most KEV additions (YTD)
VendorKEV
microsoft20
cisco11
apple7
google6
ivanti5
solarwinds4
adobe3
berriai3
fortinet3
smartertools3
Most-affected ecosystems
EcosystemAdvisories
Maven68
Packagist15
npm7
PyPI6
NuGet3
Fastest to KEV
CVEVendorDays
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
CVE-2026-34910Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171693
CVE-2021-27102n/a2021-11-171693
CVE-2021-27101n/a2021-11-171693
CVE-2021-27103n/a2021-11-171693
CVE-2021-21017Adobe2021-11-171693
CVE-2021-28550Adobe2021-11-171693
CVE-2021-42013Apache Software Foundation2021-11-171693
CVE-2021-41773Apache Software Foundation2021-11-171693
CVE-2021-30858Apple2021-11-171693
CVE-2021-30860Apple2021-11-171693

Transactions

EXPLOIT PUBLISHED — CVE-2026-10659 (zephyrproject zephyr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-49471 (oraios serena). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-55255 (langflow-ai langflow). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-55490 (openwrt). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56290 (JoomlaCK.fr Page Builder CK extension for Joomla). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56812 (phoenixframework phoenix). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-58384 (Red Hat Enterprise Linux 9). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-58583 (FluxInk Color Management Driver). Public exploit reference added.

Yesterday's Results

How to read these box scores · glossary

170 CVEs published. 25 box scores, 145 table rows — nothing truncated.

Adobe ColdFusion — ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .4239   98.6   YES
AFFECTED
  Product     Versions     Fixed
  ColdFusion  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Jul 7   Added to CISA KEV, due Jul 10
  Jul 7   Published (CNA: adobe)
CWE-22 · CNA: adobe · CVSS v3.1 · 2 references · NVD status: Analyzed · KEV due July 10, 2026
joomlack.fr JoomlaCK.fr Page Builder CK extension for Joomla — Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .3038   98.1   YES
AFFECTED
  Product                                           Versions     Fixed
  JoomlaCK.fr Page Builder CK extension for Joomla  1.0-3.6.0 –  —
TIMELINE
  Jun 20  Reserved by CNA
  Jul 7   Public exploit reference published
  Jul 7   Added to CISA KEV, due Jul 10
  Jul 7   Published (CNA: Joomla)
CWE-434 · CNA: Joomla · CVSS v4.0 · 4 references · NVD status: Analyzed · KEV due July 10, 2026
joomshaper.net SP Page Builder extension for Joomla — Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .1482   96.4   YES
AFFECTED
  Product                               Versions       Fixed
  SP Page Builder extension for Joomla  1.0.0-6.6.1 –  —
TIMELINE
  May 26  Reserved by CNA
  Jul 7   Added to CISA KEV, due Jul 10
  Jul 7   Published (CNA: Joomla)
CWE-434 · CNA: Joomla · CVSS v4.0 · 5 references · NVD status: Analyzed · KEV due July 10, 2026
langflow-ai langflow — Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  C  H  H  L    8.4   .0089   56.5   YES
AFFECTED
  Product   Versions   Fixed
  langflow  < 1.9.1 –  —
TIMELINE
  Jun 16  Reserved by CNA
  Jul 7   Public exploit reference published
  Jul 7   Added to CISA KEV, due Jul 10
  Jul 7   Published (CNA: GitHub_M)
CWE-639 · CNA: GitHub_M · CVSS v3.1 · 5 references · NVD status: Analyzed · KEV due July 10, 2026
Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0264   84.4     —
AFFECTED
  Product  Versions    Fixed
  coder    < 2.29.7 –  —
TIMELINE
  May 6   Reserved by CNA
  Jul 7   Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v3.1 · 7 references · NVD status: Analyzed
decolua 9router — 9Router < 0.4.44 - OS Command Injection via sudoPassword Parameter in Tailscale Install Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0204   79.7     —
AFFECTED
  Product  Versions     Fixed
  9router  unspecified  0.4.44
TIMELINE
  Jul 7   Reserved by CNA
  Jul 7   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0197   78.9     —
AFFECTED
  Product                   Versions     Fixed
  PowerProtect Data Domain  unspecified  —
TIMELINE
  Jun 9   Reserved by CNA
  Jul 7   Published (CNA: dell)
CWE-78 · CNA: dell · CVSS v3.1 · 1 reference · NVD status: Analyzed
Apache Airflow: DAG author RCE on webserver via unrestricted import_string() in BaseSerialization.deserialize()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0165   74.7     —
AFFECTED
  Product         Versions     Fixed
  Apache Airflow  unspecified  —
TIMELINE
  Mar 18  Reserved by CNA
  Jul 7   Published (CNA: apache)
CWE-502 · CNA: apache · CVSS v3.1 · 4 references · NVD status: Analyzed
getwpfunnels WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell — WPFunnels <= 3.12.7 - Unauthenticated Remote Code Execution via 'postData' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0139   70.3     —
AFFECTED
  Product                                                                      Versions     Fixed
  WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell  unspecified  —
TIMELINE
  Jul 1   Reserved by CNA
  Jul 7   Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 11 references · NVD status: Deferred
Vtiger CRM 8.4.0 Authenticated RCE via Module Import File Upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0123   66.5     —
AFFECTED
  Product     Versions     Fixed
  Vtiger CRM  unspecified  —
TIMELINE
  Jan 14  Reserved by CNA
  Jul 7   Published (CNA: VulnCheck)
CWE-434 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Deferred
mohammed_kaludi AMP for WP – Accelerated Mobile Pages — AMP for WP <= 1.1.12 - Authenticated (Author+) Arbitrary File Write via Role-Based Access Configuration with Local Font Upload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0102   60.9     —
AFFECTED
  Product                                Versions     Fixed
  AMP for WP – Accelerated Mobile Pages  unspecified  —
TIMELINE
  Apr 10  Reserved by CNA
  Jul 7   Published (CNA: Wordfence)
CWE-73 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
Vtiger CRM < 8.4.0 Authenticated File Upload RCE via Documents Module
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0100   60.1     —
AFFECTED
  Product     Versions     Fixed
  Vtiger CRM  unspecified  8.4.0
TIMELINE
  Jan 14  Reserved by CNA
  Jul 7   Published (CNA: VulnCheck)
CWE-434 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Deferred
coollabsio coolify — Coolify: PostgreSQL Init Script Path Traversal Leads to Arbitrary File Write and Root RCE
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0089   56.7     —
AFFECTED
  Product  Versions            Fixed
  coolify  < 4.0.0-beta.474 –  —
TIMELINE
  Apr 25  Reserved by CNA
  Jul 7   Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Deferred
mem0 - OpenMemory API Unauthenticated Access via Memory Endpoints
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0080   54.0     —
AFFECTED
  Product  Versions     Fixed
  mem0     unspecified  —
TIMELINE
  Jul 6   Reserved by CNA
  Jul 7   Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
coollabsio coolify — Coolify: Missing authorization on terminal websocket bootstrap routes allows low-privileged members to execute commands on team servers
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0080   53.7     —
AFFECTED
  Product  Versions            Fixed
  coolify  < 4.0.0-beta.471 –  —
TIMELINE
  Mar 25  Reserved by CNA
  Jul 7   Published (CNA: GitHub_M)
CWE-285, CWE-862 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Deferred
DataEase H2 RCE via Zip Protocol & File Dropper Fix bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0080   53.7     —
AFFECTED
  Product   Versions     Fixed
  dataease  < 2.10.24 –  —
TIMELINE
  Jun 16  Reserved by CNA
  Jul 7   Published (CNA: GitHub_M)
CWE-434 · CNA: GitHub_M · CVSS v4.0 · 4 references · NVD status: Deferred
coollabsio coolify — Coolify: Host RCE via Sentinel token injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0078   53.3     —
AFFECTED
  Product  Versions            Fixed
  coolify  < 4.0.0-beta.466 –  —
TIMELINE
  Mar 25  Reserved by CNA
  Jul 7   Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Deferred
coollabsio coolify — Coolify: Command injection via unsanitized persistent storage name in docker volume commands
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0078   53.3     —
AFFECTED
  Product  Versions            Fixed
  coolify  < 4.0.0-beta.471 –  —
TIMELINE
  Mar 25  Reserved by CNA
  Jul 7   Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Deferred
coollabsio coolify — Coolify: OS Command Injection via Persistent Volume Names - Root RCE on Managed Servers
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0078   53.3     —
AFFECTED
  Product  Versions            Fixed
  coolify  < 4.0.0-beta.471 –  —
TIMELINE
  Apr 24  Reserved by CNA
  Jul 7   Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Deferred
phoenixframework phoenix — Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   L    6.3   .0078   53.1     —
AFFECTED
  Product  Versions                                    Fixed
  phoenix  1.2.0-rc.0 –                                —
  phoenix  1.2.0-rc.0 –                                —
  phoenix  2270aaf21bd02c6a6a1022820564efb605a97655 –  7f7b971c1ea0994e3fbd1c11ddb05e780bd38ad8
TIMELINE
  Jun 23  Reserved by CNA
  Jul 7   Public exploit reference published
  Jul 7   Published (CNA: EEF)
CWE-754 · CNA: EEF · CVSS v4.0 · 7 references · NVD status: Analyzed
BINGOS Module::Load — Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0077   53.0     —
AFFECTED
  Product       Versions     Fixed
  Module::Load  unspecified  —
TIMELINE
  Jul 5   Reserved by CNA
  Jul 7   Published (CNA: CPANSec)
CWE-145 · CNA: CPANSec · CVSS v3.1 · 3 references · NVD status: Deferred
phoenixframework phoenix — Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0076   52.4     —
AFFECTED
  Product  Versions                                    Fixed
  phoenix  0.11.0 –                                    —
  phoenix  14a297e88023cb280a577962a49a0bbdeef9f4eb –  c498ba8cf49f6accbbd0c643a5340b58db891218
TIMELINE
  Jun 23  Reserved by CNA
  Jul 7   Published (CNA: EEF)
CWE-770 · CNA: EEF · CVSS v4.0 · 7 references · NVD status: Analyzed
coollabsio coolify — Coolify: WebSocket Endpoint Access Control Flaw Leading to Remote Code Execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0071   50.8     —
AFFECTED
  Product  Versions            Fixed
  coolify  < 4.0.0-beta.471 –  —
TIMELINE
  Mar 25  Reserved by CNA
  Jul 7   Published (CNA: GitHub_M)
CWE-863 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Deferred
n/a n/a — Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by imp…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0068   49.7     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jul 7   Published (CNA: mitre)
CWE-287, CWE-798 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Deferred
OpenWrt: EAD Integer Underflow → Pre-Auth Denial of Service
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   A   L   N   N  U  N  N  H    6.5   .0068   49.7     —
AFFECTED
  Product  Versions     Fixed
  openwrt  < 25.12.5 –  —
TIMELINE
  Jun 16  Reserved by CNA
  Jul 7   Public exploit reference published
  Jul 7   Published (CNA: GitHub_M)
CWE-191 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-144768.049.2Red HatRed Hat Enterprise Linux 10CWE-23Sssd: sssd: gpo cache path traversal via unsanitized gpcfilesyspath allows ke…
CVE-2026-488286.549.0Apache Software FoundationApache AirflowCWE-200Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact…
CVE-2026-488926.549.0Apache Software FoundationApache AirflowCWE-200Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypa…
CVE-2026-494876.549.0Apache Software FoundationApache AirflowCWE-200Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs
CVE-2026-341588.848.4coollabsiocoolifyCWE-78Coolify: Command injection via single-quote breakout in Docker Compose custom…
CVE-2026-340588.848.4coollabsiocoolifyCWE-78Coolify: OS Command Injection via Unmanaged Container Operations - Remote Cod…
CVE-2026-341528.848.4coollabsiocoolifyCWE-78Coolify: Command Injection via Newline in Pre/Post Deployment Commands (Hered…
CVE-2026-537298.748.0dataeasedataeaseCWE-639DataEase ExportCenter IDOR allows cross-user export task access
CVE-2026-372719.848.0n/an/aCWE-287Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Imp…
CVE-2026-488914.347.7Apache Software FoundationApache AirflowCWE-200Apache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identi…
CVE-2026-534819.847.5DellPowerProtect Data DomainCWE-22Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-148957.547.4BAKERSCOTString::UtilCWE-1333String::Util versions before 1.36 for Perl are susceptible to a regular expre…
CVE-2026-340358.847.4coollabsiocoolifyCWE-78Coolify: Host RCE via Log Drain secret/env command injection
CVE-2026-340578.847.4coollabsiocoolifyCWE-78Coolify: Authenticated Remote Code Execution via Command Injection in Databas…
CVE-2026-116108.847.3389ds389-ds-baseCWE-122389-ds-base: 389-ds-base: heap buffer overflow in sasl_io_recv() via padded s…
CVE-2026-534839.847.3DellPowerProtect Data DomainCWE-287Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-550777.246.7codercoderCWE-285Coder: User-admin role can reset owner account password
CVE-2026-550796.546.5codercoderCWE-789Coder's unbounded memory allocation in provisioner file upload allows authent…
CVE-2026-550786.546.1codercoderCWE-409Coder: Zip upload decompression lacks aggregate size limit, enabling denial o…
CVE-2026-578678.846.0MicroRealEstateMicroRealEstateCWE-288MicroRealEstate allows adversaries to bypass authentication due to a lack of …
CVE-2026-537518.745.9dataeasedataeaseCWE-94DataEase: H2 JDBC URL Filter Bypass Leads to Remote Code Execution (RCE)
CVE-2026-519377.545.8n/an/aCWE-306An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive infor…
CVE-2026-597088.745.7ghostfolioghostfolioCWE-862Ghostfolio - Unauthorized Portfolio Data Exposure via Public Endpoint
CVE-2026-149047.144.6AWSresCWE-59RES Auth.GetUserPrivateKey Arbitrary File Read
CVE-2026-144748.844.5Red HatRed Hat Enterprise Linux 10CWE-1188Sssd: sssd: sudo ldap provider searches entire directory tree for sudorole ob…
CVE-2026-554346.543.6codercoderCWE-770Coder vulnerable to denial of service via unbounded request body in AI Bridge…
CVE-2026-123759.843.3Unknownuncanny-automator-pro—Uncanny Automator Pro 7.3.0.5 - Backdoor via Compromised Vendor Update Server
CVE-2026-578717.143.0MicroRealEstateMicroRealEstateCWE-23Relative path traversal vulnerability in MicroRealEstate file upload function…
CVE-2026-546077.742.0labringFastGPTCWE-918FastGPT: SSRF in HTTP-tool OpenAPI schema importer via SwaggerParser $ref (by…
CVE-2026-136968.841.7HAVELSAN Inc.Liman MYSCWE-90LDAP Injection in HAVELSAN's Liman MYS
CVE-2026-584739.341.2topoteretescogneeCWE-306Cognee < 1.2.0 Unauthorized LLM Configuration Overwrite via /api/v1/settings
CVE-2026-505298.740.3dataeasedataeaseCWE-863DataEase: Link Token Leakage Prior to Share Password/Ticket Validation
CVE-2026-149405.339.7Red HatRed Hat Directory Server 11CWE-122389-ds-base: 389-ds-base: heap-buffer-overflow in dn normalization via quoted…
CVE-2026-597079.239.3LocalAILocalAICWE-918LocalAI - Server-Side Request Forgery via POST /models/apply
CVE-2026-554188.639.3labringFastGPTCWE-639FastGPT: S3 presign/read handlers do not bind the object key to the caller's …
CVE-2026-143808.839.2HMBRANDDBICWE-95DBI versions before 1.650 for Perl are vulnerable to code injection via calle…
CVE-2026-550757.439.2codercoderCWE-287Coder vulnerable to OIDC account takeover via email-based user matching and e…
CVE-2026-550767.439.2codercoderCWE-287Coder's OIDC email_verified type coercion bypass enables account takeover via…
CVE-2026-556475.138.4dataeasedataeaseCWE-79DataEase: authenticated stored XSS in the dashboard text components
CVE-2026-554278.338.3codercoderCWE-74Coder vulnerable to SSH config injection via unsanitized server-supplied valu…
CVE-2026-489586.437.9Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice…
CVE-2026-448776.537.9Hewlett Packard Enterprise (HPE)HPE Networking Instant OnCWE-200Unauthenticated Remote Disclosure of Cryptographic Secrets
CVE-2026-556317.237.8dataeasedataeaseCWE-22DataEase: Path Traversal Leading to Arbitrary File Deletion via Font Management
CVE-2026-571728.337.0dataeasedataeaseCWE-321DataEase: Hardcoded JWT Signing Secret in ShareLink
CVE-2026-421474.936.8coollabsiocoolifyCWE-918Coolify: SSRF via S3 Storage Endpoint in testConnection()
CVE-2026-597069.236.6mem0mem0CWE-306mem0 - Unauthenticated Config API Exposure and SSRF via ollama_base_url
CVE-2026-449388.836.6SUSERancherCWE-522Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent
CVE-2026-340379.936.5coollabsiocoolifyCWE-639Cross-Tenant Resource Cloning via Broken Object-Level Authorization in cloneTo()
CVE-2026-492298.336.5actualbudgetactualCWE-613Actual: Disabled OpenID users keep access through existing session tokens
CVE-2026-538776.336.2djangoprojectDjangoCWE-805Heap buffer over-read in GDALRaster
CVE-2026-130199.835.9EsriPortal for ArcGISCWE-640Missing Authentication
CVE-2026-457966.535.6codercoderCWE-918Coder vulnerable to unauthenticated SSRF via Azure Instance Identity Endpoint
CVE-2026-485882.335.5djangoprojectDjangoCWE-524Potential exposure of private data via cached Set-Cookie response
CVE-2026-500077.235.4actualbudgetactualCWE-862Actual: Shared users can perform owner-only file management actions
CVE-2026-489486.435.1Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download
CVE-2026-489576.435.1Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservic…
CVE-2026-43759.034.8UnknownDoLeads Integrator—DoLeads Integrator <= 1.2.2 & wp2epub <= 0.65 - Unauthenticated RCE
CVE-2026-554176.934.9cheveretocheveretoCWE-862Chevereto private profile setting leaks username on /json endpoint
CVE-2026-57307.534.5Idvlabs Software and Consulting Services Inc.OntimeCWE-639IDOR in Idvlabs' Ontime
CVE-2026-57997.534.5Idvlabs Software and Consulting Services Inc.OntimeCWE-639IDOR in Idvlabs' Ontime
CVE-2026-129484.834.5Digi InternationalDigi PortServer TSCWE-79Stored Cross-Site Scripting (XSS)
CVE-2026-505307.134.1dataeasedataeaseCWE-639DataEase: Token with Overly Broad Privileges in Share Mode: Access to Unshare…
CVE-2026-147399.834.1HMBRANDDBICWE-787DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL s…
CVE-2026-556358.734.0dataeasedataeaseCWE-89DataEase: Authenticated SQL Injection in Chart Quota Filters
CVE-2025-127996.533.6Red HatRed Hat JBoss Enterprise Application Platform 8.1.7.GACWE-79Jastow: jastow cross-site scripting attack due to unsanitized uri
CVE-2026-554288.233.3codercoderCWE-285Coder: Route hijacking through lack of validation of agent-supplied AllowedIP…
CVE-2026-546016.333.3labringFastGPTCWE-915FastGPT: reTrainingCollection allows server-owned datasetId override causing …
CVE-2026-70177.133.1HAARGHTTP::TinyCWE-522HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross…
CVE-2026-340447.733.0coollabsiocoolifyCWE-639Coolify: Cross-team IDOR in logs component (resource lookup not team-scoped)
CVE-2026-123525.932.9Digi InternationalPortServer TS 1/2/4CWE-863Incorrect Authorization
CVE-2026-492966.532.7Apache Software FoundationApache AirflowCWE-639Apache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET…
CVE-2026-421453.132.3coollabsiocoolifyCWE-434Coolify: File Upload Without Type or Size Validation in Database Backup Restore
CVE-2026-122778.731.9UnknownFrontend File Manager Plugin—Frontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Deletio…
CVE-2026-147409.131.5HMBRANDDBICWE-125DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse wh…
CVE-2026-277902.731.3GallagherT-20 ReadersCWE-248Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and a…
CVE-2026-278442.731.3GallagherController 7000 and 6000CWE-248Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagn…
CVE-2026-494718.330.0oraiosserenaCWE-306Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding →…
CVE-2026-597047.129.5CapCapCWE-862Cap - Missing Access Control in Video AI Metadata Endpoint
CVE-2026-537308.729.1dataeasedataeaseCWE-862DataEase: Unauthorized Access to Engine Database via previewSql Endpoint
CVE-2026-546027.129.1labringFastGPTCWE-639FastGPT: Cross-team LLM request/response disclosure (IDOR) via /api/core/ai/r…
CVE-2026-578687.129.1MicroRealEstateMicroRealEstateCWE-639MicroRealEstate is affected by broken object-level access controls in PDF gen…
CVE-2026-578697.129.1MicroRealEstateMicroRealEstateCWE-639Broken object-level access controls and the use of a deterministic pattern du…
CVE-2026-578705.329.1MicroRealEstateMicroRealEstateCWE-639Broken object-level access control on the Template API in MicroRealEstate all…
CVE-2026-341493.328.4coollabsiocoolifyCWE-78Coolify: Authenticated Host-Level RCE via Unescaped Database Credentials in B…
CVE-2026-584698.727.7gnuwgetwgetCWE-125GNU Wget 1.25.0 Heap Buffer Underread via Metalink URL Parsing
CVE-2026-113408.327.6HAVELSAN Inc.Liman MYSCWE-862Authorization Bypass in HAVELSAN's Open Source Project Liman MYS
CVE-2026-489556.427.1Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260709] - Incorrect Access Control in com_workflow
CVE-2026-467004.326.7actualbudgetactualCWE-285Actual: Missing authorization on GET /secret/:name allows non-admin OpenID us…
CVE-2026-539356.926.5ciliumciliumCWE-863CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traff…
CVE-2026-584685.126.1nocobasenocobaseCWE-918NocoBase 2.1.20 Server-Side Request Forgery via serverRequest wrapper
CVE-2026-597095.326.0GhostfolioGhostfolioCWE-862Ghostfolio - Unauthorized Portfolio Holding Tag Modification via Missing Perm…
CVE-2026-83778.226.0Armiya Information Technologies Ltd. Co.Access Control System (GKS)CWE-862Improper Authorization in Armiya Technologies' Access Control System
CVE-2026-489476.425.5Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice …
CVE-2026-538785.325.0djangoprojectDjangoCWE-144Header injection possibility since DomainNameValidator accepted newlines in i…
CVE-2026-583847.824.6Red HatRed Hat Enterprise Linux 9CWE-190Gimp: gimp: integer overflow in read_rle_channel()
CVE-2026-113286.424.3timstriflerExclusive Addons for ElementorCWE-79Exclusive Addons for Elementor <= 2.7.9.8 - Authenticated (Contributor+) Stor…
CVE-2026-463549.124.0codercoderCWE-347Coder: PKCS#7 signature bypass in Azure instance identity allows unauthentica…
CVE-2026-554355.423.7codercoderCWE-863Suspended Coder users retain access to AI Bridge LLM proxy endpoints
CVE-2026-422013.323.2coollabsiocoolifyCWE-78Coolify: OS Command Injection via Database Credential Fields in Docker Compos…
CVE-2026-421723.121.9coollabsiocoolifyCWE-613Coolify: Sanctum API Tokens Have No Expiration — Leaked Tokens Grant Permanen…
CVE-2026-501794.220.5actualbudgetactualCWE-1236Actual: CSV Formula Injection in Transaction Export via Imported Payee/Notes …
CVE-2026-555923.920.4lissy93dashyCWE-79Dashy: XSS in workspace url parameter
CVE-2026-508116.519.7n/an/aCWE-125An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions be…
CVE-2026-489566.419.3Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260710] - Incorrect Access Control in com_modules
CVE-2026-341704.318.7coollabsiocoolifyCWE-918Coolify: Server-Side Request Forgery via attacker-controlled GitHub App API URL
CVE-2026-130209.818.0EsriPortal for ArcGISCWE-640Weak Password Recovery Mechanism in Portal for ArcGIS
CVE-2026-591532.117.9ankitectsankiCWE-346Anki's local HTTP server does not sufficiently validate requests
CVE-2026-113488.116.5HAVELSAN Inc.Liman MYSCWE-347Authentication Bypass in HAVELSAN's Open Source Project Liman MYS
CVE-2026-73806.116.4Armiya Information Technologies Ltd. Co.Access Control System (GKS)CWE-80HTML Injection in Armiya Technologies' Access Control System
CVE-2026-83066.116.4Armiya Information Technologies Ltd. Co.Access Control System (GKS)CWE-79Stored XSS in Armiya Technologies' Access Control System
CVE-2026-584706.915.7gnuwgetwgetCWE-190GNU Wget 1.25.0 Integer Overflow via Content-Range Header Parsing
CVE-2026-260535.315.7GallagherCommand Centre ServerCWE-266An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Cent…
CVE-2026-554088.415.6koodo-readerkoodo-readerCWE-94Koodo Reader: Remote code execution via malicious epub file
CVE-2026-108344.615.5UnknownWP Travel Engine—WP Travel Engine < 6.8.1 - Subscriber+ Arbitrary Media File Move via user_pro…
CVE-2026-489495.915.4Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260703] - XSS in MFA method management
CVE-2026-489505.915.4Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260704] - XSS in com_templates
CVE-2026-489515.915.4Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260705] - XSS in various modalreturn layouts
CVE-2026-489525.915.4Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260706] - XSS in com_installer
CVE-2026-489535.915.4Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260707] - XSS in the generic image output layout
CVE-2026-489545.915.4Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260708] - XSS through language overrides
CVE-2026-361625.414.2n/an/aCWE-79An authenticated stored cross-site scripting (XSS) vulnerability in the Uploa…
CVE-2026-361635.414.2n/an/aCWE-79An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2…
CVE-2026-149353.713.9Red HatRed Hat Enterprise Linux 10CWE-670Gstreamer: gstreamer: webrtcbin accepts remote sdp without a=fingerprint due …
CVE-2026-283782.713.2GrafanaGrafana EnterpriseCWE-284Cross-Organization Public Dashboard Deletion via Missing Org Isolation
CVE-2026-83095.413.1Armiya Information Technologies Ltd. Co.Access Control System (GKS)CWE-79Reflected XSS in Armiya Technologies' Access Control System
CVE-2026-582666.512.4ankitectsankiCWE-346Anki: User scripts in iframes have access to the internal Anki API
CVE-2026-584716.012.4gnuwgetwgetCWE-122GNU Wget 1.25.0 Heap Buffer Overflow via convert_fname() in url.c
CVE-2026-584726.012.4gnuwgetwgetCWE-190GNU Wget 1.25.0 Heap Buffer Overflow via HTML Attribute Encoding
CVE-2026-341718.010.0coollabsiocoolifyCWE-352Coolify: Account takeover via CSRF-able GET endpoint that resets password to …
CVE-2026-341985.39.9coollabsiocoolifyCWE-346Coolify: Password reset link poisoning via X-Forwarded-Host header spoofing
CVE-2026-466724.68.3actualbudgetactualCWE-1236Actual: CSV Formula Injection in `@actual-app/cli` `--format csv` Output via …
CVE-2026-429588.48.1LabcenterProteusCWE-416Use After Free in Labcenter Proteus
CVE-2026-429538.48.0LabcenterProteusCWE-787Out-of-bounds write in Labcenter Proteus
CVE-2026-490338.48.0LabcenterProteusCWE-121Stack-Based Buffer Overflow in Labcenter Proteus
CVE-2026-546986.06.6hasuragraphql-engineCWE-863Hasura: Row-level authorization bypass on table computed fields
CVE-2026-508105.56.5n/an/aCWE-476A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/…
CVE-2026-578518.56.1Micro-Star International (MSI)KernCoreLib64.sysCWE-782MSI KernCoreLib64.sys Privilege Escalation via IOCTL Handlers
CVE-2026-131995.15.7Raspberry PiRaspberry Pi 5 and Compute Module 5CWE-331Insufficient Entropy in Raspberry Pi 5 and Compute Module 5
CVE-2026-535118.54.5kovidgoyalcalibreCWE-94calibre: Arbitrary Code Execution in Template Formatter via Book Metadata
CVE-2026-583155.14.3SEIKO EPSON CORPORATIONWeb ConfigCWE-352Cross-site request forgery vulnerability exists in SEIKO EPSON Web Config. If…
CVE-2026-585838.44.0FluxInkColor Management DriverCWE-269FluxInk Color Management Driver local privilege escalation
CVE-2026-106594.73.1zephyrprojectzephyrCWE-476NULL pointer dereference in Zephyr Dhara FTL disk driver on flash read error …
CVE-2026-148676.83.0arcinfoPcVueCWE-256Insecure password storage in User directory
CVE-2026-149694.41.2Red HatRed Hat Directory Server 11CWE-329389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc at…
CVE-2026-148688.40.0arcinfoPcVueCWE-326Weak encryption mechanism for User directory

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-07 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.