boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Wednesday, July 8, 2026 · all times UTC← 2026-07-07 · archive · 2026-07-09 →

Security Box Score — July 8, 2026

362 CVEs published, led by Foxit Software Inc. (28).

362 CVEs published July 8, 2026: 26 critical, 170 high, 148 medium, 18 low; 0 in the KEV catalog at press time; 45 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 337 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published169314096——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

616 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux37151712086653011120.17.5.0014-37 ▼
google791344149608549387760.47.8.0024-482 ▼
microsoft52809615531896286202.57.8.0046+45 ▲
red hat31253129912616200.06.5.0030+9 ▲
apple01042287228876.76.5.00320
canonical1212685000.05.5.0011+1 ▲
suse61941140000.08.6.0042+6 ▲
freebsd01601240000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ubiquiti2536142110338.38.8.0049+25 ▲
cisco830614100561136.77.5.0057+6 ▲
netgear01700161000.04.3.00240
palo alto networks112137113216.76.0.0024+1 ▲
checkpoint0915303111.17.5.0410-2 ▼
fortinet09432028333.38.3.00760
ivanti09450025555.68.8.5187-1 ▼
f50843104112.58.9.02250
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache51206387977113310.57.3.0058+5 ▲
mozilla3591218290900.07.3.0025-1 ▼
gitlab73805276425.34.7.0032+7 ▲
github171150000.06.0.0039+1 ▲
docker070520000.08.2.0016-2 ▼
drupal0511304120.05.1.00260
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle02701321161842720.78.8.00400
adobe314713537921932.06.1.0021+3 ▲
ibm21263842460600.07.5.0034-3 ▼
progress101931420600.07.5.0037+5 ▲
solarwinds07232010457.17.5.4001-2 ▼
veeam042200100.09.0.00520
zohocorp031110000.08.4.01700
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology02325133000.05.6.0025-5 ▼
d-link0120525300.05.8.0058-8 ▼
siemens090450000.06.9.0021-1 ▼
rockwell automation071510000.08.7.00300
abb060420000.07.2.0018-4 ▼
schneider electric060420000.07.8.00420
moxa050320000.07.0.00290
dahua030111000.06.9.00360
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester2798005246000.05.5.0029-8 ▼
dell2783438383211.27.0.0020+24 ▲
spring073231391000.06.5.0024-2 ▼
capgo768234311000.07.0.0037+7 ▲
openclaw1680362210000.07.0.0021+1 ▲
edimax065039026100.07.4.00800
itsourcecode1063001944000.02.1.0033-12 ▼
themerex26055410000.08.1.0043+2 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9991100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-20230.882099.88.6
CVE-2026-34910.874799.710.0
CVE-2026-34908.851999.710.0
CVE-2026-48907.781099.510.0
CVE-2026-45659.760899.58.8
CVE-2026-34909.639099.210.0
CVE-2026-49160.538398.97.5
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9991KEV
CVE-2026-3491010.0.8747KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.7810KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-4828210.0.4239KEV
CVE-2026-5629010.0.3038KEV
CVE-2026-4890810.0.1482KEV
CVE-2026-1377310.0.0610
CVE-2026-5641510.0.0436
Most disclosures (vendor)
VendorCVEs
google608
linux476
microsoft266
oracle242
adobe145
red hat137
apache126
ibm72
spring70
capgo68
Most KEV additions (YTD)
VendorKEV
microsoft20
cisco11
apple7
google6
ivanti5
solarwinds4
adobe3
berriai3
fortinet3
smartertools3
Most-affected ecosystems
EcosystemAdvisories
Maven69
Packagist13
PyPI6
npm6
NuGet3
Fastest to KEV
CVEVendorDays
CVE-2026-10520ivanti0
CVE-2026-11645Google0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20245Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
CVE-2026-34910Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171694
CVE-2021-27102n/a2021-11-171694
CVE-2021-27101n/a2021-11-171694
CVE-2021-27103n/a2021-11-171694
CVE-2021-21017Adobe2021-11-171694
CVE-2021-28550Adobe2021-11-171694
CVE-2021-42013Apache Software Foundation2021-11-171694
CVE-2021-41773Apache Software Foundation2021-11-171694
CVE-2021-30858Apple2021-11-171694
CVE-2021-30860Apple2021-11-171694

Transactions

EXPLOIT PUBLISHED — lepture mistune: 8 CVEs (CVE-2026-59922, CVE-2026-59923, CVE-2026-59924, CVE-2026-59925, CVE-2026-59927, CVE-2026-59928, CVE-2026-59929, CVE-2026-59930). Public exploit references added.

EXPLOIT PUBLISHED — Wireshark Foundation Wireshark: 8 CVEs (CVE-2026-15165, CVE-2026-15166, CVE-2026-15167, CVE-2026-15168, CVE-2026-15169, CVE-2026-15170, CVE-2026-15171, CVE-2026-15172). Public exploit references added.

EXPLOIT PUBLISHED — gofiber fiber: 3 CVEs (CVE-2026-44332, CVE-2026-45045, CVE-2026-53624). Public exploit references added.

EXPLOIT PUBLISHED — isaacs node-tar: 3 CVEs (CVE-2026-59871, CVE-2026-59873, CVE-2026-59874). Public exploit references added.

EXPLOIT PUBLISHED — nodeca js-yaml: 3 CVEs (CVE-2026-59868, CVE-2026-59869, CVE-2026-59870). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-15105 (davenardella snap7). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-15164 (Wireshark Foundation ciscodump). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-24700. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-44512 (onnx). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54499 (stanfordnlp stanza). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54527 (jupyterlab-git). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54528 (jupyterlab-git). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-55470 (hapifhir org.hl7.fhir.core). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-55471 (hapifhir org.hl7.fhir.core). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-55761 (portainer). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56297 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-58191 (appium). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-59879 (immutable-js). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-59880 (immutable-js). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-59890 (pypa setuptools). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-59939 (httplib2). Public exploit reference added.

Yesterday's Results

How to read these box scores · glossary

362 CVEs published. 25 box scores, 337 table rows — nothing truncated.

Creative Themes Blocksy Companion — Blocksy Companion Pro < 2.1.47 Unauthenticated File Upload via save_attachments
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0357   88.5     —
AFFECTED
  Product            Versions     Fixed
  Blocksy Companion  unspecified  2.1.47
TIMELINE
  Jun 30  Reserved by CNA
  Jul 8   Published (CNA: VulnCheck)
CWE-434 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
Horde VFS < 3.0.1 OS Command Injection via Horde_Vfs_Smb Driver
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   H   H   H    7.7   .0327   87.4     —
AFFECTED
  Product  Versions     Fixed
  Vfs      unspecified  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 8   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
bentoml OpenLLM Model Repository Directory Name common.py async_run_command command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    1.9   .0222   81.3     —
AFFECTED
  Product  Versions  Fixed
  OpenLLM  0.6.30 –  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 8   Published (CNA: VulDB)
CWE-78, CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Analyzed
n/a n/a — An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0185   77.5     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jan 23  Reserved by CNA
  Jul 8   Public exploit reference published
  Jul 8   Published (CNA: mitre)
CWE-78 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Analyzed
christopherthielen check-peer-dependencies peerDependencies packageUtils.js shelljs.exec os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    5.3   .0182   77.0     —
AFFECTED
  Product                  Versions  Fixed
  check-peer-dependencies  4.3.0 –   —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 8   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
joedolson My Calendar – Accessible Event Manager — My Calendar <= 3.7.8 - Unauthenticated SQL Injection via 'mc_auth' and 'mc_host' Parameters
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0158   73.6     —
AFFECTED
  Product                                 Versions     Fixed
  My Calendar – Accessible Event Manager  unspecified  —
TIMELINE
  Apr 22  Reserved by CNA
  Jul 8   Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0151   72.5     —
AFFECTED
  Product           Versions     Fixed
  Apache Gravitino  unspecified  —
TIMELINE
  Apr 16  Reserved by CNA
  Jul 8   Published (CNA: apache)
CWE-20 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Deferred
n/a n/a — An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0147   71.7     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jan 23  Reserved by CNA
  Jul 8   Published (CNA: mitre)
CWE-78 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Analyzed
n/a n/a — An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0147   71.7     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jan 23  Reserved by CNA
  Jul 8   Published (CNA: mitre)
CWE-78 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Analyzed
n/a n/a — An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0147   71.7     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jan 23  Reserved by CNA
  Jul 8   Published (CNA: mitre)
CWE-78 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Analyzed
tombgtn Simple Coherent Form — Simple Coherent Form <= 2.4.13 - Unauthenticated Arbitrary File Deletion via 'id' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0117   64.9     —
AFFECTED
  Product               Versions     Fixed
  Simple Coherent Form  unspecified  —
TIMELINE
  Jul 2   Reserved by CNA
  Jul 8   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0109   62.7     —
AFFECTED
  Product  Versions    Fixed
  fluentd  < 1.19.3 –  —
TIMELINE
  May 4   Reserved by CNA
  Jul 8   Published (CNA: GitHub_M)
CWE-22 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Analyzed
Jssor Slider by jssor.com <= 3.1.24 - Unauthenticated Arbitrary File Read via 'url' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0103   61.0     —
AFFECTED
  Product                    Versions     Fixed
  Jssor Slider by jssor.com  unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 8   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
globalprogramming WHMCS Bridge — WHMCS Bridge <= 6.9 - Unauthenticated Arbitrary File Upload via 'ccce' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0103   61.0     —
AFFECTED
  Product       Versions     Fixed
  WHMCS Bridge  unspecified  —
TIMELINE
  Jul 2   Reserved by CNA
  Jul 8   Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
totalbounty Widget Logic Visual — Widget Logic Visual <= 1.52 - Authenticated (Subscriber+) Remote Code Execution via 'nwlv[cod-tag]' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0095   58.6     —
AFFECTED
  Product              Versions     Fixed
  Widget Logic Visual  unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 8   Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 4 references · NVD status: Deferred
n/a n/a — An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0093   57.8     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 8   Published (CNA: mitre)
CWE-94 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Deferred
CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0085   55.3     —
AFFECTED
  Product  Versions             Fixed
  CoreWCF  >= 1.9.0, < 1.9.1 –  —
TIMELINE
  Jun 15  Reserved by CNA
  Jul 8   Published (CNA: GitHub_M)
CWE-400, CWE-835 · CNA: GitHub_M · CVSS v3.1 · 6 references · NVD status: Deferred
Palo Alto Networks Cloud NGFW — PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    7.2   .0083   54.9     —
AFFECTED
  Product        Versions     Fixed
  Cloud NGFW     unspecified  All
  PAN-OS         12.1.0 –     12.1.8
  Prisma Access  11.2.0 –     11.2.7-h18
TIMELINE
  Nov 3   Reserved by CNA
  Jul 8   Published (CNA: palo_alto)
CWE-787 · CNA: palo_alto · CVSS v4.0 · 2 references · NVD status: Modified
open-telemetry opentelemetry-js — OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0078   53.3     —
AFFECTED
  Product           Versions   Fixed
  opentelemetry-js  < 2.9.0 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 8   Published (CNA: GitHub_M)
CWE-248 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
wpdo5ea DoLogin Security — DoLogin Security <= 4.3 - Unauthenticated Authentication Bypass via Insufficient Randomness via 'dologin' Parameter Weak PRNG Token
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0077   52.8     —
AFFECTED
  Product           Versions     Fixed
  DoLogin Security  unspecified  —
TIMELINE
  Jul 2   Reserved by CNA
  Jul 8   Published (CNA: Wordfence)
CWE-338 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Deferred
smallnest rpcx — rpcx - Denial of Service via Gzip Decompression Bomb in Wire Protocol
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0074   51.9     —
AFFECTED
  Product  Versions     Fixed
  rpcx     unspecified  047aec18efa7d037105e2b72c36dd2ae05e1acc6
TIMELINE
  Jul 7   Reserved by CNA
  Jul 8   Published (CNA: VulnCheck)
CWE-409 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
nats-io nats-server — NATS Server: MQTT partial CONNECT packets can exhaust pre-auth memory
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0074   51.9     —
AFFECTED
  Product      Versions     Fixed
  nats-server  < 2.12.12 –  —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 8   Published (CNA: GitHub_M)
CWE-400 · CNA: GitHub_M · CVSS v3.1 · 5 references · NVD status: Analyzed
nats-io nats-server — NATS Server: Pre-auth server crash via double INFO in leafnode handshake
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0074   51.9     —
AFFECTED
  Product      Versions     Fixed
  nats-server  < 2.11.17 –  —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 8   Published (CNA: GitHub_M)
CWE-476 · CNA: GitHub_M · CVSS v3.1 · 5 references · NVD status: Analyzed
U-Boot < 2026.07-rc2 Buffer Overflow in nfs_readlink_reply() via NFS READLINK
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   L   H    8.8   .0074   51.8     —
AFFECTED
  Product  Versions     Fixed
  u-boot   unspecified  —
TIMELINE
  Mar 3   Reserved by CNA
  Jul 8   Published (CNA: VulnCheck)
CWE-120 · CNA: VulnCheck · CVSS v4.0 · 6 references · NVD status: Modified
U-Boot 2026.04-rc3 Integer Underflow DoS via tcp_rx_state_machine()
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0071   50.6     —
AFFECTED
  Product  Versions     Fixed
  u-boot   unspecified  —
TIMELINE
  Mar 3   Reserved by CNA
  Jul 8   Published (CNA: VulnCheck)
CWE-191 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-554707.549.6hapifhirorg.hl7.fhir.coreCWE-1333HAPI FHIR: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection all…
CVE-2026-121539.849.3rabilalWP Learn ManagerCWE-862WP Learn Manager <= 1.1.8 - Missing Authorization to Unauthenticated Arbitrar…
CVE-2026-290076.949.2u-bootu-bootCWE-125U-Boot 2026.04-rc3 Out-of-Bounds Read in tcp_rx_state_machine via tcp.c
CVE-2026-598798.749.0immutable-jsimmutable-jsCWE-190Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
CVE-2026-598808.749.0immutable-jsimmutable-jsCWE-407Immutable.js: Hash-collision algorithmic complexity denial of service in Immu…
CVE-2026-144549.848.7TONYCImagerCWE-196Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as…
CVE-2026-568439.948.6WebprosPleskCWE-522Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 …
CVE-2026-598212.148.6BerriAIlitellmCWE-94LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
CVE-2026-599287.548.4lepturemistuneCWE-407Mistune block_parser: quadratic-time parsing on long lists of repeated refere…
CVE-2026-123788.148.2UnknownAppointment Booking Calendar Plugin and Scheduling Plugin—BookingPress <= 1.1.28 - Unauthenticated PHP Object Injection
CVE-2026-598687.548.1nodecajs-yamlCWE-770js-yaml: YAML merge-key chains can force quadratic CPU consumption
CVE-2026-598707.548.1nodecajs-yamlCWE-770js-yaml quadratic-complexity denial of service via YAML11_SCHEMA !!omap parsing
CVE-2026-598717.548.1isaacsnode-tarCWE-704node-tar: Process crash via PAX numeric path type confusion
CVE-2026-599227.548.1lepturemistuneCWE-407Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `…
CVE-2026-599257.548.1lepturemistuneCWE-407inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` e…
CVE-2026-106987.248.1ProgressMOVEit TransferCWE-943Table scope bypass vulnerability in custom reports
CVE-2026-597257.547.8socketiosocket.ioCWE-404Socket.IO: Engine.IO Polling Transport Connection Exhaustion
CVE-2026-498667.547.4libp2pjs-libp2pCWE-770libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays
CVE-2026-566697.547.4elysiajselysiaCWE-407Elysia: Inefficient Algorithmic Complexity and Interpretation Conflict
CVE-2026-313099.847.0n/an/aCWE-862Improper authorization in the /tequilapi/config/user endpoint of Mysterium No…
CVE-2026-599358.747.0py-pdfpypdfCWE-835pypdf: Possible infinite loop for not terminated inline images (ASCII85 and A…
CVE-2026-441607.547.0fluentfluentdCWE-409Fluentd: Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and…
CVE-2026-491467.546.5PETDANCEApp::AckCWE-770App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbou…
CVE-2026-597247.546.5socketiosocket.ioCWE-20Socket.IO: Engine.IO WebTransport SID DoS
CVE-2026-598877.546.5markdown-itlinkify-itCWE-407linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on…
CVE-2026-96959.846.3Dassault SystèmesDELMIA AprisoCWE-287Improper Authentication vulnerability affecting DELMIA Apriso from Release 20…
CVE-2026-582087.546.1nats-ionats-serverCWE-248NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Serv…
CVE-2026-547756.546.0CoreWCFCoreWCFCWE-248CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-valu…
CVE-2026-574808.745.6parse-communityparse-serverCWE-407Parse Server: Denial of service via exponential-time processing of deeply nes…
CVE-2026-144828.845.5shen2多说社会化评论框CWE-269多说社会化评论框 <= 1.2 - Unauthenticated Privilege Escalation via api.php 'option'/'…
CVE-2026-540619.145.2dgraph-iodgraphCWE-306Dgraph Alpha group stores can be replaced via unauthenticated external snapsh…
CVE-2026-592575.344.7n8nn8nCWE-89n8n - SQL Injection in MySQL v1 executeQuery Operation via Expression Interpo…
CVE-2026-554718.744.5hapifhirorg.hl7.fhir.coreCWE-611HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon Transform…
CVE-2026-582076.544.1nats-ionats-serverCWE-190NATS Server: Remote crash via integer overflow in Connz pagination
CVE-2026-598739.243.9isaacsnode-tarCWE-770node-tar: Decompression/parse DoS via unlimited input
CVE-2026-557782.143.7parse-communityparse-serverCWE-434Parse Server: Stored XSS via non-standard file extension bypassing file uploa…
CVE-2026-598697.543.2nodecajs-yamlCWE-407js-yaml: YAML merge-key chains can force quadratic CPU consumption
CVE-2026-150678.842.4SnowflakeTerraform Provider for SnowflakeCWE-89Multiple Security Vulnerabilities in Terraform Provider for Snowflake Could A…
CVE-2026-557607.542.4jknackhandlebars.javaCWE-22handlebars.java FileTemplateLoader Path Traversal
CVE-2026-545279.342.3jupyterlabjupyterlab-gitCWE-79JupyterLab Git: Stored XSS leading to RCE
CVE-2026-599275.342.4lepturemistuneCWE-674Mistune directives/include: mutual `.. include::` recursion crashes the rende…
CVE-2026-574812.342.3parse-communityparse-serverCWE-200Parse Server: LiveQuery discloses object data to a subscriber across an ACL r…
CVE-2026-555758.242.0harttleliquidjsCWE-770LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filte…
CVE-2026-151218.842.0GoogleChromeCWE-416Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a r…
CVE-2026-352116.541.9OpenCTI-PlatformopenctiCWE-94OpenCTI: Elasticsearch Painless Script Injection via GraphQL `script` filter …
CVE-2026-544997.541.7stanfordnlpstanzaCWE-502Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders
CVE-2026-443325.341.6gofiberfiberCWE-203Fiber: Username Enumeration via Timing Oracle in BasicAuth Default Authorizer
CVE-2026-598228.841.5BerriAIlitellmCWE-287LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
CVE-2026-599386.941.5py-pdfpypdfCWE-789pypdf: Possible large memory usage for wrong image dimensions
CVE-2026-597038.741.4repomixrepomixCWE-552repomix - Local File Inclusion via file:// URL Scheme in Git Clone Endpoint
CVE-2026-581928.641.3appiumappiumCWE-22Appium: Unauthenticated arbitrary file/directory deletion in @appium/storage-…
CVE-2026-554298.741.0codercoderCWE-639Coder's workspace app upsert allows cross-workspace agent rebinding via user-…
CVE-2026-90749.840.9IBMAPI ConnectCWE-89IBM API Connect SQL Injection
CVE-2026-598755.340.9isaacsnode-tarCWE-248node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
CVE-2026-562734.940.5FlowiseFlowiseCWE-22Flowise - Path Traversal in Vector Store basePath Parameter
CVE-2026-106997.540.2ProgressMOVEit TransferCWE-401Memory leak in SFTP service can result in a denial of service in MOVEit Transfer
CVE-2026-557617.140.1portainerportainerCWE-287Portainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitia…
CVE-2026-545918.140.0ronfasyncsshCWE-22AsyncSSH: SCP Path Traversal to Arbitrary File Write
CVE-2026-448407.540.0dgraph-iodgraphCWE-943Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query
CVE-2026-491457.539.8PETDANCEApp::AckCWE-73App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-fr…
CVE-2026-491477.539.8PETDANCEApp::AckCWE-150App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape s…
CVE-2026-515357.539.8n/an/aCWE-400In OpENer 2.3.0 (commit 76b95cf), a resource exhaustion (Denial of Service) v…
CVE-2026-148918.739.7HashiCorpNomadCWE-59Nomad vulnerable to sandbox escape in Docker task driver
CVE-2026-355528.139.3n/an/aCWE-862In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0…
CVE-2026-558747.739.3seaweedfsseaweedfsCWE-22SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows c…
CVE-2026-601057.739.3Monsta Limited of New ZealandMonsta FTPCWE-918Monsta FTP < 2.14.5 SSRF via IPv4-Mapped IPv6 Address Bypass
CVE-2026-534827.539.3DellPowerProtect Data DomainCWE-190Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-97019.839.3joe007EventerCWE-289Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privi…
CVE-2026-440257.538.9fluentfluentdCWE-306Fluentd: Exposure of Sensitive Information via Monitor Agent API
CVE-2026-145005.338.7sayantandas20Bulk Order Update for WooCommerceCWE-22Bulk Order Update for WooCommerce <= 1.6 - Unauthenticated Arbitrary File Rea…
CVE-2026-83079.838.4Webbeyaz Web DesignMediküm WebCWE-89SQLi in Webbeyaz's Mediküm Web
CVE-2026-598078.938.4ComposioHQcomposioCWE-73Composio SDK < 0.2.32-beta.283 - Sensitive File Upload via tool-file-uploads.ts
CVE-2026-597318.238.2withastroastroCWE-647Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path …
CVE-2026-476466.138.3MicrosoftDynamics 365 Customer VoiceCWE-79Dynamics 365 Customer Voice Spoofing Vulnerability
CVE-2026-598206.138.2BerriAIlitellmCWE-22LiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path T…
CVE-2026-582526.538.2nats-ionats-serverCWE-285NATS Server: Subscribe Authz Bypass via Wildcard-Overlap
CVE-2026-62307.538.1tainacanTainacanCWE-89Tainacan <= 1.0.3 - Unauthenticated SQL Injection via 'geoquery' REST API Par…
CVE-2026-97007.538.1joe007EventerCWE-89Eventer <= 4.4.2 - Unauthenticated SQL Injection via 'code' Parameter
CVE-2026-582516.538.1nats-ionats-serverCWE-285NATS Server: Queue Subscribe Authz Bypass
CVE-2026-450455.338.1gofiberfiberCWE-290Fiber: X-Real-IP Spoofing via Header.Add() in BalancerForward
CVE-2026-599245.938.0lepturemistuneCWE-22Mistune: Arbitrary File Read via Include directive path traversal
CVE-2026-150537.537.9TaniumTanium ServerCWE-789Tanium addressed a denial of service vulnerability in Tanium Server.
CVE-2026-151546.537.9Red HatRed Hat OpenShift AI 2.25CWE-1333Guardrails-detectors: guardrails-detectors: unauthenticated regular-expressio…
CVE-2026-151328.837.3GoogleChromeCWE-457Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a re…
CVE-2026-562508.737.3CapgoCapgoCWE-862Capgo - Arbitrary R2 Object Deletion via Mutable r2_path in app_versions
CVE-2026-586568.737.3getgravgravCWE-598Grav API Plugin - Cross-Origin Admin Account Takeover via CORS Wildcard and J…
CVE-2026-98427.537.2pixelgradeBackstage – Customizer Demo AccessCWE-269Backstage <= 1.4.2 - Unauthenticated Privilege Escalation via Permissive Demo…
CVE-2026-598192.137.1BerriAIlitellmCWE-73LiteLLM: Local file read via request-supplied OIDC file references
CVE-2025-31106.936.9OpenVPNAccess ServerCWE-444OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences in…
CVE-2026-118274.936.8GitLabGitLabCWE-522Insufficiently Protected Credentials in GitLab
CVE-2026-597029.236.6repomixrepomixCWE-918repomix - Server-Side Request Forgery via Unvalidated Repository URLs in POST…
CVE-2026-441617.236.6fluentfluentdCWE-918Fluentd: Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out…
CVE-2026-129364.936.6devitemsllcRecurio – Ultimate Subscription for WooCommerceCWE-89Recurio <= 1.1.3 - Authenticated (Shop Manager+) SQL Injection via 'data' Par…
CVE-2026-600007.536.5OpenBSDOpenSSHCWE-770sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of serv…
CVE-2026-582137.136.5nats-ionats-serverCWE-74NATS Server: MQTT SUBSCRIBE Protocol Injection via Leaf Node/Route Forwarding…
CVE-2026-143624.936.5HashiCorpShared libraryCWE-770Denial of service via crafted push/pull gossip message in memberlist
CVE-2026-120975.336.3saadiqbalUser ManagementCWE-862User Management <= 1.2 - Missing Authorization to Unauthenticated Plugin Sett…
CVE-2026-598064.936.2gradio-appgradioCWE-601Gradio < 6.20.0 - Open Redirect and SSRF via /gradio_api/file= endpoint
CVE-2026-586545.336.1GravGravCWE-434Grav - Arbitrary File Upload via Avatar Endpoint
CVE-2026-598748.735.9isaacsnode-tarCWE-835node-tar: Negative tar entry size causes infinite loop in archive replace
CVE-2026-547795.936.0CoreWCFCoreWCFCWE-294CoreWCF: SAML token replay protection is inoperative
CVE-2026-562268.735.8Cap-gocapgoCWE-200Capgo - Unauthenticated Organization Data Disclosure via get_orgs_v6 RPC
CVE-2026-151345.535.7CodeAstroSimple Online Leave Management SystemCWE-74CodeAstro Simple Online Leave Management System index.php sql injection
CVE-2026-151355.535.7code-projectsOnline Food Order SystemCWE-74code-projects Online Food Order System edit_food_items.php sql injection
CVE-2026-555968.735.6udecodeplateCWE-79Plate: Media embed provider metadata can bypass URL sanitization and execute …
CVE-2026-598188.135.6etcd-ioetcdCWE-295etcd: gRPC client listener does not enforce `--client-crl-file` certificate r…
CVE-2026-560028.835.4X.OrglibXfont2CWE-122libXfont2 PCF Font Parsing Heap Buffer Overflow
CVE-2026-599397.535.1httplib2httplib2CWE-409httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Res…
CVE-2026-560868.834.5DellPowerProtect Data DomainCWE-863Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release …
CVE-2026-107067.534.3Adalo No-Code App BuilderApp Builder—Exposure of Sensitive Information to an Unauthorized attacker
CVE-2026-592627.134.3affinemonorepoCWE-862AFFiNE - Unauthorized Document Edit History Access via GraphQL histories Field
CVE-2026-5478210.034.2CoreWCFCoreWCFCWE-290CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature vali…
CVE-2026-150362.134.2n/aHarnessCWE-285Harness gitspaces Endpoint list_all.go getAuthorizedSpaces authorization
CVE-2026-151078.834.1GoogleChromeCWE-416Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed …
CVE-2026-151168.834.1GoogleChromeCWE-416Use after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a re…
CVE-2026-151188.834.1GoogleChromeCWE-416Use after free in Input in Google Chrome prior to 150.0.7871.115 allowed a re…
CVE-2026-151268.834.1GoogleChromeCWE-416Use after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a re…
CVE-2026-151338.834.1GoogleChromeCWE-416Use after free in InterestGroups in Google Chrome prior to 150.0.7871.115 all…
CVE-2026-546528.134.0blakeblackshearfrigateCWE-269Frigate viewer can read logs exposing admin and camera credentials
CVE-2026-31449.834.0IBMAPI ConnectCWE-1392IBM API Connect Default Credentials
CVE-2026-554048.834.0yt-dlpyt-dlpCWE-74yt-dlp: Downstream command injection via improper sanitization of yt-dlp --wr…
CVE-2026-545287.133.9jupyterlabjupyterlab-gitCWE-178jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded…
CVE-2026-585015.933.6mvantellingenpython-zeepCWE-918Zeep SSRF because Settings.forbid_external is not enforced
CVE-2026-119035.433.6ProgressMOVEit TransferCWE-79Stored XSS in MOVEit Transfer Ad Hoc module
CVE-2026-68187.233.4e4jvikwpVikBooking Hotel Booking Engine & PMSCWE-79VikBooking Hotel Booking Engine & PMS <= 1.8.8 - Unauthenticated Stored Cross…
CVE-2026-598906.133.4pypasetuptoolsCWE-176setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization c…
CVE-2026-68965.433.1GitLabGitLabCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…
CVE-2026-558308.332.9zopefoundationRestrictedPythonCWE-184RestrictedPython guard hooks can be shadowed via positional-only arguments
CVE-2026-36888.132.9wcloversWCFM Membership – WooCommerce Memberships for Multivendor MarketplaceCWE-639WCFM - WooCommerce Multivendor Membership <= 2.11.10 - Insecure Direct Object…
CVE-2026-562467.232.9CapgoCapgoCWE-285Capgo - Cross-Organization Authorization Bypass via Scoped API Key Privilege …
CVE-2026-560038.832.9X.OrglibXfont2CWE-122libXfont2 computeProps Property Buffer Heap Buffer Overflow
CVE-2026-151258.832.6GoogleChromeCWE-863Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.11…
CVE-2026-59225.932.5HP Inc.Poly CCXCWE-79Poly Voice – Potential Unauthorized Modification of WebUI using XSS Attack
CVE-2026-554335.432.2codercoderCWE-862Coder: Devcontainer recreate endpoint missing write authorization allows read…
CVE-2026-545905.932.1ronfasyncsshCWE-22AsyncSSH AuthorizedKeysFile username substitution bypass through ~ and enviro…
CVE-2026-560018.832.0X.OrglibXfont2CWE-122libXfont2 BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow
CVE-2026-68207.232.0e4jvikwpVikBooking Hotel Booking Engine & PMSCWE-79VikBooking Hotel Booking Engine & PMS <= 1.8.8 - Unauthenticated Stored Cross…
CVE-2026-598057.131.7antiworkgumroadCWE-862Gumroad < 2026.07.06.2 - Insecure Direct Object Reference in PurchasesController
CVE-2026-84724.331.7GitLabGitLabCWE-862Missing Authorization in GitLab
CVE-2026-133205.431.6GitLabGitLabCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…
CVE-2026-150629.631.3SnowflakeSnowpark Python SDKCWE-89SQL Injection in Snowflake Snowpark Python SDK
CVE-2026-484924.931.2grokabilitysnipe-itCWE-862Snipe-IT's selectlist visibility is too permissive
CVE-2026-149663.131.1Black Lantern SecurityBBOTCWE-59Symlink guard bypass in unarchive module allows planting symlinks during extr…
CVE-2026-425055.331.0Go standard librarycrypto/tlsCWE-201Invoking Encrypted Client Hello privacy leak in crypto/tls
CVE-2026-556686.330.5filebrowserfilebrowserCWE-22File Browser: ScopedFs follows a dangling symlink on write, letting a scoped …
CVE-2026-62806.530.5NOMYSOFT Informatics Education and Consulting Inc.NomysemCWE-213Improper Access Control in Nomysoft Informatics' Nomysem
CVE-2026-151052.130.5davenardellasnap7CWE-119davenardella snap7 ReadVar Request s7_server.cpp PerformFunctionRead out-of-b…
CVE-2026-601245.329.9mispmispCWE-862MISP importModule missing authorization allows read-only users to modify even…
CVE-2026-601049.329.8bitwardenserverCWE-639Bitwarden Server < 2026.6.0 Authorization Bypass via Admin Auth Request
CVE-2026-586574.829.9GravGravCWE-79Grav - Stored CSS Injection via Markdown Image resize() Action
CVE-2026-585258.229.7MicrosoftMicrosoft Edge (Chromium-based)CWE-284Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2026-547735.929.6CoreWCFCoreWCFCWE-347CoreWCF: WS-Security signature substitution via document-wide Signature lookup
CVE-2026-582538.829.5nats-ionats-serverCWE-287NATS Server: Route API Auth Bypass
CVE-2026-142506.329.4themehunkTH Login RegistrationCWE-269Themehunk Login Registration <= 1.0.2 - Unauthenticated Privilege Escalation …
CVE-2026-86517.529.3ProgressMOVEit TransferCWE-290IPv6 Loopback Spoof via Trusted Host Header Bypasses Origin Check in MOVEit T…
CVE-2026-86507.529.2ProgressMOVEit TransferCWE-23Authenticated Path Traversal allows MOVEit admins to view arbitrary system files
CVE-2026-598777.529.2protobufjsprotobuf.jsCWE-835protobufjs: Denial of Service via infinite loop in .proto option parsing
CVE-2026-562978.328.7FreeRDPFreeRDPCWE-362FreeRDP - Use-After-Free via Race Condition in DRDYNVC Channel Callback
CVE-2026-53567.528.8latepointLatePoint – Calendar Booking Plugin for Appointments and EventsCWE-862LatePoint - Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Un…
CVE-2026-63522.728.7GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2026-150413.728.5Red HatRed Hat Directory Server 11CWE-208389-ds-base: 389-ds-base: non-constant-time comparison in pbkdf2-sha256 passw…
CVE-2026-562846.928.5Cap-gocapgoCWE-200Capgo - Unauthenticated Metrics Disclosure via get_total_metrics RPC
CVE-2026-117986.128.2the_champSocial Share, Social Login and Social Comments Plugin – Super SocializerCWE-79Social Share, Social Login and Social Comments Plugin <= 7.14.5 - Reflected C…
CVE-2026-572596.528.1Foxit Software Inc.Foxit PDF EditorCWE-611Foxit PDF Editor/Reader XDP XFA XXE arbitrary local file read
CVE-2026-534802.728.1DellPowerProtect Data DomainCWE-22Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-352107.127.9OpenCTI-PlatformopenctiCWE-639OpenCTI: Authorization Bypass via `synchronized-upsert` HTTP Header Injection
CVE-2026-601255.327.7mispmispCWE-863importModule function in MISP ignores per-organisation import module restrict…
CVE-2026-598764.827.5protobufjsprotobuf.jsCWE-1321protobufjs: Text Format string map parsing can mutate returned map object pro…
CVE-2026-582144.327.5nats-ionats-serverCWE-863NATS Server: MQTT subscribe ACL bypass via $MQTT.deliver.pubrel prefix (incom…
CVE-2026-562207.127.4CapgoCapgoCWE-863Capgo - Unauthorized Manifest Insertion via Read-Only Org Member
CVE-2026-599236.127.4lepturemistuneCWE-79Mistune: XSS via percent-encoded javascript URI bypass in safe_url()
CVE-2026-600925.127.4AVideoAVideoCWE-79AVideo - Stored Cross-Site Scripting via Unescaped User-Agent in Participants…
CVE-2026-151096.527.2GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a…
CVE-2026-74925.327.2GitLabGitLabCWE-862Missing Authorization in GitLab
CVE-2026-88019.827.0ProgressMOVEit TransferCWE-46File Extension Restriction Bypass in MOVEit Transfer
CVE-2026-151139.627.0GoogleChromeCWE-416Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.11…
CVE-2026-151128.827.0GoogleChromeCWE-416Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a re…
CVE-2026-151238.827.1GoogleChromeCWE-122Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 …
CVE-2026-151298.827.0GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a re…
CVE-2026-558734.326.7seaweedfsseaweedfsCWE-863SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management A…
CVE-2026-582094.326.7nats-ionats-serverCWE-863NATS Server: MQTT retained and QoS replay bypass subscribe deny filters
CVE-2026-599296.126.7lepturemistuneCWE-79Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and cha…
CVE-2026-599368.726.6py-pdfpypdfCWE-400pypdf: Possible infinite loop for not terminated inline images
CVE-2026-143737.726.5HashiCorpNomadCWE-862Nomad Docker driver Linux host namespace bypass
CVE-2026-599376.926.6py-pdfpypdfCWE-400pypdf: Possible long runtimes for repeated malformed cross-reference entries
CVE-2026-558776.126.2symfonyuxCWE-79Symfony UX: XSS in symfony/ux-icons via unsanitized SVG content in local file…
CVE-2026-554316.126.0codercoderCWE-522Coder's session token leaked to arbitrary hosts via `coder open app` for exte…
CVE-2026-598026.325.4PasswordPusherPasswordPusherCWE-183PasswordPusher < 2.8.1 - Redirect-Based XSS via data URI in URL Push Payload
CVE-2026-598956.125.0honojshonoCWE-79Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
CVE-2026-599265.325.0lepturemistuneCWE-79Mistune: XSS via unescaped class option in Admonition directive
CVE-2025-125064.324.9GitLabGitLabCWE-706Use of Incorrectly-Resolved Name or Reference in GitLab
CVE-2026-151228.324.7GoogleChromeCWE-20Insufficient validation of untrusted input in Codecs in Google Chrome on Wind…
CVE-2026-551958.724.3miurahrpy7zrCWE-409py7zr: Decompression bomb (zip bomb) denial of service via unchecked extracti…
CVE-2026-552068.724.3miurahrpy7zrCWE-407py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()
CVE-2026-64596.424.3wpdevteamEssential Addons for Elementor – Popular Elementor Templates & WidgetsCWE-79Essential Addons for Elementor <= 6.6.2 - Authenticated (Author+) Stored Cros…
CVE-2026-105706.424.3idocohSympl Repeater for ACF and ElementorCWE-79Sympl Repeater for ACF and Elementor <= 2.3 - Authenticated (Author+) Stored …
CVE-2026-151148.824.0GoogleChromeCWE-125Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.1…
CVE-2026-598826.523.9guzzlepsr7CWE-436guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
CVE-2026-581916.123.8appiumappiumCWE-79Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig*…
CVE-2026-554375.423.8codercoderCWE-79Coder vulnerable to stored HTML injection via workspace agent logs in AgentLo…
CVE-2026-554325.423.7codercoderCWE-862Coder's sub-agent app registration bypasses template port-sharing policy enfo…
CVE-2026-563606.323.5n8nn8nCWE-290n8n - Webhook Forgery via Unsigned POST Requests in ZendeskTrigger
CVE-2026-598047.622.8web-infra-devmidsceneCWE-306Midscene Bridge Server - Session Hijack via Unauthenticated WebSocket
CVE-2026-582545.322.9nats-ionats-serverCWE-863NATS Server: Incomplete fix for CVE-2026-33249: Leaf node connections bypass …
CVE-2026-54595.322.7wedevsUser Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User RegistrationCWE-639User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membersh…
CVE-2026-562985.322.7CapgoCapgoCWE-200Capgo - EXIF Metadata Exposure in App Information Image Upload
CVE-2026-151208.322.4GoogleChromeCWE-416Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 al…
CVE-2026-151117.522.4GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a re…
CVE-2026-151177.522.4GoogleChromeCWE-416Use after free in Payments in Google Chrome prior to 150.0.7871.115 allowed a…
CVE-2026-567755.322.2n8nn8nCWE-863n8n - Incorrect OAuth Scope Validation in Evaluation Test Runs Endpoints
CVE-2026-600029.422.0OpenBSDOpenSSHCWE-416ssh in OpenSSH before 10.4 can have a use-after-free when a server changes it…
CVE-2026-120414.422.1chatraChatra Live Chat + ChatBot + Cart SaverCWE-79Chatra Live Chat + ChatBot + Cart Saver <= 1.0.12 - Authenticated (Administra…
CVE-2026-598966.521.9honojshonoCWE-362hono/jsx does not isolate context per request, leading to cross-request data …
CVE-2026-562175.321.5CapgoCapgoCWE-284Capgo - Encrypted Bundle Policy Bypass via Direct PostgREST Update
CVE-2026-567785.321.4n8nn8nCWE-863n8n - Authorization Bypass in Public API Execution Retry Endpoint
CVE-2026-582115.421.2nats-ionats-serverCWE-863NATS Server: `no_auth_user` pre-CONNECT fast path bypasses user connection re…
CVE-2026-600016.521.0OpenBSDOpenSSHCWE-770sshd in OpenSSH before 10.4 does not always honor the minimum authentication …
CVE-2026-150342.120.4flask-dashboardFlask-MonitoringDashboardCWE-352flask-dashboard Flask-MonitoringDashboard cross-site request forgery
CVE-2026-411227.120.1DellPowerProtect Data DomainCWE-79Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release …
CVE-2026-555421.320.0grokabilitysnipe-itCWE-862Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL
CVE-2026-592535.319.9n8nn8nCWE-639n8n - Improper Authorization in Workflow Assignment to Folders
CVE-2026-360276.819.8n/an/aCWE-1313An issue in Code27 Companion Hub SQ3A.220705.003.A1 allows a physically proxi…
CVE-2026-360286.819.8n/an/aCWE-288A protection mechanism failure in the Code 27 Companion Hub allows an attacke…
CVE-2026-150636.319.8Red HatRed Hat OpenShift AI (RHOAI)CWE-306Trustyai-service-operator: trustyai service operator: gorch port bypass when …
CVE-2026-567765.319.4n8nn8nCWE-863n8n - Incorrect OAuth Scope Validation in Workflow Test Run Endpoint
CVE-2026-592618.419.2OpenClawOpenClawCWE-522OpenClaw < 2026.5.28 - Credential Override via Workspace Dotenv Files
CVE-2026-547847.419.0CoreWCFCoreWCFCWE-311CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
CVE-2026-559997.818.6X.Orgxorg-serverCWE-122xorg-server / xwayland glamor font atlas Heap Buffer Overflow
CVE-2026-150446.318.3Red HatRed Hat OpenShift AI (RHOAI)CWE-200Trustyai-service-operator: trustyai service operator: unauthenticated access …
CVE-2026-151244.318.3GoogleChromeCWE-20Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.…
CVE-2026-151304.318.3GoogleChromeCWE-602Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0…
CVE-2026-151314.318.3GoogleChromeCWE-20Inappropriate implementation in Navigation in Google Chrome prior to 150.0.78…
CVE-2026-391786.318.0n/an/aCWE-89A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated user…
CVE-2026-391796.318.0n/an/aCWE-89A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated user…
CVE-2026-151108.817.7GoogleChromeCWE-416Use after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed…
CVE-2026-539518.817.6copier-orgcopierCWE-22Copier: trust-prefix bypass via path traversal runs tasks unprompted
CVE-2025-147856.417.4seedprodWebsite Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance ModeCWE-79Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soo…
CVE-2026-67406.417.4posimyththemesNexter Blocks – Gutenberg Blocks, Page Builder & AI Website BuilderCWE-79Nexter Blocks <= 4.7.4 - Authenticated (Contributor+) Stored Cross-Site Scrip…
CVE-2026-67426.417.4mdempfleAdvanced iFrameCWE-79Advanced iFrame <= 2026.1 - Authenticated (Contributor+) Stored Cross-Site Sc…
CVE-2026-149673.117.5Black Lantern SecurityBBOTCWE-22Path traversal in github_workflows allows writing artifacts outside output di…
CVE-2026-86499.817.1ProgressMOVEit TransferCWE-943Institution scope bypass vulnerability in custom reports
CVE-2026-554367.417.1codercoderCWE-295Coder's AI Bridge Proxy skips TLS certificate verification in default configu…
CVE-2026-83106.116.4Webbeyaz Web DesignMediküm WebCWE-79Reflected XSS in Webbeyaz's Mediküm Web
CVE-2026-543444.716.2ToolJetToolJetCWE-78ToolJet GitHub Actions comment body shell injection exposes deployment secrets
CVE-2026-599955.416.1OpenBSDOpenSSHCWE-23sftp in OpenSSH before 10.4 does not properly constrain the location of downl…
CVE-2026-599965.416.1OpenBSDOpenSSHCWE-23scp in OpenSSH before 10.4 may place a file in the parent directory of an int…
CVE-2026-148964.216.1HashiCorpNomadCWE-863Nomad vulnerable to cross-namespace host volume claim deletion
CVE-2026-547817.415.8CoreWCFCoreWCFCWE-287CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are no…
CVE-2026-574395.015.3gchqCyberChefCWE-79CyberChef: Prototype pollution in Series Chart operation
CVE-2026-563594.815.2n8nn8nCWE-79n8n - Cross-Site Scripting in Credential Management OAuth2 Authorization URL
CVE-2026-151198.315.1GoogleChromeCWE-362Race in GetUserMedia in Google Chrome prior to 150.0.7871.115 allowed a remot…
CVE-2026-597238.814.9clineclineCWE-346Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` en…
CVE-2026-562935.314.7CapgoCapgoCWE-285Capgo - Stale Cross-Organization Authorization via Incomplete deploy_history …
CVE-2026-547803.714.5CoreWCFCoreWCFCWE-327CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass
CVE-2026-558498.514.3CycloneDXcyclonedx-node-npmCWE-78@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized `--workspace` Argument
CVE-2026-562834.814.2CapgoCapgoCWE-79Capgo - HTML Injection Leading to Open Redirection in Organization Settings
CVE-2026-63714.814.0Limatek System Inc.LimRAD NACCWE-79Stored XSS in Limatek's LimRAD NAC
CVE-2026-398227.813.9Go standard libraryosCWE-61Root escape via symlink plus trailing slash in os
CVE-2026-83155.413.1Webbeyaz Web DesignMediküm WebCWE-79Stored XSS in Webbeyaz's Mediküm Web
CVE-2026-151697.512.9Wireshark FoundationWiresharkCWE-122Heap-based Buffer Overflow in Wireshark
CVE-2026-563744.812.7ImageMagickImageMagickCWE-125ImageMagick - Heap Buffer Overflow in FTXT Encoder via format Parameter
CVE-2026-560009.012.5X.Orgxorg-x11-serverCWE-416xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()
CVE-2026-554386.812.6codercoderCWE-346Coder's workspace app CORS origin check can be bypassed via UUID-based subdom…
CVE-2026-151276.112.4GoogleChromeCWE-79Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.11…
CVE-2026-151286.112.4GoogleChromeCWE-79Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.11…
CVE-2026-536244.811.4gofiberfiberCWE-319Fiber: HSTS header never set in helmet middleware due to incorrect protocol c…
CVE-2026-88008.811.0ProgressMOVEit TransferCWE-863Cross-Org External Token Metadata accessible to AuditUser role
CVE-2026-554306.810.8codercoderCWE-345Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Ho…
CVE-2026-107087.510.4Adalo No-Code App BuilderApp Builder—Insufficiently Protected Credentials
CVE-2026-547747.410.1CoreWCFCoreWCFCWE-345CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing t…
CVE-2026-59236.09.6HP Inc.Poly CCXCWE-352Poly Voice – Potential Unauthorized Modification of WebUI using CSRF Attack
CVE-2026-151084.39.5GoogleChromeCWE-190Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 a…
CVE-2026-547837.49.0CoreWCFCoreWCFCWE-294CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature…
CVE-2026-445125.58.9onnxonnxCWE-476ONNX: Null Pointer Dereference in Upsample Version Converter Adapter (Zero In…
CVE-2026-558787.88.9symfonyuxCWE-22Symfony: Path Traversal in symfony/ux-toolkit Allows Arbitrary File Write and…
CVE-2026-599304.38.8lepturemistuneCWE-345Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` …
CVE-2026-97314.38.7wpkufWp Js DetectCWE-352Wp Js Detect <= 1.0.9 - Cross-Site Request Forgery to Plugin Settings Update
CVE-2026-572407.88.5Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Form Field Use-After-Free Remote Code Execution Vulne…
CVE-2026-563622.18.5ImageMagickImageMagickCWE-125ImageMagick - Heap-buffer-overflow Read in GetPixelIndex via OpenPixelCache M…
CVE-2026-151637.58.0Wireshark FoundationWiresharkCWE-835Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
CVE-2026-229277.87.8OmnissaOmnissa Workspace ONE® Tunnel for WindowsCWE-22Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalat…
CVE-2026-564378.47.7Fuji Electric Co.,Ltd.PupsmanCWE-427Uncontrolled search path element issue exists in Pupsman versions prior to 3.…
CVE-2026-599986.57.5OpenBSDOpenSSHCWE-573sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: G…
CVE-2026-598975.37.5honojshonoCWE-348Hono: API Gateway v1 adapter can drop a distinct repeated request header valu…
CVE-2026-100378.87.1CanonicalUbuntuCWE-20Sandbox Escape in Ubuntu OpenJDK Packages via xdg-desktop-portal
CVE-2026-599975.46.9OpenBSDOpenSSHCWE-1284internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 comm…
CVE-2026-572567.86.8Foxit Software Inc.Foxit PDF EditorCWE-416Foxit Editor/Reader List Box Format Use-After-Free Vulnerability
CVE-2026-599466.16.7composercomposerCWE-22Composer: Path traversal in package bin field lets dependencies chmod arbitra…
CVE-2026-584946.56.5bytecodealliancewasmtimeCWE-281Wasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destination
CVE-2026-151675.56.5Wireshark FoundationWiresharkCWE-121Stack-based Buffer Overflow in Wireshark
CVE-2026-131267.86.5Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulne…
CVE-2026-131277.86.5Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulne…
CVE-2026-131287.86.5Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Doc Object Use-After-Free Remote Code Execution Vulne…
CVE-2026-131297.86.5Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulne…
CVE-2026-572377.86.5Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulne…
CVE-2026-572387.86.5Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulne…
CVE-2026-572427.86.5Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Page Use-After-Free Vulnerability
CVE-2026-572447.86.5Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Form Control Use-After-Free Vulnerability
CVE-2026-572457.86.5Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Signature Hyperlink Use-After-Free Vulnerability
CVE-2026-572467.86.5Foxit Software Inc.Foxit PDF EditorCWE-120Foxit PDF Editor/Reader Signature Buffer Overflow Vulnerability
CVE-2026-572477.86.5Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Field Use-After-Free Vulnerability
CVE-2026-572487.86.5Foxit Software Inc.Foxit PDF EditorCWE-763Foxit PDF Editor/Reader Annotation Improper Release Vulnerability
CVE-2026-572497.86.5Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Annotation Use-After-Free Vulnerability
CVE-2026-572507.86.5Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Form Field Use-After-Free Vulnerability
CVE-2026-572517.86.5Foxit Software Inc.Foxit PDF EditorCWE-129Foxit PDF Editor/Reader Cloud Appearance Buffer Overflow Vulnerability
CVE-2026-572527.86.5Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader AcroForm Use-After-Free Remote Code Execution Vulnera…
CVE-2026-572547.86.5Foxit Software Inc.Foxit PDF EditorCWE-843Foxit PDF Editor/Reader Annotation Type Confusion Vulnerability
CVE-2026-572607.86.5Foxit Software Inc.Foxit PDF EditorCWE-787Security vulnerability in Foxit PDF Editor/Reader — U3D Adobe Mesh Decompress…
CVE-2026-572397.86.4Foxit Software Inc.Foxit PDF EditorCWE-427Foxit PDF Editor/Reader Local Privilege Escalation
CVE-2026-598836.16.2guzzleguzzleCWE-346Guzzle: Cookie Disclosure and Injection via IP-Address Domains
CVE-2026-599487.05.8composercomposerCWE-22Composer: Arbitrary file write outside vendor via malicious transitive packag…
CVE-2026-578958.55.5Fuji Electric Co.,Ltd.PupsmanCWE-276Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0…
CVE-2026-572586.15.4Foxit Software Inc.Foxit PDF EditorCWE-125Foxit PDF Editor/Reader Crash via Malformed PRC 3D Stream
CVE-2026-508125.55.4n/an/aCWE-476A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 a…
CVE-2026-599997.55.3OpenBSDOpenSSHCWE-348In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take pr…
CVE-2026-508136.15.2n/an/aCWE-126An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacke…
CVE-2026-151655.55.0Wireshark FoundationWiresharkCWE-122Heap-based Buffer Overflow in Wireshark
CVE-2026-151665.55.0Wireshark FoundationWiresharkCWE-121Stack-based Buffer Overflow in Wireshark
CVE-2026-151705.55.0Wireshark FoundationWiresharkCWE-122Heap-based Buffer Overflow in Wireshark
CVE-2026-572416.14.7Foxit Software Inc.Foxit PDF EditorCWE-125Foxit PDF Editor/Reader Page Out-of-bounds Read Vulnerability
CVE-2026-572436.14.7Foxit Software Inc.Foxit PDF EditorCWE-125Foxit PDF Editor/Reader Page Out-of-bounds Read Vulnerability
CVE-2026-572536.14.7Foxit Software Inc.Foxit PDF EditorCWE-125Foxit PDF Editor/Reader PDF File Parsing Out-Of-Bounds Read Information Discl…
CVE-2026-572556.14.7Foxit Software Inc.Foxit PDF EditorCWE-125Security vulnerability in Foxit PDF Editor/Reader — OOB Read via NaN-Bypass C…
CVE-2026-572576.14.7Foxit Software Inc.Foxit PDF EditorCWE-125Security vulnerability in Foxit PDF Editor/Reader — PRC 3D BRep Renderer Heap…
CVE-2026-547764.44.6CoreWCFCoreWCFCWE-306CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that …
CVE-2026-120024.74.2smubSmash Balloon Social Photo Feed – Easy Social Feeds PluginCWE-352Smash Balloon Social Photo Feed – Easy Social Feeds Plugin <= 6.11.1 - Cross-…
CVE-2026-599474.73.9composercomposerCWE-532Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT …
CVE-2026-143614.73.1HashiCorpToolingCWE-59Consul-template is vulnerable to path redirection in writeToFile through syml…
CVE-2026-151683.32.7Wireshark FoundationWiresharkCWE-457Use of Uninitialized Variable in Wireshark
CVE-2026-547786.22.6CoreWCFCoreWCFCWE-362CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution
CVE-2026-151153.32.5GoogleChromeCWE-20Insufficient validation of untrusted input in WebAppInstalls in Google Chrome…
CVE-2026-151645.52.2Wireshark FoundationciscodumpCWE-122Heap-based Buffer Overflow in ciscodump
CVE-2026-151715.52.2Wireshark FoundationWiresharkCWE-476NULL Pointer Dereference in Wireshark
CVE-2026-151725.52.2Wireshark FoundationWiresharkCWE-606Unchecked Input for Loop Condition in Wireshark
CVE-2026-547776.51.8CoreWCFCoreWCFCWE-367CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe in…
CVE-2026-151745.50.6Wireshark FoundationWiresharkCWE-122Heap-based Buffer Overflow in Wireshark
CVE-2026-151735.50.5Wireshark FoundationWiresharkCWE-122Heap-based Buffer Overflow in Wireshark

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-08 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.