boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Thursday, July 9, 2026 · all times UTC← 2026-07-08 · archive · 2026-07-10 →

Security Box Score — July 9, 2026

276 CVEs published, led by Juniper Networks (22).

276 CVEs published July 9, 2026: 33 critical, 103 high, 115 medium, 24 low; 0 in the KEV catalog at press time; 16 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 251 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published196914372——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

647 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux37151712086653011120.17.5.0014-58 ▼
google791344149608549387760.47.8.0024-483 ▼
microsoft52809615531896286202.57.8.0046-155 ▼
red hat332551210112616200.06.5.0031+2 ▲
apple01042287228876.76.5.00320
canonical1212685000.05.5.0011+1 ▲
suse61941140000.08.6.0042+6 ▲
freebsd01601240000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ubiquiti2536142110338.38.8.0049+25 ▲
cisco830614100561136.77.5.0057+5 ▲
palo alto networks1425131471328.04.7.0028+14 ▲
netgear01700161000.04.3.0024-17 ▼
checkpoint0915303111.17.5.0410-2 ▼
fortinet09432028333.38.3.0076-2 ▼
ivanti09450025555.68.8.5187-3 ▼
f50843104112.58.9.02250
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache52207388077113310.57.3.0057-1 ▼
mozilla3591218290900.07.3.0025-2 ▼
gitlab73805276425.34.7.0032+7 ▲
github171150000.06.0.0039+1 ▲
docker070520000.08.2.0016-2 ▼
drupal0511304120.05.1.00260
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle02701321161842720.78.8.0040-1 ▼
adobe314713537921932.06.1.0021-120 ▼
ibm21263842460600.07.5.0034-3 ▼
progress101931420600.07.5.0037+5 ▲
solarwinds07232010457.17.5.4001-3 ▼
veeam042200100.09.0.0052-1 ▼
zohocorp031110000.08.4.01700
atlassian000000130———0
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology02325133000.05.6.0025-5 ▼
siemens4130760000.07.1.0023-3 ▼
d-link1130535300.06.0.0059-7 ▼
rockwell automation071510000.08.7.00300
abb060420000.07.2.0018-4 ▼
schneider electric060420000.07.8.0042-1 ▼
moxa050320000.07.0.00290
dahua030111000.06.9.00360
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester2899005346000.05.5.0029-7 ▼
dell2783438383211.27.0.0020+20 ▲
spring073231391000.06.5.0024-53 ▼
capgo768234311000.07.0.0037+7 ▲
openclaw1680362210000.07.0.0021+1 ▲
edimax065039026100.07.4.00800
itsourcecode1063001944000.02.1.0033-12 ▼
themerex26055410000.08.1.0043+2 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-10520.9991100.010.0
CVE-2026-20253.969499.99.8
CVE-2026-35273.954799.99.8
CVE-2026-20230.882099.88.6
CVE-2026-34910.874799.710.0
CVE-2026-34908.851999.710.0
CVE-2026-48907.781099.510.0
CVE-2026-45659.760899.58.8
CVE-2026-34909.639099.210.0
CVE-2026-48282.423998.610.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1052010.0.9991KEV
CVE-2026-3491010.0.8747KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.7810KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-4828210.0.4239KEV
CVE-2026-5629010.0.3038KEV
CVE-2026-4890810.0.1482KEV
CVE-2026-5972610.0.0688
CVE-2026-1377310.0.0610
Most disclosures (vendor)
VendorCVEs
google607
linux455
oracle241
red hat130
apache120
ibm72
capgo68
microsoft66
openclaw62
themerex60
Most KEV additions (YTD)
VendorKEV
microsoft20
cisco11
apple7
google6
ivanti5
solarwinds4
adobe3
berriai3
fortinet3
smartertools3
Most-affected ecosystems
EcosystemAdvisories
Maven70
npm6
PyPI5
NuGet3
Fastest to KEV
CVEVendorDays
CVE-2026-10520ivanti0
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
CVE-2026-34910Ubiquiti Inc0
CVE-2026-35273Oracle Corporation0
CVE-2026-45659Microsoft0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171695
CVE-2021-27102n/a2021-11-171695
CVE-2021-27101n/a2021-11-171695
CVE-2021-27103n/a2021-11-171695
CVE-2021-21017Adobe2021-11-171695
CVE-2021-28550Adobe2021-11-171695
CVE-2021-42013Apache Software Foundation2021-11-171695
CVE-2021-41773Apache Software Foundation2021-11-171695
CVE-2021-30858Apple2021-11-171695
CVE-2021-30860Apple2021-11-171695

Transactions

EXPLOIT PUBLISHED — open-webui: 9 CVEs (CVE-2026-59212, CVE-2026-59213, CVE-2026-59217, CVE-2026-59219, CVE-2026-59220, CVE-2026-59221, CVE-2026-59222, CVE-2026-59227, CVE-2026-59715). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-39243. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-39245. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-39246. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54695 (pipecat-ai pipecat). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56292 (acymailing.com AcyMailing extension for Joomla). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-58459 (ntpsec gpsd). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-59856 (vim). Public exploit reference added.

Yesterday's Results

How to read these box scores · glossary

276 CVEs published. 25 box scores, 251 table rows — nothing truncated.

ruvnet ruflo — Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0688   93.5     —
AFFECTED
  Product  Versions    Fixed
  ruflo    < 3.16.3 –  —
TIMELINE
  Jul 6   Reserved by CNA
  Jul 9   Published (CNA: GitHub_M)
CWE-78, CWE-306, CWE-942 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Deferred
n8n-io n8n — n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   H   H   N    7.6   .0313   86.9     —
AFFECTED
  Product  Versions               Fixed
  n8n      >= 2.28.0, < 2.28.1 –  —
TIMELINE
  Jul 2   Reserved by CNA
  Jul 9   Published (CNA: GitHub_M)
CWE-346, CWE-287 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Analyzed
ntpsec gpsd — gpsd gpsprof Command Injection via gnuplot plot title subtype field
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   N   A   H   H   H    8.4   .0180   76.7     —
AFFECTED
  Product  Versions     Fixed
  gpsd     unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 9   Public exploit reference published
  Jul 9   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Analyzed
Palo Alto Networks Cloud NGFW — PAN-OS: Authenticated Command Injection in CLI
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   N    6.0   .0167   75.0     —
AFFECTED
  Product        Versions     Fixed
  Cloud NGFW     unspecified  All
  PAN-OS         12.1.0 –     12.1.8
  Prisma Access  unspecified  All
TIMELINE
  Nov 3   Reserved by CNA
  Jul 9   Published (CNA: palo_alto)
CWE-78 · CNA: palo_alto · CVSS v4.0 · 2 references · NVD status: Modified
nesquena hermes-webui — Hermes WebUI < 0.51.788 Unauthenticated RCE via Terminal API
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0134   69.1     —
AFFECTED
  Product       Versions     Fixed
  hermes-webui  unspecified  —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 9   Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
danieliser Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder — Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder <= 1.22.0 - Missing Authorization to Authenticated (Editor+) Arbitrary Plugin Installation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0123   66.6     —
AFFECTED
  Product                                                                                         Versions     Fixed
  Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder  unspecified  —
TIMELINE
  May 18  Reserved by CNA
  Jul 9   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 12 references · NVD status: Deferred
getwpfunnels WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell — WPFunnels <= 3.12.7 - Authenticated (Administrator+) Local File Inclusion via 'logKey' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  H  H  H    6.6   .0121   66.0     —
AFFECTED
  Product                                                                      Versions     Fixed
  WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell  unspecified  —
TIMELINE
  Jun 23  Reserved by CNA
  Jul 9   Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
AidanPark openclaw-android Android WebView Bridge JsBridge.kt os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    1.9   .0108   62.6     —
AFFECTED
  Product           Versions  Fixed
  openclaw-android  0.1 –     —
TIMELINE
  Jul 9   Reserved by CNA
  Jul 9   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
cyberlord92 miniOrange OTP Login, Verification and SMS Notifications — miniOrange OTP Login, Verification and SMS Notifications <= 5.5.1 - Authentication Bypass to Administrator Account Takeover via 'username_b' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0107   62.3     —
AFFECTED
  Product                                                   Versions     Fixed
  miniOrange OTP Login, Verification and SMS Notifications  unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 9   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
creativethemeshq Blocksy Companion — Blocksy Companion <= 2.1.46 - Unauthenticated Arbitrary File Upload via 'blc-review-images[]' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0107   62.2     —
AFFECTED
  Product            Versions     Fixed
  Blocksy Companion  unspecified  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 9   Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 3 references · NVD status: Deferred
bitpressadmin Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder — Bit Form <= 3.1.1 - Authenticated (Subscriber+) Arbitrary File Deletion via '_old' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  L  N  H    7.1   .0106   62.0     —
AFFECTED
  Product                                                                                     Versions     Fixed
  Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder  unspecified  —
TIMELINE
  Jul 1   Reserved by CNA
  Jul 9   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 13 references · NVD status: Deferred
Xerte Xerte Online Tools — CVE-2026-14261
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0103   61.2     —
AFFECTED
  Product             Versions     Fixed
  Xerte Online Tools  unspecified  —
  Xerte Online Tools  unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 9   Published (CNA: certcc)
CNA: certcc · CVSS v3.1 · 3 references · NVD status: Deferred
LibreBooking path traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0102   60.7     —
AFFECTED
  Product       Versions     Fixed
  LibreBooking  unspecified  5.1.0
TIMELINE
  Jul 8   Reserved by CNA
  Jul 9   Published (CNA: cisa-cg)
CWE-23 · CNA: cisa-cg · CVSS v4.0 · 5 references · NVD status: Awaiting Analysis
Hoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0101   60.5     —
AFFECTED
  Product     Versions      Fixed
  hoppscotch  < 2026.6.0 –  —
TIMELINE
  Jul 6   Reserved by CNA
  Jul 9   Published (CNA: GitHub_M)
CWE-77, CWE-78, CWE-915 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Deferred
Metabase: Unsafe Deserialization of H2 Query Results
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0093   58.1     —
AFFECTED
  Product   Versions                Fixed
  metabase  >= 1.58.0, < 1.58.15 –  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 9   Published (CNA: GitHub_M)
CWE-502 · CNA: GitHub_M · CVSS v3.1 · 6 references · NVD status: Analyzed
Zeek < 8.0.9 Null Pointer Dereference DoS via Kerberos KRB_ERROR Parsing
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0092   57.7     —
AFFECTED
  Product  Versions     Fixed
  zeek     unspecified  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 9   Published (CNA: VulnCheck)
CWE-476 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Analyzed
Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .0091   57.3     —
AFFECTED
  Product   Versions    Fixed
  langroid  < 0.65.2 –  —
TIMELINE
  Jun 15  Reserved by CNA
  Jul 9   Published (CNA: GitHub_M)
CWE-94 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Deferred
D-link DIR-823G Web boa.conf least privilege violation
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   L   N   H   H   H    6.8   .0085   55.5     —
AFFECTED
  Product   Versions             Fixed
  DIR-823G  1.0.2B05_20181207 –  —
TIMELINE
  Jul 9   Reserved by CNA
  Jul 9   Published (CNA: VulDB)
CWE-266, CWE-272 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Analyzed
coollabsio coolify — Coolify: OS Command Injection in Health Check Configuration Allows Remote Code Execution
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0081   54.2     —
AFFECTED
  Product  Versions            Fixed
  coolify  < 4.0.0-beta.469 –  —
TIMELINE
  Jul 6   Reserved by CNA
  Jul 9   Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Deferred
Zeek < 8.0.9 Uncontrolled Memory Consumption DoS via FTP Analyzer
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0079   53.6     —
AFFECTED
  Product  Versions     Fixed
  zeek     unspecified  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 9   Published (CNA: VulnCheck)
CWE-770 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Analyzed
mettle sendportal APIv1 Webhooks mailjet missing authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   L   L    5.5   .0076   52.6     —
AFFECTED
  Product     Versions  Fixed
  sendportal  3.0.0 –   —
TIMELINE
  Jul 9   Reserved by CNA
  Jul 9   Published (CNA: VulDB)
CWE-287, CWE-306 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Vinchin Backup & Recovery 9.0.0.86562 Stack Buffer Overflow via ModuleHandShake
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   L   L    6.9   .0075   52.0     —
AFFECTED
  Product                Versions     Fixed
  Backup & Recovery 9.0  unspecified  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 9   Published (CNA: VulnCheck)
CWE-121 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Deferred
getkirby kirby — Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   N    9.1   .0074   51.9     —
AFFECTED
  Product  Versions   Fixed
  kirby    < 4.9.4 –  —
TIMELINE
  Jun 11  Reserved by CNA
  Jul 9   Published (CNA: GitHub_M)
CWE-454 · CNA: GitHub_M · CVSS v4.0 · 8 references · NVD status: Deferred
Discourse: Stored-XSS in 2FA delete confirmation modal
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   R  C  H  H  H    9.0   .0073   51.7     —
AFFECTED
  Product    Versions                          Fixed
  discourse  >= 2026.1.0-latest, < 2026.1.5 –  —
TIMELINE
  Jun 11  Reserved by CNA
  Jul 9   Published (CNA: GitHub_M)
CWE-79 · CNA: GitHub_M · CVSS v3.1 · 9 references · NVD status: Analyzed
rubengc GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress — GamiPress <= 7.9.4 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'access' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0072   51.1     —
AFFECTED
  Product                                                                                      Versions     Fixed
  GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress  unspecified  —
TIMELINE
  Jun 26  Reserved by CNA
  Jul 9   Published (CNA: Wordfence)
CWE-639 · CNA: Wordfence · CVSS v3.1 · 14 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-152717.750.6TOTOLINKA3000RUCWE-266TOTOLINK EX200 Web boa.conf least privilege violation
CVE-2026-121169.850.5XerteXerte Online Tools—CVE-2026-12116
CVE-2026-501808.749.9langroidlangroidCWE-22Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family e…
CVE-2026-134928.849.8stiofansislandUsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WPCWE-22UsersWP <= 1.2.65 - Authenticated (Subscriber+) Arbitrary File Deletion via F…
CVE-2026-519238.149.7n/an/aCWE-639An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm G…
CVE-2026-152045.549.3TOTOLINKX5000RCWE-22TOTOLINK X5000R OpenVPN Export cstecgi.cgi exportOvpn path traversal
CVE-2026-552078.849.0pimcorepimcoreCWE-640Pimcore: Account Takeover via Password Reset URL Injection allows unauthentic…
CVE-2026-592067.148.8n8n-ion8nCWE-1321n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated Us…
CVE-2026-392467.548.7n/an/aCWE-59decompress before 4.2.2 allows arbitrary symlink creation during archive extr…
CVE-2026-547609.348.2langroidlangroidCWE-22Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quot…
CVE-2026-600946.947.9VinchinBackup & Recovery 9.0CWE-787Vinchin Backup & Recovery 9.0.0.86562 Heap Buffer Overflow via agentlink_server
CVE-2026-153088.747.8Python Software FoundationCPythonCWE-400Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated untermin…
CVE-2026-457886.347.7discoursediscourseCWE-200Discourse: Secure uploads exposed by hotlinked image copying
CVE-2026-02791.347.6Palo Alto NetworksCloud NGFWCWE-79PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities
CVE-2026-515999.847.5n/an/aCWE-20An insufficient input validation vulnerability in the RTSP service of MERCURY…
CVE-2026-02876.647.1Palo Alto NetworksCloud NGFWCWE-754PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing
CVE-2026-548018.646.9SiemensCPCI85 Central Processing/CommunicationCWE-620A vulnerability has been identified in CPCI85 Central Processing/Communicatio…
CVE-2026-519267.546.9n/an/aCWE-203An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obt…
CVE-2026-380767.546.5n/an/aCWE-190An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex com…
CVE-2026-114048.746.4CesantaMongooseCWE-125Cesanta Mongoose Out-of-Bounds Read in MG_TLS_BUILTIN ClientHello Session ID …
CVE-2026-554208.146.2discoursediscourseCWE-78Discourse: Remote code execution via pdf uploads
CVE-2026-556055.346.1arikusideepseek-mcp-serverCWE-306@arikusi/deepseek-mcp-server Missing Authentication on Self-Hosted HTTP MCP E…
CVE-2026-597207.545.7hoppscotchhoppscotchCWE-200Hoppscotch: Insecure Default Configuration Allows Public Exposure of Private …
CVE-2026-150007.245.6rnzoConnect Contact Form 7 and MailchimpCWE-79Connect Contact Form 7 and Mailchimp <= 0.9.78.06 - Unauthenticated Stored Cr…
CVE-2026-596927.544.9Red HatRed Hat Enterprise Linux 10CWE-121Gstreamer: gstreamer: dtls certificate subject dn stack buffer overflow in op…
CVE-2026-519248.144.8n/an/aCWE-639An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute…
CVE-2026-516007.544.7n/an/aCWE-400Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length heade…
CVE-2026-592206.544.7open-webuiopen-webuiCWE-1333Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on defau…
CVE-2026-516017.544.6n/an/aCWE-121Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in …
CVE-2026-516047.544.6n/an/aCWE-121A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 …
CVE-2026-516057.544.6n/an/aCWE-121A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 …
CVE-2026-125978.144.5LoginPressLoginPress ProCWE-287LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverifie…
CVE-2026-546956.544.3pipecat-aipipecatCWE-862Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Att…
CVE-2026-124065.344.1wedevsUser Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User RegistrationCWE-862User Frontend <= 4.3.7 - Missing Authorization to Unauthenticated Arbitrary A…
CVE-2026-516027.544.0n/an/aCWE-121A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 …
CVE-2026-516037.544.0n/an/aCWE-121A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 …
CVE-2026-125958.144.0LoginPressLoginPress ProCWE-287LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverifie…
CVE-2026-125988.144.0LoginPressLoginPress ProCWE-287LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverifie…
CVE-2026-540028.543.4getkirbykirbyCWE-79Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `D…
CVE-2026-519258.143.4n/an/aCWE-639A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.1…
CVE-2026-478268.543.3CloudFoundry FoundationBOSH CLI toolCWE-22blobs.yaml Path Traversal Allows File Writes
CVE-2026-598285.343.3discoursediscourseCWE-200Discourse: Hidden post revisions leak through adjacent visible diffs
CVE-2026-598269.143.0metabasemetabaseCWE-94Metabase: Arbitrary Code Execution via Database Connection Detail Bypass
CVE-2026-515979.142.3n/an/aCWE-294MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement …
CVE-2026-598338.642.4siyuan-notesiyuanCWE-79SiYuan: Stored XSS to RCE in SiYuan via a per-attribute URL-scheme sanitizer …
CVE-2026-598558.642.4siyuan-notesiyuanCWE-80SiYuan: Store XSS To Rce via Asset.render
CVE-2026-90215.341.6matrixaddonsEasy Invoice – Invoice Generator, PDF Quotes & PaymentsCWE-862Easy Invoice <= 2.1.19 - Unauthenticated Arbitrary Quote Accept/Decline and I…
CVE-2026-464136.541.4discoursediscourseCWE-862Discourse: Regular users can route multipart uploads into the admin backup store
CVE-2026-151382.141.2tumfmcp-text-editorCWE-22tumf mcp-text-editor text_editor.py _validate_file_path path traversal
CVE-2026-319848.741.1Nozomi NetworksGuardianCWE-770DoS through oversized audit log entries in Guardian/CMC before 26.2.0
CVE-2026-598347.541.1siyuan-notesiyuanCWE-89SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content
CVE-2026-492566.341.1discoursediscourseCWE-200Discourse: Hidden tag names leaked via category serializers
CVE-2026-575010.040.9zen-browserdesktopCWE-266Zen: Context-menu "Open link in glance" / "Split link in new tab" loads a pag…
CVE-2026-539877.340.7Tag pluginGLPI 11CWE-79GLPI 11 before 2.14.4 Tag Plugin Stored Cross-Site Scripting in Kanban Badge …
CVE-2026-457804.340.4discoursediscourseCWE-200Discourse: Private event sample invitees are serialized to non-invited event …
CVE-2026-540046.340.3getkirbykirbyCWE-862Kirby: Access to files of top-level drafts is not protected by permissions
CVE-2026-134619.640.2PayRangePayRange—PayRange version 7.0.7 contains a JavaScript injection vulnerability
CVE-2026-555905.139.9cakephpauthenticationCWE-601CakePHP: Open redirect weakness via backslash bypass
CVE-2026-437524.939.9ClarisFileMaker ServerCWE-434An authenticated administrator may be able to achieve arbitrary code executio…
CVE-2026-598544.939.5siyuan-notesiyuanCWE-693SiYuan: Incomplete IsSensitivePath denylist: globalCopyFiles reads home-dir c…
CVE-2026-492745.339.5getkirbykirbyCWE-862Kirby: `pages.access` permission is not checked in the pages picker for paren…
CVE-2026-592217.739.4open-webuiopen-webuiCWE-22open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
CVE-2026-591496.539.4mockoonmockoonCWE-22Mockoon: Path traversal in templated `filePath` lets a request escape the ser…
CVE-2026-89966.538.9revmakxBackup and Staging by WP Time CapsuleCWE-862Backup and Staging by WP Time Capsule <= 1.22.26 - Missing Authorization to A…
CVE-2026-124286.538.9gamaupBlocks for ACF Fields — Display Custom Fields in the Block EditorCWE-862Blocks for ACF Fields <= 1.6.2 - Missing Authorization to Authenticated (Auth…
CVE-2026-570216.938.8Juniper NetworksJunos OSCWE-787Junos OS: SRX Series: If VPN compliance-check is configured an attacker can c…
CVE-2026-90285.338.8corvusinfoCorvusPay WooCommerce Payment GatewayCWE-862CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Missing Authorization to Una…
CVE-2026-613446.938.8Superior Court of California, County of Los AngelesHearing Reminder ServiceCWE-306Superior Court of California Hearing Reminder Service unauthenticated informa…
CVE-2026-506448.638.5SOPlanningSOPlanningCWE-89SQL Injection in SOPlanning Audit Retention Configuration
CVE-2026-59559.838.4Inrove Software and Internet ServicesBiEticaretCWE-89SQLi in Inrove Software's BiEticaret
CVE-2026-598327.738.2siyuan-notesiyuanCWE-22SiYuan: Authenticated path traversal in /snippets/ static handler (serveSnipp…
CVE-2026-02844.738.2Palo Alto NetworksCloud NGFWCWE-74PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
CVE-2026-13656.538.1Sayax Energy Technologies Inc.OSOSCWE-201Information Disclosure in Sayax's OSOS
CVE-2026-556159.238.0langroidlangroidCWE-74Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (pr…
CVE-2026-447877.137.9discoursediscourseCWE-269Discourse: Signup-time primary_group_id assignment grants whisperer access
CVE-2026-570238.737.9Juniper NetworksJunos OSCWE-1284Junos OS: MX with SPC3, SRX Series: A specifically malformed TCP packet cause…
CVE-2026-570268.737.9Juniper NetworksJunos OSCWE-1286Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malfo…
CVE-2026-516067.537.9n/an/aCWE-20An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.…
CVE-2026-151952.137.7apidevtoolsjson-schema-ref-parserCWE-94apidevtools json-schema-ref-parser pointer.ts Pointer.set prototype pollution
CVE-2026-592197.137.6open-webuiopen-webuiCWE-613Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backch…
CVE-2026-75585.337.5tokenoftrustAge Verification & Identity Verification by Token of TrustCWE-862Age Verification & Identity Verification by Token of Trust <= 4.0.2 - Missing…
CVE-2026-124334.337.5themeficHydra Booking — Appointment Scheduling & Booking CalendarCWE-639Hydra Booking <= 1.2.1 - Authenticated (Custom+) Insecure Direct Object Refer…
CVE-2026-558657.137.3jg-rpliquidCWE-835Python Liquid: Infinite loop when parsing malformed `{% case %}` tags
CVE-2026-130116.537.3wedevsERP: Complete HR, Accounting & CRM Suite Built for WooCommerceCWE-89ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM…
CVE-2026-152022.137.1n/aYzmCMSCWE-79YzmCMS Header yzmphp.php get_url cross site scripting
CVE-2025-454228.137.1n/an/aCWE-284Incorrect access control in Proximus b-box v8c.725A allows authenticated atta…
CVE-2026-592077.137.0n8n-ion8nCWE-693n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Conn…
CVE-2026-562929.236.8acymailing.comacymailing.com AcyMailing extension for JoomlaCWE-89Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 1…
CVE-2026-501886.936.7getkirbykirbyCWE-93Kirby: Request header injection in `Http\Remote`
CVE-2026-55238.836.6Divi EngineDivi Form BuilderCWE-639Divi Form Builder <= 5.1.8 - Authenticated (Subscriber+) Missing Authorizatio…
CVE-2026-583788.636.6AllwinnerH616CWE-489Allwinner TV Box TV98 ADB exposed on network
CVE-2026-336557.736.6QuantumNousnew-apiCWE-918New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
CVE-2026-143424.936.6getwpfunnelsMail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce EmailsCWE-89Mail Mint <= 1.24.2 - Authenticated (Administrator+) SQL Injection via 'conta…
CVE-2026-125938.736.1QtAxivionCWE-862Privilege escalation via forged API token creation in Axivion Dashboard OIDC/…
CVE-2026-115717.536.0UnknownEverest Forms—Everest Forms < 3.5.0 - Unauthenticated Sensitive Information Exposure via Re…
CVE-2026-492767.435.8getkirbykirbyCWE-83Kirby: Self cross-site scripting (self-XSS) in the writer field
CVE-2026-151375.535.7code-projectsInterview Management SystemCWE-74code-projects Interview Management System View.php sql injection
CVE-2026-151905.535.7SourceCodesterSimple and Nice Shopping Cart ScriptCWE-74SourceCodester Simple and Nice Shopping Cart Script login.php sql injection
CVE-2026-134417.235.5metagaussEventPrime – Events Calendar, Bookings and TicketsCWE-79EventPrime <= 4.3.4.2 - Unauthenticated Stored Cross-Site Scripting via 'new_…
CVE-2026-540057.135.4getkirbykirbyCWE-862Kirby: `pages.access` permission is not checked in the `site/find` REST API r…
CVE-2026-151872.135.4n/aenquirerCWE-94enquirer Public Package API Enquirer.set prototype pollution
CVE-2026-19897.535.2PAVO Financial Technology Solutions Inc.PAVO PayCWE-639IDOR in PAVO Inc.'s PAVO Pay
CVE-2026-124185.335.0wedevsUser Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User RegistrationCWE-639User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membersh…
CVE-2026-570327.134.8Juniper NetworksJunos OSCWE-236Junos OS: EX Series: Subscribing to an unsupported telemetry sensor path caus…
CVE-2026-592125.434.8open-webuiopen-webuiCWE-863Open WebUI: Model meta.knowledge read-only file access can be upgraded to fil…
CVE-2026-478297.734.7CloudFoundry Foundationbosh-cliCWE-88Argument Injection in BOSH CLI Allows Local Command Execution on Operator Wor…
CVE-2026-137716.434.6ivoleCustomer Reviews for WooCommerceCWE-79Customer Reviews for WooCommerce <= 5.113.0 - Authenticated (Contributor+) St…
CVE-2026-570246.934.5Juniper NetworksJunos OSCWE-694Junos OS: MX with SPC3, SRX Series: Repeated VPN negotiation failures will ev…
CVE-2026-554247.434.3discoursediscourseCWE-79Discourse: Topic featured link susceptible to stored XSS
CVE-2026-539625.434.3discoursediscourseCWE-79Discourse: Insufficient SVG sanitization logic
CVE-2026-552087.734.1pimcorepimcoreCWE-89Pimcore: SQL Injection via Column Name in DateFilter allows authenticated use…
CVE-2026-319836.934.1Nozomi NetworksGuardianCWE-306Missing authentication in SSH keys synchronization endpoint in Guardian/CMC b…
CVE-2026-592185.334.0open-webuiopen-webuiCWE-208Open WebUI: Account enumeration via observable login timing discrepancy
CVE-2026-614745.334.1mispmispCWE-863MISP: Improper sharing group authorization check when adding attributes
CVE-2026-151862.134.1macrozhengmallCWE-99macrozheng mall Portal Endpoint create resource injection
CVE-2026-125905.934.0body-parserbody-parserCWE-770body-parser vulnerable to denial of service when invalid limit value silently…
CVE-2026-547987.133.9SiemensCPCI85 Central Processing/CommunicationCWE-489A vulnerability has been identified in CPCI85 Central Processing/Communicatio…
CVE-2026-556898.133.5openfgaopenfgaCWE-287OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset
CVE-2026-337948.233.4Juniper NetworksJunos OS EvolvedCWE-754Junos OS Evolved: PTX Series: Receipt of repeated ECMP routing updates result…
CVE-2026-570228.233.4Juniper NetworksJunos OSCWE-754Junos OS: MX Series with SPC3, SRX Series: Specific packet in response to a T…
CVE-2026-598175.333.1TryGhostGhostCWE-472Ghost: Paid gift memberships obtainable at minimal cost via the donations fea…
CVE-2026-592097.133.0n8n-ion8nCWE-200n8n: Shared Credential Header Leak via HTTP Request Pagination Expression
CVE-2026-598536.533.0siyuan-notesiyuanCWE-862SiYuan: Publish-mode Reader can exfiltrate private saved-search Criteria via …
CVE-2026-333907.232.9Nozomi NetworksGuardianCWE-266Incorrect privilege assignment for Arc sensors in Guardian/CMC before 26.2.0
CVE-2026-92374.332.2crewhrmEmployee, Leave and Recruitment Management System – Crew HRMCWE-862Employee, Leave and Recruitment Management System <= 1.2.2 - Missing Authoriz…
CVE-2026-547718.132.0langroidlangroidCWE-75Langroid: handle_message() executes user-supplied tool JSON without sender ve…
CVE-2026-23429.331.9OceanicSoft Informatics Systems Ltd.ValeAppCWE-79XSS in Oceanicsoft's ValeApp
CVE-2026-592248.031.9open-webuiopen-webuiCWE-287Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user ident…
CVE-2026-151912.131.2mettlesendportalCWE-285mettle sendportal Campaign Creation Endpoint CampaignStoreRequest.php authori…
CVE-2026-592234.331.0open-webuiopen-webuiCWE-693Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via UR…
CVE-2026-570308.230.8Juniper NetworksJunos OSCWE-362Junos OS: SRX Series: Flow sessions are not getting cleared leading to a DoS
CVE-2026-133346.130.7kitae-parkMang Board WPCWE-79Mang Board WP <= 2.3.4 - Reflected Cross-Site Scripting via 'stag' Parameter
CVE-2026-564606.530.7HCLSoftwareHCL DevOps Deploy / HCL LaunchCWE-201HCL DevOps Deploy / HCL Launch is susceptible to an Insertion of Sensitive In…
CVE-2026-392456.230.2n/an/aCWE-22decompress before 4.2.2 contains an improper path containment check that enab…
CVE-2026-581229.330.0nesquenahermes-webuiCWE-348Hermes WebUI < 0.51.307 Authentication Bypass via X-Forwarded-For Header Spoo…
CVE-2026-556048.630.0arikusideepseek-mcp-serverCWE-639@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Control…
CVE-2026-592174.329.9open-webuiopen-webuiCWE-862Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-…
CVE-2026-337995.329.4Juniper NetworksJunos OSCWE-787Junos OS and Junos OS Evolved: Receipt of a specific SNMPv3 request results i…
CVE-2026-570546.929.3Juniper NetworksJunos OSCWE-706Junos OS: MX Series: Web filtering doesn't block specifically formatted URLs
CVE-2026-90275.329.3corvusinfoCorvusPay WooCommerce Payment GatewayCWE-347CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Unauthenticated Improper Ver…
CVE-2026-151895.329.3aerostackdevaerostack-mcpCWE-918aerostackdev aerostack-mcp mcp-whatsapp upload_media server-side request forgery
CVE-2026-151882.129.3manjurulhoquedjango-job-portalCWE-266manjurulhoque django-job-portal Employee Dashboard Endpoint views.py EditEmpl…
CVE-2026-132536.428.4wpxpoPost Grid Gutenberg Blocks – PostXCWE-79Post Grid Gutenberg Blocks for News, Magazines, Blog Websites <= 5.0.31 - Aut…
CVE-2026-153112.028.3NousResearchhermes-agentCWE-79NousResearch hermes-agent Matrix Adapter matrix.py MatrixAdapter._markdown_to…
CVE-2026-601205.128.2WebkulBagistoCWE-79Bagisto < 2.4.4 Stored XSS via CSTI in create.blade.php
CVE-2026-42568.228.0PEAKUP Technology Inc.PassGateCWE-90LDAP Injection in PEAKUP's PassGate
CVE-2026-42984.328.0mlfactoryDSGVO All in one for WPCWE-862DSGVO All in one for WP <= 4.9 - Missing Authorization to Authenticated (Subs…
CVE-2026-338036.928.0Juniper NetworksJunos OS EvolvedCWE-923Junos OS Evolved: A port which has been inadvertently exposed can be reached …
CVE-2026-552127.127.7pimcorepimcoreCWE-285Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint …
CVE-2026-02834.527.7Palo Alto NetworksCloud NGFWCWE-306PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)
CVE-2026-46536.427.5bouncingsproutBlock, Suspend, Report for BuddyPressCWE-79Block, Suspend, Report for BuddyPress <= 3.6.4 - Authenticated (Subscriber+) …
CVE-2026-69106.427.5safistudioBookero.pl – system rezerwacji onlineCWE-79Bookero.pl <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting …
CVE-2026-121706.427.5acybaAcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPressCWE-79AcyMailing <= 10.10.2 - Authenticated (Contributor+) Stored Cross-Site Script…
CVE-2026-143436.427.5codename065Download ManagerCWE-79Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site S…
CVE-2026-571117.527.3Apache Software FoundationApache Helix RESTCWE-1385Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestric…
CVE-2026-551702.126.3openfgaopenfgaCWE-178OpenFGA MySQL backend: case-insensitive collation on identifier columns cause…
CVE-2026-92354.326.0dhlparcelDHL eCommerce (Benelux) for WooCommerceCWE-862DHL eCommerce (Benelux) for WooCommerce <= 2.2.3 - Missing Authorization to A…
CVE-2026-92404.326.0iscpcolissimoColissimo shipping methods for WooCommerceCWE-862Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 - Missin…
CVE-2026-113594.326.0metagaussMemberships and User Profiles for WooCommerce – ProfileGrid WooCommerce IntegrationCWE-862Memberships and User Profiles for WooCommerce <= 3.4 - Missing Authorization …
CVE-2026-596917.124.9Red HatRed Hat Enterprise Linux 10CWE-787Gstreamer: gstreamer: rfbsrc/librfb hextile heap out-of-bounds write with 16b…
CVE-2026-598314.424.9clicliCWE-829GitHub CLI `gh codespace jupyter` could allow remote code execution when conn…
CVE-2026-118695.324.5UnknownWP DSGVO Tools (GDPR)—WP DSGVO Tools (GDPR) < 3.1.40 - Unauthenticated Sensitive Information Disclo…
CVE-2026-118755.324.5UnknownWP Support Plus Responsive Ticket System—WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Support T…
CVE-2026-592153.124.6open-webuiopen-webuiCWE-639Open WebUI: Private channel messages can be disclosed through cross-channel t…
CVE-2026-592226.024.4open-webuiopen-webuiCWE-200Open WebUI: /api/v1/channels/{id}/members exposes full user model including s…
CVE-2026-478317.724.1Cloud Foundry Foundationbosh-windows-stemcell-builder—Cryptographically Weak Password Generation in bosh-windows-stemcell-builder A…
CVE-2026-92537.224.0loopusWP Cost Estimation & Payment Forms BuilderCWE-79WP Cost Estimation & Payment Forms Builder (E&P Forms) <= 10.5.97 - Unauthent…
CVE-2026-312675.723.7n/an/aCWE-121Mercusys MW302R MW302R(EU)_V1_1.4.10 Build 231023 is vulnerable to Buffer Ove…
CVE-2026-02801.723.6Palo Alto NetworksCloud NGFWCWE-131PAN-OS: IPv6 Firewall Policy Bypass
CVE-2026-125165.323.4UnknownFediverse Embeds—Fediverse Embeds < 1.5.8 - Unauthenticated SSRF via Media Proxy
CVE-2026-125175.323.4UnknownFediverse Embeds—Fediverse Embeds < 1.5.8 - Unauthenticated SSRF via Site Info Endpoint
CVE-2026-592169.022.9open-webuiopen-webuiCWE-94Open WebUI: Cross-user code-interpreter and tool execution via unvalidated So…
CVE-2026-319825.322.9Nozomi NetworksGuardianCWE-601Open Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0
CVE-2026-134627.522.3PayRangePayRange—PayRange for Android, version 7.0.7, contains an SSL bypass vulnerability
CVE-2026-592264.322.4open-webuiopen-webuiCWE-285Open WebUI: Scheduled automations continue after pending-user deactivation an…
CVE-2026-570286.922.1Juniper NetworksJunos OS EvolvedCWE-923Junos OS Evolved: A port which has been inadvertently exposed can be reached …
CVE-2026-392435.522.1n/an/aCWE-59decompress before 4.2.2 allows arbitrary hardlink creation during archive ext…
CVE-2026-539616.522.0discoursediscourseCWE-345Discourse: Forged AWS SNS bounce notifications can disable a targeted user's …
CVE-2026-128795.922.0Google CloudApigeeCWE-441Cross-Tenant Data Exfiltration in Apigee via BigQuery Confused Deputy
CVE-2026-122706.521.8UnknownEverest Forms—Everest Forms < 3.5.0 - Unauthenticated Missing Authorization via Site Assist…
CVE-2026-592135.021.7open-webuiopen-webuiCWE-524Open WebUI: Cross-user model-list exposure via static cache key in get_all_mo…
CVE-2026-42758.821.4badhonrocksDivi Torque Lite – Divi Modules for the Divi Builder & ThemeCWE-352Divi Torque Lite <= 4.2.3 - Cross-Site Request Forgery to Arbitrary Plugin In…
CVE-2026-02822.721.2Palo Alto NetworksCloud NGFWCWE-20PAN-OS: File Deletion Vulnerability in Management Web Interface
CVE-2026-592149.020.5open-webuiopen-webuiCWE-79Open WebUI: Stored web worker XSS via Pyodide
CVE-2026-478288.920.5BOSH-Ecosystem / BOSH (bosh-cli)bosh-cli—Missing TLS Certificate Verification in BOSH CLI Allows Root Code Execution v…
CVE-2026-02812.120.3Palo Alto NetworksCloud NGFWCWE-524PAN-OS: Information Disclosure Vulnerability in Management Web Interface
CVE-2026-338017.120.0Juniper NetworksJunos OSCWE-754Junos OS and Junos OS Evolved: When a specifically malformed BGP route update…
CVE-2025-635797.518.7n/an/aCWE-200Unauthorized use of Kyocera printers, allows all information stored in the Ky…
CVE-2026-338007.118.5Juniper NetworksJunos OSCWE-606Junos OS: MX Series: In a VC scenario a high rate of micro-BFD session flaps …
CVE-2026-570197.118.5Juniper NetworksJunos OSCWE-1284Junos OS: MX Series: Specific traffic causes an FPC to reset
CVE-2026-570207.118.5Juniper NetworksJunos OSCWE-754Junos OS: QFX10000 Series: IPv6 multicast traffic received on non-IRB interfa…
CVE-2026-570277.118.5Juniper NetworksJunos OSCWE-401Junos OS: EX4100 Series, EX4400: With sFlow configured in a VC scenario multi…
CVE-2026-515986.518.5n/an/aCWE-20An input validation vulnerability in the RTSP service of MERCURY MIPC252W IP …
CVE-2026-592693.818.5VMwarePinniped—Privilege Escalation via Active Directory LDAP injection in Pinniped Supervis…
CVE-2026-564587.517.7HCLSoftwareHCL DevOps DeployCWE-942HCL DevOps Deploy is susceptible to a Permissive Cross-domain Security Policy…
CVE-2026-591488.817.6mockoonmockoonCWE-306Mockoon: Unauthenticated admin API + wildcard CORS allows mock-state hijack a…
CVE-2026-592275.417.2open-webuiopen-webuiCWE-862Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch an…
CVE-2026-57936.116.4Inrove Software and Internet ServicesBiEticaretCWE-79XSS in Inrove Software's BiEticaret
CVE-2026-319814.816.3Nozomi NetworksGuardianCWE-79HTML injection in Diagram tab and Graph view in Guardian/CMC before 26.2.0
CVE-2026-570315.314.6Juniper NetworksJunos OSCWE-754Junos OS: MX Series: For subscribers configured on static interfaces, input f…
CVE-2026-581438.714.3CotontiCotontiCWE-352Cotonti Siena 0.9.26 CSRF via admin.php Config Update Endpoint
CVE-2026-548006.313.5SiemensCPCI85 Central Processing/CommunicationCWE-1188A vulnerability has been identified in CPCI85 Central Processing/Communicatio…
CVE-2026-02854.713.4Palo Alto NetworksCloud NGFWCWE-918PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface
CVE-2026-418577.113.1CloudFoundry BOSHBOSH CLICWE-78BOSH CLI Shell Injection
CVE-2026-50055.413.1Twiser Informatics Technology Consulting, Trade and Education Inc.OKRs & GoalsCWE-79Stored XSS in Twiser's OKRs & Goals
CVE-2026-581445.113.1CotontiCotontiCWE-79Cotonti Siena 0.9.26 Stored XSS via PFS Module ntitle Parameter
CVE-2026-597156.512.6open-webuiopen-webuiCWE-306Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handle…
CVE-2026-478409.311.9CloudFoundry FoundationUAA—LDAP StartTLS unconditionally disables hostname verification
CVE-2026-598568.411.8vimvimCWE-94Vim: Arbitrary Code Execution via PHP Omni-Completion
CVE-2026-592256.311.2open-webuiopen-webuiCWE-862Open WebUI: Arena task endpoints can bypass underlying model access controls
CVE-2026-319858.310.1Nozomi NetworksRemote CollectorCWE-671Disabled and non-configurable TLS certificate validation in n2os-tui when con…
CVE-2026-02775.79.9Palo Alto NetworksPrisma Access AgentCWE-295Prisma Access Agent: Improper Certificate Validation on iOS
CVE-2026-443425.38.8QuantumNousnew-apiCWE-352New API CSRF in email and WeChat account binding endpoints
CVE-2026-570296.08.6Juniper NetworksJunos OS EvolvedCWE-820Junos OS Evolved: QFX Series: When sFlow collector reachability changes evo-p…
CVE-2026-151821.98.1GNULibreDWGCWE-119GNU LibreDWG BMP Image dwg.c dwg_bmp heap-based overflow
CVE-2026-501817.17.9langroidlangroidCWE-22Langroid: Path traversal in the file tools allows read/write outside configur…
CVE-2026-547998.47.9SiemensCPCI85 Central Processing/CommunicationCWE-489A vulnerability has been identified in CPCI85 Central Processing/Communicatio…
CVE-2025-581469.47.3XenXAPICWE-20XAPI UTF-8 string handling
CVE-2026-562884.66.2GNUpatchCWE-476NULL Pointer Dereference in GNU patch
CVE-2026-562894.66.2GNUpatchCWE-835Loop with Unreachable Exit Condition in GNU patch
CVE-2026-151841.96.2GNULibreDWGCWE-404GNU LibreDWG DWG File dwg.c dwg_next_entity null pointer dereference
CVE-2026-235599.46.1XenXAPICWE-250Multiple RBAC issues in XAPI
CVE-2026-235609.46.1XenXAPICWE-250Multiple RBAC issues in XAPI
CVE-2026-235619.46.1XenXAPICWE-250Multiple RBAC issues in XAPI
CVE-2026-235629.46.1XenXAPICWE-250Multiple RBAC issues in XAPI
CVE-2026-424869.46.1XenXAPICWE-250Multiple RBAC issues in XAPI
CVE-2026-219016.76.0Juniper NetworksJunos OSCWE-476Junos OS and Junos OS Evolved: Configuration of a specific SSH option results…
CVE-2026-02752.05.9Palo Alto NetworksPrisma BrowserCWE-269Prisma Browser: Local Privilege Escalation on macOS
CVE-2026-583036.15.7Samsung Open SourceEscargotCWE-121Stack-based buffer overflow vulnerability in Samsung Open Source Escargot all…
CVE-2026-583066.15.7Samsung Open SourceEscargotCWE-122Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allo…
CVE-2026-151941.95.4n/aOpen5GSCWE-119Open5GS AMF context.c amf_context_final use after free
CVE-2026-151851.95.3n/aGPACCWE-119GPAC MP4Box vobsub.c vobsub_read_idx out-of-bounds
CVE-2026-152741.95.3lo48576fbxcelCWE-404lo48576 fbxcel Node Header parser.rs denial of service
CVE-2026-152761.95.3pdeljanovSymphoniaCWE-404pdeljanov Symphonia Metadata denial of service
CVE-2025-274629.45.2XenWindows PV driversCWE-276WinPVDrivers: Excessive permissions on user-exposed devices
CVE-2025-274639.45.2XenWindows PV driversCWE-276WinPVDrivers: Excessive permissions on user-exposed devices
CVE-2025-274649.45.2XenWindows PV driversCWE-276WinPVDrivers: Excessive permissions on user-exposed devices
CVE-2026-02785.84.8Palo Alto NetworksPrisma Access AgentCWE-693Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows
CVE-2026-583046.14.5Samsung Open SourceEscargotCWE-125Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source …
CVE-2026-583056.14.5Samsung Open SourceEscargotCWE-843Access of resource using incompatible type ('type confusion') vulnerability i…
CVE-2026-583076.14.5Samsung Open SourceEscargotCWE-125Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source …
CVE-2026-478308.54.2Cloud Foundry Foundationbosh-windows-stemcell-builder—Incorrect Permission Assignment Allows Local Privilege Escalation to SYSTEM v…
CVE-2026-564595.54.2HCLSoftwareHCL DevOps Deploy / HCL LaunchCWE-532HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclo…
CVE-2026-02761.13.9Palo Alto NetworksCortex XDR Broker VMCWE-269Cortex XDR Broker VM: Privilege Escalation (PE) Vulnerability
CVE-2026-570256.83.6Juniper NetworksJunos OSCWE-466Junos OS and Junos OS Evolved: EX Series, QFX Series, MX Series: A specific '…
CVE-2025-581519.43.4XenvarstoredCWE-367varstored: TOCTOU issues with mapped guest memory
CVE-2026-235569.43.3XenoxenstoredCWE-281oxenstored keeps quota related use counts across domain destruction
CVE-2026-598588.43.3vimvimCWE-94Vim: Arbitrary Code Execution via C Omni-Completion
CVE-2026-581985.52.3gunthercoxChatterBotCWE-59ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer
CVE-2026-338026.82.2Juniper NetworksJunos OSCWE-862Junos OS: EX Series: Unauthorized users can execute service-impacting CLI com…
CVE-2026-598575.61.4vimvimCWE-787Vim: Out-of-bounds Write in SAL Soundfolding

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-09 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.