AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0688 93.5 —
AFFECTED Product Versions Fixed ruflo < 3.16.3 – —
TIMELINE Jul 6 Reserved by CNA Jul 9 Published (CNA: GitHub_M)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
276 CVEs published, led by Juniper Networks (22).
276 CVEs published July 9, 2026: 33 critical, 103 high, 115 medium, 24 low; 0 in the KEV catalog at press time; 16 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 251 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 1969 | 14372 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
647 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 37 | 1517 | 120 | 866 | 530 | 1 | 11 | 2 | 0.1 | 7.5 | .0014 | -58 ▼ |
| 79 | 1344 | 149 | 608 | 549 | 38 | 77 | 6 | 0.4 | 7.8 | .0024 | -483 ▼ | |
| microsoft | 52 | 809 | 61 | 553 | 189 | 6 | 286 | 20 | 2.5 | 7.8 | .0046 | -155 ▼ |
| red hat | 33 | 255 | 12 | 101 | 126 | 16 | 2 | 0 | 0.0 | 6.5 | .0031 | +2 ▲ |
| apple | 0 | 104 | 2 | 28 | 72 | 2 | 88 | 7 | 6.7 | 6.5 | .0032 | 0 |
| canonical | 1 | 21 | 2 | 6 | 8 | 5 | 0 | 0 | 0.0 | 5.5 | .0011 | +1 ▲ |
| suse | 6 | 19 | 4 | 11 | 4 | 0 | 0 | 0 | 0.0 | 8.6 | .0042 | +6 ▲ |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ubiquiti | 25 | 36 | 14 | 21 | 1 | 0 | 3 | 3 | 8.3 | 8.8 | .0049 | +25 ▲ |
| cisco | 8 | 30 | 6 | 14 | 10 | 0 | 56 | 11 | 36.7 | 7.5 | .0057 | +5 ▲ |
| palo alto networks | 14 | 25 | 1 | 3 | 14 | 7 | 13 | 2 | 8.0 | 4.7 | .0028 | +14 ▲ |
| netgear | 0 | 17 | 0 | 0 | 16 | 1 | 0 | 0 | 0.0 | 4.3 | .0024 | -17 ▼ |
| checkpoint | 0 | 9 | 1 | 5 | 3 | 0 | 3 | 1 | 11.1 | 7.5 | .0410 | -2 ▼ |
| fortinet | 0 | 9 | 4 | 3 | 2 | 0 | 28 | 3 | 33.3 | 8.3 | .0076 | -2 ▼ |
| ivanti | 0 | 9 | 4 | 5 | 0 | 0 | 25 | 5 | 55.6 | 8.8 | .5187 | -3 ▼ |
| f5 | 0 | 8 | 4 | 3 | 1 | 0 | 4 | 1 | 12.5 | 8.9 | .0225 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 52 | 207 | 38 | 80 | 77 | 11 | 33 | 1 | 0.5 | 7.3 | .0057 | -1 ▼ |
| mozilla | 3 | 59 | 12 | 18 | 29 | 0 | 9 | 0 | 0.0 | 7.3 | .0025 | -2 ▼ |
| gitlab | 7 | 38 | 0 | 5 | 27 | 6 | 4 | 2 | 5.3 | 4.7 | .0032 | +7 ▲ |
| github | 1 | 7 | 1 | 1 | 5 | 0 | 0 | 0 | 0.0 | 6.0 | .0039 | +1 ▲ |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.2 | .0016 | -2 ▼ |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 4 | 1 | 20.0 | 5.1 | .0026 | 0 |
| wordpress | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 270 | 132 | 116 | 18 | 4 | 27 | 2 | 0.7 | 8.8 | .0040 | -1 ▼ |
| adobe | 3 | 147 | 13 | 53 | 79 | 2 | 19 | 3 | 2.0 | 6.1 | .0021 | -120 ▼ |
| ibm | 2 | 126 | 38 | 42 | 46 | 0 | 6 | 0 | 0.0 | 7.5 | .0034 | -3 ▼ |
| progress | 10 | 19 | 3 | 14 | 2 | 0 | 6 | 0 | 0.0 | 7.5 | .0037 | +5 ▲ |
| solarwinds | 0 | 7 | 2 | 3 | 2 | 0 | 10 | 4 | 57.1 | 7.5 | .4001 | -3 ▼ |
| veeam | 0 | 4 | 2 | 2 | 0 | 0 | 1 | 0 | 0.0 | 9.0 | .0052 | -1 ▼ |
| zohocorp | 0 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 0 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -5 ▼ |
| siemens | 4 | 13 | 0 | 7 | 6 | 0 | 0 | 0 | 0.0 | 7.1 | .0023 | -3 ▼ |
| d-link | 1 | 13 | 0 | 5 | 3 | 5 | 3 | 0 | 0.0 | 6.0 | .0059 | -7 ▼ |
| rockwell automation | 0 | 7 | 1 | 5 | 1 | 0 | 0 | 0 | 0.0 | 8.7 | .0030 | 0 |
| abb | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -4 ▼ |
| schneider electric | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0042 | -1 ▼ |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | 0 |
| dahua | 0 | 3 | 0 | 1 | 1 | 1 | 0 | 0 | 0.0 | 6.9 | .0036 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 28 | 99 | 0 | 0 | 53 | 46 | 0 | 0 | 0.0 | 5.5 | .0029 | -7 ▼ |
| dell | 27 | 83 | 4 | 38 | 38 | 3 | 2 | 1 | 1.2 | 7.0 | .0020 | +20 ▲ |
| spring | 0 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | -53 ▼ |
| capgo | 7 | 68 | 2 | 34 | 31 | 1 | 0 | 0 | 0.0 | 7.0 | .0037 | +7 ▲ |
| openclaw | 1 | 68 | 0 | 36 | 22 | 10 | 0 | 0 | 0.0 | 7.0 | .0021 | +1 ▲ |
| edimax | 0 | 65 | 0 | 39 | 0 | 26 | 1 | 0 | 0.0 | 7.4 | .0080 | 0 |
| itsourcecode | 10 | 63 | 0 | 0 | 19 | 44 | 0 | 0 | 0.0 | 2.1 | .0033 | -12 ▼ |
| themerex | 2 | 60 | 5 | 54 | 1 | 0 | 0 | 0 | 0.0 | 8.1 | .0043 | +2 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-10520 | .9991 | 100.0 | 10.0 |
| CVE-2026-20253 | .9694 | 99.9 | 9.8 |
| CVE-2026-35273 | .9547 | 99.9 | 9.8 |
| CVE-2026-20230 | .8820 | 99.8 | 8.6 |
| CVE-2026-34910 | .8747 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-48907 | .7810 | 99.5 | 10.0 |
| CVE-2026-45659 | .7608 | 99.5 | 8.8 |
| CVE-2026-34909 | .6390 | 99.2 | 10.0 |
| CVE-2026-48282 | .4239 | 98.6 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-10520 | 10.0 | .9991 | KEV |
| CVE-2026-34910 | 10.0 | .8747 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-48907 | 10.0 | .7810 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-48282 | 10.0 | .4239 | KEV |
| CVE-2026-56290 | 10.0 | .3038 | KEV |
| CVE-2026-48908 | 10.0 | .1482 | KEV |
| CVE-2026-59726 | 10.0 | .0688 | |
| CVE-2026-13773 | 10.0 | .0610 |
| Vendor | CVEs |
|---|---|
| 607 | |
| linux | 455 |
| oracle | 241 |
| red hat | 130 |
| apache | 120 |
| ibm | 72 |
| capgo | 68 |
| microsoft | 66 |
| openclaw | 62 |
| themerex | 60 |
| Vendor | KEV |
|---|---|
| microsoft | 20 |
| cisco | 11 |
| apple | 7 |
| 6 | |
| ivanti | 5 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| fortinet | 3 |
| smartertools | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 70 |
| npm | 6 |
| PyPI | 5 |
| NuGet | 3 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-10520 | ivanti | 0 |
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-20253 | Splunk | 0 |
| CVE-2026-20262 | Cisco | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE-2026-34909 | Ubiquiti Inc | 0 |
| CVE-2026-34910 | Ubiquiti Inc | 0 |
| CVE-2026-35273 | Oracle Corporation | 0 |
| CVE-2026-45659 | Microsoft | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1695 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1695 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1695 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1695 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1695 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1695 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1695 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1695 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1695 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1695 |
EXPLOIT PUBLISHED — open-webui: 9 CVEs (CVE-2026-59212, CVE-2026-59213, CVE-2026-59217, CVE-2026-59219, CVE-2026-59220, CVE-2026-59221, CVE-2026-59222, CVE-2026-59227, CVE-2026-59715). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2026-39243. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-39245. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-39246. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54695 (pipecat-ai pipecat). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56292 (acymailing.com AcyMailing extension for Joomla). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58459 (ntpsec gpsd). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-59856 (vim). Public exploit reference added.
How to read these box scores · glossary
276 CVEs published. 25 box scores, 251 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0688 93.5 —
AFFECTED Product Versions Fixed ruflo < 3.16.3 – —
TIMELINE Jul 6 Reserved by CNA Jul 9 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P L N H H N 7.6 .0313 86.9 —
AFFECTED Product Versions Fixed n8n >= 2.28.0, < 2.28.1 – —
TIMELINE Jul 2 Reserved by CNA Jul 9 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N N A H H H 8.4 .0180 76.7 —
AFFECTED Product Versions Fixed gpsd unspecified —
TIMELINE Jun 30 Reserved by CNA Jul 9 Public exploit reference published Jul 9 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H N 6.0 .0167 75.0 —
AFFECTED Product Versions Fixed Cloud NGFW unspecified All PAN-OS 12.1.0 – 12.1.8 Prisma Access unspecified All
TIMELINE Nov 3 Reserved by CNA Jul 9 Published (CNA: palo_alto)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0134 69.1 —
AFFECTED Product Versions Fixed hermes-webui unspecified —
TIMELINE Jun 29 Reserved by CNA Jul 9 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0123 66.6 —
AFFECTED Product Versions Fixed Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder unspecified —
TIMELINE May 18 Reserved by CNA Jul 9 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H H N U H H H 6.6 .0121 66.0 —
AFFECTED Product Versions Fixed WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell unspecified —
TIMELINE Jun 23 Reserved by CNA Jul 9 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N L N L L L 1.9 .0108 62.6 —
AFFECTED Product Versions Fixed openclaw-android 0.1 – —
TIMELINE Jul 9 Reserved by CNA Jul 9 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0107 62.3 —
AFFECTED Product Versions Fixed miniOrange OTP Login, Verification and SMS Notifications unspecified —
TIMELINE Jun 30 Reserved by CNA Jul 9 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0107 62.2 —
AFFECTED Product Versions Fixed Blocksy Companion unspecified —
TIMELINE Jul 8 Reserved by CNA Jul 9 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U L N H 7.1 .0106 62.0 —
AFFECTED Product Versions Fixed Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder unspecified —
TIMELINE Jul 1 Reserved by CNA Jul 9 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0103 61.2 —
AFFECTED Product Versions Fixed Xerte Online Tools unspecified — Xerte Online Tools unspecified —
TIMELINE Jun 30 Reserved by CNA Jul 9 Published (CNA: certcc)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0102 60.7 —
AFFECTED Product Versions Fixed LibreBooking unspecified 5.1.0
TIMELINE Jul 8 Reserved by CNA Jul 9 Published (CNA: cisa-cg)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0101 60.5 —
AFFECTED Product Versions Fixed hoppscotch < 2026.6.0 – —
TIMELINE Jul 6 Reserved by CNA Jul 9 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0093 58.1 —
AFFECTED Product Versions Fixed metabase >= 1.58.0, < 1.58.15 – —
TIMELINE Jul 7 Reserved by CNA Jul 9 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0092 57.7 —
AFFECTED Product Versions Fixed zeek unspecified —
TIMELINE Jul 8 Reserved by CNA Jul 9 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H H 10.0 .0091 57.3 —
AFFECTED Product Versions Fixed langroid < 0.65.2 – —
TIMELINE Jun 15 Reserved by CNA Jul 9 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N L N H H H 6.8 .0085 55.5 —
AFFECTED Product Versions Fixed DIR-823G 1.0.2B05_20181207 – —
TIMELINE Jul 9 Reserved by CNA Jul 9 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0081 54.2 —
AFFECTED Product Versions Fixed coolify < 4.0.0-beta.469 – —
TIMELINE Jul 6 Reserved by CNA Jul 9 Published (CNA: GitHub_M)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0079 53.6 —
AFFECTED Product Versions Fixed zeek unspecified —
TIMELINE Jul 8 Reserved by CNA Jul 9 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N L L 5.5 .0076 52.6 —
AFFECTED Product Versions Fixed sendportal 3.0.0 – —
TIMELINE Jul 9 Reserved by CNA Jul 9 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N L L 6.9 .0075 52.0 —
AFFECTED Product Versions Fixed Backup & Recovery 9.0 unspecified —
TIMELINE Jul 8 Reserved by CNA Jul 9 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H N 9.1 .0074 51.9 —
AFFECTED Product Versions Fixed kirby < 4.9.4 – —
TIMELINE Jun 11 Reserved by CNA Jul 9 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L R C H H H 9.0 .0073 51.7 —
AFFECTED Product Versions Fixed discourse >= 2026.1.0-latest, < 2026.1.5 – —
TIMELINE Jun 11 Reserved by CNA Jul 9 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L N N 5.3 .0072 51.1 —
AFFECTED Product Versions Fixed GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress unspecified —
TIMELINE Jun 26 Reserved by CNA Jul 9 Published (CNA: Wordfence)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-15271 | 7.7 | 50.6 | TOTOLINK | A3000RU | CWE-266 | TOTOLINK EX200 Web boa.conf least privilege violation |
| CVE-2026-12116 | 9.8 | 50.5 | Xerte | Xerte Online Tools | — | CVE-2026-12116 |
| CVE-2026-50180 | 8.7 | 49.9 | langroid | langroid | CWE-22 | Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family e… |
| CVE-2026-13492 | 8.8 | 49.8 | stiofansisland | UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP | CWE-22 | UsersWP <= 1.2.65 - Authenticated (Subscriber+) Arbitrary File Deletion via F… |
| CVE-2026-51923 | 8.1 | 49.7 | n/a | n/a | CWE-639 | An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm G… |
| CVE-2026-15204 | 5.5 | 49.3 | TOTOLINK | X5000R | CWE-22 | TOTOLINK X5000R OpenVPN Export cstecgi.cgi exportOvpn path traversal |
| CVE-2026-55207 | 8.8 | 49.0 | pimcore | pimcore | CWE-640 | Pimcore: Account Takeover via Password Reset URL Injection allows unauthentic… |
| CVE-2026-59206 | 7.1 | 48.8 | n8n-io | n8n | CWE-1321 | n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated Us… |
| CVE-2026-39246 | 7.5 | 48.7 | n/a | n/a | CWE-59 | decompress before 4.2.2 allows arbitrary symlink creation during archive extr… |
| CVE-2026-54760 | 9.3 | 48.2 | langroid | langroid | CWE-22 | Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quot… |
| CVE-2026-60094 | 6.9 | 47.9 | Vinchin | Backup & Recovery 9.0 | CWE-787 | Vinchin Backup & Recovery 9.0.0.86562 Heap Buffer Overflow via agentlink_server |
| CVE-2026-15308 | 8.7 | 47.8 | Python Software Foundation | CPython | CWE-400 | Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated untermin… |
| CVE-2026-45788 | 6.3 | 47.7 | discourse | discourse | CWE-200 | Discourse: Secure uploads exposed by hotlinked image copying |
| CVE-2026-0279 | 1.3 | 47.6 | Palo Alto Networks | Cloud NGFW | CWE-79 | PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities |
| CVE-2026-51599 | 9.8 | 47.5 | n/a | n/a | CWE-20 | An insufficient input validation vulnerability in the RTSP service of MERCURY… |
| CVE-2026-0287 | 6.6 | 47.1 | Palo Alto Networks | Cloud NGFW | CWE-754 | PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing |
| CVE-2026-54801 | 8.6 | 46.9 | Siemens | CPCI85 Central Processing/Communication | CWE-620 | A vulnerability has been identified in CPCI85 Central Processing/Communicatio… |
| CVE-2026-51926 | 7.5 | 46.9 | n/a | n/a | CWE-203 | An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obt… |
| CVE-2026-38076 | 7.5 | 46.5 | n/a | n/a | CWE-190 | An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex com… |
| CVE-2026-11404 | 8.7 | 46.4 | Cesanta | Mongoose | CWE-125 | Cesanta Mongoose Out-of-Bounds Read in MG_TLS_BUILTIN ClientHello Session ID … |
| CVE-2026-55420 | 8.1 | 46.2 | discourse | discourse | CWE-78 | Discourse: Remote code execution via pdf uploads |
| CVE-2026-55605 | 5.3 | 46.1 | arikusi | deepseek-mcp-server | CWE-306 | @arikusi/deepseek-mcp-server Missing Authentication on Self-Hosted HTTP MCP E… |
| CVE-2026-59720 | 7.5 | 45.7 | hoppscotch | hoppscotch | CWE-200 | Hoppscotch: Insecure Default Configuration Allows Public Exposure of Private … |
| CVE-2026-15000 | 7.2 | 45.6 | rnzo | Connect Contact Form 7 and Mailchimp | CWE-79 | Connect Contact Form 7 and Mailchimp <= 0.9.78.06 - Unauthenticated Stored Cr… |
| CVE-2026-59692 | 7.5 | 44.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-121 | Gstreamer: gstreamer: dtls certificate subject dn stack buffer overflow in op… |
| CVE-2026-51924 | 8.1 | 44.8 | n/a | n/a | CWE-639 | An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute… |
| CVE-2026-51600 | 7.5 | 44.7 | n/a | n/a | CWE-400 | Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length heade… |
| CVE-2026-59220 | 6.5 | 44.7 | open-webui | open-webui | CWE-1333 | Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on defau… |
| CVE-2026-51601 | 7.5 | 44.6 | n/a | n/a | CWE-121 | Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in … |
| CVE-2026-51604 | 7.5 | 44.6 | n/a | n/a | CWE-121 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 … |
| CVE-2026-51605 | 7.5 | 44.6 | n/a | n/a | CWE-121 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 … |
| CVE-2026-12597 | 8.1 | 44.5 | LoginPress | LoginPress Pro | CWE-287 | LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverifie… |
| CVE-2026-54695 | 6.5 | 44.3 | pipecat-ai | pipecat | CWE-862 | Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Att… |
| CVE-2026-12406 | 5.3 | 44.1 | wedevs | User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration | CWE-862 | User Frontend <= 4.3.7 - Missing Authorization to Unauthenticated Arbitrary A… |
| CVE-2026-51602 | 7.5 | 44.0 | n/a | n/a | CWE-121 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 … |
| CVE-2026-51603 | 7.5 | 44.0 | n/a | n/a | CWE-121 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 … |
| CVE-2026-12595 | 8.1 | 44.0 | LoginPress | LoginPress Pro | CWE-287 | LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverifie… |
| CVE-2026-12598 | 8.1 | 44.0 | LoginPress | LoginPress Pro | CWE-287 | LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverifie… |
| CVE-2026-54002 | 8.5 | 43.4 | getkirby | kirby | CWE-79 | Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `D… |
| CVE-2026-51925 | 8.1 | 43.4 | n/a | n/a | CWE-639 | A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.1… |
| CVE-2026-47826 | 8.5 | 43.3 | CloudFoundry Foundation | BOSH CLI tool | CWE-22 | blobs.yaml Path Traversal Allows File Writes |
| CVE-2026-59828 | 5.3 | 43.3 | discourse | discourse | CWE-200 | Discourse: Hidden post revisions leak through adjacent visible diffs |
| CVE-2026-59826 | 9.1 | 43.0 | metabase | metabase | CWE-94 | Metabase: Arbitrary Code Execution via Database Connection Detail Bypass |
| CVE-2026-51597 | 9.1 | 42.3 | n/a | n/a | CWE-294 | MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement … |
| CVE-2026-59833 | 8.6 | 42.4 | siyuan-note | siyuan | CWE-79 | SiYuan: Stored XSS to RCE in SiYuan via a per-attribute URL-scheme sanitizer … |
| CVE-2026-59855 | 8.6 | 42.4 | siyuan-note | siyuan | CWE-80 | SiYuan: Store XSS To Rce via Asset.render |
| CVE-2026-9021 | 5.3 | 41.6 | matrixaddons | Easy Invoice – Invoice Generator, PDF Quotes & Payments | CWE-862 | Easy Invoice <= 2.1.19 - Unauthenticated Arbitrary Quote Accept/Decline and I… |
| CVE-2026-46413 | 6.5 | 41.4 | discourse | discourse | CWE-862 | Discourse: Regular users can route multipart uploads into the admin backup store |
| CVE-2026-15138 | 2.1 | 41.2 | tumf | mcp-text-editor | CWE-22 | tumf mcp-text-editor text_editor.py _validate_file_path path traversal |
| CVE-2026-31984 | 8.7 | 41.1 | Nozomi Networks | Guardian | CWE-770 | DoS through oversized audit log entries in Guardian/CMC before 26.2.0 |
| CVE-2026-59834 | 7.5 | 41.1 | siyuan-note | siyuan | CWE-89 | SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content |
| CVE-2026-49256 | 6.3 | 41.1 | discourse | discourse | CWE-200 | Discourse: Hidden tag names leaked via category serializers |
| CVE-2026-57501 | 0.0 | 40.9 | zen-browser | desktop | CWE-266 | Zen: Context-menu "Open link in glance" / "Split link in new tab" loads a pag… |
| CVE-2026-53987 | 7.3 | 40.7 | Tag plugin | GLPI 11 | CWE-79 | GLPI 11 before 2.14.4 Tag Plugin Stored Cross-Site Scripting in Kanban Badge … |
| CVE-2026-45780 | 4.3 | 40.4 | discourse | discourse | CWE-200 | Discourse: Private event sample invitees are serialized to non-invited event … |
| CVE-2026-54004 | 6.3 | 40.3 | getkirby | kirby | CWE-862 | Kirby: Access to files of top-level drafts is not protected by permissions |
| CVE-2026-13461 | 9.6 | 40.2 | PayRange | PayRange | — | PayRange version 7.0.7 contains a JavaScript injection vulnerability |
| CVE-2026-55590 | 5.1 | 39.9 | cakephp | authentication | CWE-601 | CakePHP: Open redirect weakness via backslash bypass |
| CVE-2026-43752 | 4.9 | 39.9 | Claris | FileMaker Server | CWE-434 | An authenticated administrator may be able to achieve arbitrary code executio… |
| CVE-2026-59854 | 4.9 | 39.5 | siyuan-note | siyuan | CWE-693 | SiYuan: Incomplete IsSensitivePath denylist: globalCopyFiles reads home-dir c… |
| CVE-2026-49274 | 5.3 | 39.5 | getkirby | kirby | CWE-862 | Kirby: `pages.access` permission is not checked in the pages picker for paren… |
| CVE-2026-59221 | 7.7 | 39.4 | open-webui | open-webui | CWE-22 | open-webui terminal proxy path traversal guard bypass via 9x encoded traversal |
| CVE-2026-59149 | 6.5 | 39.4 | mockoon | mockoon | CWE-22 | Mockoon: Path traversal in templated `filePath` lets a request escape the ser… |
| CVE-2026-8996 | 6.5 | 38.9 | revmakx | Backup and Staging by WP Time Capsule | CWE-862 | Backup and Staging by WP Time Capsule <= 1.22.26 - Missing Authorization to A… |
| CVE-2026-12428 | 6.5 | 38.9 | gamaup | Blocks for ACF Fields — Display Custom Fields in the Block Editor | CWE-862 | Blocks for ACF Fields <= 1.6.2 - Missing Authorization to Authenticated (Auth… |
| CVE-2026-57021 | 6.9 | 38.8 | Juniper Networks | Junos OS | CWE-787 | Junos OS: SRX Series: If VPN compliance-check is configured an attacker can c… |
| CVE-2026-9028 | 5.3 | 38.8 | corvusinfo | CorvusPay WooCommerce Payment Gateway | CWE-862 | CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Missing Authorization to Una… |
| CVE-2026-61344 | 6.9 | 38.8 | Superior Court of California, County of Los Angeles | Hearing Reminder Service | CWE-306 | Superior Court of California Hearing Reminder Service unauthenticated informa… |
| CVE-2026-50644 | 8.6 | 38.5 | SOPlanning | SOPlanning | CWE-89 | SQL Injection in SOPlanning Audit Retention Configuration |
| CVE-2026-5955 | 9.8 | 38.4 | Inrove Software and Internet Services | BiEticaret | CWE-89 | SQLi in Inrove Software's BiEticaret |
| CVE-2026-59832 | 7.7 | 38.2 | siyuan-note | siyuan | CWE-22 | SiYuan: Authenticated path traversal in /snippets/ static handler (serveSnipp… |
| CVE-2026-0284 | 4.7 | 38.2 | Palo Alto Networks | Cloud NGFW | CWE-74 | PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN) |
| CVE-2026-1365 | 6.5 | 38.1 | Sayax Energy Technologies Inc. | OSOS | CWE-201 | Information Disclosure in Sayax's OSOS |
| CVE-2026-55615 | 9.2 | 38.0 | langroid | langroid | CWE-74 | Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (pr… |
| CVE-2026-44787 | 7.1 | 37.9 | discourse | discourse | CWE-269 | Discourse: Signup-time primary_group_id assignment grants whisperer access |
| CVE-2026-57023 | 8.7 | 37.9 | Juniper Networks | Junos OS | CWE-1284 | Junos OS: MX with SPC3, SRX Series: A specifically malformed TCP packet cause… |
| CVE-2026-57026 | 8.7 | 37.9 | Juniper Networks | Junos OS | CWE-1286 | Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malfo… |
| CVE-2026-51606 | 7.5 | 37.9 | n/a | n/a | CWE-20 | An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.… |
| CVE-2026-15195 | 2.1 | 37.7 | apidevtools | json-schema-ref-parser | CWE-94 | apidevtools json-schema-ref-parser pointer.ts Pointer.set prototype pollution |
| CVE-2026-59219 | 7.1 | 37.6 | open-webui | open-webui | CWE-613 | Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backch… |
| CVE-2026-7558 | 5.3 | 37.5 | tokenoftrust | Age Verification & Identity Verification by Token of Trust | CWE-862 | Age Verification & Identity Verification by Token of Trust <= 4.0.2 - Missing… |
| CVE-2026-12433 | 4.3 | 37.5 | themefic | Hydra Booking — Appointment Scheduling & Booking Calendar | CWE-639 | Hydra Booking <= 1.2.1 - Authenticated (Custom+) Insecure Direct Object Refer… |
| CVE-2026-55865 | 7.1 | 37.3 | jg-rp | liquid | CWE-835 | Python Liquid: Infinite loop when parsing malformed `{% case %}` tags |
| CVE-2026-13011 | 6.5 | 37.3 | wedevs | ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce | CWE-89 | ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM… |
| CVE-2026-15202 | 2.1 | 37.1 | n/a | YzmCMS | CWE-79 | YzmCMS Header yzmphp.php get_url cross site scripting |
| CVE-2025-45422 | 8.1 | 37.1 | n/a | n/a | CWE-284 | Incorrect access control in Proximus b-box v8c.725A allows authenticated atta… |
| CVE-2026-59207 | 7.1 | 37.0 | n8n-io | n8n | CWE-693 | n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Conn… |
| CVE-2026-56292 | 9.2 | 36.8 | acymailing.com | acymailing.com AcyMailing extension for Joomla | CWE-89 | Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 1… |
| CVE-2026-50188 | 6.9 | 36.7 | getkirby | kirby | CWE-93 | Kirby: Request header injection in `Http\Remote` |
| CVE-2026-5523 | 8.8 | 36.6 | Divi Engine | Divi Form Builder | CWE-639 | Divi Form Builder <= 5.1.8 - Authenticated (Subscriber+) Missing Authorizatio… |
| CVE-2026-58378 | 8.6 | 36.6 | Allwinner | H616 | CWE-489 | Allwinner TV Box TV98 ADB exposed on network |
| CVE-2026-33655 | 7.7 | 36.6 | QuantumNous | new-api | CWE-918 | New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs |
| CVE-2026-14342 | 4.9 | 36.6 | getwpfunnels | Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails | CWE-89 | Mail Mint <= 1.24.2 - Authenticated (Administrator+) SQL Injection via 'conta… |
| CVE-2026-12593 | 8.7 | 36.1 | Qt | Axivion | CWE-862 | Privilege escalation via forged API token creation in Axivion Dashboard OIDC/… |
| CVE-2026-11571 | 7.5 | 36.0 | Unknown | Everest Forms | — | Everest Forms < 3.5.0 - Unauthenticated Sensitive Information Exposure via Re… |
| CVE-2026-49276 | 7.4 | 35.8 | getkirby | kirby | CWE-83 | Kirby: Self cross-site scripting (self-XSS) in the writer field |
| CVE-2026-15137 | 5.5 | 35.7 | code-projects | Interview Management System | CWE-74 | code-projects Interview Management System View.php sql injection |
| CVE-2026-15190 | 5.5 | 35.7 | SourceCodester | Simple and Nice Shopping Cart Script | CWE-74 | SourceCodester Simple and Nice Shopping Cart Script login.php sql injection |
| CVE-2026-13441 | 7.2 | 35.5 | metagauss | EventPrime – Events Calendar, Bookings and Tickets | CWE-79 | EventPrime <= 4.3.4.2 - Unauthenticated Stored Cross-Site Scripting via 'new_… |
| CVE-2026-54005 | 7.1 | 35.4 | getkirby | kirby | CWE-862 | Kirby: `pages.access` permission is not checked in the `site/find` REST API r… |
| CVE-2026-15187 | 2.1 | 35.4 | n/a | enquirer | CWE-94 | enquirer Public Package API Enquirer.set prototype pollution |
| CVE-2026-1989 | 7.5 | 35.2 | PAVO Financial Technology Solutions Inc. | PAVO Pay | CWE-639 | IDOR in PAVO Inc.'s PAVO Pay |
| CVE-2026-12418 | 5.3 | 35.0 | wedevs | User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration | CWE-639 | User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membersh… |
| CVE-2026-57032 | 7.1 | 34.8 | Juniper Networks | Junos OS | CWE-236 | Junos OS: EX Series: Subscribing to an unsupported telemetry sensor path caus… |
| CVE-2026-59212 | 5.4 | 34.8 | open-webui | open-webui | CWE-863 | Open WebUI: Model meta.knowledge read-only file access can be upgraded to fil… |
| CVE-2026-47829 | 7.7 | 34.7 | CloudFoundry Foundation | bosh-cli | CWE-88 | Argument Injection in BOSH CLI Allows Local Command Execution on Operator Wor… |
| CVE-2026-13771 | 6.4 | 34.6 | ivole | Customer Reviews for WooCommerce | CWE-79 | Customer Reviews for WooCommerce <= 5.113.0 - Authenticated (Contributor+) St… |
| CVE-2026-57024 | 6.9 | 34.5 | Juniper Networks | Junos OS | CWE-694 | Junos OS: MX with SPC3, SRX Series: Repeated VPN negotiation failures will ev… |
| CVE-2026-55424 | 7.4 | 34.3 | discourse | discourse | CWE-79 | Discourse: Topic featured link susceptible to stored XSS |
| CVE-2026-53962 | 5.4 | 34.3 | discourse | discourse | CWE-79 | Discourse: Insufficient SVG sanitization logic |
| CVE-2026-55208 | 7.7 | 34.1 | pimcore | pimcore | CWE-89 | Pimcore: SQL Injection via Column Name in DateFilter allows authenticated use… |
| CVE-2026-31983 | 6.9 | 34.1 | Nozomi Networks | Guardian | CWE-306 | Missing authentication in SSH keys synchronization endpoint in Guardian/CMC b… |
| CVE-2026-59218 | 5.3 | 34.0 | open-webui | open-webui | CWE-208 | Open WebUI: Account enumeration via observable login timing discrepancy |
| CVE-2026-61474 | 5.3 | 34.1 | misp | misp | CWE-863 | MISP: Improper sharing group authorization check when adding attributes |
| CVE-2026-15186 | 2.1 | 34.1 | macrozheng | mall | CWE-99 | macrozheng mall Portal Endpoint create resource injection |
| CVE-2026-12590 | 5.9 | 34.0 | body-parser | body-parser | CWE-770 | body-parser vulnerable to denial of service when invalid limit value silently… |
| CVE-2026-54798 | 7.1 | 33.9 | Siemens | CPCI85 Central Processing/Communication | CWE-489 | A vulnerability has been identified in CPCI85 Central Processing/Communicatio… |
| CVE-2026-55689 | 8.1 | 33.5 | openfga | openfga | CWE-287 | OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset |
| CVE-2026-33794 | 8.2 | 33.4 | Juniper Networks | Junos OS Evolved | CWE-754 | Junos OS Evolved: PTX Series: Receipt of repeated ECMP routing updates result… |
| CVE-2026-57022 | 8.2 | 33.4 | Juniper Networks | Junos OS | CWE-754 | Junos OS: MX Series with SPC3, SRX Series: Specific packet in response to a T… |
| CVE-2026-59817 | 5.3 | 33.1 | TryGhost | Ghost | CWE-472 | Ghost: Paid gift memberships obtainable at minimal cost via the donations fea… |
| CVE-2026-59209 | 7.1 | 33.0 | n8n-io | n8n | CWE-200 | n8n: Shared Credential Header Leak via HTTP Request Pagination Expression |
| CVE-2026-59853 | 6.5 | 33.0 | siyuan-note | siyuan | CWE-862 | SiYuan: Publish-mode Reader can exfiltrate private saved-search Criteria via … |
| CVE-2026-33390 | 7.2 | 32.9 | Nozomi Networks | Guardian | CWE-266 | Incorrect privilege assignment for Arc sensors in Guardian/CMC before 26.2.0 |
| CVE-2026-9237 | 4.3 | 32.2 | crewhrm | Employee, Leave and Recruitment Management System – Crew HRM | CWE-862 | Employee, Leave and Recruitment Management System <= 1.2.2 - Missing Authoriz… |
| CVE-2026-54771 | 8.1 | 32.0 | langroid | langroid | CWE-75 | Langroid: handle_message() executes user-supplied tool JSON without sender ve… |
| CVE-2026-2342 | 9.3 | 31.9 | OceanicSoft Informatics Systems Ltd. | ValeApp | CWE-79 | XSS in Oceanicsoft's ValeApp |
| CVE-2026-59224 | 8.0 | 31.9 | open-webui | open-webui | CWE-287 | Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user ident… |
| CVE-2026-15191 | 2.1 | 31.2 | mettle | sendportal | CWE-285 | mettle sendportal Campaign Creation Endpoint CampaignStoreRequest.php authori… |
| CVE-2026-59223 | 4.3 | 31.0 | open-webui | open-webui | CWE-693 | Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via UR… |
| CVE-2026-57030 | 8.2 | 30.8 | Juniper Networks | Junos OS | CWE-362 | Junos OS: SRX Series: Flow sessions are not getting cleared leading to a DoS |
| CVE-2026-13334 | 6.1 | 30.7 | kitae-park | Mang Board WP | CWE-79 | Mang Board WP <= 2.3.4 - Reflected Cross-Site Scripting via 'stag' Parameter |
| CVE-2026-56460 | 6.5 | 30.7 | HCLSoftware | HCL DevOps Deploy / HCL Launch | CWE-201 | HCL DevOps Deploy / HCL Launch is susceptible to an Insertion of Sensitive In… |
| CVE-2026-39245 | 6.2 | 30.2 | n/a | n/a | CWE-22 | decompress before 4.2.2 contains an improper path containment check that enab… |
| CVE-2026-58122 | 9.3 | 30.0 | nesquena | hermes-webui | CWE-348 | Hermes WebUI < 0.51.307 Authentication Bypass via X-Forwarded-For Header Spoo… |
| CVE-2026-55604 | 8.6 | 30.0 | arikusi | deepseek-mcp-server | CWE-639 | @arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Control… |
| CVE-2026-59217 | 4.3 | 29.9 | open-webui | open-webui | CWE-862 | Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-… |
| CVE-2026-33799 | 5.3 | 29.4 | Juniper Networks | Junos OS | CWE-787 | Junos OS and Junos OS Evolved: Receipt of a specific SNMPv3 request results i… |
| CVE-2026-57054 | 6.9 | 29.3 | Juniper Networks | Junos OS | CWE-706 | Junos OS: MX Series: Web filtering doesn't block specifically formatted URLs |
| CVE-2026-9027 | 5.3 | 29.3 | corvusinfo | CorvusPay WooCommerce Payment Gateway | CWE-347 | CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Unauthenticated Improper Ver… |
| CVE-2026-15189 | 5.3 | 29.3 | aerostackdev | aerostack-mcp | CWE-918 | aerostackdev aerostack-mcp mcp-whatsapp upload_media server-side request forgery |
| CVE-2026-15188 | 2.1 | 29.3 | manjurulhoque | django-job-portal | CWE-266 | manjurulhoque django-job-portal Employee Dashboard Endpoint views.py EditEmpl… |
| CVE-2026-13253 | 6.4 | 28.4 | wpxpo | Post Grid Gutenberg Blocks – PostX | CWE-79 | Post Grid Gutenberg Blocks for News, Magazines, Blog Websites <= 5.0.31 - Aut… |
| CVE-2026-15311 | 2.0 | 28.3 | NousResearch | hermes-agent | CWE-79 | NousResearch hermes-agent Matrix Adapter matrix.py MatrixAdapter._markdown_to… |
| CVE-2026-60120 | 5.1 | 28.2 | Webkul | Bagisto | CWE-79 | Bagisto < 2.4.4 Stored XSS via CSTI in create.blade.php |
| CVE-2026-4256 | 8.2 | 28.0 | PEAKUP Technology Inc. | PassGate | CWE-90 | LDAP Injection in PEAKUP's PassGate |
| CVE-2026-4298 | 4.3 | 28.0 | mlfactory | DSGVO All in one for WP | CWE-862 | DSGVO All in one for WP <= 4.9 - Missing Authorization to Authenticated (Subs… |
| CVE-2026-33803 | 6.9 | 28.0 | Juniper Networks | Junos OS Evolved | CWE-923 | Junos OS Evolved: A port which has been inadvertently exposed can be reached … |
| CVE-2026-55212 | 7.1 | 27.7 | pimcore | pimcore | CWE-285 | Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint … |
| CVE-2026-0283 | 4.5 | 27.7 | Palo Alto Networks | Cloud NGFW | CWE-306 | PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN) |
| CVE-2026-4653 | 6.4 | 27.5 | bouncingsprout | Block, Suspend, Report for BuddyPress | CWE-79 | Block, Suspend, Report for BuddyPress <= 3.6.4 - Authenticated (Subscriber+) … |
| CVE-2026-6910 | 6.4 | 27.5 | safistudio | Bookero.pl – system rezerwacji online | CWE-79 | Bookero.pl <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting … |
| CVE-2026-12170 | 6.4 | 27.5 | acyba | AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress | CWE-79 | AcyMailing <= 10.10.2 - Authenticated (Contributor+) Stored Cross-Site Script… |
| CVE-2026-14343 | 6.4 | 27.5 | codename065 | Download Manager | CWE-79 | Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site S… |
| CVE-2026-57111 | 7.5 | 27.3 | Apache Software Foundation | Apache Helix REST | CWE-1385 | Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestric… |
| CVE-2026-55170 | 2.1 | 26.3 | openfga | openfga | CWE-178 | OpenFGA MySQL backend: case-insensitive collation on identifier columns cause… |
| CVE-2026-9235 | 4.3 | 26.0 | dhlparcel | DHL eCommerce (Benelux) for WooCommerce | CWE-862 | DHL eCommerce (Benelux) for WooCommerce <= 2.2.3 - Missing Authorization to A… |
| CVE-2026-9240 | 4.3 | 26.0 | iscpcolissimo | Colissimo shipping methods for WooCommerce | CWE-862 | Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 - Missin… |
| CVE-2026-11359 | 4.3 | 26.0 | metagauss | Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration | CWE-862 | Memberships and User Profiles for WooCommerce <= 3.4 - Missing Authorization … |
| CVE-2026-59691 | 7.1 | 24.9 | Red Hat | Red Hat Enterprise Linux 10 | CWE-787 | Gstreamer: gstreamer: rfbsrc/librfb hextile heap out-of-bounds write with 16b… |
| CVE-2026-59831 | 4.4 | 24.9 | cli | cli | CWE-829 | GitHub CLI `gh codespace jupyter` could allow remote code execution when conn… |
| CVE-2026-11869 | 5.3 | 24.5 | Unknown | WP DSGVO Tools (GDPR) | — | WP DSGVO Tools (GDPR) < 3.1.40 - Unauthenticated Sensitive Information Disclo… |
| CVE-2026-11875 | 5.3 | 24.5 | Unknown | WP Support Plus Responsive Ticket System | — | WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Support T… |
| CVE-2026-59215 | 3.1 | 24.6 | open-webui | open-webui | CWE-639 | Open WebUI: Private channel messages can be disclosed through cross-channel t… |
| CVE-2026-59222 | 6.0 | 24.4 | open-webui | open-webui | CWE-200 | Open WebUI: /api/v1/channels/{id}/members exposes full user model including s… |
| CVE-2026-47831 | 7.7 | 24.1 | Cloud Foundry Foundation | bosh-windows-stemcell-builder | — | Cryptographically Weak Password Generation in bosh-windows-stemcell-builder A… |
| CVE-2026-9253 | 7.2 | 24.0 | loopus | WP Cost Estimation & Payment Forms Builder | CWE-79 | WP Cost Estimation & Payment Forms Builder (E&P Forms) <= 10.5.97 - Unauthent… |
| CVE-2026-31267 | 5.7 | 23.7 | n/a | n/a | CWE-121 | Mercusys MW302R MW302R(EU)_V1_1.4.10 Build 231023 is vulnerable to Buffer Ove… |
| CVE-2026-0280 | 1.7 | 23.6 | Palo Alto Networks | Cloud NGFW | CWE-131 | PAN-OS: IPv6 Firewall Policy Bypass |
| CVE-2026-12516 | 5.3 | 23.4 | Unknown | Fediverse Embeds | — | Fediverse Embeds < 1.5.8 - Unauthenticated SSRF via Media Proxy |
| CVE-2026-12517 | 5.3 | 23.4 | Unknown | Fediverse Embeds | — | Fediverse Embeds < 1.5.8 - Unauthenticated SSRF via Site Info Endpoint |
| CVE-2026-59216 | 9.0 | 22.9 | open-webui | open-webui | CWE-94 | Open WebUI: Cross-user code-interpreter and tool execution via unvalidated So… |
| CVE-2026-31982 | 5.3 | 22.9 | Nozomi Networks | Guardian | CWE-601 | Open Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0 |
| CVE-2026-13462 | 7.5 | 22.3 | PayRange | PayRange | — | PayRange for Android, version 7.0.7, contains an SSL bypass vulnerability |
| CVE-2026-59226 | 4.3 | 22.4 | open-webui | open-webui | CWE-285 | Open WebUI: Scheduled automations continue after pending-user deactivation an… |
| CVE-2026-57028 | 6.9 | 22.1 | Juniper Networks | Junos OS Evolved | CWE-923 | Junos OS Evolved: A port which has been inadvertently exposed can be reached … |
| CVE-2026-39243 | 5.5 | 22.1 | n/a | n/a | CWE-59 | decompress before 4.2.2 allows arbitrary hardlink creation during archive ext… |
| CVE-2026-53961 | 6.5 | 22.0 | discourse | discourse | CWE-345 | Discourse: Forged AWS SNS bounce notifications can disable a targeted user's … |
| CVE-2026-12879 | 5.9 | 22.0 | Google Cloud | Apigee | CWE-441 | Cross-Tenant Data Exfiltration in Apigee via BigQuery Confused Deputy |
| CVE-2026-12270 | 6.5 | 21.8 | Unknown | Everest Forms | — | Everest Forms < 3.5.0 - Unauthenticated Missing Authorization via Site Assist… |
| CVE-2026-59213 | 5.0 | 21.7 | open-webui | open-webui | CWE-524 | Open WebUI: Cross-user model-list exposure via static cache key in get_all_mo… |
| CVE-2026-4275 | 8.8 | 21.4 | badhonrocks | Divi Torque Lite – Divi Modules for the Divi Builder & Theme | CWE-352 | Divi Torque Lite <= 4.2.3 - Cross-Site Request Forgery to Arbitrary Plugin In… |
| CVE-2026-0282 | 2.7 | 21.2 | Palo Alto Networks | Cloud NGFW | CWE-20 | PAN-OS: File Deletion Vulnerability in Management Web Interface |
| CVE-2026-59214 | 9.0 | 20.5 | open-webui | open-webui | CWE-79 | Open WebUI: Stored web worker XSS via Pyodide |
| CVE-2026-47828 | 8.9 | 20.5 | BOSH-Ecosystem / BOSH (bosh-cli) | bosh-cli | — | Missing TLS Certificate Verification in BOSH CLI Allows Root Code Execution v… |
| CVE-2026-0281 | 2.1 | 20.3 | Palo Alto Networks | Cloud NGFW | CWE-524 | PAN-OS: Information Disclosure Vulnerability in Management Web Interface |
| CVE-2026-33801 | 7.1 | 20.0 | Juniper Networks | Junos OS | CWE-754 | Junos OS and Junos OS Evolved: When a specifically malformed BGP route update… |
| CVE-2025-63579 | 7.5 | 18.7 | n/a | n/a | CWE-200 | Unauthorized use of Kyocera printers, allows all information stored in the Ky… |
| CVE-2026-33800 | 7.1 | 18.5 | Juniper Networks | Junos OS | CWE-606 | Junos OS: MX Series: In a VC scenario a high rate of micro-BFD session flaps … |
| CVE-2026-57019 | 7.1 | 18.5 | Juniper Networks | Junos OS | CWE-1284 | Junos OS: MX Series: Specific traffic causes an FPC to reset |
| CVE-2026-57020 | 7.1 | 18.5 | Juniper Networks | Junos OS | CWE-754 | Junos OS: QFX10000 Series: IPv6 multicast traffic received on non-IRB interfa… |
| CVE-2026-57027 | 7.1 | 18.5 | Juniper Networks | Junos OS | CWE-401 | Junos OS: EX4100 Series, EX4400: With sFlow configured in a VC scenario multi… |
| CVE-2026-51598 | 6.5 | 18.5 | n/a | n/a | CWE-20 | An input validation vulnerability in the RTSP service of MERCURY MIPC252W IP … |
| CVE-2026-59269 | 3.8 | 18.5 | VMware | Pinniped | — | Privilege Escalation via Active Directory LDAP injection in Pinniped Supervis… |
| CVE-2026-56458 | 7.5 | 17.7 | HCLSoftware | HCL DevOps Deploy | CWE-942 | HCL DevOps Deploy is susceptible to a Permissive Cross-domain Security Policy… |
| CVE-2026-59148 | 8.8 | 17.6 | mockoon | mockoon | CWE-306 | Mockoon: Unauthenticated admin API + wildcard CORS allows mock-state hijack a… |
| CVE-2026-59227 | 5.4 | 17.2 | open-webui | open-webui | CWE-862 | Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch an… |
| CVE-2026-5793 | 6.1 | 16.4 | Inrove Software and Internet Services | BiEticaret | CWE-79 | XSS in Inrove Software's BiEticaret |
| CVE-2026-31981 | 4.8 | 16.3 | Nozomi Networks | Guardian | CWE-79 | HTML injection in Diagram tab and Graph view in Guardian/CMC before 26.2.0 |
| CVE-2026-57031 | 5.3 | 14.6 | Juniper Networks | Junos OS | CWE-754 | Junos OS: MX Series: For subscribers configured on static interfaces, input f… |
| CVE-2026-58143 | 8.7 | 14.3 | Cotonti | Cotonti | CWE-352 | Cotonti Siena 0.9.26 CSRF via admin.php Config Update Endpoint |
| CVE-2026-54800 | 6.3 | 13.5 | Siemens | CPCI85 Central Processing/Communication | CWE-1188 | A vulnerability has been identified in CPCI85 Central Processing/Communicatio… |
| CVE-2026-0285 | 4.7 | 13.4 | Palo Alto Networks | Cloud NGFW | CWE-918 | PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface |
| CVE-2026-41857 | 7.1 | 13.1 | CloudFoundry BOSH | BOSH CLI | CWE-78 | BOSH CLI Shell Injection |
| CVE-2026-5005 | 5.4 | 13.1 | Twiser Informatics Technology Consulting, Trade and Education Inc. | OKRs & Goals | CWE-79 | Stored XSS in Twiser's OKRs & Goals |
| CVE-2026-58144 | 5.1 | 13.1 | Cotonti | Cotonti | CWE-79 | Cotonti Siena 0.9.26 Stored XSS via PFS Module ntitle Parameter |
| CVE-2026-59715 | 6.5 | 12.6 | open-webui | open-webui | CWE-306 | Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handle… |
| CVE-2026-47840 | 9.3 | 11.9 | CloudFoundry Foundation | UAA | — | LDAP StartTLS unconditionally disables hostname verification |
| CVE-2026-59856 | 8.4 | 11.8 | vim | vim | CWE-94 | Vim: Arbitrary Code Execution via PHP Omni-Completion |
| CVE-2026-59225 | 6.3 | 11.2 | open-webui | open-webui | CWE-862 | Open WebUI: Arena task endpoints can bypass underlying model access controls |
| CVE-2026-31985 | 8.3 | 10.1 | Nozomi Networks | Remote Collector | CWE-671 | Disabled and non-configurable TLS certificate validation in n2os-tui when con… |
| CVE-2026-0277 | 5.7 | 9.9 | Palo Alto Networks | Prisma Access Agent | CWE-295 | Prisma Access Agent: Improper Certificate Validation on iOS |
| CVE-2026-44342 | 5.3 | 8.8 | QuantumNous | new-api | CWE-352 | New API CSRF in email and WeChat account binding endpoints |
| CVE-2026-57029 | 6.0 | 8.6 | Juniper Networks | Junos OS Evolved | CWE-820 | Junos OS Evolved: QFX Series: When sFlow collector reachability changes evo-p… |
| CVE-2026-15182 | 1.9 | 8.1 | GNU | LibreDWG | CWE-119 | GNU LibreDWG BMP Image dwg.c dwg_bmp heap-based overflow |
| CVE-2026-50181 | 7.1 | 7.9 | langroid | langroid | CWE-22 | Langroid: Path traversal in the file tools allows read/write outside configur… |
| CVE-2026-54799 | 8.4 | 7.9 | Siemens | CPCI85 Central Processing/Communication | CWE-489 | A vulnerability has been identified in CPCI85 Central Processing/Communicatio… |
| CVE-2025-58146 | 9.4 | 7.3 | Xen | XAPI | CWE-20 | XAPI UTF-8 string handling |
| CVE-2026-56288 | 4.6 | 6.2 | GNU | patch | CWE-476 | NULL Pointer Dereference in GNU patch |
| CVE-2026-56289 | 4.6 | 6.2 | GNU | patch | CWE-835 | Loop with Unreachable Exit Condition in GNU patch |
| CVE-2026-15184 | 1.9 | 6.2 | GNU | LibreDWG | CWE-404 | GNU LibreDWG DWG File dwg.c dwg_next_entity null pointer dereference |
| CVE-2026-23559 | 9.4 | 6.1 | Xen | XAPI | CWE-250 | Multiple RBAC issues in XAPI |
| CVE-2026-23560 | 9.4 | 6.1 | Xen | XAPI | CWE-250 | Multiple RBAC issues in XAPI |
| CVE-2026-23561 | 9.4 | 6.1 | Xen | XAPI | CWE-250 | Multiple RBAC issues in XAPI |
| CVE-2026-23562 | 9.4 | 6.1 | Xen | XAPI | CWE-250 | Multiple RBAC issues in XAPI |
| CVE-2026-42486 | 9.4 | 6.1 | Xen | XAPI | CWE-250 | Multiple RBAC issues in XAPI |
| CVE-2026-21901 | 6.7 | 6.0 | Juniper Networks | Junos OS | CWE-476 | Junos OS and Junos OS Evolved: Configuration of a specific SSH option results… |
| CVE-2026-0275 | 2.0 | 5.9 | Palo Alto Networks | Prisma Browser | CWE-269 | Prisma Browser: Local Privilege Escalation on macOS |
| CVE-2026-58303 | 6.1 | 5.7 | Samsung Open Source | Escargot | CWE-121 | Stack-based buffer overflow vulnerability in Samsung Open Source Escargot all… |
| CVE-2026-58306 | 6.1 | 5.7 | Samsung Open Source | Escargot | CWE-122 | Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allo… |
| CVE-2026-15194 | 1.9 | 5.4 | n/a | Open5GS | CWE-119 | Open5GS AMF context.c amf_context_final use after free |
| CVE-2026-15185 | 1.9 | 5.3 | n/a | GPAC | CWE-119 | GPAC MP4Box vobsub.c vobsub_read_idx out-of-bounds |
| CVE-2026-15274 | 1.9 | 5.3 | lo48576 | fbxcel | CWE-404 | lo48576 fbxcel Node Header parser.rs denial of service |
| CVE-2026-15276 | 1.9 | 5.3 | pdeljanov | Symphonia | CWE-404 | pdeljanov Symphonia Metadata denial of service |
| CVE-2025-27462 | 9.4 | 5.2 | Xen | Windows PV drivers | CWE-276 | WinPVDrivers: Excessive permissions on user-exposed devices |
| CVE-2025-27463 | 9.4 | 5.2 | Xen | Windows PV drivers | CWE-276 | WinPVDrivers: Excessive permissions on user-exposed devices |
| CVE-2025-27464 | 9.4 | 5.2 | Xen | Windows PV drivers | CWE-276 | WinPVDrivers: Excessive permissions on user-exposed devices |
| CVE-2026-0278 | 5.8 | 4.8 | Palo Alto Networks | Prisma Access Agent | CWE-693 | Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows |
| CVE-2026-58304 | 6.1 | 4.5 | Samsung Open Source | Escargot | CWE-125 | Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source … |
| CVE-2026-58305 | 6.1 | 4.5 | Samsung Open Source | Escargot | CWE-843 | Access of resource using incompatible type ('type confusion') vulnerability i… |
| CVE-2026-58307 | 6.1 | 4.5 | Samsung Open Source | Escargot | CWE-125 | Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source … |
| CVE-2026-47830 | 8.5 | 4.2 | Cloud Foundry Foundation | bosh-windows-stemcell-builder | — | Incorrect Permission Assignment Allows Local Privilege Escalation to SYSTEM v… |
| CVE-2026-56459 | 5.5 | 4.2 | HCLSoftware | HCL DevOps Deploy / HCL Launch | CWE-532 | HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclo… |
| CVE-2026-0276 | 1.1 | 3.9 | Palo Alto Networks | Cortex XDR Broker VM | CWE-269 | Cortex XDR Broker VM: Privilege Escalation (PE) Vulnerability |
| CVE-2026-57025 | 6.8 | 3.6 | Juniper Networks | Junos OS | CWE-466 | Junos OS and Junos OS Evolved: EX Series, QFX Series, MX Series: A specific '… |
| CVE-2025-58151 | 9.4 | 3.4 | Xen | varstored | CWE-367 | varstored: TOCTOU issues with mapped guest memory |
| CVE-2026-23556 | 9.4 | 3.3 | Xen | oxenstored | CWE-281 | oxenstored keeps quota related use counts across domain destruction |
| CVE-2026-59858 | 8.4 | 3.3 | vim | vim | CWE-94 | Vim: Arbitrary Code Execution via C Omni-Completion |
| CVE-2026-58198 | 5.5 | 2.3 | gunthercox | ChatterBot | CWE-59 | ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer |
| CVE-2026-33802 | 6.8 | 2.2 | Juniper Networks | Junos OS | CWE-862 | Junos OS: EX Series: Unauthorized users can execute service-impacting CLI com… |
| CVE-2026-59857 | 5.6 | 1.4 | vim | vim | CWE-787 | Vim: Out-of-bounds Write in SAL Soundfolding |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-09 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.