boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Monday, July 13, 2026 · all times UTC← 2026-07-12 · archive · 2026-07-14 →

Security Box Score — July 13, 2026

336 CVEs published, led by openclaw (15).

336 CVEs published July 13, 2026: 49 critical, 147 high, 108 medium, 32 low; 0 in the KEV catalog at press time; 8 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 311 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published279715200——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

682 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux40152012186653211120.17.5.0014-55 ▼
google791344149608549387760.47.8.0024-512 ▼
microsoft54811615551896286202.57.8.0046-153 ▼
red hat392611410312717200.06.5.0031-5 ▼
apple01042287228876.76.5.0032-14 ▼
canonical1212685000.05.5.0011+1 ▲
suse61941140000.08.6.0042+6 ▲
freebsd01601240000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ubiquiti2536142110338.38.8.0049+20 ▲
cisco830614100561136.77.5.0057+5 ▲
palo alto networks1425131471328.04.7.0028+5 ▲
netgear01700161000.04.3.0024-17 ▼
checkpoint0915303111.17.5.0410-3 ▼
fortinet09432028333.38.3.0076-2 ▼
ivanti09450025555.68.8.5187-4 ▼
f50843104112.58.9.02250
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache65220428680113310.57.3.0058-2 ▼
mozilla4601218300900.06.9.0026-1 ▼
drupal465165355412.05.9.0026+46 ▲
gitlab73805276425.34.7.0032-4 ▼
github171150000.06.0.0039+1 ▲
docker070520000.08.2.0016-2 ▼
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle02701321161842720.78.8.0040-2 ▼
adobe514913557921932.06.2.0021-119 ▼
ibm21263842460600.07.5.0034-9 ▼
progress101931420600.07.5.0037+5 ▲
solarwinds07232010457.17.5.4001-3 ▼
veeam042200100.09.0.0052-1 ▼
zohocorp031110000.08.4.01700
servicenow111000200.09.5.7758+1 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology02325133000.05.6.0025-5 ▼
siemens4130760000.07.1.0023-3 ▼
d-link1130535300.06.0.0059-8 ▼
rockwell automation071510000.08.7.00300
abb060420000.07.2.0018-5 ▼
schneider electric060420000.07.8.0042-1 ▼
moxa050320000.07.0.0029-1 ▼
dahua030111000.06.9.0036-3 ▼
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester35106005551000.05.5.0032-1 ▼
dell3389541403211.17.0.0021+26 ▲
capgo2283242381000.07.1.0037+20 ▲
openclaw16830482510000.07.2.0024-18 ▼
spring073231391000.06.5.0024-68 ▼
edimax065039026100.07.4.00800
itsourcecode1164001945000.02.1.0033-11 ▼
themerex26055410000.08.1.0043+2 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-20253.969499.99.8
CVE-2026-20230.882099.88.6
CVE-2026-34910.874799.710.0
CVE-2026-34908.851999.710.0
CVE-2026-48907.781099.510.0
CVE-2026-6875.775899.59.5
CVE-2026-45659.760899.58.8
CVE-2026-34909.639099.210.0
CVE-2026-48282.423998.610.0
CVE-2026-12569.405998.59.3
Highest CVSS
CVECVSSEPSSNote
CVE-2026-3491010.0.8747KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-4890710.0.7810KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-4828210.0.4239KEV
CVE-2026-5629010.0.3038KEV
CVE-2026-4893910.0.1973KEV
CVE-2026-4890810.0.1482KEV
CVE-2026-5629110.0.1459KEV
CVE-2026-5972610.0.0688
Most disclosures (vendor)
VendorCVEs
google578
linux458
oracle240
red hat123
apache119
capgo81
microsoft68
ibm66
dell64
themerex60
Most KEV additions (YTD)
VendorKEV
microsoft20
cisco11
apple7
google6
ivanti5
solarwinds4
adobe3
berriai3
fortinet3
smartertools3
Most-affected ecosystems
EcosystemAdvisories
Maven61
PyPI5
npm5
NuGet3
Fastest to KEV
CVEVendorDays
CVE-2026-12569PTC0
CVE-2026-20230Cisco0
CVE-2026-20253Splunk0
CVE-2026-20262Cisco0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
CVE-2026-34910Ubiquiti Inc0
CVE-2026-45659Microsoft0
CVE-2026-48282Adobe0
CVE-2026-48558SimpleHelp0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171699
CVE-2021-27102n/a2021-11-171699
CVE-2021-27101n/a2021-11-171699
CVE-2021-27103n/a2021-11-171699
CVE-2021-21017Adobe2021-11-171699
CVE-2021-28550Adobe2021-11-171699
CVE-2021-42013Apache Software Foundation2021-11-171699
CVE-2021-41773Apache Software Foundation2021-11-171699
CVE-2021-30858Apple2021-11-171699
CVE-2021-30860Apple2021-11-171699

Transactions

EXPLOIT PUBLISHED — CVE-2026-51536. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-51537. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-51538. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-51540. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-51541. Public exploit reference added.

Yesterday's Results

How to read these box scores · glossary

336 CVEs published. 25 box scores, 311 table rows — nothing truncated.

ServiceNow ServiceNow AI Platform — Sandbox Escape in ServiceNow AI Platform
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   H   H   H    9.5   .7758   99.5     —
AFFECTED
  Product                 Versions     Fixed
  ServiceNow AI Platform  unspecified  —
TIMELINE
  Apr 22  Reserved by CNA
  Jul 13  Published (CNA: SN)
CWE-94 · CNA: SN · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0409   89.9     —
AFFECTED
  Product   Versions  Fixed
  Flamingo  4.12.2 –  —
TIMELINE
  Jul 10  Reserved by CNA
  Jul 13  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Analyzed
decolua 9Router — 9Router 0.4.41 - Unauthenticated API Exposure via /api/providers
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0291   85.9     —
AFFECTED
  Product  Versions     Fixed
  9Router  unspecified  —
TIMELINE
  Jul 7   Reserved by CNA
  Jul 13  Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0234   82.3     —
AFFECTED
  Product   Versions  Fixed
  Flamingo  4.12.2 –  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 13  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Analyzed
Shibby Tomato start_jffs2 sub_2D568 os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0177   76.4     —
AFFECTED
  Product  Versions  Fixed
  Tomato   1.0 –     —
TIMELINE
  Jul 12  Reserved by CNA
  Jul 13  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Shibby Tomato CIFS Mount sub_2D048 os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0177   76.4     —
AFFECTED
  Product  Versions  Fixed
  Tomato   1.0 –     —
TIMELINE
  Jul 12  Reserved by CNA
  Jul 13  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
EVbee DC-80 — Command injection in diagnosis web endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0139   70.2     —
AFFECTED
  Product  Versions     Fixed
  DC-80    unspecified  —
TIMELINE
  Jan 6   Reserved by CNA
  Jul 13  Published (CNA: DIVD)
CWE-77 · CNA: DIVD · CVSS v4.0 · 1 reference · NVD status: Deferred
EVbee DC-80 — Command injection in NPC start web endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0139   70.2     —
AFFECTED
  Product  Versions     Fixed
  DC-80    unspecified  —
TIMELINE
  Jan 6   Reserved by CNA
  Jul 13  Published (CNA: DIVD)
CWE-77 · CNA: DIVD · CVSS v4.0 · 1 reference · NVD status: Deferred
n/a n/a — OpenBMB XAgent v1.0.0 and before is vulnerable to path traversal in the file() function in XAgent/XAgentSer…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0112   63.6     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Feb 16  Reserved by CNA
  Jul 13  Published (CNA: mitre)
CWE-22 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Deferred
EVbee DC-80 — Comnand injection in OCPP ReserveLogin message
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0110   63.1     —
AFFECTED
  Product  Versions     Fixed
  DC-80    unspecified  —
TIMELINE
  Jan 6   Reserved by CNA
  Jul 13  Published (CNA: DIVD)
CWE-78 · CNA: DIVD · CVSS v4.0 · 1 reference · NVD status: Deferred
plank laravel-mediable — Laravel-Mediable < 7.0.0 File Upload RCE via Extension Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   H   H   H    7.7   .0108   62.5     —
AFFECTED
  Product           Versions     Fixed
  laravel-mediable  unspecified  —
TIMELINE
  Jun 2   Reserved by CNA
  Jul 13  Published (CNA: VulnCheck)
CWE-434 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Deferred
plank laravel-mediable — Laravel-Mediable < 7.0.0 Path Traversal via File::sanitizePath()
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0103   61.0     —
AFFECTED
  Product           Versions     Fixed
  laravel-mediable  unspecified  —
TIMELINE
  Jun 2   Reserved by CNA
  Jul 13  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Deferred
4real ThemisNETPanel — Unauthenticated Remote Code Execution in ThemisNETPanel
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0088   56.3     —
AFFECTED
  Product         Versions     Fixed
  ThemisNETPanel  unspecified  —
TIMELINE
  Apr 22  Reserved by CNA
  Jul 13  Published (CNA: CERT-PL)
CWE-306 · CNA: CERT-PL · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
Rejetto HFS < 3.2.1 Session Forgery via Predictable Signing Key
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0086   55.6     —
AFFECTED
  Product  Versions  Fixed
  hfs      3.0.0 –   —
TIMELINE
  Jul 10  Reserved by CNA
  Jul 13  Published (CNA: VulnCheck)
CWE-338 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
Tenda CH22 CertListInfo formCertListInfo buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0085   55.5     —
AFFECTED
  Product  Versions   Fixed
  CH22     1.0.0.1 –  —
TIMELINE
  Jul 12  Reserved by CNA
  Jul 13  Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Centreon Infra Monitoring — A user with low privileges can inject SSTI templates that can lead to RCE in open-tickets
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  N  H    9.6   .0084   55.0     —
AFFECTED
  Product           Versions   Fixed
  Infra Monitoring  24.10.0 –  —
TIMELINE
  Jul 2   Reserved by CNA
  Jul 13  Published (CNA: Centreon)
CWE-94 · CNA: Centreon · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
Shibby Tomato apcupsd tomatodata.cgi getupsvar stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0079   53.5     —
AFFECTED
  Product  Versions  Fixed
  Tomato   1.0 –     —
TIMELINE
  Jul 12  Reserved by CNA
  Jul 13  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Shibby Tomato DNS List Rendering httpd sub_407220 stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0079   53.5     —
AFFECTED
  Product  Versions  Fixed
  Tomato   1.0 –     —
TIMELINE
  Jul 12  Reserved by CNA
  Jul 13  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
openwrt luci-app-banip — luci-app-banip Log Monitor IP Extraction Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0078   53.3     —
AFFECTED
  Product         Versions     Fixed
  luci-app-banip  unspecified  d9bbc372e29618a8807b693a1ccf6d0e42cd196c
TIMELINE
  Jul 13  Reserved by CNA
  Jul 13  Published (CNA: VulnCheck)
CWE-116 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Deferred
n/a n/a — SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to ex…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0077   52.8     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Jun 8   Reserved by CNA
  Jul 13  Published (CNA: mitre)
CWE-89 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Deferred
ChurchCRM: Authenticated Remote Code Execution (RCE) via Malicious Plugin Upload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  H  H    9.1   .0076   52.5     —
AFFECTED
  Product  Versions   Fixed
  CRM      < 7.4.0 –  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 13  Published (CNA: GitHub_M)
CWE-434 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Deferred
WAGO 0765-110x/0100-0000 — Unauthenticated Access to Internal Diagnostic Interface
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0076   52.4     —
AFFECTED
  Product              Versions   Fixed
  0765-110x/0100-0000  1.0.0.0 –  —
  0765-120x/0100-0000  1.0.0.0 –  —
  0765-150x/0100-0000  1.0.0.0 –  —
  0765-2101/0100-0000  1.0.0.0 –  —
  0765-2102/0100-0000  1.0.0.0 –  —
  0765-410x/0100-0000  1.0.0.0 –  —
  0765-420x/0100-0000  1.0.0.0 –  —
  0765-450x/0100-0000  1.0.0.0 –  —
TIMELINE
  Mar 24  Reserved by CNA
  Jul 13  Published (CNA: CERTVDE)
CWE-912 · CNA: CERTVDE · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0074   51.7     —
AFFECTED
  Product                      Versions     Fixed
  Apache Airflow Git provider  unspecified  —
TIMELINE
  Jun 28  Reserved by CNA
  Jul 13  Published (CNA: apache)
CWE-322 · CNA: apache · CVSS v3.1 · 3 references · NVD status: Modified
Shibby Tomato apcupsd tomatodata.cgi main out-of-bounds write
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0073   51.6     —
AFFECTED
  Product  Versions  Fixed
  Tomato   1.0 –     —
TIMELINE
  Jul 12  Reserved by CNA
  Jul 13  Published (CNA: VulDB)
CWE-119, CWE-787 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0072   51.0     —
AFFECTED
  Product  Versions  Fixed
  Ollama   0.7.1 –   —
TIMELINE
  Jul 13  Reserved by CNA
  Jul 13  Published (CNA: zdi)
CWE-129 · CNA: zdi · CVSS v3.0 · 1 reference · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-130149.250.5Thales CERTSuspiciousCWE-22Remote Code Execution vulnerability in "Suspicious" application
CVE-2026-122579.350.2Mura SoftwareCMSCWE-94Remote code execution in Mura Software’s CMS
CVE-2026-155426.950.2will-mossIsaiahCWE-287will-moss Isaiah Websocket Connection Authentication main.go improper authent…
CVE-2026-155575.549.9waooAIwaoowaooCWE-287waooAI waoowaoo Internal Task Header api-auth.ts requireProjectAuthLight impr…
CVE-2026-623279.347.9decolua9RouterCWE-3069Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/stats
CVE-2026-623288.747.2decolua9RouterCWE-3599Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints
CVE-2026-578568.746.3Cockpit HQCockpit CMSCWE-22Cockpit CMS Path Traversal via Bucket Name in Bucket File Storage API
CVE-2026-525339.846.1n/an/aCWE-269An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escal…
CVE-2026-592458.146.0Apache Software FoundationApache Airflow FAB providerCWE-269Apache Airflow FAB provider: FAB auth manager: a DAG named "DAGs" hijacks the…
CVE-2026-410419.145.9Apache Software FoundationApache GravitinoCWE-177Apache Gravitino: URL path injection via unencoded user-supplied identifiers …
CVE-2026-390427.545.2n/an/aCWE-190An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4…
CVE-2026-557718.844.8cedar-policycedar-javaCWE-94CedarJava has policy injection, type confusion, and incorrect equality compar…
CVE-2026-582285.144.8phoenixframeworkphoenix_live_viewCWE-79Scheme validation bypass in Phoenix.LiveView.Utils leads to XSS via <.link>
CVE-2026-5781110.044.3RealtynaRealtyna Organic IDX pluginCWE-94WordPress Realtyna Organic IDX plugin plugin <= 5.2.0 - Remote Code Execution…
CVE-2026-577249.844.3ThemeumKirkiCWE-502WordPress Kirki plugin <= 6.0.12 - PHP Object Injection vulnerability
CVE-2026-577389.844.3axiomthemes777CWE-502WordPress 777 theme <= 1.13.0 - PHP Object Injection vulnerability
CVE-2026-577449.844.3stmcanRT-Theme 18 | ExtensionsCWE-502WordPress RT-Theme 18 | Extensions plugin <= 2.5 - PHP Object Injection vulne…
CVE-2026-577709.844.3ThemeGoodsGrand PhotographyCWE-502WordPress Grand Photography theme <= 5.7.8 - PHP Object Injection vulnerability
CVE-2026-595189.844.3wpWaxDirectoristCWE-502WordPress Directorist plugin <= 8.8.2 - PHP Object Injection vulnerability
CVE-2026-574339.844.0HAARGStorableCWE-190Storable versions before 3.41 for Perl have a signed integer overflow when de…
CVE-2026-577438.143.9stmcanRT-Theme 18 | ExtensionsCWE-98WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Local File Inclusion vulne…
CVE-2026-574019.943.4Brainstorm ForceSureDashCWE-22WordPress SureDash plugin <= 1.8.0 - Arbitrary File Deletion vulnerability
CVE-2026-220969.343.3EVbeeDC-80CWE-306Missing authentication for webserver endpoints
CVE-2026-155416.943.2will-mossIsaiahCWE-862will-moss Isaiah Master Websocket server.go Server.Handle authorization
CVE-2026-595217.243.0ShapedPlugin LLCReal TestimonialsCWE-502WordPress Real Testimonials plugin <= 3.1.15 - PHP Object Injection vulnerabi…
CVE-2026-573898.642.6Adrian TobeyGroundhoggCWE-22WordPress Groundhogg plugin <= 4.4.1 - Arbitrary File Deletion vulnerability
CVE-2026-577098.642.6WP SwingsMembership For WooCommerceCWE-22WordPress Membership For WooCommerce plugin <= 3.1.0 - Arbitrary File Deletio…
CVE-2026-155305.542.5n/aWuzhiCMSCWE-200WuzhiCMS Attachment API index.php listimage information disclosure
CVE-2026-221029.342.5EVbeeDC-80CWE-20Arbitrary file overwrite through certificate update functionality
CVE-2026-621998.742.1OpenClawOpenClawCWE-184OpenClaw < 2026.6.6 Authentication Bypass via Environment Filtering
CVE-2026-622008.742.1OpenClawOpenClawCWE-184OpenClaw < 2026.6.6 Authentication Bypass via Git ext transport
CVE-2026-578558.742.0Cockpit HQCockpit CMSCWE-284Cockpit CMS Missing Authorization in Bucket File Storage API
CVE-2026-614638.742.0go-shiorishioriCWE-269Shiori Authenticated Privilege Escalation via PATCH /api/v1/auth/account
CVE-2026-5771910.041.9CodeRevolutionAimogen ProCWE-434WordPress Aimogen Pro plugin <= 2.8.3 - Arbitrary File Upload vulnerability
CVE-2026-615056.941.9rejettohfsCWE-22Rejetto HFS < 3.2.1 Limited File Disclosure via Path Traversal in lang Parameter
CVE-2026-622408.341.8crewAIInccrewAICWE-918CrewAI < 1.15.1 SSRF Filter Bypass via HTTP Redirect in Scrape Tools
CVE-2026-557738.841.7cedar-policycedar-javaCWE-94CedarJava has a policy injection vulnerability
CVE-2026-573718.841.7denishuaWPJAM BasicCWE-502WordPress WPJAM Basic plugin <= 7.0 - PHP Object Injection vulnerability
CVE-2026-577887.541.2Edge-ThemesAaltoCWE-98WordPress Aalto theme <= 1.8 - Local File Inclusion vulnerability
CVE-2026-577897.541.2jwsthemesAquaCWE-98WordPress Aqua theme <= 5.1.2 - Local File Inclusion vulnerability
CVE-2026-577907.541.2ThemeMoveBilleyCWE-98WordPress Billey theme <= 2.1.8 - Local File Inclusion vulnerability
CVE-2026-577917.541.2ThemeMoveBrookCWE-98WordPress Brook theme <= 2.9.0 - Local File Inclusion vulnerability
CVE-2026-577927.541.2Mikado-ThemesDørCWE-98WordPress Dør theme <= 2.4.1 - Local File Inclusion vulnerability
CVE-2026-577937.541.2Elated-ThemesFlowCWE-98WordPress Flow theme <= 1.8 - Local File Inclusion vulnerability
CVE-2026-577947.541.2uxperGolo FrameworkCWE-98WordPress Golo Framework plugin <= 1.7.3 - Local File Inclusion vulnerability
CVE-2026-577957.541.2themelexusKitchorCWE-98WordPress Kitchor theme <= 1.4.3 - Local File Inclusion vulnerability
CVE-2026-577967.541.2VLThemesLeedoCWE-98WordPress Leedo theme <= 3.0.0 - Local File Inclusion vulnerability
CVE-2026-577987.541.2SaurabhSharmaNewsPlus ShortcodesCWE-98WordPress NewsPlus Shortcodes plugin <= 4.2.0 - Local File Inclusion vulnerab…
CVE-2026-577997.541.2uxperNussCWE-98WordPress Nuss theme <= 1.3.6 - Local File Inclusion vulnerability
CVE-2026-578007.541.2Edge-ThemesOverworldCWE-98WordPress Overworld theme <= 1.5 - Local File Inclusion vulnerability
CVE-2026-578017.541.2Select-ThemesSetSailCWE-98WordPress SetSail theme <= 2.1 - Local File Inclusion vulnerability
CVE-2026-578027.541.2Select-ThemesStrukturCWE-98WordPress Struktur theme < 2.7 - Local File Inclusion vulnerability
CVE-2026-578037.541.2Select-ThemesStruktur CoreCWE-98WordPress Struktur Core plugin < 2.7 - Local File Inclusion vulnerability
CVE-2026-578047.541.2CodexThemesTheGem Theme Elements (for Elementor)CWE-98WordPress TheGem Theme Elements (for Elementor) plugin < 5.12.1.1 - Local Fil…
CVE-2026-578057.541.2Select-ThemesTondaCWE-98WordPress Tonda theme <= 2.5 - Local File Inclusion vulnerability
CVE-2026-614629.241.1zereightmcp-gitlabCWE-73mcp-gitlab Path Traversal via job_id Parameter
CVE-2026-621908.741.1OpenClawOpenClawCWE-706OpenClaw < 2026.6.9 Authorization Bypass via flock wrapper
CVE-2026-578157.540.7WPMU DEV - Your All-in-One WordPress PlatformForminatorCWE-22WordPress Forminator plugin <= 1.55.0.2 - Arbitrary File Download vulnerability
CVE-2026-515369.140.0n/an/aCWE-190In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial…
CVE-2026-498766.540.0Apache Software FoundationApache GravitinoCWE-918Apache Gravitino: Authenticated SSRF in Gravitino JobManager allows server-si…
CVE-2026-584875.140.0hedgedochedgedocCWE-79HedgeDoc: Stored HTML injection via email local-part
CVE-2026-515397.539.8n/an/aCWE-400A Denial of Service (DoS) vulnerability exists in the receive loop of libmodb…
CVE-2026-578139.839.4properfractionMailOptinCWE-266WordPress MailOptin plugin <= 1.2.77.3 - Privilege Escalation vulnerability
CVE-2026-622427.739.4codecentricspring-boot-adminCWE-918Spring Boot Admin Server < 4.1.2 SSRF via Unauthenticated Instance Registration
CVE-2026-515379.139.2n/an/aCWE-125EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue i…
CVE-2026-577109.939.2quantumcloudWoowBot Pro MaxCWE-434WordPress WoowBot Pro Max plugin <= 14.1.7 - Arbitrary File Upload vulnerability
CVE-2026-557728.839.2cedar-policycedar-javaCWE-843CedarJava has a type confusion vulnerability
CVE-2026-576977.539.0MetagaussProfileGridCWE-288WordPress ProfileGrid plugin <= 5.9.9.6 - Broken Authentication vulnerability
CVE-2026-155952.138.6SourceCodesterClass and Exam Timetabling SystemCWE-79SourceCodester Class and Exam Timetabling System forsubject.php cross site sc…
CVE-2026-155962.138.6SourceCodesterClass and Exam Timetabling SystemCWE-79SourceCodester Class and Exam Timetabling System subject.php cross site scrip…
CVE-2026-155942.938.1waooAIwaoowaooCWE-266waooAI waoowaoo Media hash.ts stablePublicIdFromStorageKey improper authoriza…
CVE-2026-577138.838.0Marcus (aka @msykes)Events ManagerCWE-502WordPress Events Manager plugin <= 7.3.6 - PHP Object Injection vulnerability
CVE-2026-621858.637.9argoprojargo-helmCWE-1188Argo CD Helm Chart < 10.0.0 Missing Network Policy RCE
CVE-2026-119649.137.5UnknownUser Registration & Membership—User Registration & Membership < 5.2.2 - Unauthenticated PayPal Webhook Signa…
CVE-2026-621948.737.0OpenClawOpenClawCWE-732OpenClaw 2026.5.20 < 2026.6.9 Privilege Escalation via Plugin Install
CVE-2026-155385.337.0primefacesprimereactCWE-94primefaces primereact API ObjectUtils.mutateFieldData prototype pollution
CVE-2026-125828.636.9UnknownLibrary Management System—Library Management System < 3.5.8 - Unauthenticated SQL Injection via book_id
CVE-2026-155295.336.5yzhao062pyodCWE-20yzhao062 pyod persistence.py pyod.utils.persistence.load deserialization
CVE-2026-155162.936.5n/aMacCMS ProCWE-285MacCMS Pro Installation Index.php step5 authorization
CVE-2026-155747.536.4Red HatRed Hat OpenShift AI (RHOAI)CWE-538Vllm-orchestrator-gateway: vllm-orchestrator-gateway: authorization header an…
CVE-2026-578308.836.2joomshaper.comHelix Ultimate extension for JoomlaCWE-862Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion i…
CVE-2026-156072.136.3tanstackdbCWE-94tanstack db Alias Path select.ts select prototype pollution
CVE-2026-584117.036.2ChurchCRMCRMCWE-79ChurchCRM has Reflected Cross-Site Scripting (XSS) via unsanitized request pa…
CVE-2026-615036.936.2rejettohfsCWE-204Rejetto HFS < 3.2.1 Username Enumeration via Login Response Differences
CVE-2026-47655.136.2RD Station ConversasTallos ChatCWE-79Stored Cross-Site Scripting (XSS) in Tallos Chat by RD Station Conversas
CVE-2026-155332.035.9n/aDedeCMSCWE-74DedeCMS Column Management search.php code injection
CVE-2026-132219.135.8SHAYperlCWE-190Perl versions through 5.43.9 produce silently incorrect regular expression ma…
CVE-2026-155375.535.7SourceCodesterOnline Book Store SystemCWE-74SourceCodester Online Book Store System login.php sql injection
CVE-2026-155975.535.7SourceCodesterClass and Exam Timetabling SystemCWE-74SourceCodester Class and Exam Timetabling System edit_exam2.php sql injection
CVE-2026-155352.135.6AkariAsaiself-ragCWE-20AkariAsai self-rag retrieval_lm index.py Indexer.deserialize_from deserializa…
CVE-2026-220989.235.4EVbeeDC-80CWE-532Sensitive information is written to logs
CVE-2026-148464.535.1PrestaShopThe firmwareCWE-1236Incorrect neutralisation in the PrestaShop firmware
CVE-2026-155985.335.1antvlayoutCWE-94antv layout object.js setNestedValue prototype pollution
CVE-2026-515409.834.8n/an/aCWE-191OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe m…
CVE-2026-515419.134.8n/an/aCWE-125OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message …
CVE-2026-68506.534.8MattermostMattermostCWE-1333Crafted message attachment causes client-side denial of service via markdown …
CVE-2026-155402.134.8SourceCodesterOnline Book Store SystemCWE-73SourceCodester Online Book Store System Administrative index.php php file inc…
CVE-2026-615015.334.6rejettohfsCWE-79Rejetto HFS < 3.2.1 Stored XSS in Admin Log Viewer
CVE-2026-141657.534.5Dassault SystèmesTuleap Enterprise EditionCWE-639Authorization Bypass Through User-Controlled Key vulnerability affecting Tule…
CVE-2026-499695.334.6planklaravel-mediableCWE-918Laravel-Mediable < 7.0.0 SSRF via RemoteUrlAdapter URL Handling
CVE-2026-156182.134.6mosaxivclawletCWE-693mosaxiv clawlet exec Safety Guard tool_exec.go guardExecCommand protection me…
CVE-2026-573868.834.5Kodezen LLCaBlocksCWE-266WordPress aBlocks plugin < 2.9.1 - Privilege Escalation vulnerability
CVE-2026-574108.834.5MailerPress TeamMailerPressCWE-266WordPress MailerPress plugin <= 2.0.2 - Privilege Escalation vulnerability
CVE-2026-155847.534.4Red HatPen Drive Powered by Red Hat LightspeedCWE-250Redhatinsights/incluster-checks: incluster-checks: privileged host-chroot deb…
CVE-2026-621927.234.3OpenClawOpenClawCWE-863OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass
CVE-2026-577745.334.2vowelwebVW Food CornerCWE-862WordPress VW Food Corner theme <= 1.1.0 - Broken Access Control vulnerability
CVE-2026-577765.334.2vowelwebVW WeddingCWE-862WordPress VW Wedding theme <= 1.3.7 - Broken Access Control vulnerability
CVE-2026-123854.334.0nextendwebSmart Slider 3CWE-200Smart Slider 3 <= 3.5.1.37 - Missing Authorization to Authenticated (Contribu…
CVE-2026-155175.533.9JinherOACWE-74Jinher OA PlanGiveOut.aspx sql injection
CVE-2026-155536.933.8RagicEnterprise Cloud DatabaseCWE-434Ragic|Enterprise Cloud Database - Arbitrary File Upload
CVE-2026-614588.733.7pglombardoPasswordPusherCWE-307PasswordPusher < 2.9.2 Passphrase Brute-Force via Unthrottled Endpoint
CVE-2026-156807.533.7Lorex2K Indoor Wi-Fi Security CameraCWE-134Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Co…
CVE-2026-584886.933.4hedgedochedgedocCWE-290HedgeDoc: Rate-limit bypass via CF-Connecting-IP header spoofing
CVE-2026-621438.333.3mispmisp-modulesCWE-918Server-Side Request Forgery protection bypass in misp-modules html_to_markdow…
CVE-2026-577029.332.9Melograno Venture StudioAmeliaCWE-89WordPress Amelia plugin <= 2.4.2 - SQL Injection vulnerability
CVE-2026-577079.332.9quantumcloudSimple Business Directory ProCWE-89WordPress Simple Business Directory Pro plugin <= 15.9.4 - SQL Injection vuln…
CVE-2026-577149.332.9LatePointLatePointCWE-89WordPress LatePoint plugin <= 5.6.3 - SQL Injection vulnerability
CVE-2026-577269.332.9ThemeumKirkiCWE-89WordPress Kirki plugin <= 6.0.12 - SQL Injection vulnerability
CVE-2026-577399.332.9AcyMailing Newsletter TeamAcyMailing SMTP NewsletterCWE-89WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - SQL Injection vulner…
CVE-2026-595159.332.9SergeyAIWUCWE-89WordPress AIWU plugin <= 1.5.4 - SQL Injection vulnerability
CVE-2026-584868.332.5hedgedochedgedocCWE-400HedgeDoc: Denial-of-service via YAML alias expansion in note frontmatter
CVE-2026-621958.732.4OpenClawOpenClawCWE-732OpenClaw 2026.5.20 < 2026.6.6 Authorization Bypass via MCP loopback
CVE-2026-621968.732.4OpenClawOpenClawCWE-863OpenClaw 2026.3.22 < 2026.6.6 Authorization Bypass via WhatsApp Group IDs
CVE-2026-155392.032.5SourceCodesterOnline Book Store SystemCWE-284SourceCodester Online Book Store System Book Image Upload Feature index.php b…
CVE-2026-577277.532.2ThemeumKirkiCWE-862WordPress Kirki plugin <= 6.0.13 - Broken Access Control vulnerability
CVE-2026-577297.532.2UX-themesFlatsomeCWE-862WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability
CVE-2026-568776.332.1SkillableSCORM Lab Launch IntegrationCWE-472The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026…
CVE-2026-515389.131.6n/an/aCWE-284EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access …
CVE-2026-585008.231.5appiumappium-mcpCWE-79MCP Appium: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGener…
CVE-2026-577737.631.1ZoremAdvanced Shipment Tracking for WooCommerceCWE-89WordPress Advanced Shipment Tracking for WooCommerce plugin <= 4.0 - SQL Inje…
CVE-2026-619557.631.0Hannanگرویتی فرم فارسیCWE-89WordPress گرویتی فرم فارسی plugin <= 3.0.2 - SQL Injection vulnerability
CVE-2026-155182.030.4AREA 17Twill CMSCWE-284AREA 17 Twill CMS Media Library Insert FileLibraryController.php storeFile un…
CVE-2026-621897.630.3OpenClawOpenClawCWE-59OpenClaw < 2026.6.9 Symlink Following via Mirror Sync
CVE-2026-155252.130.2kLOskadloopCWE-918kLOsk adloop write.py _validate_urls server-side request forgery
CVE-2026-573936.529.8EDGARROJASWooCommerce PDF Invoice BuilderCWE-497WordPress WooCommerce PDF Invoice Builder plugin <= 2.0.8 - Sensitive Data Ex…
CVE-2026-155321.929.5SourceCodesterOnline Book Store SystemCWE-79SourceCodester Online Book Store System User Management cross site scripting
CVE-2026-621878.629.4openclawfeishuCWE-863OpenClaw < 2026.6.9 Feishu tools Authorization Bypass
CVE-2026-621888.629.4openclawfeishuCWE-863OpenClaw < 2026.6.9 Feishu Authorization Bypass
CVE-2026-621917.129.1OpenClawOpenClawCWE-862OpenClaw 2026.6.6 < 2026.6.9 Authorization Bypass via Message Mutations
CVE-2026-584086.528.8ChurchCRMCRMCWE-862ChurchCRM : Broken Access Control in `CSVCreateFile.php` Allows Low-Privilege…
CVE-2026-97084.928.7MattermostMattermostCWE-639Incoming webhook user attribution via unvalidated webhook owner
CVE-2026-499715.328.6planklaravel-mediableCWE-79Laravel-Mediable < 7.0.0 Stored XSS via SVG File Upload
CVE-2026-573858.528.4appsbdViteposCWE-89WordPress Vitepos plugin <= 3.4.2 - SQL Injection vulnerability
CVE-2026-577718.528.4Milan PetrovicGD Rating SystemCWE-89WordPress GD Rating System plugin <= 3.7 - SQL Injection vulnerability
CVE-2026-577728.528.4WP InventoryWP Inventory ManagerCWE-89WordPress WP Inventory Manager plugin <= 2.4.0 - SQL Injection vulnerability
CVE-2026-577878.528.4CreativeWSCWS SVGiconsCWE-89WordPress CWS SVGicons plugin <= 1.5.5 - SQL Injection vulnerability
CVE-2026-578108.528.4Saad IqbalAPIExperts Square for WooCommerceCWE-89WordPress APIExperts Square for WooCommerce plugin <= 4.7.4 - SQL Injection v…
CVE-2026-576986.528.2VillaThemeAbandoned Cart Recovery for WooCommerceCWE-288WordPress Abandoned Cart Recovery for WooCommerce plugin <= 1.1.12 - Broken A…
CVE-2026-621476.528.0Red HatRed Hat OpenShift distributed tracing 3CWE-863Tempo-operator: tempo operator: query rbac bypass
CVE-2026-404695.127.9GNUgawkCWE-190Heap buffer overflow in gawk
CVE-2026-149349.427.7Google CloudBigQueryCWE-862Cross-Tenant Repository Takeover via Improper Access Control in BigQuery, Dat…
CVE-2026-573646.527.7WPDeveloperBetter Payment – Instant Payments, Donations, Fundraising with Subscriptions &amp; MoreCWE-1284WordPress Better Payment – Instant Payments, Donations, Fundraising with Subs…
CVE-2026-119638.127.6UnknownUser Registration & Membership—User Registration & Membership < 5.2.2 - Subscriber+ Cross-User Role and Memb…
CVE-2026-573787.527.2Phil KurthAdvanced FormsCWE-862WordPress Advanced Forms plugin <= 1.9.3.7 - Broken Access Control vulnerability
CVE-2026-577057.527.2NexcessEvent TicketsCWE-862WordPress Event Tickets plugin <= 5.28.5 - Broken Access Control vulnerability
CVE-2026-155191.327.1usestrixstrixCWE-829usestrix PyPI system_prompt.jinja inclusion of functionality from untrusted c…
CVE-2026-581029.126.6JONASBNCrypt::OpenSSL::X509CWE-125Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bound…
CVE-2026-155525.326.6RagicEnterprise Cloud DatabaseCWE-79Ragic|Enterprise Cloud Database - Stored Cross-Site Scripting
CVE-2026-573956.526.5ThemeficTourficCWE-862WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability
CVE-2026-574186.526.5BoldGridClient Invoicing by Sprout InvoicesCWE-862WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.13 - Broken Acce…
CVE-2025-458697.326.3n/an/aCWE-918LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server…
CVE-2026-576946.525.9ThemeumTutor LMSCWE-639WordPress Tutor LMS plugin <= 3.9.13 - Insecure Direct Object References (IDO…
CVE-2026-220979.325.8EVbeeDC-80CWE-347Missing firmware validation allows remote code execution
CVE-2026-621976.325.8OpenClawOpenClawCWE-918OpenClaw < 2026.6.6 Policy Bypass via CDP Discovery
CVE-2026-155232.125.7CodeAstroSimple Online Leave Management SystemCWE-74CodeAstro Simple Online Leave Management System dashboard.php sql injection
CVE-2026-155362.125.7itsourcecodeHospital Management SystemCWE-74itsourcecode Hospital Management System patviewprescription.php sql injection
CVE-2026-155582.125.7CodeAstroSimple Online Leave Management SystemCWE-74CodeAstro Simple Online Leave Management System deletemp.php sql injection
CVE-2026-155592.125.7CodeAstroSimple Online Leave Management SystemCWE-74CodeAstro Simple Online Leave Management System POST accept.php sql injection
CVE-2026-573776.525.6WPXPOWowAddonsCWE-862WordPress WowAddons plugin <= 1.6.8 - Broken Access Control vulnerability
CVE-2026-573906.525.6EDGARROJASExtra Product Options Builder for WooCommerceCWE-862WordPress Extra Product Options Builder for WooCommerce plugin <= 1.2.167 - B…
CVE-2026-573926.525.6ThemeficTourficCWE-862WordPress Tourfic plugin <= 2.22.5 - Broken Access Control vulnerability
CVE-2026-574006.525.6WP SwingsEvent Tickets Manager for WooCommerceCWE-862WordPress Event Tickets Manager for WooCommerce plugin <= 1.5.5 - Broken Acce…
CVE-2026-574046.525.6magepeopleteamBooking and Rental ManagerCWE-862WordPress Booking and Rental Manager plugin <= 2.6.9 - Broken Access Control …
CVE-2026-574066.525.6RoxnorFundEngineCWE-862WordPress FundEngine plugin <= 1.7.6 - Broken Access Control vulnerability
CVE-2026-574086.525.6peachpaymentsPeach Payments GatewayCWE-862WordPress Peach Payments Gateway plugin <= 4.0.2 - Broken Access Control vuln…
CVE-2026-574126.525.6CodemenschenGift VouchersCWE-862WordPress Gift Vouchers plugin <= 4.6.9 - Broken Access Control vulnerability
CVE-2026-574246.525.6knitpayRazorpay Payment Links for WooCommerceCWE-862WordPress Razorpay Payment Links for WooCommerce plugin <= 2.1.4 - Broken Acc…
CVE-2026-578126.525.6NSquaredSimply Schedule AppointmentsCWE-862WordPress Simply Schedule Appointments plugin <= 1.6.12.4 - Broken Access Con…
CVE-2026-619524.925.5Jose VegaWooCommerce Bulk Edit Products – WP Sheet EditorCWE-862WordPress WooCommerce Bulk Edit Products – WP Sheet Editor plugin <= 1.8.21 -…
CVE-2026-619755.325.3CrocoblockJetReviewsCWE-497WordPress JetReviews plugin <= 3.0.1 - Sensitive Data Exposure vulnerability
CVE-2026-619765.325.3CrocoblockJetBlocks For ElementorCWE-497WordPress JetBlocks For Elementor plugin <= 1.5.0 - Sensitive Data Exposure v…
CVE-2026-619775.325.3CrocoblockJetSearchCWE-497WordPress JetSearch plugin <= 3.6.1.2 - Sensitive Data Exposure vulnerability
CVE-2026-577974.325.3ThemeMoveEduMallCWE-862WordPress EduMall theme <= 4.5.1 - Broken Access Control vulnerability
CVE-2026-621867.225.1OpenClawOpenClawCWE-862OpenClaw < 2026.6.8 Authorization Bypass via HTTP Model Override
CVE-2026-155311.924.6yashbhalgatHashNeRF-pytorchCWE-20yashbhalgat HashNeRF-pytorch Checkpoint File run_nerf.py torch.load deseriali…
CVE-2026-577688.224.3favethemesHouzez Login RegisterCWE-266WordPress Houzez Login Register plugin <= 3.3.3 - Privilege Escalation vulner…
CVE-2026-574057.124.3themehunkOpen ShopCWE-862WordPress Open Shop theme <= 1.7.1 - Broken Access Control vulnerability
CVE-2026-577407.124.3AcyMailing Newsletter TeamAcyMailing SMTP NewsletterCWE-862WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Broken Access Contro…
CVE-2026-621936.924.1OpenClawOpenClawCWE-863OpenClaw 2026.6.5 < 2026.6.9 Authentication Bypass via Plugin Install
CVE-2026-619712.723.6CozmoslabsUser Profile PictureCWE-639WordPress User Profile Picture plugin <= 2.6.3 - Insecure Direct Object Refer…
CVE-2026-581017.523.0JONASBNCrypt::OpenSSL::X509CWE-476Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service v…
CVE-2026-95716.522.4MattermostMattermostCWE-305Deactivated user accounts can continue to obtain valid OAuth access tokens vi…
CVE-2026-220998.722.1EVbeeDC-80CWE-287Missing authentication for Bluetooth communication
CVE-2026-101066.521.9MattermostMattermostCWE-863Unauthorized users can trigger interactive post actions in private channels v…
CVE-2026-122746.521.9UnknownTutor LMS—Tutor LMS < 3.9.13 - Instructor+ Arbitrary Post Overwrite via IDOR
CVE-2026-574196.521.9Fahad MahmoodStock Locations for WooCommerceCWE-862WordPress Stock Locations for WooCommerce plugin <= 3.1.8 - Broken Access Con…
CVE-2026-577785.321.4wpdevartBooking calendar, Appointment Booking SystemCWE-862WordPress Booking calendar, Appointment Booking System plugin <= 3.2.36 - Bro…
CVE-2026-577795.321.4themebeezFascinateCWE-862WordPress Fascinate theme <= 1.1.5 - Broken Access Control vulnerability
CVE-2026-577815.321.4SovlixMeetingHubCWE-862WordPress MeetingHub plugin <= 1.25.10 - Broken Access Control vulnerability
CVE-2026-577825.321.4PressTigersUniversal ClocksCWE-862WordPress Universal Clocks plugin <= 1.2.0 - Broken Access Control vulnerability
CVE-2026-619835.321.4andy_moyleChurch AdminCWE-862WordPress Church Admin plugin <= 5.0.30 - Broken Access Control vulnerability
CVE-2026-619855.321.4magepeopleteamCar Rental ManagerCWE-862WordPress Car Rental Manager plugin <= 1.3.7 - Broken Access Control vulnerab…
CVE-2026-149065.321.0MozillaFirefox for iOSCWE-434Malicious webpage titles could allow overwriting of bundled PDF resources whe…
CVE-2026-405535.121.0GNUgawkCWE-121Stack-based buffer overflow in gawk
CVE-2026-122757.120.9UnknownTutor LMS—Tutor LMS < 3.9.13 - Subscriber+ Unauthorized Course Enrollment and Private C…
CVE-2026-584107.120.9ChurchCRMCRMCWE-639ChurchCRM: Improper object-level authorization allows low-privileged users to…
CVE-2026-100855.420.7MattermostMattermostCWE-862Ordinary group/direct message member can enable group_constrained and remove …
CVE-2026-122715.420.7UnknownTutor LMS—Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Quiz Attempt Modification via IDOR
CVE-2026-123965.420.7UnknownWP Job Portal—WP Job Portal < 2.5.5 - Subscriber+ Arbitrary Job Approval, Featuring and Rej…
CVE-2026-619585.420.7Saad IqbalLicense Manager for WooCommerceCWE-862WordPress License Manager for WooCommerce plugin <= 3.0.17 - Arbitrary Conten…
CVE-2026-619685.420.7Saad IqbalmyCredCWE-862WordPress myCred plugin <= 3.1.2 - Broken Access Control vulnerability
CVE-2026-122734.320.3UnknownTutor LMS—Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Auto-Approved Comment Creation
CVE-2026-621985.318.8OpenClawOpenClawCWE-863OpenClaw 2026.5.28 < 2026.6.6 Authorization Bypass via Web Search
CVE-2026-98244.318.7MattermostMattermostCWE-862Remote cluster metadata enumeration via /share-channel autocomplete
CVE-2026-123974.318.7UnknownWP Job Portal—WP Job Portal < 2.5.5 - Subscriber+ Employer Email Disclosure via IDOR
CVE-2026-483638.218.5AdobeColdFusionCWE-427ColdFusion | Uncontrolled Search Path Element (CWE-427)
CVE-2026-483648.218.5AdobeColdFusionCWE-427ColdFusion | Uncontrolled Search Path Element (CWE-427)
CVE-2026-573727.218.1denishuaWPJAM BasicCWE-918WordPress WPJAM Basic plugin <= 7.0 - Server Side Request Forgery (SSRF) vuln…
CVE-2026-574077.218.1WP SwingsPDF Generator for WordPressCWE-918WordPress PDF Generator for WordPress plugin <= 1.6.2 - Server Side Request F…
CVE-2026-573756.518.1FluxBuilderMStore APICWE-862WordPress MStore API plugin <= 4.18.4 - Broken Access Control vulnerability
CVE-2026-595236.518.1NSquaredSimply Schedule AppointmentsCWE-862WordPress Simply Schedule Appointments plugin <= 1.6.11.11 - Broken Access Co…
CVE-2026-220939.517.5EVbeeEVbee ServiceCWE-295Adversary-in-the-Middle (AitM) attack vulnerability in EVbee Service app
CVE-2026-125366.417.4themefusionAvada (Fusion) BuilderCWE-79Avada Builder <= 3.15.5 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-98203.816.7MattermostMattermostCWE-862Mattermost schemes teams endpoint exposes private team invite IDs
CVE-2026-65414.316.6MattermostMattermostCWE-639Unscoped updates to other playbooks' metric configuration
CVE-2026-578298.716.4joomshaper.comHelix Ultimate extension for JoomlaCWE-79Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultim…
CVE-2026-105516.116.4UnknownBreeze Cache—Breeze Cache < 2.5.6 - Unauthenticated Stored XSS via Minify Library
CVE-2026-573637.116.3QuantumCloudChatBotCWE-79WordPress ChatBot plugin <= 8.3.7 - Cross Site Scripting (XSS) vulnerability
CVE-2026-573687.116.3NooThemeJobmonsterCWE-79WordPress Jobmonster theme <= 4.8.5 - Reflected Cross Site Scripting (XSS) vu…
CVE-2026-573697.116.3themifymeThemify BuilderCWE-79WordPress Themify Builder plugin <= 7.7.4 - Cross Site Scripting (XSS) vulner…
CVE-2026-573767.116.3Element InvaderElementInvader Addons for ElementorCWE-79WordPress ElementInvader Addons for Elementor plugin <= 1.4.3 - Cross Site Sc…
CVE-2026-573797.116.3WPPOOLFormyChatCWE-79WordPress FormyChat plugin <= 2.15.3 - Cross Site Scripting (XSS) vulnerability
CVE-2026-573807.116.3hupe13Extensions for Leaflet MapCWE-79WordPress Extensions for Leaflet Map plugin <= 5.1 - Cross Site Scripting (XS…
CVE-2026-573817.116.3Property HivePropertyHiveCWE-79WordPress PropertyHive plugin <= 2.2.3 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-573827.116.3Mitchell BennisSimple File ListCWE-79WordPress Simple File List plugin <= 6.3.8 - Reflected Cross Site Scripting (…
CVE-2026-573837.116.3eyecixJobSearchCWE-79WordPress JobSearch plugin <= 3.2.9 - Cross Site Scripting (XSS) vulnerability
CVE-2026-573877.116.3picupicuCWE-79WordPress picu plugin <= 3.5.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-573887.116.3ThemeficHydra BookingCWE-79WordPress Hydra Booking plugin <= 1.1.44 - Cross Site Scripting (XSS) vulnera…
CVE-2026-573947.116.3Tribulant SoftwareNewslettersCWE-79WordPress Newsletters plugin <= 4.14 - Cross Site Scripting (XSS) vulnerability
CVE-2026-573967.116.3FlintopFree Gifts for WooCommerceCWE-79WordPress Free Gifts for WooCommerce plugin <= 13.1.0 - Cross Site Scripting …
CVE-2026-573987.116.3WebCodingPlaceReal Estate Manager ProCWE-79WordPress Real Estate Manager Pro plugin <= 12.8.3 - Cross Site Scripting (XS…
CVE-2026-573997.116.3Proxy &amp; VPN BlockerProxy &amp; VPN BlockerCWE-79WordPress Proxy & VPN Blocker plugin <= 3.5.8 - Cross Site Scripting (XSS) vu…
CVE-2026-574037.116.3Milan PetrovicGD Security HeadersCWE-79WordPress GD Security Headers plugin <= 1.8 - Cross Site Scripting (XSS) vuln…
CVE-2026-574097.116.3RealMag777Active Products Tables for WooCommerceCWE-79WordPress Active Products Tables for WooCommerce plugin <= 1.1.0 - Cross Site…
CVE-2026-574117.116.3AmanCF7 Views &#8211; Complete Entry Management for Contact Form 7CWE-79WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin <= …
CVE-2026-574157.116.2CodemenschenGift VouchersCWE-79WordPress Gift Vouchers plugin <= 4.7.0 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-574167.116.2SiteGroundSiteGround Email MarketingCWE-79WordPress SiteGround Email Marketing plugin <= 1.7.5 - Cross Site Scripting (…
CVE-2026-574177.116.2RexThemeCart LiftCWE-79WordPress Cart Lift plugin <= 3.1.57 - Cross Site Scripting (XSS) vulnerability
CVE-2026-574217.116.2CRM PerksCRM Perks FormsCWE-79WordPress CRM Perks Forms plugin <= 1.1.7 - Cross Site Scripting (XSS) vulner…
CVE-2026-574227.116.2VillaThemeBopo – WooCommerce Product Bundle BuilderCWE-79WordPress Bopo – WooCommerce Product Bundle Builder plugin <= 1.2.0 - Reflect…
CVE-2026-574237.116.2Kofi MokomeMessage Filter for Contact Form 7CWE-79WordPress Message Filter for Contact Form 7 plugin <= 1.6.3.8 - Reflected Cro…
CVE-2026-576687.116.3BasixNEX-FormsCWE-79WordPress NEX-Forms plugin <= 9.2.2 - Cross Site Scripting (XSS) vulnerability
CVE-2026-576957.116.3Dan RossiterDocument GalleryCWE-79WordPress Document Gallery plugin <= 5.1.0 - Cross Site Scripting (XSS) vulne…
CVE-2026-577067.116.3Dokan, Inc.DokanCWE-79WordPress Dokan plugin <= 5.0.6 - Cross Site Scripting (XSS) vulnerability
CVE-2026-577087.116.3CRM PerksContact Form EntriesCWE-79WordPress Contact Form Entries plugin <= 1.5.2 - Cross Site Scripting (XSS) v…
CVE-2026-577127.116.3WPZOOMWPZOOM PortfolioCWE-79WordPress WPZOOM Portfolio plugin <= 1.4.29 - Cross Site Scripting (XSS) vuln…
CVE-2026-577157.116.3WPManageNinjaFluent CRMCWE-79WordPress Fluent CRM plugin <= 3.1.7 - Cross Site Scripting (XSS) vulnerability
CVE-2026-577187.116.3Unlimited ElementsUnlimited Elements For Elementor (Free Widgets, Addons, Templates)CWE-79WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) …
CVE-2026-577257.116.3ThemeumKirkiCWE-79WordPress Kirki plugin <= 6.0.11 - Cross Site Scripting (XSS) vulnerability
CVE-2026-577287.116.3UX-themesFlatsomeCWE-79WordPress Flatsome theme <= 3.20.5 - Reflected Cross Site Scripting (XSS) vul…
CVE-2026-577327.116.3tagDivtagDiv Opt-In BuilderCWE-79WordPress tagDiv Opt-In Builder plugin <= 1.7.4 - Cross Site Scripting (XSS) …
CVE-2026-577337.116.3tagDivtagDiv Cloud LibraryCWE-79WordPress tagDiv Cloud Library plugin <= 3.9.4 - Cross Site Scripting (XSS) v…
CVE-2026-577347.116.3tagDivtagDiv ComposerCWE-79WordPress tagDiv Composer plugin <= 5.4.3 - Reflected Cross Site Scripting (X…
CVE-2026-577417.116.3AcyMailing Newsletter TeamAcyMailing SMTP NewsletterCWE-79WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - Cross Site Scripting…
CVE-2026-577457.116.3stmcanRT-Theme 18 | ExtensionsCWE-79WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Reflected Cross Site Scrip…
CVE-2026-578147.116.3WPMU DEV - Your All-in-One WordPress PlatformForminatorCWE-79WordPress Forminator plugin <= 1.55.0.1 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-578167.116.2FunnelKitFunnel Builder by FunnelKitCWE-79WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.8 - Cross Site Scripti…
CVE-2026-595167.116.3Room 34 Creative Services, LLCICS CalendarCWE-79WordPress ICS Calendar plugin <= 12.1.1 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-101034.315.0MattermostMattermostCWE-639Authenticated remote cluster can modify or delete posts it does not own in Ma…
CVE-2026-573916.514.3TangibleLoops & LogicCWE-79WordPress Loops & Logic plugin <= 4.2.3 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-615045.114.2rejettohfsCWE-79Rejetto HFS < 3.2.1 Stored XSS via File Names in Basic Web Listing
CVE-2026-156052.313.9n/awandbCWE-327wandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.downloa…
CVE-2026-577868.813.7purethemesWorkScout-CoreCWE-352WordPress WorkScout-Core plugin <= 1.7.08 - Cross Site Request Forgery (CSRF)…
CVE-2026-574136.413.6bdthemesInstant Image GeneratorCWE-918WordPress Instant Image Generator plugin <= 2.1.4 - Server Side Request Forge…
CVE-2026-95975.413.6MattermostMattermostCWE-305Deactivated guest accounts can authenticate via magic-link token in Mattermos…
CVE-2026-120815.013.0UnknownDatabase for Contact Form 7, WPforms, Elementor forms—Database for Contact Form 7, WPforms, Elementor forms < 1.5.2 - Unauthenticat…
CVE-2026-573656.512.9Hitesh ChandwanireCAPTCHA (v2 &amp; v3) for Asgaros ForumCWE-79WordPress reCAPTCHA (v2 & v3) for Asgaros Forum plugin <= 1.1.0 - Cross Site …
CVE-2026-574026.512.9wpdeskFlexible Refund and Return Order for WooCommerceCWE-79WordPress Flexible Refund and Return Order for WooCommerce plugin <= 1.0.51 -…
CVE-2026-574146.512.9QuantumCloudChatBot for eCommerce &#8211; WoowBotCWE-79WordPress ChatBot for eCommerce – WoowBot plugin <= 4.6.1 - Cross Site Script…
CVE-2026-574206.512.9NetrrAuthor Box WP LensCWE-79WordPress Author Box WP Lens plugin <= 2.1.5 - Cross Site Scripting (XSS) vul…
CVE-2026-576936.512.9SpacetimeAd InserterCWE-79WordPress Ad Inserter plugin <= 2.8.11 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-577116.512.9PSM PluginsSupportCandyCWE-79WordPress SupportCandy plugin <= 3.4.8 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-577806.512.9Plugin EnvisionEnvision Page BuilderCWE-79WordPress Envision Page Builder plugin <= 0.22 - Cross Site Scripting (XSS) v…
CVE-2026-577836.512.9merkuloveSpeakerCWE-79WordPress Speaker plugin <= 4.1.13 - Cross Site Scripting (XSS) vulnerability
CVE-2026-615025.111.8rejettohfsCWE-352Rejetto HFS < 3.2.1 Cross-Site Request Forgery via GET Requests
CVE-2026-404675.111.5GNUgawkCWE-416Use after free in gawk
CVE-2026-574328.411.2SHAYperlCWE-125Perl versions through 5.43.10 have an integer overflow in S_measure_struct le…
CVE-2026-576915.89.9EliAnti-Malware Security and Brute-Force FirewallCWE-79WordPress Anti-Malware Security and Brute-Force Firewall plugin <= 4.23.89 - …
CVE-2026-404682.19.9GNUgawkCWE-190Heap buffer overflow in gawk
CVE-2026-156847.39.1GlarysoftGlary UtilitiesCWE-59Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerabi…
CVE-2026-619704.98.4ThemeisleAuto Featured Image (Auto Post Thumbnail)CWE-918WordPress Auto Featured Image (Auto Post Thumbnail) plugin <= 5.0.4 - Server …
CVE-2026-155201.98.1GNULibreDWGCWE-119GNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section he…
CVE-2026-155241.96.8alioshrmemory-bank-mcpCWE-22alioshr memory-bank-mcp list-project-files-validation-factory.ts path traversal
CVE-2026-155261.96.8augmntaugments-mcp-serverCWE-22augmnt augments-mcp-server scan_project_deps scan-project-deps.ts scanProject…
CVE-2026-533655.56.8LinuxLinuxCWE-401vsock/virtio: fix zerocopy completion for multi-skb sends
CVE-2026-584896.86.7hedgedochedgedocCWE-352HedgeDoc: CSRF in GitHub Gist export callback
CVE-2026-155211.96.7makafelin8n-workflow-builderCWE-22makafeli n8n-workflow-builder update_node_from_file server.cjs path traversal
CVE-2026-155221.96.7tugcantopaloglugodot-mcpCWE-22tugcantopaloglu godot-mcp run_project index.js validatePath path traversal
CVE-2026-155271.96.7better-authbetter-iconsCWE-22better-auth better-icons scan_project_icons/sync_icon path traversal
CVE-2026-601036.86.3blenderblenderCWE-125Blender 3.0.0 - 5.1.2 Out-of-Bounds Read via crafted .blend SDNA block
CVE-2026-622395.35.8Dao-AILabflash-attentionCWE-59FlashAttention Symlink Attack via tarfile.extractall in hopper/setup.py
CVE-2026-533645.55.5LinuxLinuxCWE-401Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate()
CVE-2026-155281.95.4lamaalrajihkicad-mcpCWE-693lamaalrajih kicad-mcp path_validator.py protection mechanism
CVE-2026-619567.15.3hamsalamووسلام &#8211; همگام سازی ووکامرس و باسلامCWE-352WordPress ووسلام – همگام سازی ووکامرس و باسلام plugin <= 1.9.1 - Cross Site R…
CVE-2026-155156.45.3TencentPC ManagerCWE-426Tencent PC Manager QMUDisk Driver qmudisk64.sys uncontrolled search path
CVE-2026-94928.55.0GIGABYTEMBStorageCWE-782GIGABYTE|Gigabyte Control Center - Improper Access Control
CVE-2026-156837.54.3Lorex2K Indoor Wi-Fi Security CameraCWE-295Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certi…
CVE-2026-71627.83.7WinFspWinFspCWE-190Successful exploitation of the integer overflow vulnerability could allow an …
CVE-2026-156815.53.6AnyDeskAnyDeskCWE-59AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability
CVE-2026-156825.53.6AnyDeskAnyDeskCWE-59AnyDesk Support Information Link Following Denial-of-Service Vulnerability
CVE-2026-155515.51.4Samsung Open SourcerlottieCWE-190Samsung rlottie: Numeric truncation in gray_hline() leads to heap-based buffe…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-13 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.